GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-08-12 11:43:44 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdePort0 WDC_WD3200AAKS-00L9A0 rev.01.03E01 298,09GB Running: gmer.exe; Driver: C:\DOCUME~1\Pawel005\USTAWI~1\Temp\pxtdapow.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB51783C0, 0x83E20A, 0xE8000020] ---- User code sections - GMER 2.1 ---- .data C:\WINDOWS\system\svchost.exe[1904] C:\WINDOWS\system\svchost.exe unknown last section [0x00419000, 0x4B50, 0xC0000040] .text D:\Progamy\Mozilla Firefox\firefox.exe[3916] ntdll.dll!NtCreateFile 7C90D090 5 Bytes JMP 018D3D20 D:\Progamy\Mozilla Firefox\xul.dll .text D:\Progamy\Mozilla Firefox\firefox.exe[3916] ntdll.dll!NtFlushBuffersFile 7C90D310 5 Bytes JMP 018BC661 D:\Progamy\Mozilla Firefox\xul.dll .text D:\Progamy\Mozilla Firefox\firefox.exe[3916] ntdll.dll!NtQueryFullAttributesFile 7C90D790 5 Bytes JMP 018D3820 D:\Progamy\Mozilla Firefox\xul.dll .text D:\Progamy\Mozilla Firefox\firefox.exe[3916] ntdll.dll!NtReadFile 7C90D9B0 5 Bytes JMP 018BC750 D:\Progamy\Mozilla Firefox\xul.dll .text D:\Progamy\Mozilla Firefox\firefox.exe[3916] ntdll.dll!NtReadFileScatter 7C90D9C0 5 Bytes JMP 0215E1FF D:\Progamy\Mozilla Firefox\xul.dll .text D:\Progamy\Mozilla Firefox\firefox.exe[3916] ntdll.dll!NtWriteFile 7C90DF60 5 Bytes JMP 018D43D0 D:\Progamy\Mozilla Firefox\xul.dll .text D:\Progamy\Mozilla Firefox\firefox.exe[3916] ntdll.dll!NtWriteFileGather 7C90DF70 5 Bytes JMP 0215E1AE D:\Progamy\Mozilla Firefox\xul.dll .text D:\Progamy\Mozilla Firefox\firefox.exe[3916] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 10001F4C D:\Progamy\Mozilla Firefox\mozglue.dll .text D:\Progamy\Mozilla Firefox\firefox.exe[3916] kernel32.dll!lstrlenW + 43 7C809ADC 7 Bytes JMP 020FF582 D:\Progamy\Mozilla Firefox\xul.dll .text D:\Progamy\Mozilla Firefox\firefox.exe[3916] kernel32.dll!MapViewOfFileEx + 6A 7C80B990 7 Bytes JMP 020FF55F D:\Progamy\Mozilla Firefox\xul.dll .text D:\Progamy\Mozilla Firefox\firefox.exe[3916] kernel32.dll!ValidateLocale + B1E8 7C8449F8 7 Bytes JMP 018D06F3 D:\Progamy\Mozilla Firefox\xul.dll .text D:\Progamy\Mozilla Firefox\firefox.exe[3916] GDI32.dll!SetDIBitsToDevice + 209 77F19E04 7 Bytes JMP 020FF4E0 D:\Progamy\Mozilla Firefox\xul.dll .text D:\Progamy\Mozilla Firefox\firefox.exe[3916] USER32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 0200E5A9 D:\Progamy\Mozilla Firefox\xul.dll ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Control\Video\{80B23931-3848-4F6B-9AC2-B50CE7D20C64}\0000@D3D_\x3332\x3331 2089309684 Reg HKLM\SYSTEM\ControlSet002\Control\Video\{80B23931-3848-4F6B-9AC2-B50CE7D20C64}\0000@D3D_\x3332\x3331 2089309684 ---- EOF - GMER 2.1 ----