GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-12-14 00:38:52 Windows 6.2.9200 x64 \Device\Harddisk1\DR1 -> \Device\00000035 KINGSTON_SV300S37A120G rev.541ABBF0 111.79GB Running: gmer.exe; Driver: C:\Users\Gabi\AppData\Local\Temp\kxldqpod.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files\Microsoft Office\Office15\WINWORD.EXE[5480] C:\Windows\system32\KERNEL32.DLL!SetUnhandledExceptionFilter + 1 00007ffdddd7915d 11 bytes {MOV RAX, 0x7ffdaddd4dc8; JMP RAX} .text C:\Program Files\Microsoft Office\Office15\WINWORD.EXE[5480] C:\Windows\system32\ole32.dll!OleLoadFromStream 00007ffdddf82db4 5 bytes JMP 00007ffe9c3f02f8 .text C:\Program Files\Microsoft Office\Office15\WINWORD.EXE[5480] C:\Windows\system32\OLEAUT32.dll!SysFreeString 00007ffddc1d1720 5 bytes JMP 00007ffe9c3f03b8 .text C:\Program Files\Microsoft Office\Office15\WINWORD.EXE[5480] C:\Windows\system32\OLEAUT32.dll!VariantClear 00007ffddc1d1810 5 bytes JMP 00007ffe9c3f0478 .text C:\Program Files\Microsoft Office\Office15\WINWORD.EXE[5480] C:\Windows\system32\OLEAUT32.dll!SysAllocStringByteLen 00007ffddc1d2300 5 bytes JMP 00007ffe9c3f0358 .text C:\Program Files\Microsoft Office\Office15\WINWORD.EXE[5480] C:\Windows\system32\OLEAUT32.dll!VariantChangeType 00007ffddc1e3f40 10 bytes JMP 00007ffe9c3f0418 .text C:\Program Files\Microsoft Office\Office15\WINWORD.EXE[5480] C:\Windows\system32\USER32.dll!BeginPaint 00007ffddc3f1050 8 bytes JMP 00007ffe9c3f0238 .text C:\Program Files\Microsoft Office\Office15\WINWORD.EXE[5480] C:\Windows\system32\USER32.dll!ValidateRect 00007ffddc3f1330 8 bytes JMP 00007ffe9c3f0298 .text C:\Program Files\Microsoft Office\Office15\WINWORD.EXE[5480] C:\Windows\system32\USER32.dll!RegisterClipboardFormatW 00007ffddc3f5f04 9 bytes JMP 00007ffe9c3f01d8 .text C:\Program Files\Microsoft Office\Office15\WINWORD.EXE[5480] C:\Windows\system32\USER32.dll!RegisterClipboardFormatA 00007ffddc3f65a8 6 bytes JMP 00007ffe9c3f0178 .text C:\Program Files\Microsoft Office\Office15\WINWORD.EXE[5480] C:\Windows\system32\SHELL32.dll!SHParseDisplayName 00007ffddc6d5f28 5 bytes JMP 00007ffe9c3f04d8 .text C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17477_none_fa2b7d3b9b36c7b4\TiWorker.exe[2212] C:\Windows\system32\PsApi.dll!GetModuleBaseNameA + 506 00007ffddc3e169a 4 bytes [3E, DC, FD, 7F] .text C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17477_none_fa2b7d3b9b36c7b4\TiWorker.exe[2212] C:\Windows\system32\PsApi.dll!GetModuleBaseNameA + 514 00007ffddc3e16a2 4 bytes [3E, DC, FD, 7F] .text C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17477_none_fa2b7d3b9b36c7b4\TiWorker.exe[2212] C:\Windows\system32\PsApi.dll!QueryWorkingSet + 118 00007ffddc3e181a 4 bytes [3E, DC, FD, 7F] .text C:\Windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17477_none_fa2b7d3b9b36c7b4\TiWorker.exe[2212] C:\Windows\system32\PsApi.dll!QueryWorkingSet + 142 00007ffddc3e1832 4 bytes [3E, DC, FD, 7F] .text C:\Windows\system32\atiesrxx.exe[6492] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffddc3e169a 4 bytes [3E, DC, FD, 7F] .text C:\Windows\system32\atiesrxx.exe[6492] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffddc3e16a2 4 bytes [3E, DC, FD, 7F] .text C:\Windows\system32\atiesrxx.exe[6492] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffddc3e181a 4 bytes [3E, DC, FD, 7F] .text C:\Windows\system32\atiesrxx.exe[6492] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffddc3e1832 4 bytes [3E, DC, FD, 7F] .text C:\Windows\system32\atieclxx.exe[6508] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffddc3e169a 4 bytes [3E, DC, FD, 7F] .text C:\Windows\system32\atieclxx.exe[6508] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffddc3e16a2 4 bytes [3E, DC, FD, 7F] .text C:\Windows\system32\atieclxx.exe[6508] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffddc3e181a 4 bytes [3E, DC, FD, 7F] .text C:\Windows\system32\atieclxx.exe[6508] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffddc3e1832 4 bytes [3E, DC, FD, 7F] ---- Threads - GMER 2.1 ---- Thread C:\Windows\system32\csrss.exe [636:6164] fffff96000903b90 Thread C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2672:1228] 00007ffdcc733e0c Thread C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2672:1072] 00007ffdcc733e0c Thread C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2672:1068] 00007ffdc8b1bc60 Thread C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2996:1996] 00007ffdcc733e0c Thread C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2996:3848] 00007ffdc8c7f5f8 Thread C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2996:3052] 00007ffdcc733e0c Thread C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2996:3048] 00007ffdc8b1bc60 Thread C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2996:3036] 00007ffdcc733e0c Thread C:\Windows\System32\WWAHost.exe [4992:5016] 00007ffddc010310 Thread C:\Windows\System32\WWAHost.exe [4992:5020] 00007ffdd98ba1f0 Thread C:\Windows\System32\WWAHost.exe [4992:5024] 00007ffdd56f7d70 Thread C:\Windows\System32\WWAHost.exe [4992:5032] 00007ffdda19cb88 Thread C:\Windows\System32\WWAHost.exe [4992:5036] 00007ffdbb3f3010 Thread C:\Windows\System32\WWAHost.exe [4992:5040] 00007ffdbb3f6230 Thread C:\Windows\System32\WWAHost.exe [4992:5044] 00007ffdbb5484e0 Thread C:\Windows\System32\WWAHost.exe [4992:5052] 00007ffdbb3f6230 Thread C:\Windows\System32\WWAHost.exe [4992:5060] 00007ffdbb3f6230 Thread C:\Windows\System32\WWAHost.exe [4992:5064] 00007ffddbca99b0 Thread C:\Windows\System32\WWAHost.exe [4992:5068] 00007ffddbca99b0 Thread C:\Windows\System32\WWAHost.exe [4992:5072] 00007ffdbb3f6230 Thread C:\Windows\System32\WWAHost.exe [4992:5084] 00007ffdcdcd8b48 Thread C:\Windows\System32\WWAHost.exe [4992:5088] 00007ffddc010310 Thread C:\Windows\System32\WWAHost.exe [4992:5092] 00007ffddc010310 Thread C:\Windows\System32\WWAHost.exe [4992:4140] 00007ffdcdccd2b0 Thread C:\Windows\System32\WWAHost.exe [4992:4004] 00007ffddc8579b4 Thread C:\Windows\System32\WWAHost.exe [4992:4144] 00007ffddb6cad30 ---- Services - GMER 2.1 ---- Service C:\Windows\system32\drivers\IOMap64.sys (*** hidden *** ) [MANUAL] IOMap <-- ROOTKIT !!! Service System32\drivers\natyvio.sys (*** hidden *** ) [BOOT] txvc <-- ROOTKIT !!! ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData@SystemStartTime 0x73 0xDF 0x53 0x83 ... Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData@SystemLastStartTime 0x1A 0x47 0x36 0xA9 ... Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData@CMFLastStartTime 0xE4 0xB8 0x1C 0xBE ... Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData\BootLanguages@en-US 22 Reg HKLM\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\Configuration\DEL4072RJWPW3BDA8DL_2E_07DD_CB^DE16D3B28FE235A0C4A7F5C467F99B5C@Timestamp 0x77 0x06 0x7F 0x45 ... Reg HKLM\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\Configuration\MSNILDEL4072RJWPW3BDA8DL_2E_07DD_CB_1414_008D_FFFFFFFF_FFFFFFFF_0^1966E1D36DEA40EB0E12659CF8579CBE@Timestamp 0x2E 0x4A 0x28 0x3A ... Reg HKLM\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings@StringCacheGeneration 103 Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{88A94823-2F86-4469-A254-5BFCD01484FA}\Connection@Name Reusable ISATAP Interface {88A94823-2F86-4469-A254-5BFCD01484FA} Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@PendingFileRenameOperations \??\C:\Users\Gabi\AppData\Local\Temp\is-268OH.tmp\OCSetupHlp.dll??\??\C:\Users\Gabi\AppData\Local\Temp\is-268OH.tmp??\??\C:\Users\Gabi\AppData\Local\Temp\is-5M8FF.tmp\OCSetupHlp.dll??\??\C:\Users\Gabi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbalnpbcmecdckpghgacibglihkgamkl\1.6.0_0\_metadata\computed_hashes.json??\??\C:\Users\Gabi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbalnpbcmecdckpghgacibglihkgamkl\1.6.0_0\_metadata\verified_contents.json??\??\C:\Users\Gabi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbalnpbcmecdckpghgacibglihkgamkl??\??\C:\Users\Gabi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbalnpbcmecdckpghgacibglihkgamkl\1.6.0_0??\??\C:\Users\Gabi\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbalnpbcmecdckpghgacibglihkgamkl\1.6.0_0\_metadata??\??\C:\Users\Gabi\AppData\Local\Temp\is-5M8FF.tmp\OCSetupHlp.dll??\??\C:\Users\Gabi\AppData\Local\Temp\is-5M8FF.tmp?? Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Executive@UuidSequenceNumber 3900001 Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Kernel\RNG@RNGAuxiliarySeed 1004228246 Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters@BootId 23 Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters@BaseTime 429838446 Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@POSTTime 0 Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@FwPOSTTime 26342 Reg HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server@InstanceID da31f36d-02b6-4bd6-ae4b-a2a0b40 Reg HKLM\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WdiContextLog@FileCounter 2 Reg HKLM\SYSTEM\CurrentControlSet\Services\AMD External Events Utility@Owners oem9.inf? Reg