Code:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-28 10:51:09
Windows 6.0.6002 Service Pack 2
Running: z4qce655.exe; Driver: C:\Users\MICHAE~1\AppData\Local\Temp\aftoqpoc.sys
---- System - GMER 1.0.15 ----
SSDT 9BCE27AC ZwCreateThread
SSDT 9BCE2798 ZwOpenProcess
SSDT 9BCE279D ZwOpenThread
SSDT 9BCE27A7 ZwTerminateProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 221 824C0964 4 Bytes [AC, 27, CE, 9B] {LODSB ; DAA ; INTO ; WAIT }
.text ntkrnlpa.exe!KeSetEvent + 3F1 824C0B34 4 Bytes [98, 27, CE, 9B] {CWDE ; DAA ; INTO ; WAIT }
.text ntkrnlpa.exe!KeSetEvent + 40D 824C0B50 4 Bytes [9D, 27, CE, 9B] {POPF ; DAA ; INTO ; WAIT }
.text ntkrnlpa.exe!KeSetEvent + 621 824C0D64 4 Bytes [A7, 27, CE, 9B] {CMPSD ; DAA ; INTO ; WAIT }
.text C:\Windows\system32\DRIVERS\tos_sps32.sys section is writeable [0x8B74F000, 0x4036D, 0xE8000020]
.dsrt C:\Windows\system32\DRIVERS\tos_sps32.sys unknown last section [0x8B798000, 0x510, 0x40000040]
.text C:\Windows\system32\drivers\acedrv01.sys section is writeable [0x90BA3000, 0x2E0F4, 0xE8000020]
.pklstb C:\Windows\system32\drivers\acedrv01.sys entry point in ".pklstb" section [0x90BE2000]
.relo2 C:\Windows\system32\drivers\acedrv01.sys unknown last section [0x90BFC000, 0x8E, 0x42000040]
.text C:\Windows\system32\drivers\acedrv02.sys section is writeable [0x9A208000, 0x303A4, 0xE8000020]
.pklstb C:\Windows\system32\drivers\acedrv02.sys entry point in ".pklstb" section [0x9A24A000]
.relo2 C:\Windows\system32\drivers\acedrv02.sys unknown last section [0x9A265000, 0x8E, 0x42000040]
.text C:\Windows\system32\drivers\acedrv03.sys section is writeable [0x9A267000, 0x303A4, 0xE8000020]
.pklstb C:\Windows\system32\drivers\acedrv03.sys entry point in ".pklstb" section [0x9A2A9000]
.relo2 C:\Windows\system32\drivers\acedrv03.sys unknown last section [0x9A2C4000, 0x8E, 0x42000040]
.text C:\Windows\system32\drivers\acedrv04.sys section is writeable [0x9A2C6000, 0x303A4, 0xE8000020]
.pklstb C:\Windows\system32\drivers\acedrv04.sys entry point in ".pklstb" section [0x9A308000]
.relo2 C:\Windows\system32\drivers\acedrv04.sys unknown last section [0x9A323000, 0x8E, 0x42000040]
.text C:\Windows\system32\drivers\acedrv05.sys section is writeable [0x9A325000, 0x30A4A, 0xE8000020]
.pklstb C:\Windows\system32\drivers\acedrv05.sys entry point in ".pklstb" section [0x9A367000]
.relo2 C:\Windows\system32\drivers\acedrv05.sys unknown last section [0x9A382000, 0x8E, 0x42000040]
.text C:\Windows\system32\drivers\acedrv06.sys section is writeable [0x9A384000, 0x319AA, 0xE8000020]
.pklstb C:\Windows\system32\drivers\acedrv06.sys entry point in ".pklstb" section [0x9A3C7000]
.relo2 C:\Windows\system32\drivers\acedrv06.sys unknown last section [0x9A3E2000, 0x8E, 0x42000040]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe[1648] ntdll.dll!DbgBreakPoint 77BD8B2E 1 Byte [90]
.text C:\Program Files\Internet Explorer\iexplore.exe[4528] USER32.dll!CreateWindowExW 774E1305 5 Bytes JMP 6C8AD9BC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4528] USER32.dll!DialogBoxParamW 775010B0 5 Bytes JMP 6C7D5689 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4528] USER32.dll!DialogBoxIndirectParamW 77502EF5 5 Bytes JMP 6C9A43F7 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4528] USER32.dll!DialogBoxParamA 77518152 5 Bytes JMP 6C9A4394 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4528] USER32.dll!DialogBoxIndirectParamA 7751847D 5 Bytes JMP 6C9A445A C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4528] USER32.dll!MessageBoxIndirectA 7752D4D9 5 Bytes JMP 6C9A4329 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4528] USER32.dll!MessageBoxIndirectW 7752D5D3 5 Bytes JMP 6C9A42BE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4528] USER32.dll!MessageBoxExA 7752D639 5 Bytes JMP 6C9A425C C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4528] USER32.dll!MessageBoxExW 7752D65D 5 Bytes JMP 6C9A41FA C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5204] USER32.dll!CreateWindowExW 774E1305 5 Bytes JMP 6C8AD9BC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5204] USER32.dll!DialogBoxParamW 775010B0 5 Bytes JMP 6C7D5689 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5204] USER32.dll!DialogBoxIndirectParamW 77502EF5 5 Bytes JMP 6C9A43F7 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5204] USER32.dll!DialogBoxParamA 77518152 5 Bytes JMP 6C9A4394 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5204] USER32.dll!DialogBoxIndirectParamA 7751847D 5 Bytes JMP 6C9A445A C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5204] USER32.dll!MessageBoxIndirectA 7752D4D9 5 Bytes JMP 6C9A4329 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5204] USER32.dll!MessageBoxIndirectW 7752D5D3 5 Bytes JMP 6C9A42BE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5204] USER32.dll!MessageBoxExA 7752D639 5 Bytes JMP 6C9A425C C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5204] USER32.dll!MessageBoxExW 7752D65D 5 Bytes JMP 6C9A41FA C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5940] USER32.dll!CreateWindowExW 774E1305 5 Bytes JMP 6C8AD9BC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5940] USER32.dll!DialogBoxParamW 775010B0 5 Bytes JMP 6C7D5689 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5940] USER32.dll!DialogBoxIndirectParamW 77502EF5 5 Bytes JMP 6C9A43F7 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5940] USER32.dll!DialogBoxParamA 77518152 5 Bytes JMP 6C9A4394 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5940] USER32.dll!DialogBoxIndirectParamA 7751847D 5 Bytes JMP 6C9A445A C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5940] USER32.dll!MessageBoxIndirectA 7752D4D9 5 Bytes JMP 6C9A4329 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5940] USER32.dll!MessageBoxIndirectW 7752D5D3 5 Bytes JMP 6C9A42BE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5940] USER32.dll!MessageBoxExA 7752D639 5 Bytes JMP 6C9A425C C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5940] USER32.dll!MessageBoxExW 7752D65D 5 Bytes JMP 6C9A41FA C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\Explorer.EXE[2976] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [73F27817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2976] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [73F7A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2976] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [73F2BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2976] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [73F1F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2976] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [73F275E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2976] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [73F1E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2976] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [73F58395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2976] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [73F2DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2976] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [73F1FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2976] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [73F1FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2976] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [73F171CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2976] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [73FACAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2976] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [73F4C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2976] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [73F1D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2976] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [73F16853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2976] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [73F1687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2976] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [73F22AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----