GMER 2.1.19324 - http://www.gmer.net Rootkit scan 2014-01-19 16:19:35 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD3200AVJS-63WDA0 rev.12.01B02 298.09GB Running: e3uxrt1r.exe; Driver: C:\DOCUME~1\Zurawski\USTAWI~1\Temp\kweiqpob.sys ---- Kernel code sections - GMER 2.1 ---- ? Combo-Fix.sys Nie można odnaleźć określonego pliku. ! .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB718E3C0, 0x7FDE3A, 0xE8000020] ? C:\ComboFix\catchme.sys System nie może odnaleźć określonej ścieżki. ! ? C:\WINDOWS\system32\Drivers\PROCEXP113.SYS Nie można odnaleźć określonego pliku. ! ---- User code sections - GMER 2.1 ---- .text C:\Program Files\Mozilla Firefox\plugin-container.exe[2704] USER32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 1060F36E C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\plugin-container.exe[2704] USER32.dll!GetMenuContextHelpId + 1A 7E3B5319 7 Bytes JMP 10608DFA C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3512] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0172B780 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3512] kernel32.dll!lstrlenW + 43 7C809ADC 7 Bytes JMP 01F66EFD C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3512] kernel32.dll!MapViewOfFileEx + 6A 7C80B990 7 Bytes JMP 01F66EDA C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3512] kernel32.dll!ValidateLocale + B1E8 7C8449F8 7 Bytes JMP 01730836 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3512] GDI32.dll!SetDIBitsToDevice + 209 77F19E04 7 Bytes JMP 01F66E5B C:\Program Files\Mozilla Firefox\xul.dll ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\ControlSet001\Control\Video\{B4D0C0F7-7757-4CCE-98EF-6C9B8D094558}\0000@D3D_\x3332\x3331 2089309684 Reg HKLM\SYSTEM\ControlSet002\Control\Video\{B4D0C0F7-7757-4CCE-98EF-6C9B8D094558}\0000@D3D_\x3332\x3331 2089309684 Reg HKLM\SYSTEM\CurrentControlSet\Control\Video\{B4D0C0F7-7757-4CCE-98EF-6C9B8D094558}\0000@D3D_\x3332\x3331 2089309684 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0347C33E-8762-4905-BF09-768834316C61}\iexplore@Count 303 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\2\Shell@ScrollPos1024x768(1).y 0