GMER 1.0.15.15530 - http://www.gmer.net Rootkit scan 2010-11-21 15:01:17 Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-3 SAMSUNG_HD252HJ rev.1AC01118 Running: ri1um1n5.exe; Driver: C:\DOCUME~1\Piotrek\USTAWI~1\Temp\aflorpob.sys ---- System - GMER 1.0.15 ---- SSDT BA6BD33E ZwCreateKey SSDT BA6BD334 ZwCreateThread SSDT BA6BD343 ZwDeleteKey SSDT BA6BD34D ZwDeleteValueKey SSDT BA6BD352 ZwLoadKey SSDT BA6BD320 ZwOpenProcess SSDT BA6BD325 ZwOpenThread SSDT BA6BD35C ZwReplaceKey SSDT BA6BD357 ZwRestoreKey SSDT BA6BD348 ZwSetValueKey ---- Kernel code sections - GMER 1.0.15 ---- .text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xB98A4000, 0x253E67, 0xE8000020] ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\Tunngle\TnglCtrl.exe[676] ntdll.dll!DbgBreakPoint 7C90120E 1 Byte [90] .text C:\Program Files\Mozilla Firefox\plugin-container.exe[1808] USER32.dll!TrackPopupMenu 7E3B531E 5 Bytes JMP 10405CF5 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Pando Networks\Media Booster\PMB.exe[2168] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4} .text C:\Program Files\Mozilla Firefox\firefox.exe[3952] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation) ---- EOF - GMER 1.0.15 ----