GMER 2.2.19882 - http://www.gmer.net Rootkit scan 2016-10-14 22:07:23 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD75 rev.01.0 698,64GB Running: wuffpyb5.exe; Driver: C:\Users\Marcin\AppData\Local\Temp\pwrdrpoc.sys ---- User code sections - GMER 2.2 ---- .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1860] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 00000000762c8769 8 bytes [31, C0, C2, 04, 00, 90, 90, ...] .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075fe1401 2 bytes JMP 762eb20b C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1860] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075fe1419 2 bytes JMP 762eb336 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075fe1431 2 bytes JMP 76368f39 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075fe144a 2 bytes CALL 762c4885 C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1860] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075fe14dd 2 bytes JMP 76368832 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075fe14f5 2 bytes JMP 76368a08 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1860] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075fe150d 2 bytes JMP 76368728 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075fe1525 2 bytes JMP 76368af2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075fe153d 2 bytes JMP 762dfc98 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1860] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075fe1555 2 bytes JMP 762e68df C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075fe156d 2 bytes JMP 76368ff1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075fe1585 2 bytes JMP 76368b52 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1860] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075fe159d 2 bytes JMP 763686ec C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075fe15b5 2 bytes JMP 762dfd31 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075fe15cd 2 bytes JMP 762eb2cc C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075fe16b2 2 bytes JMP 76368eb4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\afwServ.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075fe16bd 2 bytes JMP 76368681 C:\Windows\syswow64\kernel32.dll .text C:\Windows\AsScrPro.exe[1840] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075fe1401 2 bytes JMP 762eb20b C:\Windows\syswow64\kernel32.dll .text C:\Windows\AsScrPro.exe[1840] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075fe1419 2 bytes JMP 762eb336 C:\Windows\syswow64\kernel32.dll .text C:\Windows\AsScrPro.exe[1840] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075fe1431 2 bytes JMP 76368f39 C:\Windows\syswow64\kernel32.dll .text C:\Windows\AsScrPro.exe[1840] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075fe144a 2 bytes CALL 762c4885 C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Windows\AsScrPro.exe[1840] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075fe14dd 2 bytes JMP 76368832 C:\Windows\syswow64\kernel32.dll .text C:\Windows\AsScrPro.exe[1840] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075fe14f5 2 bytes JMP 76368a08 C:\Windows\syswow64\kernel32.dll .text C:\Windows\AsScrPro.exe[1840] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075fe150d 2 bytes JMP 76368728 C:\Windows\syswow64\kernel32.dll .text C:\Windows\AsScrPro.exe[1840] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075fe1525 2 bytes JMP 76368af2 C:\Windows\syswow64\kernel32.dll .text C:\Windows\AsScrPro.exe[1840] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075fe153d 2 bytes JMP 762dfc98 C:\Windows\syswow64\kernel32.dll .text C:\Windows\AsScrPro.exe[1840] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075fe1555 2 bytes JMP 762e68df C:\Windows\syswow64\kernel32.dll .text C:\Windows\AsScrPro.exe[1840] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075fe156d 2 bytes JMP 76368ff1 C:\Windows\syswow64\kernel32.dll .text C:\Windows\AsScrPro.exe[1840] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075fe1585 2 bytes JMP 76368b52 C:\Windows\syswow64\kernel32.dll .text C:\Windows\AsScrPro.exe[1840] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075fe159d 2 bytes JMP 763686ec C:\Windows\syswow64\kernel32.dll .text C:\Windows\AsScrPro.exe[1840] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075fe15b5 2 bytes JMP 762dfd31 C:\Windows\syswow64\kernel32.dll .text C:\Windows\AsScrPro.exe[1840] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075fe15cd 2 bytes JMP 762eb2cc C:\Windows\syswow64\kernel32.dll .text C:\Windows\AsScrPro.exe[1840] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075fe16b2 2 bytes JMP 76368eb4 C:\Windows\syswow64\kernel32.dll .text C:\Windows\AsScrPro.exe[1840] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075fe16bd 2 bytes JMP 76368681 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\syncables.exe[4308] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075fe1401 2 bytes JMP 762eb20b C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\syncables.exe[4308] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075fe1419 2 bytes JMP 762eb336 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\syncables.exe[4308] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075fe1431 2 bytes JMP 76368f39 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\syncables.exe[4308] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075fe144a 2 bytes CALL 762c4885 C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\syncables\syncables desktop\syncables.exe[4308] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075fe14dd 2 bytes JMP 76368832 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\syncables.exe[4308] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075fe14f5 2 bytes JMP 76368a08 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\syncables.exe[4308] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075fe150d 2 bytes JMP 76368728 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\syncables.exe[4308] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075fe1525 2 bytes JMP 76368af2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\syncables.exe[4308] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075fe153d 2 bytes JMP 762dfc98 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\syncables.exe[4308] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075fe1555 2 bytes JMP 762e68df C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\syncables.exe[4308] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075fe156d 2 bytes JMP 76368ff1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\syncables.exe[4308] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075fe1585 2 bytes JMP 76368b52 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\syncables.exe[4308] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075fe159d 2 bytes JMP 763686ec C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\syncables.exe[4308] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075fe15b5 2 bytes JMP 762dfd31 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\syncables.exe[4308] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075fe15cd 2 bytes JMP 762eb2cc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\syncables.exe[4308] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075fe16b2 2 bytes JMP 76368eb4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\syncables.exe[4308] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075fe16bd 2 bytes JMP 76368681 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe[5572] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075fe1401 2 bytes JMP 762eb20b C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe[5572] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075fe1419 2 bytes JMP 762eb336 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe[5572] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075fe1431 2 bytes JMP 76368f39 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe[5572] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075fe144a 2 bytes CALL 762c4885 C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe[5572] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075fe14dd 2 bytes JMP 76368832 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe[5572] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075fe14f5 2 bytes JMP 76368a08 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe[5572] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075fe150d 2 bytes JMP 76368728 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe[5572] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075fe1525 2 bytes JMP 76368af2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe[5572] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075fe153d 2 bytes JMP 762dfc98 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe[5572] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075fe1555 2 bytes JMP 762e68df C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe[5572] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075fe156d 2 bytes JMP 76368ff1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe[5572] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075fe1585 2 bytes JMP 76368b52 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe[5572] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075fe159d 2 bytes JMP 763686ec C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe[5572] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075fe15b5 2 bytes JMP 762dfd31 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe[5572] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075fe15cd 2 bytes JMP 762eb2cc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe[5572] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075fe16b2 2 bytes JMP 76368eb4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\syncables\syncables desktop\jre\bin\javaw.exe[5572] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075fe16bd 2 bytes JMP 76368681 C:\Windows\syswow64\kernel32.dll .text C:\Program Files\AVAST Software\Avast\avastui.exe[4440] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 00000000762c8769 8 bytes [31, C0, C2, 04, 00, 90, 90, ...] .text C:\Program Files (x86)\syncables\syncables desktop\syncablesMAPI.exe[2308] C:\Program Files (x86)\Common Files\SYSTEM\MSMAPI\1045\MSMAPI32.DLL!HrDispatchNotifications@4 + 112 0000000072de1b80 4 bytes [88, F6, 3E, ED] ? C:\Windows\system32\mssprxy.dll [2308] entry point in ".rdata" section 0000000072d971e6 ---- Registry - GMER 2.2 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters\Instup_14733531492422280@SetupOperations ??????????P???????????????????????????????????$????????????n?????????????????????w?w????????????machine.inf_amd64_neutral_9e6bb86c3b39a3e9???????????????????????????????????????????e???4?4?i?i?x?j?i??bi??.sys?????????????????????????????:??os????????????????????