GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-09-28 20:23:58 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 KINGSTON rev.507A 111,79GB Running: 0f80nwrz.exe; Driver: C:\Users\Pozioma\AppData\Local\Temp\kxldqpow.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\LibreOffice 4\program\soffice.bin[3992] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075ce1465 2 bytes [CE, 75] .text C:\Program Files (x86)\LibreOffice 4\program\soffice.bin[3992] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075ce14bb 2 bytes [CE, 75] .text ... * 2 ---- Processes - GMER 2.1 ---- Library C:\ProgramData\Microsoft\Secure\Icons\SecureIconsProvider.dll (*** suspicious ***) @ C:\Windows\Explorer.EXE [1576] (Secure overlay library/Microsoft)(2014-09-20 16:24:30) 000007fef9890000 Library C:\ProgramData\Microsoft\Secure\Icons\IconsCacheHelper.dll (*** suspicious ***) @ C:\Windows\Explorer.EXE [1576](2014-09-20 16:24:30) 000007fef03a0000 ---- EOF - GMER 2.1 ----