GMER 2.1.19163 - http://www.gmer.net Rootkit scan 2013-04-17 20:21:51 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD1600BEVT-22ZCT0 rev.11.01A11 149,05GB Running: t9sogzy0.exe; Driver: C:\DOCUME~1\MSI\USTAWI~1\Temp\fxrdypow.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB8E0B360, 0x2FE337, 0xE8000020] ---- User code sections - GMER 2.1 ---- .text C:\Program Files\Mozilla Firefox\firefox.exe[2884] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 01596D70 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2884] kernel32.dll!lstrlenW + 43 7C809AEC 7 Bytes JMP 018ED736 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2884] kernel32.dll!MapViewOfFileEx + 6A 7C80B9A0 7 Bytes JMP 018ED713 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2884] kernel32.dll!ValidateLocale + B1C8 7C8449C8 7 Bytes JMP 015B1C62 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2884] GDI32.dll!SetDIBitsToDevice + 20A 77F19E14 7 Bytes JMP 018ED694 C:\Program Files\Mozilla Firefox\xul.dll ---- Devices - GMER 2.1 ---- Device Ntfs.sys AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys Device mrxsmb.sys Device Cdfs.SYS ---- EOF - GMER 2.1 ----