GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-07-11 16:56:52 Windows 6.1.7600 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST950032 rev.0003 465,76GB Running: vtgw51mv.exe; Driver: C:\Users\user\AppData\Local\Temp\aftcaaob.sys ---- User code sections - GMER 2.1 ---- .text C:\Windows\SysWOW64\PnkBstrA.exe[2520] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 0000000072d71a22 2 bytes [D7, 72] .text C:\Windows\SysWOW64\PnkBstrA.exe[2520] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 0000000072d71ad0 2 bytes [D7, 72] .text C:\Windows\SysWOW64\PnkBstrA.exe[2520] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 0000000072d71b08 2 bytes [D7, 72] .text C:\Windows\SysWOW64\PnkBstrA.exe[2520] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 0000000072d71bba 2 bytes [D7, 72] .text C:\Windows\SysWOW64\PnkBstrA.exe[2520] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 0000000072d71bda 2 bytes [D7, 72] .text C:\Program Files (x86)\VuuPC\remoteengine.exe[2544] C:\Windows\syswow64\PSAPI.dll!GetModuleInformation + 69 00000000754f1465 2 bytes [4F, 75] .text C:\Program Files (x86)\VuuPC\remoteengine.exe[2544] C:\Windows\syswow64\PSAPI.dll!GetModuleInformation + 155 00000000754f14bb 2 bytes [4F, 75] .text ... * 2 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4316] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000754f1465 2 bytes [4F, 75] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4316] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000754f14bb 2 bytes [4F, 75] .text ... * 2 .text C:\Program Files\AVAST Software\Avast\avastui.exe[4340] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000075e3d03c 8 bytes [31, C0, C2, 04, 00, 90, 90, ...] ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001b10002aec Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\001b10002aec@a0f4197369e5 0x0C 0x0A 0x4F 0xE0 ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001b10002aec (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\001b10002aec@a0f4197369e5 0x0C 0x0A 0x4F 0xE0 ... ---- EOF - GMER 2.1 ----