GMER 2.2.19882 - http://www.gmer.net Rootkit scan 2016-09-07 12:58:13 Windows 6.1.7600 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.PB3O 298,09GB Running: erjcymmy.exe; Driver: C:\Users\Julita\AppData\Local\Temp\ugrdipog.sys ---- User code sections - GMER 2.2 ---- .text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2816] C:\Windows\system32\kernel32.dll!LoadLibraryW 0000000076c90420 5 bytes JMP 0000000062423448 .text C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe[2816] C:\Windows\system32\kernel32.dll!LoadLibraryA 0000000076c90bc0 5 bytes JMP 000000006242333c ---- User IAT/EAT - GMER 2.2 ---- IAT C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe[1924] @ C:\Windows\system32\CRYPT32.dll[KERNEL32.dll!LoadLibraryA] [13fd78960] C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe IAT C:\Windows\Explorer.EXE[1820] @ C:\Windows\system32\SHLWAPI.dll[KERNEL32.dll!FreeLibraryAndExitThread] [10002350] C:\Program Files (x86)\EgisTec MyWinLocker\x64\psdprotect.dll IAT C:\Windows\Explorer.EXE[1820] @ C:\Windows\system32\SHLWAPI.dll[KERNEL32.dll!CreateThread] [10003450] C:\Program Files (x86)\EgisTec MyWinLocker\x64\psdprotect.dll IAT C:\Windows\Explorer.EXE[1820] @ C:\Windows\system32\SHELL32.dll[KERNEL32.dll!LoadLibraryA] [100011e0] C:\Program Files (x86)\EgisTec MyWinLocker\x64\psdprotect.dll ---- EOF - GMER 2.2 ----