
GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-11-12 22:58:53
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD3200BPVT-22JJ5T0 rev.01.01A01 298,09GB
Running: ugh76yt8.exe; Driver: C:\Users\Damian\AppData\Local\Temp\uxdirpod.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\AVG Web TuneUp\vprot.exe[3412] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076f81465 2 bytes [F8, 76]
.text C:\Program Files (x86)\AVG Web TuneUp\vprot.exe[3412] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076f814bb 2 bytes [F8, 76]
.text ... * 2
---- Threads - GMER 2.1 ----
Thread C:\Windows\System32\svchost.exe [844:1204] 000007fefb56f2f4
Thread C:\Windows\System32\svchost.exe [844:1232] 000007fefb4e6204
Thread C:\Windows\System32\svchost.exe [844:1460] 000007fef9d55440
Thread C:\Windows\System32\svchost.exe [844:6076] 000007fefda8c608
Thread C:\Windows\System32\svchost.exe [844:6644] 000007feef8e6b8c
Thread C:\Windows\System32\svchost.exe [844:6652] 000007feef8e1d88
Thread C:\Windows\System32\svchost.exe [844:3056] 000007fef9e52070
Thread C:\Windows\System32\svchost.exe [844:5088] 000007fef8d85fd0
Thread C:\Windows\System32\svchost.exe [844:7724] 000007fef9d53130
Thread C:\Windows\System32\svchost.exe [352:1532] 000007fef98959a0
Thread C:\Windows\System32\svchost.exe [352:3172] 000007fef8ab88f8
Thread C:\Windows\System32\svchost.exe [352:4360] 000007feece720c0
Thread C:\Windows\System32\svchost.exe [352:4368] 000007feece726a8
Thread C:\Windows\System32\svchost.exe [352:5228] 000007fef85144e0
Thread C:\Windows\System32\svchost.exe [352:4500] 000007feeb213efc
Thread C:\Windows\System32\svchost.exe [352:1080] 000007feeb3e8a4c
Thread C:\Windows\System32\svchost.exe [352:4580] 000007fef3a814a0
Thread C:\Windows\system32\svchost.exe [1316:4272] 000007fef7d90ea8
Thread C:\Windows\system32\svchost.exe [1316:4280] 000007fef7d89db0
Thread C:\Windows\system32\svchost.exe [1316:4308] 000007fef7d91c94
Thread C:\Windows\system32\svchost.exe [1316:5152] 000007feef87b1b0
Thread C:\Windows\system32\svchost.exe [1316:3780] 000007fef7d8aa10
Thread C:\Windows\system32\svchost.exe [1316:984] 000007feeec0d3c8
Thread C:\Windows\system32\svchost.exe [1316:4608] 000007feeec0d3c8
Thread C:\Windows\system32\svchost.exe [1316:7152] 000007feeec0d3c8
Thread C:\Windows\system32\svchost.exe [1316:7308] 000007feeec0d3c8
Thread C:\Windows\System32\spoolsv.exe [1680:2408] 000007fef80710c8
Thread C:\Windows\System32\spoolsv.exe [1680:2432] 000007fef8026144
Thread C:\Windows\System32\spoolsv.exe [1680:2440] 000007fef8d85fd0
Thread C:\Windows\System32\spoolsv.exe [1680:2448] 000007fef7f53438
Thread C:\Windows\System32\spoolsv.exe [1680:2452] 000007fef8d863ec
Thread C:\Windows\System32\spoolsv.exe [1680:2460] 000007fef8105e5c
Thread C:\Windows\System32\spoolsv.exe [1680:2464] 000007fef81b5090
Thread C:\Windows\system32\svchost.exe [1708:1948] 000007fef91635c0
Thread C:\Windows\system32\svchost.exe [1708:4344] 000007fef9165600
Thread C:\Windows\system32\svchost.exe [1708:4400] 000007feeccb2888
Thread C:\Windows\system32\svchost.exe [1708:4408] 000007feecca2940
Thread C:\Windows\system32\svchost.exe [1708:2840] 000007feeccb2a40
