Cellschock | 01.02.2015 10:58 | Windows Vista - Internet wird lahmgelegt, sobald sich Windows 7 Pc in den Router wählt Liste der Anhänge anzeigen (Anzahl: 1) Hallo,
erstmal finde ich es toll, dass es so ein Forum gibt. Vielen Dank schon mal für die Hilfe!
Das Problem fing bereits vor einem Jahr an. Mein Hauptrechner (Windows 7) machte faxen. Sobald er ins Internet ging, wurde das komplette Internet lahmgelegt. Jedoch nicht nur an diesem Rechner, sondern auch an allen anderen von meinen Geräten (Tablet, Handy, Notebook).
Dann hab ich was Dummes gemacht und Registry Einträge gelöscht, obwohl ich davon eigentlich keine Ahnung habe. Als nichts mehr so richtig funktionierte, habe ich dann nacheinander Laufwerke des Rechners formatiert und Antivirenscans durchgeführt. Wobei ich mir nicht ganz sicher bin, ob ich das richtig gemacht habe. Hatte keine Recovery DVD, sondern nur ne ganz normale WIN7 Version, die ich mir mal bei Fritz bestellt hatte.
Zu allem Übel funktionierte der PC nie wieder richtig und plötzlich wurde mir auch angezeigt, dass ich keine Original Windows Version hätte. Und gerade an dem Punkt bin ich mir unsicher. Das kann nämlich tatsächlich sein, da diese Firma Fritz oder Hardware-Fritz oder so ähnlich, damals sogar in den Medien war und beschuldigt wurde, illegale Kopien von Microsoft verkauft zu haben. Mein Internet ging jedenfalls wieder, wenn auch mehr schlecht als recht und obwohl mein Bildschirmschoner immer wieder auf einen schwarzen Bildschirm umgestellt wurde (Virus oder weil ich die Originalversion nicht habe?), war das ok für mich.
Jetzt bin ich umgezogen, habe zwei neue WG-Mitbewohnerinnen und als ich mich mit dem besagten PC in den Router eingeloggt habe, gingen plötzlich wieder keine Geräte mehr. Ich habe den Rechner sofort vom Internet genommen und siehe, da...die Mädels meinen es funktioniert wieder alles. Ich habe ein wenig Angst, dass ich da jetzt ein Virus auf den Router übertragen haben könnte. Also mein Tablet läuft immer noch recht langsam, wobei auch 3 Wände bis zum Router verlaufen. Könnte also auch die Entfernung sein. Das Routerpasswort ist das standardmäßig eingestellte...was ja eigentlich auch nicht so gut ist, gerade wenn man evtl einen Virus drauf hat.
Ich poste jetzt hier die Log-Files meines Notebooks mit Windows Vista...soll ich die Log-Files auch von meinem verursachendem Rechner posten? Ist das notwendig? Wollte ihn nämlich eh nicht mehr ins Internet lassen und komplett formatieren mit einer neuen Windows 7 DVD. Normalerweise müsste dann dort doch auch alles runtergelöscht sein (auch Viren usw oder?).
Und jetzt für mich die wichtigste und unangenehmste Angelegenheit: Ist es möglich, dass der Virus, den mein PC auf den Router übertragen haben könnte, wiederum auf die Rechner meiner Mitbewohnerinen übergeht? Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 10:01 on 01/02/2015 (admin)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-
---------------------------
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-02-2015
Ran by admin (administrator) on USER-PC on 01-02-2015 10:03:07
Running from C:\Users\admin\Desktop\Antivirus
Loaded Profiles: admin (Available profiles: admin & user)
Platform: Microsoft® Windows Vista™ Business Service Pack 2 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Dell Inc.) C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE
(Dell Inc.) C:\Program Files\Dell\DW WLAN Card\BCMWLTRY.EXE
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Dell Inc.) C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE
(Elaborate Bytes AG) C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
() C:\Program Files\Lexmark S800 Series\lxefmon.exe
() C:\Program Files\Lexmark S800 Series\ezprint.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(SlySoft, Inc.) C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Akamai Technologies, Inc.) C:\Users\admin\AppData\Local\Akamai\netsession_win.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
( ) C:\Windows\System32\lxefcoms.exe
(Akamai Technologies, Inc.) C:\Users\admin\AppData\Local\Akamai\netsession_win.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(AceBIT GmbH) C:\Program Files\AceBIT\Password Depot 7\PasswordDepot.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation)
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [5955072 2011-01-18] (Dell Inc.)
HKLM\...\Run: [AnyProtect Scanner] => "C:\Program Files\AnyProtectEx\AnyProtect.exe"
HKLM\...\Run: [VirtualCloneDrive] => C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-09-11] (AVAST Software)
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [lxefmon.exe] => C:\Program Files\Lexmark S800 Series\lxefmon.exe [715368 2013-01-23] ()
HKLM\...\Run: [EzPrint] => C:\Program Files\Lexmark S800 Series\ezprint.exe [150272 2013-01-23] ()
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
HKLM\...\Run: [CloneCDTray] => C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-29] (SlySoft, Inc.)
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-2596615060-55448930-4252937802-1000\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-2596615060-55448930-4252937802-1000\...\Run: [Akamai NetSession Interface] => C:\Users\admin\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-29] (Akamai Technologies, Inc.)
