GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-11-09 12:18:56 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 SAMSUNG_ rev.2AJ1 298,09GB Running: phuwgis9.exe; Driver: C:\Users\Agata\AppData\Local\Temp\fwddakog.sys ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- Devices - GMER 2.1 ---- Device \FileSystem\Ntfs \Ntfs fffffa8002ccb2c0 ---- Threads - GMER 2.1 ---- Thread C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe [1716:3004] 0000000076f62e65 Thread C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe [1716:1580] 0000000065fb8f48 Thread C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe [1716:5864] 0000000076f63e85 Thread C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe [1716:5328] 0000000076f63e85 Thread C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe [1716:2872] 0000000076f63e85 ---- Processes - GMER 2.1 ---- Library C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll (*** suspicious ***) @ C:\Windows\Explorer.EXE [1216] (GG drive overlay/GG Network S.A.)(2012-09-23 14:39:04) 000000005c080000 ---- EOF - GMER 2.1 ----