GMER 1.0.15.14972 -
http://www.gmer.netRootkit scan 2009-06-16 11:23:04
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.15 ----
Code 84AB67FE ZwEnumerateKey
Code 8495416E ZwFlushInstructionCache
Code 845D11ED IofCallDriver
Code 847C552D IofCompleteRequest
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!IofCallDriver 804EEF9C 5 Bytes JMP 845D11F2
.text ntkrnlpa.exe!IofCompleteRequest 804EF02C 5 Bytes JMP 847C5532
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 805B51D2 5 Bytes JMP 84954172
PAGE ntkrnlpa.exe!ZwEnumerateKey 806228DE 5 Bytes JMP 84AB6802
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe[188] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 08B2000A
.text C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe[188] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 08C4000A
.text C:\WINDOWS\RTHDCPL.EXE[236] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 09BC000A
.text C:\WINDOWS\RTHDCPL.EXE[236] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 09BD000A
.text C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe[252] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 08B1000A
.text C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe[252] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 08B2000A
.text C:\Program Files\CA\eTrustITM\realmon.exe[264] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 08CC000A
.text C:\WINDOWS\system32\ctfmon.exe[292] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 089D000A
.text C:\WINDOWS\system32\ctfmon.exe[292] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 08AF000A
.text C:\Acer\LANScope Agent\awServ.exe[300] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0195000A
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe[312] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 08B3000A
.text C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe[312] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 08C5000A
.text C:\WINDOWS\system32\sistray.exe[320] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 08BA000A
.text C:\WINDOWS\system32\sistray.exe[320] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 08BB000A
.text C:\Program Files\Outlook Express\msimn.exe[328] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00A6000A
.text C:\Program Files\CA\SharedComponents\iTechnology\igateway.exe[544] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00B3000A
.text C:\Program Files\CA\eTrustITM\InoRpc.exe[556] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00A3000A
.text C:\Program Files\CA\eTrustITM\InoRT.exe[604] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00B3000A
.text ...
.text C:\WINDOWS\system32\winlogon.exe[772] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0072000A
.text C:\WINDOWS\system32\winlogon.exe[772] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0074000A
.text C:\WINDOWS\system32\services.exe[816] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0085000A
.text C:\WINDOWS\system32\services.exe[816] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0086000A
.text C:\WINDOWS\system32\lsass.exe[828] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0097000A
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[1096] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 009F000A
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[1096] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00A0000A
.text C:\Acer\LANScope Agent\LockKM.exe[1500] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0117000A
.text C:\Acer\LANScope Agent\LockKM.exe[1500] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0118000A
.text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1596] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0084000A
.text C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe[1596] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 0085000A
.text C:\WINDOWS\system32\spoolsv.exe[1660] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00BD000A
.text C:\WINDOWS\Explorer.EXE[1848] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 00AF000A
.text C:\WINDOWS\Explorer.EXE[1848] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00B0000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[1868] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 00B6000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[1868] WININET.dll!HttpAddRequestHeadersA 771C411E 5 Bytes JMP 00C2000C
.text C:\Program Files\Internet Explorer\Iexplore.exe[1868] WININET.dll!HttpAddRequestHeadersW 771CEF65 5 Bytes JMP 00CD000A
.text C:\Program Files\Internet Explorer\Iexplore.exe[1868] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 00CEF9F0 \\?\globalroot\systemroot\system32\UACfkeafpcclvbnabb.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[1868] WS2_32.dll!connect 71AB406A 5 Bytes JMP 00CF08A0 \\?\globalroot\systemroot\system32\UACfkeafpcclvbnabb.dll
.text C:\Program Files\Internet Explorer\Iexplore.exe[1868] WS2_32.dll!send 71AB428A 5 Bytes JMP 00CF0780 \\?\globalroot\systemroot\system32\UACfkeafpcclvbnabb.dll