GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-08-17 13:44:03
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 WDC_WD3200AAJS-00B4A0 rev.01.03A01
Running: 0dkxs8gl.exe; Driver: C:\Users\claire\AppData\Local\Temp\axliaaoc.sys
---- System - GMER 1.0.15 ----
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwAssignProcessToJobObject [0x8EEF80DA]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwCreateFile [0x8EEF8CA6]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwDeleteFile [0x8EEF8EB8]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwDeleteKey [0x8EEFC714]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwDeleteValueKey [0x8EEFC756]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwLoadKey [0x8EEFC8FA]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwOpenFile [0x8EEF8DCA]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwOpenProcess [0x8EEF8282]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwOpenThread [0x8EEF8482]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwProtectVirtualMemory [0x8EEF85C2]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwQueryValueKey [0x8EEFC85E]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwRenameKey [0x8EEFC7A8]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwReplaceKey [0x8EEFC7EA]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwRestoreKey [0x8EEFC824]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwSetContextThread [0x8EEF8068]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwSetInformationFile [0x8EEF8F6A]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwSetValueKey [0x8EEFC69C]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwSuspendThread [0x8EEF7FE6]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwTerminateProcess [0x8EEF7EEE]
SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwTerminateThread [0x8EEF7F46]
SSDT \??\C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus32_42020.sys ZwCreateThreadEx [0x8EB3E640]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 191 836C6854 4 Bytes [DA, 80, EF, 8E]
.text ntkrnlpa.exe!KeSetEvent + 1D9 836C689C 4 Bytes [A6, 8C, EF, 8E]
.text ntkrnlpa.exe!KeSetEvent + 2D1 836C6994 5 Bytes [B8, 8E, EF, 8E, 14] {MOV EAX, 0x148eef8e}
.text ntkrnlpa.exe!KeSetEvent + 2D7 836C699A 2 Bytes [EF, 8E]
.text ntkrnlpa.exe!KeSetEvent + 2E1 836C69A4 4 Bytes [56, C7, EF, 8E]
.text ...
.text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x8DC05340, 0x35AF37, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1028] ntdll.dll!KiUserApcDispatcher 77D25B78 5 Bytes JMP 00414FF0 C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe (RapportMgmtService/Trusteer Ltd.)
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1028] kernel32.dll!LoadLibraryExW + 173 778B93EF 4 Bytes JMP 71AB000A
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1028] WS2_32.dll!getaddrinfo 774A418A 5 Bytes JMP 71A50022
.text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1028] WS2_32.dll!gethostbyname 774B62D4 5 Bytes JMP 71AE0022
.text C:\Program Files\Mozilla Firefox\firefox.exe[2676] ntdll.dll!LdrLoadDll 77CE9378 5 Bytes JMP 699BB52A C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2676] ntdll.dll!NtMapViewOfSection 77D24994 5 Bytes JMP 719F0022
.text C:\Program Files\Mozilla Firefox\firefox.exe[2676] ntdll.dll!KiUserApcDispatcher + E 77D25B86 5 Bytes JMP 00D4E2B0 c:\program files\trusteer\rapport\bin\rooksdol.dll (Rooks/Dolomite/Trusteer Ltd.)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2676] kernel32.dll!LoadLibraryExW + 173 778B93EF 4 Bytes JMP 71AC000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2676] kernel32.dll!SetUnhandledExceptionFilter 778BA8C5 6 Bytes PUSH 71A30022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[2676] kernel32.dll!LockResource + C 778D6B0B 7 Bytes JMP 69C6B6D2 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2676] kernel32.dll!VirtualAllocEx + 54 778DAF70 7 Bytes JMP 69C6B6F5 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2676] GDI32.dll!BitBlt 764E70A6 6 Bytes PUSH 71750022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[2676] GDI32.dll!SetStretchBltMode + 256 764E745C 7 Bytes JMP 69C6B653 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[2676] USER32.dll!DdeInitializeW 77277921 6 Bytes PUSH 71710022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[2676] USER32.dll!RegisterClassExW 7727DA30 6 Bytes PUSH 71AE0022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[2676] USER32.dll!CreateWindowExA 7727DC2A 6 Bytes JMP 7192000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2676] USER32.dll!RegisterClassW 7727E1AB 6 Bytes PUSH 71A60022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[2676] USER32.dll!CreateWindowExW 77281305 6 Bytes JMP 7196000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[2676] USER32.dll!GetMessageW 7728FEF7 6 Bytes PUSH 71650022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[2676] USER32.dll!TranslateMessage 772901AD 6 Bytes PUSH 715B0022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[2676] USER32.dll!DispatchMessageW 7729021C 6 Bytes PUSH 716D0022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[2676] USER32.dll!PeekMessageW 7729045A 6 Bytes PUSH 719B0022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[2676] USER32.dll!GetWindowRect 77290E21 6 Bytes PUSH 71610022; RET
.text C:\Program Files\Mozilla Firefox\firefox.exe[2676] USER32.dll!GetClipboardData 772B715A 6 Bytes PUSH 71690022; RET
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[2760] ntdll.dll!KiUserApcDispatcher 77D25B78 5 Bytes JMP 0043A9F0 C:\Program Files\Trusteer\Rapport\bin\RapportService.exe (RapportService/Trusteer Ltd.)
