i have the gmer log GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-27 05:49:45
Windows 6.0.6001 Service Pack 1
Running: ewgrqd99.exe; Driver: C:\Users\LILBIG~1\AppData\Local\Temp\ufxiqkob.sys
---- System - GMER 1.0.15 ----
Code 8482A798 ZwEnumerateKey
Code 8482A760 ZwFlushInstructionCache
Code 84C86E2D IofCallDriver
Code 84C86E66 IofCompleteRequest
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!IofCompleteRequest 81E81FE2 5 Bytes JMP 84C86E6B
.text ntkrnlpa.exe!IofCallDriver 81F03F6F 5 Bytes JMP 84C86E32
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 81FFA30B 5 Bytes JMP 8482A764
PAGE ntkrnlpa.exe!ZwEnumerateKey 8204FBAC 5 Bytes JMP 8482A79C
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Internet Explorer\iexplore.exe[192] USER32.dll!DialogBoxIndirectParamW 76E9BD25 5 Bytes JMP 727843F7 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[192] USER32.dll!CreateWindowExW 76EA3D67 5 Bytes JMP 7268D9BC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[192] USER32.dll!DialogBoxParamA 76ED80B2 5 Bytes JMP 72784394 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[192] USER32.dll!DialogBoxIndirectParamA 76ED83DD 5 Bytes JMP 7278445A C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[192] USER32.dll!MessageBoxIndirectA 76EED471 5 Bytes JMP 72784329 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[192] USER32.dll!MessageBoxIndirectW 76EED56B 5 Bytes JMP 727842BE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[192] USER32.dll!MessageBoxExA 76EED5D1 5 Bytes JMP 7278425C C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[192] USER32.dll!MessageBoxExW 76EED5F5 5 Bytes JMP 727841FA C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[192] ole32.dll!OleLoadFromStream 76FD9726 5 Bytes JMP 72784778 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[192] WININET.dll!HttpAddRequestHeadersA 7712CF46 5 Bytes JMP 008F000A
.text C:\Program Files\Internet Explorer\iexplore.exe[192] WININET.dll!HttpOpenRequestA 7712D508 5 Bytes JMP 00D6000A
.text C:\Program Files\Internet Explorer\iexplore.exe[192] WININET.dll!InternetConnectA 7712DEAE 5 Bytes JMP 00D8000A
.text C:\Program Files\Internet Explorer\iexplore.exe[192] WININET.dll!InternetConnectW 7712F862 5 Bytes JMP 00D7000A
.text C:\Program Files\Internet Explorer\iexplore.exe[192] WININET.dll!HttpOpenRequestW 7712FBFB 5 Bytes JMP 00D5000A
.text C:\Program Files\Internet Explorer\iexplore.exe[192] WININET.dll!HttpAddRequestHeadersW 7712FE49 5 Bytes JMP 00D4000A
.text C:\Program Files\Internet Explorer\iexplore.exe[192] WS2_32.dll!closesocket 76F3330C 5 Bytes JMP 031F000A
.text C:\Program Files\Internet Explorer\iexplore.exe[192] WS2_32.dll!recv 76F3343A 5 Bytes JMP 0309000A
.text C:\Program Files\Internet Explorer\iexplore.exe[192] WS2_32.dll!connect 76F340D9 5 Bytes JMP 030A000A
.text C:\Program Files\Internet Explorer\iexplore.exe[192] WS2_32.dll!send 76F3659B 5 Bytes JMP 0320000A
.text C:\Program Files\Trend Micro\supercool\HijackThis.exe[312] kernel32.dll!CreateProcessW 76CF1C01 5 Bytes JMP 0177000A
.text C:\Program Files\DAP\DAP.EXE[320] kernel32.dll!CreateProcessW 76CF1C01 5 Bytes JMP 00A9000A
.text C:\Windows\Explorer.EXE[440] kernel32.dll!CreateProcessW 76CF1C01 5 Bytes JMP 01D9000A
.text C:\Windows\system32\wininit.exe[572] kernel32.dll!CreateProcessW 76CF1C01 5 Bytes JMP 009A000A
.text C:\Windows\system32\services.exe[648] kernel32.dll!CreateProcessW 76CF1C01 5 Bytes JMP 00EB000A
.text ...
.text C:\Program Files\Mozilla Firefox\firefox.exe[1896] WS2_32.dll!closesocket 76F3330C 5 Bytes JMP 034F000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[1896] WS2_32.dll!connect 76F340D9 5 Bytes JMP 034E000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[1896] WS2_32.dll!send 76F3659B 5 Bytes JMP 0350000A
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileA] 0203BFC0
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileW] 0203C030
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!ExitProcess] 02039F00
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetCommandLineA] 0203C560
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CloseHandle] 0203B230
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] 020386C0
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] 02039920
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] 02039B90
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileType] 0203B340
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetProcessHeap] 0203C550
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DuplicateHandle] 0203B190
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFilePointer] 0203AFF0
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileA] 0203A3F0
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!ReadFile] 0203AB80
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileW] 0203A830
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!WriteFile] 0203AFB0
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetACP] 0203C570
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetEnvironmentStringsW] 02039E80
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryW] 020399A0
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!TerminateProcess] 0203A000
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetModuleHandleA] 0203C230
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateThread] 0203A150
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcessHeap] 0203C550
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW] 0203C030
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DuplicateHandle] 0203B190
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!IsDebuggerPresent] 0203CAD0
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateThread] 0203A150
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 02039B00
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetEnvironmentStringsW] 02039E80
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SetFilePointer] 0203AFF0
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!MapViewOfFileEx] 0203B6B0
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileMappingW] 0203B440
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!MapViewOfFile] 0203B630
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!OpenFileMappingW] 0203BB10
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!UnmapViewOfFile] 0203B820
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileType] 0203B340
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FlushViewOfFile] 0203B580
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileSize] 0203B130
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!WriteFile] 0203AFB0
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetACP] 0203C570
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!TerminateProcess] 0203A000
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalAlloc] 0203C290
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalLock] 0203C1B0
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalUnlock] 0203C170
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW] 0203A830
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] 020399A0
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CloseHandle] 0203B230
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] 02039920
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FreeLibrary] 02039B90
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcAddress] 020386C0
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!ReadFile] 0203AB80
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetVersion] 0203C540
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadIconW] 0203C810
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadCursorW] 0203C7B0
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [USER32.dll!CreateDialogParamW] 0203CA00
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [USER32.dll!DialogBoxParamW] 0203CAA0
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadStringW] 0203C8D0
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA] 0203C4C0
IAT C:\Program Files\DAP\DAP.EXE[320] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW] 0203C470
