GMER 2.1.19155 - http://www.gmer.net Rootkit scan 2013-03-13 12:11:21 Windows 5.1.2600 Dodatek Service Pack 2 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 TOSHIBA_MK6026GAX rev.PA200U 55,89GB Running: f37k14tx.exe; Driver: C:\DOCUME~1\Jarek\USTAWI~1\Temp\pxtdypow.sys ---- System - GMER 2.1 ---- SSDT 840E7868 ZwConnectPort ---- Kernel code sections - GMER 2.1 ---- init C:\WINDOWS\system32\drivers\mpfilt.sys entry point in "init" section [0xF7A622A0] ? System32\Drivers\SYMTDI.SYS System nie może odnaleźć określonej ścieżki. ! ? C:\Program Files\Symantec\SYMEVENT.SYS System nie może odnaleźć określonej ścieżki. ! ---- User code sections - GMER 2.1 ---- .text C:\Program Files\MSN Toolbar Suite\DS\02.05.0000.1082\en-gb\bin\WindowsSearchIndexer.exe[2240] kernel32.dll!WriteFile 7C810F9F 7 Bytes JMP 646A05C2 C:\Program Files\MSN Toolbar Suite\DS\02.05.0000.1082\en-gb\bin\mssrch.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3128] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0153D180 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3128] kernel32.dll!lstrlenW + 43 7C809A7C 7 Bytes JMP 01886B9C C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3128] kernel32.dll!MapViewOfFileEx + 6A 7C80B788 7 Bytes JMP 01886B79 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3128] kernel32.dll!lstrcpyn + 70 7C810381 7 Bytes JMP 0154F84B C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3128] GDI32.dll!SetWindowOrgEx + 15E 77F1960B 7 Bytes JMP 01886AFA C:\Program Files\Mozilla Firefox\xul.dll ---- Devices - GMER 2.1 ---- AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS Device \FileSystem\Cdfs \Cdfs tfsnifs.sys ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ----