GMER 1.0.15.15281 - http://www.gmer.net Rootkit scan 2010-07-26 07:39:00 Windows 5.1.2600 Service Pack 3 Running: qssfoi01.exe; Driver: D:\DOCUME~1\JAMES~1.JAM\LOCALS~1\Temp\awlyqaow.sys ---- System - GMER 1.0.15 ---- SSDT 8A712210 ZwAllocateVirtualMemory SSDT 8A75CA58 ZwCreateKey SSDT 8A75B168 ZwCreateProcess SSDT 8A75D120 ZwCreateProcessEx SSDT 8A758020 ZwCreateThread SSDT 8A7011E8 ZwDeleteKey SSDT 8A67A318 ZwDeleteValueKey SSDT 8A712288 ZwQueueApcThread SSDT 8A74EA08 ZwReadVirtualMemory SSDT 8A6D0180 ZwRenameKey SSDT 8A695FA8 ZwSetContextThread SSDT 8A74E070 ZwSetInformationKey SSDT 8A695A70 ZwSetInformationProcess SSDT 8A757238 ZwSetInformationThread SSDT 8A75D398 ZwSetValueKey SSDT 8A6EECB0 ZwSuspendProcess SSDT 8A695F30 ZwSuspendThread SSDT 8A67A098 ZwTerminateProcess SSDT 8A764748 ZwTerminateThread SSDT 8A712198 ZwWriteVirtualMemory ---- Kernel code sections - GMER 1.0.15 ---- .text ntkrnlpa.exe!ZwCallbackReturn + 2468 80501CA0 4 Bytes CALL 5ADA8CB6 .text ntkrnlpa.exe!ZwCallbackReturn + 2654 80501E8C 4 Bytes JMP 8A608A74 .text D:\WINDOWS\System32\DRIVERS\nv4_mini.sys section is writeable [0xB66E0360, 0x3D46A5, 0xE8000020] ---- User code sections - GMER 1.0.15 ---- .text D:\Program Files\a-squared Free\a2service.exe[144] kernel32.dll!CreateThread + 1A 7C8106F1 4 Bytes CALL 00454E05 D:\Program Files\a-squared Free\a2service.exe (a-squared Service/Emsi Software GmbH) .text D:\WINDOWS\Explorer.EXE[776] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B7000A .text D:\WINDOWS\Explorer.EXE[776] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00BD000A .text D:\WINDOWS\Explorer.EXE[776] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B6000C .text D:\WINDOWS\System32\svchost.exe[1324] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0092000A .text D:\WINDOWS\System32\svchost.exe[1324] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0093000A .text D:\WINDOWS\System32\svchost.exe[1324] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0091000C .text D:\WINDOWS\System32\svchost.exe[1324] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 0088000A .text D:\WINDOWS\System32\svchost.exe[1324] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00D8000A .text D:\Program Files\Mozilla Firefox\firefox.exe[3712] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0132000A .text D:\Program Files\Mozilla Firefox\firefox.exe[3712] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0133000A .text D:\Program Files\Mozilla Firefox\firefox.exe[3712] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0131000C .text D:\Program Files\Mozilla Firefox\plugin-container.exe[3864] USER32.dll!TrackPopupMenu 7E46531E 5 Bytes JMP 1044721D D:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) ---- Devices - GMER 1.0.15 ---- AttachedDevice \FileSystem\Ntfs \Ntfs ssfs0bbc.sys (Spy Sweeper FileSystem Filter Driver/Webroot Software, Inc. (www.webroot.com)) Device \Driver\Tcpip \Device\Ip 8A374120 Device \Driver\Tcpip \Device\Ip 8A557CC0 Device \Driver\Tcpip \Device\Ip 8A6D9628 Device \Driver\Tcpip \Device\Ip 89492340 Device \Driver\Tcpip \Device\Ip 895E5630 Device \Driver\Tcpip \Device\Ip 8A2C7608 Device \Driver\Tcpip \Device\Tcp 8A374120 Device \Driver\Tcpip \Device\Tcp 8A557CC0 Device \Driver\Tcpip \Device\Tcp 8A6D9628 Device \Driver\Tcpip \Device\Tcp 89492340 Device \Driver\Tcpip \Device\Tcp 895E5630 Device \Driver\Tcpip \Device\Tcp 8A2C7608 Device \Driver\Tcpip \Device\Udp 8A374120 Device \Driver\Tcpip \Device\Udp 8A557CC0 Device \Driver\Tcpip \Device\Udp 8A6D9628 Device \Driver\Tcpip \Device\Udp 89492340 Device \Driver\Tcpip \Device\Udp 895E5630 Device \Driver\Tcpip \Device\Udp 8A2C7608 Device \Driver\Tcpip \Device\RawIp 8A374120 Device \Driver\Tcpip \Device\RawIp 8A557CC0 Device \Driver\Tcpip \Device\RawIp 8A6D9628 Device \Driver\Tcpip \Device\RawIp 89492340 Device \Driver\Tcpip \Device\RawIp 895E5630 Device \Driver\Tcpip \Device\RawIp 8A2C7608 Device \Driver\Tcpip \Device\IPMULTICAST 8A374120 Device \Driver\Tcpip \Device\IPMULTICAST 8A557CC0 Device \Driver\Tcpip \Device\IPMULTICAST 8A6D9628 Device \Driver\Tcpip \Device\IPMULTICAST 89492340 Device \Driver\Tcpip \Device\IPMULTICAST 895E5630 Device \Driver\Tcpip \Device\IPMULTICAST 8A2C7608 AttachedDevice \FileSystem\Fastfat \Fat ssfs0bbc.sys (Spy Sweeper FileSystem Filter Driver/Webroot Software, Inc. (www.webroot.com)) ---- EOF - GMER 1.0.15 ----