GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-05-26 21:42:17 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.FB4O 298,09GB Running: z6hxfcim.exe; Driver: C:\Users\Zdzisek\AppData\Local\Temp\uxtyyaob.sys ---- Processes - GMER 2.1 ---- Library C:\Windows\TEMP\6323203B-104D-4D59-B283-55D9CF4385B7\dismhost.exe (*** suspicious ***) @ C:\Windows\TEMP\6323203B-104D-4D59-B283-55D9CF4385B7\dismhost.exe [1568] 00000000ff030000 Library C:\Windows\TEMP\6323203B-104D-4D59-B283-55D9CF4385B7\DismCorePS.dll (*** suspicious ***) @ C:\Windows\TEMP\6323203B-104D-4D59-B283-55D9CF4385B7\dismhost.exe [1568] 000007feef7a0000 Library C:\Windows\TEMP\6323203B-104D-4D59-B283-55D9CF4385B7\wdscore.dll (*** suspicious ***) @ C:\Windows\TEMP\6323203B-104D-4D59-B283-55D9CF4385B7\dismhost.exe [1568] 000007feef750000 Library C:\Windows\TEMP\6323203B-104D-4D59-B283-55D9CF4385B7\dismprov.dll (*** suspicious ***) @ C:\Windows\TEMP\6323203B-104D-4D59-B283-55D9CF4385B7\dismhost.exe [1568] 000007feef580000 Library C:\Windows\TEMP\6323203B-104D-4D59-B283-55D9CF4385B7\OSProvider.dll (*** suspicious ***) @ C:\Windows\TEMP\6323203B-104D-4D59-B283-55D9CF4385B7\dismhost.exe [1568] 000007feef710000 Library C:\Windows\TEMP\6323203B-104D-4D59-B283-55D9CF4385B7\LogProvider.dll (*** suspicious ***) @ C:\Windows\TEMP\6323203B-104D-4D59-B283-55D9CF4385B7\dismhost.exe [1568] 000007feef550000 Library C:\Windows\TEMP\6323203B-104D-4D59-B283-55D9CF4385B7\DmiProvider.dll (*** suspicious ***) @ C:\Windows\TEMP\6323203B-104D-4D59-B283-55D9CF4385B7\dismhost.exe [1568] 000007feef330000 ---- EOF - GMER 2.1 ----