GMER 2.1.19163 - http://www.gmer.net Rootkit scan 2013-06-11 19:28:18 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 SAMSUNG_ rev.2AJ1 298,09GB Running: m57g1hli.exe; Driver: C:\Users\Agata\AppData\Local\Temp\fwddakog.sys ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- Devices - GMER 2.1 ---- Device \FileSystem\Ntfs \Ntfs fffffa8002cdc2c0 ---- Threads - GMER 2.1 ---- Thread C:\Windows\SysWOW64\ctfmon.exe [3264:5728] 0000000077442e25 Thread C:\Windows\SysWOW64\ctfmon.exe [3264:5868] 00000000769c8bec Thread C:\Program Files (x86)\Windows Live\Mail\wlmail.exe [4616:3832] 000000006643765f Thread C:\Program Files (x86)\Windows Live\Mail\wlmail.exe [4616:812] 00000000664b2695 Thread C:\Program Files (x86)\Windows Live\Mail\wlmail.exe [4616:3924] 00000000664b2695 Thread C:\Program Files (x86)\Windows Live\Mail\wlmail.exe [4616:4564] 00000000664b2695 Thread C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe [6976:3372] 0000000077442e25 Thread C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe [6976:6704] 0000000068a88f48 Thread C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe [6976:596] 0000000077443e45 Thread C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe [6976:1724] 0000000077443e45 Thread C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe [6976:2984] 0000000077443e45 Thread C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe [6976:6592] 0000000077443e45 ---- EOF - GMER 2.1 ----