Windoof02 | 09.07.2014 17:32 | Entschuldigung, das ich das falsch gemacht habe.
Jetzt sollte es richtig sein.
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-07-2014
Ran by ***** (administrator) on RUMPELKISTE on 09-07-2014 12:57:13
Running from C:\Users\*****\Downloads\Virus entfernung
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\vsserv.exe
(SurfRight B.V.) C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
(Foxit Corporation) C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\bdagent.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\seccenter.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender\bdagent.exe [1743088 2014-05-29] (Bitdefender)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2352072 2014-05-30] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1279480 2014-05-30] (NVIDIA Corporation)
HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation)
HKLM\...\Run: [CanonSolutionMenu] => C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe [767312 2009-09-04] (CANON INC.)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [JMB36X IDE Setup] => C:\Windows\RaidTool\xInsIDE.exe [36864 2007-03-20] ()
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [224128 2014-03-18] (Oracle Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKLM\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse-Agent] => C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [568400 2014-05-29] (Bitdefender)
HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse] => C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe [1002048 2014-05-29] (Bitdefender)
HKU\.DEFAULT\...\Run: [Bitdefender-Geldbörse-Anwendungs-Agent] => C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [614744 2014-05-29] (Bitdefender)
HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\Windows\System32\SPReview\SPReview.exe [301568 2014-01-20] (Microsoft Corporation)
HKU\S-1-5-21-515958047-510650339-1647490138-1000\...\Run: [Bitdefender-Geldbörse-Agent] => C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [568400 2014-05-29] (Bitdefender)
HKU\S-1-5-21-515958047-510650339-1647490138-1000\...\Run: [Bitdefender-Geldbörse] => C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe [1002048 2014-05-29] (Bitdefender)
HKU\S-1-5-21-515958047-510650339-1647490138-1000\...\Run: [Bitdefender-Geldbörse-Anwendungs-Agent] => C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe [614744 2014-05-29] (Bitdefender)
HKU\S-1-5-21-515958047-510650339-1647490138-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3666224 2013-09-20] (Safer-Networking Ltd.)
HKU\S-1-5-21-515958047-510650339-1647490138-1000\...\Policies\Explorer: [LinkResolveIgnoreLinkInfo] 1
HKU\S-1-5-21-515958047-510650339-1647490138-1000\...\Policies\Explorer: [NoResolveSearch] 1
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Spybot-S&D Start Center.lnk
ShortcutTarget: Spybot-S&D Start Center.lnk -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWelcome.exe (Safer-Networking Ltd.)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: localhost:21320
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xEB4A2347DD15CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
BHO: Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender\pmbxie.dll (Bitdefender)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre8\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre8\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Bitdefender-Geldbörse - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxie.dll (Bitdefender)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\6boc8hrt.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll ()
FF Plugin: @java.com/DTPlugin,version=11.5.2 - C:\Program Files\Java\jre8\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.5.2 - C:\Program Files\Java\jre8\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Tea Timer - C:\Users\*****\AppData\Roaming\Mozilla\Firefox\Profiles\6boc8hrt.default\Extensions\ttimer@addons.mozilla.org.xpi [2014-01-20]
FF HKLM-x32\...\Firefox\Extensions: [ffpwdman@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman
FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman [2014-01-20]
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR StartupUrls: "hxxp://www.google.com/"
CHR Extension: (Google Docs) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-20]
CHR Extension: (Google Drive) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-20]
CHR Extension: (YouTube) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-20]
CHR Extension: (Bitdefender Wallet) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccahoghmggldkcdjiebjkidpfongdfbl [2014-01-20]
CHR Extension: (Google-Suche) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-20]
CHR Extension: (Google Wallet) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-20]
CHR Extension: (Google Mail) - C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-20]
CHR HKLM-x32\...\Chrome\Extension: [958047-510650339-1647490138-1002] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxcr.crx [2014-03-31]
CHR HKLM-x32\...\Chrome\Extension: [ccahoghmggldkcdjiebjkidpfongdfbl] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\pmbxcr.crx [2014-03-31]
==================== Services (Whitelisted) =================
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2135232 2014-05-21] ()
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [647680 2014-01-21] (Macrovision Europe Ltd.) [File not signed]
R2 FoxitCloudUpdateService; C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [241704 2014-03-25] (Foxit Corporation)
R2 hmpalertsvc; C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1876816 2014-04-14] (SurfRight B.V.)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [50688 2013-11-14] (Hewlett-Packard) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1631008 2014-05-30] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21055432 2014-05-30] (NVIDIA Corporation)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [66048 2013-11-14] (Hewlett-Packard) [File not signed]
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe [67320 2013-10-07] (Bitdefender)
S3 VsEtwService120; C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [87728 2013-10-05] (Microsoft Corporation)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender\vsserv.exe [1526800 2014-05-29] (Bitdefender)
==================== Drivers (Whitelisted) ====================
S3 ADIHdAudAddService; No ImagePath
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [893440 2014-03-01] (BitDefender)
R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [261056 2012-11-02] (BitDefender)
S3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [635392 2014-03-01] (BitDefender)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [103504 2011-11-14] (BitDefender LLC)
S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [82824 2013-11-04] (BitDefender SRL)
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [150256 2013-08-23] (BitDefender LLC)
R2 hmpalert; C:\Windows\System32\drivers\hmpalert.sys [93144 2014-04-14] ()
R3 libusb0; C:\Windows\System32\drivers\libusb0.sys [52832 2014-04-28] (hxxp://libusb-win32.sourceforge.net)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-05-30] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [389240 2013-08-07] (BitDefender S.R.L.)
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()
S3 WinDriver6; C:\Windows\System32\drivers\windrvr6.sys [268800 2014-04-28] (Jungo Connectivity) [File not signed]
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x64.sys [395264 2009-09-28] ()
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-09 12:26 - 2014-06-30 04:09 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-09 12:26 - 2014-06-30 04:04 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-09 12:26 - 2014-06-20 22:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-09 12:26 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-09 12:26 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 12:26 - 2014-06-19 03:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 12:26 - 2014-06-19 03:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-09 12:26 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 12:26 - 2014-06-19 02:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 12:26 - 2014-06-19 02:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-09 12:26 - 2014-06-19 02:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-09 12:26 - 2014-06-19 02:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-09 12:26 - 2014-06-19 02:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 12:26 - 2014-06-19 02:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-09 12:26 - 2014-06-19 02:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-09 12:26 - 2014-06-19 02:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-09 12:26 - 2014-06-19 02:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-09 12:26 - 2014-06-19 02:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-09 12:26 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-09 12:26 - 2014-06-19 02:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-09 12:26 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 12:26 - 2014-06-19 01:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-09 12:26 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-09 12:26 - 2014-06-19 01:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-09 12:26 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 12:26 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 12:26 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 12:26 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-09 12:26 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-09 12:26 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-09 12:26 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-09 12:26 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-09 12:26 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 12:26 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-09 12:26 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-09 12:26 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-09 12:26 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 12:26 - 2014-06-19 01:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-09 12:26 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-09 12:26 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-09 12:26 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-09 12:26 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-09 12:26 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-09 12:26 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-09 12:26 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-09 12:26 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 12:26 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-09 12:26 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-09 12:26 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 12:26 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-09 12:26 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-09 12:26 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-09 12:26 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-09 12:26 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 12:26 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-09 12:26 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-09 12:26 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-09 12:26 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-09 12:26 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-09 12:26 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-09 12:26 - 2014-06-18 03:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 12:26 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 12:26 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-09 12:26 - 2014-05-30 10:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-09 12:26 - 2014-05-30 10:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-09 12:26 - 2014-05-30 10:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-09 12:26 - 2014-05-30 10:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-09 12:26 - 2014-05-30 10:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-09 12:26 - 2014-05-30 10:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-09 12:26 - 2014-05-30 10:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-09 12:26 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-09 12:26 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-09 12:26 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-09 12:26 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-09 12:26 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-09 12:26 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-09 12:26 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-09 12:26 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-09 12:25 - 2014-06-05 16:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-09 12:25 - 2014-06-05 16:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-09 12:25 - 2014-06-05 16:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-07-07 21:46 - 2014-07-07 21:46 - 00000000 ____D () C:\ProgramData\bdch
2014-07-04 12:54 - 2014-07-04 12:54 - 00313256 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-07-04 12:54 - 2014-07-04 12:54 - 00191400 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-07-04 12:54 - 2014-07-04 12:54 - 00190888 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-07-04 12:54 - 2014-07-04 12:54 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-07-04 12:54 - 2014-07-04 12:54 - 00000000 ____D () C:\ProgramData\Oracle
2014-07-04 12:53 - 2014-07-04 12:54 - 00000000 ____D () C:\Program Files\Java
2014-07-04 12:53 - 2014-07-04 12:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2014-07-03 17:08 - 2014-07-03 17:08 - 00000000 ____D () C:\Users\*****\Documents\GitHub
2014-07-03 17:06 - 2014-07-03 17:06 - 00000000 ____D () C:\Users\*****\.ssh
2014-07-03 16:58 - 2014-07-03 17:16 - 00000000 ____D () C:\Users\*****\AppData\Local\GitHub
2014-07-03 16:58 - 2014-07-03 17:08 - 00000000 ____D () C:\Users\*****\AppData\Roaming\GitHub
2014-07-03 16:58 - 2014-07-03 16:58 - 00002140 _____ () C:\Users\*****\Desktop\Git Shell.lnk
2014-07-03 16:58 - 2014-07-03 16:58 - 00000308 _____ () C:\Users\*****\Desktop\GitHub.appref-ms
2014-07-03 16:58 - 2014-07-03 16:58 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GitHub, Inc
2014-07-03 16:56 - 2014-07-03 17:08 - 00000000 ____D () C:\Users\*****\AppData\Local\Deployment
2014-07-03 16:56 - 2014-07-03 16:56 - 00000000 ____D () C:\Users\*****\AppData\Local\Apps\2.0
2014-07-02 13:52 - 2014-07-02 13:58 - 00000000 ____D () C:\Users\*****\Documents\Atmel Studio
2014-07-02 13:52 - 2014-07-02 13:53 - 00000000 ____D () C:\Users\*****\AppData\Roaming\VisualAssistAtmel
2014-07-02 13:52 - 2014-07-02 13:52 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Atmel
2014-07-02 13:52 - 2014-07-02 13:52 - 00000000 ____D () C:\Users\*****\AppData\Local\VisualAssistAtmel
2014-07-02 13:52 - 2014-07-02 13:52 - 00000000 ____D () C:\Users\*****\AppData\Local\IsolatedStorage
2014-07-02 13:52 - 2014-07-02 13:52 - 00000000 ____D () C:\Users\*****\AppData\Local\Atmel
2014-07-02 11:09 - 2014-07-02 11:09 - 00218775 _____ () C:\Users\*****\Desktop\Durchlichtwinlkel_doppelt.dxf
2014-07-02 11:09 - 2014-07-02 11:08 - 00028426 _____ () C:\Users\*****\Desktop\Durchlichtwinlkel_doppelt.brd
2014-07-02 11:05 - 2014-07-09 12:49 - 00296296 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-02 11:05 - 2014-07-09 12:49 - 00002184 _____ () C:\Windows\setupact.log
2014-07-02 11:05 - 2014-07-02 11:05 - 00000640 _____ () C:\Windows\PFRO.log
2014-07-02 11:05 - 2014-07-02 11:05 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-30 18:30 - 2014-06-30 18:30 - 01852683 _____ () C:\Users\*****\Downloads\avrcalc.zip
2014-06-30 18:24 - 2014-06-30 18:32 - 00000000 ____D () C:\Users\*****\Desktop\Flashen
2014-06-30 17:26 - 2014-06-30 17:26 - 00003234 _____ () C:\Users\*****\Desktop\CFile1.c
2014-06-30 16:40 - 2014-06-30 18:06 - 00000373 _____ () C:\Users\*****\Desktop\counter16bit.eep
2014-06-30 16:37 - 2014-06-30 16:37 - 00001241 _____ () C:\Users\*****\Desktop\notepad - Verknüpfung.lnk
2014-06-30 16:37 - 2007-02-18 09:17 - 00003234 _____ () C:\Users\*****\Desktop\counter16bit.hex
2014-06-30 16:31 - 2014-06-30 16:31 - 00001673 _____ () C:\Users\*****\Desktop\atmelstudio - Verknüpfung.lnk
2014-06-30 16:21 - 2014-06-30 16:23 - 128738380 _____ () C:\Users\*****\Downloads\as-asf-msi-6.2.1277-win32.win32.x86.msi
2014-06-30 16:08 - 2014-06-30 16:08 - 00025088 _____ () C:\Users\*****\Desktop\installer_x64.exe
2014-06-30 16:08 - 2014-06-30 16:08 - 00004588 _____ () C:\Users\*****\Desktop\AVRISP_mkII.cat
2014-06-30 16:08 - 2014-06-30 16:08 - 00000446 __RSH () C:\ProgramData\ntuser.pol
2014-06-30 16:08 - 2014-06-30 16:08 - 00000000 ____D () C:\Users\*****\Desktop\x86
2014-06-30 16:08 - 2014-06-30 16:08 - 00000000 ____D () C:\Users\*****\Desktop\license
2014-06-30 16:08 - 2014-06-30 16:08 - 00000000 ____D () C:\Users\*****\Desktop\ia64
2014-06-30 16:08 - 2014-06-30 16:08 - 00000000 ____D () C:\Users\*****\Desktop\amd64
2014-06-30 16:07 - 2014-06-30 16:07 - 00913186 _____ () C:\Users\*****\Downloads\libusb-win32-bin-1.2.6.0.zip
2014-06-30 16:07 - 2014-06-30 16:07 - 00000000 ____D () C:\Users\*****\Downloads\libusb-win32-bin-1.2.6.0
2014-06-30 15:26 - 2014-06-30 15:26 - 00026948 _____ () C:\Users\*****\Desktop\bookmarks-2014-06-30.json
2014-06-30 15:04 - 2014-06-30 16:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibUSB-Win32
2014-06-30 15:04 - 2014-06-30 16:01 - 00000000 ____D () C:\Program Files\LibUSB-Win32
2014-06-30 14:51 - 2014-07-02 13:52 - 00000202 _____ () C:\Users\*****\Documents\timer.aws
2014-06-30 14:48 - 2014-07-02 13:49 - 00002627 _____ () C:\Users\*****\Documents\timer.aps
2014-06-30 14:48 - 2014-06-30 14:50 - 00003234 _____ () C:\Users\*****\Documents\timer.asm
2014-06-30 13:54 - 2014-06-30 13:54 - 00003858 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1390222602
2014-06-30 13:51 - 2014-06-30 13:51 - 00000000 ____D () C:\Users\*****\AppData\Local\Secunia PSI
2014-06-28 23:15 - 2014-06-28 23:15 - 00000000 ____D () C:\ProgramData\VS
2014-06-27 10:37 - 2014-06-27 10:30 - 00075541 _____ () C:\Users\*****\Desktop\PT4115 klein.brd
2014-06-27 10:36 - 2014-06-27 10:34 - 00075574 _____ () C:\Users\*****\Desktop\PT4115 standard.brd
2014-06-24 19:43 - 2014-06-24 19:43 - 00000000 ____D () C:\Users\*****\Desktop\Verlnüpfungen Browser
2014-06-24 19:40 - 2014-06-24 19:42 - 00000000 ____D () C:\Users\*****\Desktop\Verknüpfungen Platine
2014-06-24 13:44 - 2014-06-24 13:44 - 00076303 _____ () C:\Users\*****\Desktop\Gmer.log
2014-06-24 11:44 - 2014-06-24 11:44 - 00057124 _____ () C:\Users\*****\Desktop\FRST.txt
2014-06-24 11:40 - 2014-06-24 11:40 - 00000000 _____ () C:\Users\*****\defogger_reenable
2014-06-24 10:15 - 2014-06-24 10:15 - 00001241 _____ () C:\Users\*****\Desktop\netstat -a - Verknüpfung.lnk
2014-06-24 10:12 - 2014-06-24 10:12 - 00001104 _____ () C:\Users\*****\Desktop\netstat - Verknüpfung.lnk
2014-06-23 20:34 - 2014-06-23 20:36 - 00006930 _____ () C:\Windows\wininit.ini
2014-06-21 16:14 - 2014-06-21 16:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-18 22:31 - 2014-06-30 17:40 - 00000000 ____D () C:\Users\*****\AppData\Local\VirtualStore
2014-06-18 17:57 - 2014-07-09 12:57 - 00000000 ____D () C:\FRST
2014-06-18 17:46 - 2014-06-18 17:46 - 00000278 _____ () C:\Windows\system32\GfLstC71.dat
2014-06-18 17:45 - 2014-07-04 12:54 - 00000000 ____D () C:\Users\*****\AppData\Temp
2014-06-18 17:45 - 2014-06-18 17:45 - 00000000 ____D () C:\Users\*****\AppData\Temp
2014-06-18 17:45 - 2014-06-18 17:21 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-06-18 17:22 - 2014-06-18 22:31 - 00027246 _____ () C:\zoek-results.log
2014-06-18 17:20 - 2014-06-18 17:37 - 00000000 ____D () C:\zoek_backup
2014-06-18 17:10 - 2014-06-18 17:10 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-18 16:55 - 2014-07-09 12:57 - 00000000 ____D () C:\Users\*****\Downloads\Virus entfernung
2014-06-18 16:54 - 2014-06-18 16:54 - 00000000 ____D () C:\Windows\ERUNT
2014-06-18 16:46 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-06-18 16:45 - 2014-06-18 17:50 - 00000000 ____D () C:\AdwCleaner
2014-06-18 14:28 - 2014-06-18 14:28 - 00000000 ____D () C:\Users\Default\Documents\Visual Studio 2010
2014-06-18 14:28 - 2014-06-18 14:28 - 00000000 ____D () C:\Users\Default User\Documents\Visual Studio 2010
2014-06-18 13:52 - 2014-06-18 13:52 - 00001759 _____ () C:\Users\*****\Desktop\AVRStudio - Verknüpfung.lnk
2014-06-18 12:32 - 2014-07-01 18:25 - 00000000 ____D () C:\Users\*****\AppData\Local\VisualAssistAtmel
2014-06-18 12:32 - 2014-07-01 17:44 - 00000000 ____D () C:\Users\*****\AppData\Roaming\VisualAssistAtmel
2014-06-18 12:28 - 2014-05-15 01:49 - 03774821 _____ () C:\Windows\system32\nvcoproc.bin
2014-06-18 12:26 - 2014-05-20 04:44 - 31387936 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-06-18 12:26 - 2014-05-20 04:44 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-06-18 12:26 - 2014-05-20 04:44 - 24025376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-06-18 12:26 - 2014-05-20 04:44 - 17561544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-06-18 12:26 - 2014-05-20 04:44 - 12688328 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-06-18 12:26 - 2014-05-20 04:44 - 11644928 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-06-18 12:26 - 2014-05-20 04:44 - 11599072 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-06-18 12:26 - 2014-05-20 04:44 - 09735256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-06-18 12:26 - 2014-05-20 04:44 - 09697640 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-06-18 12:26 - 2014-05-20 04:44 - 03141976 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-06-18 12:26 - 2014-05-20 04:44 - 02953672 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-06-18 12:26 - 2014-05-20 04:44 - 02785568 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2014-06-18 12:26 - 2014-05-20 04:44 - 02412376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2014-06-18 12:26 - 2014-05-20 04:44 - 01889112 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433788.dll
2014-06-18 12:26 - 2014-05-20 04:44 - 01541576 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433788.dll
2014-06-18 12:26 - 2014-05-20 04:44 - 00895776 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-06-18 12:26 - 2014-05-20 04:44 - 00892704 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-06-18 12:26 - 2014-05-20 04:44 - 00867784 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-06-18 12:26 - 2014-05-20 04:44 - 00861128 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-06-18 12:23 - 2014-06-18 12:34 - 00000000 ____D () C:\Users\*****\Documents\Atmel Studio
2014-06-18 12:23 - 2014-06-18 12:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Atmel
2014-06-18 12:23 - 2014-06-18 12:23 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Atmel
2014-06-18 12:23 - 2014-06-18 12:23 - 00000000 ____D () C:\Users\*****\AppData\Local\Atmel
2014-06-18 12:15 - 2014-06-18 12:15 - 00000000 ____D () C:\Users\*****\Downloads\AVR1913
2014-06-18 12:00 - 2014-05-30 01:07 - 01715176 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2014-06-18 12:00 - 2014-05-30 01:07 - 01291232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2014-06-18 12:00 - 2014-03-31 18:42 - 00040392 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-06-18 12:00 - 2014-03-31 18:42 - 00034760 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-06-18 11:57 - 2014-06-18 11:57 - 00000000 ____D () C:\Users\*****\Documents\Visual Studio 2010
2014-06-18 11:56 - 2014-06-18 11:56 - 00000000 ____D () C:\Windows\PCHEALTH
2014-06-18 11:56 - 2014-06-18 11:56 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 10.0
2014-06-18 11:41 - 2014-06-18 11:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Atmel AVR Tools
2014-06-18 11:41 - 2009-07-07 07:31 - 00290904 _____ () C:\Windows\SysWOW64\vc6-re200l.dll
2014-06-18 11:41 - 2009-07-07 07:31 - 00073728 _____ (Rogue Wave Software Inc) C:\Windows\SysWOW64\RWUXThemeS.dll
2014-06-18 11:41 - 2009-05-20 11:46 - 05752320 _____ (BCGSoft Ltd) C:\Windows\SysWOW64\BCGCBPRO103090.dll
2014-06-18 11:41 - 2009-01-29 16:25 - 04419584 _____ (BCGSoft Ltd) C:\Windows\SysWOW64\BCGCBPRO10180.dll
2014-06-18 11:41 - 2002-01-05 02:37 - 00344064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr70.dll
2014-06-16 20:52 - 2014-06-16 20:52 - 00000000 ____D () C:\Users\*****\IGC
2014-06-16 20:52 - 2014-06-16 20:52 - 00000000 ____D () C:\Users\*****\AppData\Roaming\IGC
2014-06-16 20:51 - 2014-06-16 20:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free DWG Viewer
