rubiksgeek
Posts: 7 +0
Hello!
About 3 days ago, advertisements started playing in the background randomly. This can happen when I'm not even touching the computer.
Windows 7 is dual booted from my MacBook Pro. My windows partition is used for Skype and programs I run for school.
GMER Log:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-02-28 22:39:34
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Hitachi_HTS545016B9SA02 rev.PBBAC60Q
Running: kb9ottbu.exe; Driver: C:\Users\Admin\AppData\Local\Temp\pwlorpob.sys
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82A935D9 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82AB8092 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text dfsc.sys 90028000 245 Bytes [00, 00, 00, 00, 00, 00, 8B, ...]
.text dfsc.sys 900280F6 89 Bytes [CC, CC, 8B, FF, 55, 8B, EC, ...]
.text dfsc.sys 90028150 125 Bytes [75, 08, FF, 15, A4, C1, 02, ...]
.text dfsc.sys 900281CE 77 Bytes [6A, 01, EB, 19, 83, C0, D0, ...]
.text dfsc.sys 9002821C 41 Bytes [8B, 4D, F8, 8B, 35, F0, B1, ...]
.text ...
? C:\Windows\System32\Drivers\dfsc.sys suspicious PE modification
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\svchost.exe[820] ntdll.dll!NtProtectVirtualMemory 77BC5000 5 Bytes JMP 005E000A
.text C:\Windows\system32\svchost.exe[820] ntdll.dll!NtWriteVirtualMemory 77BC5B80 5 Bytes JMP 005F000A
.text C:\Windows\system32\svchost.exe[820] ntdll.dll!KiUserExceptionDispatcher 77BC60E8 5 Bytes JMP 005D000A
? C:\Windows\system32\svchost.exe[820] C:\Windows\system32\smss.exe image checksum mismatch; time/date stamp mismatch;
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[932] USER32.dll!TrackPopupMenu 761A4B3B 5 Bytes JMP 66A6AF78 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Windows\System32\ping.exe[1320] ntdll.dll!NtCreateProcess 77BC4780 5 Bytes JMP 002C000A
.text C:\Windows\System32\ping.exe[1320] ntdll.dll!NtCreateProcessEx 77BC4790 5 Bytes JMP 002D000A
.text C:\Windows\System32\ping.exe[1320] ntdll.dll!NtCreateUserProcess 77BC4860 5 Bytes JMP 005C000A
.text C:\Windows\System32\ping.exe[1320] ntdll.dll!NtProtectVirtualMemory 77BC5000 5 Bytes JMP 001E000A
.text C:\Windows\System32\ping.exe[1320] ntdll.dll!NtWriteVirtualMemory 77BC5B80 5 Bytes JMP 001F000A
.text C:\Windows\System32\ping.exe[1320] ntdll.dll!KiUserExceptionDispatcher 77BC60E8 5 Bytes JMP 001D000A
.text C:\Windows\System32\ping.exe[1320] USER32.dll!GetCursorPos 7617C198 5 Bytes JMP 0063000A
.text C:\Windows\System32\ping.exe[1320] USER32.dll!GetForegroundWindow 7618565D 5 Bytes JMP 0065000A
.text C:\Windows\System32\ping.exe[1320] USER32.dll!WindowFromPoint 761A6D0C 5 Bytes JMP 0064000A
.text C:\Windows\System32\ping.exe[1320] ole32.dll!CoCreateInstance 7771590C 5 Bytes JMP 0062000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3208] ntdll.dll!LdrLoadDll 77BDF425 5 Bytes JMP 000A13F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlFreeHeap] 83EC8B55
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlFreeUnicodeString] 458D74EC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!DbgPrintEx] 15FF50F8
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlUpcaseUnicodeChar] [00ECF014] C:\Windows\system32\smss.exe (Windows Session Manager/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtClose] 01FC7531
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSetInformationFile] 458DF875
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtOpenFile] 15FF508C
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQueryInformationFile] [00ECF004] C:\Windows\system32\smss.exe (Windows Session Manager/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCompareUnicodeString] 458D086A
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAppendUnicodeStringToString] 458D50F8
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAllocateHeap] 15FF508C
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlUnicodeStringToInteger] [00ECF000] C:\Windows\system32\smss.exe (Windows Session Manager/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtCreatePagingFile] 508C458D
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!_alldiv] F00815FF
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQuerySystemInformation] 458B00EC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!_allmul] E84533E4
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtFlushKey] 33EC4533
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtDeleteValueKey] C3C9F045
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSetValueKey] 8BEC8B55
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtCreateKey] EC833040
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCompareMemory] 57565314
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtDeviceIoControlFile] D98B388B
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlInitUnicodeStringEx] EB04708D
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlExtendedIntegerMultiply] 46B70F20
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQueryVolumeInformationFile] 30448D1A
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQueryInformationProcess] F0F0681C
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAppendUnicodeToString] 4F5000EC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlInitUnicodeString] 00DCAFE8
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSetSystemInformation] 85595900
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlDosPathNameToNtPathName_U] 811374C0
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlExpandEnvironmentStrings_U] 00011CC6
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQueryValueKey] [75FF8500] C:\Windows\system32\SETUPAPI.dll (Windows Setup API/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtCreateFile] 5FC033DC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtOpenKey] C2C95B5E
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!_vsnwprintf] 468B0008
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!EtwEventWrite] F4458908
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!EtwEventEnabled] 8B0C468B
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSetSecurityObject] 45890473
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetOwnerSecurityDescriptor] [74F685F0] C:\Windows\system32\PROPSYS.dll (Microsoft Property System/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetDaclSecurityDescriptor] D8BB8D77
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAddAccessAllowedAce] 57000000
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCreateAcl] ED015068
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCreateSecurityDescriptor] 8D426A00
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAllocateAndInitializeSid] 4E50FC45
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCreateUnicodeString] F0E015FF
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtReadFile] C08500EC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!_chkstk] 458D537C
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtMakeTemporaryObject] 046A50EC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtCreateSymbolicLinkObject] 50F8458D
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtOpenDirectoryObject] [75FF096A] C:\Windows\system32\SETUPAPI.dll (Windows Setup API/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAnsiStringToUnicodeString] DC15FFFC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlInitAnsiString] 8500ECF0
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!_stricmp] 8B317CC0
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!qsort] 452BF845
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlRandomEx] F0453BF4
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!LdrVerifyImageMatchesChecksumEx] 006A2673
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtCreateDirectoryObject] FFFC75FF
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlEqualUnicodeString] ECF0D415
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!memcpy] 7CC08500
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!_wcsicmp] 0C4D8B17
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetEnvironmentVariable] 1F8B018B
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!iswspace] 8908558B
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlQueryEnvironmentVariable_U] 5F8BC21C
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlFindSetBits] C25C8904
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlInterlockedSetBitRun] 01894004
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlTestBit] FFFC75FF
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlUnlockBootStatusData] ECF0D815
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlGetSetBootStatusData] 40C78300
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlLockBootStatusData] 8F75F685
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetSaclSecurityDescriptor] E940C033
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAddMandatoryAce] FFFFFF67
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlLengthSid] 51EC8B55
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlGetAce] 0173A051
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlPrefixUnicodeString] 565300ED
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQuerySymbolicLinkObject] C0BE0F57
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtOpenSymbolicLinkObject] 7D89FF33
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQueryDirectoryObject] DC2AE8F8
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlTimeToTimeFields] DC8B0000
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSerializeBoot] 45C7F633
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!memset] 001000FC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtMapViewOfSection] FC458B00
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtCreateSection] 0F73F83B
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlQueryRegistryValues] 11E8C72B
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlDosSearchPath_U] 8B0000DC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtResumeThread] 2BC38BF4
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtWaitForSingleObject] 8DF88BC6
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtTerminateProcess] 5750FC45
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlDestroyProcessParameters] FF056A56
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCreateUserProcess] ECF0D015
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCreateProcessParametersEx] 00043D00
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtDisplayString] D574C000
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtWriteFile] 047DC085
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!_wcsupr] 60EBC033
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAdjustPrivilege] F003C033
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtInitializeRegistry] 468D016A
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!TpReleaseWork] 18685038
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!TpPostWork] FF00ECF1
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!TpAllocWork] ECF0CC15
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSetEvent] [75C08400] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetCurrentEnvironment] 85068B08
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCreateEnvironment] EBE375C0
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtOpenEvent] 68006A3C
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetBits] 00040000
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlClearAllBits] F07415FF
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlInitializeBitMap] F88B00EC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtAlpcCreatePort] 2974FF85
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSetInformationProcess] FF016A57
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCreateTagHeap] 15FF4476
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlReleaseSRWLockExclusive] [00ECF020] C:\Windows\system32\smss.exe (Windows Session Manager/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAcquireSRWLockExclusive] 127CC085
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSetInformationThread] 8B0C75FF
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQueryInformationToken] 0875FFCE
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtOpenThreadToken] 81E8C78B
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtAlpcImpersonateClientOfPort] 89FFFFFE
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlReleaseSRWLockShared] FF57F845
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAcquireSRWLockShared] ECF02415
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!TpSetPoolMinThreads] F8458B00
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtAlpcDisconnectPort] 5FEC658D
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlInitializeSRWLock] C2C95B5E
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtConnectPort] 8B550008
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!AlpcGetMessageAttribute] 3CEC81EC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtAlpcAcceptConnectPort] 56000002
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtAlpcOpenSenderProcess] E856F08B
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtAlpcCancelMessage] 0000DB36
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtAlpcSendWaitReceivePort] 00803D59
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!AlpcInitializeMessageAttribute] 870F0000
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetThreadIsCritical] 000000AC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtRequestWaitReplyPort] 0F2E3E80
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtDuplicateObject] 0000A384
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtCreateEvent] 858D5600
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlWakeConditionVariable] FFFFFDC8
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlClearBits] ECF12068
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlDeleteNoSplay] 15FF5000
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtClearEvent] [00ECF02C] C:\Windows\system32\smss.exe (Windows Session Manager/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSleepConditionVariableSRW] FDC8858D
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlWakeAllConditionVariable] 2E6AFFFF
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlFindClearBits] DB06E850
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlFreeSid] C4830000
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtRaiseHardError] 74C08514
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtWaitForMultipleObjects] 66C9337B
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!TpAllocAlpcCompletion] C0830889
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!TpAllocPool] F1906802
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetProcessIsCritical] E85000EC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!EtwEventRegister] 0000DAF2
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetHeapInformation] C0855959
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlInitializeConditionVariable] 858D6275
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtDelayExecution] FFFFFDC8
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlUnicodeStringToAnsiString] CC758D50
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQueryEvent] 000DFFE8
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlReleasePrivilege] 19685000
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAcquirePrivilege] 8D000200
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!LdrQueryImageFileExecutionOptions] FF50FC45
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!wcstoul] ECF03815
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!_wcsnicmp] 7CC08500
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlUnhandledExceptionFilter] EC458D3F
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlUnwind] 50106A50
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlNormalizeProcessParams] 2868026A
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlConnectToSm] FF00ECF2
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSendMsgToSm] F633FC75
---- Devices - GMER 1.0.15 ----
Device \Driver\ACPI_HAL \Device\00000047 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\00000074 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\00000076 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
---- Modules - GMER 1.0.15 ----
Module (noname) (*** hidden *** ) 90011000-90027000 (90112 bytes)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002608d835bd
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002608d835bd (not active ControlSet)
---- Files - GMER 1.0.15 ----
File C:\Windows\$NtUninstallKB36107$\3266436414 0 bytes
File C:\Windows\$NtUninstallKB36107$\664251036 0 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\@ 2048 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\bckfg.tmp 856 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\cfg.ini 377 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\Desktop.ini 4608 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\keywords 18 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\kwrd.dll 223744 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\L 0 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\L\xadqgnnk 78336 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\lsflt7.ver 5176 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\oemid 186 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\U 0 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\U\00000001.@ 2048 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\U\00000002.@ 224768 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\U\00000004.@ 1024 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\U\80000000.@ 66560 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\U\80000004.@ 12800 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\U\80000032.@ 73216 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\version 842 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{C6FD1004-628C-11E1-A025-002608D835BD}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{C6FD1005-628C-11E1-A025-002608D835BD}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{C6FD1006-628C-11E1-A025-002608D835BD}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{D72458D4-628C-11E1-A025-002608D835BD}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{D72458D5-628C-11E1-A025-002608D835BD}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{D72458D6-628C-11E1-A025-002608D835BD}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{E746E6B4-628C-11E1-A025-002608D835BD}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{E746E6B5-628C-11E1-A025-002608D835BD}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{E746E6B6-628C-11E1-A025-002608D835BD}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{FE5B8FE4-628C-11E1-A025-002608D835BD}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\34A05EZ3\errorPageStrings[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\80N60RJN\ErrorPageTemplate[1] 2168 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8PG8Q4L7\tools[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T8Y5WIVR\httpErrorPagesScripts[1] 8601 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T8Y5WIVR\favcenter[1] 3366 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VY8W1WDM\errorPageStrings[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VY8W1WDM\dnserror[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EBE9JRQ2\dnserror[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHSFCM3J\down[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LAZJO355\ErrorPageTemplate[1] 2168 bytes
---- EOF - GMER 1.0.15 ----
.
About 3 days ago, advertisements started playing in the background randomly. This can happen when I'm not even touching the computer.
Windows 7 is dual booted from my MacBook Pro. My windows partition is used for Skype and programs I run for school.
GMER Log:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-02-28 22:39:34
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Hitachi_HTS545016B9SA02 rev.PBBAC60Q
Running: kb9ottbu.exe; Driver: C:\Users\Admin\AppData\Local\Temp\pwlorpob.sys
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82A935D9 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82AB8092 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text dfsc.sys 90028000 245 Bytes [00, 00, 00, 00, 00, 00, 8B, ...]
.text dfsc.sys 900280F6 89 Bytes [CC, CC, 8B, FF, 55, 8B, EC, ...]
.text dfsc.sys 90028150 125 Bytes [75, 08, FF, 15, A4, C1, 02, ...]
.text dfsc.sys 900281CE 77 Bytes [6A, 01, EB, 19, 83, C0, D0, ...]
.text dfsc.sys 9002821C 41 Bytes [8B, 4D, F8, 8B, 35, F0, B1, ...]
.text ...
