Bobbye,
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-08-01 12:33:57
Windows 5.1.2600 Service Pack 3
Running: gqhiezkl.exe; Driver: C:\DOCUME~1\Marvin\LOCALS~1\Temp\fgndyfog.sys
---- System - GMER 1.0.15 ----
SSDT 82CFC4F8 ZwAlertResumeThread
SSDT 82CFC5B8 ZwAlertThread
SSDT 82811798 ZwAllocateVirtualMemory
SSDT 82DD40E8 ZwAssignProcessToJobObject
SSDT 82D0CD98 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xEC6E0210]
SSDT 82DA4180 ZwCreateMutant
SSDT 82F4F190 ZwCreateSymbolicLinkObject
SSDT 82F4ABA8 ZwCreateThread
SSDT 82DD41C8 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xEC6E0490]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xEC6E09F0]
SSDT 82D61798 ZwDuplicateObject
SSDT 828B87F8 ZwFreeVirtualMemory
SSDT 82DA4270 ZwImpersonateAnonymousToken
SSDT 82CFC418 ZwImpersonateThread
SSDT 82CE6E90 ZwLoadDriver
SSDT 828B8718 ZwMapViewOfSection
SSDT 82DA40A0 ZwOpenEvent
SSDT 82864300 ZwOpenProcess
SSDT 82808058 ZwOpenProcessToken
SSDT 82DD1150 ZwOpenSection
SSDT 82D63710 ZwOpenThread
SSDT 82F4F260 ZwProtectVirtualMemory
SSDT 82D99758 ZwResumeThread
SSDT 82833588 ZwSetContextThread
SSDT 82833668 ZwSetInformationProcess
SSDT 82DD4008 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xEC6E0C40]
SSDT 82DD1230 ZwSuspendProcess
SSDT 82D99838 ZwSuspendThread
SSDT 82CFA3D0 ZwTerminateProcess
SSDT 82D99918 ZwTerminateThread
SSDT 828B8638 ZwUnmapViewOfSection
SSDT 828116C8 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!_abnormal_termination + 98 804E2704 4 Bytes CALL 44D10449
.text ntoskrnl.exe!_abnormal_termination + 15C 804E27C8 1 Byte [98]
.text ntoskrnl.exe!_abnormal_termination + 240 804E28AC 1 Byte [50]
? SYMDS.SYS The system cannot find the file specified. !
? SYMEFA.SYS The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\Explorer.EXE[784] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B7000A
.text C:\WINDOWS\Explorer.EXE[784] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00BD000A
.text C:\WINDOWS\Explorer.EXE[784] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B6000C
.text C:\WINDOWS\System32\svchost.exe[1500] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 3 Bytes JMP 0091000A
.text C:\WINDOWS\System32\svchost.exe[1500] ntdll.dll!NtProtectVirtualMemory + 4 7C90D6F2 1 Byte [84]
.text C:\WINDOWS\System32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0092000A
.text C:\WINDOWS\System32\svchost.exe[1500] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0090000C
.text C:\WINDOWS\System32\svchost.exe[1500] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 01AD000A
.text C:\WINDOWS\System32\svchost.exe[1500] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00AF000A
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 tdrpm258.sys (Acronis Try&Decide Volume Filter Driver/Acronis)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
---- EOF - GMER 1.0.15 ----
I'm going to look at the anti virus on Norton to see which one it is.