HKU\S-1-5-21-2596615060-55448930-4252937802-1000\...\Run: [Password Depot] => C:\Program Files\AceBIT\Password Depot 7\PasswordDepot.exe [12274336 2014-07-31] (AceBIT GmbH)
HKU\S-1-5-21-2596615060-55448930-4252937802-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-2596615060-55448930-4252937802-1000\...\MountPoints2: {be5c1451-1f8e-11e4-863c-904ce51b9a26} - G:\LGAutoRun.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
AutoConfigURL: [S-1-5-21-2596615060-55448930-4252937802-1000] => httP://gate-03.network.hs-anhalt/proxy.pac
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1405815776&from=cor&uid=ST9160412ASG_5VG24J1DXXXX5VG24J1D&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1405815776&from=cor&uid=ST9160412ASG_5VG24J1DXXXX5VG24J1D&q={searchTerms}
HKU\S-1-5-21-2596615060-55448930-4252937802-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?publisher=YahooTU&dpid=YahooTU&co=DE&userid=c973019d-b8c5-4084-b4fc-2dc10698f54a&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp18000
HKU\S-1-5-21-2596615060-55448930-4252937802-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2596615060-55448930-4252937802-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.helperbar.com/?publisher=YahooTU&dpid=YahooTU&co=DE&userid=c973019d-b8c5-4084-b4fc-2dc10698f54a&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp18000
SearchScopes: HKU\S-1-5-21-2596615060-55448930-4252937802-1000 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooTU&dpid=YahooTU&co=DE&userid=c973019d-b8c5-4084-b4fc-2dc10698f54a&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp18000
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Password Depot 7 -> {9F79B165-70F7-4C46-B1A5-8828E2FF21F9} -> C:\Program Files\AceBIT\Password Depot 7\pdIEAddOn32.dll (AceBIT)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
BHO: No Name -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> No File
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ze5vckjl.default
FF DefaultSearchEngine: Google (avast)
FF DefaultSearchUrl: https://www.google.com/search/?trackid=sp-006
FF SearchEngineOrder.1: Google (avast)
FF SelectedSearchEngine: Google (avast)
FF Homepage: https://www.google.com/?trackid=sp-006
FF Keyword.URL: https://www.google.com/search/?trackid=sp-006
FF NetworkProxy: "autoconfig_url", "hxxp://gate-03.network.hs-anhalt.de/proxy.pac"
FF NetworkProxy: "type", 2
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ze5vckjl.default\searchplugins\google-avast.xml
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-01-17]
FF HKLM\...\Firefox\Extensions: [passworddepot@acebit.com] - C:\Program Files\AceBIT\Password Depot 7\Firefox
FF Extension: Password Depot Extension - C:\Program Files\AceBIT\Password Depot 7\Firefox [2014-08-18]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-09-11]
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-10-08]
FF HKU\S-1-5-21-2596615060-55448930-4252937802-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
Chrome:
=======
CHR DefaultSuggestURL: Default -> hxxp://ssmsp.ask.com/query?sstype=prefix&li=ff&q={searchTerms}
CHR Profile: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-07-20]
CHR Extension: (Google Drive) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-07-20]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-10-20]
CHR Extension: (YouTube) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-20]
CHR Extension: (Adblock Plus) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-07-20]
CHR Extension: (Google-Suche) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-20]
CHR Extension: (Avast Online Security) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-09-11]
CHR Extension: (Password Depot Add-On) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcgmdbhgeplifgopfnmafmhfmoekiekn [2014-08-05]
CHR Extension: (Google Wallet) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-20]
CHR Extension: (Bitdefender QuickScan) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie [2014-08-17]
CHR Extension: (Google Mail) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-20]
CHR HKLM\...\Chrome\Extension: [aaaaaiabcopkplhgaedhbloeejhhankf] - C:\ProgramData\AskPartnerNetwork\Toolbar\Shared\CRX\aaaaaiabcopkplhgaedhbloeejhhankf.crx [2014-11-24]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-09-11]
CHR HKLM\...\Chrome\Extension: [mcgmdbhgeplifgopfnmafmhfmoekiekn] - C:\Program Files\AceBIT\Password Depot 7\crx.crx [2014-08-18]
CHR HKLM\...\Chrome\Extension: [ocbnpbkmjpgbdcgiflkgkpnkinifpgpj] - C:\Users\admin\ChromeExtensions\ocbnpbkmjpgbdcgiflkgkpnkinifpgpj\amazon-icon-2.crx [2014-08-08]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-09-11] (AVAST Software)
S2 lxefCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxefserv.exe [189096 2010-09-09] (Lexmark International, Inc.)
R2 lxef_device; C:\Windows\system32\lxefcoms.exe [598696 2010-09-09] ( )
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2009-05-14] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2009-05-14] (Hewlett-Packard) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)
R2 wltrysvc; C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe [5210112 2011-01-18] (Dell Inc.) [File not signed]
S2 APNMCP; "C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-09-11] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-09-11] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [55112 2014-09-11] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-09-11] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [779536 2014-11-22] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [414520 2014-09-11] (AVAST Software)
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57800 2014-09-11] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [192352 2014-09-11] ()
R3 BCM42RLY; C:\Windows\System32\drivers\BCM42RLY.sys [18496 2011-01-18] (Broadcom Corporation)
R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [34760 2007-02-16] (SlySoft, Inc.)
