GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-09-27 19:53:39 Windows 5.1.2600 Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 Hitachi_HTS545025B9SA02 rev.PB2AC60W 232,89GB Running: qkj7l9es.exe; Driver: C:\DOCUME~1\KRZYSZ~1\LOCALS~1\Temp\axlyikog.sys ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!KeReleaseInStackQueuedSpinLockFromDpcLevel + B62 805417CA 6 Bytes JMP B7F4D29F TsFltMgr.sys .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB4C2B380, 0x568845, 0xE8000020] ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\5c5948cf3c87 Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\5c5948cf3c87@b84fd5942cb5 0x37 0x4A 0xE4 0x32 ... Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\5c5948cf3c87 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\5c5948cf3c87@b84fd5942cb5 0x37 0x4A 0xE4 0x32 ... Reg HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\MediaPlayer\Setup\CatalogIteration@drm.cat 1 Reg HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\MediaPlayer\Setup\CatalogIteration@WMFSDK.cat 1 Reg HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Multimedia\Components\Installed\Codec_fhg\Files\File1@Version 0.2002.10.28 Reg HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Multimedia\Components\Installed\DRM_DRM\Files\File0@Version 9.0.0.3250 Reg HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Multimedia\Components\Installed\DRM_DRM\Files\File1@Version 9.0.0.3250 Reg HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Multimedia\Components\Installed\DRM_DRM\Files\File3@Version 9.0.0.3250 Reg HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Multimedia\Components\Installed\DRM_DRM\Files\File4@Version 9.0.0.3250 Reg HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Multimedia\Components\Installed\playback_wmfsdk\Files\File0@Size 230400 Reg HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Multimedia\Components\Installed\playback_wmfsdk\Files\File0@Version 9.0.0.3250 Reg HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Multimedia\Components\Installed\playback_wmfsdk\Files\File1@Version 9.0.0.3272 Reg HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Multimedia\Components\Installed\playback_wmfsdk\Files\File2@Version 9.0.0.3250 Reg HKLM\SOFTWARE\Classes\SOFTWARE\Microsoft\Multimedia\Components\Installed\playback_wmfsdk\Files\File3@Version 9.0.0.3268 ---- EOF - GMER 2.1 ----