GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-11-19 21:08:55 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000021 WDC_WD10JPCX-24UE4T0 rev.01.01A01 931,51GB Running: dim59126.exe; Driver: C:\Users\Natalia\AppData\Local\Temp\uxrdqpow.sys ---- Threads - GMER 2.1 ---- Thread C:\WINDOWS\system32\csrss.exe [1344:1356] fffff960009432d0 ---- Processes - GMER 2.1 ---- Library C:\Users\Natalia\AppData\Local\SweetLabs App Platform\Engine\libPokki.dll (*** suspicious ***) @ C:\Users\Natalia\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe [6248] (Chromium/The Chromium Authors)(2015-10-30 16:20:24) 0000000058f80000 Library C:\Users\Natalia\AppData\Local\SweetLabs App Platform\Engine\icudt.dll (*** suspicious ***) @ C:\Users\Natalia\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe [6248] (ICU Data DLL/The ICU Project)(2015-04-28 20:15:22) 0000000051df0000 Library C:\Users\Natalia\AppData\Local\SweetLabs App Platform\Engine\libPokki.dll (*** suspicious ***) @ C:\Users\Natalia\AppData\Local\SweetLabs App Platform\Engine\ServiceHostApp.exe [6296] (Chromium/The Chromium Authors)(2015-10-30 16:20:24) 0000000058f80000 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ----