GMER 2.1.19163 - http://www.gmer.net Rootkit scan 2014-08-26 22:46:27 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST950032 rev.0001 465,76GB Running: m57g1hli.exe; Driver: C:\Users\BLALA\AppData\Local\Temp\pwldapog.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80002fb9000 45 bytes [00, 00, 10, 02, 4D, 6D, 43, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575 fffff80002fb902f 16 bytes [00, 02, 00, 00, 00, 00, 00, ...] ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074ed1465 2 bytes [ED, 74] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074ed14bb 2 bytes [ED, 74] .text ... * 2 .text C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[3400] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074ed1465 2 bytes [ED, 74] .text C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[3400] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074ed14bb 2 bytes [ED, 74] .text ... * 2 .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3992] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074ed1465 2 bytes [ED, 74] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3992] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074ed14bb 2 bytes [ED, 74] .text ... * 2 ---- EOF - GMER 2.1 ----