GMER 1.0.15.15077 [11bixzy1.exe] -
http://www.gmer.netRootkit scan 2009-08-21 07:07:21
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT spov.sys ZwCreateKey [0xB7EA80E0]
SSDT spov.sys ZwEnumerateKey [0xB7EC6CA2]
SSDT spov.sys ZwEnumerateValueKey [0xB7EC7030]
SSDT spov.sys ZwOpenKey [0xB7EA80C0]
SSDT spov.sys ZwQueryKey [0xB7EC7108]
SSDT spov.sys ZwQueryValueKey [0xB7EC6F88]
SSDT spov.sys ZwSetValueKey [0xB7EC719A]
INT 0x62 ? 8A79FBF8
INT 0x63 ? 8A5FAF00
INT 0x73 ? 8A79FBF8
INT 0x73 ? 8A79FBF8
INT 0x73 ? 8A79FBF8
INT 0x73 ? 8A79FBF8
INT 0x73 ? 8A5FAF00
INT 0x73 ? 8A79FBF8
INT 0x82 ? 8A79FBF8
INT 0x83 ? 8A5FAF00
INT 0x94 ? 8A5FAF00
INT 0xB4 ? 8A5FAF00
INT 0xB4 ? 8A5FAF00
INT 0xB4 ? 8A5FAF00
INT 0xB4 ? 8A5FAF00
---- Kernel code sections - GMER 1.0.15 ----
? spov.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload B6E988AC 5 Bytes JMP 8A5FA4E0
.text a07do4kt.SYS B6DD4386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text a07do4kt.SYS B6DD43AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text a07do4kt.SYS B6DD43C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text a07do4kt.SYS B6DD43C9 1 Byte [2E]
.text a07do4kt.SYS B6DD43C9 11 Bytes [2E, 00, 00, 00, 5C, 02, 00, ...] {ADD CS:[EAX], AL; ADD [EDX+EAX+0x0], BL; ADD [EAX], AL; ADD [EAX], AL}
.text ...
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B7EA9040] spov.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B7EA913C] spov.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B7EA90BE] spov.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B7EA97FC] spov.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B7EA96D2] spov.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [B7EB9048] spov.sys
IAT \SystemRoot\System32\Drivers\a07do4kt.SYS[HAL.dll!KfAcquireSpinLock] 4B8BDF8B
IAT \SystemRoot\System32\Drivers\a07do4kt.SYS[HAL.dll!READ_PORT_UCHAR] 8D3F0304
IAT \SystemRoot\System32\Drivers\a07do4kt.SYS[HAL.dll!KeGetCurrentIrql] CB033043
IAT \SystemRoot\System32\Drivers\a07do4kt.SYS[HAL.dll!KfRaiseIrql] 0673C13B
IAT \SystemRoot\System32\Drivers\a07do4kt.SYS[HAL.dll!KfLowerIrql] C13B0003
IAT \SystemRoot\System32\Drivers\a07do4kt.SYS[HAL.dll!HalGetInterruptVector] 8366FA72
IAT \SystemRoot\System32\Drivers\a07do4kt.SYS[HAL.dll!HalTranslateBusAddress] 75000E7B
IAT \SystemRoot\System32\Drivers\a07do4kt.SYS[HAL.dll!KeStallExecutionProcessor] 0B7D80E3
IAT \SystemRoot\System32\Drivers\a07do4kt.SYS[HAL.dll!KfReleaseSpinLock] 307B8D00
IAT \SystemRoot\System32\Drivers\a07do4kt.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 00AA840F
IAT \SystemRoot\System32\Drivers\a07do4kt.SYS[HAL.dll!READ_PORT_USHORT] 83660000
IAT \SystemRoot\System32\Drivers\a07do4kt.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 6A000E7A
IAT \SystemRoot\System32\Drivers\a07do4kt.SYS[HAL.dll!WRITE_PORT_UCHAR] C6647400
IAT \SystemRoot\System32\Drivers\a07do4kt.SYS[WMILIB.SYS!WmiSystemControl] 4F8B0200
IAT \SystemRoot\System32\Drivers\a07do4kt.SYS[WMILIB.SYS!WmiCompleteRequest] 968D5140
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8A79E1F8
Device \FileSystem\Fastfat \FatCdrom 89A5C500
Device \FileSystem\Udfs \UdfsCdRom 8A312500
Device \FileSystem\Udfs \UdfsDisk 8A312500
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)