GMER 1.0.15.15530 - http://www.gmer.net Rootkit scan 2010-11-25 16:58:57 Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\0000005f SAMSUNG_HD502HJ rev.1AJ10001 Running: gmer.exe; Driver: C:\DOCUME~1\birdas\USTAWI~1\Temp\fxtdqpob.sys ---- Kernel code sections - GMER 1.0.15 ---- .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB8FB4360, 0x372FAD, 0xE8000020] ---- User code sections - GMER 1.0.15 ---- .text C:\WINDOWS\system32\WISPTIS.EXE[432] WS2_32.dll!closesocket 71A53E2B 5 Bytes JMP 00FAB48B .text C:\WINDOWS\system32\WISPTIS.EXE[432] WS2_32.dll!send 71A54C27 5 Bytes JMP 00FAB028 .text C:\WINDOWS\system32\WISPTIS.EXE[432] WS2_32.dll!WSARecv 71A54CB5 5 Bytes JMP 00FAB33D .text C:\WINDOWS\system32\WISPTIS.EXE[432] WS2_32.dll!recv 71A5676F 5 Bytes JMP 00FAB109 .text C:\WINDOWS\system32\WISPTIS.EXE[432] WS2_32.dll!WSASend 71A568FA 5 Bytes JMP 00FAB1DC .text C:\WINDOWS\System32\alg.exe[532] WS2_32.dll!closesocket 71A53E2B 5 Bytes JMP 00B8B48B .text C:\WINDOWS\System32\alg.exe[532] WS2_32.dll!send 71A54C27 5 Bytes JMP 00B8B028 .text C:\WINDOWS\System32\alg.exe[532] WS2_32.dll!WSARecv 71A54CB5 5 Bytes JMP 00B8B33D .text C:\WINDOWS\System32\alg.exe[532] WS2_32.dll!recv 71A5676F 5 Bytes JMP 00B8B109 .text C:\WINDOWS\System32\alg.exe[532] WS2_32.dll!WSASend 71A568FA 5 Bytes JMP 00B8B1DC .text C:\WINDOWS\system32\winlogon.exe[644] Secur32.dll!LsaLogonUser 77FE33D8 5 Bytes JMP 01A12946 .text C:\Program Files\Java\jre6\bin\jqs.exe[1060] WS2_32.dll!closesocket 71A53E2B 5 Bytes JMP 017FB48B .text C:\Program Files\Java\jre6\bin\jqs.exe[1060] WS2_32.dll!send 71A54C27 5 Bytes JMP 017FB028 .text C:\Program Files\Java\jre6\bin\jqs.exe[1060] WS2_32.dll!WSARecv 71A54CB5 5 Bytes JMP 017FB33D .text C:\Program Files\Java\jre6\bin\jqs.exe[1060] WS2_32.dll!recv 71A5676F 5 Bytes JMP 017FB109 .text C:\Program Files\Java\jre6\bin\jqs.exe[1060] WS2_32.dll!WSASend 71A568FA 5 Bytes JMP 017FB1DC .text C:\WINDOWS\Explorer.EXE[1448] USER32.dll!DisplayExitWindowsWarnings 7E3A9F91 5 Bytes JMP 01F12758 .text C:\WINDOWS\Explorer.EXE[1448] WS2_32.dll!closesocket 71A53E2B 5 Bytes JMP 01E2B48B .text C:\WINDOWS\Explorer.EXE[1448] WS2_32.dll!send 71A54C27 5 Bytes JMP 01E2B028 .text C:\WINDOWS\Explorer.EXE[1448] WS2_32.dll!WSARecv 71A54CB5 5 Bytes JMP 01E2B33D .text C:\WINDOWS\Explorer.EXE[1448] WS2_32.dll!recv 71A5676F 5 Bytes JMP 01E2B109 .text C:\WINDOWS\Explorer.EXE[1448] WS2_32.dll!WSASend 71A568FA 5 Bytes JMP 01E2B1DC .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1676] WS2_32.dll!closesocket 71A53E2B 5 Bytes JMP 00D8B48B .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1676] WS2_32.dll!send 71A54C27 5 Bytes JMP 00D8B028 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1676] WS2_32.dll!WSARecv 71A54CB5 5 Bytes JMP 00D8B33D .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1676] WS2_32.dll!recv 71A5676F 5 Bytes JMP 00D8B109 .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[1676] WS2_32.dll!WSASend 71A568FA 5 Bytes JMP 00D8B1DC .text C:\Program Files\Gadu-Gadu 10\gg.exe[1708] WS2_32.dll!closesocket 71A53E2B 5 Bytes JMP 07F5B48B .text C:\Program Files\Gadu-Gadu 10\gg.exe[1708] WS2_32.dll!send 71A54C27 5 Bytes JMP 07F5B028 .text C:\Program Files\Gadu-Gadu 10\gg.exe[1708] WS2_32.dll!WSARecv 71A54CB5 5 Bytes JMP 07F5B33D .text C:\Program Files\Gadu-Gadu 10\gg.exe[1708] WS2_32.dll!recv 71A5676F 5 Bytes JMP 07F5B109 .text C:\Program Files\Gadu-Gadu 10\gg.exe[1708] WS2_32.dll!WSASend 71A568FA 5 Bytes JMP 07F5B1DC .text C:\Program Files\Mozilla Firefox\firefox.exe[3048] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3240] WS2_32.dll!closesocket 71A53E2B 5 Bytes JMP 0268B48B .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3240] WS2_32.dll!send 71A54C27 5 Bytes JMP 0268B028 .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3240] WS2_32.dll!WSARecv 71A54CB5 5 Bytes JMP 0268B33D .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3240] WS2_32.dll!recv 71A5676F 5 Bytes JMP 0268B109 .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3240] WS2_32.dll!WSASend 71A568FA 5 Bytes JMP 0268B1DC .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3240] USER32.dll!TrackPopupMenu 7E3B531E 5 Bytes JMP 10405CF5 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) ---- EOF - GMER 1.0.15 ----