GMER 2.2.19882 - http://www.gmer.net Rootkit scan 2016-11-19 13:17:42 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000003c ST1000LM014-SSHD-8GB rev.LVD3 931,51GB Running: dfqbn1u1.exe; Driver: C:\Users\PAWE~1\AppData\Local\Temp\kxldrpow.sys ---- Threads - GMER 2.2 ---- Thread C:\WINDOWS\system32\csrss.exe [760:920] ffffc42555a16c20 ---- Services - GMER 2.2 ---- Service C:\WINDOWS\System32\drivers\L1C63x64.sys (*** hidden *** ) [MANUAL] L1C <-- ROOTKIT !!! ---- Registry - GMER 2.2 ---- Reg HKLM\SYSTEM\CurrentControlSet\Control\BackupRestore\FilesNotToSnapshot@OfficeODC ?????????????????????????r???3???????????????????? ???????????????????????????????????????????????? ??? ???%???%???%???%???%???%???%???%???(???(???(???(???(???(???(???)???)???)???)???)?:?)???)???)???)???)???)???)???)???)???)???)???)???)???)???*???+???+???+???+???+???-???-???.???.???1???=???=???=???A???B???B???B???B???B???C???C???C???C???C???C???D???D???D???D???H?A?H???H???H???H???H???H???H???H???H???H???H???I???I?C?I???I???I???I???I???I???I???I???I???I???I???I???I???O???O???O????? ??????????????????????????????N??????????? ?????N??????????e??%SystemRoot%\system32\AppReadiness.dll??????? ????????????????????????"?????????????????? ????????????????????????$????????? ???????e???? ????????????????????????????L???????????????????b??????`?W?`??%SystemRoot%\system32\LogFiles\WMI\RtBackup\*.*?????????????????????????????????????????????????????????????????????????????????\System Volume Information\FVE2.{e40ad34d-dae9-4bc7-95bd-b16218c10f72}.*????????????????????\System Volume Information\FVE2.{c9ca54a3-6983-46b7-868 Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData@SystemStartTime 0xBA 0x53 0x59 0xAE ... Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData@SystemLastStartTime 0xEC 0x4F 0xD0 0x3B ... Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData@CMFStartTime 0xBA 0x53 0x59 0xAE ... Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData@CMFLastStartTime 0xEC 0x4F 0xD0 0x3B ... Reg HKLM\SYSTEM\CurrentControlSet\Control\CMF\SqmData\BootLanguages@pl-PL 42 Reg HKLM\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\Configuration\LGD033A0_00_07DB_82^0C347888ABDF2AA846DFF8D24673327F@Timestamp 0x7F 0xE3 0x17 0x86 ... Reg HKLM\SYSTEM\CurrentControlSet\Control\Lsa@LsaPid 828 Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Qualcomm Atheros AR8171/8175 PCI-E Gigabit Ethernet Controller (NDIS 6.30) 1? Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{55E58BFD-4F5A-472B-A9C1-5FC8D521D9F1}\Connection@Name Reusable ISATAP Interface {55E58BFD-4F5A-472B-A9C1-5FC8D521D9F1} Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{A08B5C0F-015B-495E-80CF-3CAA50732CE0} Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{A08B5C0F-015B-495E-80CF-3CAA50732CE0}\Connection Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{A08B5C0F-015B-495E-80CF-3CAA50732CE0}\Connection@Name Ethernet Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{A08B5C0F-015B-495E-80CF-3CAA50732CE0}\Connection@PnPInstanceId PCI\VEN_1969&DEV_10A1&SUBSYS_380017AA&REV_10\FF9C048328D244FF00 Reg HKLM\SYSTEM\CurrentControlSet\Control\Power\User\PowerSchemes\8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c\7516b95f-f776-4464-8c53-06167f40cc99\aded5e82-b909-4619-9949-f5d71dac0bcb@DCSettingIndex 30 Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@PendingFileRenameOperations \??\C:\Config.Msi\4749a2c.rbf??\??\C:\Config.Msi\4749a2d.rbf??\??\C:\Users\PAWE~1\AppData\Local\Temp\DEL419A.tmp??\??\C:\Users\PAWE~1\AppData\Local\Temp\DEL41AA.tmp??\??\C:\Users\PAWE~1\AppData\Local\Temp\DEL41AB.tmp??\??\C:\Users\PAWE~1\AppData\Local\Temp\DEL41AC.tmp?? Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Executive@UuidSequenceNumber 3900169 Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\kernel\RNG@RNGAuxiliarySeed 1733495998 Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters@BootId 43 Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters@BaseTime 489424875 Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@POSTTime 0 Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@FwPOSTTime 2130 Reg HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server@InstanceID dab5b064-ec6c-428d-b1da-597d583 Reg HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\ClusterSettings@LastLSMInstanceID dab5b064-ec6c-428d-b1da-597d583 Reg HKLM\SYSTEM\CurrentControlSet\Control\WDI\Config@ServerName \BaseNamedObjects\WDI_{7cba4d84-0185-4389-bc67-c9075ee69602} Reg HKLM\SYSTEM\CurrentControlSet\Control\WMI\Autologger\AITEventLog@FileCounter 2 Reg HKLM\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WdiContextLog@FileCounter 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters@BootCounter 32 Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_14734119416252280@SetupOperations ???g?????g?h?h?h?h???????????????????????????s??????????????????????????????????? ???????g???????????g???????? ??????????????????????????g???-??Reverted?