What is klmdb.sys, How to remove klmdb.sys
Thursday, May 20th, 2010klmdb.sys is a harmful program.
It is a component of malware or spyware, you should immediately remove it using an antivirus and antispyware program. If that does not help, then ask us for help in the Spyware removal forum. |
Name: klmdb
Filename: klmdb.sys
Registry key:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmdb.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\klmdb.sys
Command: C:\WINDOWS\system32\drivers\klmdb.sys
Startup Type: Driver
Combofix/RSIT Line:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmdb.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\klmdb.sys]
S4 klmdb;klmdb; C:\WINDOWS\system32\drivers\klmdb.sys [2010-05-14 36488]
Description: trojan-rootkit
How to remove: use Malwarebytes` Anti-malware + Kaspersky virus removal tool or manually instructions below.
Download Avenger from here and unzip to your desktop. Run Avenger, copy,then paste the following text in Input script Box:
Drivers to delete:
klmdbRegistry keys to delete:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\klmdb.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\klmdb.sysFiles to delete:
C:\WINDOWS\system32\drivers\klmdb.sys
Then click on ‘Execute’.