GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-04-10 17:17:35 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 TOSHIBA_ rev.AX00 298,09GB Running: 9jrsmv0f.exe; Driver: C:\Users\samsung\AppData\Local\Temp\pgeiqkob.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\windows\System32\win32k.sys!W32pServiceTable fffff96000154c00 7 bytes [00, 93, F3, FF, 41, A4, F0] .text C:\windows\System32\win32k.sys!W32pServiceTable + 8 fffff96000154c08 3 bytes [00, 07, 02] ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\50b7c31a6726 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\50b7c31a6726@184617cd671b 0x1D 0xBF 0x58 0xAC ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\50b7c31a6726@0018a4b93f73 0xDB 0x96 0x7D 0xBF ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\50b7c31a6726@0025473c57d0 0x19 0x90 0x52 0x0B ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\50b7c31a6726@a47760c5fe23 0x78 0x3B 0xF5 0x86 ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\50b7c31a6726@329246657230 0x9B 0x77 0xDF 0x11 ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\e81132ed2537 Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\50b7c31a6726 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\50b7c31a6726@184617cd671b 0x1D 0xBF 0x58 0xAC ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\50b7c31a6726@0018a4b93f73 0xDB 0x96 0x7D 0xBF ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\50b7c31a6726@0025473c57d0 0x19 0x90 0x52 0x0B ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\50b7c31a6726@a47760c5fe23 0x78 0x3B 0xF5 0x86 ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\50b7c31a6726@329246657230 0x9B 0x77 0xDF 0x11 ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\e81132ed2537 (not active ControlSet) ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ----