GMER 2.2.19882 - http://www.gmer.net Rootkit scan 2016-03-20 15:32:22 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\00000060 TOSHIBA_ rev.MS1O 465,76GB Running: rprm0gil.exe; Driver: C:\Users\Marcin\AppData\Local\Temp\awrdrpoc.sys ---- User code sections - GMER 2.2 ---- .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076921465 2 bytes [92, 76] .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000769214bb 2 bytes [92, 76] .text ... * 2 .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3240] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076921465 2 bytes [92, 76] .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3240] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000769214bb 2 bytes [92, 76] .text ... * 2 ---- Threads - GMER 2.2 ---- Thread C:\Windows\Explorer.EXE [2204:2680] 000007fef4dc2118 Thread C:\Windows\Explorer.EXE [2204:3204] 000007fefbcf1010 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4020:3484] 000007fefc2e2a7c Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4020:3600] 000007fef19fd618 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4020:3632] 000007fef19fd618 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4020:3636] 000007fef19fd618 Thread C:\Windows\System32\svchost.exe [3748:3888] 000007fef27f9688 ---- EOF - GMER 2.2 ----