GMER 2.2.19882 - http://www.gmer.net Rootkit scan 2017-01-15 14:15:24 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000033 WDC_WD5000BPKT-75PK4T0 rev.01.01A01 465,76GB Running: 1lyzt1ng.exe; Driver: C:\Users\Pryta\AppData\Local\Temp\fwdyrkog.sys ---- Modules - GMER 2.2 ---- Module \??\C:\Program Files (x86)\UCBrowser\Security:ucdrv-x64.sys fffff80f50a20000-fffff80f50a2e000 (57344 bytes) ---- Threads - GMER 2.2 ---- Thread C:\WINDOWS\system32\csrss.exe [660:712] ffffde9e373b6c20 Thread C:\WINDOWS\system32\SettingSyncHost.exe [7340:7424] 00007ffb829fdbe0 Thread C:\WINDOWS\system32\SettingSyncHost.exe [7340:7444] 00007ffb829fdbe0 ---- Services - GMER 2.2 ---- Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] CDPUserSvc_4e416 <-- ROOTKIT !!! Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] MessagingService_4e416 <-- ROOTKIT !!! Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] OneSyncSvc_4e416 <-- ROOTKIT !!! Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [MANUAL] PimIndexMaintenanceSvc_4e416 <-- ROOTKIT !!! Service C:\WINDOWS\System32\svchost.exe (*** hidden *** ) [MANUAL] UnistoreSvc_4e416 <-- ROOTKIT !!! Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [MANUAL] UserDataSvc_4e416 <-- ROOTKIT !!! Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [MANUAL] WpnUserService_4e416 <-- ROOTKIT !!! ---- EOF - GMER 2.2 ----