2014-06-16 20:51 - 2014-06-16 20:51 - 00000000 ____D () C:\Program Files (x86)\IGC
2014-06-16 20:45 - 2014-06-16 20:45 - 00008640 _____ () C:\Users\*****\AppData\Local\recently-used.xbel
2014-06-11 17:16 - 2014-06-11 17:16 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Atmel AVR Tools
2014-06-11 16:49 - 2014-06-30 14:50 - 00000327 _____ () C:\Users\*****\Documents\AvrBuild.bat
2014-06-11 16:42 - 2014-06-11 16:42 - 00000000 ____D () C:\ProgramData\Atmel
2014-06-11 16:33 - 2009-07-14 09:07 - 00143360 _____ (Jungo) C:\Windows\SysWOW64\wdapi1002.dll
2014-06-11 16:33 - 2009-05-14 12:21 - 00157184 _____ (Jungo) C:\Windows\SysWOW64\wdapi1001.dll
2014-06-11 16:33 - 2006-10-18 14:39 - 00102400 _____ (Jungo) C:\Windows\SysWOW64\wdapi811.dll
2014-06-11 15:44 - 2014-06-11 15:44 - 00000000 ____D () C:\Program Files\Microsoft Help Viewer
2014-06-11 15:37 - 2014-06-18 12:24 - 00000000 ____D () C:\Program Files (x86)\Atmel
2014-06-11 15:37 - 2014-06-11 15:37 - 00000000 ____D () C:\Program Files\DIFX
2014-06-11 15:37 - 2014-04-28 09:28 - 00151552 _____ (Jungo Connectivity) C:\Windows\SysWOW64\wdapi1150.dll
2014-06-11 15:37 - 2014-04-28 09:28 - 00151552 _____ (Jungo Connectivity) C:\Windows\SysWOW64\wdapi1140.dll
2014-06-11 15:37 - 2014-04-28 09:28 - 00143360 _____ (Jungo) C:\Windows\SysWOW64\wdapi1010.dll
2014-06-11 15:37 - 2014-04-28 09:28 - 00110592 _____ (Jungo) C:\Windows\SysWOW64\wdapi1100.dll
2014-06-11 15:37 - 2014-04-28 09:28 - 00110592 _____ (Jungo) C:\Windows\SysWOW64\wdapi102.dll
2014-06-11 15:37 - 2014-04-28 09:28 - 00110592 _____ (Jungo) C:\Windows\SysWOW64\wdapi1011.dll
2014-06-11 15:37 - 2014-04-28 09:26 - 00076384 _____ (hxxp://libusb-win32.sourceforge.net) C:\Windows\system32\libusb0.dll
2014-06-11 15:37 - 2014-04-28 09:26 - 00067680 _____ (hxxp://libusb-win32.sourceforge.net) C:\Windows\SysWOW64\libusb0.dll
2014-06-11 15:37 - 2014-04-28 09:26 - 00052832 _____ (hxxp://libusb-win32.sourceforge.net) C:\Windows\system32\Drivers\libusb0.sys
2014-06-11 14:59 - 2014-05-08 11:32 - 03178496 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-06-11 14:59 - 2014-05-08 11:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-06-11 14:59 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-11 14:59 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-11 14:59 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-11 14:59 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-11 14:59 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-11 14:59 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-11 14:59 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-11 14:59 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-11 14:59 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-11 14:59 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-11 14:59 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-06-11 14:59 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
==================== One Month Modified Files and Folders =======
2014-07-09 12:57 - 2014-06-18 17:57 - 00000000 ____D () C:\FRST
2014-07-09 12:57 - 2014-06-18 16:55 - 00000000 ____D () C:\Users\*****\Downloads\Virus entfernung
2014-07-09 12:55 - 2014-01-20 15:43 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-09 12:55 - 2009-07-14 19:58 - 00702562 _____ () C:\Windows\system32\perfh007.dat
2014-07-09 12:55 - 2009-07-14 19:58 - 00151278 _____ () C:\Windows\system32\perfc007.dat
2014-07-09 12:55 - 2009-07-14 07:13 - 01630080 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-09 12:54 - 2009-07-14 06:45 - 00015152 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-09 12:54 - 2009-07-14 06:45 - 00015152 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-09 12:53 - 2014-01-20 14:35 - 01890174 _____ () C:\Windows\WindowsUpdate.log
2014-07-09 12:49 - 2014-07-02 11:05 - 00296296 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-09 12:49 - 2014-07-02 11:05 - 00002184 _____ () C:\Windows\setupact.log
2014-07-09 12:49 - 2014-01-20 15:43 - 00001116 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-09 12:49 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-09 12:48 - 2014-04-30 13:11 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-09 12:48 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-09 12:48 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-09 12:47 - 2014-01-20 15:44 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-09 12:46 - 2014-01-20 15:44 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-07 21:46 - 2014-07-07 21:46 - 00000000 ____D () C:\ProgramData\bdch
2014-07-07 21:11 - 2014-05-14 21:11 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-07 18:07 - 2014-04-08 15:13 - 00000000 ____D () C:\Windows\CryptoGuard
2014-07-07 18:06 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-07-06 13:36 - 2014-03-10 01:13 - 00004146 _____ () C:\Users\*****\AppData\Roaming\LTspiceIV.ini
2014-07-04 12:54 - 2014-07-04 12:54 - 00313256 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-07-04 12:54 - 2014-07-04 12:54 - 00191400 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-07-04 12:54 - 2014-07-04 12:54 - 00190888 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-07-04 12:54 - 2014-07-04 12:54 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-07-04 12:54 - 2014-07-04 12:54 - 00000000 ____D () C:\ProgramData\Oracle
2014-07-04 12:54 - 2014-07-04 12:53 - 00000000 ____D () C:\Program Files\Java
2014-07-04 12:54 - 2014-06-18 17:45 - 00000000 ____D () C:\Users\*****\AppData\Temp
2014-07-04 12:53 - 2014-07-04 12:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2014-07-04 12:53 - 2014-04-29 09:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-07-03 17:16 - 2014-07-03 16:58 - 00000000 ____D () C:\Users\*****\AppData\Local\GitHub
2014-07-03 17:08 - 2014-07-03 17:08 - 00000000 ____D () C:\Users\*****\Documents\GitHub
2014-07-03 17:08 - 2014-07-03 16:58 - 00000000 ____D () C:\Users\*****\AppData\Roaming\GitHub
2014-07-03 17:08 - 2014-07-03 16:56 - 00000000 ____D () C:\Users\*****\AppData\Local\Deployment
2014-07-03 17:06 - 2014-07-03 17:06 - 00000000 ____D () C:\Users\*****\.ssh
2014-07-03 17:06 - 2014-01-21 11:33 - 00000000 ____D () C:\Users\*****
2014-07-03 16:58 - 2014-07-03 16:58 - 00002140 _____ () C:\Users\*****\Desktop\Git Shell.lnk
2014-07-03 16:58 - 2014-07-03 16:58 - 00000308 _____ () C:\Users\*****\Desktop\GitHub.appref-ms
2014-07-03 16:58 - 2014-07-03 16:58 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GitHub, Inc
2014-07-03 16:56 - 2014-07-03 16:56 - 00000000 ____D () C:\Users\*****\AppData\Local\Apps\2.0
2014-07-03 16:39 - 2014-03-02 22:39 - 00000000 ____D () C:\Users\*****\Documents\eagle
2014-07-02 13:58 - 2014-07-02 13:52 - 00000000 ____D () C:\Users\*****\Documents\Atmel Studio
2014-07-02 13:53 - 2014-07-02 13:52 - 00000000 ____D () C:\Users\*****\AppData\Roaming\VisualAssistAtmel
2014-07-02 13:52 - 2014-07-02 13:52 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Atmel
2014-07-02 13:52 - 2014-07-02 13:52 - 00000000 ____D () C:\Users\*****\AppData\Local\VisualAssistAtmel
2014-07-02 13:52 - 2014-07-02 13:52 - 00000000 ____D () C:\Users\*****\AppData\Local\IsolatedStorage
2014-07-02 13:52 - 2014-07-02 13:52 - 00000000 ____D () C:\Users\*****\AppData\Local\Atmel
2014-07-02 13:52 - 2014-06-30 14:51 - 00000202 _____ () C:\Users\*****\Documents\timer.aws
2014-07-02 13:49 - 2014-06-30 14:48 - 00002627 _____ () C:\Users\*****\Documents\timer.aps
2014-07-02 11:09 - 2014-07-02 11:09 - 00218775 _____ () C:\Users\*****\Desktop\Durchlichtwinlkel_doppelt.dxf
2014-07-02 11:08 - 2014-07-02 11:09 - 00028426 _____ () C:\Users\*****\Desktop\Durchlichtwinlkel_doppelt.brd
2014-07-02 11:05 - 2014-07-02 11:05 - 00000640 _____ () C:\Windows\PFRO.log
2014-07-02 11:05 - 2014-07-02 11:05 - 00000000 _____ () C:\Windows\setuperr.log
2014-07-02 11:05 - 2014-01-20 21:47 - 00000000 ____D () C:\Program Files (x86)\BleachBit
2014-07-01 18:25 - 2014-06-18 12:32 - 00000000 ____D () C:\Users\*****\AppData\Local\VisualAssistAtmel
2014-07-01 17:44 - 2014-06-18 12:32 - 00000000 ____D () C:\Users\*****\AppData\Roaming\VisualAssistAtmel
2014-06-30 18:32 - 2014-06-30 18:24 - 00000000 ____D () C:\Users\*****\Desktop\Flashen
2014-06-30 18:30 - 2014-06-30 18:30 - 01852683 _____ () C:\Users\*****\Downloads\avrcalc.zip
2014-06-30 18:06 - 2014-06-30 16:40 - 00000373 _____ () C:\Users\*****\Desktop\counter16bit.eep
2014-06-30 17:40 - 2014-06-18 22:31 - 00000000 ____D () C:\Users\*****\AppData\Local\VirtualStore
2014-06-30 17:26 - 2014-06-30 17:26 - 00003234 _____ () C:\Users\*****\Desktop\CFile1.c
2014-06-30 16:37 - 2014-06-30 16:37 - 00001241 _____ () C:\Users\*****\Desktop\notepad - Verknüpfung.lnk
2014-06-30 16:31 - 2014-06-30 16:31 - 00001673 _____ () C:\Users\*****\Desktop\atmelstudio - Verknüpfung.lnk
2014-06-30 16:23 - 2014-06-30 16:21 - 128738380 _____ () C:\Users\*****\Downloads\as-asf-msi-6.2.1277-win32.win32.x86.msi
2014-06-30 16:08 - 2014-06-30 16:08 - 00025088 _____ () C:\Users\*****\Desktop\installer_x64.exe
2014-06-30 16:08 - 2014-06-30 16:08 - 00004588 _____ () C:\Users\*****\Desktop\AVRISP_mkII.cat
2014-06-30 16:08 - 2014-06-30 16:08 - 00000446 __RSH () C:\ProgramData\ntuser.pol
2014-06-30 16:08 - 2014-06-30 16:08 - 00000000 ____D () C:\Users\*****\Desktop\x86
2014-06-30 16:08 - 2014-06-30 16:08 - 00000000 ____D () C:\Users\*****\Desktop\license
2014-06-30 16:08 - 2014-06-30 16:08 - 00000000 ____D () C:\Users\*****\Desktop\ia64
2014-06-30 16:08 - 2014-06-30 16:08 - 00000000 ____D () C:\Users\*****\Desktop\amd64
2014-06-30 16:08 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-06-30 16:07 - 2014-06-30 16:07 - 00913186 _____ () C:\Users\*****\Downloads\libusb-win32-bin-1.2.6.0.zip
2014-06-30 16:07 - 2014-06-30 16:07 - 00000000 ____D () C:\Users\*****\Downloads\libusb-win32-bin-1.2.6.0
2014-06-30 16:01 - 2014-06-30 15:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibUSB-Win32
2014-06-30 16:01 - 2014-06-30 15:04 - 00000000 ____D () C:\Program Files\LibUSB-Win32
2014-06-30 15:57 - 2014-01-20 14:41 - 00000000 ____D () C:\Users\*****
2014-06-30 15:57 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-06-30 15:26 - 2014-06-30 15:26 - 00026948 _____ () C:\Users\*****\Desktop\bookmarks-2014-06-30.json
2014-06-30 14:50 - 2014-06-30 14:48 - 00003234 _____ () C:\Users\*****\Documents\timer.asm
2014-06-30 14:50 - 2014-06-11 16:49 - 00000327 _____ () C:\Users\*****\Documents\AvrBuild.bat
2014-06-30 13:58 - 2014-01-20 16:13 - 00000000 ____D () C:\Users\*****\Downloads\installiert
2014-06-30 13:56 - 2014-04-11 21:07 - 00000000 ____D () C:\Python27
2014-06-30 13:56 - 2014-04-11 21:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7
2014-06-30 13:55 - 2014-04-11 21:08 - 00000000 ____D () C:\Python34
2014-06-30 13:55 - 2014-04-11 21:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 3.4
2014-06-30 13:54 - 2014-06-30 13:54 - 00003858 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1390222602
2014-06-30 13:54 - 2014-01-20 14:56 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-06-30 13:51 - 2014-06-30 13:51 - 00000000 ____D () C:\Users\*****\AppData\Local\Secunia PSI
2014-06-30 04:09 - 2014-07-09 12:26 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-30 04:04 - 2014-07-09 12:26 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-28 23:39 - 2014-01-20 16:07 - 00000975 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-06-28 23:24 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-06-28 23:15 - 2014-06-28 23:15 - 00000000 ____D () C:\ProgramData\VS
2014-06-27 13:54 - 2014-04-30 15:51 - 00001578 _____ () C:\Users\*****\AppData\Roaming\FoxitReaderUpdateInfo.txt
2014-06-27 10:34 - 2014-06-27 10:36 - 00075574 _____ () C:\Users\*****\Desktop\PT4115 standard.brd
2014-06-27 10:30 - 2014-06-27 10:37 - 00075541 _____ () C:\Users\*****\Desktop\PT4115 klein.brd
2014-06-25 21:50 - 2014-01-20 15:43 - 00004116 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-06-25 21:50 - 2014-01-20 15:43 - 00003864 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-06-24 19:43 - 2014-06-24 19:43 - 00000000 ____D () C:\Users\*****\Desktop\Verlnüpfungen Browser
2014-06-24 19:43 - 2014-03-02 22:30 - 00000000 ___RD () C:\Users\*****\Eagle Projekte
2014-06-24 19:42 - 2014-06-24 19:40 - 00000000 ____D () C:\Users\*****\Desktop\Verknüpfungen Platine
2014-06-24 13:44 - 2014-06-24 13:44 - 00076303 _____ () C:\Users\*****\Desktop\Gmer.log
2014-06-24 11:44 - 2014-06-24 11:44 - 00057124 _____ () C:\Users\*****\Desktop\FRST.txt
2014-06-24 11:40 - 2014-06-24 11:40 - 00000000 _____ () C:\Users\*****\defogger_reenable
2014-06-24 11:35 - 2014-03-02 22:43 - 00001054 _____ () C:\Users\*****\Desktop\Eagle Projekte in eigene Dokumente.lnk
2014-06-24 10:15 - 2014-06-24 10:15 - 00001241 _____ () C:\Users\*****\Desktop\netstat -a - Verknüpfung.lnk
2014-06-24 10:12 - 2014-06-24 10:12 - 00001104 _____ () C:\Users\*****\Desktop\netstat - Verknüpfung.lnk
2014-06-24 09:22 - 2014-01-20 14:53 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-23 20:36 - 2014-06-23 20:34 - 00006930 _____ () C:\Windows\wininit.ini
2014-06-21 16:14 - 2014-06-21 16:14 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-20 22:14 - 2014-07-09 12:26 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-06-20 21:39 - 2014-07-09 12:26 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-06-19 03:39 - 2014-07-09 12:26 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-19 03:06 - 2014-07-09 12:26 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-19 03:06 - 2014-07-09 12:26 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-19 02:48 - 2014-07-09 12:26 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-19 02:42 - 2014-07-09 12:26 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-19 02:42 - 2014-07-09 12:26 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-19 02:41 - 2014-07-09 12:26 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-06-19 02:41 - 2014-07-09 12:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-19 02:32 - 2014-07-09 12:26 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-19 02:31 - 2014-07-09 12:26 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-19 02:26 - 2014-07-09 12:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-19 02:24 - 2014-07-09 12:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-19 02:24 - 2014-07-09 12:26 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-19 02:23 - 2014-07-09 12:26 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-19 02:16 - 2014-07-09 12:26 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-19 02:14 - 2014-07-09 12:26 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-19 02:09 - 2014-07-09 12:26 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-19 01:59 - 2014-07-09 12:26 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-19 01:56 - 2014-07-09 12:26 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-19 01:53 - 2014-07-09 12:26 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-19 01:51 - 2014-07-09 12:26 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-19 01:50 - 2014-07-09 12:26 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-19 01:48 - 2014-07-09 12:26 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-19 01:39 - 2014-07-09 12:26 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-19 01:38 - 2014-07-09 12:26 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-19 01:37 - 2014-07-09 12:26 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-19 01:36 - 2014-07-09 12:26 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-19 01:35 - 2014-07-09 12:26 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-06-19 01:33 - 2014-07-09 12:26 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-19 01:32 - 2014-07-09 12:26 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-19 01:28 - 2014-07-09 12:26 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-19 01:28 - 2014-07-09 12:26 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-19 01:27 - 2014-07-09 12:26 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-19 01:27 - 2014-07-09 12:26 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-19 01:25 - 2014-07-09 12:26 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-19 01:23 - 2014-07-09 12:26 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-19 01:22 - 2014-07-09 12:26 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-19 01:12 - 2014-07-09 12:26 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-19 01:06 - 2014-07-09 12:26 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-19 01:01 - 2014-07-09 12:26 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-19 00:59 - 2014-07-09 12:26 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-19 00:58 - 2014-07-09 12:26 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-19 00:58 - 2014-07-09 12:26 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-19 00:52 - 2014-07-09 12:26 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-19 00:51 - 2014-07-09 12:26 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-19 00:49 - 2014-07-09 12:26 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-19 00:46 - 2014-07-09 12:26 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-06-19 00:45 - 2014-07-09 12:26 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-19 00:35 - 2014-07-09 12:26 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-19 00:34 - 2014-07-09 12:26 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-19 00:15 - 2014-07-09 12:26 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-19 00:13 - 2014-07-09 12:26 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-19 00:09 - 2014-07-09 12:26 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-19 00:07 - 2014-07-09 12:26 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-06-18 22:31 - 2014-06-18 17:22 - 00027246 _____ () C:\zoek-results.log
2014-06-18 17:50 - 2014-06-18 16:45 - 00000000 ____D () C:\AdwCleaner
2014-06-18 17:46 - 2014-06-18 17:46 - 00000278 _____ () C:\Windows\system32\GfLstC71.dat
2014-06-18 17:45 - 2014-06-18 17:45 - 00000000 ____D () C:\Users\*****\AppData\Temp
2014-06-18 17:37 - 2014-06-18 17:20 - 00000000 ____D () C:\zoek_backup
2014-06-18 17:21 - 2014-06-18 17:45 - 00024064 _____ () C:\Windows\zoek-delete.exe
2014-06-18 17:18 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports
2014-06-18 17:10 - 2014-06-18 17:10 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-18 16:54 - 2014-06-18 16:54 - 00000000 ____D () C:\Windows\ERUNT
2014-06-18 16:32 - 2014-01-21 11:34 - 00000000 ____D () C:\Users\*****\AppData\Local\NVIDIA Corporation
2014-06-18 15:06 - 2014-01-20 16:07 - 00000000 ____D () C:\Program Files\CCleaner
2014-06-18 14:58 - 2014-05-23 14:36 - 00000000 _____ () C:\Users\*****\AppData\Roaming\FoxitReaderUpdateInfo.txt
2014-06-18 14:28 - 2014-06-18 14:28 - 00000000 ____D () C:\Users\Default\Documents\Visual Studio 2010
2014-06-18 14:28 - 2014-06-18 14:28 - 00000000 ____D () C:\Users\Default User\Documents\Visual Studio 2010
2014-06-18 13:52 - 2014-06-18 13:52 - 00001759 _____ () C:\Users\*****\Desktop\AVRStudio - Verknüpfung.lnk
2014-06-18 12:34 - 2014-06-18 12:23 - 00000000 ____D () C:\Users\*****\Documents\Atmel Studio
2014-06-18 12:28 - 2014-01-20 18:05 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-06-18 12:25 - 2014-06-18 12:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Atmel
2014-06-18 12:24 - 2014-06-11 15:37 - 00000000 ____D () C:\Program Files (x86)\Atmel
2014-06-18 12:23 - 2014-06-18 12:23 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Atmel
2014-06-18 12:23 - 2014-06-18 12:23 - 00000000 ____D () C:\Users\*****\AppData\Local\Atmel
2014-06-18 12:23 - 2014-05-23 13:57 - 00000000 ____D () C:\Users\*****\AppData\Roaming\inkscape
2014-06-18 12:23 - 2014-01-20 18:40 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-06-18 12:15 - 2014-06-18 12:15 - 00000000 ____D () C:\Users\*****\Downloads\AVR1913
2014-06-18 12:00 - 2014-01-20 18:39 - 00000000 ____D () C:\Users\*****\AppData\Local\NVIDIA Corporation
2014-06-18 12:00 - 2014-01-20 18:05 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-06-18 12:00 - 2014-01-20 15:53 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-06-18 12:00 - 2014-01-20 15:53 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-06-18 11:59 - 2014-01-20 18:06 - 00000000 ____D () C:\Users\*****\AppData\Local\NVIDIA
2014-06-18 11:57 - 2014-06-18 11:57 - 00000000 ____D () C:\Users\*****\Documents\Visual Studio 2010
2014-06-18 11:57 - 2014-01-20 22:49 - 00000000 ____D () C:\Program Files (x86)\Microsoft SQL Server
2014-06-18 11:56 - 2014-06-18 11:56 - 00000000 ____D () C:\Windows\PCHEALTH
2014-06-18 11:56 - 2014-06-18 11:56 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 10.0
2014-06-18 11:56 - 2014-01-20 22:49 - 00000000 ____D () C:\Windows\SysWOW64\1033
2014-06-18 11:41 - 2014-06-18 11:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Atmel AVR Tools
2014-06-18 04:18 - 2014-07-09 12:26 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-06-18 03:51 - 2014-07-09 12:26 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-06-18 03:10 - 2014-07-09 12:26 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-06-16 21:19 - 2014-05-23 14:40 - 00000000 ____D () C:\Users\*****\AppData\Roaming\inkscape
2014-06-16 20:52 - 2014-06-16 20:52 - 00000000 ____D () C:\Users\*****\IGC
2014-06-16 20:52 - 2014-06-16 20:52 - 00000000 ____D () C:\Users\*****\AppData\Roaming\IGC
2014-06-16 20:51 - 2014-06-16 20:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free DWG Viewer
2014-06-16 20:51 - 2014-06-16 20:51 - 00000000 ____D () C:\Program Files (x86)\IGC
2014-06-16 20:45 - 2014-06-16 20:45 - 00008640 _____ () C:\Users\*****\AppData\Local\recently-used.xbel
2014-06-16 19:51 - 2014-01-20 15:44 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-06-15 17:46 - 2014-06-02 09:41 - 00000367 _____ () C:\Users\*****\Sti_Trace.log
2014-06-15 16:50 - 2014-03-01 15:20 - 00000000 ____D () C:\Users\*****\Downloads\PCB
2014-06-13 15:20 - 2014-05-14 21:11 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-06-13 15:20 - 2014-01-20 15:43 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-13 15:20 - 2014-01-20 15:43 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-11 18:38 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-06-11 17:16 - 2014-06-11 17:16 - 00000000 ____D () C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Atmel AVR Tools
2014-06-11 16:42 - 2014-06-11 16:42 - 00000000 ____D () C:\ProgramData\Atmel
2014-06-11 15:44 - 2014-06-11 15:44 - 00000000 ____D () C:\Program Files\Microsoft Help Viewer
2014-06-11 15:37 - 2014-06-11 15:37 - 00000000 ____D () C:\Program Files\DIFX
2014-06-10 15:32 - 2009-07-14 04:34 - 00450709 ____R () C:\Windows\system32\Drivers\etc\hosts.20140701-182502.backup
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-30 20:57
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
Und der Zweite: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-07-09 13:07:10
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Scsi\mv91xx1Port4Path0Target0Lun0 KINGSTON rev.503A 111,79GB
Running: Gmer-19357.exe; Driver: C:\Users\+++++\AppData\Local\Temp\uwdirpoc.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\Windows\System32\win32k.sys!W32pServiceTable fffff96000144000 7 bytes [00, 93, F3, FF, 01, A0, F0]
.text C:\Windows\System32\win32k.sys!W32pServiceTable + 8 fffff96000144008 3 bytes [C0, 06, 02]
---- User code sections - GMER 2.1 ----
.text C:\Program Files\Bitdefender\Bitdefender\vsserv.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077041570 6 bytes [48, B8, F0, 12, 8E, 01]
.text C:\Program Files\Bitdefender\Bitdefender\vsserv.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 8 0000000077041578 4 bytes [00, 00, 50, C3]
.text C:\Program Files\Bitdefender\Bitdefender\vsserv.exe[964] C:\Windows\system32\kernel32.dll!UnhandledExceptionFilter + 1 0000000076f6b7e1 11 bytes [B8, F0, 12, B0, 01, 00, 00, ...]
.text C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe[1056] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 00000000771efac0 5 bytes JMP 0000000174918cf0
.text C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe[1056] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 00000000771efb58 5 bytes JMP 0000000174918ea0
.text C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe[1056] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 00000000771f0038 5 bytes JMP 0000000174918d80
.text C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe[1056] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000766d1465 2 bytes [6D, 76]
.text C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe[1056] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766d14bb 2 bytes [6D, 76]
.text ... * 2
.text C:\Windows\system32\nvvsvc.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\system32\nvvsvc.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\system32\nvvsvc.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\system32\nvvsvc.exe[1100] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Windows\system32\svchost.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\system32\svchost.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\system32\svchost.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\system32\svchost.exe[1188] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Windows\System32\svchost.exe[1280] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\System32\svchost.exe[1280] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\System32\svchost.exe[1280] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\System32\svchost.exe[1280] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Windows\System32\svchost.exe[1316] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\System32\svchost.exe[1316] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\System32\svchost.exe[1316] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\System32\svchost.exe[1316] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Windows\system32\svchost.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\system32\svchost.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\system32\svchost.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\system32\svchost.exe[1364] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Windows\system32\svchost.exe[1388] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\system32\svchost.exe[1388] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\system32\svchost.exe[1388] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\system32\svchost.exe[1388] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Windows\servicing\TrustedInstaller.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\servicing\TrustedInstaller.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\servicing\TrustedInstaller.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\servicing\TrustedInstaller.exe[1556] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Windows\system32\svchost.exe[1768] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\system32\svchost.exe[1768] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\system32\svchost.exe[1768] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\system32\svchost.exe[1768] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Windows\System32\spoolsv.exe[1880] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\System32\spoolsv.exe[1880] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\System32\spoolsv.exe[1880] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\System32\spoolsv.exe[1880] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Windows\system32\svchost.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\system32\svchost.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\system32\svchost.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\system32\svchost.exe[1908] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\system32\svchost.exe[696] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe[1032] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 00000000771efac0 5 bytes JMP 0000000174918cf0
.text C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe[1032] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 00000000771efb58 5 bytes JMP 0000000174918ea0
.text C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe[1032] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 00000000771f0038 5 bytes JMP 0000000174918d80
.text C:\Windows\System32\svchost.exe[556] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\System32\svchost.exe[556] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\System32\svchost.exe[556] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\System32\svchost.exe[556] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[592] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 00000000771efac0 5 bytes JMP 0000000174918cf0
.text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[592] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 00000000771efb58 5 bytes JMP 0000000174918ea0
.text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[592] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 00000000771f0038 5 bytes JMP 0000000174918d80
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1760] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1760] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1760] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1760] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Windows\System32\svchost.exe[2072] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\System32\svchost.exe[2072] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\System32\svchost.exe[2072] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\System32\svchost.exe[2072] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2120] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 00000000771efac0 5 bytes JMP 0000000174918cf0
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2120] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 00000000771efb58 5 bytes JMP 0000000174918ea0
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2120] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 00000000771f0038 5 bytes JMP 0000000174918d80
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2120] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 00000000766d1465 2 bytes [6D, 76]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2120] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 00000000766d14bb 2 bytes [6D, 76]
.text ... * 2
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[2216] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 00000000771efac0 5 bytes JMP 0000000174918cf0
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[2216] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 00000000771efb58 5 bytes JMP 0000000174918ea0
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[2216] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 00000000771f0038 5 bytes JMP 0000000174918d80
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[2216] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000766d1465 2 bytes [6D, 76]
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[2216] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766d14bb 2 bytes [6D, 76]
.text ... * 2
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2280] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2280] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2280] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe[2280] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe[2336] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe[2336] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe[2336] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077041570 6 bytes [48, B8, F0, 12, 8E, 01]
.text C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe[2336] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 8 0000000077041578 4 bytes [00, 00, 50, C3]
.text C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe[2336] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe[2336] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe[2336] C:\Windows\system32\KERNEL32.dll!UnhandledExceptionFilter + 1 0000000076f6b7e1 11 bytes [B8, F0, 12, AA, 01, 00, 00, ...]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[2388] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 00000000771efac0 5 bytes JMP 0000000174918cf0
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[2388] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 00000000771efb58 5 bytes JMP 0000000174918ea0
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[2388] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 00000000771f0038 5 bytes JMP 0000000174918d80
.text C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2580] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 00000000771efac0 5 bytes JMP 0000000174918cf0
.text C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2580] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 00000000771efb58 5 bytes JMP 0000000174918ea0
.text C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe[2580] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 00000000771f0038 5 bytes JMP 0000000174918d80
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2680] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 00000000771efac0 5 bytes JMP 0000000174918cf0
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2680] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 00000000771efb58 5 bytes JMP 0000000174918ea0
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[2680] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 00000000771f0038 5 bytes JMP 0000000174918d80
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2972] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2972] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2972] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2972] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[3456] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[3456] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[3456] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[3456] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Windows\system32\nvvsvc.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\system32\nvvsvc.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\system32\nvvsvc.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\system32\nvvsvc.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Windows\System32\svchost.exe[3624] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\System32\svchost.exe[3624] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\System32\svchost.exe[3624] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\System32\svchost.exe[3624] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Windows\system32\taskhost.exe[3236] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\system32\taskhost.exe[3236] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\system32\taskhost.exe[3236] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\system32\taskhost.exe[3236] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Windows\system32\Dwm.exe[3188] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\system32\Dwm.exe[3188] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\system32\Dwm.exe[3188] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\system32\Dwm.exe[3188] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Windows\Explorer.EXE[3576] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\Explorer.EXE[3576] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\Explorer.EXE[3576] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\Explorer.EXE[3576] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Windows\system32\taskeng.exe[3768] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\system32\taskeng.exe[3768] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\system32\taskeng.exe[3768] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\system32\taskeng.exe[3768] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3128] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 00000000771efac0 5 bytes JMP 0000000174918cf0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3128] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 00000000771efb58 5 bytes JMP 0000000174918ea0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3128] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 00000000771f0038 5 bytes JMP 0000000174918d80
.text C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe[3792] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 00000000771efac0 5 bytes JMP 0000000174918cf0
.text C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe[3792] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 00000000771efb58 5 bytes JMP 0000000174918ea0
.text C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe[3792] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 00000000771f0038 5 bytes JMP 0000000174918d80
.text C:\Program Files\Windows Sidebar\sidebar.exe[3808] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Program Files\Windows Sidebar\sidebar.exe[3808] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Program Files\Windows Sidebar\sidebar.exe[3808] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Program Files\Windows Sidebar\sidebar.exe[3808] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[4072] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 00000000771efac0 5 bytes JMP 0000000174918cf0
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[4072] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 00000000771efb58 5 bytes JMP 0000000174918ea0
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[4072] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 00000000771f0038 5 bytes JMP 0000000174918d80
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[4072] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000766d1465 2 bytes [6D, 76]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[4072] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766d14bb 2 bytes [6D, 76]
.text ... * 2
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4112] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 00000000771efac0 5 bytes JMP 0000000174918cf0
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4112] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 00000000771efb58 5 bytes JMP 0000000174918ea0
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4112] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 00000000771f0038 5 bytes JMP 0000000174918d80
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4120] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 00000000771efac0 5 bytes JMP 0000000174918cf0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4120] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 00000000771efb58 5 bytes JMP 0000000174918ea0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4120] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 00000000771f0038 5 bytes JMP 0000000174918d80
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4656] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4792] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4792] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4792] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4792] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Windows\system32\conhost.exe[4800] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\system32\conhost.exe[4800] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\system32\conhost.exe[4800] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\system32\conhost.exe[4800] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Windows\system32\SearchIndexer.exe[3180] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\system32\SearchIndexer.exe[3180] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\system32\SearchIndexer.exe[3180] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\system32\SearchIndexer.exe[3180] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Program Files\Bitdefender\Bitdefender\seccenter.exe[2812] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Program Files\Bitdefender\Bitdefender\seccenter.exe[2812] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Program Files\Bitdefender\Bitdefender\seccenter.exe[2812] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077041570 6 bytes [48, B8, F0, 12, E7, 03]
.text C:\Program Files\Bitdefender\Bitdefender\seccenter.exe[2812] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 8 0000000077041578 4 bytes [00, 00, 50, C3]
.text C:\Program Files\Bitdefender\Bitdefender\seccenter.exe[2812] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Program Files\Bitdefender\Bitdefender\seccenter.exe[2812] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Program Files\Bitdefender\Bitdefender\seccenter.exe[2812] C:\Windows\system32\KERNEL32.dll!UnhandledExceptionFilter + 1 0000000076f6b7e1 11 bytes [B8, F0, 12, 0E, 04, 00, 00, ...]
.text C:\Program Files (x86)\Secunia\PSI\psi.exe[6112] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 00000000771efac0 5 bytes JMP 0000000174918cf0
.text C:\Program Files (x86)\Secunia\PSI\psi.exe[6112] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 00000000771efb58 5 bytes JMP 0000000174918ea0
.text C:\Program Files (x86)\Secunia\PSI\psi.exe[6112] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 00000000771f0038 5 bytes JMP 0000000174918d80
.text C:\Program Files (x86)\Secunia\PSI\psi.exe[6112] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000766d1465 2 bytes [6D, 76]
.text C:\Program Files (x86)\Secunia\PSI\psi.exe[6112] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766d14bb 2 bytes [6D, 76]
.text ... * 2
.text C:\Windows\system32\DllHost.exe[5200] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077041430 5 bytes JMP 00000000771a0010
.text C:\Windows\system32\DllHost.exe[5200] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077041490 5 bytes JMP 00000000771a0028
.text C:\Windows\system32\DllHost.exe[5200] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 00000000770417b0 1 byte JMP 00000000771a0040
.text C:\Windows\system32\DllHost.exe[5200] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 2 00000000770417b2 3 bytes {JMP 0x15e890}
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[6016] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 00000000771efac0 5 bytes JMP 0000000174918cf0
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[6016] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 00000000771efb58 5 bytes JMP 0000000174918ea0
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[6016] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 00000000771f0038 5 bytes JMP 0000000174918d80
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[6016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000766d1465 2 bytes [6D, 76]
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[6016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000766d14bb 2 bytes [6D, 76]
.text ... * 2
.text C:\Users\+++++\Downloads\Virus entfernung\Gmer-19357.exe[5360] C:\Windows\SysWOW64\ntdll.dll!NtAllocateVirtualMemory 00000000771efac0 5 bytes JMP 0000000174918cf0
.text C:\Users\+++++\Downloads\Virus entfernung\Gmer-19357.exe[5360] C:\Windows\SysWOW64\ntdll.dll!NtFreeVirtualMemory 00000000771efb58 5 bytes JMP 0000000174918ea0
.text C:\Users\+++++\Downloads\Virus entfernung\Gmer-19357.exe[5360] C:\Windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 00000000771f0038 5 bytes JMP 0000000174918d80
---- EOF - GMER 2.1 ----
Gruß Jürgen |