Help me!!!!!!!!!!! After the GMER scan, the file i was talking about has infected like almost all my processes. I will paste the log here. PLease find a way to help.OK its a little long i will upload on megaupload.
GMER 1.0.15.15077 [gmer.exe] -
http://www.gmer.netRootkit scan 2009-08-19 19:29:47
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
Code 89F8A3A8 ZwEnumerateKey
Code 89F7E3D0 ZwFlushInstructionCache
Code \SystemRoot\System32\Drivers\sptd.sys IoCreateFile
Code 89F8EC96 IofCallDriver
Code 89FBBC96 IofCompleteRequest
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!IofCallDriver 804EF1A6 5 Bytes JMP 89F8EC9B
.text ntkrnlpa.exe!IofCompleteRequest 804EF236 5 Bytes JMP 89FBBC9B
.text ntkrnlpa.exe!KeReleaseInStackQueuedSpinLockFromDpcLevel + 862 8054131A 4 Bytes CALL A4E9E19A 00005340
PAGE ntkrnlpa.exe!IoCreateFile 8057691C 5 Bytes JMP B52995FB \SystemRoot\System32\Drivers\sptd.sys
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 805B6812 5 Bytes JMP 89F7E3D4
PAGE ntkrnlpa.exe!ZwEnumerateKey 80623FF0 5 Bytes JMP 89F8A3AC
? 00005340 The system cannot find the file specified. !
? C:\WINDOWS\system32\drivers\synsenddrv.sys The system cannot find the file specified. !
.text ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 003B000A
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Microsoft IntelliPoint\ipoint.exe[180] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0151000A
.text C:\WINDOWS\system32\svchost.exe[348] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0066000A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[392] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0137000A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[428] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 014C000A
.text ...
.text C:\Program Files\Internet Explorer\iexplore.exe[1328] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2151FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1328] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9521 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1328] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DCB69 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1328] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2ED3AC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1328] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E2543F6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1328] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E3C10 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1328] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E3B42 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1328] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E3BAD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1328] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E3A13 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1328] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E3A75 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1328] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E3C73 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1328] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E3AD7 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1328] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2ED408 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1328] ole32.dll!OleLoadFromStream 77529C85 5 Bytes JMP 3E3E3F78 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe[1448] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 016D000A
.text C:\WINDOWS\system32\Ati2evxx.exe[1512] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 003B000A
.text C:\WINDOWS\RTHDCPL.EXE[1944] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 003F000A
.text C:\WINDOWS\VMSnap3.EXE[1968] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 003A000A
.text C:\WINDOWS\Domino.EXE[1976] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 003A000A
.text ...
.text C:\Program Files\Internet Explorer\iexplore.exe[2780] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2151FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2780] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2ED3AC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2780] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E3C10 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2780] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E3B42 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2780] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E3BAD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2780] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E3A13 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2780] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E3A75 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2780] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E3C73 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2780] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E3AD7 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\MagicTune Premium\MagicTuneEngine.exe[3008] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 003A000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3200] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2151FD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3200] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9521 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3200] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DCB69 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3200] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2ED3AC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3200] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E2543F6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3200] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E3C10 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3200] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E3B42 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3200] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E3BAD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3200] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E3A13 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3200] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E3A75 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3200] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E3C73 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3200] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E3AD7 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3200] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2ED408 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3200] ole32.dll!OleLoadFromStream 77529C85 5 Bytes JMP 3E3E3F78 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\WINDOWS\system32\svchost.exe[3368] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0066000A
.text C:\WINDOWS\system32\wscntfy.exe[3900] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0086000A
.text C:\Documents and Settings\User\Desktop\gmer.exe[4012] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 003B000A
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Internet Explorer\iexplore.exe[1328] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1ACB] C:\Program Files\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[3200] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1ACB] C:\Program Files\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Tcp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
Device \Driver\bugkdpzgr \Device\{9DD6AFA1-8646-4720-836B-EDCB1085864A} 00005340
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Threads - GMER 1.0.15 ----
Thread System [4:1276] SSDT 0x8A015748 != 0x80504460
SSDT 00005340 System [4.1276] ZwDeleteValueKey [0xA4E9D5A4]
SSDT 00005340 System [4.1276] ZwEnumerateKey [0xA4E9D254]
SSDT 00005340 System [4.1276] ZwEnumerateValueKey [0xA4E9D360]
SSDT 00005340 System [4.1276] ZwOpenKey [0xA4E9D19C]
SSDT 00005340 System [4.1276] ZwOpenProcess [0xA4E9CF06]
SSDT 00005340 System [4.1276] ZwOpenThread [0xA4E9CF8E]
SSDT 00005340 System [4.1276] ZwProtectVirtualMemory [0xA4E9D768]
SSDT 00005340 System [4.1276] ZwQuerySystemInformation [0xA4E9CE00]
SSDT 00005340 System [4.1276] ZwReadVirtualMemory [0xA4E9D69C]
SSDT 00005340 System [4.1276] ZwSetContextThread [0xA4E9D139]
SSDT 00005340 System [4.1276] ZwSetValueKey [0xA4E9D4A0]
SSDT 00005340 System [4.1276] ZwSuspendThread [0xA4E9D0D6]
SSDT 00005340 System [4.1276] ZwTerminateThread [0xA4E9D073]
SSDT 00005340 System [4.1276] ZwWriteVirtualMemory [0xA4E9D702]
---- Threads - GMER 1.0.15 ----
Thread System [4:2624] SSDT 0x8A015748 != 0x80504460
SSDT 00005340 System [4.2624] ZwDeleteValueKey [0xA4E9D5A4]
SSDT 00005340 System [4.2624] ZwEnumerateKey [0xA4E9D254]
SSDT 00005340 System [4.2624] ZwEnumerateValueKey [0xA4E9D360]
SSDT 00005340 System [4.2624] ZwOpenKey [0xA4E9D19C]
SSDT 00005340 System [4.2624] ZwOpenProcess [0xA4E9CF06]
SSDT 00005340 System [4.2624] ZwOpenThread [0xA4E9CF8E]
SSDT 00005340 System [4.2624] ZwProtectVirtualMemory [0xA4E9D768]
SSDT 00005340 System [4.2624] ZwQuerySystemInformation [0xA4E9CE00]
SSDT 00005340 System [4.2624] ZwReadVirtualMemory [0xA4E9D69C]
SSDT 00005340 System [4.2624] ZwSetContextThread [0xA4E9D139]
SSDT 00005340 System [4.2624] ZwSetValueKey [0xA4E9D4A0]
SSDT 00005340 System [4.2624] ZwSuspendThread [0xA4E9D0D6]
SSDT 00005340 System [4.2624] ZwTerminateThread [0xA4E9D073]
SSDT 00005340 System [4.2624] ZwWriteVirtualMemory [0xA4E9D702]
---- Threads - GMER 1.0.15 ----
Thread System [4:1776] SSDT 0x8A015748 != 0x80504460
SSDT 00005340 System [4.1776] ZwDeleteValueKey [0xA4E9D5A4]
SSDT 00005340 System [4.1776] ZwEnumerateKey [0xA4E9D254]
SSDT 00005340 System [4.1776] ZwEnumerateValueKey [0xA4E9D360]
SSDT 00005340 System [4.1776] ZwOpenKey [0xA4E9D19C]
SSDT 00005340 System [4.1776] ZwOpenProcess [0xA4E9CF06]
SSDT 00005340 System [4.1776] ZwOpenThread [0xA4E9CF8E]
SSDT 00005340 System [4.1776] ZwProtectVirtualMemory [0xA4E9D768]
SSDT 00005340 System [4.1776] ZwQuerySystemInformation [0xA4E9CE00]
SSDT 00005340 System [4.1776] ZwReadVirtualMemory [0xA4E9D69C]
SSDT 00005340 System [4.1776] ZwSetContextThread [0xA4E9D139]
SSDT 00005340 System [4.1776] ZwSetValueKey [0xA4E9D4A0]
SSDT 00005340 System [4.1776] ZwSuspendThread [0xA4E9D0D6]
SSDT 00005340 System [4.1776] ZwTerminateThread [0xA4E9D073]
SSDT 00005340 System [4.1776] ZwWriteVirtualMemory [0xA4E9D702]
---- Processes - GMER 1.0.15 ----
Library \\?\globalroot\systemroot\system32\hjgruixeyqfuwk.dll (*** hidden *** ) @ C:\WINDOWS\system32\spoolsv.exe [148] 0x10000000
Library \\?\globalroot\systemroot\system32\hjgruixeyqfuwk.dll (*** hidden *** ) @ C:\Program Files\Microsoft IntelliPoint\ipoint.exe [180] 0x003F0000
---- Threads - GMER 1.0.15 ----
Thread ipoint.exe [180:1924] SSDT 0x8A015748 != 0x80504460
SSDT 00005340 ipoint.exe [180.1924] ZwDeleteValueKey [0xA4E9D5A4]
SSDT 00005340 ipoint.exe [180.1924] ZwEnumerateKey [0xA4E9D254]
SSDT 00005340 ipoint.exe [180.1924] ZwEnumerateValueKey [0xA4E9D360]
SSDT 00005340 ipoint.exe [180.1924] ZwOpenKey [0xA4E9D19C]
SSDT 00005340 ipoint.exe [180.1924] ZwOpenProcess [0xA4E9CF06]
SSDT 00005340 ipoint.exe [180.1924] ZwOpenThread [0xA4E9CF8E]
SSDT 00005340 ipoint.exe [180.1924] ZwProtectVirtualMemory [0xA4E9D768]
SSDT 00005340 ipoint.exe [180.1924] ZwQuerySystemInformation [0xA4E9CE00]
SSDT 00005340 ipoint.exe [180.1924] ZwReadVirtualMemory [0xA4E9D69C]
SSDT 00005340 ipoint.exe [180.1924] ZwSetContextThread [0xA4E9D139]
SSDT 00005340 ipoint.exe [180.1924] ZwSetValueKey [0xA4E9D4A0]
SSDT 00005340 ipoint.exe [180.1924] ZwSuspendThread [0xA4E9D0D6]
SSDT 00005340 ipoint.exe [180.1924] ZwTerminateThread [0xA4E9D073]
SSDT 00005340 ipoint.exe [180.1924] ZwWriteVirtualMemory [0xA4E9D702]
Library \\?\globalroot\systemroot\system32\hjgruixeyqfuwk.dll (*** hidden *** ) @ C:\Program Files\Avira\AntiVir Desktop\sched.exe [204] 0x10000000
Library \\?\globalroot\systemroot\system32\hjgruixeyqfuwk.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [348] 0x10000000
Library \\?\globalroot\systemroot\system32\hjgruixeyqfuwk.dll (*** hidden *** ) @ C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe [392] 0x10000000
---- Threads - GMER 1.0.15 ----
Thread CCC.exe [392:2108] SSDT 0x88AC4B90 != 0x80504460
SSDT 00005340 CCC.exe [392.2108] ZwDeleteValueKey [0xA4E9D5A4]
SSDT 00005340 CCC.exe [392.2108] ZwEnumerateKey [0xA4E9D254]
SSDT 00005340 CCC.exe [392.2108] ZwEnumerateValueKey [0xA4E9D360]
SSDT 00005340 CCC.exe [392.2108] ZwOpenKey [0xA4E9D19C]
SSDT 00005340 CCC.exe [392.2108] ZwOpenProcess [0xA4E9CF06]
SSDT 00005340 CCC.exe [392.2108] ZwOpenThread [0xA4E9CF8E]
SSDT 00005340 CCC.exe [392.2108] ZwProtectVirtualMemory [0xA4E9D768]
SSDT 00005340 CCC.exe [392.2108] ZwQuerySystemInformation [0xA4E9CE00]
SSDT 00005340 CCC.exe [392.2108] ZwReadVirtualMemory [0xA4E9D69C]
SSDT 00005340 CCC.exe [392.2108] ZwSetContextThread [0xA4E9D139]
SSDT 00005340 CCC.exe [392.2108] ZwSetValueKey [0xA4E9D4A0]
SSDT 00005340 CCC.exe [392.2108] ZwSuspendThread [0xA4E9D0D6]
SSDT 00005340 CCC.exe [392.2108] ZwTerminateThread [0xA4E9D073]
SSDT 00005340 CCC.exe [392.2108] ZwWriteVirtualMemory [0xA4E9D702]
Library \\?\globalroot\systemroot\system32\hjgruixeyqfuwk.dll (*** hidden *** ) @ C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [428] 0x00AA0000
Library \\?\globalroot\systemroot\system32\hjgruixeyqfuwk.dll (*** hidden *** ) @ C:\Program Files\iTunes\iTunesHelper.exe [452] 0x10000000
Library \\?\globalroot\systemroot\system32\hjgruixeyqfuwk.dll (*** hidden *** ) @ C:\Program Files\Windows Live\Messenger\msnmsgr.exe [460] 0x10000000
