GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-10-10 02:44:47 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 WDC_WD3200AAJS-00B4A0 rev.01.03A01 298,09GB Running: b6wj0oll.exe; Driver: C:\Users\User\AppData\Local\Temp\fwrcaaob.sys ---- User code sections - GMER 2.1 ---- .text C:\Windows\SysWOW64\PnkBstrA.exe[1900] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 0000000073f51a22 2 bytes [F5, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[1900] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 0000000073f51ad0 2 bytes [F5, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[1900] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 0000000073f51b08 2 bytes [F5, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[1900] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 0000000073f51bba 2 bytes [F5, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[1900] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 0000000073f51bda 2 bytes [F5, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[1900] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075fc1465 2 bytes [FC, 75] .text C:\Windows\SysWOW64\PnkBstrA.exe[1900] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075fc14bb 2 bytes [FC, 75] .text ... * 2 .text C:\Users\User\AppData\Local\Akamai\netsession_win.exe[2500] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075fc1465 2 bytes [FC, 75] .text C:\Users\User\AppData\Local\Akamai\netsession_win.exe[2500] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075fc14bb 2 bytes [FC, 75] .text ... * 2 .text D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe[2604] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075fc1465 2 bytes [FC, 75] .text D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe[2604] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075fc14bb 2 bytes [FC, 75] .text ... * 2 .text C:\Users\User\AppData\Local\Akamai\netsession_win.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075fc1465 2 bytes [FC, 75] .text C:\Users\User\AppData\Local\Akamai\netsession_win.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075fc14bb 2 bytes [FC, 75] .text ... * 2 .text C:\Program Files\AVAST Software\Avast\avastui.exe[3612] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 00000000765187c9 8 bytes [31, C0, C2, 04, 00, 90, 90, ...] ---- EOF - GMER 2.1 ----