GMER 1.0.15.15530 -
http://www.gmer.net
Rootkit scan 2010-11-15 06:46:28
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Scsi\a320raid1Port1Path0Target0Lun0 MAXTOR__ rev.JNZH
Running: lj8dgb34.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\fgrcypog.sys
---- System - GMER 1.0.15 ----
SSDT TfSysMon.sys (ThreatFire System Monitor/PC Tools) ZwCreateKey [0xF72B3AC2]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0xF72CA2D6]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0xF72CA4C8]
SSDT F7C09A24 ZwCreateThread
SSDT TfSysMon.sys (ThreatFire System Monitor/PC Tools) ZwDeleteKey [0xF72B3CB6]
SSDT TfSysMon.sys (ThreatFire System Monitor/PC Tools) ZwDeleteValueKey [0xF72B3D5C]
SSDT spym.sys ZwEnumerateKey [0xF7437DA4]
SSDT spym.sys ZwEnumerateValueKey [0xF7438132]
SSDT F7C09A42 ZwLoadKey
SSDT TfSysMon.sys (ThreatFire System Monitor/PC Tools) ZwOpenKey [0xF72B39B2]
SSDT F7C09A10 ZwOpenProcess
SSDT F7C09A15 ZwOpenThread
SSDT spym.sys ZwQueryKey [0xF743820A]
SSDT spym.sys ZwQueryValueKey [0xF743808A]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwRenameKey [0xF72EC020]
SSDT F7C09A4C ZwReplaceKey
SSDT F7C09A47 ZwRestoreKey
SSDT TfSysMon.sys (ThreatFire System Monitor/PC Tools) ZwSetValueKey [0xF72B3EF8]
SSDT TfSysMon.sys (ThreatFire System Monitor/PC Tools) ZwTerminateProcess [0xF72B5BD6]
INT 0x63 ? 86A9CBF8
INT 0x64 ? 86A9CBF8
INT 0x74 ? 86A9CBF8
INT 0x82 ? 86FD5BF8
INT 0x83 ? 86A9CBF8
INT 0x83 ? 86A9CBF8
INT 0xB4 ? 86FD8BF8
---- Kernel code sections - GMER 1.0.15 ----
? spym.sys The system cannot find the file specified. !
.text C:\windows\system32\DRIVERS\ati2mtag.sys section is writeable [0xF6535000, 0x1C5D38, 0xE8000020]
.text USBPORT.SYS!DllUnload F65148EC 5 Bytes JMP 86A9C1D8
init C:\windows\system32\drivers\senfilt.sys entry point in "init" section [0xF6479F80]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Pando Networks\Media Booster\PMB.exe[1284] kernel32.dll!SetUnhandledExceptionFilter 7C844935 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2696] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215541 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2696] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDBC4 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2696] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E4F87 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2696] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4EB9 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2696] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4F24 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2696] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4D8A C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2696] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4DEC C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2696] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E4FEA C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2696] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4E4E C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215541 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9B69 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD1BD C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDBC4 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E2546BE C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E4F87 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4EB9 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4F24 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4D8A C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4DEC C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E4FEA C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4E4E C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] ole32.dll!CoCreateInstance 774FF1C4 5 Bytes JMP 3E2EDC20 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] ole32.dll!OleLoadFromStream 775297FD 5 Bytes JMP 3E3E52EF C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3588] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215541 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3588] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9B69 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3588] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD1BD C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3588] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDBC4 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3588] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E2546BE C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3588] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E4F87 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3588] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4EB9 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3588] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E4F24 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3588] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4D8A C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3588] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4DEC C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3588] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E4FEA C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3588] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4E4E C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3588] ole32.dll!CoCreateInstance 774FF1C4 5 Bytes JMP 3E2EDC20 C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3588] ole32.dll!OleLoadFromStream 775297FD 5 Bytes JMP 3E3E52EF C:\windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F7420042] spym.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F742013E] spym.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74200C0] spym.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F7420800] spym.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74206D6] spym.sys
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\ADVAPI32.dll [KERNEL32.dll!CloseHandle] [025DC3F0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [02602DF0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\ADVAPI32.dll [KERNEL32.dll!CreateFileA] [025DB950] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [02602D20] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\ADVAPI32.dll [KERNEL32.dll!WriteFile] [025DC5B0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\ADVAPI32.dll [KERNEL32.dll!ReadFile] [025DC4F0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\ADVAPI32.dll [KERNEL32.dll!CreateFileW] [025DBB60] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [02602CF0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [02602E30] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\RPCRT4.dll [KERNEL32.dll!CreateFileW] [025DBB60] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [02602CF0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [02602D20] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [02602E30] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\RPCRT4.dll [KERNEL32.dll!CloseHandle] [025DC3F0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\RPCRT4.dll [KERNEL32.dll!WriteFile] [025DC5B0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [02602CF0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\Secur32.dll [KERNEL32.dll!CreateFileW] [025DBB60] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\Secur32.dll [KERNEL32.dll!CloseHandle] [025DC3F0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [02602D20] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [02602E30] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [02602DF0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\USER32.dll [KERNEL32.dll!CloseHandle] [025DC3F0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\USER32.dll [KERNEL32.dll!ReadFile] [025DC4F0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\USER32.dll [KERNEL32.dll!CreateProcessW] [025DC040] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [02602CF0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [02602E30] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [02602D20] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\USER32.dll [KERNEL32.dll!CreateFileW] [025DBB60] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [02602DF0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [02602CF0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [02602E30] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [02602D20] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!CloseHandle] [025DC3F0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!WriteFile] [025DC5B0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\GDI32.dll [KERNEL32.dll!CreateFileW] [025DBB60] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\msvcrt.dll [KERNEL32.dll!CloseHandle] [025DC3F0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [02602E30] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [02602CF0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] [025DBE20] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] [025DC040] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileA] [025DB950] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\msvcrt.dll [KERNEL32.dll!ReadFile] [025DC4F0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileW] [025DBB60] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\msvcrt.dll [KERNEL32.dll!WriteFile] [025DC5B0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!WriteFile] [025DC5B0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileA] [025DB950] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileW] [025DBB60] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [02602DC0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [02602DF0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [02602D20] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] [025DBE20] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] [025DC040] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!ReadFile] [025DC4F0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [02602CF0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [02602E30] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHLWAPI.dll [KERNEL32.dll!CloseHandle] [025DC3F0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHLWAPI.dll [USER32.dll!DialogBoxParamW] [025DA1A0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHLWAPI.dll [USER32.dll!MessageBoxIndirectA] [025DAA00] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHLWAPI.dll [USER32.dll!MessageBoxIndirectW] [025DB1D0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [02602CF0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] [025DC040] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [02602D20] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [02602E30] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!CreateFileW] [025DBB60] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!ReadFile] [025DC4F0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!CloseHandle] [025DC3F0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!WriteFile] [025DC5B0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [02602DF0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [02602DC0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHELL32.dll [USER32.dll!DialogBoxParamW] [025DA1A0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\SHELL32.dll [USER32.dll!MessageBoxIndirectW] [025DB1D0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [02602E30] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [02602CF0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\ole32.dll [KERNEL32.dll!CloseHandle] [025DC3F0] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [02602D20] C:\windows\PCTBDCore.dll (Browser Defender Core/Threat Expert Ltd.)
IAT C:\Program Files\Internet Explorer\IEXPLORE.EXE[2828] @ C:\windows\system32