as i was helped so much on my laptop i am getting parents PC looked at
its a HP Pavillian a6325.uk
here are the logs
Malwarebytes
Malwarebytes Anti-Malware (Trial) 1.60.1.1000
www.malwarebytes.org
Database version: v2012.01.30.04
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
User :: VALRORIK-PC [administrator]
Protection: Enabled
31/01/2012 01:47:22
mbam-log-2012-01-31 (01-47-22).txt
Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 343226
Time elapsed: 1 hour(s), 11 minute(s),
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3} (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
GMER
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-01-31 04:53:12
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD50 rev.12.0
Running: 1u6gwtk6.exe; Driver: C:\Users\User\AppData\Local\Temp\ufldqkob.sys
---- System - GMER 1.0.15 ----
SSDT 89CB3C30 ZwAlertResumeThread
SSDT 89CB3D10 ZwAlertThread
SSDT 89CE9640 ZwAllocateVirtualMemory
SSDT 89B32930 ZwAlpcConnectPort
SSDT 89CBE8F0 ZwAssignProcessToJobObject
SSDT 89CBEE58 ZwCreateMutant
SSDT 89CE8CE8 ZwCreateSymbolicLinkObject
SSDT 89CE5C68 ZwCreateThread
SSDT 89CBE990 ZwDebugActiveProcess
SSDT 89CE5990 ZwDuplicateObject
SSDT 89CE9460 ZwFreeVirtualMemory
SSDT 89CBEF48 ZwImpersonateAnonymousToken
SSDT 89CB3B50 ZwImpersonateThread
SSDT 89B93A18 ZwLoadDriver
SSDT 89CBFF28 ZwMapViewOfSection
SSDT 89CBED78 ZwOpenEvent
SSDT 89CE5B50 ZwOpenProcess
SSDT 89CE9730 ZwOpenProcessToken
SSDT 89CBEBB8 ZwOpenSection
SSDT 89CE5A80 ZwOpenThread
SSDT 89CE8ED8 ZwProtectVirtualMemory
SSDT 89CB3DF0 ZwResumeThread
SSDT 89CBFC78 ZwSetContextThread
SSDT 89CBFD58 ZwSetInformationProcess
SSDT 89CBEA70 ZwSetSystemInformation
SSDT 89CBEC98 ZwSuspendProcess
SSDT 89CB3ED0 ZwSuspendThread
SSDT 89CC4E10 ZwTerminateProcess
SSDT 89CB3F90 ZwTerminateThread
SSDT 89CBFE48 ZwUnmapViewOfSection
SSDT 89CE9550 ZwWriteVirtualMemory
SSDT 89CE8DD8 ZwCreateThreadEx
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 11D 82AB48A0 8 Bytes [30, 3C, CB, 89, 10, 3D, CB, ...]
.text ntkrnlpa.exe!KeSetEvent + 131 82AB48B4 4 Bytes [40, 96, CE, 89]
.text ntkrnlpa.exe!KeSetEvent + 13D 82AB48C0 4 Bytes [30, 29, B3, 89] {XOR [ECX], CH; MOV BL, 0x89}
.text ntkrnlpa.exe!KeSetEvent + 191 82AB4914 4 Bytes CALL D5C7D2E4
.text ntkrnlpa.exe!KeSetEvent + 1F5 82AB4978 4 Bytes [58, EE, CB, 89]
.text ...
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Internet Explorer\iexplore.exe[648] USER32.dll!EnableWindow 7755CD8B 5 Bytes JMP 6C689A14 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[648] USER32.dll!DialogBoxParamW 775810B0 5 Bytes JMP 6C5E170B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[648] USER32.dll!DialogBoxIndirectParamW 77582EF5 5 Bytes JMP 6C7D62BE C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[648] USER32.dll!DialogBoxParamA 77598152 5 Bytes JMP 6C7D6259 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[648] USER32.dll!DialogBoxIndirectParamA 7759847D 5 Bytes JMP 6C7D6323 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[648] USER32.dll!MessageBoxIndirectA 775AD4D9 5 Bytes JMP 6C7D61E0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[648] USER32.dll!MessageBoxIndirectW 775AD5D3 5 Bytes JMP 6C7D6167 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[648] USER32.dll!MessageBoxExA 775AD639 5 Bytes JMP 6C7D6103 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[648] USER32.dll!MessageBoxExW 775AD65D 5 Bytes JMP 6C7D609F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] ntdll.dll!NtMapViewOfSection 77724994 5 Bytes JMP 044C003A
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] ntdll.dll!NtSetInformationProcess 77725194 5 Bytes JMP 044C00F7
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] kernel32.dll!ReadProcessMemory + 3E 75F11CB3 7 Bytes JMP 044C01B0
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] kernel32.dll!WriteProcessMemory + 106 75F11DBE 7 Bytes JMP 044C03D2
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] kernel32.dll!CreateIoCompletionPort + 52 75F39DA6 7 Bytes JMP 044C0488
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] kernel32.dll!VirtualAllocEx + 54 75F5AF70 7 Bytes JMP 044C031C
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] kernel32.dll!CreateThread 75F5CB2E 5 Bytes JMP 6C647303 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] kernel32.dll!GetProcessHandleCount + 35 75FA5D4F 7 Bytes JMP 044C0266
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!CreateDialogParamW 775572A2 5 Bytes JMP 6C7D6628 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!GetAsyncKeyState 7755863C 5 Bytes JMP 6C62DD8D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!SetWindowsHookExW 775587AD 5 Bytes JMP 6C682194 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!CallNextHookEx 77558E3B 5 Bytes JMP 6C6A7BB7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!UnhookWindowsHookEx 775598DB 5 Bytes JMP 6C6CEB74 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!EnableWindow 7755CD8B 5 Bytes JMP 6C689A14 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!DefWindowProcA 7755DB88 7 Bytes JMP 6C64952D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!CreateWindowExA 7755DC2A 5 Bytes JMP 6C653363 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!CreateWindowExW 77561305 5 Bytes JMP 6C6AFF8F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!GetKeyState 77568CB1 5 Bytes JMP 6C62DC67 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!DefWindowProcW 775703B4 7 Bytes JMP 6C6A7C1A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!IsDialogMessageW 77570745 5 Bytes JMP 6C7D6D82 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!CreateDialogParamA 775717AA 5 Bytes JMP 6C7D65F0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!IsDialogMessage 77571847 2 Bytes JMP 6C7D6D5A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!IsDialogMessage + 3 7757184A 2 Bytes [26, F5]
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!CreateDialogIndirectParamA 775726F1 5 Bytes JMP 6C7D6660 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!CreateDialogIndirectParamW 77579A62 5 Bytes JMP 6C7D6698 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!SetKeyboardState 77580987 5 Bytes JMP 6C7D7649 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!DialogBoxParamW 775810B0 5 Bytes JMP 6C5E170B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!DialogBoxIndirectParamW 77582EF5 5 Bytes JMP 6C7D62BE C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!SendInput 77582F75 5 Bytes JMP 6C7D75F1 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!EndDialog 7758326E 5 Bytes JMP 6C7D702E C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!SetCursorPos 77596FB2 5 Bytes JMP 6C7D76CA