GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-04-25 20:42:48 Windows 6.3.9600 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST2000DM001-1CH164 rev.CC27 1863,02GB Running: le4hdnde.exe; Driver: C:\Users\Root\AppData\Local\Temp\pwliqpoc.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\Windows\system32\ntoskrnl.exe!NtCallbackReturn + 960 fffff80024571a00 12 bytes [40, BF, A7, FF, 82, F4, 4B, ...] .text C:\Windows\system32\ntoskrnl.exe!NtCallbackReturn + 973 fffff80024571a0d 39 bytes [D9, 4A, 02, 00, C4, FF, FF, ...] ---- Threads - GMER 2.1 ---- Thread C:\Windows\system32\csrss.exe [464:480] fffff960009152d0 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ----