GMER 2.1.19163 - http://www.gmer.net Rootkit scan 2013-09-06 11:55:22 Windows 5.1.2600 Dodatek Service Pack 2 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-10 SAMSUNG_HD250HJ rev.FH100-05 232,88GB Running: ddjftc0q.exe; Driver: C:\DOCUME~1\WACICI~1.SIC\USTAWI~1\Temp\kwacapoc.sys ---- Kernel code sections - GMER 2.1 ---- .sfrelocÿÿÿÿsfsync03unknown last section [0xF7644000, 0xA20, 0x40000040] C:\WINDOWS\system32\drivers\sfsync03.sys unknown last section [0xF7644000, 0xA20, 0x40000040] .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB6E993C0, 0x843B7A, 0xE8000020] ---- Devices - GMER 2.1 ---- Device \Driver\USBSTOR \Device\00000063 sfsync03.sys Device \Driver\USBSTOR \Device\00000064 sfsync03.sys Device \Driver\atapi \Device\Ide\IdePort0 sfsync03.sys Device \Driver\atapi \Device\Ide\IdePort1 sfsync03.sys Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-5 sfsync03.sys Device \Driver\atapi \Device\Ide\IdePort2 sfsync03.sys Device \Driver\atapi \Device\Ide\IdePort3 sfsync03.sys Device \Driver\atapi \Device\Ide\IdeDeviceP3T0L0-10 sfsync03.sys ---- EOF - GMER 2.1 ----