GMER 2.1.19163 - http://www.gmer.net Rootkit scan 2013-07-12 23:41:50 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-e ST9120822AS rev.3.ALD 111,79GB Running: 82yztgwb.exe; Driver: C:\DOCUME~1\User\USTAWI~1\Temp\uwlcyaob.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF67FF380, 0x2F1147, 0xE8000020] ? C:\WINDOWS\system32\drivers\blzblk.sys Nie można odnaleźć określonego pliku. ! ---- User code sections - GMER 2.1 ---- .text C:\Program Files\Mozilla Firefox\firefox.exe[2464] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0171EEB0 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2464] kernel32.dll!lstrlenW + 43 7C809ADC 7 Bytes JMP 01D2979B C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2464] kernel32.dll!MapViewOfFileEx + 6A 7C80B990 7 Bytes JMP 01D29778 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2464] kernel32.dll!ValidateLocale + B1E8 7C8449F8 7 Bytes JMP 01724CE9 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2464] GDI32.dll!SetDIBitsToDevice + 209 77F19E04 7 Bytes JMP 01D296F9 C:\Program Files\Mozilla Firefox\xul.dll ---- Devices - GMER 2.1 ---- AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys ---- Registry - GMER 2.1 ---- Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@Taskman C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-8763\lsq.exe (Privacy Assist/GPA)(2011-03-20 14:32:48) ---- EOF - GMER 2.1 ----