GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-04-27 20:38:35 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-12 Maxtor_6L080L0 rev.BAJ41G20 76,33GB Running: 9rfv549w.exe; Driver: C:\DOCUME~1\Matiasik\USTAWI~1\Temp\kwqiifoc.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF623D360, 0x37388D, 0xE8000020] ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch@Epoch 60043 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{024E7A6D-0ADE-46E5-A545-60A70D43E4DA}@LeaseObtainedTime 1430153314 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{024E7A6D-0ADE-46E5-A545-60A70D43E4DA}@T1 1430153441 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{024E7A6D-0ADE-46E5-A545-60A70D43E4DA}@T2 1430153537 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{024E7A6D-0ADE-46E5-A545-60A70D43E4DA}@LeaseTerminatesTime 1430153569 Reg HKLM\SYSTEM\CurrentControlSet\Services\{024E7A6D-0ADE-46E5-A545-60A70D43E4DA}\Parameters\Tcpip@LeaseObtainedTime 1430153314 Reg HKLM\SYSTEM\CurrentControlSet\Services\{024E7A6D-0ADE-46E5-A545-60A70D43E4DA}\Parameters\Tcpip@T1 1430153441 Reg HKLM\SYSTEM\CurrentControlSet\Services\{024E7A6D-0ADE-46E5-A545-60A70D43E4DA}\Parameters\Tcpip@T2 1430153537 Reg HKLM\SYSTEM\CurrentControlSet\Services\{024E7A6D-0ADE-46E5-A545-60A70D43E4DA}\Parameters\Tcpip@LeaseTerminatesTime 1430153569 ---- EOF - GMER 2.1 ----