|
Log-Analyse und Auswertung: Flash Installation infiziertWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
06.02.2013, 13:10 | #1 |
| Flash Installation infiziert Hallo liebes TB-Team, als ich gestern an meinem PC arbeitete kam plötzlich ein Popup von Kaspersky Internet security 2013, dass mir mitteilte das in Datei "install_flashplayer11x32au_mssd_aih.exe" ein Malware sei, obwohl diese Datei schon länger da sein dürfte, sicher bin ich mir aber nicht, genauso wenig sicher bin ich mir ob Kaspersky jetzt die Datei desinfiziert hat. Deshalb möchte ich hier nochmal nachschauen lassen. Vorweg schon mal sorry für die fehlende Gmer.txt, aber jedesmal wenn ich damit scannen wollte stürzte mein ganzer PC ab und startete neu. Vielleicht weiß jemand wie ich dennoch einen Scan hin bekomme oder woran es liegen könnte. Edit: Gmer hängt sich beim Scan von sich selber auf... Warum auch immer. Die Defrogger, otl und extras hab ich in den Anhang gepackt. Ich hoffe mir kann weitergeholfen werden. Martin Geändert von Plex1234 (06.02.2013 um 13:45 Uhr) |
06.02.2013, 15:30 | #2 |
| Flash Installation infiziert Sorry wegen dem Doppelpost, aber ich hab jetzt nach 10x Absturz von GMER im Abgesicherten Modus versucht GMER ans laufen zu bringen und siehe da es klappte. Anbei der Log:
__________________Code:
ATTFilter GMER 2.0.18454 - hxxp://www.gmer.net Rootkit scan 2013-02-06 15:23:25 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 ST925031 rev.0001 232,89GB Running: gmer_2.0.18454.exe; Driver: C:\Users\MYPC\AppData\Local\Temp\agdiypow.sys ---- User IAT/EAT - GMER 2.0 ---- IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\SHLWAPI.dll[KERNEL32.dll!FreeLibraryAndExitThread] [10002350] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\psdprotect.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\SHLWAPI.dll[KERNEL32.dll!CreateThread] [10003450] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\psdprotect.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\SHELL32.dll[KERNEL32.dll!LoadLibraryA] [100011e0] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\psdprotect.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!free] [10000000000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!??_U@YAPEAX_K@Z] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!??_V@YAXPEAX@Z] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!_XcptFilter] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!malloc] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!_initterm] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!realloc] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!_unlock] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!__dllonexit] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!memcpy] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!memset] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!_ultow_s] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!_vsnwprintf] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!_amsg_exit] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!memcmp] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!_lock] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!_onexit] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!_ui64tow_s] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ntdll.dll!RtlLookupFunctionEntry] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ntdll.dll!RtlCaptureContext] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ntdll.dll!RtlInitUnicodeString] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ntdll.dll!RtlMapGenericMask] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ntdll.dll!RtlCreateAcl] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ntdll.dll!RtlAddAccessAllowedAce] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ntdll.dll!RtlCreateSecurityDescriptor] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ntdll.dll!RtlSetDaclSecurityDescriptor] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ntdll.dll!NtQueryInformationFile] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ntdll.dll!RtlVirtualUnwind] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!LsaOpenPolicy] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!CopySid] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!LsaLookupNames2] [4754710564d] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!LsaClose] [fffffb8ab8efa9b2] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!GetTokenInformation] [7fef9c85ec0] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!GetAclInformation] [7fef9c72ed0] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!GetAce] [7fef9c745e0] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!OpenProcessToken] [7fef9c80ce8] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!RegOpenKeyExW] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!RegCloseKey] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!RegQueryValueExW] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!GetNamedSecurityInfoW] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!GetSecurityDescriptorControl] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!IsValidSid] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!EqualSid] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!GetLengthSid] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!LsaFreeMemory] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[USER32.dll!CopyImage] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[USER32.dll!LoadStringW] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[USER32.dll!ReleaseDC] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[USER32.dll!GetDC] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[GDI32.dll!CreateDIBSection] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[GDI32.dll!DeleteDC] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[GDI32.dll!GetBitmapBits] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[GDI32.dll!CreateCompatibleDC] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[GDI32.dll!SelectObject] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[GDI32.dll!BitBlt] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[GDI32.dll!GetObjectW] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