GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-03-18 16:22:44 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-19 ST500DM002-1BD142 rev.KC44 465,76GB Running: gmer.exe; Driver: C:\DOCUME~1\BERGER~2.XP-\USTAWI~1\Temp\fwryrkob.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB2DCE3C0, 0x829A2A, 0xE8000020] ? C:\DOCUME~1\BERGER~2.XP-\USTAWI~1\Temp\ALSysIO.sys Nazwa pliku, nazwa katalogu lub składnia etykiety woluminu jest niepoprawna. ! ---- User code sections - GMER 2.1 ---- .text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[2772] ntdll.dll!NtQueryVirtualMemory + 6 7C90D966 4 Bytes [DC, 81, 9D, 00] .text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[2772] kernel32.dll!SetUnhandledExceptionFilter 7C8449FD 5 Bytes JMP 32605629 ---- Processes - GMER 2.1 ---- Library C:\Program Files\Microsoft Office\Office12\WINWORD.EXE (*** hidden *** ) @ C:\Program Files\Microsoft Office\Office12\WINWORD.EXE [2772] 0x30000000 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Control\Video\{0E05E4B2-C606-4635-9711-D25005921B6A}\0000@D3D_\x3332\x3331 2089309684 Reg HKLM\SYSTEM\CurrentControlSet\Control\Video\{3A9163A2-C9F5-4566-93F6-880DAB05F7C3}\0000@D3D_\x3332\x3331 2089309684 Reg HKLM\SYSTEM\CurrentControlSet\Control\Video\{9368827E-9296-4EA0-BBD8-C23C898E590B}\0000@D3D_\x3332\x3331 2089309684 Reg HKLM\SYSTEM\CurrentControlSet\Control\Video\{CA7C261A-4668-4463-B618-759CCC099B33}\0000@D3D_\x3332\x3331 2089309684 Reg HKLM\SYSTEM\CurrentControlSet\Control\Video\{D2798D5D-C5E3-465F-8EA8-06BB6C946E66}\0000@D3D_\x3332\x3331 2089309684 Reg HKLM\SYSTEM\CurrentControlSet\Control\Video\{D2A15BB8-3B27-4BCA-8AC4-0300F19AA559}\0000@D3D_\x3332\x3331 2089309684 Reg HKLM\SYSTEM\ControlSet003\Control\Video\{0E05E4B2-C606-4635-9711-D25005921B6A}\0000@D3D_\x3332\x3331 2089309684 Reg HKLM\SYSTEM\ControlSet003\Control\Video\{3A9163A2-C9F5-4566-93F6-880DAB05F7C3}\0000@D3D_\x3332\x3331 2089309684 Reg HKLM\SYSTEM\ControlSet003\Control\Video\{9368827E-9296-4EA0-BBD8-C23C898E590B}\0000@D3D_\x3332\x3331 2089309684 Reg HKLM\SYSTEM\ControlSet003\Control\Video\{CA7C261A-4668-4463-B618-759CCC099B33}\0000@D3D_\x3332\x3331 2089309684 Reg HKLM\SYSTEM\ControlSet003\Control\Video\{D2798D5D-C5E3-465F-8EA8-06BB6C946E66}\0000@D3D_\x3332\x3331 2089309684 Reg HKLM\SYSTEM\ControlSet003\Control\Video\{D2A15BB8-3B27-4BCA-8AC4-0300F19AA559}\0000@D3D_\x3332\x3331 2089309684 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher@TracesProcessed 31 Reg HKLM\SOFTWARE\Classes\Zanoza.3DEditor.Document\DefaultIcon@ D:\MOJEDO~1\Profil1\NOWYFO~1\ZModeler\zmodeler.exe,1 Reg HKLM\SOFTWARE\Classes\Zanoza.3DEditor.Document\shell\open\command@ D:\MOJEDO~1\Profil1\NOWYFO~1\ZModeler\zmodeler.exe "%1" Reg HKLM\SOFTWARE\Classes\Zanoza.3DEditor.Document\shell\print\command@ D:\MOJEDO~1\Profil1\NOWYFO~1\ZModeler\zmodeler.exe /p "%1" Reg HKLM\SOFTWARE\Classes\Zanoza.3DEditor.Document\shell\printto\command@ D:\MOJEDO~1\Profil1\NOWYFO~1\ZModeler\zmodeler.exe /pt "%1" "%2" "%3" "%4" Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1\Shell@WinPos1024x768(1).left 110 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1\Shell@WinPos1024x768(1).top 66 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1\Shell@WinPos1024x768(1).right 910 Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1\Shell@WinPos1024x768(1).bottom 666 ---- EOF - GMER 2.1 ----