Markelix | 30.11.2013 14:18 | So, jetzt der 2. Rechner: Avira: wie gesagt keine Treffer Defogger: Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 10:03 on 30/11/2013 (Markelix)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=- FRST:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-11-2013
Ran by Markelix (administrator) on MARKELIX-PC on 30-11-2013 10:07:47
Running from C:\Users\Markelix\Downloads
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
() C:\Windows\System32\AsusService.exe
(Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE
() C:\ProgramData\DatacardService\DCService.exe
(McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
(Chris Pietschmann (hxxp://pietschsoft.com)) C:\Program Files\Virtual Router\VirtualRouterService.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(CANON INC.) C:\Windows\System32\CNAC4RPK.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(ASUS) C:\Program Files\EeePC\CapsHook\CapsHook.exe
(ASUSTeK Computer Inc.) C:\Program Files\EeePC\HotkeyService\HotkeyService.exe
(ASUSTeK Computer Inc.) C:\Program Files\ASUS\SHE\SuperHybridEngine.exe
(AsusTek Computer Inc.) C:\Program Files\ASUS\LiveUpdate\LiveUpdate.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(APN) C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google) C:\Program Files\Google\Drive\googledrivesync.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Chris Pietschmann (hxxp://pietschsoft.com)) C:\Program Files\Virtual Router\VirtualRouterClient.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google) C:\Program Files\Google\Drive\googledrivesync.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor\saUI.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1750312 2010-07-01] (Synaptics Incorporated)
HKLM\...\Run: [HotkeyService] - C:\Program Files\EeePC\HotkeyService\HotkeyService.exe [1245104 2010-09-03] (ASUSTeK Computer Inc.)
HKLM\...\Run: [SuperHybridEngine] - C:\Program Files\ASUS\SHE\SuperHybridEngine.exe [425400 2011-08-01] (ASUSTeK Computer Inc.)
HKLM\...\Run: [LiveUpdate] - C:\Program Files\ASUS\LiveUpdate\LiveUpdate.exe [1090984 2010-09-08] (AsusTek Computer Inc.)
HKLM\...\Run: [CapsHook] - C:\Program Files\EeePC\CapsHook\CapsHook.exe [445344 2010-05-29] (ASUS)
HKLM\...\Run: [mcui_exe] - "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
HKLM\...\Run: [EEESplendidAR] - C:\Program Files\ASUS\EeeSplendid\AutoRun.exe [169472 2009-11-18] (ASUSTeK Computer Inc.)
HKLM\...\Run: [AMD AVT] - Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files\AMD AVT\bin\kdbsync.exe" aml
HKLM\...\Run: [Eee Docking] - C:\Program Files\ASUS\Eee Docking\Eee Docking.exe [414384 2011-01-06] (ASUSTek Computer Inc.)
HKLM\...\Run: [ASUSPRP] - C:\Program Files\ASUS\APRP\aprp.exe [2018032 2010-11-19] (ASUSTek Computer Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [683576 2013-11-30] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [ApnTBMon] - C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1673680 2013-10-23] (APN)
HKCU\...\Run: [GoogleChromeAutoLaunch_2DC8FBDB48D02252664EC1C24344B896] - C:\Program Files\Google\Chrome\Application\chrome.exe [863184 2013-11-14] (Google Inc.)
HKCU\...\Run: [GoogleDriveSync] - C:\Program Files\Google\Drive\googledrivesync.exe [20133824 2013-09-25] (Google)
MountPoints2: E - E:\AutoRun.exe
MountPoints2: {5578d354-1097-11e2-b107-806e6f6e6963} - E:\AutoRun.exe
MountPoints2: {5578d46a-1097-11e2-b107-bcaec526d7ca} - E:\AutoRun.exe
MountPoints2: {6b477991-d609-11e2-8e63-bcaec526d7ca} - E:\AutoRun.exe
MountPoints2: {91a270bf-bb94-11e2-bcd4-bcaec526d7ca} - E:\AutoRun.exe
MountPoints2: {9a631c68-3797-11e2-a4b9-bcaec526d7ca} - E:\AutoRun.exe
MountPoints2: {d9687c70-69fa-11e2-b2b5-bcaec526d7ca} - E:\AutoRun.exe
MountPoints2: {d9687c8b-69fa-11e2-b2b5-bcaec526d7ca} - E:\AutoRun.exe
MountPoints2: {d9687c98-69fa-11e2-b2b5-bcaec526d7ca} - E:\AutoRun.exe
MountPoints2: {ea8b2806-2771-11e2-a392-bcaec526d7ca} - E:\AutoRun.exe
HKU\Default\...\RunOnce: [Reboot] - C:\Windows\Reboot.exe [ 2010-09-21] (AsusTek Computer Inc.)
HKU\Default\...\RunOnce: [AskScreensaver] - C:\Program Files\ASUS\AsusScreensaver\AsusScreensaver.exe [ 2010-09-08] (AsusTek Computer Inc.)
