GMER 2.2.19882 - http://www.gmer.net Rootkit scan 2016-03-18 08:33:05 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 ST3500320AS rev.SD15 465,76GB Running: 15rk49ij.exe; Driver: C:\Users\PAWE~1\AppData\Local\Temp\kwlcipob.sys ---- User code sections - GMER 2.2 ---- .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[2600] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000074bd2aa4 5 bytes JMP 00000000009e3610 ---- User IAT/EAT - GMER 2.2 ---- IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\system32\XPSSHHDR.DLL[XpsSvcs.DLL!CreateContainerConsumer] [7feed6aca2c] IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\system32\XPSSHHDR.DLL[XpsSvcs.DLL!CreateStreamReceiverOnFileHandle] [7feed6ac05c] IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\system32\XPSSHHDR.DLL[XpsSvcs.DLL!CreateStreamSenderOnFileHandle] [7feed6ac28c] IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\system32\XPSSHHDR.DLL[XpsSvcs.DLL!CreateContainerProducer] [7feed6ac814] ---- EOF - GMER 2.2 ----