![]() |
|
Log-Analyse und Auswertung: Windows 8.1 64-Bit: BKA-Trojaner ohne SperrschirmWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() Windows 8.1 64-Bit: BKA-Trojaner ohne Sperrschirm Hallo an alle, vor kurzem hat mir mein kleiner Bruder offenbart, dass sich mein PC einen BKA-Trojaner eingefangen hätte, nachdem er auf bestimmte Seiten war...Da der PC aber keinen Sperrschirm hat, sondern ganz normal bootet, wollte er mir das anfänglich nicht sagen. Aus diesem Grund kann ich leider nicht genau sagen, wann sich mein PC den BKA-Trojaner eingefangen hat; zumal ich ihn selbst auch nicht gesehen habe, sondern auf die Aussage meines Bruders vertraue. Beim GMER-Scan kam es zu folgendem Vorfall: Beim Öffnen von GMER (also noch vor dem Scannen) öffnete sich ein Fenster mit folgendem Inhalt: C:\WINDOWS\system32\config\system: Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird. Kurz vor Schluss des Scans kam dieses Fenster erneut und nachdem ich auf OK geklickt hatte (man konnte nur auf OK klicken), öffnete sich ein weiteres Fenster mit folgendem Inhalt: C:\Users\Anki\ntuser.dat: Der Prozess kann nicht auf die Datei zugreifen, da sie von einem anderen Prozess verwendet wird. Ich hoffe, ihr könnt mir helfen und bedanke mich herzlich schon mal im Voraus!!! Nachfolgend meine Logfiles: defogger_disable.txt Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 18:24 on 27/01/2015 (Anki) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-01-2015 01 Ran by Anki at 2015-01-27 18:28:09 Running from C:\Users\Anki\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Avira (HKLM-x32\...\{e7c7c227-b742-4878-9425-f09bbf9951db}) (Version: 1.1.27.25527 - Avira Operations & Co. KG) Avira (x32 Version: 1.1.27.25527 - Avira Operations & Co. KG) Hidden Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.7.468 - Avira) Citavi 4 (HKLM-x32\...\{CC0A85B2-734A-45B3-B678-05F6A6499AC7}) (Version: 4.2.0.11 - Swiss Academic Software) CyberLink PowerDVD 10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.4427.02 - CyberLink Corp.) DriverUpdate (HKLM-x32\...\{6FF69967-0BFE-4F14-B6DF-E73783E52340}) (Version: 2.2.36428 - SlimWare Utilities, Inc.) ELAN 4.7.3 (HKLM-x32\...\ELAN 4.7.3) (Version: 4.7.3.0 - MPI - The Language Archive) Free YouTube Download version 3.2.46.923 (HKLM-x32\...\Free YouTube Download_is1) (Version: 3.2.46.923 - DVDVideoSoft Ltd.) Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.9.234 - SurfRight B.V.) HitmanPro.Alert (HKLM\...\HitmanPro.Alert) (Version: 2.6.5.77 - SurfRight B.V.) HP Deskjet 2510 series - Grundlegende Software für das Gerät (HKLM\...\{288614B1-F070-4B47-A1F5-4790BD8A3176}) (Version: 28.0.1313.0 - Hewlett-Packard Co.) HP Deskjet 2510 series Hilfe (HKLM-x32\...\{07B48D2C-E60D-41E6-B546-11D128F633EC}) (Version: 27.0.0 - Hewlett Packard) HP Deskjet 2510 series Setup Guide (HKLM-x32\...\{216C7F38-4BBC-4E9A-8392-C9FA21B54386}) (Version: 27.0.0 - Hewlett Packard) HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP) HP Support Solutions Framework (HKLM-x32\...\{96D12EC9-720B-45FB-904C-36D6307A1C76}) (Version: 11.51.0048 - Hewlett-Packard Company) HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard) HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1323 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3347 - Intel Corporation) Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation) Intel(R) Update Manager (HKLM-x32\...\{12914061-EB9B-4AE7-AC7E-0B8A607C7DF4}) (Version: 2.3.1338 - Intel Corporation) Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 35.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 34.0.5 - Mozilla) MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.6.9 - Notepad++ Team) OpenOffice 4.1.1 (HKLM-x32\...\{ACD0FFF9-6B35-43C1-82DB-9FF6990E8602}) (Version: 4.11.9775 - Apache Software Foundation) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.15.410.2013 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6873 - Realtek Semiconductor Corp.) Secunia PSI (3.0.0.9015) (HKLM-x32\...\Secunia PSI) (Version: 3.0.0.9015 - Secunia) SpywareBlaster 5.0 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC) Studie zur Verbesserung von HP Deskjet 2510 series Produkten (HKLM\...\{96EFECB7-6359-4D6A-B3FE-4A3CE0B6444F}) (Version: 28.0.1313.0 - Hewlett-Packard Co.) WEB.DE MailCheck für Mozilla Firefox (HKLM-x32\...\1&1 Mail & Media GmbH Toolbar FF) (Version: 2.10.1.1735 - 1&1 Mail & Media GmbH) WinPatrol (HKLM\...\{84481A87-2316-4923-8FAB-3BA8CA29323D}) (Version: 29.1.2013 - BillP Studios) WOT für Internet Explorer (HKLM\...\{373B90E1-A28C-434C-92B6-7281AFA6115A}) (Version: 13.9.2.0 - WOT Services Oy) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 03-01-2015 13:45:55 Geplanter Prüfpunkt 14-01-2015 18:39:22 Windows Update 20-01-2015 14:54:20 Prüfpunkt von HitmanPro ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {1E741F7F-FF46-4F0C-83EC-F1D5D836F322} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-26] (Google Inc.) Task: {35B5CC35-4D5C-4484-AA4C-9C922D9549EE} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-25] (Adobe Systems Incorporated) Task: {3E3030C9-F54D-4A5F-ACB0-04ABDE25AB8E} - System32\Tasks\HPCustParticipation HP Deskjet 2510 series => C:\Program Files\HP\HP Deskjet 2510 series\Bin\HPCustPartic.exe [2012-10-02] (Hewlett-Packard Co.) Task: {43115A55-C6E3-4E42-9A0E-D9B7BB55143D} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] () Task: {452F55FF-EA48-4726-9CF3-BB82AB736C13} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-02-28] () Task: {6C9E632F-A341-45E9-8F46-A3400B0A7DF0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-03-26] (Google Inc.) Task: {C8346E19-9DA9-4E49-BD16-E918DEFB4E01} - System32\Tasks\DriverUpdate Startup => C:\Program Files (x86)\DriverUpdate\DriverUpdate.exe [2014-02-26] (SlimWare Utilities, Inc.) Task: {F3DBB4E1-27C6-41A3-94AA-6BAA201472FC} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\DriverUpdate Startup.job => C:\Program Files (x86)\DriverUpdate\DriverUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-01-29 23:02 - 2014-01-29 23:02 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2013-07-01 06:24 - 2013-03-12 12:20 - 01199576 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2015-01-26 18:29 - 2015-01-26 18:29 - 03925104 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2013-11-07 18:30 - 2013-07-17 23:56 - 00430080 _____ () C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox\components\FirefoxPickerCommunication.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\Temp:5C321E34 AlternateDataStreams: C:\Users\Anki\SkyDrive:ms-properties AlternateDataStreams: C:\Users\Anki\Downloads\Re_Dropbox_Konferenz_Fachschaft_und_Werwolf.eml:OECustomProperty ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-2076012648-3723097027-4092154972-500 - Administrator - Disabled) Anki (S-1-5-21-2076012648-3723097027-4092154972-1001 - Administrator - Enabled) => C:\Users\Anki Gast (S-1-5-21-2076012648-3723097027-4092154972-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2076012648-3723097027-4092154972-1005 - Limited - Enabled) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (01/27/2015 06:24:24 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (01/26/2015 06:36:52 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (01/25/2015 00:22:08 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (01/24/2015 10:27:58 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (01/23/2015 11:59:50 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (01/22/2015 04:12:39 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (01/21/2015 05:31:47 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (01/20/2015 02:54:19 PM) (Source: VSS) (EventID: 8194) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert . Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {cad68e09-c443-4f50-beac-e31e5d44dd7d} Error: (01/20/2015 00:22:24 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (01/20/2015 11:37:55 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 System errors: ============= Error: (01/27/2015 05:59:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "AppX-Bereitstellungsdienst (AppXSVC)" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (01/27/2015 05:59:52 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst AppX-Bereitstellungsdienst (AppXSVC) erreicht. Error: (01/27/2015 05:58:17 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "AppX-Bereitstellungsdienst (AppXSVC)" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (01/27/2015 05:58:17 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst AppX-Bereitstellungsdienst (AppXSVC) erreicht. Error: (01/26/2015 07:57:35 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Software Protection" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (01/26/2015 07:57:35 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Software Protection erreicht. Error: (01/26/2015 07:08:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Software Protection" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (01/26/2015 07:08:52 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Software Protection erreicht. Error: (01/26/2015 06:16:08 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Software Protection" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (01/26/2015 06:16:08 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Software Protection erreicht. Microsoft Office Sessions: ========================= Error: (01/27/2015 06:24:24 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (01/26/2015 06:36:52 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (01/25/2015 00:22:08 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (01/24/2015 10:27:58 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (01/23/2015 11:59:50 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (01/22/2015 04:12:39 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (01/21/2015 05:31:47 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (01/20/2015 02:54:19 PM) (Source: VSS) (EventID: 8194) (User: ) Description: 0x80070005, Zugriff verweigert Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {cad68e09-c443-4f50-beac-e31e5d44dd7d} Error: (01/20/2015 00:22:24 PM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 Error: (01/20/2015 11:37:55 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: ) Description: 80070005 CodeIntegrity Errors: =================================== Date: 2015-01-27 18:25:27.706 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\hmpalert.dll because the set of per-page image hashes could not be found on the system. Date: 2015-01-27 18:23:07.815 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\hmpalert.dll because the set of per-page image hashes could not be found on the system. Date: 2015-01-27 18:12:50.772 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\hmpalert.dll because the set of per-page image hashes could not be found on the system. Date: 2015-01-27 18:02:37.721 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\hmpalert.dll because the set of per-page image hashes could not be found on the system. Date: 2015-01-27 18:00:27.789 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\hmpalert.dll that did not meet the Windows signing level requirements. Date: 2015-01-27 18:00:27.633 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\hmpalert.dll that did not meet the Windows signing level requirements. Date: 2015-01-27 18:00:27.601 Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\hmpalert.dll that did not meet the Windows signing level requirements. Date: 2015-01-27 17:55:27.762 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\hmpalert.dll because the set of per-page image hashes could not be found on the system. Date: 2015-01-27 17:55:27.559 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\hmpalert.dll because the set of per-page image hashes could not be found on the system. Date: 2015-01-26 19:26:57.527 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\hmpalert.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Celeron(R) CPU 847 @ 1.10GHz Percentage of memory in use: 37% Total physical RAM: 3977.24 MB Available physical RAM: 2501.1 MB Total Pagefile: 4681.24 MB Available Pagefile: 2895.77 MB Total Virtual: 131072 MB Available Virtual: 131071.79 MB ==================== Drives ================================ Drive c: (Windows) (Fixed) (Total:450.25 GB) (Free:400.97 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: C2BF21B2) Partition: GPT Partition Type. ==================== End Of Log ============================ Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-01-2015 01 Ran by Anki (administrator) on NIKIANNA on 27-01-2015 18:26:41 Running from C:\Users\Anki\Downloads Loaded Profiles: Anki (Available profiles: Anki) Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (SurfRight B.V.) C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe (SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Hewlett-Packard Company) C:\Program Files (x86)\HP\Common\HPSupportSolutionsFrameworkService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (SlimWare Utilities, Inc.) C:\Program Files (x86)\DriverUpdate\DriverUpdate.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7174728 2013-04-11] (Realtek Semiconductor) HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [93296 2012-07-13] (CyberLink Corp.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-16] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2076012648-3723097027-4092154972-1001\...\MountPoints2: {d63a24ff-6bc1-11e4-be9d-d43d7edf8fa5} - "E:\LGAutoRun.exe" HKU\S-1-5-21-2076012648-3723097027-4092154972-1001\...\MountPoints2: {d63a3a46-6bc1-11e4-be9d-d43d7edf8fa5} - "F:\LGAutoRun.exe" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-2076012648-3723097027-4092154972-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-21-2076012648-3723097027-4092154972-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.hyrican.de HKU\S-1-5-21-2076012648-3723097027-4092154972-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.hyrican.de SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = SearchScopes: HKU\S-1-5-21-2076012648-3723097027-4092154972-1001 -> URL hxxp://www.trovigo.com/Results.aspx?gd=&ctid=CT3319434&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SPC3551D08-851A-4D6D-94EC-6403B2560D3E&q={searchTerms}&SSPV= SearchScopes: HKU\S-1-5-21-2076012648-3723097027-4092154972-1001 -> SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms} BHO: WOT Helper -> {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} -> C:\Program Files\WOT\WOT.dll () BHO-x32: Citavi Picker -> {609D670F-B735-4da7-AC6D-F3BD358E325E} -> C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: WOT Helper -> {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} -> C:\Program Files (x86)\WOT\WOT.dll () Toolbar: HKLM - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll () Toolbar: HKLM-x32 - WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files (x86)\WOT\WOT.dll () Toolbar: HKU\S-1-5-21-2076012648-3723097027-4092154972-1001 -> No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File Toolbar: HKU\S-1-5-21-2076012648-3723097027-4092154972-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Toolbar: HKU\S-1-5-21-2076012648-3723097027-4092154972-1001 -> WOT - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll () Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll () Handler-x32: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files (x86)\WOT\WOT.dll () Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Anki\AppData\Roaming\Mozilla\Firefox\Profiles\tt8ti2ve.default FF NewTab: chrome://unitedtb/content/newtab/newtab-page.xhtml FF SelectedSearchEngine: Google FF Homepage: https://www.google.de/?gfe_rd=cr&ei=uyFIU5TaDYqh8wfroYHIBQ FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Anki\AppData\Roaming\Mozilla\Firefox\Profiles\tt8ti2ve.default\searchplugins\11-suche.xml FF SearchPlugin: C:\Users\Anki\AppData\Roaming\Mozilla\Firefox\Profiles\tt8ti2ve.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Anki\AppData\Roaming\Mozilla\Firefox\Profiles\tt8ti2ve.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Anki\AppData\Roaming\Mozilla\Firefox\Profiles\tt8ti2ve.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Anki\AppData\Roaming\Mozilla\Firefox\Profiles\tt8ti2ve.default\searchplugins\webde-suche.xml FF Extension: Avira Browser Safety - C:\Users\Anki\AppData\Roaming\Mozilla\Firefox\Profiles\tt8ti2ve.default\Extensions\abs@avira.com [2014-12-11] FF Extension: WEB.DE MailCheck - C:\Users\Anki\AppData\Roaming\Mozilla\Firefox\Profiles\tt8ti2ve.default\Extensions\toolbar@web.de [2014-12-18] FF Extension: WOT - C:\Users\Anki\AppData\Roaming\Mozilla\Firefox\Profiles\tt8ti2ve.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-12-02] FF Extension: NoScript - C:\Users\Anki\AppData\Roaming\Mozilla\Firefox\Profiles\tt8ti2ve.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-12-02] FF Extension: Adblock Plus - C:\Users\Anki\AppData\Roaming\Mozilla\Firefox\Profiles\tt8ti2ve.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-02] FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\{edd7fc99-d65c-4979-85c2-ddeed30c50c7} [2015-01-26] FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2013-11-07] Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-16] (Avira Operations GmbH & Co. KG) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG) R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [127752 2015-01-15] (SurfRight B.V.) R2 hmpalertsvc; C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1876816 2014-07-07] (SurfRight B.V.) R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89864 2014-12-11] (Hewlett-Packard Company) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-03-12] (Intel Corporation) S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1228504 2013-11-04] (Secunia) R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [660184 2013-11-04] (Secunia) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-14] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-14] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-12-02] (Avira Operations GmbH & Co. KG) R2 hmpalert; C:\Windows\System32\drivers\hmpalert.sys [93144 2014-07-07] () R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-27] (Malwarebytes Corporation) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-11-04] (Secunia) S3 SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [16152 2015-01-27] () S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-27 18:26 - 2015-01-27 18:27 - 00013671 _____ () C:\Users\Anki\Downloads\FRST.txt 2015-01-27 18:26 - 2015-01-27 18:26 - 00000000 ____D () C:\FRST 2015-01-27 18:25 - 2015-01-27 18:25 - 02129920 _____ (Farbar) C:\Users\Anki\Downloads\FRST64.exe 2015-01-27 18:23 - 2015-01-27 18:24 - 00000470 _____ () C:\Users\Anki\Downloads\defogger_disable.log 2015-01-27 18:23 - 2015-01-27 18:23 - 00000000 _____ () C:\Users\Anki\defogger_reenable 2015-01-27 18:22 - 2015-01-27 18:22 - 00050477 _____ () C:\Users\Anki\Downloads\Defogger.exe 2015-01-26 18:29 - 2015-01-26 18:29 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-01-25 19:13 - 2002-12-27 18:44 - 00535642 _____ () C:\Users\Anki\Desktop\V006.WAV 2015-01-14 20:58 - 2015-01-14 20:58 - 00000000 ____D () C:\WINDOWS\system32\appraiser 2015-01-14 17:29 - 2014-11-10 03:29 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupStatusProvider.dll 2015-01-14 17:29 - 2014-11-10 02:51 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceSetupStatusProvider.dll 2015-01-14 16:36 - 2014-12-04 00:37 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll 2015-01-14 16:36 - 2014-12-04 00:09 - 00830464 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2015-01-14 16:36 - 2014-12-03 00:09 - 01083392 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2015-01-14 16:36 - 2014-12-03 00:09 - 00740864 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll 2015-01-14 16:36 - 2014-12-03 00:09 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll 2015-01-14 16:36 - 2014-12-03 00:09 - 00396288 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2015-01-14 16:36 - 2014-12-03 00:09 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll 2015-01-14 16:36 - 2014-10-31 00:39 - 01970432 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll 2015-01-14 16:36 - 2014-10-31 00:38 - 01612992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll 2015-01-14 16:30 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2015-01-14 16:30 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2015-01-14 16:29 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll 2015-01-14 16:29 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2015-01-14 16:29 - 2014-11-22 03:49 - 00417280 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec 2015-01-14 16:29 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll 2015-01-14 16:29 - 2014-11-22 03:35 - 00812544 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2015-01-14 16:29 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2015-01-14 16:29 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2015-01-14 16:29 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll 2015-01-14 16:29 - 2014-11-22 03:06 - 00340992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec 2015-01-14 16:29 - 2014-11-22 03:06 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll 2015-01-14 16:29 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2015-01-14 16:29 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll 2015-01-14 16:29 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2015-01-14 16:29 - 2014-11-22 02:59 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll 2015-01-14 16:29 - 2014-11-22 02:55 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2015-01-14 16:29 - 2014-11-22 02:52 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll 2015-01-14 16:29 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2015-01-14 16:29 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2015-01-14 16:29 - 2014-11-22 02:49 - 00373760 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2015-01-14 16:29 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2015-01-14 16:29 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2015-01-14 16:29 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2015-01-14 16:29 - 2014-11-22 02:34 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll 2015-01-14 16:29 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2015-01-14 16:29 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2015-01-14 16:29 - 2014-11-22 02:29 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll 2015-01-14 16:29 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2015-01-14 16:29 - 2014-11-22 02:25 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll 2015-01-14 16:29 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2015-01-14 16:29 - 2014-11-22 02:23 - 00326656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2015-01-14 16:29 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2015-01-14 16:29 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2015-01-14 16:29 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2015-01-14 16:29 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2015-01-14 16:29 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2015-01-14 16:29 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2015-01-14 16:29 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2015-01-14 16:29 - 2014-11-07 05:16 - 01762840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll 2015-01-14 16:29 - 2014-11-07 04:26 - 01489072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll 2015-01-14 16:29 - 2014-11-01 00:57 - 01091072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll 2015-01-14 16:29 - 2014-11-01 00:47 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll 2015-01-14 16:29 - 2014-10-13 03:43 - 00238912 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys 2015-01-14 16:29 - 2014-10-13 03:43 - 00153920 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys 2015-01-14 16:29 - 2014-10-13 03:43 - 00086336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys 2015-01-14 16:29 - 2014-10-13 03:43 - 00039744 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys 2015-01-14 16:28 - 2014-10-30 23:37 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe 2015-01-14 16:28 - 2014-10-30 23:34 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe 2015-01-11 18:18 - 2015-01-11 18:18 - 00000000 ____D () C:\Program Files (x86)\Hewlett-Packard 2015-01-06 16:36 - 2015-01-06 16:36 - 06015907 _____ () C:\Users\Anki\Downloads\dict-en(3).oxt 2015-01-03 16:21 - 2015-01-04 11:37 - 00024534 _____ () C:\Users\Anki\Desktop\DSA06N.odt ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-27 18:23 - 2014-02-13 19:26 - 00000000 ____D () C:\Users\Anki 2015-01-27 18:22 - 2014-02-13 19:43 - 01681732 _____ () C:\WINDOWS\WindowsUpdate.log 2015-01-27 18:18 - 2014-09-09 19:37 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-01-27 18:02 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2015-01-27 18:01 - 2014-07-07 20:10 - 00000000 ____D () C:\WINDOWS\CryptoGuard 2015-01-27 18:01 - 2014-03-19 11:29 - 00003926 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{825A1576-B4D6-4017-855C-DA81E86AC85C} 2015-01-27 17:57 - 2014-06-25 16:34 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys 2015-01-27 17:57 - 2014-06-22 17:27 - 00000434 _____ () C:\WINDOWS\Tasks\DriverUpdate Startup.job 2015-01-27 17:56 - 2013-10-23 01:44 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-01-27 17:55 - 2014-06-22 17:27 - 00016152 _____ () C:\WINDOWS\system32\Drivers\SWDUMon.sys 2015-01-27 17:55 - 2014-03-26 23:57 - 00001132 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-26 19:40 - 2014-03-26 23:57 - 00001136 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-01-26 18:12 - 2013-11-14 08:27 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2015-01-26 18:12 - 2013-11-14 08:11 - 00764340 _____ () C:\WINDOWS\system32\perfh007.dat 2015-01-26 18:12 - 2013-11-14 08:11 - 00159160 _____ () C:\WINDOWS\system32\perfc007.dat 2015-01-25 17:49 - 2013-11-25 20:12 - 00229888 ___SH () C:\Users\Anki\Documents\Thumbs.db 2015-01-25 12:18 - 2014-09-09 19:37 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2015-01-25 12:05 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2015-01-23 07:13 - 2014-02-27 19:39 - 00315392 ___SH () C:\Users\Anki\Downloads\Thumbs.db 2015-01-18 17:33 - 2013-10-18 17:27 - 00000000 ____D () C:\Users\Anki\AppData\Roaming\HpUpdate 2015-01-15 19:26 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache 2015-01-15 08:04 - 2013-08-22 15:44 - 00422536 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2015-01-15 08:03 - 2013-11-13 23:18 - 00072932 _____ () C:\WINDOWS\PFRO.log 2015-01-14 21:00 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2015-01-14 20:58 - 2014-07-22 15:47 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel 2015-01-14 20:58 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sr-Latn-RS 2015-01-14 20:58 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sr-Latn-CS 2015-01-14 20:58 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\PolicyDefinitions 2015-01-14 18:48 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp 2015-01-14 16:21 - 2013-12-28 16:03 - 01452032 ___SH () C:\Users\Anki\Desktop\Thumbs.db 2015-01-03 22:04 - 2013-08-22 15:46 - 00294865 _____ () C:\WINDOWS\setupact.log 2014-12-29 08:13 - 2013-10-23 01:47 - 00000000 ____D () C:\Users\Anki\AppData\Local\Adobe ==================== Files in the root of some directories ======= 2013-12-02 18:07 - 2014-04-13 07:13 - 0001002 _____ () C:\Users\Anki\AppData\Local\Citavi Picker Internet Explorer Protocol.txt 2013-10-18 17:26 - 2013-10-18 17:26 - 0000057 _____ () C:\ProgramData\Ament.ini Some content of TEMP: ==================== C:\Users\Anki\AppData\Local\Temp\avgnt.exe C:\Users\Anki\AppData\Local\Temp\DseShExt-x64.dll C:\Users\Anki\AppData\Local\Temp\DseShExt-x86.dll C:\Users\Anki\AppData\Local\Temp\npp.6.6.9.Installer.exe C:\Users\Anki\AppData\Local\Temp\SDShelEx-win32.dll C:\Users\Anki\AppData\Local\Temp\SDShelEx-x64.dll C:\Users\Anki\AppData\Local\Temp\tmd_34019194.exe C:\Users\Anki\AppData\Local\Temp\tmd_34019531.exe C:\Users\Anki\AppData\Local\Temp\xmlUpdater.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-25 12:48 ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2015-01-27 18:49:18 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000002a HGST_HTS545050A7E380 rev.GG2OAC90 465,76GB Running: Gmer-19357.exe; Driver: C:\Users\Anki\AppData\Local\Temp\ugrdqpod.sys ---- User code sections - GMER 2.1 ---- .text C:\WINDOWS\system32\svchost.exe[996] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 00007ffe063617f0 5 bytes JMP 00007fff062c0010 .text C:\WINDOWS\system32\svchost.exe[996] C:\WINDOWS\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00007ffe06361850 5 bytes JMP 00007fff062c0028 .text C:\WINDOWS\system32\svchost.exe[996] C:\WINDOWS\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00007ffe06361b70 5 bytes JMP 00007fff062c0040 .text C:\WINDOWS\System32\svchost.exe[432] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 00007ffe063617f0 5 bytes JMP 00007fff062c0010 .text C:\WINDOWS\System32\svchost.exe[432] C:\WINDOWS\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00007ffe06361850 5 bytes JMP 00007fff062c0028 .text C:\WINDOWS\System32\svchost.exe[432] C:\WINDOWS\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00007ffe06361b70 5 bytes JMP 00007fff062c0040 .text C:\WINDOWS\system32\svchost.exe[1008] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 00007ffe063617f0 5 bytes JMP 00007fff062c0010 .text C:\WINDOWS\system32\svchost.exe[1008] C:\WINDOWS\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00007ffe06361850 5 bytes JMP 00007fff062c0028 .text C:\WINDOWS\system32\svchost.exe[1008] C:\WINDOWS\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00007ffe06361b70 5 bytes JMP 00007fff062c0040 .text C:\WINDOWS\system32\WLANExt.exe[1076] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 00007ffe063617f0 5 bytes JMP 00007fff062c0010 .text C:\WINDOWS\system32\WLANExt.exe[1076] C:\WINDOWS\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00007ffe06361850 5 bytes JMP 00007fff062c0028 .text C:\WINDOWS\system32\WLANExt.exe[1076] C:\WINDOWS\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00007ffe06361b70 5 bytes JMP 00007fff062c0040 .text C:\WINDOWS\System32\spoolsv.exe[1204] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 00007ffe063617f0 5 bytes JMP 00007fff062c0010 .text C:\WINDOWS\System32\spoolsv.exe[1204] C:\WINDOWS\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00007ffe06361850 5 bytes JMP 00007fff062c0028 .text C:\WINDOWS\System32\spoolsv.exe[1204] C:\WINDOWS\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00007ffe06361b70 5 bytes JMP 00007fff062c0040 .text C:\WINDOWS\system32\svchost.exe[1260] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 00007ffe063617f0 5 bytes JMP 00007fff062c0010 .text C:\WINDOWS\system32\svchost.exe[1260] C:\WINDOWS\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00007ffe06361850 5 bytes JMP 00007fff062c0028 .text C:\WINDOWS\system32\svchost.exe[1260] C:\WINDOWS\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00007ffe06361b70 5 bytes JMP 00007fff062c0040 .text C:\WINDOWS\system32\SearchIndexer.exe[2600] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 00007ffe063617f0 5 bytes JMP 00007fff062c0010 .text C:\WINDOWS\system32\SearchIndexer.exe[2600] C:\WINDOWS\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00007ffe06361850 5 bytes JMP 00007fff062c0028 .text C:\WINDOWS\system32\SearchIndexer.exe[2600] C:\WINDOWS\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00007ffe06361b70 5 bytes JMP 00007fff062c0040 .text C:\WINDOWS\system32\svchost.exe[2584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 00007ffe063617f0 5 bytes JMP 00007fff062c0010 .text C:\WINDOWS\system32\svchost.exe[2584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00007ffe06361850 5 bytes JMP 00007fff062c0028 .text C:\WINDOWS\system32\svchost.exe[2584] C:\WINDOWS\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00007ffe06361b70 5 bytes JMP 00007fff062c0040 .text C:\Windows\System32\WUDFHost.exe[3188] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 00007ffe063617f0 5 bytes JMP 00007fff062c0010 .text C:\Windows\System32\WUDFHost.exe[3188] C:\WINDOWS\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00007ffe06361850 5 bytes JMP 00007fff062c0028 .text C:\Windows\System32\WUDFHost.exe[3188] C:\WINDOWS\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00007ffe06361b70 5 bytes JMP 00007fff062c0040 .text C:\WINDOWS\System32\svchost.exe[3548] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 00007ffe063617f0 5 bytes JMP 00007fff062c0010 .text C:\WINDOWS\System32\svchost.exe[3548] C:\WINDOWS\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00007ffe06361850 5 bytes JMP 00007fff062c0028 .text C:\WINDOWS\System32\svchost.exe[3548] C:\WINDOWS\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00007ffe06361b70 5 bytes JMP 00007fff062c0040 .text C:\WINDOWS\system32\dashost.exe[3604] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 00007ffe063617f0 5 bytes JMP 00007fff062c0010 .text C:\WINDOWS\system32\dashost.exe[3604] C:\WINDOWS\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00007ffe06361850 5 bytes JMP 00007fff062c0028 .text C:\WINDOWS\system32\dashost.exe[3604] C:\WINDOWS\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00007ffe06361b70 5 bytes JMP 00007fff062c0040 .text C:\WINDOWS\System32\WinLogon.exe[10952] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 00007ffe063617f0 5 bytes JMP 00007fff062c0010 .text C:\WINDOWS\System32\WinLogon.exe[10952] C:\WINDOWS\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00007ffe06361850 5 bytes JMP 00007fff062c0028 .text C:\WINDOWS\System32\WinLogon.exe[10952] C:\WINDOWS\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00007ffe06361b70 5 bytes JMP 00007fff062c0040 .text C:\WINDOWS\System32\dwm.exe[2256] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 00007ffe063617f0 5 bytes JMP 00007fff062c0010 .text C:\WINDOWS\System32\dwm.exe[2256] C:\WINDOWS\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00007ffe06361850 