Startup: C:\Users\Markelix\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:Tabs
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://eeepc.asus.com
URLSearchHook: HKCU - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
SearchScopes: HKCU - {73C6AEC5-76BD-414A-BA8E-F070AA632FA0} URL = hxxp://de.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{58108F04-766D-46B9-AACF-8B104C689511}: [NameServer]193.189.244.225 193.189.244.206
Tcpip\..\Interfaces\{6E97C89A-61B5-47FF-943B-EA72FBE4C7E7}: [NameServer]193.189.244.206 193.189.244.225
Tcpip\..\Interfaces\{D6859F24-E31C-441A-9435-1DA7E1983D81}: [NameServer]193.189.244.206 193.189.244.225
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "hxxp://www.spiegel.de/", "hxxp://www.spiegel.de/panorama/justiz/berlin-15-jaehriger-soll-paedophilen-ermordet-haben-a-865219.html", "hxxp://www.spiegel.de/gesundheit/ernaehrung/olympiagold-2012-senioren-europameister-klemens-wittig-5-mal-gesiegt-a-864528.html", "hxxp://www.spiegel.de/gesundheit/ernaehrung/fettleber-leberverfettung-kann-diabetes-und-leberkrebs-ausloesen-a-864183.html", "hxxp://www.spiegel.de/gesundheit/diagnose/weg-mit-den-zigaretten-methoden-mit-dem-rauchen-aufzuhoeren-a-863537.html", "hxxp://www.spiegel.de/gesundheit/diagnose/knackiger-po-die-beste-buero-uebung-fuer-eine-straffe-gesaessmuskulatur-a-862028.html", "hxxp://einestages.spiegel.de/s/tb/25809/unvollendete-filme-kubricks-napoleon-orson-welles-don-quijote.html", "hxxp://www.spiegel.de/reise/europa/die-wand-spurensuche-in-marlen-haushofers-heimat-in-oesterreich-a-861596.html", "hxxp://www.spiegel.de/wirtschaft/soziales/wirtschaftsnobelpreis-geht-an-us-spieltheoretiker-roth-und-shapley-a-861392.html", "hxxp://www.fleecys.de/", "hxxp://www.spiegel.de/wirtschaft/george-soros-deutschland-muss-fuehren-oder-aus-dem-euro-austreten-a-854595-5.html", "hxxp://de.hillempire.com/?ref=spads2a", "hxxp://www.spiegel.de/sport/sonst/bild-844430-376436.html", "hxxp://www.spiegel.de/panorama/gesellschaft/jugendamtsmitarbeiter-beschreiben-berufsalltag-a-841443.html", "https://accounts.google.com/ServiceLogin?service=mail&passive=true&rm=false&continue=https://mail.google.com/mail/?shva%3D1&ss=1&scc=1<mpl=googlemail#search/The+West/1335440165eebacb", "hxxp://de.lagoonia.com/", "hxxp://www.tchibo.de/Matratzentopper-p400026544.html?dim1=R30", "https://accounts.google.com/ServiceLogin?service=mail&passive=true&rm=false&continue=https://mail.google.com/mail/?ui%3D2%26ik%3Dccdbf7fe50%26view%3Datt%26th%3D13a29c996919b65f%26attid%3D0.1%26disp%3Dinline%26safe%3D1%26zw%26sadssc%3D1%26sadnir%3D1&scc=1<mpl=googlemail", "hxxp://www.spiegel.de/spiegelwissen/beziehungen-partnersuche-hat-selten-mit-zufall-zu-tun-a-831811-3.html", "https://www.facebook.com/", "hxxp://de.upjers.com/", "https://accounts.google.com/ServiceLogin?service=wise&passive=1209600&continue=https://drive.google.com/?tab%3Dmo%26authuser%3D0%26pli%3D1%23all&followup=https://drive.google.com/?tab%3Dmo%26authuser%3D0%26pli%3D1<mpl=drive", "hxxp://de16.the-west.de/game.php#", "hxxp://forum.the-west.de/showthread.php?t=610&page=2", "hxxp://grauenderfinsternis.forumieren.com/", "hxxp://secret-relict.blogspot.de/2012/02/wahrung.html"
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.57\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Garmin Communicator Plug-In) - C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U25) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File
CHR Plugin: (Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\windows\system32\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
CHR Plugin: (Java Deployment Toolkit 7.0.250.17) - C:\windows\system32\npDeployJava1.dll No File
CHR Plugin: (McAfee SecurityCenter) - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL No File
CHR Extension: (Avira SearchFree Toolbar plus Web Protection) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaacalgebmfelllfiaoknifldpngjh\25.62074_0
CHR Extension: (Sudoku) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\agdhembpgcpfegeigidembjopfhghnpj\1.0.1.0_0
CHR Extension: (Fabulous) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\ambjmeohlajelahhhniggkkceagdlcgj\31.2_1
CHR Extension: (Sort by Name) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\amigcgbheognjmfkaieeeadojiibgbdp\2.0.0_0
CHR Extension: (Google Drive) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (ImageZoom) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbmigpjhdoghhhmecocklaokmmamgobo\1.5_0
CHR Extension: (YouTube Options) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdokagampppgbnjfdlkfpphniapiiifn\1.8.148_0
CHR Extension: (OneTab) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\chphlpgkkbolifaimnlloiipkdnihall\1.6_0
CHR Extension: (Tampermonkey) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo\3.5.3630.77_0
CHR Extension: (Color Changer for Facebook) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\dheljpcbhldkdiabdemaflamgfnbpnkd\19.0_0
CHR Extension: (MondoZoo - Zoo game) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejafdpedefplpgoacblaboikebhhjlib\1.1.0.0_0
CHR Extension: (Sudoku) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbldalicehmlaalddffibogeplifangc\1.0.3_0
CHR Extension: (SiteAdvisor) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.6.4.1291_0
CHR Extension: (Vimeo\u2122 Download Videos) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\geeljcibkkackafmeepgadbfgmpjmdeg\3.0.0_0
CHR Extension: (Lord of Ultima) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdheeblenjmceeppomdgokgilmkonced\1.0.12_0
CHR Extension: (Green Farm) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbgdenhobifcbckaiohandoodkepleif\2.1.7.8_0
CHR Extension: (Little Alchemy) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\knkapnclbofjjgicpkfoagdjohlfjhpd\0.0.15.7_0
CHR Extension: (Parallel Kingdom) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\lindbaaodgocnekppljikhgdgedliclg\1_0
CHR Extension: (Fieldrunners) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkpikhjbfbffdblahfidklcohlaeabak\1.0.0.5_0
CHR Extension: (WGT Golf Game) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpedbpkelbhcbkdaglillalioeeekbpb\45.0.0_0
CHR Extension: (Curling) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhalnajmigjnpjpdbpkpgfhekbjmolhp\1.0.10_0
CHR Extension: (Google Wallet) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: ( "name": "MonitorTab") - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\ognampngfcbddbfemdapefohjiobgbdl\0.27_0
CHR Extension: (Currently) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojhmphdkpgbibohbnpbfiefkgieacjmh\2.7.0_0
CHR Extension: (Yann Arthus-Bertrand) - C:\Users\Markelix\AppData\Local\Google\Chrome\User Data\Default\Extensions\plaekpceeonanmjojailaojkconcgofc\3_0
CHR HKLM\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files\McAfee\SiteAdvisor\McChPlg.crx
========================== Services (Whitelisted) =================
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [291840 2012-07-04] (Advanced Micro Devices, Inc.)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-11-30] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-30] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1164360 2013-11-30] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.)
