GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-07-16 09:36:22 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000030 Hitachi_HTS545050A7E380 rev.GG2OA6C0 465,76GB Running: tz51hegy.exe; Driver: C:\Users\Jasiu\AppData\Local\Temp\fxldypow.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\WINDOWS\System32\win32k.sys!W32pServiceTable fffff96000089600 15 bytes [00, 96, F2, 01, 00, 6A, 6C, ...] .text C:\WINDOWS\System32\win32k.sys!W32pServiceTable + 16 fffff96000089610 11 bytes [00, D7, FB, FF, 00, 7B, D1, ...] ---- User IAT/EAT - GMER 2.1 ---- IAT C:\WINDOWS\Explorer.EXE[2300] @ C:\WINDOWS\Explorer.EXE[USER32.dll!SetWindowPos] [45e93e0] C:\Program Files (x86)\IObit\Start Menu 8\StartMenuDll.dll IAT C:\WINDOWS\Explorer.EXE[2300] @ C:\WINDOWS\Explorer.EXE[USER32.dll!EndPaint] [45e8df0] C:\Program Files (x86)\IObit\Start Menu 8\StartMenuDll.dll ---- Threads - GMER 2.1 ---- Thread C:\WINDOWS\system32\csrss.exe [516:528] fffff960008182d0 Thread C:\WINDOWS\system32\RunDll32.exe [3212:3596] 00007fff835cb040 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ----