Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-12-14 17:49:42
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 KINGSTON rev.507A 111,79GB
Running: Gmer-19357.exe; Driver: C:\Users\T410\AppData\Local\Temp\kxldipog.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 630 fffff800033b9066 35 bytes {MOV ECX, [RAX+0x70]; ADD RCX, 0x208; MOV RDX, RSI; CALL 0x4f7fa}
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 666 fffff800033b908a 6 bytes [8B, 94, 24, 98, 01, 00]
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe[1672] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075581401 2 bytes JMP 74f0b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe[1672] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075581419 2 bytes JMP 74f0b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe[1672] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075581431 2 bytes JMP 74f88ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe[1672] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007558144a 2 bytes CALL 74ee48ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe[1672] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000755814dd 2 bytes JMP 74f887a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe[1672] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000755814f5 2 bytes JMP 74f88978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe[1672] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007558150d 2 bytes JMP 74f88698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe[1672] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075581525 2 bytes JMP 74f88a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe[1672] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007558153d 2 bytes JMP 74effca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe[1672] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075581555 2 bytes JMP 74f068ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe[1672] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007558156d 2 bytes JMP 74f88f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe[1672] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075581585 2 bytes JMP 74f88ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe[1672] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007558159d 2 bytes JMP 74f8865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe[1672] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000755815b5 2 bytes JMP 74effd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe[1672] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000755815cd 2 bytes JMP 74f0b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe[1672] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000755816b2 2 bytes JMP 74f88e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe[1672] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000755816bd 2 bytes JMP 74f885f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe[2876] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075581401 2 bytes JMP 74f0b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe[2876] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075581419 2 bytes JMP 74f0b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe[2876] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075581431 2 bytes JMP 74f88ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe[2876] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007558144a 2 bytes CALL 74ee48ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe[2876] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000755814dd 2 bytes JMP 74f887a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe[2876] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000755814f5 2 bytes JMP 74f88978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe[2876] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007558150d 2 bytes JMP 74f88698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe[2876] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075581525 2 bytes JMP 74f88a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe[2876] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007558153d 2 bytes JMP 74effca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe[2876] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075581555 2 bytes JMP 74f068ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe[2876] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007558156d 2 bytes JMP 74f88f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe[2876] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075581585 2 bytes JMP 74f88ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe[2876] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007558159d 2 bytes JMP 74f8865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe[2876] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000755815b5 2 bytes JMP 74effd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe[2876] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000755815cd 2 bytes JMP 74f0b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe[2876] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000755816b2 2 bytes JMP 74f88e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe[2876] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000755816bd 2 bytes JMP 74f885f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe[3664] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075581401 2 bytes JMP 74f0b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe[3664] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075581419 2 bytes JMP 74f0b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe[3664] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075581431 2 bytes JMP 74f88ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe[3664] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007558144a 2 bytes CALL 74ee48ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe[3664] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000755814dd 2 bytes JMP 74f887a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe[3664] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000755814f5 2 bytes JMP 74f88978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe[3664] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007558150d 2 bytes JMP 74f88698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe[3664] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075581525 2 bytes JMP 74f88a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe[3664] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007558153d 2 bytes JMP 74effca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe[3664] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075581555 2 bytes JMP 74f068ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe[3664] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007558156d 2 bytes JMP 74f88f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe[3664] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075581585 2 bytes JMP 74f88ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe[3664] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007558159d 2 bytes JMP 74f8865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe[3664] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000755815b5 2 bytes JMP 74effd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe[3664] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000755815cd 2 bytes JMP 74f0b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe[3664] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000755816b2 2 bytes JMP 74f88e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe[3664] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000755816bd 2 bytes JMP 74f885f1 C:\Windows\syswow64\kernel32.dll
? C:\Windows\system32\mssprxy.dll [4368] entry point in ".rdata" section 0000000071c671e6
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4652] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075581401 2 bytes JMP 74f0b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4652] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075581419 2 bytes JMP 74f0b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4652] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075581431 2 bytes JMP 74f88ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4652] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007558144a 2 bytes CALL 74ee48ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4652] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000755814dd 2 bytes JMP 74f887a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4652] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000755814f5 2 bytes JMP 74f88978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4652] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007558150d 2 bytes JMP 74f88698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4652] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075581525 2 bytes JMP 74f88a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4652] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007558153d 2 bytes JMP 74effca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4652] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075581555 2 bytes JMP 74f068ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4652] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007558156d 2 bytes JMP 74f88f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4652] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075581585 2 bytes JMP 74f88ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4652] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007558159d 2 bytes JMP 74f8865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4652] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000755815b5 2 bytes JMP 74effd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4652] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000755815cd 2 bytes JMP 74f0b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4652] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000755816b2 2 bytes JMP 74f88e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4652] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000755816bd 2 bytes JMP 74f885f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe[4724] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075581401 2 bytes JMP 74f0b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe[4724] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075581419 2 bytes JMP 74f0b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe[4724] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075581431 2 bytes JMP 74f88ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe[4724] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007558144a 2 bytes CALL 74ee48ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe[4724] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000755814dd 2 bytes JMP 74f887a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe[4724] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000755814f5 2 bytes JMP 74f88978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe[4724] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007558150d 2 bytes JMP 74f88698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe[4724] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075581525 2 bytes JMP 74f88a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe[4724] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007558153d 2 bytes JMP 74effca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe[4724] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075581555 2 bytes JMP 74f068ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe[4724] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007558156d 2 bytes JMP 74f88f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe[4724] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075581585 2 bytes JMP 74f88ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe[4724] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007558159d 2 bytes JMP 74f8865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe[4724] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000755815b5 2 bytes JMP 74effd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe[4724] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000755815cd 2 bytes JMP 74f0b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe[4724] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000755816b2 2 bytes JMP 74f88e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe[4724] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000755816bd 2 bytes JMP 74f885f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE[4688] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075581401 2 bytes JMP 74f0b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE[4688] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075581419 2 bytes JMP 74f0b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE[4688] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075581431 2 bytes JMP 74f88ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE[4688] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007558144a 2 bytes CALL 74ee48ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE[4688] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000755814dd 2 bytes JMP 74f887a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE[4688] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000755814f5 2 bytes JMP 74f88978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE[4688] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007558150d 2 bytes JMP 74f88698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE[4688] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075581525 2 bytes JMP 74f88a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE[4688] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007558153d 2 bytes JMP 74effca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE[4688] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075581555 2 bytes JMP 74f068ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE[4688] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007558156d 2 bytes JMP 74f88f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE[4688] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075581585 2 bytes JMP 74f88ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE[4688] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007558159d 2 bytes JMP 74f8865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE[4688] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000755815b5 2 bytes JMP 74effd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE[4688] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000755815cd 2 bytes JMP 74f0b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE[4688] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000755816b2 2 bytes JMP 74f88e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE[4688] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000755816bd 2 bytes JMP 74f885f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4016] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075581401 2 bytes JMP 74f0b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4016] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075581419 2 bytes JMP 74f0b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075581431 2 bytes JMP 74f88ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007558144a 2 bytes CALL 74ee48ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4016] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000755814dd 2 bytes JMP 74f887a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4016] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000755814f5 2 bytes JMP 74f88978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4016] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007558150d 2 bytes JMP 74f88698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4016] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075581525 2 bytes JMP 74f88a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4016] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007558153d 2 bytes JMP 74effca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4016] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075581555 2 bytes JMP 74f068ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4016] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007558156d 2 bytes JMP 74f88f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4016] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075581585 2 bytes JMP 74f88ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4016] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007558159d 2 bytes JMP 74f8865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4016] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000755815b5 2 bytes JMP 74effd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4016] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000755815cd 2 bytes JMP 74f0b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4016] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000755816b2 2 bytes JMP 74f88e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4016] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000755816bd 2 bytes JMP 74f885f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[4236] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075581401 2 bytes JMP 74f0b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[4236] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075581419 2 bytes JMP 74f0b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[4236] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075581431 2 bytes JMP 74f88ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[4236] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007558144a 2 bytes CALL 74ee48ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[4236] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000755814dd 2 bytes JMP 74f887a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[4236] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000755814f5 2 bytes JMP 74f88978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[4236] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007558150d 2 bytes JMP 74f88698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[4236] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075581525 2 bytes JMP 74f88a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[4236] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007558153d 2 bytes JMP 74effca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[4236] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075581555 2 bytes JMP 74f068ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[4236] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007558156d 2 bytes JMP 74f88f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[4236] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075581585 2 bytes JMP 74f88ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[4236] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007558159d 2 bytes JMP 74f8865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[4236] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000755815b5 2 bytes JMP 74effd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[4236] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000755815cd 2 bytes JMP 74f0b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[4236] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000755816b2 2 bytes JMP 74f88e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[4236] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000755816bd 2 bytes JMP 74f885f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[7024] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075581401 2 bytes JMP 74f0b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[7024] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075581419 2 bytes JMP 74f0b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[7024] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075581431 2 bytes JMP 74f88ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[7024] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007558144a 2 bytes CALL 74ee48ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[7024] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000755814dd 2 bytes JMP 74f887a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[7024] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000755814f5 2 bytes JMP 74f88978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[7024] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007558150d 2 bytes JMP 74f88698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[7024] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075581525 2 bytes JMP 74f88a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[7024] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007558153d 2 bytes JMP 74effca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[7024] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075581555 2 bytes JMP 74f068ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[7024] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007558156d 2 bytes JMP 74f88f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[7024] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075581585 2 bytes JMP 74f88ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[7024] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007558159d 2 bytes JMP 74f8865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[7024] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000755815b5 2 bytes JMP 74effd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[7024] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000755815cd 2 bytes JMP 74f0b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[7024] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000755816b2 2 bytes JMP 74f88e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[7024] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000755816bd 2 bytes JMP 74f885f1 C:\Windows\syswow64\kernel32.dll
? C:\Windows\system32\mssprxy.dll [7024] entry point in ".rdata" section 0000000071c671e6
---- Processes - GMER 2.1 ----
Library c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D1591309-A600-45BD-80FD-6B455DBF56F0}\offreg.dll (*** suspicious ***) @ c:\Program Files\Microsoft Security Client\MsMpEng.exe [380](2014-12-14 16:34:11) 000007feefc60000
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\70f395443ca0
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\70f395443ca0 (not active ControlSet)
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0F46332E-83FA-824C-670A-D87CD17C2209}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0F46332E-83FA-824C-670A-D87CD17C2209}@oaloebpiagagidkiocndchldgggfnb 0x6A 0x61 0x62 0x69 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{0F46332E-83FA-824C-670A-D87CD17C2209}@pafncfajgbcaoenhicabnincmfdlbolc 0x6A 0x61 0x67 0x6B ...
---- EOF - GMER 2.1 ---- Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 14.12.2014
Suchlauf-Zeit: 17:01:39
Logdatei: SuchlaufMalwarebytes.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2014.12.14.06
Rootkit Datenbank: v2014.12.08.03
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bˆsartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: T410
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 335273
Verstrichene Zeit: 8 Min, 29 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Warnen
PUM: Aktiviert
Prozesse: 2
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\updateHoldPage.exe, 9300, Lˆschen bei Neustart, [c6014a1698e480b6888b6687b64b51af]
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\utilHoldPage.exe, 10492, Lˆschen bei Neustart, [7b4cd090eb912f075eb5a449fb066898]
Module: 0
(Keine sch‰dliche Elemente erkannt)
Registrierungsschl¸ssel: 25
PUP.Optional.HoldPage.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update Hold Page, In Quarant‰ne, [c6014a1698e480b6888b6687b64b51af],
PUP.Optional.HoldPage.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util Hold Page, In Quarant‰ne, [7b4cd090eb912f075eb5a449fb066898],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarant‰ne, [7057e57bed8f310521779c6cd330c937],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarant‰ne, [7057e57bed8f310521779c6cd330c937],
PUP.Optional.HoldPage.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6c14185e-4de6-4a79-985b-19f23fd1e638}, In Quarant‰ne, [44830f5184f895a1c35a85475ba75aa6],
PUP.Optional.HoldPage.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{180BD92C-7EC0-4CF9-9329-7CEA0405B796}, In Quarant‰ne, [44830f5184f895a1c35a85475ba75aa6],
PUP.Optional.HoldPage.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{9B0B3C08-2AC3-43AD-AC78-3DB45181A1E1}, In Quarant‰ne, [44830f5184f895a1c35a85475ba75aa6],
PUP.Optional.HoldPage.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9B0B3C08-2AC3-43AD-AC78-3DB45181A1E1}, In Quarant‰ne, [44830f5184f895a1c35a85475ba75aa6],
PUP.Optional.HoldPage.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{180BD92C-7EC0-4CF9-9329-7CEA0405B796}, In Quarant‰ne, [44830f5184f895a1c35a85475ba75aa6],
PUP.Optional.HoldPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{6C14185E-4DE6-4A79-985B-19F23FD1E638}, In Quarant‰ne, [44830f5184f895a1c35a85475ba75aa6],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{078ad437-dc9f-4228-9edb-b3d1c0246ff8}w64, In Quarant‰ne, [537472eee19bdf572e31ccfb57addb25],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{a16a1775-5ab3-4034-ac52-de0795db97f0}w64, In Quarant‰ne, [f3d45907f38988ae95ca9f28f90ba858],
PUP.Optional.HoldPage.A, HKLM\SOFTWARE\WOW6432NODE\Hold Page, In Quarant‰ne, [2b9cfa661f5d152110325003f211b749],
PUP.Optional.HoldPage.A, HKU\S-1-5-21-331670129-925724647-3591002109-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Hold Page, In Quarant‰ne, [50776df3443878be5be6b69d8083be42],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-331670129-925724647-3591002109-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarant‰ne, [60677ae66a12b680c7d2c9c89b687a86],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-331670129-925724647-3591002109-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarant‰ne, [7f48035d502c68ce3089c7e05ba9c13f],
PUP.Optional.HoldPage.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Hold Page, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, HKLM\SOFTWARE\CLASSES\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
Registrierungswerte: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-331670129-925724647-3591002109-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0Z1B1L2Z1S, In Quarant‰ne, [7f48035d502c68ce3089c7e05ba9c13f]
Registrierungsdaten: 0
(Keine sch‰dliche Elemente erkannt)
Ordner: 4
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page, Lˆschen bei Neustart, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin, Lˆschen bei Neustart, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\plugins, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\TEMP, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
Dateien: 45
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{078ad437-dc9f-4228-9edb-b3d1c0246ff8}w64.sys, Lˆschen bei Neustart, [b49db9da7a65199172eb26b132e44724],
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{a16a1775-5ab3-4034-ac52-de0795db97f0}w64.sys, Lˆschen bei Neustart, [d396e94150e7d024d208db637d2766bd],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\updateHoldPage.exe, Lˆschen bei Neustart, [c6014a1698e480b6888b6687b64b51af],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\utilHoldPage.exe, Lˆschen bei Neustart, [7b4cd090eb912f075eb5a449fb066898],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\HoldPagebho.dll, In Quarant‰ne, [44830f5184f895a1c35a85475ba75aa6],
PUP.Optional.InstallCore, C:\Users\T410\Downloads\FileZilla_3.9.0.6_win32-setup.exe, In Quarant‰ne, [27a0550bd7a5a49297f351102ed741bf],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\0, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\HoldPage.ico, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\HoldPageUninstall.exe, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\ljbbmbgagpjnafekbkklmfbjccbnjmnh.crx, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\updateHoldPage.InstallState, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\7za.exe, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\tmp3965.tmp, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\078ad437dc9f42289edb.dll, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\078ad437dc9f42289edb64.dll, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\a16a17755ab34034ac52.dll, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\a16a17755ab34034ac5264.dll, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\BrowserAdapter.7z, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\HoldPage.BrowserAdapter.exe, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\HoldPage.BrowserAdapter64.exe, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\HoldPage.expext.exe, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\HoldPage.expext.zip, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\HoldPage.expextdll.dll, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\HoldPage.PurBrowse.zip, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\HoldPage.PurBrowse64.exe, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\sqlite3.dll, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\tmp1893.tmp, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\tmp6A85.tmp, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\tmp98C0.tmp, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\tmpA453.tmp, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\tmpEB3F.tmp, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\utilHoldPage.InstallState, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\{078ad437-dc9f-4228-9edb-b3d1c0246ff8}.dll, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\{078ad437-dc9f-4228-9edb-b3d1c0246ff8}64.dll, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\{a16a1775-5ab3-4034-ac52-de0795db97f0}.dll, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\{a16a1775-5ab3-4034-ac52-de0795db97f0}64.dll, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\plugins\HoldPage.Bromon.dll, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\plugins\HoldPage.BroStats.dll, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\plugins\HoldPage.BrowserAdapter.dll, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\plugins\HoldPage.CompatibilityChecker.dll, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\plugins\HoldPage.ExpExt.dll, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\plugins\HoldPage.FFUpdate.dll, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\plugins\HoldPage.GCUpdate.dll, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\plugins\HoldPage.IEUpdate.dll, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
PUP.Optional.HoldPage.A, C:\Program Files (x86)\Hold Page\bin\plugins\HoldPage.PurBrowse.dll, In Quarant‰ne, [67603030f28af640a1c4113a61a2a25e],
Physische Sektoren: 0
(Keine sch‰dliche Elemente erkannt)
(end)
Mittlerweile beim starten: "CHKDSK überprüft dateien...." und ""CHKDSK überprüft Sicherheitserkennung..."
Danach ist mein Desktop schwarz (sehe nur noch die Maus) Explorer wurde wahrscheinlich deaktiviert
=> explorer.exe => "Die Anwendung konnte nicht korrekt gestartet werden (0xc0000022)
klicken sie ok um die Anwendung zu schliessen." |