GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-11-30 20:55:58 Windows 6.3.9600 x64 \Device\Harddisk0\DR0 -> \Device\0000002b ST500LT012-9WS142 rev.0001SDM1 465,76GB Running: hkz8yt2p.exe; Driver: C:\Users\ANDRRZ~1\AppData\Local\Temp\ugldrpog.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\WINDOWS\system32\ntoskrnl.exe!NtCallbackReturn + 960 fffff802147e1f00 4 bytes [40, 01, A8, FF] .text C:\WINDOWS\system32\ntoskrnl.exe!NtCallbackReturn + 965 fffff802147e1f05 5 bytes [C4, 66, 03, C0, 88] ---- User code sections - GMER 2.1 ---- .text C:\WINDOWS\Explorer.EXE[1096] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 714 00007ffb3d8e154a 4 bytes [8E, 3D, FB, 7F] .text C:\WINDOWS\Explorer.EXE[1096] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 722 00007ffb3d8e1552 4 bytes [8E, 3D, FB, 7F] .text C:\WINDOWS\Explorer.EXE[1096] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 98 00007ffb3d8e162a 4 bytes [8E, 3D, FB, 7F] .text C:\WINDOWS\Explorer.EXE[1096] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 122 00007ffb3d8e1642 4 bytes [8E, 3D, FB, 7F] ---- Threads - GMER 2.1 ---- Thread C:\WINDOWS\system32\csrss.exe [444:460] fffff96000995b90 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ----