GMER 2.2.19882 - http://www.gmer.net Rootkit scan 2017-01-03 23:48:17 Windows 6.0.6001 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD25 rev.11.0 232,89GB Running: ybz2vpf5.exe; Driver: C:\Users\valdgir\AppData\Local\Temp\fxdiifob.sys ---- Kernel code sections - GMER 2.2 ---- .text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x8F007340, 0x3E9407, 0xE8000020] ---- Devices - GMER 2.2 ---- AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys ---- Processes - GMER 2.2 ---- Process (*** hidden *** ) [4] 83A58C10 ---- Registry - GMER 2.2 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0002787923ce Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001fe1f5d89c Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0002787923ce (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001fe1f5d89c (not active ControlSet) ---- Disk sectors - GMER 2.2 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.2 ----