![]() |
Lenovo Netbook ist sehr langsam und stürtzt ab, vermute diverse Viren Hallo zusammen, habe das Problem, dass mein Lenovo Netbook sehr langsam läuft und ab und zu abstürzt. Habe schon den Thread: http://www.trojaner-board.de/71631-p...samer-tun.html genutzt. Leider lässt sich meine C-Platte nicht defragmentieren. Es dauert ewig bis er diese geprüft hat und wenn ich dann selbst "Kurzdefrag" anklicke, dauert es ewig. Das doofe is, dass diese Aktion dann nicht zu Ende geführt werden kann, da das Netbook mittendrin hängen bleibt/ abstürtzt. Ansonsten habe ich alle Punkte aus diesem Thread durchführen können. Bin dann auf http://www.trojaner-board.de/69886-a...-beachten.html gestoßen und versuche so mein Problem zu lösen. Dateien befinden sich im Anhang. Kann leider den "Gmer.txt." nicht hochladen, da dieser die max. Dateigröße überschreitet (hat 124 kb). Ich nutze Comodo als Firewall/ Antivirenprogramm. Es wurden keine "offensichtlichen" Viren gefunden. Ich nutze noch den CCleaner, habe alle Autostarts (außer Comodo) ausgeschaltet. Habe bemerkt, dass enorm viele "svchost dinger" in meinem Taskmanager Prozess zu finden sind. Mein CPU ist sehr stark ausgelastet. Hoffe ich habe alles notiert was ich bemerkt habe. Meinem Leihenwissen möge verziehen werden. Danke euch |
Hi und :hallo: Logs bitte nicht anhängen, notfalls splitten und über mehrere Postings verteilt posten ![]() Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
|
Entschuldige bitte. Hier die Logs: Defogger: defogger_disable by jpshortstuff (23.02.10.1) Log created at 10:27 on 27/08/2014 (**** *******) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- ____________________________________________________ FRST: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:26-08-2014 --- --- --- ____________________________________________________________________ Addition: Additional scan result of Farbar Recovery Scan Tool (x86) Version:26-08-2014 Ran by **** ******* at 2014-08-27 10:50:19 Running from C:\Dokumente und Einstellungen\**** *******\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 2007 Microsoft Office system (HKLM\...\PROHYBRIDR) (Version: 12.0.6425.1000 - Microsoft Corporation) Adobe Flash Player 14 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Flash Player 14 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Reader XI (11.0.08) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated) Ashampoo Photo Commander 11 v.11.1.6 (HKLM\...\{C92AB6F1-0F9C-8526-5DF1-0A2FD0FB33D9}_is1) (Version: 11.1.6 - Ashampoo GmbH & Co. KG) Broadcom WLAN (HKLM\...\{8991E763-21F5-4DEA-A938-5D9D77DCB488}) (Version: 5.10.38.14 Round2 - Lenovo Electronics Inc.) Canon PIXMA iP4000R (HKLM\...\CANONBJ_Deinstall_CNMCP6j.DLL) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 3.08 - Piriform) COMODO Internet Security Premium (HKLM\...\{D32EF4F9-1506-434E-A813-3D4C0AA50300}) (Version: 7.0.53315.4132 - COMODO Security Solutions Inc.) Defraggler (HKLM\...\Defraggler) (Version: 2.18 - Piriform) Google Update Helper (Version: 1.3.23.0 - PriceMeter) Hidden <==== ATTENTION Hotfix für Windows Media Player 11 (KB939683) (HKLM\...\KB939683) (Version: - Microsoft Corporation) Hotfix für Windows XP (KB2158563) (HKLM\...\KB2158563) (Version: 1 - Microsoft Corporation) Hotfix für Windows XP (KB2443685) (HKLM\...\KB2443685) (Version: 1 - Microsoft Corporation) Hotfix für Windows XP (KB2570791) (HKLM\...\KB2570791) (Version: 1 - Microsoft Corporation) Hotfix für Windows XP (KB2633952) (HKLM\...\KB2633952) (Version: 1 - Microsoft Corporation) Hotfix für Windows XP (KB952287) (HKLM\...\KB952287) (Version: 1 - Microsoft Corporation) Hotfix für Windows XP (KB961118) (HKLM\...\KB961118) (Version: 1 - Microsoft Corporation) Hotfix für Windows XP (KB976098-v2) (HKLM\...\KB976098-v2) (Version: 2 - Microsoft Corporation) Hotfix für Windows XP (KB979306) (HKLM\...\KB979306) (Version: 1 - Microsoft Corporation) Hotfix für Windows XP (KB981793) (HKLM\...\KB981793) (Version: 1 - Microsoft Corporation) Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: - ) Intel(R) Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) Lenovo Quick Start (HKLM\...\{357B11ED-5417-4CF3-8EB2-386299BC30E0}) (Version: 1.1.8.7 - DeviceVM, Inc.) Lenovo System Repair - Windows Update Monitor (HKLM\...\{717E0AD5-91EB-459F-AB8B-1B5219BAF7CE}) (Version: 1.3.0.2127 - Lenovo) Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation) Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Choice Guard (Version: 2.0.48.0 - Microsoft Corporation) Hidden Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\...\MSCompPackV1) (Version: 1 - Microsoft Corporation) Microsoft Internationalized Domain Names Mitigation APIs (Version: - Microsoft Corporation) Hidden Microsoft National Language Support Downlevel APIs (Version: - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 2 (SP2) (HKLM\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Access MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Groove Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Hybrid 2007 (Version: 12.0.6425.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Small Business Connectivity Components (HKLM\...\{A939D341-5A04-4E0A-BB55-3E65B386432D}) (Version: 2.0.7024.0 - Microsoft Corporation) Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Software Update for Web Folders (English) 12 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Software Update for Web Folders (German) 12 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft SQL Server VSS Writer (HKLM\...\{FDE96E86-7780-431C-92F7-679C6A7CEC51}) (Version: 9.00.5000.00 - Microsoft Corporation) Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Sync Framework Services Native v1.0 (x86) (HKLM\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\...\Wudf01000) (Version: - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 31.0 (x86 de) (HKLM\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla) MSVCRT (Version: 14.0.1468.721 - Microsoft) Hidden MSXML 6.0 Parser (HKLM\...\{909B62B0-8ACA-4061-A83B-09CAEF609619}) (Version: 6.10.1129.0 - Microsoft Corporation) OpenOffice.org 3.4.1 (HKLM\...\{2303AEEA-0FA8-4AFD-80A9-8F86BA4B44D2}) (Version: 3.41.9593 - Apache Software Foundation) QuickTime (HKLM\...\{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}) (Version: 7.65.17.80 - Apple Inc.) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 5.10.0.5817 - Realtek Semiconductor Corp.) Segoe UI (Version: 14.0.4327.805 - Microsoft Corp) Hidden Sicherheitsupdate für Microsoft Windows (KB2564958) (HKLM\...\KB2564958) (Version: - Microsoft Corporation) Sicherheitsupdate für Windows Internet Explorer 7 (KB2183461) (Version: 1 - Microsoft Corporation) Hidden Sicherheitsupdate für Windows Internet Explorer 7 (KB2360131) (Version: 1 - Microsoft Corporation) Hidden Sicherheitsupdate für Windows Internet Explorer 7 (KB938127-v2) (Version: 2 - Microsoft Corporation) Hidden Sicherheitsupdate für Windows Internet Explorer 7 (KB978207) (Version: 1 - Microsoft Corporation) Hidden Sicherheitsupdate für Windows Internet Explorer 7 (KB982381) (Version: 1 - Microsoft Corporation) Hidden Sicherheitsupdate für Windows Internet Explorer 8 (KB2510531) (HKLM\...\KB2510531-IE8) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows Internet Explorer 8 (KB2544521) (HKLM\...\KB2544521-IE8) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows Internet Explorer 8 (KB2647516) (HKLM\...\KB2647516-IE8) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows Internet Explorer 8 (KB2675157) (HKLM\...\KB2675157-IE8) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows Internet Explorer 8 (KB2879017) (HKLM\...\KB2879017-IE8) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows Internet Explorer 8 (KB2888505) (HKLM\...\KB2888505-IE8) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows Internet Explorer 8 (KB2898785) (HKLM\...\KB2898785-IE8) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows Internet Explorer 8 (KB2909210) (HKLM\...\KB2909210-IE8) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows Internet Explorer 8 (KB2909921) (HKLM\...\KB2909921-IE8) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows Internet Explorer 8 (KB2925418) (HKLM\...\KB2925418-IE8) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows Internet Explorer 8 (KB2936068) (HKLM\...\KB2936068-IE8) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows Internet Explorer 8 (KB2964358) (HKLM\...\KB2964358-IE8) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows Media Player (KB2378111) (HKLM\...\KB2378111_WM9) (Version: - Microsoft Corporation) Sicherheitsupdate für Windows Media Player (KB2834904-v2) (HKLM\...\KB2834904-v2_WM11) (Version: - Microsoft Corporation) Sicherheitsupdate für Windows Media Player (KB952069) (HKLM\...\KB952069_WM9) (Version: - Microsoft Corporation) Sicherheitsupdate für Windows Media Player (KB954155) (HKLM\...\KB954155_WM9) (Version: - Microsoft Corporation) Sicherheitsupdate für Windows Media Player (KB968816) (HKLM\...\KB968816_WM9) (Version: - Microsoft Corporation) Sicherheitsupdate für Windows Media Player (KB973540) (HKLM\...\KB973540_WM9) (Version: - Microsoft Corporation) Sicherheitsupdate für Windows Media Player (KB975558) (HKLM\...\KB975558_WM8) (Version: - Microsoft Corporation) Sicherheitsupdate für Windows Media Player (KB978695) (HKLM\...\KB978695_WM9) (Version: - Microsoft Corporation) Sicherheitsupdate für Windows Media Player (KB979402) (HKLM\...\KB979402_WM9) (Version: - Microsoft Corporation) Sicherheitsupdate für Windows Media Player 11 (KB954154) (HKLM\...\KB954154_WM11) (Version: - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2079403) (HKLM\...\KB2079403) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2115168) (HKLM\...\KB2115168) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2121546) (HKLM\...\KB2121546) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2160329) (HKLM\...\KB2160329) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2229593) (HKLM\...\KB2229593) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2259922) (HKLM\...\KB2259922) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2279986) (HKLM\...\KB2279986) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2286198) (HKLM\...\KB2286198) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2296011) (HKLM\...\KB2296011) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2296199) (HKLM\...\KB2296199) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2347290) (HKLM\...\KB2347290) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2360937) (HKLM\...\KB2360937) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2387149) (HKLM\...\KB2387149) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2393802) (HKLM\...\KB2393802) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2412687) (HKLM\...\KB2412687) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2419632) (HKLM\...\KB2419632) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2423089) (HKLM\...\KB2423089) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2476490) (HKLM\...\KB2476490) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2476687) (HKLM\...\KB2476687) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2478960) (HKLM\...\KB2478960) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2478971) (HKLM\...\KB2478971) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2479628) (HKLM\...\KB2479628) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2479943) (HKLM\...\KB2479943) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2481109) (HKLM\...\KB2481109) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2483185) (HKLM\...\KB2483185) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2485376) (HKLM\...\KB2485376) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2485663) (HKLM\...\KB2485663) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2503658) (HKLM\...\KB2503658) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2503665) (HKLM\...\KB2503665) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2506212) (HKLM\...\KB2506212) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2506223) (HKLM\...\KB2506223) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2507618) (HKLM\...\KB2507618) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2507938) (HKLM\...\KB2507938) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2508272) (HKLM\...\KB2508272) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2508429) (HKLM\...\KB2508429) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2509553) (HKLM\...\KB2509553) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2510581) (Version: 1 - Microsoft Corporation) Hidden Sicherheitsupdate für Windows XP (KB2511455) (HKLM\...\KB2511455) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2524375) (HKLM\...\KB2524375) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2535512) (HKLM\...\KB2535512) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2536276) (HKLM\...\KB2536276) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2536276-v2) (HKLM\...