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[2760] kernel32.dll!LoadLibraryExW + 173 778B93EF 4 Bytes JMP 71AC000A
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[2760] USER32.dll!InSendMessageEx + 3B1 7727E6B0 6 Bytes JMP 71AE001E
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[2760] WS2_32.dll!getaddrinfo 774A418A 5 Bytes JMP 71A20022
.text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[2760] WS2_32.dll!gethostbyname 774B62D4 5 Bytes JMP 71A60022
.text C:\Users\claire\AppData\Roaming\eType\eType.exe[3040] kernel32.dll!SetUnhandledExceptionFilter 778BA8C5 5 Bytes JMP 00E5D1F9 C:\Users\claire\AppData\Roaming\eType\eType.exe (eType Application/DSNR Media Innovations)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[3812] USER32.dll!GetWindowInfo 7728428E 5 Bytes JMP 69B3BACC C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[3812] USER32.dll!SetMenuItemBitmaps + 71 772914EE 7 Bytes JMP 69B3C0F9 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtCreateFile + 6 77D2424A 4 Bytes [28, 00, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtCreateFile + B 77D2424F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtCreateKey + 6 77D2428A 4 Bytes [68, 01, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtCreateKey + B 77D2428F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtCreateMutant + 6 77D242BA 4 Bytes [28, 02, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtCreateMutant + B 77D242BF 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtCreateSection + 6 77D2433A 4 Bytes [68, 02, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtCreateSection + B 77D2433F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtMapViewOfSection + 6 77D2499A 4 Bytes [A8, 04, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtMapViewOfSection + B 77D2499F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenFile + 6 77D24A2A 4 Bytes [68, 00, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenFile + B 77D24A2F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenKey + 6 77D24A5A 4 Bytes [A8, 01, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenKey + B 77D24A5F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenMutant + 6 77D24A7A 4 Bytes CALL 76D25080 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenMutant + B 77D24A7F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenProcess + 6 77D24AAA 1 Byte [28]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenProcess + 6 77D24AAA 4 Bytes [28, 03, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenProcess + B 77D24AAF 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenProcessToken + 6 77D24ABA 1 Byte [68]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenProcessToken + 6 77D24ABA 4 Bytes [68, 03, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenProcessToken + B 77D24ABF 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenProcessTokenEx + 6 77D24ACA 4 Bytes [28, 04, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenProcessTokenEx + B 77D24ACF 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenSection + 6 77D24ADA 4 Bytes [A8, 02, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenSection + B 77D24ADF 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenThread + 6 77D24B1A 4 Bytes CALL 76D25121 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenThread + B 77D24B1F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenThreadToken + 6 77D24B2A 1 Byte [E8]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenThreadToken + 6 77D24B2A 4 Bytes CALL 76D25132 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenThreadToken + B 77D24B2F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenThreadTokenEx + 6 77D24B3A 4 Bytes [68, 04, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtOpenThreadTokenEx + B 77D24B3F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtQueryAttributesFile + 6 77D24BCA 4 Bytes [A8, 00, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtQueryAttributesFile + B 77D24BCF 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtQueryFullAttributesFile + 6 77D24C7A 4 Bytes CALL 76D2527F C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtQueryFullAttributesFile + B 77D24C7F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtSetInformationFile + 6 77D2515A 4 Bytes [28, 01, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtSetInformationFile + B 77D2515F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtSetInformationThread + 6 77D251AA 1 Byte [A8]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtSetInformationThread + 6 77D251AA 4 Bytes [A8, 03, 06, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtSetInformationThread + B 77D251AF 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtUnmapViewOfSection + 6 77D2544A 4 Bytes CALL 76D25A53 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ntdll.dll!NtUnmapViewOfSection + B 77D2544F 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] kernel32.dll!CreateProcessW 77891BF3 5 Bytes JMP 000100B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] kernel32.dll!CreateProcessA 77891C28 5 Bytes JMP 000100F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] kernel32.dll!OpenEventW 778AC033 5 Bytes JMP 00010070
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] kernel32.dll!CreateEventW 778DB87E 5 Bytes JMP 00010030
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!DeleteObject 764E5A37 5 Bytes JMP 000801B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!GetDeviceCaps 764E617F 5 Bytes JMP 000803B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!SelectObject 764E62A0 5 Bytes JMP 000805F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!SetTextColor 764E666B 5 Bytes JMP 000809F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!SetBkMode 764E6716 5 Bytes JMP 000808B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!DeleteDC 764E68CD 5 Bytes JMP 00080170
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!GetCurrentObject 764E6B58 5 Bytes JMP 00080370
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!SetStretchBltMode 764E7206 5 Bytes JMP 00080670
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!SaveDC 764E75BA 5 Bytes JMP 00080570
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!RestoreDC 764E7675 5 Bytes JMP 00080530
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!StretchDIBits 764E78CF 5 Bytes JMP 00080730
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!ExtSelectClipRgn 764E79F8 5 Bytes JMP 000802F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!SelectClipRgn 764E7AF9 5 Bytes JMP 000805B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!MoveToEx 764E7C33 5 Bytes JMP 00080470
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!Rectangle 764E7EA9 5 Bytes JMP 00080970
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!GetTextAlign 764E82E0 5 Bytes JMP 00080D30
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!SetTextAlign 764E85CB 5 Bytes JMP 000809B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!ExtTextOutW 764E872B 5 Bytes JMP 00080930
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!GetTextMetricsW 764E8A81 5 Bytes JMP 00080DF0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!IntersectClipRect 764E8B64 5 Bytes JMP 000803F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!GetClipBox 764E9071 5 Bytes JMP 00080330
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!SetICMMode 764E94E7 5 Bytes JMP 00080D70
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!CreateDCW 764EA91D 5 Bytes JMP 000800F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!CreateDCA 764EAA49 5 Bytes JMP 000800B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!CreateICW 764EB2E9 5 Bytes JMP 00080130
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!GetTextFaceW 764EB637 5 Bytes JMP 00080CF0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!GetFontData 764EBA6C 5 Bytes JMP 00080C30
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!GetTextExtentPoint32W 764EC01A 5 Bytes JMP 00080630
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!SetWorldTransform 764EC46A 5 Bytes JMP 000806B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!LineTo 764EC65E 5 Bytes JMP 00080430
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!GetTextMetricsA 764ECCEB 5 Bytes JMP 00080DB0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!ExtTextOutA 764F00A5 5 Bytes JMP 000808F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!ExtEscape 764F22A7 5 Bytes JMP 000802B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!Escape 764F27F1 5 Bytes JMP 00080270
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!ResetDCW 764F3132 5 Bytes JMP 00080A70
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!EndPage 764F375E 5 Bytes JMP 00080230
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!SetPolyFillMode 764F61D3 5 Bytes JMP 00080AF0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!SetMiterLimit 764F62E2 5 Bytes JMP 00080B30
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!GetTextFaceA 764FF4C5 5 Bytes JMP 00080CB0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!GetGlyphOutlineW 7650A41F 5 Bytes JMP 00080C70
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!CreateScalableFontResourceW 7650C88B 5 Bytes JMP 00080B70
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!AddFontResourceW 7650CC93 5 Bytes JMP 00080BB0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!RemoveFontResourceW 7650D129 5 Bytes JMP 00080BF0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!AbortDoc 76512CC4 5 Bytes JMP 00080030
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!EndDoc 765130D8 5 Bytes JMP 000801F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!StartPage 765131C3 5 Bytes JMP 000806F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!StartDocW 76513CA7 5 Bytes JMP 000807B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!BeginPath 76514465 5 Bytes JMP 000807F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!SelectClipPath 765144BC 5 Bytes JMP 00080AB0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!CloseFigure 76514517 5 Bytes JMP 00080070
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!EndPath 7651456E 5 Bytes JMP 00080A30
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!StrokePath 765147A0 5 Bytes JMP 00080770
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!FillPath 7651482C 1 Byte [E9]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!FillPath 7651482C 5 Bytes JMP 00080830
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!PolylineTo 76514C95 5 Bytes JMP 000804F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!PolyBezierTo 76514D25 5 Bytes JMP 000804B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] GDI32.dll!PolyDraw 76514DD6 5 Bytes JMP 00080870
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!SetCursor 7727D37D 5 Bytes JMP 00090530
