GMER 2.2.19882 - http://www.gmer.net Rootkit scan 2016-05-01 15:49:49 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 SAMSUNG_HD253GJ rev.1AJ10001 232,89GB Running: gmer.exe; Driver: C:\Users\Arek\AppData\Local\Temp\ffkdipoc.sys ---- User code sections - GMER 2.2 ---- ? C:\WINDOWS\system32\apphelp.dll [1752] entry point in ".rdata" section 00000000747c0ab0 ---- Threads - GMER 2.2 ---- Thread C:\WINDOWS\system32\csrss.exe [528:584] fffff96139f67300 ---- Registry - GMER 2.2 ---- Reg HKLM\SYSTEM\CurrentControlSet\Control\Lsa@LsaPid 708 Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\kernel\RNG@RNGAuxiliarySeed 1422008078 Reg HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server@InstanceID 6157bb53-04a3-4003-a5d7-1f232bb Reg HKLM\SYSTEM\CurrentControlSet\Hardware Profiles\UnitedVideo\SERVICES\BASICDISPLAY@DefaultSettings.XResolution 1920 Reg HKLM\SYSTEM\CurrentControlSet\Hardware Profiles\UnitedVideo\SERVICES\BASICDISPLAY@DefaultSettings.YResolution 1080 Reg HKLM\SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters\Internet\ManualProxies@ Reg HKLM\SYSTEM\CurrentControlSet\Services\Winmgmt\Parameters@ServiceDllUnloadOnStop 0 Reg HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shutdown@CleanShutdown 1 Reg HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Security and Maintenance@MessageTime 0x54 0xC1 0x0E 0x7E ... ---- Disk sectors - GMER 2.2 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.2 ----