very slow startup
Page 1 of 2 12 LastLast
Results 1 to 15 of 17

Thread: very slow startup

  1. #1
    Join Date
    Jun 2008
    Posts
    45

    very slow startup

    My xp system starts up very slowly 20-30 mins to start up then open the homepage in firefox.
    1)I ran Ccleaner.
    2)ran spybot s and d
    3) I use avast
    4) I ran disk clean up on C: (seems to hang/get stuck when "disk cleanup utility is cleaning up the unnecessary files) i.e. didnt finish
    5) I am not sure if infected or just need to reinstall win xp (last install was a few years back)

    malaware bytes log

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4451

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    20/08/2010 2:36:31 PM
    mbam-log-2010-08-20 (14-36-31).txt

    Scan type: Quick scan
    Objects scanned: 146880
    Time elapsed: 20 minute(s), 28 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 2
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    restarting then gmer scan

  2. #2
    Join Date
    Feb 2004
    Location
    Mandurah, Western Australia
    Posts
    10,157
    Once you have posted all the requested logs from the forum sticky, I will take a look.

  3. #3
    Join Date
    Jun 2008
    Posts
    45
    sorry, the gmer log took too long on Friday afternoon, so i had to re-run it this morning.
    Here it is, (Gmer.log)
    DDS will follow in the next post:

    GMER 1.0.15.15281 - http://www.gmer.net
    Rootkit scan 2010-08-20 16:59:37
    Windows 5.1.2600 Service Pack 3
    Running: uuz4l8vk.exe; Driver: C:\DOCUME~1\SIPSEA~1\LOCALS~1\Temp\uxtdypod.sys


    ---- System - GMER 1.0.15 ----

    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xF1B60618]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xF1B604D4]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xF1B609B2]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xF1B600AC]
    SSDT spvv.sys ZwEnumerateKey [0xF73DDCA4]
    SSDT spvv.sys ZwEnumerateValueKey [0xF73DE032]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xF1B605AE]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xF1B5FFEC]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xF1B60050]
    SSDT spvv.sys ZwQueryKey [0xF73DE10A]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xF1B606CE]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xF1B6068E]
    SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xF1B6080E]

    INT 0x62 ? 84D75BF8
    INT 0x63 ? 84D77BF8
    INT 0x73 ? 84D75BF8
    INT 0x82 ? 84D75BF8
    INT 0x83 ? 84D75BF8
    INT 0xA4 ? 84AE5BF8
    INT 0xA4 ? 84AE5BF8
    INT 0xA4 ? 84AE5BF8
    INT 0xA4 ? 84AE5BF8

    ---- Kernel code sections - GMER 1.0.15 ----

    PAGE ntkrnlpa.exe!IoWMISetNotificationCallback + 258 805F5E00 2 Bytes [D4, 8B] {AAM 0x8b}
    PAGE ntkrnlpa.exe!IoWMISetNotificationCallback + 25B 805F5E03 98 Bytes [0C, 83, 08, FF, B8, 96, 02, ...]
    PAGE ntkrnlpa.exe!IoWMISetNotificationCallback + 2BE 805F5E66 86 Bytes [80, 00, 00, 02, 00, 89, 9D, ...]
    PAGE ntkrnlpa.exe!IoWMISetNotificationCallback + 315 805F5EBD 8 Bytes [FF, FF, FF, 8B, 85, 50, FF, ...]
    PAGE ntkrnlpa.exe!IoWMISetNotificationCallback + 31E 805F5EC6 10 Bytes [3B, 05, 6C, 0B, 67, 80, 8B, ...]
    PAGE ...

  4. #4
    Join Date
    Jun 2008
    Posts
    45
    PAGE ntkrnlpa.exe!FsRtlInitializeOplock + 92 805F662A 9 Bytes [75, 0F, 6A, 07, 59, E8, 1A, ...]
    PAGE ntkrnlpa.exe!FsRtlInitializeOplock + 9C 805F6634 68 Bytes [83, 0D, 40, AA, 54, 80, FF, ...]
    PAGE ntkrnlpa.exe!FsRtlInitializeOplock + E1 805F6679 100 Bytes [45, 0C, 89, 30, 8B, 5D, 08, ...]
    PAGE ntkrnlpa.exe!FsRtlInitializeOplock + 146 805F66DE 239 Bytes [00, 00, 8B, 08, 8D, 3C, 11, ...]
    PAGE ntkrnlpa.exe!FsRtlInitializeOplock + 236 805F67CE 30 Bytes [13, 89, 7D, D8, B8, FF, FF, ...]
    PAGE ...
    PAGE ntkrnlpa.exe!ExAcquireRundownProtection + 15 80602C23 7 Bytes [02, 89, 45, F8, 8B, 45, FC] {ADD CL, [ECX+0x458bf845]; CLD }
    PAGE ntkrnlpa.exe!ExAcquireRundownProtection + 1D 80602C2B 2 Bytes [4D, F4] {DEC EBP; HLT }
    PAGE ntkrnlpa.exe!ExAcquireRundownProtection + 20 80602C2E 13 Bytes [55, F8, 0F, B1, 11, 3B, C3, ...] {PUSH EBP; CLC ; CMPXCHG [ECX], EDX; CMP EAX, EBX; JZ 0x16; MOV EBX, EAX; TEST AL, 0x1}
    PAGE ntkrnlpa.exe!ExAcquireRundownProtection + 2E 80602C3C 140 Bytes [5D, FC, 74, E1, 32, C0, EB, ...]
    PAGE ntkrnlpa.exe!ExReleaseRundownProtection + 33 80602CC9 7 Bytes [E3, FE, 89, 5D, F4, B8, FF]
    PAGE ntkrnlpa.exe!ExReleaseRundownProtection + 3B 80602CD1 89 Bytes [FF, FF, 8B, 4D, F4, 0F, C1, ...]
    PAGE ntkrnlpa.exe!ExReleaseRundownProtectionEx + 39 80602D2B 4 Bytes [5D, FC, 74, E0] {POP EBP; CLD ; JZ 0xffffffffffffffe4}
    PAGE ntkrnlpa.exe!ExReleaseRundownProtectionEx + 3E 80602D30 15 Bytes [C6, 83, E3, FE, F7, D8, 89, ...] {MOV BYTE [EBX-0x2708011d], 0x89; POP EBP; HLT ; MOV [EBP-0x8], EAX; MOV EAX, [EBP-0x8]}
    PAGE ntkrnlpa.exe!ExReleaseRundownProtectionEx + 4F 80602D41 81 Bytes [F4, 0F, C1, 01, 3B, C6, 75, ...]
    PAGE ntkrnlpa.exe!ExWaitForRundownProtectionRelease + 33 80602D93 100 Bytes [89, 45, F4, 56, 8B, 75, FC, ...]
    PAGE ntkrnlpa.exe!ExWaitForRundownProtectionRelease + 98 80602DF8 55 Bytes CALL 80544866 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ExfAcquirePushLockExclusive + 20 80602E30 139 Bytes [45, F8, 8B, 4D, F4, 8B, 55, ...]
    PAGE ntkrnlpa.exe!ExfAcquirePushLockShared + 19 80602EBD 227 Bytes [04, 89, 45, FC, 8B, 45, F8, ...]
    PAGE ntkrnlpa.exe!ExfReleasePushLock + 71 80602FA1 66 Bytes [75, 06, 80, 7E, 18, 00, 74, ...]
    PAGE ntkrnlpa.exe!ExfReleasePushLock + B4 80602FE4 220 Bytes CALL 804F903D \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ExfReleasePushLock + 191 806030C1 25 Bytes [75, 1D, 68, 50, 6C, 63, 6C, ...]
    PAGE ntkrnlpa.exe!ExfReleasePushLock + 1AC 806030DC 123 Bytes [89, 07, EB, 3E, 0F, BE, 0D, ...]
    PAGE ntkrnlpa.exe!ExfReleasePushLock + 228 80603158 1 Byte [8B]
    PAGE ...
    PAGE ntkrnlpa.exe!ExCreateCallback + 5 806032ED 1 Byte [51]
    PAGE ntkrnlpa.exe!ExCreateCallback + 8 806032F0 42 Bytes [8B, 75, 0C, 33, DB, 39, 5E, ...]
    PAGE ntkrnlpa.exe!ExCreateCallback + 33 8060331B 2 Bytes [3B, FB] {CMP EDI, EBX}
    PAGE ntkrnlpa.exe!ExCreateCallback + 36 8060331E 20 Bytes [57, 38, 5D, 10, 74, 4E, 8D, ...]
    PAGE ntkrnlpa.exe!ExCreateCallback + 4B 80603333 45 Bytes CALL 805B6DDB \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ...
    PAGE ntkrnlpa.exe!ExInitializePagedLookasideList + 27 8060365F 34 Bytes [48, 04, 66, C7, 40, 08, 04, ...]
    PAGE ntkrnlpa.exe!ExInitializePagedLookasideList + 4A 80603682 131 Bytes [EB, 03, 89, 50, 28, 8B, 55, ...]
    PAGE ntkrnlpa.exe!ExInitializePagedLookasideList + CE 80603706 66 Bytes CALL 80519D54 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ExInitializePagedLookasideList + 111 80603749 3 Bytes CALL 80519CFB \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ExInitializePagedLookasideList + 115 8060374D 75 Bytes CALL 805A99BF \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ...
    PAGE ntkrnlpa.exe!ExEnumHandleTable + 1C 8060453C 9 Bytes [FF, 8F, D4, 00, 00, 00, C6, ...]
    PAGE ntkrnlpa.exe!ExEnumHandleTable + 26 80604546 69 Bytes CALL 80603F2E \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ExEnumHandleTable + 6C 8060458C 12 Bytes [75, 08, 88, 45, FF, E8, 8A, ...]
    PAGE ntkrnlpa.exe!ExEnumHandleTable + 79 80604599 37 Bytes [00, 75, 26, 83, 45, F8, 04, ...]
    PAGE ntkrnlpa.exe!ExEnumHandleTable + A0 806045C0 15 Bytes [EB, 9E, 8B, 45, 14, 85, C0, ...] {JMP 0xffffffffffffffa0; MOV EAX, [EBP+0x14]; TEST EAX, EAX; JZ 0xe; MOV ECX, [EBP-0x8]; MOV [EAX], ECX; POP EBX}
    PAGE ...
    PAGE ntkrnlpa.exe!ZwClearEvent + 4 80605182 43 Bytes [EC, 51, 56, 64, A1, 24, 01, ...]
    PAGE ntkrnlpa.exe!ZwClearEvent + 30 806051AE 14 Bytes [F0, 85, F6, 8B, 45, 08, 8B, ...]
    PAGE ntkrnlpa.exe!ZwClearEvent + 3F 806051BD 3 Bytes CALL 80522B93 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwClearEvent + 43 806051C1 29 Bytes [8B, C6, 5E, C9, C2, 04, 00, ...]
    PAGE ntkrnlpa.exe!NtCreateEvent + 11 806051DF 74 Bytes [00, 8A, 80, 40, 01, 00, 00, ...]
    PAGE ntkrnlpa.exe!NtCreateEvent + 5C 8060522A 15 Bytes [75, 08, 39, 5D, 14, 74, 10, ...]
    PAGE ntkrnlpa.exe!NtCreateEvent + 6C 8060523A 4 Bytes [00, C0, E9, 80]
    PAGE ntkrnlpa.exe!NtCreateEvent + 73 80605241 20 Bytes [8D, 45, D4, 50, 53, 53, 6A, ...]
    PAGE ntkrnlpa.exe!NtCreateEvent + 89 80605257 187 Bytes CALL 805B6DDC \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwOpenEvent + 45 80605313 36 Bytes CALL 80609304 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwOpenEvent + 6A 80605338 2 Bytes [75, DC] {JNZ 0xffffffffffffffde}
    PAGE ntkrnlpa.exe!ZwOpenEvent + 6D 8060533B 98 Bytes [35, C0, B4, 55, 80, FF, 75, ...]
    PAGE ntkrnlpa.exe!ZwPulseEvent + 18 8060539E 24 Bytes [88, 45, E0, 8B, 75, 0C, 33, ...]
    PAGE ntkrnlpa.exe!ZwPulseEvent + 31 806053B7 26 Bytes [F0, 72, 02, 89, 18, 8B, 06, ...]
    PAGE ntkrnlpa.exe!ZwPulseEvent + 4C 806053D2 79 Bytes [6A, 02, FF, 75, 08, E8, 5A, ...]
    PAGE ntkrnlpa.exe!ZwPulseEvent + 9D 80605423 80 Bytes CALL 805CA1AB \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwQueryEvent + 27 80605475 19 Bytes JMP 80605552 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwQueryEvent + 3B 80605489 77 Bytes [E0, 84, C0, 74, 48, 89, 7D, ...]
    PAGE ntkrnlpa.exe!ZwQueryEvent + 8A 806054D8 61 Bytes [10, 57, 8D, 45, E4, 50, FF, ...]
    PAGE ntkrnlpa.exe!ZwQueryEvent + C8 80605516 22 Bytes [FC, 01, 00, 00, 00, 89, 3E, ...]
    PAGE ntkrnlpa.exe!ZwQueryEvent + DF 8060552D 35 Bytes [83, 4D, FC, FF, EB, 1D, E8, ...]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwResetEvent + 1D 8060557D 25 Bytes [0C, 33, FF, 3B, F7, 74, 1A, ...]
    PAGE ntkrnlpa.exe!ZwResetEvent + 37 80605597 20 Bytes [06, 89, 06, 83, 4D, FC, FF, ...]
    PAGE ntkrnlpa.exe!ZwResetEvent + 4C 806055AC 138 Bytes [6A, 02, FF, 75, 08, E8, 80, ...]
    PAGE ntkrnlpa.exe!NtSetEvent + 17 80605637 8 Bytes [00, 88, 45, E4, 33, DB, 89, ...]
    PAGE ntkrnlpa.exe!NtSetEvent + 20 80605640 70 Bytes [8B, 7D, 0C, 84, C0, 74, 13, ...]
    PAGE ntkrnlpa.exe!NtSetEvent + 67 80605687 55 Bytes [35, 38, AB, 54, 80, 56, E8, ...]
    PAGE ntkrnlpa.exe!NtSetEvent + 9F 806056BF 72 Bytes [45, DC, EB, 1A, 8B, 45, EC, ...]
    PAGE ntkrnlpa.exe!ZwSetEventBoostPriority + 1E 80605708 77 Bytes [FC, FF, 35, C0, B4, 55, 80, ...]
    PAGE ntkrnlpa.exe!ZwSetEventBoostPriority + 6C 80605756 19 Bytes [79, 00, 5C, 00, 4D, 00, 61, ...] {JNS 0x2; POP ESP; ADD [EBP+0x0], CL; POPA ; ADD [EBX+0x0], AH; PUSH 0x6e006900; ADD [EBP+0x0], AH; POP ESP}
    PAGE ntkrnlpa.exe!ZwSetEventBoostPriority + 80 8060576A 5 Bytes [53, 00, 4F, 00, 46] {PUSH EBX; ADD [EDI+0x0], CL; INC ESI}
    PAGE ntkrnlpa.exe!ZwSetEventBoostPriority + 86 80605770 39 Bytes [54, 00, 57, 00, 41, 00, 52, ...]
    PAGE ntkrnlpa.exe!ZwSetEventBoostPriority + AE 80605798 1 Byte [46]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwSetSystemInformation + 24 80605F44 10 Bytes [89, 85, 40, FF, FF, FF, 8A, ...]
    PAGE ntkrnlpa.exe!ZwSetSystemInformation + 2F 80605F4F 4 Bytes [00, 88, 4D, E0]
    PAGE ntkrnlpa.exe!ZwSetSystemInformation + 34 80605F54 2 Bytes [75, 10] {JNZ 0x12}
    PAGE ntkrnlpa.exe!ZwSetSystemInformation + 37 80605F57 269 Bytes [5D, 0C, 84, C9, 74, 28, 3B, ...]
    PAGE ntkrnlpa.exe!ZwSetSystemInformation + 145 80606065 77 Bytes [FF, 35, 24, 08, 67, 80, E8, ...]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwQueryDefaultLocale 80606F12 55 Bytes [6A, 14, 68, A0, C6, 4D, 80, ...]
    PAGE ntkrnlpa.exe!ZwQueryDefaultLocale + 38 80606F4A 137 Bytes [06, 89, 06, 38, 4D, 08, 74, ...]

  5. #5
    Join Date
    Jun 2008
    Posts
    45
    PAGE ntkrnlpa.exe!ZwQueryDefaultLocale + C2 80606FD4 31 Bytes [75, 00, 6C, 00, 74, 00, 00, ...]
    PAGE ntkrnlpa.exe!ZwQueryDefaultLocale + E2 80606FF4 29 Bytes [63, 00, 68, 00, 69, 00, 6E, ...]
    PAGE ntkrnlpa.exe!ZwQueryDefaultLocale + 100 80607012 3 Bytes [72, 00, 72]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwSetDefaultLocale + 4 80607066 13 Bytes [EC, 81, EC, 38, 01, 00, 00, ...] {IN AL, DX ; SUB ESP, 0x138; MOV EAX, [0x8054aec0]; PUSH EDI}
    PAGE ntkrnlpa.exe!ZwSetDefaultLocale + 13 80607075 107 Bytes [0C, F7, C7, 00, 00, FF, FF, ...]
    PAGE ntkrnlpa.exe!ZwSetDefaultLocale + 7F 806070E1 9 Bytes CALL 8052AD9C \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwSetDefaultLocale + 89 806070EB 22 Bytes [8D, 85, E4, FE, FF, FF, 50, ...]
    PAGE ntkrnlpa.exe!ZwSetDefaultLocale + A0 80607102 74 Bytes [3B, FB, 8B, 8D, F4, FE, FF, ...]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwQueryInstallUILanguage + F 8060731F 15 Bytes [55, FC, 64, A1, 24, 01, 00, ...]
    PAGE ntkrnlpa.exe!ZwQueryInstallUILanguage + 1F 8060732F 34 Bytes [00, 88, 45, E7, 8B, 4D, 08, ...]
    PAGE ntkrnlpa.exe!ZwQueryInstallUILanguage + 42 80607352 1 Byte [66]
    PAGE ntkrnlpa.exe!ZwQueryInstallUILanguage + 42 80607352 133 Bytes [66, 89, 01, EB, 14, 8B, 45, ...]
    PAGE ntkrnlpa.exe!ZwQueryInstallUILanguage + C8 806073D8 1 Byte [5C]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwSetDefaultUILanguage + 8A 8060795E 6 Bytes [0F, 00, 00, C1, EA, 0C] {SLDT DWORD [EAX]; SHR EDX, 0xc}
    PAGE ntkrnlpa.exe!ZwSetDefaultUILanguage + 91 80607965 51 Bytes [14, 95, 1C, 00, 00, 00, 66, ...]
    PAGE ntkrnlpa.exe!ZwSetDefaultUILanguage + C5 80607999 5 Bytes [46, 06, 05, 74, 05]
    PAGE ntkrnlpa.exe!ZwSetDefaultUILanguage + CB 8060799F 18 Bytes [46, 0C, EB, 08, 6A, 00, 56, ...]
    PAGE ntkrnlpa.exe!ZwSetDefaultUILanguage + DE 806079B2 24 Bytes CALL 805340C5 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ...
    PAGE ntkrnlpa.exe!ZwQueryDefaultUILanguage + 2F 80607BA1 24 Bytes [3B, F0, 72, 03, 66, 89, 38, ...]
    PAGE ntkrnlpa.exe!ZwQueryDefaultUILanguage + 49 80607BBB 147 Bytes [85, C0, 7D, 1F, 66, A1, 30, ...]
    PAGE ntkrnlpa.exe!NtQuerySystemInformation + 5D 80607C4F 68 Bytes [3B, F0, 72, 06, C7, 00, 00, ...]
    PAGE ntkrnlpa.exe!NtQuerySystemInformation + A3 80607C95 24 Bytes CALL 80533FD1 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!NtQuerySystemInformation + BC 80607CAE 9 Bytes [C7, 06, 2C, 00, 00, 00, E9, ...]
    PAGE ntkrnlpa.exe!NtQuerySystemInformation + C6 80607CB8 140 Bytes [00, 83, FF, 0C, 72, CD, 53, ...]
    PAGE ntkrnlpa.exe!NtQuerySystemInformation + 153 80607D45 9 Bytes [55, A0, 33, F6, 89, 75, B4, ...]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwDisplayString + 4C 806091C4 24 Bytes [00, 00, 89, 7D, FC, A1, 54, ...]
    PAGE ntkrnlpa.exe!ZwDisplayString + 65 806091DD 40 Bytes [0E, 89, 4D, C0, 8B, 76, 04, ...]
    PAGE ntkrnlpa.exe!ZwDisplayString + 8E 80609206 48 Bytes [CE, 72, 04, 3B, C8, 76, 05, ...]
    PAGE ntkrnlpa.exe!ZwDisplayString + C0 80609238 43 Bytes [00, C7, 45, FC, 01, 00, 00, ...]
    PAGE ntkrnlpa.exe!ZwDisplayString + EC 80609264 47 Bytes [72, 67, 0F, B7, 46, 02, 50, ...]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwQueryTimerResolution + 95 806093DB 50 Bytes [8B, 0D, 2C, AE, 54, 80, 89, ...]
    PAGE ntkrnlpa.exe!ZwQueryTimerResolution + C8 8060940E 41 Bytes [C0, 39, 45, 08, 74, 17, 8D, ...]
    PAGE ntkrnlpa.exe!ZwQueryTimerResolution + F2 80609438 15 Bytes [69, 00, 73, 00, 74, 00, 72, ...] {IMUL EAX, [EAX], 0x740073; JB 0x8; JNS 0xa; POP ESP; ADD [EBP+0x0], CL; POPA }
    PAGE ntkrnlpa.exe!ZwQueryTimerResolution + 102 80609448 13 Bytes [63, 00, 68, 00, 69, 00, 6E, ...]
    PAGE ntkrnlpa.exe!ZwQueryTimerResolution + 110 80609456 7 Bytes [79, 00, 73, 00, 74, 00, 65]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwLockProductActivationKeys + D 806096E7 337 Bytes [F2, FF, A1, C0, AE, 54, 80, ...]
    PAGE ntkrnlpa.exe!ZwLockProductActivationKeys + 15F 80609839 19 Bytes [EB, 55, 8B, 45, EC, 8B, 00, ...] {JMP 0x57; MOV EAX, [EBP-0x14]; MOV EAX, [EAX]; MOV EAX, [EAX]; MOV [EBP-0x88c], EAX; XOR EAX, EAX; INC EAX; RET }
    PAGE ntkrnlpa.exe!ZwLockProductActivationKeys + 173 8060984D 16 Bytes CALL 805CE5D5 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwLockProductActivationKeys + 184 8060985E 22 Bytes [8B, 85, 88, F7, FF, FF, 3B, ...]
    PAGE ntkrnlpa.exe!ZwLockProductActivationKeys + 19B 80609875 40 Bytes [FF, 81, C1, 7D, 21, 00, 00, ...]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwQuerySystemTime + 7 80609A95 26 Bytes CALL 80537F40 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwQuerySystemTime + 22 80609AB0 66 Bytes [08, 89, 5D, E0, A1, 54, 8A, ...]
    PAGE ntkrnlpa.exe!ZwQuerySystemTime + 65 80609AF3 1 Byte [8B]
    PAGE ntkrnlpa.exe!ZwQuerySystemTime + 65 80609AF3 31 Bytes [8B, 00, 89, 45, E4, 33, C0, ...]
    PAGE ntkrnlpa.exe!ZwQuerySystemTime + 85 80609B13 3 Bytes CALL 80537F7C \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ...
    PAGE ntkrnlpa.exe!ZwSetTimerResolution + 39 80609B59 71 Bytes [EB, 22, 8B, 45, EC, 8B, 00, ...]
    PAGE ntkrnlpa.exe!ZwSetTimerResolution + 81 80609BA1 60 Bytes [75, 49, B9, FF, EF, FF, FF, ...]
    PAGE ntkrnlpa.exe!ZwSetTimerResolution + BE 80609BDE 19 Bytes CALL 804FB85D \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwSetTimerResolution + D2 80609BF2 31 Bytes [D1, 8B, 07, 8B, D8, 0B, DA, ...]
    PAGE ntkrnlpa.exe!ZwSetTimerResolution + F2 80609C12 21 Bytes [F8, 73, 02, 8B, F8, 3B, 3D, ...]
    PAGE ...
    PAGE ntkrnlpa.exe!ExSetTimerResolution + 2A 80609CA8 49 Bytes [75, 6D, FF, 0D, CC, 0C, 67, ...]
    PAGE ntkrnlpa.exe!ExSetTimerResolution + 5C 80609CDA 41 Bytes [75, 06, FF, 05, CC, 0C, 67, ...]
    PAGE ntkrnlpa.exe!ExSetTimerResolution + 86 80609D04 33 Bytes CALL 0BE0EA7F
    PAGE ntkrnlpa.exe!ExSetTimerResolution + A8 80609D26 13 Bytes [52, 00, 65, 00, 67, 00, 69, ...]
    PAGE ntkrnlpa.exe!ExSetTimerResolution + B6 80609D34 11 Bytes [79, 00, 5C, 00, 4D, 00, 61, ...]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwSetSystemTime + 18 8060A666 6 Bytes [00, 64, A1, 24, 01, 00] {ADD [ECX+0x24], AH; ADD [EAX], EAX}
    PAGE ntkrnlpa.exe!ZwSetSystemTime + 1F 8060A66D 4 Bytes [8A, 80, 40, 01]
    PAGE ntkrnlpa.exe!ZwSetSystemTime + 25 8060A673 29 Bytes [88, 45, E4, FF, 75, E4, FF, ...]
    PAGE ntkrnlpa.exe!ZwSetSystemTime + 43 8060A691 24 Bytes JMP 8060A85A \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwSetSystemTime + 5D 8060A6AB 23 Bytes [A1, 54, 8A, 55, 80, 3B, D8, ...]
    PAGE ...

  6. #6
    Join Date
    Jun 2008
    Posts
    45
    PAGE ntkrnlpa.exe!ExRaiseDatatypeMisalignment + 44 8060ABAC 3 Bytes CALL 805EE059 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ExRaiseDatatypeMisalignment + 48 8060ABB0 8 Bytes [84, C0, 75, 0A, B8, 61, 00, ...]
    PAGE ntkrnlpa.exe!ExRaiseDatatypeMisalignment + 51 8060ABB9 50 Bytes JMP 8060AD4B \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ExRaiseDatatypeMisalignment + 84 8060ABEC 23 Bytes [75, 24, 8B, CE, B8, 00, 00, ...]
    PAGE ntkrnlpa.exe!ExRaiseDatatypeMisalignment + 9C 8060AC04 42 Bytes [75, 14, FF, 75, 10, FF, 75, ...]
    PAGE ...
    PAGE ntkrnlpa.exe!ExRaiseHardError + C 8060AD64 136 Bytes [54, 80, 00, 74, 10, 8B, 45, ...]
    PAGE ntkrnlpa.exe!ExRaiseHardError + 95 8060ADED 60 Bytes [FC, 8B, F0, 83, C0, 14, 33, ...]
    PAGE ntkrnlpa.exe!ExRaiseHardError + D2 8060AE2A 13 Bytes [14, 8E, 0F, B7, 4C, 05, BE, ...]
    PAGE ntkrnlpa.exe!ExRaiseHardError + E0 8060AE38 24 Bytes JMP 0C06A13F
    PAGE ntkrnlpa.exe!ExRaiseHardError + F9 8060AE51 49 Bytes [7C, 05, C0, 8B, 44, 05, C0, ...]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwSetDefaultHardErrorPort + 38 8060AF0A 18 Bytes [07, B8, 01, 00, 00, C0, EB, ...]
    PAGE ntkrnlpa.exe!ZwSetDefaultHardErrorPort + 4C 8060AF1E 176 Bytes [6A, 00, 88, 45, FC, 8D, 45, ...]
    PAGE ntkrnlpa.exe!ZwSetDefaultHardErrorPort + FD 8060AFCF 176 Bytes [72, 65, 20, 6F, 6E, 20, 66, ...]
    PAGE ntkrnlpa.exe!ZwRaiseHardError + 58 8060B080 94 Bytes [00, 00, 00, 00, 8B, 01, 89, ...]
    PAGE ntkrnlpa.exe!ZwRaiseHardError + B7 8060B0DF 19 Bytes [CE, D3, E0, 85, C7, 74, 49, ...]
    PAGE ntkrnlpa.exe!ZwRaiseHardError + CB 8060B0F3 24 Bytes [FF, A1, 54, 8A, 55, 80, 3B, ...]
    PAGE ntkrnlpa.exe!ZwRaiseHardError + E4 8060B10C 167 Bytes [5D, D4, 66, 83, 7D, D2, 00, ...]
    PAGE ntkrnlpa.exe!ZwRaiseHardError + 18C 8060B1B4 136 Bytes [8B, 45, EC, 8B, 00, 8B, 00, ...]
    PAGE ntkrnlpa.exe!ZwCreateSemaphore + 39 8060B23D 76 Bytes [FF, EB, 22, 8B, 45, EC, 8B, ...]
    PAGE ntkrnlpa.exe!ZwCreateSemaphore + 86 8060B28A 21 Bytes [55, 80, FF, 75, E0, E8, 4A, ...]
    PAGE ntkrnlpa.exe!ZwCreateSemaphore + 9C 8060B2A0 42 Bytes CALL 804FB4E4 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwCreateSemaphore + C7 8060B2CB 42 Bytes [00, 8B, 45, E4, 89, 06, 83, ...]
    PAGE ntkrnlpa.exe!ZwCreateSemaphore + F2 8060B2F6 68 Bytes [C2, 14, 00, CC, CC, CC, CC, ...]
    PAGE ntkrnlpa.exe!ZwOpenSemaphore + 3D 8060B33B 15 Bytes [EB, 1F, 8B, 45, EC, 8B, 00, ...]
    PAGE ntkrnlpa.exe!ZwOpenSemaphore + 4D 8060B34B 23 Bytes CALL 805D00D3 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwOpenSemaphore + 65 8060B363 105 Bytes [75, 0C, 6A, 00, FF, 75, DC, ...]
    PAGE ntkrnlpa.exe!ZwQuerySemaphore + 17 8060B3CD 53 Bytes [00, 88, 45, E0, 84, C0, 74, ...]
    PAGE ntkrnlpa.exe!ZwQuerySemaphore + 4D 8060B403 13 Bytes [C9, 74, 13, A1, 54, 8A, 55, ...]
    PAGE ntkrnlpa.exe!ZwQuerySemaphore + 5D 8060B413 18 Bytes [00, 00, 8B, 01, 89, 01, 83, ...]
    PAGE ntkrnlpa.exe!ZwQuerySemaphore + 70 8060B426 40 Bytes CALL 80609305 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwQuerySemaphore + 99 8060B44F 68 Bytes [00, 00, 83, 7D, 14, 08, 74, ...]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwReleaseSemaphore + 7 8060B4ED 63 Bytes CALL 80537F40 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwReleaseSemaphore + 47 8060B52D 19 Bytes JMP 8060B5F1 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwReleaseSemaphore + 5B 8060B541 54 Bytes CALL 805D02C9 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwReleaseSemaphore + 92 8060B578 13 Bytes [00, 00, 00, 53, FF, 75, 0C, ...] {ADD [EAX], AL; ADD [EBX-0x1], DL; JNZ 0x13; PUSH DWORD [0x8054ab84]}
    PAGE ntkrnlpa.exe!ZwReleaseSemaphore + A0 8060B586 22 Bytes CALL 804FB510 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ...
    PAGE ntkrnlpa.exe!ZwSetUuidSeed + B 8060B9A7 35 Bytes [FF, C7, 45, D4, E7, 03, 00, ...]
    PAGE ntkrnlpa.exe!ZwSetUuidSeed + 2F 8060B9CB 84 Bytes [C3, 75, 03, 8B, 45, C4, 8D, ...]
    PAGE ntkrnlpa.exe!ZwSetUuidSeed + 84 8060BA20 28 Bytes CALL A531B02C
    PAGE ntkrnlpa.exe!ZwSetUuidSeed + A1 8060BA3D 17 Bytes [00, 89, 45, DC, 33, C0, 40, ...]
    PAGE ntkrnlpa.exe!ZwSetUuidSeed + B3 8060BA4F 185 Bytes [33, DB, 38, 5D, E7, 74, 09, ...]
    PAGE ntkrnlpa.exe!NtAllocateUuids + 23 8060BB09 49 Bytes [5D, 08, 84, C0, 0F, 84, 85, ...]
    PAGE ntkrnlpa.exe!NtAllocateUuids + 55 8060BB3B 1 Byte [C4]
    PAGE ntkrnlpa.exe!NtAllocateUuids + 55 8060BB3B 36 Bytes [C4, 8B, 0D, 54, 8A, 55, 80, ...]
    PAGE ntkrnlpa.exe!NtAllocateUuids + 7A 8060BB60 11 Bytes [0D, 54, 8A, 55, 80, 3B, C1, ...]
    PAGE ntkrnlpa.exe!NtAllocateUuids + 86 8060BB6C 33 Bytes CALL 8060AB64 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ...
    PAGE ntkrnlpa.exe!ExUuidCreate + 1 8060BC99 29 Bytes [FF, 55, 8B, EC, 83, EC, 0C, ...]
    PAGE ntkrnlpa.exe!ExUuidCreate + 20 8060BCB8 34 Bytes [15, F8, 0C, 67, 80, 8B, 3D, ...]
    PAGE ntkrnlpa.exe!ExUuidCreate + 43 8060BCDB 35 Bytes [0F, C1, 01, 48, 3B, 15, F8, ...]
    PAGE ntkrnlpa.exe!ExUuidCreate + 67 8060BCFF 3 Bytes CALL 80542635 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ExUuidCreate + 6B 8060BD03 78 Bytes [8B, 45, F4, 3B, 05, F8, 0C, ...]
    PAGE ...
    PAGE ntkrnlpa.exe!NtAddAtom + 1F 8060BEC7 14 Bytes [FF, 8B, 75, 10, 89, B5, 50, ...]
    PAGE ntkrnlpa.exe!NtAddAtom + 2E 8060BED6 40 Bytes [89, 85, 4C, FF, FF, FF, 85, ...]
    PAGE ntkrnlpa.exe!NtAddAtom + 57 8060BEFF 11 Bytes [64, A1, 24, 01, 00, 00, 8A, ...]
    PAGE ntkrnlpa.exe!NtAddAtom + 63 8060BF0B 16 Bytes [88, 85, 5B, FF, FF, FF, 8B, ...]
    PAGE ntkrnlpa.exe!NtAddAtom + 74 8060BF1C 21 Bytes [FF, 84, C0, 0F, 84, EB, 00, ...]
    PAGE ...

    PAGE ntkrnlpa.exe!NtFindAtom + 64 8060C176 132 Bytes [8D, 58, FF, FF, FF, 89, 8D, ...]
    PAGE ntkrnlpa.exe!NtFindAtom + E9 8060C1FB 10 Bytes [FF, FF, EB, 45, 8B, 45, EC, ...]
    PAGE ntkrnlpa.exe!NtFindAtom + F4 8060C206 66 Bytes [89, 85, 40, FF, FF, FF, 33, ...]
    PAGE ntkrnlpa.exe!NtFindAtom + 137 8060C249 64 Bytes [00, 00, 8B, CB, 8B, B5, 58, ...]
    PAGE ntkrnlpa.exe!NtFindAtom + 178 8060C28A 21 Bytes [FC, FF, 8B, F0, 85, F6, 0F, ...]
    PAGE ...
    PAGE ntkrnlpa.exe!NtQueryInformationAtom + 7 8060C38D 31 Bytes CALL 80537F40 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!NtQueryInformationAtom + 27 8060C3AD 18 Bytes [64, A1, 24, 01, 00, 00, 89, ...] {MOV EAX, FS:[0x124]; MOV [EBP-0x3c], EAX; MOV AL, [EAX+0x140]; MOV [EBP-0x19], AL}
    PAGE ntkrnlpa.exe!NtQueryInformationAtom + 3A 8060C3C0 55 Bytes [75, 10, 8B, 7D, 14, 3A, C3, ...]
    PAGE ntkrnlpa.exe!NtQueryInformationAtom + 72 8060C3F8 4 Bytes [00, C0, 89, 45]
    PAGE ntkrnlpa.exe!NtQueryInformationAtom + 77 8060C3FD 4 Bytes JMP 8060C49A \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ...
    PAGE ntkrnlpa.exe!NtAllocateLocallyUniqueId + 10 8060C4DE 48 Bytes [64, A1, 24, 01, 00, 00, 89, ...]
    PAGE ntkrnlpa.exe!NtAllocateLocallyUniqueId + 42 8060C510 76 Bytes [8A, 03, 88, 03, 8A, 43, 04, ...]
    PAGE ntkrnlpa.exe!ProbeForWrite + D 8060C55D 14 Bytes [4D, 10, 56, 8B, 75, 08, 49, ...]
    PAGE ntkrnlpa.exe!ProbeForWrite + 1C 8060C56C 15 Bytes [3B, F0, 77, 28, 3B, 05, 54, ...]

  7. #7
    Join Date
    Jun 2008
    Posts
    45
    PAGE ntkrnlpa.exe!ProbeForWrite + 2C 8060C57C 93 Bytes [FF, 23, C2, B9, 00, 10, 00, ...]
    PAGE ntkrnlpa.exe!ProbeForRead + 2C 8060C5DA 300 Bytes CALL 8060AB56 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ProbeForRead + 159 8060C707 18 Bytes [C0, EB, 2E, 3B, C3, 74, 25, ...]
    PAGE ntkrnlpa.exe!ProbeForRead + 16C 8060C71A 71 Bytes [57, 89, 5D, F8, 89, 5D, FC, ...]
    PAGE ntkrnlpa.exe!ProbeForRead + 1B4 8060C762 1 Byte [F3]
    PAGE ntkrnlpa.exe!ProbeForRead + 1B4 8060C762 197 Bytes [F3, 75, 0D, FF, 05, 4C, B0, ...]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwDelayExecution + 1A 8060CB56 57 Bytes [E0, 84, C0, 74, 4B, 83, 65, ...]
    PAGE ntkrnlpa.exe!ZwDelayExecution + 54 8060CB90 18 Bytes [00, 8B, 00, 89, 45, E4, 33, ...]
    PAGE ntkrnlpa.exe!ZwDelayExecution + 67 8060CBA3 176 Bytes [E4, EB, 1D, 8B, 45, 0C, 8B, ...]
    PAGE ntkrnlpa.exe!ZwQuerySystemEnvironmentValue + 4C 8060CC54 33 Bytes [5B, 04, 89, 5D, C4, 66, 3B, ...]
    PAGE ntkrnlpa.exe!ZwQuerySystemEnvironmentValue + 6E 8060CC76 1 Byte [FF]
    PAGE ntkrnlpa.exe!ZwQuerySystemEnvironmentValue + 6E 8060CC76 62 Bytes [FF, 8B, 5D, C4, 0F, B7, 45, ...]
    PAGE ntkrnlpa.exe!ZwQuerySystemEnvironmentValue + AD 8060CCB5 7 Bytes [01, 66, 89, 01, FF, 75, DC] {ADD [ESI-0x77], ESP; ADD EDI, EDI; JNZ 0xffffffffffffffe3}
    PAGE ntkrnlpa.exe!ZwQuerySystemEnvironmentValue + B5 8060CCBD 160 Bytes [35, B0, 08, 67, 80, FF, 35, ...]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwSetSystemEnvironmentValue + 7 8060CE93 4 Bytes CALL 80537F40 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwSetSystemEnvironmentValue + C 8060CE98 45 Bytes [33, FF, 89, 7D, C8, 89, 7D, ...]
    PAGE ntkrnlpa.exe!ZwSetSystemEnvironmentValue + 3A 8060CEC6 3 Bytes CALL 8060AB69 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwSetSystemEnvironmentValue + 3E 8060CECA 42 Bytes [A1, 54, 8A, 55, 80, 3B, D8, ...]
    PAGE ntkrnlpa.exe!ZwSetSystemEnvironmentValue + 69 8060CEF5 5 Bytes [74, 08, E8, 6C, DC]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwCancelDeviceWakeupRequest + 3 8060D12D 28 Bytes [00, C0, C2, 04, 00, CC, CC, ...]
    PAGE ntkrnlpa.exe!ZwCreateTimer + 12 8060D14A 46 Bytes [8A, 80, 40, 01, 00, 00, 88, ...]
    PAGE ntkrnlpa.exe!ZwCreateTimer + 41 8060D179 1 Byte [8B]
    PAGE ntkrnlpa.exe!ZwCreateTimer + 41 8060D179 23 Bytes [8B, 00, 89, 45, D8, E8, 85, ...]
    PAGE ntkrnlpa.exe!ZwCreateTimer + 59 8060D191 34 Bytes [00, 00, 8B, 7D, 08, 39, 5D, ...]
    PAGE ntkrnlpa.exe!ZwCreateTimer + 7D 8060D1B5 8 Bytes [00, 53, FF, 75, E0, FF, 75, ...] {ADD [EBX-0x1], DL; JNZ 0xffffffffffffffe5; PUSH DWORD [EBP+0x10]}
    PAGE ...
    PAGE ntkrnlpa.exe!ZwOpenTimer + 11 8060D26B 25 Bytes [00, 8A, 98, 40, 01, 00, 00, ...]
    PAGE ntkrnlpa.exe!ZwOpenTimer + 2B 8060D285 6 Bytes [3B, F0, 72, 06, C7, 00]
    PAGE ntkrnlpa.exe!ZwOpenTimer + 32 8060D28C 175 Bytes [00, 00, 00, 8B, 06, 89, 06, ...]
    PAGE ntkrnlpa.exe!ZwQueryTimer + 2A 8060D33C 3 Bytes [54, 8A, 55]
    PAGE ntkrnlpa.exe!ZwQueryTimer + 2E 8060D340 5 Bytes [3B, D8, 72, 03, C6]
    PAGE ntkrnlpa.exe!ZwQueryTimer + 34 8060D346 32 Bytes [00, F6, C3, 03, 74, 05, E8, ...]
    PAGE ntkrnlpa.exe!ZwQueryTimer + 55 8060D367 92 Bytes [3B, C8, 72, 06, C7, 00, 00, ...]
    PAGE ntkrnlpa.exe!ZwQueryTimer + B2 8060D3C4 4 Bytes [35, 0C, B0, 55]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwCreateEventPair + 44 8060D4B4 5 Bytes [45, D4, E8, 4D, BE]
    PAGE ntkrnlpa.exe!ZwCreateEventPair + 4A 8060D4BA 95 Bytes CALL 805D2242 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwCreateEventPair + AB 8060D51B 18 Bytes [00, 8B, 45, E4, 89, 06, 83, ...] {ADD [EBX+0x689e445], CL; OR DWORD [EBP-0x4], -0x1; JMP 0x1c; CALL 0xffffffffffffbded; RET }
    PAGE ntkrnlpa.exe!ZwCreateEventPair + BE 8060D52E 61 Bytes CALL C5ECC51E
    PAGE ntkrnlpa.exe!ZwOpenEventPair + 24 8060D56C 31 Bytes [75, 08, A1, 54, 8A, 55, 80, ...]
    PAGE ntkrnlpa.exe!ZwOpenEventPair + 44 8060D58C 1 Byte [8B]
    PAGE ntkrnlpa.exe!ZwOpenEventPair + 44 8060D58C 17 Bytes [8B, 00, 89, 45, E0, E8, 72, ...]
    PAGE ntkrnlpa.exe!ZwOpenEventPair + 56 8060D59E 52 Bytes [8B, 45, E0, EB, 4F, 8B, 75, ...]
    PAGE ntkrnlpa.exe!ZwOpenEventPair + 8C 8060D5D4 74 Bytes [8B, 45, E4, 89, 06, 83, 4D, ...]
    PAGE ntkrnlpa.exe!ZwWaitLowEventPair + 1F 8060D61F 20 Bytes [75, FC, FF, 35, 08, B0, 55, ...]
    PAGE ntkrnlpa.exe!ZwWaitLowEventPair + 34 8060D634 51 Bytes [8B, F8, 3B, FE, 7C, 1C, 56, ...]
    PAGE ntkrnlpa.exe!ZwWaitHighEventPair + 4 8060D668 12 Bytes [EC, 51, 56, 57, 64, A1, 24, ...]
    PAGE ntkrnlpa.exe!ZwWaitHighEventPair + 11 8060D675 69 Bytes [01, 00, 00, 88, 45, FC, 33, ...]
    PAGE ntkrnlpa.exe!ZwWaitHighEventPair + 57 8060D6BB 75 Bytes [C7, 5F, 5E, C9, C2, 04, 00, ...]
    PAGE ntkrnlpa.exe!ZwSetLowWaitHighEventPair + 3F 8060D707 37 Bytes [56, 8B, 75, 08, 0F, BE, C3, ...]
    PAGE ntkrnlpa.exe!ZwSetLowWaitHighEventPair + 65 8060D72D 7 Bytes [00, CC, CC, CC, CC, CC, CC] {ADD AH, CL; INT 3 ; INT 3 ; INT 3 ; INT 3 ; INT 3 }
    PAGE ntkrnlpa.exe!ZwSetHighWaitLowEventPair + 1 8060D735 17 Bytes [FF, 55, 8B, EC, 51, 53, 57, ...]
    PAGE ntkrnlpa.exe!ZwSetHighWaitLowEventPair + 13 8060D747 23 Bytes [00, 6A, 00, 8D, 45, 08, 50, ...]
    PAGE ntkrnlpa.exe!ZwSetHighWaitLowEventPair + 2B 8060D75F 65 Bytes CALL 805B0B33 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwSetLowEventPair + 1 8060D7A1 41 Bytes [FF, 55, 8B, EC, 51, 57, 64, ...]
    PAGE ntkrnlpa.exe!ZwSetLowEventPair + 2B 8060D7CB 26 Bytes CALL 805B0B34 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwSetLowEventPair + 46 8060D7E6 41 Bytes CALL 804F8FB8 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwSetHighEventPair + C 8060D810 5 Bytes [00, 8A, 80, 40, 01]
    PAGE ntkrnlpa.exe!ZwSetHighEventPair + 12 8060D816 21 Bytes [00, 6A, 00, 88, 45, FC, 8D, ...]
    PAGE ntkrnlpa.exe!ZwSetHighEventPair + 28 8060D82C 1 Byte [10]
    PAGE ntkrnlpa.exe!ZwSetHighEventPair + 28 8060D82C 21 Bytes [10, 00, FF, 75, 08, E8, 00, ...]
    PAGE ntkrnlpa.exe!ZwSetHighEventPair + 3E 8060D842 5 Bytes [56, 8B, 75, 08, 6A]
    PAGE ...

