Freddy1472 | 02.11.2014 14:33 | ... und hier der zweite (letzte) Schwung:
Addition.txt:
FRST Additions Logfile: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-11-2014
Ran by Freddy at 2014-11-02 01:44:56
Running from C:\Users\Freddy\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Sophos Anti-Virus (Enabled - Up to date) {6BABF8F7-3EB6-BD1D-9167-8C5ECA060A29}
AS: Sophos Anti-Virus (Enabled - Up to date) {D0CA1913-188C-B293-ABD7-B72CB1814094}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
ActivClient x64 (Version: 6.2 - ActivIdentity) Hidden
Adobe Acrobat X Pro - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.12 - Adobe Systems)
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.167 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.189 - Adobe Systems Incorporated)
AuthenTec Fingerprint System (Version: 8.0.202.0 - AuthenTec, Inc.) Hidden
AVM FRITZ!fax für FRITZ!Box (HKLM-x32\...\FRITZ! 2.0) (Version: - AVM Berlin)
BIOS Configuration for HP ProtectTools (HKLM-x32\...\{1960BE46-E85A-4933-B10A-6D8516585288}) (Version: 4.00 E1 - Hewlett-Packard)
Broadcom 802.11 Wireless LAN Adapter (HKLM\...\Broadcom 802.11 Wireless LAN Adapter) (Version: 5.60.18.12 - Broadcom Corporation)
Broadcom Wireless Utility (HKLM\...\Broadcom Wireless Utility) (Version: 5.60.18.12 - Broadcom Corporation)
Brother MFL-Pro Suite MFC-J6710DW (HKLM-x32\...\{17795164-3BC1-4D4F-8ADA-65C895EBFC9A}) (Version: 1.0.20.0 - Brother Industries, Ltd.)
CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
Cisco Systems VPN Client 5.0.07.0290 (HKLM\...\{467D5E81-8349-4892-9E81-C3674ED8E451}) (Version: 5.0.7 - Cisco Systems, Inc.)
Citrix Receiver (HKLM-x32\...\CitrixOnlinePluginPackWeb) (Version: 14.1.0.0 - Citrix Systems, Inc.)
Credential Manager for HP ProtectTools (x32 Version: 4.1.6.1484 - Hewlett-Packard Company) Hidden
Device Access Manager for HP ProtectTools (HKLM\...\{55B52830-024A-443E-AF61-61E1E71AFA1B}) (Version: 5.0.1.3 - Hewlett-Packard)
DHTML Editing Component (HKLM-x32\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0001 - Microsoft Corporation)
DisplayLink Core Software (HKLM\...\{8FCE3895-45F7-4C42-9AB2-4A6D6ED6324F}) (Version: 5.2.22271.0 - DisplayLink Corp.)
Drive Encryption for HP ProtectTools (Version: 4.0.24 - Hewlett-Packard) Hidden
ElsterFormular (HKLM-x32\...\ElsterFormular) (Version: 15.2.20140326 - Landesfinanzdirektion Thüringen)
Embedded Security for HP ProtectTools (HKLM\...\{4599ECEA-44C6-418C-9F66-9AAF5561CBDC}) (Version: 5.6.000 - Hewlett-Packard)
Enterprise Architect 9.3 (HKLM-x32\...\{CC98E8B3-FAAA-4D09-A813-A44C9FA1A3EE}) (Version: 9.3.930.102 - Sparx Systems)
File Sanitizer For HP ProtectTools (HKLM-x32\...\{789C97CE-9E17-4126-BDF4-11FF458BF705}) (Version: 1.0.1.10 - Hewlett-Packard)
FreeFileSync 6.5 (HKLM-x32\...\FreeFileSync) (Version: 6.5 - Zenju)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 38.0.2125.111 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.5 - Google Inc.) Hidden
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP 3D DriveGuard (HKLM\...\{9B6079F8-EBA2-4C55-96A6-325E8E22DF0C}) (Version: 4.0.4.1 - Hewlett-Packard)
HP Connection Manager (HKLM-x32\...\{7A6B4340-7090-418F-8976-EE9650B35550}) (Version: 4.1.22.1 - Hewlett-Packard Company)
HP ESU for Microsoft Windows 7 (HKLM-x32\...\{4850C1AE-BD1D-468C-9ABC-5486DC21E1E5}) (Version: 1.0.3.1 - Hewlett-Packard)
HP Integrated Module with Bluetooth wireless technology (HKLM\...\{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}) (Version: 6.2.0.9602 - Broadcom Corporation)
HP ProtectTools Security Manager Suite (HKLM-x32\...\{75D7BB3A-9AB7-4ad1-AD5E-0059B90C624B}) (Version: 04.10.10.0003 - Hewlett-Packard)
HP Quick Launch Buttons (HKLM-x32\...\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.50.14.1 - Hewlett-Packard Company)
HP SoftPaq Download Manager (HKLM-x32\...\{34FF930E-DBF9-4858-BAB5-BAC957BF616E}) (Version: 3.5.1.0 - Hewlett-Packard Company)
HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company)
HP USB Docking Video (HKLM\...\{AD73C813-335F-45E7-9772-A4583FDFD177}) (Version: 5.2.22372.0 - Hewlett-Packard)
HP Wireless Assistant (HKLM-x32\...\{1061DF04-CF33-40B0-8360-D07C9BBEB122}) (Version: 3.50.10.1 - Hewlett-Packard)
Intel(R) Active Management Technology Device Software (HKLM\...\MESOL) (Version: - )
Intel(R) Management Engine Interface (HKLM\...\HECI) (Version: - )
Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation)
Java 7 Update 67 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217055FF}) (Version: 7.0.670 - Oracle)
LightScribe System Software (HKLM-x32\...\{82EF29B1-9B60-4142-A155-0599216DD053}) (Version: 1.18.6.1 - LightScribe)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Image Composite Editor (HKLM\...\{B821CDAA-34DE-46FD-87C9-E6EE7158DB5D}) (Version: 1.4.4 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Sync Framework 2.0 Core Components (x64) ENU (HKLM\...\{8CCBEC22-D2DB-4DC9-A58A-E1A1F3A38C8A}) (Version: 2.0.1578.0 - Microsoft Corporation)
Microsoft Sync Framework 2.0 Provider Services (x64) ENU (HKLM\...\{03AC245F-4C64-425C-89CF-7783C1D3AB2C}) (Version: 2.0.1578.0 - Microsoft Corporation)
Microsoft Visio Premium 2010 (HKLM-x32\...\Office14.VISIO) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 33.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 33.0 (x86 de)) (Version: 33.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MyDriveConnect 3.3.0.1756 (HKLM-x32\...\MyDriveConnect) (Version: 3.3.0.1756 - TomTom)
Nuance PaperPort 12 (HKLM-x32\...\{6C0A559F-8583-4B5A-8B50-20BEE15D8E64}) (Version: 12.1.0000 - Nuance Communications, Inc.)
Nuance PDF Viewer Plus (HKLM-x32\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc)
NVIDIA 3D Vision Treiber 327.02 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 327.02 - NVIDIA Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.4 - NVIDIA Corporation)
NVIDIA Grafiktreiber 327.02 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 327.02 - NVIDIA Corporation)
NVIDIA nView 140.62 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView) (Version: 140.62 - NVIDIA Corporation)
NVIDIA nView Desktop Manager (HKLM\...\nView Desktop Manager) (Version: - )
NVIDIA WMI 2.14.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVWMI) (Version: 2.14.0 - NVIDIA Corporation)
Online Plug-in (x32 Version: 14.1.0.0 - Citrix Systems, Inc.) Hidden
PaperPort Image Printer 64-bit (HKLM\...\{715CAACC-579B-4831-A5F4-A83A8DE3EFE2}) (Version: 1.00.0001 - Nuance Communications, Inc.)
Privacy Manager for HP ProtectTools (HKLM-x32\...\{4E8E3D7B-B20D-4FD6-9E72-A84BAD1C35CC}) (Version: 1.0.1.599 - DigitalPersona, Inc.)
QLBCASL (x32 Version: 6.40.17.2 - Hewlett-Packard) Hidden
RICOH Media Driver (HKLM-x32\...\{F5CC2EF8-20A4-4366-A681-3FE849E65809}) (Version: 2.10.00.04 - RICOH)
Scan Tailor (HKLM-x32\...\Scan Tailor) (Version: - )
Scansoft PDF Professional (x32 Version: - ) Hidden
Self-Service Plug-in (x32 Version: 4.1.0.41738 - Citrix Systems, Inc.) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-0057-0000-0000-0000000FF1CE}_Office14.VISIO_{359ADBEC-068A-4CC9-9174-77AB8EDB867A}) (Version: - Microsoft)
Sibelius Scorch (Firefox, Opera, Netscape, Chrome only) (HKLM-x32\...\{41626CC0-A854-4402-AD06-D7939515C282}) (Version: 6.2.0 - Sibelius Software, a division of Avid Technology, Inc.)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.)
Soft Data Fax Modem with SmartCP (HKLM\...\CNXT_MODEM_PCI_VEN_14F1&DEV_2C06_hpZ1379y) (Version: 7.80.3.52 - Conexant Systems)
Sophos Anti-Virus (HKLM-x32\...\{D929B3B5-56C6-46CC-B3A3-A1A784CBB8E4}) (Version: 10.3.11 - Sophos Limited)
Sophos AutoUpdate (HKLM-x32\...\{D924231F-D02D-4E0B-B511-CC4A0E3ED547}) (Version: 3.1.4.81 - Sophos Limited)
SoundMAX (HKLM-x32\...\{F0A37341-D692-11D4-A984-009027EC0A9C}) (Version: 6.10.2.5240 - Analog Devices)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.24.0 - Synaptics Incorporated)
SyncToy 2.1 (x64) (HKLM\...\{88DAAF05-5A72-46D2-A7C5-C3759697E943}) (Version: 2.1.0 - Microsoft)
Turbo Lister 2 (HKLM-x32\...\{8927E07C-97F7-4A54-88FB-D976F50DD46E}) (Version: 2.00.0000 - eBay Inc.)
TV-Browser 3.3.3 (HKLM-x32\...\tvbrowser) (Version: 3.3.3 - TV-Browser Team)
Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.)
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Windows 7 Default Setting (HKLM-x32\...\{AEACD7BE-7E12-490D-80B2-C7DEBDBD8915}) (Version: 1.0.0.8 - Hewlett-Packard)
XnView 2.24 (HKLM-x32\...\XnView_is1) (Version: 2.24 - Gougelet Pierre-e)
XnViewMP 0.69 (HKLM\...\XnViewMP_is1) (Version: 0.69 - Gougelet Pierre-e)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
10-10-2014 10:51:49 Windows Update
14-10-2014 13:39:46 Windows Update
16-10-2014 22:13:44 Windows Update
21-10-2014 05:49:30 Windows Update
21-10-2014 15:06:36 Installed Microsoft Image Composite Editor
24-10-2014 09:34:07 Windows Update
28-10-2014 22:30:16 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {028AC29A-C35F-4260-AC3A-4D1B29A5B7E8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-09-26] (Google Inc.)
Task: {2B351BA4-E87A-46E6-A4B3-D0011C386754} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: {7E060A38-ABF0-4B29-94BB-B569F1B1446A} - System32\Tasks\Microsoft\Windows\MobilePC\DisplayLink TMM Control
Task: {B17FA6EB-E59C-48CC-89EC-CF4441AE5554} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd)
Task: {C9ACBEAD-3EE9-4327-92C7-9D2FEB0BA1BB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-09-26] (Google Inc.)
Task: {DF40D6A6-8241-442C-921A-95367CAE913E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company)
Task: {E87FCC57-5033-4E3E-85A4-9A8D6AB85EC2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-21] (Adobe Systems Incorporated)
Task: {EDF78B53-D7A0-4853-8191-74F0E3535176} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-05-05 16:10 - 2014-05-05 16:10 - 00033280 _____ () C:\Program Files\Broadcom\Broadcom 802.11\WLTRYSVC.EXE
2014-09-24 22:04 - 2006-02-23 10:35 - 00020480 _____ () C:\Windows\System32\FritzColorPort64.dll
2014-09-24 22:04 - 2006-02-22 09:39 - 00020480 _____ () C:\Windows\System32\FritzPort64.dll
2014-05-07 21:02 - 2010-03-16 00:04 - 00143360 ____R () C:\Windows\system32\BrSNMP64.dll
2013-09-04 23:17 - 2013-09-04 23:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2009-07-30 16:42 - 2009-07-30 16:42 - 00173344 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll
2009-07-01 14:44 - 2009-07-01 14:44 - 00632888 _____ () C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe
2011-04-08 08:57 - 2011-04-08 08:57 - 01102336 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\System.Data.SQLite.dll
2010-03-23 12:26 - 2010-03-23 12:26 - 00201512 _____ () C:\Program Files (x86)\Cisco Systems\VPN Client\vpnapi.dll
2009-06-17 10:40 - 2009-06-17 10:40 - 02121728 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll
2009-06-17 10:40 - 2009-06-17 10:40 - 07745536 _____ () C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll
2009-06-17 10:40 - 2009-06-17 10:40 - 00135168 _____ () C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
2014-09-04 13:51 - 2014-09-04 13:51 - 00019968 _____ () C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\locale\de_de\acrotray.deu
2014-05-07 21:02 - 2009-02-27 15:38 - 00139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2011-04-08 08:57 - 2011-04-08 08:57 - 00514570 _____ () C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\sqlite3.dll
2014-10-15 15:21 - 2014-10-15 15:21 - 03649648 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-09-04 23:14 - 2013-09-04 23:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2014-10-21 10:57 - 2014-10-21 10:57 - 16832176 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SAVService => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
========================= Accounts: ==========================
Administrator (S-1-5-21-521797729-4090322044-886415676-500 - Administrator - Enabled) => C:\Users\Administrator
Gast (S-1-5-21-521797729-4090322044-886415676-501 - Limited - Disabled)
Freddy (S-1-5-21-521797729-4090322044-886415676-1000 - Administrator - Enabled) => C:\Users\Freddy
HomeGroupUser$ (S-1-5-21-521797729-4090322044-886415676-1002 - Limited - Enabled)
SophosSAUFREDDY-P0 (S-1-5-21-521797729-4090322044-886415676-1003 - Limited - Enabled)
==================== Faulty Device Manager Devices =============
Name: Cisco Systems VPN Adapter for 64-bit Windows
Description: Cisco Systems VPN Adapter for 64-bit Windows
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: CVirtA
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (11/02/2014 01:37:26 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm Acrobat.exe, Version 10.1.12.15 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: d8
Startzeit: 01cff1da448e0c67
Endzeit: 370
Anwendungspfad: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat.exe
Berichts-ID: 447bba83-6228-11e4-8953-001eece3c490
Error: (10/27/2014 09:12:25 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/26/2014 01:07:23 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/25/2014 10:07:55 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 33.0.0.5397, Zeitstempel: 0x543924b1
Name des fehlerhaften Moduls: mozalloc.dll, Version: 33.0.0.5397, Zeitstempel: 0x5438ffbb
Ausnahmecode: 0x80000003
Fehleroffset: 0x00001425
ID des fehlerhaften Prozesses: 0x22e8
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3
Error: (10/25/2014 10:07:52 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm firefox.exe, Version 33.0.0.5397 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 3bb0
Startzeit: 01cfed30a9a6337a
Endzeit: 5629
Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Berichts-ID: 555adefe-5c26-11e4-b8c2-001eece3c490
Error: (10/21/2014 10:49:20 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/19/2014 02:01:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: xnview.exe, Version: 2.24.0.0, Zeitstempel: 0x54325291
Name des fehlerhaften Moduls: xnview.exe, Version: 2.24.0.0, Zeitstempel: 0x54325291
Ausnahmecode: 0xc0000094
Fehleroffset: 0x00068366
ID des fehlerhaften Prozesses: 0x2918
Startzeit der fehlerhaften Anwendung: 0xxnview.exe0
Pfad der fehlerhaften Anwendung: xnview.exe1
Pfad des fehlerhaften Moduls: xnview.exe2
Berichtskennung: xnview.exe3
Error: (10/17/2014 08:24:49 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/17/2014 08:22:16 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/11/2014 02:24:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AsGHost.exe, Version: 3.1.1.75, Zeitstempel: 0x4a6ec1a7
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521ea8e7
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0002e3be
ID des fehlerhaften Prozesses: 0x658
Startzeit der fehlerhaften Anwendung: 0xAsGHost.exe0
Pfad der fehlerhaften Anwendung: AsGHost.exe1
Pfad des fehlerhaften Moduls: AsGHost.exe2
Berichtskennung: AsGHost.exe3
System errors:
=============
Error: (11/01/2014 03:38:50 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}
Error: (10/26/2014 02:15:32 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {53362C64-A296-4F2D-A2F8-FD984D08340B}
Error: (10/26/2014 00:11:56 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {53362C64-A296-4F2D-A2F8-FD984D08340B}
Error: (10/26/2014 00:11:51 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {7429F543-2A60-4CB7-8BC5-F27EA898FB44}
Error: (10/25/2014 09:22:07 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst HP ProtectTools Service erreicht.
Error: (10/22/2014 09:14:29 PM) (Source: bowser) (EventID: 8003) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "FRITZ-NAS",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{2CF2894D-83B0-4098-817D-0CBE940F94B6}-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.
Error: (10/21/2014 01:38:56 PM) (Source: SAVOnAccess) (EventID: 85) (User: )
Description: Der Scan von Datei [...lher\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini] wurde nach einer Zeitüberschreitung/Auslastung durchgeführt. Sie wird protokolliert. Prozess explorer.exe, (Überprüfung des Zeitstempels [ 1cfed2bfb152366]).
Error: (10/21/2014 01:38:49 PM) (Source: SAVOnAccess) (EventID: 85) (User: )
Description: Der Scan von Datei [...ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini] wurde nach einer Zeitüberschreitung/Auslastung durchgeführt. Sie wird protokolliert. Prozess explorer.exe, (Überprüfung des Zeitstempels [ 1cfed2bf695f30b]).
Error: (10/21/2014 01:38:48 PM) (Source: SAVOnAccess) (EventID: 85) (User: )
Description: Der Scan von Datei [...kVolume1\ProgramData\Microsoft\Windows\Start Menu\desktop.ini] wurde nach einer Zeitüberschreitung/Auslastung durchgeführt. Sie wird protokolliert. Prozess explorer.exe, (Überprüfung des Zeitstempels [ 1cfed2bf6261897]).
Error: (10/21/2014 01:38:38 PM) (Source: SAVOnAccess) (EventID: 85) (User: )
Description: Der Scan von Datei [...\Device\HarddiskVolume1\Users\Public\Libraries\desktop.ini] wurde nach einer Zeitüberschreitung/Auslastung durchgeführt. Sie wird protokolliert. Prozess wmpnetwk.exe, (Überprüfung des Zeitstempels [ 1cfed2befaa2669]).
Microsoft Office Sessions:
=========================
Error: (11/02/2014 01:37:26 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Acrobat.exe10.1.12.15d801cff1da448e0c67370C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat.exe447bba83-6228-11e4-8953-001eece3c490
Error: (10/27/2014 09:12:25 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/26/2014 01:07:23 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/25/2014 10:07:55 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe33.0.0.5397543924b1mozalloc.dll33.0.0.53975438ffbb800000030000142522e801cfed38576781fbC:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dll675b9819-5c26-11e4-b8c2-001eece3c490
Error: (10/25/2014 10:07:52 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: firefox.exe33.0.0.53973bb001cfed30a9a6337a5629C:\Program Files (x86)\Mozilla Firefox\firefox.exe555adefe-5c26-11e4-b8c2-001eece3c490
Error: (10/21/2014 10:49:20 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/19/2014 02:01:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: xnview.exe2.24.0.054325291xnview.exe2.24.0.054325291c000009400068366291801cfeb85101cb2eeC:\Program Files (x86)\XnView\xnview.exeC:\Program Files (x86)\XnView\xnview.exe18751aa2-5790-11e4-85cf-001eece3c490
Error: (10/17/2014 08:24:49 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/17/2014 08:22:16 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (10/11/2014 02:24:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: AsGHost.exe3.1.1.754a6ec1a7ntdll.dll6.1.7601.18247521ea8e7c00000050002e3be65801cfe2ba1c942562C:\Program Files (x86)\Hewlett-Packard\IAM\Bin\AsGHost.exeC:\Windows\SysWOW64\ntdll.dlldd05412f-5149-11e4-a58a-001eece3c490
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Duo CPU T9500 @ 2.60GHz
Percentage of memory in use: 53%
Total physical RAM: 4031.3 MB
Available physical RAM: 1869.63 MB
Total Pagefile: 8060.79 MB
Available Pagefile: 4780.1 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:177.77 GB) (Free:75.61 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (HP_RECOVERY) (Fixed) (Total:8.53 GB) (Free:0.41 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 186.3 GB) (Disk ID: B0C9B0C9)
Partition 1: (Active) - (Size=177.8 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=8.5 GB) - (Type=07 NTFS)
==================== End Of Log ============================ --- --- ---
Gmer.txt:
GMER Logfile: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-11-02 13:23:05
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 Hitachi_ rev.DC4O 186,31GB
Running: 0evy3oe4.exe; Driver: C:\Users\Freddy\AppData\Local\Temp\pwddrkow.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80002da4000 63 bytes [43, 4D, 33, 31, 05, 00, 00, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 592 fffff80002da4040 1 byte [01]
---- User code sections - GMER 2.1 ----
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\SysWOW64\ntdll.dll!KiUserExceptionDispatcher 0000000077ac0124 5 bytes JMP 00000001750a8620
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077aec4dd 5 bytes JMP 00000001750a4e10
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\SysWOW64\ntdll.dll!RtlExitUserThread 0000000077b0801c 5 bytes JMP 00000001750a4ff0
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\syswow64\kernel32.dll!CreateProcessA 0000000075c41072 5 bytes JMP 00000001750a5050
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\syswow64\kernel32.dll!GetProcAddress 0000000075c41222 5 bytes JMP 00000001750a4fd0
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\syswow64\kernel32.dll!WriteFile 0000000075c41282 5 bytes JMP 00000001750a4e70
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\syswow64\kernel32.dll!FreeLibrary 0000000075c43488 5 bytes JMP 00000001750a5240
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\syswow64\kernel32.dll!VirtualProtect 0000000075c44327 5 bytes JMP 00000001750a4ed0
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\syswow64\kernel32.dll!LoadLibraryExA 0000000075c448db 5 bytes JMP 00000001750a4f50
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\syswow64\kernel32.dll!LoadLibraryW 0000000075c448f3 5 bytes JMP 00000001750a4f10
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\syswow64\kernel32.dll!LoadLibraryExW 0000000075c44925 5 bytes JMP 00000001750a4f30
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\syswow64\kernel32.dll!LoadLibraryA 0000000075c4499f 5 bytes JMP 00000001750a4f70
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\syswow64\kernel32.dll!CreateFileA 0000000075c4538e 5 bytes JMP 00000001750a5070
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\syswow64\kernel32.dll!GlobalAlloc 0000000075c45856 5 bytes JMP 00000001750a4f90
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\syswow64\kernel32.dll!ExitProcess 0000000075c479d8 5 bytes JMP 00000001750a5010
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalA 0000000075c5a48f 5 bytes JMP 00000001750a5030
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\syswow64\kernel32.dll!WriteProcessMemory 0000000075c5d9b0 5 bytes JMP 00000001750a4e30
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\syswow64\kernel32.dll!GetThreadContext 0000000075c6799c 5 bytes JMP 00000001750a4fb0
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\syswow64\kernel32.dll!WinExec 0000000075cc2ff1 5 bytes JMP 00000001750a4e90
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\syswow64\kernel32.dll!VirtualProtectEx 0000000075cc4aff 5 bytes JMP 00000001750a4eb0
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\syswow64\kernel32.dll!WriteFileEx 0000000075cc4b2f 5 bytes JMP 00000001750a4e50
.text C:\Windows\SysWOW64\svchost.exe[756] C:\Windows\syswow64\kernel32.dll!SetThreadContext 0000000075cc58d3 5 bytes JMP 00000001750a4ef0
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\SysWOW64\ntdll.dll!KiUserExceptionDispatcher 0000000077ac0124 5 bytes JMP 00000001750a8620
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077aec4dd 5 bytes JMP 00000001750a4e10
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\SysWOW64\ntdll.dll!RtlExitUserThread 0000000077b0801c 5 bytes JMP 00000001750a4ff0
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\kernel32.dll!CreateProcessA 0000000075c41072 5 bytes JMP 00000001750a5050
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\kernel32.dll!GetProcAddress 0000000075c41222 5 bytes JMP 00000001750a4fd0
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\kernel32.dll!WriteFile 0000000075c41282 5 bytes JMP 00000001750a4e70
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\kernel32.dll!FreeLibrary 0000000075c43488 5 bytes JMP 00000001750a5240
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\kernel32.dll!VirtualProtect 0000000075c44327 5 bytes JMP 00000001750a4ed0
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\kernel32.dll!LoadLibraryExA 0000000075c448db 5 bytes JMP 00000001750a4f50
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\kernel32.dll!LoadLibraryW 0000000075c448f3 5 bytes JMP 00000001750a4f10
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\kernel32.dll!LoadLibraryExW 0000000075c44925 5 bytes JMP 00000001750a4f30
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\kernel32.dll!LoadLibraryA 0000000075c4499f 5 bytes JMP 00000001750a4f70
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\kernel32.dll!CreateFileA 0000000075c4538e 5 bytes JMP 00000001750a5070
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\kernel32.dll!GlobalAlloc 0000000075c45856 5 bytes JMP 00000001750a4f90
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\kernel32.dll!ExitProcess 0000000075c479d8 5 bytes JMP 00000001750a5010
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalA 0000000075c5a48f 5 bytes JMP 00000001750a5030
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\kernel32.dll!WriteProcessMemory 0000000075c5d9b0 5 bytes JMP 00000001750a4e30
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\kernel32.dll!GetThreadContext 0000000075c6799c 5 bytes JMP 00000001750a4fb0
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\kernel32.dll!WinExec 0000000075cc2ff1 5 bytes JMP 00000001750a4e90
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\kernel32.dll!VirtualProtectEx 0000000075cc4aff 5 bytes JMP 00000001750a4eb0
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\kernel32.dll!WriteFileEx 0000000075cc4b2f 5 bytes JMP 00000001750a4e50
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\kernel32.dll!SetThreadContext 0000000075cc58d3 5 bytes JMP 00000001750a4ef0
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075953918 5 bytes JMP 00000001750a4cf0
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\WS2_32.dll!WSAStartup 0000000075953ab2 7 bytes JMP 00000001750a4d50
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\WS2_32.dll!bind 0000000075954582 5 bytes JMP 00000001750a4d10
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\WS2_32.dll!accept 00000000759568b6 5 bytes JMP 00000001750a4d30
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\WS2_32.dll!recv 0000000075956b0e 5 bytes JMP 00000001750a4c70
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\WS2_32.dll!connect 0000000075956bdd 5 bytes JMP 00000001750a4cd0
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\WS2_32.dll!send 0000000075956f01 5 bytes JMP 00000001750a4c50
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\WS2_32.dll!getpeername 0000000075957147 5 bytes JMP 00000001750a4cb0
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\WS2_32.dll!listen 000000007595b001 5 bytes JMP 00000001750a4c90
.text C:\Windows\SysWOW64\svchost.exe[776] C:\Windows\syswow64\WS2_32.dll!WSASocketA 000000007595c82a 5 bytes JMP 00000001750a4d70
.text C:\Program Files (x86)\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe[1000] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe[1000] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[2408] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[2408] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Intel\AMT\atchksrv.exe[2496] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Intel\AMT\atchksrv.exe[2496] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe[2600] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe[2600] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe[2728] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe[2728] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe[2980] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe[2980] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe[3016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe[3016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Intel\AMT\UNS.exe[3344] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Intel\AMT\UNS.exe[3344] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Windows\Explorer.EXE[4956] C:\Windows\system32\kernel32.dll!CopyFileExW 00000000777c1890 5 bytes JMP 000000016fff00d8
.text C:\Windows\Explorer.EXE[4956] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW 000000007783f490 8 bytes JMP 000000016fff0110
.text C:\Windows\Explorer.EXE[4956] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefdea7490 11 bytes JMP 000007fffde000d8
.text C:\Program Files (x86)\Hewlett-Packard\IAM\Bin\AsGHost.exe[4176] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Hewlett-Packard\IAM\Bin\AsGHost.exe[4176] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Intel\AMT\atchk.exe[676] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Intel\AMT\atchk.exe[676] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe[3900] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe[3900] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe[4384] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe[4384] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe[732] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe[732] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe[852] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe[852] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\pthosttr.exe[1496] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\pthosttr.exe[1496] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe[4204] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe[4204] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\PSDrt.exe[3172] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\PSDrt.exe[3172] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2120] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2120] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Citrix\ICA Client\concentr.exe[5196] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Citrix\ICA Client\concentr.exe[5196] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Citrix\ICA Client\redirector.exe[5216] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Citrix\ICA Client\redirector.exe[5216] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[5300] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe[5300] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe[5432] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe[5432] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe[5468] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe[5468] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe[5540] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe[5540] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe[5600] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe[5600] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Citrix\Receiver\Receiver.exe[5912] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Citrix\Receiver\Receiver.exe[5912] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[6068] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Browny02\BrYNSvc.exe[6068] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe[6240] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Hewlett-Packard\Shared\hpqToaster.exe[6240] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe[6536] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe[6536] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe[6548] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe[6548] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[5092] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe[5092] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe[8188] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe[8188] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[5344] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[5344] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\ProgramData\FLEXnet\Connect\11\agent.exe[1704] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\ProgramData\FLEXnet\Connect\11\agent.exe[1704] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
.text C:\Users\Freddy\Desktop\0evy3oe4.exe[6108] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077661465 2 bytes [66, 77]
.text C:\Users\Freddy\Desktop\0evy3oe4.exe[6108] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000776614bb 2 bytes [66, 77]
.text ... * 2
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002186c9ec5f
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002186c9ec5f (not active ControlSet)
---- EOF - GMER 2.1 ---- --- --- --- |