Hi, I am trying to repair two workstations that are infected with the google redirect virus. At this moment I am only concentrating on one of the workstations and do not know if the solution for this computer will work on the other. Both computers are windows 7.
Here are the log files.
Malwarebytes
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6618
Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514
5/19/2011 1:03:08 PM
mbam-log-2011-05-19 (13-03-08).txt
Scan type: Quick scan
Objects scanned: 157913
Time elapsed: 2 minute(s), 29 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER
GMER 1.0.15.15627 - http://www.gmer.net
Rootkit scan 2011-05-18 23:37:03
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST3160815AS rev.3.ADA
Running: 6hu8nidq.exe; Driver: C:\Users\Sharkey\AppData\Local\Temp\uwtorkob.sys
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13C1 8287A339 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 828B3D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
PAGE spsys.sys!?SPRevision@@3PADA + 4F90 9CBAB000 290 Bytes [8B, FF, 55, 8B, EC, 33, C0, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 50B3 9CBAB123 629 Bytes [65, BA, 9C, FE, 05, 34, 65, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 5329 9CBAB399 101 Bytes [6A, 28, 59, A5, 5E, C6, 03, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 538F 9CBAB3FF 148 Bytes [18, 5D, C2, 14, 00, 8B, FF, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 543B 9CBAB4AB 2228 Bytes [8B, FF, 55, 8B, EC, FF, 75, ...]
PAGE ...
? C:\Users\Sharkey\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\lsm.exe[472] ntdll.dll!NtOpenProcess 77D95D88 5 Bytes JMP 00330010
.text C:\Windows\system32\lsm.exe[472] ntdll.dll!NtTerminateProcess 77D968C8 5 Bytes JMP 00340010
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!EnableWindow 769A8D02 5 Bytes JMP 711DA855 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!GetAsyncKeyState 769AA256 5 Bytes JMP 711DB202 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!CallNextHookEx 769AABE1 5 Bytes JMP 71223CC1 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!UnhookWindowsHookEx 769AADF9 5 Bytes JMP 712DD96F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!SetWindowsHookExW 769AE30C 5 Bytes JMP 71277DF1 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!CreateWindowExW 769AEC7C 5 Bytes JMP 712B384C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!GetKeyState 769B2B4D 5 Bytes JMP 711E0F61 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!IsDialogMessageW 769B4104 5 Bytes JMP 711DADAE C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!CreateDialogParamA 769C1F42 5 Bytes JMP 713EE9C8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!IsDialogMessage 769C2019 5 Bytes JMP 713EE202 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!DialogBoxParamW 769C3B9B 5 Bytes JMP 711E7F65 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!CreateDialogIndirectParamA 769C721D 5 Bytes JMP 713EEA36 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!CreateDialogIndirectParamW 769CEA10 5 Bytes JMP 713EEA6D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!DialogBoxIndirectParamW 769D3B7F 5 Bytes JMP 713EDD30 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!EndDialog 769D3BA3 5 Bytes JMP 711DB000 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!CreateDialogParamW 769D5630 5 Bytes JMP 713EE9FF C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!SetKeyboardState 769D695A 5 Bytes JMP 713EE567 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!SendInput 769D7019 5 Bytes JMP 713EF18C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!SetCursorPos 769EC1B0 5 Bytes JMP 713EF1E4 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!DialogBoxParamA 769ECF42 5 Bytes JMP 713EDCCD C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!DialogBoxIndirectParamA 769ED274 5 Bytes JMP 713EDD93 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!MessageBoxIndirectA 769FE869 5 Bytes JMP 713EDC62 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!MessageBoxIndirectW 769FE963 5 Bytes JMP 713EDBF7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!MessageBoxExA 769FE9C9 5 Bytes JMP 713EDB95 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!MessageBoxExW 769FE9ED 5 Bytes JMP 713EDB33 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!keybd_event 769FEC3B 5 Bytes JMP 713EF517 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] SHELL32.dll!RealDriveType + 173D 7710FE10 4 Bytes [A5, 35, C0, 6E]
.text C:\Program Files\Internet Explorer\iexplore.exe[600] SHELL32.dll!RealDriveType + 1745 7710FE18 8 Bytes [F3, 34, C0, 6E, 17, 73, BF, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[600] ole32.dll!OleLoadFromStream 76576143 5 Bytes JMP 713EE0A7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] ole32.dll!CoCreateInstance 765B9D0B 5 Bytes JMP 712B33DA C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3748] USER32.dll!CreateWindowExW 769AEC7C 5 Bytes JMP 712B384C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3748] USER32.dll!DialogBoxParamW 769C3B9B 5 Bytes JMP 711E7F65 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3748] USER32.dll!DialogBoxIndirectParamW 769D3B7F 5 Bytes JMP 713EDD30 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3748] USER32.dll!DialogBoxParamA 769ECF42 5 Bytes JMP 713EDCCD C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3748] USER32.dll!DialogBoxIndirectParamA 769ED274 5 Bytes JMP 713EDD93 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3748] USER32.dll!MessageBoxIndirectA 769FE869 5 Bytes JMP 713EDC62 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3748] USER32.dll!MessageBoxIndirectW 769FE963 5 Bytes JMP 713EDBF7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3748] USER32.dll!MessageBoxExA 769FE9C9 5 Bytes JMP 713EDB95 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3748] USER32.dll!MessageBoxExW 769FE9ED 5 Bytes JMP 713EDB33 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device \Driver\ACPI_HAL \Device\00000041 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
DDS and Attach on next post
Here are the log files.
Malwarebytes
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6618
Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514
5/19/2011 1:03:08 PM
mbam-log-2011-05-19 (13-03-08).txt
Scan type: Quick scan
Objects scanned: 157913
Time elapsed: 2 minute(s), 29 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER
GMER 1.0.15.15627 - http://www.gmer.net
Rootkit scan 2011-05-18 23:37:03
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST3160815AS rev.3.ADA
Running: 6hu8nidq.exe; Driver: C:\Users\Sharkey\AppData\Local\Temp\uwtorkob.sys
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13C1 8287A339 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 828B3D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
PAGE spsys.sys!?SPRevision@@3PADA + 4F90 9CBAB000 290 Bytes [8B, FF, 55, 8B, EC, 33, C0, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 50B3 9CBAB123 629 Bytes [65, BA, 9C, FE, 05, 34, 65, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 5329 9CBAB399 101 Bytes [6A, 28, 59, A5, 5E, C6, 03, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 538F 9CBAB3FF 148 Bytes [18, 5D, C2, 14, 00, 8B, FF, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 543B 9CBAB4AB 2228 Bytes [8B, FF, 55, 8B, EC, FF, 75, ...]
PAGE ...
? C:\Users\Sharkey\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\lsm.exe[472] ntdll.dll!NtOpenProcess 77D95D88 5 Bytes JMP 00330010
.text C:\Windows\system32\lsm.exe[472] ntdll.dll!NtTerminateProcess 77D968C8 5 Bytes JMP 00340010
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!EnableWindow 769A8D02 5 Bytes JMP 711DA855 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!GetAsyncKeyState 769AA256 5 Bytes JMP 711DB202 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!CallNextHookEx 769AABE1 5 Bytes JMP 71223CC1 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!UnhookWindowsHookEx 769AADF9 5 Bytes JMP 712DD96F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!SetWindowsHookExW 769AE30C 5 Bytes JMP 71277DF1 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!CreateWindowExW 769AEC7C 5 Bytes JMP 712B384C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!GetKeyState 769B2B4D 5 Bytes JMP 711E0F61 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!IsDialogMessageW 769B4104 5 Bytes JMP 711DADAE C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!CreateDialogParamA 769C1F42 5 Bytes JMP 713EE9C8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!IsDialogMessage 769C2019 5 Bytes JMP 713EE202 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!DialogBoxParamW 769C3B9B 5 Bytes JMP 711E7F65 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!CreateDialogIndirectParamA 769C721D 5 Bytes JMP 713EEA36 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!CreateDialogIndirectParamW 769CEA10 5 Bytes JMP 713EEA6D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!DialogBoxIndirectParamW 769D3B7F 5 Bytes JMP 713EDD30 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!EndDialog 769D3BA3 5 Bytes JMP 711DB000 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!CreateDialogParamW 769D5630 5 Bytes JMP 713EE9FF C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!SetKeyboardState 769D695A 5 Bytes JMP 713EE567 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!SendInput 769D7019 5 Bytes JMP 713EF18C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!SetCursorPos 769EC1B0 5 Bytes JMP 713EF1E4 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!DialogBoxParamA 769ECF42 5 Bytes JMP 713EDCCD C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!DialogBoxIndirectParamA 769ED274 5 Bytes JMP 713EDD93 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!MessageBoxIndirectA 769FE869 5 Bytes JMP 713EDC62 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!MessageBoxIndirectW 769FE963 5 Bytes JMP 713EDBF7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!MessageBoxExA 769FE9C9 5 Bytes JMP 713EDB95 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!MessageBoxExW 769FE9ED 5 Bytes JMP 713EDB33 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] USER32.dll!keybd_event 769FEC3B 5 Bytes JMP 713EF517 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] SHELL32.dll!RealDriveType + 173D 7710FE10 4 Bytes [A5, 35, C0, 6E]
.text C:\Program Files\Internet Explorer\iexplore.exe[600] SHELL32.dll!RealDriveType + 1745 7710FE18 8 Bytes [F3, 34, C0, 6E, 17, 73, BF, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[600] ole32.dll!OleLoadFromStream 76576143 5 Bytes JMP 713EE0A7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[600] ole32.dll!CoCreateInstance 765B9D0B 5 Bytes JMP 712B33DA C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3748] USER32.dll!CreateWindowExW 769AEC7C 5 Bytes JMP 712B384C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3748] USER32.dll!DialogBoxParamW 769C3B9B 5 Bytes JMP 711E7F65 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3748] USER32.dll!DialogBoxIndirectParamW 769D3B7F 5 Bytes JMP 713EDD30 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3748] USER32.dll!DialogBoxParamA 769ECF42 5 Bytes JMP 713EDCCD C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3748] USER32.dll!DialogBoxIndirectParamA 769ED274 5 Bytes JMP 713EDD93 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3748] USER32.dll!MessageBoxIndirectA 769FE869 5 Bytes JMP 713EDC62 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3748] USER32.dll!MessageBoxIndirectW 769FE963 5 Bytes JMP 713EDBF7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3748] USER32.dll!MessageBoxExA 769FE9C9 5 Bytes JMP 713EDB95 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3748] USER32.dll!MessageBoxExW 769FE9ED 5 Bytes JMP 713EDB33 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device \Driver\ACPI_HAL \Device\00000041 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
DDS and Attach on next post