R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [30616 2013-03-04] (Elaborate Bytes AG)
R0 fsbts; C:\Windows\System32\Drivers\fsbts.sys [44240 2015-02-01] ()
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-01 10:03 - 2015-02-01 10:03 - 00000000 ____D () C:\FRST
2015-02-01 10:01 - 2015-02-01 10:01 - 00000000 _____ () C:\Users\admin\defogger_reenable
2015-02-01 09:59 - 2015-02-01 10:03 - 00000000 ____D () C:\Users\admin\Desktop\Antivirus
2015-02-01 00:47 - 2015-02-01 00:47 - 00044240 _____ () C:\Windows\system32\Drivers\fsbts.sys
2015-02-01 00:36 - 2015-02-01 00:36 - 00002317 _____ () C:\Users\admin\Desktop\Windows 7 USB DVD Download Tool.lnk
2015-02-01 00:36 - 2015-02-01 00:36 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool
2015-02-01 00:36 - 2015-02-01 00:36 - 00000000 ____D () C:\Users\admin\AppData\Local\Apps\Windows 7 USB DVD Download Tool
2015-02-01 00:35 - 2015-02-01 00:35 - 175000563 _____ () C:\Users\admin\Downloads\X17-59885.iso.crdownload
2015-02-01 00:34 - 2015-02-01 00:34 - 02721168 _____ (Microsoft Corporation) C:\Users\admin\Downloads\Windows7-USB-DVD1024-tool.exe
2015-02-01 00:22 - 2015-02-01 00:22 - 00000000 ____D () C:\ProgramData\F-Secure
2015-02-01 00:16 - 2015-02-01 00:20 - 05176232 _____ (F-Secure Corporation) C:\Users\admin\Downloads\F-SecureOnlineScanner.exe
2015-01-16 23:06 - 2015-01-16 23:06 - 00000000 ____D () C:\ProgramData\WindowsSearch
2015-01-16 22:10 - 2015-01-16 22:10 - 00000000 ____D () C:\Windows\system32\X86
2015-01-16 22:10 - 2015-01-16 22:10 - 00000000 ____D () C:\Windows\system32\AMD64
2015-01-16 22:10 - 2015-01-16 22:10 - 00000000 ____D () C:\Program Files\EZDownloader
2015-01-16 22:09 - 2015-01-16 22:09 - 00000000 ____D () C:\Program Files\youtubeadblocker
2015-01-16 22:09 - 2015-01-16 22:09 - 00000000 ____D () C:\Program Files\User Agent Switcher
2015-01-16 22:09 - 2015-01-16 22:09 - 00000000 ____D () C:\Program Files\unaisales
2015-01-16 22:08 - 2015-01-16 22:08 - 00000000 ____D () C:\Program Files\unisaaleoS
2015-01-16 22:07 - 2015-01-16 22:07 - 00000000 ____D () C:\ProgramData\jobcoaaahncbpmlbjligbdccnogkefol
2015-01-16 22:06 - 2015-01-16 22:06 - 00000000 ____D () C:\ProgramData\{1e804cbe-bd44-9afd-1e80-04cbebd432fa}
2015-01-16 22:06 - 2015-01-16 22:06 - 00000000 ____D () C:\Program Files\WinRAR
2015-01-16 21:18 - 2015-01-16 21:31 - 00000006 _____ () C:\ScrubRetValFile.txt
2015-01-15 23:05 - 2015-01-15 23:05 - 00251954 _____ () C:\Users\admin\Downloads\Spektren (2).xlsx
2015-01-15 22:55 - 2015-01-16 02:26 - 00252029 _____ () C:\Users\admin\Downloads\Spektren (1).xlsx
2015-01-15 14:11 - 2015-01-15 14:11 - 00000000 ____D () C:\Users\user.user-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP
2015-01-15 10:24 - 2014-12-19 01:25 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-15 10:10 - 2014-12-06 04:14 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-15 10:10 - 2014-12-06 04:14 - 00153600 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-15 10:10 - 2014-12-06 04:14 - 00093184 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-01-15 10:10 - 2014-12-06 04:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-01-14 23:39 - 2015-01-14 23:39 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-01-13 23:15 - 2015-01-13 23:20 - 150363880 _____ () C:\Users\admin\Downloads\DJ_AIO_06_F4500_USW_Full_Win_WW_140_175-4 (1).exe
2015-01-13 22:45 - 2015-01-13 22:57 - 150363880 _____ () C:\Users\admin\Downloads\DJ_AIO_06_F4500_USW_Full_Win_WW_140_175-4.exe
2015-01-13 20:32 - 2015-01-13 20:34 - 00000000 ____D () C:\Users\admin\Desktop\Turtles
2015-01-11 10:11 - 2015-01-11 10:11 - 00000000 ____D () C:\ProgramData\Canneverbe Limited
2015-01-11 10:10 - 2015-01-11 10:10 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Canneverbe Limited
2015-01-11 10:09 - 2015-01-11 10:09 - 05409016 _____ (Canneverbe Limited ) C:\Users\admin\Downloads\cdbxp_setup_4.5.4.5306_minimal.exe
2015-01-11 10:09 - 2015-01-11 10:09 - 05409016 _____ (Canneverbe Limited ) C:\Users\admin\Downloads\cdbxp_setup_4.5.4.5306_minimal (1).exe
2015-01-11 10:02 - 2015-01-11 10:22 - 00000000 ____D () C:\Users\admin\Documents\Nero Burning Rom
2015-01-11 09:58 - 2015-01-11 09:58 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Nero
2015-01-10 15:34 - 2015-01-10 15:34 - 00000072 _____ () C:\Windows\7889428C51A50091.log
2015-01-10 11:54 - 2015-01-15 10:39 - 00000000 ____D () C:\ProgramData\Nero
2015-01-10 11:49 - 2015-01-10 11:50 - 85828344 _____ (Nero AG) C:\Users\admin\Downloads\Nero_BurningROM2015_setup-16.0.02000_3p_trial.exe
2015-01-10 11:45 - 2015-01-10 11:45 - 05185720 _____ () C:\Users\admin\Downloads\SetupCloneDVD2_CB-DL-Manager [1].exe
2015-01-10 11:45 - 2015-01-10 11:45 - 00823792 _____ ( ) C:\Users\admin\Downloads\SetupCloneDVD2_CB-DL-Manager.exe
2015-01-10 11:45 - 2015-01-10 11:45 - 00000000 ____D () C:\Users\admin\AppData\Local\Pirates
2015-01-10 11:26 - 2015-01-10 11:33 - 648366432 _____ () C:\Users\admin\Desktop\IMAGE.img
2015-01-10 11:26 - 2015-01-10 11:33 - 26463936 _____ () C:\Users\admin\Desktop\IMAGE.sub
2015-01-10 11:26 - 2015-01-10 11:33 - 00002452 _____ () C:\Users\admin\Desktop\IMAGE.ccd
2015-01-10 11:21 - 2015-01-10 11:49 - 00000126 ___SH () C:\ProgramData\.zreglib
2015-01-10 11:21 - 2015-01-10 11:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlySoft
2015-01-10 11:21 - 2015-01-10 11:21 - 00000000 ____D () C:\Program Files\SlySoft
2015-01-10 11:19 - 2015-01-10 11:19 - 02734688 _____ () C:\Users\admin\Downloads\SetupCloneCD5314.exe
2015-01-09 18:27 - 2015-01-09 18:27 - 00000000 ____D () C:\BIING!
2015-01-09 18:19 - 2015-01-09 18:19 - 00000000 ____D () C:\Users\admin\AppData\Local\WinZip
2015-01-09 18:18 - 2015-01-09 18:19 - 00000000 ____D () C:\ProgramData\WinZip
2015-01-09 18:17 - 2015-01-09 18:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
2015-01-09 18:17 - 2015-01-09 18:18 - 00000000 ____D () C:\Program Files\WinZip
2015-01-09 18:15 - 2015-01-09 18:16 - 60529152 _____ () C:\Users\admin\Downloads\wz190gev-32.msi
2015-01-09 18:13 - 2015-01-09 18:25 - 00000000 ____D () C:\Biing
2015-01-08 17:34 - 2015-01-08 17:34 - 00008590 _____ () C:\Users\admin\Downloads\winmail.dat
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-01 10:01 - 2014-03-28 15:23 - 00000000 ____D () C:\Users\admin
2015-02-01 09:50 - 2008-01-21 02:39 - 01840225 _____ () C:\Windows\WindowsUpdate.log
2015-02-01 09:40 - 2014-07-20 01:12 - 00002224 _____ () C:\Windows\Tasks\44f0d4e0-73bd-4bc1-a0b9-50e135daab47-4.job
2015-02-01 09:40 - 2014-07-20 01:12 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-01 09:40 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-01 09:40 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-01 09:40 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-01 01:04 - 2006-11-02 14:01 - 00032514 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-02-01 00:26 - 2014-07-20 01:12 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-27 09:36 - 2014-07-20 03:11 - 00001963 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-01-27 09:33 - 2014-08-08 19:49 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-01-26 17:29 - 2014-10-08 18:13 - 00000000 ____D () C:\Users\admin\AppData\Roaming\HpUpdate
2015-01-26 17:16 - 2006-11-02 11:33 - 01565124 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-01-26 17:14 - 2006-11-02 13:52 - 00116742 _____ () C:\Windows\setupact.log
2015-01-21 18:23 - 2014-11-29 11:28 - 00000000 ____D () C:\Users\admin\Desktop\Uni
2015-01-18 12:03 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-01-17 12:07 - 2014-08-18 10:07 - 00000000 ____D () C:\Users\admin\Documents\Password Depot
2015-01-17 01:49 - 2014-09-23 16:42 - 18356934 _____ () C:\Users\admin\Downloads\s25rttr_20140724-9484_windows.i386.tar.bz2
2015-01-17 01:49 - 2014-09-23 16:40 - 17321176 _____ () C:\Users\admin\Downloads\s25rttr_0.8.1-9016_windows.i386.tar.bz2
2015-01-17 00:27 - 2014-07-20 01:23 - 00000000 ____D () C:\ProgramData\IePluginServices
2015-01-16 23:14 - 2014-08-08 17:09 - 00000000 ____D () C:\ProgramData\KMSAutoS
2015-01-16 23:14 - 2014-08-08 17:00 - 00008240 _____ () C:\Windows\certutil.log
2015-01-16 22:37 - 2014-09-11 07:07 - 00001873 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2015-01-16 22:34 - 2014-03-28 15:24 - 00107216 _____ () C:\Users\admin\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-16 22:32 - 2014-08-08 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2015-01-16 22:32 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\Msdtc
2015-01-16 22:31 - 2014-08-08 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
