GMER 2.2.19882 - http://www.gmer.net Rootkit scan 2016-09-27 11:40:41 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-2 TOSHIBA_MK1656GSY rev.LH013C 149,05GB Running: tid5x09s.exe; Driver: C:\Users\HP\AppData\Local\Temp\kglciaog.sys ---- Registry - GMER 2.2 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00247e3ba925 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00247e44a04a Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00247e44a04a@a89fba2446a6 0x5D 0x4B 0x3C 0x50 ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0027134d7ddc Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00247e3ba925 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00247e44a04a (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00247e44a04a@a89fba2446a6 0x5D 0x4B 0x3C 0x50 ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0027134d7ddc (not active ControlSet) ---- Files - GMER 2.2 ---- File C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp\mpam-b6911ff7.exe (size mismatch) 1245184/0 bytes executable ---- EOF - GMER 2.2 ----