GMER 2.1.19163 - http://www.gmer.net Rootkit scan 2013-07-16 13:34:11 Windows 6.1.7600 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 TOSHIBA_ rev.GJ00 298,09GB Running: uhji13r2.exe; Driver: C:\Users\Edward\AppData\Local\Temp\ugrdqpoc.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1604] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 00000000752fd03c 4 bytes [C2, 04, 00, 00] .text C:\Program Files (x86)\Skype\Phone\Skype.exe[3572] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075631465 2 bytes [63, 75] .text C:\Program Files (x86)\Skype\Phone\Skype.exe[3572] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756314bb 2 bytes [63, 75] .text ... * 2 .text C:\Program Files (x86)\Skype\Phone\Skype.exe[3572] C:\Windows\SysWOW64\ksuser.dll!KsCreatePin + 35 00000000741e11a8 2 bytes [1E, 74] .text C:\Program Files (x86)\Skype\Phone\Skype.exe[3572] C:\Windows\SysWOW64\ksuser.dll!KsCreateAllocator + 21 00000000741e13a8 2 bytes [1E, 74] .text C:\Program Files (x86)\Skype\Phone\Skype.exe[3572] C:\Windows\SysWOW64\ksuser.dll!KsCreateClock + 21 00000000741e1422 2 bytes [1E, 74] .text C:\Program Files (x86)\Skype\Phone\Skype.exe[3572] C:\Windows\SysWOW64\ksuser.dll!KsCreateTopologyNode + 19 00000000741e1498 2 bytes [1E, 74] .text C:\ProgramData\GameXN\GameXNGO.exe[3680] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075631465 2 bytes [63, 75] .text C:\ProgramData\GameXN\GameXNGO.exe[3680] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756314bb 2 bytes [63, 75] .text ... * 2 ---- Threads - GMER 2.1 ---- Thread C:\Windows\system32\svchost.exe [124:1692] 000007fef920f978 Thread C:\Windows\system32\svchost.exe [124:2364] 000007fef90c5124 Thread C:\Windows\system32\svchost.exe [124:3824] 000007fef9f581ac Thread C:\Windows\system32\svchost.exe [124:2888] 000007fef41b83e8 Thread C:\Windows\system32\svchost.exe [124:3368] 000007fef41b83e8 Thread C:\Windows\system32\svchost.exe [124:3432] 000007fef41b83e8 Thread C:\Windows\system32\svchost.exe [124:3372] 000007fef41b83e8 Thread C:\Windows\system32\svchost.exe [124:3340] 000007fef4093f0c Thread C:\Windows\system32\svchost.exe [124:3328] 000007fef6dd1a38 Thread C:\Windows\system32\svchost.exe [124:3320] 000007fef4065388 Thread C:\Windows\system32\svchost.exe [124:2948] 000007fef4047738 Thread C:\Windows\system32\svchost.exe [124:3916] 000007fef4031f90 Thread C:\Windows\system32\svchost.exe [124:4500] 000007fef422fdf0 Thread C:\Windows\System32\svchost.exe [1808:4944] 000007fef6ee9688 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ----