GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2015-03-21 19:45:18
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST950032 rev.0003 465,76GB
Running: bs4ccogw.exe; Driver: C:\Users\Asus\AppData\Local\Temp\kftcqaoc.sys


---- User code sections - GMER 2.1 ----

.text   C:\Windows\AsScrPro.exe[1904] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                                                                          0000000076f21401 2 bytes JMP 7497b21b C:\Windows\syswow64\kernel32.dll
.text   C:\Windows\AsScrPro.exe[1904] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                                                                            0000000076f21419 2 bytes JMP 7497b346 C:\Windows\syswow64\kernel32.dll
.text   C:\Windows\AsScrPro.exe[1904] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                                                                          0000000076f21431 2 bytes JMP 749f8ea9 C:\Windows\syswow64\kernel32.dll
.text   C:\Windows\AsScrPro.exe[1904] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                                                                          0000000076f2144a 2 bytes CALL 749548ad C:\Windows\syswow64\kernel32.dll
.text   ...                                                                                                                                                                                            * 9
.text   C:\Windows\AsScrPro.exe[1904] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                                                                             0000000076f214dd 2 bytes JMP 749f87a2 C:\Windows\syswow64\kernel32.dll
.text   C:\Windows\AsScrPro.exe[1904] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                                                                                      0000000076f214f5 2 bytes JMP 749f8978 C:\Windows\syswow64\kernel32.dll
.text   C:\Windows\AsScrPro.exe[1904] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                                                                             0000000076f2150d 2 bytes JMP 749f8698 C:\Windows\syswow64\kernel32.dll
.text   C:\Windows\AsScrPro.exe[1904] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                                                                                      0000000076f21525 2 bytes JMP 749f8a62 C:\Windows\syswow64\kernel32.dll
.text   C:\Windows\AsScrPro.exe[1904] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                                                                            0000000076f2153d 2 bytes JMP 7496fca8 C:\Windows\syswow64\kernel32.dll
.text   C:\Windows\AsScrPro.exe[1904] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                                                                                 0000000076f21555 2 bytes JMP 749768ef C:\Windows\syswow64\kernel32.dll
.text   C:\Windows\AsScrPro.exe[1904] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                                                                          0000000076f2156d 2 bytes JMP 749f8f61 C:\Windows\syswow64\kernel32.dll
.text   C:\Windows\AsScrPro.exe[1904] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                                                                            0000000076f21585 2 bytes JMP 749f8ac2 C:\Windows\syswow64\kernel32.dll
.text   C:\Windows\AsScrPro.exe[1904] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                                                                               0000000076f2159d 2 bytes JMP 749f865c C:\Windows\syswow64\kernel32.dll
.text   C:\Windows\AsScrPro.exe[1904] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                                                                            0000000076f215b5 2 bytes JMP 7496fd41 C:\Windows\syswow64\kernel32.dll
.text   C:\Windows\AsScrPro.exe[1904] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                                                                          0000000076f215cd 2 bytes JMP 7497b2dc C:\Windows\syswow64\kernel32.dll
.text   C:\Windows\AsScrPro.exe[1904] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                                                                                      0000000076f216b2 2 bytes JMP 749f8e24 C:\Windows\syswow64\kernel32.dll
.text   C:\Windows\AsScrPro.exe[1904] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                                                                                      0000000076f216bd 2 bytes JMP 749f85f1 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\OrangeBusinessServices\Manager polaczen\{ad30a369-08e3-414c-9d2c-7f47dbe748da}\BusinessEverywhere.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17      0000000076f21401 2 bytes JMP 7497b21b C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\OrangeBusinessServices\Manager polaczen\{ad30a369-08e3-414c-9d2c-7f47dbe748da}\BusinessEverywhere.exe[952] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17        0000000076f21419 2 bytes JMP 7497b346 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\OrangeBusinessServices\Manager polaczen\{ad30a369-08e3-414c-9d2c-7f47dbe748da}\BusinessEverywhere.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17      0000000076f21431 2 bytes JMP 749f8ea9 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\OrangeBusinessServices\Manager polaczen\{ad30a369-08e3-414c-9d2c-7f47dbe748da}\BusinessEverywhere.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42      0000000076f2144a 2 bytes CALL 749548ad C:\Windows\syswow64\kernel32.dll
.text   ...                                                                                                                                                                                            * 9
.text   C:\Program Files (x86)\OrangeBusinessServices\Manager polaczen\{ad30a369-08e3-414c-9d2c-7f47dbe748da}\BusinessEverywhere.exe[952] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17         0000000076f214dd 2 bytes JMP 749f87a2 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\OrangeBusinessServices\Manager polaczen\{ad30a369-08e3-414c-9d2c-7f47dbe748da}\BusinessEverywhere.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17  0000000076f214f5 2 bytes JMP 749f8978 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\OrangeBusinessServices\Manager polaczen\{ad30a369-08e3-414c-9d2c-7f47dbe748da}\BusinessEverywhere.exe[952] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17         0000000076f2150d 2 bytes JMP 749f8698 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\OrangeBusinessServices\Manager polaczen\{ad30a369-08e3-414c-9d2c-7f47dbe748da}\BusinessEverywhere.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17  0000000076f21525 2 bytes JMP 749f8a62 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\OrangeBusinessServices\Manager polaczen\{ad30a369-08e3-414c-9d2c-7f47dbe748da}\BusinessEverywhere.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17        0000000076f2153d 2 bytes JMP 7496fca8 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\OrangeBusinessServices\Manager polaczen\{ad30a369-08e3-414c-9d2c-7f47dbe748da}\BusinessEverywhere.exe[952] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17             0000000076f21555 2 bytes JMP 749768ef C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\OrangeBusinessServices\Manager polaczen\{ad30a369-08e3-414c-9d2c-7f47dbe748da}\BusinessEverywhere.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17      0000000076f2156d 2 bytes JMP 749f8f61 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\OrangeBusinessServices\Manager polaczen\{ad30a369-08e3-414c-9d2c-7f47dbe748da}\BusinessEverywhere.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17        0000000076f21585 2 bytes JMP 749f8ac2 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\OrangeBusinessServices\Manager polaczen\{ad30a369-08e3-414c-9d2c-7f47dbe748da}\BusinessEverywhere.exe[952] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17           0000000076f2159d 2 bytes JMP 749f865c C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\OrangeBusinessServices\Manager polaczen\{ad30a369-08e3-414c-9d2c-7f47dbe748da}\BusinessEverywhere.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17        0000000076f215b5 2 bytes JMP 7496fd41 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\OrangeBusinessServices\Manager polaczen\{ad30a369-08e3-414c-9d2c-7f47dbe748da}\BusinessEverywhere.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17      0000000076f215cd 2 bytes JMP 7497b2dc C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\OrangeBusinessServices\Manager polaczen\{ad30a369-08e3-414c-9d2c-7f47dbe748da}\BusinessEverywhere.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20  0000000076f216b2 2 bytes JMP 749f8e24 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\OrangeBusinessServices\Manager polaczen\{ad30a369-08e3-414c-9d2c-7f47dbe748da}\BusinessEverywhere.exe[952] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31  0000000076f216bd 2 bytes JMP 749f85f1 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[3116] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                                                             0000000076f21401 2 bytes JMP 7497b21b C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[3116] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                                                               0000000076f21419 2 bytes JMP 7497b346 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[3116] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                                                             0000000076f21431 2 bytes JMP 749f8ea9 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[3116] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                                                             0000000076f2144a 2 bytes CALL 749548ad C:\Windows\syswow64\kernel32.dll
.text   ...                                                                                                                                                                                            * 9
.text   C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[3116] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                                                                0000000076f214dd 2 bytes JMP 749f87a2 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[3116] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                                                         0000000076f214f5 2 bytes JMP 749f8978 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[3116] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                                                                0000000076f2150d 2 bytes JMP 749f8698 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[3116] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                                                         0000000076f21525 2 bytes JMP 749f8a62 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[3116] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                                                               0000000076f2153d 2 bytes JMP 7496fca8 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[3116] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                                                                    0000000076f21555 2 bytes JMP 749768ef C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[3116] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                                                             0000000076f2156d 2 bytes JMP 749f8f61 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[3116] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                                                               0000000076f21585 2 bytes JMP 749f8ac2 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[3116] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                                                                  0000000076f2159d 2 bytes JMP 749f865c C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[3116] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                                                               0000000076f215b5 2 bytes JMP 7496fd41 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[3116] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                                                             0000000076f215cd 2 bytes JMP 7497b2dc C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[3116] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                                                         0000000076f216b2 2 bytes JMP 749f8e24 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe[3116] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                                                         0000000076f216bd 2 bytes JMP 749f85f1 C:\Windows\syswow64\kernel32.dll
.text   C:\Program Files\Alwil Software\Avast5\avastui.exe[3336] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter                                                                          0000000074958791 8 bytes [31, C0, C2, 04, 00, 90, 90, ...]

