Hi Blade, sorry about the "z" above
Ran program in safe mode, I still can't boot normally. Here is the log
GMER 1.0.15.15087 - http://www.gmer.net
Rootkit scan 2009-09-16 07:00:35
Windows 6.0.6001 Service Pack 1
Running: 254evpvq.exe; Driver: C:\Users\JIM'SL~1\AppData\Local\Temp\kwloikoc.sys
---- System - GMER 1.0.15 ----
INT 0x52 ? 86BA1BF8
INT 0x52 ? 86BA1BF8
INT 0x52 ? 86BA1BF8
INT 0x62 ? 86BA1BF8
INT 0x72 ? 86BA1BF8
INT 0x72 ? 86BA1BF8
INT 0x72 ? 86BA1BF8
INT 0x72 ? 86BA1BF8
INT 0x92 ? 84F19BF8
INT 0xB2 ? 85CCDBF8
Code 8954C070 ZwEnumerateKey
Code 89694A78 ZwFlushInstructionCache
Code 8960F336 ZwSaveKey
Code 896A9CE6 ZwSaveKeyEx
Code 89548135 IofCallDriver
Code 8954E01E IofCompleteRequest
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!IofCompleteRequest 82072FBA 5 Bytes JMP 8954E023
.text ntkrnlpa.exe!IofCallDriver 820F4FEF 5 Bytes JMP 8954813A
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 821EB30B 5 Bytes JMP 89694A7C
PAGE ntkrnlpa.exe!ZwEnumerateKey 82240BB4 5 Bytes JMP 8954C074
PAGE ntkrnlpa.exe!ZwSaveKey 8228E523 5 Bytes JMP 8960F33A
PAGE ntkrnlpa.exe!ZwSaveKeyEx 8228E62A 5 Bytes JMP 896A9CEA
? System32\Drivers\spcb.sys The system cannot find the path specified. !
.text USBPORT.SYS!DllUnload 8BB4C46F 5 Bytes JMP 86BA11D8
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Internet Explorer\iexplore.exe[1784] USER32.dll!DialogBoxIndirectParamW 75DBBD25 5 Bytes JMP 71635ACB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1784] USER32.dll!DialogBoxParamW 75DD1FD5 5 Bytes JMP 71635A55 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1784] USER32.dll!DialogBoxParamA 75DF80B2 5 Bytes JMP 71635A90 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1784] USER32.dll!DialogBoxIndirectParamA 75DF83DD 5 Bytes JMP 71635B06 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1784] USER32.dll!MessageBoxIndirectA 75E0D471 5 Bytes JMP 71635A11 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1784] USER32.dll!MessageBoxIndirectW 75E0D56B 5 Bytes JMP 716359CD C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1784] USER32.dll!MessageBoxExA 75E0D5D1 5 Bytes JMP 71635993 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[1784] USER32.dll!MessageBoxExW 75E0D5F5 5 Bytes JMP 71635959 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [806936D2] \SystemRoot\System32\Drivers\spcb.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [80693040] \SystemRoot\System32\Drivers\spcb.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [806937FC] \SystemRoot\System32\Drivers\spcb.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUshort] [806930BE] \SystemRoot\System32\Drivers\spcb.sys
IAT \SystemRoot\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [8069313C] \SystemRoot\System32\Drivers\spcb.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [806A3048] \SystemRoot\System32\Drivers\spcb.sys
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 85CCF1F8
Device \Driver\volmgr \Device\VolMgrControl 84F1B1F8
Device \Driver\usbuhci \Device\USBPDO-0 86AF81F8
Device \Driver\usbuhci \Device\USBPDO-1 86AF81F8
Device \Driver\usbehci \Device\USBPDO-2 86AF91F8
Device \Driver\usbuhci \Device\USBPDO-3 86AF81F8
Device \Driver\usbuhci \Device\USBPDO-4 86AF81F8
AttachedDevice \Driver\tdx \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
Device \Driver\usbuhci \Device\USBPDO-5 86AF81F8
Device \Driver\usbehci \Device\USBPDO-6 86AF91F8
Device \Driver\volmgr \Device\HarddiskVolume1 84F1B1F8
Device \Driver\volmgr \Device\HarddiskVolume2 84F1B1F8
Device \Driver\cdrom \Device\CdRom0 86B481F8
Device \Driver\volmgr \Device\HarddiskVolume3 84F1B1F8
Device \Driver\cdrom \Device\CdRom1 86B481F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 85CCE1F8
Device \Driver\atapi \Device\Ide\IdePort0 85CCE1F8
Device \Driver\sptd \Device\3345995432 spcb.sys
Device \Driver\volmgr \Device\HarddiskVolume4 84F1B1F8
Device \Driver\netbt \Device\NetBt_Wins_Export 897FA1F8
Device \Driver\Smb \Device\NetbiosSmb 897AF1F8
Device \Driver\iScsiPrt \Device\RaidPort0 86B671F8
AttachedDevice \Driver\tdx \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
Device \Driver\netbt \Device\NetBT_Tcpip_{E8630708-6774-4261-8816-48F364D0765D} 897FA1F8
AttachedDevice \Driver\tdx \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
Device \Driver\usbuhci \Device\USBFDO-0 86AF81F8
Device \Driver\usbuhci \Device\USBFDO-1 86AF81F8
Device \Driver\PCI_PNP3415 \Device\0000007b spcb.sys
Device \Driver\usbehci \Device\USBFDO-2 86AF91F8
Device \Driver\usbuhci \Device\USBFDO-3 86AF81F8
Device \Driver\usbuhci \Device\USBFDO-4 86AF81F8
Device \Driver\netbt \Device\NetBT_Tcpip_{3DB87139-8809-44D9-A754-182AB7C47D2C} 897FA1F8
Device \Driver\usbuhci \Device\USBFDO-5 86AF81F8
Device \Driver\usbehci \Device\USBFDO-6 86AF91F8
Device \Driver\aiywpziq \Device\Scsi\aiywpziq1Port3Path0Target0Lun0 86B631F8
Device \Driver\aiywpziq \Device\Scsi\aiywpziq1 86B631F8
Device \FileSystem\fastfat \Fat 89D8D1F8
Device \FileSystem\fastfat \Fat 8BA8945E
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\cdfs \Cdfs 89D3D1F8
---- Services - GMER 1.0.15 ----
Service C:\Windows\System32\alg.exe? (*** hidden *** ) [MANUAL] ALG <-- ROOTKIT !!!
Service C:\Windows\system32\drivers\rotscxkoxxvels.sys (*** hidden *** ) [SYSTEM] rotscxqyxxxucd <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\BTHPORT\Parameters\Keys\001fe1effe99 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd@start 1
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd@type 1
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd@group file system
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd@imagepath \systemroot\system32\drivers\rotscxkoxxvels.sys
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd\main@aid 10094
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd\main@sid 0
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd\main\injector@* rotscxwsp.dll
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd\main\tasks\0000000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd\main\tasks\0000000001@fn (null)
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd\main\tasks\0000000001@url http://top1959.cn/PC_protect.exe
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd\main\tasks\0000000001@knock (null)
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd\main\tasks\0000000001@timeout 300
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd\main\tasks\0000000001@type 0
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd\main\tasks\0000000001@count 1
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd\modules@rotscxrk.sys \systemroot\system32\drivers\rotscxkoxxvels.sys
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd\modules@rotscxcmd.dll \systemroot\system32\rotscxnwvwpvgt.dll
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd\modules@rotscxlog.dat \systemroot\system32\rotscxtvencebp.dat
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd\modules@rotscxwsp.dll \systemroot\system32\rotscxqpooewnk.dll
Reg HKLM\SYSTEM\ControlSet001\Services\rotscxqyxxxucd\modules@rotscx.dat \systemroot\system32\rotscxgbjmeqjq.dat
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xCD 0x33 0xB8 0x1E ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x60 0xFC 0x2C 0x22 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xA7 0x08 0x99 0xCA ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x8F 0x71 0xBB 0x08 ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001fe1effe99 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxqyxxxucd (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxqyxxxucd@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxqyxxxucd@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxqyxxxucd@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxqyxxxucd@imagepath \systemroot\system32\drivers\rotscxkoxxvels.sys
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxqyxxxucd\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxqyxxxucd\main@aid 10094
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxqyxxxucd\main@sid 0
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxqyxxxucd\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxqyxxxucd\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxqyxxxucd\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxqyxxxucd\main\injector@* rotscxwsp8.dll
