GMER 1.0.14.14205 - http://www.gmer.net
Rootkit scan 2008-03-26 18:16:09
Windows 5.1.2600
---- System - GMER 1.0.14 ----
SSDT ??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys ZwTerminateProcess [0xB4F28660]
Code 8765DB74 NlsAnsiCodePage
Code xybygsai.dat ObOpenObjectByName
---- Kernel code sections - GMER 1.0.14 ----
.text ntoskrnl.exe!KeInitializeInterrupt + B79 804D4F8E 1 Byte [ 06 ]
.text ntoskrnl.exe!KeI386Call16BitCStyleFunction + 510 804FCA28 4 Bytes [ 60, 86, F2, B4 ]
PAGE ntoskrnl.exe!ObOpenObjectByName 80572C92 6 Bytes JMP F87B9312 xybygsai.dat
? xybygsai.dat The system cannot find the file specified. !
? C:\WINDOWS\system32\drivers\kbd.sys The system cannot find the file specified. !
---- Devices - GMER 1.0.14 ----
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- Processes - GMER 1.0.14 ----
Process hidden process (*** hidden *** ) 14512
Process hidden process (*** hidden *** ) 15616
Process hidden process (*** hidden *** ) 17048
Process hidden process (*** hidden *** ) 18360
Process hidden process (*** hidden *** ) 18376
Process hidden process (*** hidden *** ) 27764
Process hidden process (*** hidden *** ) 29984
Process hidden process (*** hidden *** ) 51740
Process hidden process (*** hidden *** ) 58200
---- Services - GMER 1.0.14 ----
Service system32\drivers\xybygsai.dat (*** hidden *** ) [BOOT] zriclriv ← ROOTKIT !!!
---- Registry - GMER 1.0.14 ----
Reg HKLM\SOFTWARE\Classes\CLSID{1FD58F1C-E9DC-4C2F-954E-665BFCF15792}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID{1FD58F1C-E9DC-4C2F-954E-665BFCF15792}\InprocServer32@ C:\WINDOWS\System32\d3di.dll
Reg HKLM\SOFTWARE\Classes\CLSID{1FD58F1C-E9DC-4C2F-954E-665BFCF15792}\InprocServer32@ThreadingModel apartment
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComputerDescriptions@\xd7ŗł\xa4
---- EOF - GMER 1.0.14 ----