GMER 2.0.18327 - http://www.gmer.net Rootkit scan 2013-01-06 18:12:16 Windows 6.0.6002 Service Pack 2 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 TOSHIBA_ rev.LV01 298,09GB Running: qp6yvqmq.exe; Driver: C:\Users\BEATAH~1\AppData\Local\Temp\kfliipow.sys ---- Kernel code sections - GMER 2.0 ---- .text C:\Windows\system32\DRIVERS\tos_sps32.sys section is writeable [0x8A95C000, 0x4036D, 0xE8000020] .dsrt C:\Windows\system32\DRIVERS\tos_sps32.sys unknown last section [0x8A9A5000, 0x510, 0x40000040] .text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8EC04000, 0x1E73A0, 0xE8000020] ---- User code sections - GMER 2.0 ---- .text C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe[792] ntdll.dll!DbgBreakPoint 7772878E 1 Byte [90] ---- User IAT/EAT - GMER 2.0 ---- IAT C:\Windows\Explorer.EXE[2160] @ C:\Windows\system32\ole32.dll [msvcrt.dll!free] [64D3F3FB] C:\Windows\AppPatch\AcSpecfc.DLL (Windows Compatibility DLL/Microsoft Corporation) IAT C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe[3932] @ C:\Windows\system32\NETAPI32.dll [PSAPI.DLL!GetModuleBaseNameW] [75D9159E] C:\Windows\system32\PSAPI.DLL (Process Status Helper/Microsoft Corporation) ---- EOF - GMER 2.0 ----