GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-06-28 19:42:02 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST320LM0 rev.2AJ1 298,09GB Running: 193i2mf6.exe; Driver: C:\Users\Kasia\AppData\Local\Temp\fwddykob.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\windows\System32\win32k.sys!W32pServiceTable fffff960000d4d00 7 bytes [00, 89, F3, FF, C1, 98, F0] .text C:\windows\System32\win32k.sys!W32pServiceTable + 8 fffff960000d4d08 3 bytes [C0, 06, 02] ---- Processes - GMER 2.1 ---- Library C:\Users\Kasia\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll (*** suspicious ***) @ C:\windows\Explorer.EXE [2040] (GG drive menu/GG Network S.A.)(201 000000005ff80000 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- Files - GMER 2.1 ---- File C:\Windows\assembly\NativeImages_v4.0.30319_64\Temp\171c-0 0 bytes ---- EOF - GMER 2.1 ----