GMER 2.2.19882 - http://www.gmer.net Rootkit scan 2016-12-25 23:30:37 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Hitachi_HTS547550A9E384 rev.JE3OA60A 465,76GB Running: rmq2tm48.exe; Driver: C:\Users\Monika\AppData\Local\Temp\awrdrpog.sys ---- User code sections - GMER 2.2 ---- .text C:\Program Files\AVAST Software\Avast\avastui.exe[4384] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000074fa8791 8 bytes [31, C0, C2, 04, 00, 90, 90, ...] ---- Registry - GMER 2.2 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0025d3b2962e Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\742f68f787bb Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0025d3b2962e (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\742f68f787bb (not active ControlSet) ---- Files - GMER 2.2 ---- File C:\Users\Monika\AppData\Local\Mozilla\Firefox\Profiles\mw49hoam.default\cache2\entries\8AC109169C2852B19733C52ED64073200A22878F 330 bytes File C:\Users\Monika\AppData\Local\Mozilla\Firefox\Profiles\mw49hoam.default\cache2\entries\7D4E266215DDE00DD5F609A52320A056C15BDB2C 0 bytes File C:\Users\Monika\AppData\Local\Mozilla\Firefox\Profiles\mw49hoam.default\cache2\entries\ECBD4C67789D2B076C2D85C3FC8FCF84F5F074B5 27164 bytes File C:\Users\Monika\AppData\Local\Mozilla\Firefox\Profiles\mw49hoam.default\cache2\entries\282B56ED24C8B5D5E86314C2E0DD54CAC7C292EE 2468 bytes File C:\Users\Monika\AppData\Local\Mozilla\Firefox\Profiles\mw49hoam.default\cache2\entries\E6FBAD7E74004258314FD2130B91C7E76F815BE9 7217 bytes File C:\Users\Monika\AppData\Local\Mozilla\Firefox\Profiles\mw49hoam.default\cache2\entries\4A40978E01FE9FA1E8823E7BDE69F6DDCBFEA380 2213 bytes File C:\Users\Monika\AppData\Local\Mozilla\Firefox\Profiles\mw49hoam.default\cache2\entries\D8F6A54E6580B527A643AE47B7FA8E9BAF6BED24 3590 bytes File C:\Users\Monika\AppData\Local\Mozilla\Firefox\Profiles\mw49hoam.default\cache2\entries\33DFBE21A62A4DE7BB38573228AC2606BB53599D 3703 bytes File C:\Users\Monika\AppData\Local\Mozilla\Firefox\Profiles\mw49hoam.default\cache2\entries\66A31082D547816F0D413D0F1A5FD8AC1303237F 1848 bytes File C:\Users\Monika\AppData\Local\Mozilla\Firefox\Profiles\mw49hoam.default\cache2\entries\3CA8D2741EAA13230E7CE309E6FA9ACA48DD9C2F 26297 bytes File C:\Users\Monika\AppData\Local\Mozilla\Firefox\Profiles\mw49hoam.default\cache2\entries\3CC8BB5F3722C0E966AD18D055ABB9ED3B1AF741 15640 bytes File C:\Users\Monika\AppData\Local\Mozilla\Firefox\Profiles\mw49hoam.default\cache2\entries\C0F910C7D25C948875EA4193214D61E67A96A7EC 1771 bytes File C:\Users\Monika\AppData\Local\Mozilla\Firefox\Profiles\mw49hoam.default\cache2\entries\8BB9E2EBB8F93EF34DD459E147BB6862AF5FB1EE 27426 bytes File C:\Users\Monika\AppData\Local\Mozilla\Firefox\Profiles\mw49hoam.default\cache2\entries\074BDD5AD0D980C496C88ABF24F17EC42C04416C 26031 bytes File C:\Users\Monika\AppData\Local\Mozilla\Firefox\Profiles\mw49hoam.default\cache2\entries\A935581B27353A064478CA40324F6136D8304FCE 2163 bytes File C:\Users\Monika\AppData\Local\Mozilla\Firefox\Profiles\mw49hoam.default\cache2\entries\173A69D30F9C104B4A2DD922B7963797DD3C36BF 17683 bytes ---- EOF - GMER 2.2 ----