\KB2536276-v2) (Version: 2 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2544893) (HKLM\...\KB2544893) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2544893-v2) (HKLM\...\KB2544893-v2) (Version: 2 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2555917) (HKLM\...\KB2555917) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2562937) (HKLM\...\KB2562937) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2566454) (HKLM\...\KB2566454) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2567053) (HKLM\...\KB2567053) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2567680) (HKLM\...\KB2567680) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2570222) (HKLM\...\KB2570222) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2570947) (HKLM\...\KB2570947) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2584146) (HKLM\...\KB2584146) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2585542) (HKLM\...\KB2585542) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2592799) (HKLM\...\KB2592799) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2598479) (HKLM\...\KB2598479) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2603381) (HKLM\...\KB2603381) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2618451) (HKLM\...\KB2618451) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2619339) (HKLM\...\KB2619339) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2620712) (HKLM\...\KB2620712) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2621440) (HKLM\...\KB2621440) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2624667) (HKLM\...\KB2624667) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2631813) (HKLM\...\KB2631813) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2633171) (HKLM\...\KB2633171) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2639417) (HKLM\...\KB2639417) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2641653) (HKLM\...\KB2641653) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2646524) (HKLM\...\KB2646524) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2647518) (HKLM\...\KB2647518) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2653956) (HKLM\...\KB2653956) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2655992) (HKLM\...\KB2655992) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2659262) (HKLM\...\KB2659262) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2660465) (HKLM\...\KB2660465) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2661637) (HKLM\...\KB2661637) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2676562) (HKLM\...\KB2676562) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2686509) (HKLM\...\KB2686509) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2691442) (HKLM\...\KB2691442) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2698365) (HKLM\...\KB2698365) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2705219-v2) (HKLM\...\KB2705219-v2) (Version: 2 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2712808) (HKLM\...\KB2712808) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2719985) (HKLM\...\KB2719985) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2723135-v2) (HKLM\...\KB2723135-v2) (Version: 2 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2727528) (HKLM\...\KB2727528) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2757638) (HKLM\...\KB2757638) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2758857) (HKLM\...\KB2758857) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2770660) (HKLM\...\KB2770660) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2780091) (HKLM\...\KB2780091) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2802968) (HKLM\...\KB2802968) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2807986) (HKLM\...\KB2807986) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2813345) (HKLM\...\KB2813345) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2820197) (HKLM\...\KB2820197) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2820917) (HKLM\...\KB2820917) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2834886) (HKLM\...\KB2834886) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2845187) (HKLM\...\KB2845187) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2847311) (HKLM\...\KB2847311) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2849470) (HKLM\...\KB2849470) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2850869) (HKLM\...\KB2850869) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2859537) (HKLM\...\KB2859537) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2862152) (HKLM\...\KB2862152) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2862330) (HKLM\...\KB2862330) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2862335) (HKLM\...\KB2862335) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2864063) (HKLM\...\KB2864063) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2868038) (HKLM\...\KB2868038) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2868626) (HKLM\...\KB2868626) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2876217) (HKLM\...\KB2876217) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2876331) (HKLM\...\KB2876331) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2883150) (HKLM\...\KB2883150) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2884256) (HKLM\...\KB2884256) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2892075) (HKLM\...\KB2892075) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2893294) (HKLM\...\KB2893294) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2893984) (HKLM\...\KB2893984) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2898715) (HKLM\...\KB2898715) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2900986) (HKLM\...\KB2900986) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2914368) (HKLM\...\KB2914368) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2916036) (HKLM\...\KB2916036) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2922229) (HKLM\...\KB2922229) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2929961) (HKLM\...\KB2929961) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB2930275) (HKLM\...\KB2930275) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB923561) (HKLM\...\KB923561) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB941569) (HKLM\...\KB941569) (Version: - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB946648) (HKLM\...\KB946648) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB950762) (HKLM\...\KB950762) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB950974) (HKLM\...\KB950974) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB951066) (HKLM\...\KB951066) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB951376-v2) (HKLM\...\KB951376-v2) (Version: 2 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB951748) (HKLM\...\KB951748) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB952004) (HKLM\...\KB952004) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB952954) (HKLM\...\KB952954) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB954459) (HKLM\...\KB954459) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB955069) (HKLM\...\KB955069) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB956572) (HKLM\...\KB956572) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB956744) (HKLM\...\KB956744) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB956802) (HKLM\...\KB956802) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB956803) (HKLM\...\KB956803) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB956844) (HKLM\...\KB956844) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB957097) (HKLM\...\KB957097) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB958644) (HKLM\...\KB958644) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB958687) (HKLM\...\KB958687) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB958869) (HKLM\...\KB958869) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB959426) (HKLM\...\KB959426) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB960225) (HKLM\...\KB960225) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB960803) (HKLM\...\KB960803) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB960859) (HKLM\...\KB960859) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB961501) (HKLM\...\KB961501) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB969059) (HKLM\...\KB969059) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB969947) (HKLM\...\KB969947) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB970238) (HKLM\...\KB970238) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB970430) (HKLM\...\KB970430) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB971468) (HKLM\...\KB971468) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB971486) (HKLM\...\KB971486) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB971557) (HKLM\...\KB971557) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB971633) (HKLM\...\KB971633) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB971657) (HKLM\...\KB971657) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB971961) (Version: 1 - Microsoft Corporation) Hidden Sicherheitsupdate für Windows XP (KB972270) (HKLM\...\KB972270) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB973354) (HKLM\...\KB973354) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB973507) (HKLM\...\KB973507) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB973525) (HKLM\...\KB973525) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB973869) (HKLM\...\KB973869) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB973904) (HKLM\...\KB973904) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB974112) (HKLM\...\KB974112) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB974318) (HKLM\...\KB974318) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB974392) (HKLM\...\KB974392) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB974571) (HKLM\...\KB974571) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB975025) (HKLM\...\KB975025) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB975467) (HKLM\...\KB975467) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB975560) (HKLM\...\KB975560) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB975561) (HKLM\...\KB975561) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB975562) (HKLM\...\KB975562) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB975713) (Version: 1 - Microsoft Corporation) Hidden Sicherheitsupdate für Windows XP (KB977165) (HKLM\...\KB977165) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB977816) (HKLM\...\KB977816) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB977914) (HKLM\...\KB977914) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB978037) (HKLM\...\KB978037) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB978251) (HKLM\...\KB978251) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB978262) (HKLM\...\KB978262) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB978338) (HKLM\...\KB978338) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB978542) (HKLM\...\KB978542) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB978601) (HKLM\...\KB978601) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB978706) (HKLM\...\KB978706) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB979309) (HKLM\...\KB979309) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB979559) (HKLM\...\KB979559) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB979683) (HKLM\...\KB979683) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB979687) (HKLM\...\KB979687) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB980195) (HKLM\...\KB980195) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB980218) (HKLM\...\KB980218) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB980232) (HKLM\...\KB980232) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB980436) (HKLM\...\KB980436) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB981322) (HKLM\...\KB981322) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB981349) (Version: 1 - Microsoft Corporation) Hidden Sicherheitsupdate für Windows XP (KB981852) (HKLM\...\KB981852) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB981957) (HKLM\...\KB981957) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB981997) (HKLM\...\KB981997) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB982132) (HKLM\...\KB982132) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB982214) (HKLM\...\KB982214) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB982665) (HKLM\...\KB982665) (Version: 1 - Microsoft Corporation) Sicherheitsupdate für Windows XP (KB982802) (HKLM\...\KB982802) (Version: 1 - Microsoft Corporation) Skype™ 6.18 (HKLM\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.18.106 - Skype Technologies S.A.) Sony PC Companion 2.10.181 (HKLM\...\{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}) (Version: 2.10.181 - Sony) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 10.1.8.0 - Synaptics) Unterstützungsdateien für das Microsoft SQL Server-Setup (Englisch) (HKLM\...\{07629207-FAA0-4F1A-8092-BF5085BE511F}) (Version: 9.00.5000.00 - Microsoft Corporation) Update for 2007 Microsoft Office System (KB967642) (HKLM\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for 2007 Microsoft Office System (KB981715) (HKLM\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{661B3F32-FFE4-4606-AE3A-DFA11DCC0D79}) (Version: - Microsoft) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (HKLM\...\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707) (Version: 1 - Microsoft Corporation) Update for Microsoft Office InfoPath 2007 (KB976416) (HKLM\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{432C5EE4-8096-4FF1-95E1-65219365DFF7}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM\...\{90120000-001A-0407-0000-0000000FF1CE}_PROHYBRIDR_{EA54F104-79D2-48CC-9ABC-91A63C43D353}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM\...\{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{ED38F8A3-4F61-494E-8BCA-E3AC7760C924}) (Version: - Microsoft) Update for Outlook 2007 Junk Email Filter (kb983486) (HKLM\...\{91120000-0031-0000-0000-0000000FF1CE}_PROHYBRIDR_{913DFE19-32EC-4099-89AC-27FC493A7A2E}) (Version: - Microsoft) Update für Windows Internet Explorer 7 (KB980182) (Version: 1 - Microsoft Corporation) Hidden Update für Windows XP (KB2141007) (HKLM\...\KB2141007) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB2345886) (HKLM\...\KB2345886) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB2541763) (HKLM\...\KB2541763) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB2607712) (HKLM\...\KB2607712) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB2616676) (HKLM\...\KB2616676) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB2641690) (HKLM\...\KB2641690) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB2661254-v2) (HKLM\...\KB2661254-v2) (Version: 2 - Microsoft Corporation) Update für Windows XP (KB2749655) (HKLM\...\KB2749655) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB2863058) (HKLM\...\KB2863058) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB2904266) (HKLM\...\KB2904266) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB2934207) (HKLM\...\KB2934207) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB898461) (HKLM\...\KB898461) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB951978) (Version: 1 - Microsoft Corporation) Hidden Update für Windows XP (KB955759) (HKLM\...\KB955759) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB961503) (HKLM\...\KB961503) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB967715) (HKLM\...\KB967715) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB968389) (HKLM\...\KB968389) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB971029) (HKLM\...\KB971029) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB971737) (HKLM\...\KB971737) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB973687) (HKLM\...\KB973687) (Version: 1 - Microsoft Corporation) Update für Windows XP (KB973815) (HKLM\...\KB973815) (Version: 1 - Microsoft Corporation) USB2.0 Card Reader Software (HKLM\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.0.6000.81 - Realtek Semiconductor Corp.) VeriFace III (HKLM\...\VeriFace III) (Version: - Lenovo) VLC media player 1.1.2 (HKLM\...\VLC media player) (Version: 1.1.2 - VideoLAN) WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation) Windows Live Call (Version: 14.0.8117.0416 - Microsoft Corporation) Hidden Windows Live Communications Platform (Version: 14.0.8117.416 - Microsoft Corporation) Hidden Windows Live Essentials (Version: 14.0.8117.416 - Microsoft Corporation) Hidden Windows Live Messenger (Version: 14.0.8117.0416 - Microsoft Corporation) Hidden Windows Media Format 11 runtime (HKLM\...\Windows Media Format Runtime) (Version: - ) Windows Media Format 11 runtime (Version: - Microsoft Corporation) Hidden Windows Presentation Foundation (Version: 3.0.6920.0 - Microsoft Corporation) Hidden XML Paper Specification Shared Components Pack 1.0 (Version: - Microsoft Corporation) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= Could not list Restore Points. Check "winmgmt" service or repair WMI. ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2008-04-14 04:00 - 2008-04-14 04:00 - 00000820 ____A C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\Ende des Supports für Microsoft Windows XP – Monatliche Benachrichtigung.job => C:\WINDOWS\system32\xp_eos.exe Task: C:\WINDOWS\Tasks\Ende des Supports für Microsoft Windows XP – Benachrichtigung – Anmeldung.job => C:\WINDOWS\system32\xp_eos.exe Task: C:\WINDOWS\Tasks\At1.job => C:\DOKUME~1\****LI~1\ANWEND~1\PRICEM~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\WINDOWS\Tasks\PriceMeterLiveUpdateUpdateTaskMachineCore.job => C:\Programme\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\PriceMeterLiveUpdateUpdateTaskMachineUA.job => C:\Programme\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\pricemetertask.job => C:\Dokumente und Einstellungen\**** *******\Lokale Einstellungen\Anwendungsdaten\PriceMeter\TEMP\pricemeter.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\pricemeterwatcher.job => C:\Dokumente und Einstellungen\**** *******\Lokale Einstellungen\Anwendungsdaten\PriceMeter\pricemeterw.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22}.job => C:\Programme\COMODO\COMODO Internet Security\cfpconfg.exe Task: C:\WINDOWS\Tasks\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9}.job => C:\Programme\COMODO\COMODO Internet Security\cfpconfg.exe Task: C:\WINDOWS\Tasks\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59}.job => C:\Programme\COMODO\COMODO Internet Security\cfpconfg.exe Task: C:\WINDOWS\Tasks\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85}.job => C:\Programme\COMODO\COMODO Internet Security\cfpconfg.exe ==================== Loaded Modules (whitelisted) ============= 2009-09-10 00:12 - 2009-09-10 00:12 - 01167360 _____ () C:\WINDOWS\system32\PicNotify.dll 2009-09-10 00:12 - 2009-09-10 00:12 - 09502720 _____ () C:\WINDOWS\system32\FaceVerify.dll 2009-09-10 00:12 - 2009-09-10 00:12 - 01564672 _____ () C:\WINDOWS\system32\MainOp.dll 2009-09-10 00:12 - 2009-09-10 00:12 - 00126976 _____ () C:\WINDOWS\system32\VideoOp.dll 2009-09-10 00:12 - 2009-09-10 00:12 - 00208896 _____ () C:\WINDOWS\system32\Image.dll 2009-09-10 00:12 - 2009-09-10 00:12 - 00094208 _____ () C:\WINDOWS\system32\Momo.dll 2009-09-10 00:12 - 2009-09-10 00:12 - 00974848 _____ () C:\WINDOWS\system32\Apblend.dll 2009-09-10 00:12 - 2009-09-10 00:12 - 00221184 _____ () C:\WINDOWS\system32\SetDev.dll 2009-09-10 00:12 - 2009-09-10 00:12 - 00053248 _____ () C:\WINDOWS\system32\FunFrm.dll 2009-09-10 00:12 - 2009-09-10 00:12 - 09338880 _____ () C:\WINDOWS\system32\facev.dll 2009-09-10 00:12 - 2009-09-10 00:12 - 00241752 _____ () C:\WINDOWS\system32\IcnOvrly.dll 2009-09-10 00:12 - 2009-09-10 00:12 - 00507904 _____ () C:\WINDOWS\system32\SimpleExt.dll 2009-09-10 00:25 - 2008-01-03 19:23 - 00167936 _____ () C:\Program Files\Lenovo\OneKey App\System Repair\LenovoAPI.dll 2013-11-09 06:26 - 2014-08-18 16:59 - 03800688 _____ () C:\Programme\Mozilla Firefox\mozjs.dll ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^Dokumente und Einstellungen^**** *******^Startmenü^Programme^Autostart^OpenOffice.org 3.4.1.lnk => C:\WINDOWS\pss\OpenOffice.org 3.4.1.lnkStartup MSCONFIG\startupreg: 331BigDog => C:\Programme\USB Camera\VM331_STI.EXE MSCONFIG\startupreg: Adobe ARM => "C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: CTFMON.EXE => C:\WINDOWS\system32\ctfmon.exe MSCONFIG\startupreg: GrooveMonitor => "C:\Programme\Microsoft Office\Office12\GrooveMonitor.exe" MSCONFIG\startupreg: HotKeysCmds => C:\WINDOWS\system32\hkcmd.exe MSCONFIG\startupreg: IAAnotif => C:\Programme\Intel\Intel Matrix Storage Manager\iaanotif.exe MSCONFIG\startupreg: IgfxTray => C:\WINDOWS\system32\igfxtray.exe MSCONFIG\startupreg: iTunesHelper => "C:\Programme\iTunes\iTunesHelper.exe" MSCONFIG\startupreg: Optimizer Pro => C:\Programme\Optimizer Pro\OptProLauncher.exe MSCONFIG\startupreg: Persistence => C:\WINDOWS\system32\igfxpers.exe MSCONFIG\startupreg: PriceMeterW => "C:\Dokumente und Einstellungen\**** *******\Lokale Einstellungen\Anwendungsdaten\PriceMeter\pricemeterw.exe" MSCONFIG\startupreg: QuickTime Task => "C:\Programme\QuickTime\qttask.exe" -atboottime MSCONFIG\startupreg: RTHDCPL => RTHDCPL.EXE MSCONFIG\startupreg: SynTPEnh => C:\Programme\Synaptics\SynTP\SynTPEnh.exe MSCONFIG\startupreg: VeriFaceManager => C:\Programme\Lenovo\VeriFaceIII\PManage.exe ==================== Faulty Device Manager Devices ============= Could not list Devices. Check "winmgmt" service or repair WMI. ==================== Event log errors: ========================= Application errors: ================== Error: (08/27/2014 06:43:39 AM) (Source: LoadPerf) (EventID: 3006) (User: ) Description: Die Zeichenfolgen der Leistungsindikatoren der Sprachkennung 007 können nicht gelesen werden. Der zurückgegebene Win32-Status ist das erste DWORD im Datenbereich. Error: (08/27/2014 06:43:36 AM) (Source: LoadPerf) (EventID: 3011) (User: ) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst WmiApRpl (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error: (08/27/2014 06:39:18 AM) (Source: DvmMDES) (EventID: 104) (User: ) Description: Error: (08/26/2014 00:00:25 PM) (Source: LoadPerf) (EventID: 3006) (User: ) Description: Die Zeichenfolgen der Leistungsindikatoren der Sprachkennung 007 können nicht gelesen werden. Der zurückgegebene Win32-Status ist das erste DWORD im Datenbereich. Error: (08/26/2014 00:00:22 PM) (Source: LoadPerf) (EventID: 3011) (User: ) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst WmiApRpl (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error: (08/26/2014 11:55:55 AM) (Source: DvmMDES) (EventID: 104) (User: ) Description: Error: (08/26/2014 10:22:24 AM) (Source: LoadPerf) (EventID: 3006) (User: ) Description: Die Zeichenfolgen der Leistungsindikatoren der Sprachkennung 007 können nicht gelesen werden. Der zurückgegebene Win32-Status ist das erste DWORD im Datenbereich. Error: (08/26/2014 10:22:21 AM) (Source: LoadPerf) (EventID: 3011) (User: ) Description: Fehler beim Herunterladen der Zeichenfolgen der Leistungsindikatoren für Dienst WmiApRpl (WmiApRpl). Der Fehlercode ist das erste DWORD im Datenbereich. Error: (08/26/2014 10:17:33 AM) (Source: DvmMDES) (EventID: 104) (User: ) Description: Error: (08/25/2014 10:29:01 PM) (Source: LoadPerf) (EventID: 3006) (User: ) Description: Die Zeichenfolgen der Leistungsindikatoren der Sprachkennung 007 können nicht gelesen werden. Der zurückgegebene Win32-Status ist das erste DWORD im Datenbereich. System errors: ============= Error: (08/27/2014 10:29:00 AM) (Source: Schedule) (EventID: 7901) (User: ) Description: Der Befehl "At1.job" konnte aufgrund folgenden Fehlers nicht ausgeführt werden: %%2147942402 Error: (08/27/2014 09:29:00 AM) (Source: Schedule) (EventID: 7901) (User: ) Description: Der Befehl "At1.job" konnte aufgrund folgenden Fehlers nicht ausgeführt werden: %%2147942402 Error: (08/27/2014 09:21:12 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "Optimizer Pro Crash Monitor" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (08/27/2014 08:29:00 AM) (Source: Schedule) (EventID: 7901) (User: ) Description: Der Befehl "At1.job" konnte aufgrund folgenden Fehlers nicht ausgeführt werden: %%2147942402 Error: (08/27/2014 07:29:00 AM) (Source: Schedule) (EventID: 7901) (User: ) Description: Der Befehl "At1.job" konnte aufgrund folgenden Fehlers nicht ausgeführt werden: %%2147942402 Error: (08/27/2014 06:49:15 AM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: Dienst "SQL Server VSS Writer" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert. Error: (08/27/2014 06:41:01 AM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "SQL Server VSS Writer" wurde nicht ordnungsgemäß gestartet. Error: (08/27/2014 06:39:35 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "DeviceVM Meta Data Export Service" wurde mit folgendem Fehler beendet: %%2 Error: (08/26/2014 06:29:00 PM) (Source: Schedule) (EventID: 7901) (User: ) Description: Der Befehl "At1.job" konnte aufgrund folgenden Fehlers nicht ausgeführt werden: %%2147942402 Error: (08/26/2014 05:29:00 PM) (Source: Schedule) (EventID: 7901) (User: ) Description: Der Befehl "At1.job" konnte aufgrund folgenden Fehlers nicht ausgeführt werden: %%2147942402 Microsoft Office Sessions: ========================= ==================== Memory info =========================== Processor: Intel(R) Atom(TM) CPU N270 @ 1.60GHz Percentage of memory in use: 77% Total physical RAM: 1014.36 MB Available physical RAM: 223.35 MB Total Pagefile: 3914.96 MB Available Pagefile: 3024.19 MB Total Virtual: 2047.88 MB Available Virtual: 1950.66 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:103.89 GB) (Free:72.5 GB) FAT32 ==>[Drive with boot components (Windows XP)] Drive d: (LENOVO) (Fixed) (Total:30.38 GB) (Free:26.21 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 149.1 GB) (Disk ID: D1B02BF6) Partition 1: (Active) - (Size=103.9 GB) - (Type=0C) Partition 2: (Not Active) - (Size=30.4 GB) - (Type=OF Extended) Partition 3: (Not Active) - (Size=14.8 GB) - (Type=12) ==================== End Of Log ============================ __________________________________________________________________ |
GMER Log: GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-08-27 11:22:31 Windows 5.1.2600 Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 WDC_WD16 rev.11.0 149,05GB Running: Gmer-19357.exe; Driver: C:\DOKUME~1\****LI~1\LOKALE~1\Temp\uwadrpow.sys ---- System - GMER 2.1 ---- SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwAdjustPrivilegesToken [0xAA1C972A] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwClose [0xAA1CAAC0] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwConnectPort [0xAA1C89DA] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwCreateFile [0xAA1C9358] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwCreateKey [0xAA1CA102] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwCreateSection [0xAA1C90EA] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwCreateSymbolicLinkObject [0xAA1CBAC4] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwCreateThread [0xAA1C8384] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwDeleteKey [0xAA1C991E] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwDeleteValueKey [0xAA1C9B6E] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwDuplicateObject [0xAA1C816E] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwEnumerateKey [0xAA1CABD6] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwEnumerateValueKey [0xAA1CADEA] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwLoadDriver [0xAA1CB4CA] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwMakeTemporaryObject [0xAA1C8CBE] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwNotifyChangeKey [0xAA1CBD96] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwNotifyChangeMultipleKeys [0xAA1CA994] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwOpenFile [0xAA1C9550] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwOpenKey [0xAA1C9FF0] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwOpenProcess [0xAA1C7D74] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwOpenSection [0xAA1C8F72] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwOpenThread [0xAA1C7F8C] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwQueryKey [0xAA1CAF5C] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwQueryMultipleValueKey [0xAA1CB210] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwQueryValueKey [0xAA1CB08E] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwRenameKey [0xAA1CA6E8] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwSetSecurityObject [0xAA1C9E14] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwSetSystemInformation [0xAA1CB7CA] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwSetValueKey [0xAA1CA410] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwShutdownSystem [0xAA1C8C28] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwSystemDebugControl [0xAA1C8E5E] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwTerminateProcess [0xAA1C87BA] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwTerminateThread [0xAA1C8588] ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!ZwCallbackReturn + 2D50 80504638 4 Bytes JMP E0AA1C90 .text ntkrnlpa.exe!ZwCallbackReturn + 2DAC 80504694 4 Bytes [EA, AD, 1C, AA] .text ntkrnlpa.exe!ZwCallbackReturn + 2F88 80504870 4 Bytes CALL BEFA651B ---- User code sections - GMER 2.1 ---- .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] ntdll.dll!NtClose 7C91CFEE 3 Bytes [FF, 25, 1E] .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] ntdll.dll!NtClose + 4 7C91CFF2 2 Bytes [AE, 71] .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] ntdll.dll!NtReplyWaitReceivePort 7C91DA8E 3 Bytes [FF, 25, 1E] .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] ntdll.dll!NtReplyWaitReceivePort + 4 7C91DA92 2 Bytes [74, 71] {JZ 0x73} .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] ntdll.dll!NtReplyWaitReceivePortEx 7C91DA9E 3 Bytes [FF, 25, 1E] .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] ntdll.dll!NtReplyWaitReceivePortEx + 4 7C91DAA2 2 Bytes [71, 71] {JNO 0x73} .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] ntdll.dll!LdrUnloadDll 7C9271CD 3 Bytes [FF, 25, 1E] .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] ntdll.dll!LdrUnloadDll + 4 7C9271D1 2 Bytes [A7, 71] .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AC0001 .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 719E001E .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 719B001E .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] USER32.dll!SetWindowsHookExW 7E37820F 6 Bytes JMP 717A001E .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] USER32.dll!SetWindowsHookExA 7E381211 6 Bytes JMP 717D001E .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] USER32.dll!SetWinEventHook 7E3817F7 6 Bytes JMP 7177001E .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] GDI32.dll!DeleteDC 77EF6E5F 6 Bytes JMP 7183001E .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] GDI32.dll!GetPixel 77EFB74C 6 Bytes JMP 7186001E .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] GDI32.dll!CreateDCA 77EFB7D2 6 Bytes JMP 718C001E .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] GDI32.dll!CreateDCW 77EFBE38 6 Bytes JMP 7189001E .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] ADVAPI32.dll!LsaClose + 51C 77DB2410 4 Bytes [20, 6B, 8C, 00] .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] ADVAPI32.dll!LsaClose + 524 77DB2418 4 Bytes [B0, 6B, 8C, 00] {MOV AL, 0x6b; MOV [EAX], ES} .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] ADVAPI32.dll!CreateProcessAsUserW 77DBA8A9 6 Bytes JMP 7192001E .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] ADVAPI32.dll!CreateProcessAsUserA 77DE0CE8 6 Bytes JMP 7198001E .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] ADVAPI32.dll!CreateProcessWithLogonW 77DE5FFD 3 Bytes [FF, 25, 1E] .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] ADVAPI32.dll!CreateProcessWithLogonW + 4 77DE6001 2 Bytes [95, 71] .text C:\Programme\Intel\Intel Matrix Storage Manager\IAANTMon.exe[464] Secur32.dll!EncryptMessage 77FCA68D 6 Bytes JMP 7180001E .text C:\WINDOWS\system32\csrss.exe[716] ntdll.dll!NtReplyWaitReceivePort 7C91DA8E 5 Bytes JMP 10001970 C:\WINDOWS\system32\cmdcsr.dll .text C:\WINDOWS\system32\csrss.exe[716] ntdll.dll!NtReplyWaitReceivePortEx 7C91DA9E 5 Bytes JMP 10001DF0 C:\WINDOWS\system32\cmdcsr.dll .text C:\WINDOWS\system32\services.exe[792] ntdll.dll!NtClose 7C91CFEE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\services.exe[792] ntdll.dll!NtClose + 4 7C91CFF2 2 Bytes [AE, 71] .text C:\WINDOWS\system32\services.exe[792] ntdll.dll!NtReplyWaitReceivePort 7C91DA8E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\services.exe[792] ntdll.dll!NtReplyWaitReceivePort + 4 7C91DA92 2 Bytes [74, 71] {JZ 0x73} .text C:\WINDOWS\system32\services.exe[792] ntdll.dll!NtReplyWaitReceivePortEx 7C91DA9E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\services.exe[792] ntdll.dll!NtReplyWaitReceivePortEx + 4 7C91DAA2 2 Bytes [71, 71] {JNO 0x73} .text C:\WINDOWS\system32\services.exe[792] ntdll.dll!LdrUnloadDll 7C9271CD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\services.exe[792] ntdll.dll!LdrUnloadDll + 4 7C9271D1 2 Bytes [A7, 71] .text C:\WINDOWS\system32\services.exe[792] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AC0001 .text C:\WINDOWS\system32\services.exe[792] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 719E001E .text C:\WINDOWS\system32\services.exe[792] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 719B001E .text C:\WINDOWS\system32\services.exe[792] ADVAPI32.dll!CreateProcessAsUserW 77DBA8A9 6 Bytes JMP 7192001E .text C:\WINDOWS\system32\services.exe[792] ADVAPI32.dll!CreateProcessAsUserA 77DE0CE8 6 Bytes JMP 7198001E .text C:\WINDOWS\system32\services.exe[792] ADVAPI32.dll!CreateProcessWithLogonW 77DE5FFD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\services.exe[792] ADVAPI32.dll!CreateProcessWithLogonW + 4 77DE6001 2 Bytes [95, 71] .text C:\WINDOWS\system32\services.exe[792] RPCRT4.dll!RpcServerRegisterIfEx 77E6CE4B 6 Bytes JMP 718F001E .text C:\WINDOWS\system32\services.exe[792] Secur32.dll!EncryptMessage 77FCA68D 6 Bytes JMP 7180001E .text C:\WINDOWS\system32\services.exe[792] USER32.dll!SetWindowsHookExW 7E37820F 6 Bytes JMP 717A001E .text C:\WINDOWS\system32\services.exe[792] USER32.dll!SetWindowsHookExA 7E381211 6 Bytes JMP 717D001E .text C:\WINDOWS\system32\services.exe[792] USER32.dll!SetWinEventHook 7E3817F7 6 Bytes JMP 7177001E .text C:\WINDOWS\system32\services.exe[792] GDI32.dll!DeleteDC 77EF6E5F 6 Bytes JMP 7183001E .text C:\WINDOWS\system32\services.exe[792] GDI32.dll!GetPixel 77EFB74C 6 Bytes JMP 7186001E .text C:\WINDOWS\system32\services.exe[792] GDI32.dll!CreateDCA 77EFB7D2 6 Bytes JMP 718C001E .text C:\WINDOWS\system32\services.exe[792] GDI32.dll!CreateDCW 77EFBE38 6 Bytes JMP 7189001E .text C:\WINDOWS\system32\lsass.exe[804] ntdll.dll!NtClose 7C91CFEE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\lsass.exe[804] ntdll.dll!NtClose + 4 7C91CFF2 2 Bytes [AE, 71] .text C:\WINDOWS\system32\lsass.exe[804] ntdll.dll!NtReplyWaitReceivePort 7C91DA8E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\lsass.exe[804] ntdll.dll!NtReplyWaitReceivePort + 4 7C91DA92 2 Bytes [6F, 71] .text C:\WINDOWS\system32\lsass.exe[804] ntdll.dll!NtReplyWaitReceivePortEx 7C91DA9E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\lsass.exe[804] ntdll.dll!NtReplyWaitReceivePortEx + 4 7C91DAA2 2 Bytes [6C, 71] .text C:\WINDOWS\system32\lsass.exe[804] ntdll.dll!LdrUnloadDll 7C9271CD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\lsass.exe[804] ntdll.dll!LdrUnloadDll + 4 7C9271D1 2 Bytes [A5, 71] .text C:\WINDOWS\system32\lsass.exe[804] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AC0001 .text C:\WINDOWS\system32\lsass.exe[804] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 7199001E .text C:\WINDOWS\system32\lsass.exe[804] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 7196001E .text C:\WINDOWS\system32\lsass.exe[804] ADVAPI32.dll!LsaClose + 51C 77DB2410 4 Bytes [20, 6B, 6B, 00] .text C:\WINDOWS\system32\lsass.exe[804] ADVAPI32.dll!LsaClose + 524 77DB2418 4 Bytes [B0, 6B, 6B, 00] .text C:\WINDOWS\system32\lsass.exe[804] ADVAPI32.dll!CreateProcessAsUserW 77DBA8A9 6 Bytes JMP 718D001E .text C:\WINDOWS\system32\lsass.exe[804] ADVAPI32.dll!CreateProcessAsUserA 77DE0CE8 6 Bytes JMP 7193001E .text C:\WINDOWS\system32\lsass.exe[804] ADVAPI32.dll!CreateProcessWithLogonW 77DE5FFD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\lsass.exe[804] ADVAPI32.dll!CreateProcessWithLogonW + 4 77DE6001 2 Bytes [90, 71] .text C:\WINDOWS\system32\lsass.exe[804] Secur32.dll!EncryptMessage 77FCA68D 6 Bytes JMP 717B001E .text C:\WINDOWS\system32\lsass.exe[804] USER32.dll!SetWindowsHookExW 7E37820F 6 Bytes JMP 7175001E .text C:\WINDOWS\system32\lsass.exe[804] USER32.dll!SetWindowsHookExA 7E381211 6 Bytes JMP 7178001E .text C:\WINDOWS\system32\lsass.exe[804] USER32.dll!SetWinEventHook 7E3817F7 6 Bytes JMP 7172001E .text C:\WINDOWS\system32\lsass.exe[804] GDI32.dll!DeleteDC 77EF6E5F 6 Bytes JMP 717E001E .text C:\WINDOWS\system32\lsass.exe[804] GDI32.dll!GetPixel 77EFB74C 6 Bytes JMP 7181001E .text C:\WINDOWS\system32\lsass.exe[804] GDI32.dll!CreateDCA 77EFB7D2 6 Bytes JMP 7187001E .text C:\WINDOWS\system32\lsass.exe[804] GDI32.dll!CreateDCW 77EFBE38 6 Bytes JMP 7184001E .text C:\WINDOWS\system32\svchost.exe[964] ntdll.dll!NtClose 7C91CFEE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[964] ntdll.dll!NtClose + 4 7C91CFF2 2 Bytes [AE, 71] .text C:\WINDOWS\system32\svchost.exe[964] ntdll.dll!NtReplyWaitReceivePort 7C91DA8E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[964] ntdll.dll!NtReplyWaitReceivePort + 4 7C91DA92 2 Bytes [74, 71] {JZ 0x73} .text C:\WINDOWS\system32\svchost.exe[964] ntdll.dll!NtReplyWaitReceivePortEx 7C91DA9E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[964] ntdll.dll!NtReplyWaitReceivePortEx + 4 7C91DAA2 2 Bytes [71, 71] {JNO 0x73} .text C:\WINDOWS\system32\svchost.exe[964] ntdll.dll!LdrUnloadDll 7C9271CD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[964] ntdll.dll!LdrUnloadDll + 4 7C9271D1 2 Bytes [A7, 71] .text C:\WINDOWS\system32\svchost.exe[964] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AC0001 .text C:\WINDOWS\system32\svchost.exe[964] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 719E001E .text C:\WINDOWS\system32\svchost.exe[964] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 719B001E .text C:\WINDOWS\system32\svchost.exe[964] ADVAPI32.dll!CreateProcessAsUserW 77DBA8A9 6 Bytes JMP 7192001E .text C:\WINDOWS\system32\svchost.exe[964] ADVAPI32.dll!CreateProcessAsUserA 77DE0CE8 6 Bytes JMP 7198001E .text C:\WINDOWS\system32\svchost.exe[964] ADVAPI32.dll!CreateProcessWithLogonW 77DE5FFD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[964] ADVAPI32.dll!CreateProcessWithLogonW + 4 77DE6001 2 Bytes [95, 71] .text C:\WINDOWS\system32\svchost.exe[964] RPCRT4.dll!RpcServerRegisterIfEx 77E6CE4B 6 Bytes JMP 718F001E .text C:\WINDOWS\system32\svchost.exe[964] Secur32.dll!EncryptMessage 77FCA68D 6 Bytes JMP 7180001E .text C:\WINDOWS\system32\svchost.exe[964] USER32.dll!SetWindowsHookExW 7E37820F 6 Bytes JMP 717A001E .text C:\WINDOWS\system32\svchost.exe[964] USER32.dll!SetWindowsHookExA 7E381211 6 Bytes JMP 717D001E .text C:\WINDOWS\system32\svchost.exe[964] USER32.dll!SetWinEventHook 7E3817F7 6 Bytes JMP 7177001E .text C:\WINDOWS\system32\svchost.exe[964] GDI32.dll!DeleteDC 77EF6E5F 6 Bytes JMP 7183001E .text C:\WINDOWS\system32\svchost.exe[964] GDI32.dll!GetPixel 77EFB74C 6 Bytes JMP 7186001E .text C:\WINDOWS\system32\svchost.exe[964] GDI32.dll!CreateDCA 77EFB7D2 6 Bytes JMP 718C001E .text C:\WINDOWS\system32\svchost.exe[964] GDI32.dll!CreateDCW 77EFBE38 6 Bytes JMP 7189001E .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] ntdll.dll!NtClose 7C91CFEE 3 Bytes [FF, 25, 1E] .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] ntdll.dll!NtClose + 4 7C91CFF2 2 Bytes [AE, 71] .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] ntdll.dll!NtReplyWaitReceivePort 7C91DA8E 3 Bytes [FF, 25, 1E] .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] ntdll.dll!NtReplyWaitReceivePort + 4 7C91DA92 2 Bytes [74, 71] {JZ 0x73} .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] ntdll.dll!NtReplyWaitReceivePortEx 7C91DA9E 3 Bytes [FF, 25, 1E] .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] ntdll.dll!NtReplyWaitReceivePortEx + 4 7C91DAA2 2 Bytes [71, 71] {JNO 0x73} .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] ntdll.dll!LdrUnloadDll 7C9271CD 3 Bytes [FF, 25, 1E] .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] ntdll.dll!LdrUnloadDll + 4 7C9271D1 2 Bytes [A7, 71] .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] KERNEL32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AC0001 .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] KERNEL32.dll!CreateProcessW 7C802336 6 Bytes JMP 719E001E .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] KERNEL32.dll!CreateProcessA 7C80236B 6 Bytes JMP 719B001E .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] USER32.dll!SetWindowsHookExW 7E37820F 6 Bytes JMP 717A001E .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] USER32.dll!SetWindowsHookExA 7E381211 6 Bytes JMP 717D001E .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] USER32.dll!SetWinEventHook 7E3817F7 6 Bytes JMP 7177001E .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] GDI32.dll!DeleteDC 77EF6E5F 6 Bytes JMP 7183001E .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] GDI32.dll!GetPixel 77EFB74C 6 Bytes JMP 7186001E .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] GDI32.dll!CreateDCA 77EFB7D2 6 Bytes JMP 718C001E .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] GDI32.dll!CreateDCW 77EFBE38 6 Bytes JMP 7189001E .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] ADVAPI32.dll!LsaClose + 51C 77DB2410 4 Bytes [20, 6B, 01, 10] .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] ADVAPI32.dll!LsaClose + 524 77DB2418 4 Bytes [B0, 6B, 01, 10] {MOV AL, 0x6b; ADD [EAX], EDX} .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] ADVAPI32.dll!CreateProcessAsUserW 77DBA8A9 6 Bytes JMP 7192001E .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] ADVAPI32.dll!CreateProcessAsUserA 77DE0CE8 6 Bytes JMP 7198001E .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] ADVAPI32.dll!CreateProcessWithLogonW 77DE5FFD 3 Bytes [FF, 25, 1E] .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] ADVAPI32.dll!CreateProcessWithLogonW + 4 77DE6001 2 Bytes [95, 71] .text C:\DOKUME~1\****LI~1\LOKALE~1\Temp\DMR\dmr_72.exe[1008] Secur32.dll!EncryptMessage 77FCA68D 6 Bytes JMP 7180001E .text C:\WINDOWS\system32\svchost.exe[1048] ntdll.dll!NtClose 7C91CFEE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1048] ntdll.dll!NtClose + 4 7C91CFF2 2 Bytes [AE, 71] .text C:\WINDOWS\system32\svchost.exe[1048] ntdll.dll!NtReplyWaitReceivePort 7C91DA8E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1048] ntdll.dll!NtReplyWaitReceivePort + 4 7C91DA92 2 Bytes [74, 71] {JZ 0x73} .text C:\WINDOWS\system32\svchost.exe[1048] ntdll.dll!NtReplyWaitReceivePortEx 7C91DA9E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1048] ntdll.dll!NtReplyWaitReceivePortEx + 4 7C91DAA2 2 Bytes [71, 71] {JNO 0x73} .text C:\WINDOWS\system32\svchost.exe[1048] ntdll.dll!LdrUnloadDll 7C9271CD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1048] ntdll.dll!LdrUnloadDll + 4 7C9271D1 2 Bytes [A7, 71] .text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AC0001 .text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 719E001E .text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 719B001E .text C:\WINDOWS\system32\svchost.exe[1048] ADVAPI32.dll!CreateProcessAsUserW 77DBA8A9 6 Bytes JMP 7192001E .text C:\WINDOWS\system32\svchost.exe[1048] ADVAPI32.dll!CreateProcessAsUserA 77DE0CE8 6 Bytes JMP 7198001E .text C:\WINDOWS\system32\svchost.exe[1048] ADVAPI32.dll!CreateProcessWithLogonW 77DE5FFD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1048] ADVAPI32.dll!CreateProcessWithLogonW + 4 77DE6001 2 Bytes [95, 71] .text C:\WINDOWS\system32\svchost.exe[1048] RPCRT4.dll!RpcServerRegisterIfEx 77E6CE4B 6 Bytes JMP 718F001E .text C:\WINDOWS\system32\svchost.exe[1048] Secur32.dll!EncryptMessage 77FCA68D 6 Bytes JMP 7180001E .text C:\WINDOWS\system32\svchost.exe[1048] USER32.dll!SetWindowsHookExW 7E37820F 6 Bytes JMP 717A001E .text C:\WINDOWS\system32\svchost.exe[1048] USER32.dll!SetWindowsHookExA 7E381211 6 Bytes JMP 717D001E .text C:\WINDOWS\system32\svchost.exe[1048] USER32.dll!SetWinEventHook 7E3817F7 6 Bytes JMP 7177001E .text C:\WINDOWS\system32\svchost.exe[1048] GDI32.dll!DeleteDC 77EF6E5F 6 Bytes JMP 7183001E .text C:\WINDOWS\system32\svchost.exe[1048] GDI32.dll!GetPixel 77EFB74C 6 Bytes JMP 7186001E .text C:\WINDOWS\system32\svchost.exe[1048] GDI32.dll!CreateDCA 77EFB7D2 6 Bytes JMP 718C001E .text C:\WINDOWS\system32\svchost.exe[1048] GDI32.dll!CreateDCW 77EFBE38 6 Bytes JMP 7189001E .text C:\WINDOWS\system32\svchost.exe[1048] rpcss.dll!WhichService 76A34234 8 Bytes [80, 4F, 67, 00, 40, 4D, 67, ...] .text C:\Programme\COMODO\COMODO Internet Security\cmdagent.exe[1136] ntdll.dll!NtAllocateVirtualMemory 7C91CF6E 5 Bytes JMP 00403760 C:\Programme\COMODO\COMODO Internet Security\cmdagent.exe .text C:\Programme\COMODO\COMODO Internet Security\cmdagent.exe[1136] ntdll.dll!NtCreateFile 7C91D0AE 5 Bytes JMP 0044D090 C:\Programme\COMODO\COMODO Internet Security\cmdagent.exe .text C:\WINDOWS\system32\svchost.exe[1176] ntdll.dll!NtClose 7C91CFEE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1176] ntdll.dll!NtClose + 4 7C91CFF2 2 Bytes [AE, 71] .text C:\WINDOWS\system32\svchost.exe[1176] ntdll.dll!NtReplyWaitReceivePort 7C91DA8E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1176] ntdll.dll!NtReplyWaitReceivePort + 4 7C91DA92 2 Bytes [74, 71] {JZ 0x73} .text C:\WINDOWS\system32\svchost.exe[1176] ntdll.dll!NtReplyWaitReceivePortEx 7C91DA9E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1176] ntdll.dll!NtReplyWaitReceivePortEx + 4 7C91DAA2 2 Bytes [71, 71] {JNO 0x73} .text C:\WINDOWS\system32\svchost.exe[1176] ntdll.dll!LdrUnloadDll 7C9271CD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1176] ntdll.dll!LdrUnloadDll + 4 7C9271D1 2 Bytes [A7, 71] .text C:\WINDOWS\system32\svchost.exe[1176] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AC0001 .text C:\WINDOWS\system32\svchost.exe[1176] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 719E001E .text C:\WINDOWS\system32\svchost.exe[1176] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 719B001E .text C:\WINDOWS\system32\svchost.exe[1176] ADVAPI32.dll!CreateProcessAsUserW 77DBA8A9 6 Bytes JMP 7192001E .text C:\WINDOWS\system32\svchost.exe[1176] ADVAPI32.dll!CreateProcessAsUserA 77DE0CE8 6 Bytes JMP 7198001E .text C:\WINDOWS\system32\svchost.exe[1176] ADVAPI32.dll!CreateProcessWithLogonW 77DE5FFD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1176] ADVAPI32.dll!CreateProcessWithLogonW + 4 77DE6001 2 Bytes [95, 71] .text C:\WINDOWS\system32\svchost.exe[1176] RPCRT4.dll!RpcServerRegisterIfEx 77E6CE4B 6 Bytes JMP 718F001E .text C:\WINDOWS\system32\svchost.exe[1176] Secur32.dll!EncryptMessage 77FCA68D 6 Bytes JMP 7180001E .text C:\WINDOWS\system32\svchost.exe[1176] USER32.dll!SetWindowsHookExW 7E37820F 6 Bytes JMP 717A001E .text C:\WINDOWS\system32\svchost.exe[1176] USER32.dll!SetWindowsHookExA 7E381211 6 Bytes JMP 717D001E .text C:\WINDOWS\system32\svchost.exe[1176] USER32.dll!SetWinEventHook 7E3817F7 6 Bytes JMP 7177001E .text C:\WINDOWS\system32\svchost.exe[1176] GDI32.dll!DeleteDC 77EF6E5F 6 Bytes JMP 7183001E .text C:\WINDOWS\system32\svchost.exe[1176] GDI32.dll!GetPixel 77EFB74C 6 Bytes JMP 7186001E .text C:\WINDOWS\system32\svchost.exe[1176] GDI32.dll!CreateDCA 77EFB7D2 6 Bytes JMP 718C001E .text C:\WINDOWS\system32\svchost.exe[1176] GDI32.dll!CreateDCW 77EFBE38 6 Bytes JMP 7189001E .text C:\WINDOWS\system32\svchost.exe[1252] ntdll.dll!NtClose 7C91CFEE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1252] ntdll.dll!NtClose + 4 7C91CFF2 2 Bytes [AE, 71] .text C:\WINDOWS\system32\svchost.exe[1252] ntdll.dll!NtReplyWaitReceivePort 7C91DA8E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1252] ntdll.dll!NtReplyWaitReceivePort + 4 7C91DA92 2 Bytes [74, 71] {JZ 0x73} .text C:\WINDOWS\system32\svchost.exe[1252] ntdll.dll!NtReplyWaitReceivePortEx 7C91DA9E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1252] ntdll.dll!NtReplyWaitReceivePortEx + 4 7C91DAA2 2 Bytes [71, 71] {JNO 0x73} .text C:\WINDOWS\system32\svchost.exe[1252] ntdll.dll!LdrUnloadDll 7C9271CD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1252] ntdll.dll!LdrUnloadDll + 4 7C9271D1 2 Bytes [A7, 71] .text C:\WINDOWS\system32\svchost.exe[1252] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AC0001 .text C:\WINDOWS\system32\svchost.exe[1252] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 719E001E .text C:\WINDOWS\system32\svchost.exe[1252] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 719B001E .text C:\WINDOWS\system32\svchost.exe[1252] ADVAPI32.dll!LsaClose + 51C 77DB2410 4 Bytes [20, 6B, 67, 00] .text C:\WINDOWS\system32\svchost.exe[1252] ADVAPI32.dll!LsaClose + 524 77DB2418 4 Bytes [B0, 6B, 67, 00] .text C:\WINDOWS\system32\svchost.exe[1252] ADVAPI32.dll!CreateProcessAsUserW 77DBA8A9 6 Bytes JMP 7192001E .text C:\WINDOWS\system32\svchost.exe[1252] ADVAPI32.dll!CreateProcessAsUserA 77DE0CE8 6 Bytes JMP 7198001E .text C:\WINDOWS\system32\svchost.exe[1252] ADVAPI32.dll!CreateProcessWithLogonW 77DE5FFD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1252] ADVAPI32.dll!CreateProcessWithLogonW + 4 77DE6001 2 Bytes [95, 71] .text C:\WINDOWS\system32\svchost.exe[1252] Secur32.dll!EncryptMessage 77FCA68D 6 Bytes JMP 7180001E .text C:\WINDOWS\system32\svchost.exe[1252] USER32.dll!SetWindowsHookExW 7E37820F 6 Bytes JMP 717A001E .text C:\WINDOWS\system32\svchost.exe[1252] USER32.dll!SetWindowsHookExA 7E381211 6 Bytes JMP 717D001E .text C:\WINDOWS\system32\svchost.exe[1252] USER32.dll!SetWinEventHook 7E3817F7 6 Bytes JMP 7177001E .text C:\WINDOWS\system32\svchost.exe[1252] GDI32.dll!DeleteDC 77EF6E5F 6 Bytes JMP 7183001E .text C:\WINDOWS\system32\svchost.exe[1252] GDI32.dll!GetPixel 77EFB74C 6 Bytes JMP 7186001E .text C:\WINDOWS\system32\svchost.exe[1252] GDI32.dll!CreateDCA 77EFB7D2 6 Bytes JMP 718C001E .text C:\WINDOWS\system32\svchost.exe[1252] GDI32.dll!CreateDCW 77EFBE38 6 Bytes JMP 7189001E .text C:\WINDOWS\system32\svchost.exe[1364] ntdll.dll!NtClose 7C91CFEE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1364] ntdll.dll!NtClose + 4 7C91CFF2 2 Bytes [AE, 71] .text C:\WINDOWS\system32\svchost.exe[1364] ntdll.dll!NtReplyWaitReceivePort 7C91DA8E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1364] ntdll.dll!NtReplyWaitReceivePort + 4 7C91DA92 2 Bytes [74, 71] {JZ 0x73} .text C:\WINDOWS\system32\svchost.exe[1364] ntdll.dll!NtReplyWaitReceivePortEx 7C91DA9E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1364] ntdll.dll!NtReplyWaitReceivePortEx + 4 7C91DAA2 2 Bytes [71, 71] {JNO 0x73} .text C:\WINDOWS\system32\svchost.exe[1364] ntdll.dll!LdrUnloadDll 7C9271CD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1364] ntdll.dll!LdrUnloadDll + 4 7C9271D1 2 Bytes [A7, 71] .text C:\WINDOWS\system32\svchost.exe[1364] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AC0001 .text C:\WINDOWS\system32\svchost.exe[1364] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 719E001E .text C:\WINDOWS\system32\svchost.exe[1364] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 719B001E .text C:\WINDOWS\system32\svchost.exe[1364] ADVAPI32.dll!LsaClose + 51C 77DB2410 4 Bytes [20, 6B, 67, 00] .text C:\WINDOWS\system32\svchost.exe[1364] ADVAPI32.dll!LsaClose + 524 77DB2418 4 Bytes [B0, 6B, 67, 00] .text C:\WINDOWS\system32\svchost.exe[1364] ADVAPI32.dll!CreateProcessAsUserW 77DBA8A9 6 Bytes JMP 7192001E .text C:\WINDOWS\system32\svchost.exe[1364] ADVAPI32.dll!CreateProcessAsUserA 77DE0CE8 6 Bytes JMP 7198001E .text C:\WINDOWS\system32\svchost.exe[1364] ADVAPI32.dll!CreateProcessWithLogonW 77DE5FFD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1364] ADVAPI32.dll!CreateProcessWithLogonW + 4 77DE6001 2 Bytes [95, 71] .text C:\WINDOWS\system32\svchost.exe[1364] Secur32.dll!EncryptMessage 77FCA68D 6 Bytes JMP 7180001E .text C:\WINDOWS\system32\svchost.exe[1364] USER32.dll!SetWindowsHookExW 7E37820F 6 Bytes JMP 717A001E .text C:\WINDOWS\system32\svchost.exe[1364] USER32.dll!SetWindowsHookExA 7E381211 6 Bytes JMP 717D001E .text C:\WINDOWS\system32\svchost.exe[1364] USER32.dll!SetWinEventHook 7E3817F7 6 Bytes JMP 7177001E .text C:\WINDOWS\system32\svchost.exe[1364] GDI32.dll!DeleteDC 77EF6E5F 6 Bytes JMP 7183001E .text C:\WINDOWS\system32\svchost.exe[1364] GDI32.dll!GetPixel 77EFB74C 6 Bytes JMP 7186001E .text C:\WINDOWS\system32\svchost.exe[1364] GDI32.dll!CreateDCA 77EFB7D2 6 Bytes JMP 718C001E .text C:\WINDOWS\system32\svchost.exe[1364] GDI32.dll!CreateDCW 77EFBE38 6 Bytes JMP 7189001E .text C:\WINDOWS\system32\svchost.exe[1420] ntdll.dll!NtClose 7C91CFEE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1420] ntdll.dll!NtClose + 4 7C91CFF2 2 Bytes [AE, 71] .text C:\WINDOWS\system32\svchost.exe[1420] ntdll.dll!NtReplyWaitReceivePort 7C91DA8E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1420] ntdll.dll!NtReplyWaitReceivePort + 4 7C91DA92 2 Bytes [74, 71] {JZ 0x73} .text C:\WINDOWS\system32\svchost.exe[1420] ntdll.dll!NtReplyWaitReceivePortEx 7C91DA9E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1420] ntdll.dll!NtReplyWaitReceivePortEx + 4 7C91DAA2 2 Bytes [71, 71] {JNO 0x73} .text C:\WINDOWS\system32\svchost.exe[1420] ntdll.dll!LdrUnloadDll 7C9271CD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1420] ntdll.dll!LdrUnloadDll + 4 7C9271D1 2 Bytes [A7, 71] .text C:\WINDOWS\system32\svchost.exe[1420] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AC0001 .text C:\WINDOWS\system32\svchost.exe[1420] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 719E001E .text C:\WINDOWS\system32\svchost.exe[1420] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 719B001E .text C:\WINDOWS\system32\svchost.exe[1420] ADVAPI32.dll!LsaClose + 51C 77DB2410 4 Bytes [20, 6B, 67, 00] .text C:\WINDOWS\system32\svchost.exe[1420] ADVAPI32.dll!LsaClose + 524 77DB2418 4 Bytes [B0, 6B, 67, 00] .text C:\WINDOWS\system32\svchost.exe[1420] ADVAPI32.dll!CreateProcessAsUserW 77DBA8A9 6 Bytes JMP 7192001E .text C:\WINDOWS\system32\svchost.exe[1420] ADVAPI32.dll!CreateProcessAsUserA 77DE0CE8 6 Bytes JMP 7198001E .text C:\WINDOWS\system32\svchost.exe[1420] ADVAPI32.dll!CreateProcessWithLogonW 77DE5FFD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1420] ADVAPI32.dll!CreateProcessWithLogonW + 4 77DE6001 2 Bytes [95, 71] .text C:\WINDOWS\system32\svchost.exe[1420] Secur32.dll!EncryptMessage 77FCA68D 6 Bytes JMP 7180001E .text C:\WINDOWS\system32\svchost.exe[1420] USER32.dll!SetWindowsHookExW 7E37820F 6 Bytes JMP 717A001E .text C:\WINDOWS\system32\svchost.exe[1420] USER32.dll!SetWindowsHookExA 7E381211 6 Bytes JMP 717D001E .text C:\WINDOWS\system32\svchost.exe[1420] USER32.dll!SetWinEventHook 7E3817F7 6 Bytes JMP 7177001E .text C:\WINDOWS\system32\svchost.exe[1420] GDI32.dll!DeleteDC 77EF6E5F 6 Bytes JMP 7183001E .text C:\WINDOWS\system32\svchost.exe[1420] GDI32.dll!GetPixel 77EFB74C 6 Bytes JMP 7186001E .text C:\WINDOWS\system32\svchost.exe[1420] GDI32.dll!CreateDCA 77EFB7D2 6 Bytes JMP 718C001E .text C:\WINDOWS\system32\svchost.exe[1420] GDI32.dll!CreateDCW 77EFBE38 6 Bytes JMP 7189001E .text C:\WINDOWS\system32\svchost.exe[1556] ntdll.dll!NtClose 7C91CFEE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1556] ntdll.dll!NtClose + 4 7C91CFF2 2 Bytes [AE, 71] .text C:\WINDOWS\system32\svchost.exe[1556] ntdll.dll!NtReplyWaitReceivePort 7C91DA8E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1556] ntdll.dll!NtReplyWaitReceivePort + 4 7C91DA92 2 Bytes [74, 71] {JZ 0x73} .text C:\WINDOWS\system32\svchost.exe[1556] ntdll.dll!NtReplyWaitReceivePortEx 7C91DA9E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1556] ntdll.dll!NtReplyWaitReceivePortEx + 4 7C91DAA2 2 Bytes [71, 71] {JNO 0x73} .text C:\WINDOWS\system32\svchost.exe[1556] ntdll.dll!LdrUnloadDll 7C9271CD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1556] ntdll.dll!LdrUnloadDll + 4 7C9271D1 2 Bytes [A7, 71] .text C:\WINDOWS\system32\svchost.exe[1556] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AC0001 .text C:\WINDOWS\system32\svchost.exe[1556] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 719E001E .text C:\WINDOWS\system32\svchost.exe[1556] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 719B001E .text C:\WINDOWS\system32\svchost.exe[1556] ADVAPI32.dll!LsaClose + 51C 77DB2410 4 Bytes [20, 6B, 67, 00] .text C:\WINDOWS\system32\svchost.exe[1556] ADVAPI32.dll!LsaClose + 524 77DB2418 4 Bytes [B0, 6B, 67, 00] .text C:\WINDOWS\system32\svchost.exe[1556] ADVAPI32.dll!CreateProcessAsUserW 77DBA8A9 6 Bytes JMP 7192001E .text C:\WINDOWS\system32\svchost.exe[1556] ADVAPI32.dll!CreateProcessAsUserA 77DE0CE8 6 Bytes JMP 7198001E .text C:\WINDOWS\system32\svchost.exe[1556] ADVAPI32.dll!CreateProcessWithLogonW 77DE5FFD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1556] ADVAPI32.dll!CreateProcessWithLogonW + 4 77DE6001 2 Bytes [95, 71] .text C:\WINDOWS\system32\svchost.exe[1556] Secur32.dll!EncryptMessage 77FCA68D 6 Bytes JMP 7180001E .text C:\WINDOWS\system32\svchost.exe[1556] USER32.dll!SetWindowsHookExW 7E37820F 6 Bytes JMP 717A001E .text C:\WINDOWS\system32\svchost.exe[1556] USER32.dll!SetWindowsHookExA 7E381211 6 Bytes JMP 717D001E .text C:\WINDOWS\system32\svchost.exe[1556] USER32.dll!SetWinEventHook 7E3817F7 6 Bytes JMP 7177001E .text C:\WINDOWS\system32\svchost.exe[1556] GDI32.dll!DeleteDC 77EF6E5F 6 Bytes JMP 7183001E .text C:\WINDOWS\system32\svchost.exe[1556] GDI32.dll!GetPixel 77EFB74C 6 Bytes JMP 7186001E .text C:\WINDOWS\system32\svchost.exe[1556] GDI32.dll!CreateDCA 77EFB7D2 6 Bytes JMP 718C001E .text C:\WINDOWS\system32\svchost.exe[1556] GDI32.dll!CreateDCW 77EFBE38 6 Bytes JMP 7189001E .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] ntdll.dll!NtClose 7C91CFEE 3 Bytes [FF, 25, 1E] .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] ntdll.dll!NtClose + 4 7C91CFF2 2 Bytes [AE, 71] .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] ntdll.dll!NtReplyWaitReceivePort 7C91DA8E 3 Bytes [FF, 25, 1E] .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] ntdll.dll!NtReplyWaitReceivePort + 4 7C91DA92 2 Bytes [74, 71] {JZ 0x73} .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] ntdll.dll!NtReplyWaitReceivePortEx 7C91DA9E 3 Bytes [FF, 25, 1E] .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] ntdll.dll!NtReplyWaitReceivePortEx + 4 7C91DAA2 2 Bytes [71, 71] {JNO 0x73} .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] ntdll.dll!LdrUnloadDll 7C9271CD 3 Bytes [FF, 25, 1E] .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] ntdll.dll!LdrUnloadDll + 4 7C9271D1 2 Bytes [A7, 71] .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AC0001 .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 719E001E .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 719B001E .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] USER32.dll!SetWindowsHookExW 7E37820F 6 Bytes JMP 717A001E .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] USER32.dll!SetWindowsHookExA 7E381211 6 Bytes JMP 717D001E .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] USER32.dll!SetWinEventHook 7E3817F7 6 Bytes JMP 7177001E .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] GDI32.dll!DeleteDC 77EF6E5F 6 Bytes JMP 7183001E .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] GDI32.dll!GetPixel 77EFB74C 6 Bytes JMP 7186001E .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] GDI32.dll!CreateDCA 77EFB7D2 6 Bytes JMP 718C001E .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] GDI32.dll!CreateDCW 77EFBE38 6 Bytes JMP 7189001E .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] ADVAPI32.dll!LsaClose + 51C 77DB2410 4 Bytes [20, 6B, A8, 00] .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] ADVAPI32.dll!LsaClose + 524 77DB2418 4 Bytes [B0, 6B, A8, 00] {MOV AL, 0x6b; TEST AL, 0x0} .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] ADVAPI32.dll!CreateProcessAsUserW 77DBA8A9 6 Bytes JMP 7192001E .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] ADVAPI32.dll!CreateProcessAsUserA 77DE0CE8 6 Bytes JMP 7198001E .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] ADVAPI32.dll!CreateProcessWithLogonW 77DE5FFD 3 Bytes [FF, 25, 1E] .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] ADVAPI32.dll!CreateProcessWithLogonW + 4 77DE6001 2 Bytes [95, 71] .text C:\Program Files\Lenovo\OneKey App\System Repair\UpdateMonitor.exe[1580] Secur32.dll!EncryptMessage 77FCA68D 6 Bytes JMP 7180001E .text C:\WINDOWS\system32\spoolsv.exe[1728] ntdll.dll!NtClose 7C91CFEE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\spoolsv.exe[1728] ntdll.dll!NtClose + 4 7C91CFF2 2 Bytes [AE, 71] .text C:\WINDOWS\system32\spoolsv.exe[1728] ntdll.dll!NtReplyWaitReceivePort 7C91DA8E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\spoolsv.exe[1728] ntdll.dll!NtReplyWaitReceivePort + 4 7C91DA92 2 Bytes [74, 71] {JZ 0x73} .text C:\WINDOWS\system32\spoolsv.exe[1728] ntdll.dll!NtReplyWaitReceivePortEx 7C91DA9E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\spoolsv.exe[1728] ntdll.dll!NtReplyWaitReceivePortEx + 4 7C91DAA2 2 Bytes [71, 71] {JNO 0x73} .text C:\WINDOWS\system32\spoolsv.exe[1728] ntdll.dll!LdrUnloadDll 7C9271CD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\spoolsv.exe[1728] ntdll.dll!LdrUnloadDll + 4 7C9271D1 2 Bytes [A7, 71] .text C:\WINDOWS\system32\spoolsv.exe[1728] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AC0001 .text C:\WINDOWS\system32\spoolsv.exe[1728] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 719E001E .text C:\WINDOWS\system32\spoolsv.exe[1728] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 719B001E .text C:\WINDOWS\system32\spoolsv.exe[1728] ADVAPI32.dll!LsaClose + 51C 77DB2410 4 Bytes [20, 6B, 90, 00] .text C:\WINDOWS\system32\spoolsv.exe[1728] ADVAPI32.dll!LsaClose + 524 77DB2418 4 Bytes [B0, 6B, 90, 00] .text C:\WINDOWS\system32\spoolsv.exe[1728] ADVAPI32.dll!CreateProcessAsUserW 77DBA8A9 6 Bytes JMP 7192001E .text C:\WINDOWS\system32\spoolsv.exe[1728] ADVAPI32.dll!CreateProcessAsUserA 77DE0CE8 6 Bytes JMP 7198001E .text C:\WINDOWS\system32\spoolsv.exe[1728] ADVAPI32.dll!CreateProcessWithLogonW 77DE5FFD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\spoolsv.exe[1728] ADVAPI32.dll!CreateProcessWithLogonW + 4 77DE6001 2 Bytes [95, 71] .text C:\WINDOWS\system32\spoolsv.exe[1728] Secur32.dll!EncryptMessage 77FCA68D 6 Bytes JMP 7180001E .text C:\WINDOWS\system32\spoolsv.exe[1728] GDI32.dll!DeleteDC 77EF6E5F 6 Bytes JMP 7183001E .text C:\WINDOWS\system32\spoolsv.exe[1728] GDI32.dll!GetPixel 77EFB74C 6 Bytes JMP 7186001E .text C:\WINDOWS\system32\spoolsv.exe[1728] GDI32.dll!CreateDCA 77EFB7D2 6 Bytes JMP 718C001E .text C:\WINDOWS\system32\spoolsv.exe[1728] GDI32.dll!CreateDCW 77EFBE38 6 Bytes JMP 7189001E .text C:\WINDOWS\system32\spoolsv.exe[1728] USER32.dll!SetWindowsHookExW 7E37820F 6 Bytes JMP 717A001E .text C:\WINDOWS\system32\spoolsv.exe[1728] USER32.dll!SetWindowsHookExA 7E381211 6 Bytes JMP 717D001E .text C:\WINDOWS\system32\spoolsv.exe[1728] USER32.dll!SetWinEventHook 7E3817F7 6 Bytes JMP 7177001E .text C:\WINDOWS\system32\svchost.exe[1864] ntdll.dll!NtClose 7C91CFEE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1864] ntdll.dll!NtClose + 4 7C91CFF2 2 Bytes [AE, 71] .text C:\WINDOWS\system32\svchost.exe[1864] ntdll.dll!NtReplyWaitReceivePort 7C91DA8E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1864] ntdll.dll!NtReplyWaitReceivePort + 4 7C91DA92 2 Bytes [74, 71] {JZ 0x73} .text C:\WINDOWS\system32\svchost.exe[1864] ntdll.dll!NtReplyWaitReceivePortEx 7C91DA9E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1864] ntdll.dll!NtReplyWaitReceivePortEx + 4 7C91DAA2 2 Bytes [71, 71] {JNO 0x73} .text C:\WINDOWS\system32\svchost.exe[1864] ntdll.dll!LdrUnloadDll 7C9271CD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1864] ntdll.dll!LdrUnloadDll + 4 7C9271D1 2 Bytes [A7, 71] .text C:\WINDOWS\system32\svchost.exe[1864] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AC0001 .text C:\WINDOWS\system32\svchost.exe[1864] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 719E001E .text C:\WINDOWS\system32\svchost.exe[1864] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 719B001E .text C:\WINDOWS\system32\svchost.exe[1864] ADVAPI32.dll!LsaClose + 51C 77DB2410 4 Bytes [20, 6B, 67, 00] .text C:\WINDOWS\system32\svchost.exe[1864] ADVAPI32.dll!LsaClose + 524 77DB2418 4 Bytes [B0, 6B, 67, 00] .text C:\WINDOWS\system32\svchost.exe[1864] ADVAPI32.dll!CreateProcessAsUserW 77DBA8A9 6 Bytes JMP 7192001E .text C:\WINDOWS\system32\svchost.exe[1864] ADVAPI32.dll!CreateProcessAsUserA 77DE0CE8 6 Bytes JMP 7198001E .text C:\WINDOWS\system32\svchost.exe[1864] ADVAPI32.dll!CreateProcessWithLogonW 77DE5FFD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\svchost.exe[1864] ADVAPI32.dll!CreateProcessWithLogonW + 4 77DE6001 2 Bytes [95, 71] .text C:\WINDOWS\system32\svchost.exe[1864] Secur32.dll!EncryptMessage 77FCA68D 6 Bytes JMP 7180001E .text C:\WINDOWS\system32\svchost.exe[1864] USER32.dll!SetWindowsHookExW 7E37820F 6 Bytes JMP 717A001E .text C:\WINDOWS\system32\svchost.exe[1864] USER32.dll!SetWindowsHookExA 7E381211 6 Bytes JMP 717D001E .text C:\WINDOWS\system32\svchost.exe[1864] USER32.dll!SetWinEventHook 7E3817F7 6 Bytes JMP 7177001E .text C:\WINDOWS\system32\svchost.exe[1864] GDI32.dll!DeleteDC 77EF6E5F 6 Bytes JMP 7183001E .text C:\WINDOWS\system32\svchost.exe[1864] GDI32.dll!GetPixel 77EFB74C 6 Bytes JMP 7186001E .text C:\WINDOWS\system32\svchost.exe[1864] GDI32.dll!CreateDCA 77EFB7D2 6 Bytes JMP 718C001E .text C:\WINDOWS\system32\svchost.exe[1864] GDI32.dll!CreateDCW 77EFBE38 6 Bytes JMP 7189001E .text C:\WINDOWS\system32\ctfmon.exe[1952] ntdll.dll!NtClose 7C91CFEE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\ctfmon.exe[1952] ntdll.dll!NtClose + 4 7C91CFF2 2 Bytes [AE, 71] .text C:\WINDOWS\system32\ctfmon.exe[1952] ntdll.dll!NtReplyWaitReceivePort 7C91DA8E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\ctfmon.exe[1952] ntdll.dll!NtReplyWaitReceivePort + 4 7C91DA92 2 Bytes [74, 71] {JZ 0x73} .text C:\WINDOWS\system32\ctfmon.exe[1952] ntdll.dll!NtReplyWaitReceivePortEx 7C91DA9E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\ctfmon.exe[1952] ntdll.dll!NtReplyWaitReceivePortEx + 4 7C91DAA2 2 Bytes [71, 71] {JNO 0x73} .text C:\WINDOWS\system32\ctfmon.exe[1952] ntdll.dll!LdrUnloadDll 7C9271CD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\ctfmon.exe[1952] ntdll.dll!LdrUnloadDll + 4 7C9271D1 2 Bytes [A7, 71] .text C:\WINDOWS\system32\ctfmon.exe[1952] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AC0001 .text C:\WINDOWS\system32\ctfmon.exe[1952] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 719E001E .text C:\WINDOWS\system32\ctfmon.exe[1952] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 719B001E .text C:\WINDOWS\system32\ctfmon.exe[1952] ADVAPI32.dll!CreateProcessAsUserW 77DBA8A9 6 Bytes JMP 7192001E .text C:\WINDOWS\system32\ctfmon.exe[1952] ADVAPI32.dll!CreateProcessAsUserA 77DE0CE8 6 Bytes JMP 7198001E .text C:\WINDOWS\system32\ctfmon.exe[1952] ADVAPI32.dll!CreateProcessWithLogonW 77DE5FFD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\system32\ctfmon.exe[1952] ADVAPI32.dll!CreateProcessWithLogonW + 4 77DE6001 2 Bytes [95, 71] .text C:\WINDOWS\system32\ctfmon.exe[1952] Secur32.dll!EncryptMessage 77FCA68D 6 Bytes JMP 7180001E .text C:\WINDOWS\system32\ctfmon.exe[1952] USER32.dll!SetWindowsHookExW 7E37820F 6 Bytes JMP 717A001E .text C:\WINDOWS\system32\ctfmon.exe[1952] USER32.dll!SetWindowsHookExA 7E381211 6 Bytes JMP 717D001E .text C:\WINDOWS\system32\ctfmon.exe[1952] USER32.dll!SetWinEventHook 7E3817F7 6 Bytes JMP 7177001E .text C:\WINDOWS\system32\ctfmon.exe[1952] GDI32.dll!DeleteDC 77EF6E5F 6 Bytes JMP 7183001E .text C:\WINDOWS\system32\ctfmon.exe[1952] GDI32.dll!GetPixel 77EFB74C 6 Bytes JMP 7186001E .text C:\WINDOWS\system32\ctfmon.exe[1952] GDI32.dll!CreateDCA 77EFB7D2 6 Bytes JMP 718C001E .text C:\WINDOWS\system32\ctfmon.exe[1952] GDI32.dll!CreateDCW 77EFBE38 6 Bytes JMP 7189001E .text C:\WINDOWS\Explorer.EXE[2036] ntdll.dll!NtClose 7C91CFEE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\Explorer.EXE[2036] ntdll.dll!NtClose + 4 7C91CFF2 2 Bytes [AE, 71] .text C:\WINDOWS\Explorer.EXE[2036] ntdll.dll!NtReplyWaitReceivePort 7C91DA8E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\Explorer.EXE[2036] ntdll.dll!NtReplyWaitReceivePort + 4 7C91DA92 2 Bytes [74, 71] {JZ 0x73} .text C:\WINDOWS\Explorer.EXE[2036] ntdll.dll!NtReplyWaitReceivePortEx 7C91DA9E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\Explorer.EXE[2036] ntdll.dll!NtReplyWaitReceivePortEx + 4 7C91DAA2 2 Bytes [71, 71] {JNO 0x73} .text C:\WINDOWS\Explorer.EXE[2036] ntdll.dll!LdrUnloadDll 7C9271CD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\Explorer.EXE[2036] ntdll.dll!LdrUnloadDll + 4 7C9271D1 2 Bytes [A7, 71] .text C:\WINDOWS\Explorer.EXE[2036] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AC0001 .text C:\WINDOWS\Explorer.EXE[2036] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 719E001E .text C:\WINDOWS\Explorer.EXE[2036] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 719B001E .text C:\WINDOWS\Explorer.EXE[2036] ADVAPI32.dll!LsaClose + 51C 77DB2410 4 Bytes [20, 6B, C0, 00] .text C:\WINDOWS\Explorer.EXE[2036] ADVAPI32.dll!LsaClose + 524 77DB2418 4 Bytes [B0, 6B, C0, 00] .text C:\WINDOWS\Explorer.EXE[2036] ADVAPI32.dll!CreateProcessAsUserW 77DBA8A9 6 Bytes JMP 7192001E .text C:\WINDOWS\Explorer.EXE[2036] ADVAPI32.dll!CreateProcessAsUserA 77DE0CE8 6 Bytes JMP 7198001E .text C:\WINDOWS\Explorer.EXE[2036] ADVAPI32.dll!CreateProcessWithLogonW 77DE5FFD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\Explorer.EXE[2036] ADVAPI32.dll!CreateProcessWithLogonW + 4 77DE6001 2 Bytes [95, 71] .text C:\WINDOWS\Explorer.EXE[2036] Secur32.dll!EncryptMessage 77FCA68D 6 Bytes JMP 7180001E .text C:\WINDOWS\Explorer.EXE[2036] GDI32.dll!DeleteDC 77EF6E5F 6 Bytes JMP 7183001E .text C:\WINDOWS\Explorer.EXE[2036] GDI32.dll!GetPixel 77EFB74C 6 Bytes JMP 7186001E .text C:\WINDOWS\Explorer.EXE[2036] GDI32.dll!CreateDCA 77EFB7D2 6 Bytes JMP 718C001E .text C:\WINDOWS\Explorer.EXE[2036] GDI32.dll!CreateDCW 77EFBE38 6 Bytes JMP 7189001E .text C:\WINDOWS\Explorer.EXE[2036] USER32.dll!SetWindowsHookExW 7E37820F 6 Bytes JMP 717A001E .text C:\WINDOWS\Explorer.EXE[2036] USER32.dll!SetWindowsHookExA 7E381211 6 Bytes JMP 717D001E .text C:\WINDOWS\Explorer.EXE[2036] USER32.dll!SetWinEventHook 7E3817F7 6 Bytes JMP 7177001E .text C:\WINDOWS\System32\alg.exe[2580] ntdll.dll!NtClose 7C91CFEE 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\System32\alg.exe[2580] ntdll.dll!NtClose + 4 7C91CFF2 2 Bytes [AE, 71] .text C:\WINDOWS\System32\alg.exe[2580] ntdll.dll!NtReplyWaitReceivePort 7C91DA8E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\System32\alg.exe[2580] ntdll.dll!NtReplyWaitReceivePort + 4 7C91DA92 2 Bytes [6C, 71] .text C:\WINDOWS\System32\alg.exe[2580] ntdll.dll!NtReplyWaitReceivePortEx 7C91DA9E 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\System32\alg.exe[2580] ntdll.dll!NtReplyWaitReceivePortEx + 4 7C91DAA2 2 Bytes [69, 71] .text C:\WINDOWS\System32\alg.exe[2580] ntdll.dll!LdrUnloadDll 7C9271CD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\System32\alg.exe[2580] ntdll.dll!LdrUnloadDll + 4 7C9271D1 2 Bytes [A7, 71] .text C:\WINDOWS\System32\alg.exe[2580] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AC0001 .text C:\WINDOWS\System32\alg.exe[2580] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 7196001E .text C:\WINDOWS\System32\alg.exe[2580] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 7193001E .text C:\WINDOWS\System32\alg.exe[2580] USER32.dll!SetWindowsHookExW 7E37820F 6 Bytes JMP 7172001E .text C:\WINDOWS\System32\alg.exe[2580] USER32.dll!SetWindowsHookExA 7E381211 6 Bytes JMP 7175001E .text C:\WINDOWS\System32\alg.exe[2580] USER32.dll!SetWinEventHook 7E3817F7 6 Bytes JMP 716F001E .text C:\WINDOWS\System32\alg.exe[2580] GDI32.dll!DeleteDC 77EF6E5F 6 Bytes JMP 717B001E .text C:\WINDOWS\System32\alg.exe[2580] GDI32.dll!GetPixel 77EFB74C 6 Bytes JMP 717E001E .text C:\WINDOWS\System32\alg.exe[2580] GDI32.dll!CreateDCA 77EFB7D2 6 Bytes JMP 7184001E .text C:\WINDOWS\System32\alg.exe[2580] GDI32.dll!CreateDCW 77EFBE38 6 Bytes JMP 7181001E .text C:\WINDOWS\System32\alg.exe[2580] ADVAPI32.dll!LsaClose + 51C 77DB2410 4 Bytes [20, 6B, 70, 00] .text C:\WINDOWS\System32\alg.exe[2580] ADVAPI32.dll!LsaClose + 524 77DB2418 4 Bytes [B0, 6B, 70, 00] {MOV AL, 0x6b; JO 0x4} .text C:\WINDOWS\System32\alg.exe[2580] ADVAPI32.dll!CreateProcessAsUserW 77DBA8A9 6 Bytes JMP 718A001E .text C:\WINDOWS\System32\alg.exe[2580] ADVAPI32.dll!CreateProcessAsUserA 77DE0CE8 6 Bytes JMP 7190001E .text C:\WINDOWS\System32\alg.exe[2580] ADVAPI32.dll!CreateProcessWithLogonW 77DE5FFD 3 Bytes [FF, 25, 1E] .text C:\WINDOWS\System32\alg.exe[2580] ADVAPI32.dll!CreateProcessWithLogonW + 4 77DE6001 2 Bytes [8D, 71] .text C:\WINDOWS\System32\alg.exe[2580] Secur32.dll!EncryptMessage 77FCA68D 6 Bytes JMP 7178001E .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] ntdll.dll!NtClose 7C91CFEE 3 Bytes [FF, 25, 1E] .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] ntdll.dll!NtClose + 4 7C91CFF2 2 Bytes [AE, 71] .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] ntdll.dll!NtReplyWaitReceivePort 7C91DA8E 3 Bytes [FF, 25, 1E] .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] ntdll.dll!NtReplyWaitReceivePort + 4 7C91DA92 2 Bytes [74, 71] {JZ 0x73} .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] ntdll.dll!NtReplyWaitReceivePortEx 7C91DA9E 3 Bytes [FF, 25, 1E] .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] ntdll.dll!NtReplyWaitReceivePortEx + 4 7C91DAA2 2 Bytes [71, 71] {JNO 0x73} .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] ntdll.dll!LdrUnloadDll 7C9271CD 3 Bytes [FF, 25, 1E] .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] ntdll.dll!LdrUnloadDll + 4 7C9271D1 2 Bytes [A7, 71] .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AC0001 .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] kernel32.dll!CreateProcessW 7C802336 6 Bytes JMP 719F000A .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] kernel32.dll!CreateProcessA 7C80236B 6 Bytes JMP 719C000A .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] USER32.dll!SetWindowsHookExW 7E37820F 6 Bytes JMP 717B000A .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] USER32.dll!SetWindowsHookExA 7E381211 6 Bytes JMP 717E000A .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] USER32.dll!SetWinEventHook 7E3817F7 6 Bytes JMP 7178000A .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] GDI32.dll!DeleteDC 77EF6E5F 6 Bytes JMP 7184000A .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] GDI32.dll!GetPixel 77EFB74C 6 Bytes JMP 7187000A .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] GDI32.dll!CreateDCA 77EFB7D2 6 Bytes JMP 718D000A .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] GDI32.dll!CreateDCW 77EFBE38 6 Bytes JMP 718A000A .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] ADVAPI32.dll!LsaClose + 51C 77DB2410 4 Bytes [20, 6B, 01, 10] .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] ADVAPI32.dll!LsaClose + 524 77DB2418 4 Bytes [B0, 6B, 01, 10] {MOV AL, 0x6b; ADD [EAX], EDX} .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] ADVAPI32.dll!CreateProcessAsUserW 77DBA8A9 6 Bytes JMP 7193000A .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] ADVAPI32.dll!CreateProcessAsUserA 77DE0CE8 6 Bytes JMP 7199000A .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] ADVAPI32.dll!CreateProcessWithLogonW 77DE5FFD 3 Bytes [FF, 25, 1E] .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] ADVAPI32.dll!CreateProcessWithLogonW + 4 77DE6001 2 Bytes [95, 71] .text C:\Dokumente und Einstellungen\**** *******\Desktop\Gmer-19357.exe[3000] Secur32.dll!EncryptMessage 77FCA68D 6 Bytes JMP 7181000A .text C:\Programme\COMODO\COMODO Internet Security\cavwp.exe[3288] ntdll.dll!NtAllocateVirtualMemory 7C91CF6E 5 Bytes JMP 004011F0 C:\Programme\COMODO\COMODO Internet Security\cavwp.exe .text C:\Programme\COMODO\COMODO Internet Security\cavwp.exe[3288] ntdll.dll!NtCreateFile 7C91D0AE 5 Bytes JMP 00401000 C:\Programme\COMODO\COMODO Internet Security\cavwp.exe ---- Devices - GMER 2.1 ---- AttachedDevice \FileSystem\Ntfs \Ntfs tvtumon.sys AttachedDevice \Driver\Tcpip \Device\Ip cmdhlp.sys AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys AttachedDevice \Driver\Tcpip \Device\Tcp cmdhlp.sys AttachedDevice \Driver\Tcpip \Device\Udp cmdhlp.sys AttachedDevice \Driver\Tcpip \Device\RawIp cmdhlp.sys AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys AttachedDevice \FileSystem\Fastfat \Fat tvtumon.sys ---- Processes - GMER 2.1 ---- Process (*** hidden *** ) [4] 86FC3458 |
---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\CmdAgent\Mode\Configurations@SymbolicLinkValue 0x5C 0x00 0x52 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\CmdAgent\Mode\Data@SymbolicLinkValue 0x5C 0x00 0x52 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\CmdAgent\Mode\Options@SymbolicLinkValue 0x5C 0x00 0x52 0x00 ... Reg HKLM\SYSTEM\Software\COMODO\Cam@SymbolicLinkValue 0x5C 0x00 0x52 0x00 ... Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro@SymbolicLinkValue 0x5C 0x00 0x52 0x00 ... Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroExt.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroExt.exe@DisableExceptionChainValidation 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroExt.exe@MitigationOptions 0x00 0x01 0x00 0x00 ... Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroRd32.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroRd32.exe@DisableExceptionChainValidation 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroRd32.exe@MitigationOptions 0x00 0x01 0x00 0x00 ... Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroRd32Info.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroRd32Info.exe@DisableExceptionChainValidation 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AcroRd32Info.exe@MitigationOptions 0x00 0x01 0x00 0x00 ... Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\apitrap.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\apitrap.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ASSTE.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ASSTE.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVSTE.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVSTE.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cleanup.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cleanup.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cqw32.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cqw32.exe@ApplicationGoo 0x14 0x02 0x00 0x00 ... Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divxdec.ax Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divxdec.ax@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DJSMAR00.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DJSMAR00.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DRMINST.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DRMINST.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dw20.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dw20.exe@DisableExceptionChainValidation 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dwtrig20.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dwtrig20.exe@DisableExceptionChainValidation 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\enc98.EXE Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\enc98.EXE@DisableHeapLookAside 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EncodeDivXExt.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EncodeDivXExt.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EncryptPatchVer.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EncryptPatchVer.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerApp.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerApp.exe@DisableExceptionChainValidation 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerPlugin_11_9_900_152.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerPlugin_11_9_900_152.exe@DisableExceptionChainValidation 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerPlugin_11_9_900_170.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerPlugin_11_9_900_170.exe@DisableExceptionChainValidation 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerPlugin_12_0_0_44.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerPlugin_12_0_0_44.exe@DisableExceptionChainValidation 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerPlugin_12_0_0_70.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerPlugin_12_0_0_70.exe@DisableExceptionChainValidation 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerPlugin_12_0_0_77.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerPlugin_12_0_0_77.exe@DisableExceptionChainValidation 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerPlugin_13_0_0_206.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerPlugin_13_0_0_206.exe@DisableExceptionChainValidation 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerPlugin_13_0_0_214.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerPlugin_13_0_0_214.exe@DisableExceptionChainValidation 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerPlugin_14_0_0_145.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerPlugin_14_0_0_145.exe@DisableExceptionChainValidation 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerUpdateService.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerUpdateService.exe@DisableExceptionChainValidation 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil32_14_0_0_145_ActiveX.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil32_14_0_0_145_ActiveX.exe@DisableExceptionChainValidation 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil32_14_0_0_145_pepper.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil32_14_0_0_145_pepper.exe@DisableExceptionChainValidation 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil32_14_0_0_145_Plugin.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil32_14_0_0_145_Plugin.exe@DisableExceptionChainValidation 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\front.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\front.exe@ApplicationGoo 0x54 0x09 0x00 0x00 ... Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fullsoft.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fullsoft.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GBROWSER.DLL Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GBROWSER.DLL@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\htmlmarq.ocx Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\htmlmarq.ocx@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\htmlmm.ocx Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\htmlmm.ocx@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install.exe@ApplicationGoo 0x58 0x02 0x00 0x00 ... Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ishscan.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ishscan.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ISSTE.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ISSTE.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\javai.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\javai.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jvm.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jvm.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jvm_g.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jvm_g.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\main123w.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\main123w.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mngreg32.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mngreg32.exe@ApplicationGoo 0x58 0x02 0x00 0x00 ... Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msci_uno.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msci_uno.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscoree.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscoree.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscorsvr.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscorsvr.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscorwks.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscorwks.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msjava.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msjava.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mso.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mso.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssdmn.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssdmn.exe@DisableExceptionChainValidation 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssearch.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mssearch.exe@DisableExceptionChainValidation 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NAVOPTRF.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NAVOPTRF.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NeVideoFX.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NeVideoFX.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NPMLIC.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NPMLIC.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NSWSTE.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NSWSTE.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\photohse.EXE Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\photohse.EXE@GlobalFlag 0x00200000 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PMSTE.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PMSTE.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppw32hlp.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppw32hlp.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PriceMeterLiveUpdate.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PriceMeterLiveUpdate.exe@DisableExceptionChainValidation 0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\printhse.EXE Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\printhse.EXE@GlobalFlag 0x00200000 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\prwin8.EXE Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\prwin8.EXE@DisableHeapLookAside 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ps80.EXE Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ps80.EXE@DisableHeapLookAside 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\psdmt.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\psdmt.exe@ApplicationGoo 0x14 0x02 0x00 0x00 ... Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qfinder.EXE Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qfinder.EXE@DisableHeapLookAside 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qpw.EXE Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qpw.EXE@DisableHeapLookAside 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\salwrap.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\salwrap.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe@ApplicationGoo 0x00 0x07 0x00 0x00 ... Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup32.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup32.dll@ApplicationGoo 0x14 0x02 0x00 0x00 ... Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcnet.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcnet.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tcore_ebook.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tcore_ebook.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TFDTCTT8.DLL Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TFDTCTT8.DLL@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ua80.EXE Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ua80.EXE@DisableHeapLookAside 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\udtapi.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\udtapi.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ums.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ums.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vb40032.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vb40032.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbe6.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbe6.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wpwin8.EXE Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wpwin8.EXE@DisableHeapLookAside 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xlmlEN.dll Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xlmlEN.dll@CheckAppHelp 1 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xwsetup.EXE Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xwsetup.EXE@ApplicationGoo 0x14 0x02 0x00 0x00 ... Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path@Debugger ntsd -d Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path@GlobalFlag 0x000010F0 Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_INSTPGM.EXE Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_INSTPGM.EXE@ApplicationGoo 0x14 0x02 0x00 0x00 ... ---- EOF - GMER 2.1 ---- ____________________________________________ Hoffe ich habe jetzt nichts falsch verstanden. Riesen Post :O |
Hm...was hast du an den CODE-Tags nicht verstanden? |
FRST hat noch geklappt. Mist... Soll ich die drei restlichen nochmal verpacken oder ist das jetzt hinfällig. Mein Fehler - Entschuldigung |
Postings bitte editieren |
Neuer Versuch (editieren geht nicht mehr?!) Code: defogger_disable by jpshortstuff (23.02.10.1) FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:26-08-2014 --- --- --- Code: Additional scan result of Farbar Recovery Scan Tool (x86) Version:26-08-2014 |
Code: GMER 2.1.19357 - hxxp://www.gmer.net |
Code: ---- Registry - GMER 2.1 ---- Hoffe ich habe es jetzt so hinbekommen wie gewollt :) Edit: Könnte man denn meine Failposts löschen? |
Das Ding sieht hoffnungslos veraltet aus...wie alt ist denn das Netbook? ![]() Windows XP Auf deinem Rechner läuft noch Windows XP. Microsoft hat dieses Betriebssystem bereits 2001 veröffentlicht und stellt den Support endgültig ab April 2014 ein, d.h. ab Mai 2014 gibt es keine weiteren Updates mehr und danach gefundene Lücken werden nicht mehr durch Updates/Hotfixes geschlossen werden können. Mit Windows XP nach April 2014 zu surfen wird damit ein großes Sicherheitsrisiko. Du solltest dir jetzt unbedingt Gedanken machen, möglichst schnell auf ein aktuelleres Betriebssystem umzusteigen. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 05:37 Uhr. |
Copyright ©2000-2025, Trojaner-Board