micmueller99 | 04.02.2014 20:13 | Hallo Schrauber,
gerne, hier die Scanns: - defogger_disable.txt
- FRST.txt
- Addition.txt
- gmer.txt
:
und vielen Dank vorab
Michael
defogger_disable.txt Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 15:47 on 04/02/2014 (Biggi Stockhinger)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
Unable to read sptd.sys
SPTD -> Disabled (Service running -> reboot required)
-=E.O.F=- Scann FRST.txt:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-02-2014
Ran by Biggi Stockhinger (administrator) on ACER-9EC38315D8 on 04-02-2014 16:26:10
Running from C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop
Microsoft Windows XP Service Pack 3 (X86) OS Language: German Standard
Internet Explorer Version 7
Boot Mode: Normal
ATTENTION: If processes are not listed WMI should be repaired.
==================== Processes (Whitelisted) ===================
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Adobe ARM] - C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [LifeCam] - C:\Programme\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation)
HKLM\...\Run: [AvastUI.exe] - D:\Eigene Dateien\Programme\Avast\AvastUI.exe [3568312 2013-12-06] (AVAST Software)
HKLM\...\Run: [igfxhkcmd] - C:\WINDOWS\system32\hkcmd.exe [118784 2003-10-02] (Intel Corporation)
HKLM\...\Run: [igfxpers] - C:\WINDOWS\system32\igfxpers.exe [118784 2006-02-07] (Intel Corporation)
HKLM\...\Run: [upfst_es_11.exe] - C:\Dokumente und Einstellungen\Biggi Stockhinger\Lokale Einstellungen\Anwendungsdaten\fst_es_11\upfst_es_11.exe -runhelper
HKLM\...\Run: [PenWes] - C:\Programme\PenWes\penwes.exe [1712640 2013-08-14] ()
HKLM\...\Run: [SunJavaUpdateSched] - C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
HKU\S-1-5-21-2085705805-1061376139-1431769568-1005\...\MountPoints2: {0b45b6be-c98e-11db-9d00-0014a4065a46} - F:\starter.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com
HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = hxxp://www.icq.com/search/results.php?q={searchTerms}&ch_id=osd
HKCU\Software\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = hxxp://www.google.de/
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://de.yahoo.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://de.yahoo.com
SearchScopes: HKCU - DefaultScope {1E5F7004-8DA2-4FE3-A5D3-0A35BF1E169A} URL = hxxp://www.google.de/search?q={searchTerms}
SearchScopes: HKCU - BrowserMngrDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
SearchScopes: HKCU - {1E5F7004-8DA2-4FE3-A5D3-0A35BF1E169A} URL = hxxp://www.google.de/search?q={searchTerms}
BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Eigene Dateien\Programme\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {0BF43445-2F28-4351-9252-17FE6E806AA0} - No File
Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Eigene Dateien\Programme\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU - &Adresse - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
Toolbar: HKCU - &Links - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\SHELL32.dll (Microsoft Corporation)
Toolbar: HKCU - No Name - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - No File
Toolbar: HKCU - No Name - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
Toolbar: HKCU - No Name - {855F3B16-6D32-4FE6-8A56-BBB695989046} - No File
Toolbar: HKCU - No Name - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - No File
Toolbar: HKCU - No Name - {E1BACF55-35E1-4E47-9247-2D48660E5545} - No File
Toolbar: HKCU - &Links - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - No File
Handler: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Programme\Gemeinsame Dateien\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll (Skype Technologies)
ShellExecuteHooks: Windows Desktop Search Namespace Manager - {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Programme\Windows Desktop Search\MsnlNamespaceMgr.dll [304128 2009-05-24] (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 80.58.61.250 80.58.61.254
FireFox:
========
FF ProfilePath: C:\Dokumente und Einstellungen\Biggi Stockhinger\Anwendungsdaten\Mozilla\Firefox\Profiles\g2zsd3fe.default-1388428298343
FF Homepage: https://www.google.de/|file:///C:/Dokumente%20und%20Einstellungen/Biggi%20Stockhinger/Desktop/Job%20Suche%20Page%20Webside%20Vers%2010.0.html
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_43.dll ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 - D:\Eigene Dateien\Programme\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Programme\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Programme\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.0 - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.0 - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.0 - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin: @realnetworks.com/npdlplugin;version=1 - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin: @videolan.org/vlc,version=2.0.7 - D:\Eigene Dateien\Programme\Free Media Player\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 - D:\Eigene Dateien\Programme\Free Media Player\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Programme\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\npupd62.dll ()
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\upd62i9x.dll ()
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\upd62int.dll ()
FF Plugin ProgramFiles/Appdata: C:\Programme\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Programme\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: YouTube Unblocker - C:\Dokumente und Einstellungen\Biggi Stockhinger\Anwendungsdaten\Mozilla\Firefox\Profiles\g2zsd3fe.default-1388428298343\Extensions\youtubeunblocker@unblocker.yt [2014-01-16]
FF Extension: Quick Translator - C:\Dokumente und Einstellungen\Biggi Stockhinger\Anwendungsdaten\Mozilla\Firefox\Profiles\g2zsd3fe.default-1388428298343\Extensions\{5C655500-E712-41e7-9349-CE462F844B19}.xpi [2013-12-30]
FF Extension: No Name - C:\Programme\Mozilla Firefox\extensions\ffxtlbr@babylon.com [2013-12-11]
FF Extension: Java Console - C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2013-12-11]
FF Extension: Skype Click to Call - C:\Programme\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2013-12-11]
FF Extension: Java Console - C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2013-12-11]
FF HKLM\...\Firefox\Extensions: [{3112ca9c-de6d-4884-a869-9855de68056c}] - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Mozilla\Firefox Extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF Extension: Google Toolbar for Firefox - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Mozilla\Firefox Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2008-03-08]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Firefox\Extensions: [fmdownloader@gmail.com] - C:\Programme\Freemake\Freemake Youtube Mp3 Converter\BrowserPlugin\Firefox\fmdownloader@gmail.com\
FF Extension: Freemake Video Downloader Plugin - C:\Programme\Freemake\Freemake Youtube Mp3 Converter\BrowserPlugin\Firefox\fmdownloader@gmail.com\ []
FF HKLM\...\Firefox\Extensions: [{34712C68-7391-4c47-94F3-8F88D49AD632}] - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ []
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-01-17]
FF HKLM\...\Firefox\Extensions: [ytfmdownloader@gmail.com] - C:\Programme\Freemake\Freemake Youtube Mp3 Converter\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\
FF Extension: Freemake Youtube Download Button - C:\Programme\Freemake\Freemake Youtube Mp3 Converter\BrowserPlugin\Firefox\ytfmdownloader@gmail.com\ []
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - D:\Eigene Dateien\Programme\Avast\WebRep\FF
FF Extension: avast! Online Security - D:\Eigene Dateien\Programme\Avast\WebRep\FF [2013-12-06]
========================== Services (Whitelisted) =================
R2 avast! Antivirus; D:\Eigene Dateien\Programme\Avast\AvastSvc.exe [50344 2013-12-06] (AVAST Software)
S3 Freemake Improver; C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [103936 2013-12-12] (Freemake)
S3 FreemakeVideoCapture; C:\Programme\Freemake\CaptureLib\CaptureLibService.exe [9216 2013-12-12] (Ellora Assets Corp.)
