GMER 2.1.19163 - http://www.gmer.net Rootkit scan 2013-12-28 16:36:52 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 Hitachi_HDS721616PLA380 rev.P22OABEA 149,05GB Running: p57mqb86.exe; Driver: C:\DOCUME~1\dom\USTAWI~1\Temp\awldypow.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3308] USER32.dll!DefWindowProcA + 11A 7E37C298 7 Bytes JMP 1060B55A C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3308] USER32.dll!SetWindowLongA + 19 7E37C2B6 7 Bytes JMP 1060B5CB C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3308] USER32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 1060F36E C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3308] USER32.dll!GetMenuContextHelpId + 1A 7E3B5319 7 Bytes JMP 10608DFA C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 0172B780 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] kernel32.dll!lstrlenW + 43 7C809AEC 7 Bytes JMP 01F66EFD C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] kernel32.dll!MapViewOfFileEx + 6A 7C80B9A0 7 Bytes JMP 01F66EDA C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] kernel32.dll!ValidateLocale + B1C8 7C8449C8 7 Bytes JMP 01730836 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] USER32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 01E0B28C C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] GDI32.dll!SetDIBitsToDevice + 20A 77F19E14 7 Bytes JMP 01F66E5B C:\Program Files\Mozilla Firefox\xul.dll ---- Devices - GMER 2.1 ---- AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys ---- Registry - GMER 2.1 ---- Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\HP Officejet 5600 series@ChangeID 19442890 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\HP Officejet 5600 series fax@ChangeID 19441859 ---- EOF - GMER 2.1 ----