---- Threads - GMER 1.0.15 ----
Thread msnmsgr.exe [460:1536] SSDT 0x88AC4B90 != 0x80504460
SSDT 00005340 msnmsgr.exe [460.1536] ZwDeleteValueKey [0xA4E9D5A4]
SSDT 00005340 msnmsgr.exe [460.1536] ZwEnumerateKey [0xA4E9D254]
SSDT 00005340 msnmsgr.exe [460.1536] ZwEnumerateValueKey [0xA4E9D360]
SSDT 00005340 msnmsgr.exe [460.1536] ZwOpenKey [0xA4E9D19C]
SSDT 00005340 msnmsgr.exe [460.1536] ZwOpenProcess [0xA4E9CF06]
SSDT 00005340 msnmsgr.exe [460.1536] ZwOpenThread [0xA4E9CF8E]
SSDT 00005340 msnmsgr.exe [460.1536] ZwProtectVirtualMemory [0xA4E9D768]
SSDT 00005340 msnmsgr.exe [460.1536] ZwQuerySystemInformation [0xA4E9CE00]
SSDT 00005340 msnmsgr.exe [460.1536] ZwReadVirtualMemory [0xA4E9D69C]
SSDT 00005340 msnmsgr.exe [460.1536] ZwSetContextThread [0xA4E9D139]
SSDT 00005340 msnmsgr.exe [460.1536] ZwSetValueKey [0xA4E9D4A0]
SSDT 00005340 msnmsgr.exe [460.1536] ZwSuspendThread [0xA4E9D0D6]
SSDT 00005340 msnmsgr.exe [460.1536] ZwTerminateThread [0xA4E9D073]
SSDT 00005340 msnmsgr.exe [460.1536] ZwWriteVirtualMemory [0xA4E9D702]
Library \\?\globalroot\systemroot\system32\hjgruixeyqfuwk.dll (*** hidden *** ) @ C:\WINDOWS\system32\ctfmon.exe [472] 0x10000000
Library \\?\globalroot\systemroot\system32\hjgruixeyqfuwk.dll (*** hidden *** ) @ C:\Program Files\Messenger\msmsgs.exe [480] 0x10000000
Library \\?\globalroot\systemroot\system32\hjgruixeyqfuwk.dll (*** hidden *** ) @ C:\Documents and Settings\User\Desktop\Origami Instructions or stuff\3GP_Converter034\uTorrent.exe [492] 0x10000000
Library \\?\globalroot\systemroot\system32\hjgruixeyqfuwk.dll (*** hidden *** ) @ C:\Program Files\MagicTune Premium\GammaTray.exe [692] 0x10000000
Library \\?\globalroot\systemroot\system32\hjgruixeyqfuwk.dll (*** hidden *** ) @ C:\Program Files\iPod\bin\iPodService.exe [708] 0x10000000
Library \\?\globalroot\systemroot\system32\hjgruixeyqfuwk.dll (*** hidden *** ) @ C:\Program Files\MagicTune Premium\MagicTune.exe [736] 0x011A0000
---- Threads - GMER 1.0.15 ----
Thread csrss.exe [880:3584] SSDT 0x88AC4B90 != 0x80504460
SSDT 00005340 csrss.exe [880.3584] ZwDeleteValueKey [0xA4E9D5A4]
SSDT 00005340 csrss.exe [880.3584] ZwEnumerateKey [0xA4E9D254]
SSDT 00005340 csrss.exe [880.3584] ZwEnumerateValueKey [0xA4E9D360]
SSDT 00005340 csrss.exe [880.3584] ZwOpenKey [0xA4E9D19C]
SSDT 00005340 csrss.exe [880.3584] ZwOpenProcess [0xA4E9CF06]
SSDT 00005340 csrss.exe [880.3584] ZwOpenThread [0xA4E9CF8E]
SSDT 00005340 csrss.exe [880.3584] ZwProtectVirtualMemory [0xA4E9D768]
SSDT 00005340 csrss.exe [880.3584] ZwQuerySystemInformation [0xA4E9CE00]
SSDT 00005340 csrss.exe [880.3584] ZwReadVirtualMemory [0xA4E9D69C]
SSDT 00005340 csrss.exe [880.3584] ZwSetContextThread [0xA4E9D139]
SSDT 00005340 csrss.exe [880.3584] ZwSetValueKey [0xA4E9D4A0]
SSDT 00005340 csrss.exe [880.3584] ZwSuspendThread [0xA4E9D0D6]
SSDT 00005340 csrss.exe [880.3584] ZwTerminateThread [0xA4E9D073]
SSDT 00005340 csrss.exe [880.3584] ZwWriteVirtualMemory [0xA4E9D702]
Library \\?\globalroot\systemroot\system32\hjgruixeyqfuwk.dll (*** hidden *** ) @ C:\WINDOWS\system32\winlogon.exe [912] 0x10000000
---- Threads - GMER 1.0.15 ----
Thread winlogon.exe [912:2816] SSDT 0x8A015748 != 0x80504460
SSDT 00005340 winlogon.exe [912.2816] ZwDeleteValueKey [0xA4E9D5A4]
SSDT 00005340 winlogon.exe [912.2816] ZwEnumerateKey [0xA4E9D254]
SSDT 00005340 winlogon.exe [912.2816] ZwEnumerateValueKey [0xA4E9D360]
SSDT 00005340 winlogon.exe [912.2816] ZwOpenKey [0xA4E9D19C]
SSDT 00005340 winlogon.exe [912.2816] ZwOpenProcess [0xA4E9CF06]
SSDT 00005340 winlogon.exe [912.2816] ZwOpenThread [0xA4E9CF8E]
SSDT 00005340 winlogon.exe [912.2816] ZwProtectVirtualMemory [0xA4E9D768]
SSDT 00005340 winlogon.exe [912.2816] ZwQuerySystemInformation [0xA4E9CE00]
SSDT 00005340 winlogon.exe [912.2816] ZwReadVirtualMemory [0xA4E9D69C]
SSDT 00005340 winlogon.exe [912.2816] ZwSetContextThread [0xA4E9D139]
SSDT 00005340 winlogon.exe [912.2816] ZwSetValueKey [0xA4E9D4A0]
SSDT 00005340 winlogon.exe [912.2816] ZwSuspendThread [0xA4E9D0D6]
SSDT 00005340 winlogon.exe [912.2816] ZwTerminateThread [0xA4E9D073]
SSDT 00005340 winlogon.exe [912.2816] ZwWriteVirtualMemory [0xA4E9D702]
---- Threads - GMER 1.0.15 ----
Thread winlogon.exe [912:1912] SSDT 0x8A015748 != 0x80504460
SSDT 00005340 winlogon.exe [912.1912] ZwDeleteValueKey [0xA4E9D5A4]
SSDT 00005340 winlogon.exe [912.1912] ZwEnumerateKey [0xA4E9D254]
SSDT 00005340 winlogon.exe [912.1912] ZwEnumerateValueKey [0xA4E9D360]
SSDT 00005340 winlogon.exe [912.1912] ZwOpenKey [0xA4E9D19C]
SSDT 00005340 winlogon.exe [912.1912] ZwOpenProcess [0xA4E9CF06]
SSDT 00005340 winlogon.exe [912.1912] ZwOpenThread [0xA4E9CF8E]
SSDT 00005340 winlogon.exe [912.1912] ZwProtectVirtualMemory [0xA4E9D768]
SSDT 00005340 winlogon.exe [912.1912] ZwQuerySystemInformation [0xA4E9CE00]
SSDT 00005340 winlogon.exe [912.1912] ZwReadVirtualMemory [0xA4E9D69C]
SSDT 00005340 winlogon.exe [912.1912] ZwSetContextThread [0xA4E9D139]
SSDT 00005340 winlogon.exe [912.1912] ZwSetValueKey [0xA4E9D4A0]
SSDT 00005340 winlogon.exe [912.1912] ZwSuspendThread [0xA4E9D0D6]
SSDT 00005340 winlogon.exe [912.1912] ZwTerminateThread [0xA4E9D073]
SSDT 00005340 winlogon.exe [912.1912] ZwWriteVirtualMemory [0xA4E9D702]
Library \\?\globalroot\systemroot\system32\hjgruixeyqfuwk.dll (*** hidden *** ) @ C:\WINDOWS\system32\services.exe [960] 0x10000000
---- Threads - GMER 1.0.15 ----
Thread services.exe [960:1364] SSDT 0x8A015748 != 0x80504460
SSDT 00005340 services.exe [960.1364] ZwDeleteValueKey [0xA4E9D5A4]
SSDT 00005340 services.exe [960.1364] ZwEnumerateKey [0xA4E9D254]
SSDT 00005340 services.exe [960.1364] ZwEnumerateValueKey [0xA4E9D360]
SSDT 00005340 services.exe [960.1364] ZwOpenKey [0xA4E9D19C]
SSDT 00005340 services.exe [960.1364] ZwOpenProcess [0xA4E9CF06]
SSDT 00005340 services.exe [960.1364] ZwOpenThread [0xA4E9CF8E]
SSDT 00005340 services.exe [960.1364] ZwProtectVirtualMemory [0xA4E9D768]
SSDT 00005340 services.exe [960.1364] ZwQuerySystemInformation [0xA4E9CE00]
SSDT 00005340 services.exe [960.1364] ZwReadVirtualMemory [0xA4E9D69C]
SSDT 00005340 services.exe [960.1364] ZwSetContextThread [0xA4E9D139]
SSDT 00005340 services.exe [960.1364] ZwSetValueKey [0xA4E9D4A0]
SSDT 00005340 services.exe [960.1364] ZwSuspendThread [0xA4E9D0D6]
SSDT 00005340 services.exe [960.1364] ZwTerminateThread [0xA4E9D073]
SSDT 00005340 services.exe [960.1364] ZwWriteVirtualMemory [0xA4E9D702]
Library \\?\globalroot\systemroot\system32\hjgruixeyqfuwk.dll (*** hidden *** ) @ C:\WINDOWS\system32\lsass.exe [972] 0x10000000
---- Threads - GMER 1.0.15 ----
Thread lsass.exe [972:3360] SSDT 0x8A015748 != 0x80504460
SSDT 00005340 lsass.exe [972.3360] ZwDeleteValueKey [0xA4E9D5A4]
SSDT 00005340 lsass.exe [972.3360] ZwEnumerateKey [0xA4E9D254]
SSDT 00005340 lsass.exe [972.3360] ZwEnumerateValueKey [0xA4E9D360]
SSDT 00005340 lsass.exe [972.3360] ZwOpenKey [0xA4E9D19C]
SSDT 00005340