defogger und gmer hier angefügt. Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 21:22 on 31/07/2012 (***)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=- Code:
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-07-31 21:55:11
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP4T0L0-6 WDC_WD6400AAKS-65A7B2 rev.01.03B01
Running: mvfjqsz8.exe; Driver: C:\Users\***\AppData\Local\Temp\pwdiypog.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0xA9A2B536]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0xAA71D7BA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAssignProcessToJobObject [0xA9A2BF52]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0xA9A36D7A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0xA9A36DC6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0xA9A36F48]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0xA9A36CE8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateSection [0xAA71DBAC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0xA9A36D30]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateThread [0xA9A2C146]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateThreadEx [0xA9A2C2CE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0xA9A36F02]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDebugActiveProcess [0xA9A2C8CA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0xA9A2B584]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0xAA71D89E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0xA9A2B1EC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0xA9A2B5D2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0xA9A302A8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0xA9A2D292]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0xA9A36DA4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0xA9A36DE8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0xA9A36F6C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0xA9A36D0E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0xA9A36E8C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0xA9A36D58]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0xA9A36F26]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0xAA71DA1E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0xA9A2D15E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueueApcThreadEx [0xA9A2CE9A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0xA9A2B620]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0xA9A2B66E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetContextThread [0xA9A2C74A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0xA9A2B276]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0xA9A2B426]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0xA9A2B3CC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSuspendProcess [0xA9A2CA2C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSuspendThread [0xA9A2CB88]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0xA9A2B496]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwTerminateProcess [0xAA71DAE8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwTerminateThread [0xA9A2C5CA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0xA9A2B6BC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwWriteVirtualMemory [0xAA71D954]
INT 0x52 ? 9E490A58
INT 0x62 ? 9E490558
INT 0x71 ? 9F73CA58
INT 0x72 ? 9E489558
INT 0x82 ? 9E4897D8
INT 0x91 ? 9F73CCD8
INT 0x92 ? 9E489A58
INT 0xA2 ? 9E4907D8
INT 0xB0 ? 9F73C7D8
INT 0xB1 ? 9E489CD8
INT 0xB3 ? 9E490058
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0xAA735744]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 140D E2E773C9 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 E2EB0D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10CB E2EB7D80 4 Bytes [36, B5, A2, A9]
.text ntkrnlpa.exe!KeRemoveQueueEx + 10F3 E2EB7DA8 4 Bytes [BA, D7, 71, AA]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1153 E2EB7E08 4 Bytes [52, BF, A2, A9]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11A7 E2EB7E5C 8 Bytes [7A, 6D, A3, A9, C6, 6D, A3, ...]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11B3 E2EB7E68 4 Bytes [48, 6F, A3, A9]
.text ...
PAGE ntkrnlpa.exe!ObMakeTemporaryObject E3044C64 5 Bytes JMP AA73261C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ObInsertObject + 27 E305D290 5 Bytes JMP AA734116 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 108 E30723D7 4 Bytes CALL A9A2D959 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 122 E308C1E0 4 Bytes CALL A9A2D96F \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx E311611A 7 Bytes JMP AA735748 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0xAAE31000, 0x3A3E05, 0xE8000020]
.text kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\Explorer.EXE[352] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Windows\Explorer.EXE[352] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Windows\Explorer.EXE[352] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\Explorer.EXE[352] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00110A08
.text C:\Windows\Explorer.EXE[352] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 001103FC
.text C:\Windows\Explorer.EXE[352] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00110804
.text C:\Windows\Explorer.EXE[352] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 001101F8
.text C:\Windows\Explorer.EXE[352] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00110600
.text C:\Windows\system32\csrss.exe[428] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[444] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[444] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[444] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[444] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00190A08
.text C:\Windows\system32\svchost.exe[444] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 001903FC
.text C:\Windows\system32\svchost.exe[444] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00190804
.text C:\Windows\system32\svchost.exe[444] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 001901F8
.text C:\Windows\system32\svchost.exe[444] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00190600
.text C:\Windows\system32\wininit.exe[508] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\system32\csrss.exe[516] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\system32\services.exe[556] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\system32\lsass.exe[580] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\system32\lsm.exe[588] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text ...
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1324] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000703FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1324] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000701F8
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1324] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1324] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00110A08
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1324] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 001103FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1324] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00110804
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1324] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 001101F8
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1324] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00110600
.text C:\Windows\system32\svchost.exe[1332] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1408] kernel32.dll!SetUnhandledExceptionFilter 761FF4FB 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }
.text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1408] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1492] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1492] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1492] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1492] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00110A08
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1492] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 001103FC
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1492] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00110804
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1492] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 001101F8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1492] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00110600
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[1536] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 001603FC
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[1536] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 001601F8
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[1536] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[1536] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 001F0A08
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[1536] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 001F03FC
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[1536] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 001F0804
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[1536] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 001F01F8
.text C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe[1536] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 001F0600
.text C:\Program Files\Bonjour\mDNSResponder.exe[1556] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Program Files\Bonjour\mDNSResponder.exe[1556] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Program Files\Bonjour\mDNSResponder.exe[1556] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1556] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00100A08
.text C:\Program Files\Bonjour\mDNSResponder.exe[1556] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 001003FC
.text C:\Program Files\Bonjour\mDNSResponder.exe[1556] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00100804
.text C:\Program Files\Bonjour\mDNSResponder.exe[1556] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 001001F8
.text C:\Program Files\Bonjour\mDNSResponder.exe[1556] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00100600
.text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1572] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1572] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1572] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1572] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00200A08
.text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1572] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 002003FC
.text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1572] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00200804
.text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1572] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 002001F8
.text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1572] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00200600
.text C:\Windows\system32\svchost.exe[1932] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1932] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1932] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1932] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00270A08
.text C:\Windows\system32\svchost.exe[1932] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 002703FC
.text C:\Windows\system32\svchost.exe[1932] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00270804
.text C:\Windows\system32\svchost.exe[1932] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 002701F8
.text C:\Windows\system32\svchost.exe[1932] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00270600
.text C:\Windows\System32\spoolsv.exe[2008] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000A03FC
.text C:\Windows\System32\spoolsv.exe[2008] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000A01F8
.text C:\Windows\System32\spoolsv.exe[2008] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\System32\spoolsv.exe[2008] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00150A08
.text C:\Windows\System32\spoolsv.exe[2008] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 001503FC
.text C:\Windows\System32\spoolsv.exe[2008] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00150804
.text C:\Windows\System32\spoolsv.exe[2008] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 001501F8
.text C:\Windows\System32\spoolsv.exe[2008] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00150600
.text C:\Windows\system32\taskhost.exe[2016] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000503FC
.text C:\Windows\system32\taskhost.exe[2016] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000501F8
.text C:\Windows\system32\taskhost.exe[2016] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\system32\taskhost.exe[2016] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00070A08
.text C:\Windows\system32\taskhost.exe[2016] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 000703FC
.text C:\Windows\system32\taskhost.exe[2016] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00070804
.text C:\Windows\system32\taskhost.exe[2016] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 000701F8
.text C:\Windows\system32\taskhost.exe[2016] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00070600
.text C:\Windows\system32\Dwm.exe[2024] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Windows\system32\Dwm.exe[2024] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Windows\system32\Dwm.exe[2024] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\system32\Dwm.exe[2024] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00080A08
.text C:\Windows\system32\Dwm.exe[2024] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 000803FC
.text C:\Windows\system32\Dwm.exe[2024] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00080804
.text C:\Windows\system32\Dwm.exe[2024] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 000801F8
.text C:\Windows\system32\Dwm.exe[2024] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00080600
.text C:\Windows\system32\FsUsbExService.Exe[2136] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 001503FC
.text C:\Windows\system32\FsUsbExService.Exe[2136] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 001501F8
.text C:\Windows\system32\FsUsbExService.Exe[2136] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\system32\FsUsbExService.Exe[2136] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 001E0A08
.text C:\Windows\system32\FsUsbExService.Exe[2136] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 001E03FC
.text C:\Windows\system32\FsUsbExService.Exe[2136] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 001E0804
.text C:\Windows\system32\FsUsbExService.Exe[2136] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 001E01F8
.text C:\Windows\system32\FsUsbExService.Exe[2136] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 001E0600
.text C:\Windows\system32\svchost.exe[2160] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[2160] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[2160] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\System32\svchost.exe[2188] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[2188] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[2188] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\System32\svchost.exe[2284] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[2284] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[2284] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\system32\PnkBstrA.exe[2312] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 001503FC