HKLM\SYSTEM\CurrentControlSet\Services\amdkmdag@ReleaseVersion 13.20-130911a-163788C-Asus Reg HKLM\SYSTEM\CurrentControlSet\Services\amdkmdag@TVForceDetection 2 Reg HKLM\SYSTEM\CurrentControlSet\Services\amdkmdag@AMDKMPFD %SystemDrive%\AMD\AMDKMPFD Reg HKLM\SYSTEM\CurrentControlSet\Services\amdkmdag@Owners oem9.inf?oem1.inf? Reg HKLM\SYSTEM\CurrentControlSet\Services\amdkmdag@TVCompositeFilter 3 Reg HKLM\SYSTEM\CurrentControlSet\Services\amdkmdag@DALRULE_ALLOWMONITORRANGELIMITMODESCRT 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\amdkmdag@DisablePCIEx1LaneUVD 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\amdkmdap@Owners oem9.inf?oem1.inf? Reg HKLM\SYSTEM\CurrentControlSet\Services\amdkmdap@PX_AI_IndInstallSupport 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\amdkmdap\Device0@Device Description ASUS R9 270X Series Reg HKLM\SYSTEM\CurrentControlSet\Services\amdkmdap\Device1@Device Description ASUS R9 270X Series Reg HKLM\SYSTEM\CurrentControlSet\Services\amdkmdap\Device2@Device Description ASUS R9 270X Series Reg HKLM\SYSTEM\CurrentControlSet\Services\amdkmdap\Device3@Device Description ASUS R9 270X Series Reg HKLM\SYSTEM\CurrentControlSet\Services\BITS@Start 3 Reg HKLM\SYSTEM\CurrentControlSet\Services\BITS Reg HKLM\SYSTEM\CurrentControlSet\Services\DeviceInstall\Parameters@DeviceInstallDisabled 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters\Probe\{59c5cee8-1a3f-4424-b99c-37dac301932f}@LastProbeTime 1418432981 Reg HKLM\SYSTEM\CurrentControlSet\Services\IOMap@Start 3 Reg HKLM\SYSTEM\CurrentControlSet\Services\IOMap\Parameters@RunningCounte2 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\IOMap Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch@Epoch 2468 Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch2@Epoch 96 Reg HKLM\SYSTEM\CurrentControlSet\Services\srvnet\Parameters@MajorSequence 22 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B3168141-4282-4419-BBDD-A806B97B479B}@LeaseObtainedTime 1418492932 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B3168141-4282-4419-BBDD-A806B97B479B}@T1 1418494732 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B3168141-4282-4419-BBDD-A806B97B479B}@T2 1418496082 Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B3168141-4282-4419-BBDD-A806B97B479B}@LeaseTerminatesTime 1418496532 Reg HKLM\SYSTEM\CurrentControlSet\Services\txvc Reg HKLM\SYSTEM\CurrentControlSet\Services\txvc@ImagePath System32\drivers\natyvio.sys Reg HKLM\SYSTEM\CurrentControlSet\Services\txvc@Start 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\txvc@Type 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\txvc@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\txvc@wwahnetp \??\C:\Windows\ServiceProfiles\xrnrvsvk Reg HKLM\SYSTEM\CurrentControlSet\Services\txvc@mrkwxyof C:\Windows Reg HKLM\SYSTEM\CurrentControlSet\Services\txvc@wcuhxjja 69679 Reg HKLM\SYSTEM\CurrentControlSet\Services\txvc@Group System Reserved Reg HKLM\SYSTEM\CurrentControlSet\Services\txvc Reg HKLM\SYSTEM\CurrentControlSet\Services\Winmgmt\Parameters@ServiceDllUnloadOnStop 0 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shutdown@CleanShutdown 1 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}\iexplore@Count 89 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\ImmersiveShell\StateStore@ProcessedPackageStateChangeVersion 484 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014111720141124 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014111720141124@CachePrefix :2014111720141124: Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014111720141124@CachePath %USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012014111720141124 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014111720141124@CacheOptions 11 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014111720141124@CacheRepair 0 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014111720141124@CacheLimit 1 Reg HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce@FlashPlayerUpdate C:\Windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Store@LastStoreActivity 0x08 0x81 0x44 0x57 ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Store@LastTileRefresh 0xE7 0x2C 0xA2 0xB4 ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Store\RefreshBannedAppList@BannedAppsLastModified 0x80 0x31 0x06 0xF1 ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\UFH\SHC@16 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro\HitmanPro.lnk?C:\Program Files\HitmanPro\HitmanPro.exe?? ---- EOF - GMER 2.1 ----