GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2014-01-04 22:19:40
Windows 6.2.9200  x64 \Device\Harddisk0\DR0 -> \Device\00000021 ST1000LM024_HN-M101MBB rev.2AR10002 931,51GB
Running: gn8sh6dk.exe; Driver: C:\Users\Maciek\AppData\Local\Temp\ugddapow.sys


---- Kernel code sections - GMER 2.1 ----

.text   C:\WINDOWS\System32\win32k.sys!W32pServiceTable                                                             fffff960001be700 15 bytes [00, EA, 0F, 02, 00, 7F, 6F, ...]
.text   C:\WINDOWS\System32\win32k.sys!W32pServiceTable + 16                                                        fffff960001be710 11 bytes [00, 1F, FC, FF, 80, 52, DE, ...]

---- User code sections - GMER 2.1 ----

.text   C:\WINDOWS\system32\atiesrxx.exe[292] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                00007ff8702f169a 4 bytes [2F, 70, F8, 7F]
.text   C:\WINDOWS\system32\atiesrxx.exe[292] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                00007ff8702f16a2 4 bytes [2F, 70, F8, 7F]
.text   C:\WINDOWS\system32\atiesrxx.exe[292] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                   00007ff8702f181a 4 bytes [2F, 70, F8, 7F]
.text   C:\WINDOWS\system32\atiesrxx.exe[292] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                   00007ff8702f1832 4 bytes [2F, 70, F8, 7F]
.text   C:\WINDOWS\system32\atieclxx.exe[1068] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506               00007ff8702f169a 4 bytes [2F, 70, F8, 7F]
.text   C:\WINDOWS\system32\atieclxx.exe[1068] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514               00007ff8702f16a2 4 bytes [2F, 70, F8, 7F]
.text   C:\WINDOWS\system32\atieclxx.exe[1068] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                  00007ff8702f181a 4 bytes [2F, 70, F8, 7F]
.text   C:\WINDOWS\system32\atieclxx.exe[1068] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                  00007ff8702f1832 4 bytes [2F, 70, F8, 7F]
.text   C:\WINDOWS\System32\spoolsv.exe[1544] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                00007ff8702f169a 4 bytes [2F, 70, F8, 7F]
.text   C:\WINDOWS\System32\spoolsv.exe[1544] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                00007ff8702f16a2 4 bytes [2F, 70, F8, 7F]
.text   C:\WINDOWS\System32\spoolsv.exe[1544] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                   00007ff8702f181a 4 bytes [2F, 70, F8, 7F]
.text   C:\WINDOWS\System32\spoolsv.exe[1544] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                   00007ff8702f1832 4 bytes [2F, 70, F8, 7F]
.text   C:\Program Files\Windows Defender\MsMpEng.exe[1232] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 506  00007ff8702f169a 4 bytes [2F, 70, F8, 7F]
.text   C:\Program Files\Windows Defender\MsMpEng.exe[1232] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 514  00007ff8702f16a2 4 bytes [2F, 70, F8, 7F]
.text   C:\Program Files\Windows Defender\MsMpEng.exe[1232] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 118     00007ff8702f181a 4 bytes [2F, 70, F8, 7F]
.text   C:\Program Files\Windows Defender\MsMpEng.exe[1232] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 142     00007ff8702f1832 4 bytes [2F, 70, F8, 7F]
.text   C:\WINDOWS\Explorer.EXE[3036] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506                        00007ff8702f169a 4 bytes [2F, 70, F8, 7F]
.text   C:\WINDOWS\Explorer.EXE[3036] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514                        00007ff8702f16a2 4 bytes [2F, 70, F8, 7F]
.text   C:\WINDOWS\Explorer.EXE[3036] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118                           00007ff8702f181a 4 bytes [2F, 70, F8, 7F]
.text   C:\WINDOWS\Explorer.EXE[3036] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142                           00007ff8702f1832 4 bytes [2F, 70, F8, 7F]
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[2244] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 194  00007ff8650b1f6a 4 bytes [0B, 65, F8, 7F]
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[2244] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 218  00007ff8650b1f82 4 bytes [0B, 65, F8, 7F]

---- Threads - GMER 2.1 ----

Thread  C:\WINDOWS\system32\csrss.exe [740:764]                                                                     fffff960008334d0

---- Disk sectors - GMER 2.1 ----

Disk    \Device\Harddisk0\DR0                                                                                       unknown MBR code

---- EOF - GMER 2.1 ----
