GMER 2.1.19163 - http://www.gmer.net Rootkit scan 2013-10-29 08:49:33 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.JEDO 596,17GB Running: ejxs71vr.exe; Driver: C:\Users\Smok\AppData\Local\Temp\kgldqpoc.sys ---- Threads - GMER 2.1 ---- Thread C:\Windows\SysWOW64\ntdll.dll [1524:1844] 000000000030301f Thread C:\Windows\SysWOW64\ntdll.dll [1524:4008] 0000000074e16c50 Thread C:\Windows\SysWOW64\ntdll.dll [1524:1364] 000000006d381120 Thread C:\Windows\SysWOW64\ntdll.dll [1524:6016] 000000006d7231f8 Thread C:\Windows\SysWOW64\ntdll.dll [1524:5464] 000000006fec62ee Thread C:\Windows\SysWOW64\ntdll.dll [1524:3792] 000000006ab83821 Thread C:\Windows\SysWOW64\ntdll.dll [1524:4404] 000000006ab83821 Thread C:\Windows\SysWOW64\ntdll.dll [1524:6224] 0000000060f963c3 Thread C:\Windows\SysWOW64\ntdll.dll [1524:6288] 000000006017a590 Thread C:\Windows\SysWOW64\ntdll.dll [1524:6320] 0000000060bc2210 Thread C:\Windows\SysWOW64\ntdll.dll [1524:6336] 0000000061bc6680 Thread C:\Windows\SysWOW64\ntdll.dll [1524:6448] 000000005f7d961d Thread C:\Windows\SysWOW64\ntdll.dll [1524:6500] 0000000060f963c3 Thread C:\Windows\SysWOW64\ntdll.dll [1524:6508] 000000005e425780 Thread C:\Windows\SysWOW64\ntdll.dll [1524:6512] 000000005e425780 Thread C:\Windows\SysWOW64\ntdll.dll [1524:6516] 000000005e46fbd0 Thread C:\Windows\SysWOW64\ntdll.dll [1524:1516] 0000000060e3ef50 Thread C:\Windows\SysWOW64\ntdll.dll [1524:3532] 000000006ab83821 Thread C:\Windows\SysWOW64\ntdll.dll [1524:1736] 0000000060e21e70 Thread C:\Windows\SysWOW64\ntdll.dll [1524:6192] 000000006f323840 Thread C:\Windows\SysWOW64\ntdll.dll [1524:5328] 000000006f3234b0 Thread C:\Windows\SysWOW64\ntdll.dll [1524:5952] 000000006f323840 Thread C:\Windows\SysWOW64\ntdll.dll [1524:3476] 000000006f3234b0 ---- EOF - GMER 2.1 ----