GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-06-16 22:33:49 Windows 6.3.9600 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-6 WDC_WD5000AAKX-083CA1 rev.19.01H19 465,76GB Running: gmer.exe; Driver: C:\Users\PokeDorm\AppData\Local\Temp\kwdoqpow.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\Windows\system32\ntoskrnl.exe!NtCallbackReturn + 960 fffff80140fd4e00 84 bytes [80, 5F, AE, FF, C2, 0A, 61, ...] ---- User code sections - GMER 2.1 ---- .text C:\Windows\Explorer.EXE[360] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 714 00007fffa3a6154a 4 bytes [A6, A3, FF, 7F] .text C:\Windows\Explorer.EXE[360] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 722 00007fffa3a61552 4 bytes [A6, A3, FF, 7F] .text C:\Windows\Explorer.EXE[360] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 98 00007fffa3a6162a 4 bytes [A6, A3, FF, 7F] .text C:\Windows\Explorer.EXE[360] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 122 00007fffa3a61642 4 bytes [A6, A3, FF, 7F] ---- Threads - GMER 2.1 ---- Thread C:\Windows\system32\csrss.exe [464:476] fffff960009004d0 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ----