GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2012-05-07 12:18:36 Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 SAMSUNG_SP1203N rev.TL100-24 Running: x9h5yf90.exe; Driver: D:\DOCUME~1\Marcin\USTAWI~1\Temp\axlyafog.sys ---- Kernel code sections - GMER 1.0.15 ---- .text D:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB731B380, 0x566465, 0xE8000020] ---- User code sections - GMER 1.0.15 ---- .text D:\Program Files\Mozilla Firefox\firefox.exe[3520] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 0126C930 D:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text D:\Program Files\Mozilla Firefox\firefox.exe[3520] kernel32.dll!VirtualAlloc 7C809AF1 5 Bytes JMP 0149E0AA D:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text D:\Program Files\Mozilla Firefox\firefox.exe[3520] kernel32.dll!MapViewOfFile 7C80B9A5 5 Bytes JMP 0149E083 D:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) .text D:\Program Files\Mozilla Firefox\firefox.exe[3520] GDI32.dll!CreateDIBSection 77F19E19 5 Bytes JMP 0149E00D D:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) ---- EOF - GMER 1.0.15 ----