GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2012-08-13 21:51:21 Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 ST340016A rev.3.19 Running: m955i2pj.exe; Driver: C:\DOCUME~1\Ewa\USTAWI~1\Temp\pwddrpob.sys ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\Mozilla Firefox\firefox.exe[1616] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 0117B52A C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[1616] kernel32.dll!lstrlenW + 43 7C809AEC 7 Bytes JMP 0142B6F5 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[1616] kernel32.dll!MapViewOfFileEx + 6A 7C80B9A0 7 Bytes JMP 0142B6D2 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[1616] GDI32.dll!SetDIBitsToDevice + 20A 77F19E14 7 Bytes JMP 0142B653 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[2328] USER32.dll!DefWindowProcA + 11A 7E37C298 7 Bytes JMP 1067C453 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[2328] USER32.dll!SetWindowLongA + 19 7E37C2B6 7 Bytes JMP 1067C3E2 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[2328] USER32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 1043BACC C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[2328] USER32.dll!GetMenuContextHelpId + 1A 7E3B5319 7 Bytes JMP 1043C0F9 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001b10000706 Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001f81000830 Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001b10000706 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001f81000830 (not active ControlSet) ---- EOF - GMER 1.0.15 ----