GMER 1.0.15.15281 - http://www.gmer.net Rootkit scan 2010-08-01 19:35:34 Windows 5.1.2600 Dodatek Service Pack 2 Running: k2j9cmvs.exe; Driver: C:\DOCUME~1\beny\USTAWI~1\Temp\kxdcrfow.sys ---- Kernel code sections - GMER 1.0.15 ---- .rsrc C:\WINDOWS\system32\drivers\nvatabus.sys entry point in ".rsrc" section [0xF7461C00] ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\Mozilla Firefox\plugin-container.exe[248] USER32.dll!TrackPopupMenu 77D84F16 5 Bytes JMP 1044721D C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[1784] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation) ---- Devices - GMER 1.0.15 ---- AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation) ---- Files - GMER 1.0.15 ---- File C:\WINDOWS\system32\drivers\nvatabus.sys suspicious modification ---- EOF - GMER 1.0.15 ----