GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-07-02 14:07:55 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST1000DM003-1CH162 rev.CC47 931,51GB Running: 8u538nfn.exe; Driver: C:\Users\Admin\AppData\Local\Temp\pxldypow.sys ---- User code sections - GMER 2.1 ---- .text C:\Windows\system32\hasplms.exe[2020] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076771465 2 bytes [77, 76] .text C:\Windows\system32\hasplms.exe[2020] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000767714bb 2 bytes [77, 76] .text ... * 2 .text C:\Program Files (x86)\MiuiTab\ProtectService.exe[1092] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076771465 2 bytes [77, 76] .text C:\Program Files (x86)\MiuiTab\ProtectService.exe[1092] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000767714bb 2 bytes [77, 76] .text ... * 2 .text C:\Windows\SysWOW64\PnkBstrA.exe[1424] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 0000000073da1a22 2 bytes [DA, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[1424] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 0000000073da1ad0 2 bytes [DA, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[1424] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 0000000073da1b08 2 bytes [DA, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[1424] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 0000000073da1bba 2 bytes [DA, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[1424] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 0000000073da1bda 2 bytes [DA, 73] .text C:\Windows\SysWOW64\PnkBstrA.exe[1424] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076771465 2 bytes [77, 76] .text C:\Windows\SysWOW64\PnkBstrA.exe[1424] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000767714bb 2 bytes [77, 76] .text ... * 2 .text C:\Program Files\AVAST Software\Avast\avastui.exe[3752] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 00000000765a87c9 8 bytes [31, C0, C2, 04, 00, 90, 90, ...] .text C:\Users\Admin\AppData\Local\GG\Application\ggdrive\ggdrive.exe[5028] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076771465 2 bytes [77, 76] .text C:\Users\Admin\AppData\Local\GG\Application\ggdrive\ggdrive.exe[5028] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000767714bb 2 bytes [77, 76] .text ... * 2 .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[880] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076771465 2 bytes [77, 76] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[880] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000767714bb 2 bytes [77, 76] .text ... * 2 .text C:\Program Files (x86)\MiuiTab\HPNotify.exe[5012] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076771465 2 bytes [77, 76] .text C:\Program Files (x86)\MiuiTab\HPNotify.exe[5012] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000767714bb 2 bytes [77, 76] .text ... * 2 ---- User IAT/EAT - GMER 2.1 ---- IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1952] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamDWord] [7fef9ca741c] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1952] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSet] [7fef9ca5f10] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1952] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmEndSession] [7fef9ca5674] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1952] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartSession] [7fef9ca5e2c] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1952] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartUpload] [7fef9ca7f48] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1952] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppVersion] [7fef9ca6a38] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1952] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetMachineId] [7fef9ca6ee8] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1952] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmWriteSharedMachineId] [7fef9ca7b58] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1952] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmCreateNewId] [7fef9ca7ea0] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1952] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmReadSharedMachineId] [7fef9ca78b0] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1952] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmGetSession] [7fef9ca4fb4] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1952] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppId] [7fef9ca5d38] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[1952] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamString] [7fef9ca7584] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll ---- Threads - GMER 2.1 ---- Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [3216:3968] 000007fefc202ab8 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [3216:592] 000007fefa105124 Thread C:\Windows\System32\svchost.exe [4916:1448] 000007fee35c9688 ---- EOF - GMER 2.1 ----