|
Plagegeister aller Art und deren Bekämpfung: Win32/Adware.AddLyrics.LWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
06.09.2013, 16:36 | #1 |
| Win32/Adware.AddLyrics.L Hallo, vorab: danke für die Hilfe! Bekomme seit heute beim Start von Chrome eine Warnung von ESET Ich vermute es liegt mit der Installation des SciLor's grooveshark(tm).com Downloader zusammen, den ich am 3. über eine Installationdatei installierte. Der Link war über die "offizielle" Seite des Programms verlinkt auf die ich über chip.de gestoßen bin (deshalb war ich mir auch relativ sicher) Link: hxxp://download.cnet.com/SciLor-s-Grooveshark-com-Downloader/3000-2071_4-75764950.html?part=dl-10055889&subj=dl nach der Installation habe ich mit adwcleaner einen Redirector entfernen können, der mich in Chrome über Links zu einer Seite (monstermegasale oder so...) weiterleiten wollte, jetzt heute das. (edit: im Zuge der ganzen Prozedur deaktivierte ich den Virenscanner für GMER scan, öffnete aus versehen Chrome mit und schwups, es wurde eine Erweiterung mit dem Namen addlyrics oder so installiert, die ich deinstallieren konnte, bisher kommen jetzt bei chrome neustart aber keine fehlermeldungen seitens eset) logs im Anhang allerings: FRST liefters keinen addition log! kA warum Geändert von colourhazed (06.09.2013 um 16:53 Uhr) |
06.09.2013, 16:54 | #2 |
/// the machine /// TB-Ausbilder | Win32/Adware.AddLyrics.L Hi,
__________________Logs bitte zur Not aufteilen und einzeln posten, auch in mehreren Posts. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
06.09.2013, 17:08 | #3 |
| Win32/Adware.AddLyrics.LCode:
ATTFilter <?xml version="1.0" encoding="utf-8" ?> <ESET> <LOG> <RECORD> <COLUMN NAME="Zeit"> <DATE>06.09.2013</DATE> <TIME>14:42:35</TIME> </COLUMN> <COLUMN NAME="Prüfung">Echtzeit-Dateischutz</COLUMN> <COLUMN NAME="Objekt">Datei</COLUMN> <COLUMN NAME="Name">C:\Users\eule\AppData\Local\Temp\scoped_dir_6584_27466\CRX_INSTALL\cs.js</COLUMN> <COLUMN NAME="Bedrohung">Win32/Adware.AddLyrics.L Anwendung</COLUMN> <COLUMN NAME="Aktion">Gesäubert durch Löschen - in Quarantäne kopiert</COLUMN> <COLUMN NAME="Benutzer">eule-PC\eule</COLUMN> <COLUMN NAME="Informationen">Ereignis beim Erstellen einer neuen Datei durch die Anwendung: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.</COLUMN> </RECORD> <RECORD> <COLUMN NAME="Zeit"> <DATE>06.09.2013</DATE> <TIME>14:42:03</TIME> </COLUMN> <COLUMN NAME="Prüfung">Echtzeit-Dateischutz</COLUMN> <COLUMN NAME="Objekt">Datei</COLUMN> <COLUMN NAME="Name">C:\Users\eule\AppData\Local\Temp\scoped_dir_8972_23559\CRX_INSTALL\cs.js</COLUMN> <COLUMN NAME="Bedrohung">Win32/Adware.AddLyrics.L Anwendung</COLUMN> <COLUMN NAME="Aktion">Gesäubert durch Löschen - in Quarantäne kopiert</COLUMN> <COLUMN NAME="Benutzer">eule-PC\eule</COLUMN> <COLUMN NAME="Informationen">Ereignis beim Erstellen einer neuen Datei durch die Anwendung: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.</COLUMN> </RECORD> <RECORD> <COLUMN NAME="Zeit"> <DATE>06.09.2013</DATE> <TIME>14:21:26</TIME> </COLUMN> <COLUMN NAME="Prüfung">Echtzeit-Dateischutz</COLUMN> <COLUMN NAME="Objekt">Datei</COLUMN> <COLUMN NAME="Name">C:\Users\eule\AppData\Local\Temp\scoped_dir_4844_25724\CRX_INSTALL\cs.js</COLUMN> <COLUMN NAME="Bedrohung">Win32/Adware.AddLyrics.L Anwendung</COLUMN> <COLUMN NAME="Aktion">Gesäubert durch Löschen - in Quarantäne kopiert</COLUMN> <COLUMN NAME="Benutzer">eule-PC\eule</COLUMN> <COLUMN NAME="Informationen">Ereignis beim Erstellen einer neuen Datei durch die Anwendung: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.</COLUMN> </RECORD> <RECORD> <COLUMN NAME="Zeit"> <DATE>06.09.2013</DATE> <TIME>13:58:21</TIME> </COLUMN> <COLUMN NAME="Prüfung">Echtzeit-Dateischutz</COLUMN> <COLUMN NAME="Objekt">Datei</COLUMN> <COLUMN NAME="Name">C:\Users\eule\AppData\Local\Temp\scoped_dir_3216_20281\CRX_INSTALL\cs.js</COLUMN> <COLUMN NAME="Bedrohung">Win32/Adware.AddLyrics.L Anwendung</COLUMN> <COLUMN NAME="Aktion">Gesäubert durch Löschen - in Quarantäne kopiert</COLUMN> <COLUMN NAME="Benutzer">eule-PC\eule</COLUMN> <COLUMN NAME="Informationen">Ereignis beim Erstellen einer neuen Datei durch die Anwendung: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.</COLUMN> </RECORD> <RECORD> <COLUMN NAME="Zeit"> <DATE>06.09.2013</DATE> <TIME>13:55:44</TIME> </COLUMN> <COLUMN NAME="Prüfung">Echtzeit-Dateischutz</COLUMN> <COLUMN NAME="Objekt">Datei</COLUMN> <COLUMN NAME="Name">C:\Users\eule\AppData\Local\Temp\scoped_dir_4940_18457\CRX_INSTALL\cs.js</COLUMN> <COLUMN NAME="Bedrohung">Win32/Adware.AddLyrics.L Anwendung</COLUMN> <COLUMN NAME="Aktion">Gesäubert durch Löschen - in Quarantäne kopiert</COLUMN> <COLUMN NAME="Benutzer">eule-PC\eule</COLUMN> <COLUMN NAME="Informationen">Ereignis beim Erstellen einer neuen Datei durch die Anwendung: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.</COLUMN> </RECORD> <RECORD> <COLUMN NAME="Zeit"> <DATE>06.09.2013</DATE> <TIME>13:39:38</TIME> </COLUMN> <COLUMN NAME="Prüfung">Echtzeit-Dateischutz</COLUMN> <COLUMN NAME="Objekt">Datei</COLUMN> <COLUMN NAME="Name">C:\Users\eule\AppData\Local\Temp\scoped_dir_5644_11004\CRX_INSTALL\cs.js</COLUMN> <COLUMN NAME="Bedrohung">Win32/Adware.AddLyrics.L Anwendung</COLUMN> <COLUMN NAME="Aktion">Gesäubert durch Löschen - in Quarantäne kopiert</COLUMN> <COLUMN NAME="Benutzer">eule-PC\eule</COLUMN> <COLUMN NAME="Informationen">Ereignis beim Erstellen einer neuen Datei durch die Anwendung: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.</COLUMN> </RECORD> <RECORD> <COLUMN NAME="Zeit"> <DATE>06.09.2013</DATE> <TIME>13:38:55</TIME> </COLUMN> <COLUMN NAME="Prüfung">Echtzeit-Dateischutz</COLUMN> <COLUMN NAME="Objekt">Datei</COLUMN> <COLUMN NAME="Name">C:\Users\eule\AppData\Local\Temp\scoped_dir_5828_3220\CRX_INSTALL\cs.js</COLUMN> <COLUMN NAME="Bedrohung">Win32/Adware.AddLyrics.L Anwendung</COLUMN> <COLUMN NAME="Aktion">Gesäubert durch Löschen - in Quarantäne kopiert</COLUMN> <COLUMN NAME="Benutzer">eule-PC\eule</COLUMN> <COLUMN NAME="Informationen">Ereignis beim Erstellen einer neuen Datei durch die Anwendung: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.</COLUMN> </RECORD> <RECORD> <COLUMN NAME="Zeit"> <DATE>06.09.2013</DATE> <TIME>13:25:05</TIME> </COLUMN> <COLUMN NAME="Prüfung">Echtzeit-Dateischutz</COLUMN> <COLUMN NAME="Objekt">Datei</COLUMN> <COLUMN NAME="Name">C:\Users\eule\AppData\Local\Temp\scoped_dir_4276_22600\CRX_INSTALL\cs.js</COLUMN> <COLUMN NAME="Bedrohung">Win32/Adware.AddLyrics.L Anwendung</COLUMN> <COLUMN NAME="Aktion">Gesäubert durch Löschen - in Quarantäne kopiert</COLUMN> <COLUMN NAME="Benutzer">eule-PC\eule</COLUMN> <COLUMN NAME="Informationen">Ereignis beim Erstellen einer neuen Datei durch die Anwendung: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.</COLUMN> </RECORD> <RECORD> <COLUMN NAME="Zeit"> <DATE>06.09.2013</DATE> <TIME>13:24:54</TIME> </COLUMN> <COLUMN NAME="Prüfung">Echtzeit-Dateischutz</COLUMN> <COLUMN NAME="Objekt">Datei</COLUMN> <COLUMN NAME="Name">C:\Users\eule\AppData\Local\Temp\scoped_dir_3592_26830\CRX_INSTALL\cs.js</COLUMN> <COLUMN NAME="Bedrohung">Win32/Adware.AddLyrics.L Anwendung</COLUMN> <COLUMN NAME="Aktion">Gesäubert durch Löschen - in Quarantäne kopiert</COLUMN> <COLUMN NAME="Benutzer">eule-PC\eule</COLUMN> <COLUMN NAME="Informationen">Ereignis beim Erstellen einer neuen Datei durch die Anwendung: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.</COLUMN> </RECORD> <RECORD> <COLUMN NAME="Zeit"> <DATE>04.09.2013</DATE> <TIME>15:53:12</TIME> </COLUMN> <COLUMN NAME="Prüfung">Echtzeit-Dateischutz</COLUMN> <COLUMN NAME="Objekt">Datei</COLUMN> <COLUMN NAME="Name">C:\program files (x86)\a2zlyr\ulyrme.exe</COLUMN> <COLUMN NAME="Bedrohung">Win32/AdWare.AddLyrics.P Anwendung</COLUMN> <COLUMN NAME="Aktion">Gesäubert durch Löschen - in Quarantäne kopiert</COLUMN> <COLUMN NAME="Benutzer">NT-AUTORITÄT\SYSTEM</COLUMN> <COLUMN NAME="Informationen">Ereignis aufgetreten beim Versuch, die Datei zu öffnen durch die Anwendung: C:\Windows\System32\rundll32.exe.</COLUMN> </RECORD> <RECORD> <COLUMN NAME="Zeit"> <DATE>03.09.2013</DATE> <TIME>18:21:55</TIME> </COLUMN> <COLUMN NAME="Prüfung">Echtzeit-Dateischutz</COLUMN> <COLUMN NAME="Objekt">Datei</COLUMN> <COLUMN NAME="Name">C:\Users\eule\AppData\Local\Temp\OptimizerPro.exe</COLUMN> <COLUMN NAME="Bedrohung">möglicherweise Variante von Win32/SpeedingUpMyPC.B Anwendung</COLUMN> <COLUMN NAME="Aktion">Gesäubert durch Löschen - in Quarantäne kopiert</COLUMN> <COLUMN NAME="Benutzer">eule-PC\eule</COLUMN> <COLUMN NAME="Informationen">Ereignis beim Erstellen einer neuen Datei durch die Anwendung: C:\Users\eule\AppData\Local\Temp\BetterInstaller.exe.</COLUMN> </RECORD> <RECORD> <COLUMN NAME="Zeit"> <DATE>03.09.2013</DATE> <TIME>18:21:55</TIME> </COLUMN> <COLUMN NAME="Prüfung">HTTP-Prüfung</COLUMN> <COLUMN NAME="Objekt">Datei</COLUMN> <COLUMN NAME="Name">hxxp://dl.softservers.net/111000779/OptimizerPro.exe</COLUMN> <COLUMN NAME="Bedrohung">möglicherweise Variante von Win32/SpeedingUpMyPC.B Anwendung</COLUMN> <COLUMN NAME="Aktion">Verbindung getrennt - in Quarantäne kopiert</COLUMN> <COLUMN NAME="Benutzer">eule-PC\eule</COLUMN> <COLUMN NAME="Informationen">Bedrohung erkannt beim Zugriff auf das Web durch die Anwendung: C:\Users\eule\AppData\Local\Temp\BetterInstaller.exe.</COLUMN> </RECORD> </LOG> </ESET> FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-09-2013 Ran by eule (administrator) on EULE-PC on 06-09-2013 17:29:07 Running from C:\Users\eule\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\pg_ctl.exe (Ralink Technology, Corp.) C:\Program Files (x86)\TRENDnet\Common\RaRegistry.exe (Ralink Technology, Corp.) C:\Program Files (x86)\TRENDnet\Common\RaRegistry64.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe () C:\Windows\SysWOW64\HsMgr.exe () C:\Windows\system\HsMgr64.exe (Microsoft Corporation) C:\Program Files\Microsoft IntelliType Pro\itype.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe (CMedia) C:\Program Files\ASUS Xonar DS Audio\Customapp\ASUSAUDIOCENTER.EXE (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe () C:\Users\eule\Local Settings\Apps\F.lux\flux.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung Electronics) C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe () C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe (Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE (EnTech Taiwan) C:\Program Files (x86)\Dell\Dell Display Manager\ddm.exe (TRENDnet) C:\Program Files (x86)\TRENDnet\Common\RaUI.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Dominik Reichl) C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Cmaudio8788] - C:\Windows\Syswow64\cmicnfgp.dll [8769536 2011-05-12] (C-Media Corporation) HKLM\...\Run: [Cmaudio8788GX] - C:\Windows\syswow64\HsMgr.exe [200704 2008-07-11] () HKLM\...\Run: [Cmaudio8788GX64] - C:\Windows\system\HsMgr64.exe [282112 2008-07-11] () HKLM\...\Run: [itype] - C:\Program Files\Microsoft IntelliType Pro\itype.exe [1873256 2011-08-10] (Microsoft Corporation) HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [1744152 2011-06-24] (Logitech, Inc.) HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [4081008 2012-03-07] (ESET) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) HKLM\...\Policies\Explorer: [NoActiveDesktop] 1 HKLM\...\Policies\Explorer: [NoActiveDesktopChanges] 1 HKCU\...\Run: [Rainlendar2] - C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe [x] HKCU\...\Run: [F.lux] - C:\Users\eule\Local Settings\Apps\F.lux\flux.exe [966656 2009-08-29] () HKCU\...\Run: [CPN Notifier] - C:\Program Files (x86)\Cake Poker 2.0\PokerNotifier.exe [x] HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [966072 2012-10-11] (Samsung) HKCU\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe [580096 2012-10-09] (Samsung Electronics) HKCU\...\Run: [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [843208 2012-10-19] (Samsung) HKCU\...\Run: [Pando Media Booster] - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2012-11-16] () HKCU\...\Run: [GoogleChromeAutoLaunch_C444C2D27A4094264BBB68880A11A0E3] - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [829392 2013-09-02] (Google Inc.) HKCU\...\Run: [HP Officejet Pro 8600 (NET)] - C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe [2676584 2011-09-09] (Hewlett-Packard Co.) HKLM-x32\...\Run: [KeePass 2 PreLoad] - C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [1823744 2012-01-05] (Dominik Reichl) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2012-02-20] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [421736 2012-03-27] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [309688 2012-10-11] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard) HKLM-x32\...\Run: [] - [x] HKU\Default\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x] HKU\Default User\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x] Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Dell Display Manager.lnk ShortcutTarget: Dell Display Manager.lnk -> C:\Program Files (x86)\Dell\Dell Display Manager\ddm.exe (EnTech Taiwan) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TRENDnet Wireless Utility.lnk ShortcutTarget: TRENDnet Wireless Utility.lnk -> C:\Program Files (x86)\TRENDnet\Common\RaUI.exe (TRENDnet) Startup: C:\Users\eule\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041) Startup: C:\Users\eule\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet Pro 8600 (Netzwerk).lnk ShortcutTarget: Tintenwarnungen überwachen - HP Officejet Pro 8600 (Netzwerk).lnk -> C:\Program Files\HP\HP Officejet Pro 8600\bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp BHO: Expat Shield Class - {3706EE7C-3CAD-445D-8A43-03EBC3B75908} - C:\Program Files (x86)\Expat Shield\HssIE\ExpatIE_64.dll No File BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: a2zLyrics - {a8600235-6084-48f1-af19-d1ed312cf660} - C:\Program Files (x86)\a2zlyr\131.dll (a2zLyrics) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Chrome: ======= CHR Extension: (AdBlock) - C:\Users\eule\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.6_1 CHR Extension: (Chrome In-App Payments service) - C:\Users\eule\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_1 CHR HKLM-x32\...\Chrome\Extension: [ciljpgjahkpnilhbolpaphfjhlejnplm] - C:\Program Files (x86)\a2zlyr\131.crx ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-12-19] (Advanced Micro Devices, Inc.) R2 DevoloNetworkService; C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [2231616 2010-07-19] () R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [913144 2012-03-07] (ESET) R2 RalinkRegistryWriter; C:\Program Files (x86)\TRENDnet\Common\RaRegistry.exe [374112 2010-11-11] (Ralink Technology, Corp.) R2 RalinkRegistryWriter64; C:\Program Files (x86)\TRENDnet\Common\RaRegistry64.exe [451936 2010-11-11] (Ralink Technology, Corp.) S3 RaMediaServer; C:\Program Files (x86)\TRENDnet\Common\RaMediaServer.exe [619872 2010-12-31] () R2 postgresql-8.4; C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N "postgresql-8.4" -D "C:/Program Files (x86)/PostgreSQL/8.4/data" -w [x] ==================== Drivers (Whitelisted) ==================== R2 AODDriver4.2; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [57472 2012-04-09] (Advanced Micro Devices) R3 cmudaxp; C:\Windows\System32\drivers\cmudaxp.sys [2725376 2011-03-10] (C-Media Inc) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [209768 2012-03-14] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [148528 2012-03-14] (ESET) R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [137144 2012-03-14] (ESET) R2 NPF_devolo; C:\Windows\sysWOW64\drivers\npf_devolo.sys [34048 2010-06-10] (CACE Technologies) S3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [22016 2013-03-04] (Razer USA Ltd) S3 dgderdrv; System32\drivers\dgderdrv.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-06 16:49 - 2013-09-06 16:49 - 00059099 _____ C:\Users\eule\Desktop\gmer.log 2013-09-06 16:43 - 2013-09-06 16:34 - 00377856 _____ C:\Users\eule\Desktop\gxkx2etp.exe 2013-09-06 16:42 - 2013-09-06 16:32 - 00050477 _____ C:\Users\eule\Desktop\Defogger.exe 2013-09-06 16:37 - 2013-09-06 17:28 - 00000470 _____ C:\Users\eule\Desktop\defogger_disable.log 2013-09-06 16:37 - 2013-09-06 16:37 - 00000000 ____D C:\FRST 2013-09-06 16:37 - 2013-09-06 16:37 - 00000000 _____ C:\Users\eule\defogger_reenable 2013-09-06 16:36 - 2013-09-06 16:41 - 00002127 _____ C:\Users\eule\Desktop\Neues Textdokument.txt 2013-09-06 16:35 - 2013-09-06 17:03 - 00001081 _____ C:\Users\eule\Desktop\post.txt 2013-09-06 16:34 - 2013-09-06 16:34 - 00377856 _____ C:\Users\eule\Downloads\gxkx2etp.exe 2013-09-06 16:33 - 2013-09-06 16:33 - 01948360 _____ (Farbar) C:\Users\eule\Desktop\FRST64.exe 2013-09-06 16:33 - 2013-09-06 16:33 - 00377856 _____ C:\Users\eule\Downloads\npivki83.exe 2013-09-06 16:32 - 2013-09-06 16:32 - 00050477 _____ C:\Users\eule\Downloads\Defogger.exe 2013-09-06 16:23 - 2013-09-06 16:23 - 00000000 _____ C:\Users\eule\Desktop\Neue Bitmap.bmp 2013-09-06 16:11 - 2013-09-06 16:12 - 232747636 _____ C:\Users\eule\Desktop\Diplomarbeit.rar 2013-09-06 10:51 - 2013-09-04 19:41 - 89818591 _____ C:\Users\eule\Desktop\20130904_194013.mp4 2013-09-03 21:55 - 2013-09-03 21:57 - 00000000 ____D C:\AdwCleaner 2013-09-03 21:30 - 2013-09-03 21:30 - 01037222 _____ C:\Users\eule\Downloads\adwcleaner.exe 2013-09-03 20:22 - 2013-09-06 17:06 - 00000360 _____ C:\Windows\Tasks\a2zLyrics Update.job 2013-09-03 20:22 - 2013-09-05 20:51 - 00000000 ____D C:\Users\eule\Desktop\SciLor's Grooveshark.com Downloader 2013-09-03 20:22 - 2013-09-04 17:53 - 00000000 ____D C:\Program Files (x86)\a2zlyr 2013-09-03 20:22 - 2013-09-03 20:22 - 00003006 _____ C:\Windows\System32\Tasks\a2zLyrics Update 2013-09-03 20:22 - 2013-09-03 20:22 - 00000877 _____ C:\Users\eule\Desktop\SciLor's grooveshark(tm).com Downloader.lnk 2013-09-01 17:47 - 2013-09-01 17:48 - 00000000 ____D C:\Users\eule\Desktop\HEM2 2013-08-31 15:06 - 2013-08-31 15:06 - 18101344 _____ (Adobe Systems Inc.) C:\Users\eule\Downloads\AdobeAIRInstaller.exe 2013-08-28 18:08 - 2013-08-29 00:22 - 00000000 ____D C:\Users\eule\AppData\Roaming\HandBrake 2013-08-28 18:07 - 2013-08-28 18:07 - 14298467 _____ C:\Users\eule\Downloads\handbrake-0.9.9-1_x86_64-win_gui.exe 2013-08-28 18:07 - 2013-08-28 18:07 - 00000824 _____ C:\Users\postgres\Desktop\Handbrake.lnk 2013-08-28 18:07 - 2013-08-28 18:07 - 00000000 ____D C:\Users\eule\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Handbrake 2013-08-28 18:07 - 2013-08-28 18:07 - 00000000 ____D C:\Program Files\Handbrake 2013-08-28 17:55 - 2013-08-28 17:55 - 00026744 _____ C:\Users\eule\Downloads\Streaming Harry-Potter-1---Der-Stein-...-2001-.avi - BitShare.com - Free File Hosting and Cloud Storage.avi 2013-08-28 14:23 - 2013-08-28 14:23 - 00000000 ____D C:\Users\eule\AppData\Roaming\ImgBurn 2013-08-28 14:15 - 2013-08-28 14:15 - 00000000 ____D C:\Program Files (x86)\ImgBurn 2013-08-28 14:14 - 2013-08-28 14:14 - 03469871 _____ (LIGHTNING UK!) C:\Users\eule\Downloads\SetupImgBurn_2.5.8.0.exe 2013-08-27 11:21 - 2013-08-27 11:21 - 00124219 _____ C:\Users\eule\Desktop\sixmax.xml 2013-08-15 00:38 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-15 00:38 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-15 00:38 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-15 00:38 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-15 00:38 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-15 00:38 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-15 00:38 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-15 00:38 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-15 00:38 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-15 00:38 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-15 00:38 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-15 00:38 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-15 00:38 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-15 00:38 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-15 00:38 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-15 00:38 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-15 00:38 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-15 00:38 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-15 00:38 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-15 00:38 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-15 00:38 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-15 00:38 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-15 00:38 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-15 00:38 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-15 00:38 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-15 00:38 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-15 00:38 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-15 00:38 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-15 00:38 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-15 00:38 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-15 00:38 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-14 14:41 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-14 14:41 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-14 14:41 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 14:41 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-14 14:41 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 14:41 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 14:41 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-14 14:41 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 14:41 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 14:41 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 14:41 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 14:41 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 14:41 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-08-14 14:41 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-08-14 14:41 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-14 14:41 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 14:41 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 14:41 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-14 14:41 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 14:41 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-14 14:41 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-14 14:41 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-14 14:41 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-14 14:41 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-14 14:41 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-14 14:41 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 14:41 - 2013-06-15 06:35 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2013-08-14 14:41 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-08 18:25 - 2013-08-08 19:12 - 00000155 _____ C:\Users\eule\Desktop\Kündigen.txt 2013-08-08 16:00 - 2013-08-08 18:40 - 00000000 ____D C:\Users\eule\Desktop\Export Holdemmanger2 DB haende 2013-08-08 13:15 - 2013-08-08 13:15 - 00000000 ____D C:\Users\eule\Desktop\Neuer Ordner 2013-08-08 00:37 - 2013-08-08 00:37 - 11568927 _____ C:\Users\eule\Downloads\4 Tables $10-$20 and $25-$50 6-Max Deep Ante PLO (part 1) - Pot Limit Omaha - Run It Once.mp4 2013-08-07 21:50 - 2013-08-07 21:50 - 00000000 ____D C:\ProgramData\id Software 2013-08-07 21:49 - 2013-08-07 21:49 - 02095104 _____ C:\Users\eule\Downloads\QuakeLiveNP_520.msi 2013-08-07 20:43 - 2013-08-08 00:55 - 00000000 ____D C:\Users\eule\Desktop\HEM2 fullbackup 2012+13 ==================== One Month Modified Files and Folders ======= 2013-09-06 17:28 - 2013-09-06 16:37 - 00000470 _____ C:\Users\eule\Desktop\defogger_disable.log 2013-09-06 17:26 - 2012-04-28 17:01 - 01126132 _____ C:\Windows\WindowsUpdate.log 2013-09-06 17:19 - 2012-04-28 17:49 - 00000000 ____D C:\Users\eule\AppData\Roaming\Skype 2013-09-06 17:13 - 2009-07-14 06:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-06 17:13 - 2009-07-14 06:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-06 17:11 - 2011-04-12 09:43 - 00696832 _____ C:\Windows\system32\perfh007.dat 2013-09-06 17:11 - 2011-04-12 09:43 - 00148128 _____ C:\Windows\system32\perfc007.dat 2013-09-06 17:11 - 2009-07-14 07:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-06 17:08 - 2012-04-28 17:25 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-06 17:06 - 2013-09-03 20:22 - 00000360 _____ C:\Windows\Tasks\a2zLyrics Update.job 2013-09-06 17:06 - 2012-04-28 17:25 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-06 17:06 - 2009-07-14 06:51 - 00240149 _____ C:\Windows\setupact.log 2013-09-06 17:05 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-06 17:04 - 2012-04-28 18:26 - 00000000 ____D C:\Users\eule\AppData\Roaming\KeePass 2013-09-06 17:03 - 2013-09-06 16:35 - 00001081 _____ C:\Users\eule\Desktop\post.txt 2013-09-06 16:54 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-09-06 16:49 - 2013-09-06 16:49 - 00059099 _____ C:\Users\eule\Desktop\gmer.log 2013-09-06 16:41 - 2013-09-06 16:36 - 00002127 _____ C:\Users\eule\Desktop\Neues Textdokument.txt 2013-09-06 16:41 - 2012-04-28 11:46 - 00000000 ____D C:\hm 2013-09-06 16:37 - 2013-09-06 16:37 - 00000000 ____D C:\FRST 2013-09-06 16:37 - 2013-09-06 16:37 - 00000000 _____ C:\Users\eule\defogger_reenable 2013-09-06 16:37 - 2012-04-28 17:01 - 00000000 ____D C:\Users\eule 2013-09-06 16:34 - 2013-09-06 16:43 - 00377856 _____ C:\Users\eule\Desktop\gxkx2etp.exe 2013-09-06 16:34 - 2013-09-06 16:34 - 00377856 _____ C:\Users\eule\Downloads\gxkx2etp.exe 2013-09-06 16:33 - 2013-09-06 16:33 - 01948360 _____ (Farbar) C:\Users\eule\Desktop\FRST64.exe 2013-09-06 16:33 - 2013-09-06 16:33 - 00377856 _____ C:\Users\eule\Downloads\npivki83.exe 2013-09-06 16:32 - 2013-09-06 16:42 - 00050477 _____ C:\Users\eule\Desktop\Defogger.exe 2013-09-06 16:32 - 2013-09-06 16:32 - 00050477 _____ C:\Users\eule\Downloads\Defogger.exe 2013-09-06 16:23 - 2013-09-06 16:23 - 00000000 _____ C:\Users\eule\Desktop\Neue Bitmap.bmp 2013-09-06 16:13 - 2012-04-28 18:10 - 00000000 ____D C:\Users\eule\AppData\Roaming\Microgaming 2013-09-06 16:12 - 2013-09-06 16:11 - 232747636 _____ C:\Users\eule\Desktop\Diplomarbeit.rar 2013-09-06 16:09 - 2013-02-09 13:53 - 00000000 ____D C:\Users\eule\Desktop\Diplomarbeit 2013-09-06 15:36 - 2012-12-15 21:19 - 00000000 ____D C:\Users\eule\Documents\Citavi 3 2013-09-06 11:16 - 2012-04-29 11:41 - 00000000 ____D C:\Users\eule\AppData\Roaming\vlc 2013-09-05 20:51 - 2013-09-03 20:22 - 00000000 ____D C:\Users\eule\Desktop\SciLor's Grooveshark.com Downloader 2013-09-05 19:42 - 2013-02-18 17:47 - 00000000 ____D C:\Program Files (x86)\Full Tilt Poker.Eu 2013-09-05 19:39 - 2012-04-28 18:04 - 00000000 ____D C:\Users\eule\AppData\Local\PokerStars.EU 2013-09-05 12:40 - 2012-09-30 01:08 - 00000000 ____D C:\Users\eule\Documents\My Kindle Content 2013-09-04 19:41 - 2013-09-06 10:51 - 89818591 _____ C:\Users\eule\Desktop\20130904_194013.mp4 2013-09-04 17:53 - 2013-09-03 20:22 - 00000000 ____D C:\Program Files (x86)\a2zlyr 2013-09-03 22:01 - 2010-11-21 05:47 - 00013644 _____ C:\Windows\PFRO.log 2013-09-03 21:57 - 2013-09-03 21:55 - 00000000 ____D C:\AdwCleaner 2013-09-03 21:30 - 2013-09-03 21:30 - 01037222 _____ C:\Users\eule\Downloads\adwcleaner.exe 2013-09-03 20:22 - 2013-09-03 20:22 - 00003006 _____ C:\Windows\System32\Tasks\a2zLyrics Update 2013-09-03 20:22 - 2013-09-03 20:22 - 00000877 _____ C:\Users\eule\Desktop\SciLor's grooveshark(tm).com Downloader.lnk 2013-09-02 17:11 - 2012-12-15 21:19 - 00000000 ____D C:\Users\eule\AppData\Roaming\Swiss Academic Software 2013-09-02 01:53 - 2012-05-05 16:27 - 00000000 ____D C:\Users\eule\AppData\Roaming\HoldemManager 2013-09-02 00:51 - 2012-04-28 17:19 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-09-02 00:50 - 2012-11-16 21:14 - 00000000 ____D C:\ProgramData\PMB Files 2013-09-01 17:48 - 2013-09-01 17:47 - 00000000 ____D C:\Users\eule\Desktop\HEM2 2013-09-01 14:34 - 2012-04-29 02:03 - 00000000 ____D C:\Users\eule\AppData\Roaming\HEM Data 2013-09-01 11:58 - 2013-01-07 11:00 - 00016655 _____ C:\speederr.txt 2013-09-01 11:44 - 2012-04-29 19:14 - 00319317 _____ C:\blitzerr.txt 2013-09-01 11:43 - 2013-02-18 17:48 - 00000000 ____D C:\Users\eule\AppData\Local\FullTiltPoker.eu 2013-09-01 10:30 - 2012-11-09 10:18 - 00000000 ____D C:\Program Files (x86)\TableNinjaFT 2013-09-01 10:29 - 2012-04-29 00:55 - 00000000 ____D C:\Program Files (x86)\TableNinja 2013-08-31 15:06 - 2013-08-31 15:06 - 18101344 _____ (Adobe Systems Inc.) C:\Users\eule\Downloads\AdobeAIRInstaller.exe 2013-08-29 00:22 - 2013-08-28 18:08 - 00000000 ____D C:\Users\eule\AppData\Roaming\HandBrake 2013-08-28 18:07 - 2013-08-28 18:07 - 14298467 _____ C:\Users\eule\Downloads\handbrake-0.9.9-1_x86_64-win_gui.exe 2013-08-28 18:07 - 2013-08-28 18:07 - 00000824 _____ C:\Users\postgres\Desktop\Handbrake.lnk 2013-08-28 18:07 - 2013-08-28 18:07 - 00000000 ____D C:\Users\eule\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Handbrake 2013-08-28 18:07 - 2013-08-28 18:07 - 00000000 ____D C:\Program Files\Handbrake 2013-08-28 17:55 - 2013-08-28 17:55 - 00026744 _____ C:\Users\eule\Downloads\Streaming Harry-Potter-1---Der-Stein-...-2001-.avi - BitShare.com - Free File Hosting and Cloud Storage.avi 2013-08-28 14:23 - 2013-08-28 14:23 - 00000000 ____D C:\Users\eule\AppData\Roaming\ImgBurn 2013-08-28 14:15 - 2013-08-28 14:15 - 00000000 ____D C:\Program Files (x86)\ImgBurn 2013-08-28 14:14 - 2013-08-28 14:14 - 03469871 _____ (LIGHTNING UK!) C:\Users\eule\Downloads\SetupImgBurn_2.5.8.0.exe 2013-08-27 11:21 - 2013-08-27 11:21 - 00124219 _____ C:\Users\eule\Desktop\sixmax.xml 2013-08-26 14:05 - 2012-04-28 18:02 - 00000000 ____D C:\Users\eule\Documents\888poker 2013-08-15 18:38 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-08-15 00:33 - 2012-05-03 07:08 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-08-14 18:53 - 2013-01-15 14:25 - 00000000 ____D C:\Users\eule\AppData\Local\Windows Live 2013-08-10 20:39 - 2012-07-24 22:19 - 00517205 _____ C:\Users\eule\pokerclient-redbet.log 2013-08-08 19:12 - 2013-08-08 18:25 - 00000155 _____ C:\Users\eule\Desktop\Kündigen.txt 2013-08-08 18:40 - 2013-08-08 16:00 - 00000000 ____D C:\Users\eule\Desktop\Export Holdemmanger2 DB haende 2013-08-08 13:15 - 2013-08-08 13:15 - 00000000 ____D C:\Users\eule\Desktop\Neuer Ordner 2013-08-08 00:55 - 2013-08-07 20:43 - 00000000 ____D C:\Users\eule\Desktop\HEM2 fullbackup 2012+13 2013-08-08 00:37 - 2013-08-08 00:37 - 11568927 _____ C:\Users\eule\Downloads\4 Tables $10-$20 and $25-$50 6-Max Deep Ante PLO (part 1) - Pot Limit Omaha - Run It Once.mp4 2013-08-07 21:50 - 2013-08-07 21:50 - 00000000 ____D C:\ProgramData\id Software 2013-08-07 21:49 - 2013-08-07 21:49 - 02095104 _____ C:\Users\eule\Downloads\QuakeLiveNP_520.msi 2013-08-07 20:47 - 2012-10-01 20:55 - 00000000 ____D C:\Users\eule\Desktop\asdf Files to move or delete: ==================== C:\Users\eule\AppData\Local\Temp\appshat-distribution.exe C:\Users\eule\AppData\Local\Temp\AskSLib.dll C:\Users\eule\AppData\Local\Temp\DeltaTB.exe C:\Users\eule\AppData\Local\Temp\incredibar_installer.exe C:\Users\eule\AppData\Local\Temp\install.exe C:\Users\eule\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\eule\AppData\Local\Temp\LMkRstPt.exe C:\Users\eule\AppData\Local\Temp\MyBabylonTB_google_20120807.exe C:\Users\eule\AppData\Local\Temp\ose00000.exe C:\Users\eule\AppData\Local\Temp\pricepeep_130001_0101.exe C:\Users\eule\AppData\Local\Temp\Quarantine.exe C:\Users\eule\AppData\Local\Temp\setup.exe C:\Users\eule\AppData\Local\Temp\sfamcc00001.dll C:\Users\eule\AppData\Local\Temp\sfamcc00002.dll C:\Users\eule\AppData\Local\Temp\sfareca00002.dll C:\Users\eule\AppData\Local\Temp\sfextra.dll C:\Users\eule\AppData\Local\Temp\SkypeSetup.exe C:\Users\eule\AppData\Local\Temp\swt-win32-3740.dll C:\Users\eule\AppData\Local\Temp\tmp586B.exe C:\Users\eule\AppData\Local\Temp\tmp6CA7.exe C:\Users\eule\AppData\Local\Temp\tmpB499.exe C:\Users\eule\AppData\Local\Temp\UpdateCheckerSetup.exe C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\mfc80u.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\msvcp80.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\msvcr80.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx86\vcredist_x86\install.exe C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx86\vcredist_x86\install.res.1028.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx86\vcredist_x86\install.res.1031.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx86\vcredist_x86\install.res.1033.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx86\vcredist_x86\install.res.1036.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx86\vcredist_x86\install.res.1040.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx86\vcredist_x86\install.res.1041.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx86\vcredist_x86\install.res.1042.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx86\vcredist_x86\install.res.1049.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx86\vcredist_x86\install.res.2052.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx86\vcredist_x86\install.res.3082.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx64\vcredist_x64\install.exe C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx64\vcredist_x64\install.res.1028.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx64\vcredist_x64\install.res.1031.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx64\vcredist_x64\install.res.1033.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx64\vcredist_x64\install.res.1036.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx64\vcredist_x64\install.res.1040.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx64\vcredist_x64\install.res.1041.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx64\vcredist_x64\install.res.1042.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx64\vcredist_x64\install.res.1049.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx64\vcredist_x64\install.res.2052.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\VC8RTx64\vcredist_x64\install.res.3082.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\RAIDXpert_SB8xx\3rdParty\SB8xx_RAIDXpert.exe C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\NetFx64\NetFx64\NetFx64.exe C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Packages\Apps\dotnetfx\dotnetfx\dotnetfx.exe C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin64\ATILog.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin64\ATIManifestDLMExt.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin64\ATISetup.exe C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin64\CompressionDLMExt.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin64\ControlCenterActions.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin64\CRCVerDLMExt.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin64\DetectionManager.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin64\difxapi.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin64\DLMCom.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin64\EncryptionDLMExt.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin64\InstallManager.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin64\InstallManagerApp.exe C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin64\LanguageMgr.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin64\mfc80u.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin64\msvcp80.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin64\msvcr80.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin64\PackageManager.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin64\Setup.exe C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin64\xerces-c_2_6.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin64\zlibwapi.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin\ATILog.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin\ATIManifestDLMExt.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin\ATISetup.exe C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin\CompressionDLMExt.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin\ControlCenterActions.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin\CRCVerDLMExt.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin\DetectionManager.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin\difxapi.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin\DLMCom.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin\EncryptionDLMExt.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin\InstallManager.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin\InstallManagerApp.exe C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin\LanguageMgr.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin\mfc80u.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin\msvcp80.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin\msvcr80.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin\PackageManager.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin\Setup.exe C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin\xerces-c_2_6.dll C:\Users\eule\AppData\Local\Temp\Temp1_AllIn1_Win7-64_Win7_Vista64_Vista_XP64_XP(8.70a_WHQL).zip\AllIn1(8.70a_WHQL)\Bin\zlibwapi.dll C:\Users\eule\AppData\Local\Temp\TeamViewer\Version7\TeamViewer_.exe C:\Users\eule\AppData\Local\Temp\swtlib-32\swt-awt-win32-3631.dll C:\Users\eule\AppData\Local\Temp\swtlib-32\swt-win32-3631.dll C:\Users\eule\AppData\Local\Temp\setup_0114808\888pokersetup.exe C:\Users\eule\AppData\Local\Temp\RzUpdater\Ionic.Zip.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\log4net.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\RzCommon.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\RzStorage.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\RzUpdateManager.exe C:\Users\eule\AppData\Local\Temp\RzUpdater\RzUpdateManagerUI.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\zh-CN\RzSynapse.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\zh-CN\RzSynapseLoginUI.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\zh-CN\RzUpdateManager.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\zh-CHT\RzSynapse.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\zh-CHT\RzSynapseLoginUI.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\zh-CHT\RzUpdateManager.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\Uninstallers\Razer_Common_Driver\RazerCommonDriverUninstaller.exe C:\Users\eule\AppData\Local\Temp\RzUpdater\Uninstallers\RazerFonts\RazerFonts_Uninstaller.exe C:\Users\eule\AppData\Local\Temp\RzUpdater\Uninstallers\RazerDeathAdder2013Config\RazerDeathAdder2013Config_Uninstaller.exe C:\Users\eule\AppData\Local\Temp\RzUpdater\Uninstallers\RazerCommonConfig\RazerCommonConfig_Uninstaller.exe C:\Users\eule\AppData\Local\Temp\RzUpdater\ru-RU\RzSynapse.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\ru-RU\RzSynapseLoginUI.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\ru-RU\RzUpdateManager.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\pt-BR\RzSynapse.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\pt-BR\RzSynapseLoginUI.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\pt-BR\RzUpdateManager.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\ko-KR\RzSynapse.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\ko-KR\RzSynapseLoginUI.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\ko-KR\RzUpdateManager.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\ja-JP\RzSynapse.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\ja-JP\RzSynapseLoginUI.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\ja-JP\RzUpdateManager.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\fr-FR\RzSynapse.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\fr-FR\RzSynapseLoginUI.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\fr-FR\RzUpdateManager.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\es-ES\RzSynapse.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\es-ES\RzSynapseLoginUI.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\es-ES\RzUpdateManager.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\de-DE\RzSynapse.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\de-DE\RzSynapseLoginUI.resources.dll C:\Users\eule\AppData\Local\Temp\RzUpdater\de-DE\RzUpdateManager.resources.dll C:\Users\eule\AppData\Local\Temp\RarSFX0\IPSU\Setup.exe C:\Users\eule\AppData\Local\Temp\RarSFX0\IPSU\Install\x86\cabarc.exe C:\Users\eule\AppData\Local\Temp\RarSFX0\IPSU\Install\x86\engine.dll C:\Users\eule\AppData\Local\Temp\RarSFX0\IPSU\Install\x86\InstallGui.exe C:\Users\eule\AppData\Local\Temp\RarSFX0\IPSU\Install\x86\lexlog.dll C:\Users\eule\AppData\Local\Temp\RarSFX0\IPSU\Install\x86\LiveUpdt.dll C:\Users\eule\AppData\Local\Temp\RarSFX0\IPSU\Install\x86\LM__bc.dll C:\Users\eule\AppData\Local\Temp\RarSFX0\IPSU\Install\x86\LM__hcp.dll C:\Users\eule\AppData\Local\Temp\RarSFX0\IPSU\Install\x86\NetSupp.dll C:\Users\eule\AppData\Local\Temp\RarSFX0\IPSU\Install\x86\PkgInstall.exe C:\Users\eule\AppData\Local\Temp\RarSFX0\IPSU\Install\x86\softcoin.dll C:\Users\eule\AppData\Local\Temp\RarSFX0\IPSU\Install\x64\engine.dll C:\Users\eule\AppData\Local\Temp\RarSFX0\IPSU\Install\x64\InstallGui.exe C:\Users\eule\AppData\Local\Temp\RarSFX0\IPSU\Install\x64\lexlog.dll C:\Users\eule\AppData\Local\Temp\RarSFX0\IPSU\Install\x64\LiveUpdt.dll C:\Users\eule\AppData\Local\Temp\RarSFX0\IPSU\Install\x64\LM__bc.dll C:\Users\eule\AppData\Local\Temp\RarSFX0\IPSU\Install\x64\LM__hcp.dll C:\Users\eule\AppData\Local\Temp\RarSFX0\IPSU\Install\x64\NetSupp.dll C:\Users\eule\AppData\Local\Temp\RarSFX0\IPSU\Install\x64\softcoin.dll C:\Users\eule\AppData\Local\Temp\PG\SmartUpgrader\PGSmartUpgrade.exe C:\Users\eule\AppData\Local\Temp\PG\SmartUpgrader\zlib.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\dotNetFx40LP_Full_x86_x64de.exe C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\Setup.exe C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\SetupEngine.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\SetupUi.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\SetupUtility.exe C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\sqmapi.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\3082\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\3076\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\2070\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\2052\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1055\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1053\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1049\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1046\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1045\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1044\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1043\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1042\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1041\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1040\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1038\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1037\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1036\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1035\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1033\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1032\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1031\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1030\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1029\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1028\SetupResources.dll C:\Users\eule\AppData\Local\Temp\Microsoft .NET Framework 4 Setup_4.0.30319\1025\SetupResources.dll C:\Users\eule\AppData\Local\Temp\MarkAny\ContentSafer\MaAgent.exe C:\Users\eule\AppData\Local\Temp\MarkAny\ContentSafer\MAAuthProc.dll C:\Users\eule\AppData\Local\Temp\MarkAny\ContentSafer\MACLICX13.dll C:\Users\eule\AppData\Local\Temp\MarkAny\ContentSafer\MACLicX15.dll C:\Users\eule\AppData\Local\Temp\MarkAny\ContentSafer\MACSMANAGER.dll C:\Users\eule\AppData\Local\Temp\MarkAny\ContentSafer\MaCSMgr.exe C:\Users\eule\AppData\Local\Temp\MarkAny\ContentSafer\MaCSProHook.dll C:\Users\eule\AppData\Local\Temp\MarkAny\ContentSafer\mapshapi.dll C:\Users\eule\AppData\Local\Temp\MarkAny\ContentSafer\mapwij10.dll C:\Users\eule\AppData\Local\Temp\MarkAny\ContentSafer\MaSyncP.dll C:\Users\eule\AppData\Local\Temp\MarkAny\ContentSafer\MaWAMP.dll C:\Users\eule\AppData\Local\Temp\MarkAny\ContentSafer\MAWebControl.exe C:\Users\eule\AppData\Local\Temp\MarkAny\ContentSafer\MaWMP.dll C:\Users\eule\AppData\Local\Temp\MarkAny\ContentSafer\MPXBox.exe C:\Users\eule\AppData\Local\Temp\MarkAny\ContentSafer\MtpAccess.dll C:\Users\eule\AppData\Local\Temp\MarkAny\ContentSafer\UserShare.dll C:\Users\eule\AppData\Local\Temp\MarkAny\ContentSafer\XSYNCClt.dll C:\Users\eule\AppData\Local\Temp\MarkAny\ContentSafer\UpdateClient\MAFileUpdate.dll C:\Users\eule\AppData\Local\Temp\MarkAny\ContentSafer\UpdateClient\MAUpdate.exe C:\Users\eule\AppData\Local\Temp\MarkAny\ContentSafer\UpdateClient\MAUpdateBoot.exe C:\Users\eule\AppData\Local\Temp\MarkAny\ContentSafer\UpdateClient\MaUpdateClient.exe C:\Users\eule\AppData\Local\Temp\lu\1_dj_unifysw.exe C:\Users\eule\AppData\Local\Temp\lu\1_spp_10000a1.exe C:\Users\eule\AppData\Local\Temp\lu\1_spp_Q4004.exe C:\Users\eule\AppData\Local\Temp\lu\2_spp_200006d.exe C:\Users\eule\AppData\Local\Temp\lu\3_spp_10000a2.exe C:\Users\eule\AppData\Local\Temp\lu\3_spp_200006d.exe C:\Users\eule\AppData\Local\Temp\lu\sp_10064_5_setpoint_logitech_64.exe C:\Users\eule\AppData\Local\Temp\lu\sp_20064_6_unifying_logitech_64.exe C:\Users\eule\AppData\Local\Temp\lu\sp_30064_3b_redistr64_logitech_64.exe C:\Users\eule\AppData\Local\Temp\lu\sp_40064_7a_lu_logitech_64.exe C:\Users\eule\AppData\Local\Temp\Logitech\DevicePackageSAM\DPHlpr.dll C:\Users\eule\AppData\Local\Temp\joi9F7F.tmp\lmiscrhook64-Clone000.dll C:\Users\eule\AppData\Local\Temp\joi8667.tmp\lmiscrhook32-Clone000.dll C:\Users\eule\AppData\Local\Temp\joi8667.tmp\lmiscrhook64-Clone000.dll C:\Users\eule\AppData\Local\Temp\joi863A.tmp\lmiscrhook32-Clone000.dll C:\Users\eule\AppData\Local\Temp\joi863A.tmp\lmiscrhook64-Clone000.dll C:\Users\eule\AppData\Local\Temp\joi85ED.tmp\lmiscrhook32-Clone000.dll C:\Users\eule\AppData\Local\Temp\joi85ED.tmp\lmiscrhook64-Clone000.dll C:\Users\eule\AppData\Local\Temp\joi21C.tmp\lmiscrhook32-Clone000.dll C:\Users\eule\AppData\Local\Temp\joi21C.tmp\lmiscrhook64-Clone000.dll C:\Users\eule\AppData\Local\Temp\is-7UQ1U.tmp\dvssyshelper.dll C:\Users\eule\AppData\Local\Temp\is-7UQ1U.tmp\InnoCallback.dll C:\Users\eule\AppData\Local\Temp\is-7UQ1U.tmp\psvince.dll C:\Users\eule\AppData\Local\Temp\is-7UQ1U.tmp\_isetup\_shfoldr.dll C:\Users\eule\AppData\Local\Temp\is-2F7E8.tmp\dvssyshelper.dll C:\Users\eule\AppData\Local\Temp\is-2F7E8.tmp\InnoCallback.dll C:\Users\eule\AppData\Local\Temp\is-2F7E8.tmp\psvince.dll C:\Users\eule\AppData\Local\Temp\is-2F7E8.tmp\_isetup\_shfoldr.dll C:\Users\eule\AppData\Local\Temp\ICD1.tmp\FP_AX_CAB_INSTALLER64.exe C:\Users\eule\AppData\Local\Temp\e4j8287.tmp_dir\i4jinst.dll C:\Users\eule\AppData\Local\Temp\be29e7f1-71ae-4703-50cb-1d52be512f51\twapi-be29e7f1-71ae-4703-50cb-1d52be512f51.dll C:\Users\eule\AppData\Local\Temp\5eb7a3db-8621-4131-b849-4f59e4b7e373\CliSecureRT.dll C:\Users\eule\AppData\Local\Temp\51dcc584-8329-4198-a7d3-3588a70ffbd0\CliSecureRT.dll C:\Users\eule\AppData\Local\Temp\28b64586-8ca8-47a1-aa7a-b34872124d3e\CliSecureRT.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-01 00:44 ==================== End Of Log ============================ |
06.09.2013, 17:09 | #4 |
| Win32/Adware.AddLyrics.L GMER Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-09-06 16:49:36 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\0000006d SAMSUNG_ rev.CXM0 119,24GB Running: gxkx2etp.exe; Driver: C:\Users\eule\AppData\Local\Temp\kxldapow.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1692] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 00000000752387b1 4 bytes [C2, 04, 00, 00] .text C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1692] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 00000000762b1465 2 bytes [2B, 76] .text C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1692] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 00000000762b14bb 2 bytes [2B, 76] .text ... * 2 .text C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe[1956] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000762b1465 2 bytes [2B, 76] .text C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe[1956] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000762b14bb 2 bytes [2B, 76] .text ... * 2 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076779d0b 5 bytes JMP 000000011000a4d0 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx 0000000076779d4e 5 bytes JMP 000000011000a630 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\WINMM.dll!waveOutOpen 000000007323451e 5 bytes JMP 000000011000ab40 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\WINMM.dll!waveOutClose 0000000073234b6d 5 bytes JMP 000000011000abb0 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\WINMM.dll!waveOutUnprepareHeader 0000000073234bf2 5 bytes JMP 000000011000ac90 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\WINMM.dll!waveOutPrepareHeader 0000000073234f0f 5 bytes JMP 000000011000ac50 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\WINMM.dll!waveOutWrite 0000000073234f7b 5 bytes JMP 000000011000ac10 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\WINMM.dll!waveInOpen 0000000073239054 5 bytes JMP 000000011000ad10 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\WINMM.dll!waveOutReset 000000007323adf9 5 bytes JMP 000000011000abe0 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\WINMM.dll!waveOutGetVolume 00000000732552e8 5 bytes JMP 000000011000acd0 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\WINMM.dll!waveOutSetVolume 000000007325535f 5 bytes JMP 000000011000acf0 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\WINMM.dll!waveInClose 00000000732559cc 5 bytes JMP 000000011000ae40 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\WINMM.dll!waveInPrepareHeader 0000000073255a6a 5 bytes JMP 000000011000aec0 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\WINMM.dll!waveInUnprepareHeader 0000000073255ad7 5 bytes JMP 000000011000af00 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\WINMM.dll!waveInAddBuffer 0000000073255b5b 5 bytes JMP 000000011000af40 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\WINMM.dll!waveInStart 0000000073255bba 5 bytes JMP 000000011000af80 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\WINMM.dll!waveInStop 0000000073255bee 5 bytes JMP 000000011000b000 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\WINMM.dll!waveInReset 0000000073255c22 5 bytes JMP 000000011000b060 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\WINMM.dll!waveInGetPosition 0000000073255c67 5 bytes JMP 000000011000b0d0 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 00000000647f7e3d 5 bytes JMP 000000011000a690 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006482de69 5 bytes JMP 000000011000a770 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006483d2c5 5 bytes JMP 000000011000a8a0 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006483d371 5 bytes JMP 000000011000a990 .text C:\Windows\SysWOW64\HsMgr.exe[3352] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006483d429 5 bytes JMP 000000011000aa80 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\WINMM.dll!waveOutClose 000007fefada36ac 5 bytes JMP 000007fefd3501f0 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\WINMM.dll!waveOutUnprepareHeader 000007fefada3770 5 bytes JMP 000007fefd350298 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\WINMM.dll!waveOutOpen 000007fefada38d0 5 bytes JMP 000007fefd3501b8 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\WINMM.dll!waveOutPrepareHeader 000007fefada3ca4 5 bytes JMP 000007fefd350260 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\WINMM.dll!waveOutWrite 000007fefada3d40 5 bytes JMP 000007fefd350228 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\WINMM.dll!waveInOpen 000007fefada7fe0 7 bytes JMP 000007fefd350378 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\WINMM.dll!waveOutReset 000007fefadaa38c 5 bytes JMP 000007fefd3502d0 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\WINMM.dll!waveOutGetVolume 000007fefadc49f0 5 bytes JMP 000007fefd350308 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\WINMM.dll!waveOutSetVolume 000007fefadc4ab0 5 bytes JMP 000007fefd350340 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\WINMM.dll!waveInClose 000007fefadc52e0 5 bytes JMP 000007fefd3503b0 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\WINMM.dll!waveInPrepareHeader 000007fefadc53c0 5 bytes JMP 000007fefd350490 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\WINMM.dll!waveInUnprepareHeader 000007fefadc5454 5 bytes JMP 000007fefd3504c8 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\WINMM.dll!waveInAddBuffer 000007fefadc5514 5 bytes JMP 000007fefd350500 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\WINMM.dll!waveInStart 000007fefadc55a4 6 bytes JMP 000007fefd3503e8 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\WINMM.dll!waveInStop 000007fefadc55e4 6 bytes JMP 000007fefd350420 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\WINMM.dll!waveInReset 000007fefadc5624 5 bytes JMP 000007fefd350458 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\WINMM.dll!waveInGetPosition 000007fefadc567c 5 bytes JMP 000007fefd350538 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\DSOUND.dll!DirectSoundCreate8 000007fef0716944 7 bytes JMP 000007fefd350180 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\DSOUND.dll!DirectSoundCreate 000007fef0735a84 7 bytes JMP 000007fefd350148 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\DSOUND.dll!DirectSoundCaptureCreate 000007fef0735b90 7 bytes JMP 000007fefd350570 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\DSOUND.dll!DirectSoundCaptureCreate8 000007fef0735c94 7 bytes JMP 000007fefd3505a8 .text C:\Windows\system\HsMgr64.exe[3360] C:\Windows\system32\DSOUND.dll!DirectSoundFullDuplexCreate 000007fef0735da8 5 bytes JMP 000007fefd3505e0 .text C:\Users\eule\Local Settings\Apps\F.lux\flux.exe[3420] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000762b1465 2 bytes [2B, 76] .text C:\Users\eule\Local Settings\Apps\F.lux\flux.exe[3420] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000762b14bb 2 bytes [2B, 76] .text ... * 2 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076779d0b 5 bytes JMP 000000011000a4d0 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx 0000000076779d4e 5 bytes JMP 000000011000a630 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\WINMM.dll!waveOutOpen 000000007323451e 5 bytes JMP 000000011000ab40 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\WINMM.dll!waveOutClose 0000000073234b6d 5 bytes JMP 000000011000abb0 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\WINMM.dll!waveOutUnprepareHeader 0000000073234bf2 5 bytes JMP 000000011000ac90 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\WINMM.dll!waveOutPrepareHeader 0000000073234f0f 5 bytes JMP 000000011000ac50 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\WINMM.dll!waveOutWrite 0000000073234f7b 5 bytes JMP 000000011000ac10 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\WINMM.dll!waveInOpen 0000000073239054 5 bytes JMP 000000011000ad10 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\WINMM.dll!waveOutReset 000000007323adf9 5 bytes JMP 000000011000abe0 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\WINMM.dll!waveOutGetVolume 00000000732552e8 5 bytes JMP 000000011000acd0 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\WINMM.dll!waveOutSetVolume 000000007325535f 5 bytes JMP 000000011000acf0 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\WINMM.dll!waveInClose 00000000732559cc 5 bytes JMP 000000011000ae40 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\WINMM.dll!waveInPrepareHeader 0000000073255a6a 5 bytes JMP 000000011000aec0 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\WINMM.dll!waveInUnprepareHeader 0000000073255ad7 5 bytes JMP 000000011000af00 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\WINMM.dll!waveInAddBuffer 0000000073255b5b 5 bytes JMP 000000011000af40 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\WINMM.dll!waveInStart 0000000073255bba 5 bytes JMP 000000011000af80 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\WINMM.dll!waveInStop 0000000073255bee 5 bytes JMP 000000011000b000 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\WINMM.dll!waveInReset 0000000073255c22 5 bytes JMP 000000011000b060 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\WINMM.dll!waveInGetPosition 0000000073255c67 5 bytes JMP 000000011000b0d0 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 00000000647f7e3d 5 bytes JMP 000000011000a690 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006482de69 5 bytes JMP 000000011000a770 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006483d2c5 5 bytes JMP 000000011000a8a0 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006483d371 5 bytes JMP 000000011000a990 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006483d429 5 bytes JMP 000000011000aa80 .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000762b1465 2 bytes [2B, 76] .text C:\Program Files (x86)\Samsung\Kies\Kies.exe[3440] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000762b14bb 2 bytes [2B, 76] .text ... * 2 .text C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe[3448] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076779d0b 5 bytes JMP 000000011000a4d0 .text C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe[3448] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx 0000000076779d4e 5 bytes JMP 000000011000a630 .text C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe[3448] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 00000000647f7e3d 5 bytes JMP 000000011000a690 .text C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe[3448] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006482de69 5 bytes JMP 000000011000a770 .text C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe[3448] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006483d2c5 5 bytes JMP 000000011000a8a0 .text C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe[3448] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006483d371 5 bytes JMP 000000011000a990 .text C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe[3448] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006483d429 5 bytes JMP 000000011000aa80 .text C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[3528] C:\Windows\SysWOW64\ntdll.dll!DbgBreakPoint 000000007734000c 1 byte [C3] .text C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[3528] C:\Windows\SysWOW64\ntdll.dll!DbgUiRemoteBreakin 00000000773cf8ea 5 bytes JMP 000000017737d5c1 .text C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[3528] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076779d0b 5 bytes JMP 000000011000a4d0 .text C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[3528] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx 0000000076779d4e 5 bytes JMP 000000011000a630 .text C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[3528] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 00000000647f7e3d 5 bytes JMP 000000011000a690 .text C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[3528] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006482de69 5 bytes JMP 000000011000a770 .text C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[3528] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006483d2c5 5 bytes JMP 000000011000a8a0 .text C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[3528] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006483d371 5 bytes JMP 000000011000a990 .text C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[3528] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006483d429 5 bytes JMP 000000011000aa80 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\syswow64\OLE32.DLL!CoCreateInstance 0000000076779d0b 5 bytes JMP 000000011000a4d0 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\syswow64\OLE32.DLL!CoCreateInstanceEx 0000000076779d4e 5 bytes JMP 000000011000a630 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\WINMM.dll!waveOutOpen 000000007323451e 5 bytes JMP 000000011000ab40 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\WINMM.dll!waveOutClose 0000000073234b6d 5 bytes JMP 000000011000abb0 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\WINMM.dll!waveOutUnprepareHeader 0000000073234bf2 5 bytes JMP 000000011000ac90 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\WINMM.dll!waveOutPrepareHeader 0000000073234f0f 5 bytes JMP 000000011000ac50 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\WINMM.dll!waveOutWrite 0000000073234f7b 5 bytes JMP 000000011000ac10 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\WINMM.dll!waveInOpen 0000000073239054 5 bytes JMP 000000011000ad10 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\WINMM.dll!waveOutReset 000000007323adf9 5 bytes JMP 000000011000abe0 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\WINMM.dll!waveOutGetVolume 00000000732552e8 5 bytes JMP 000000011000acd0 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\WINMM.dll!waveOutSetVolume 000000007325535f 5 bytes JMP 000000011000acf0 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\WINMM.dll!waveInClose 00000000732559cc 5 bytes JMP 000000011000ae40 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\WINMM.dll!waveInPrepareHeader 0000000073255a6a 5 bytes JMP 000000011000aec0 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\WINMM.dll!waveInUnprepareHeader 0000000073255ad7 5 bytes JMP 000000011000af00 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\WINMM.dll!waveInAddBuffer 0000000073255b5b 5 bytes JMP 000000011000af40 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\WINMM.dll!waveInStart 0000000073255bba 5 bytes JMP 000000011000af80 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\WINMM.dll!waveInStop 0000000073255bee 5 bytes JMP 000000011000b000 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\WINMM.dll!waveInReset 0000000073255c22 5 bytes JMP 000000011000b060 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\WINMM.dll!waveInGetPosition 0000000073255c67 5 bytes JMP 000000011000b0d0 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 00000000647f7e3d 5 bytes JMP 000000011000a690 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006482de69 5 bytes JMP 000000011000a770 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006483d2c5 5 bytes JMP 000000011000a8a0 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006483d371 5 bytes JMP 000000011000a990 .text C:\Program Files (x86)\TRENDnet\Common\RaUI.exe[3948] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006483d429 5 bytes JMP 000000011000aa80 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076779d0b 5 bytes JMP 000000011000a4d0 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx 0000000076779d4e 5 bytes JMP 000000011000a630 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\WINMM.dll!waveOutOpen 000000007323451e 5 bytes JMP 000000011000ab40 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\WINMM.dll!waveOutClose 0000000073234b6d 5 bytes JMP 000000011000abb0 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\WINMM.dll!waveOutUnprepareHeader 0000000073234bf2 5 bytes JMP 000000011000ac90 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\WINMM.dll!waveOutPrepareHeader 0000000073234f0f 5 bytes JMP 000000011000ac50 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\WINMM.dll!waveOutWrite 0000000073234f7b 5 bytes JMP 000000011000ac10 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\WINMM.dll!waveInOpen 0000000073239054 5 bytes JMP 000000011000ad10 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\WINMM.dll!waveOutReset 000000007323adf9 5 bytes JMP 000000011000abe0 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\WINMM.dll!waveOutGetVolume 00000000732552e8 5 bytes JMP 000000011000acd0 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\WINMM.dll!waveOutSetVolume 000000007325535f 5 bytes JMP 000000011000acf0 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\WINMM.dll!waveInClose 00000000732559cc 5 bytes JMP 000000011000ae40 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\WINMM.dll!waveInPrepareHeader 0000000073255a6a 5 bytes JMP 000000011000aec0 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\WINMM.dll!waveInUnprepareHeader 0000000073255ad7 5 bytes JMP 000000011000af00 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\WINMM.dll!waveInAddBuffer 0000000073255b5b 5 bytes JMP 000000011000af40 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\WINMM.dll!waveInStart 0000000073255bba 5 bytes JMP 000000011000af80 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\WINMM.dll!waveInStop 0000000073255bee 5 bytes JMP 000000011000b000 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\WINMM.dll!waveInReset 0000000073255c22 5 bytes JMP 000000011000b060 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\WINMM.dll!waveInGetPosition 0000000073255c67 5 bytes JMP 000000011000b0d0 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 00000000647f7e3d 5 bytes JMP 000000011000a690 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006482de69 5 bytes JMP 000000011000a770 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006483d2c5 5 bytes JMP 000000011000a8a0 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006483d371 5 bytes JMP 000000011000a990 .text C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe[4076] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006483d429 5 bytes JMP 000000011000aa80 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076779d0b 5 bytes JMP 000000011000a4d0 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx 0000000076779d4e 5 bytes JMP 000000011000a630 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000762b1465 2 bytes [2B, 76] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000762b14bb 2 bytes [2B, 76] .text ... * 2 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\WINMM.dll!waveOutOpen 000000007323451e 5 bytes JMP 000000011000ab40 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\WINMM.dll!waveOutClose 0000000073234b6d 5 bytes JMP 000000011000abb0 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\WINMM.dll!waveOutUnprepareHeader 0000000073234bf2 5 bytes JMP 000000011000ac90 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\WINMM.dll!waveOutPrepareHeader 0000000073234f0f 5 bytes JMP 000000011000ac50 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\WINMM.dll!waveOutWrite 0000000073234f7b 5 bytes JMP 000000011000ac10 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\WINMM.dll!waveInOpen 0000000073239054 5 bytes JMP 000000011000ad10 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\WINMM.dll!waveOutReset 000000007323adf9 5 bytes JMP 000000011000abe0 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\WINMM.dll!waveOutGetVolume 00000000732552e8 5 bytes JMP 000000011000acd0 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\WINMM.dll!waveOutSetVolume 000000007325535f 5 bytes JMP 000000011000acf0 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\WINMM.dll!waveInClose 00000000732559cc 5 bytes JMP 000000011000ae40 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\WINMM.dll!waveInPrepareHeader 0000000073255a6a 5 bytes JMP 000000011000aec0 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\WINMM.dll!waveInUnprepareHeader 0000000073255ad7 5 bytes JMP 000000011000af00 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\WINMM.dll!waveInAddBuffer 0000000073255b5b 5 bytes JMP 000000011000af40 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\WINMM.dll!waveInStart 0000000073255bba 5 bytes JMP 000000011000af80 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\WINMM.dll!waveInStop 0000000073255bee 5 bytes JMP 000000011000b000 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\WINMM.dll!waveInReset 0000000073255c22 5 bytes JMP 000000011000b060 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\WINMM.dll!waveInGetPosition 0000000073255c67 5 bytes JMP 000000011000b0d0 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 00000000647f7e3d 5 bytes JMP 000000011000a690 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006482de69 5 bytes JMP 000000011000a770 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006483d2c5 5 bytes JMP 000000011000a8a0 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006483d371 5 bytes JMP 000000011000a990 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3140] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006483d429 5 bytes JMP 000000011000aa80 .text C:\Program Files (x86)\iTunes\iTunesHelper.exe[3276] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076779d0b 5 bytes JMP 000000011000a4d0 .text C:\Program Files (x86)\iTunes\iTunesHelper.exe[3276] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx 0000000076779d4e 5 bytes JMP 000000011000a630 .text C:\Program Files (x86)\iTunes\iTunesHelper.exe[3276] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 00000000647f7e3d 5 bytes JMP 000000011000a690 .text C:\Program Files (x86)\iTunes\iTunesHelper.exe[3276] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006482de69 5 bytes JMP 000000011000a770 .text C:\Program Files (x86)\iTunes\iTunesHelper.exe[3276] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006483d2c5 5 bytes JMP 000000011000a8a0 .text C:\Program Files (x86)\iTunes\iTunesHelper.exe[3276] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006483d371 5 bytes JMP 000000011000a990 .text C:\Program Files (x86)\iTunes\iTunesHelper.exe[3276] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006483d429 5 bytes JMP 000000011000aa80 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076779d0b 5 bytes JMP 000000011000a4d0 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx 0000000076779d4e 5 bytes JMP 000000011000a630 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\WINMM.dll!waveOutOpen 000000007323451e 5 bytes JMP 000000011000ab40 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\WINMM.dll!waveOutClose 0000000073234b6d 5 bytes JMP 000000011000abb0 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\WINMM.dll!waveOutUnprepareHeader 0000000073234bf2 5 bytes JMP 000000011000ac90 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\WINMM.dll!waveOutPrepareHeader 0000000073234f0f 5 bytes JMP 000000011000ac50 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\WINMM.dll!waveOutWrite 0000000073234f7b 5 bytes JMP 000000011000ac10 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\WINMM.dll!waveInOpen 0000000073239054 5 bytes JMP 000000011000ad10 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\WINMM.dll!waveOutReset 000000007323adf9 5 bytes JMP 000000011000abe0 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\WINMM.dll!waveOutGetVolume 00000000732552e8 5 bytes JMP 000000011000acd0 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\WINMM.dll!waveOutSetVolume 000000007325535f 5 bytes JMP 000000011000acf0 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\WINMM.dll!waveInClose 00000000732559cc 5 bytes JMP 000000011000ae40 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\WINMM.dll!waveInPrepareHeader 0000000073255a6a 5 bytes JMP 000000011000aec0 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\WINMM.dll!waveInUnprepareHeader 0000000073255ad7 5 bytes JMP 000000011000af00 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\WINMM.dll!waveInAddBuffer 0000000073255b5b 5 bytes JMP 000000011000af40 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\WINMM.dll!waveInStart 0000000073255bba 5 bytes JMP 000000011000af80 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\WINMM.dll!waveInStop 0000000073255bee 5 bytes JMP 000000011000b000 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\WINMM.dll!waveInReset 0000000073255c22 5 bytes JMP 000000011000b060 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\WINMM.dll!waveInGetPosition 0000000073255c67 5 bytes JMP 000000011000b0d0 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 00000000647f7e3d 5 bytes JMP 000000011000a690 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006482de69 5 bytes JMP 000000011000a770 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006483d2c5 5 bytes JMP 000000011000a8a0 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006483d371 5 bytes JMP 000000011000a990 .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4192] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006483d429 5 bytes JMP 000000011000aa80 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076779d0b 5 bytes JMP 000000011000a4d0 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx 0000000076779d4e 5 bytes JMP 000000011000a630 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\WINMM.dll!waveOutOpen 000000007323451e 5 bytes JMP 000000011000ab40 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\WINMM.dll!waveOutClose 0000000073234b6d 5 bytes JMP 000000011000abb0 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\WINMM.dll!waveOutUnprepareHeader 0000000073234bf2 5 bytes JMP 000000011000ac90 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\WINMM.dll!waveOutPrepareHeader 0000000073234f0f 5 bytes JMP 000000011000ac50 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\WINMM.dll!waveOutWrite 0000000073234f7b 5 bytes JMP 000000011000ac10 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\WINMM.dll!waveInOpen 0000000073239054 5 bytes JMP 000000011000ad10 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\WINMM.dll!waveOutReset 000000007323adf9 5 bytes JMP 000000011000abe0 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\WINMM.dll!waveOutGetVolume 00000000732552e8 5 bytes JMP 000000011000acd0 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\WINMM.dll!waveOutSetVolume 000000007325535f 5 bytes JMP 000000011000acf0 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\WINMM.dll!waveInClose 00000000732559cc 5 bytes JMP 000000011000ae40 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\WINMM.dll!waveInPrepareHeader 0000000073255a6a 5 bytes JMP 000000011000aec0 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\WINMM.dll!waveInUnprepareHeader 0000000073255ad7 5 bytes JMP 000000011000af00 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\WINMM.dll!waveInAddBuffer 0000000073255b5b 5 bytes JMP 000000011000af40 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\WINMM.dll!waveInStart 0000000073255bba 5 bytes JMP 000000011000af80 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\WINMM.dll!waveInStop 0000000073255bee 5 bytes JMP 000000011000b000 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\WINMM.dll!waveInReset 0000000073255c22 5 bytes JMP 000000011000b060 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\WINMM.dll!waveInGetPosition 0000000073255c67 5 bytes JMP 000000011000b0d0 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 00000000647f7e3d 5 bytes JMP 000000011000a690 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006482de69 5 bytes JMP 000000011000a770 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006483d2c5 5 bytes JMP 000000011000a8a0 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006483d371 5 bytes JMP 000000011000a990 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006483d429 5 bytes JMP 000000011000aa80 .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000762b1465 2 bytes [2B, 76] .text C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe[4260] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000762b14bb 2 bytes [2B, 76] .text ... * 2 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\WINMM.dll!waveOutOpen 000000007323451e 5 bytes JMP 000000011000ab40 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\WINMM.dll!waveOutClose 0000000073234b6d 5 bytes JMP 000000011000abb0 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\WINMM.dll!waveOutUnprepareHeader 0000000073234bf2 5 bytes JMP 000000011000ac90 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\WINMM.dll!waveOutPrepareHeader 0000000073234f0f 5 bytes JMP 000000011000ac50 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\WINMM.dll!waveOutWrite 0000000073234f7b 5 bytes JMP 000000011000ac10 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\WINMM.dll!waveInOpen 0000000073239054 5 bytes JMP 000000011000ad10 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\WINMM.dll!waveOutReset 000000007323adf9 5 bytes JMP 000000011000abe0 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\WINMM.dll!waveOutGetVolume 00000000732552e8 5 bytes JMP 000000011000acd0 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\WINMM.dll!waveOutSetVolume 000000007325535f 5 bytes JMP 000000011000acf0 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\WINMM.dll!waveInClose 00000000732559cc 5 bytes JMP 000000011000ae40 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\WINMM.dll!waveInPrepareHeader 0000000073255a6a 5 bytes JMP 000000011000aec0 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\WINMM.dll!waveInUnprepareHeader 0000000073255ad7 5 bytes JMP 000000011000af00 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\WINMM.dll!waveInAddBuffer 0000000073255b5b 5 bytes JMP 000000011000af40 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\WINMM.dll!waveInStart 0000000073255bba 5 bytes JMP 000000011000af80 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\WINMM.dll!waveInStop 0000000073255bee 5 bytes JMP 000000011000b000 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\WINMM.dll!waveInReset 0000000073255c22 5 bytes JMP 000000011000b060 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\WINMM.dll!waveInGetPosition 0000000073255c67 5 bytes JMP 000000011000b0d0 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 00000000647f7e3d 5 bytes JMP 000000011000a690 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006482de69 5 bytes JMP 000000011000a770 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006483d2c5 5 bytes JMP 000000011000a8a0 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006483d371 5 bytes JMP 000000011000a990 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006483d429 5 bytes JMP 000000011000aa80 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076779d0b 5 bytes JMP 000000011000a4d0 .text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[4584] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx 0000000076779d4e 5 bytes JMP 000000011000a630 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\syswow64\ole32.DLL!CoCreateInstance 0000000076779d0b 5 bytes JMP 000000011000a4d0 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\syswow64\ole32.DLL!CoCreateInstanceEx 0000000076779d4e 5 bytes JMP 000000011000a630 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\WINMM.dll!waveOutOpen 000000007323451e 5 bytes JMP 000000011000ab40 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\WINMM.dll!waveOutClose 0000000073234b6d 5 bytes JMP 000000011000abb0 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\WINMM.dll!waveOutUnprepareHeader 0000000073234bf2 5 bytes JMP 000000011000ac90 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\WINMM.dll!waveOutPrepareHeader 0000000073234f0f 5 bytes JMP 000000011000ac50 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\WINMM.dll!waveOutWrite 0000000073234f7b 5 bytes JMP 000000011000ac10 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\WINMM.dll!waveInOpen 0000000073239054 5 bytes JMP 000000011000ad10 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\WINMM.dll!waveOutReset 000000007323adf9 5 bytes JMP 000000011000abe0 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\WINMM.dll!waveOutGetVolume 00000000732552e8 5 bytes JMP 000000011000acd0 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\WINMM.dll!waveOutSetVolume 000000007325535f 5 bytes JMP 000000011000acf0 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\WINMM.dll!waveInClose 00000000732559cc 5 bytes JMP 000000011000ae40 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\WINMM.dll!waveInPrepareHeader 0000000073255a6a 5 bytes JMP 000000011000aec0 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\WINMM.dll!waveInUnprepareHeader 0000000073255ad7 5 bytes JMP 000000011000af00 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\WINMM.dll!waveInAddBuffer 0000000073255b5b 5 bytes JMP 000000011000af40 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\WINMM.dll!waveInStart 0000000073255bba 5 bytes JMP 000000011000af80 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\WINMM.dll!waveInStop 0000000073255bee 5 bytes JMP 000000011000b000 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\WINMM.dll!waveInReset 0000000073255c22 5 bytes JMP 000000011000b060 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\WINMM.dll!waveInGetPosition 0000000073255c67 5 bytes JMP 000000011000b0d0 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 00000000647f7e3d 5 bytes JMP 000000011000a690 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006482de69 5 bytes JMP 000000011000a770 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006483d2c5 5 bytes JMP 000000011000a8a0 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006483d371 5 bytes JMP 000000011000a990 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006483d429 5 bytes JMP 000000011000aa80 .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000762b1465 2 bytes [2B, 76] .text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[3164] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000762b14bb 2 bytes [2B, 76] .text ... * 2 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\WINMM.dll!waveOutOpen 000000007323451e 5 bytes JMP 000000011000ab40 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\WINMM.dll!waveOutClose 0000000073234b6d 5 bytes JMP 000000011000abb0 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\WINMM.dll!waveOutUnprepareHeader 0000000073234bf2 5 bytes JMP 000000011000ac90 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\WINMM.dll!waveOutPrepareHeader 0000000073234f0f 5 bytes JMP 000000011000ac50 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\WINMM.dll!waveOutWrite 0000000073234f7b 5 bytes JMP 000000011000ac10 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\WINMM.dll!waveInOpen 0000000073239054 5 bytes JMP 000000011000ad10 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\WINMM.dll!waveOutReset 000000007323adf9 5 bytes JMP 000000011000abe0 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\WINMM.dll!waveOutGetVolume 00000000732552e8 5 bytes JMP 000000011000acd0 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\WINMM.dll!waveOutSetVolume 000000007325535f 5 bytes JMP 000000011000acf0 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\WINMM.dll!waveInClose 00000000732559cc 5 bytes JMP 000000011000ae40 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\WINMM.dll!waveInPrepareHeader 0000000073255a6a 5 bytes JMP 000000011000aec0 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\WINMM.dll!waveInUnprepareHeader 0000000073255ad7 5 bytes JMP 000000011000af00 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\WINMM.dll!waveInAddBuffer 0000000073255b5b 5 bytes JMP 000000011000af40 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\WINMM.dll!waveInStart 0000000073255bba 5 bytes JMP 000000011000af80 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\WINMM.dll!waveInStop 0000000073255bee 5 bytes JMP 000000011000b000 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\WINMM.dll!waveInReset 0000000073255c22 5 bytes JMP 000000011000b060 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\WINMM.dll!waveInGetPosition 0000000073255c67 5 bytes JMP 000000011000b0d0 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 00000000647f7e3d 5 bytes JMP 000000011000a690 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006482de69 5 bytes JMP 000000011000a770 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006483d2c5 5 bytes JMP 000000011000a8a0 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006483d371 5 bytes JMP 000000011000a990 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006483d429 5 bytes JMP 000000011000aa80 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076779d0b 5 bytes JMP 000000011000a4d0 .text C:\Users\eule\Desktop\gxkx2etp.exe[9204] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx 0000000076779d4e 5 bytes JMP 000000011000a630 ---- EOF - GMER 2.1 ---- |
07.09.2013, 07:23 | #5 | |
/// the machine /// TB-Ausbilder | Win32/Adware.AddLyrics.LCombofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
07.09.2013, 13:49 | #6 |
| Win32/Adware.AddLyrics.LCode:
ATTFilter ComboFix 13-09-06.01 - eule 07.09.2013 14:39:52.1.8 - x64 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.8169.5426 [GMT 2:00] ausgeführt von:: c:\users\eule\Desktop\ComboFix.exe AV: ESET NOD32 Antivirus 5.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1} SP: ESET NOD32 Antivirus 5.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\app c:\programdata\app\drivers.ini c:\users\eule\AppData\Local\TempFullTiltPokerEuSetup.exe c:\users\eule\AppData\Roaming\Roaming c:\users\eule\AppData\Roaming\Roaming\HoldemManager\config\FTPRushTables.xml . . ((((((((((((((((((((((( Dateien erstellt von 2013-08-07 bis 2013-09-07 )))))))))))))))))))))))))))))) . . 2013-09-07 12:45 . 2013-09-07 12:45 -------- d-----w- c:\users\postgres\AppData\Local\temp 2013-09-07 12:45 . 2013-09-07 12:45 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-09-07 08:12 . 2013-09-07 08:12 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{64AC14FE-E392-404B-94C1-8BA4ED9B35ED}\offreg.dll 2013-09-06 14:37 . 2013-09-06 14:37 -------- d-----w- C:\FRST 2013-09-06 07:56 . 2013-08-06 08:58 9515512 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{64AC14FE-E392-404B-94C1-8BA4ED9B35ED}\mpengine.dll 2013-09-03 22:28 . 2013-09-03 22:28 -------- d-----w- c:\windows\SysWow64\Wat 2013-09-03 22:28 . 2013-09-03 22:28 -------- d-----w- c:\windows\system32\Wat 2013-09-03 19:55 . 2013-09-03 19:57 -------- d-----w- C:\AdwCleaner 2013-08-28 16:08 . 2013-08-28 22:22 -------- d-----w- c:\users\eule\AppData\Roaming\HandBrake 2013-08-28 16:07 . 2013-08-28 16:07 -------- d-----w- c:\program files\Handbrake 2013-08-28 12:23 . 2013-08-28 12:23 -------- d-----w- c:\users\eule\AppData\Roaming\ImgBurn 2013-08-28 12:15 . 2013-08-28 12:15 -------- d-----w- c:\program files (x86)\ImgBurn 2013-08-14 12:41 . 2013-07-09 05:52 224256 ----a-w- c:\windows\system32\wintrust.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-07-09 04:45 . 2013-08-14 12:41 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2006-05-03 10:06 163328 --sha-r- c:\windows\SysWOW64\flvDX.dll 2007-02-21 11:47 31232 --sha-r- c:\windows\SysWOW64\msfDX.dll 2008-03-16 13:30 216064 --sha-r- c:\windows\SysWOW64\nbDX.dll 2010-01-06 22:00 107520 --sha-r- c:\windows\SysWOW64\TAKDSDecoder.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "F.lux"="c:\users\eule\Local Settings\Apps\F.lux\flux.exe" [2009-08-29 966656] "KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-10-11 966072] "KiesAirMessage"="c:\program files (x86)\Samsung\Kies\KiesAirMessage.exe" [2012-10-09 580096] "Pando Media Booster"="c:\program files (x86)\Pando Networks\Media Booster\PMB.exe" [2012-11-16 3093624] "GoogleChromeAutoLaunch_C444C2D27A4094264BBB68880A11A0E3"="c:\program files (x86)\Google\Chrome\Application\chrome.exe" [2013-09-02 829392] "HP Officejet Pro 8600 (NET)"="c:\program files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe" [2011-09-09 2676584] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "KeePass 2 PreLoad"="c:\program files (x86)\KeePass Password Safe 2\KeePass.exe" [2012-01-05 1823744] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-03-27 421736] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848] "KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-10-11 309688] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-12-19 642808] "HP Software Update"="c:\program files (x86)\Hp\HP Software Update\HPWuSchd2.exe" [2011-03-24 49208] . c:\users\eule\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ EvernoteClipper.lnk - c:\program files (x86)\Evernote\Evernote\EvernoteClipper.exe [2012-10-26 1017184] Tintenwarnungen überwachen - HP Officejet Pro 8600 (Netzwerk).lnk - c:\windows\system32\RunDll32.exe "c:\program files\HP\HP Officejet Pro 8600\bin\HPStatusBL.dll",RunDLLEntry SERIALNUMBER=CN2CEC4M5D05KD;CONNECTION=NW;MONITOR=1; [2009-7-14 45568] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Display Manager.lnk - c:\program files (x86)\Dell\Dell Display Manager\ddm.exe [2013-7-27 569488] TRENDnet Wireless Utility.lnk - c:\program files (x86)\TRENDnet\Common\RaUI.exe -s [2012-4-28 10934784] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys;c:\windows\SYSNATIVE\Drivers\ssadadb.sys [x] R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys;c:\windows\SYSNATIVE\DRIVERS\dc3d.sys [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys;c:\windows\SYSNATIVE\drivers\dgderdrv.sys [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 RaMediaServer;RaMediaServer;c:\program files (x86)\TRENDnet\Common\RaMediaServer.exe;c:\program files (x86)\TRENDnet\Common\RaMediaServer.exe [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 rzendpt;rzendpt;c:\windows\system32\DRIVERS\rzendpt.sys;c:\windows\SYSNATIVE\DRIVERS\rzendpt.sys [x] R3 rzudd;Razer Mouse Driver;c:\windows\system32\DRIVERS\rzudd.sys;c:\windows\SYSNATIVE\DRIVERS\rzudd.sys [x] R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssadbus.sys [x] R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdfl.sys [x] R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdm.sys [x] R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys;c:\windows\SYSNATIVE\DRIVERS\ssadserd.sys [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x] R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys;c:\windows\SYSNATIVE\drivers\terminpt.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x] S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x] S2 AODDriver4.2;AODDriver4.2;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x] S2 DevoloNetworkService;devolo Network Service;c:\program files (x86)\devolo\dlan\devolonetsvc.exe;c:\program files (x86)\devolo\dlan\devolonetsvc.exe [x] S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [x] S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfpr.sys [x] S2 NPF_devolo;NetGroup Packet Filter Driver (devolo);c:\windows\sysWOW64\drivers\npf_devolo.sys;c:\windows\sysWOW64\drivers\npf_devolo.sys [x] S2 postgresql-8.4;postgresql-8.4 - PostgreSQL Server 8.4;C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N postgresql-8.4 -D C:/Program Files (x86)/PostgreSQL/8.4/data -w;C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N postgresql-8.4 -D C:/Program Files (x86)/PostgreSQL/8.4/data -w [x] S2 RalinkRegistryWriter64;Ralink Registry Writer 64;c:\program files (x86)\TRENDnet\Common\RaRegistry64.exe;c:\program files (x86)\TRENDnet\Common\RaRegistry64.exe [x] S2 TeamViewer8;TeamViewer 8;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x] S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 cmudaxp;ASUS Xonar DS Audio Interface;c:\windows\system32\drivers\cmudaxp.sys;c:\windows\SYSNATIVE\drivers\cmudaxp.sys [x] S3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\DRIVERS\LEqdUsb.Sys;c:\windows\SYSNATIVE\DRIVERS\LEqdUsb.Sys [x] S3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\DRIVERS\LHidEqd.Sys;c:\windows\SYSNATIVE\DRIVERS\LHidEqd.Sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-09-05 21:09 1177552 ----a-w- c:\program files (x86)\Google\Chrome\Application\29.0.1547.66\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2013-09-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-28 15:25] . 