.text C:\Windows\system32\PnkBstrA.exe[2312] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 001501F8
.text C:\Windows\system32\PnkBstrA.exe[2312] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\system32\PnkBstrA.exe[2312] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00170A08
.text C:\Windows\system32\PnkBstrA.exe[2312] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 001703FC
.text C:\Windows\system32\PnkBstrA.exe[2312] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00170804
.text C:\Windows\system32\PnkBstrA.exe[2312] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 001701F8
.text C:\Windows\system32\PnkBstrA.exe[2312] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00170600
.text C:\Windows\system32\svchost.exe[2340] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[2340] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[2340] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[2640] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[2640] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[2640] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\system32\svchost.exe[2640] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 002B0A08
.text C:\Windows\system32\svchost.exe[2640] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 002B03FC
.text C:\Windows\system32\svchost.exe[2640] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 002B0804
.text C:\Windows\system32\svchost.exe[2640] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 002B01F8
.text C:\Windows\system32\svchost.exe[2640] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 002B0600
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2996] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2996] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2996] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2996] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00AB0A08
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2996] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 00AB03FC
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2996] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00AB0804
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2996] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 00AB01F8
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe[2996] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00AB0600
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3092] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3092] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3092] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3092] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00100A08
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3092] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 001003FC
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3092] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00100804
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3092] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 001001F8
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3092] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00100600
.text C:\Program Files\Alwil Software\Avast5\AvastUI.exe[3140] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3148] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 001603FC
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3148] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 001601F8
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3148] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3148] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 001F0A08
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3148] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 001F03FC
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3148] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 001F0804
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3148] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 001F01F8
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3148] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 001F0600
.text C:\Program Files\CM Storm\Spawn Gaming Mouse\Spawn_Icon.exe[3352] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 001503FC
.text C:\Program Files\CM Storm\Spawn Gaming Mouse\Spawn_Icon.exe[3352] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 001501F8
.text C:\Program Files\CM Storm\Spawn Gaming Mouse\Spawn_Icon.exe[3352] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Program Files\CM Storm\Spawn Gaming Mouse\Spawn_Icon.exe[3352] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00170A08
.text C:\Program Files\CM Storm\Spawn Gaming Mouse\Spawn_Icon.exe[3352] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 001703FC
.text C:\Program Files\CM Storm\Spawn Gaming Mouse\Spawn_Icon.exe[3352] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00170804
.text C:\Program Files\CM Storm\Spawn Gaming Mouse\Spawn_Icon.exe[3352] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 001701F8
.text C:\Program Files\CM Storm\Spawn Gaming Mouse\Spawn_Icon.exe[3352] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00170600
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3368] KERNEL32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Program Files\iTunes\iTunesHelper.exe[3376] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Program Files\iTunes\iTunesHelper.exe[3376] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Program Files\iTunes\iTunesHelper.exe[3376] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Program Files\iTunes\iTunesHelper.exe[3376] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00090A08
.text C:\Program Files\iTunes\iTunesHelper.exe[3376] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 000903FC
.text C:\Program Files\iTunes\iTunesHelper.exe[3376] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00090804
.text C:\Program Files\iTunes\iTunesHelper.exe[3376] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 000901F8
.text C:\Program Files\iTunes\iTunesHelper.exe[3376] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00090600
.text C:\Windows\system32\SearchIndexer.exe[3408] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Windows\system32\SearchIndexer.exe[3408] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Windows\system32\SearchIndexer.exe[3408] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\system32\SearchIndexer.exe[3408] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00100A08
.text C:\Windows\system32\SearchIndexer.exe[3408] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 001003FC
.text C:\Windows\system32\SearchIndexer.exe[3408] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00100804
.text C:\Windows\system32\SearchIndexer.exe[3408] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 001001F8
.text C:\Windows\system32\SearchIndexer.exe[3408] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00100600
.text C:\Windows\system32\wbem\wmiprvse.exe[3440] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Windows\system32\wbem\wmiprvse.exe[3440] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Windows\system32\wbem\wmiprvse.exe[3440] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\system32\wbem\wmiprvse.exe[3440] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00110A08
.text C:\Windows\system32\wbem\wmiprvse.exe[3440] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 001103FC
.text C:\Windows\system32\wbem\wmiprvse.exe[3440] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00110804
.text C:\Windows\system32\wbem\wmiprvse.exe[3440] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 001101F8
.text C:\Windows\system32\wbem\wmiprvse.exe[3440] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00110600
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3456] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 001703FC
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3456] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 001701F8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3456] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3456] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 001A0A08
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3456] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 001A03FC
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3456] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 001A0804
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3456] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 001A01F8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3456] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 001A0600
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3464] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3464] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3464] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3464] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00110A08
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3464] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 001103FC
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3464] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00110804
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3464] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 001101F8
.text C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe[3464] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00110600
.text C:\Program Files\Windows Sidebar\sidebar.exe[3476] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Program Files\Windows Sidebar\sidebar.exe[3476] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Program Files\Windows Sidebar\sidebar.exe[3476] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Program Files\Windows Sidebar\sidebar.exe[3476] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00120A08
.text C:\Program Files\Windows Sidebar\sidebar.exe[3476] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 001203FC
.text C:\Program Files\Windows Sidebar\sidebar.exe[3476] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00120804
.text C:\Program Files\Windows Sidebar\sidebar.exe[3476] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 001201F8
.text C:\Program Files\Windows Sidebar\sidebar.exe[3476] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00120600
.text C:\Program Files\Samsung\Kies\KiesTrayAgent.exe[3536] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 001603FC
.text C:\Program Files\Samsung\Kies\KiesTrayAgent.exe[3536] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 001601F8
.text C:\Program Files\Samsung\Kies\KiesTrayAgent.exe[3536] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Program Files\Samsung\Kies\KiesTrayAgent.exe[3536] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 001F0A08
.text C:\Program Files\Samsung\Kies\KiesTrayAgent.exe[3536] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 001F03FC
.text C:\Program Files\Samsung\Kies\KiesTrayAgent.exe[3536] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 001F0804
.text C:\Program Files\Samsung\Kies\KiesTrayAgent.exe[3536] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 001F01F8
.text C:\Program Files\Samsung\Kies\KiesTrayAgent.exe[3536] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 001F0600
.text C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[3548] ntdll.dll!DbgUiRemoteBreakin 778FF17D 1 Byte [C3]
.text C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe[3548] KERNEL32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Program Files\iPod\bin\iPodService.exe[3616] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Program Files\iPod\bin\iPodService.exe[3616] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Program Files\iPod\bin\iPodService.exe[3616] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Program Files\iPod\bin\iPodService.exe[3616] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00200A08
.text C:\Program Files\iPod\bin\iPodService.exe[3616] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 002003FC
.text C:\Program Files\iPod\bin\iPodService.exe[3616] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00200804
.text C:\Program Files\iPod\bin\iPodService.exe[3616] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 002001F8
.text C:\Program Files\iPod\bin\iPodService.exe[3616] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00200600
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3772] KERNEL32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Users\***\Desktop\mvfjqsz8.exe[3820] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\System32\svchost.exe[4168] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[4168] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[4168] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\System32\svchost.exe[4168] user32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00330A08
.text C:\Windows\System32\svchost.exe[4168] user32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 003303FC
.text C:\Windows\System32\svchost.exe[4168] user32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00330804
.text C:\Windows\System32\svchost.exe[4168] user32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 003301F8
.text C:\Windows\System32\svchost.exe[4168] user32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00330600
.text C:\Windows\System32\svchost.exe[5424] ntdll.dll!LdrUnloadDll 778BC86E 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[5424] ntdll.dll!LdrLoadDll 778C223E 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[5424] kernel32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
.text C:\Windows\System32\svchost.exe[5424] USER32.dll!UnhookWindowsHookEx 75DDADF9 5 Bytes JMP 00190A08
.text C:\Windows\System32\svchost.exe[5424] USER32.dll!UnhookWinEvent 75DDB750 5 Bytes JMP 001903FC
.text C:\Windows\System32\svchost.exe[5424] USER32.dll!SetWindowsHookExW 75DDE30C 5 Bytes JMP 00190804
.text C:\Windows\System32\svchost.exe[5424] USER32.dll!SetWinEventHook 75DE24DC 5 Bytes JMP 001901F8
.text C:\Windows\System32\svchost.exe[5424] USER32.dll!SetWindowsHookExA 75E06D0C 5 Bytes JMP 00190600
.text C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe[5960] KERNEL32.dll!GetBinaryTypeW + 70 762169F4 1 Byte [62]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\Explorer.EXE[352] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [745824CB] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[352] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [7456562E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[352] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [745656EC] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[352] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74582546] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[352] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [745785AA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[352] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [74574D5E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[352] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [74575105] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[352] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [745751DA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[352] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [74576707] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[352] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [74578301] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[352] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74578850] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[352] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [745790B1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[352] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7457E254] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[352] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74574C90] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1408] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [7258F6D0] C:\Program Files\Alwil Software\Avast5\aswCmnBS.dll (Common functions/AVAST Software)
IAT C:\Program Files\Alwil Software\Avast5\AvastUI.exe[3140] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [7258F6D0] C:\Program Files\Alwil Software\Avast5\aswCmnBS.dll (Common functions/AVAST Software)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/AVAST Software)
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
Device \Driver\ACPI_HAL \Device\00000049 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ---- heute habe ich noch einen kompletten scan mit anti-malware gemacht. hier das ergebnis
was muss ich nun noch machen bzw. log. dateien ersetzten wie ich es hier lese nur auf meinen fall bezogen??? Code:
Malwarebytes Anti-Malware (Test) 1.62.0.1300
www.malwarebytes.org
Datenbank Version: v2012.08.01.02
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 8.0.7601.17514
*** :: ***-PC [Administrator]
Schutz: Aktiviert
01.08.2012 08:23:58
mbam-log-2012-08-01 (08-23-58).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 355002
Laufzeit: 52 Minute(n), 38 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende) |