GMER 2.2.19882 - http://www.gmer.net Rootkit scan 2016-04-16 22:05:57 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 SAMSUNG_HD502HI rev.1AG01118 465,76GB Running: 4yytu8tb.exe; Driver: C:\Users\Adrian\AppData\Local\Temp\awrdypog.sys ---- User code sections - GMER 2.2 ---- .text C:\Windows\SysWOW64\PnkBstrA.exe[1680] C:\Windows\SysWOW64\WSOCK32.dll!recv + 82 000000006f9b17fa 2 bytes CALL 752c11a9 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1680] C:\Windows\SysWOW64\WSOCK32.dll!recvfrom + 88 000000006f9b1860 2 bytes CALL 752c11a9 C:\Windows\syswow64\kernel32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1680] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 98 000000006f9b1942 2 bytes JMP 76bc7089 C:\Windows\syswow64\WS2_32.dll .text C:\Windows\SysWOW64\PnkBstrA.exe[1680] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 109 000000006f9b194d 2 bytes JMP 76bccba6 C:\Windows\syswow64\WS2_32.dll ---- Files - GMER 2.2 ---- File C:\Users\Adrian\AppData\Local\Mozilla\Firefox\Profiles\7jg2r192.default-1460470008977\cache2\entries\CB1CDE92B44C26519E39A96359B2BE2D5405FD12 0 bytes File C:\Users\Adrian\AppData\Local\Mozilla\Firefox\Profiles\7jg2r192.default-1460470008977\cache2\entries\06D2C4A9F50A8E41E2A3E88C53C95FDE03481A5A 0 bytes File C:\Users\Adrian\AppData\Local\Mozilla\Firefox\Profiles\7jg2r192.default-1460470008977\cache2\entries\D402D211A5A8C3797E235A12C818EFFC82E229FA 0 bytes File C:\Users\Adrian\AppData\Local\Mozilla\Firefox\Profiles\7jg2r192.default-1460470008977\cache2\entries\E1CCF8CE4C0E63D39B85387B7BFAE7DCC3C5F99B 4120 bytes File C:\Users\Adrian\AppData\Local\Mozilla\Firefox\Profiles\7jg2r192.default-1460470008977\cache2\entries\5C6A9EAB2035744E388773D95ABE65E458ED62E0 4141 bytes File C:\Users\Adrian\AppData\Local\Mozilla\Firefox\Profiles\7jg2r192.default-1460470008977\cache2\entries\8B261CF2C3CBE0A72C336EE52E736A1F591043AE 318 bytes File C:\Users\Adrian\AppData\Local\Mozilla\Firefox\Profiles\7jg2r192.default-1460470008977\cache2\entries\A1CAF8F71B666502FE766C5AC9A55C663B63E399 4200 bytes File C:\Users\Adrian\AppData\Local\Mozilla\Firefox\Profiles\7jg2r192.default-1460470008977\cache2\entries\9FD12521DBE5671D3B28551563982F10A296F598 3760 bytes ---- EOF - GMER 2.2 ----