GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-08-26 12:01:50
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 WDC_WD1200BEVS-22RST0 rev.04.01G04
Running: lqkj0kom.exe; Driver: C:\Users\AGUNGC~1\AppData\Local\Temp\aflcrkow.sys
---- System - GMER 1.0.15 ----
SSDT 8696A2F0 ZwAlertResumeThread
SSDT 86784098 ZwAlertThread
SSDT 86797788 ZwAllocateVirtualMemory
SSDT 867358B0 ZwConnectPort
SSDT 867E4080 ZwCreateMutant
SSDT 867CF0B0 ZwCreateThread
SSDT 867B40A0 ZwFreeVirtualMemory
SSDT 8607E928 ZwImpersonateAnonymousToken
SSDT 869853C0 ZwImpersonateThread
SSDT 867CC578 ZwMapViewOfSection
SSDT 868FAB10 ZwOpenEvent
SSDT 867D50B0 ZwOpenProcessToken
SSDT 868009B8 ZwOpenThreadToken
SSDT \??\C:\Windows\system32\drivers\wpsdrvnt.sys ZwProtectVirtualMemory [0x8B972880]
SSDT 867BBBF8 ZwResumeThread
SSDT 8693B5E0 ZwSetContextThread
SSDT 867D8D78 ZwSetInformationProcess
SSDT 867FABD8 ZwSetInformationThread
SSDT 867390C0 ZwSuspendProcess
SSDT 869430D0 ZwSuspendThread
SSDT 8673DBE8 ZwTerminateProcess
SSDT 867DB070 ZwTerminateThread
SSDT 867F70B0 ZwUnmapViewOfSection
SSDT 8679F448 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 140D 82E893C9 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82EC2D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10DB 82EC9D90 8 Bytes [F0, A2, 96, 86, 98, 40, 78, ...]
.text ntkrnlpa.exe!KeRemoveQueueEx + 10F3 82EC9DA8 4 Bytes [88, 77, 79, 86]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1193 82EC9E48 4 Bytes [B0, 58, 73, 86] {MOV AL, 0x58; JAE 0xffffffffffffff8a}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11CF 82EC9E84 4 Bytes [80, 40, 7E, 86] {ADD BYTE [EAX+0x7e], 0x86}
.text ntkrnlpa.exe!KeRemoveQueueEx + 1203 82EC9EB8 4 Bytes [B0, F0, 7C, 86] {MOV AL, 0xf0; JL 0xffffffffffffff8a}
.text ...
PAGE spsys.sys!?SPRevision@@3PADA + 4F90 B96F8000 290 Bytes [8B, FF, 55, 8B, EC, 33, C0, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 50B3 B96F8123 629 Bytes [35, 6F, B9, FE, 05, 34, 35, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 5329 B96F8399 101 Bytes [6A, 28, 59, A5, 5E, C6, 03, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 538F B96F83FF 148 Bytes [18, 5D, C2, 14, 00, 8B, FF, ...]
PAGE spsys.sys!?SPRevision@@3PADA + 543B B96F84AB 2228 Bytes [8B, FF, 55, 8B, EC, FF, 75, ...]
PAGE ...
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Mozilla Firefox\firefox.exe[4900] ntdll.dll!LdrGetProcedureAddress + 26 77532239 7 Bytes JMP 6308B52A C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[4900] kernel32.dll!K32GetDeviceDriverBaseNameW + 5D 75CB93D6 7 Bytes JMP 6333B6D2 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[4900] kernel32.dll!QueryPerformanceCounter + 13 75CBC435 7 Bytes JMP 6333B6F5 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[4900] GDI32.dll!GetViewportOrgEx + 26C 75C2884B 7 Bytes JMP 6333B653 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[5168] USER32.dll!GetWindowInfo 77644B5E 5 Bytes JMP 6320BACC C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[5168] USER32.dll!ToUnicodeEx + 71 77652223 7 Bytes JMP 6320C0F9 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtCreateFile + 6 775155CE 4 Bytes [28, 00, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtCreateFile + B 775155D3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtCreateKey + 6 7751560E 4 Bytes [68, 01, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtCreateKey + B 77515613 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtCreateMutant + 6 7751564E 4 Bytes [68, 02, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtCreateMutant + B 77515653 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtCreateSection + 6 775156EE 4 Bytes [A8, 02, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtCreateSection + B 775156F3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtMapViewOfSection + 6 77515C2E 4 Bytes CALL 76516337 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtMapViewOfSection + B 77515C33 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenFile + 6 77515CDE 4 Bytes [68, 00, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenFile + B 77515CE3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenKey + 6 77515D0E 4 Bytes [A8, 01, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenKey + B 77515D13 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenKeyEx + 6 77515D1E 4 Bytes CALL 76516424 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenKeyEx + B 77515D23 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenMutant + 6 77515D5E 4 Bytes [28, 02, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenMutant + B 77515D63 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenProcess + 6 77515D8E 1 Byte [68]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenProcess + 6 77515D8E 4 Bytes [68, 03, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenProcess + B 77515D93 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenProcessToken + 6 77515D9E 1 Byte [A8]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenProcessToken + 6 77515D9E 4 Bytes [A8, 03, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenProcessToken + B 77515DA3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenProcessTokenEx + 6 77515DAE 4 Bytes [68, 04, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenProcessTokenEx + B 77515DB3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenSection + 6 77515DCE 4 Bytes CALL 765164D5 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenSection + B 77515DD3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenThread + 6 77515E0E 1 Byte [28]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenThread + 6 77515E0E 4 Bytes [28, 03, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenThread + B 77515E13 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenThreadToken + 6 77515E1E 4 Bytes [28, 04, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenThreadToken + B 77515E23 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenThreadTokenEx + 6 77515E2E 4 Bytes [A8, 04, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtOpenThreadTokenEx + B 77515E33 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtQueryAttributesFile + 6 77515F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtQueryAttributesFile + B 77515F43 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtQueryFullAttributesFile + 6 77515FEE 4 Bytes CALL 765166F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtQueryFullAttributesFile + B 77515FF3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtSetInformationFile + 6 7751663E 4 Bytes [28, 01, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtSetInformationFile + B 77516643 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtSetInformationThread + 6 7751669E 1 Byte [E8]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtSetInformationThread + 6 7751669E 4 Bytes CALL 76516DA6 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtSetInformationThread + B 775166A3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtUnmapViewOfSection + 6 775169BE 4 Bytes [28, 05, 07, 00]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ntdll.dll!NtUnmapViewOfSection + B 775169C3 1 Byte [E2]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] kernel32.dll!CreateProcessW 75C7204D 5 Bytes JMP 00010030
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] kernel32.dll!CreateProcessA 75C72082 5 Bytes JMP 00010070
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!DeleteObject 75C25F14 5 Bytes JMP 001101B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!SelectObject 75C26640 5 Bytes JMP 001105F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!SetTextColor 75C26906 5 Bytes JMP 001109F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!SetBkMode 75C269B1 5 Bytes JMP 001108B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!DeleteDC 75C26EAA 5 Bytes JMP 00110170
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!GetDeviceCaps 75C26F7F 5 Bytes JMP 001103B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!ExtSelectClipRgn 75C27114 5 Bytes JMP 001102F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!SelectClipRgn 75C27242 5 Bytes JMP 001105B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!SetStretchBltMode 75C27705 5 Bytes JMP 00110670
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!GetCurrentObject 75C27917 5 Bytes JMP 00110370
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!GetTextMetricsW 75C27B8F 5 Bytes JMP 00110DF0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!GetTextAlign 75C27DAF 5 Bytes JMP 00110D30
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!IntersectClipRect 75C27DFE 5 Bytes JMP 001103F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!ExtTextOutW 75C28192 5 Bytes JMP 00110930
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!SetTextAlign 75C2828E 5 Bytes JMP 001109B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!GetClipBox 75C28525 5 Bytes JMP 00110330
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!MoveToEx 75C28C21 5 Bytes JMP 00110470
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!StretchDIBits 75C2A53E 5 Bytes JMP 00110730
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!RestoreDC 75C2A67B 5 Bytes JMP 00110530
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!SaveDC 75C2A74B 5 Bytes JMP 00110570
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!GetTextExtentPoint32W 75C2B4B5 5 Bytes JMP 00110630
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!GetTextFaceW 75C2B73A 2 Bytes JMP 00110CF0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!GetTextFaceW + 3 75C2B73D 2 Bytes [4E, 8A]
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!GetFontData 75C2BCC4 5 Bytes JMP 00110C30
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!SetWorldTransform 75C2C90A 5 Bytes JMP 001106B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!CreateDCA 75C2CCA9 5 Bytes JMP 001100B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!CreateDCW 75C2CF79 5 Bytes JMP 001100F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!CreateICW 75C2CFD0 5 Bytes JMP 00110130
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!GetTextMetricsA 75C2D0F2 5 Bytes JMP 00110DB0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!Rectangle 75C2F1FF 5 Bytes JMP 00110970
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!LineTo 75C2F59B 5 Bytes JMP 00110430
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!SetICMMode 75C2FAA4 5 Bytes JMP 00110D70
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!ExtTextOutA 75C303F9 5 Bytes JMP 001108F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!ExtEscape 75C32949 5 Bytes JMP 001102B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!Escape 75C33939 5 Bytes JMP 00110270
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!GetTextFaceA 75C33E6A 5 Bytes JMP 00110CB0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!SetPolyFillMode 75C3D851 5 Bytes JMP 00110AF0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!SetMiterLimit 75C3DA0D 5 Bytes JMP 00110B30
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!EndPage 75C400D7 5 Bytes JMP 00110230
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!ResetDCW 75C4050D 5 Bytes JMP 00110A70
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!GetGlyphOutlineW 75C4C1BA 5 Bytes JMP 00110C70
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!CreateScalableFontResourceW 75C4E817 5 Bytes JMP 00110B70
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!AddFontResourceW 75C4EC13 5 Bytes JMP 00110BB0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!RemoveFontResourceW 75C4F109 5 Bytes JMP 00110BF0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!AbortDoc 75C54C63 5 Bytes JMP 00110030
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!EndDoc 75C550AA 5 Bytes JMP 001101F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!StartPage 75C55195 5 Bytes JMP 001106F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!StartDocW 75C55BB0 5 Bytes JMP 001107B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!BeginPath 75C5635D 5 Bytes JMP 001107F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!SelectClipPath 75C563B4 5 Bytes JMP 00110AB0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!CloseFigure 75C5640F 5 Bytes JMP 00110070
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!EndPath 75C56466 5 Bytes JMP 00110A30
