GMER 2.2.19882 - http://www.gmer.net Rootkit scan 2016-03-21 21:48:35 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\00000068 HGST rev.GG2O 465,76GB Running: etxho4y5.exe; Driver: C:\Users\Sonia\AppData\Local\Temp\uwloypod.sys ---- Kernel code sections - GMER 2.2 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80002fbb000 45 bytes [43, 4D, 33, 31, 05, 00, 00, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575 fffff80002fbb02f 16 bytes [00, 00, 00, 00, 00, 00, 00, ...] ---- User code sections - GMER 2.2 ---- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[3060] C:\Windows\syswow64\kernel32.dll!SetFileCompletionNotificationModes 0000000076bdaec6 5 bytes JMP 00000000100078e0 .text C:\Program Files\Windows Media Player\wmpnetwk.exe[3644] C:\Windows\system32\kernel32.dll!SetFileCompletionNotificationModes 0000000077280520 14 bytes {JMP QWORD [RIP+0x0]} .text C:\Users\Sonia\Desktop\Usuwanie wirusów\etxho4y5.exe[4328] C:\Windows\syswow64\kernel32.dll!SetFileCompletionNotificationModes 0000000076bdaec6 5 bytes JMP 00000000100078e0 ---- EOF - GMER 2.2 ----