GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-08-02 17:50:11 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 CT250BX100SSD1 rev.MU02 232,89GB Running: gmer.exe; Driver: C:\Users\ania\AppData\Local\Temp\axdyipog.sys ---- User code sections - GMER 2.1 ---- .text C:\Windows\SysWOW64\rundll32.exe[2968] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathW + 26 00000000703113c6 2 bytes [31, 70] .text C:\Windows\SysWOW64\rundll32.exe[2968] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathW + 74 00000000703113f6 2 bytes [31, 70] .text C:\Windows\SysWOW64\rundll32.exe[2968] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathW + 257 00000000703114ad 2 bytes [31, 70] .text C:\Windows\SysWOW64\rundll32.exe[2968] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathW + 303 00000000703114db 2 bytes [31, 70] .text ... * 2 .text C:\Windows\SysWOW64\rundll32.exe[2968] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathA + 79 0000000070311577 2 bytes [31, 70] .text C:\Windows\SysWOW64\rundll32.exe[2968] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathA + 175 00000000703115d7 2 bytes [31, 70] .text C:\Windows\SysWOW64\rundll32.exe[2968] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathA + 620 0000000070311794 2 bytes [31, 70] .text C:\Windows\SysWOW64\rundll32.exe[2968] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathA + 921 00000000703118c1 2 bytes [31, 70] .text C:\Windows\SysWOW64\rundll32.exe[3652] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathW + 26 00000000703113c6 2 bytes [31, 70] .text C:\Windows\SysWOW64\rundll32.exe[3652] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathW + 74 00000000703113f6 2 bytes [31, 70] .text C:\Windows\SysWOW64\rundll32.exe[3652] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathW + 257 00000000703114ad 2 bytes [31, 70] .text C:\Windows\SysWOW64\rundll32.exe[3652] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathW + 303 00000000703114db 2 bytes [31, 70] .text ... * 2 .text C:\Windows\SysWOW64\rundll32.exe[3652] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathA + 79 0000000070311577 2 bytes [31, 70] .text C:\Windows\SysWOW64\rundll32.exe[3652] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathA + 175 00000000703115d7 2 bytes [31, 70] .text C:\Windows\SysWOW64\rundll32.exe[3652] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathA + 620 0000000070311794 2 bytes [31, 70] .text C:\Windows\SysWOW64\rundll32.exe[3652] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathA + 921 00000000703118c1 2 bytes [31, 70] ---- Files - GMER 2.1 ---- File C:\Users\ania\AppData\Local\Temp\tmp1D31.tmp 0 bytes ---- EOF - GMER 2.1 ----