GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-09-21 19:22:09 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD2500BEKT-60A25T1 rev.02.01A02 232,89GB Running: 5ksixoem.exe; Driver: C:\Users\oem\AppData\Local\Temp\uxriqpow.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff800037ac000 16 bytes [8B, E3, 41, 5F, 41, 5E, 41, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 545 fffff800037ac011 35 bytes {LEA ECX, [RSP+0x70]; CALL 0x3d64f} ---- Threads - GMER 2.1 ---- Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [2152:3584] 000007fefbc62bf8 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [2152:3948] 000007fef74e4830 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [2152:4380] 000007fefa665124 ---- Processes - GMER 2.1 ---- Process C:\ProgramData\IePluginServices\PluginService.exe (*** suspicious ***) @ C:\ProgramData\IePluginServices\PluginService.exe [1664] (IePlugin Service/Cherished Technololgy LIMITED)(2014-09-20 14:00:47) 0000000000a90000 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\70f395800ca4 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\70f395809366 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\70f395cf64b5 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\e02a8236c7d8 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\e02a82d11990 Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\70f395800ca4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\70f395809366 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\70f395cf64b5 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\e02a8236c7d8 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\e02a82d11990 (not active ControlSet) ---- EOF - GMER 2.1 ----