GMER 2.2.19882 - http://www.gmer.net Rootkit scan 2017-04-04 13:52:23 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\00000060 ST1000DM rev.CC46 931,51GB Running: 2fx9lfdx.exe; Driver: C:\Users\PAWE~1\AppData\Local\Temp\pgddqpoc.sys ---- User code sections - GMER 2.2 ---- .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3128] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000077292bdc 5 bytes JMP 000000000010f046 ---- Processes - GMER 2.2 ---- Library c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{9CFABAF8-C1E3-40AC-9CF7-419248120527}\offreg.164.dll (*** suspicious ***) @ c:\Program Files\Microsoft Security Client\MsMpEng.exe [164] 000007fefb3d0000 ---- EOF - GMER 2.2 ----