GMER 2.2.19882 - http://www.gmer.net Rootkit scan 2017-04-27 21:48:07 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000002c ADATA_SP550 rev.O1203AB 223.57GB Running: rmq2tm48.exe; Driver: C:\Users\tada4\AppData\Local\Temp\kflcqkow.sys ---- Disk sectors - GMER 2.2 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- Threads - GMER 2.2 ---- Thread C:\WINDOWS\system32\csrss.exe [604:1000] ffff8f3c2b1d9ac0 ---- Services - GMER 2.2 ---- Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] CDPUserSvc_548bb <-- ROOTKIT !!! Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [MANUAL] DevicesFlowUserSvc_548bb <-- ROOTKIT !!! Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [MANUAL] MessagingService_548bb <-- ROOTKIT !!! Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] OneSyncSvc_548bb <-- ROOTKIT !!! Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [MANUAL] PimIndexMaintenanceSvc_548bb <-- ROOTKIT !!! Service C:\WINDOWS\System32\svchost.exe (*** hidden *** ) [MANUAL] UnistoreSvc_548bb <-- ROOTKIT !!! Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [MANUAL] UserDataSvc_548bb <-- ROOTKIT !!! Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] WpnUserService_548bb <-- ROOTKIT !!! ---- EOF - GMER 2.2 ----