GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-10-17 18:11:44 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.JE3O 465,76GB Running: 78jt1qz7.exe; Driver: C:\Users\zbyszek\AppData\Local\Temp\pwdiykod.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2520] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000757a1465 2 bytes [7A, 75] .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2520] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000757a14bb 2 bytes [7A, 75] .text ... * 2 .text C:\Program Files (x86)\AVG\AVG2012\avgtray.exe[2940] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000757a1465 2 bytes [7A, 75] .text C:\Program Files (x86)\AVG\AVG2012\avgtray.exe[2940] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000757a14bb 2 bytes [7A, 75] .text ... * 2 .text C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe[3216] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000757a1465 2 bytes [7A, 75] .text C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe[3216] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000757a14bb 2 bytes [7A, 75] .text ... * 2 .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3676] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000757a1465 2 bytes [7A, 75] .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3676] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000757a14bb 2 bytes [7A, 75] .text ... * 2 ? C:\Windows\system32\mssprxy.dll [3676] entry point in ".rdata" section 00000000736f71e6 .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[5524] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000757a1465 2 bytes [7A, 75] .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[5524] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000757a14bb 2 bytes [7A, 75] .text ... * 2 .text C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe[4580] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000757a1465 2 bytes [7A, 75] .text C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe[4580] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000757a14bb 2 bytes [7A, 75] .text ... * 2 .text C:\Users\zbyszek\Downloads\OTL.exe[6212] C:\Windows\syswow64\PSAPI.dll!GetModuleInformation + 69 00000000757a1465 2 bytes [7A, 75] .text C:\Users\zbyszek\Downloads\OTL.exe[6212] C:\Windows\syswow64\PSAPI.dll!GetModuleInformation + 155 00000000757a14bb 2 bytes [7A, 75] .text ... * 2 ---- EOF - GMER 2.1 ----