---- User IAT/EAT - GMER 2.1 ----

IAT     C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3512] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamDWord]        [7fef355741c] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT     C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3512] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSet]                     [7fef3555f10] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT     C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3512] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmEndSession]              [7fef3555674] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT     C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3512] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartSession]            [7fef3555e2c] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT     C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3512] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartUpload]             [7fef3557f48] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT     C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3512] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppVersion]           [7fef3556a38] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT     C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3512] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetMachineId]            [7fef3556ee8] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT     C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3512] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmWriteSharedMachineId]    [7fef3557b58] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT     C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3512] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmCreateNewId]             [7fef3557ea0] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT     C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3512] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmReadSharedMachineId]     [7fef35578b0] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT     C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3512] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmGetSession]              [7fef3554fb4] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT     C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3512] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppId]                [7fef3555d38] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT     C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3512] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamString]       [7fef3557584] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll

---- Threads - GMER 2.1 ----

Thread  C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2784:2876]                                                                                                                        00000000710b52c9
Thread  C:\Windows\System32\svchost.exe [4040:3600]                                                                                                                                                    000007feefdd9688
Thread  C:\Program Files\Windows Media Player\wmpnetwk.exe [4432:832]                                                                                                                                  000007fefb1e2bf8

---- Files - GMER 2.1 ----

File    C:\ADSM_PData_0150                                                                                                                                                                             0 bytes
File    C:\ADSM_PData_0150\DB                                                                                                                                                                          0 bytes
File    C:\ADSM_PData_0150\DB\SI.db                                                                                                                                                                    624 bytes
File    C:\ADSM_PData_0150\DB\UL.db                                                                                                                                                                    16 bytes
File    C:\ADSM_PData_0150\DB\VL.db                                                                                                                                                                    16 bytes
File    C:\ADSM_PData_0150\DB\WAL.db                                                                                                                                                                   2048 bytes
File    C:\ADSM_PData_0150\DragWait.exe                                                                                                                                                                315392 bytes executable
File    C:\ADSM_PData_0150\_avt                                                                                                                                                                        512 bytes

---- EOF - GMER 2.1 ----
