GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-05-20 07:48:37
Windows 6.2.9200  x64 \Device\Harddisk0\DR0 -> \Device\0000003b TOSHIBA_MQ01ABD100 rev.AX001C 931,51GB
Running: iwsuvvez.exe; Driver: C:\Users\Robert\AppData\Local\Temp\agloapow.sys


---- Kernel code sections - GMER 2.1 ----

.text   C:\Windows\system32\ntoskrnl.exe!KiCpuId + 988                                                                       fffff800332de3dc 1 byte [31]

---- User code sections - GMER 2.1 ----

.text   C:\Windows\system32\dwm.exe[964] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW                                     000007fe2ec0259c 8 bytes JMP 000007ff2d9d0340
.text   C:\Windows\system32\dwm.exe[964] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW                                   000007fe2ec06b00 9 bytes JMP 000007ff2d9d0298
.text   C:\Windows\system32\dwm.exe[964] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation                            000007fe2ec85908 7 bytes JMP 000007ff2d9d0260
.text   C:\Windows\system32\dwm.exe[964] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW                                    000007fe2eca1610 7 bytes JMP 000007ff2d9d02d0
.text   C:\Windows\system32\dwm.exe[964] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW                              000007fe2ecb49a4 7 bytes JMP 000007ff2d9d0228
.text   C:\Windows\system32\dwm.exe[964] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx                            000007fe2ecb4a38 8 bytes JMP 000007ff2d9d01f0
.text   C:\Windows\system32\dwm.exe[964] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA                                     000007fe2ecb5074 8 bytes JMP 000007ff2d9d0308
.text   C:\Windows\system32\dwm.exe[964] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                 000007fe2d9e1f70 7 bytes JMP 000007ff2d9d00d8
.text   C:\Windows\system32\dwm.exe[964] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                      000007fe2d9e1ff0 5 bytes JMP 000007ff2d9d0180
.text   C:\Windows\system32\dwm.exe[964] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                               000007fe2d9e5880 5 bytes JMP 000007ff2d9d0110
.text   C:\Windows\system32\dwm.exe[964] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                   000007fe2d9e8650 6 bytes JMP 000007ff2d9d0148
.text   C:\Windows\system32\dwm.exe[964] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW                             000007fe2da10510 5 bytes JMP 000007ff2d9d01b8
.text   C:\Windows\system32\dwm.exe[964] C:\Windows\system32\USER32.dll!CreateWindowExW                                      000007fe2edfc5b0 7 bytes JMP 000007ff2d9d0420
.text   C:\Windows\system32\dwm.exe[964] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo                           000007fe2ee031f0 1 byte JMP 000007ff2d9d0378
.text   C:\Windows\system32\dwm.exe[964] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo + 2                       000007fe2ee031f2 7 bytes {JMP 0xfffffffffebcd188}
.text   C:\Windows\system32\dwm.exe[964] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW                                  000007fe2ee033e0 5 bytes JMP 000007ff2d9d03e8
.text   C:\Windows\system32\dwm.exe[964] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA                                  000007fe2ee07160 5 bytes JMP 000007ff2d9d03b0
.text   C:\Windows\system32\dwm.exe[964] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                000007fe30501070 8 bytes JMP 000007ff2d9d0490
.text   C:\Windows\system32\dwm.exe[964] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                              000007fe30520c10 8 bytes JMP 000007ff2d9d0458
.text   C:\Windows\system32\dwm.exe[964] C:\Windows\system32\dxgi.dll!CreateDXGIFactory1                                     000007fe2b8a6d10 5 bytes JMP 000007ff2b690110
.text   C:\Windows\system32\dwm.exe[964] C:\Windows\system32\dxgi.dll!CreateDXGIFactory                                      000007fe2b8ad060 5 bytes JMP 000007ff2b6900d8
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[1152] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690              000007fe29ed1532 4 bytes [ED, 29, FE, 07]
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[1152] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698              000007fe29ed153a 4 bytes [ED, 29, FE, 07]
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[1152] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246            000007fe29ed165a 4 bytes [ED, 29, FE, 07]
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1192] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690    000007fe29ed1532 4 bytes [ED, 29, FE, 07]
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1192] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698    000007fe29ed153a 4 bytes [ED, 29, FE, 07]
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1192] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246  000007fe29ed165a 4 bytes [ED, 29, FE, 07]
.text   C:\Windows\system32\nvvsvc.exe[1200] C:\Windows\system32\MSIMG32.dll!GradientFill + 690                              000007fe29ed1532 4 bytes [ED, 29, FE, 07]
.text   C:\Windows\system32\nvvsvc.exe[1200] C:\Windows\system32\MSIMG32.dll!GradientFill + 698                              000007fe29ed153a 4 bytes [ED, 29, FE, 07]
.text   C:\Windows\system32\nvvsvc.exe[1200] C:\Windows\system32\MSIMG32.dll!TransparentBlt + 246                            000007fe29ed165a 4 bytes [ED, 29, FE, 07]
.text   C:\Windows\system32\nvvsvc.exe[1200] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306                    000007fe2e5e177a 4 bytes [5E, 2E, FE, 07]
.text   C:\Windows\system32\nvvsvc.exe[1200] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314                    000007fe2e5e1782 4 bytes [5E, 2E, FE, 07]
.text   C:\Windows\System32\spoolsv.exe[1620] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306                   000007fe2e5e177a 4 bytes [5E, 2E, FE, 07]
.text   C:\Windows\System32\spoolsv.exe[1620] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314                   000007fe2e5e1782 4 bytes [5E, 2E, FE, 07]
?       C:\Windows\SYSTEM32\BsHelpCSps.dll [1948] entry point in ".data" section                                             00000000029d5055
.text   C:\Windows\Explorer.EXE[3520] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306                           000007fe2e5e177a 4 bytes [5E, 2E, FE, 07]
.text   C:\Windows\Explorer.EXE[3520] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314                           000007fe2e5e1782 4 bytes [5E, 2E, FE, 07]
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3088] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690      000007fe29ed1532 4 bytes [ED, 29, FE, 07]
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3088] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698      000007fe29ed153a 4 bytes [ED, 29, FE, 07]
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3088] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246    000007fe29ed165a 4 bytes [ED, 29, FE, 07]
.text   C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4276] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690            000007fe29ed1532 4 bytes [ED, 29, FE, 07]
.text   C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4276] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698            000007fe29ed153a 4 bytes [ED, 29, FE, 07]
.text   C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4276] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246          000007fe29ed165a 4 bytes [ED, 29, FE, 07]
?       C:\Windows\SYSTEM32\BsHelpCSps.dll [4584] entry point in ".data" section                                             0000000003775055
?       C:\Windows\SYSTEM32\BlueSoleilCSps.dll [4584] entry point in ".rdata" section                                        00000000037a4085

---- Threads - GMER 2.1 ----

Thread  C:\Windows\system32\csrss.exe [604:628]                                                                              fffff9600094f5e8

---- Disk sectors - GMER 2.1 ----

Disk    \Device\Harddisk0\DR0                                                                                                unknown MBR code

---- EOF - GMER 2.1 ----
