I will tell you asap (saturday) abot details, menawhile here is the gmer log, running Gmer
I forgot to untick some flags on the right pane of gmer window, so all checkboxes in the left column were ticked,
it took 30 mins to compile alla the infos, scrolling thru the tabs I saw a lot of freshly generated info, but saving the log it seems to be concise... strange, hope it is sufficient:
---
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2011-12-29 22:44:52
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST3200826AS rev.3.03
Running: gmer.exe; Driver: C:\DOCUME~1\HP_PRO~1\IMPOST~1\Temp\kfliaaod.sys
---- System - GMER 1.0.15 ----
SSDT 86B13610 ZwAlertResumeThread
SSDT 86B14DF0 ZwAlertThread
SSDT 86B16380 ZwAllocateVirtualMemory
SSDT 86BB45D8 ZwAssignProcessToJobObject
SSDT 86BD9218 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xF3DDB710]
SSDT 86681748 ZwCreateMutant
SSDT 86A10D30 ZwCreateSymbolicLinkObject
SSDT 86B1D2F8 ZwCreateThread
SSDT 86C8F278 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xF3DDB990]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xF3DDBEF0]
SSDT 86B2CD68 ZwDuplicateObject
SSDT 86B435E0 ZwFreeVirtualMemory
SSDT 86B115D0 ZwImpersonateAnonymousToken
SSDT 86B13478 ZwImpersonateThread
SSDT 86E94158 ZwLoadDriver
SSDT 86B1CD08 ZwMapViewOfSection
SSDT 86B10FD0 ZwOpenEvent
SSDT 869FB248 ZwOpenProcess
SSDT 86B365F8 ZwOpenProcessToken
SSDT 86CBD498 ZwOpenSection
SSDT 86B277D0 ZwOpenThread
SSDT 86BDD990 ZwProtectVirtualMemory
SSDT 8667C140 ZwResumeThread
SSDT 8667B4A8 ZwSetContextThread
SSDT 86B02780 ZwSetInformationProcess
SSDT 86CBD460 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xF3DDC140]
SSDT 86B0ECD0 ZwSuspendProcess
SSDT 8667BC40 ZwSuspendThread
SSDT 86B43590 ZwTerminateProcess
SSDT 86A13468 ZwTerminateThread
SSDT 86B2F110 ZwUnmapViewOfSection
SSDT 86B5B148 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
? SYMDS.SYS Impossibile trovare il file specificato. !
? SYMEFA.SYS Impossibile trovare il file specificato. !
---- User code sections - GMER 1.0.15 ----
.text C:\Programmi\Mozilla Firefox\firefox.exe[2336] ntdll.dll!LdrLoadDll 7C92632D 5 Bytes JMP 0121B750 C:\Programmi\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Programmi\Mozilla Firefox\plugin-container.exe[2540] USER32.dll!GetWindowInfo 7E3AC49C 5 Bytes JMP 1046C909 C:\Programmi\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Programmi\Mozilla Firefox\plugin-container.exe[2540] USER32.dll!TrackPopupMenu 7E3E531E 5 Bytes JMP 1046CEBD C:\Programmi\Mozilla Firefox\xul.dll (Mozilla Foundation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
Edited by ferrux, 29 December 2011 - 04:18 PM.