GMER 1.0.15.14939 -
http://www.gmer.net
Rootkit scan 2009-03-17 16

01
Windows 5.1.2600 Service Pack 3
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\ZoneLabs\vsmon.exe[520] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 00FF6EB0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\WINDOWS\system32\ZoneLabs\vsmon.exe[520] ADVAPI32.dll!CryptGenKey 77E117D9 5 Bytes JMP 00FF5010 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\WINDOWS\system32\ZoneLabs\vsmon.exe[520] Crypt32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 00FF5020 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\WINDOWS\system32\ZoneLabs\vsmon.exe[520] WININET.dll!InternetCloseHandle 7805DA59 5 Bytes JMP 00FF5540 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\WINDOWS\system32\ZoneLabs\vsmon.exe[520] WININET.dll!InternetCloseHandle + 156A 7805EFC3 5 Bytes JMP 00FF68A0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\WINDOWS\system32\ZoneLabs\vsmon.exe[520] WININET.dll!HttpQueryInfoA 78060C6D 5 Bytes JMP 00FF6000 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\WINDOWS\system32\ZoneLabs\vsmon.exe[520] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 00FF2FF0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\WINDOWS\system32\ZoneLabs\vsmon.exe[520] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 00FF2FC0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\WINDOWS\system32\ZoneLabs\vsmon.exe[520] WININET.dll!InternetReadFileExW 78082AAA 5 Bytes JMP 00FF3020 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\WINDOWS\system32\ZoneLabs\vsmon.exe[520] WININET.dll!InternetReadFileExA 78082AE2 5 Bytes JMP 00FF3050 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\WINDOWS\system32\ZoneLabs\vsmon.exe[520] WININET.dll!InternetGetCookieExA 7808386E 5 Bytes JMP 00FF29F0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\WINDOWS\system32\ZoneLabs\vsmon.exe[520] WININET.dll!InternetSetCookieExW 78083AE5 5 Bytes JMP 00FF2790 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[1352] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 10006EB0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[1352] ADVAPI32.dll!CryptGenKey 77E117D9 5 Bytes JMP 10005010 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[1352] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 10005020 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[1352] WININET.dll!InternetCloseHandle 7805DA59 5 Bytes JMP 10005540 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[1352] WININET.dll!InternetCloseHandle + 156A 7805EFC3 5 Bytes JMP 100068A0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[1352] WININET.dll!HttpQueryInfoA 78060C6D 5 Bytes JMP 10006000 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[1352] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 10002FF0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[1352] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 10002FC0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[1352] WININET.dll!InternetReadFileExW 78082AAA 5 Bytes JMP 10003020 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[1352] WININET.dll!InternetReadFileExA 78082AE2 5 Bytes JMP 10003050 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[1352] WININET.dll!InternetGetCookieExA 7808386E 5 Bytes JMP 100029F0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\PROGRA~1\AVG\AVG8\avgemc.exe[1352] WININET.dll!InternetSetCookieExW 78083AE5 5 Bytes JMP 10002790 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe[1548] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 10006EB0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe[1548] ADVAPI32.dll!CryptGenKey 77E117D9 5 Bytes JMP 10005010 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe[1548] Crypt32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 10005020 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe[1548] WININET.dll!InternetCloseHandle 7805DA59 5 Bytes JMP 10005540 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe[1548] WININET.dll!InternetCloseHandle + 156A 7805EFC3 5 Bytes JMP 100068A0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe[1548] WININET.dll!HttpQueryInfoA 78060C6D 5 Bytes JMP 10006000 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe[1548] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 10002FF0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe[1548] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 10002FC0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe[1548] WININET.dll!InternetReadFileExW 78082AAA 5 Bytes JMP 10003020 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe[1548] WININET.dll!InternetReadFileExA 78082AE2 5 Bytes JMP 10003050 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe[1548] WININET.dll!InternetGetCookieExA 7808386E 5 Bytes JMP 100029F0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe[1548] WININET.dll!InternetSetCookieExW 78083AE5 5 Bytes JMP 10002790 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\WINDOWS\system32\SearchIndexer.exe[1552] kernel32.dll!WriteFile 7C810E17 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\Program Files\Webroot\Washer\WasherSvc.exe[1744] kernel32.dll!CreateThread + 1A 7C8106E1 4 Bytes CALL 0008ED99 C:\Program Files\Webroot\Washer\WasherSvc.exe (Window Washer Engine/Webroot Software, Inc.)
