GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2011-10-23 07:52:03
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 SAMSUNG_HM060HI rev.YD100-15
Running: kc4dvz07.exe; Driver: C:\DOCUME~1\mroper\LOCALS~1\Temp\uftoypoc.sys
---- System - GMER 1.0.15 ----
SSDT 86319A78 ZwAlertResumeThread
SSDT 865689A0 ZwAlertThread
SSDT 862D2B38 ZwAllocateVirtualMemory
SSDT 862A2C50 ZwConnectPort
SSDT 861E0E50 ZwCreateMutant
SSDT 861DDE30 ZwCreateThread
SSDT 8652F0A8 ZwFreeVirtualMemory
SSDT 86259C50 ZwImpersonateAnonymousToken
SSDT 86408EF8 ZwImpersonateThread
SSDT 86EBD8D8 ZwMapViewOfSection
SSDT 865320C8 ZwOpenEvent
SSDT 86337AF0 ZwOpenProcessToken
SSDT 86266DB0 ZwOpenThreadToken
SSDT \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation) ZwProtectVirtualMemory [0xF66BE8B0]
SSDT 8600B800 ZwResumeThread
SSDT 86EB6618 ZwSetContextThread
SSDT 86352C68 ZwSetInformationProcess
SSDT 862B1C40 ZwSetInformationThread
SSDT 861E3C50 ZwSuspendProcess
SSDT 8626CA78 ZwSuspendThread
SSDT 863D8C80 ZwTerminateProcess
SSDT 862F6A78 ZwTerminateThread
SSDT 86EDA1F0 ZwUnmapViewOfSection
SSDT 862BAC38 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2E08 805046A4 4 Bytes [B0, E8, 6B, F6]
page C:\WINDOWS\System32\Drivers\oz776.sys entry point in "page" section [0xF66B3E34]
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip tcpipBM.SYS (Bytemobile Kernel Network Provider/Bytemobile, Inc.)
Device \Driver\tcpipBM \Device\bmktcp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp tcpipBM.SYS (Bytemobile Kernel Network Provider/Bytemobile, Inc.)
Device \Driver\tcpipBM \Device\bmksa wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
Device \Driver\tcpipBM \Device\bmknet wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp wpsdrvnt.sys (Symantec CMC Firewall WPS/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp tcpipBM.SYS (Bytemobile Kernel Network Provider/Bytemobile, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
---- EOF - GMER 1.0.15 ----