GMER 2.1.19163 - http://www.gmer.net Rootkit scan 2014-10-15 01:16:19 Windows 6.3.9600 x64 \Device\Harddisk0\DR0 -> \Device\00000032 ST750LM022_HN-M750MBB rev.2AR10002 698,64GB Running: m57g1hli.exe; Driver: C:\Users\MICHA~1\AppData\Local\Temp\uwldypow.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\WINDOWS\System32\win32k.sys!W32pServiceTable fffff960000f2e00 15 bytes [00, FA, 0E, 02, C0, 9C, 70, ...] .text C:\WINDOWS\System32\win32k.sys!W32pServiceTable + 16 fffff960000f2e10 11 bytes [00, 00, FC, FF, 80, FA, C0, ...] ---- User code sections - GMER 2.1 ---- .text C:\WINDOWS\Explorer.EXE[316] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 714 00007ffbb81b154a 4 bytes [1B, B8, FB, 7F] .text C:\WINDOWS\Explorer.EXE[316] C:\WINDOWS\SYSTEM32\MSIMG32.dll!GradientFill + 722 00007ffbb81b1552 4 bytes [1B, B8, FB, 7F] .text C:\WINDOWS\Explorer.EXE[316] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 98 00007ffbb81b162a 4 bytes [1B, B8, FB, 7F] .text C:\WINDOWS\Explorer.EXE[316] C:\WINDOWS\SYSTEM32\MSIMG32.dll!TransparentBlt + 122 00007ffbb81b1642 4 bytes [1B, B8, FB, 7F] ---- Threads - GMER 2.1 ---- Thread C:\WINDOWS\system32\csrss.exe [472:496] fffff960009014d0 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ----