Hello,
All of my search engines (google, yahoo etc.) are not working. When I type in a direct link it works fine, or even if I click on a link it usually works. When I try to search this is what comes up:
"The connection was reset
The connection to the server was reset while the page was loading.
* The site could be temporarily unavailable or too busy. Try again in a few
moments.
* If you are unable to load any pages, check your computer's network
connection.
* If your computer or network is protected by a firewall or proxy, make sure
that Firefox is permitted to access the Web."
I've tried every browser. Also, the DDS scan link is not working for me.
Here is my malwarebytes scan:
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8357
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 7.0.5730.13
12/14/2011 9:50:24 AM
mbam-log-2011-12-14 (09-50-24).txt
Scan type: Full scan (C:\|D:\|E:\|G:\|)
Objects scanned: 328717
Time elapsed: 26 minute(s), 0 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 12
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\i386\fsquirt.exe (Trojan.Dropper.BCM) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP356\A0084412.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP356\A0084413.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP372\A0090234.exe (Trojan.Dropper.BCM) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP372\A0090235.exe (Trojan.Dropper.BCM) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP372\A0090238.exe (Trojan.Dropper.BCM) -> Quarantined and deleted successfully.
c:\tdsskiller_quarantine\23.09.2011_11.54.12\mbr0000\tdlfs0000\tsk0004.dta (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\tdsskiller_quarantine\23.09.2011_11.54.12\mbr0000\tdlfs0000\tsk0016.dta (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\tdsskiller_quarantine\23.09.2011_11.54.12\mbr0000\tdlfs0000\tsk0017.dta (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\tdsskiller_quarantine\23.09.2011_11.54.12\mbr0000\tdlfs0000\tsk0018.dta (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\$ntservicepackuninstall$\fsquirt.exe (Trojan.Dropper.BCM) -> Quarantined and deleted successfully.
c:\WINDOWS\servicepackfiles\i386\fsquirt.exe (Trojan.Dropper.BCM) -> Quarantined and deleted successfully.
Here is my GMER log:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-12-14 12:50:43
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST316081 rev.3.AD
Running: v0n1dp4x.exe; Driver: C:\DOCUME~1\OFFICE~1\LOCALS~1\Temp\awlyyfow.sys
---- System - GMER 1.0.15 ----
SSDT 8978A8A0 ZwAlertResumeThread
SSDT 897A89E0 ZwAlertThread
SSDT 8980DA08 ZwAllocateVirtualMemory
SSDT 897F1738 ZwAssignProcessToJobObject
SSDT 89678E30 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xA1C63020]
SSDT 89735720 ZwCreateMutant
SSDT 89ABA1F0 ZwCreateSymbolicLinkObject
SSDT 89768190 ZwCreateThread
SSDT 8980F908 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xA1C632A0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xA1C63800]
SSDT 89795C58 ZwDuplicateObject
SSDT 8996B0B8 ZwFreeVirtualMemory
SSDT 89782B10 ZwImpersonateAnonymousToken
SSDT 8978CAB0 ZwImpersonateThread
SSDT 8967F4E8 ZwLoadDriver
SSDT 89A0F940 ZwMapViewOfSection
SSDT 89786318 ZwOpenEvent
SSDT 896CD378 ZwOpenProcess
SSDT 89A32D88 ZwOpenProcessToken
SSDT 89783F40 ZwOpenSection
SSDT 897C70D8 ZwOpenThread
SSDT 89A91428 ZwProtectVirtualMemory
SSDT 89B48E50 ZwResumeThread
SSDT 8977A0A8 ZwSetContextThread
SSDT 897C1800 ZwSetInformationProcess
SSDT 897AF990 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xA1C63A50]
SSDT 89788198 ZwSuspendProcess
SSDT 8977D3B0 ZwSuspendThread
SSDT 899E73C8 ZwTerminateProcess
SSDT 8977EBC8 ZwTerminateThread
SSDT 89A31770 ZwUnmapViewOfSection
SSDT 8981CE80 ZwWriteVirtualMemory
Code \??\C:\DOCUME~1\OFFICE~1\LOCALS~1\Temp\catchme.sys pIofCallDriver
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2D68 80504604 4 Bytes CALL 94D9ADFD
? npissll.sys The system cannot find the file specified. !
.text iaStor.sys B9E7ECFC 1 Byte [CC] {INT 3 }
? SYMEFA.SYS The system cannot find the file specified. !
init C:\WINDOWS\system32\drivers\Senfilt.sys entry point in "init" section [0xA5631A00]
? C:\DOCUME~1\OFFICE~1\LOCALS~1\Temp\aswMBR.sys The system cannot find the file specified. !
? C:\WINDOWS\system32\Drivers\PROCEXP113.SYS The system cannot find the file specified. !
? C:\DOCUME~1\OFFICE~1\LOCALS~1\Temp\catchme.sys The system cannot find the file specified. !
? C:\WINDOWS\system32\drivers\mbamswissarmy.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[2936] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002D0010
IAT C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002D0010
IAT C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002D0010
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device Cdfs.SYS (CD-ROM File System Driver/Microsoft Corporation)
---- Threads - GMER 1.0.15 ----
Thread System [4:156] 89B99161
Thread System [4:400] 89A3FC30
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@RequireSignedAppInit_DLLs 1
---- EOF - GMER 1.0.15 ----
All of my search engines (google, yahoo etc.) are not working. When I type in a direct link it works fine, or even if I click on a link it usually works. When I try to search this is what comes up:
"The connection was reset
The connection to the server was reset while the page was loading.
