GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-02-28 15:27:37 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 ST3802110A rev.3.AAD 74,53GB Running: 6hz3d2u8.exe; Driver: C:\DOCUME~1\DOM\USTAWI~1\Temp\awpdifow.sys ---- System - GMER 2.1 ---- SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwNotifyChangeKey [0xF77A86E0] SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwNotifyChangeMultipleKeys [0xF77A8800] SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwOpenProcess [0xF77A8010] SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwOpenThread [0xF77A84D0] SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwSuspendProcess [0xF77A8300] SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwSuspendThread [0xF77A83E0] SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwTerminateProcess [0xF77A8120] SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwTerminateThread [0xF77A8210] SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwWriteVirtualMemory [0xF77A85E0] ---- Kernel code sections - GMER 2.1 ---- .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xBA014360, 0x372FAD, 0xE8000020] ---- User code sections - GMER 2.1 ---- .text C:\Program Files\Mozilla Firefox\firefox.exe[3176] ntdll.dll!NtCreateFile 7C90D090 5 Bytes JMP 01829AE0 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3176] ntdll.dll!NtFlushBuffersFile 7C90D310 5 Bytes JMP 0180C434 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3176] ntdll.dll!NtQueryFullAttributesFile 7C90D790 5 Bytes JMP 0180C150 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3176] ntdll.dll!NtReadFile 7C90D9B0 5 Bytes JMP 0180C330 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3176] ntdll.dll!NtReadFileScatter 7C90D9C0 5 Bytes JMP 0222F60F C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3176] ntdll.dll!NtWriteFile 7C90DF60 5 Bytes JMP 0182A9F0 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3176] ntdll.dll!NtWriteFileGather 7C90DF70 5 Bytes JMP 0222F5BE C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3176] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 10001F42 C:\Program Files\Mozilla Firefox\mozglue.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3176] kernel32.dll!lstrlenW + 43 7C809ADC 7 Bytes JMP 02154AC3 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3176] kernel32.dll!MapViewOfFileEx + 6A 7C80B990 7 Bytes JMP 02154AA0 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3176] kernel32.dll!ValidateLocale + B1E8 7C8449F8 7 Bytes JMP 018263D0 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3176] GDI32.dll!SetDIBitsToDevice + 209 77F19E04 7 Bytes JMP 02154A21 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3176] USER32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 0204B991 C:\Program Files\Mozilla Firefox\xul.dll ---- Devices - GMER 2.1 ---- AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys ---- Files - GMER 2.1 ---- File C:\Documents and Settings\DOM\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\6j7e5b30.default\cache2\entries\90CD4A25703027AA88C3AD7E9FBA524F0EE4FF73 900 bytes File C:\Documents and Settings\DOM\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\6j7e5b30.default\cache2\entries\C4E71098732A39D277803A067E3D7ACE3DFBCB32 900 bytes ---- EOF - GMER 2.1 ----