GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2016-01-17 16:17:26 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000002e ST1000DX001-1CM162 rev.CC43 931,51GB Running: gmer.exe; Driver: C:\Users\JANZBY~1\AppData\Local\Temp\pgldypow.sys ---- User code sections - GMER 2.1 ---- .text C:\Windows\Explorer.EXE[1452] C:\Windows\system32\KERNEL32.DLL!CreateProcessInternalW 00007ffe71490070 5 bytes JMP 00007fff62aa25e8 ---- Threads - GMER 2.1 ---- Thread C:\Windows\system32\csrss.exe [2440:4720] fffff960008152d0 Thread C:\Windows\System32\SettingSyncHost.exe [5544:5820] 00007ffe63d87090 Thread C:\Windows\System32\SettingSyncHost.exe [5544:5320] 00007ffe67507470 ---- Processes - GMER 2.1 ---- Process C:\Users\jan zbylut\AppData\Local\Temp\Temp2_gmer.zip\gmer.exe (*** suspicious ***) @ C:\Users\jan zbylut\AppData\Local\Temp\Temp2_gmer.zip\gmer.exe [2696](2014-01-28 17:36:04) 0000000000400000 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ----