GMER 2.1.19163 - [URL="http://www.gmer.net"]GMER - Rootkit Detector and Remover[/URL]
Rootkit scan 2013-12-11 01:51:28
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T1L0-3 SAMSUNG_HD103SI rev.1AG01118 931,51GB
Running: gmer.exe; Driver: C:\Users\Okan\AppData\Local\Temp\kxldapog.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\WINDOWS\System32\win32k.sys!W32pServiceTable fffff96000183f00 15 bytes [00, D9, 10, 02, 40, B2, 6F, ...]
.text C:\WINDOWS\System32\win32k.sys!W32pServiceTable + 16 fffff96000183f10 11 bytes [00, D0, FB, FF, 80, 5C, C4, ...]
---- User code sections - GMER 2.1 ----
.text C:\WINDOWS\system32\atiesrxx.exe[956] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffa210a169a 4 bytes [0A, 21, FA, 7F]
.text C:\WINDOWS\system32\atiesrxx.exe[956] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffa210a16a2 4 bytes [0A, 21, FA, 7F]
.text C:\WINDOWS\system32\atiesrxx.exe[956] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffa210a181a 4 bytes [0A, 21, FA, 7F]
.text C:\WINDOWS\system32\atiesrxx.exe[956] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffa210a1832 4 bytes [0A, 21, FA, 7F]
.text C:\WINDOWS\system32\atieclxx.exe[752] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffa210a169a 4 bytes [0A, 21, FA, 7F]
.text C:\WINDOWS\system32\atieclxx.exe[752] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffa210a16a2 4 bytes [0A, 21, FA, 7F]
.text C:\WINDOWS\system32\atieclxx.exe[752] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffa210a181a 4 bytes [0A, 21, FA, 7F]
.text C:\WINDOWS\system32\atieclxx.exe[752] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffa210a1832 4 bytes [0A, 21, FA, 7F]
.text C:\Program Files\Windows Defender\MsMpEng.exe[1648] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 506 00007ffa210a169a 4 bytes [0A, 21, FA, 7F]
.text C:\Program Files\Windows Defender\MsMpEng.exe[1648] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 514 00007ffa210a16a2 4 bytes [0A, 21, FA, 7F]
.text C:\Program Files\Windows Defender\MsMpEng.exe[1648] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 118 00007ffa210a181a 4 bytes [0A, 21, FA, 7F]
.text C:\Program Files\Windows Defender\MsMpEng.exe[1648] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 142 00007ffa210a1832 4 bytes [0A, 21, FA, 7F]
---- Threads - GMER 2.1 ----
Thread C:\WINDOWS\system32\csrss.exe [604:660] fffff960008b14d0
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4824:4904] 00007ffa210481b0
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4824:3696] 00007ffa20c799b0
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4824:3800] 00007ffa206ad770
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4824:344] 00007ffa206ad770
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{9FDD2A74-85DC-40BA-88A1-443512619185}\Connection@Name isatap.{41B13FB1-C7B8-4AD4-8883-942AF7E9E21A}
Reg HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters\Isatap\{9FDD2A74-85DC-40BA-88A1-443512619185}@InterfaceName isatap.{41B13FB1-C7B8-4AD4-8883-942AF7E9E21A}
Reg HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters\Isatap\{9FDD2A74-85DC-40BA-88A1-443512619185}@ReusableType 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\iphlpsvc\Parameters\Isatap\{9FDD2A74-85DC-40BA-88A1-443512619185}@DefunctTimestamp 0xCE 0x6D 0xA7 0x52 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch@Epoch 4402
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch2@Epoch 925
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Notifications\Alarm\Microsoft.WindowsAlarms_8wekyb3d8bbwe!App@PackageFullName Microsoft.WindowsAlarms_6.3.9600.20278_x64__8wekyb3d8bbwe
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Notifications\Alarm\Microsoft.WindowsAlarms_8wekyb3d8bbwe!App@Version 1688863374331702
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Notifications\Badge\Microsoft.WindowsAlarms_8wekyb3d8bbwe!App@PackageFullName Microsoft.WindowsAlarms_6.3.9600.20278_x64__8wekyb3d8bbwe
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Notifications\Badge\Microsoft.WindowsAlarms_8wekyb3d8bbwe!App@Version 1688863374331702
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\DeviceSetup@AppInstallNotificationChangeStamp 72
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\DeviceSetup@AppUninstallNotificationChangeStamp 42
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\ImmersiveShell\Grid@Logo100 %USERPROFILE%\AppData\Local\Microsoft\Windows\Explorer\TileCacheLogo-7196937_100.dat
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\ImmersiveShell\StateStore@ProcessedPackageStateChangeVersion 499
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@PolicyDocumentLastRefresh 0xDA 0x2E 0x07 0x48 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@WindowsBandwidthBucketCounter 98607
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastWindowsBandwidthBucketDrainTime 0x4D 0xA4 0x98 0x48 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@WindowsRequestBucketCounter 2549
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastWindowsRequestBucketDrainTime 0x39 0x15 0xD9 0xB2 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@WindowsLargeBandwidthBucketCounter 570642
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastWindowsLargeBandwidthBucketDrainTime 0xA9 0x52 0xA0 0x87 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastWindowsLargeRequestBucketDrainTime 0x39 0x15 0xD9 0xB2 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@OtherBandwidthBucketCounter 9339
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@OtherRequestBucketCounter 197
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastOtherRequestBucketDrainTime 0x39 0x15 0xD9 0xB2 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@GlobalBandwidthBucketCounter 106923
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@GlobalRequestBucketCounter 1057
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastGlobalRequestBucketDrainTime 0x39 0x15 0xD9 0xB2 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@CloudUsertileDirtyMarks 8
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@CloudSettingsDirtyMarks 8
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\PolicyData@LastUploadTime 0x49 0x3C 0xE0 0xB2 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Live\Roaming\RegistrarData@LastRenewCollectionsInterest 0x28 0xCD 0x2E 0xBB ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData@PendingOperations 14
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\SettingSync\SyncData\Namespace\windows\startlayout@PendingOperations 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Store@LastTileRefresh 0x07 0x08 0xAB 0xDE ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Store\RefreshBannedAppList@BannedAppsLastModified 0x00 0xAC 0x0E 0xD7 ...
---- EOF - GMER 2.1 ----