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!StrokePath 75C56699 5 Bytes JMP 00110770
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!FillPath 75C56726 5 Bytes JMP 00110830
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!PolylineTo 75C56B94 5 Bytes JMP 001104F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!PolyBezierTo 75C56C25 5 Bytes JMP 001104B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] GDI32.dll!PolyDraw 75C56CD7 5 Bytes JMP 00110870
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!ActivateKeyboardLayout 77638203 5 Bytes JMP 001204F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!ScreenToClient 7763A506 7 Bytes JMP 00120670
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!RegisterClipboardFormatA 7763C091 5 Bytes JMP 001202F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!RegisterClipboardFormatW 7763DF8D 5 Bytes JMP 001202B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!SetCursor 77643075 5 Bytes JMP 00120530
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!MonitorFromWindow 77643622 7 Bytes JMP 00120630
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!PostMessageW 7764447B 5 Bytes JMP 001205F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!IsWindowVisible 77644D69 7 Bytes JMP 001206B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!GetClientRect 776454DD 7 Bytes JMP 001205B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!MapWindowPoints 77645CAA 5 Bytes JMP 00120570
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!GetParent 77646029 7 Bytes JMP 001206F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!EmptyClipboard 7765290C 5 Bytes JMP 00120130
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!SetClipboardData 77652962 5 Bytes JMP 00120170
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!GetClipboardData 77652BA7 5 Bytes JMP 00120030
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!GetClipboardFormatNameW 77655FD2 5 Bytes JMP 00120230
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!SetClipboardViewer 77656FF6 5 Bytes JMP 001204B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!GetClipboardFormatNameA 7765700A 5 Bytes JMP 00120270
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!ChangeClipboardChain 7766147C 5 Bytes JMP 00120430
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!GetTopWindow 776624D9 7 Bytes JMP 00120730
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!CloseClipboard 7766446C 5 Bytes JMP 001200B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!OpenClipboard 7766447E 5 Bytes JMP 00120070
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!IsClipboardFormatAvailable 776644FF 5 Bytes JMP 001200F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!GetClipboardSequenceNumber 77664513 5 Bytes JMP 00120330
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!GetClipboardOwner 77664525 5 Bytes JMP 00120370
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!CountClipboardFormats 7766470A 5 Bytes JMP 001201F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!EnumClipboardFormats 776647EC 5 Bytes JMP 001201B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!GetOpenClipboardWindow 7766480B 5 Bytes JMP 001203F0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!SetCursorPos 7767C1B0 5 Bytes JMP 00120770
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!GetClipboardViewer 77694AF7 5 Bytes JMP 00120470
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] USER32.dll!GetPriorityClipboardFormat 77694BF9 5 Bytes JMP 001203B0
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ole32.dll!OleSetClipboard 77270045 5 Bytes JMP 00130030
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ole32.dll!OleIsCurrentClipboard 772736B2 5 Bytes JMP 00130070
.text C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] ole32.dll!OleGetClipboard 7729FDCD 5 Bytes JMP 001300B0
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\Explorer.EXE[1752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [741B24CB] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [7419562E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [741956EC] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [741B2546] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [741A85AA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [741A4D5E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [741A5105] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [741A51DA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [741A6707] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [741A8301] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [741A8850] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [741A90B1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [741AE254] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1752] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [741A4C90] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3248] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [7556FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3248] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [7556FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3248] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [7556FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3248] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [7556FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[3248] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [7556FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!MoveFileExW] 00010090
IAT C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetFocus] 00120790
IAT C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetKeyState] 001207D0
IAT C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW] 00010090
IAT C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_3_300_270.exe[5228] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!MoveFileExW] 00010090
---- Devices - GMER 1.0.15 ----
Device \Driver\ACPI_HAL \Device\00000061 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
---- EOF - GMER 1.0.15 ----
=====================================================