2015-01-16 22:31 - 2014-08-08 19:49 - 00000000 __RHD () C:\MSOCache
2015-01-16 22:31 - 2014-08-08 19:49 - 00000000 ____D () C:\Program Files\Microsoft Office
2015-01-16 22:31 - 2014-08-08 15:04 - 00000000 ____D () C:\Users\admin\AppData\Local\Akamai
2015-01-16 22:31 - 2014-07-20 10:05 - 00000000 ____D () C:\Users\user.user-PC
2015-01-16 22:31 - 2006-11-02 13:37 - 00000000 ____D () C:\Windows\ShellNew
2015-01-16 22:31 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\spool
2015-01-16 22:31 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\registration
2015-01-16 22:31 - 2006-11-02 12:18 - 00000000 ____D () C:\Program Files\Common Files\System
2015-01-16 22:31 - 2006-11-02 12:18 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2015-01-16 22:31 - 2006-11-02 11:22 - 48234496 _____ () C:\Windows\system32\config\software_previous
2015-01-16 22:31 - 2006-11-02 11:22 - 38273024 _____ () C:\Windows\system32\config\components_previous
2015-01-16 22:31 - 2006-11-02 11:22 - 30932992 _____ () C:\Windows\system32\config\system_previous
2015-01-16 22:31 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\security_previous
2015-01-16 22:31 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\sam_previous
2015-01-16 22:31 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\default_previous
2015-01-16 22:11 - 2014-08-17 18:16 - 00000000 ____D () C:\Users\admin\AppData\Roaming\QuickScan
2015-01-16 21:25 - 2014-08-07 08:23 - 00000000 ____D () C:\ProgramData\Microsoft Toolkit
2015-01-16 21:22 - 2014-08-08 19:52 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 8
2015-01-16 17:06 - 2014-10-14 10:45 - 00000000 ____D () C:\Users\admin\AppData\Local\Apple Computer
2015-01-16 07:38 - 2014-11-20 11:53 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-01-15 14:10 - 2014-07-20 10:06 - 00107216 _____ () C:\Users\user.user-PC\AppData\Local\GDIPFONTCACHEV1.DAT
2015-01-15 10:32 - 2014-07-20 00:29 - 00000000 ____D () C:\ProgramData\Package Cache
2015-01-15 10:24 - 2014-08-14 22:59 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-15 10:11 - 2006-11-02 11:24 - 110348472 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-01-14 11:22 - 2014-10-19 16:54 - 00000000 ____D () C:\ProgramData\Lx_cats
2015-01-13 23:53 - 2014-07-20 01:17 - 00000000 ____D () C:\Users\admin\Documents\Eigene Scans
2015-01-13 23:25 - 2014-07-20 01:07 - 00230583 _____ () C:\Windows\hpoins46.dat
2015-01-13 23:25 - 2014-07-20 01:07 - 00002447 _____ () C:\ProgramData\hpzinstall.log
2015-01-12 12:45 - 2014-08-08 16:00 - 00000000 ____D () C:\Users\admin\Desktop\Sonstiges
2015-01-10 18:25 - 2006-11-02 14:00 - 00238336 _____ () C:\Windows\PFRO.log
2015-01-10 11:50 - 2014-08-08 19:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes
2015-01-10 11:50 - 2014-08-08 19:22 - 00000000 ____D () C:\Program Files\Elaborate Bytes
2015-01-07 23:12 - 2014-08-16 20:11 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP
2015-01-06 04:36 - 2014-07-20 01:14 - 00249488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-01-05 12:51 - 2014-08-08 19:49 - 00000000 ____D () C:\Users\admin\AppData\Local\Microsoft Help
2015-01-04 22:53 - 2014-12-28 20:12 - 00000000 ____D () C:\starcraft
==================== Files in the root of some directories =======
2014-07-20 01:22 - 2014-07-16 14:41 - 0573339 _____ (ClickMeIn Limited) C:\Users\admin\AppData\Local\AnyProtectScannerSetup.exe
2014-07-20 01:54 - 2014-07-20 01:54 - 2580480 _____ () C:\Users\admin\AppData\Local\bpckxdre.exe
2014-03-28 15:24 - 2014-03-28 15:28 - 0000680 _____ () C:\Users\admin\AppData\Local\d3d9caps.dat
2014-11-24 20:18 - 2014-12-28 19:49 - 0013312 _____ () C:\Users\admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-01-10 11:21 - 2015-01-10 11:49 - 0000126 ___SH () C:\ProgramData\.zreglib
2014-10-19 16:55 - 2014-10-19 16:55 - 0000252 _____ () C:\ProgramData\FastPics.log
2014-07-20 01:07 - 2015-01-13 23:25 - 0002447 _____ () C:\ProgramData\hpzinstall.log
2014-10-19 16:49 - 2014-10-19 16:49 - 0000000 _____ () C:\ProgramData\UpdaterLog.txt
Some content of TEMP:
====================
C:\Users\admin\AppData\Local\Temp\amazonicon_v8.exe
C:\Users\admin\AppData\Local\Temp\amazoninstallernircmdc.exe
C:\Users\admin\AppData\Local\Temp\APNSetup.exe
C:\Users\admin\AppData\Local\Temp\avgnt.exe
C:\Users\admin\AppData\Local\Temp\bitool.dll
C:\Users\admin\AppData\Local\Temp\FP_AX_MSI_INSTALLER.exe
C:\Users\admin\AppData\Local\Temp\FreeWebMVideoConverter.exe
C:\Users\admin\AppData\Local\Temp\PidGenX.dll
C:\Users\admin\AppData\Local\Temp\sdanircmdc.exe
C:\Users\admin\AppData\Local\Temp\sdapskill.exe
C:\Users\admin\AppData\Local\Temp\sdaspwn.exe
C:\Users\admin\AppData\Local\Temp\uninst.exe
C:\Users\admin\AppData\Local\Temp\{05C319F9-4634-4C79-977F-29DE30EA5283}-36.0.1985.125_chrome_installer.exe
C:\Users\user.user-PC\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-01 09:46
==================== End Of Log ============================ --- --- ---
--- --- ---
-------------------------------------------- Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 01-02-2015
Ran by admin at 2015-02-01 10:04:58
Running from C:\Users\admin\Desktop\Antivirus
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
32 Bit HP CIO Components Installer (Version: 6.1.2 - Hewlett-Packard) Hidden
7-Zip 9.20 (HKLM\...\7-Zip) (Version: - )
Adobe Reader X (10.1.12) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.12 - Adobe Systems Incorporated)
Akamai NetSession Interface (HKU\S-1-5-21-2596615060-55448930-4252937802-1000\...\Akamai) (Version: - Akamai Technologies, Inc)
Apple Application Support (HKLM\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
avast! Free Antivirus (HKLM\...\Avast) (Version: 9.0.2021 - AVAST Software)
Blender (HKLM\...\Blender) (Version: 2.71 - Blender Foundation)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
BufferChm (Version: 140.0.212.000 - Hewlett-Packard) Hidden
Capitalism II (remove only) (HKLM\...\Capitalism II) (Version: - )
Chaos Overlords (HKLM\...\GOGPACKCHAOSOVERLORDS_is1) (Version: 2.1.0.17 - GOG.com)
chaosoverlords (HKLM\...\{16bdccc0-b956-42de-a044-27446f036f99}.sdb) (Version: - )
Cisco EAP-FAST Module (Version: 2.2.14 - Cisco Systems, Inc.) Hidden
Cisco LEAP Module (Version: 1.0.19 - Cisco Systems, Inc.) Hidden
Cisco PEAP Module (Version: 1.1.6 - Cisco Systems, Inc.) Hidden
CloneCD (HKLM\...\CloneCD) (Version: - SlySoft)
Copy (Version: 140.0.212.000 - Hewlett-Packard) Hidden
DeviceDiscovery (Version: 140.0.212.000 - Hewlett-Packard) Hidden
D-Fend Reloaded 1.4.2 (deinstallieren) (HKLM\...\D-Fend Reloaded) (Version: 1.4.2 - Alexander Herzog)
DJ_AIO_06_F4500_SW_MIN (Version: 140.0.690.000 - Hewlett-Packard) Hidden
DW WLAN Card Utility (HKLM\...\DW WLAN Card Utility) (Version: 5.100.235.13 - Dell Inc.)
Edna Bricht Aus 6.3 (HKLM\...\{0D00CD3F-AEDC-45F1-A2DD-DADF74407D7B}_is1) (Version: - )
Europäisches Arzneibuch (HKLM\...\Deutscher Apotheker Verlag_Arzneibuch_D) (Version: - Deutscher Apotheker Verlag)
Europäisches Arzneibuch 7 (HKLM\...\Deutscher Apotheker Verlag_Arzneibuch7_D_isbn_978_3_7692_5416_7_D) (Version: - Deutscher Apotheker Verlag)
F4500 (Version: 140.0.690.000 - Hewlett-Packard) Hidden
FTL version 1.5.13 (HKLM\...\{20E23A40-38E5-4DD6-B738-BC8097AE66B6}_is1) (Version: 1.5.13 - Subset Games)
Google Chrome (HKLM\...\Google Chrome) (Version: 40.0.2214.93 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
GPBaseService2 (Version: 140.0.211.000 - Hewlett-Packard) Hidden
Hotline Miami version v1.0 (HKLM\...\{BA30996C-FB03-4395-BB50-727008597E5B}_is1) (Version: v1.0 - )
HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP)
HP Deskjet F4500 All-in-One Driver Software 14.0 Rel. 6 (HKLM\...\{0AFFEA39-60AF-4C4F-BB47-4A1F7CB12129}) (Version: 14.0 - HP)
HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP)
HP Print Projects 1.0 (HKLM\...\HP Print Projects) (Version: 1.0 - HP)
HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP)
HP Update (HKLM\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
hpPrintProjects (Version: 130.0.303.000 - Hewlett-Packard) Hidden
HPProductAssistant (Version: 140.0.212.000 - Hewlett-Packard) Hidden
HPSSupply (Version: 130.0.371.000 - Hewlett-Packard) Hidden
hpWLPGInstaller (Version: 130.0.303.000 - Hewlett-Packard) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2555 - Intel Corporation)
Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 14.5 - Intel)
iTunes (HKLM\...\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.)
Java 8 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Lexmark S800 Series (HKLM\...\Lexmark S800 Series) (Version: - Lexmark International, Inc.)
MarketResearch (Version: 140.0.212.000 - Hewlett-Packard) Hidden
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mozilla Firefox 34.0.5 (x86 de) (HKLM\...\Mozilla Firefox 34.0.5 (x86 de)) (Version: 34.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 33.1.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Network (Version: 140.0.215.000 - Hewlett-Packard) Hidden
OpenAL (HKLM\...\OpenAL) (Version: - )
OpenOffice 4.1.0 (HKLM\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation)
Papers, Please (HKLM\...\{428CF694-7D31-4C42-8F7D-7187F5EF6937}) (Version: 1.1.65 - 3909 LLC)
Password Depot 7 (HKLM\...\{500F4898-C705-4B91-9C98-3D125330A022}_is1) (Version: 7.5.9 - AceBIT GmbH)
QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.)
RICOH R5U241 / R5C847 Media Driver ver.2.04.01.00 (HKLM\...\{2B818257-E6C7-4841-8C29-C5C9A982BCE5}) (Version: 2.04.01.00 - RICOH)
Scan (Version: 140.0.80.000 - Hewlett-Packard) Hidden
Search App by Ask (HKLM\...\{4F524A2D-5350-4500-76A7-A758B70C1500}) (Version: 12.21.0.114 - APN, LLC) <==== ATTENTION
SEGA Bass Fishing (HKLM\...\Steam App 71240) (Version: - SEGA)
SEGA Genesis & Mega Drive Classics (HKLM\...\Steam App 34270) (Version: - Sega)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 13.0 - HP)
SmartWebPrinting (Version: 140.0.186.000 - Hewlett-Packard) Hidden
SolutionCenter (Version: 140.0.213.000 - Hewlett-Packard) Hidden
Sonic & All-Stars Racing Transformed (HKLM\...\Steam App 212480) (Version: - Sumo Digital)
Status (Version: 140.0.212.000 - Hewlett-Packard) Hidden
Steam (HKLM\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
StuffIt Expander 2011 (HKLM\...\{59E98F3F-48D6-42A9-8250-079671E02B2D}) (Version: 15.0.1.17 - Smith Micro Software, Inc.)
Supporter 1.80 (HKLM\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{40030ae4}) (Version: - Costmin) <==== ATTENTION
Toolbox (Version: 140.0.428.000 - Hewlett-Packard) Hidden
TrayApp (Version: 140.0.212.000 - Hewlett-Packard) Hidden
VirtualCloneDrive (HKLM\...\VirtualCloneDrive) (Version: 5.4.7.0 - Elaborate Bytes)
WebReg (Version: 140.0.212.017 - Hewlett-Packard) Hidden
Windows 7 USB/DVD Download Tool (HKLM\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation)
WinZip 19.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E4}) (Version: 19.0.11293 - WinZip Computing, S.L. )
Zip Motion Block Video codec (Remove Only) (HKLM\...\ZMBV) (Version: - DOSBox Team)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-2596615060-55448930-4252937802-1000_Classes\CLSID\{32C15893-74C0-4478-879B-FE14EB684AB4}\InprocServer32 -> C:\Users\admin\AppData\Local\Microsoft\Windows Sidebar\Gadgets\HPPhoto.gadget\x86\hpqgps01.dll (Hewlett-Packard Co.)
CustomCLSID: HKU\S-1-5-21-2596615060-55448930-4252937802-1000_Classes\CLSID\{39C26CEE-9070-4B47-9261-6743499AFBF7}\InprocServer32 -> C:\Users\admin\AppData\Local\Microsoft\Windows Sidebar\Gadgets\HPPhoto.gadget\x86\hpqgutil.dll (Hewlett-Packard Co.)
CustomCLSID: HKU\S-1-5-21-2596615060-55448930-4252937802-1000_Classes\CLSID\{9CC1FE07-02F9-49A6-A3F4-63AD8BAE9E49}\InprocServer32 -> C:\Users\admin\AppData\Local\Microsoft\Windows Sidebar\Gadgets\HPPhoto.gadget\x86\hpqgps01.dll (Hewlett-Packard Co.)
==================== Restore Points =========================
16-01-2015 22:22:06 Wiederherstellungsvorgang
16-01-2015 22:32:59 avast! antivirus system restore point
17-01-2015 03:43:05 Windows Update
17-01-2015 12:58:53 Windows Update
18-01-2015 12:38:22 Geplanter Prüfpunkt
19-01-2015 16:35:55 Geplanter Prüfpunkt
21-01-2015 00:11:09 Geplanter Prüfpunkt
21-01-2015 08:28:42 Windows Update
22-01-2015 00:00:00 Geplanter Prüfpunkt
27-01-2015 09:27:06 Windows Update
31-01-2015 10:51:39 Windows Update
01-02-2015 00:35:41 Installed Windows 7 USB/DVD Download Tool
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {2DA74EB2-7952-4EB7-AE07-8D1D0997A082} - System32\Tasks\PC Speed Maximizer Schedule => C:\Program Files\PC Speed Maximizer\SPMLauncher.exe
Task: {39819532-D6E9-4798-B958-43E6DFE203DA} - System32\Tasks\KMSAutoNet => C:\ProgramData\KMSAutoS\KMSAuto Net.exe [2014-08-08] (MSfree Inc.)