? C:\Windows\System32\Drivers\dfsc.sys suspicious PE modification
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\svchost.exe[820] ntdll.dll!NtProtectVirtualMemory 77BC5000 5 Bytes JMP 005E000A
.text C:\Windows\system32\svchost.exe[820] ntdll.dll!NtWriteVirtualMemory 77BC5B80 5 Bytes JMP 005F000A
.text C:\Windows\system32\svchost.exe[820] ntdll.dll!KiUserExceptionDispatcher 77BC60E8 5 Bytes JMP 005D000A
? C:\Windows\system32\svchost.exe[820] C:\Windows\system32\smss.exe image checksum mismatch; time/date stamp mismatch;
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[932] USER32.dll!TrackPopupMenu 761A4B3B 5 Bytes JMP 66A6AF78 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Windows\System32\ping.exe[1320] ntdll.dll!NtCreateProcess 77BC4780 5 Bytes JMP 002C000A
.text C:\Windows\System32\ping.exe[1320] ntdll.dll!NtCreateProcessEx 77BC4790 5 Bytes JMP 002D000A
.text C:\Windows\System32\ping.exe[1320] ntdll.dll!NtCreateUserProcess 77BC4860 5 Bytes JMP 005C000A
.text C:\Windows\System32\ping.exe[1320] ntdll.dll!NtProtectVirtualMemory 77BC5000 5 Bytes JMP 001E000A
.text C:\Windows\System32\ping.exe[1320] ntdll.dll!NtWriteVirtualMemory 77BC5B80 5 Bytes JMP 001F000A
.text C:\Windows\System32\ping.exe[1320] ntdll.dll!KiUserExceptionDispatcher 77BC60E8 5 Bytes JMP 001D000A
.text C:\Windows\System32\ping.exe[1320] USER32.dll!GetCursorPos 7617C198 5 Bytes JMP 0063000A
.text C:\Windows\System32\ping.exe[1320] USER32.dll!GetForegroundWindow 7618565D 5 Bytes JMP 0065000A
.text C:\Windows\System32\ping.exe[1320] USER32.dll!WindowFromPoint 761A6D0C 5 Bytes JMP 0064000A
.text C:\Windows\System32\ping.exe[1320] ole32.dll!CoCreateInstance 7771590C 5 Bytes JMP 0062000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3208] ntdll.dll!LdrLoadDll 77BDF425 5 Bytes JMP 000A13F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlFreeHeap] 83EC8B55
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlFreeUnicodeString] 458D74EC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!DbgPrintEx] 15FF50F8
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlUpcaseUnicodeChar] [00ECF014] C:\Windows\system32\smss.exe (Windows Session Manager/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtClose] 01FC7531
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSetInformationFile] 458DF875
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtOpenFile] 15FF508C
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQueryInformationFile] [00ECF004] C:\Windows\system32\smss.exe (Windows Session Manager/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCompareUnicodeString] 458D086A
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAppendUnicodeStringToString] 458D50F8
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAllocateHeap] 15FF508C
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlUnicodeStringToInteger] [00ECF000] C:\Windows\system32\smss.exe (Windows Session Manager/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtCreatePagingFile] 508C458D
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!_alldiv] F00815FF
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQuerySystemInformation] 458B00EC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!_allmul] E84533E4
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtFlushKey] 33EC4533
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtDeleteValueKey] C3C9F045
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSetValueKey] 8BEC8B55
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtCreateKey] EC833040
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCompareMemory] 57565314
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtDeviceIoControlFile] D98B388B
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlInitUnicodeStringEx] EB04708D
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlExtendedIntegerMultiply] 46B70F20
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQueryVolumeInformationFile] 30448D1A
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQueryInformationProcess] F0F0681C
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAppendUnicodeToString] 4F5000EC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlInitUnicodeString] 00DCAFE8
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSetSystemInformation] 85595900
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlDosPathNameToNtPathName_U] 811374C0
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlExpandEnvironmentStrings_U] 00011CC6
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQueryValueKey] [75FF8500] C:\Windows\system32\SETUPAPI.dll (Windows Setup API/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtCreateFile] 5FC033DC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtOpenKey] C2C95B5E
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!_vsnwprintf] 468B0008
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!EtwEventWrite] F4458908
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!EtwEventEnabled] 8B0C468B
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSetSecurityObject] 45890473
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetOwnerSecurityDescriptor] [74F685F0] C:\Windows\system32\PROPSYS.dll (Microsoft Property System/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetDaclSecurityDescriptor] D8BB8D77
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAddAccessAllowedAce] 57000000
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCreateAcl] ED015068
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCreateSecurityDescriptor] 8D426A00
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAllocateAndInitializeSid] 4E50FC45
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCreateUnicodeString] F0E015FF
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtReadFile] C08500EC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!_chkstk] 458D537C
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtMakeTemporaryObject] 046A50EC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtCreateSymbolicLinkObject] 50F8458D
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtOpenDirectoryObject] [75FF096A] C:\Windows\system32\SETUPAPI.dll (Windows Setup API/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAnsiStringToUnicodeString] DC15FFFC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlInitAnsiString] 8500ECF0
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!_stricmp] 8B317CC0
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!qsort] 452BF845
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlRandomEx] F0453BF4
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!LdrVerifyImageMatchesChecksumEx] 006A2673
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtCreateDirectoryObject] FFFC75FF
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlEqualUnicodeString] ECF0D415
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!memcpy] 7CC08500
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!_wcsicmp] 0C4D8B17
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetEnvironmentVariable] 1F8B018B
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!iswspace] 8908558B
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlQueryEnvironmentVariable_U] 5F8BC21C
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlFindSetBits] C25C8904
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlInterlockedSetBitRun] 01894004
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlTestBit] FFFC75FF
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlUnlockBootStatusData] ECF0D815
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlGetSetBootStatusData] 40C78300
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlLockBootStatusData] 8F75F685
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetSaclSecurityDescriptor] E940C033
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAddMandatoryAce] FFFFFF67
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlLengthSid] 51EC8B55
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlGetAce] 0173A051
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlPrefixUnicodeString] 565300ED
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQuerySymbolicLinkObject] C0BE0F57
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtOpenSymbolicLinkObject] 7D89FF33
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQueryDirectoryObject] DC2AE8F8
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlTimeToTimeFields] DC8B0000
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSerializeBoot] 45C7F633
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!memset] 001000FC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtMapViewOfSection] FC458B00
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtCreateSection] 0F73F83B
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlQueryRegistryValues] 11E8C72B
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlDosSearchPath_U] 8B0000DC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtResumeThread] 2BC38BF4
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtWaitForSingleObject] 8DF88BC6
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtTerminateProcess] 5750FC45
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlDestroyProcessParameters] FF056A56
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCreateUserProcess] ECF0D015
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCreateProcessParametersEx] 00043D00
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtDisplayString] D574C000
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtWriteFile] 047DC085
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!_wcsupr] 60EBC033
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAdjustPrivilege] F003C033
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtInitializeRegistry] 468D016A
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!TpReleaseWork] 18685038
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!TpPostWork] FF00ECF1
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!TpAllocWork] ECF0CC15
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSetEvent] [75C08400] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetCurrentEnvironment] 85068B08
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCreateEnvironment] EBE375C0
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtOpenEvent] 68006A3C
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetBits] 00040000
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlClearAllBits] F07415FF
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlInitializeBitMap] F88B00EC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtAlpcCreatePort] 2974FF85
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSetInformationProcess] FF016A57
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlCreateTagHeap] 15FF4476
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlReleaseSRWLockExclusive] [00ECF020] C:\Windows\system32\smss.exe (Windows Session Manager/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAcquireSRWLockExclusive] 127CC085
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtSetInformationThread] 8B0C75FF
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQueryInformationToken] 0875FFCE
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtOpenThreadToken] 81E8C78B
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtAlpcImpersonateClientOfPort] 89FFFFFE
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlReleaseSRWLockShared] FF57F845
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAcquireSRWLockShared] ECF02415
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!TpSetPoolMinThreads] F8458B00
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtAlpcDisconnectPort] 5FEC658D
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlInitializeSRWLock] C2C95B5E
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtConnectPort] 8B550008
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!AlpcGetMessageAttribute] 3CEC81EC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtAlpcAcceptConnectPort] 56000002
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtAlpcOpenSenderProcess] E856F08B
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtAlpcCancelMessage] 0000DB36
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtAlpcSendWaitReceivePort] 00803D59
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!AlpcInitializeMessageAttribute] 870F0000
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetThreadIsCritical] 000000AC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtRequestWaitReplyPort] 0F2E3E80
