GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-11-22 15:47:20 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD10EARX-00N0YB0 rev.51.0AB51 931,51GB Running: vf67j886.exe; Driver: C:\Users\Karol\AppData\Local\Temp\awddykod.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff800031a3000 45 bytes [43, 4D, 33, 31, 05, 00, 00, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575 fffff800031a302f 16 bytes [00, 00, 00, 00, 00, 00, 00, ...] ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[2236] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075fe1465 2 bytes [FE, 75] .text C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[2236] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075fe14bb 2 bytes [FE, 75] .text ... * 2 .text C:\Users\Karol\AppData\Local\Akamai\netsession_win.exe[3560] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075fe1465 2 bytes [FE, 75] .text C:\Users\Karol\AppData\Local\Akamai\netsession_win.exe[3560] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075fe14bb 2 bytes [FE, 75] .text ... * 2 .text C:\Users\Karol\AppData\Local\Akamai\netsession_win.exe[3724] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075fe1465 2 bytes [FE, 75] .text C:\Users\Karol\AppData\Local\Akamai\netsession_win.exe[3724] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075fe14bb 2 bytes [FE, 75] .text ... * 2 ---- EOF - GMER 2.1 ----