GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2016-02-13 23:34:02
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST3320613AS rev.SD22 298,09GB
Running: huzqp8ys.exe; Driver: C:\Users\Marcin\AppData\Local\Temp\awrdrpoc.sys


---- Kernel code sections - GMER 2.1 ----

.text           ntkrnlpa.exe!ZwReplaceKey + 1525                                                                  82E48B55 1 Byte  [06]
.text           ntkrnlpa.exe!KiDispatchInterrupt + 5A2                                                            82E82BF2 19 Bytes  [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}

---- User code sections - GMER 2.1 ----

.text           C:\Program Files\Mozilla Firefox\firefox.exe[1844] ntdll.dll!NtCreateFile                         778555EC 5 Bytes  JMP 6243FF71 C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[1844] ntdll.dll!NtFlushBuffersFile                   7785597C 5 Bytes  JMP 6243FCB1 C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[1844] ntdll.dll!NtQueryFullAttributesFile            7785600C 5 Bytes  JMP 6243FE64 C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[1844] ntdll.dll!NtReadFile                           778562DC 5 Bytes  JMP 6243FCEB C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[1844] ntdll.dll!NtReadFileScatter                    778562EC 5 Bytes  JMP 627CF233 C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[1844] ntdll.dll!NtWriteFile                          77856A8C 5 Bytes  JMP 62440115 C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[1844] ntdll.dll!NtWriteFileGather                    77856A9C 5 Bytes  JMP 627CF283 C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[1844] ntdll.dll!LdrLoadDll                           77872611 5 Bytes  JMP 650DA7DC C:\Program Files\Mozilla Firefox\mozglue.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[1844] kernel32.dll!K32GetDeviceDriverBaseNameW + 5D  75CA95DE 7 Bytes  JMP 627B88D7 C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[1844] kernel32.dll!QueryPerformanceCounter + 13      75CAC5E5 7 Bytes  JMP 627B92B8 C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[1844] kernel32.dll!LoadAppInitDlls + 355             75CAF6A6 7 Bytes  JMP 6252C918 C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[1844] USER32.dll!GetWindowInfo                       77484B66 5 Bytes  JMP 6327AB31 C:\Program Files\Mozilla Firefox\xul.dll
.text           C:\Program Files\Mozilla Firefox\firefox.exe[1844] GDI32.dll!GetViewportOrgEx + 26C               779B87DB 7 Bytes  JMP 627B8258 C:\Program Files\Mozilla Firefox\xul.dll

---- Devices - GMER 2.1 ----

AttachedDevice  \FileSystem\fastfat \Fat                                                                          fltmgr.sys

---- Registry - GMER 2.1 ----

Reg             HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\CIT\System\Active                
Reg             HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\CIT\System\Active@5B131E4A       634

---- EOF - GMER 2.1 ----
