GMER 2.1.19324 - http://www.gmer.net Rootkit scan 2014-01-19 11:38:21 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.PB4O 465,76GB Running: gmer.exe; Driver: C:\Users\User\AppData\Local\Temp\kwldapob.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff800037a8000 45 bytes [00, 00, 09, 02, 56, 61, 64, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575 fffff800037a802f 17 bytes [00, D0, 1D, 00, 00, 00, 00, ...] ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[3032] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076331465 2 bytes [33, 76] .text C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[3032] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000763314bb 2 bytes [33, 76] .text ... * 2 .text C:\Windows\SysWOW64\rundll32.exe[3992] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076331465 2 bytes [33, 76] .text C:\Windows\SysWOW64\rundll32.exe[3992] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000763314bb 2 bytes [33, 76] .text ... * 2 .text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[3132] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076331465 2 bytes [33, 76] .text C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe[3132] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000763314bb 2 bytes [33, 76] .text ... * 2 .text C:\Windows\SysWOW64\RunDll32.exe[3868] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076331465 2 bytes [33, 76] .text C:\Windows\SysWOW64\RunDll32.exe[3868] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000763314bb 2 bytes [33, 76] .text ... * 2 ---- Threads - GMER 2.1 ---- Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [3804:4056] 000007fefb822a7c Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [3804:4324] 000007fef6aa5124 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4624:4640] 00000000766d7587 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4624:4648] 0000000074967712 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4624:4668] 00000000777d2e65 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4624:4832] 00000000777d3e85 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4624:776] 00000000777d3e85 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4624:3400] 00000000777d3e85 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Parameters\Keys\7ce9d3d1b814 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Parameters\Keys\7ce9d3d1b814@1c66aa6d0763 0x40 0x17 0x9D 0x37 ... Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Parameters\Keys\7ce9d3d1b814@28987be19066 0x4D 0x04 0xFC 0x96 ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\7ce9d3d1b814 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\7ce9d3d1b814@1c66aa6d0763 0x40 0x17 0x9D 0x37 ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\7ce9d3d1b814@28987be19066 0x4D 0x04 0xFC 0x96 ... Reg HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Epoch2@Epoch 7640 Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Parameters\Keys\7ce9d3d1b814 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Parameters\Keys\7ce9d3d1b814@1c66aa6d0763 0x40 0x17 0x9D 0x37 ... Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Parameters\Keys\7ce9d3d1b814@28987be19066 0x4D 0x04 0xFC 0x96 ... ---- EOF - GMER 2.1 ----