[GDI32.dll!DeleteObject] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHELL32.dll!SHGetTemporaryPropertyForItem] [7fef9c745b0] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHELL32.dll!SHGetFolderPathAndSubDirW] [7fef9c80d3c] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHELL32.dll!SHChangeNotify] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!StrCmpNIW] [7fef9c745f0] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!PathFindExtensionW] [7fef9c80d18] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!SHRegGetValueW] [7fef9c73360] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!SHCreateStreamOnFileW] [7fef9c80ce8] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!PathCombineW] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!PathRemoveFileSpecW] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!PathIsNetworkPathW] [7fef9c73650] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!PathStripToRootW] [7fef9c745a0] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!PathSkipRootW] [7fef9c80ce8] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!PathAppendW] [7fef9c80d18] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!SHGetValueW] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!PathIsRootW] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!PathIsUNCW] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!SHStrDupW] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetProcessHeap] [7fef9c80d3c] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!HeapFree] [7fef9c80d18] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!DisableThreadLibraryCalls] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!LoadLibraryW] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetProcAddress] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!FreeLibrary] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetLastError] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!LoadLibraryExA] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!DelayLoadFailureHook] [ffffffffffffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!CloseHandle] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!lstrlenW] [7fef9c757f8] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!LCMapStringW] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetCurrentThreadId] [7fef9c756d8] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetFileAttributesW] [7fef9c756a8] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!CreateDirectoryW] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!FindFirstFileW] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!DeleteFileW] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!FindNextFileW] [7fef9c756d8] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!FindClose] [7fef9c75690] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!RemoveDirectoryW] [1] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetDiskFreeSpaceExW] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetTempFileNameW] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!MoveFileExW] [7fef9c75680] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetVolumeInformationW] [7fef9c75660] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetDriveTypeW] [2] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!MulDiv] [1] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!CreateFileW] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetFileSize] [7fef9c75680] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!RaiseException] [7fef9c75630] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!SetFilePointer] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!WriteFile] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!SetEndOfFile] [7fef9c756d8] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetTickCount] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!SetFileAttributesW] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!UnmapViewOfFile] [7fef9c756d8] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!Sleep] [7fef9c755f0] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!QueryPerformanceCounter] [7] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetCurrentProcessId] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetSystemTimeAsFileTime] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!TerminateProcess] [7fef9c756d8] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetCurrentProcess] [7fef9c755c8] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!UnhandledExceptionFilter] [8] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!SetUnhandledExceptionFilter] [1] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!LocalAlloc] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!DuplicateHandle] [7fef9c756d8] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!LocalFree] [7fef9c755a8] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetModuleHandleW] [9] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!SystemTimeToFileTime] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!OpenProcess] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetProcessId] [7fef9c756d8] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!CreateMutexW] [7fef9c75588] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!CreateEventW] [a] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!ReleaseMutex] [32] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!SetEvent] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!ResetEvent] [7fef9c756d8] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!CreateFileMappingW] [7fef9c75568] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!MapViewOfFile] [b] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetFileInformationByHandleEx] [1f4] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!SetFileInformationByHandle] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!WaitForSingleObject] [7fef9c756d8] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetSystemInfo] [7fef9c75550] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[PSAPI.DLL!QueryWorkingSetEx] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[PROPSYS.dll!PropVariantToUInt64] [7fef9c756d8] C:\Windows\system32\thumbcache.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!wcsstr] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!wcschr] [90900000946a25ff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!wcsrchr] [956e25ff90909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!_vsnwprintf] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!memcmp] [90900000955a25ff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!memcpy] [954625ff90909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!memset] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!iswalpha] [90900000953225ff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!_XcptFilter] [951e25ff90909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!malloc] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!_initterm] [90900000950a25ff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!free] [94f625ff90909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!memmove] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!_onexit] [9090000094e225ff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!_lock] [94ce25ff90909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!__dllonexit] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!_unlock] [9090000094ba25ff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!_amsg_exit] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[ntdll.dll!RtlVirtualUnwind] [950625ff90909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[ntdll.dll!RtlLookupFunctionEntry] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[ntdll.dll!RtlCaptureContext] [90900000946a25ff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[ntdll.dll!RtlNtStatusToDosError] [945625ff90909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[ntdll.dll!NtFsControlFile] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[ntdll.dll!NtQueryInformationFile] [90900000944225ff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[ntdll.dll!WinSqmAddToStream] [942e25ff90909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!FindResourceExW] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!SystemTimeToTzSpecificLocalTime] [9090000090d225ff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!TzSpecificLocalTimeToSystemTime] [90ae25ff90909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!FileTimeToSystemTime] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetProcessHeap] [907625ff90909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!HeapFree] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!DisableThreadLibraryCalls] [90900000906225ff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!LocalFree] [904625ff90909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!CompareFileTime] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!lstrlenW] [90900000902a25ff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetFileAttributesW] [901625ff90909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetLastError] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!MulDiv] [90900000900225ff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetFileAttributesExW] [8fee25ff90909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!LocalAlloc] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetVolumePathNameW] [909000008fd225ff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!SystemTimeToFileTime] [8348f3ff90909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!FreeLibrary] [da8b48188b4520ec] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetProcAddress] [41f8e38341c98b4c] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!LoadLibraryExA] [1374d18b4c0400f6] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!DelayLoadFailureHook] [450634d08408b41] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!Sleep] [c86348d1034cd8f7] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!QueryPerformanceCounter] [8b4ac36349d1234c] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetTickCount] [488b10438b481014] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetCurrentThreadId] [341f6084b034808] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetCurrentProcessId] [830341b60f0c740f] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetSystemTimeAsFileTime] [4cc8034c9848f0e0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!TerminateProcess] [c48348c98b49ca33] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetCurrentProcess] [90fff6ff41e95b20] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!UnhandledExceptionFilter] [9090909090909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!SetUnhandledExceptionFilter] [38418b4d28ec8348] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetVersionExW] [81e8d18b49ca8b48] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!FormatMessageW] [1b8ffffff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!MultiByteToWideChar] [909090c328c48348] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetDriveTypeW] [48c48b4890909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!LoadResource] [4810688948085889] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!LockResource] [4120788948187089] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetComputerNameW] [518b4d20ec834854] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetComputerNameExW] [41e08b4df28b4838] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetFileInformationByHandle] [d18b49e98b48028b] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!lstrcmpiW] [8b49ce8b48c00348] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!CreateEventW] [8b4c04c25c8d49f9] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!WaitForSingleObject] [8b44ffffff2ee8c3] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!lstrcmpA] [c38b4104558b441b] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!RegCloseKey] [1ba02e38341] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!LoadLibraryW] [245c8b48d08b0000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!CreateFileW] [8b4838246c8b4830] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!lstrlenA] [48247c8b48402474] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!CloseHandle] [5c4120c48348c28b] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetModuleFileNameW] [90909090909090c3] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!DeactivateActCtx] [909000008e9225ff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!ActivateActCtx] [9090909090909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!ReleaseActCtx] [9090909090909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!CreateActCtxW] [5a4db9c18b48] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetModuleHandleW] [c3c0330374083966] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!SetMenuItemInfoW] [38ec834890909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!GetMenuItemInfoW] [4489486024448b48] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!GetMenuItemCount] [48ffffff45e82024] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!DeleteMenu] [90909090c338c483] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!RedrawWindow] [8b5625ff90909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!SetWindowLongPtrW] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!GetWindowLongPtrW] [909000008d3225ff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!EnableWindow] [8d3625ff90909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!GetFocus] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!MoveWindow] [909000008d4225ff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!MapWindowPoints] [8d3e25ff90909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!GetWindowRect] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!KillTimer] [909000008d3a25ff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!GetSystemMetrics] [8d3625ff90909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!GetClientRect] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!SetTimer] [909000008d3225ff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!PostMessageW] [8d4625ff90909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!GetDlgItem] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!SetWindowPos] [909000008d4225ff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!GetWindowLongW] [8df625ff90909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!SetWindowLongW] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!SetDlgItemTextW] [909000008dfa25ff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!LoadStringA] [8df625ff90909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!InsertMenuItemW] [9090909090900000] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!LoadStringW] [909000008df225ff] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHCreateDefaultExtractIcon] [9090c3c18b48c3c0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHGetIDListFromObject] [ff5ee8c98b49fff6] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHBindToParent] [f71fe8c124408b0f] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHGetItemFromDataObject] [c03302eb01e083d0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!ShellExecuteExW] [909090c328c48348] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHGetKnownFolderPath] [9090909090909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHCreateShellItemArray] [244c894890909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHBindToObject] [3de858244c8b4860] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHParseDisplayName] [5024448948000002] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHCreateItemFromIDList] [41740050247c8348] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHCreateItemFromParsingName] [382444c748] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHBindToFolderIDListParentEx] [4024448d48302444] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHCreateDefaultContextMenu] [8b4c50244c8b4c20] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!PSGetPropertyDescriptionListFromString] [75000045503981c0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!PSCreateMultiplexPropertyStore] [39660000020bba0c] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!InitPropVariantFromResource] [90c3f3c0940f1851] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!PSCreateMemoryPropertyStore] [9090909090909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!InitVariantFromFileTime] [9090909090909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!PropVariantToStringAlloc] [4cc933453c41634c] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!PropVariantCompareEx] [b70f41c1034cd28b] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!VariantCompare] [4a0658b70f451440] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!VariantToPropVariant] [74db854518004c8d] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!PSFormatForDisplay] [72d23b4c0c518b1e] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!VariantToBuffer] [3b4cc20308418b0a] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!PSPropertyBag_WriteStr] [8348c1ff410f72d0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!StrDupW] [eb000001e5e8c933] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!SHRegGetValueW] [612e058b48000460] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!PathBuildRootW] [45f9f0589480004] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!StrChrW] [460a005894800] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!StrIsIntlEqualW] [40900045f7605c7] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!StrRetToBufW] [c5058b4800000001] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!SHStrDupW] [682444894800045c] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!SHSkipJunction] [15ffc93370244489] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!StrPBrkW] [ba0000920115ff00] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!StrCmpIW] [ffc88b48c0000409] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!PathRemoveFileSpecW] [9090909090909090] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!PathFindFileNameW] [158249c8b48] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!PathGetDriveNumberW] [894848244c8d4840] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!PathIsUNCW] [50244c8d4830244c] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!PathIsNetworkPathW] [28244c8948c88b4c] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!StrRetToStrW] [480000053824848b] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!PathRemoveBackslashW] [480000053824848d] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!PathIsUNCServerW] [15ff00010aca0d8d] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!_amsg_exit] [76e23bd0] C:\Windows\SYSTEM32\ntdll.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!free] [767336c0] C:\Windows\SYSTEM32\kernel32.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!_initterm] [76733620] C:\Windows\SYSTEM32\kernel32.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!malloc] [76e18050] C:\Windows\SYSTEM32\ntdll.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!_XcptFilter] [76e18020] C:\Windows\SYSTEM32\ntdll.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!wcsncmp] [76e154b0] C:\Windows\SYSTEM32\ntdll.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!wcstoul] [76e154e0] C:\Windows\SYSTEM32\ntdll.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!iswctype] [76729b80] C:\Windows\SYSTEM32\kernel32.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!_vsnwprintf] [767a9300] C:\Windows\SYSTEM32\kernel32.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!strtoul] [76725cf0] C:\Windows\SYSTEM32\kernel32.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!isdigit] [7675bca0] C:\Windows\SYSTEM32\kernel32.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!memcpy] [76723f40] C:\Windows\SYSTEM32\kernel32.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ntdll.dll!RtlLookupFunctionEntry] [76723ee0] C:\Windows\SYSTEM32\kernel32.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ntdll.dll!RtlVirtualUnwind] [76e284f0] C:\Windows\SYSTEM32\ntdll.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ntdll.dll!RtlCaptureContext] [76e19c50] C:\Windows\SYSTEM32\ntdll.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[KERNEL32.dll!GetCurrentThreadId] [0] IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[KERNEL32.dll!GetTickCount] [76723f00] C:\Windows\SYSTEM32\kernel32.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[KERNEL32.dll!GetCurrentProcess] [76732d60] C:\Windows\SYSTEM32\kernel32.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[KERNEL32.dll!SetUnhandledExceptionFilter] [76732f10] C:\Windows\SYSTEM32\kernel32.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[KERNEL32.dll!UnhandledExceptionFilter] [7671d9a0] C:\Windows\SYSTEM32\kernel32.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[KERNEL32.dll!DisableThreadLibraryCalls] [76dfc540] C:\Windows\SYSTEM32\ntdll.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[KERNEL32.dll!GetProcessHeap] [76e0e170] C:\Windows\SYSTEM32\ntdll.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[KERNEL32.dll!QueryPerformanceCounter] [76716650] C:\Windows\SYSTEM32\kernel32.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[KERNEL32.dll!Sleep] [76e02330] C:\Windows\SYSTEM32\ntdll.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[KERNEL32.dll!HeapFree] [76e021f0] C:\Windows\SYSTEM32\ntdll.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ADVAPI32.dll!RegEnumKeyExW] [7fefe3c1820] C:\Windows\system32\ADVAPI32.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ADVAPI32.dll!RegQueryValueExW] [7fefe3cb9e0] C:\Windows\system32\ADVAPI32.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ADVAPI32.dll!RegOpenKeyExW] [7fefe3cb9b0] C:\Windows\system32\ADVAPI32.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ADVAPI32.dll!RegQueryMultipleValuesA] [7fefe3bd980] C:\Windows\system32\ADVAPI32.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ADVAPI32.dll!RegCloseKey] [7fefe3bdd34] C:\Windows\system32\ADVAPI32.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ADVAPI32.dll!RegEnumKeyExA] [7fefe3cbd70] C:\Windows\system32\ADVAPI32.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ADVAPI32.dll!RegQueryValueExA] [7fefe3d0710] C:\Windows\system32\ADVAPI32.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ADVAPI32.dll!RegOpenKeyExA] [7fefe3d06f0] C:\Windows\system32\ADVAPI32.dll IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ADVAPI32.dll!RegDeleteValueW] [0] ---- EOF - GMER 2.0 ---- |
08.02.2013, 03:49 | #3 |
/// Helfer-Team | Flash Installation infiziertDie Bereinigung besteht aus mehreren Schritten, die ausgefuehrt werden muessen. Diese Nacheinander abarbeiten und die 3 Logs, die dabei erstellt werden bitte in deine naechste Antwort einfuegen. Sollte der OTL-FIX nicht richig durchgelaufen sein. Fahre nicht fort, sondern melde dies bitte. 1. Schritt Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Ersetze die verwendeten Platzhalter wieder in den Benutzernamen zurück! Code:
ATTFilter :OTL SRV - [2012.11.30 10:24:48 | 000,008,192 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\srvany.exe -- (KMService) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28 [2009.08.20 06:17:47 | 000,036,136 | ---- | C] (Oberon Media) -- C:\ProgramData\FullRemove.exe [2012.11.30 10:25:16 | 000,077,824 | ---- | C] () -- C:\Windows\KMService.exe [2012.11.30 10:25:16 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\srvany.exe :Files C:\ProgramData\*.exe C:\ProgramData\*.dll C:\ProgramData\*.tmp C:\ProgramData\TEMP C:\Users\MYNAME\*.tmp C:\Users\MYNAME\AppData\Local\Temp\*.exe C:\Users\MYNAME\AppData\LocalLow\Sun\Java\Deployment\cache ipconfig /flushdns /c :Commands [emptytemp]
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! 2. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 3. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
__________________ |
16.04.2013, 17:00 | #4 |
/// Helfer-Team | Flash Installation infiziert Fehlende Rückmeldung Gibt es Probleme beim Abarbeiten obiger Anleitung? Um Kapazitäten für andere Hilfesuchende freizumachen, lösche ich dieses Thema aus meinen Benachrichtigungen. Solltest Du weitermachen wollen, schreibe mir eine PN oder eröffne ein neues Thema. http://www.trojaner-board.de/69886-a...-beachten.html Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner sauber ist. |
Themen zu Flash Installation infiziert |
anhang, datei, desinfiziert, fehlende, flash, flashplayer, gestern, hoffe, infiziert, install, installation, interne, internet, internet security 2013, kaspersky, kaspersky internet security 2013, länger, malware, plötzlich, popup, scan, scanne, scannen, security, starte, warum, wenig, woran |