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!RegisterClipboardFormatW 7727D6AC 1 Byte [E9]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!RegisterClipboardFormatW 7727D6AC 5 Bytes JMP 000902B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!ActivateKeyboardLayout 7728478C 5 Bytes JMP 000904F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!IsWindowVisible 7728878A 7 Bytes JMP 000906B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!MonitorFromWindow 772888D4 7 Bytes JMP 00090630
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!ScreenToClient 77288C56 7 Bytes JMP 00090670
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!GetClientRect 77288F0D 7 Bytes JMP 000905B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!GetParent 772890AA 7 Bytes JMP 000906F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!RegisterClipboardFormatA 7728A111 5 Bytes JMP 000902F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!PostMessageW 7728A175 5 Bytes JMP 000905F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!MapWindowPoints 7728A30D 5 Bytes JMP 00090570
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!GetClipboardFormatNameA 7728A552 5 Bytes JMP 00090270
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!GetOpenClipboardWindow 772926A6 5 Bytes JMP 000903F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!SetClipboardViewer 7729BA2D 5 Bytes JMP 000904B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!IsClipboardFormatAvailable 7729C2E3 5 Bytes JMP 000900F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!CloseClipboard 7729C2F7 5 Bytes JMP 000900B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!OpenClipboard 7729C31D 5 Bytes JMP 00090070
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!GetTopWindow 7729CE0A 7 Bytes JMP 00090730
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!GetClipboardSequenceNumber 7729D8B7 5 Bytes JMP 00090330
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!ChangeClipboardChain 7729DF83 5 Bytes JMP 00090430
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!CountClipboardFormats 772A0048 5 Bytes JMP 000901F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!GetClipboardOwner 772A26EF 5 Bytes JMP 00090370
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!SetClipboardData 772B6410 5 Bytes JMP 00090170
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!EnumClipboardFormats 772B6D16 5 Bytes JMP 000901B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!SetCursorPos 772B6FB2 5 Bytes JMP 00090770
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!GetClipboardData 772B715A 5 Bytes JMP 00090030
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!GetClipboardFormatNameW 772BA99F 5 Bytes JMP 00090230
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!EmptyClipboard 772D398B 5 Bytes JMP 00090130
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!GetClipboardViewer 772D39ED 5 Bytes JMP 00090470
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] USER32.dll!GetPriorityClipboardFormat 772D3AEF 5 Bytes JMP 000903B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ole32.dll!OleGetClipboard 765A74C9 5 Bytes JMP 000A00B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ole32.dll!OleSetClipboard 765D11E3 5 Bytes JMP 000A0030
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] ole32.dll!OleIsCurrentClipboard 765DA8F9 5 Bytes JMP 000A0070
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] Secur32.dll!FreeContextBuffer 76212D83 5 Bytes JMP 000C00F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] Secur32.dll!DeleteSecurityContext 76212F18 5 Bytes JMP 000C0270
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] Secur32.dll!FreeCredentialsHandle 76213598 5 Bytes JMP 000C0130
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] Secur32.dll!EncryptMessage 76213745 5 Bytes JMP 000C01F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] Secur32.dll!DecryptMessage 76213813 5 Bytes JMP 000C0230
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] Secur32.dll!InitializeSecurityContextA 762187DF 5 Bytes JMP 000C0170
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] Secur32.dll!AcquireCredentialsHandleA 76218A43 5 Bytes JMP 000C0030
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] Secur32.dll!QueryContextAttributesA 76218E77 5 Bytes JMP 000C0070
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] Secur32.dll!ApplyControlToken 7621DE4F 5 Bytes JMP 000C01B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] Secur32.dll!QueryCredentialsAttributesA 7621E052 5 Bytes JMP 000C00B0
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!MoveFileExW] 00010110
IAT C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!GetKeyState] 000907D0
IAT C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] @ C:\Windows\system32\ole32.dll [USER32.dll!GetKeyState] 000907D0
IAT C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!MoveFileExW] 00010110
IAT C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW] 00010110
IAT C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetFocus] 00090790
IAT C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_271.exe[4008] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetKeyState] 000907D0
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Classes\CLSID\{B6A930A0-A4F5-43A5-9B4E-6189A6C2B9E8}@\22!s!m!\22!y!d!f!{!f!r!f!I!d!`!\22!`! 19583823
---- EOF - GMER 1.0.15 ----