GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2012-04-28 00:38:48 Windows 5.1.2600 Dodatek Service Pack 2 Harddisk0\DR0 -> \Device\00000059 SAMSUNG_HD502HJ rev.1AJ10001 Running: 641xb03v.exe; Driver: C:\DOCUME~1\Max\USTAWI~1\Temp\pxtdapow.sys ---- Kernel code sections - GMER 1.0.15 ---- .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF6FD9360, 0x24526E, 0xE8000020] ---- User code sections - GMER 1.0.15 ---- .text H:\Program Files\Mozilla Firefox\firefox.exe[380] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 01219720 H:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text H:\Program Files\Mozilla Firefox\firefox.exe[380] kernel32.dll!VirtualAlloc 7C809A81 5 Bytes JMP 0144E21B H:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text H:\Program Files\Mozilla Firefox\firefox.exe[380] kernel32.dll!MapViewOfFile 7C80B78D 5 Bytes JMP 0144E1F4 H:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text H:\Program Files\Mozilla Firefox\firefox.exe[380] GDI32.dll!CreateDIBSection 77F19610 5 Bytes JMP 0144E17E H:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text H:\Program Files\Mozilla Firefox\plugin-container.exe[516] USER32.dll!GetWindowInfo 77D3F122 5 Bytes JMP 1044FE0A H:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text H:\Program Files\Mozilla Firefox\plugin-container.exe[516] USER32.dll!TrackPopupMenu 77D84F16 5 Bytes JMP 104503C5 H:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) ---- EOF - GMER 1.0.15 ----