Hi, I had a rootkit virus last year which you guys resolved (many thanks!) and I have been problem free until this week when I have had several hardware and software issues (USB port errors, blue screen of death, unstable system, network problems)
Normal Avira and Malwarebytes scans have not uncovered anything sinister however I want to be sure it's not a virus before I start looking at faulty components. (no faults reported during windows hardware scan)
Logs enclosed:
Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org
Database version: v2012.02.06.03
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Dan :: DANCREATION4 [administrator]
2/6/2012 4:32:58 PM
mbam-log-2012-02-06 (16-32-58).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 239488
Time elapsed: 6 minute(s), 30 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-02-06 18:29:17
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T1L0-e STM3250318AS rev.CC37
Running: 26v8tz3q.exe; Driver: C:\DOCUME~1\Dan\LOCALS~1\Temp\kwroipob.sys
---- System - GMER 1.0.15 ----
SSDT B8775D84 ZwClose
SSDT B8775D3E ZwCreateKey
SSDT B8775D8E ZwCreateSection
SSDT B8775D34 ZwCreateThread
SSDT B8775D43 ZwDeleteKey
SSDT B8775D4D ZwDeleteValueKey
SSDT B8775D7F ZwDuplicateObject
SSDT spms.sys ZwEnumerateKey [0xB7ECDDA4]
SSDT spms.sys ZwEnumerateValueKey [0xB7ECE132]
SSDT B8775D52 ZwLoadKey
SSDT spms.sys ZwOpenKey [0xB7EB50C0]
SSDT B8775D20 ZwOpenProcess
SSDT B8775D25 ZwOpenThread
SSDT spms.sys ZwQueryKey [0xB7ECE20A]
SSDT B8775DA7 ZwQueryValueKey
SSDT B8775D5C ZwReplaceKey
SSDT B8775D98 ZwRequestWaitReplyPort
SSDT B8775D57 ZwRestoreKey
SSDT B8775D93 ZwSetContextThread
SSDT B8775D9D ZwSetSecurityObject
SSDT B8775D48 ZwSetValueKey
SSDT B8775DA2 ZwSystemDebugControl
SSDT B8775D2F ZwTerminateProcess
INT 0x62 ? 8A652BF8
INT 0x63 ? 8A652BF8
INT 0x63 ? 8A652BF8
INT 0x63 ? 8A332BF8
INT 0x63 ? 8A652BF8
INT 0x83 ? 8A332BF8
INT 0xA4 ? 8A332BF8
INT 0xB4 ? 8A332BF8
---- Kernel code sections - GMER 1.0.15 ----
? spms.sys The system cannot find the file specified. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB67ED380, 0x8D6CD5, 0xE8000020]
.text USBPORT.SYS!DllUnload B67798AC 5 Bytes JMP 8A3321D8
.text azqqt6en.SYS B6705386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text azqqt6en.SYS B67053AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text azqqt6en.SYS B67053C4 3 Bytes [00, 80, 02]
.text azqqt6en.SYS B67053C9 1 Byte [30]
.text azqqt6en.SYS B67053C9 11 Bytes [30, 00, 00, 00, 5E, 02, 00, ...] {XOR [EAX], AL; ADD [EAX], AL; POP ESI; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text ...
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B7EB6042] spms.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B7EB613E] spms.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B7EB60C0] spms.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B7EB6800] spms.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B7EB66D6] spms.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [B7EC5B90] spms.sys
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!KfAcquireSpinLock] 18C4830E
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!READ_PORT_UCHAR] 1C959E88
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!KeGetCurrentIrql] 9E880000
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!KfRaiseIrql] 00001CB1
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!KfLowerIrql] 0E798366
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!HalGetInterruptVector] 74AAB000
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!HalTranslateBusAddress] 8986C636
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!KeStallExecutionProcessor] 1A00001C
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!KfReleaseSpinLock] 1C8B86C6
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] C6020000
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!READ_PORT_USHORT] 001C9686
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 86C60200
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!WRITE_PORT_UCHAR] 00001CB2
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[WMILIB.SYS!WmiSystemControl] 8800001C
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[WMILIB.SYS!WmiCompleteRequest] 001CB99E
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8A6511F8
Device \FileSystem\Udfs \UdfsCdRom 8A28E500
Device \FileSystem\Udfs \UdfsDisk 8A28E500
AttachedDevice \Driver\Tcpip \Device\Ip mdvrmng.sys
Device \Driver\usbuhci \Device\USBPDO-0 8A3FC1F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8A5E21F8
Device \Driver\dmio \Device\DmControl\DmConfig 8A5E21F8
Device \Driver\dmio \Device\DmControl\DmPnP 8A5E21F8
Device \Driver\dmio \Device\DmControl\DmInfo 8A5E21F8
Device \Driver\usbuhci \Device\USBPDO-1 8A3FC1F8
Device \Driver\usbuhci \Device\USBPDO-2 8A3FC1F8
Device \Driver\usbuhci \Device\USBPDO-3 8A3FC1F8
Device \Driver\sptd \Device\3155751772 spms.sys
Device \Driver\NetBT \Device\NetBT_Tcpip_{2EF6E43C-6A13-4AAE-9DDB-5006A0708CDA} 8A2AF500
Device \Driver\usbehci \Device\USBPDO-4 8A401500
AttachedDevice \Driver\Tcpip \Device\Tcp mdvrmng.sys
Device \Driver\prodrv06 \Device\ProDrv06 E1D61420
Device \Driver\Ftdisk \Device\HarddiskVolume1 8A6531F8
Device \Driver\Cdrom \Device\CdRom0 8A30E1F8
Device \Driver\atapi \Device\Ide\IdePort0 [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort1 [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort2 [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort2 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-e [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-e prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\Cdrom \Device\CdRom1 8A30E1F8
Device \Driver\Cdrom \Device\CdRom2 8A30E1F8
Device \Driver\USBSTOR \Device\00000080 8A29C500
Device \Driver\Cdrom \Device\CdRom3 8A30E1F8
Device \Driver\USBSTOR \Device\00000082 8A29C500
Device \Driver\prohlp02 \Device\ProHlp02 E1014338
Device \Driver\USBSTOR \Device\00000083 8A29C500
Device \Driver\NetBT \Device\NetBt_Wins_Export 8A2AF500
Device \Driver\NetBT \Device\NetbiosSmb 8A2AF500
Device \Driver\PCI_PNP8022 \Device\0000004d spms.sys
AttachedDevice \Driver\Tcpip \Device\Udp mdvrmng.sys
AttachedDevice \Driver\Tcpip \Device\RawIp mdvrmng.sys
Device \Driver\usbuhci \Device\USBFDO-0 8A3FC1F8
Device \Driver\usbuhci \Device\USBFDO-1 8A3FC1F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89FEB500
Device \Driver\usbuhci \Device\USBFDO-2 8A3FC1F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 89FEB500
Device \Driver\usbuhci \Device\USBFDO-3 8A3FC1F8
Device \Driver\usbehci \Device\USBFDO-4 8A401500
Device \Driver\Ftdisk \Device\FtControl 8A6531F8
Device \Driver\azqqt6en \Device\Scsi\azqqt6en1Port3Path0Target1Lun0 8A3DA1F8
Device \Driver\azqqt6en \Device\Scsi\azqqt6en1Port3Path0Target0Lun0 8A3DA1F8
Device \Driver\azqqt6en \Device\Scsi\azqqt6en1 8A3DA1F8
Device \FileSystem\Cdfs \Cdfs 89CEC500
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x6D 0xE3 0xA8 0x37 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xCA 0xA1 0x2A 0xA8 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xF4 0x17 0xBF 0x28 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x8F 0xB8 0x15 0xDA ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2@hdf12 0x8F 0x1C 0xA8 0x77 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3@hdf12 0xF4 0x6E 0x8A 0x39 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x6D 0xE3 0xA8 0x37 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xCA 0xA1 0x2A 0xA8 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xF4 0x17 0xBF 0x28 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x8F 0xB8 0x15 0xDA ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2@hdf12 0x8F 0x1C 0xA8 0x77 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3@hdf12 0xF4 0x6E 0x8A 0x39 ...
---- EOF - GMER 1.0.15 ----
(NB. Midway during the GMER scan I got the dreaded blue screen and my system retarted. The error details are as follows:
The system has recovered from a serious error.
C:\DOCUME~1\Dan\LOCALS~1\Temp\WERcbc2.dir00\Mini020612-02.dmp
C:\DOCUME~1\Dan\LOCALS~1\Temp\WERcbc2.dir00\sysdata.xml
The system has recovered from a serious error.
C:\DOCUME~1\Dan\LOCALS~1\Temp\WERcbc2.dir00\Mini020612-02.dmp
C:\DOCUME~1\Dan\LOCALS~1\Temp\WERcbc2.dir00\sysdata.xml
Error signature
BCCode : 100000d1 BCP1 : 0000000C BCP2 : 00000005 BCP3 : 00000001
BCP4 : B7E085F7 OSVer : 5_1_2600 SP : 3_0 Product : 256_1
Error signature
BCCode : 100000d1 BCP1 : 0000000C BCP2 : 00000005 BCP3 : 00000001
BCP4 : B7E085F7 OSVer : 5_1_2600 SP : 3_0 Product : 256_1
.
Normal Avira and Malwarebytes scans have not uncovered anything sinister however I want to be sure it's not a virus before I start looking at faulty components. (no faults reported during windows hardware scan)
Logs enclosed:
Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org
Database version: v2012.02.06.03
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Dan :: DANCREATION4 [administrator]
2/6/2012 4:32:58 PM
mbam-log-2012-02-06 (16-32-58).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 239488
Time elapsed: 6 minute(s), 30 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-02-06 18:29:17
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T1L0-e STM3250318AS rev.CC37
Running: 26v8tz3q.exe; Driver: C:\DOCUME~1\Dan\LOCALS~1\Temp\kwroipob.sys
---- System - GMER 1.0.15 ----
SSDT B8775D84 ZwClose
SSDT B8775D3E ZwCreateKey
SSDT B8775D8E ZwCreateSection
SSDT B8775D34 ZwCreateThread
SSDT B8775D43 ZwDeleteKey
SSDT B8775D4D ZwDeleteValueKey
SSDT B8775D7F ZwDuplicateObject
SSDT spms.sys ZwEnumerateKey [0xB7ECDDA4]
SSDT spms.sys ZwEnumerateValueKey [0xB7ECE132]
SSDT B8775D52 ZwLoadKey
SSDT spms.sys ZwOpenKey [0xB7EB50C0]
SSDT B8775D20 ZwOpenProcess
SSDT B8775D25 ZwOpenThread
SSDT spms.sys ZwQueryKey [0xB7ECE20A]
SSDT B8775DA7 ZwQueryValueKey
SSDT B8775D5C ZwReplaceKey
SSDT B8775D98 ZwRequestWaitReplyPort
SSDT B8775D57 ZwRestoreKey
SSDT B8775D93 ZwSetContextThread
SSDT B8775D9D ZwSetSecurityObject
SSDT B8775D48 ZwSetValueKey
SSDT B8775DA2 ZwSystemDebugControl
SSDT B8775D2F ZwTerminateProcess
INT 0x62 ? 8A652BF8
INT 0x63 ? 8A652BF8
INT 0x63 ? 8A652BF8
INT 0x63 ? 8A332BF8
INT 0x63 ? 8A652BF8
INT 0x83 ? 8A332BF8
INT 0xA4 ? 8A332BF8
INT 0xB4 ? 8A332BF8
---- Kernel code sections - GMER 1.0.15 ----
? spms.sys The system cannot find the file specified. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB67ED380, 0x8D6CD5, 0xE8000020]
.text USBPORT.SYS!DllUnload B67798AC 5 Bytes JMP 8A3321D8
.text azqqt6en.SYS B6705386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text azqqt6en.SYS B67053AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text azqqt6en.SYS B67053C4 3 Bytes [00, 80, 02]
.text azqqt6en.SYS B67053C9 1 Byte [30]
.text azqqt6en.SYS B67053C9 11 Bytes [30, 00, 00, 00, 5E, 02, 00, ...] {XOR [EAX], AL; ADD [EAX], AL; POP ESI; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text ...
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B7EB6042] spms.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B7EB613E] spms.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B7EB60C0] spms.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B7EB6800] spms.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B7EB66D6] spms.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [B7EC5B90] spms.sys
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!KfAcquireSpinLock] 18C4830E
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!READ_PORT_UCHAR] 1C959E88
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!KeGetCurrentIrql] 9E880000
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!KfRaiseIrql] 00001CB1
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!KfLowerIrql] 0E798366
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!HalGetInterruptVector] 74AAB000
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!HalTranslateBusAddress] 8986C636
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!KeStallExecutionProcessor] 1A00001C
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!KfReleaseSpinLock] 1C8B86C6
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] C6020000
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!READ_PORT_USHORT] 001C9686
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 86C60200
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[HAL.dll!WRITE_PORT_UCHAR] 00001CB2
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[WMILIB.SYS!WmiSystemControl] 8800001C
IAT \SystemRoot\System32\Drivers\azqqt6en.SYS[WMILIB.SYS!WmiCompleteRequest] 001CB99E
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8A6511F8
Device \FileSystem\Udfs \UdfsCdRom 8A28E500
Device \FileSystem\Udfs \UdfsDisk 8A28E500
AttachedDevice \Driver\Tcpip \Device\Ip mdvrmng.sys
Device \Driver\usbuhci \Device\USBPDO-0 8A3FC1F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8A5E21F8
Device \Driver\dmio \Device\DmControl\DmConfig 8A5E21F8
Device \Driver\dmio \Device\DmControl\DmPnP 8A5E21F8
Device \Driver\dmio \Device\DmControl\DmInfo 8A5E21F8
Device \Driver\usbuhci \Device\USBPDO-1 8A3FC1F8
Device \Driver\usbuhci \Device\USBPDO-2 8A3FC1F8
Device \Driver\usbuhci \Device\USBPDO-3 8A3FC1F8
Device \Driver\sptd \Device\3155751772 spms.sys
Device \Driver\NetBT \Device\NetBT_Tcpip_{2EF6E43C-6A13-4AAE-9DDB-5006A0708CDA} 8A2AF500
Device \Driver\usbehci \Device\USBPDO-4 8A401500
AttachedDevice \Driver\Tcpip \Device\Tcp mdvrmng.sys
Device \Driver\prodrv06 \Device\ProDrv06 E1D61420
Device \Driver\Ftdisk \Device\HarddiskVolume1 8A6531F8
Device \Driver\Cdrom \Device\CdRom0 8A30E1F8
Device \Driver\atapi \Device\Ide\IdePort0 [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort0 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort1 [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdePort2 [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort2 prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-e [B7E09B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-e prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\Cdrom \Device\CdRom1 8A30E1F8
Device \Driver\Cdrom \Device\CdRom2 8A30E1F8
Device \Driver\USBSTOR \Device\00000080 8A29C500
Device \Driver\Cdrom \Device\CdRom3 8A30E1F8
Device \Driver\USBSTOR \Device\00000082 8A29C500
Device \Driver\prohlp02 \Device\ProHlp02 E1014338
Device \Driver\USBSTOR \Device\00000083 8A29C500
Device \Driver\NetBT \Device\NetBt_Wins_Export 8A2AF500
Device \Driver\NetBT \Device\NetbiosSmb 8A2AF500
Device \Driver\PCI_PNP8022 \Device\0000004d spms.sys
AttachedDevice \Driver\Tcpip \Device\Udp mdvrmng.sys
AttachedDevice \Driver\Tcpip \Device\RawIp mdvrmng.sys
Device \Driver\usbuhci \Device\USBFDO-0 8A3FC1F8
Device \Driver\usbuhci \Device\USBFDO-1 8A3FC1F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89FEB500
Device \Driver\usbuhci \Device\USBFDO-2 8A3FC1F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 89FEB500
Device \Driver\usbuhci \Device\USBFDO-3 8A3FC1F8
Device \Driver\usbehci \Device\USBFDO-4 8A401500
Device \Driver\Ftdisk \Device\FtControl 8A6531F8
Device \Driver\azqqt6en \Device\Scsi\azqqt6en1Port3Path0Target1Lun0 8A3DA1F8
Device \Driver\azqqt6en \Device\Scsi\azqqt6en1Port3Path0Target0Lun0 8A3DA1F8
Device \Driver\azqqt6en \Device\Scsi\azqqt6en1 8A3DA1F8
Device \FileSystem\Cdfs \Cdfs 89CEC500
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x6D 0xE3 0xA8 0x37 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xCA 0xA1 0x2A 0xA8 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xF4 0x17 0xBF 0x28 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x8F 0xB8 0x15 0xDA ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2@hdf12 0x8F 0x1C 0xA8 0x77 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3@hdf12 0xF4 0x6E 0x8A 0x39 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x6D 0xE3 0xA8 0x37 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xCA 0xA1 0x2A 0xA8 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xF4 0x17 0xBF 0x28 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x8F 0xB8 0x15 0xDA ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2@hdf12 0x8F 0x1C 0xA8 0x77 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq3@hdf12 0xF4 0x6E 0x8A 0x39 ...
---- EOF - GMER 1.0.15 ----
(NB. Midway during the GMER scan I got the dreaded blue screen and my system retarted. The error details are as follows:
The system has recovered from a serious error.
C:\DOCUME~1\Dan\LOCALS~1\Temp\WERcbc2.dir00\Mini020612-02.dmp
C:\DOCUME~1\Dan\LOCALS~1\Temp\WERcbc2.dir00\sysdata.xml
The system has recovered from a serious error.
C:\DOCUME~1\Dan\LOCALS~1\Temp\WERcbc2.dir00\Mini020612-02.dmp
C:\DOCUME~1\Dan\LOCALS~1\Temp\WERcbc2.dir00\sysdata.xml
Error signature
BCCode : 100000d1 BCP1 : 0000000C BCP2 : 00000005 BCP3 : 00000001
BCP4 : B7E085F7 OSVer : 5_1_2600 SP : 3_0 Product : 256_1
Error signature
BCCode : 100000d1 BCP1 : 0000000C BCP2 : 00000005 BCP3 : 00000001
BCP4 : B7E085F7 OSVer : 5_1_2600 SP : 3_0 Product : 256_1
.