GMER 2.1.19163 - http://www.gmer.net Rootkit scan 2013-11-18 12:18:02 Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-3 WDC_WD800JB-00FMA0 rev.13.03G13 74,53GB Running: 529hh682.exe; Driver: C:\Users\NAUCZY~1\AppData\Local\Temp\kxldapow.sys ---- System - GMER 2.1 ---- SSDT 854853D8 ZwAlpcConnectPort SSDT 852EC540 ZwLoadDriver ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!ZwRollbackEnlistment + 142D 82A7AA15 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82AB4212 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} .text ntkrnlpa.exe!KeRemoveQueueEx + 10FF 82ABB494 4 Bytes [D8, 53, 48, 85] .text ntkrnlpa.exe!KeRemoveQueueEx + 1314 82ABB6A9 3 Bytes [C5, 2E, 85] ---- Devices - GMER 2.1 ---- AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys ---- EOF - GMER 2.1 ----