2013-09-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-04-28 15:25] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Cmaudio8788"="c:\windows\Syswow64\cmicnfgp.dll" [2011-05-12 8769536] "Cmaudio8788GX"="c:\windows\syswow64\HsMgr.exe" [2008-07-11 200704] "Cmaudio8788GX64"="c:\windows\system\HsMgr64.exe" [2008-07-11 282112] "itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2011-08-10 1873256] "EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-06-23 1744152] "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2012-03-07 4081008] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Add to Evernote 4.0 - c:\program files (x86)\Evernote\Evernote\EvernoteIE.dll/204 IE: Free YouTube Download - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.178.1 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKCU-Run-Rainlendar2 - c:\program files (x86)\Rainlendar2\Rainlendar2.exe Wow6432Node-HKCU-Run-CPN Notifier - c:\program files (x86)\Cake Poker 2.0\PokerNotifier.exe Wow6432Node-HKLM-Run-<NO NAME> - (no file) HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start BHO-{3706EE7C-3CAD-445D-8A43-03EBC3B75908} - c:\program files (x86)\Expat Shield\HssIE\ExpatIE_64.dll . . . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\postgresql-8.4] "ImagePath"="C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"C:/Program Files (x86)/PostgreSQL/8.4/data\" -w" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\postgresql-8.4] "ImagePath"="C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N \"postgresql-8.4\" -D \"C:/Program Files (x86)/PostgreSQL/8.4/data\" -w" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_149_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_5_502_149_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_149_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_5_502_149_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_5_502_149.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG*] "Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d, bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\ "Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d, bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\ "Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d, bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\ "Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d, bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\ "Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d, bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\ "Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d, bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\ "Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d, bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\ "Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d, bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\ "Seed"=hex:49,31,f4,88,04,28,01,14,c5,ca,fa,5f,f5,cf,66,6e,1f,6c,42,48,3b,1d, bb,84,6e,c3,98,a3,07,68,b8,a1,8e,3f,71,ca,a8,53,6d,af,a8,e5,29,51,a3,e5,99,\ . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-09-07 14:48:35 ComboFix-quarantined-files.txt 2013-09-07 12:48 . Vor Suchlauf: 26 Verzeichnis(se), 19.492.818.944 Bytes frei Nach Suchlauf: 32 Verzeichnis(se), 25.630.883.840 Bytes frei . - - End Of File - - B8B7E74E8A982311A3058467AAC0564F |
07.09.2013, 21:10 | #7 |
/// the machine /// TB-Ausbilder | Win32/Adware.AddLyrics.L Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
07.09.2013, 22:19 | #8 |
| Win32/Adware.AddLyrics.LCode:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.09.07.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16660 eule :: EULE-PC [Administrator] 07.09.2013 22:51:08 mbam-log-2013-09-07 (22-51-08).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 251812 Laufzeit: 2 Minute(n), 45 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 2 HKCR\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} (PUP.Optional.BrowseFox.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23} (PUP.Optional.BrowseFox.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 2 C:\Users\eule\Downloads\SciLorsGroovesharkcomDownloader.exe (PUP.Optional.Somoto) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\eule\Downloads\SetupImgBurn_2.5.8.0.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter # AdwCleaner v3.003 - Bericht erstellt am 07/09/2013 um 22:59:44 # Updated 07/09/2013 von Xplode # Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits) # Benutzername : eule - EULE-PC # Gestartet von : C:\Users\eule\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16660 -\\ Google Chrome v29.0.1547.66 [ Datei : C:\Users\eule\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [3813 octets] - [03/09/2013 21:55:57] AdwCleaner[R1].txt - [902 octets] - [07/09/2013 22:59:02] AdwCleaner[S0].txt - [3685 octets] - [03/09/2013 21:57:34] AdwCleaner[S1].txt - [824 octets] - [07/09/2013 22:59:44] ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [883 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.5.8 (09.05.2013:1) OS: Windows 7 Ultimate x64 Ran by eule on 07.09.2013 at 23:02:01,74 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 07.09.2013 at 23:07:44,17 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-09-2013 03 Ran by eule (administrator) on EULE-PC on 07-09-2013 23:18:45 Running from C:\Users\eule\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (AMD) C:\Windows\system32\atieclxx.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\pg_ctl.exe (Ralink Technology, Corp.) C:\Program Files (x86)\TRENDnet\Common\RaRegistry.exe (Ralink Technology, Corp.) C:\Program Files (x86)\TRENDnet\Common\RaRegistry64.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Program Files\Microsoft IntelliType Pro\itype.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe (CMedia) C:\Program Files\ASUS Xonar DS Audio\Customapp\ASUSAUDIOCENTER.EXE (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe () C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe (Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe (EnTech Taiwan) C:\Program Files (x86)\Dell\Dell Display Manager\ddm.exe (TRENDnet) C:\Program Files (x86)\TRENDnet\Common\RaUI.exe (Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Sun Microsystems, Inc.) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (PostgreSQL Global Development Group) C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Cmaudio8788] - C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cmicnfgp.dll,CMICtrlWnd HKLM\...\Run: [Cmaudio8788GX] - C:\Windows\syswow64\HsMgr.exe [200704 2008-07-11] () HKLM\...\Run: [Cmaudio8788GX64] - C:\Windows\system\HsMgr64.exe [282112 2008-07-11] () HKLM\...\Run: [itype] - C:\Program Files\Microsoft IntelliType Pro\itype.exe [1873256 2011-08-10] (Microsoft Corporation) HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [1744152 2011-06-24] (Logitech, Inc.) HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [4081008 2012-03-07] (ESET) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) HKCU\...\Run: [F.lux] - C:\Users\eule\Local Settings\Apps\F.lux\flux.exe [966656 2009-08-29] () HKCU\...\Run: [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe [966072 2012-10-11] (Samsung) HKCU\...\Run: [KiesAirMessage] - C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe [580096 2012-10-09] (Samsung Electronics) HKCU\...\Run: [Pando Media Booster] - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2012-11-16] () HKCU\...\Run: [GoogleChromeAutoLaunch_C444C2D27A4094264BBB68880A11A0E3] - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [829392 2013-09-02] (Google Inc.) HKCU\...\Run: [HP Officejet Pro 8600 (NET)] - C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe [2676584 2011-09-09] (Hewlett-Packard Co.) HKLM-x32\...\Run: [KeePass 2 PreLoad] - C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [1823744 2012-01-05] (Dominik Reichl) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2012-02-20] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [421736 2012-03-27] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.) HKLM-x32\...\Run: [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [309688 2012-10-11] (Samsung Electronics Co., Ltd.) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard) HKLM-x32\...\Run: [] - [x] HKU\Default\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun HKU\Default User\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Dell Display Manager.lnk ShortcutTarget: Dell Display Manager.lnk -> C:\Program Files (x86)\Dell\Dell Display Manager\ddm.exe (EnTech Taiwan) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TRENDnet Wireless Utility.lnk ShortcutTarget: TRENDnet Wireless Utility.lnk -> C:\Program Files (x86)\TRENDnet\Common\RaUI.exe (TRENDnet) Startup: C:\Users\eule\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041) Startup: C:\Users\eule\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet Pro 8600 (Netzwerk).lnk ShortcutTarget: Tintenwarnungen überwachen - HP Officejet Pro 8600 (Netzwerk).lnk -> C:\Program Files\HP\HP Officejet Pro 8600\bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Expat Shield Class - {3706EE7C-3CAD-445D-8A43-03EBC3B75908} - C:\Program Files (x86)\Expat Shield\HssIE\ExpatIE_64.dll No File BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\29.0.1547.66\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Java(TM) Platform SE 7 U7) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Plugin: (QUAKE LIVE) - C:\ProgramData\id Software\QuakeLive\npquakezero.dll (id Software Inc.) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_171.dll () CHR Plugin: (Java Deployment Toolkit 7.0.70.10) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) CHR Extension: (AdBlock) - C:\Users\eule\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.6_1 CHR Extension: (Chrome In-App Payments service) - C:\Users\eule\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_1 ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-12-19] (Advanced Micro Devices, Inc.) R2 DevoloNetworkService; C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [2231616 2010-07-19] () R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [913144 2012-03-07] (ESET) R2 RalinkRegistryWriter; C:\Program Files (x86)\TRENDnet\Common\RaRegistry.exe [374112 2010-11-11] (Ralink Technology, Corp.) R2 RalinkRegistryWriter64; C:\Program Files (x86)\TRENDnet\Common\RaRegistry64.exe [451936 2010-11-11] (Ralink Technology, Corp.) S3 RaMediaServer; C:\Program Files (x86)\TRENDnet\Common\RaMediaServer.exe [619872 2010-12-31] () R2 postgresql-8.4; C:/Program Files (x86)/PostgreSQL/8.4/bin/pg_ctl.exe runservice -N "postgresql-8.4" -D "C:/Program Files (x86)/PostgreSQL/8.4/data" -w [x] ==================== Drivers (Whitelisted) ==================== R2 AODDriver4.2; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [57472 2012-04-09] (Advanced Micro Devices) R3 cmudaxp; C:\Windows\System32\drivers\cmudaxp.sys [2725376 2011-03-10] (C-Media Inc) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [209768 2012-03-14] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [148528 2012-03-14] (ESET) R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [137144 2012-03-14] (ESET) R2 NPF_devolo; C:\Windows\sysWOW64\drivers\npf_devolo.sys [34048 2010-06-10] (CACE Technologies) S3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [22016 2013-03-04] (Razer USA Ltd) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 dgderdrv; System32\drivers\dgderdrv.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-09-07 23:17 - 2013-09-07 23:17 - 00021410 _____ C:\ComboFix.txt 2013-09-07 23:07 - 2013-09-07 23:07 - 00000620 _____ C:\Users\eule\Desktop\JRT.txt 2013-09-07 23:02 - 2013-09-07 23:02 - 00000000 ____D C:\Windows\ERUNT 2013-09-07 23:01 - 2013-09-07 23:01 - 01028823 _____ (Thisisu) C:\Users\eule\Downloads\JRT.exe 2013-09-07 22:58 - 2013-09-07 22:58 - 01037278 _____ C:\Users\eule\Desktop\adwcleaner.exe 2013-09-07 22:49 - 2013-09-07 22:49 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-07 22:49 - 2013-09-07 22:49 - 00000000 ____D C:\Users\eule\AppData\Roaming\Malwarebytes 2013-09-07 22:49 - 2013-09-07 22:49 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-07 22:49 - 2013-09-07 22:49 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-09-07 22:49 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-09-07 22:46 - 2013-09-07 22:46 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\eule\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-07 14:38 - 2013-09-07 23:17 - 00000000 ____D C:\Qoobox 2013-09-07 14:38 - 2013-09-07 14:47 - 00000000 ____D C:\Windows\erdnt 2013-09-07 14:38 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-09-07 14:38 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-09-07 14:38 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-09-07 14:38 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-09-07 14:38 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-09-07 14:38 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-09-07 14:38 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-09-07 14:38 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-09-07 14:37 - 2013-09-07 14:37 - 05120615 ____R (Swearware) C:\Users\eule\Desktop\ComboFix.exe 2013-09-07 14:36 - 2013-09-07 14:37 - 05120615 _____ (Swearware) C:\Users\eule\Downloads\ComboFix.exe 2013-09-06 18:05 - 2013-09-06 18:05 - 00012391 _____ C:\Users\eule\Downloads\log.rar 2013-09-06 18:05 - 2013-09-06 18:05 - 00000000 ____D C:\Users\eule\Downloads\log 2013-09-06 16:37 - 2013-09-06 16:37 - 00000000 ____D C:\FRST 2013-09-06 16:37 - 2013-09-06 16:37 - 00000000 _____ C:\Users\eule\defogger_reenable 2013-09-06 16:34 - 2013-09-06 16:34 - 00377856 _____ C:\Users\eule\Downloads\gxkx2etp.exe 2013-09-06 16:33 - 2013-09-06 16:33 - 00377856 _____ C:\Users\eule\Downloads\npivki83.exe 2013-09-06 16:32 - 2013-09-06 16:32 - 00050477 _____ C:\Users\eule\Downloads\Defogger.exe 2013-09-06 16:11 - 2013-09-06 16:12 - 232747636 _____ C:\Users\eule\Desktop\Diplomarbeit.rar 2013-09-03 21:55 - 2013-09-07 22:59 - 00000000 ____D C:\AdwCleaner 2013-09-03 20:22 - 2013-09-05 20:51 - 00000000 ____D C:\Users\eule\Desktop\SciLor's Grooveshark.com Downloader 2013-09-03 20:22 - 2013-09-03 20:22 - 00000877 _____ C:\Users\eule\Desktop\SciLor's grooveshark(tm).com Downloader.lnk 2013-09-01 17:47 - 2013-09-01 17:48 - 00000000 ____D C:\Users\eule\Desktop\HEM2 2013-08-31 15:06 - 2013-08-31 15:06 - 18101344 _____ (Adobe Systems Inc.) C:\Users\eule\Downloads\AdobeAIRInstaller.exe 2013-08-28 18:08 - 2013-08-29 00:22 - 00000000 ____D C:\Users\eule\AppData\Roaming\HandBrake 2013-08-28 18:07 - 2013-08-28 18:07 - 14298467 _____ C:\Users\eule\Downloads\handbrake-0.9.9-1_x86_64-win_gui.exe 2013-08-28 18:07 - 2013-08-28 18:07 - 00000824 _____ C:\Users\postgres\Desktop\Handbrake.lnk 2013-08-28 18:07 - 2013-08-28 18:07 - 00000000 ____D C:\Users\eule\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Handbrake 2013-08-28 18:07 - 2013-08-28 18:07 - 00000000 ____D C:\Program Files\Handbrake 2013-08-28 17:55 - 2013-08-28 17:55 - 00026744 _____ C:\Users\eule\Downloads\Streaming Harry-Potter-1---Der-Stein-...-2001-.avi - BitShare.com - Free File Hosting and Cloud Storage.avi 2013-08-28 14:23 - 2013-08-28 14:23 - 00000000 ____D C:\Users\eule\AppData\Roaming\ImgBurn 2013-08-28 14:15 - 2013-08-28 14:15 - 00000000 ____D C:\Program Files (x86)\ImgBurn 2013-08-27 11:21 - 2013-08-27 11:21 - 00124219 _____ C:\Users\eule\Desktop\sixmax.xml 2013-08-15 00:38 - 2013-07-26 07:13 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-15 00:38 - 2013-07-26 07:13 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-15 00:38 - 2013-07-26 07:13 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-08-15 00:38 - 2013-07-26 07:12 - 19239424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-15 00:38 - 2013-07-26 07:12 - 15405056 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-15 00:38 - 2013-07-26 07:12 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-15 00:38 - 2013-07-26 07:12 - 02647040 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-15 00:38 - 2013-07-26 07:12 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-15 00:38 - 2013-07-26 07:12 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-15 00:38 - 2013-07-26 07:12 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-15 00:38 - 2013-07-26 07:12 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-08-15 00:38 - 2013-07-26 07:12 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-08-15 00:38 - 2013-07-26 07:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-15 00:38 - 2013-07-26 07:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-08-15 00:38 - 2013-07-26 05:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-15 00:38 - 2013-07-26 05:13 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-15 00:38 - 2013-07-26 05:13 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-15 00:38 - 2013-07-26 05:12 - 14329344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-15 00:38 - 2013-07-26 05:12 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-15 00:38 - 2013-07-26 05:12 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-15 00:38 - 2013-07-26 05:12 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-15 00:38 - 2013-07-26 05:12 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-15 00:38 - 2013-07-26 05:12 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-08-15 00:38 - 2013-07-26 05:12 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-08-15 00:38 - 2013-07-26 05:12 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-08-15 00:38 - 2013-07-26 05:12 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-15 00:38 - 2013-07-26 05:11 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-15 00:38 - 2013-07-26 05:11 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-08-15 00:38 - 2013-07-26 04:49 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-15 00:38 - 2013-07-26 04:39 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-08-15 00:38 - 2013-07-26 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-08-14 14:41 - 2013-07-25 11:25 - 01888768 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-08-14 14:41 - 2013-07-25 10:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-08-14 14:41 - 2013-07-19 03:58 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-08-14 14:41 - 2013-07-19 03:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2013-08-14 14:41 - 2013-07-09 08:03 - 05550528 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-08-14 14:41 - 2013-07-09 07:54 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-08-14 14:41 - 2013-07-09 07:53 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-08-14 14:41 - 2013-07-09 07:52 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2013-08-14 14:41 - 2013-07-09 07:51 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2013-08-14 14:41 - 2013-07-09 07:46 - 01472512 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-08-14 14:41 - 2013-07-09 07:46 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2013-08-14 14:41 - 2013-07-09 07:46 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll 2013-08-14 14:41 - 2013-07-09 07:03 - 03968960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-08-14 14:41 - 2013-07-09 07:03 - 03913664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-08-14 14:41 - 2013-07-09 06:53 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-08-14 14:41 - 2013-07-09 06:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2013-08-14 14:41 - 2013-07-09 06:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2013-08-14 14:41 - 2013-07-09 06:52 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-08-14 14:41 - 2013-07-09 06:46 - 01166848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-08-14 14:41 - 2013-07-09 06:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2013-08-14 14:41 - 2013-07-09 06:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll 2013-08-14 14:41 - 2013-07-09 04:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-08-14 14:41 - 2013-07-09 04:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-08-14 14:41 - 2013-07-09 04:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-08-14 14:41 - 2013-07-09 04:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-08-14 14:41 - 2013-07-06 08:03 - 01910208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-08-14 14:41 - 2013-06-15 06:35 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2013-08-14 14:41 - 2013-06-15 06:32 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2013-08-08 18:25 - 2013-08-08 19:12 - 00000155 _____ C:\Users\eule\Desktop\Kündigen.txt 2013-08-08 16:00 - 2013-08-08 18:40 - 00000000 ____D C:\Users\eule\Desktop\Export Holdemmanger2 DB haende 2013-08-08 13:15 - 2013-08-08 13:15 - 00000000 ____D C:\Users\eule\Desktop\Neuer Ordner 2013-08-08 00:37 - 2013-08-08 00:37 - 11568927 _____ C:\Users\eule\Downloads\4 Tables $10-$20 and $25-$50 6-Max Deep Ante PLO (part 1) - Pot Limit Omaha - Run It Once.mp4 ==================== One Month Modified Files and Folders ======= 2013-09-07 23:18 - 2013-09-07 23:18 - 01948628 _____ (Farbar) C:\Users\eule\Desktop\FRST64.exe 2013-09-07 23:17 - 2013-09-07 23:17 - 00021410 _____ C:\ComboFix.txt 2013-09-07 23:17 - 2013-09-07 14:38 - 00000000 ____D C:\Qoobox 2013-09-07 23:15 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2013-09-07 23:08 - 2012-04-28 17:25 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-09-07 23:07 - 2013-09-07 23:07 - 00000620 _____ C:\Users\eule\Desktop\JRT.txt 2013-09-07 23:07 - 2009-07-14 06:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-09-07 23:07 - 2009-07-14 06:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-09-07 23:06 - 2011-04-12 09:43 - 00696832 _____ C:\Windows\system32\perfh007.dat 2013-09-07 23:06 - 2011-04-12 09:43 - 00148128 _____ C:\Windows\system32\perfc007.dat 2013-09-07 23:06 - 2009-07-14 07:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI 2013-09-07 23:02 - 2013-09-07 23:02 - 00000000 ____D C:\Windows\ERUNT 2013-09-07 23:01 - 2013-09-07 23:01 - 01028823 _____ (Thisisu) C:\Users\eule\Downloads\JRT.exe 2013-09-07 23:00 - 2012-04-28 17:25 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-09-07 23:00 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-09-07 23:00 - 2009-07-14 06:51 - 00241493 _____ C:\Windows\setupact.log 2013-09-07 22:59 - 2013-09-03 21:55 - 00000000 ____D C:\AdwCleaner 2013-09-07 22:59 - 2012-04-28 17:01 - 01197873 _____ C:\Windows\WindowsUpdate.log 2013-09-07 22:58 - 2013-09-07 22:58 - 01037278 _____ C:\Users\eule\Desktop\adwcleaner.exe 2013-09-07 22:55 - 2010-11-21 05:47 - 00016456 _____ C:\Windows\PFRO.log 2013-09-07 22:54 - 2012-04-28 18:26 - 00000000 ____D C:\Users\eule\AppData\Roaming\KeePass 2013-09-07 22:49 - 2013-09-07 22:49 - 00001109 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-09-07 22:49 - 2013-09-07 22:49 - 00000000 ____D C:\Users\eule\AppData\Roaming\Malwarebytes 2013-09-07 22:49 - 2013-09-07 22:49 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-09-07 22:49 - 2013-09-07 22:49 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-09-07 22:46 - 2013-09-07 22:46 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\eule\Downloads\mbam-setup-1.75.0.1300.exe 2013-09-07 22:36 - 2012-04-28 17:49 - 00000000 ____D C:\Users\eule\AppData\Roaming\Skype 2013-09-07 22:13 - 2013-02-09 13:53 - 00000000 ____D C:\Users\eule\Desktop\Diplomarbeit 2013-09-07 18:05 - 2012-12-15 21:19 - 00000000 ____D C:\Users\eule\Documents\Citavi 3 2013-09-07 14:48 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2013-09-07 14:47 - 2013-09-07 14:38 - 00000000 ____D C:\Windows\erdnt 2013-09-07 14:37 - 2013-09-07 14:37 - 05120615 ____R (Swearware) C:\Users\eule\Desktop\ComboFix.exe 2013-09-07 14:37 - 2013-09-07 14:36 - 05120615 _____ (Swearware) C:\Users\eule\Downloads\ComboFix.exe 2013-09-07 11:17 - 2012-04-28 18:03 - 00000000 ____D C:\Program Files (x86)\24hPoker 2013-09-07 10:17 - 2012-04-28 18:10 - 00000000 ____D C:\Users\eule\AppData\Roaming\Microgaming 2013-09-07 00:37 - 2012-04-28 11:46 - 00000000 ____D C:\hm 2013-09-06 18:05 - 2013-09-06 18:05 - 00012391 _____ C:\Users\eule\Downloads\log.rar 2013-09-06 18:05 - 2013-09-06 18:05 - 00000000 ____D C:\Users\eule\Downloads\log 2013-09-06 16:54 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-09-06 16:37 - 2013-09-06 16:37 - 00000000 ____D C:\FRST 2013-09-06 16:37 - 2013-09-06 16:37 - 00000000 _____ C:\Users\eule\defogger_reenable 2013-09-06 16:37 - 2012-04-28 17:01 - 00000000 ____D C:\Users\eule 2013-09-06 16:34 - 2013-09-06 16:34 - 00377856 _____ C:\Users\eule\Downloads\gxkx2etp.exe 2013-09-06 16:33 - 2013-09-06 16:33 - 00377856 _____ C:\Users\eule\Downloads\npivki83.exe 2013-09-06 16:32 - 2013-09-06 16:32 - 00050477 _____ C:\Users\eule\Downloads\Defogger.exe 2013-09-06 16:12 - 2013-09-06 16:11 - 232747636 _____ C:\Users\eule\Desktop\Diplomarbeit.rar 2013-09-06 11:16 - 2012-04-29 11:41 - 00000000 ____D C:\Users\eule\AppData\Roaming\vlc 2013-09-05 20:51 - 2013-09-03 20:22 - 00000000 ____D C:\Users\eule\Desktop\SciLor's Grooveshark.com Downloader 2013-09-05 19:42 - 2013-02-18 17:47 - 00000000 ____D C:\Program Files (x86)\Full Tilt Poker.Eu 2013-09-05 19:39 - 2012-04-28 18:04 - 00000000 ____D C:\Users\eule\AppData\Local\PokerStars.EU 2013-09-05 12:40 - 2012-09-30 01:08 - 00000000 ____D C:\Users\eule\Documents\My Kindle Content 2013-09-03 20:22 - 2013-09-03 20:22 - 00000877 _____ C:\Users\eule\Desktop\SciLor's grooveshark(tm).com Downloader.lnk 2013-09-02 17:11 - 2012-12-15 21:19 - 00000000 ____D C:\Users\eule\AppData\Roaming\Swiss Academic Software 2013-09-02 01:53 - 2012-05-05 16:27 - 00000000 ____D C:\Users\eule\AppData\Roaming\HoldemManager 2013-09-02 00:51 - 2012-04-28 17:19 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-09-02 00:50 - 2012-11-16 21:14 - 00000000 ____D C:\ProgramData\PMB Files 2013-09-01 17:48 - 2013-09-01 17:47 - 00000000 ____D C:\Users\eule\Desktop\HEM2 2013-09-01 14:34 - 2012-04-29 02:03 - 00000000 ____D C:\Users\eule\AppData\Roaming\HEM Data 2013-09-01 11:58 - 2013-01-07 11:00 - 00016655 _____ C:\speederr.txt 2013-09-01 11:44 - 2012-04-29 19:14 - 00319317 _____ C:\blitzerr.txt 2013-09-01 11:43 - 2013-02-18 17:48 - 00000000 ____D C:\Users\eule\AppData\Local\FullTiltPoker.eu 2013-09-01 10:30 - 2012-11-09 10:18 - 00000000 ____D C:\Program Files (x86)\TableNinjaFT 2013-09-01 10:29 - 2012-04-29 00:55 - 00000000 ____D C:\Program Files (x86)\TableNinja 2013-08-31 15:06 - 2013-08-31 15:06 - 18101344 _____ (Adobe Systems Inc.) C:\Users\eule\Downloads\AdobeAIRInstaller.exe 2013-08-29 00:22 - 2013-08-28 18:08 - 00000000 ____D C:\Users\eule\AppData\Roaming\HandBrake 2013-08-28 18:07 - 2013-08-28 18:07 - 14298467 _____ C:\Users\eule\Downloads\handbrake-0.9.9-1_x86_64-win_gui.exe 2013-08-28 18:07 - 2013-08-28 18:07 - 00000824 _____ C:\Users\postgres\Desktop\Handbrake.lnk 2013-08-28 18:07 - 2013-08-28 18:07 - 00000000 ____D C:\Users\eule\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Handbrake 2013-08-28 18:07 - 2013-08-28 18:07 - 00000000 ____D C:\Program Files\Handbrake 2013-08-28 17:55 - 2013-08-28 17:55 - 00026744 _____ C:\Users\eule\Downloads\Streaming Harry-Potter-1---Der-Stein-...-2001-.avi - BitShare.com - Free File Hosting and Cloud Storage.avi 2013-08-28 14:23 - 2013-08-28 14:23 - 00000000 ____D C:\Users\eule\AppData\Roaming\ImgBurn 2013-08-28 14:15 - 2013-08-28 14:15 - 00000000 ____D C:\Program Files (x86)\ImgBurn 2013-08-27 11:21 - 2013-08-27 11:21 - 00124219 _____ C:\Users\eule\Desktop\sixmax.xml 2013-08-26 14:05 - 2012-04-28 18:02 - 00000000 ____D C:\Users\eule\Documents\888poker 2013-08-15 18:38 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-08-15 00:33 - 2012-05-03 07:08 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-08-14 18:53 - 2013-01-15 14:25 - 00000000 ____D C:\Users\eule\AppData\Local\Windows Live 2013-08-10 20:39 - 2012-07-24 22:19 - 00517205 _____ C:\Users\eule\pokerclient-redbet.log 2013-08-08 19:12 - 2013-08-08 18:25 - 00000155 _____ C:\Users\eule\Desktop\Kündigen.txt 2013-08-08 18:40 - 2013-08-08 16:00 - 00000000 ____D C:\Users\eule\Desktop\Export Holdemmanger2 DB haende 2013-08-08 13:15 - 2013-08-08 13:15 - 00000000 ____D C:\Users\eule\Desktop\Neuer Ordner 2013-08-08 00:55 - 2013-08-07 20:43 - 00000000 ____D C:\Users\eule\Desktop\HEM2 fullbackup 2012+13 2013-08-08 00:37 - 2013-08-08 00:37 - 11568927 _____ C:\Users\eule\Downloads\4 Tables $10-$20 and $25-$50 6-Max Deep Ante PLO (part 1) - Pot Limit Omaha - Run It Once.mp4 ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-09-01 00:44 ==================== End Of Log ============================ --- --- --- |
09.09.2013, 05:16 | #9 |
/// the machine /// TB-Ausbilder | Win32/Adware.AddLyrics.LESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.09.2013, 12:03 | #10 |
| Win32/Adware.AddLyrics.LCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=6b873b005a8d8546b4753fa316d59982 # engine=15058 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-09-09 10:52:36 # local_time=2013-09-09 12:52:36 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=771 16777214 16 1 24872691 24872691 0 0 # compatibility_mode=5893 16776573 100 94 53497 130353806 0 0 # compatibility_mode=8204 16776701 100 73 6447 47596346 0 0 # scanned=427746 # found=0 # cleaned=0 # scan_time=6141 # nod_component=V3 Build:0x30000000 Code:
ATTFilter Results of screen317's Security Check version 0.99.72 Windows 7 Service Pack 1 x64 (UAC is disabled!) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` ESET NOD32 Antivirus 5.2 Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Java(TM) 6 Update 31 Java 7 Update 7 Java version out of Date! Adobe Flash Player 11.6.602.171 Adobe Reader 10.1.6 Adobe Reader out of Date! Google Chrome 29.0.1547.62 Google Chrome 29.0.1547.66 ````````Process Check: objlist.exe by Laurent```````` ESET NOD32 Antivirus egui.exe ESET NOD32 Antivirus ekrn.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` vielen, vielen dank hat mri rechner Neuaufsetzen erspart, was normalerweise ne kuerzere prozdur gewesen waere aber schreibe gerade am rechner meine diplomarbeit udn haette auch datenbanken back uppen muessen usw THX! sehe gerade: werde mal java und reader updaten |
09.09.2013, 17:14 | #11 |
/// the machine /// TB-Ausbilder | Win32/Adware.AddLyrics.L genau, mach da die updates. Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Win32/Adware.AddLyrics.L |
.com, 100%, addlyrics, anwendung, chip.de, datei, erweiterung, gmer, installation, link, neustart, passwort, pup.optional.browsefox.a, pup.optional.opencandy, pup.optional.somoto, rechner, start, virenscanner, warnung, warum, win, win32/adware.addlyrics.l, win32/speedingupmypc.b |