This is the Gmer scan. Sometimes when I leave the computer for a while, it is at the login screen. When I log in, there is an error message that there was a windows shutdown.
Thank you,
Gary
GMER 1.0.15.15641 -
http://www.gmer.netRootkit scan 2012-04-07 22:42:18
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST3320620AS rev.3.ADG
Running: gmer.exe; Driver: C:\Users\Gary\AppData\Local\Temp\pxldqpob.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xA02D6F3C]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xA02D6FE4]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xA02D7080]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xA02D711C]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 3F1 83AC6B74 4 Bytes [3C, 6F, 2D, A0]
.text ntkrnlpa.exe!KeSetEvent + 621 83AC6DA4 8 Bytes [E4, 6F, 2D, A0, 80, 70, 2D, ...]
.text ntkrnlpa.exe!KeSetEvent + 681 83AC6E04 4 Bytes [1C, 71, 2D, A0]
.text ataport.SYS!AtaPortGetScatterGatherList + A3C 807A7A2C 1 Byte [CC] {INT 3 }
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Internet Explorer\iexplore.exe[580] kernel32.dll!CreateThread 761ACB2E 5 Bytes JMP 6CB17303 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!CreateDialogParamW 769172A2 5 Bytes JMP 6CCA66A0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!GetAsyncKeyState 7691863C 5 Bytes JMP 6CAFDD8D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!SetWindowsHookExW 769187AD 5 Bytes JMP 6CB52194 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!CallNextHookEx 76918E3B 5 Bytes JMP 6CB77BAF C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!UnhookWindowsHookEx 769198DB 5 Bytes JMP 6CB9EB00 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!EnableWindow 7691CD8B 5 Bytes JMP 6CB59A14 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!DefWindowProcA 7691DB88 7 Bytes JMP 6CB1952D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!CreateWindowExA 7691DC2A 5 Bytes JMP 6CB23363 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!CreateWindowExW 76921305 5 Bytes JMP 6CB7FF87 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!GetKeyState 76928CB1 5 Bytes JMP 6CAFDC67 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!DefWindowProcW 769303B4 7 Bytes JMP 6CB77C12 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!IsDialogMessageW 76930745 5 Bytes JMP 6CCA6E05 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!CreateDialogParamA 769317AA 5 Bytes JMP 6CCA6668 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!IsDialogMessage 76931847 2 Bytes JMP 6CCA6DDD C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!IsDialogMessage + 3 7693184A 2 Bytes [37, F6]
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!CreateDialogIndirectParamA 769326F1 5 Bytes JMP 6CCA66D8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!CreateDialogIndirectParamW 76939A62 5 Bytes JMP 6CCA6710 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!SetKeyboardState 76940987 5 Bytes JMP 6CCA76D1 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!DialogBoxParamW 769410B0 5 Bytes JMP 6CAB170B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!DialogBoxIndirectParamW 76942EF5 5 Bytes JMP 6CCA6336 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!SendInput 76942F75 5 Bytes JMP 6CCA7679 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!EndDialog 7694326E 5 Bytes JMP 6CCA70B4 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!SetCursorPos 76956FB2 5 Bytes JMP 6CCA7752 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!DialogBoxParamA 76958152 5 Bytes JMP 6CCA62D1 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!DialogBoxIndirectParamA 7695847D 5 Bytes JMP 6CCA639B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!MessageBoxIndirectA 7696D4D9 5 Bytes JMP 6CCA6258 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!MessageBoxIndirectW 7696D5D3 5 Bytes JMP 6CCA61DF C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!MessageBoxExA 7696D639 5 Bytes JMP 6CCA617B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!MessageBoxExW 7696D65D 5 Bytes JMP 6CCA6117 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] USER32.dll!keybd_event 7696D972 5 Bytes JMP 6CCA7636 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[580] SHELL32.dll!SHRestricted + D95 756C89A8 4 Bytes [CF, 01, 7E, 6B] {IRET ; ADD [ESI+0x6b], EDI}
.text C:\Program Files\Internet Explorer\iexplore.exe[580] SHELL32.dll!SHRestricted + D9D 756C89B0 8 Bytes [E0, 61, 7D, 6B, 79, F7, 7D, ...] {LOOPNZ 0x63; JGE 0x6f; JNS 0xfffffffffffffffd; JGE 0x73}
