GMER 2.1.19324 - http://www.gmer.net Rootkit scan 2014-01-18 20:23:53 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD3200BPVT-80JJ5T0 rev.01.01A01 298,09GB Running: gmer.exe; Driver: C:\Users\Ania\AppData\Local\Temp\aftcqaog.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff800035b6000 65 bytes [00, 00, FC, 02, 74, 6D, 74, ...] INITKDBG C:\windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 594 fffff800035b6042 4 bytes [00, 00, 06, 00] ---- User code sections - GMER 2.1 ---- .text C:\ProgramData\WPM\wprotectmanager.exe[1472] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076a41465 2 bytes [A4, 76] .text C:\ProgramData\WPM\wprotectmanager.exe[1472] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076a414bb 2 bytes [A4, 76] .text ... * 2 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3584] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076a41465 2 bytes [A4, 76] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3584] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076a414bb 2 bytes [A4, 76] .text ... * 2 .text C:\Program Files (x86)\ASUS\SmartCamera\SmartCamera.exe[3940] C:\Windows\SysWOW64\ksuser.dll!KsCreatePin + 35 000000006e7611a8 2 bytes [76, 6E] .text C:\Program Files (x86)\ASUS\SmartCamera\SmartCamera.exe[3940] C:\Windows\SysWOW64\ksuser.dll!KsCreateAllocator + 21 000000006e7613a8 2 bytes [76, 6E] .text C:\Program Files (x86)\ASUS\SmartCamera\SmartCamera.exe[3940] C:\Windows\SysWOW64\ksuser.dll!KsCreateClock + 21 000000006e761422 2 bytes [76, 6E] .text C:\Program Files (x86)\ASUS\SmartCamera\SmartCamera.exe[3940] C:\Windows\SysWOW64\ksuser.dll!KsCreateTopologyNode + 19 000000006e761498 2 bytes [76, 6E] .text C:\Program Files (x86)\ASUS\SmartCamera\SmartCamera.exe[3940] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 195 0000000071241b41 2 bytes [24, 71] .text C:\Program Files (x86)\ASUS\SmartCamera\SmartCamera.exe[3940] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 362 0000000071241be8 2 bytes [24, 71] .text C:\Program Files (x86)\ASUS\SmartCamera\SmartCamera.exe[3940] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 418 0000000071241c20 2 bytes [24, 71] .text C:\Program Files (x86)\ASUS\SmartCamera\SmartCamera.exe[3940] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 596 0000000071241cd2 2 bytes [24, 71] .text C:\Program Files (x86)\ASUS\SmartCamera\SmartCamera.exe[3940] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 628 0000000071241cf2 2 bytes [24, 71] .text C:\windows\SysWOW64\RunDll32.exe[4640] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076a41465 2 bytes [A4, 76] .text C:\windows\SysWOW64\RunDll32.exe[4640] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076a414bb 2 bytes [A4, 76] .text ... * 2 .text C:\Program Files\AVAST Software\Avast\avastUi.exe[4688] C:\windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000751fa2ba 1 byte [62] .text C:\windows\system32\AUDIODG.EXE[7140] C:\windows\System32\kernel32.dll!GetBinaryTypeW + 189 00000000771deecd 1 byte [62] .text C:\Users\Ania\AppData\Local\Lollipop\lollipop_01181833.exe[5112] C:\windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000751fa2ba 1 byte [62] .text C:\Users\Ania\AppData\Local\Lollipop\lollipop_01181833.exe[5112] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076a41465 2 bytes [A4, 76] .text C:\Users\Ania\AppData\Local\Lollipop\lollipop_01181833.exe[5112] C:\windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076a414bb 2 bytes [A4, 76] .text ... * 2 ? C:\windows\system32\mssprxy.dll [5112] entry point in ".rdata" section 00000000728371e6 .text C:\Users\Ania\Desktop\fixitpc\gmer.exe[6792] C:\windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000751fa2ba 1 byte [62] ---- Threads - GMER 2.1 ---- Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4516:4888] 000007fefb7f2a7c Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4516:4944] 000007feecb94830 Thread C:\Users\Ania\AppData\Local\Lollipop\lollipop_01181833.exe [5112:6888] 00000000100239f2 Thread C:\Users\Ania\AppData\Local\Lollipop\lollipop_01181833.exe [5112:5488] 000000001003d8bd Thread C:\Users\Ania\AppData\Local\Lollipop\lollipop_01181833.exe [5112:3168] 0000000010032ad7 Thread C:\Users\Ania\AppData\Local\Lollipop\lollipop_01181833.exe [5112:6344] 00000000100449f1 Thread C:\Users\Ania\AppData\Local\Lollipop\lollipop_01181833.exe [5112:6892] 0000000010013f88 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0008caad8bed Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0008caad8bed@a4ebd3160a59 0xDD 0xE6 0x0F 0x5F ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0008caad8bed@20689dd0bfb3 0x57 0x99 0x4A 0x3B ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0025d3b2962e Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Teredo\PreviousState\00-25-86-ce-83-bc@TeredoAddress 2001:0:9d38:6ab8:8e6:b718:4f22:8639 Reg HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Epoch2@Epoch 21289 Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0008caad8bed (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0008caad8bed@a4ebd3160a59 0xDD 0xE6 0x0F 0x5F ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0008caad8bed@20689dd0bfb3 0x57 0x99 0x4A 0x3B ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0025d3b2962e (not active ControlSet) ---- EOF - GMER 2.1 ----