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtDuplicateObject] 0000A384
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtCreateEvent] 858D5600
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlWakeConditionVariable] FFFFFDC8
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlClearBits] ECF12068
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlDeleteNoSplay] 15FF5000
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtClearEvent] [00ECF02C] C:\Windows\system32\smss.exe (Windows Session Manager/Microsoft Corporation)
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSleepConditionVariableSRW] FDC8858D
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlWakeAllConditionVariable] 2E6AFFFF
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlFindClearBits] DB06E850
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlFreeSid] C4830000
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtRaiseHardError] 74C08514
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtWaitForMultipleObjects] 66C9337B
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!TpAllocAlpcCompletion] C0830889
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!TpAllocPool] F1906802
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetProcessIsCritical] E85000EC
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!EtwEventRegister] 0000DAF2
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSetHeapInformation] C0855959
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlInitializeConditionVariable] 858D6275
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtDelayExecution] FFFFFDC8
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlUnicodeStringToAnsiString] CC758D50
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!NtQueryEvent] 000DFFE8
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlReleasePrivilege] 19685000
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlAcquirePrivilege] 8D000200
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!LdrQueryImageFileExecutionOptions] FF50FC45
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!wcstoul] ECF03815
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!_wcsnicmp] 7CC08500
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlUnhandledExceptionFilter] EC458D3F
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlUnwind] 50106A50
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlNormalizeProcessParams] 2868026A
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlConnectToSm] FF00ECF2
IAT C:\Windows\system32\svchost.exe[820] @ C:\Windows\system32\smss.exe [ntdll.dll!RtlSendMsgToSm] F633FC75
---- Devices - GMER 1.0.15 ----
Device \Driver\ACPI_HAL \Device\00000047 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\00000074 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\00000076 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
---- Modules - GMER 1.0.15 ----
Module (noname) (*** hidden *** ) 90011000-90027000 (90112 bytes)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002608d835bd
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002608d835bd (not active ControlSet)
---- Files - GMER 1.0.15 ----
File C:\Windows\$NtUninstallKB36107$\3266436414 0 bytes
File C:\Windows\$NtUninstallKB36107$\664251036 0 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\@ 2048 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\bckfg.tmp 856 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\cfg.ini 377 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\Desktop.ini 4608 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\keywords 18 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\kwrd.dll 223744 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\L 0 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\L\xadqgnnk 78336 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\lsflt7.ver 5176 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\oemid 186 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\U 0 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\U\00000001.@ 2048 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\U\00000002.@ 224768 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\U\00000004.@ 1024 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\U\80000000.@ 66560 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\U\80000004.@ 12800 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\U\80000032.@ 73216 bytes
File C:\Windows\$NtUninstallKB36107$\664251036\version 842 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{C6FD1004-628C-11E1-A025-002608D835BD}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{C6FD1005-628C-11E1-A025-002608D835BD}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{C6FD1006-628C-11E1-A025-002608D835BD}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{D72458D4-628C-11E1-A025-002608D835BD}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{D72458D5-628C-11E1-A025-002608D835BD}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{D72458D6-628C-11E1-A025-002608D835BD}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{E746E6B4-628C-11E1-A025-002608D835BD}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{E746E6B5-628C-11E1-A025-002608D835BD}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{E746E6B6-628C-11E1-A025-002608D835BD}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{FE5B8FE4-628C-11E1-A025-002608D835BD}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\34A05EZ3\errorPageStrings[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\80N60RJN\ErrorPageTemplate[1] 2168 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8PG8Q4L7\tools[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T8Y5WIVR\httpErrorPagesScripts[1] 8601 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T8Y5WIVR\favcenter[1] 3366 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VY8W1WDM\errorPageStrings[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VY8W1WDM\dnserror[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EBE9JRQ2\dnserror[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHSFCM3J\down[1] 0 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LAZJO355\ErrorPageTemplate[1] 2168 bytes
---- EOF - GMER 1.0.15 ----
.