GMER 2.1.19163 - http://www.gmer.net Rootkit scan 2013-10-19 00:23:56 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD1600JS-22MHB0 rev.02.01C03 149,05GB Running: m57g1hli.exe; Driver: C:\Users\admin\AppData\Local\Temp\kwloqpow.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe[1380] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000077448769 4 bytes [C2, 04, 00, 00] .text C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe[1380] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000075de1465 2 bytes [DE, 75] .text C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe[1380] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 0000000075de14bb 2 bytes [DE, 75] .text ... * 2 .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1108] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075de1465 2 bytes [DE, 75] .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1108] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075de14bb 2 bytes [DE, 75] .text ... * 2 ---- Threads - GMER 2.1 ---- Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [1416:1456] 0000000076527587 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [1416:2716] 0000000074710cb3 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [1416:2696] 0000000077e02e65 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [1416:3680] 0000000077e03e85 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [1416:3064] 0000000077e03e85 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [1416:3604] 0000000077e03e85 ---- EOF - GMER 2.1 ----