que2trash | 14.08.2013 12:46 | FRST Additions Logfile: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-08-2013
Ran by S5470 at 2013-08-14 12:08:23
Running from C:\Users\S5470\Desktop
Boot Mode: Normal
==========================================================
==================== Installed Programs =======================
Update for Microsoft Office 2007 (KB2508958) (x32)
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
Acronis*Disk*Director*11*Home (x32 Version: 11.0.2121)
Acronis*True*Image*Home (x32 Version: 11.0.8010)
Adobe Flash Player 11 ActiveX (x32 Version: 11.7.700.224)
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94)
Adobe Reader X (10.1.7) - Deutsch (x32 Version: 10.1.7)
Adobe Shockwave Player 12.0 (x32 Version: 12.0.3.133)
BestPractice (remove only) (x32)
Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.04059)
Cisco AnyConnect Secure Mobility Client (x32 Version: 3.1.04059)
Citavi (x32 Version: 3.1.0.0)
Corel Graphics - Windows Shell Extension (x32 Version: 15.0.0.487)
Corel Graphics - Windows Shell Extension (x32 Version: 15.0.487)
CorelDRAW Graphics Suite X5 - BR (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - Capture (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - Common (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - Connect (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - Custom Data (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - DE (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - Draw (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - EN (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - ES (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - Filters (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - FontNav (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - FR (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - IPM (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - IT (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - NL (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - PHOTO-PAINT (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - Photozoom Plugin (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - Redist (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - Setup Files (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - VBA (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - VideoBrowser (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - VSTA (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 - Windows Shell Extension 64 Bit (Version: 15.0.487)
CorelDRAW Graphics Suite X5 - WT (x32 Version: 15.0)
CorelDRAW Graphics Suite X5 (x32 Version: 15.0)
CorelDRAW(R) Graphics Suite X5 (x32 Version: 15.0.0.486)
Counter-Strike: Source (x32)
DAEMON Tools Lite (x32 Version: 4.41.3.0173)
Dota 2 (x32)
DriveImage XML (Private Edition) (x32 Version: 2.44.000)
EASEUS Partition Master 8.0.1 Home Edition (x32)
ElsterFormular (x32 Version: 14.3.20130522)
FreeCommander 2009.02b (x32 Version: 2009.02)
Gpg4win (2.1.1) (x32 Version: 2.1.1)
Hotfix für Microsoft Visual Studio 2007 Tools for Applications - ENU (KB947789) (x32 Version: 1)
ImgBurn (x32 Version: 2.5.5.0)
Java 7 Update 25 (x32 Version: 7.0.250)
Java Auto Updater (x32 Version: 2.1.9.5)
MediaMonkey 3.2 (x32 Version: 3.2)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.88.0)
Microsoft Games for Windows Marketplace (x32 Version: 3.5.50.0)
Microsoft Office 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003)
Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000)
Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Professional Plus 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual Studio Tools for Applications 2.0 - ENU (x32 Version: 9.0.30729)
Microsoft Visual Studio Tools for Applications 2.0 Language Pack - DEU (x32 Version: 9.0.30729)
Microsoft Visual Studio Tools for Applications 2.0 Runtime (x32 Version: 9.0.30729)
Microsoft Visual Studio Tools for Applications 2.0 Runtime Language Pack - DEU (x32 Version: 9.0.30729)
Microsoft-Maus- und Tastatur-Center (Version: 2.2.173.0)
Mozilla Firefox 23.0 (x86 de) (x32 Version: 23.0)
Mozilla Maintenance Service (x32 Version: 23.0)
Notepad++ (x32 Version: 6.4.2)
NVIDIA 3D Vision Controller Driver (x32 Version: 275.33)
NVIDIA 3D Vision Controller-Treiber 320.49 (Version: 320.49)
NVIDIA 3D Vision Treiber 320.49 (Version: 320.49)
NVIDIA Display Control Panel (Version: 1.10)
NVIDIA Grafiktreiber 320.49 (Version: 320.49)
NVIDIA Install Application (Version: 2.1002.131.854)
NVIDIA PhysX (x32 Version: 9.13.0604)
NVIDIA PhysX-Systemsoftware 9.13.0604 (Version: 9.13.0604)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.2049)
NVIDIA Systemsteuerung 320.49 (Version: 320.49)
Opera 12.16 (x32 Version: 12.16.1860)
pdfsam (x32 Version: 2.2.1)
PDF-XChange Viewer (Version: 2.5.197.0)
RICOH R5C83x/84x Media Driver Ver.3.53.02 (x32 Version: 3.53.02)
ROCCAT Kone Mouse Driver (x32 Version: 1.0)
RocketDock 1.3.5 (x32)
Sandboxie 3.54 (64-bit)
Skype Toolbars (x32 Version: 5.3.7555)
Skype™ 6.6 (x32 Version: 6.6.106)
Sophos Anti-Virus (x32 Version: 10.2.8)
Sophos AutoUpdate (x32 Version: 2.9.0.344)
Steam (x32 Version: 1.0.0.0)
swMSM (x32 Version: 12.0.0.1)
Synaptics Pointing Device Driver (Version: 14.0.3.0)
top Integrated Webcam Driver (1.04.01.1011)
Trillian (x32)
Update for 2007 Microsoft Office System (KB967642) (x32)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596802) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (x32)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817563) 32-Bit Edition (x32)
Update für Microsoft Office Excel 2007 Help (KB963678) (x32)
Update für Microsoft Office Outlook 2007 Help (KB963677) (x32)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32)
Update für Microsoft Office Word 2007 Help (KB963665) (x32)
Veetle TV (x32 Version: 0.9.18)
Visual Basic for Applications (R) Core - English (x32 Version: 6.4.99.69)
Visual Basic for Applications (R) Core - German (x32 Version: 6.4.99.69)
Visual Basic for Applications (R) Core (x32 Version: 6.4.99.69)
VLC media player 2.0.7 (x32 Version: 2.0.7)
Windows 7 USB/DVD Download Tool (x32 Version: 1.0.30)
Windows Live ID Sign-in Assistant (Version: 6.500.3165.0)
WinSCP 4.3.3 (x32 Version: 4.3.3)
==================== Restore Points =========================
==================== Hosts content: ==========================
2009-07-14 04:34 - 2013-08-01 10:54 - 00000895 ____A C:\Windows\system32\Drivers\etc\hosts
131.188.12.8 ciscovpn.rrze.uni-erlangen.de
==================== Scheduled Tasks (whitelisted) =============
Task: {07B5847B-B495-4182-B842-0CB1D4E685A9} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {0A8D093B-EFB7-4661-A6B6-018F2F8D77CD} - System32\Tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor => C:\Windows\system32\sdclt.exe [2010-11-20] (Microsoft Corporation)
Task: {69CC551E-64D7-44C6-A5BA-EC1F97EB3CAF} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {89761739-344A-43E8-BCA5-43570E7BC6D9} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2013-05-13] (Microsoft Corporation)
Task: {9311D1F6-D757-4A1A-B6A5-70AE0949261F} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2013-05-13] (Microsoft)
Task: {9F380913-0802-47D7-898E-2539BF5DA4D2} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => C:\Windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation)
Task: {AAB8BCF5-5E1B-4F56-9C1F-6AF801486F21} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-22] (Adobe Systems Incorporated)
Task: {B2EFEB65-A750-4892-889C-BF3A1F38326C} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2013-05-13] (Microsoft Corporation)
Task: {BE319257-F889-4FD7-BE16-708F1F8DBDCE} - System32\Tasks\{6F2A38CF-251E-4480-BBE3-3EEF38C33E9D} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2013-06-21] (Skype Technologies S.A.)
Task: {F757485E-5391-4F35-B2F2-CF1BEC1D7D82} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation)
Task: {FAD1BD2A-AABF-4E49-B794-6B8628BAACB8} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Faulty Device Manager Devices =============
Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows x64
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: vpnva
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (08/13/2013 07:20:35 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3.
Der Wert "*" des "language"-Attributs im assemblyIdentity-Element ist ungültig.
Error: (08/13/2013 07:19:23 PM) (Source: System Restore) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation; Beschreibung = Geplanter Prüfpunkt; Fehler = 0x80070422).
Error: (08/13/2013 07:14:47 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (08/13/2013 07:14:29 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (08/13/2013 07:14:05 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (08/13/2013 07:12:44 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"1".
Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (08/13/2013 09:30:02 AM) (Source: System Restore) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\msiexec.exe /V; Beschreibung = Installed Windows 7 USB/DVD Download Tool; Fehler = 0x80070422).
Error: (08/13/2013 09:30:02 AM) (Source: System Restore) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\msiexec.exe /V; Beschreibung = Installed Windows 7 USB/DVD Download Tool; Fehler = 0x80070422).
Error: (08/13/2013 09:29:30 AM) (Source: System Restore) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\msiexec.exe /V; Beschreibung = Removed Windows 7 USB/DVD Download Tool; Fehler = 0x80070422).
Error: (08/13/2013 09:29:29 AM) (Source: System Restore) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\msiexec.exe /V; Beschreibung = Removed Windows 7 USB/DVD Download Tool; Fehler = 0x80070422).
System errors:
=============
Error: (08/14/2013 11:14:56 AM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 14.08.2013 um 11:12:57 unerwartet heruntergefahren.
Error: (08/14/2013 09:41:00 AM) (Source: DCOM) (User: )
Description: {0E9A7BB5-F699-4D66-8A47-B919F5B6A1DB}
Error: (08/14/2013 09:31:03 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Update" wurde nicht richtig gestartet.
Error: (08/14/2013 09:30:28 AM) (Source: DCOM) (User: )
Description: {4991D34B-80A1-4291-83B6-3328366B9097}
Error: (08/14/2013 09:28:36 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Intelligenter Hintergrundübertragungsdienst" wurde nicht richtig gestartet.
