GMER 2.1.19163 - http://www.gmer.net Rootkit scan 2013-12-15 14:24:40 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T1L0-9 WDC_WD5000AAKS-00UU3A0 rev.01.03B01 465,76GB Running: m57g1hli.exe; Driver: C:\Users\Pietras\AppData\Local\Temp\kwtiyfow.sys ---- User code sections - GMER 2.1 ---- .text C:\Windows\SysWOW64\PnkBstrA.exe[2200] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 0000000071bc1a22 2 bytes [BC, 71] .text C:\Windows\SysWOW64\PnkBstrA.exe[2200] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 0000000071bc1ad0 2 bytes [BC, 71] .text C:\Windows\SysWOW64\PnkBstrA.exe[2200] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 0000000071bc1b08 2 bytes [BC, 71] .text C:\Windows\SysWOW64\PnkBstrA.exe[2200] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 0000000071bc1bba 2 bytes [BC, 71] .text C:\Windows\SysWOW64\PnkBstrA.exe[2200] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 0000000071bc1bda 2 bytes [BC, 71] .text C:\Windows\SysWOW64\PnkBstrA.exe[2200] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076a81465 2 bytes [A8, 76] .text C:\Windows\SysWOW64\PnkBstrA.exe[2200] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076a814bb 2 bytes [A8, 76] .text ... * 2 .text C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe[2224] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076a81465 2 bytes [A8, 76] .text C:\Program Files (x86)\GIGABYTE\Smart6\Timelock\TimeMgmtDaemon.exe[2224] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076a814bb 2 bytes [A8, 76] .text ... * 2 .text C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[2932] C:\Windows\SysWOW64\ntdll.dll!DbgBreakPoint 00000000775c000c 1 byte [C3] .text C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[2932] C:\Windows\SysWOW64\ntdll.dll!DbgUiRemoteBreakin 000000007764f8ea 5 bytes JMP 00000001775fd5c1 .text C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[4488] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076a81465 2 bytes [A8, 76] .text C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[4488] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076a814bb 2 bytes [A8, 76] .text ... * 2 ---- EOF - GMER 2.1 ----