GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-05-25 21:01:24 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST9500325AS rev.0003BSM1 465,76GB Running: h3lg4nv8.exe; Driver: C:\Users\TEST\AppData\Local\Temp\kwldapow.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe[4244] C:\Windows\SysWOW64\ksuser.dll!KsCreatePin + 35 00000000735611a8 2 bytes [56, 73] .text C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe[4244] C:\Windows\SysWOW64\ksuser.dll!KsCreateAllocator + 21 00000000735613a8 2 bytes [56, 73] .text C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe[4244] C:\Windows\SysWOW64\ksuser.dll!KsCreateClock + 21 0000000073561422 2 bytes [56, 73] .text C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe[4244] C:\Windows\SysWOW64\ksuser.dll!KsCreateTopologyNode + 19 0000000073561498 2 bytes [56, 73] .text C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe[4244] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 195 00000000731b1b41 2 bytes [1B, 73] .text C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe[4244] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 362 00000000731b1be8 2 bytes [1B, 73] .text C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe[4244] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 418 00000000731b1c20 2 bytes [1B, 73] .text C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe[4244] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 596 00000000731b1cd2 2 bytes [1B, 73] .text C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe[4244] C:\Windows\SysWOW64\d3d8thk.dll!OsThunkDdWaitForVerticalBlank + 628 00000000731b1cf2 2 bytes [1B, 73] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076571465 2 bytes [57, 76] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000765714bb 2 bytes [57, 76] .text ... * 2 ---- Threads - GMER 2.1 ---- Thread C:\Windows\System32\svchost.exe [2504:3952] 000007fef2529688 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0008f4209543 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0008f4209543@001fcdcec68f 0x37 0x07 0xC5 0x81 ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0008f4209543@000761851781 0xE3 0xF3 0x5B 0x38 ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0008f4209543@001167810827 0xEB 0x3F 0xBD 0x24 ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\000272ca87ef Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\000272ca87ef@000761851781 0x5E 0x36 0x9C 0x98 ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\000272ca87ef@001167810827 0x30 0xEA 0x7A 0xF4 ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0008f4209543 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0008f4209543@000761851781 0x9F 0x56 0xE2 0x7E ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0008f4209543@001167810827 0xEB 0x3F 0xBD 0x24 ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0008f4209543@001fcdcec68f 0xCC 0x63 0x3A 0x50 ... Reg HKLM\SYSTEM\ControlSet004\services\BTHPORT\Parameters\Keys\000272ca87ef (not active ControlSet) Reg HKLM\SYSTEM\ControlSet004\services\BTHPORT\Parameters\Keys\000272ca87ef@000761851781 0x5E 0x36 0x9C 0x98 ... Reg HKLM\SYSTEM\ControlSet004\services\BTHPORT\Parameters\Keys\000272ca87ef@001167810827 0x30 0xEA 0x7A 0xF4 ... Reg HKLM\SYSTEM\ControlSet004\services\BTHPORT\Parameters\Keys\0008f4209543 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet004\services\BTHPORT\Parameters\Keys\0008f4209543@000761851781 0x9F 0x56 0xE2 0x7E ... Reg HKLM\SYSTEM\ControlSet004\services\BTHPORT\Parameters\Keys\0008f4209543@001167810827 0xEB 0x3F 0xBD 0x24 ... Reg HKLM\SYSTEM\ControlSet004\services\BTHPORT\Parameters\Keys\0008f4209543@001fcdcec68f 0xCC 0x63 0x3A 0x50 ... ---- EOF - GMER 2.1 ----