GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-10-30 11:46:45 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 ST31000524AS rev.JC45 931,51GB Running: kzwxlgo0.exe; Driver: C:\Users\Kornel\AppData\Local\Temp\kwrdapow.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000759a1465 2 bytes [9A, 75] .text C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe[1568] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000759a14bb 2 bytes [9A, 75] .text ... * 2 .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[1756] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000759a1465 2 bytes [9A, 75] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[1756] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000759a14bb 2 bytes [9A, 75] .text ... * 2 .text C:\Users\Kornel\AppData\Roaming\uTorrent\uTorrent.exe[2840] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000759a1465 2 bytes [9A, 75] .text C:\Users\Kornel\AppData\Roaming\uTorrent\uTorrent.exe[2840] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000759a14bb 2 bytes [9A, 75] .text ... * 2 .text C:\Program Files (x86)\RocketDock\RocketDock.exe[2848] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000759a1465 2 bytes [9A, 75] .text C:\Program Files (x86)\RocketDock\RocketDock.exe[2848] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000759a14bb 2 bytes [9A, 75] .text ... * 2 .text C:\Program Files (x86)\screenSHU\screenSHU.exe[2856] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000759a1465 2 bytes [9A, 75] .text C:\Program Files (x86)\screenSHU\screenSHU.exe[2856] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000759a14bb 2 bytes [9A, 75] .text ... * 2 .text C:\Users\Kornel\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[2916] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000759a1465 2 bytes [9A, 75] .text C:\Users\Kornel\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe[2916] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000759a14bb 2 bytes [9A, 75] .text ... * 2 .text C:\Users\Kornel\AppData\Roaming\Dropbox\bin\Dropbox.exe[2988] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000759a1465 2 bytes [9A, 75] .text C:\Users\Kornel\AppData\Roaming\Dropbox\bin\Dropbox.exe[2988] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000759a14bb 2 bytes [9A, 75] .text ... * 2 .text C:\Users\Kornel\Desktop\Nowy folder\kzwxlgo0.exe[3028] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000759a1465 2 bytes [9A, 75] .text C:\Users\Kornel\Desktop\Nowy folder\kzwxlgo0.exe[3028] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000759a14bb 2 bytes [9A, 75] .text ... * 2 ---- Threads - GMER 2.1 ---- Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [2996:2120] 000007fefb6e2ab8 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [2996:2556] 000007fee511d618 ---- Processes - GMER 2.1 ---- Library C:\Users\Kornel\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll (*** suspicious ***) @ C:\Users\Kornel\AppData\Roaming\Dropbox\bin\Dropbox.exe [2988](2014-09-13 00:20:58) 0000000003fd0000 Library c:\users\kornel\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpcx0sll.dll (*** suspicious ***) @ C:\Users\Kornel\AppData\Roaming\Dropbox\bin\Dropbox.exe [2988](2014-10-30 09:31:50) 0000000004420000 Library C:\Users\Kornel\AppData\Roaming\Dropbox\bin\libcef.dll (*** suspicious ***) @ C:\Users\Kornel\AppData\Roaming\Dropbox\bin\Dropbox.exe [2988](2013-08-23 19:01:44) 000000006d310000 Library C:\Users\Kornel\AppData\Roaming\Dropbox\bin\icudt.dll (*** suspicious ***) @ C:\Users\Kornel\AppData\Roaming\Dropbox\bin\Dropbox.exe [2988] (ICU Data DLL/The ICU Project)(2013-08-23 19:01:42) 000000006b910000 ---- EOF - GMER 2.1 ----