GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-12-26 17:17:49 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\00000053 WDC_WD10 rev.51.0 931,51GB Running: sukwp0qn.exe; Driver: C:\Users\Rafi\AppData\Local\Temp\kxldrpod.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80002fa9000 45 bytes [00, 00, 00, 00, 00, 00, 00, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575 fffff80002fa902f 16 bytes [00, 00, 00, 00, 00, 00, 00, ...] ---- User code sections - GMER 2.1 ---- .text C:\Windows\SysWOW64\PnkBstrA.exe[1772] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 00000000743d1a22 2 bytes [3D, 74] .text C:\Windows\SysWOW64\PnkBstrA.exe[1772] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 00000000743d1ad0 2 bytes [3D, 74] .text C:\Windows\SysWOW64\PnkBstrA.exe[1772] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 00000000743d1b08 2 bytes [3D, 74] .text C:\Windows\SysWOW64\PnkBstrA.exe[1772] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 00000000743d1bba 2 bytes [3D, 74] .text C:\Windows\SysWOW64\PnkBstrA.exe[1772] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 00000000743d1bda 2 bytes [3D, 74] .text C:\Windows\SysWOW64\PnkBstrA.exe[1772] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075d81465 2 bytes [D8, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[1772] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075d814bb 2 bytes [D8, 75] .text ... * 2 .text C:\Users\Rafi\Downloads\sukwp0qn.exe[4852] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075d81465 2 bytes [D8, 75] .text C:\Users\Rafi\Downloads\sukwp0qn.exe[4852] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075d814bb 2 bytes [D8, 75] .text ... * 2 ---- Files - GMER 2.1 ---- File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\59C2.tmp 28134 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\5BA8.tmp 0 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\5BA9.tmp 28134 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\5CA4.tmp 28134 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\5CF4.tmp 28134 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\5D54.tmp 28134 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\5D75.tmp 28134 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\5DB5.tmp 28134 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\5DE6.tmp 28134 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\5E36.tmp 0 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\5E37.tmp 28134 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\5E97.tmp 28134 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\5F16.tmp 28134 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\5F66.tmp 0 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\5F67.tmp 28134 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\5FC6.tmp 28134 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\6035.tmp 28134 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\6076.tmp 28134 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\6183.tmp 28134 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\633A.tmp 28134 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\64A3.tmp 28134 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\661B.tmp 28134 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\667B.tmp 28134 bytes File C:\Users\Rafi\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\6776.tmp 28134 bytes ---- EOF - GMER 2.1 ----