R2 AsusService; C:\Windows\System32\AsusService.exe [219136 2009-08-19] ()
R2 DCService.exe; C:\ProgramData\DatacardService\DCService.exe [229376 2010-05-08] ()
S2 MAGIX StartUp Analyze Service; C:\Program Files\MAGIX\PC_Check_Tuning_2012\MXSAS.exe [187168 2012-01-06] (MAGIX AG)
R2 McAfee SiteAdvisor Service; C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [103112 2013-11-05] (McAfee, Inc.)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService.exe [150600 2013-04-10] (Realtek Semiconductor)
R2 Virtual Router; C:\Program Files\Virtual Router\VirtualRouterService.exe [12288 2013-02-10] (Chris Pietschmann (hxxp://pietschsoft.com))
==================== Drivers (Whitelisted) ====================
R0 amd_sata; C:\Windows\System32\DRIVERS\amd_sata.sys [70784 2012-04-11] (Advanced Micro Devices)
R0 amd_xata; C:\Windows\System32\DRIVERS\amd_xata.sys [34944 2012-04-11] (Advanced Micro Devices)
R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\i386\AODDriver2.sys [45184 2012-03-05] (Advanced Micro Devices)
R1 AsUpIO; C:\Windows\System32\drivers\AsUpIO.sys [11520 2010-03-31] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-11-30] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137208 2013-11-30] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-30] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [67680 2013-11-30] (Avira Operations GmbH & Co. KG)
R0 DiskSec; C:\Windows\System32\Drivers\DiskSec.sys [14208 2008-04-04] (MAGIX)
S3 grmnusb; C:\Windows\System32\drivers\grmnusb.sys [15720 2012-04-18] (GARMIN Corp.)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [13880 2009-07-20] ( )
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-11-30] (Avira GmbH)
S3 TOO; \??\D:\genport.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-11-30 10:07 - 2013-11-30 10:09 - 00020762 _____ C:\Users\Markelix\Downloads\FRST.txt
2013-11-30 10:07 - 2013-11-30 10:07 - 00000000 ____D C:\FRST
2013-11-30 10:06 - 2013-11-30 10:06 - 01092049 _____ (Farbar) C:\Users\Markelix\Downloads\FRST.exe
2013-11-30 10:00 - 2013-11-30 10:04 - 00000478 _____ C:\Users\Markelix\Downloads\defogger_disable.log
2013-11-30 10:00 - 2013-11-30 10:00 - 00000000 _____ C:\Users\Markelix\defogger_reenable
2013-11-30 09:57 - 2013-11-30 09:58 - 00050477 _____ C:\Users\Markelix\Downloads\Defogger.exe
2013-11-30 09:23 - 2013-11-30 09:23 - 00000000 ____D C:\ProgramData\AskPartnerNetwork
2013-11-30 09:23 - 2013-11-30 09:23 - 00000000 ____D C:\Program Files\AskPartnerNetwork
2013-11-30 09:20 - 2013-11-30 09:20 - 00000000 ____D C:\Users\Markelix\AppData\Roaming\Avira
2013-11-30 09:20 - 2013-11-30 09:20 - 00000000 ____D C:\ProgramData\APN
2013-11-30 09:12 - 2013-11-30 09:12 - 00001976 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-11-30 09:11 - 2013-11-30 09:11 - 00000000 ____D C:\ProgramData\Avira
2013-11-30 09:11 - 2013-11-30 09:11 - 00000000 ____D C:\Program Files\Avira
2013-11-30 09:11 - 2013-11-30 08:48 - 00137208 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys
2013-11-30 09:11 - 2013-11-30 08:48 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys
2013-11-30 09:11 - 2013-11-30 08:48 - 00067680 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys
2013-11-30 09:11 - 2013-11-30 08:48 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avkmgr.sys
2013-11-30 09:11 - 2013-11-30 08:48 - 00028520 _____ (Avira GmbH) C:\windows\system32\Drivers\ssmdrv.sys
2013-11-30 08:36 - 2013-11-30 08:39 - 02294160 _____ C:\Users\Markelix\Downloads\avira_free_antivirus.exe
2013-11-30 07:52 - 2013-11-30 07:53 - 00000000 ____D C:\ProgramData\Oracle
2013-11-30 07:52 - 2013-11-30 07:52 - 00094632 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge.dll
2013-11-30 07:52 - 2013-11-30 07:52 - 00000000 ____D C:\Program Files\Common Files\Java
2013-11-30 07:52 - 2013-11-30 07:49 - 00174504 _____ (Oracle Corporation) C:\windows\system32\java.exe
2013-11-30 07:52 - 2013-10-08 07:46 - 00264616 _____ (Oracle Corporation) C:\windows\system32\javaws.exe
2013-11-30 07:52 - 2013-10-08 07:46 - 00175016 _____ (Oracle Corporation) C:\windows\system32\javaw.exe
2013-11-30 07:49 - 2013-11-30 07:52 - 00004874 _____ C:\windows\system32\jupdate-1.7.0_45-b18.log
2013-11-22 16:38 - 2013-11-22 16:38 - 01373696 _____ C:\Users\Markelix\Downloads\VirtualRouterInstaller_1.0.msi
2013-11-21 14:42 - 2013-10-12 08:04 - 00042496 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2013-11-21 14:42 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2013-11-21 14:42 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2013-11-21 14:42 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2013-11-21 14:42 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2013-11-21 14:42 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2013-11-21 14:42 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2013-11-21 14:42 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2013-11-21 14:42 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2013-11-21 14:42 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2013-11-21 14:42 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2013-11-21 14:42 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2013-11-21 14:42 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2013-11-21 14:42 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2013-11-21 14:42 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2013-11-21 14:42 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\windows\system32\RegisterIEPKEYs.exe
2013-11-19 07:09 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\windows\system32\SmartcardCredentialProvider.dll
2013-11-19 07:09 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2013-11-19 07:09 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\credui.dll
2013-11-19 07:08 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2013-11-19 07:07 - 2013-09-25 03:01 - 00136640 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2013-11-19 07:07 - 2013-09-25 03:01 - 00067520 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2013-11-19 07:07 - 2013-09-25 02:57 - 00099840 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2013-11-19 07:07 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2013-11-19 07:07 - 2013-09-25 02:56 - 01038848 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2013-11-19 07:07 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2013-11-19 07:07 - 2013-09-25 01:49 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2013-11-19 07:07 - 2013-09-25 01:49 - 00015872 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2013-11-19 07:07 - 2013-07-04 13:16 - 00369848 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2013-11-19 07:06 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\windows\system32\nshwfp.dll
2013-11-19 07:06 - 2013-10-12 03:01 - 00679424 _____ (Microsoft Corporation) C:\windows\system32\IKEEXT.DLL
2013-11-19 07:06 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\windows\system32\FWPUCLNT.DLL
2013-11-19 07:06 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
2013-11-19 07:06 - 2013-10-03 02:58 - 00305152 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
==================== One Month Modified Files and Folders =======
2013-11-30 10:09 - 2013-11-30 10:07 - 00020762 _____ C:\Users\Markelix\Downloads\FRST.txt
2013-11-30 10:08 - 2009-07-14 03:37 - 00000000 ___RD C:\Users\Public
2013-11-30 10:07 - 2013-11-30 10:07 - 00000000 ____D C:\FRST
2013-11-30 10:06 - 2013-11-30 10:06 - 01092049 _____ (Farbar) C:\Users\Markelix\Downloads\FRST.exe
2013-11-30 10:06 - 2013-06-09 11:16 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-11-30 10:04 - 2013-11-30 10:00 - 00000478 _____ C:\Users\Markelix\Downloads\defogger_disable.log
2013-11-30 10:00 - 2013-11-30 10:00 - 00000000 _____ C:\Users\Markelix\defogger_reenable
2013-11-30 10:00 - 2012-10-05 23:06 - 00000000 ____D C:\Users\Markelix
2013-11-30 09:58 - 2013-11-30 09:57 - 00050477 _____ C:\Users\Markelix\Downloads\Defogger.exe
2013-11-30 09:52 - 2012-10-01 19:30 - 01979869 _____ C:\windows\WindowsUpdate.log
2013-11-30 09:51 - 2009-07-14 05:34 - 00009920 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-30 09:51 - 2009-07-14 05:34 - 00009920 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-30 09:45 - 2013-04-28 19:22 - 00000000 ___RD C:\Users\Markelix\Google Drive
2013-11-30 09:42 - 2012-10-05 23:43 - 00000000 ____D C:\ProgramData\McAfee
2013-11-30 09:41 - 2013-07-21 14:54 - 00000520 _____ C:\windows\system32\Drivers\etc\hosts.ics
2013-11-30 09:39 - 2013-08-25 09:51 - 00016384 _____ C:\windows\system32\Ikeext.etl
2013-11-30 09:39 - 2013-02-25 12:47 - 00001094 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-30 09:39 - 2012-10-05 23:57 - 00000000 ____D C:\Program Files\Common Files\Mcafee
2013-11-30 09:39 - 2012-10-05 23:56 - 00000000 ____D C:\Program Files\McAfee
2013-11-30 09:39 - 2009-07-14 05:53 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-11-30 09:39 - 2009-07-14 05:39 - 00083870 _____ C:\windows\setupact.log
2013-11-30 09:38 - 2012-10-06 01:00 - 00156454 _____ C:\windows\PFRO.log
2013-11-30 09:23 - 2013-11-30 09:23 - 00000000 ____D C:\ProgramData\AskPartnerNetwork
2013-11-30 09:23 - 2013-11-30 09:23 - 00000000 ____D C:\Program Files\AskPartnerNetwork
2013-11-30 09:20 - 2013-11-30 09:20 - 00000000 ____D C:\Users\Markelix\AppData\Roaming\Avira
2013-11-30 09:20 - 2013-11-30 09:20 - 00000000 ____D C:\ProgramData\APN
2013-11-30 09:18 - 2012-10-06 02:25 - 00001102 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-30 09:12 - 2013-11-30 09:12 - 00001976 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2013-11-30 09:11 - 2013-11-30 09:11 - 00000000 ____D C:\ProgramData\Avira
2013-11-30 09:11 - 2013-11-30 09:11 - 00000000 ____D C:\Program Files\Avira
2013-11-30 08:48 - 2013-11-30 09:11 - 00137208 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avipbb.sys
2013-11-30 08:48 - 2013-11-30 09:11 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys
2013-11-30 08:48 - 2013-11-30 09:11 - 00067680 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avnetflt.sys
2013-11-30 08:48 - 2013-11-30 09:11 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avkmgr.sys
2013-11-30 08:48 - 2013-11-30 09:11 - 00028520 _____ (Avira GmbH) C:\windows\system32\Drivers\ssmdrv.sys
2013-11-30 08:39 - 2013-11-30 08:36 - 02294160 _____ C:\Users\Markelix\Downloads\avira_free_antivirus.exe
2013-11-30 07:53 - 2013-11-30 07:52 - 00000000 ____D C:\ProgramData\Oracle
2013-11-30 07:52 - 2013-11-30 07:52 - 00094632 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge.dll
2013-11-30 07:52 - 2013-11-30 07:52 - 00000000 ____D C:\Program Files\Common Files\Java
2013-11-30 07:52 - 2013-11-30 07:49 - 00004874 _____ C:\windows\system32\jupdate-1.7.0_45-b18.log
2013-11-30 07:52 - 2012-11-11 22:20 - 00000000 ____D C:\Program Files\Java
2013-11-30 07:49 - 2013-11-30 07:52 - 00174504 _____ (Oracle Corporation) C:\windows\system32\java.exe
2013-11-29 22:23 - 2009-07-14 03:37 - 00000000 ____D C:\windows\tracing
2013-11-22 16:44 - 2013-07-21 14:45 - 00000000 ____D C:\Program Files\Virtual Router
2013-11-22 16:38 - 2013-11-22 16:38 - 01373696 _____ C:\Users\Markelix\Downloads\VirtualRouterInstaller_1.0.msi
2013-11-22 16:23 - 2009-07-26 22:56 - 01498506 _____ C:\windows\system32\PerfStringBackup.INI
2013-11-21 15:12 - 2009-07-14 03:37 - 00000000 ____D C:\windows\system32\de-DE
2013-11-21 14:53 - 2012-10-06 10:57 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-11-21 14:42 - 2013-08-14 13:54 - 00000000 ____D C:\windows\system32\MRT
2013-11-21 14:36 - 2012-10-08 23:07 - 80340640 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\Markelix\AppData\Local\Temp\0110081385798751mcinst.exe
C:\Users\Markelix\AppData\Local\Temp\avgnt.exe
C:\Users\Markelix\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\Markelix\AppData\Local\Temp\MozyUninstaller.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-11-22 05:19
==================== End Of Log ============================ --- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 28-11-2013
Ran by Markelix at 2013-11-30 10:17:36
Running from C:\Users\Markelix\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
32 Bit HP CIO Components Installer (Version: 1.1.0)
Acrobat.com (Version: 1.6.65)
Adobe AIR (Version: 3.7.0.1860)
Adobe Digital Editions 2.0 (Version: 2.0)
Adobe Flash Player 11 ActiveX (Version: 11.9.900.117)
Adobe Reader 9.1 MUI (Version: 9.1.0)
Adobe Shockwave Player 12.0 (Version: 12.0.0.112)
AMD Accelerated Video Transcoding (Version: 2.00.0002)
AMD APP SDK Runtime (Version: 10.0.937.2)
AMD Catalyst Install Manager (Version: 8.0.903.0)
AMD Drag and Drop Transcoding (Version: 2.00.0000)
AMD Fuel (Version: 2012.0704.122.388)
