GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-04-13 12:49:21 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST3320418AS rev.CC38 298,09GB Running: zlyh0vvu.exe; Driver: C:\DOCUME~1\Admin\USTAWI~1\Temp\ffndakoc.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files\Mozilla Firefox\firefox.exe[2980] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10001FD9 C:\Program Files\Mozilla Firefox\mozglue.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2980] kernel32.dll!lstrlenW + 43 7C809AEC 7 Bytes JMP 022F4104 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2980] kernel32.dll!MapViewOfFileEx + 6A 7C80B9A0 7 Bytes JMP 022F40E1 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2980] kernel32.dll!ValidateLocale + B648 7C844EE0 7 Bytes JMP 019C3255 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2980] GDI32.dll!SetDIBitsToDevice + 20A 77F19E14 7 Bytes JMP 022F4062 C:\Program Files\Mozilla Firefox\xul.dll ---- Devices - GMER 2.1 ---- AttachedDevice \Driver\Tcpip \Device\Ip arcawfp.sys AttachedDevice \Driver\Tcpip \Device\Tcp arcawfp.sys AttachedDevice \Driver\Tcpip \Device\Udp arcawfp.sys AttachedDevice \Driver\Tcpip \Device\RawIp arcawfp.sys ---- EOF - GMER 2.1 ----