GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2012-06-27 19:51:43 Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 TOSHIBA_MK2546GSX rev.LB014C Running: gmer.exe; Driver: C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\pxtdipob.sys ---- User code sections - GMER 1.0.15 ---- .text D:\FIREFOX\plugin-container.exe[1064] USER32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 1044FE0A D:\FIREFOX\xul.dll (Mozilla Foundation) .text D:\FIREFOX\plugin-container.exe[1064] USER32.dll!TrackPopupMenu 7E3B531E 5 Bytes JMP 104503C5 D:\FIREFOX\xul.dll (Mozilla Foundation) .text D:\FIREFOX\firefox.exe[1580] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 01269720 D:\FIREFOX\xul.dll (Mozilla Foundation) .text D:\FIREFOX\firefox.exe[1580] kernel32.dll!VirtualAlloc 7C809AF1 5 Bytes JMP 0149E21B D:\FIREFOX\xul.dll (Mozilla Foundation) .text D:\FIREFOX\firefox.exe[1580] kernel32.dll!MapViewOfFile 7C80B9A5 5 Bytes JMP 0149E1F4 D:\FIREFOX\xul.dll (Mozilla Foundation) .text D:\FIREFOX\firefox.exe[1580] GDI32.dll!CreateDIBSection 77F19E19 5 Bytes JMP 0149E17E D:\FIREFOX\xul.dll (Mozilla Foundation) ---- Devices - GMER 1.0.15 ---- AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.) AttachedDevice \Driver\Tcpip \Device\Tcp aswRdr.SYS (avast! TDI Redirect Driver/AVAST Software) ---- Disk sectors - GMER 1.0.15 ---- Disk \Device\Harddisk0\DR0 malicious Win32:MBRoot code @ sector 488392068 ---- EOF - GMER 1.0.15 ----