GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-03-04 19:34:22 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-3 ST380011A rev.3.06 74,53GB Running: goiq6e8z.exe; Driver: C:\DOCUME~1\Mariusz\USTAWI~1\Temp\fgxdafog.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files\Mozilla Firefox\firefox.exe[1304] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 01829AE0 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1304] ntdll.dll!NtFlushBuffersFile 7C90D32E 5 Bytes JMP 0180C434 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1304] ntdll.dll!NtQueryFullAttributesFile 7C90D7AE 5 Bytes JMP 0180C150 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1304] ntdll.dll!NtReadFile 7C90D9CE 5 Bytes JMP 0180C330 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1304] ntdll.dll!NtReadFileScatter 7C90D9DE 5 Bytes JMP 0222F60F C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1304] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 0182A9F0 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1304] ntdll.dll!NtWriteFileGather 7C90DF8E 5 Bytes JMP 0222F5BE C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1304] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10001F42 C:\Program Files\Mozilla Firefox\mozglue.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1304] kernel32.dll!lstrlenW + 43 7C809AEC 7 Bytes JMP 02154AC3 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1304] kernel32.dll!MapViewOfFileEx + 6A 7C80B9A0 2 Bytes JMP 02154AA0 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1304] kernel32.dll!MapViewOfFileEx + 6D 7C80B9A3 4 Bytes [94, 85, EB, F9] {XCHG ESP, EAX; TEST EBX, EBP; STC } .text C:\Program Files\Mozilla Firefox\firefox.exe[1304] kernel32.dll!ValidateLocale + B648 7C844EE0 7 Bytes JMP 018263D0 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1304] GDI32.dll!SetDIBitsToDevice + 20A 77F19E14 7 Bytes JMP 02154A21 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1304] USER32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 0204B991 C:\Program Files\Mozilla Firefox\xul.dll ---- EOF - GMER 2.1 ----