GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-07-15 22:09:27 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 TOSHIBA_ rev.GU00 931,51GB Running: hu3brzji.exe; Driver: C:\Users\ZANET\AppData\Local\Temp\fgtiypow.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\Windows\System32\win32k.sys!W32pServiceTable fffff960001a4c00 7 bytes [00, 93, F3, FF, 41, A4, F0] .text C:\Windows\System32\win32k.sys!W32pServiceTable + 8 fffff960001a4c08 3 bytes [00, 07, 02] ---- Processes - GMER 2.1 ---- Library C:\ProgramData\Microsoft\Secure\Icons\SecureIconsProvider.dll (*** suspicious ***) @ C:\Windows\Explorer.EXE [980] (Secure overlay library/Microsoft)(2014-11-19 21:36:36) 000007fef9840000 ---- EOF - GMER 2.1 ----