GMER 2.1.19163 - http://www.gmer.net Rootkit scan 2013-07-27 01:18:42 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-3 OCZ-AGILITY3 rev.2.15 55,90GB Running: m11bnidi.exe; Driver: C:\Users\User\AppData\Local\Temp\aftcaaob.sys ---- User code sections - GMER 2.1 ---- .text C:\Windows\SysWOW64\PnkBstrA.exe[1948] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 00000000739e1a22 2 bytes [9E, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[1948] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 00000000739e1ad0 2 bytes [9E, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[1948] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 00000000739e1b08 2 bytes [9E, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[1948] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 00000000739e1bba 2 bytes [9E, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[1948] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 00000000739e1bda 2 bytes [9E, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[1948] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000771d1465 2 bytes [1D, 77] .text C:\Windows\SysWOW64\PnkBstrA.exe[1948] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000771d14bb 2 bytes [1D, 77] .text ... * 2 .text C:\Program Files (x86)\Gadu-Gadu\gg.exe[2144] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000771d1465 2 bytes [1D, 77] .text C:\Program Files (x86)\Gadu-Gadu\gg.exe[2144] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000771d14bb 2 bytes [1D, 77] .text ... * 2 .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2228] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 00000000770d87c9 5 bytes [33, C0, C2, 04, 00] .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000771d1465 2 bytes [1D, 77] .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000771d14bb 2 bytes [1D, 77] .text ... * 2 .text C:\Program Files (x86)\ASUS\GPU Tweak\GPUTweak.exe[2296] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000771d1465 2 bytes [1D, 77] .text C:\Program Files (x86)\ASUS\GPU Tweak\GPUTweak.exe[2296] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000771d14bb 2 bytes [1D, 77] .text ... * 2 .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3056] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000771d1465 2 bytes [1D, 77] .text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3056] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000771d14bb 2 bytes [1D, 77] .text ... * 2 ---- User IAT/EAT - GMER 2.1 ---- IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1516] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamDWord] [7fef93f741c] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1516] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSet] [7fef93f5f10] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1516] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmEndSession] [7fef93f5674] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1516] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartSession] [7fef93f5e2c] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1516] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartUpload] [7fef93f7f48] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1516] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppVersion] [7fef93f6a38] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1516] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetMachineId] [7fef93f6ee8] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1516] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmWriteSharedMachineId] [7fef93f7b58] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1516] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmCreateNewId] [7fef93f7ea0] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1516] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmReadSharedMachineId] [7fef93f78b0] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1516] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmGetSession] [7fef93f4fb4] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1516] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppId] [7fef93f5d38] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1516] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamString] [7fef93f7584] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll ---- Files - GMER 2.1 ---- File C:\Users\User\AppData\Local\Temp\acro_rd_dir\fla3596.tmp 0 bytes ---- EOF - GMER 2.1 ----