AMD Media Foundation Decoders (Version: 1.0.70704.0230)
AMD VISION Engine Control Center (Version: 2012.0704.122.388)
ASUS WebStorage (Version: 3.0.108.222)
AsusScreensaver (Version: 1.04)
ASUSUpdate for Eee PC (Version: 1.04.01)
AsusVibe2.0 (Version: 2.0.9.157)
Atheros Client Installation Program (Version: 7.0)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (Version: 1.0.0.36)
Avira Free Antivirus (Version: 14.0.1.749)
Avira SearchFree Toolbar (Version: 12.6.0.1898)
Bing Bar (Version: 7.0.850.0)
Boingo Wi-Fi (Version: 1.7.0048)
Broadcom Wireless Network Adapter (Version: 1.00.0000)
Canon LBP5000
CapsHook (Version: 1.0.0.5)
Catalyst Control Center - Branding (Version: 1.00.0000)
Catalyst Control Center Graphics Previews Common (Version: 2012.0704.122.388)
Catalyst Control Center Localization All (Version: 2012.0704.122.388)
CCC Help Chinese Standard (Version: 2012.0704.0121.388)
CCC Help Chinese Traditional (Version: 2012.0704.0121.388)
CCC Help Czech (Version: 2012.0704.0121.388)
CCC Help Danish (Version: 2012.0704.0121.388)
CCC Help Dutch (Version: 2012.0704.0121.388)
CCC Help English (Version: 2012.0704.0121.388)
CCC Help Finnish (Version: 2012.0704.0121.388)
CCC Help French (Version: 2012.0704.0121.388)
CCC Help German (Version: 2012.0704.0121.388)
CCC Help Greek (Version: 2012.0704.0121.388)
CCC Help Hungarian (Version: 2012.0704.0121.388)
CCC Help Italian (Version: 2012.0704.0121.388)
CCC Help Japanese (Version: 2012.0704.0121.388)
CCC Help Korean (Version: 2012.0704.0121.388)
CCC Help Norwegian (Version: 2012.0704.0121.388)
CCC Help Polish (Version: 2012.0704.0121.388)
CCC Help Portuguese (Version: 2012.0704.0121.388)
CCC Help Russian (Version: 2012.0704.0121.388)
CCC Help Spanish (Version: 2012.0704.0121.388)
CCC Help Swedish (Version: 2012.0704.0121.388)
CCC Help Thai (Version: 2012.0704.0121.388)
CCC Help Turkish (Version: 2012.0704.0121.388)
ccc-utility (Version: 2012.0704.122.388)
Chicken Invaders 2
D3DX10 (Version: 15.4.2368.0902)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Der Planer 4 Version 1.3
ebi.BookReader3J (Version: 3.75.14)
E-Cam (Version: 2.0.2.6)
Eee Docking 3.8.3 (Version: 3.8.3)
EeeSplendid (Version: 5.1.2.0011)
FontResizer (Version: 1.01.0011)
Fotogalerie (Version: 16.4.3505.0912)
Galerie de photos (Version: 16.4.3505.0912)
Game Park Console (Version: 6.2.0.3)
Garmin Communicator Plugin (Version: 4.0.4)
Garmin USB Drivers (Version: 2.3.1.0)
Garmin WebUpdater (Version: 2.5.6)
Google Chrome (Version: 31.0.1650.57)
Google Drive (Version: 1.12.5329.1887)
Google Earth Plug-in (Version: 7.1.1.1888)
Google Update Helper (Version: 1.3.21.165)
Hotkey Service (Version: 1.32)
Java 7 Update 45 (Version: 7.0.450)
Java Auto Updater (Version: 2.1.9.8)
Java SE Development Kit 7 Update 21 (Version: 1.7.0.210)
Junk Mail filter update (Version: 16.4.3505.0912)
LiveUpdate (Version: 1.29)
LocaleMe (Version: 1.3)
MAGIX PC Check & Tuning 2012 (Version: 7.0.401.2)
MAGIX PC Live (Version: 1.0.4.6)
MAGIX Screenshare (Version: 4.3.6.1987)
McAfee SiteAdvisor (Version: 3.6.4.160)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Home and Student 2010 (Version: 14.0.6029.1000)
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Outlook Connector (Version: 14.0.5118.5000)
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000)
Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Office Single Image 2010 (Version: 14.0.6029.1000)
Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000)
Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit (Version: 14.0.5120.5000)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SkyDrive (HKCU Version: 17.0.2006.0314)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Mobile Partner (Version: 11.302.09.04.382)
Movie Maker (Version: 16.4.3505.0912)
MSVCRT (Version: 15.4.2862.0708)
MSVCRT110 (Version: 16.4.1108.0727)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MSXML 4.0 SP3 Parser (KB2721691) (Version: 4.30.2114.0)
MSXML 4.0 SP3 Parser (KB2758694) (Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (KB973685) (Version: 4.30.2107.0)
MSXML 4.0 SP3 Parser (Version: 4.30.2100.0)
Photo Common (Version: 16.4.3505.0912)
Photo Gallery (Version: 16.4.3505.0912)
Raccolta foto (Version: 16.4.3505.0912)
Realtek High Definition Audio Driver (Version: 6.0.1.6886)
Shared C Run-time for x86 (Version: 10.0.0)
Super Hybrid Engine (Version: 2.19)
swMSM (Version: 12.0.0.1)
Synaptics Pointing Device Driver (Version: 15.0.20.0)
syncables desktop SE (Version: 5.5.746.11492)
Times Reader (Version: 2.055)
Trend Micro Titanium (Version: 1.0)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (Version: 3)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition
Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition
Update for Microsoft Word 2010 (KB2827323) 32-Bit Edition
Virtual Router v1.0 (Version: 1.0)
Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0) (Version: 04/19/2012 2.3.1.0)
Windows Live (Version: 16.4.3505.0912)
Windows Live Communications Platform (Version: 16.4.3505.0912)
Windows Live Essentials (Version: 16.4.3505.0912)
Windows Live Family Safety (Version: 16.4.3505.0912)
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0)
Windows Live Installer (Version: 16.4.3505.0912)
Windows Live Mail (Version: 16.4.3505.0912)
Windows Live Messenger (Version: 16.4.3505.0912)
Windows Live MIME IFilter (Version: 16.4.3505.0912)
Windows Live Photo Common (Version: 16.4.3505.0912)
Windows Live PIMT Platform (Version: 16.4.3505.0912)
Windows Live SOXE (Version: 16.4.3505.0912)
Windows Live SOXE Definitions (Version: 16.4.3505.0912)
Windows Live UX Platform (Version: 16.4.3505.0912)
Windows Live UX Platform Language Pack (Version: 16.4.3505.0912)
Windows Live Writer (Version: 16.4.3505.0912)
Windows Live Writer Resources (Version: 16.4.3505.0912)
==================== Restore Points =========================
28-09-2013 13:44:31 Geplanter Prüfpunkt
13-10-2013 15:42:39 Windows Update
21-11-2013 13:33:42 Windows Update
22-11-2013 15:40:02 Installed Virtual Router v1.0
30-11-2013 06:45:07 Installed Java 7 Update 45
30-11-2013 07:56:57 Removed Boingo Wi-Fi
==================== Hosts content: ==========================
2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {08612A37-45EA-4376-9E17-54649455234F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-10-06] (Google Inc.)