  8. #8
    Join Date
    Jun 2008
    Posts
    45
    PAGE ntkrnlpa.exe!ZwCreateMutant + 20 8060D888 110 Bytes [88, 45, E0, 8B, 7D, 08, 3A, ...]
    PAGE ntkrnlpa.exe!ZwCreateMutant + 90 8060D8F8 54 Bytes [8B, 45, E4, 89, 07, 89, 5D, ...]
    PAGE ntkrnlpa.exe!ZwCreateMutant + C7 8060D92F 77 Bytes CALL 80537F78 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwOpenMutant + 3D 8060D97D 13 Bytes [53, FF, 75, 0C, 53, FF, 75, ...]
    PAGE ntkrnlpa.exe!ZwOpenMutant + 4B 8060D98B 27 Bytes CALL 805B0FF7 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwOpenMutant + 67 8060D9A7 8 Bytes [5D, FC, EB, 0D, E8, 58, B9, ...]
    PAGE ntkrnlpa.exe!ZwOpenMutant + 70 8060D9B0 7 Bytes [C3, 8B, 65, E8, 83, 65, FC]
    PAGE ntkrnlpa.exe!ZwOpenMutant + 78 8060D9B8 3 Bytes [83, 4D, FC]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwQueryMutant + E 8060D9F6 111 Bytes [89, 7D, FC, 64, A1, 24, 01, ...]
    PAGE ntkrnlpa.exe!ZwQueryMutant + 7E 8060DA66 4 Bytes JMP 8060DB12 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwQueryMutant + 83 8060DA6B 13 Bytes [A1, 04, B0, 55, 80, 89, 45, ...] {MOV EAX, [0x8055b004]; MOV [EBP-0x38], EAX; PUSH EDI; LEA ECX, [EBP-0x24]; PUSH ECX}
    PAGE ntkrnlpa.exe!ZwQueryMutant + 91 8060DA79 22 Bytes [75, E2, 50, 6A, 01, FF, 75, ...]
    PAGE ntkrnlpa.exe!ZwQueryMutant + A8 8060DA90 11 Bytes [45, C0, 3B, C7, 7C, 59, 56, ...]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwReleaseMutant + 18 8060DB38 55 Bytes [45, CC, 8A, 80, 40, 01, 00, ...]
    PAGE ntkrnlpa.exe!ZwReleaseMutant + 50 8060DB70 6 Bytes [75, 08, E8, BF, 2F, FA]
    PAGE ntkrnlpa.exe!ZwReleaseMutant + 57 8060DB77 34 Bytes [89, 45, D4, 8B, 75, E4, 89, ...]
    PAGE ntkrnlpa.exe!ZwReleaseMutant + 7A 8060DB9A 14 Bytes CALL 80522B91 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwReleaseMutant + 8B 8060DBAB 24 Bytes [8B, 45, DC, 89, 07, C7, 45, ...]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwSetIntervalProfile + 1 8060DC6D 9 Bytes [FF, 55, 8B, EC, FF, 75, 0C, ...]
    PAGE ntkrnlpa.exe!ZwSetIntervalProfile + B 8060DC77 7 Bytes CALL 8053C7B2 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwSetIntervalProfile + 14 8060DC80 1 Byte [08]
    PAGE ntkrnlpa.exe!ZwCreateProfile + 1 8060DC89 1 Byte [44]
    PAGE ntkrnlpa.exe!ZwCreateProfile + 1 8060DC89 4 Bytes [44, 68, D0, CA]
    PAGE ntkrnlpa.exe!ZwCreateProfile + 9 8060DC91 2 Bytes CALL 80537F42 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwCreateProfile + D 8060DC95 1 Byte [DB]
    PAGE ntkrnlpa.exe!ZwCreateProfile + D 8060DC95 3 Bytes [DB, 89, 5D]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwStartProfile + 7 8060DEBD 16 Bytes CALL 80537F40 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwStartProfile + 18 8060DECE 7 Bytes [88, 45, E4, 33, FF, 57, 8D]
    PAGE ntkrnlpa.exe!ZwStartProfile + 20 8060DED6 20 Bytes [DC, 50, FF, 75, E4, FF, 35, ...]
    PAGE ntkrnlpa.exe!ZwStartProfile + 35 8060DEEB 16 Bytes [3B, C7, 0F, 8C, 5F, 01, 00, ...]
    PAGE ntkrnlpa.exe!ZwStartProfile + 46 8060DEFC 66 Bytes CALL 804F9BB0 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ...
    PAGE ntkrnlpa.exe!ZwStopProfile + 14 8060E074 17 Bytes [88, 45, FC, 33, DB, 53, 8D, ...]
    PAGE ntkrnlpa.exe!ZwStopProfile + 26 8060E086 16 Bytes [80, 6A, 01, FF, 75, 08, E8, ...] {SUB BYTE [EDX+0x1], 0xff; JNZ 0xe; CALL 0xfffffffffffa2ab0; CMP EAX, EBX; MOV ESI, [EBP+0x8]}
    PAGE ntkrnlpa.exe!ZwStopProfile + 37 8060E097 12 Bytes [75, FC, 7C, 63, 57, 53, 53, ...]
    PAGE ntkrnlpa.exe!ZwStopProfile + 44 8060E0A4 159 Bytes CALL 804F9BAE \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwQueryIntervalProfile + 3A 8060E144 50 Bytes [EB, 1D, 8B, 45, EC, 8B, 00, ...]
    PAGE ntkrnlpa.exe!ZwQueryIntervalProfile + 6D 8060E177 126 Bytes [06, 83, 4D, FC, FF, EB, 0B, ...]
    PAGE ntkrnlpa.exe!ZwQueryPerformanceCounter + 5E 8060E1F6 47 Bytes [C6, 01, 00, A8, 03, 74, 08, ...]
    PAGE ntkrnlpa.exe!ZwQueryPerformanceCounter + 8E 8060E226 30 Bytes [4D, D4, 89, 08, 8B, 4D, D8, ...]
    PAGE ntkrnlpa.exe!ZwQueryPerformanceCounter + AD 8060E245 5 Bytes [65, E8, 83, 4D, FC]
    PAGE ntkrnlpa.exe!ZwQueryPerformanceCounter + B3 8060E24B 126 Bytes [8B, 45, E4, EB, 26, 8D, 45, ...]
    PAGE ntkrnlpa.exe!ZwSystemDebugControl + 46 8060E2CA 14 Bytes JMP 8060E67E \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwSystemDebugControl + 55 8060E2D9 16 Bytes [5D, 0C, 74, 4F, 85, F6, 74, ...]
    PAGE ntkrnlpa.exe!ZwSystemDebugControl + 66 8060E2EA 12 Bytes [FF, 8D, 04, 33, 3B, C3, 72, ...]
    PAGE ntkrnlpa.exe!ZwSystemDebugControl + 73 8060E2F7 26 Bytes CALL 8060AB55 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwSystemDebugControl + 8E 8060E312 120 Bytes [8B, 4D, 1C, 85, C9, 74, 13, ...]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwOpenKeyedEvent + 11 8060E7D7 36 Bytes [00, 8A, 80, 40, 01, 00, 00, ...]
    PAGE ntkrnlpa.exe!ZwOpenKeyedEvent + 36 8060E7FC 106 Bytes [3B, D8, 72, 02, 89, 30, 89, ...]
    PAGE ntkrnlpa.exe!ZwOpenKeyedEvent + A1 8060E867 3 Bytes [8B, 45, D8] {MOV EAX, [EBP-0x28]}
    PAGE ntkrnlpa.exe!ZwOpenKeyedEvent + A5 8060E86B 3 Bytes CALL 80537F7C \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwOpenKeyedEvent + A9 8060E86F 42 Bytes [C2, 0C, 00, CC, CC, CC, CC, ...]
    PAGE ntkrnlpa.exe!ZwReleaseKeyedEvent + 22 8060E89A 5 Bytes [64, A1, 24, 01, 00]
    PAGE ntkrnlpa.exe!ZwReleaseKeyedEvent + 28 8060E8A0 125 Bytes [8B, F0, 8A, 86, 40, 01, 00, ...]
    PAGE ntkrnlpa.exe!ZwReleaseKeyedEvent + A6 8060E91E 24 Bytes [00, 00, 00, 8B, 4D, CC, BA, ...]
    PAGE ntkrnlpa.exe!ZwReleaseKeyedEvent + BF 8060E937 28 Bytes [FF, 8B, 07, EB, 3D, 8B, 45, ...]
    PAGE ntkrnlpa.exe!ZwReleaseKeyedEvent + DC 8060E954 5 Bytes [45, D0, E9, 9C, 01]
    PAGE ...
    PAGE ntkrnlpa.exe!ZwWaitForKeyedEvent + 6 8060EB0A 31 Bytes CALL 80537F3F \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!ZwWaitForKeyedEvent + 26 8060EB2A 7 Bytes [00, 8B, F0, 8A, 86, 40, 01]
    PAGE ntkrnlpa.exe!ZwWaitForKeyedEvent + 2E 8060EB32 93 Bytes [00, 88, 45, E0, 8B, 7D, 14, ...]
    PAGE ntkrnlpa.exe!ZwWaitForKeyedEvent + 8C 8060EB90 15 Bytes [8B, 46, 44, 89, 45, CC, 8B, ...]
    PAGE ntkrnlpa.exe!ZwWaitForKeyedEvent + 9C 8060EBA0 1 Byte [00]
    PAGE ...

  9. #9
    Join Date
    Jun 2008
    Posts
    45
    PAGE ntkrnlpa.exe!LsaFreeReturnBuffer + A 8060EDF7 61 Bytes [68, 00, 80, 00, 00, 8D, 45, ...]
    PAGE ntkrnlpa.exe!LsaRegisterLogonProcess + 22 8060EE36 27 Bytes [89, 85, 68, FF, FF, FF, 76, ...]
    PAGE ntkrnlpa.exe!LsaRegisterLogonProcess + 3E 8060EE52 76 Bytes CALL 8052AD99 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!LsaRegisterLogonProcess + 8B 8060EE9F 5 Bytes [FF, FF, E8, 28, 64]
    PAGE ntkrnlpa.exe!LsaRegisterLogonProcess + 91 8060EEA5 51 Bytes [FF, 3B, C3, 0F, 8C, E5, 00, ...]
    PAGE ntkrnlpa.exe!LsaRegisterLogonProcess + C5 8060EED9 20 Bytes [00, 00, 0F, B7, 06, 50, FF, ...]
    PAGE ...
    PAGE ntkrnlpa.exe!LsaLookupAuthenticationPackage + B 8060EFB2 6 Bytes [66, 83, A5, 58, FF, FF]
    PAGE ntkrnlpa.exe!LsaLookupAuthenticationPackage + 12 8060EFB9 14 Bytes [00, 56, 8B, 75, 0C, 57, 6A, ...]
    PAGE ntkrnlpa.exe!LsaLookupAuthenticationPackage + 21 8060EFC8 62 Bytes [FF, FF, F3, AB, 66, AB, 66, ...]
    PAGE ntkrnlpa.exe!LsaLookupAuthenticationPackage + 60 8060F007 9 Bytes [FF, FF, 00, 83, C4, 0C, 8D, ...]
    PAGE ntkrnlpa.exe!LsaLookupAuthenticationPackage + 6A 8060F011 4 Bytes [FF, FF, 50, 50]
    PAGE ...
    PAGE ntkrnlpa.exe!LsaLogonUser + 1B 8060F06A 4 Bytes [F3, AB, 66, AB] {REP STOSD ; STOSW }
    PAGE ntkrnlpa.exe!LsaLogonUser + 20 8060F06F 75 Bytes [45, 14, 89, 45, 84, 8B, 45, ...]
    PAGE ntkrnlpa.exe!LsaLogonUser + 6C 8060F0BB 8 Bytes [FF, FF, 50, 50, FF, 75, 08, ...]
    PAGE ntkrnlpa.exe!LsaLogonUser + 75 8060F0C4 25 Bytes [70, FF, FF, FF, 01, 00, 00, ...]
    PAGE ntkrnlpa.exe!LsaLogonUser + 8F 8060F0DE 16 Bytes [89, B5, 5C, FF, FF, FF, E8, ...] {MOV [EBP-0xa4], ESI; CALL 0xffffffffffeefc6a; CMP EAX, ESI; MOV ECX, [EBP+0x3c]}
    PAGE ...
    PAGE ntkrnlpa.exe!LsaCallAuthenticationPackage + 1 8060F145 34 Bytes [FF, 55, 8B, EC, 81, EC, A8, ...]
    PAGE ntkrnlpa.exe!LsaCallAuthenticationPackage + 24 8060F168 15 Bytes [00, 89, 85, 78, FF, FF, FF, ...]
    PAGE ntkrnlpa.exe!LsaCallAuthenticationPackage + 34 8060F178 25 Bytes [8B, 45, 14, 89, 45, 80, 8D, ...]
    PAGE ntkrnlpa.exe!LsaCallAuthenticationPackage + 4F 8060F193 64 Bytes [66, C7, 85, 58, FF, FF, FF, ...]
    PAGE ntkrnlpa.exe!LsaCallAuthenticationPackage + 90 8060F1D4 67 Bytes [85, 74, FF, FF, FF, C9, C2, ...]
    PAGE ntkrnlpa.exe!LsaDeregisterLogonProcess + 36 8060F218 39 Bytes [00, 00, 66, C7, 85, 58, FF, ...]
    PAGE ntkrnlpa.exe!LsaDeregisterLogonProcess + 5E 8060F240 39 Bytes [B5, 74, FF, FF, FF, 5F, 8B, ...]
    PAGE ntkrnlpa.exe!LsaDeregisterLogonProcess + 86 8060F268 10 Bytes CALL 806107A3 \WINDOWS\system32\ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
    PAGE ntkrnlpa.exe!LsaDeregisterLogonProcess + 91 8060F273 12 Bytes [3F, 68, 07, 90, 00, 00, 50, ...]
    PAGE ntkrnlpa.exe!LsaDeregisterLogonProcess + 9E 8060F280 51 Bytes [3B, C7, 74, 2F, 6A, 10, 8D, ...]
    PAGE ...
    ? spvv.sys The system cannot find the file specified. !
    .text USBPORT.SYS!DllUnload F696A8AC 5 Bytes JMP 84AE51D8
    .text aiwk15sp.SYS F66C7386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
    .text aiwk15sp.SYS F66C73AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
    .text aiwk15sp.SYS F66C73C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
    .text aiwk15sp.SYS F66C73C9 1 Byte [30]
    .text aiwk15sp.SYS F66C73C9 11 Bytes [30, 00, 00, 00, 5C, 02, 00, ...] {XOR [EAX], AL; ADD [EAX], AL; POP ESP; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
    .text ...

    ---- Kernel IAT/EAT - GMER 1.0.15 ----

    IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F73C0042] spvv.sys
    IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F73C013E] spvv.sys
    IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F73C00C0] spvv.sys
    IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F73C0800] spvv.sys
    IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F73C06D6] spvv.sys
    IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F73CFE9C] spvv.sys
    IAT \SystemRoot\System32\Drivers\aiwk15sp.SYS[HAL.dll!KfAcquireSpinLock] 18C4830E
    IAT \SystemRoot\System32\Drivers\aiwk15sp.SYS[HAL.dll!READ_PORT_UCHAR] 1C8D9E88
    IAT \SystemRoot\System32\Drivers\aiwk15sp.SYS[HAL.dll!KeGetCurrentIrql] 9E880000
    IAT \SystemRoot\System32\Drivers\aiwk15sp.SYS[HAL.dll!KfRaiseIrql] 00001CA9
    IAT \SystemRoot\System32\Drivers\aiwk15sp.SYS[HAL.dll!KfLowerIrql] 0E798366
    IAT \SystemRoot\System32\Drivers\aiwk15sp.SYS[HAL.dll!HalGetInterruptVector] 74AAB000
    IAT \SystemRoot\System32\Drivers\aiwk15sp.SYS[HAL.dll!HalTranslateBusAddress] 8186C636
    IAT \SystemRoot\System32\Drivers\aiwk15sp.SYS[HAL.dll!KeStallExecutionProcessor] 1A00001C
    IAT \SystemRoot\System32\Drivers\aiwk15sp.SYS[HAL.dll!KfReleaseSpinLock] 1C8386C6
    IAT \SystemRoot\System32\Drivers\aiwk15sp.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] C6020000
    IAT \SystemRoot\System32\Drivers\aiwk15sp.SYS[HAL.dll!READ_PORT_USHORT] 001C8E86
    IAT \SystemRoot\System32\Drivers\aiwk15sp.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 86C60200
    IAT \SystemRoot\System32\Drivers\aiwk15sp.SYS[HAL.dll!WRITE_PORT_UCHAR] 00001CAA
    IAT \SystemRoot\System32\Drivers\aiwk15sp.SYS[WMILIB.SYS!WmiSystemControl] 8800001C
    IAT \SystemRoot\System32\Drivers\aiwk15sp.SYS[WMILIB.SYS!WmiCompleteRequest] 001CB19E

    ---- User IAT/EAT - GMER 1.0.15 ----

  10. #10
    Join Date
    Jun 2008
    Posts
    45
    IAT C:\WINDOWS\system32\services.exe[764] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00390002
    IAT C:\WINDOWS\system32\services.exe[764] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00390000

    ---- Devices - GMER 1.0.15 ----

    Device \FileSystem\Ntfs \Ntfs 84D741F8

    AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
    AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

    Device \Driver\usbohci \Device\USBPDO-0 84AE41F8
    Device \Driver\usbohci \Device\USBPDO-1 84AE41F8
    Device \Driver\sptd \Device\68763590 spvv.sys
    Device \Driver\usbehci \Device\USBPDO-2 84ACD500

    AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

    Device \Driver\usbstor \Device\00000063 83FD11F8
    Device \Driver\Ftdisk \Device\HarddiskVolume1 84DE31F8
    Device \Driver\usbstor \Device\00000064 83FD11F8
    Device \Driver\Ftdisk \Device\HarddiskVolume2 84DE31F8
    Device \Driver\Cdrom \Device\CdRom0 84AB31F8
    Device \Driver\usbstor \Device\00000065 83FD11F8
    Device \Driver\Cdrom \Device\CdRom1 84AB31F8
    Device \Driver\atapi \Device\Ide\IdePort0 [F7339B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
    Device \Driver\atapi \Device\Ide\IdePort1 [F7339B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
    Device \Driver\atapi \Device\Ide\IdePort2 [F7339B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
    Device \Driver\atapi \Device\Ide\IdePort3 [F7339B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
    Device \Driver\atapi \Device\Ide\IdePort4 [F7339B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
    Device \Driver\atapi \Device\Ide\IdePort5 [F7339B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
    Device \Driver\atapi \Device\Ide\IdeDeviceP4T0L0-16 [F7339B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
    Device \Driver\atapi \Device\Ide\IdeDeviceP5T0L0-b [F7339B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
    Device \Driver\usbstor \Device\00000066 83FD11F8
    Device \Driver\usbstor \Device\00000067 83FD11F8
    Device \Driver\NetBT \Device\NetBt_Wins_Export 846AE500
    Device \Driver\PCI_PNP2340 \Device\0000003f spvv.sys
    Device \Driver\PCI_PNP2340 \Device\0000003f spvv.sys
    Device \Driver\NetBT \Device\NetbiosSmb 846AE500
    Device \Driver\NetBT \Device\NetBT_Tcpip_{6870E281-7EA2-4664-8B61-8FD563CFEC6B} 846AE500
    Device \Driver\NetBT \Device\NetBT_Tcpip_{C19388EF-AA1A-4097-A605-A76F2F986058} 846AE500

    AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
    AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

    Device \Driver\usbohci \Device\USBFDO-0 84AE41F8
    Device \Driver\usbohci \Device\USBFDO-1 84AE41F8
    Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 84720500
    Device \Driver\usbehci \Device\USBFDO-2 84ACD500
    Device \FileSystem\MRxSmb \Device\LanmanRedirector 84720500
    Device \Driver\Ftdisk \Device\FtControl 84DE31F8
    Device \Driver\aiwk15sp \Device\Scsi\aiwk15sp1 849B61F8
    Device \Driver\aiwk15sp \Device\Scsi\aiwk15sp1Port6Path0Target0Lun0 849B61F8
    Device \FileSystem\Cdfs \Cdfs 84C23500

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD8 0xBE 0x4D 0x67 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xE5 0x5A 0x2D 0x55 ...
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
    Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x83 0xFA 0x9C 0xC7 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD8 0xBE 0x4D 0x67 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xE5 0x5A 0x2D 0x55 ...
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x83 0xFA 0x9C 0xC7 ...

  11. #11
    Join Date
    Jun 2008
    Posts
    45
    Wow, thats a long log file, I didn't check the she all box, I promise.
    Sorry, if I made a mistake anyway.

  12. #12
    Join Date
    Jun 2008
    Posts
    45
    DDS (Ver_10-03-17.01) - NTFSx86
    Run by sip sea at 14:06:39.06 on Mon 23/08/2010
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.446.33 [GMT -7:00]

    AV: avast! antivirus 4.8.1229 [VPS 100822-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

    ============== Running Processes ===============

    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\Application Updater\ApplicationUpdater.exe
    C:\Program Files\BUFFALO\Client Manager3\bwsvc\bwsvc.exe
    C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
    C:\WINDOWS\system32\IoctlSvc.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\BUFFALO\Client Manager3\cm3_tray.exe
    C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\sip sea\My Documents\Downloads\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.ninemsn.com.au
    uSearch Page = hxxp://www.google.com
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uDefault_Page_URL = hxxp://www.ninemsn.com.au
    uInternet Connection Wizard,ShellNext = iexplore
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    mSearchAssistant = hxxp://www.google.com/ie
    uURLSearchHooks: {e312764e-7706-43f1-8dab-fcdd2b1e416d} - c:\program files\pdfforge toolbar\SearchSettings.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll
    BHO: pdfforge Toolbar: {b922d405-6d13-4a2b-ae89-08a030da4402} - c:\program files\pdfforge toolbar\ie\1.1.2\pdfforgeToolbarIE.dll
    BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
    BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: {e312764e-7706-43f1-8dab-fcdd2b1e416d} - c:\program files\pdfforge toolbar\SearchSettings.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
    TB: pdfforge Toolbar: {b922d405-6d13-4a2b-ae89-08a030da4402} - c:\program files\pdfforge toolbar\ie\1.1.2\pdfforgeToolbarIE.dll
    TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
    TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
    mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
    mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
    mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
    mRun: [RTHDCPL] RTHDCPL.EXE
    mRun: [Alcmtr] ALCMTR.EXE
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ncag}l~1.lnk - c:\program files\buffalo\client manager3\cm3_tray.exe
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    DPF: {A903E5AB-C67E-40FB-94F1-E1305982F6E0} - hxxp://www.ooxtv.com/livetv.ocx
    DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} - hxxp://www.crucial.com/controls/cpcScanner.cab
    DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {D1548A26-B8F6-4E86-AE74-E7062CCC2E2A} - hxxp://www.miniclip.com/igloader/igloader.CAB
    DPF: {D3A2FE00-8380-4803-B7C3-191A3EE8B542} - hxxp://live.ripcurl.com/player/player_ocx.jpeg
    DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://www.popcap.com/webgames/popcaploader_v10.cab
    Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
    Notify: AtiExtEvent - Ati2evxx.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\sipsea~1\applic~1\mozilla\firefox\profiles\d6lge2mu.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.cprogramming.com/
    FF - component: c:\documents and settings\sip sea\application data\mozilla\firefox\profiles\d6lge2mu.default\extensions\{0b457caa-602d-484a-8fe7-c1d894a011ba}\platform\winnt_x86-msvc\components\SSSLauncher.dll
    FF - component: c:\program files\pdfforge toolbar\ff\components\pdfforgeToolbarFF.dll
    FF - component: c:\program files\pdfforge toolbar\ssff\components\SearchSettingsFF.dll
    FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\joost plugin\npjoost.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");

    ============= SERVICES / DRIVERS ===============

    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-6-25 78416]
    R2 Application Updater;Application Updater;c:\program files\application updater\ApplicationUpdater.exe [2010-1-8 380928]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-6-25 20560]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2008-6-25 147640]
    R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2008-6-25 250040]
    R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2008-6-25 348344]
    R3 ucag300n;BUFFALO WLI-UC-AG300N Wireless LAN Driver;c:\windows\system32\drivers\ucag300n.sys [2008-6-10 580096]
    S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2008-7-10 47128]
    S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [2008-7-10 242712]
    S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\microsoft sql server\mssql10.sqlexpress\mssql\binn\SQLAGENT.EXE [2008-7-10 369688]

    =============== Created Last 30 ================

    2010-08-20 22:24:25 0 d-----w- c:\program files\WS_FTP
    2010-08-20 21:04:34 0 d-----w- c:\docume~1\sipsea~1\applic~1\Malwarebytes
    2010-08-20 21:03:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-08-20 21:03:37 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
    2010-08-20 21:03:35 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-08-20 21:03:34 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-08-20 19:19:44 0 d-----w- c:\documents and settings\sip sea\.ssh
    2010-08-20 19:19:41 99 ----a-w- c:\documents and settings\sip sea\.Xauthority
    2010-08-20 18:25:21 0 d-----w- c:\documents and settings\sip sea\.nx
    2010-08-20 17:56:58 0 d-----w- c:\program files\NX Client for Windows
    2010-08-20 16:37:52 0 d-----w- c:\program files\Spybot - Search & Destroy
    2010-08-20 16:37:52 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy

    ==================== Find3M ====================

    2010-06-30 12:31:35 149504 ----a-w- c:\windows\system32\schannel.dll
    2010-06-24 12:22:03 916480 ----a-w- c:\windows\system32\wininet.dll
    2010-06-23 13:44:04 1851904 ----a-w- c:\windows\system32\win32k.sys
    2010-06-17 14:03:00 80384 ----a-w- c:\windows\system32\iccvid.dll
    2010-06-14 07:41:45 1172480 ----a-w- c:\windows\system32\msxml3.dll
    2010-06-11 00:07:06 411368 ----a-w- c:\windows\system32\deployJava1.dll
    2008-09-11 17:34:45 32768 -csha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091120080912\index.dat

    ============= FINISH: 14:07:32.29 ===============

  13. #13
    Join Date
    Feb 2004
    Location
    Mandurah, Western Australia
    Posts
    10,157
    Download Malwarebytes' Anti-Malware (http://www.majorgeeks.com/Malwarebyt...are_d5756.html) to your desktop.

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure to checkmark the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Download the update from here if you have problems.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    Make sure that you restart the computer.

    Post new HJT log.

  14. #14
    Join Date
    Jun 2008
    Posts
    45
    Malwarebytes log

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4468

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    24/08/2010 4:16:40 PM
    mbam-log-2010-08-24 (16-16-40).txt

    Scan type: Full scan (C:\|H:\|)
    Objects scanned: 248211
    Time elapsed: 1 hour(s), 27 minute(s), 27 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 3
    Registry Values Infected: 1
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 4

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\CLSID\{b922d405-6d13-4a2b-ae89-08a030da4402} (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b922d405-6d13-4a2b-ae89-08a030da4402} (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b922d405-6d13-4a2b-ae89-08a030da4402} (Adware.WidgiToolbar) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{b922d405-6d13-4a2b-ae89-08a030da4402} (Adware.WidgiToolbar) -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Documents and Settings\sip sea\My Documents\Downloads\Mojo Presents In My Room beach boys\Mojo Presents In My Room - Mojo - back.jpg (Extension.Mismatch) -> Quarantined and deleted successfully.
    C:\Documents and Settings\sip sea\My Documents\Nero Ultra 8.3.6.0 + Keygen (halofubar)\Nero 8 Keygen.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Program Files\pdfforge Toolbar\WidgiHelper.exe (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
    C:\Program Files\pdfforge Toolbar\IE\1.1.2\pdfforgeToolbarIE.dll (Adware.WidgiToolbar) -> Quarantined and deleted successfully.

  15. #15
    Join Date
    Feb 2004
    Location
    Mandurah, Western Australia
    Posts
    10,157
    A word of advice. Keygen have trojans and whatever else packed inside them and they will get you every time.

    How is the PC now?

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •