GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-12-11 17:50:03 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T0L0-0 ST3160811AS rev.3.AAE 149,05GB Running: i51z372e.exe; Driver: C:\Users\Witek\AppData\Local\Temp\kwddakog.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff800041fc000 16 bytes [8B, E3, 41, 5F, 41, 5E, 41, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 545 fffff800041fc011 35 bytes {LEA ECX, [RSP+0x70]; CALL 0x3d64f} ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[1692] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074d21465 2 bytes [D2, 74] .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[1692] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074d214bb 2 bytes [D2, 74] .text ... * 2 .text C:\Windows\SysWOW64\PnkBstrA.exe[1992] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 0000000071bc1a22 2 bytes [BC, 71] .text C:\Windows\SysWOW64\PnkBstrA.exe[1992] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 0000000071bc1ad0 2 bytes [BC, 71] .text C:\Windows\SysWOW64\PnkBstrA.exe[1992] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 0000000071bc1b08 2 bytes [BC, 71] .text C:\Windows\SysWOW64\PnkBstrA.exe[1992] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 0000000071bc1bba 2 bytes [BC, 71] .text C:\Windows\SysWOW64\PnkBstrA.exe[1992] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 0000000071bc1bda 2 bytes [BC, 71] .text C:\Windows\SysWOW64\PnkBstrA.exe[1992] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074d21465 2 bytes [D2, 74] .text C:\Windows\SysWOW64\PnkBstrA.exe[1992] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074d214bb 2 bytes [D2, 74] .text ... * 2 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2044] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000074d21465 2 bytes [D2, 74] .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2044] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 0000000074d214bb 2 bytes [D2, 74] .text ... * 2 .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2100] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074d21465 2 bytes [D2, 74] .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2100] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074d214bb 2 bytes [D2, 74] .text ... * 2 ---- EOF - GMER 2.1 ----