|
Log-Analyse und Auswertung: win 7 64 avast meldet bösartige URLSWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
10.12.2013, 21:46 | #1 |
| win 7 64 avast meldet bösartige URLS Moin Moin, Ich hab mal wieder ein Problem Vorab: Ich habe nicht oder nicht bewusst Programme installiert. Trotzdem bekomme ich alle 2-3 Minuten eine Warnung mit dem Hinweis das die bösartige http //cybeitrapp.info/get/ gesperrt wurde.. Dies auch wenn ich nur in Ruhe etwas lese und keinen "KLick" ausführe. Scheinbar arbeitet da was im Hintergrund? addition Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-12-2013 Ran by chris at 2013-12-10 21:03:50 Running from C:\Users\chris\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C} AS: avast! Antivirus (Enabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Update for Microsoft Office 2007 (KB2508958) (x32) 7-Zip 9.20 (x64 edition) (Version: 9.20.00.0) Adobe AIR (x32 Version: 3.8.0.870) Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.94) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117) Adobe Reader X (10.1.8) MUI (x32 Version: 10.1.8) Adobe SVG Viewer 3.0 (x32 Version: 3.0) AGEIA PhysX v7.09.13 (x32 Version: 7.09.13) AMI VR-pulse OS Switcher (Version: 1.1) aOUTo Version 1.20 (x32 Version: 1.20) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 1.0.0.39) avast! Free Antivirus (x32 Version: 8.0.1489.0) congstar Internet-Manager (x32 Version: 1.0.0.3) Corel Graphics - Windows Shell Extension (x32 Version: 15.1.0.588) Corel Graphics - Windows Shell Extension (x32 Version: 15.1.588) CorelDRAW Essentials X5 - Common (x32 Version: 15.0) CorelDRAW Essentials X5 - Connect (x32 Version: 15.0) CorelDRAW Essentials X5 - Custom Data (x32 Version: 15.0) CorelDRAW Essentials X5 - DE (x32 Version: 15.0) CorelDRAW Essentials X5 - Draw (x32 Version: 15.0) CorelDRAW Essentials X5 - EN (x32 Version: 15.0) CorelDRAW Essentials X5 - ES (x32 Version: 15.0) CorelDRAW Essentials X5 - Extra Content (x32 Version: 15.0) CorelDRAW Essentials X5 - Extra Content (x32) CorelDRAW Essentials X5 - Filters (x32 Version: 15.0) CorelDRAW Essentials X5 - FR (x32 Version: 15.0) CorelDRAW Essentials X5 - IPM (x32 Version: 15.0) CorelDRAW Essentials X5 - IT (x32 Version: 15.0) CorelDRAW Essentials X5 - PHOTO-PAINT (x32 Version: 15.0) CorelDRAW Essentials X5 - Redist (x32 Version: 15.0) CorelDRAW Essentials X5 - Setup Files (x32 Version: 15.0) CorelDRAW Essentials X5 - WT (x32 Version: 15.0) CorelDRAW Essentials X5 (x32 Version: 15.0) CorelDRAW Essentials X5 (x32 Version: 15.1.0.588) CorelDRAW Graphics Suite X5 - Windows Shell Extension 64 Bit (Version: 15.1.588) CyberLink LabelPrint (x32 Version: 2.5.3624) CyberLink MediaEspresso (x32 Version: 6.5.1508_36229) CyberLink MediaShow (x32 Version: 5.1.2414) CyberLink PhotoNow (x32 Version: 1.1.0.6904) CyberLink Power2Go (x32 Version: 6.1.4813) CyberLink PowerDirector (x32 Version: 8.0.3224a) CyberLink PowerDVD 10 (x32 Version: 10.0.2225.02) CyberLink PowerDVD Copy (x32 Version: 1.5.1306) CyberLink YouCam (x32 Version: 3.1.3428) D3DX10 (x32 Version: 15.4.2368.0902) DAEMON Tools Lite (x32 Version: 4.45.4.0314) DC Universe Online Live (HKCU) DivX-Setup (x32 Version: 2.6.1.84) Dropbox (HKCU Version: 2.2.9) Fotogalerie (x32 Version: 16.4.3505.0912) Fotogalleriet (x32 Version: 16.4.3505.0912) Free Disc Burner version 3.0.18.430 (x32 Version: 3.0.18.430) Free MP4 Video Converter version 5.0.29.925 (x32 Version: 5.0.29.925) Free YouTube Download version 3.2.13.925 (x32 Version: 3.2.13.925) Galerie de photos (x32 Version: 16.4.3505.0912) Google Chrome (x32 Version: 31.0.1650.63) Google Drive (x32 Version: 1.12.5329.1887) Google Earth Plug-in (x32 Version: 7.1.1.1888) Google Update Helper (x32 Version: 1.3.22.3) GPS Tracker (x32 Version: 1.0.0) Intel PROSet Wireless Intel(R) Processor Graphics (x32 Version: 9.17.10.2867) Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (Version: 1.0.0.0135) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: 1.0.2.0518) Intel(R) PROSet/Wireless WiFi Software (Version: 14.0.3000) Intel(R) Rapid Storage Technology (x32 Version: 10.1.0.1008) Intel(R) Wireless Display (x32 Version: 2.0.30.0) Java 7 Update 45 (x32 Version: 7.0.450) Java Auto Updater (x32 Version: 2.1.9.8) JDownloader 0.9 (x32 Version: 0.9) Junk Mail filter update (x32 Version: 16.4.3505.0912) Launch Manager (x32 Version: 1.5.1.3) Lexware Info Service (x32 Version: 2.70.00.0081) Lexware zeitmanagement 2011 (x32 Version: 2.05.00.0169) Medion Home Cinema (x32 Version: 8.0.2608) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office 2007 Service Pack 3 (SP3) (x32) Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003) Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000) Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32) Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft SkyDrive (HKCU Version: 16.4.6013.0910) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Movie Maker (x32 Version: 16.4.3505.0912) Mozilla Firefox 25.0.1 (x86 de) (x32 Version: 25.0.1) Mozilla Maintenance Service (x32 Version: 25.0.1) MP4 To MP3 Converter V3.0 (x32) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT_amd64 (x32 Version: 15.4.2862.0708) MSVCRT110 (x32 Version: 16.4.1108.0727) MSVCRT110_amd64 (Version: 16.4.1109.0912) MyFreeCodec (HKCU) NAVIGON Fresh 3.4.1 (x32 Version: 3.4.1) Notepad++ (x32 Version: 6.4.5) Photo Common (x32 Version: 16.4.3505.0912) Photo Gallery (x32 Version: 16.4.3505.0912) PL-2303 Vista Driver Installer (x32 Version: 3.2.0.0) PlayReady PC Runtime amd64 (Version: 1.3.0) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6321) Realtek USB 2.0 Reader Driver (x32 Version: 6.1.7600.10003) Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.34.0) Samsung Kies (x32 Version: 2.6.0.13091_9) SAMSUNG USB Driver for Mobile Phones (Version: 1.5.27.0) Search Assistant WebSearch 1.74 (x32) <==== ATTENTION Serious Sam HD: Gold Edition (x32 Version: 1.0) T4E.Live Player 1.1.4 (x32 Version: 1.1.4) TECDOC CD (x32 Version: 2.2011) TECDOC CD 2.2011 (x32 Version: 2.2011) TomTom HOME (x32 Version: 2.9.1) TomTom HOME Visual Studio Merge Modules (x32 Version: 1.0.2) Unreal Tournament 3 (HKCU Version: 1.00.0000) Unreal Tournament 3 (x32 Version: 1.00.0000) Update for 2007 Microsoft Office System (KB967642) (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2825642) 32-Bit Edition (x32) Update für Microsoft Office Excel 2007 Help (KB963678) (x32) Update für Microsoft Office Outlook 2007 Help (KB963677) (x32) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32) Update für Microsoft Office Word 2007 Help (KB963665) (x32) UseNeXT by Tangysoft (x32) Valokuvavalikoima (x32 Version: 16.4.3505.0912) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0) VCDS AIB 11.11 (x32 Version: AIB 11.11) VCDS DRV 11.11 (x32 Version: DRV 11.11) Vehicle Explorer (x32 Version: 1.0.1) VLC media player 2.1.1 (x32 Version: 2.1.1) VR-pulse Installer (Version: 1.2.0) Winamp (x32 Version: 5.66 ) Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1) windata SOHO (x32 Version: 08.08.0000) Windows Live (x32 Version: 16.4.3505.0912) Windows Live Communications Platform (x32 Version: 16.4.3505.0912) Windows Live Essentials (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 16.4.3505.0912) Windows Live Fotogalleri (x32 Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4311.0) Windows Live Installer (x32 Version: 16.4.3505.0912) Windows Live Mail (x32 Version: 15.4.3502.0922) Windows Live Mail (x32 Version: 16.4.3505.0912) Windows Live Messenger (x32 Version: 15.4.3502.0922) Windows Live Messenger (x32 Version: 16.4.3505.0912) Windows Live MIME IFilter (Version: 16.4.3505.0912) Windows Live Movie Maker (x32 Version: 15.4.3502.0922) Windows Live Photo Common (x32 Version: 15.4.3502.0922) Windows Live Photo Common (x32 Version: 16.4.3505.0912) Windows Live PIMT Platform (x32 Version: 16.4.3505.0912) Windows Live SOXE (x32 Version: 16.4.3505.0912) Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912) Windows Live UX Platform (x32 Version: 16.4.3505.0912) Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109) Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912) Windows Live Writer (x32 Version: 15.4.3502.0922) Windows Live Writer (x32 Version: 16.4.3505.0912) Windows Live Writer Resources (x32 Version: 15.4.3502.0922) Windows Live Writer Resources (x32 Version: 16.4.3505.0912) Windows Liven peruspaketti (x32 Version: 16.4.3505.0912) Windows Liven sähköposti (x32 Version: 16.4.3505.0912) Windows Media Encoder 9 Series (x32 Version: 9.00.2980) Windows Media Encoder 9 Series (x32) Windows Mobile-Gerätecenter (Version: 6.1.6965.0) Windows-Treiberpaket - Auto-Intern USB-Treiber (03/30/2010 2.06.02) (Version: 03/30/2010 2.06.02) Windows-Treiberpaket - Auto-Intern Virtueller COM-Port-Treiber (03/30/2010 2.06.02) (Version: 03/30/2010 2.06.02) Windows-Treiberpaket - Ross-Tech USB Driver Package (06/16/2010 2.06.02) (Version: 06/16/2010 2.06.02) WinRAR 5.00 beta 8 (64-bit) (Version: 5.00.8) Wuala (HKCU Version: 1.0.428.0) Wuala CBFS (x32 Version: 3.2.107.0) Wuala OverlayIcons (x32 Version: 1.0.0.2) X10 Hardware(TM) (x32) XolidoSign V 2.2.0.1 (Version: 2.2.0.1) ==================== Restore Points ========================= 10-11-2013 11:07:42 Geplanter Prüfpunkt 16-11-2013 05:51:02 Windows Update 08-12-2013 08:10:34 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {3DF5CCB0-3923-4FD5-B7AF-19D879121BE2} - System32\Tasks\Divx-Online-Aktualisierungsprogramm => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [2013-08-29] () Task: {6ECFDD35-7FD8-4D76-88C9-F3A08CFE92FF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-29] (Adobe Systems Incorporated) Task: {814DC857-75D9-4C75-B954-0B3ED0DD55D9} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated) Task: {8857137B-4BA7-406A-8B1D-919D7F330A73} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-03-05] (Google Inc.) Task: {DA48C88B-85DF-4BC5-9E48-4361611BE793} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-05-09] (AVAST Software) Task: {F8631F1A-A7FF-43E5-A4C8-FBF642B68D58} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-03-05] (Google Inc.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-02-04 23:42 - 2011-02-04 23:42 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll 2011-02-04 12:38 - 2011-01-27 08:11 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2013-12-10 16:18 - 2013-12-10 13:19 - 02244096 _____ () C:\Program Files\AVAST Software\Avast\defs\13121000\algo.dll 2013-08-20 15:52 - 2011-05-06 04:03 - 00594944 _____ () C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-1.dll 2013-08-20 15:52 - 2011-11-07 09:39 - 00099328 _____ () C:\Program Files (x86)\congstar\Internet-Manager\Bin\itapi.dll 2013-08-20 15:52 - 2011-11-07 09:38 - 00027136 _____ () C:\Program Files (x86)\congstar\Internet-Manager\Bin\log.dll 2013-08-20 15:52 - 2010-10-14 10:37 - 00971776 _____ () C:\Program Files (x86)\congstar\Internet-Manager\Bin\libxml2.dll 2013-08-20 15:52 - 2010-10-14 10:37 - 00080688 _____ () C:\Program Files (x86)\congstar\Internet-Manager\Bin\zlib1.dll 2013-08-20 15:52 - 2011-11-07 09:38 - 00055296 _____ () C:\Program Files (x86)\congstar\Internet-Manager\Bin\coder.dll 2013-08-20 15:52 - 2011-11-07 09:39 - 00043008 _____ () C:\Program Files (x86)\congstar\Internet-Manager\Bin\audio.dll 2013-08-20 15:52 - 2011-11-07 09:38 - 00035840 _____ () C:\Program Files (x86)\congstar\Internet-Manager\Bin\libConfig.dll 2013-08-20 15:52 - 2011-11-07 09:43 - 00020992 _____ () C:\Program Files (x86)\congstar\Internet-Manager\Bin\libctlsvr.dll 2013-11-16 07:23 - 2013-11-16 07:23 - 00165376 _____ () C:\Users\chris\AppData\Local\Wuala\Program0\lib.447\orangevolt-4n-1.1.2.dll 2013-11-16 07:24 - 2013-11-16 07:24 - 00370688 _____ () C:\Users\chris\AppData\Local\Wuala\Program0\lib.447\jcbfs3.dll 2013-08-20 15:52 - 2007-09-09 16:07 - 00151552 _____ () C:\Program Files (x86)\congstar\Internet-Manager\Bin\libexpat.dll 2013-08-20 15:52 - 2011-05-06 04:02 - 00341504 _____ () C:\Program Files (x86)\congstar\Internet-Manager\Bin\sqlite3.dll 2013-01-24 12:25 - 2013-01-24 12:25 - 01044480 _____ () C:\Program Files (x86)\WebSearch\sprotector.dll 2013-11-16 07:06 - 2013-11-16 07:06 - 03363952 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2013-08-17 18:46 - 2013-08-17 18:46 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\eb4812681f6ab4406053f3a1803e6da0\IsdiInterop.ni.dll 2011-03-13 01:02 - 2010-11-06 08:50 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (12/10/2013 08:53:23 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/08/2013 08:25:57 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/06/2013 05:53:38 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/04/2013 04:56:29 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/02/2013 07:00:29 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2" in Zeile C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Error: (12/02/2013 07:00:29 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2" in Zeile C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Error: (12/01/2013 07:29:23 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: tof.exe, Version: 1.0.0.1, Zeitstempel: 0x46b148c6 Name des fehlerhaften Moduls: AcroPDF.dll_unloaded, Version: 0.0.0.0, Zeitstempel: 0x5225e230 Ausnahmecode: 0xc0000005 Fehleroffset: 0x72ed9769 ID des fehlerhaften Prozesses: 0x1a30 Startzeit der fehlerhaften Anwendung: 0xtof.exe0 Pfad der fehlerhaften Anwendung: tof.exe1 Pfad des fehlerhaften Moduls: tof.exe2 Berichtskennung: tof.exe3 Error: (11/26/2013 10:26:52 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/23/2013 07:40:39 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Haufe.TimeManagement.exe, Version: 2.5.0.117, Zeitstempel: 0x4f9111e8 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18229, Zeitstempel: 0x51fb1116 Ausnahmecode: 0xe0434352 Fehleroffset: 0x0000c41f ID des fehlerhaften Prozesses: 0x1028 Startzeit der fehlerhaften Anwendung: 0xHaufe.TimeManagement.exe0 Pfad der fehlerhaften Anwendung: Haufe.TimeManagement.exe1 Pfad des fehlerhaften Moduls: Haufe.TimeManagement.exe2 Berichtskennung: Haufe.TimeManagement.exe3 Error: (11/23/2013 07:40:38 PM) (Source: .NET Runtime) (User: ) Description: Application: Haufe.TimeManagement.exe Framework Version: v4.0.30319 Description: The process was terminated due to an unhandled exception. Exception Info: System.ComponentModel.Win32Exception Stack: at Microsoft.VisualBasic.ApplicationServices.WindowsFormsApplicationBase.DoApplicationModel() at Microsoft.VisualBasic.ApplicationServices.WindowsFormsApplicationBase.Run(System.String[]) at Haufe.TimeManagement.SingleInstanceManager.Main(System.String[]) System errors: ============= Error: (12/08/2013 08:24:52 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Intel(R) Rapid Storage Technology" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/08/2013 08:24:52 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Intel(R) Rapid Storage Technology erreicht. Error: (12/08/2013 08:20:40 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 08.12.2013 um 20:01:14 unerwartet heruntergefahren. Error: (12/08/2013 00:50:31 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Internet Explorer 11 für Windows 7 für x64-basierte Systeme Error: (12/08/2013 00:50:14 PM) (Source: DCOM) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (12/08/2013 00:50:08 PM) (Source: DCOM) (User: ) Description: {FE9617F6-E606-42AA-BECC-0E9CDA246D63} Error: (12/01/2013 04:53:06 PM) (Source: bowser) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "VICKY-VAIO", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{B630595A-1F98-41CA-B659-BC7CD3604FEA}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (11/16/2013 00:00:31 PM) (Source: VDS Basic Provider) (User: ) Description: Unerwarteter Fehler. Fehlercode: 490@01010004 Error: (11/16/2013 11:59:28 AM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR3. Error: (11/16/2013 11:59:28 AM) (Source: Disk) (User: ) Description: Fehlerhafter Block bei Gerät \Device\Harddisk1\DR3. Microsoft Office Sessions: ========================= Error: (09/22/2013 08:08:29 AM) (Source: Microsoft Office 12 Sessions)(User: ) Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6679.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 540 seconds with 120 seconds of active time. This session ended with a crash. ==================== Memory info =========================== Percentage of memory in use: 46% Total physical RAM: 4003 MB Available physical RAM: 2126.79 MB Total Pagefile: 8004.19 MB Available Pagefile: 6111.84 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: (Boot) (Fixed) (Total:657.54 GB) (Free:432.52 GB) NTFS Drive d: (Recover) (Fixed) (Total:38 GB) (Free:11.54 GB) NTFS Drive w: (Wuala) (Network) (Total:7 GB) (Free:4.99 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 699 GB) (Disk ID: D3AF660C) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=658 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=40 GB) - (Type=OF Extended) Partition 4: (Not Active) - (Size=1 GB) - (Type=12) ==================== End Of Log ============================ und FRST Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-12-2013 Ran by chris (administrator) on MEDION-CHRIS on 10-12-2013 21:00:40 Running from C:\Users\chris\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (Transaction Software, D 81829 Munich) C:\TECDOC_CD\2_2011\db\tbmux32.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (X10) C:\Program Files (x86)\Common Files\X10\Common\X10nets.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (ZTE) C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (LaCie) C:\Users\chris\AppData\Roaming\Wuala\Wuala.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Wistron Corp.) C:\Program Files (x86)\Launch Manager\OSD.exe (Wistron) C:\Program Files (x86)\Launch Manager\HotkeyApp.exe (Wistron Corp.) C:\Program Files (x86)\Launch Manager\WButton.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Wistron Corp.) C:\Program Files (x86)\Launch Manager\WisLMSvc.exe () C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe () C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [IntelWireless] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1933584 2011-02-05] (Intel(R) Corporation) HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [660360 2007-05-31] (Microsoft Corporation) HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] () HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2294568 2011-03-24] (Synaptics Incorporated) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) MountPoints2: {85f26fa3-0664-11e3-911f-00262dc5dc6c} - G:\windows\Data\setup.exe HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [LMgrVolOSD] - C:\Program Files (x86)\Launch Manager\OSD.exe [348960 2009-12-11] (Wistron Corp.) HKLM-x32\...\Run: [HotkeyApp] - C:\Program Files (x86)\Launch Manager\HotkeyApp.exe [207400 2010-12-15] (Wistron) HKLM-x32\...\Run: [Wbutton] - C:\Program Files (x86)\Launch Manager\WButton.exe [436264 2010-06-21] (Wistron Corp.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKU\Default\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs HKU\Default User\...\RunOnce: [Screensaver] - C:\Windows\Web\Wallpaper\MEDION\start.vbs AppInit_DLLs-x32: c:\progra~2\websea~1\sprote~1.dll [1044480 2013-01-24] () Startup: C:\Users\chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Wuala.lnk ShortcutTarget: Wuala.lnk -> C:\Users\chris\AppData\Roaming\Wuala\Wuala.exe (LaCie) SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\system32\CbFsMntNtf3.dll (EldoS Corporation) SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://websearch.simplesearches.info/?pid=924&r=2013/08/18&hid=1073822747&lg=EN&cc=DE&unqvl=31 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.aldi.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://websearch.simplesearches.info/?pid=924&r=2013/08/18&hid=1073822747&lg=EN&cc=DE&unqvl=31 SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.simplesearches.info/?l=1&q={searchTerms}&pid=924&r=2013/08/18&hid=1073822747&lg=EN&cc=DE&unqvl=31 SearchScopes: HKCU - {483830EE-A4CD-4b71-B0A3-3D82E62A6909} URL = SearchScopes: HKCU - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.simplesearches.info/?l=1&q={searchTerms}&pid=924&r=2013/08/18&hid=1073822747&lg=EN&cc=DE&unqvl=31 BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File BHO: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File DPF: HKLM {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\chris\AppData\Roaming\Mozilla\Firefox\Profiles\66wn2myf.default FF user.js: detected! => C:\Users\chris\AppData\Roaming\Mozilla\Firefox\Profiles\66wn2myf.default\user.js FF Homepage: hxxp://websearch.simplesearches.info/?pid=924&r=2013/08/18&hid=1073822747&lg=EN&cc=DE&unqvl=31 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nullsoft.com/winampDetector;version=1 - C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\chris\AppData\Roaming\Mozilla\Firefox\Profiles\66wn2myf.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\chris\AppData\Roaming\Mozilla\Firefox\Profiles\66wn2myf.default\searchplugins\delta.xml FF SearchPlugin: C:\Users\chris\AppData\Roaming\Mozilla\Firefox\Profiles\66wn2myf.default\searchplugins\WebSearch.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Wörterbuch Deutsch (de-DE), Hunspell-unterstützt - C:\Users\chris\AppData\Roaming\Mozilla\Firefox\Profiles\66wn2myf.default\Extensions\de_DE@dicts.j3e.de FF Extension: translator - C:\Users\chris\AppData\Roaming\Mozilla\Firefox\Profiles\66wn2myf.default\Extensions\translator@zoli.bod.xpi FF Extension: speeddial - C:\Users\chris\AppData\Roaming\Mozilla\Firefox\Profiles\66wn2myf.default\Extensions\{64161300-e22b-11db-8314-0800200c9a66}.xpi FF Extension: No Name - C:\Users\chris\AppData\Roaming\Mozilla\Firefox\Profiles\66wn2myf.default\Extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}.xpi FF Extension: Adblock Plus - C:\Users\chris\AppData\Roaming\Mozilla\Firefox\Profiles\66wn2myf.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: dta - C:\Users\chris\AppData\Roaming\Mozilla\Firefox\Profiles\66wn2myf.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\virtualKeyboard@kaspersky.ru FF HKLM-x32\...\Firefox\Extensions: [KavAntiBanner@Kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\KavAntiBanner@kaspersky.ru FF HKLM-x32\...\Firefox\Extensions: [linkfilter@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\linkfilter@kaspersky.ru FF HKLM-x32\...\Firefox\Extensions: [{ACAA314B-EEBA-48e4-AD47-84E31C44796C}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\ FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files (x86)\congstar\Internet-Manager\Bin\addon FF Extension: Bytemobile Optimization Client - C:\Program Files (x86)\congstar\Internet-Manager\Bin\addon Chrome: ======= CHR HomePage: hxxp://websearch.simplesearches.info/?pid=924&r=2013/08/18&hid=1073822747&lg=EN&cc=DE&unqvl=31 CHR RestoreOnStartup: "hxxp://websearch.simplesearches.info/?pid=924&r=2013/08/18&hid=1073822747&lg=EN&cc=DE&unqvl=31" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.57\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) CHR Plugin: (DivX Plus Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll No File CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll No File CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\Windows\SysWOW64\npDeployJava1.dll No File CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File CHR Extension: (Google Drive) - C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (DVDVideoSoft) - C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.3.0.0_0 CHR Extension: (Chrome In-App Payments service) - C:\Users\chris\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0 ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-02-05] () R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-12-14] () R2 Transbase TECDOC CD 2_2011 Service; C:\TECDOC_CD\2_2011\db\tbmux32.exe [356352 2010-10-25] (Transaction Software, D 81829 Munich) R3 WisLMSvc; C:\Program Files (x86)\Launch Manager\WisLMSvc.exe [118560 2009-10-23] (Wistron Corp.) R2 x10nets; C:\Program Files (x86)\Common Files\X10\Common\X10nets.exe [20480 2009-11-07] (X10) ==================== Drivers (Whitelisted) ==================== S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [32768 2010-04-29] (Google Inc) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-07-04] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-07-04] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-07-04] () R0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2009-12-15] (Bytemobile, Inc.) R1 cbfs3; C:\Windows\system32\drivers\cbfs3.sys [352144 2012-04-09] (EldoS Corporation) S3 FTDIBUS; C:\Windows\System32\drivers\ai-usb.sys [69808 2011-12-23] (FTDI Ltd.) S3 HSPADataCardusbmdm; C:\Windows\System32\DRIVERS\HSPADataCardusbmdm.sys [122752 2011-08-19] (HSPADataCard Incorporated) S3 HSPADataCardusbnmea; C:\Windows\System32\DRIVERS\HSPADataCardusbnmea.sys [122752 2011-08-19] (HSPADataCard Incorporated) S3 HSPADataCardusbser; C:\Windows\System32\DRIVERS\HSPADataCardusbser.sys [122752 2011-08-19] (HSPADataCard Incorporated) S3 mod7764; C:\Windows\System32\DRIVERS\mod77-64.sys [1077416 2010-09-16] (DiBcom SA) R1 tcpipBM; C:\Windows\system32\drivers\tcpipBM.sys [39552 2009-12-15] (Bytemobile, Inc.) R3 X10Hid; C:\Windows\System32\Drivers\x10hid.sys [15896 2009-05-13] (X10 Wireless Technology, Inc.) S3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [32792 2009-05-13] (X10 Wireless Technology, Inc.) S4 sptd; \SystemRoot\\SystemRoot\System32\Drivers\sptd.sys [x] U5 SynTP; C:\Windows\System32\Drivers\SynTP.sys [1392688 2011-03-24] (Synaptics Incorporated) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-10 21:00 - 2013-12-10 21:01 - 00019324 _____ C:\Users\chris\Downloads\FRST.txt 2013-12-10 21:00 - 2013-12-10 21:00 - 00000000 ____D C:\FRST 2013-12-10 20:59 - 2013-12-10 20:59 - 01928110 _____ (Farbar) C:\Users\chris\Downloads\FRST64.exe 2013-12-10 20:50 - 2013-12-10 20:51 - 00000424 _____ C:\Users\chris\Desktop\Neues Textdokument.txt 2013-12-10 20:49 - 2013-12-10 20:49 - 00050477 _____ C:\Users\chris\Downloads\Defogger.exe 2013-12-10 20:49 - 2013-12-10 20:49 - 00000582 _____ C:\Users\chris\Downloads\defogger_disable.log 2013-12-10 20:49 - 2013-12-10 20:49 - 00000020 _____ C:\Users\chris\defogger_reenable 2013-12-08 12:53 - 2013-12-08 12:53 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-08 12:53 - 2013-12-08 12:53 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-08 12:53 - 2013-12-08 12:53 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-08 12:53 - 2013-12-08 12:53 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-08 12:53 - 2013-12-08 12:53 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-08 12:53 - 2013-12-08 12:53 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-08 12:53 - 2013-12-08 12:53 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-08 12:53 - 2013-12-08 12:53 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-08 12:53 - 2013-12-08 12:53 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-08 12:53 - 2013-12-08 12:53 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-08 12:53 - 2013-12-08 12:53 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-08 09:13 - 2013-12-08 12:50 - 00007110 _____ C:\Windows\IE11_main.log 2013-12-06 04:37 - 2013-12-06 04:38 - 00000000 ____D C:\Users\chris\Downloads\Waiöiölmaaa470uoe 2013-12-06 04:36 - 2013-12-06 04:36 - 08469062 _____ C:\Users\chris\Downloads\Waiöiölmaaa470uoe.rar 2013-12-05 07:45 - 2013-12-05 07:45 - 01071224 _____ (Solid State Networks) C:\Users\chris\Downloads\install_flashplayer11x32au_mssd_aaa_aih(1).exe 2013-12-01 22:45 - 2013-11-24 09:52 - 03955293 _____ C:\Users\chris\Desktop\Root Call Blocker Pro_v2.2.3.6.apk 2013-12-01 22:43 - 2013-12-01 22:43 - 02789472 _____ C:\Users\chris\Downloads\Rooaoeo2236.rar 2013-11-30 10:41 - 2013-11-30 10:42 - 03611697 _____ C:\Users\chris\Downloads\iuMVRqag.zip 2013-11-30 10:30 - 2013-11-30 10:30 - 01202010 _____ C:\Users\chris\Downloads\roooieoio385.rar 2013-11-23 14:23 - 2013-11-23 14:25 - 00000000 ____D C:\Users\chris\Desktop\Katja Navigation 2013-11-22 23:21 - 2013-11-22 23:21 - 00027738 _____ C:\Users\chris\Downloads\Bueeeeeuiee11.rar 2013-11-22 22:46 - 2013-11-22 22:46 - 00000939 _____ C:\Users\chris\Desktop\W-LAN Streaming Adapter - Verknüpfung.lnk 2013-11-22 22:34 - 2013-11-22 22:34 - 00000000 ____D C:\Users\chris\Downloads\Ina_Mueller-48-DE-2013-VOiCE 2013-11-22 22:30 - 2013-11-22 22:31 - 05734400 _____ C:\Users\chris\Downloads\miami_rockers_feat_mc_dragon_d_and_dreiundzwanzig_-_to_the_beat_20.mp3.part 2013-11-22 22:23 - 2013-11-22 22:29 - 101265288 _____ C:\Users\chris\Downloads\Ina_Mueller-48-DE-2013-VOiCE.rar 2013-11-22 22:05 - 2013-11-22 22:05 - 00000000 ____D C:\Users\chris\Downloads\Fettes_Brot_-_3_Is_Ne_Party-2CD-DE-2013-MOD 2013-11-22 22:01 - 2013-11-22 22:05 - 150000000 _____ C:\Users\chris\Downloads\Fettes_Brot_-_3_Is_Ne_Party-2CD-DE-2013-MOD.rar 2013-11-22 21:57 - 2013-11-22 21:59 - 75941955 _____ C:\Users\chris\Downloads\Fettes_Brot_-_3_Is_Ne_Party-2CD-DE-2013-MOD.r00 2013-11-22 21:21 - 2013-11-22 21:21 - 05154575 _____ C:\Users\chris\Downloads\Remote_Speakers_output_v3_2.exe 2013-11-22 21:21 - 2011-12-28 20:53 - 02885120 ____R C:\Users\chris\Downloads\rsoutput-4.0.msi 2013-11-22 21:21 - 2011-12-28 20:16 - 00001766 ____R C:\Users\chris\Downloads\!HISTORY.txt 2013-11-22 21:21 - 2011-12-28 20:03 - 00018375 ____R C:\Users\chris\Downloads\!LICENSE.txt 2013-11-22 21:21 - 2011-12-28 20:03 - 00006001 ____R C:\Users\chris\Downloads\!README.txt 2013-11-22 21:21 - 2011-11-24 09:30 - 00000209 ____R C:\Users\chris\Downloads\Shortcut to DebugView program.url 2013-11-22 21:21 - 2011-09-15 11:53 - 02682368 ____R C:\Users\chris\Downloads\bonjour64-3.0.msi 2013-11-22 21:21 - 2011-09-15 11:53 - 02358784 ____R C:\Users\chris\Downloads\bonjour32-3.0.msi 2013-11-22 21:21 - 2010-12-18 12:39 - 00000636 ____R C:\Users\chris\Downloads\Shortcut to default install location.lnk 2013-11-22 21:09 - 2013-11-22 21:09 - 00000987 _____ C:\Users\Public\Desktop\Winamp.lnk 2013-11-22 21:09 - 2013-11-22 21:09 - 00000000 ____D C:\Users\chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in 2013-11-22 21:09 - 2013-11-22 21:09 - 00000000 ____D C:\Program Files (x86)\Winamp Detect 2013-11-22 21:08 - 2013-11-22 21:21 - 00000000 ____D C:\Users\chris\AppData\Roaming\Winamp 2013-11-22 21:08 - 2013-11-22 21:09 - 00000000 ____D C:\Program Files (x86)\Winamp 2013-11-22 21:07 - 2013-11-22 21:07 - 12996104 _____ (Nullsoft, Inc.) C:\Users\chris\Downloads\winamp566_full_de-de.exe 2013-11-22 07:48 - 2013-11-22 07:48 - 00000000 ____D C:\Users\chris\Downloads\Frei.Wild-Still-2CD-DE-2013-VOiCE 2013-11-22 07:45 - 2013-11-22 07:47 - 90223531 _____ C:\Users\chris\Downloads\Frei.Wild-Still-2CD-DE-2013-VOiCE.r00 2013-11-22 07:43 - 2013-11-22 07:46 - 120000000 _____ C:\Users\chris\Downloads\Frei.Wild-Still-2CD-DE-2013-VOiCE.rar 2013-11-16 12:22 - 2013-11-16 12:22 - 01002576 _____ C:\Users\chris\Downloads\Suiöiöiöeuo169.rar 2013-11-16 12:13 - 2013-11-16 12:13 - 00001074 _____ C:\Users\Public\Desktop\VLC media player.lnk 2013-11-16 08:00 - 2013-11-16 08:00 - 00246064 _____ C:\Users\chris\Downloads\Gaiöiöiöeo113.rar 2013-11-16 07:45 - 2013-11-16 07:45 - 04217433 _____ C:\Users\chris\Downloads\Saiöiöiöoo163(1).rar 2013-11-16 07:36 - 2013-11-16 07:36 - 01517935 _____ C:\Users\chris\Downloads\Koiöiöiöoiiaio201011.rar 2013-11-16 07:06 - 2013-11-16 07:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-13 18:51 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-13 18:51 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-13 18:51 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-13 18:51 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-13 18:51 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-13 18:51 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-13 18:51 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-13 18:51 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-13 18:51 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-13 18:51 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-13 18:51 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-13 18:51 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-13 18:51 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-13 18:51 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-13 18:51 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-13 18:51 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-13 18:51 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-13 18:51 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-13 18:51 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-13 18:51 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-13 18:51 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-13 18:51 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-13 18:51 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-13 18:51 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-13 18:51 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-13 18:51 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-13 18:51 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-13 18:51 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-13 18:51 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-13 18:51 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys ==================== One Month Modified Files and Folders ======= 2013-12-10 21:01 - 2013-12-10 21:00 - 00019324 _____ C:\Users\chris\Downloads\FRST.txt 2013-12-10 21:00 - 2013-12-10 21:00 - 00000000 ____D C:\FRST 2013-12-10 20:59 - 2013-12-10 20:59 - 01928110 _____ (Farbar) C:\Users\chris\Downloads\FRST64.exe 2013-12-10 20:58 - 2012-03-05 08:56 - 01212473 _____ C:\Windows\WindowsUpdate.log 2013-12-10 20:53 - 2012-03-05 08:58 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-10 20:53 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-10 20:52 - 2010-11-21 04:47 - 00150002 _____ C:\Windows\PFRO.log 2013-12-10 20:52 - 2009-07-14 05:51 - 00034981 _____ C:\Windows\setupact.log 2013-12-10 20:51 - 2013-12-10 20:50 - 00000424 _____ C:\Users\chris\Desktop\Neues Textdokument.txt 2013-12-10 20:49 - 2013-12-10 20:49 - 00050477 _____ C:\Users\chris\Downloads\Defogger.exe 2013-12-10 20:49 - 2013-12-10 20:49 - 00000582 _____ C:\Users\chris\Downloads\defogger_disable.log 2013-12-10 20:49 - 2013-12-10 20:49 - 00000020 _____ C:\Users\chris\defogger_reenable 2013-12-10 20:49 - 2012-03-05 09:04 - 00000000 ____D C:\Users\chris 2013-12-10 20:42 - 2012-03-05 08:58 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-10 20:38 - 2012-08-13 20:00 - 00000000 ____D C:\Users\chris\AppData\Local\Windows Live 2013-12-10 20:27 - 2012-04-19 06:29 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-12-10 16:18 - 2013-07-04 17:53 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-12-09 13:04 - 2012-04-26 18:22 - 00000000 ____D C:\Users\chris\Documents\UseNeXT 2013-12-09 13:04 - 2012-04-26 18:22 - 00000000 ____D C:\Users\chris\AppData\Roaming\UseNeXT 2013-12-08 20:28 - 2009-07-14 05:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-08 20:28 - 2009-07-14 05:45 - 00016752 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-08 20:25 - 2013-08-24 08:24 - 00000000 ___RD C:\Users\chris\Google Drive 2013-12-08 20:23 - 2012-03-05 09:05 - 00001421 _____ C:\Users\chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-08 20:19 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-12-08 12:53 - 2013-12-08 12:53 - 23212032 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 17142784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 12995584 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 11220992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 05765120 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 04240384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-08 12:53 - 2013-12-08 12:53 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-08 12:53 - 2013-12-08 12:53 - 02332160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 02166272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 01993728 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-08 12:53 - 2013-12-08 12:53 - 01926656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-08 12:53 - 2013-12-08 12:53 - 01818112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 01394176 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 01156608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-08 12:53 - 2013-12-08 12:53 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-08 12:53 - 2013-12-08 12:53 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-08 12:53 - 2013-12-08 12:53 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-08 