GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-07-04 17:16:54 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 SAMSUNG_HD103SJ rev.1AJ100E5 931,51GB Running: 7dw64tvp.exe; Driver: C:\Users\PAWE~1\AppData\Local\Temp\pwddapoc.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff800039af000 45 bytes [00, 00, 22, 02, 4D, 6D, 43, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575 fffff800039af02f 16 bytes [00, 02, 00, 00, 00, 00, 00, ...] ---- User code sections - GMER 2.1 ---- .text C:\Windows\SysWOW64\PnkBstrA.exe[2036] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 0000000072881a22 2 bytes [88, 72] .text C:\Windows\SysWOW64\PnkBstrA.exe[2036] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 0000000072881ad0 2 bytes [88, 72] .text C:\Windows\SysWOW64\PnkBstrA.exe[2036] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 0000000072881b08 2 bytes [88, 72] .text C:\Windows\SysWOW64\PnkBstrA.exe[2036] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 0000000072881bba 2 bytes [88, 72] .text C:\Windows\SysWOW64\PnkBstrA.exe[2036] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 0000000072881bda 2 bytes [88, 72] .text C:\Windows\SysWOW64\PnkBstrA.exe[2036] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076ee1465 2 bytes [EE, 76] .text C:\Windows\SysWOW64\PnkBstrA.exe[2036] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076ee14bb 2 bytes [EE, 76] .text ... * 2 .text C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe[1960] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076ee1465 2 bytes [EE, 76] .text C:\Program Files (x86)\OSCAR Editor X7\OscarEditor.exe[1960] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076ee14bb 2 bytes [EE, 76] .text ... * 2 .text C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.0\bin\TrayPopupE\TrayTipAgentE.exe[2244] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076ee1465 2 bytes [EE, 76] .text C:\Program Files (x86)\EaseUS\EaseUS Partition Master 10.0\bin\TrayPopupE\TrayTipAgentE.exe[2244] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076ee14bb 2 bytes [EE, 76] .text ... * 2 ---- EOF - GMER 2.1 ----