GMER 1.0.14.14536 -
http://www.gmer.netRootkit scan 2008-07-30 21:59:03
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.14 ----
SSDT 86AD8A38 ZwAlertResumeThread
SSDT 86AD89C8 ZwAlertThread
SSDT 86F9F408 ZwAllocateVirtualMemory
SSDT 86AB8110 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xAAEAEEB0]
SSDT 86AA18C0 ZwCreateMutant
SSDT 86E63638 ZwCreateThread
SSDT 86AA1820 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xAAEAF130]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xAAEAF690]
SSDT 86E8D5A8 ZwFreeVirtualMemory
SSDT 86AD8B18 ZwImpersonateAnonymousToken
SSDT 86AD8AA8 ZwImpersonateThread
SSDT 86B90E78 ZwMapViewOfSection
SSDT 86C71460 ZwOpenEvent
SSDT 86AB47F8 ZwOpenProcessToken
SSDT 86B8E7A0 ZwOpenSection
SSDT 86C80E80 ZwOpenThreadToken
SSDT 86AB87C8 ZwResumeThread
SSDT 86AB48D8 ZwSetContextThread
SSDT 86C7A008 ZwSetInformationProcess
SSDT 86C85D90 ZwSetInformationThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xAAEAF8E0]
SSDT 86C716D8 ZwSuspendProcess
SSDT 86AD8958 ZwSuspendThread
SSDT 86AC4FD0 ZwTerminateProcess
SSDT 86AB4948 ZwTerminateThread
SSDT 86AB4868 ZwUnmapViewOfSection
SSDT 86EA1958 ZwWriteVirtualMemory
---- User code sections - GMER 1.0.14 ----
.text C:\Programmi\Internet Explorer\iexplore.exe[2876] kernel32.dll!VirtualProtect + 1C 7C801AF0 7 Bytes JMP 02200034
.text C:\Programmi\Internet Explorer\iexplore.exe[2876] USER32.dll!DialogBoxParamW 7E3A47AB 5 Bytes JMP 435FF301 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Programmi\Internet Explorer\iexplore.exe[2876] USER32.dll!DialogBoxIndirectParamW 7E3B2072 5 Bytes JMP 43791667 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Programmi\Internet Explorer\iexplore.exe[2876] USER32.dll!MessageBoxIndirectA 7E3BA082 5 Bytes JMP 437915E8 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Programmi\Internet Explorer\iexplore.exe[2876] USER32.dll!DialogBoxParamA 7E3BB144 5 Bytes JMP 4379162C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Programmi\Internet Explorer\iexplore.exe[2876] USER32.dll!MessageBoxExW 7E3D0838 5 Bytes JMP 43791574 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Programmi\Internet Explorer\iexplore.exe[2876] USER32.dll!MessageBoxExA 7E3D085C 5 Bytes JMP 437915AE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Programmi\Internet Explorer\iexplore.exe[2876] USER32.dll!DialogBoxIndirectParamA 7E3D6D7D 5 Bytes JMP 437916A2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Programmi\Internet Explorer\iexplore.exe[2876] USER32.dll!MessageBoxIndirectW 7E3E64D5 5 Bytes JMP 436216B6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Programmi\Internet Explorer\iexplore.exe[2876] ole32.dll!CoCreateInstanceEx 774D0526 5 Bytes JMP 022000B8
.text C:\Programmi\Internet Explorer\iexplore.exe[2876] ole32.dll!CoGetClassObject 774E56C5 5 Bytes JMP 0220013F
---- Devices - GMER 1.0.14 ----
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume5 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.14 ----