12:53 - 2013-12-08 12:53 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-08 12:53 - 2013-12-08 12:53 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-08 12:53 - 2013-12-08 12:53 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-08 12:53 - 2013-12-08 12:53 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-08 12:53 - 2013-12-08 12:53 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-08 12:50 - 2013-12-08 09:13 - 00007110 _____ C:\Windows\IE11_main.log 2013-12-07 09:15 - 2012-06-25 16:16 - 00000000 ____D C:\Users\chris\AppData\Roaming\vlc 2013-12-07 07:08 - 2013-11-02 20:18 - 00000000 ____D C:\Users\chris\AppData\Roaming\dvdcss 2013-12-06 18:07 - 2012-04-21 15:25 - 00000000 ____D C:\Users\chris\Documents\My Received Files 2013-12-06 05:19 - 2012-04-29 17:33 - 00000040 ___RH C:\Windows\ssystda.dat 2013-12-06 04:38 - 2013-12-06 04:37 - 00000000 ____D C:\Users\chris\Downloads\Waiöiölmaaa470uoe 2013-12-06 04:37 - 2012-03-05 08:58 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-12-06 04:37 - 2012-03-05 08:58 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-12-06 04:36 - 2013-12-06 04:36 - 08469062 _____ C:\Users\chris\Downloads\Waiöiölmaaa470uoe.rar 2013-12-05 07:45 - 2013-12-05 07:45 - 01071224 _____ (Solid State Networks) C:\Users\chris\Downloads\install_flashplayer11x32au_mssd_aaa_aih(1).exe 2013-12-01 22:43 - 2013-12-01 22:43 - 02789472 _____ C:\Users\chris\Downloads\Rooaoeo2236.rar 2013-12-01 21:12 - 2013-03-02 22:26 - 00497664 ___SH C:\Users\chris\Desktop\Thumbs.db 2013-11-30 10:42 - 2013-11-30 10:41 - 03611697 _____ C:\Users\chris\Downloads\iuMVRqag.zip 2013-11-30 10:30 - 2013-11-30 10:30 - 01202010 _____ C:\Users\chris\Downloads\roooieoio385.rar 2013-11-24 09:52 - 2013-12-01 22:45 - 03955293 _____ C:\Users\chris\Desktop\Root Call Blocker Pro_v2.2.3.6.apk 2013-11-23 14:25 - 2013-11-23 14:23 - 00000000 ____D C:\Users\chris\Desktop\Katja Navigation 2013-11-22 23:21 - 2013-11-22 23:21 - 00027738 _____ C:\Users\chris\Downloads\Bueeeeeuiee11.rar 2013-11-22 22:46 - 2013-11-22 22:46 - 00000939 _____ C:\Users\chris\Desktop\W-LAN Streaming Adapter - Verknüpfung.lnk 2013-11-22 22:34 - 2013-11-22 22:34 - 00000000 ____D C:\Users\chris\Downloads\Ina_Mueller-48-DE-2013-VOiCE 2013-11-22 22:31 - 2013-11-22 22:30 - 05734400 _____ C:\Users\chris\Downloads\miami_rockers_feat_mc_dragon_d_and_dreiundzwanzig_-_to_the_beat_20.mp3.part 2013-11-22 22:29 - 2013-11-22 22:23 - 101265288 _____ C:\Users\chris\Downloads\Ina_Mueller-48-DE-2013-VOiCE.rar 2013-11-22 22:05 - 2013-11-22 22:05 - 00000000 ____D C:\Users\chris\Downloads\Fettes_Brot_-_3_Is_Ne_Party-2CD-DE-2013-MOD 2013-11-22 22:05 - 2013-11-22 22:01 - 150000000 _____ C:\Users\chris\Downloads\Fettes_Brot_-_3_Is_Ne_Party-2CD-DE-2013-MOD.rar 2013-11-22 21:59 - 2013-11-22 21:57 - 75941955 _____ C:\Users\chris\Downloads\Fettes_Brot_-_3_Is_Ne_Party-2CD-DE-2013-MOD.r00 2013-11-22 21:21 - 2013-11-22 21:21 - 05154575 _____ C:\Users\chris\Downloads\Remote_Speakers_output_v3_2.exe 2013-11-22 21:21 - 2013-11-22 21:08 - 00000000 ____D C:\Users\chris\AppData\Roaming\Winamp 2013-11-22 21:09 - 2013-11-22 21:09 - 00000987 _____ C:\Users\Public\Desktop\Winamp.lnk 2013-11-22 21:09 - 2013-11-22 21:09 - 00000000 ____D C:\Users\chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Winamp Erkennungs-Plug-in 2013-11-22 21:09 - 2013-11-22 21:09 - 00000000 ____D C:\Program Files (x86)\Winamp Detect 2013-11-22 21:09 - 2013-11-22 21:08 - 00000000 ____D C:\Program Files (x86)\Winamp 2013-11-22 21:07 - 2013-11-22 21:07 - 12996104 _____ (Nullsoft, Inc.) C:\Users\chris\Downloads\winamp566_full_de-de.exe 2013-11-22 07:48 - 2013-11-22 07:48 - 00000000 ____D C:\Users\chris\Downloads\Frei.Wild-Still-2CD-DE-2013-VOiCE 2013-11-22 07:47 - 2013-11-22 07:45 - 90223531 _____ C:\Users\chris\Downloads\Frei.Wild-Still-2CD-DE-2013-VOiCE.r00 2013-11-22 07:46 - 2013-11-22 07:43 - 120000000 _____ C:\Users\chris\Downloads\Frei.Wild-Still-2CD-DE-2013-VOiCE.rar 2013-11-21 07:42 - 2012-05-06 10:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-16 18:34 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2013-11-16 12:22 - 2013-11-16 12:22 - 01002576 _____ C:\Users\chris\Downloads\Suiöiöiöeuo169.rar 2013-11-16 12:13 - 2013-11-16 12:13 - 00001074 _____ C:\Users\Public\Desktop\VLC media player.lnk 2013-11-16 11:57 - 2011-03-12 19:22 - 00654400 _____ C:\Windows\system32\perfh007.dat 2013-11-16 11:57 - 2011-03-12 19:22 - 00130240 _____ C:\Windows\system32\perfc007.dat 2013-11-16 11:57 - 2009-07-14 06:13 - 01498742 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-16 08:00 - 2013-11-16 08:00 - 00246064 _____ C:\Users\chris\Downloads\Gaiöiöiöeo113.rar 2013-11-16 07:45 - 2013-11-16 07:45 - 04217433 _____ C:\Users\chris\Downloads\Saiöiöiöoo163(1).rar 2013-11-16 07:36 - 2013-11-16 07:36 - 01517935 _____ C:\Users\chris\Downloads\Koiöiöiöoiiaio201011.rar 2013-11-16 07:06 - 2013-11-16 07:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-16 06:59 - 2012-03-06 21:03 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-16 06:58 - 2013-08-16 11:33 - 00000000 ____D C:\Windows\system32\MRT 2013-11-16 06:55 - 2011-03-12 20:24 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-11-10 12:08 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache Some content of TEMP: ==================== C:\Users\chris\AppData\Local\Temp\AskSLib.dll C:\Users\chris\AppData\Local\Temp\DivXSetup.exe C:\Users\chris\AppData\Local\Temp\jre-7u11-windows-i586-iftw.exe C:\Users\chris\AppData\Local\Temp\jre-7u13-windows-i586-iftw.exe C:\Users\chris\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe C:\Users\chris\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe C:\Users\chris\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\chris\AppData\Local\Temp\jre-7u9-windows-i586-iftw.exe C:\Users\chris\AppData\Local\Temp\proxy_util_w32.dll C:\Users\chris\AppData\Local\Temp\temp.exe C:\Users\chris\AppData\Local\Temp\uninst1.exe C:\Users\chris\AppData\Local\Temp\vlc-2.0.2-win32.exe C:\Users\chris\AppData\Local\Temp\vlc-2.1.1-win32.exe C:\Users\chris\AppData\Local\Temp\xmlUpdater.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-08 13:40 ==================== End Of Log ============================ Danke euch Gruss Chris |
10.12.2013, 21:47 | #2 |
| win 7 64 avast meldet bösartige URLS GMER
__________________Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-12-10 21:39:31 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.JE4O 698,64GB Running: jbgu6vr6.exe; Driver: C:\Users\chris\AppData\Local\Temp\ugroyuoc.sys ---- User code sections - GMER 2.1 ---- .text C:\Windows\system32\wininit.exe[652] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Windows\system32\services.exe[716] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Windows\system32\winlogon.exe[752] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[900] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Windows\System32\svchost.exe[588] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Windows\System32\svchost.exe[512] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[836] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[1040] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[1224] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Windows\system32\WLANExt.exe[1316] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Windows\System32\spoolsv.exe[1508] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[1536] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1620] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1652] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[1680] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\Windows\Explorer.EXE[1820] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[1876] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1952] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[1036] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe[1740] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\Windows\system32\svchost.exe[1448] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe[1404] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\TECDOC_CD\2_2011\db\tbmux32.exe[1676] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\TECDOC_CD\2_2011\db\tbmux32.exe[1676] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077c91465 2 bytes [C9, 77] .text C:\TECDOC_CD\2_2011\db\tbmux32.exe[1676] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000077c914bb 2 bytes [C9, 77] .text ... * 2 .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2092] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\PROGRA~2\COMMON~1\X10\Common\x10nets.exe[2132] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe[2236] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\Windows\system32\taskhost.exe[2924] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Windows\System32\rundll32.exe[3088] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[3192] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Windows\System32\rundll32.exe[3216] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Windows\System32\igfxpers.exe[3224] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Windows\System32\igfxtray.exe[3232] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[3332] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[3332] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077c91465 2 bytes [C9, 77] .text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[3332] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000077c914bb 2 bytes [C9, 77] .text ... * 2 .text C:\Windows\System32\hkcmd.exe[3496] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe[3524] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe[3524] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077c91465 2 bytes [C9, 77] .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe[3524] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000077c914bb 2 bytes [C9, 77] .text ... * 2 .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3568] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[3576] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\Windows\system32\SearchIndexer.exe[3600] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Program Files (x86)\Launch Manager\OSD.exe[3724] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\Program Files (x86)\Launch Manager\HotkeyApp.exe[3732] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\Program Files (x86)\Launch Manager\WButton.exe[3740] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3748] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[3880] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\Program Files (x86)\Launch Manager\WisLMSvc.exe[1700] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 0000000077cdfac0 5 bytes JMP 0000000100030600 .text C:\Program Files (x86)\Launch Manager\WisLMSvc.exe[1700] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 0000000077cdfb58 5 bytes JMP 0000000100030804 .text C:\Program Files (x86)\Launch Manager\WisLMSvc.exe[1700] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 0000000077cdfcb0 5 bytes JMP 0000000100030c0c .text C:\Program Files (x86)\Launch Manager\WisLMSvc.exe[1700] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 0000000077ce0038 5 bytes JMP 0000000100030a08 .text C:\Program Files (x86)\Launch Manager\WisLMSvc.exe[1700] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread 0000000077ce1920 5 bytes JMP 0000000100030e10 .text C:\Program Files (x86)\Launch Manager\WisLMSvc.exe[1700] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077cfc4dd 5 bytes JMP 00000001000301f8 .text C:\Program Files (x86)\Launch Manager\WisLMSvc.exe[1700] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll 0000000077d01287 5 bytes JMP 00000001000303fc .text C:\Program Files (x86)\Launch Manager\WisLMSvc.exe[1700] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\Program Files (x86)\Launch Manager\WisLMSvc.exe[1700] C:\Windows\syswow64\USER32.dll!SetWinEventHook 0000000076ecee09 5 bytes JMP 00000001003c01f8 .text C:\Program Files (x86)\Launch Manager\WisLMSvc.exe[1700] C:\Windows\syswow64\USER32.dll!UnhookWinEvent 0000000076ed3982 5 bytes JMP 00000001003c03fc .text C:\Program Files (x86)\Launch Manager\WisLMSvc.exe[1700] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 0000000076ed7603 5 bytes JMP 00000001003c0804 .text C:\Program Files (x86)\Launch Manager\WisLMSvc.exe[1700] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA 0000000076ed835c 5 bytes JMP 00000001003c0600 .text C:\Program Files (x86)\Launch Manager\WisLMSvc.exe[1700] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx 0000000076eef52b 5 bytes JMP 00000001003c0a08 .text C:\Program Files (x86)\Launch Manager\WisLMSvc.exe[1700] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity 00000000775e5181 5 bytes JMP 00000001003d1014 .text C:\Program Files (x86)\Launch Manager\WisLMSvc.exe[1700] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA 00000000775e5254 5 bytes JMP 00000001003d0804 .text C:\Program Files (x86)\Launch Manager\WisLMSvc.exe[1700] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW 00000000775e53d5 5 bytes JMP 00000001003d0a08 .text C:\Program Files (x86)\Launch Manager\WisLMSvc.exe[1700] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A 00000000775e54c2 5 bytes JMP 00000001003d0c0c .text C:\Program Files (x86)\Launch Manager\WisLMSvc.exe[1700] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W 00000000775e55e2 5 bytes JMP 00000001003d0e10 .text C:\Program Files (x86)\Launch Manager\WisLMSvc.exe[1700] C:\Windows\SysWOW64\sechost.dll!CreateServiceA 00000000775e567c 5 bytes JMP 00000001003d01f8 .text C:\Program Files (x86)\Launch Manager\WisLMSvc.exe[1700] C:\Windows\SysWOW64\sechost.dll!CreateServiceW 00000000775e589f 5 bytes JMP 00000001003d03fc .text C:\Program Files (x86)\Launch Manager\WisLMSvc.exe[1700] C:\Windows\SysWOW64\sechost.dll!DeleteService 00000000775e5a22 5 bytes JMP 00000001003d0600 .text C:\Windows\SysWOW64\cmd.exe[3320] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 0000000077cdfac0 5 bytes JMP 0000000100180600 .text C:\Windows\SysWOW64\cmd.exe[3320] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 0000000077cdfb58 5 bytes JMP 0000000100180804 .text C:\Windows\SysWOW64\cmd.exe[3320] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 0000000077cdfcb0 5 bytes JMP 0000000100180c0c .text C:\Windows\SysWOW64\cmd.exe[3320] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 0000000077ce0038 5 bytes JMP 0000000100180a08 .text C:\Windows\SysWOW64\cmd.exe[3320] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread 0000000077ce1920 5 bytes JMP 0000000100180e10 .text C:\Windows\SysWOW64\cmd.exe[3320] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077cfc4dd 5 bytes JMP 00000001001801f8 .text C:\Windows\SysWOW64\cmd.exe[3320] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll 0000000077d01287 5 bytes JMP 00000001001803fc .text C:\Windows\SysWOW64\cmd.exe[3320] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\Windows\SysWOW64\cmd.exe[3320] C:\Windows\syswow64\USER32.dll!SetWinEventHook 0000000076ecee09 5 bytes JMP 00000001001d01f8 .text C:\Windows\SysWOW64\cmd.exe[3320] C:\Windows\syswow64\USER32.dll!UnhookWinEvent 0000000076ed3982 5 bytes JMP 00000001001d03fc .text C:\Windows\SysWOW64\cmd.exe[3320] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 0000000076ed7603 5 bytes JMP 00000001001d0804 .text C:\Windows\SysWOW64\cmd.exe[3320] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA 0000000076ed835c 5 bytes JMP 00000001001d0600 .text C:\Windows\SysWOW64\cmd.exe[3320] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx 0000000076eef52b 5 bytes JMP 00000001001d0a08 .text C:\Windows\SysWOW64\cmd.exe[3320] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity 00000000775e5181 5 bytes JMP 00000001001e1014 .text C:\Windows\SysWOW64\cmd.exe[3320] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA 00000000775e5254 5 bytes JMP 00000001001e0804 .text C:\Windows\SysWOW64\cmd.exe[3320] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW 00000000775e53d5 5 bytes JMP 00000001001e0a08 .text C:\Windows\SysWOW64\cmd.exe[3320] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A 00000000775e54c2 5 bytes JMP 00000001001e0c0c .text C:\Windows\SysWOW64\cmd.exe[3320] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W 00000000775e55e2 5 bytes JMP 00000001001e0e10 .text C:\Windows\SysWOW64\cmd.exe[3320] C:\Windows\SysWOW64\sechost.dll!CreateServiceA 00000000775e567c 5 bytes JMP 00000001001e01f8 .text C:\Windows\SysWOW64\cmd.exe[3320] C:\Windows\SysWOW64\sechost.dll!CreateServiceW 00000000775e589f 5 bytes JMP 00000001001e03fc .text C:\Windows\SysWOW64\cmd.exe[3320] C:\Windows\SysWOW64\sechost.dll!DeleteService 00000000775e5a22 5 bytes JMP 00000001001e0600 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe[2328] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 0000000077cdfac0 5 bytes JMP 0000000100100600 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe[2328] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 0000000077cdfb58 5 bytes JMP 0000000100100804 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe[2328] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 0000000077cdfcb0 5 bytes JMP 0000000100100c0c .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe[2328] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 0000000077ce0038 5 bytes JMP 0000000100100a08 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe[2328] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread 0000000077ce1920 5 bytes JMP 0000000100100e10 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe[2328] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077cfc4dd 5 bytes JMP 00000001001001f8 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe[2328] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll 0000000077d01287 5 bytes JMP 00000001001003fc .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe[2328] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe[2328] C:\Windows\syswow64\USER32.dll!SetWinEventHook 0000000076ecee09 5 bytes JMP 0000000100b301f8 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe[2328] C:\Windows\syswow64\USER32.dll!UnhookWinEvent 0000000076ed3982 5 bytes JMP 0000000100b303fc .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe[2328] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 0000000076ed7603 5 bytes JMP 0000000100b30804 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe[2328] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA 0000000076ed835c 5 bytes JMP 0000000100b30600 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe[2328] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx 0000000076eef52b 5 bytes JMP 0000000100b30a08 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe[2328] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity 00000000775e5181 5 bytes JMP 0000000100b41014 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe[2328] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA 00000000775e5254 5 bytes JMP 0000000100b40804 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe[2328] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW 00000000775e53d5 5 bytes JMP 0000000100b40a08 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe[2328] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A 00000000775e54c2 5 bytes JMP 0000000100b40c0c .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe[2328] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W 00000000775e55e2 5 bytes JMP 0000000100b40e10 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe[2328] C:\Windows\SysWOW64\sechost.dll!CreateServiceA 00000000775e567c 5 bytes JMP 0000000100b401f8 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe[2328] C:\Windows\SysWOW64\sechost.dll!CreateServiceW 00000000775e589f 5 bytes JMP 0000000100b403fc .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe[2328] C:\Windows\SysWOW64\sechost.dll!DeleteService 00000000775e5a22 5 bytes JMP 0000000100b40600 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe[828] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 0000000077cdfac0 5 bytes JMP 00000001000d0600 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe[828] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 0000000077cdfb58 5 bytes JMP 00000001000d0804 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe[828] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 0000000077cdfcb0 5 bytes JMP 00000001000d0c0c .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe[828] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 0000000077ce0038 5 bytes JMP 00000001000d0a08 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe[828] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread 0000000077ce1920 5 bytes JMP 00000001000d0e10 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe[828] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077cfc4dd 5 bytes JMP 00000001000d01f8 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe[828] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll 0000000077d01287 5 bytes JMP 00000001000d03fc .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe[828] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe[828] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity 00000000775e5181 5 bytes JMP 00000001000f1014 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe[828] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA 00000000775e5254 5 bytes JMP 00000001000f0804 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe[828] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW 00000000775e53d5 5 bytes JMP 00000001000f0a08 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe[828] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A 00000000775e54c2 5 bytes JMP 00000001000f0c0c .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe[828] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W 00000000775e55e2 5 bytes JMP 00000001000f0e10 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe[828] C:\Windows\SysWOW64\sechost.dll!CreateServiceA 00000000775e567c 5 bytes JMP 00000001000f01f8 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe[828] C:\Windows\SysWOW64\sechost.dll!CreateServiceW 00000000775e589f 5 bytes JMP 00000001000f03fc .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe[828] C:\Windows\SysWOW64\sechost.dll!DeleteService 00000000775e5a22 5 bytes JMP 00000001000f0600 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe[828] C:\Windows\syswow64\USER32.dll!SetWinEventHook 0000000076ecee09 5 bytes JMP 00000001001001f8 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe[828] C:\Windows\syswow64\USER32.dll!UnhookWinEvent 0000000076ed3982 5 bytes JMP 00000001001003fc .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe[828] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 0000000076ed7603 5 bytes JMP 0000000100100804 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe[828] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA 0000000076ed835c 5 bytes JMP 0000000100100600 .text C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe[828] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx 0000000076eef52b 5 bytes JMP 0000000100100a08 .text C:\Windows\system32\NOTEPAD.EXE[2308] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077b03b10 5 bytes JMP 000000010039075c .text C:\Windows\system32\NOTEPAD.EXE[2308] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077b07ac0 5 bytes JMP 00000001003903a4 .text C:\Windows\system32\NOTEPAD.EXE[2308] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077b31430 5 bytes JMP 0000000100390b14 .text C:\Windows\system32\NOTEPAD.EXE[2308] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077b31490 5 bytes JMP 0000000100390ecc .text C:\Windows\system32\NOTEPAD.EXE[2308] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b31570 5 bytes JMP 000000010039163c .text C:\Windows\system32\NOTEPAD.EXE[2308] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 0000000077b317b0 5 bytes JMP 0000000100391284 .text C:\Windows\system32\NOTEPAD.EXE[2308] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b327e0 5 bytes JMP 00000001003919f4 .text C:\Windows\system32\NOTEPAD.EXE[2308] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Windows\system32\NOTEPAD.EXE[2308] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007fefef26e00 5 bytes JMP 000007ff7ef41dac .text C:\Windows\system32\NOTEPAD.EXE[2308] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007fefef26f2c 5 bytes JMP 000007ff7ef40ecc .text C:\Windows\system32\NOTEPAD.EXE[2308] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007fefef27220 5 bytes JMP 000007ff7ef41284 .text C:\Windows\system32\NOTEPAD.EXE[2308] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007fefef2739c 5 bytes JMP 000007ff7ef4163c .text C:\Windows\system32\NOTEPAD.EXE[2308] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007fefef27538 5 bytes JMP 000007ff7ef419f4 .text C:\Windows\system32\NOTEPAD.EXE[2308] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fefef275e8 5 bytes JMP 000007ff7ef403a4 .text C:\Windows\system32\NOTEPAD.EXE[2308] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fefef2790c 5 bytes JMP 000007ff7ef4075c .text C:\Windows\system32\NOTEPAD.EXE[2308] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007fefef27ab4 5 bytes JMP 000007ff7ef40b14 .text C:\Windows\system32\wbem\wmiprvse.exe[4380] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077b03b10 5 bytes JMP 000000010021075c .text C:\Windows\system32\wbem\wmiprvse.exe[4380] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077b07ac0 5 bytes JMP 00000001002103a4 .text C:\Windows\system32\wbem\wmiprvse.exe[4380] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077b31430 5 bytes JMP 0000000100210b14 .text C:\Windows\system32\wbem\wmiprvse.exe[4380] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077b31490 5 bytes JMP 0000000100210ecc .text C:\Windows\system32\wbem\wmiprvse.exe[4380] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b31570 5 bytes JMP 000000010021163c .text C:\Windows\system32\wbem\wmiprvse.exe[4380] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 0000000077b317b0 5 bytes JMP 0000000100211284 .text C:\Windows\system32\wbem\wmiprvse.exe[4380] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b327e0 5 bytes JMP 00000001002119f4 .text C:\Windows\system32\wbem\wmiprvse.exe[4380] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Windows\system32\wbem\wmiprvse.exe[4380] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007fefef26e00 5 bytes JMP 000007ff7ef41dac .text C:\Windows\system32\wbem\wmiprvse.exe[4380] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007fefef26f2c 5 bytes JMP 000007ff7ef40ecc .text C:\Windows\system32\wbem\wmiprvse.exe[4380] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007fefef27220 5 bytes JMP 000007ff7ef41284 .text C:\Windows\system32\wbem\wmiprvse.exe[4380] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007fefef2739c 5 bytes JMP 000007ff7ef4163c .text C:\Windows\system32\wbem\wmiprvse.exe[4380] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007fefef27538 5 bytes JMP 000007ff7ef419f4 .text C:\Windows\system32\wbem\wmiprvse.exe[4380] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fefef275e8 5 bytes JMP 000007ff7ef403a4 .text C:\Windows\system32\wbem\wmiprvse.exe[4380] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fefef2790c 5 bytes JMP 000007ff7ef4075c .text C:\Windows\system32\wbem\wmiprvse.exe[4380] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007fefef27ab4 5 bytes JMP 000007ff7ef40b14 .text C:\Windows\system32\wbem\unsecapp.exe[4456] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007fefef26e00 5 bytes JMP 000007ff7ef41dac .text C:\Windows\system32\wbem\unsecapp.exe[4456] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007fefef26f2c 5 bytes JMP 000007ff7ef40ecc .text C:\Windows\system32\wbem\unsecapp.exe[4456] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007fefef27220 5 bytes JMP 000007ff7ef41284 .text C:\Windows\system32\wbem\unsecapp.exe[4456] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007fefef2739c 5 bytes JMP 000007ff7ef4163c .text C:\Windows\system32\wbem\unsecapp.exe[4456] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007fefef27538 5 bytes JMP 000007ff7ef419f4 .text C:\Windows\system32\wbem\unsecapp.exe[4456] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fefef275e8 5 bytes JMP 000007ff7ef403a4 .text C:\Windows\system32\wbem\unsecapp.exe[4456] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fefef2790c 5 bytes JMP 000007ff7ef4075c .text C:\Windows\system32\wbem\unsecapp.exe[4456] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007fefef27ab4 5 bytes JMP 000007ff7ef40b14 .text C:\Windows\system32\wbem\unsecapp.exe[4480] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007fefef26e00 5 bytes JMP 000007ff7ef41dac .text C:\Windows\system32\wbem\unsecapp.exe[4480] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007fefef26f2c 5 bytes JMP 000007ff7ef40ecc .text C:\Windows\system32\wbem\unsecapp.exe[4480] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007fefef27220 5 bytes JMP 000007ff7ef41284 .text C:\Windows\system32\wbem\unsecapp.exe[4480] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007fefef2739c 5 bytes JMP 000007ff7ef4163c .text C:\Windows\system32\wbem\unsecapp.exe[4480] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007fefef27538 5 bytes JMP 000007ff7ef419f4 .text C:\Windows\system32\wbem\unsecapp.exe[4480] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fefef275e8 5 bytes JMP 000007ff7ef403a4 .text C:\Windows\system32\wbem\unsecapp.exe[4480] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fefef2790c 5 bytes JMP 000007ff7ef4075c .text C:\Windows\system32\wbem\unsecapp.exe[4480] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007fefef27ab4 5 bytes JMP 000007ff7ef40b14 .text C:\Windows\system32\svchost.exe[4780] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077b03b10 5 bytes JMP 000000010012075c .text C:\Windows\system32\svchost.exe[4780] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077b07ac0 5 bytes JMP 00000001001203a4 .text C:\Windows\system32\svchost.exe[4780] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077b31430 5 bytes JMP 0000000100120b14 .text C:\Windows\system32\svchost.exe[4780] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077b31490 5 bytes JMP 0000000100120ecc .text C:\Windows\system32\svchost.exe[4780] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b31570 5 bytes JMP 000000010012163c .text C:\Windows\system32\svchost.exe[4780] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 0000000077b317b0 5 bytes JMP 0000000100121284 .text C:\Windows\system32\svchost.exe[4780] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b327e0 5 bytes JMP 00000001001219f4 .text C:\Windows\system32\svchost.exe[4780] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[4780] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007fefef26e00 5 bytes JMP 000007ff7ef41dac .text C:\Windows\system32\svchost.exe[4780] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007fefef26f2c 5 bytes JMP 000007ff7ef40ecc .text C:\Windows\system32\svchost.exe[4780] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007fefef27220 5 bytes JMP 000007ff7ef41284 .text C:\Windows\system32\svchost.exe[4780] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007fefef2739c 5 bytes JMP 000007ff7ef4163c .text C:\Windows\system32\svchost.exe[4780] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007fefef27538 5 bytes JMP 000007ff7ef419f4 .text C:\Windows\system32\svchost.exe[4780] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fefef275e8 5 bytes JMP 000007ff7ef403a4 .text C:\Windows\system32\svchost.exe[4780] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fefef2790c 5 bytes JMP 000007ff7ef4075c .text C:\Windows\system32\svchost.exe[4780] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007fefef27ab4 5 bytes JMP 000007ff7ef40b14 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4984] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 0000000077cdfac0 5 bytes JMP 0000000100030600 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4984] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 0000000077cdfb58 5 bytes JMP 0000000100030804 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4984] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 0000000077cdfcb0 5 bytes JMP 0000000100030c0c .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4984] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 0000000077ce0038 5 bytes JMP 0000000100030a08 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4984] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread 0000000077ce1920 5 bytes JMP 0000000100030e10 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4984] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077cfc4dd 5 bytes JMP 00000001000301f8 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4984] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll 0000000077d01287 5 bytes JMP 00000001000303fc .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4984] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4984] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity 00000000775e5181 5 bytes JMP 0000000100091014 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4984] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA 00000000775e5254 5 bytes JMP 0000000100090804 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4984] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW 00000000775e53d5 5 bytes JMP 0000000100090a08 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4984] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A 00000000775e54c2 5 bytes JMP 0000000100090c0c .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4984] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W 00000000775e55e2 5 bytes JMP 0000000100090e10 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4984] C:\Windows\SysWOW64\sechost.dll!CreateServiceA 00000000775e567c 5 bytes JMP 00000001000901f8 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4984] C:\Windows\SysWOW64\sechost.dll!CreateServiceW 00000000775e589f 5 bytes JMP 00000001000903fc .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4984] C:\Windows\SysWOW64\sechost.dll!DeleteService 00000000775e5a22 5 bytes JMP 0000000100090600 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4984] C:\Windows\syswow64\USER32.dll!SetWinEventHook 0000000076ecee09 5 bytes JMP 00000001000a01f8 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4984] C:\Windows\syswow64\USER32.dll!UnhookWinEvent 0000000076ed3982 5 bytes JMP 00000001000a03fc .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4984] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 0000000076ed7603 5 bytes JMP 00000001000a0804 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4984] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA 0000000076ed835c 5 bytes JMP 00000001000a0600 .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4984] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx 0000000076eef52b 5 bytes JMP 00000001000a0a08 .text C:\Program Files\Windows Media Player\wmpnetwk.exe[1108] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[2380] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007fefef26e00 5 bytes JMP 000007ff7ef41dac .text C:\Windows\system32\svchost.exe[2380] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007fefef26f2c 5 bytes JMP 000007ff7ef40ecc .text C:\Windows\system32\svchost.exe[2380] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007fefef27220 5 bytes JMP 000007ff7ef41284 .text C:\Windows\system32\svchost.exe[2380] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007fefef2739c 5 bytes JMP 000007ff7ef4163c .text C:\Windows\system32\svchost.exe[2380] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007fefef27538 5 bytes JMP 000007ff7ef419f4 .text C:\Windows\system32\svchost.exe[2380] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fefef275e8 5 bytes JMP 000007ff7ef403a4 .text C:\Windows\system32\svchost.exe[2380] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fefef2790c 5 bytes JMP 000007ff7ef4075c .text C:\Windows\system32\svchost.exe[2380] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007fefef27ab4 5 bytes JMP 000007ff7ef40b14 .text C:\Windows\System32\svchost.exe[1400] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077b03b10 5 bytes JMP 000000010032075c .text C:\Windows\System32\svchost.exe[1400] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077b07ac0 5 bytes JMP 00000001003203a4 .text C:\Windows\System32\svchost.exe[1400] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077b31430 5 bytes JMP 0000000100320b14 .text C:\Windows\System32\svchost.exe[1400] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077b31490 5 bytes JMP 0000000100320ecc .text C:\Windows\System32\svchost.exe[1400] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b31570 5 bytes JMP 000000010032163c .text C:\Windows\System32\svchost.exe[1400] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 0000000077b317b0 5 bytes JMP 0000000100321284 .text C:\Windows\System32\svchost.exe[1400] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b327e0 5 bytes JMP 00000001003219f4 .text C:\Windows\System32\svchost.exe[1400] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007fefef26e00 5 bytes JMP 000007ff7ef41dac .text C:\Windows\System32\svchost.exe[1400] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007fefef26f2c 5 bytes JMP 000007ff7ef40ecc .text C:\Windows\System32\svchost.exe[1400] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007fefef27220 5 bytes JMP 000007ff7ef41284 .text C:\Windows\System32\svchost.exe[1400] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007fefef2739c 5 bytes JMP 000007ff7ef4163c .text C:\Windows\System32\svchost.exe[1400] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007fefef27538 5 bytes JMP 000007ff7ef419f4 .text C:\Windows\System32\svchost.exe[1400] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fefef275e8 5 bytes JMP 000007ff7ef403a4 .text C:\Windows\System32\svchost.exe[1400] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fefef2790c 5 bytes JMP 000007ff7ef4075c .text C:\Windows\System32\svchost.exe[1400] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007fefef27ab4 5 bytes JMP 000007ff7ef40b14 .text C:\Windows\system32\svchost.exe[5244] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189 0000000077a1eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[5244] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007fefef26e00 5 bytes JMP 000007ff7ef41dac .text C:\Windows\system32\svchost.exe[5244] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007fefef26f2c 5 bytes JMP 000007ff7ef40ecc .text C:\Windows\system32\svchost.exe[5244] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007fefef27220 5 bytes JMP 000007ff7ef41284 .text C:\Windows\system32\svchost.exe[5244] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007fefef2739c 5 bytes JMP 000007ff7ef4163c .text C:\Windows\system32\svchost.exe[5244] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007fefef27538 5 bytes JMP 000007ff7ef419f4 .text C:\Windows\system32\svchost.exe[5244] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fefef275e8 5 bytes JMP 000007ff7ef403a4 .text C:\Windows\system32\svchost.exe[5244] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fefef2790c 5 bytes JMP 000007ff7ef4075c .text C:\Windows\system32\svchost.exe[5244] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007fefef27ab4 5 bytes JMP 000007ff7ef40b14 .text C:\Windows\system32\DllHost.exe[5684] C:\Windows\SYSTEM32\sechost.dll!SetServiceObjectSecurity 000007fefef26e00 5 bytes JMP 000007ff7ef41dac .text C:\Windows\system32\DllHost.exe[5684] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA 000007fefef26f2c 5 bytes JMP 000007ff7ef40ecc .text C:\Windows\system32\DllHost.exe[5684] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW 000007fefef27220 5 bytes JMP 000007ff7ef41284 .text C:\Windows\system32\DllHost.exe[5684] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2A 000007fefef2739c 5 bytes JMP 000007ff7ef4163c .text C:\Windows\system32\DllHost.exe[5684] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfig2W 000007fefef27538 5 bytes JMP 000007ff7ef419f4 .text C:\Windows\system32\DllHost.exe[5684] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fefef275e8 5 bytes JMP 000007ff7ef403a4 .text C:\Windows\system32\DllHost.exe[5684] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fefef2790c 5 bytes JMP 000007ff7ef4075c .text C:\Windows\system32\DllHost.exe[5684] C:\Windows\SYSTEM32\sechost.dll!DeleteService 000007fefef27ab4 5 bytes JMP 000007ff7ef40b14 .text C:\Users\chris\Downloads\jbgu6vr6.exe[4808] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 0000000077cdfac0 5 bytes JMP 0000000100030600 .text C:\Users\chris\Downloads\jbgu6vr6.exe[4808] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 0000000077cdfb58 5 bytes JMP 0000000100030804 .text C:\Users\chris\Downloads\jbgu6vr6.exe[4808] C:\Windows\SysWOW64\ntdll.dll!NtTerminateProcess 0000000077cdfcb0 5 bytes JMP 0000000100030c0c .text C:\Users\chris\Downloads\jbgu6vr6.exe[4808] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 0000000077ce0038 5 bytes JMP 0000000100030a08 .text C:\Users\chris\Downloads\jbgu6vr6.exe[4808] C:\Windows\SysWOW64\ntdll.dll!NtSetContextThread 0000000077ce1920 5 bytes JMP 0000000100030e10 .text C:\Users\chris\Downloads\jbgu6vr6.exe[4808] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077cfc4dd 5 bytes JMP 00000001000301f8 .text C:\Users\chris\Downloads\jbgu6vr6.exe[4808] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll 0000000077d01287 5 bytes JMP 00000001000303fc .text C:\Users\chris\Downloads\jbgu6vr6.exe[4808] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 00000000777ea2ba 1 byte [62] .text C:\Users\chris\Downloads\jbgu6vr6.exe[4808] C:\Windows\SysWOW64\sechost.dll!SetServiceObjectSecurity 00000000775e5181 5 bytes JMP 0000000100241014 .text C:\Users\chris\Downloads\jbgu6vr6.exe[4808] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigA 00000000775e5254 5 bytes JMP 0000000100240804 .text C:\Users\chris\Downloads\jbgu6vr6.exe[4808] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfigW 00000000775e53d5 5 bytes JMP 0000000100240a08 .text C:\Users\chris\Downloads\jbgu6vr6.exe[4808] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2A 00000000775e54c2 5 bytes JMP 0000000100240c0c .text C:\Users\chris\Downloads\jbgu6vr6.exe[4808] C:\Windows\SysWOW64\sechost.dll!ChangeServiceConfig2W 00000000775e55e2 5 bytes JMP 0000000100240e10 .text C:\Users\chris\Downloads\jbgu6vr6.exe[4808] C:\Windows\SysWOW64\sechost.dll!CreateServiceA 00000000775e567c 5 bytes JMP 00000001002401f8 .text C:\Users\chris\Downloads\jbgu6vr6.exe[4808] C:\Windows\SysWOW64\sechost.dll!CreateServiceW 00000000775e589f 5 bytes JMP 00000001002403fc .text C:\Users\chris\Downloads\jbgu6vr6.exe[4808] C:\Windows\SysWOW64\sechost.dll!DeleteService 00000000775e5a22 5 bytes JMP 0000000100240600 .text C:\Users\chris\Downloads\jbgu6vr6.exe[4808] C:\Windows\syswow64\USER32.dll!SetWinEventHook 0000000076ecee09 5 bytes JMP 00000001002501f8 .text C:\Users\chris\Downloads\jbgu6vr6.exe[4808] C:\Windows\syswow64\USER32.dll!UnhookWinEvent 0000000076ed3982 5 bytes JMP 00000001002503fc .text C:\Users\chris\Downloads\jbgu6vr6.exe[4808] C:\Windows\syswow64\USER32.dll!SetWindowsHookExW 0000000076ed7603 5 bytes JMP 0000000100250804 .text C:\Users\chris\Downloads\jbgu6vr6.exe[4808] C:\Windows\syswow64\USER32.dll!SetWindowsHookExA 0000000076ed835c 5 bytes JMP 0000000100250600 .text C:\Users\chris\Downloads\jbgu6vr6.exe[4808] C:\Windows\syswow64\USER32.dll!UnhookWindowsHookEx 0000000076eef52b 5 bytes JMP 0000000100250a08 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Type 2 Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Start 2 Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@DisplayName aswFsBlk Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Group FSFilter Activity Monitor Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@DependOnService FltMgr? Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Description avast! mini-filter driver (aswFsBlk) Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk@Tag 3 Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances@DefaultInstance aswFsBlk Instance Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances\aswFsBlk Instance Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances\aswFsBlk Instance@Altitude 388400 Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk\Instances\aswFsBlk Instance@Flags 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswFsBlk Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Type 2 Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Start 2 Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@ImagePath \??\C:\Windows\system32\drivers\aswMonFlt.sys Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@DisplayName aswMonFlt Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Group FSFilter Anti-Virus Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@DependOnService FltMgr? Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt@Description avast! mini-filter driver (aswMonFlt) Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances@DefaultInstance aswMonFlt Instance Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances\aswMonFlt Instance Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances\aswMonFlt Instance@Altitude 320700 Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt\Instances\aswMonFlt Instance@Flags 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswMonFlt Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@ImagePath \SystemRoot\System32\Drivers\aswrdr2.sys Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Type 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Start 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@DisplayName aswRdr Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Group PNP_TDI Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@DependOnService tcpip? Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr@Description avast! WFP Redirect driver Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr\Parameters Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr\Parameters@MSIgnoreLSPDefault Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr\Parameters@WSIgnoreLSPDefault nl_lsp.dll,imon.dll,xfire_lsp.dll,mslsp.dll,mssplsp.dll,cwhook.dll,spi.dll,bmnet.dll,winsflt.dll Reg HKLM\SYSTEM\CurrentControlSet\services\aswRdr Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@Type 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@Start 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@DisplayName aswRvrt Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt@Description avast! Revert Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@BootCounter 61 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@TickCounter 10681448 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@SystemRoot \Device\Harddisk0\Partition2\Windows Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt\Parameters@ImproperShutdown 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswRvrt Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Type 2 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Start 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@DisplayName aswSnx Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Group FSFilter Virtualization Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@DependOnService FltMgr? Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Description avast! virtualization driver (aswSnx) Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx@Tag 2 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances@DefaultInstance aswSnx Instance Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances\aswSnx Instance Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances\aswSnx Instance@Altitude 137600 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Instances\aswSnx Instance@Flags 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Parameters Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Parameters@ProgramFolder \DosDevices\C:\Program Files\AVAST Software\Avast Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx\Parameters@DataFolder \DosDevices\C:\ProgramData\AVAST Software\Avast Reg HKLM\SYSTEM\CurrentControlSet\services\aswSnx Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP@Type 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP@Start 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP@DisplayName aswSP Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP@Description avast! Self Protection Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@BehavShield 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@ProgramFolder \DosDevices\C:\Program Files\AVAST Software\Avast Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@DataFolder \DosDevices\C:\ProgramData\AVAST Software\Avast Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@ProgramFilesFolder \DosDevices\C:\Program Files Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@GadgetFolder \DosDevices\C:\Program Files\Windows Sidebar\Shared Gadgets\aswSidebar.gadget Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP\Parameters@NoWelcomeScreen 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswSP Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Type 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Start 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@DisplayName avast! Network Shield Support Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Group PNP_TDI Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@DependOnService tcpip? Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Description avast! Network Shield TDI driver Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi@Tag 10 Reg HKLM\SYSTEM\CurrentControlSet\services\aswTdi Reg HKLM\SYSTEM\CurrentControlSet\services\aswVmm@Type 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswVmm@Start 0 Reg HKLM\SYSTEM\CurrentControlSet\services\aswVmm@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\aswVmm@DisplayName aswVmm Reg HKLM\SYSTEM\CurrentControlSet\services\aswVmm@Description avast! VM Monitor Reg HKLM\SYSTEM\CurrentControlSet\services\aswVmm\Parameters Reg HKLM\SYSTEM\CurrentControlSet\services\aswVmm Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Type 32 Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Start 2 Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ErrorControl 1 Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ImagePath "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@DisplayName avast! Antivirus Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Group ShellSvcGroup Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@DependOnService aswMonFlt?RpcSS? Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@WOW64 1 Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ObjectName LocalSystem Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@ServiceSidType 1 Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus@Description Verwaltet und implementiert avast! Antivirus-Dienste f?r diesen Computer. Dies beinhaltet den Echtzeit-Schutz, den Virus-Container und den Planer. Reg HKLM\SYSTEM\CurrentControlSet\services\avast! Antivirus Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\bc773703c1b7 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\bc77370e75c6 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\bc77370e75c6@60a10a188888 0xA6 0xCD 0x95 0x87 ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\bc77370e75c6@002646daaa30 0xB9 0xD5 0xD5 0xAD ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\bc77370e75c6@38ece48406aa 0x83 0x91 0x78 0x95 ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\bc77370e75c6@0c1420885ea6 0xD7 0x86 0xD6 0x5B ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\bc77370e75c6@fe7b46662871 0xCC 0x64 0x48 0x1B ... Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\bc77370e75c6@b85e7b123922 0xD1 0x10 0xF9 0x47 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\ Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xCC 0xBA 0xB4 0x77 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xE5 0xA6 0xF5 0x32 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x59 0xB4 0x07 0xD5 ... Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Type 2 Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Start 2 Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@DisplayName aswFsBlk Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Group FSFilter Activity Monitor Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@DependOnService FltMgr? Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Description avast! mini-filter driver (aswFsBlk) Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk@Tag 3 Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances@DefaultInstance aswFsBlk Instance Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances\aswFsBlk Instance (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances\aswFsBlk Instance@Altitude 388400 Reg HKLM\SYSTEM\ControlSet002\services\aswFsBlk\Instances\aswFsBlk Instance@Flags 0 Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Type 2 Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Start 2 Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@ImagePath \??\C:\Windows\system32\drivers\aswMonFlt.sys Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@DisplayName aswMonFlt Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Group FSFilter Anti-Virus Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@DependOnService FltMgr? Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt@Description avast! mini-filter driver (aswMonFlt) Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances@DefaultInstance aswMonFlt Instance Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances\aswMonFlt Instance (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances\aswMonFlt Instance@Altitude 320700 Reg HKLM\SYSTEM\ControlSet002\services\aswMonFlt\Instances\aswMonFlt Instance@Flags 0 Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@ImagePath \SystemRoot\System32\Drivers\aswrdr2.sys Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@Type 1 Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@Start 1 Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@DisplayName aswRdr Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@Group PNP_TDI Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@DependOnService tcpip? Reg HKLM\SYSTEM\ControlSet002\services\aswRdr@Description avast! WFP Redirect driver Reg HKLM\SYSTEM\ControlSet002\services\aswRdr\Parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswRdr\Parameters@MSIgnoreLSPDefault Reg HKLM\SYSTEM\ControlSet002\services\aswRdr\Parameters@WSIgnoreLSPDefault nl_lsp.dll,imon.dll,xfire_lsp.dll,mslsp.dll,mssplsp.dll,cwhook.dll,spi.dll,bmnet.dll,winsflt.dll Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt@Type 1 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt@Start 0 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt@DisplayName aswRvrt Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt@Description avast! Revert Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@BootCounter 61 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@TickCounter 10681448 Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@SystemRoot \Device\Harddisk0\Partition2\Windows Reg HKLM\SYSTEM\ControlSet002\services\aswRvrt\Parameters@ImproperShutdown 1 Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@Type 2 Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@Start 1 Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@DisplayName aswSnx Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@Group FSFilter Virtualization Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@DependOnService FltMgr? Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@Description avast! virtualization driver (aswSnx) Reg HKLM\SYSTEM\ControlSet002\services\aswSnx@Tag 2 Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances@DefaultInstance aswSnx Instance Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances\aswSnx Instance (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances\aswSnx Instance@Altitude 137600 Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Instances\aswSnx Instance@Flags 0 Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Parameters@ProgramFolder \DosDevices\C:\Program Files\AVAST Software\Avast Reg HKLM\SYSTEM\ControlSet002\services\aswSnx\Parameters@DataFolder \DosDevices\C:\ProgramData\AVAST Software\Avast Reg HKLM\SYSTEM\ControlSet002\services\aswSP@Type 1 Reg HKLM\SYSTEM\ControlSet002\services\aswSP@Start 1 Reg HKLM\SYSTEM\ControlSet002\services\aswSP@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswSP@DisplayName aswSP Reg HKLM\SYSTEM\ControlSet002\services\aswSP@Description avast! Self Protection Reg HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@BehavShield 1 Reg HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@ProgramFolder \DosDevices\C:\Program Files\AVAST Software\Avast Reg HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@DataFolder \DosDevices\C:\ProgramData\AVAST Software\Avast Reg HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@ProgramFilesFolder \DosDevices\C:\Program Files Reg HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@GadgetFolder \DosDevices\C:\Program Files\Windows Sidebar\Shared Gadgets\aswSidebar.gadget Reg HKLM\SYSTEM\ControlSet002\services\aswSP\Parameters@NoWelcomeScreen 1 Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@Type 1 Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@Start 1 Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@DisplayName avast! Network Shield Support Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@Group PNP_TDI Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@DependOnService tcpip? Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@Description avast! Network Shield TDI driver Reg HKLM\SYSTEM\ControlSet002\services\aswTdi@Tag 10 Reg HKLM\SYSTEM\ControlSet002\services\aswVmm@Type 1 Reg HKLM\SYSTEM\ControlSet002\services\aswVmm@Start 0 Reg HKLM\SYSTEM\ControlSet002\services\aswVmm@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\aswVmm@DisplayName aswVmm Reg HKLM\SYSTEM\ControlSet002\services\aswVmm@Description avast! VM Monitor Reg HKLM\SYSTEM\ControlSet002\services\aswVmm\Parameters (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Type 32 Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Start 2 Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ErrorControl 1 Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ImagePath "C:\Program Files\AVAST Software\Avast\AvastSvc.exe" Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@DisplayName avast! Antivirus Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Group ShellSvcGroup Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@DependOnService aswMonFlt?RpcSS? Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@WOW64 1 Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ObjectName LocalSystem Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@ServiceSidType 1 Reg HKLM\SYSTEM\ControlSet002\services\avast! Antivirus@Description Verwaltet und implementiert avast! Antivirus-Dienste f?r diesen Computer. Dies beinhaltet den Echtzeit-Schutz, den Virus-Container und den Planer. Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\bc773703c1b7 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\bc77370e75c6 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\bc77370e75c6@60a10a188888 0xA6 0xCD 0x95 0x87 ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\bc77370e75c6@002646daaa30 0xB9 0xD5 0xD5 0xAD ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\bc77370e75c6@38ece48406aa 0x83 0x91 0x78 0x95 ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\bc77370e75c6@0c1420885ea6 0xD7 0x86 0xD6 0x5B ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\bc77370e75c6@fe7b46662871 0xCC 0x64 0x48 0x1B ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\bc77370e75c6@b85e7b123922 0xD1 0x10 0xF9 0x47 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xCC 0xBA 0xB4 0x77 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xE5 0xA6 0xF5 0x32 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x59 0xB4 0x07 0xD5 ... ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ---- |
10.12.2013, 21:56 | #3 |
/// Winkelfunktion /// TB-Süch-Tiger™ | win 7 64 avast meldet bösartige URLS Hallo und
__________________Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten! Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht! Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
Themen zu win 7 64 avast meldet bösartige URLS |
adblock, antivirus, bonjour, computer, converter, desktop, dvdvideosoft ltd., email, error, excel, fehler, firefox, flash player, helper, home, homepage, mp3, plug-in, problem, registry, richtlinie, scan, security, server, software, svchost.exe, system, tracker, vista, windows |