Thread C:\Windows\system32\svchost.exe [2300:5392] 000007fef8d85fd0
Thread C:\Windows\system32\svchost.exe [2300:4260] 000007fef7f53438
Thread C:\Windows\system32\svchost.exe [2300:5892] 000007fef8d863ec
Thread C:\Program Files\Windows Sidebar\sidebar.exe [3120:3704] 000007fefa721ebc
Thread C:\Program Files\Windows Sidebar\sidebar.exe [3120:1340] 000007fefa681e30
Thread C:\Program Files\Windows Sidebar\sidebar.exe [3120:1544] 000007fefa681e30
Thread C:\Program Files\Windows Sidebar\sidebar.exe [3120:1652] 000007fefa681e30
Thread C:\Program Files\Windows Sidebar\sidebar.exe [3120:1076] 000007fefa681e30
Thread C:\Program Files\Windows Sidebar\sidebar.exe [3120:1484] 000007fefa681e30
Thread C:\Program Files\Windows Sidebar\sidebar.exe [3120:1404] 000007fefa681e30
Thread C:\Program Files\Windows Sidebar\sidebar.exe [3120:3720] 000007fefa681e30
Thread C:\Program Files\Windows Sidebar\sidebar.exe [3120:3832] 000007fefa681e30
Thread C:\Program Files\Windows Sidebar\sidebar.exe [3120:3604] 000007fefbf4ea40
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [5508:5176] 000007fefac22ab8
Thread C:\Windows\System32\svchost.exe [5192:1212] 000007feee855170
Thread C:\Windows\System32\svchost.exe [5192:4588] 000007fef8bc9874
---- Processes - GMER 2.1 ----
Library C:\Users\Damian\AppData\Local\Viber\4.3.0.1453\libViber.dll (*** suspicious ***) @ C:\Users\Damian\AppData\Local\Viber\Viber.exe [3432](2014-09-16 16:31:51) 000000006b0f0000
Library C:\Users\Damian\AppData\Local\Viber\4.3.0.1453\libGLESv2.dll (*** suspicious ***) @ C:\Users\Damian\AppData\Local\Viber\Viber.exe [3432](2014-09-16 16:31:51) 0000000074b90000
Library C:\Users\Damian\AppData\Local\Viber\4.3.0.1453\qfacebook.dll (*** suspicious ***) @ C:\Users\Damian\AppData\Local\Viber\Viber.exe [3432](2014-09-16 16:31:52) 0000000074b60000
Library C:\Users\Damian\AppData\Local\Viber\4.3.0.1453\Qt5Network.dll (*** suspicious ***) @ C:\Users\Damian\AppData\Local\Viber\Viber.exe [3432] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2014-09-16 16:31:52) 00000000745a0000
Library C:\Users\Damian\AppData\Local\Viber\4.3.0.1453\Qt5Core.dll (*** suspicious ***) @ C:\Users\Damian\AppData\Local\Viber\Viber.exe [3432] (C++ application development framework./Digia Plc and/or its subsidiary(-ies))(2014-09-16 16:31:52) 00000000741a0000
Library C:\Users\Damian\AppData\Local\Viber\4.3.0.1453\icuin51.dll (*** suspicious ***) @ C:\Users\Damian\AppData\Local\Viber\Viber.exe [3432] (ICU I18N DLL/The ICU Project)(2014-09-16 16:31:51) 000000004a900000
Library C:\Users\Damian\AppData\Local\Viber\4.3.0.1453\icuuc51.dll (*** suspicious ***) @ C:\Users\Damian\AppData\Local\Viber\Viber.exe [3432] (ICU Common DLL/The ICU Project)(2014-09-16 16:31:51) 0000000000aa0000
Library C:\Users\Damian\AppData\Local\Viber\4.3.0.1453\icudt51.dll (*** suspicious ***) @ C:\Users\Damian\AppData\Local\Viber\Viber.exe [3432] (ICU Data DLL/The ICU Project)(2014-09-16 16:31:51) 0000000069ba0000
Library C:\Users\Damian\AppData\Local\Viber\4.3.0.1453\libexif.dll (*** suspicious ***) @ C:\Users\Damian\AppData\Local\Viber\Viber.exe [3432](2014-09-16 16:31:51) 0000000074170000
---- EOF - GMER 2.1 ----