GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2012-10-25 23:46:32 Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e ST3120827AS rev.3.42 Running: qy661sjz.exe; Driver: C:\DOCUME~1\Rafal\USTAWI~1\Temp\ufrdapob.sys ---- Kernel code sections - GMER 1.0.15 ---- .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF65F33C0, 0x95AECA, 0xE8000020] ---- User code sections - GMER 1.0.15 ---- ÒuÛŠëÔÿÿÿÿservicesentry point in "ÒuÛŠëÔÿÿÿÿservicesentry point in "" section [0x00431B68] C:\Documents and Settings\Rafal\Ustawienia lokalne\Dane aplikacji\services.exe[268] C:\Documents and Settings\Rafal\Ustawienia lokalne\Dane aplikacji\services.exe entry point in "ÒuÛŠëÔÿÿÿÿservicesentry point in "" section [0x00431B68] ÒuÛŠëÔÿÿÿÿservicesunknown last code section [0x00427000, 0x19000, 0xC00000E0] C:\Documents and Settings\Rafal\Ustawienia lokalne\Dane aplikacji\services.exe[268] C:\Documents and Settings\Rafal\Ustawienia lokalne\Dane aplikacji\services.exe unknown last code section [0x00427000, 0x19000, 0xC00000E0] .text C:\Program Files\Mozilla Firefox\firefox.exe[1240] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0149A650 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[1240] kernel32.dll!lstrlenW + 43 7C809ADC 7 Bytes JMP 016D7E1A C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[1240] kernel32.dll!MapViewOfFileEx + 6A 7C80B990 7 Bytes JMP 016D7DF7 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[1240] kernel32.dll!ValidateLocale + B1E8 7C8449F8 7 Bytes JMP 0149EDB3 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[1240] GDI32.dll!SetDIBitsToDevice + 209 77F19E04 7 Bytes JMP 016D7D78 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) ÒuÛŠëÔÿÿÿÿwinlogonentry point in "ÒuÛŠëÔÿÿÿÿwinlogonentry point in "" section [0x00431B68] C:\Documents and Settings\Rafal\Ustawienia lokalne\Dane aplikacji\winlogon.exe[1312] C:\Documents and Settings\Rafal\Ustawienia lokalne\Dane aplikacji\winlogon.exe entry point in "ÒuÛŠëÔÿÿÿÿwinlogonentry point in "" section [0x00431B68] ÒuÛŠëÔÿÿÿÿwinlogonunknown last code section [0x00427000, 0x19000, 0xC00000E0] C:\Documents and Settings\Rafal\Ustawienia lokalne\Dane aplikacji\winlogon.exe[1312] C:\Documents and Settings\Rafal\Ustawienia lokalne\Dane aplikacji\winlogon.exe unknown last code section [0x00427000, 0x19000, 0xC00000E0] .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3296] USER32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 104247EC C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3296] USER32.dll!GetMenuContextHelpId + 1A 7E3B5319 7 Bytes JMP 10424E1E C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) ---- Files - GMER 1.0.15 ---- File C:\Documents and Settings\Rafal\Ustawienia lokalne\Dane aplikacji\Nokia\Nokia Data Store\DataBase\MDATAS~1.DB3-journal 0 bytes ---- EOF - GMER 1.0.15 ----