GMER 1.0.15.15281 - http://www.gmer.net Rootkit scan 2010-09-05 17:49:43 Windows 5.1.2600 Service Pack 2 Running: rr3l07ss.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\uxtdapow.sys ---- Kernel code sections - GMER 1.0.15 ---- .rsrc C:\WINDOWS\system32\drivers\ql1080.sys entry point in ".rsrc" section [0xF78C5814] ---- User code sections - GMER 1.0.15 ---- .text C:\WINDOWS\system32\svchost.exe[1344] USER32.dll!GetCursorPos 7E41BD76 5 Bytes JMP 00A9000A .text C:\WINDOWS\system32\svchost.exe[1344] ole32.dll!CoCreateInstance 774FFAC3 5 Bytes JMP 00A8000A .text C:\WINDOWS\Explorer.EXE[1660] kernel32.dll!CreateProcessInternalW 7C819527 5 Bytes JMP 00B5874A ---- Devices - GMER 1.0.15 ---- AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.) AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) Device -> \Driver\iaStor \Device\Harddisk0\DR0 861A5EC5 ---- Files - GMER 1.0.15 ---- File C:\WINDOWS\system32\drivers\ql1080.sys suspicious modification File C:\WINDOWS\system32\drivers\iaStor.sys suspicious modification ---- EOF - GMER 1.0.15 ----