Hi Myrti:
I hope this second run of the GMER tool fixes something... Here is the log result.
Regards,
JAIME
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-01-23 10:14:13
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST910021AS rev.4.06
Running: xsw2dm6m.exe; Driver: C:\DOCUME~1\IBM\LOCALS~1\Temp\pxldipog.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xAD4CFF3C]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xAD4CFFE4]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xAD4D0080]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xAD4D011C]
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xB8EE2000, 0x1C5D38, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2860] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002D0010
IAT C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3232] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002D0010
IAT C:\Documents and Settings\IBM\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5372] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002D0010
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
---- EOF - GMER 1.0.15 ----