GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-10-22 23:21:06 Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-1 ST3500830A rev.3.AAD 465,76GB Running: 6q0w2g3n.exe; Driver: C:\Users\user\AppData\Local\Temp\aftcaaob.sys ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!ZwSaveKey + 13C1 81E43339 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 81E7CD52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} ---- EOF - GMER 2.1 ----