S3 gusvc; C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe [136120 2014-01-06] (Google)
R2 JavaQuickStarterService; C:\Programme\Java\jre7\bin\jqs.exe [182696 2014-01-22] (Oracle Corporation)
S2 MozillaMaintenance; C:\Programme\Mozilla Maintenance Service\maintenanceservice.exe [119408 2013-12-11] (Mozilla Foundation)
S3 MSCamSvc; C:\Programme\Microsoft LifeCam\MSCamS32.exe [135536 2010-12-13] (Microsoft Corporation)
S4 RealNetworks Downloader Resolver Service; C:\Programme\RealNetworks\RealDownloader\rndlresolversvc.exe [38608 2012-11-29] ()
R2 RemoteEngineService; C:\Programme\VuuPC\remoteengine.exe [2967568 2014-01-28] (ClickMeIn Limited)
S3 Skype C2C Service; C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Skype\Toolbars\Skype C2C Service\c2c_service.exe [3064000 2012-10-02] (Skype Technologies S.A.)
S2 SkypeUpdate; C:\Programme\Skype\Updater\Updater.exe [171680 2013-09-05] (Skype Technologies)
S3 SystemExplorerHelpService; D:\Eigene Dateien\Programme\System Explorer\service\SystemExplorerService.exe [567256 2012-11-25] (Mister Group)
R2 VuuPCConnectivity; C:\Programme\VuuPC\Connectivity.exe [4747280 2014-01-28] (ClickMeIn Limited)
S3 WMPNetworkSvc; C:\Programme\Windows Media Player\WMPNetwk.exe [920576 2006-11-03] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R3 ALCXSENS; C:\WINDOWS\System32\drivers\ALCXSENS.SYS [400384 2004-02-24] (Sensaura)
R3 ALCXWDM; C:\WINDOWS\System32\drivers\ALCXWDM.SYS [635281 2004-08-02] (Realtek Semiconductor Corp.)
R1 Asapi; C:\WINDOWS\system32\Drivers\Asapi.sys [11264 2002-04-17] (VOB Computersysteme GmbH)
S3 ASPI; C:\WINDOWS\System32\DRIVERS\ASPI32.sys [16512 2002-07-17] (Adaptec)
R2 Aspi32; C:\WINDOWS\system32\Drivers\Aspi32.sys [16512 2002-07-17] (Adaptec)
R2 aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [35656 2013-12-06] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [70384 2013-12-06] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [54832 2013-12-06] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49944 2013-12-06] ()
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [774392 2013-12-06] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [403440 2013-12-06] (AVAST Software)
R1 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57672 2013-12-06] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [178304 2013-12-06] ()
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation)
R2 EpmPsd; C:\WINDOWS\system32\drivers\epm-psd.sys [4096 2004-07-19] (Acer Value Labs, USA)
R2 EpmShd; C:\WINDOWS\system32\drivers\epm-shd.sys [78208 2004-09-02] (Acer Value Labs, USA)
S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2007-03-08] (HP)
S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2007-03-08] (HP)
S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2007-03-08] (HP)
S3 IPN2220; C:\WINDOWS\System32\DRIVERS\i2220ntx.sys [155392 2004-11-04] (Inprocomm, Inc.)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation)
R3 Rasirda; C:\WINDOWS\System32\DRIVERS\rasirda.sys [19584 2001-08-17] (Microsoft Corporation)
R3 RTL8023xp; C:\WINDOWS\System32\DRIVERS\Rtlnicxp.sys [70144 2004-08-09] (Realtek Semiconductor Corporation )
R0 sfvfs02; C:\WINDOWS\System32\drivers\sfvfs02.sys [63488 2005-11-03] (Protection Technology)
S3 SMCIRDA; C:\WINDOWS\System32\DRIVERS\smcirda.sys [35913 2001-08-18] (SMC)
S4 sptd; C:\WINDOWS\System32\Drivers\sptd.sys [715248 2008-01-05] (Duplex Secure Ltd.)
S3 w29n51; C:\WINDOWS\System32\DRIVERS\w29n51.sys [3210496 2004-08-07] (Intel® Corporation)
R3 {6080A529-897E-4629-A488-ABA0C29B635E}; C:\WINDOWS\System32\drivers\ialmsbw.sys [120830 2003-10-08] (Intel Corporation)
R3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91}; C:\WINDOWS\System32\drivers\ialmkchw.sys [98842 2003-10-08] (Intel Corporation)
S3 {E2B953A6-195A-44F9-9BA3-3D5F4E32BB55}; C:\WINDOWS\System32\drivers\wA301a.sys [33847 2003-10-08] (Intel Corporation)
S3 BlueletAudio; system32\DRIVERS\blueletaudio.sys [X]
S3 BlueletSCOAudio; system32\DRIVERS\BlueletSCOAudio.sys [X]
S3 BT; system32\DRIVERS\btnetdrv.sys [X]
S3 Btcsrusb; System32\Drivers\btcusb.sys [X]
S3 BTHidEnum; system32\DRIVERS\vbtenum.sys [X]
S0 BTHidMgr; System32\Drivers\BTHidMgr.sys [X]
S2 osaio; \SystemRoot\system32\drivers\osaio.sys [X]
S2 osanbm; \SystemRoot\system32\drivers\osanbm.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
S3 USBAAPL; System32\Drivers\usbaapl.sys [X]
S3 VComm; system32\DRIVERS\VComm.sys [X]
S3 VcommMgr; System32\Drivers\VcommMgr.sys [X]
U1 WS2IFSL;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-04 16:26 - 2014-02-04 16:26 - 00019569 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\FRST.txt
2014-02-04 16:25 - 2014-02-04 16:21 - 01137152 _____ (Farbar) C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\FRST(1).exe
2014-02-04 16:25 - 2014-02-04 15:58 - 00380416 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\Gmer-19357.exe
2014-02-04 16:22 - 2014-02-04 16:22 - 00000000 ____D () C:\FRST
2014-02-04 15:47 - 2014-02-04 15:48 - 00000020 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\defogger_reenable
2014-02-04 15:40 - 2014-02-04 15:40 - 00000358 _____ () C:\WINDOWS\Tasks\APSnotifierCA.job
2014-02-04 15:38 - 2014-02-04 15:40 - 00000605 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Anwendungsdaten\aps.scan.quick.results
2014-02-04 15:37 - 2014-02-04 15:37 - 00000598 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\AnyProtect.lnk
2014-02-04 15:37 - 2014-02-04 15:37 - 00000000 ____D () C:\Dokumente und Einstellungen\Biggi Stockhinger\Startmenü\Programme\AnyProtect PC Backup
2014-02-04 15:36 - 2014-02-03 17:04 - 00825832 _____ (AnyProtect.com) C:\Dokumente und Einstellungen\Biggi Stockhinger\Lokale Einstellungen\Anwendungsdaten\AnyProtectScannerSetup.exe
2014-02-04 15:35 - 2014-02-04 15:35 - 00000000 ____D () C:\Programme\AnyProtectEx
2014-02-04 15:23 - 2014-02-04 16:06 - 00019616 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\TrojanerBoard.txt
2014-02-04 15:21 - 2014-02-04 15:21 - 00001268 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\My VuuPC.lnk
2014-02-04 15:21 - 2014-02-04 15:21 - 00000000 ____D () C:\Dokumente und Einstellungen\Biggi Stockhinger\Startmenü\Programme\VuuPC
2014-02-04 15:20 - 2014-02-04 15:20 - 00000000 ____D () C:\Programme\VuuPC
2014-02-04 15:12 - 2014-02-04 15:12 - 00016677 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\AdwCleaner[R0].txt
2014-02-04 13:07 - 2014-02-04 13:07 - 00000000 ____D () C:\AdwCleaner
2014-02-03 22:14 - 2014-02-03 22:14 - 00000000 __SHD () C:\FOUND.004
2014-02-03 21:38 - 2014-02-03 21:38 - 00410288 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-01-25 20:56 - 2014-01-25 20:56 - 00000074 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\SUCHEN.URL
2014-01-25 17:43 - 2014-01-25 17:44 - 00004919 _____ () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\rznaopga.sea
2014-01-25 17:42 - 2014-01-25 17:42 - 00000000 ____D () C:\Dokumente und Einstellungen\Biggi Stockhinger\Lokale Einstellungen\TempDIR
2014-01-23 19:07 - 2014-01-23 19:07 - 00000000 __SHD () C:\FOUND.003
2014-01-22 20:41 - 2014-01-22 20:41 - 00001003 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\MailShield2.der
2014-01-22 19:22 - 2014-01-22 19:22 - 00000488 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\Picasa 3.lnk
2014-01-22 19:19 - 2014-01-22 19:19 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Picasa 3
2014-01-22 17:02 - 2014-01-22 17:02 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Java
2014-01-22 17:02 - 2014-01-22 17:01 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2014-01-22 17:02 - 2014-01-22 17:01 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2014-01-22 17:02 - 2014-01-22 17:01 - 00174504 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2014-01-22 17:02 - 2014-01-22 17:01 - 00145408 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2014-01-22 17:02 - 2014-01-22 17:01 - 00094632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-01-21 20:27 - 2014-01-31 22:05 - 00001550 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\DJ Namen.txt
2014-01-21 14:27 - 2014-01-21 14:27 - 00001003 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\MailShield.der
2014-01-21 00:56 - 2014-01-21 00:56 - 00420776 _____ (WinZip Computing) C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\WinZip180.exe
2014-01-16 22:05 - 2013-10-18 16:48 - 00450632 ____R () C:\WINDOWS\system32\Drivers\etc\hosts.20140116-220524.backup
2014-01-16 19:43 - 2014-01-16 19:43 - 00000553 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\System Explorer.lnk
2014-01-16 19:43 - 2014-01-16 19:43 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\System Explorer
2014-01-16 19:43 - 2014-01-16 19:43 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SystemExplorer
2014-01-07 18:51 - 2014-01-07 18:51 - 00000000 ____D () C:\Programme\PenWes
2014-01-07 18:51 - 2014-01-07 18:51 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Penwes
2014-01-06 20:23 - 2014-01-06 20:23 - 04558848 _____ (Google Inc.) C:\WINDOWS\system32\GPhotos.scr
2014-01-06 19:46 - 2014-01-06 19:46 - 00922112 ____N (Microsoft Corporation) C:\WINDOWS\system32\imapi2fs.dll
2014-01-06 19:46 - 2014-01-06 19:46 - 00922112 ____N (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imapi2fs.dll
2014-01-06 19:46 - 2014-01-06 19:46 - 00426496 ____N (Microsoft Corporation) C:\WINDOWS\system32\imapi2.dll
2014-01-06 19:46 - 2014-01-06 19:46 - 00426496 ____N (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imapi2.dll
2014-01-05 05:07 - 2014-01-05 05:07 - 00000000 ____D () C:\Dokumente und Einstellungen\Biggi Stockhinger\Lokale Einstellungen\Anwendungsdaten\FreemakeVideoDownloader
2014-01-05 02:38 - 2014-01-05 05:17 - 00003152 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\Rikki.txt
==================== One Month Modified Files and Folders =======
2014-02-04 16:26 - 2014-02-04 16:26 - 00019569 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\FRST.txt
2014-02-04 16:22 - 2014-02-04 16:22 - 00000000 ____D () C:\FRST
2014-02-04 16:21 - 2014-02-04 16:25 - 01137152 _____ (Farbar) C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\FRST(1).exe
2014-02-04 16:10 - 1980-01-01 00:00 - 00001158 _____ () C:\WINDOWS\system32\wpa.dbl
2014-02-04 16:09 - 2013-12-24 09:12 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2014-02-04 16:08 - 2004-10-07 16:36 - 00000190 ___SH () C:\Dokumente und Einstellungen\LocalService\ntuser.ini
2014-02-04 16:07 - 2013-12-24 09:12 - 00000050 _____ () C:\WINDOWS\wiaservc.log
2014-02-04 16:07 - 2013-12-07 00:24 - 01321070 _____ () C:\WINDOWS\WindowsUpdate.log
2014-02-04 16:07 - 2006-03-22 21:07 - 00000190 ___SH () C:\Dokumente und Einstellungen\Biggi Stockhinger\ntuser.ini
2014-02-04 16:06 - 2014-02-04 15:23 - 00019616 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\TrojanerBoard.txt
2014-02-04 15:58 - 2014-02-04 16:25 - 00380416 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\Gmer-19357.exe
2014-02-04 15:48 - 2014-02-04 15:47 - 00000020 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\defogger_reenable
2014-02-04 15:40 - 2014-02-04 15:40 - 00000358 _____ () C:\WINDOWS\Tasks\APSnotifierCA.job
2014-02-04 15:40 - 2014-02-04 15:38 - 00000605 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Anwendungsdaten\aps.scan.quick.results
2014-02-04 15:37 - 2014-02-04 15:37 - 00000598 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\AnyProtect.lnk
2014-02-04 15:37 - 2014-02-04 15:37 - 00000000 ____D () C:\Dokumente und Einstellungen\Biggi Stockhinger\Startmenü\Programme\AnyProtect PC Backup
2014-02-04 15:35 - 2014-02-04 15:35 - 00000000 ____D () C:\Programme\AnyProtectEx
2014-02-04 15:21 - 2014-02-04 15:21 - 00001268 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\My VuuPC.lnk
2014-02-04 15:21 - 2014-02-04 15:21 - 00000000 ____D () C:\Dokumente und Einstellungen\Biggi Stockhinger\Startmenü\Programme\VuuPC
2014-02-04 15:20 - 2014-02-04 15:20 - 00000000 ____D () C:\Programme\VuuPC
2014-02-04 15:12 - 2014-02-04 15:12 - 00016677 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\AdwCleaner[R0].txt
2014-02-04 13:07 - 2014-02-04 13:07 - 00000000 ____D () C:\AdwCleaner
2014-02-03 22:14 - 2014-02-03 22:14 - 00000000 __SHD () C:\FOUND.004
2014-02-03 21:43 - 2013-12-06 19:45 - 00000378 ____H () C:\WINDOWS\Tasks\avast! Emergency Update.job
2014-02-03 21:38 - 2014-02-03 21:38 - 00410288 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-02-03 17:04 - 2014-02-04 15:36 - 00825832 _____ (AnyProtect.com) C:\Dokumente und Einstellungen\Biggi Stockhinger\Lokale Einstellungen\Anwendungsdaten\AnyProtectScannerSetup.exe
2014-02-01 04:22 - 2013-08-19 10:44 - 00001324 _____ () C:\WINDOWS\system32\d3d9caps.dat
2014-01-31 22:05 - 2014-01-21 20:27 - 00001550 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\DJ Namen.txt
2014-01-29 14:25 - 2012-07-20 12:19 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-01-29 14:24 - 2012-07-04 12:10 - 00692616 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2014-01-29 14:24 - 2012-07-04 12:10 - 00071048 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2014-01-27 01:18 - 2012-08-02 23:28 - 02588581 _____ () C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-S-1-5-21-2085705805-1061376139-1431769568-1005-0.dat
2014-01-27 01:18 - 2012-08-02 23:28 - 00432170 _____ () C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\WPFFontCache_v0400-System.dat
2014-01-27 01:18 - 2012-08-02 22:02 - 00458752 _____ () C:\WINDOWS\system32\config\CaptureL.evt
2014-01-25 20:56 - 2014-01-25 20:56 - 00000074 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\SUCHEN.URL
2014-01-25 17:44 - 2014-01-25 17:43 - 00004919 _____ () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\rznaopga.sea
2014-01-25 17:42 - 2014-01-25 17:42 - 00000000 ____D () C:\Dokumente und Einstellungen\Biggi Stockhinger\Lokale Einstellungen\TempDIR
2014-01-23 19:07 - 2014-01-23 19:07 - 00000000 __SHD () C:\FOUND.003
2014-01-22 20:41 - 2014-01-22 20:41 - 00001003 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\MailShield2.der
2014-01-22 19:22 - 2014-01-22 19:22 - 00000488 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\Picasa 3.lnk
2014-01-22 19:19 - 2014-01-22 19:19 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Picasa 3
2014-01-22 17:02 - 2014-01-22 17:02 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Java
2014-01-22 17:01 - 2014-01-22 17:02 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\system32\javaws.exe
2014-01-22 17:01 - 2014-01-22 17:02 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\system32\javaw.exe
2014-01-22 17:01 - 2014-01-22 17:02 - 00174504 _____ (Oracle Corporation) C:\WINDOWS\system32\java.exe
2014-01-22 17:01 - 2014-01-22 17:02 - 00145408 _____ (Oracle Corporation) C:\WINDOWS\system32\javacpl.cpl
2014-01-22 17:01 - 2014-01-22 17:02 - 00094632 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge.dll
2014-01-22 16:48 - 2013-12-07 00:02 - 00000593 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\IrfanView Thumbnails.lnk
2014-01-22 16:48 - 2013-12-07 00:02 - 00000479 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\IrfanView.lnk
2014-01-22 04:16 - 2013-12-06 20:15 - 00196608 _____ () C:\WINDOWS\system32\config\WindowsPowerShell.evt
2014-01-21 14:27 - 2014-01-21 14:27 - 00001003 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\MailShield.der
2014-01-21 00:56 - 2014-01-21 00:56 - 00420776 _____ (WinZip Computing) C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\WinZip180.exe
2014-01-20 14:14 - 2006-03-29 08:21 - 80340640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-01-17 07:44 - 2012-07-04 17:30 - 00001193 _____ () C:\WINDOWS\wininit.ini
2014-01-16 19:43 - 2014-01-16 19:43 - 00000553 _____ () C:\Dokumente und Einstellungen\All Users\Desktop\System Explorer.lnk
2014-01-16 19:43 - 2014-01-16 19:43 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\System Explorer
2014-01-16 19:43 - 2014-01-16 19:43 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SystemExplorer
2014-01-16 19:05 - 2013-12-09 21:29 - 00086025 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\Job Suche Page Webside Vers 10.html
2014-01-07 20:08 - 2013-10-14 16:34 - 00001118 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\esrach.txt
2014-01-07 18:51 - 2014-01-07 18:51 - 00000000 ____D () C:\Programme\PenWes
2014-01-07 18:51 - 2014-01-07 18:51 - 00000000 ____D () C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Penwes
2014-01-06 20:23 - 2014-01-06 20:23 - 04558848 _____ (Google Inc.) C:\WINDOWS\system32\GPhotos.scr
2014-01-06 19:46 - 2014-01-06 19:46 - 00922112 ____N (Microsoft Corporation) C:\WINDOWS\system32\imapi2fs.dll
2014-01-06 19:46 - 2014-01-06 19:46 - 00922112 ____N (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imapi2fs.dll
2014-01-06 19:46 - 2014-01-06 19:46 - 00426496 ____N (Microsoft Corporation) C:\WINDOWS\system32\imapi2.dll
2014-01-06 19:46 - 2014-01-06 19:46 - 00426496 ____N (Microsoft Corporation) C:\WINDOWS\system32\dllcache\imapi2.dll
2014-01-05 05:17 - 2014-01-05 02:38 - 00003152 _____ () C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\Rikki.txt
2014-01-05 05:07 - 2014-01-05 05:07 - 00000000 ____D () C:\Dokumente und Einstellungen\Biggi Stockhinger\Lokale Einstellungen\Anwendungsdaten\FreemakeVideoDownloader
==================== Bamital & volsnap Check =================
C:\WINDOWS\explorer.exe
[1980-01-01 00:00] - [2008-04-14 04:22] - 1036800 ____A (Microsoft Corporation) 418045a93cd87a352098ab7dabe1b53e
C:\WINDOWS\system32\winlogon.exe
[1980-01-01 00:00] - [2008-04-14 04:23] - 0513024 ____A (Microsoft Corporation) f09a527b422e25c478e38caa0e44417a
C:\WINDOWS\system32\svchost.exe
[1980-01-01 00:00] - [2008-04-14 04:23] - 0014336 ____A (Microsoft Corporation) 4fbc75b74479c7a6f829e0ca19df3366
C:\WINDOWS\system32\services.exe
[1980-01-01 00:00] - [2009-02-09 13:21] - 0111104 ____A (Microsoft Corporation) a3edbe9053889fb24ab22492472b39dc
C:\WINDOWS\system32\User32.dll
[1980-01-01 00:00] - [2008-04-14 04:22] - 0580096 ____A (Microsoft Corporation) b0050cc5340e3a0760dd8b417ff7aebd
C:\WINDOWS\system32\userinit.exe
[1980-01-01 00:00] - [2008-04-14 04:23] - 0026624 ____A (Microsoft Corporation) 788f95312e26389d596c0fa55834e106
C:\WINDOWS\system32\rpcss.dll
[1980-01-01 00:00] - [2009-02-09 12:51] - 0401408 ____A (Microsoft Corporation) 3127afbf2c1ed0ab14a1bbb7aaecb85b
ATTENTION ======> If the system is having audio adware rpcss.dll is patched. Google the MD5, if the MD5 is unique the file is infected.
C:\WINDOWS\system32\Drivers\volsnap.sys
[1980-01-01 00:00] - [2008-04-14 03:52] - 0053760 ____A (Microsoft Corporation) a5a712f4e880874a477af790b5186e1d
==================== End Of Log ============================ --- --- ---
Scann Addition.txt: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 03-02-2014
Ran by Biggi Stockhinger at 2014-02-04 16:27:11
Running from C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira AntiVir PersonalEdition Classic (Disabled - Up to date) {804FD0EC-FFA4-00EB-0D24-347CA8A3377C}
AV: Avira AntiVir PersonalEdition Classic (Disabled - Up to date) {00000000-0000-0000-0000-000000000000}
AV: avast! Antivirus (Disabled - Up to date) {7591DB91-41F0-48A3-B128-1A293FD8233D}
==================== Installed Programs ======================
32 Bit HP CIO Components Installer (Version: 1.0.0 - Hewlett-Packard) Hidden
Acer ePowerManagement (Version: 1.235.5.2 - )
Adobe Flash Player 11 ActiveX (Version: 11.8.800.94 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (Version: 12.0.0.43 - Adobe Systems Incorporated)
Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8 - Adobe Systems Incorporated)
Advanced Fix 2013 version 2.1.3.80 (Version: 2.1.3.80 - Advanced Fix, Inc.)
Agere Systems AC'97 Modem (Version: - )
AIO_Scan (Version: 90.0.222.000 - Hewlett-Packard) Hidden
AnyProtect (Version: 1.0.0.0 - CMI Limited)
ASAPI Update (Version: - )
Audiophile USB 1.5.4.15 (Version: - )
avast! Free Antivirus (Version: 9.0.2008 - Avast Software)
CCleaner (Version: 4.03 - Piriform)
DriverToolkit version 8.1.1.0 (Version: 8.1.1.0 - Megaify Software)
Free Media Player 2.0.7 (Version: 2.0.7 - Somoto Ltd.) <==== ATTENTION
Free YouTube to Mp3 Converter version 3.1 (Version: - DVDVideoSoft Limited.)
Freemake Video Downloader (Version: 3.6.2 - Ellora Assets Corporation)
Freemake Youtube Mp3 Converter (Version: 3.6.2 - Ellora Assets Corporation)
Intel(R) Extreme Graphics 2 Driver (Version: 6.14.10.4497 - )
IrfanView (remove only) (Version: 4.37 - Irfan Skiljan)
Java 7 Update 51 (Version: 7.0.510 - Oracle)
Java Auto Updater (Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
LibreOffice 4.1.3.2 (Version: 4.1.3.2 - The Document Foundation)
Microsoft .NET Framework 2.0 Service Pack 1 Language Pack - DEU (Version: 2.1.21022 - Microsoft Corporation)
Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Corporation (Version: 9.1.0.0 - Microsoft Corporation) Hidden
Microsoft Internationalized Domain Names Mitigation APIs (Version: - Microsoft Corporation) Hidden
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 (Version: - Microsoft Corporation) Hidden
Microsoft LifeCam (Version: 3.60.253.0 - Microsoft Corporation)
Microsoft National Language Support Downlevel APIs (Version: - Microsoft Corporation) Hidden
Microsoft Silverlight (Version: 3.0.40624.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Works (Version: 08.05.0822 - Microsoft Corporation)
MozBackup 1.5.1 (Version: - Pavel Cvrcek)
Mozilla Firefox 26.0 (x86 de) (Version: 26.0 - Mozilla)
Mozilla Maintenance Service (Version: 26.0 - Mozilla)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation)
PenWes [9346] (Version: - )
Picasa 3 (Version: 3.9 - Google, Inc.)
PowerDVD (Version: - )
RealDownloader (Version: 1.3.0 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
Realtek AC'97 Audio (Version: - )
REALTEK Gigabit and Fast Ethernet NIC Driver (Version: 1.60 - REALTEK Semiconductor Corp.)
RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
Security Task Manager 1.8g (Version: 1.8g - Neuber Software)
Sicherheitsupdate für Windows Internet Explorer 7 (KB2544521) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 7 (KB2699988) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 7 (KB2722913) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 7 (KB2744842) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 7 (KB2761465) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 7 (KB2792100) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 7 (KB2797052) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 7 (KB2799329) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 7 (KB2809289) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 7 (KB2817183) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 7 (KB2829530) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 7 (KB2862772) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Media Player (KB911564) (Version: - Microsoft Corporation) Hidden
Skype Click to Call (Version: 6.3.11079 - Skype Technologies S.A.)
Skype™ 6.11 (Version: 6.11.102 - Skype Technologies S.A.)
Spybot - Search & Destroy (Version: 1.6.2 - Safer Networking Limited)
Synaptics Pointing Device Driver (Version: 16.3.15.1 - Synaptics Incorporated)
System Explorer 4.5.0 (Version: - Mister Group)
Toolbox (Version: 90.0.146.000 - Hewlett-Packard) Hidden
Uninstall 1.0.0.1 (Version: - )
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1 - Microsoft Corporation)
VLC media player 2.1.1 (Version: 2.1.1 - VideoLAN)
VuuPC, You're Always a Click Away! (Version: 1.0.0.266 - VuuPC Limited)
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
Windows Media Format 11 runtime (Version: - )
Windows Media Player 11 (Version: - )
Windows XP Service Pack 3 (Version: 20080414.031514 - Microsoft Corporation)
==================== Restore Points =========================
Could not list Restore Points. Check WMI.
==================== Hosts content: ==========================
1980-01-01 00:00 - 2014-01-16 22:05 - 00450656 ____R C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 www.100888290cs.com
127.0.0.1 100888290cs.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 www.10sek.com
127.0.0.1 10sek.com
127.0.0.1 1-2005-search.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 www.123fporn.info
127.0.0.1 123fporn.info
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123haustiereundmehr.com
There are 1000 more lines.
==================== Scheduled Tasks (whitelisted) =============
Task: C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-2085705805-1061376139-1431769568-1005.job => C:\Programme\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-2085705805-1061376139-1431769568-1005.job => C:\Programme\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2085705805-1061376139-1431769568-1005.job => C:\Programme\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2085705805-1061376139-1431769568-1005.job => C:\Programme\Real\RealUpgrade\realupgrade.exe
Task: C:\WINDOWS\Tasks\APSnotifierCA.job => C:\Programme\AnyProtectEx\AnyProtect.exe
Task: C:\WINDOWS\Tasks\avast! Emergency Update.job => D:\Eigene Dateien\Programme\Avast\AvastEmUpdate.exe
Task: C:\WINDOWS\Tasks\EPUpdater.job => C:\DOKUME~1\BIGGIS~1\ANWEND~1\BABSOL~1\Shared\BabMaint.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_LifeExp_exe.job => C:\Programme\Microsoft LifeCam\LifeExp.exe
Task: C:\WINDOWS\Tasks\DriverDoc_UPDATES.job => C:\Programme\DriverDoc\Solvusoftdd.exe
==================== Loaded Modules (whitelisted) =============
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nm => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nm.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== Faulty Device Manager Devices =============
Could not list Devices. Check WMI.
==================== Event log errors: =========================
Application errors:
==================
Error: (02/04/2014 03:25:19 PM) (Source: Application Error) (User: )
Description: Fehlgeschlagene Anwendung wajam_validate.exe, Version 0.0.0.0, fehlgeschlagenes Modul wajam_validate.exe, Version 0.0.0.0, Fehleradresse 0x0000496c.
Das medienspezifische Ereignis für [wajam_validate.exe!ws!] wird verarbeitet.
Error: (02/04/2014 03:19:55 PM) (Source: Application Error) (User: )
Description: Fehlgeschlagene Anwendung wajam_validate.exe, Version 0.0.0.0, fehlgeschlagenes Modul wajam_validate.exe, Version 0.0.0.0, Fehleradresse 0x0000496c.
Das medienspezifische Ereignis für [wajam_validate.exe!ws!] wird verarbeitet.
Error: (02/03/2014 11:18:40 PM) (Source: Application Error) (User: )
Description: Fehlgeschlagene Anwendung explorer.exe, Version 6.0.2900.5512, fehlgeschlagenes Modul unknown, Version 0.0.0.0, Fehleradresse 0x151ed554.
Das medienspezifische Ereignis für [explorer.exe!ws!] wird verarbeitet.
Error: (01/26/2014 07:20:48 PM) (Source: .NET Runtime 4.0 Error Reporting) (User: )
Description: EventType clr20r3, P1 freemakeutilsservice.exe, P2 1.0.0.0, P3 52a98c1a, P4 system.management, P5 4.0.0.0, P6 4ba1e140, P7 fe, P8 133, P9 clr20r30, P10 clr20r31.
Error: (01/26/2014 05:22:08 PM) (Source: .NET Runtime) (User: )
Description: Anwendung: FreemakeUtilsService.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet.
Ausnahmeinformationen: System.Runtime.InteropServices.COMException
Stapel:
bei System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32, IntPtr)
bei System.Management.ManagementObjectCollection+ManagementObjectEnumerator.MoveNext()
bei FreemakeUtilsService.Common.ToolbarInstallationChecker.GetLoggedOnUsersList()
bei FreemakeUtilsService.Common.ToolbarInstallationChecker.CollectInformation()
bei FreemakeUtilsService.Common.ToolbarInstallationChecker.CheckInfo(FreemakeUtilsService.Common.FreemakeToolbarsInfo)
bei FreemakeUtilsService.Statistics.Manager.StartToolbarInfoCheck()
bei FreemakeUtilsService.Statistics.Manager.SettingsSyncFailed(System.Object, System.EventArgs)
bei FreemakeUtilsService.Common.Synchronizer.OnWorkerCompleted(System.Object, System.ComponentModel.RunWorkerCompletedEventArgs)
bei System.ComponentModel.BackgroundWorker.OnRunWorkerCompleted(System.ComponentModel.RunWorkerCompletedEventArgs)
bei System.ComponentModel.BackgroundWorker.AsyncOperationCompleted(System.Object)
bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
bei System.Threading.ThreadPoolWorkQueue.Dispatch()
bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()
Error: (01/26/2014 05:21:00 PM) (Source: .NET Runtime 4.0 Error Reporting) (User: )
Description: EventType clr20r3, P1 freemakeutilsservice.exe, P2 1.0.0.0, P3 52a98c1a, P4 system.management, P5 4.0.0.0, P6 4ba1e140, P7 fe, P8 133, P9 clr20r30, P10 clr20r31.
Error: (01/25/2014 08:27:44 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Aufrufen von Routine "CoCreateInstance" ist ein unerwarteter Fehler aufgetreten. hr = 0x80040206.
Error: (01/25/2014 08:27:44 PM) (Source: EventSystem) (User: )
Description: Das COM+-Ereignissystem hat einen ungültigen Rückgabecode während der internen Verarbeitung erkannt. HRESULT war 800706BA von Zeile 44 von d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp. Wenden Sie sich an den Microsoft-Produktsupport.
Error: (01/25/2014 06:10:10 PM) (Source: .NET Runtime) (User: )
Description: Anwendung: FreemakeUtilsService.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund einer unbehandelten Ausnahme beendet.
Ausnahmeinformationen: System.Runtime.InteropServices.COMException
Stapel:
bei System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32, IntPtr)
bei System.Management.ManagementObjectCollection+ManagementObjectEnumerator.MoveNext()
bei FreemakeUtilsService.Common.ToolbarInstallationChecker.GetLoggedOnUsersList()
bei FreemakeUtilsService.Common.ToolbarInstallationChecker.CollectInformation()
bei FreemakeUtilsService.Common.ToolbarInstallationChecker.CheckInfo(FreemakeUtilsService.Common.FreemakeToolbarsInfo)
bei FreemakeUtilsService.Statistics.Manager.StartToolbarInfoCheck()
bei FreemakeUtilsService.Statistics.Manager.SettingsSyncFailed(System.Object, System.EventArgs)
bei FreemakeUtilsService.Common.Synchronizer.OnWorkerCompleted(System.Object, System.ComponentModel.RunWorkerCompletedEventArgs)
bei System.ComponentModel.BackgroundWorker.OnRunWorkerCompleted(System.ComponentModel.RunWorkerCompletedEventArgs)
bei System.ComponentModel.BackgroundWorker.AsyncOperationCompleted(System.Object)
bei System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
bei System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
bei System.Threading.ThreadPoolWorkQueue.Dispatch()
bei System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()
Error: (01/25/2014 06:09:00 PM) (Source: .NET Runtime 4.0 Error Reporting) (User: )
Description: EventType clr20r3, P1 freemakeutilsservice.exe, P2 1.0.0.0, P3 52a98c1a, P4 system.management, P5 4.0.0.0, P6 4ba1e140, P7 fe, P8 133, P9 clr20r30, P10 clr20r31.
System errors:
=============
Error: (02/04/2014 04:09:59 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "osanbm" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (02/04/2014 04:09:59 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "osaio" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (02/04/2014 00:52:24 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "osanbm" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (02/04/2014 00:52:24 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "osaio" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (02/04/2014 04:01:44 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "osanbm" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (02/04/2014 04:01:44 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "osaio" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (02/04/2014 03:59:54 AM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
AFD
aswRdr
aswRvrt
aswSnx
aswSP
aswTdi
aswVmm
Fips
intelppm
IPSec
MRxSmb
NetBIOS
NetBT
RasAcd
Rdbss
Tcpip
Error: (02/04/2014 03:59:54 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "DHCP-Client" ist vom Dienst "NetBios über TCP/IP" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%31
Error: (02/04/2014 03:55:59 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "osanbm" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (02/04/2014 03:55:59 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "osaio" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Percentage of memory in use: 68%
Total physical RAM: 751.48 MB
Available physical RAM: 239.16 MB
Total Pagefile: 1210.76 MB
Available Pagefile: 693.28 MB
Total Virtual: 2047.88 MB
Available Virtual: 1933.27 MB
==================== Drives ================================
Drive c: (XP) (Fixed) (Total:17.56 GB) (Free:3.91 GB) FAT32 ==>[Drive with boot components (Windows XP)]
Drive d: (DATA) (Fixed) (Total:17.73 GB) (Free:4.49 GB) FAT32
Drive e: (Michi CD 1) (CDROM) (Total:4.35 GB) (Free:0 GB) UDF
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 37 GB) (Disk ID: 0D1A0D19)
Partition 1: (Not Active) - (Size=2 GB) - (Type=12)
Partition 2: (Active) - (Size=18 GB) - (Type=0C)
Partition 3: (Not Active) - (Size=18 GB) - (Type=OF Extended)
==================== End Of Log ============================ Scann Gmer.txt Code:
GMER Logfile:
Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-02-04 17:41:19
Windows 5.1.2600 Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST94019A rev.3.05 37,26GB
Running: Gmer-19357.exe; Driver: C:\DOKUME~1\BIGGIS~1\LOKALE~1\Temp\fflcapob.sys
---- System - GMER 2.1 ----
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwAddBootEntry [0xB1EE5B10]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwAssignProcessToJobObject [0xB1EE65EE]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwClose [0xB1F2A43E]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwCreateEvent [0xB1EF25E0]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwCreateEventPair [0xB1EF262C]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwCreateIoCompletion [0xB1EF27C6]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwCreateKey [0xB1F29DF2]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwCreateMutant [0xB1EF254E]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwCreateSection [0xB1EF2670]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwCreateSemaphore [0xB1EF2596]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwCreateThread [0xB1EE6B24]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwCreateTimer [0xB1EF2780]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwDebugActiveProcess [0xB1EE73DC]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwDeleteBootEntry [0xB1EE5B76]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwDeleteKey [0xB1F2AB04]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwDeleteValueKey [0xB1F2ADBA]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwDuplicateObject [0xB1EEAB58]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwEnumerateKey [0xB1F2A96F]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwEnumerateValueKey [0xB1F2A7DA]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwLoadDriver [0xB1EE575E]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwModifyBootEntry [0xB1EE5BDC]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwNotifyChangeKey [0xB1EEAF4E]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwNotifyChangeMultipleKeys [0xB1EE7E6C]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwOpenEvent [0xB1EF260A]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwOpenEventPair [0xB1EF264E]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwOpenIoCompletion [0xB1EF27EA]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwOpenKey [0xB1F2A14E]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwOpenMutant [0xB1EF2574]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwOpenProcess [0xB1EEA452]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwOpenSection [0xB1EF26FE]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwOpenSemaphore [0xB1EF25BE]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwOpenThread [0xB1EEA83A]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwOpenTimer [0xB1EF27A4]
SSDT \??\C:\WINDOWS\system32\drivers\aswSP.sys ZwProtectVirtualMemory [0xB1FBA0CC]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwQueryKey [0xB1F2A655]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwQueryObject [0xB1EE7D38]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwQueryValueKey [0xB1F2A4A7]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwQueueApcThread [0xB1EE788E]
SSDT \??\C:\WINDOWS\system32\drivers\aswSP.sys ZwRenameKey [0xB1FC7F22]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwRestoreKey [0xB1F29438]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwSetBootEntryOrder [0xB1EE5C42]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwSetBootOptions [0xB1EE5CA8]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwSetContextThread [0xB1EE7256]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwSetSystemInformation [0xB1EE57F8]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwSetSystemPowerState [0xB1EE59CE]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwSetValueKey [0xB1F2AC0B]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwShutdownSystem [0xB1EE595C]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwSuspendProcess [0xB1EE75A6]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwSuspendThread [0xB1EE7708]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwSystemDebugControl [0xB1EE5A56]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwTerminateProcess [0xB1EE7094]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwTerminateThread [0xB1EE7236]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwVdmControl [0xB1EE5D0E]
SSDT \??\C:\WINDOWS\system32\drivers\aswSnx.sys ZwWriteVirtualMemory [0xB1EE664A]
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 25F8 80501E54 4 Bytes JMP FCB1EF27
.text ntkrnlpa.exe!ZwCallbackReturn + 2770 80501FCC 12 Bytes [42, 5C, EE, B1, A8, 5C, EE, ...]
.text ntkrnlpa.exe!ZwCallbackReturn + 2818 80502074 12 Bytes [A6, 75, EE, B1, 08, 77, EE, ...]
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 5EC 8059BA02 4 Bytes CALL B1EE8519 \??\C:\WINDOWS\system32\drivers\aswSnx.sys
init C:\WINDOWS\system32\drivers\ALCXSENS.SYS entry point in "init" section [0xBA5C9900]
---- User code sections - GMER 2.1 ----
.text C:\WINDOWS\System32\smss.exe[352] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[376] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[376] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[388] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[388] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\WINDOWS\system32\csrss.exe[400] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\WINDOWS\system32\csrss.exe[400] KERNEL32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\WINDOWS\system32\winlogon.exe[424] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\WINDOWS\system32\winlogon.exe[424] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\WINDOWS\system32\services.exe[468] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\WINDOWS\system32\services.exe[468] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\WINDOWS\system32\lsass.exe[480] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\WINDOWS\system32\lsass.exe[480] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[660] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[660] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\WINDOWS\System32\svchost.exe[696] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\WINDOWS\System32\svchost.exe[696] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text D:\Eigene Dateien\Programme\Avast\AvastSvc.exe[760] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text D:\Eigene Dateien\Programme\Avast\AvastSvc.exe[760] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\Programme\VuuPC\Connectivity.exe[1008] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\Programme\VuuPC\Connectivity.exe[1008] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text D:\Eigene Dateien\Programme\Avast\AvastUI.exe[1136] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text D:\Eigene Dateien\Programme\Avast\AvastUI.exe[1136] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\WINDOWS\system32\igfxtray.exe[1384] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\WINDOWS\system32\igfxtray.exe[1384] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\WINDOWS\system32\hkcmd.exe[1436] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\WINDOWS\system32\hkcmd.exe[1436] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\Programme\VuuPC\remoteengine.exe[1464] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\Programme\VuuPC\remoteengine.exe[1464] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\Programme\PenWes\penwes.exe[1768] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\Programme\PenWes\penwes.exe[1768] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe[1804] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\Programme\Gemeinsame Dateien\Java\Java Update\jusched.exe[1804] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\WINDOWS\system32\ctfmon.exe[1844] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\WINDOWS\system32\ctfmon.exe[1844] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\WINDOWS\System32\svchost.exe[1856] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\WINDOWS\System32\svchost.exe[1856] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\WINDOWS\System32\svchost.exe[1876] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\WINDOWS\System32\svchost.exe[1876] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\Programme\Java\jre7\bin\jqs.exe[1944] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\Programme\Java\jre7\bin\jqs.exe[1944] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\WINDOWS\Explorer.EXE[1992] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\WINDOWS\Explorer.EXE[1992] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\WINDOWS\system32\wbem\wmiapsrv.exe[2108] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\WINDOWS\system32\wbem\wmiapsrv.exe[2108] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\WINDOWS\system32\wscntfy.exe[2180] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\WINDOWS\system32\wscntfy.exe[2180] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\Programme\VuuPC\RemoteEngineHelper.exe[3948] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\Programme\VuuPC\RemoteEngineHelper.exe[3948] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\Programme\VuuPC\RemoteEngineHelper.exe[3960] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\Programme\VuuPC\RemoteEngineHelper.exe[3960] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
.text C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\Gmer-19357.exe[4052] ntdll.dll!RtlDosSearchPath_U + 186 7C926865 1 Byte [62]
.text C:\Dokumente und Einstellungen\Biggi Stockhinger\Desktop\Gmer-19357.exe[4052] kernel32.dll!GetBinaryTypeW + 80 7C868E04 1 Byte [62]
---- Devices - GMER 2.1 ----
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.sys
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.sys
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.sys
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.sys
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x84 0xFE 0x11 0x7C ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x84 0xFE 0x11 0x7C ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x84 0xFE 0x11 0x7C ...
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0x2E 0xE8 0xE1 0x00 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x71 0x3B 0x04 0x66 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0xFF 0x7C 0x85 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xCD 0x44 0xCD 0xB9 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xB0 0x18 0xED 0xA7 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0x31 0x77 0xE1 0xBA ...
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x01 0x3A 0x48 0xFC ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xF6 0x0F 0x4E 0x58 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0xB1 0xCD 0x45 0x5A ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0xF8 0x31 0x0F 0xA9 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0x6C 0x43 0x2D 0x1E ...
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- --- --- --- |