Task: {0DDDE046-2CED-4B87-B1E3-D8EE4C8B3E6C} - System32\Tasks\Java(TM) Platform SE Auto Updater 2 0 MAGIX PCCT => C:\Program Files\Common Files\Java\Java Update\jusched.exe [2013-07-02] (Oracle Corporation)
Task: {21B94300-7C5A-4CF8-BED4-946A2BDDD7BD} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-12] (Adobe Systems Incorporated)
Task: {337BB81E-8CA6-4B4D-8647-4584A0F839DB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-10-06] (Google Inc.)
Task: {6FAF0162-7542-490D-9748-DC6188F79D7B} - System32\Tasks\Games\UpdateCheck_S-1-5-21-1046992144-3196577750-3050798589-1001
Task: {80C5330D-6D6E-4081-A2AE-D7CDC5901740} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\Java(TM) Platform SE Auto Updater 2 0 MAGIX PCCT.job => C:\Program Files\Common Files\Java\Java Update\jusched.exe
==================== Loaded Modules (whitelisted) =============
2010-09-02 12:08 - 2010-09-02 12:08 - 00118784 _____ () C:\Program Files\ASUS\ASUS WebStorage\3.0.108.222\AsusWSShellExt.dll
2013-11-22 09:32 - 2013-11-14 12:28 - 00702416 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.57\libglesv2.dll
2013-11-22 09:32 - 2013-11-14 12:28 - 00099792 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.57\libegl.dll
2013-11-22 09:32 - 2013-11-14 12:29 - 04055504 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.57\pdf.dll
2013-11-22 09:32 - 2013-11-14 12:29 - 00399312 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll
2013-11-22 09:32 - 2013-11-14 12:28 - 01619408 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.57\ffmpegsumo.dll
2013-11-30 09:42 - 2013-11-30 09:42 - 00098816 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\win32api.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00110080 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\pywintypes27.dll
2013-11-30 09:42 - 2013-11-30 09:42 - 00364544 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\pythoncom27.dll
2013-11-30 09:42 - 2013-11-30 09:42 - 00044032 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\_socket.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 01153024 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\_ssl.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00320512 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\win32com.shell.shell.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00711680 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\_hashlib.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 01175040 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\wx._core_.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00805888 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\wx._gdi_.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00811008 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\wx._windows_.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 01062400 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\wx._controls_.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00735232 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\wx._misc_.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00128512 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\_elementtree.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00127488 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\pyexpat.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00557056 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\pysqlite2._sqlite.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00087040 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\_ctypes.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00119808 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\win32file.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00108544 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\win32security.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00018432 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\win32event.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00038912 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\win32inet.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00122368 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\wx._wizard.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00686080 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\unicodedata.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00026624 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\_multiprocessing.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00070656 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\wx._html2.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00010240 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\select.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00025600 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\win32pdh.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00504832 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\windows._cacheinvalidation.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00011264 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\win32crypt.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00035840 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\win32process.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00017408 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\win32profile.pyd
2013-11-30 09:42 - 2013-11-30 09:42 - 00022528 _____ () C:\Users\Markelix\AppData\Local\Temp\_MEI31442\win32ts.pyd
2013-11-22 09:32 - 2013-11-14 12:29 - 13582800 _____ () C:\Program Files\Google\Chrome\Application\31.0.1650.57\PepperFlash\pepflashplayer.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (11/30/2013 09:35:01 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: Fuel.Service.exe, Version: 1.0.0.0, Zeitstempel: 0x4ff3d5ed
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea91c
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0003224d
ID des fehlerhaften Prozesses: 0x740
Startzeit der fehlerhaften Anwendung: 0xFuel.Service.exe0
Pfad der fehlerhaften Anwendung: Fuel.Service.exe1
Pfad des fehlerhaften Moduls: Fuel.Service.exe2
Berichtskennung: Fuel.Service.exe3
Error: (11/30/2013 07:32:39 AM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {3e09cfd7-948b-40e3-abdd-cd8018ace93f}
Error: (11/29/2013 07:28:39 PM) (Source: Customer Experience Improvement Program) (User: )
Description: 80004005
Error: (11/29/2013 06:25:50 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {4b1b3246-5b45-4ce3-a6ae-dd0ed9da74cf}
Error: (11/29/2013 06:19:50 AM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {e1891654-14f5-40f7-a304-ed81d25a2293}
Error: (11/28/2013 05:34:47 PM) (Source: Customer Experience Improvement Program) (User: )
Description: 80004005
Error: (11/28/2013 04:59:51 PM) (Source: Customer Experience Improvement Program) (User: )
Description: 80004005
Error: (11/28/2013 03:59:54 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {8943f05a-b7f3-450b-ba52-4406bf868e26}
Error: (11/24/2013 06:56:45 PM) (Source: Customer Experience Improvement Program) (User: )
Description: 80004005
Error: (11/24/2013 01:53:09 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {6c63c128-55fe-4b67-b14c-0535a48582ab}
System errors:
=============
Error: (11/30/2013 09:43:58 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Google Update-Dienst (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (11/30/2013 09:43:58 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Google Update-Dienst (gupdate) erreicht.
Error: (11/30/2013 09:40:52 AM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Error: (11/30/2013 08:13:58 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Update" wurde nicht richtig gestartet.
Error: (11/30/2013 08:11:44 AM) (Source: DCOM) (User: )
Description: {209500FC-6B45-4693-8871-6296C4843751}
Error: (11/30/2013 08:09:57 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Software Protection" wurde nicht richtig gestartet.
Error: (11/30/2013 08:07:18 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "1%" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (11/30/2013 08:07:18 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst 1% erreicht.
Error: (11/30/2013 08:06:46 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "McAfee Home Network" wurde nicht richtig gestartet.
