GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-03-15 19:37:16 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-19 ST500DM002-1BD142 rev.KC44 465,76GB Running: 6m3zfmnh.exe; Driver: C:\DOCUME~1\BERGER~2.XP-\USTAWI~1\Temp\fwryrkob.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB2C59380, 0x8D6CD5, 0xE8000020] ? C:\DOCUME~1\BERGER~2.XP-\USTAWI~1\Temp\ALSysIO.sys Nazwa pliku, nazwa katalogu lub składnia etykiety woluminu jest niepoprawna.! ---- User code sections - GMER 2.1 ---- .text C:\Program Files\Mozilla Firefox\firefox.exe[2252] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 01653300 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2252] kernel32.dll!lstrlenW + 43 7C809ADC 7 Bytes JMP 0189DF1C C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2252] kernel32.dll!MapViewOfFileEx + 6A 7C80B990 7 Bytes JMP 0189DEF9 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2252] kernel32.dll!ValidateLocale + B1E8 7C8449F8 7 Bytes JMP 0165DEB7 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2252] GDI32.dll!SetDIBitsToDevice + 209 7 7F19E04 7 Bytes JMP 0189DE7A C:\Program Files\Mozilla Firefox\xul.dll ---- Registry - GMER 2.1 ---- Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\8\Shell@WFlags 0 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\8\Shell@ShowCmd 1 ---- EOF - GMER 2.1 ----