Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- GMER 1.0.15.15641 - http://www.gmer.net
- Rootkit scan 2011-12-13 11:31:35
- Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.FC2O
- Running: e0miri9d.exe; Driver: E:\DOCUME~1\mzhang\LOCALS~1\Temp\pftdrpow.sys
- ---- Kernel code sections - GMER 1.0.15 ----
- ? E:\DOCUME~1\mzhang\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !
- ---- User code sections - GMER 1.0.15 ----
- .text E:\Program Files\Mozilla Firefox\firefox.exe[604] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 02C0000A
- .text E:\Program Files\Mozilla Firefox\firefox.exe[604] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 02C1000A
- .text E:\Program Files\Mozilla Firefox\firefox.exe[604] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 029F000C
- .text E:\WINDOWS\System32\ping.exe[728] ntdll.dll!NtCreateProcess 7C90D14E 5 Bytes JMP 00A5000A
- .text E:\WINDOWS\System32\ping.exe[728] ntdll.dll!NtCreateProcessEx 7C90D15E 5 Bytes JMP 00A6000A
- .text E:\WINDOWS\System32\ping.exe[728] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 006F000A
- .text E:\WINDOWS\System32\ping.exe[728] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 3 Bytes JMP 0091000A
- .text E:\WINDOWS\System32\ping.exe[728] ntdll.dll!NtWriteVirtualMemory + 4 7C90DFB2 1 Byte [84]
- .text E:\WINDOWS\System32\ping.exe[728] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 006E000C
- .text E:\WINDOWS\System32\ping.exe[728] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 00A9000A
- .text E:\WINDOWS\System32\ping.exe[728] USER32.dll!WindowFromPoint 7E429766 5 Bytes JMP 00AA000A
- .text E:\WINDOWS\System32\ping.exe[728] USER32.dll!GetForegroundWindow 7E429823 5 Bytes JMP 00AB000A
- .text E:\WINDOWS\System32\ping.exe[728] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 00A8000A
- .text E:\WINDOWS\system32\svchost.exe[1100] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 01FF000A
- .text E:\WINDOWS\system32\svchost.exe[1100] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0200000A
- .text E:\WINDOWS\system32\svchost.exe[1100] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 01FE000C
- .text E:\Program Files\Mozilla Firefox\plugin-container.exe[1856] USER32.dll!SetWindowLongA 7E42C29D 5 Bytes JMP 106ACCFA E:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
- .text E:\Program Files\Mozilla Firefox\plugin-container.exe[1856] USER32.dll!SetWindowLongW 7E42C2BB 5 Bytes JMP 106ACC8C E:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
- .text E:\Program Files\Mozilla Firefox\plugin-container.exe[1856] USER32.dll!GetWindowInfo 7E42C49C 5 Bytes JMP 1045E78C E:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
- .text E:\Program Files\Mozilla Firefox\plugin-container.exe[1856] USER32.dll!TrackPopupMenu 7E46531E 5 Bytes JMP 1045ED49 E:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
- ---- Devices - GMER 1.0.15 ----
- Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
- Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
- Device Cdfs.SYS (CD-ROM File System Driver/Microsoft Corporation)
- ---- Modules - GMER 1.0.15 ----
- Module (noname) (*** hidden *** ) 9C58B000-9C5A1000 (90112 bytes)
- ---- Files - GMER 1.0.15 ----
- File E:\clean\log\2011-07-05__22:11boot-repair56\2011-07-05__22:11.boot-repair.log.tee 10007 bytes
- File E:\clean\log\2011-07-05__22:11boot-repair56\608CBAC28CBA9250 4 bytes
- File E:\clean\log\2011-07-05__22:11boot-repair56\sda 0 bytes
- File E:\clean\log\2011-07-05__22:11boot-repair56\sda\current_mbr.img 1048576 bytes
- File E:\clean\log\2011-07-05__22:11boot-repair56\sda\mbr_before_reinstalling_grub.img 1048576 bytes
- File E:\WINDOWS\$NtUninstallKB14528$\1388125074 0 bytes
- File E:\WINDOWS\$NtUninstallKB14528$\2764807179 0 bytes
- File E:\WINDOWS\$NtUninstallKB14528$\2764807179\@ 2048 bytes
- File E:\WINDOWS\$NtUninstallKB14528$\2764807179\bckfg.tmp 850 bytes
- File E:\WINDOWS\$NtUninstallKB14528$\2764807179\cfg.ini 208 bytes
- File E:\WINDOWS\$NtUninstallKB14528$\2764807179\Desktop.ini 4608 bytes
- File E:\WINDOWS\$NtUninstallKB14528$\2764807179\keywords 151 bytes
- File E:\WINDOWS\$NtUninstallKB14528$\2764807179\kwrd.dll 223744 bytes
- File E:\WINDOWS\$NtUninstallKB14528$\2764807179\L 0 bytes
- File E:\WINDOWS\$NtUninstallKB14528$\2764807179\L\qjoiokwu 75264 bytes
- File E:\WINDOWS\$NtUninstallKB14528$\2764807179\lsflt7.ver 5176 bytes
- File E:\WINDOWS\$NtUninstallKB14528$\2764807179\U 0 bytes
- File E:\WINDOWS\$NtUninstallKB14528$\2764807179\U\00000001.@ 2048 bytes
- File E:\WINDOWS\$NtUninstallKB14528$\2764807179\U\00000002.@ 224768 bytes
- File E:\WINDOWS\$NtUninstallKB14528$\2764807179\U\00000004.@ 1024 bytes
- File E:\WINDOWS\$NtUninstallKB14528$\2764807179\U\80000000.@ 1024 bytes
- File E:\WINDOWS\$NtUninstallKB14528$\2764807179\U\80000004.@ 12800 bytes
- File E:\WINDOWS\$NtUninstallKB14528$\2764807179\U\80000032.@ 98304 bytes
- ---- EOF - GMER 1.0.15 ----
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement