GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-04-20 16:24:09 Windows 6.1.7600 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD3200BEKT-60V5T1 rev.12.01A12 298,09GB Running: 29gmkvgt.exe; Driver: C:\Users\hp\AppData\Local\Temp\uglciaoc.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe[2272] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000765a1465 2 bytes [5A, 76] .text C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe[2272] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000765a14bb 2 bytes [5A, 76] .text ... * 2 .text C:\Windows\SysWOW64\ezSharedSvcHost.exe[2628] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000765a1465 2 bytes [5A, 76] .text C:\Windows\SysWOW64\ezSharedSvcHost.exe[2628] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000765a14bb 2 bytes [5A, 76] .text ... * 2 .text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[2748] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000765a1465 2 bytes [5A, 76] .text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[2748] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000765a14bb 2 bytes [5A, 76] .text ... * 2 .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2780] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000765a1465 2 bytes [5A, 76] .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2780] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000765a14bb 2 bytes [5A, 76] .text ... * 2 .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2876] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000765a1465 2 bytes [5A, 76] .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2876] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000765a14bb 2 bytes [5A, 76] .text ... * 2 .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[5284] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000765a1465 2 bytes [5A, 76] .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[5284] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000765a14bb 2 bytes [5A, 76] .text ... * 2 ? C:\Windows\system32\mssprxy.dll [5284] entry point in ".rdata" section 000000006ab071e6 .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2936] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000765a1465 2 bytes [5A, 76] .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2936] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000765a14bb 2 bytes [5A, 76] .text ... * 2 .text C:\Program Files (x86)\AVG\AVG2013\avgui.exe[5580] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000765a1465 2 bytes [5A, 76] .text C:\Program Files (x86)\AVG\AVG2013\avgui.exe[5580] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000765a14bb 2 bytes [5A, 76] .text ... * 2 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ----