GMER 2.1.19163 - http://www.gmer.net Rootkit scan 2013-09-11 19:49:39 Windows 6.1.7600 x64 \Device\Harddisk2\DR2 -> \Device\Ide\IdeDeviceP0T0L0-2 SanDisk_SDSSDP128G rev.2.0.0 119,24GB Running: rz89upgz.exe; Driver: C:\Users\Pawel\AppData\Local\Temp\awddrkog.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe suspicious modification .text C:\Windows\System32\win32k.sys!W32pServiceTable fffff96000191c00 7 bytes [00, 98, F3, FF, 01, A3, F0] .text C:\Windows\System32\win32k.sys!W32pServiceTable + 8 fffff96000191c08 3 bytes [C0, 06, 02] INITKDBG C:\Windows\system32\ntoskrnl.exe suspicious modification INITKDBG C:\Windows\system32\ntoskrnl.exe suspicious modification INITKDBG C:\Windows\system32\ntoskrnl.exe suspicious modification INITKDBG C:\Windows\system32\ntoskrnl.exe suspicious modification INITKDBG C:\Windows\system32\ntoskrnl.exe suspicious modification INITKDBG C:\Windows\system32\ntoskrnl.exe suspicious modification ---- Files - GMER 2.1 ---- File C:\Users\Pawel\AppData\Roaming\Microsoft\Windows\Recent\143e51309c.lnk 1289 bytes File C:\Users\Pawel\AppData\Roaming\Mozilla\Firefox\Profiles\en9tpheo.default\sessionstore.js.tmp 0 bytes ---- EOF - GMER 2.1 ----