GMER.txt Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-05-24 19:53:15
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 SanDisk_SDSSDP128G rev.3.1.0 117,38GB
Running: 60458zfe.exe; Driver: C:\Users\SEBAST~1\AppData\Local\Temp\kgldapow.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\Windows\System32\win32k.sys!W32pServiceTable + 1 fffff96000212201 7 bytes [20, 0A, 02, 00, F0, 70, 01]
.text C:\Windows\System32\win32k.sys!W32pServiceTable + 9 fffff96000212209 6 bytes [88, B0, FF, 01, 23, DC]
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\dwm.exe[976] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffd7965169a 4 bytes [65, 79, FD, 7F]
.text C:\Windows\system32\dwm.exe[976] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffd796516a2 4 bytes [65, 79, FD, 7F]
.text C:\Windows\system32\dwm.exe[976] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffd7965181a 4 bytes [65, 79, FD, 7F]
.text C:\Windows\system32\dwm.exe[976] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffd79651832 4 bytes [65, 79, FD, 7F]
.text C:\Windows\system32\nvvsvc.exe[376] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffd7965169a 4 bytes [65, 79, FD, 7F]
.text C:\Windows\system32\nvvsvc.exe[376] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffd796516a2 4 bytes [65, 79, FD, 7F]
.text C:\Windows\system32\nvvsvc.exe[376] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffd7965181a 4 bytes [65, 79, FD, 7F]
.text C:\Windows\system32\nvvsvc.exe[376] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffd79651832 4 bytes [65, 79, FD, 7F]
.text C:\Windows\explorer.exe[5072] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffd7965169a 4 bytes [65, 79, FD, 7F]
.text C:\Windows\explorer.exe[5072] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffd796516a2 4 bytes [65, 79, FD, 7F]
.text C:\Windows\explorer.exe[5072] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffd7965181a 4 bytes [65, 79, FD, 7F]
.text C:\Windows\explorer.exe[5072] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffd79651832 4 bytes [65, 79, FD, 7F]
.text C:\Program Files\Windows Defender\MsMpEng.exe[2272] C:\Windows\system32\psapi.dll!GetModuleBaseNameA + 506 00007ffd7965169a 4 bytes [65, 79, FD, 7F]
.text C:\Program Files\Windows Defender\MsMpEng.exe[2272] C:\Windows\system32\psapi.dll!GetModuleBaseNameA + 514 00007ffd796516a2 4 bytes [65, 79, FD, 7F]
.text C:\Program Files\Windows Defender\MsMpEng.exe[2272] C:\Windows\system32\psapi.dll!QueryWorkingSet + 118 00007ffd7965181a 4 bytes [65, 79, FD, 7F]
.text C:\Program Files\Windows Defender\MsMpEng.exe[2272] C:\Windows\system32\psapi.dll!QueryWorkingSet + 142 00007ffd79651832 4 bytes [65, 79, FD, 7F]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlDefaultNpAcl + 772 00007ffd79e7293c 8 bytes {JMP 0xffffffffffffff8c}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!WinSqmAddToAverageDWORD + 21 00007ffd79e72959 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!WinSqmSetIfMaxDWORD + 95 00007ffd79e729c7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!EtwEventWriteEndScenario + 220 00007ffd79e72aac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!WinSqmEndSession + 272 00007ffd79e72bc4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!WinSqmStartSession + 8 00007ffd79e73018 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!WinSqmStartSession + 940 00007ffd79e733bc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!EtwEventWriteFull + 64 00007ffd79e73404 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!EtwEventWriteFull + 503 00007ffd79e735bb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!WinSqmIsSessionDisabled + 792 00007ffd79e73fe0 8 bytes {JMP 0xffffffffffffffa9}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlVerifyVersionInfo + 835 00007ffd79e74933 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!SbSelectProcedure + 336 00007ffd79e74bac 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!SbSelectProcedure + 472 00007ffd79e74c34 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlGetNtProductType + 567 00007ffd79e7543f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!WinSqmAddToStream + 592 00007ffd79e756b4 8 bytes {JMP 0xffffffffffffffa9}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!WinSqmAddToStreamEx + 875 00007ffd79e75a27 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!WinSqmEventEnabled + 139 00007ffd79e75f8b 8 bytes {JMP 0xffffffffffffffd1}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!WinSqmEventEnabled + 224 00007ffd79e75fe0 16 bytes {JMP 0xffffffffffffffcf}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!WinSqmEventWrite + 119 00007ffd79e760df 8 bytes {JMP 0xffffffffffffffac}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!EtwEventWrite + 43 00007ffd79e76113 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!EtwEventWrite + 628 00007ffd79e7635c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateBoundaryDescriptor + 584 00007ffd79e76658 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlAddSIDToBoundaryDescriptor + 8 00007ffd79e76668 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlAddSIDToBoundaryDescriptor + 519 00007ffd79e76867 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteBoundaryDescriptor + 23 00007ffd79e76887 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!A_SHAFinal + 300 00007ffd79e76bf0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!A_SHAInit + 44 00007ffd79e76c24 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateServiceSid + 292 00007ffd79e79188 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlLengthRequiredSid + 20 00007ffd79e791a4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlLengthRequiredSid + 352 00007ffd79e792f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeSid + 35 00007ffd79e7931b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlAddAce + 339 00007ffd79e7950b 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlNewSecurityObjectEx + 99 00007ffd79e79577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlIsValidProcessTrustLabelSid + 103 00007ffd79e795e7 8 bytes {JMP 0xffffffffffffffe6}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlIsValidProcessTrustLabelSid + 751 00007ffd79e7986f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlSidDominatesForTrust + 135 00007ffd79e79a67 8 bytes {JMP 0xffffffffffffffaa}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateSecurityDescriptor + 43 00007ffd79e7a7bf 8 bytes {JMP 0xfffffffffffffff5}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlSetDaclSecurityDescriptor + 104 00007ffd79e7a8e8 8 bytes {JMP 0xffffffffffffffe5}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlAddMandatoryAce + 356 00007ffd79e7aa78 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlMapGenericMask + 64 00007ffd79e7d270 8 bytes {JMP 0xffffffffffffffd0}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlOpenCurrentUser + 208 00007ffd79e7d39c 8 bytes {JMP 0xffffffffffffffa3}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlCheckTokenCapability + 952 00007ffd79e7d75c 8 bytes [F0, 69, F8, 7F, 00, 00, 00, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlAppendUnicodeToString + 167 00007ffd79e7e56b 8 bytes [D0, 69, F8, 7F, 00, 00, 00, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlLengthSidAsUnicodeString + 84 00007ffd79e7e5c8 8 bytes {JMP 0xffffffffffffffdc}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlValidSecurityDescriptor + 243 00007ffd79e7e6c3 8 bytes [B0, 69, F8, 7F, 00, 00, 00, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!RtlAddAccessAllowedAce + 379 00007ffd79e7e847 8 bytes [A0, 69, F8, 7F, 00, 00, 00, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffd79efac50 8 bytes {JMP QWORD [RIP-0x7c8ac]}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffd79efadd0 8 bytes {JMP QWORD [RIP-0x7c86b]}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffd79efae00 8 bytes {JMP QWORD [RIP-0x7db96]}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffd79efaf20 8 bytes {JMP QWORD [RIP-0x7d7ca]}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffd79efafd0 8 bytes {JMP QWORD [RIP-0x7dc3a]}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffd79efb690 8 bytes {JMP QWORD [RIP-0x7ce4f]}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffd79efb990 8 bytes {JMP QWORD [RIP-0x7d2d3]}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffd79efc210 8 bytes {JMP QWORD [RIP-0x7dc4e]}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 381 000000007734137d 16 bytes {JMP 0xffffffffffffffd3}
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 386 0000000077341512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077341551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077341577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077341784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\system32\wow64cpu.dll!CpuThreadInit + 50 00000000773417c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 00000000773417e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077341834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077341841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077341a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077342ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077342c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Users\Sebastian\Downloads\60458zfe.exe[2472] C:\Windows\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077342c43 8 bytes [7C, 68, F8, 7F, 00, 00, 00, ...]
---- Threads - GMER 2.1 ----
Thread C:\Windows\system32\csrss.exe [668:3828] fffff96000827b90
Thread C:\Windows\explorer.exe [5072:4240] 00007ffd6aa8d6bc
---- Processes - GMER 2.1 ----
Library C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\shellex.dll (*** suspicious ***) @ C:\Windows\explorer.exe [5072] 00007ffd6bb00000
Library C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\MSVCP100.dll (*** suspicious ***) @ C:\Windows\explorer.exe [5072] 000000005d290000
Library C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\MSVCR100.dll (*** suspicious ***) @ C:\Windows\explorer.exe [5072] 000000005d1b0000
Library C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\prremote.dll (*** suspicious ***) @ C:\Windows\explorer.exe [5072] 000000005d140000
Library C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\prloader.dll (*** suspicious ***) @ C:\Windows\explorer.exe [5072] 00007ffd69b40000
---- Services - GMER 2.1 ----
Service C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe (*** hidden *** ) [AUTO] AVP <-- ROOTKIT !!!
Service system32\DRIVERS\kl1.sys (*** hidden *** ) [BOOT] kl1 <-- ROOTKIT !!!
Service system32\DRIVERS\klelam.sys (*** hidden *** ) [BOOT] klelam <-- ROOTKIT !!!
Service (*** hidden *** ) klflt <-- ROOTKIT !!!
Service system32\DRIVERS\klif.sys (*** hidden *** ) [SYSTEM] KLIF <-- ROOTKIT !!!
Service system32\DRIVERS\klim6.sys (*** hidden *** ) [SYSTEM] KLIM6 <-- ROOTKIT !!!
Service system32\DRIVERS\klkbdflt.sys (*** hidden *** ) [MANUAL] klkbdflt <-- ROOTKIT !!!
Service system32\DRIVERS\klmouflt.sys (*** hidden *** ) [MANUAL] klmouflt <-- ROOTKIT !!!
Service system32\DRIVERS\klpd.sys (*** hidden *** ) [SYSTEM] klpd <-- ROOTKIT !!!
Service system32\DRIVERS\klwfp.sys (*** hidden *** ) [SYSTEM] klwfp <-- ROOTKIT !!!
Service system32\DRIVERS\kneps.sys (*** hidden *** ) [SYSTEM] kneps <-- ROOTKIT !!!
Service C:\Program Files (x86)\Windows Defender\MsMpEng.exe (*** hidden *** ) [MANUAL] WinDefend <-- ROOTKIT !!!
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings@StringCacheGeneration 22
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}@Characteristics 262144
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}@ComponentId kl_klim6
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}@InfPath oem12.inf
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}@InfSection Install
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}@LocDescription @oem12.inf,%klim6_desc%;Kaspersky Anti-Virus NDIS 6 Filter
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}@Description Kaspersky Anti-Virus NDIS 6 Filter
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}@InstallTimeStamp 0xDE 0x07 0x05 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}\Ndi
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}\Ndi@Service KLIM6
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}\Ndi@CoServices KLIM6?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}\Ndi@HelpText Kaspersky Anti-Virus Network Filter
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}\Ndi@FilterClass compression
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}\Ndi@FilterType 2
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}\Ndi@FilterRunType 2
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}\Ndi@TimeStamp 0xDE 0x07 0x05 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}\Ndi\Interfaces
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}\Ndi\Interfaces@UpperRange noupper
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}\Ndi\Interfaces@LowerRange nolower
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}\Ndi\Interfaces@FilterMediaTypes ethernet, wan, atm
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}\Ndi\Interfaces@LowerExclude ndisatm, ndiscowan, ndiswan, ndiswanasync, ndiswanipx, ndiswannbf
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@PendingFileRenameOperations \??\C:\Users\Sebastian\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage??\??\C:\Users\Sebastian\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal??\??\C:\Users\SEBAST~1\AppData\Local\Temp\DEL78FA.tmp??\??\C:\Users\SEBAST~1\AppData\Local\Temp\DEL7DCD.tmp??\??\C:\Program Files (x86)\Avira\AntiVir Desktop\avrestart.exe??\??\C:\Program Files (x86)\Avira\AntiVir Desktop\ccwkrlib.dll??\??\C:\Program Files (x86)\Avira\AntiVir Desktop\firewall.dll??\??\C:\Program Files (x86)\Avira\AntiVir Desktop\mfc120u.dll??\??\C:\Program Files (x86)\Avira\AntiVir Desktop\msvcp120.dll??\??\C:\Program Files (x86)\Avira\AntiVir Desktop\msvcr120.dll??\??\C:\Program Files (x86)\Avira\AntiVir Desktop\rcimage.dll??\??\C:\Program Files (x86)\Avira\AntiVir Desktop\rctext.dll??\??\C:\Program Files (x86)\Avira\AntiVir Desktop\restartrc.dll??\??\C:\Program Files (x86)\Avira\AntiVir Desktop\scewxmlw.dll??\??\C:\Program Files (x86)\Avira\An
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Kernel\RNG@RNGAuxiliarySeed -613814331
Reg HKLM\SYSTEM\CurrentControlSet\Services\AVP
Reg HKLM\SYSTEM\CurrentControlSet\Services\AVP@Type 16
Reg HKLM\SYSTEM\CurrentControlSet\Services\AVP@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\AVP@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\AVP@ImagePath "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe" -r
Reg HKLM\SYSTEM\CurrentControlSet\Services\AVP@DisplayName Kaspersky Anti-Virus Service
Reg HKLM\SYSTEM\CurrentControlSet\Services\AVP@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\Services\AVP@Description Provides computer protection against viruses, dangerous software, network attacks, internet fraud and spam.
