There are a lot of McAfee junk in memdump as well as rootkit markers. This rootkit looks like updated MaxSS variant which were spreading in Aug-Sept-Oct. There seems no more debug dll (ldr_dll.dll) or it functionality moved somewhere else. As for blocklist, these values mostly the same as in MaxSS cfg's recovered in Aug-Sept-Oct. There is MBAM.sys special ban code embedded in MaxSS driver, just like in the beginning of this year.
Some more cfg data.
BKFS[PANEL_SIGN_CHECK]
[runs_count_begin]
30
[runs_count_end]
[urls_to_serf_begin]
hxxp://www.dewytogabsu.com/ac4.php?aid=574&sid=direc40
hxxp://www.uniquedentu.com/ac4.php?aid=574&sid=direc40
hxxp://www.buseforode.com/ac4.php?aid=574&sid=direc40
hxxp://www.tavelfelegon.com/ac4.php?aid=574&sid=direc40
hxxp://www.ingesuricow.com/ac4.php?aid=574&sid=direc40
hxxp://www.ranboceubap.com/ac4.php?aid=574&sid=direc40
[urls_to_serf_end]
[refs_to_change_begin]
http://www.buseforode.com/ac4.php=|www.buseforode.com/search.php
http://www.tavelfelegon.com/ac4.php=|www.tavelfelegon.com/search.php
http://www.ranboceubap.com/ac4.php=|www.ranboceubap.com/search.php
http://www.ingesuricow.com/ac4.php=|www.ingesuricow.com/search.php
http://www.dewytogabsu.com/ac4.php=|www.dewytogabsu.com/search.php
http://www.uniquedentu.com/ac4.php=|www.uniquedentu.com/search.php
[refs_to_change_end]
[panels_begin]
interalotimub.com
hotokelahout.com
joburgonfroco.com
sumbaiturful.com
mosendoysu.com
francispolar.com
webgetclick.com
[panels_end]
[popupcount_begin]
3
[popupcount_end]
[popupurl_begin]
[popupurl_end]
[popupurl2_begin]
[popupurl2_end]
TDL "BKFS"
mbr
bid
boot
cmd64
dbg64
drv64
ldr64
info
mainfb.script
serf_conf
sant32
vbr
affid
cmd32
dbg32
drv32
ldr32
subid
main
com32
serf332
bbr_conf
time.txt