GMER Log
Run in safe mode w/networking
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-01-10 06:28:24
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdePort0 ST3160815AS rev.3.ADA
Running: g6bm1et1.exe; Driver: C:\Users\Admin\AppData\Local\Temp\pxldypog.sys
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13D1 82640369 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82679D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
? System32\drivers\jntqrwk.sys The system cannot find the path specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\svchost.exe[896] kernel32.dll!WriteFile 75C553EE 5 Bytes JMP 000A000A
.text C:\Windows\system32\svchost.exe[896] USER32.dll!GetCursorPos 7575A4B3 5 Bytes JMP 0064000A
.text C:\Windows\system32\svchost.exe[896] USER32.dll!GetForegroundWindow 7576335D 5 Bytes JMP 0066000A
.text C:\Windows\system32\svchost.exe[896] USER32.dll!WindowFromPoint 75786BE9 5 Bytes JMP 0065000A
.text C:\Windows\system32\svchost.exe[896] ole32.dll!CoCreateInstance 75AD9D0B 5 Bytes JMP 0042000A
.text C:\Program Files\Internet Explorer\iexplore.exe[1196] USER32.dll!CreateWindowExW 7575EC7C 5 Bytes JMP 6F603894 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1196] USER32.dll!DialogBoxParamW 75773B9B 5 Bytes JMP 6F537F51 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1196] USER32.dll!DialogBoxIndirectParamW 75783B7F 5 Bytes JMP 6F73DF28 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1196] USER32.dll!DialogBoxParamA 7579CF42 5 Bytes JMP 6F73DEC5 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1196] USER32.dll!DialogBoxIndirectParamA 7579D274 5 Bytes JMP 6F73DF8B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1196] USER32.dll!MessageBoxIndirectA 757AE869 5 Bytes JMP 6F73DE5A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1196] USER32.dll!MessageBoxIndirectW 757AE963 5 Bytes JMP 6F73DDEF C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1196] USER32.dll!MessageBoxExA 757AE9C9 5 Bytes JMP 6F73DD8D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1196] USER32.dll!MessageBoxExW 757AE9ED 5 Bytes JMP 6F73DD2B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2004] USER32.dll!CallNextHookEx 7575ABE1 5 Bytes JMP 6F573CA7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2004] USER32.dll!UnhookWindowsHookEx 7575ADF9 5 Bytes JMP 6F62D90F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2004] USER32.dll!SetWindowsHookExW 7575E30C 5 Bytes JMP 6F5C7DD1 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2004] USER32.dll!CreateWindowExW 7575EC7C 5 Bytes JMP 6F603894 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2004] USER32.dll!DialogBoxParamW 75773B9B 5 Bytes JMP 6F537F51 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2004] USER32.dll!DialogBoxIndirectParamW 75783B7F 5 Bytes JMP 6F73DF28 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2004] USER32.dll!DialogBoxParamA 7579CF42 5 Bytes JMP 6F73DEC5 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2004] USER32.dll!DialogBoxIndirectParamA 7579D274 5 Bytes JMP 6F73DF8B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2004] USER32.dll!MessageBoxIndirectA 757AE869 5 Bytes JMP 6F73DE5A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2004] USER32.dll!MessageBoxIndirectW 757AE963 5 Bytes JMP 6F73DDEF C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2004] USER32.dll!MessageBoxExA 757AE9C9 5 Bytes JMP 6F73DD8D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2004] USER32.dll!MessageBoxExW 757AE9ED 5 Bytes JMP 6F73DD2B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2004] ole32.dll!OleLoadFromStream 75A96143 5 Bytes JMP 6F73E27B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2004] ole32.dll!CoCreateInstance 75AD9D0B 5 Bytes JMP 6F603422 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!CallNextHookEx 7575ABE1 5 Bytes JMP 6F573CA7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!UnhookWindowsHookEx 7575ADF9 5 Bytes JMP 6F62D90F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!SetWindowsHookExW 7575E30C 5 Bytes JMP 6F5C7DD1 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!CreateWindowExW 7575EC7C 5 Bytes JMP 6F603894 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!DialogBoxParamW 75773B9B 5 Bytes JMP 6F537F51 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!DialogBoxIndirectParamW 75783B7F 5 Bytes JMP 6F73DF28 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!DialogBoxParamA 7579CF42 5 Bytes JMP 6F73DEC5 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!DialogBoxIndirectParamA 7579D274 5 Bytes JMP 6F73DF8B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!MessageBoxIndirectA 757AE869 5 Bytes JMP 6F73DE5A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!MessageBoxIndirectW 757AE963 5 Bytes JMP 6F73DDEF C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!MessageBoxExA 757AE9C9 5 Bytes JMP 6F73DD8D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] USER32.dll!MessageBoxExW 757AE9ED 5 Bytes JMP 6F73DD2B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] ole32.dll!OleLoadFromStream 75A96143 5 Bytes JMP 6F73E27B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2536] ole32.dll!CoCreateInstance 75AD9D0B 5 Bytes JMP 6F603422 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe[1264] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [0103A510] C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee Process Validation Service/McAfee, Inc.)
IAT C:\Windows\Explorer.EXE[1484] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [739D2437] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1484] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [739B5600] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1484] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [739B56BE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1484] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [739D24B2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1484] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [739C8514] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1484] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [739C4CC8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1484] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [739C506F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1484] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [739C5144] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1484] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [739C6671] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1484] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [739C826B] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1484] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [739C87BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1484] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [739C901B] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1484] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [739CE1BE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1484] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [739C4BFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device \Driver\ACPI_HAL \Device\00000051 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 TDL4@MBR code has been found <-- ROOTKIT !!!
Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior
---- EOF - GMER 1.0.15 ----