* The site could be temporarily unavailable or too busy. Try again in a few
moments.
* If you are unable to load any pages, check your computer's network
connection.
* If your computer or network is protected by a firewall or proxy, make sure
that Firefox is permitted to access the Web."
I've tried every browser. Also, the DDS scan link is not working for me.
Here is my malwarebytes scan:
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8357
Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 7.0.5730.13
12/14/2011 9:50:24 AM
mbam-log-2011-12-14 (09-50-24).txt
Scan type: Full scan (C:\|D:\|E:\|G:\|)
Objects scanned: 328717
Time elapsed: 26 minute(s), 0 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 12
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\i386\fsquirt.exe (Trojan.Dropper.BCM) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP356\A0084412.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP356\A0084413.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP372\A0090234.exe (Trojan.Dropper.BCM) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP372\A0090235.exe (Trojan.Dropper.BCM) -> Quarantined and deleted successfully.
c:\system volume information\_restore{46de8921-1d39-44d2-a9e9-64119261f211}\RP372\A0090238.exe (Trojan.Dropper.BCM) -> Quarantined and deleted successfully.
c:\tdsskiller_quarantine\23.09.2011_11.54.12\mbr0000\tdlfs0000\tsk0004.dta (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\tdsskiller_quarantine\23.09.2011_11.54.12\mbr0000\tdlfs0000\tsk0016.dta (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\tdsskiller_quarantine\23.09.2011_11.54.12\mbr0000\tdlfs0000\tsk0017.dta (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\tdsskiller_quarantine\23.09.2011_11.54.12\mbr0000\tdlfs0000\tsk0018.dta (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\$ntservicepackuninstall$\fsquirt.exe (Trojan.Dropper.BCM) -> Quarantined and deleted successfully.
c:\WINDOWS\servicepackfiles\i386\fsquirt.exe (Trojan.Dropper.BCM) -> Quarantined and deleted successfully.
Here is my GMER log:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-12-14 12:50:43
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST316081 rev.3.AD
Running: v0n1dp4x.exe; Driver: C:\DOCUME~1\OFFICE~1\LOCALS~1\Temp\awlyyfow.sys
---- System - GMER 1.0.15 ----
SSDT 8978A8A0 ZwAlertResumeThread
SSDT 897A89E0 ZwAlertThread
SSDT 8980DA08 ZwAllocateVirtualMemory
SSDT 897F1738 ZwAssignProcessToJobObject
SSDT 89678E30 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xA1C63020]
SSDT 89735720 ZwCreateMutant
SSDT 89ABA1F0 ZwCreateSymbolicLinkObject
SSDT 89768190 ZwCreateThread
SSDT 8980F908 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xA1C632A0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xA1C63800]
SSDT 89795C58 ZwDuplicateObject
SSDT 8996B0B8 ZwFreeVirtualMemory
SSDT 89782B10 ZwImpersonateAnonymousToken
SSDT 8978CAB0 ZwImpersonateThread
SSDT 8967F4E8 ZwLoadDriver
SSDT 89A0F940 ZwMapViewOfSection
SSDT 89786318 ZwOpenEvent
SSDT 896CD378 ZwOpenProcess
SSDT 89A32D88 ZwOpenProcessToken
SSDT 89783F40 ZwOpenSection
SSDT 897C70D8 ZwOpenThread
SSDT 89A91428 ZwProtectVirtualMemory
SSDT 89B48E50 ZwResumeThread
SSDT 8977A0A8 ZwSetContextThread
SSDT 897C1800 ZwSetInformationProcess
SSDT 897AF990 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xA1C63A50]
SSDT 89788198 ZwSuspendProcess
SSDT 8977D3B0 ZwSuspendThread
SSDT 899E73C8 ZwTerminateProcess
SSDT 8977EBC8 ZwTerminateThread
SSDT 89A31770 ZwUnmapViewOfSection
SSDT 8981CE80 ZwWriteVirtualMemory
Code \??\C:\DOCUME~1\OFFICE~1\LOCALS~1\Temp\catchme.sys pIofCallDriver
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2D68 80504604 4 Bytes CALL 94D9ADFD
? npissll.sys The system cannot find the file specified. !
.text iaStor.sys B9E7ECFC 1 Byte [CC] {INT 3 }
? SYMEFA.SYS The system cannot find the file specified. !
init C:\WINDOWS\system32\drivers\Senfilt.sys entry point in "init" section [0xA5631A00]
? C:\DOCUME~1\OFFICE~1\LOCALS~1\Temp\aswMBR.sys The system cannot find the file specified. !
? C:\WINDOWS\system32\Drivers\PROCEXP113.SYS The system cannot find the file specified. !
? C:\DOCUME~1\OFFICE~1\LOCALS~1\Temp\catchme.sys The system cannot find the file specified. !
? C:\WINDOWS\system32\drivers\mbamswissarmy.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text C:\Program Files\Real\RealPlayer\update\realsched.exe[2936] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1148] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002D0010
IAT C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1188] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002D0010
IAT C:\Documents and Settings\Office Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1300] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002D0010
---- Devices - GMER 1.0.15 ----
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device Cdfs.SYS (CD-ROM File System Driver/Microsoft Corporation)
---- Threads - GMER 1.0.15 ----
Thread System [4:156] 89B99161
Thread System [4:400] 89A3FC30
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@RequireSignedAppInit_DLLs 1
---- EOF - GMER 1.0.15 ----