Error: (08/13/2013 11:27:36 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Anwendungserfahrung" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1115
Error: (08/13/2013 06:33:59 PM) (Source: BTHUSB) (User: )
Description: Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen und wird nicht verwendet. Der Treiber wurde entladen.
Error: (08/13/2013 03:13:59 PM) (Source: BTHUSB) (User: )
Description: Der lokale Bluetooth-Adapter ist aus einem unbekannten Grund fehlgeschlagen und wird nicht verwendet. Der Treiber wurde entladen.
Error: (08/13/2013 08:25:49 AM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.
Error: (08/13/2013 08:25:48 AM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR2 gefunden.
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Percentage of memory in use: 51%
Total physical RAM: 4094.04 MB
Available physical RAM: 1972.67 MB
Total Pagefile: 8186.25 MB
Available Pagefile: 5838.58 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:195.32 GB) (Free:126.92 GB) NTFS (Disk=0 Partition=1) ==>[Drive with boot components (obtained from BCD)]
Drive d: (Software) (Fixed) (Total:29.3 GB) (Free:15.16 GB) NTFS (Disk=0 Partition=3)
Drive e: (Daten) (Fixed) (Total:146.58 GB) (Free:135.39 GB) NTFS (Disk=0 Partition=2)
Drive r: (BATTLESTAR_GALACTICA_221) (CDROM) (Total:7.7 GB) (Free:0 GB) UDF
Drive y: (Backup) (Fixed) (Total:94.56 GB) (Free:23.06 GB) NTFS (Disk=0 Partition=4)
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: E7BE3FD6)
Partition 1: (Active) - (Size=195 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=147 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=124 GB) - (Type=05)
==================== End Of Log ============================ --- --- ---
GMER Logfile: Code:
GMER 2.1.19163 - GMER - Rootkit Detector and Remover
Rootkit scan 2013-08-14 12:48:12
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-2 ST9500420AS rev.0002SDM1 465,76GB
Running: 3ld7i03w.exe; Driver: C:\Users\S5470\AppData\Local\Temp\fgloypod.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 560 fffff80002db1000 45 bytes [00, 00, 15, 02, 46, 69, 6C, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 607 fffff80002db102f 16 bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text C:\Windows\System32\win32k.sys!W32pServiceTable fffff96000113e00 7 bytes [00, A3, F3, FF, 01, AF, F0]
.text C:\Windows\System32\win32k.sys!W32pServiceTable + 8 fffff96000113e08 3 bytes [C0, 06, 02]
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[944] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[944] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1488] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[1488] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1972] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe[1972] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe[2160] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe[2160] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2260] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2260] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe[2320] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe[2320] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Windows\Explorer.EXE[2444] C:\Windows\system32\kernel32.dll!CopyFileExW 0000000076f623d0 5 bytes JMP 000000016fff00d8
.text C:\Windows\Explorer.EXE[2444] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW 0000000076fdf6c0 8 bytes JMP 000000016fff0110
.text C:\Windows\Explorer.EXE[2444] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefdc37490 11 bytes JMP 000007fffdb600d8
.text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2684] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[2684] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2808] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[2808] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text c:\Program Files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[2908] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text c:\Program Files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe[2908] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe[3024] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe[3024] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe[2084] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe[2084] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[400] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[400] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe[1448] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe[1448] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Windows\OEM02Mon.exe[3088] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Windows\OEM02Mon.exe[3088] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Program Files (x86)\ROCCAT\Kone Mouse\KoneHID.EXE[3120] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\ROCCAT\Kone Mouse\KoneHID.EXE[3120] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[3188] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[3188] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe[3276] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe[3276] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3312] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3312] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe[3320] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe[3320] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Program Files (x86)\ROCCAT\Kone Mouse\osd.exe[3580] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\ROCCAT\Kone Mouse\osd.exe[3580] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Program Files (x86)\GNU\GnuPG\bin\dbus-daemon.exe[4640] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\GNU\GnuPG\bin\dbus-daemon.exe[4640] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Program Files (x86)\GNU\GnuPG\bin\kleopatra.exe[4428] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\GNU\GnuPG\bin\kleopatra.exe[4428] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Program Files (x86)\GNU\GnuPG\gpg-agent.exe[3708] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\GNU\GnuPG\gpg-agent.exe[3708] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Program Files (x86)\GNU\GnuPG\scdaemon.exe[2648] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Program Files (x86)\GNU\GnuPG\scdaemon.exe[2648] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
.text C:\Users\S5470\Desktop\3ld7i03w.exe[2088] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e21465 2 bytes [E2, 74]
.text C:\Users\S5470\Desktop\3ld7i03w.exe[2088] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e214bb 2 bytes [E2, 74]
.text ... * 2
---- Threads - GMER 2.1 ----
Thread C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2456:2692] 000007fef4e9c680
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00197eda2267
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00197eda2267 (not active ControlSet)
---- EOF - GMER 2.1 ---- --- --- --- |