Error: (11/30/2013 08:06:34 AM) (Source: DCOM) (User: )
Description: {209500FC-6B45-4693-8871-6296C4843751}
Microsoft Office Sessions:
=========================
Error: (11/30/2013 09:35:01 AM) (Source: Application Error)(User: )
Description: Fuel.Service.exe1.0.0.04ff3d5edntdll.dll6.1.7601.18247521ea91cc00000050003224d74001ceed99eafb2169C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exeC:\windows\SYSTEM32\ntdll.dll4d1bbd69-599a-11e3-b946-bcaec526d7ca
Error: (11/30/2013 07:32:39 AM) (Source: VSS)(User: )
Description: 0x80070005, Zugriff verweigert
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {3e09cfd7-948b-40e3-abdd-cd8018ace93f}
Error: (11/29/2013 07:28:39 PM) (Source: Customer Experience Improvement Program)(User: )
Description: 80004005
Error: (11/29/2013 06:25:50 PM) (Source: VSS)(User: )
Description: 0x80070005, Zugriff verweigert
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {4b1b3246-5b45-4ce3-a6ae-dd0ed9da74cf}
Error: (11/29/2013 06:19:50 AM) (Source: VSS)(User: )
Description: 0x80070005, Zugriff verweigert
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {e1891654-14f5-40f7-a304-ed81d25a2293}
Error: (11/28/2013 05:34:47 PM) (Source: Customer Experience Improvement Program)(User: )
Description: 80004005
Error: (11/28/2013 04:59:51 PM) (Source: Customer Experience Improvement Program)(User: )
Description: 80004005
Error: (11/28/2013 03:59:54 PM) (Source: VSS)(User: )
Description: 0x80070005, Zugriff verweigert
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {8943f05a-b7f3-450b-ba52-4406bf868e26}
Error: (11/24/2013 06:56:45 PM) (Source: Customer Experience Improvement Program)(User: )
Description: 80004005
Error: (11/24/2013 01:53:09 PM) (Source: VSS)(User: )
Description: 0x80070005, Zugriff verweigert
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {6c63c128-55fe-4b67-b14c-0535a48582ab}
==================== Memory info ===========================
Percentage of memory in use: 95%
Total physical RAM: 767.12 MB
Available physical RAM: 34.84 MB
Total Pagefile: 2108.12 MB
Available Pagefile: 298.6 MB
Total Virtual: 2047.88 MB
Available Virtual: 1896.39 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:100 GB) (Free:56.43 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: () (Fixed) (Total:117.87 GB) (Free:117.63 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: 733FF947)
Partition 1: (Active) - (Size=100 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=15 GB) - (Type=1B)
Partition 3: (Not Active) - (Size=118 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=16 MB) - (Type=EF)
==================== End Of Log ============================ GMER: Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-11-30 11:05:52
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\0000005e WDC_WD25 rev.01.0 232,89GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\Markelix\AppData\Local\Temp\uwlyqkoc.sys
---- System - GMER 2.1 ----
SSDT 8DB28536 ZwCreateSection
SSDT 8DB28540 ZwRequestWaitReplyPort
SSDT 8DB2853B ZwSetContextThread
SSDT 8DB28545 ZwSetSecurityObject
SSDT 8DB2854A ZwSystemDebugControl
SSDT 8DB284D7 ZwTerminateProcess
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 142D 83253A15 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 8328D212 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11F7 8329458C 4 Bytes [36, 85, B2, 8D]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1553 832948E8 4 Bytes [40, 85, B2, 8D]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1597 8329492C 4 Bytes [3B, 85, B2, 8D]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1613 832949A8 4 Bytes [45, 85, B2, 8D]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1667 832949FC 4 Bytes [4A, 85, B2, 8D]
.text ...
.text C:\windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8E610000, 0x2BFBF0, 0xE8000020]
---- User code sections - GMER 2.1 ----
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtCreateFile + 6 77C6560E 4 Bytes [28, B8, AE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtCreateFile + B 77C65613 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtMapViewOfSection + 6 77C65C6E 4 Bytes [28, BB, AE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtMapViewOfSection + B 77C65C73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtOpenFile + 6 77C65D1E 4 Bytes [68, B8, AE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtOpenFile + B 77C65D23 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtOpenProcess + 6 77C65DCE 4 Bytes [A8, B9, AE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtOpenProcess + B 77C65DD3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtOpenProcessToken + B 77C65DE3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtOpenProcessTokenEx + 6 77C65DEE 4 Bytes [A8, BA, AE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtOpenProcessTokenEx + B 77C65DF3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtOpenThread + 6 77C65E4E 4 Bytes [68, B9, AE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtOpenThread + B 77C65E53 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtOpenThreadToken + 6 77C65E5E 4 Bytes [68, BA, AE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtOpenThreadToken + B 77C65E63 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtOpenThreadTokenEx + B 77C65E73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtQueryAttributesFile + 6 77C65F7E 4 Bytes [A8, B8, AE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtQueryAttributesFile + B 77C65F83 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtQueryFullAttributesFile + B 77C66033 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtSetInformationFile + 6 77C6667E 4 Bytes [28, B9, AE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtSetInformationFile + B 77C66683 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtSetInformationThread + 6 77C666DE 4 Bytes [28, BA, AE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtSetInformationThread + B 77C666E3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtUnmapViewOfSection + 6 77C669FE 4 Bytes [68, BB, AE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[144] ntdll.dll!NtUnmapViewOfSection + B 77C66A03 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtCreateFile + 6 77C6560E 4 Bytes [28, 94, 7B, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtCreateFile + B 77C65613 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtMapViewOfSection + 6 77C65C6E 4 Bytes [28, 97, 7B, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtMapViewOfSection + B 77C65C73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtOpenFile + 6 77C65D1E 4 Bytes [68, 94, 7B, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtOpenFile + B 77C65D23 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtOpenProcess + 6 77C65DCE 4 Bytes [A8, 95, 7B, 00] {TEST AL, 0x95; JNP 0x4}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtOpenProcess + B 77C65DD3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtOpenProcessToken + B 77C65DE3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtOpenProcessTokenEx + 6 77C65DEE 4 Bytes [A8, 96, 7B, 00] {TEST AL, 0x96; JNP 0x4}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtOpenProcessTokenEx + B 77C65DF3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtOpenThread + 6 77C65E4E 4 Bytes [68, 95, 7B, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtOpenThread + B 77C65E53 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtOpenThreadToken + 6 77C65E5E 4 Bytes [68, 96, 7B, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtOpenThreadToken + B 77C65E63 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtOpenThreadTokenEx + B 77C65E73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtQueryAttributesFile + 6 77C65F7E 4 Bytes [A8, 94, 7B, 00] {TEST AL, 0x94; JNP 0x4}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtQueryAttributesFile + B 77C65F83 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtQueryFullAttributesFile + B 77C66033 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtSetInformationFile + 6 77C6667E 4 Bytes [28, 95, 7B, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtSetInformationFile + B 77C66683 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtSetInformationThread + 6 77C666DE 4 Bytes [28, 96, 7B, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtSetInformationThread + B 77C666E3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtUnmapViewOfSection + 6 77C669FE 4 Bytes [68, 97, 7B, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1468] ntdll.dll!NtUnmapViewOfSection + B 77C66A03 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtCreateFile + 6 77C6560E 4 Bytes [28, 40, A8, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtCreateFile + B 77C65613 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtMapViewOfSection + 6 77C65C6E 4 Bytes [28, 43, A8, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtMapViewOfSection + B 77C65C73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtOpenFile + 6 77C65D1E 4 Bytes [68, 40, A8, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtOpenFile + B 77C65D23 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtOpenProcess + 6 77C65DCE 4 Bytes [A8, 41, A8, 00] {TEST AL, 0x41; TEST AL, 0x0}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtOpenProcess + B 77C65DD3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtOpenProcessToken + B 77C65DE3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtOpenProcessTokenEx + 6 77C65DEE 4 Bytes [A8, 42, A8, 00] {TEST AL, 0x42; TEST AL, 0x0}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtOpenProcessTokenEx + B 77C65DF3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtOpenThread + 6 77C65E4E 4 Bytes [68, 41, A8, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtOpenThread + B 77C65E53 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtOpenThreadToken + 6 77C65E5E 4 Bytes [68, 42, A8, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtOpenThreadToken + B 77C65E63 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtOpenThreadTokenEx + B 77C65E73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtQueryAttributesFile + 6 77C65F7E 4 Bytes [A8, 40, A8, 00] {TEST AL, 0x40; TEST AL, 0x0}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtQueryAttributesFile + B 77C65F83 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtQueryFullAttributesFile + B 77C66033 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtSetInformationFile + 6 77C6667E 4 Bytes [28, 41, A8, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtSetInformationFile + B 77C66683 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtSetInformationThread + 6 77C666DE 4 Bytes [28, 42, A8, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtSetInformationThread + B 77C666E3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtUnmapViewOfSection + 6 77C669FE 4 Bytes [68, 43, A8, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1500] ntdll.dll!NtUnmapViewOfSection + B 77C66A03 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtCreateFile + 6 77C6560E 4 Bytes [28, D8, EC, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtCreateFile + B 77C65613 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtMapViewOfSection + 6 77C65C6E 4 Bytes [28, DB, EC, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtMapViewOfSection + B 77C65C73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtOpenFile + 6 77C65D1E 4 Bytes [68, D8, EC, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtOpenFile + B 77C65D23 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtOpenProcess + 6 77C65DCE 4 Bytes [A8, D9, EC, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtOpenProcess + B 77C65DD3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtOpenProcessToken + B 77C65DE3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtOpenProcessTokenEx + 6 77C65DEE 4 Bytes [A8, DA, EC, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtOpenProcessTokenEx + B 77C65DF3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtOpenThread + 6 77C65E4E 4 Bytes [68, D9, EC, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtOpenThread + B 77C65E53 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtOpenThreadToken + 6 77C65E5E 4 Bytes [68, DA, EC, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtOpenThreadToken + B 77C65E63 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtOpenThreadTokenEx + B 77C65E73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtQueryAttributesFile + 6 77C65F7E 4 Bytes [A8, D8, EC, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtQueryAttributesFile + B 77C65F83 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtQueryFullAttributesFile + B 77C66033 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtSetInformationFile + 6 77C6667E 4 Bytes [28, D9, EC, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtSetInformationFile + B 77C66683 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtSetInformationThread + 6 77C666DE 4 Bytes [28, DA, EC, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtSetInformationThread + B 77C666E3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtUnmapViewOfSection + 6 77C669FE 4 Bytes [68, DB, EC, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3472] ntdll.dll!NtUnmapViewOfSection + B 77C66A03 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtCreateFile + 6 77C6560E 4 Bytes [28, 14, 27, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtCreateFile + B 77C65613 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtMapViewOfSection + 6 77C65C6E 4 Bytes [28, 17, 27, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtMapViewOfSection + B 77C65C73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtOpenFile + 6 77C65D1E 4 Bytes [68, 14, 27, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtOpenFile + B 77C65D23 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtOpenProcess + 6 77C65DCE 4 Bytes [A8, 15, 27, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtOpenProcess + B 77C65DD3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtOpenProcessToken + B 77C65DE3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtOpenProcessTokenEx + 6 77C65DEE 4 Bytes [A8, 16, 27, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtOpenProcessTokenEx + B 77C65DF3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtOpenThread + 6 77C65E4E 4 Bytes [68, 15, 27, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtOpenThread + B 77C65E53 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtOpenThreadToken + 6 77C65E5E 4 Bytes [68, 16, 27, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtOpenThreadToken + B 77C65E63 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtOpenThreadTokenEx + B 77C65E73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtQueryAttributesFile + 6 77C65F7E 4 Bytes [A8, 14, 27, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtQueryAttributesFile + B 77C65F83 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtQueryFullAttributesFile + B 77C66033 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtSetInformationFile + 6 77C6667E 4 Bytes [28, 15, 27, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtSetInformationFile + B 77C66683 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtSetInformationThread + 6 77C666DE 4 Bytes [28, 16, 27, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtSetInformationThread + B 77C666E3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtUnmapViewOfSection + 6 77C669FE 4 Bytes [68, 17, 27, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3984] ntdll.dll!NtUnmapViewOfSection + B 77C66A03 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtCreateFile + 6 77C6560E 4 Bytes [28, 84, 24, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtCreateFile + B 77C65613 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtMapViewOfSection + 6 77C65C6E 4 Bytes [28, 87, 24, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtMapViewOfSection + B 77C65C73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtOpenFile + 6 77C65D1E 4 Bytes [68, 84, 24, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtOpenFile + B 77C65D23 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtOpenProcess + 6 77C65DCE 4 Bytes [A8, 85, 24, 00] {TEST AL, 0x85; AND AL, 0x0}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtOpenProcess + B 77C65DD3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtOpenProcessToken + B 77C65DE3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtOpenProcessTokenEx + 6 77C65DEE 4 Bytes [A8, 86, 24, 00] {TEST AL, 0x86; AND AL, 0x0}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtOpenProcessTokenEx + B 77C65DF3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtOpenThread + 6 77C65E4E 4 Bytes [68, 85, 24, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtOpenThread + B 77C65E53 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtOpenThreadToken + 6 77C65E5E 4 Bytes [68, 86, 24, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtOpenThreadToken + B 77C65E63 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtOpenThreadTokenEx + B 77C65E73 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtQueryAttributesFile + 6 77C65F7E 4 Bytes [A8, 84, 24, 00] {TEST AL, 0x84; AND AL, 0x0}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtQueryAttributesFile + B 77C65F83 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtQueryFullAttributesFile + B 77C66033 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtSetInformationFile + 6 77C6667E 4 Bytes [28, 85, 24, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtSetInformationFile + B 77C66683 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtSetInformationThread + 6 77C666DE 4 Bytes [28, 86, 24, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtSetInformationThread + B 77C666E3 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtUnmapViewOfSection + 6 77C669FE 4 Bytes [68, 87, 24, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5312] ntdll.dll!NtUnmapViewOfSection + B 77C66A03 1 Byte [E2]
---- Devices - GMER 2.1 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys
---- Threads - GMER 2.1 ----
Thread System [4:1640] A6846F2E
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\74f06daaea81
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\74f06daaea81 (not active ControlSet)
Reg HKLM\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Servers@AliveServerCount 2
Reg HKLM\SOFTWARE\Microsoft\Windows Search\UsnNotifier\Windows\Catalogs\SystemIndex@{9DBF58DE-0BF5-11E2-A5FD-806E6F6E6963} 1841856224
---- EOF - GMER 2.1 ---- |