GMER 1.0.15.15530 -
http://www.gmer.netRootkit scan 2010-12-15 21:19:45
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 QUANTUM_FIREBALLP_LM20.5 rev.A35.0700
Running: iwz3qru5.exe; Driver: C:\DOCUME~1\x\IMPOST~1\Temp\kgayrkoc.sys
---- System - GMER 1.0.15 ----
SSDT F8CD3466 ZwCreateKey
SSDT F8CD345C ZwCreateThread
SSDT F8CD346B ZwDeleteKey
SSDT F8CD3475 ZwDeleteValueKey
SSDT F8CD347A ZwLoadKey
SSDT F8CD3448 ZwOpenProcess
SSDT F8CD344D ZwOpenThread
SSDT F8CD3484 ZwReplaceKey
SSDT F8CD347F ZwRestoreKey
SSDT F8CD3470 ZwSetValueKey
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF811C360, 0x204DFD, 0xE8000020]
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----