GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-08-26 08:10:43 Windows 6.3.9600 x64 \Device\Harddisk0\DR0 -> \Device\00000032 ST500LM012_HN-M500MBB rev.2AR10002 465,76GB Running: rx4oxuhb.exe; Driver: C:\Users\Marcin\AppData\Local\Temp\kgliqpow.sys ---- User code sections - GMER 2.1 ---- .text C:\WINDOWS\Explorer.EXE[1228] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 714 00007fffda55154a 4 bytes [55, DA, FF, 7F] .text C:\WINDOWS\Explorer.EXE[1228] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 722 00007fffda551552 4 bytes [55, DA, FF, 7F] .text C:\WINDOWS\Explorer.EXE[1228] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 98 00007fffda55162a 4 bytes [55, DA, FF, 7F] .text C:\WINDOWS\Explorer.EXE[1228] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 122 00007fffda551642 4 bytes [55, DA, FF, 7F] ---- Threads - GMER 2.1 ---- Thread C:\WINDOWS\system32\csrss.exe [500:524] fffff96000939b90 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ----