Malwarebytes Anti-Malware (Trial) 1.60.1.1000
www.malwarebytes.org
Database version: v2012.02.01.07
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
IBM USER :: IBM-BB3D939A762 [administrator]
Protection: Disabled
2/2/2012 1:12:53 PM
mbam-log-2012-02-02 (13-12-53).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 201227
Time elapsed: 44 minute(s), 27 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
h
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-02-02 21:19:24
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 HTS424040M9AT00 rev.MA2IA75A
Running: divvmle6.exe; Driver: C:\DOCUME~1\IBMUSE~1\LOCALS~1\Temp\kfxdqkoc.sys
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] GDI32.dll!TextOutW 77F17EAC 5 Bytes JMP 00C9CE46
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] GDI32.dll!ExtTextOutW 77F18086 5 Bytes JMP 00C9D37A
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] GDI32.dll!TextOutA 77F1BA4F 5 Bytes JMP 00C9CD7A
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] GDI32.dll!ExtTextOutA 77F1D3FA 5 Bytes JMP 00C9D296
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] GDI32.dll!GetGlyphIndicesA 77F3DFE3 5 Bytes JMP 00C9D73A
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] GDI32.dll!GetGlyphIndicesW 77F52604 5 Bytes JMP 00C9D807
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 00C9C0A2
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] USER32.dll!DrawTextExW 7E42B415 5 Bytes JMP 00C9D1AF
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] USER32.dll!DrawTextW 7E42D7E2 5 Bytes JMP 00C9CFED
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] USER32.dll!SetClipboardData 7E430F9E 5 Bytes JMP 00C9CC63
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] USER32.dll!DrawTextA 7E43C702 5 Bytes JMP 00C9CF12
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] USER32.dll!DrawTextExA 7E43C739 5 Bytes JMP 00C9D0C8
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] WININET.dll!InternetCrackUrlW 3D9340C0 5 Bytes JMP 00C9DC16
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] WININET.dll!InternetCrackUrlA 3D954928 5 Bytes JMP 00C9DACD
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 00C9BBFA
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00C9CBBC
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00C9C731
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00C9C958
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] WS2_32.dll!gethostbyname 71AB5355 5 Bytes JMP 00C9BB39
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00C9C7D6
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00C9C884
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] WS2_32.dll!WSAAsyncGetHostByName 71ABE99D 5 Bytes JMP 00C9BFC3
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2504] WS2_32.dll!WSAGetOverlappedResult 71AC0D1B 5 Bytes JMP 00C9CA9C
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4076] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Google\Chrome\Application\chrome.exe[4076] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002D0010
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Fastfat \Fat AE9FBD20
Device \FileSystem\Fastfat \Fat AEA028C1
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
---- EOF - GMER 1.0.15 ----