GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2012-07-12 15:14:45 Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\00000066 ST3320620AS rev.3.AAK Running: ynjx88wm.exe; Driver: C:\DOCUME~1\Damian\USTAWI~1\Temp\afldqkob.sys ---- Kernel code sections - GMER 1.0.15 ---- .text USBPORT.SYS!USBPORT_RegisterUSBPortDriver B86CDA6E 1 Byte [00] .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB785D3C0, 0x95B7EA, 0xE8000020] ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\Mozilla Firefox\firefox.exe[2648] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 011AFA35 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[2648] kernel32.dll!VirtualAlloc 7C809AF1 5 Bytes JMP 014507C5 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[2648] kernel32.dll!MapViewOfFile 7C80B9A5 5 Bytes JMP 0145079E C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[2648] GDI32.dll!CreateDIBSection 77F19E19 5 Bytes JMP 01450728 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3028] USER32.dll!SetWindowLongA 7E37C29D 5 Bytes JMP 1066003B C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3028] USER32.dll!SetWindowLongW 7E37C2BB 5 Bytes JMP 1065FFCA C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3028] USER32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 1043AEF3 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3028] USER32.dll!TrackPopupMenu 7E3B531E 5 Bytes JMP 1043B50D C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) ---- EOF - GMER 1.0.15 ----