.text C:\Program Files\IncrediMail\bin\ImApp.exe[3932] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 01DB6EB0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\IncrediMail\bin\ImApp.exe[3932] ADVAPI32.dll!CryptGenKey 77E117D9 5 Bytes JMP 01DB5010 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\IncrediMail\bin\ImApp.exe[3932] WININET.dll!InternetCloseHandle 7805DA59 5 Bytes JMP 01DB5540 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\IncrediMail\bin\ImApp.exe[3932] WININET.dll!InternetCloseHandle + 156A 7805EFC3 5 Bytes JMP 01DB68A0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\IncrediMail\bin\ImApp.exe[3932] WININET.dll!HttpQueryInfoA 78060C6D 5 Bytes JMP 01DB6000 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\IncrediMail\bin\ImApp.exe[3932] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 01DB2FF0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\IncrediMail\bin\ImApp.exe[3932] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 01DB2FC0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\IncrediMail\bin\ImApp.exe[3932] WININET.dll!InternetReadFileExW 78082AAA 5 Bytes JMP 01DB3020 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\IncrediMail\bin\ImApp.exe[3932] WININET.dll!InternetReadFileExA 78082AE2 5 Bytes JMP 01DB3050 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\IncrediMail\bin\ImApp.exe[3932] WININET.dll!InternetGetCookieExA 7808386E 5 Bytes JMP 01DB29F0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\IncrediMail\bin\ImApp.exe[3932] WININET.dll!InternetSetCookieExW 78083AE5 5 Bytes JMP 01DB2790 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\IncrediMail\bin\ImApp.exe[3932] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 01DB5020 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4076] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 026C6EB0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4076] ADVAPI32.dll!CryptGenKey 77E117D9 5 Bytes JMP 026C5010 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4076] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 42F0F341 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4076] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 430A187F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4076] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 430A1800 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4076] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 430A1844 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4076] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 430A178C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4076] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 430A17C6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4076] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 430A18BA C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4076] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 42F316F6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4076] WININET.dll!InternetCloseHandle 7805DA59 5 Bytes JMP 026C5540 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4076] WININET.dll!InternetCloseHandle + 156A 7805EFC3 5 Bytes JMP 026C68A0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4076] WININET.dll!HttpQueryInfoA 78060C6D 5 Bytes JMP 026C6000 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4076] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 026C2FF0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4076] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 026C2FC0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4076] WININET.dll!InternetReadFileExW 78082AAA 5 Bytes JMP 026C3020 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4076] WININET.dll!InternetReadFileExA 78082AE2 5 Bytes JMP 026C3050 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4076] WININET.dll!InternetGetCookieExA 7808386E 5 Bytes JMP 026C29F0 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4076] WININET.dll!InternetSetCookieExW 78083AE5 5 Bytes JMP 026C2790 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[4076] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 026C5020 C:\WINDOWS\system32\lsprly.dll (LSP Dynamic Link Library/Adobe)
---- Devices - GMER 1.0.15 ----
Device \Driver\Tcpip \Device\Ip vsdatant.sys (TrueVector Device Driver/Zone Labs Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Ip ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
Device \Driver\Tcpip \Device\Tcp vsdatant.sys (TrueVector Device Driver/Zone Labs Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
Device \Driver\Tcpip \Device\Udp vsdatant.sys (TrueVector Device Driver/Zone Labs Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
Device \Driver\Tcpip \Device\RawIp vsdatant.sys (TrueVector Device Driver/Zone Labs Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
Device \Driver\Tcpip \Device\IPMULTICAST vsdatant.sys (TrueVector Device Driver/Zone Labs Inc.)
Device \Driver\AFD \Device\Afd vsdatant.sys (TrueVector Device Driver/Zone Labs Inc.)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
---- EOF - GMER 1.0.15 ----
hope this helps,thanks for your time