GMER 2.1.19163 - http://www.gmer.net Rootkit scan 2014-11-06 14:06:49 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\00000068 WDC_____ rev.08.0 149,05GB Running: m57g1hli.exe; Driver: C:\Users\xxxxx\AppData\Local\Temp\ugrdifow.sys ---- User code sections - GMER 2.1 ---- .text C:\Windows\system32\PnkBstrA.exe[1804] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000763c1465 2 bytes [3C, 76] .text C:\Windows\system32\PnkBstrA.exe[1804] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000763c14bb 2 bytes [3C, 76] .text ... * 2 .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4092] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000763c1465 2 bytes [3C, 76] .text C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4092] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000763c14bb 2 bytes [3C, 76] .text ... * 2 .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[3872] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000763c1465 2 bytes [3C, 76] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[3872] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000763c14bb 2 bytes [3C, 76] .text ... * 2 .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4084] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000763c1465 2 bytes [3C, 76] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[4084] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000763c14bb 2 bytes [3C, 76] .text ... * 2 ---- Threads - GMER 2.1 ---- Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [3560:3868] 000007fefb032bf8 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [3560:3968] 000007fef9285124 ---- EOF - GMER 2.1 ----