ps. antywirus ani malwarebytes niczego nie znalazł
- Kod: Zaznacz wszystko
GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2015-05-20 18:02:13
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 SAMSUNG_HM320JI rev.2SS00_01 298,09GB
Running: 17dnbwbs.exe; Driver: C:\Users\oem\AppData\Local\Temp\uxriqpow.sys
---- Threads - GMER 2.1 ----
Thread C:\Windows\system32\svchost.exe [1124:1176] 000007fefa6e341c
Thread C:\Windows\system32\svchost.exe [1124:1184] 000007fefa6e3a2c
Thread C:\Windows\system32\svchost.exe [1124:1188] 000007fefa6e3768
Thread C:\Windows\system32\svchost.exe [1124:1192] 000007fefa6e5c20
Thread C:\Windows\system32\svchost.exe [1124:1200] 000007fefa62bd88
Thread C:\Windows\system32\svchost.exe [1124:1896] 000007fefa6e3900
Thread C:\Windows\system32\svchost.exe [1124:3312] 000007fef1a683d8
Thread C:\Windows\system32\svchost.exe [1124:3316] 000007fef1a683d8
Thread C:\Windows\system32\svchost.exe [1124:3428] 000007fef13e3f1c
Thread C:\Windows\system32\svchost.exe [1124:3448] 000007fef13b22b8
Thread C:\Windows\system32\svchost.exe [1124:3452] 000007fef13b1a38
Thread C:\Windows\system32\svchost.exe [1124:3456] 000007fef1215388
Thread C:\Windows\system32\svchost.exe [1124:3460] 000007fef11f7738
Thread C:\Windows\system32\svchost.exe [1124:3464] 000007fef11e1f90
Thread C:\Windows\system32\svchost.exe [1124:3724] 000007fef2345170
Thread C:\Windows\system32\svchost.exe [1124:3800] 000007fefa2c5124
Thread C:\Windows\system32\svchost.exe [1216:1624] 000007fefd7b1a70
Thread C:\Windows\system32\svchost.exe [1216:1632] 000007fefd7b1a70
Thread C:\Windows\system32\svchost.exe [1216:1672] 000007fefd7b1a70
Thread C:\Windows\system32\svchost.exe [1216:1680] 000007fef8c32c70
Thread C:\Windows\system32\svchost.exe [1216:1688] 000007fef8c3fb40
Thread C:\Windows\system32\svchost.exe [1216:1700] 000007fef8c51d20
Thread C:\Windows\system32\svchost.exe [1216:1704] 000007fef8c3f6f0
Thread C:\Windows\system32\svchost.exe [1216:2020] 000007fef75735c0
Thread C:\Windows\system32\svchost.exe [1216:2208] 000007fef7575600
Thread C:\Windows\system32\svchost.exe [1216:1092] 000007fef1fd2888
Thread C:\Windows\system32\svchost.exe [1216:1904] 000007fef1fc2940
Thread C:\Windows\system32\svchost.exe [1216:3880] 000007fef1fd2a40
Thread C:\Windows\System32\spoolsv.exe [1484:2940] 000007fef6eb10c8
Thread C:\Windows\System32\spoolsv.exe [1484:2932] 000007fef6e76144
Thread C:\Windows\System32\spoolsv.exe [1484:2924] 000007fef0ae5fd0
Thread C:\Windows\System32\spoolsv.exe [1484:2916] 000007fef6e53438
Thread C:\Windows\System32\spoolsv.exe [1484:2920] 000007fef0ae63ec
Thread C:\Windows\System32\spoolsv.exe [1484:3444] 000007fef6f55e5c
Thread C:\Windows\System32\spoolsv.exe [1484:2196] 000007fef6f85074
Thread C:\Program Files\Windows Sidebar\sidebar.exe [2212:2728] 00000000730b24e0
Thread C:\Program Files\Windows Sidebar\sidebar.exe [2212:3388] 000007fef1ac1ebc
Thread C:\Windows\system32\svchost.exe [3416:3492] 000007fef12865c4
Thread C:\Windows\system32\svchost.exe [3416:3792] 000007fef1938470
Thread C:\Windows\system32\svchost.exe [3416:3796] 000007fef1942418
Thread C:\Windows\system32\svchost.exe [3416:3956] 000007fef0ae5fd0
Thread C:\Windows\system32\svchost.exe [3416:3960] 000007fef0ae63ec
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0021857d24fa
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0021857d24fa@1c7b21732d5d 0xC0 0x1F 0x87 0x92 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0021857d24fa@c44619afa8a1 0xD0 0x0D 0xB0 0x7F ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0021857d24fa (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0021857d24fa@1c7b21732d5d 0xC0 0x1F 0x87 0x92 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0021857d24fa@c44619afa8a1 0xD0 0x0D 0xB0 0x7F ...
---- Files - GMER 2.1 ----
File C:\Users\oem\AppData\Local\Mozilla\Firefox\Profiles\neiqfhtl.default\cache2\entries\F4754352506FC40628E43C7372BFD1C938C0D50D 8149 bytes
File C:\Users\oem\AppData\Local\Mozilla\Firefox\Profiles\neiqfhtl.default\cache2\entries\B3B8861BD26823B9F960A4F227556CA9DA364F2A 8996 bytes
File C:\Users\oem\AppData\Local\Mozilla\Firefox\Profiles\neiqfhtl.default\cache2\entries\649D8F6AB43BF270CA89627F5AC7E1714A0A16DB 0 bytes
File C:\Users\oem\AppData\Local\Mozilla\Firefox\Profiles\neiqfhtl.default\cache2\entries\B525BDE79F317800120DDDE66A620981ADCEF8D9 0 bytes
File C:\Users\oem\AppData\Local\Mozilla\Firefox\Profiles\neiqfhtl.default\cache2\entries\85E35C042268532C02E84E0A04DF4283F525679E 0 bytes
File C:\Users\oem\AppData\Local\Mozilla\Firefox\Profiles\neiqfhtl.default\cache2\entries\43A10852364F8057112571DB83BD802567DDABAE 0 bytes
File C:\Users\oem\AppData\Local\Mozilla\Firefox\Profiles\neiqfhtl.default\cache2\entries\D01485268223E590DCC3A8A05FEE1F009B4334E3 0 bytes
File C:\Users\oem\AppData\Local\Mozilla\Firefox\Profiles\neiqfhtl.default\cache2\entries\533BB37222AA6BCF3C6011D3B224B2D05B9F55B2 0 bytes
File C:\Users\oem\AppData\Local\Mozilla\Firefox\Profiles\neiqfhtl.default\cache2\entries\FD0D88B7CFB2D5C1D2FC47B76EF7DDECE62269CF 3494 bytes
File C:\Users\oem\AppData\Local\Mozilla\Firefox\Profiles\neiqfhtl.default\cache2\entries\27E37B38CBD0A1F51F7ADC2B56A4F4E3BA6D23AE 0 bytes
File C:\Users\oem\AppData\Local\Mozilla\Firefox\Profiles\neiqfhtl.default\cache2\entries\27F60A748B19089AEBB828178E4A4B655A1C7561 4006 bytes
File C:\Users\oem\AppData\Local\Mozilla\Firefox\Profiles\neiqfhtl.default\cache2\entries\08ACB3B2F19E088523A92E60D5ECDB3BE6B85CE6 9717 bytes
File C:\Users\oem\AppData\Local\Mozilla\Firefox\Profiles\neiqfhtl.default\cache2\entries\52BB03642F660606599058D9D311D6015DE3A0C5 3429 bytes
File C:\Users\oem\AppData\Local\Mozilla\Firefox\Profiles\neiqfhtl.default\cache2\entries\80A5990BE93B3EC9DE654A578A563B78E1A805BC 0 bytes
File C:\Users\oem\AppData\Local\Mozilla\Firefox\Profiles\neiqfhtl.default\cache2\entries\7896624750CEA8E0851206314D661CD49305C318 2657 bytes
File C:\Users\oem\AppData\Local\Mozilla\Firefox\Profiles\neiqfhtl.default\cache2\entries\0BD794C5BF70FB726CE533D8DCA6E4D54A632C57 8823 bytes
File C:\Users\oem\AppData\Local\Mozilla\Firefox\Profiles\neiqfhtl.default\cache2\entries\0CD6D7F2A8338FF9ECCC71947329F96CB6E49514 0 bytes
---- EOF - GMER 2.1 ----