GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-10-11 13:47:11 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\0000005b WDC_____ rev.03.0 465,76GB Running: 8d6o1po4.exe; Driver: C:\Users\oem\AppData\Local\Temp\uxriqpow.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80002dec000 58 bytes [D4, 1D, D6, 9D, 97, 40, B5, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 587 fffff80002dec03b 31 bytes [47, B2, 81, AF, 2A, 05, 8E, ...] ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\642737c8fc7c Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\642737c8fc7c@0c14201a1e7f 0x4E 0xBE 0xF0 0xDE ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\642737c8fc7c (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\642737c8fc7c@0c14201a1e7f 0x4E 0xBE 0xF0 0xDE ... ---- EOF - GMER 2.1 ----