C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!DialogBoxParamA 77598152 5 Bytes JMP 6C7D6259 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!DialogBoxIndirectParamA 7759847D 5 Bytes JMP 6C7D6323 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!MessageBoxIndirectA 775AD4D9 5 Bytes JMP 6C7D61E0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!MessageBoxIndirectW 775AD5D3 5 Bytes JMP 6C7D6167 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!MessageBoxExA 775AD639 5 Bytes JMP 6C7D6103 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!MessageBoxExW 775AD65D 5 Bytes JMP 6C7D609F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!keybd_event 775AD972 5 Bytes JMP 6C7D75AE C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] SHELL32.dll!SHRestricted + D95 762B89A8 4 Bytes [CF, 01, BC, 6D]
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] SHELL32.dll!SHRestricted + D9D 762B89B0 8 Bytes [E0, 61, BB, 6D, 79, F7, BB, ...] {LOOPNZ 0x63; MOV EBX, 0xbbf7796d; INSD }
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] ole32.dll!OleLoadFromStream 77421E80 5 Bytes JMP 6C7D6A8C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] ole32.dll!CoGetTreatAsClass + D2F 7743FAE3 7 Bytes JMP 044C053E
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] ole32.dll!CoCreateInstance + 3E 77459F7C 7 Bytes JMP 044C05F8
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] WS2_32.dll!closesocket 76DB330C 5 Bytes JMP 66AA41DF C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] WS2_32.dll!recv 76DB343A 5 Bytes JMP 66AA4549 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] WS2_32.dll!socket 76DB36D1 5 Bytes JMP 66AA354C C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] WS2_32.dll!connect 76DB40D9 5 Bytes JMP 66AA35DC C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] WS2_32.dll!getaddrinfo 76DB418A 5 Bytes JMP 66AA3704 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] WS2_32.dll!send 76DB659B 5 Bytes JMP 66AA3B92 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
---- User IAT/EAT - GMER 1.0.15 ----
its a HP Pavillian a6325.uk
here are the logs
Malwarebytes
Malwarebytes Anti-Malware (Trial) 1.60.1.1000
www.malwarebytes.org
Database version: v2012.01.30.04
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
User :: VALRORIK-PC [administrator]
Protection: Enabled
31/01/2012 01:47:22
mbam-log-2012-01-31 (01-47-22).txt
Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 343226
Time elapsed: 1 hour(s), 11 minute(s),
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549B5CA7-4A86-11D7-A4DF-000874180BB3} (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
GMER
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-01-31 04:53:12
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD50 rev.12.0
Running: 1u6gwtk6.exe; Driver: C:\Users\User\AppData\Local\Temp\ufldqkob.sys
---- System - GMER 1.0.15 ----
SSDT 89CB3C30 ZwAlertResumeThread
SSDT 89CB3D10 ZwAlertThread
SSDT 89CE9640 ZwAllocateVirtualMemory
SSDT 89B32930 ZwAlpcConnectPort
SSDT 89CBE8F0 ZwAssignProcessToJobObject
SSDT 89CBEE58 ZwCreateMutant
SSDT 89CE8CE8 ZwCreateSymbolicLinkObject
SSDT 89CE5C68 ZwCreateThread
SSDT 89CBE990 ZwDebugActiveProcess
SSDT 89CE5990 ZwDuplicateObject
SSDT 89CE9460 ZwFreeVirtualMemory
SSDT 89CBEF48 ZwImpersonateAnonymousToken
SSDT 89CB3B50 ZwImpersonateThread
SSDT 89B93A18 ZwLoadDriver
SSDT 89CBFF28 ZwMapViewOfSection
SSDT 89CBED78 ZwOpenEvent
SSDT 89CE5B50 ZwOpenProcess
SSDT 89CE9730 ZwOpenProcessToken
SSDT 89CBEBB8 ZwOpenSection
SSDT 89CE5A80 ZwOpenThread
SSDT 89CE8ED8 ZwProtectVirtualMemory
SSDT 89CB3DF0 ZwResumeThread
SSDT 89CBFC78 ZwSetContextThread
SSDT 89CBFD58 ZwSetInformationProcess
SSDT 89CBEA70 ZwSetSystemInformation
SSDT 89CBEC98 ZwSuspendProcess
SSDT 89CB3ED0 ZwSuspendThread
SSDT 89CC4E10 ZwTerminateProcess
SSDT 89CB3F90 ZwTerminateThread
SSDT 89CBFE48 ZwUnmapViewOfSection
SSDT 89CE9550 ZwWriteVirtualMemory
SSDT 89CE8DD8 ZwCreateThreadEx
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 11D 82AB48A0 8 Bytes [30, 3C, CB, 89, 10, 3D, CB, ...]
.text ntkrnlpa.exe!KeSetEvent + 131 82AB48B4 4 Bytes [40, 96, CE, 89]
.text ntkrnlpa.exe!KeSetEvent + 13D 82AB48C0 4 Bytes [30, 29, B3, 89] {XOR [ECX], CH; MOV BL, 0x89}
.text ntkrnlpa.exe!KeSetEvent + 191 82AB4914 4 Bytes CALL D5C7D2E4
.text ntkrnlpa.exe!KeSetEvent + 1F5 82AB4978 4 Bytes [58, EE, CB, 89]
.text ...
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Internet Explorer\iexplore.exe[648] USER32.dll!EnableWindow 7755CD8B 5 Bytes JMP 6C689A14 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[648] USER32.dll!DialogBoxParamW 775810B0 5 Bytes JMP 6C5E170B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[648] USER32.dll!DialogBoxIndirectParamW 77582EF5 5 Bytes JMP 6C7D62BE C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[648] USER32.dll!DialogBoxParamA 77598152 5 Bytes JMP 6C7D6259 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[648] USER32.dll!DialogBoxIndirectParamA 7759847D 5 Bytes JMP 6C7D6323 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[648] USER32.dll!MessageBoxIndirectA 775AD4D9 5 Bytes JMP 6C7D61E0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[648] USER32.dll!MessageBoxIndirectW 775AD5D3 5 Bytes JMP 6C7D6167 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[648] USER32.dll!MessageBoxExA 775AD639 5 Bytes JMP 6C7D6103 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[648] USER32.dll!MessageBoxExW 775AD65D 5 Bytes JMP 6C7D609F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] ntdll.dll!NtMapViewOfSection 77724994 5 Bytes JMP 044C003A
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] ntdll.dll!NtSetInformationProcess 77725194 5 Bytes JMP 044C00F7
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] kernel32.dll!ReadProcessMemory + 3E 75F11CB3 7 Bytes JMP 044C01B0
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] kernel32.dll!WriteProcessMemory + 106 75F11DBE 7 Bytes JMP 044C03D2
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] kernel32.dll!CreateIoCompletionPort + 52 75F39DA6 7 Bytes JMP 044C0488
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] kernel32.dll!VirtualAllocEx + 54 75F5AF70 7 Bytes JMP 044C031C
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] kernel32.dll!CreateThread 75F5CB2E 5 Bytes JMP 6C647303 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] kernel32.dll!GetProcessHandleCount + 35 75FA5D4F 7 Bytes JMP 044C0266
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!CreateDialogParamW 775572A2 5 Bytes JMP 6C7D6628 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!GetAsyncKeyState 7755863C 5 Bytes JMP 6C62DD8D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!SetWindowsHookExW 775587AD 5 Bytes JMP 6C682194 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!CallNextHookEx 77558E3B 5 Bytes JMP 6C6A7BB7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!UnhookWindowsHookEx 775598DB 5 Bytes JMP 6C6CEB74 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!EnableWindow 7755CD8B 5 Bytes JMP 6C689A14 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!DefWindowProcA 7755DB88 7 Bytes JMP 6C64952D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!CreateWindowExA 7755DC2A 5 Bytes JMP 6C653363 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!CreateWindowExW 77561305 5 Bytes JMP 6C6AFF8F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!GetKeyState 77568CB1 5 Bytes JMP 6C62DC67 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!DefWindowProcW 775703B4 7 Bytes JMP 6C6A7C1A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!IsDialogMessageW 77570745 5 Bytes JMP 6C7D6D82 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!CreateDialogParamA 775717AA 5 Bytes JMP 6C7D65F0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!IsDialogMessage 77571847 2 Bytes JMP 6C7D6D5A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!IsDialogMessage + 3 7757184A 2 Bytes [26, F5]
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!CreateDialogIndirectParamA 775726F1 5 Bytes JMP 6C7D6660 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!CreateDialogIndirectParamW 77579A62 5 Bytes JMP 6C7D6698 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!SetKeyboardState 77580987 5 Bytes JMP 6C7D7649 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!DialogBoxParamW 775810B0 5 Bytes JMP 6C5E170B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!DialogBoxIndirectParamW 77582EF5 5 Bytes JMP 6C7D62BE C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!SendInput 77582F75 5 Bytes JMP 6C7D75F1 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!EndDialog 7758326E 5 Bytes JMP 6C7D702E C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!SetCursorPos 77596FB2 5 Bytes JMP 6C7D76CA C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!DialogBoxParamA 77598152 5 Bytes JMP 6C7D6259 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!DialogBoxIndirectParamA 7759847D 5 Bytes JMP 6C7D6323 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!MessageBoxIndirectA 775AD4D9 5 Bytes JMP 6C7D61E0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!MessageBoxIndirectW 775AD5D3 5 Bytes JMP 6C7D6167 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!MessageBoxExA 775AD639 5 Bytes JMP 6C7D6103 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!MessageBoxExW 775AD65D 5 Bytes JMP 6C7D609F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] USER32.dll!keybd_event 775AD972 5 Bytes JMP 6C7D75AE C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] SHELL32.dll!SHRestricted + D95 762B89A8 4 Bytes [CF, 01, BC, 6D]
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] SHELL32.dll!SHRestricted + D9D 762B89B0 8 Bytes [E0, 61, BB, 6D, 79, F7, BB, ...] {LOOPNZ 0x63; MOV EBX, 0xbbf7796d; INSD }
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] ole32.dll!OleLoadFromStream 77421E80 5 Bytes JMP 6C7D6A8C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] ole32.dll!CoGetTreatAsClass + D2F 7743FAE3 7 Bytes JMP 044C053E
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] ole32.dll!CoCreateInstance + 3E 77459F7C 7 Bytes JMP 044C05F8
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] WS2_32.dll!closesocket 76DB330C 5 Bytes JMP 66AA41DF C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] WS2_32.dll!recv 76DB343A 5 Bytes JMP 66AA4549 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] WS2_32.dll!socket 76DB36D1 5 Bytes JMP 66AA354C C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] WS2_32.dll!connect 76DB40D9 5 Bytes JMP 66AA35DC C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] WS2_32.dll!getaddrinfo 76DB418A 5 Bytes JMP 66AA3704 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3752] WS2_32.dll!send 76DB659B 5 Bytes JMP 66AA3B92 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
---- User IAT/EAT - GMER 1.0.15 ----