GMER 2.0.18444 - http://www.gmer.net Rootkit scan 2013-01-27 20:55:11 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-3 WDC_WD800JD-75MSA3 rev.10.01E04 74,50GB Running: 4x3t6mo0.exe; Driver: C:\DOCUME~1\Herman\USTAWI~1\Temp\kwpdrkod.sys ---- System - GMER 2.0 ---- SSDT \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys ZwCreateSection [0xF7AF5700] ---- Kernel code sections - GMER 2.0 ---- .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF68A93C0, 0x706FCA, 0xE8000020] ---- User code sections - GMER 2.0 ---- .text C:\WINDOWS\System32\svchost.exe[1112] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes JMP 02409DD2 .text C:\WINDOWS\System32\svchost.exe[1112] NETAPI32.dll!NetpwPathCanonicalize 6FF4A3A9 5 Bytes JMP 02409D72 .text C:\WINDOWS\system32\svchost.exe[1172] ntdll.dll!NtQueryInformationProcess 7C90D7E0 5 Bytes JMP 00829DD2 .text C:\Program Files\Mozilla Firefox\plugin-container.exe[1580] USER32.dll!DefWindowProcA + 11A 7E37C298 7 Bytes JMP 107F56D7 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[1580] USER32.dll!SetWindowLongA + 19 7E37C2B6 7 Bytes JMP 107F5666 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[1580] USER32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 1044B5C8 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\plugin-container.exe[1580] USER32.dll!GetMenuContextHelpId + 1A 7E3B5319 7 Bytes JMP 1044BB81 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[1812] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0155C5B0 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[1812] kernel32.dll!lstrlenW + 43 7C809ADC 7 Bytes JMP 018A61C7 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[1812] kernel32.dll!MapViewOfFileEx + 6A 7C80B990 7 Bytes JMP 018A61A4 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[1812] kernel32.dll!ValidateLocale + B1E8 7C8449F8 7 Bytes JMP 0157544E C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text C:\Program Files\Mozilla Firefox\firefox.exe[1812] GDI32.dll!SetDIBitsToDevice + 209 77F19E04 7 Bytes JMP 018A6125 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) ---- Registry - GMER 2.0 ---- Reg HKLM\SYSTEM\CurrentControlSet\Control\Video\{9F607933-90AC-4445-BB75-240AF292F97D}\0000@D3D_\x3332\x3331 2089309684 ---- EOF - GMER 2.0 ----