5 bytes JMP 00007fff062c0028 .text C:\WINDOWS\System32\dwm.exe[2256] C:\WINDOWS\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00007ffe06361b70 5 bytes JMP 00007fff062c0040 .text C:\WINDOWS\system32\taskhostex.exe[3952] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 00007ffe063617f0 5 bytes JMP 00007fff062c0010 .text C:\WINDOWS\system32\taskhostex.exe[3952] C:\WINDOWS\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00007ffe06361850 5 bytes JMP 00007fff062c0028 .text C:\WINDOWS\system32\taskhostex.exe[3952] C:\WINDOWS\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00007ffe06361b70 5 bytes JMP 00007fff062c0040 .text C:\WINDOWS\Explorer.EXE[8556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 00007ffe063617f0 5 bytes JMP 00007fff062c0010 .text C:\WINDOWS\Explorer.EXE[8556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00007ffe06361850 5 bytes JMP 00007fff062c0028 .text C:\WINDOWS\Explorer.EXE[8556] C:\WINDOWS\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00007ffe06361b70 5 bytes JMP 00007fff062c0040 .text C:\WINDOWS\system32\taskeng.exe[9176] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 00007ffe063617f0 5 bytes JMP 00007fff062c0010 .text C:\WINDOWS\system32\taskeng.exe[9176] C:\WINDOWS\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00007ffe06361850 5 bytes JMP 00007fff062c0028 .text C:\WINDOWS\system32\taskeng.exe[9176] C:\WINDOWS\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00007ffe06361b70 5 bytes JMP 00007fff062c0040 .text C:\Windows\System32\igfxtray.exe[9328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 00007ffe063617f0 5 bytes JMP 00007fff062c0010 .text C:\Windows\System32\igfxtray.exe[9328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00007ffe06361850 5 bytes JMP 00007fff062c0028 .text C:\Windows\System32\igfxtray.exe[9328] C:\WINDOWS\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00007ffe06361b70 5 bytes JMP 00007fff062c0040 .text C:\Windows\System32\hkcmd.exe[2500] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 00007ffe063617f0 5 bytes JMP 00007fff062c0010 .text C:\Windows\System32\hkcmd.exe[2500] C:\WINDOWS\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00007ffe06361850 5 bytes JMP 00007fff062c0028 .text C:\Windows\System32\hkcmd.exe[2500] C:\WINDOWS\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00007ffe06361b70 5 bytes JMP 00007fff062c0040 .text C:\Windows\System32\igfxpers.exe[844] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 00007ffe063617f0 5 bytes JMP 00007fff062c0010 .text C:\Windows\System32\igfxpers.exe[844] C:\WINDOWS\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00007ffe06361850 5 bytes JMP 00007fff062c0028 .text C:\Windows\System32\igfxpers.exe[844] C:\WINDOWS\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00007ffe06361b70 5 bytes JMP 00007fff062c0040 .text C:\Windows\System32\igfxpers.exe[844] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffe0447169a 4 bytes [47, 04, FE, 7F] .text C:\Windows\System32\igfxpers.exe[844] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffe044716a2 4 bytes [47, 04, FE, 7F] .text C:\Windows\System32\igfxpers.exe[844] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffe0447181a 4 bytes [47, 04, FE, 7F] .text C:\Windows\System32\igfxpers.exe[844] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffe04471832 4 bytes [47, 04, FE, 7F] .text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[7352] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 00007ffe063617f0 5 bytes JMP 00007fff062c0010 .text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[7352] C:\WINDOWS\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00007ffe06361850 5 bytes JMP 00007fff062c0028 .text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[7352] C:\WINDOWS\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00007ffe06361b70 5 bytes JMP 00007fff062c0040 .text C:\WINDOWS\system32\svchost.exe[11356] C:\WINDOWS\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 00007ffe063617f0 5 bytes JMP 00007fff062c0010 .text C:\WINDOWS\system32\svchost.exe[11356] C:\WINDOWS\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 00007ffe06361850 5 bytes JMP 00007fff062c0028 .text C:\WINDOWS\system32\svchost.exe[11356] C:\WINDOWS\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00007ffe06361b70 5 bytes JMP 00007fff062c0040 ---- Threads - GMER 2.1 ---- Thread C:\WINDOWS\system32\csrss.exe [9044:7652] fffff96000941b90 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ---- Code:
ATTFilter
|
Themen zu Windows 8.1 64-Bit: BKA-Trojaner ohne Sperrschirm |
adware, antivirus, avira, bestimmte seiten, browser, computer, cpu, defender, desktop, dvdvideosoft ltd., explorer, fehler, firefox, flash player, helper, homepage, internet, internet explorer, kaspersky, newtab, prozess, security, services.exe, software, svchost.exe, system, temp, windows |