GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2012-09-01 09:36:40 Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD3200AAJB-00J3A0 rev.01.03E01 Running: 66mfmp7j.exe; Driver: C:\DOCUME~1\DOM\USTAWI~1\Temp\uwtdqpob.sys ---- Kernel code sections - GMER 1.0.15 ---- .text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF6DEA000, 0x1C5D38, 0xE8000020] ---- Disk sectors - GMER 1.0.15 ---- Disk \Device\Harddisk0\DR0 malicious Win32:MBRoot code @ sector 625121283 Disk \Device\Harddisk0\DR0 PE file @ sector 625121305 ---- EOF - GMER 1.0.15 ----