GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2016-01-26 14:18:12 Windows 6.3.9600 x64 \Device\Harddisk0\DR0 -> \Device\00000030 Hitachi_HTS547575A9E384 rev.JE4OA50A 698,64GB Running: 5rgjoqnc.exe; Driver: C:\Users\Michal\AppData\Local\Temp\fflcypoc.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\WINDOWS\system32\ntoskrnl.exe!NtCallbackReturn + 960 fffff8009b371000 12 bytes [80, C9, A4, FF, 02, A8, 44, ...] .text C:\WINDOWS\system32\ntoskrnl.exe!NtCallbackReturn + 973 fffff8009b37100d 31 bytes [E4, 7C, 02, 00, C4, FF, FF, ...] ---- Threads - GMER 2.1 ---- Thread C:\WINDOWS\system32\csrss.exe [484:508] fffff960009812d0 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ----