GMER 1.0.15.15627 - http://www.gmer.net Rootkit quick scan 2011-05-13 22:14:03 Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST98823AS rev.8.03 Running: gmer.exe; Driver: C:\DOCUME~1\Paulina\USTAWI~1\Temp\kftcypod.sys ---- Disk sectors - GMER 1.0.15 ---- Disk \Device\Harddisk0\DR0 MBR read error Disk \Device\Harddisk0\DR0 MBR BIOS signature not found 0 ---- System - GMER 1.0.15 ---- SSDT spyv.sys ZwEnumerateKey [0xF7436DA4] SSDT spyv.sys ZwEnumerateValueKey [0xF7437132] ---- Devices - GMER 1.0.15 ---- Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 8666953B Device \Driver\atapi \Device\Ide\IdePort0 [F7371B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP0T0L0-3 8666953B Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F7371B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 8666953B Device \Driver\atapi \Device\Ide\IdePort1 [F7371B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP1T0L0-e 8666953B Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [F7371B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\ab0i6bve \Device\Scsi\ab0i6bve1Port2Path0Target0Lun0 863721F8 Device \Driver\ab0i6bve \Device\Scsi\ab0i6bve1 863721F8 Device \FileSystem\Ntfs \Ntfs 867D61F8 AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.) AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.) ---- EOF - GMER 1.0.15 ----