GMER 2.1.19163 - http://www.gmer.net Rootkit scan 2013-10-01 21:12:10 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e ST3160812A rev.2AAA 149,05GB Running: bk9xkvlt.exe; Driver: C:\DOCUME~1\xp\USTAWI~1\Temp\pxtdipow.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF6C4E360, 0x372FAD, 0xE8000020] ---- User code sections - GMER 2.1 ---- .text C:\WINDOWS\system32\winlogon.exe[632] ntdll.dll!NtLockProductActivationKeys 7C90D490 5 Bytes JMP 10001000 C:\WINDOWS\system32\antiwpa.dll .text C:\WINDOWS\system32\winlogon.exe[632] USER32.dll!GetSystemMetrics 7E368F9C 5 Bytes JMP 10001018 C:\WINDOWS\system32\antiwpa.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3160] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 015EDFF0 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3160] kernel32.dll!lstrlenW + 43 7C809ADC 7 Bytes JMP 01D79796 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3160] kernel32.dll!MapViewOfFileEx + 6A 7C80B990 7 Bytes JMP 01D79773 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3160] kernel32.dll!ValidateLocale + B1E8 7C8449F8 7 Bytes JMP 015F5F1A C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3160] GDI32.dll!SetDIBitsToDevice + 209 77F19E04 7 Bytes JMP 01D796F4 C:\Program Files\Mozilla Firefox\xul.dll ---- EOF - GMER 2.1 ----