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxqyxxxucd\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxqyxxxucd\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxqyxxxucd\modules@rotscxrk.sys \systemroot\system32\drivers\rotscxkoxxvels.sys
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxqyxxxucd\modules@rotscxcmd.dll \systemroot\system32\rotscxnwvwpvgt.dll
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxqyxxxucd\modules@rotscxlog.dat \systemroot\system32\rotscxtvencebp.dat
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxqyxxxucd\modules@rotscxwsp.dll \systemroot\system32\rotscxqpooewnk.dll
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxqyxxxucd\modules@rotscx.dat \systemroot\system32\rotscxgbjmeqjq.dat
Reg HKLM\SYSTEM\ControlSet002\Services\rotscxqyxxxucd\modules@rotscxwsp8.dll \systemroot\system32\rotscxpxuesfcq.dll
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xCD 0x33 0xB8 0x1E ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x60 0xFC 0x2C 0x22 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xA7 0x08 0x99 0xCA ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x8F 0x71 0xBB 0x08 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001fe1effe99
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxqyxxxucd
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxqyxxxucd@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxqyxxxucd@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxqyxxxucd@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxqyxxxucd@imagepath \systemroot\system32\drivers\rotscxkoxxvels.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxqyxxxucd\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxqyxxxucd\main@aid 10094
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxqyxxxucd\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxqyxxxucd\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxqyxxxucd\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxqyxxxucd\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxqyxxxucd\main\injector@* rotscxwsp8.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxqyxxxucd\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxqyxxxucd\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxqyxxxucd\modules@rotscxrk.sys \systemroot\system32\drivers\rotscxkoxxvels.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxqyxxxucd\modules@rotscxcmd.dll \systemroot\system32\rotscxnwvwpvgt.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxqyxxxucd\modules@rotscxlog.dat \systemroot\system32\rotscxtvencebp.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxqyxxxucd\modules@rotscxwsp.dll \systemroot\system32\rotscxqpooewnk.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxqyxxxucd\modules@rotscx.dat \systemroot\system32\rotscxgbjmeqjq.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxqyxxxucd\modules@rotscxwsp8.dll \systemroot\system32\rotscxpxuesfcq.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xCD 0x33 0xB8 0x1E ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x60 0xFC 0x2C 0x22 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xA7 0x08 0x99 0xCA ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x8F 0x71 0xBB 0x08 ...
Reg HKLM\SOFTWARE\Microsoft\Windows Mobile Getting Started Disc\AppInstalled@HTC Touch Pro\x2122 User Guide_Installed 4
Reg HKLM\SOFTWARE\Microsoft\Windows Mobile Getting Started Disc\AppInstalled@Windows Mobile\xae Device Center_Installed 4
---- Files - GMER 1.0.15 ----
File C:\Qoobox\Quarantine\C\Windows\System32\drivers\rotscxkoxxvels.sys.vir 71168 bytes
File C:\Users\Jim's Laptop\AppData\Local\Temp\rotscx000 0 bytes
File C:\Users\Jim's Laptop\AppData\Local\Temp\rotscxhlkwxotkgs.tmp 680448 bytes executable
File C:\Windows\System32\drivers\rotscxkoxxvels.sys 71168 bytes <-- ROOTKIT !!!
File C:\Windows\System32\rotscxgbjmeqjq.dat 43 bytes
File C:\Windows\System32\rotscxnwvwpvgt.dll 45568 bytes
File C:\Windows\System32\rotscxpxuesfcq.dll 19456 bytes executable
File C:\Windows\System32\rotscxqpooewnk.dll 20480 bytes executable
File C:\Windows\System32\rotscxtvencebp.dat 70624 bytes
File C:\Windows\temp\rotscxcdyiknvahr.tmp 19456 bytes executable
File C:\Windows\temp\rotscxyjdprtctta.tmp 43 bytes
---- EOF - GMER 1.0.15 ----