GMER 2.2.19882 - http://www.gmer.net Rootkit scan 2017-04-10 20:49:51 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000003c SAMSUNG_MZNLN128HCGR-000L2 rev.EMT23L0Q 119,24GB Running: zi0njlcb.exe; Driver: C:\WINDOWS\TEMP\kfeiqfow.sys ---- Modules - GMER 2.2 ---- Module \??\C:\WINDOWS\System32\drivers:ucdrv-x64.sys fffff805529c0000-fffff805529cf000 (61440 bytes) ---- Threads - GMER 2.2 ---- Thread C:\WINDOWS\system32\csrss.exe [720:772] ffff985e8a136c20 Thread C:\WINDOWS\Explorer.EXE [5152:6940] 00007ff92cac20e0 Thread C:\WINDOWS\Explorer.EXE [5152:4408] 00007ff92cac20e0 Thread C:\WINDOWS\Explorer.EXE [5152:7260] 00007ff92cac20e0 ---- Registry - GMER 2.2 ---- Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData@SystemStartTime 0xA6 0x3A 0xB4 0x3D ... Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData@SystemLastStartTime 0xA3 0xA5 0xE6 0x61 ... Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData\BootLanguages@pl-PL 25 Reg HKLM\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\Configuration\LGD04A70_00_07DF_4F^15B987778A572E1ABB2E757E20FCF02D@Timestamp 0xEF 0xD9 0xD4 0xDA ... Reg HKLM\SYSTEM\CurrentControlSet\Control\Lsa@LsaPid 852 Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@PendingFileRenameOperations ????03???????&???????\????N??4?????????D????{00000000-0000-0000-ffff-ffffffffffff}???????.??????????????????????????????????? 0??4???e??????????STORAGE\VolumeSnapshot????????N??4????????D?????{533c5b84-ec70-11d2-9505-00c04f79deaf}??????? ???4??????????????@volsnap.inf,%storage\volumesnapshot.devicedesc%;Generic volume shadow copy??-??????? ???4????????????????X??'???6???C????