GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-02-09 19:52:16 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-7 WDC_WD10EZEX-00RKKA0 rev.80.00A80 931,51GB Running: o8iv9548.exe; Driver: C:\Users\THEBER~1\AppData\Local\Temp\kfliypow.sys ---- User code sections - GMER 2.1 ---- .text C:\Windows\SysWOW64\PnkBstrA.exe[1776] C:\Windows\SysWOW64\WSOCK32.dll!recv + 82 0000000074e917fa 2 bytes JMP 00000000852ea373 .text C:\Windows\SysWOW64\PnkBstrA.exe[1776] C:\Windows\SysWOW64\WSOCK32.dll!recvfrom + 88 0000000074e91860 2 bytes JMP 00000000852ea3d9 .text C:\Windows\SysWOW64\PnkBstrA.exe[1776] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 98 0000000074e91942 2 bytes JMP 000000010579a9bb .text C:\Windows\SysWOW64\PnkBstrA.exe[1776] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 109 0000000074e9194d 2 bytes JMP 000000010579a9c6 .text C:\Windows\SysWOW64\PnkBstrA.exe[1776] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000771b1465 2 bytes [1B, 77] .text C:\Windows\SysWOW64\PnkBstrA.exe[1776] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000771b14bb 2 bytes [1B, 77] .text ... * 2 .text C:\Program Files (x86)\Skype\Phone\Skype.exe[3020] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000771b1465 2 bytes [1B, 77] .text C:\Program Files (x86)\Skype\Phone\Skype.exe[3020] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000771b14bb 2 bytes [1B, 77] .text ... * 2 .text D:\Steam\Steam.exe[5500] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 00000000771b1465 2 bytes [1B, 77] .text D:\Steam\Steam.exe[5500] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 00000000771b14bb 2 bytes [1B, 77] .text ... * 2 .text D:\Steam\bin\steamwebhelper.exe[5692] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000771b1465 2 bytes [1B, 77] .text D:\Steam\bin\steamwebhelper.exe[5692] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000771b14bb 2 bytes [1B, 77] .text ... * 2 .text D:\Steam\bin\steamwebhelper.exe[5020] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000771b1465 2 bytes [1B, 77] .text D:\Steam\bin\steamwebhelper.exe[5020] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000771b14bb 2 bytes [1B, 77] .text ... * 2 ---- EOF - GMER 2.1 ----