GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2012-06-21 20:58:40 Windows 5.1.2600 Dodatek Service Pack 2 Harddisk0\DR0 -> \Device\Scsi\nvgts1Port2Path0Target0Lun0 WDC_WD16 rev.01.0 Running: yhy77shm.exe; Driver: C:\DOCUME~1\ADMINI~1\USTAWI~1\Temp\pxtdipod.sys ---- Kernel code sections - GMER 1.0.15 ---- .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF6652380, 0x566465, 0xE8000020] ---- User code sections - GMER 1.0.15 ---- .text K:\firefox.exe[2120] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 0116FA35 K:\xul.dll (Mozilla Foundation) .text K:\firefox.exe[2120] kernel32.dll!VirtualAlloc 7C809A81 5 Bytes JMP 014107C5 K:\xul.dll (Mozilla Foundation) .text K:\firefox.exe[2120] kernel32.dll!MapViewOfFile 7C80B78D 5 Bytes JMP 0141079E K:\xul.dll (Mozilla Foundation) .text K:\firefox.exe[2120] GDI32.dll!CreateDIBSection 77F19610 5 Bytes JMP 01410728 K:\xul.dll (Mozilla Foundation) ---- EOF - GMER 1.0.15 ----