GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-04-22 15:57:17 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e TOSHIBA_MK8052GSX rev.LV011D 74,53GB Running: 8vdmrwjj.exe; Driver: C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\kwndraow.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files\Mozilla Firefox\firefox.exe[2844] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10001FD9 C:\Program Files\Mozilla Firefox\mozglue.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2844] kernel32.dll!lstrlenW + 43 7C809AEC 7 Bytes JMP 022F4104 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2844] kernel32.dll!MapViewOfFileEx + 6A 7C80B9A0 7 Bytes JMP 022F40E1 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2844] kernel32.dll!ValidateLocale + B648 7C844EE0 7 Bytes JMP 019C3255 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2844] GDI32.dll!SetDIBitsToDevice + 20A 77F19E14 7 Bytes JMP 022F4062 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3072] USER32.dll!DefWindowProcA + 11A 7E37C298 7 Bytes JMP 104EE610 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3072] USER32.dll!SetWindowLongA + 19 7E37C2B6 7 Bytes JMP 104EE681 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3072] USER32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 104F2366 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3072] USER32.dll!GetMenuContextHelpId + 1A 7E3B5319 7 Bytes JMP 104EBD82 C:\Program Files\Mozilla Firefox\xul.dll ---- EOF - GMER 2.1 ----