GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-01-11 17:36:17 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000029 ST1000DM003-1CH162 rev.CC57 931,51GB Running: jdluig4q.exe; Driver: C:\Users\LUDMIA~1\AppData\Local\Temp\axtdapog.sys ---- User code sections - GMER 2.1 ---- .text C:\WINDOWS\system32\nvvsvc.exe[448] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffeabe4169a 4 bytes [E4, AB, FE, 7F] .text C:\WINDOWS\system32\nvvsvc.exe[448] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffeabe416a2 4 bytes [E4, AB, FE, 7F] .text C:\WINDOWS\system32\nvvsvc.exe[448] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffeabe4181a 4 bytes [E4, AB, FE, 7F] .text C:\WINDOWS\system32\nvvsvc.exe[448] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffeabe41832 4 bytes [E4, AB, FE, 7F] .text C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[1540] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffeabe4169a 4 bytes [E4, AB, FE, 7F] .text C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[1540] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffeabe416a2 4 bytes [E4, AB, FE, 7F] .text C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[1540] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffeabe4181a 4 bytes [E4, AB, FE, 7F] .text C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe[1540] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffeabe41832 4 bytes [E4, AB, FE, 7F] .text C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.BrowserAdapter64.exe[6768] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffeabe4169a 4 bytes [E4, AB, FE, 7F] .text C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.BrowserAdapter64.exe[6768] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffeabe416a2 4 bytes [E4, AB, FE, 7F] .text C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.BrowserAdapter64.exe[6768] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffeabe4181a 4 bytes [E4, AB, FE, 7F] .text C:\Program Files (x86)\Dynamo Combo\bin\DynamoCombo.BrowserAdapter64.exe[6768] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffeabe41832 4 bytes [E4, AB, FE, 7F] ---- Threads - GMER 2.1 ---- Thread C:\WINDOWS\system32\csrss.exe [668:692] fffff9600082db90 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [1428:2436] 00007ffeabec81b0 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ----