GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-03-11 14:19:40 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 TOSHIBA_MK5061GSYN rev.MH000D 465,76GB Running: 1f4ic7mc.exe; Driver: C:\Users\user\AppData\Local\Temp\aftcaaob.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff800031a2000 63 bytes [00, 00, 00, 00, 00, 00, 00, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 594 fffff800031a2042 4 bytes [00, 00, 00, 00] ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[5632] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000753a1465 2 bytes [3A, 75] .text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[5632] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000753a14bb 2 bytes [3A, 75] .text ... * 2 .text C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe[5340] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000753a1465 2 bytes [3A, 75] .text C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe[5340] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000753a14bb 2 bytes [3A, 75] .text ... * 2 .text C:\Users\user\Desktop\OTL.exe[3324] C:\Windows\syswow64\PSAPI.dll!GetModuleInformation + 69 00000000753a1465 2 bytes [3A, 75] .text C:\Users\user\Desktop\OTL.exe[3324] C:\Windows\syswow64\PSAPI.dll!GetModuleInformation + 155 00000000753a14bb 2 bytes [3A, 75] .text ... * 2 ---- Processes - GMER 2.1 ---- Library C:\ProgramData\Internet Manager\OnlineUpdate\mingwm10.dll (*** suspicious ***) @ C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe [2140](2013-12-04 09:50:07) 000000006fbc0000 Library C:\ProgramData\Internet Manager\OnlineUpdate\libgcc_s_dw2-1.dll (*** suspicious ***) @ C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe [2140](2013-12-04 09:50:07) 000000006e940000 Library C:\ProgramData\Internet Manager\OnlineUpdate\QtCore4.dll (*** suspicious ***) @ C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe [2140](2013-12-04 09:50:07) 000000006a1c0000 Library C:\ProgramData\Internet Manager\OnlineUpdate\QtNetwork4.dll (*** suspicious ***) @ C:\ProgramData\Internet Manager\OnlineUpdate\ouc.exe [2140](2013-12-04 09:50:07) 000000006ff00000 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\bc77378f5bd2 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\bc77378f5bd2@5ce8ebdba882 0x26 0xC5 0xE0 0xBB ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\bc77378f5bd2@001ddfce4ac2 0xE8 0x8A 0xFB 0x21 ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\bc77378f5bd2 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\bc77378f5bd2@5ce8ebdba882 0x26 0xC5 0xE0 0xBB ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\bc77378f5bd2@001ddfce4ac2 0xE8 0x8A 0xFB 0x21 ... ---- EOF - GMER 2.1 ----