.text C:\Program Files\Internet Explorer\iexplore.exe[580] ole32.dll!OleLoadFromStream 767E1E80 5 Bytes JMP 6CCA6B0F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2368] USER32.dll!EnableWindow 7691CD8B 5 Bytes JMP 6CB59A14 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2368] USER32.dll!DialogBoxParamW 769410B0 5 Bytes JMP 6CAB170B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2368] USER32.dll!DialogBoxIndirectParamW 76942EF5 5 Bytes JMP 6CCA6336 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2368] USER32.dll!DialogBoxParamA 76958152 5 Bytes JMP 6CCA62D1 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2368] USER32.dll!DialogBoxIndirectParamA 7695847D 5 Bytes JMP 6CCA639B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2368] USER32.dll!MessageBoxIndirectA 7696D4D9 5 Bytes JMP 6CCA6258 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2368] USER32.dll!MessageBoxIndirectW 7696D5D3 5 Bytes JMP 6CCA61DF C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2368] USER32.dll!MessageBoxExA 7696D639 5 Bytes JMP 6CCA617B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2368] USER32.dll!MessageBoxExW 7696D65D 5 Bytes JMP 6CCA6117 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Real\realplayer\Update\realsched.exe[2796] kernel32.dll!SetUnhandledExceptionFilter 7618A8C5 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] kernel32.dll!CreateThread 761ACB2E 5 Bytes JMP 6CB17303 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!CreateDialogParamW 769172A2 5 Bytes JMP 6CCA66A0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!GetAsyncKeyState 7691863C 5 Bytes JMP 6CAFDD8D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!SetWindowsHookExW 769187AD 5 Bytes JMP 6CB52194 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!CallNextHookEx 76918E3B 5 Bytes JMP 6CB77BAF C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!UnhookWindowsHookEx 769198DB 5 Bytes JMP 6CB9EB00 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!EnableWindow 7691CD8B 5 Bytes JMP 6CB59A14 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!DefWindowProcA 7691DB88 7 Bytes JMP 6CB1952D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!CreateWindowExA 7691DC2A 5 Bytes JMP 6CB23363 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!CreateWindowExW 76921305 5 Bytes JMP 6CB7FF87 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!GetKeyState 76928CB1 5 Bytes JMP 6CAFDC67 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!DefWindowProcW 769303B4 7 Bytes JMP 6CB77C12 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!IsDialogMessageW 76930745 5 Bytes JMP 6CCA6E05 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!CreateDialogParamA 769317AA 5 Bytes JMP 6CCA6668 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!IsDialogMessage 76931847 2 Bytes JMP 6CCA6DDD C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!IsDialogMessage + 3 7693184A 2 Bytes [37, F6]
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!CreateDialogIndirectParamA 769326F1 5 Bytes JMP 6CCA66D8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!CreateDialogIndirectParamW 76939A62 5 Bytes JMP 6CCA6710 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!SetKeyboardState 76940987 5 Bytes JMP 6CCA76D1 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!DialogBoxParamW 769410B0 5 Bytes JMP 6CAB170B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!DialogBoxIndirectParamW 76942EF5 5 Bytes JMP 6CCA6336 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!SendInput 76942F75 5 Bytes JMP 6CCA7679 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!EndDialog 7694326E 5 Bytes JMP 6CCA70B4 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!SetCursorPos 76956FB2 5 Bytes JMP 6CCA7752 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!DialogBoxParamA 76958152 5 Bytes JMP 6CCA62D1 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!DialogBoxIndirectParamA 7695847D 5 Bytes JMP 6CCA639B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!MessageBoxIndirectA 7696D4D9 5 Bytes JMP 6CCA6258 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!MessageBoxIndirectW 7696D5D3 5 Bytes JMP 6CCA61DF C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!MessageBoxExA 7696D639 5 Bytes JMP 6CCA617B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!MessageBoxExW 7696D65D 5 Bytes JMP 6CCA6117 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] USER32.dll!keybd_event 7696D972 5 Bytes JMP 6CCA7636 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] SHELL32.dll!SHRestricted + D95 756C89A8 4 Bytes [CF, 01, 7E, 6B] {IRET ; ADD [ESI+0x6b], EDI}
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] SHELL32.dll!SHRestricted + D9D 756C89B0 8 Bytes [E0, 61, 7D, 6B, 79, F7, 7D, ...] {LOOPNZ 0x63; JGE 0x6f; JNS 0xfffffffffffffffd; JGE 0x73}
.text C:\Program Files\Internet Explorer\iexplore.exe[5604] ole32.dll!OleLoadFromStream 767E1E80 5 Bytes JMP 6CCA6B0F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
Device \Driver\BTHUSB \Device\0000008e bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\BTHUSB \Device\0000008c bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
---- Threads - GMER 1.0.15 ----
Thread System [4:432] 8795539F
Thread System [4:472] 882BA0F4
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0016cfd21a85
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0016cfd21a85@000761a880e4 0x6E 0xE2 0xEC 0xB3 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0016cfd21a85@000761a2fdfb 0x5D 0xDA 0xE4 0xA9 ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0016cfd21a85 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0016cfd21a85@000761a880e4 0xB1 0xBC 0x98 0x2D ...
---- EOF - GMER 1.0.15 ----