Reg HKLM\SYSTEM\CurrentControlSet\Services\AVP@FailureActions 0x80 0x51 0x01 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\AVP\Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\AVP\Security@Security 0x01 0x00 0x14 0x80 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\AVP
Reg HKLM\SYSTEM\CurrentControlSet\Services\kl1@Start 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\kl1@HookIp 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kl1@HookRawIp 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kl1@AutoBoot 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kl1@RegLoad 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kl1
Reg HKLM\SYSTEM\CurrentControlSet\Services\klelam
Reg HKLM\SYSTEM\CurrentControlSet\Services\klelam@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\klelam@Start 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\klelam@ErrorControl 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\klelam@Tag 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\klelam@ImagePath system32\DRIVERS\klelam.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\klelam@DisplayName klelam
Reg HKLM\SYSTEM\CurrentControlSet\Services\klelam@Group Early-Launch
Reg HKLM\SYSTEM\CurrentControlSet\Services\klelam@Description Kaspersky Lab Real Time Protection Component
Reg HKLM\SYSTEM\CurrentControlSet\Services\klelam\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\klelam\Parameters\Journal
Reg HKLM\SYSTEM\CurrentControlSet\Services\klelam
Reg HKLM\SYSTEM\CurrentControlSet\Services\klflt
Reg HKLM\SYSTEM\CurrentControlSet\Services\klflt\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\klflt\Parameters\ClientData
Reg HKLM\SYSTEM\CurrentControlSet\Services\klflt\Parameters\ClientData@
Reg HKLM\SYSTEM\CurrentControlSet\Services\klflt\Parameters\ClientData@38D 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\klflt\Parameters\ClientData@3EC 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\klflt\Parameters\ClientData@4B0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\klflt\Parameters\ClientData@3EB 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\klflt\Parameters\CollectionData
Reg HKLM\SYSTEM\CurrentControlSet\Services\klflt\Parameters\CollectionData@
Reg HKLM\SYSTEM\CurrentControlSet\Services\klflt
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIF@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIF\Parameters@ProcHash 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIF\Parameters@LastProcessedRevision 1002844
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIF
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6@Tag 27
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6@ImagePath \SystemRoot\system32\DRIVERS\klim6.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6@DisplayName @oem12.inf,%KLIM6_Desc%;Kaspersky Anti-Virus NDIS 6 Filter
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6@Group NDIS
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6@Description @oem12.inf,%KLIM6_Desc%;Kaspersky Anti-Virus NDIS 6 Filter
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6@NdisMajorVersion 6
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6@NdisMinorVersion 30
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6@DriverMajorVersion 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6@DriverMinorVersion 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6\Parameters@DefaultFilterSettings 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6\Parameters\Adapters
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6\Parameters\Adapters\{8718928D-CBEB-45EA-A621-800A9249001D}
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6\Parameters\Adapters\{8718928D-CBEB-45EA-A621-800A9249001D}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}-0000
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6\Parameters\Adapters\{B7F6194A-CE4B-40B0-B750-1E66D3B07DB7}
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6\Parameters\Adapters\{B7F6194A-CE4B-40B0-B750-1E66D3B07DB7}\{C477F579-9F31-474D-86CC-E1567F0BFD1D}-0000
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6\Parameters\NdisAdapters
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6\Parameters\NdisAdapters\{B7F6194A-CE4B-40B0-B750-1E66D3B07DB7}
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6\Parameters\NdisAdapters\{B7F6194A-CE4B-40B0-B750-1E66D3B07DB7}@InterfaceGuid 0x75 0x1C 0xCA 0xCD ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIM6
Reg HKLM\SYSTEM\CurrentControlSet\Services\klkbdflt
Reg HKLM\SYSTEM\CurrentControlSet\Services\klkbdflt@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\klkbdflt@Start 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\klkbdflt@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\klkbdflt@Tag 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\klkbdflt@ImagePath \SystemRoot\system32\DRIVERS\klkbdflt.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\klkbdflt@DisplayName Kaspersky Lab KLKBDFLT
Reg HKLM\SYSTEM\CurrentControlSet\Services\klkbdflt@Group Pnp Device Filter
Reg HKLM\SYSTEM\CurrentControlSet\Services\klkbdflt@Description Kaspersky Lab Keyboard Class Filter
Reg HKLM\SYSTEM\CurrentControlSet\Services\klkbdflt
Reg HKLM\SYSTEM\CurrentControlSet\Services\klmouflt
Reg HKLM\SYSTEM\CurrentControlSet\Services\klmouflt@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\klmouflt@Start 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\klmouflt@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\klmouflt@Tag 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\klmouflt@ImagePath \SystemRoot\system32\DRIVERS\klmouflt.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\klmouflt@DisplayName Kaspersky Lab KLMOUFLT
Reg HKLM\SYSTEM\CurrentControlSet\Services\klmouflt@Group Pnp Device Filter
Reg HKLM\SYSTEM\CurrentControlSet\Services\klmouflt@Description Kaspersky Lab Mouse Class Filter
Reg HKLM\SYSTEM\CurrentControlSet\Services\klmouflt
Reg HKLM\SYSTEM\CurrentControlSet\Services\klpd@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\klpd
Reg HKLM\SYSTEM\CurrentControlSet\Services\klwfp@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\klwfp
Reg HKLM\SYSTEM\CurrentControlSet\Services\kneps@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kneps
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch@Epoch 1177
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch2@Epoch 80
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B7F6194A-CE4B-40B0-B750-1E66D3B07DB7}@LeaseObtainedTime 1400934903
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B7F6194A-CE4B-40B0-B750-1E66D3B07DB7}@T1 1401366903
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B7F6194A-CE4B-40B0-B750-1E66D3B07DB7}@T2 1401690903
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B7F6194A-CE4B-40B0-B750-1E66D3B07DB7}@LeaseTerminatesTime 1401798903
Reg HKLM\SYSTEM\CurrentControlSet\Services\TCPIP6\Parameters\Interfaces\{B7F6194A-CE4B-40B0-B750-1E66D3B07DB7}@Dhcpv6InformationObtainedTime 1400934903
Reg HKLM\SYSTEM\CurrentControlSet\Services\WdBoot@Group _Early-Launch
Reg HKLM\SYSTEM\CurrentControlSet\Services\WdBoot@ImagePath \SystemRoot\system32\drivers\WdBoot.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\WdBoot@Start 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\WdBoot
Reg HKLM\SYSTEM\CurrentControlSet\Services\WdFilter@ImagePath \SystemRoot\system32\drivers\WdFilter.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\WdFilter@Start 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\WdFilter
Reg HKLM\SYSTEM\CurrentControlSet\Services\WinDefend@Start 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\WinDefend
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@PolicyDocumentLastRefresh 0x4C 0x29 0xCD 0x3C ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@WindowsBandwidthBucketCounter 39918
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastWindowsBandwidthBucketDrainTime 0x4C 0x7D 0x05 0x3E ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastWindowsRequestBucketDrainTime 0x86 0x1E 0xD1 0x58 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastWindowsLargeRequestBucketDrainTime 0x86 0x1E 0xD1 0x58 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastOtherRequestBucketDrainTime 0x86 0x1E 0xD1 0x58 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@GlobalBandwidthBucketCounter 34553
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastGlobalRequestBucketDrainTime 0x86 0x1E 0xD1 0x58 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@RoamingSyncToken LM%3d63536534607107%3bID%3dE3E98211B9A65F93!106%3bLR%3d63536531707810%3bEP%3d4%3bTD%3dTrue%3bSO%3d0
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastUploadTime 0xB0 0xAA 0x40 0x61 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\RegistrarData@LastRenewCollectionsInterest 0x32 0x87 0x5D 0x14 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData@PendingOperations 5
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\SkyDrive@MoSkyFileSync WLS_SubscriptionId_576c7c7d-6ee7-4955-a9fb-c5c248cf932a
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\SkyDrive@MoSkyQuotaStateChange WLS_SubscriptionId_c0167fc8-9fb7-4d16-999b-805594da2d0a
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\StartupNotify@EnableStartupAppNotification 1
Reg HKCU\Software\Microsoft\Windows\Windows Error Reporting@LastRateLimitedDumpGenerationTime 0x31 0x45 0x59 0xBA ...
Reg HKCU\Software\Microsoft\Windows\Windows Error Reporting\Debug@StoreLocation C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_mbam.exe_122dd8266e6da32b2e886027b27deb705de64b96_6d63998c_10aa9092
Reg HKCU\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles@CheckingForSolutionDialog 0x3E 0x04 0x0A 0x00 ...
Reg HKCU\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles@CloseDialog 0x3E 0x04 0x0A 0x00 ...
---- EOF - GMER 2.1 ---- |