Task: {5457BDAE-3284-48E1-9A80-9023D90FD386} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - admin => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation)
Task: {68B445DB-1619-42BC-BFD5-82449AE10683} - System32\Tasks\{1984A371-E849-4C67-A4D1-20FF1DB52C87} => pcalua.exe -a D:\INSTALL.EXE -d D:\
Task: {69C02AC9-5D7D-40FF-82B0-416548A28613} - System32\Tasks\{EDF8CAA6-25C9-439F-854B-9505D3B41C3A} => pcalua.exe -a C:\Users\admin\Downloads\tasten.exe -d C:\Users\admin\Downloads
Task: {6F6E53CF-AC1F-4A93-8E04-D03B24821A1C} - System32\Tasks\44f0d4e0-73bd-4bc1-a0b9-50e135daab47-4 => C:\Program Files\HQual-V1.8\44f0d4e0-73bd-4bc1-a0b9-50e135daab47-4.exe <==== ATTENTION
Task: {81C8DBAA-74DC-4D7F-B2E7-6BCFC12B96F4} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {9C86938D-A7FD-4231-8DCA-B6682878F206} - System32\Tasks\temp_44f0d4e0-73bd-4bc1-a0b9-50e135daab47-2 => C:\Program Files\HQual-V1.8\44f0d4e0-73bd-4bc1-a0b9-50e135daab47-2.exe <==== ATTENTION
Task: {C852BB05-ADA3-4131-93A9-0CAA53FC2CD5} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-09-11] (AVAST Software)
Task: {CA0E35E8-578C-4AF2-9A95-B09BCAAA70EF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-07-20] (Google Inc.)
Task: {D266B74C-89B7-4961-95F0-7A8B16A55D2B} - System32\Tasks\{7FF9D8C5-AC68-4694-B83F-D56E4487CDE1} => pcalua.exe -a C:\Users\admin\Desktop\ja1\INSTALL.EXE -d C:\Users\admin\Desktop\ja1
Task: {E985FEF6-56AB-40A2-A778-380146EBDDF9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-07-20] (Google Inc.)
Task: {ED3251B2-12E1-43B8-B700-FCFA7310B0D6} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\44f0d4e0-73bd-4bc1-a0b9-50e135daab47-4.job => C:\Program Files\HQual-V1.8\44f0d4e0-73bd-4bc1-a0b9-50e135daab47-4.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\temp_44f0d4e0-73bd-4bc1-a0b9-50e135daab47-2.job => C:\Program Files\HQual-V1.8\44f0d4e0-73bd-4bc1-a0b9-50e135daab47-2.exe <==== ATTENTION
==================== Loaded Modules (whitelisted) =============
2014-09-11 07:06 - 2014-09-11 07:06 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll
2015-01-31 23:56 - 2015-01-31 23:56 - 02913280 _____ () C:\Program Files\AVAST Software\Avast\defs\15013101\algo.dll
2014-10-19 16:50 - 2010-07-20 06:55 - 00181248 _____ () C:\Windows\system32\spool\PRTPROCS\W32X86\lxefdrpp.dll
2013-09-04 23:14 - 2013-09-04 23:14 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2014-09-11 07:06 - 2014-09-11 07:06 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-10-19 16:50 - 2013-01-23 09:47 - 00715368 _____ () C:\Program Files\Lexmark S800 Series\lxefmon.exe
2014-10-19 16:50 - 2010-08-26 14:55 - 01847296 _____ () C:\Program Files\Lexmark S800 Series\lxefdrs.dll
2014-10-19 16:50 - 2010-08-03 03:17 - 00155648 _____ () C:\Program Files\Lexmark S800 Series\lxefcaps.dll
2014-10-19 16:49 - 2013-01-23 09:47 - 00150272 _____ () C:\Program Files\Lexmark S800 Series\ezprint.exe
2014-10-19 16:49 - 2010-01-11 01:43 - 00716961 _____ () C:\Program Files\Lexmark S800 Series\Epwizard.DLL
2014-10-19 16:49 - 2010-01-11 01:42 - 00159897 _____ () C:\Program Files\Lexmark S800 Series\customui.dll
2014-10-19 16:49 - 2010-01-11 01:42 - 00123040 _____ () C:\Program Files\Lexmark S800 Series\Eputil.DLL
2014-10-19 16:49 - 2010-01-11 01:42 - 00143509 _____ () C:\Program Files\Lexmark S800 Series\Imagutil.DLL
2014-10-19 16:49 - 2010-01-11 01:42 - 00061611 _____ () C:\Program Files\Lexmark S800 Series\Epfunct.DLL
2014-10-19 16:49 - 2010-03-22 07:24 - 02203794 _____ () C:\Program Files\Lexmark S800 Series\EPWizRes.dll
2014-10-19 16:49 - 2010-03-22 07:25 - 00045212 _____ () C:\Program Files\Lexmark S800 Series\epstring.dll
2014-10-19 16:49 - 2010-03-22 07:26 - 00102542 _____ () C:\Program Files\Lexmark S800 Series\EPOEMDll.dll
2014-10-19 16:49 - 2010-03-29 12:15 - 00512000 _____ () C:\Program Files\Lexmark S800 Series\iptk.dll
2014-10-19 16:50 - 2010-01-18 00:34 - 00159849 _____ () C:\Program Files\Lexmark S800 Series\lxefptp.dll
2014-07-31 11:16 - 2014-07-31 11:16 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-01-27 09:33 - 2015-01-25 22:08 - 09170760 _____ () C:\Program Files\Google\Chrome\Application\40.0.2214.93\pdf.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
========================= Accounts: ==========================
admin (S-1-5-21-2596615060-55448930-4252937802-1000 - Administrator - Enabled) => C:\Users\admin
Administrator (S-1-5-21-2596615060-55448930-4252937802-500 - Administrator - Disabled)
Gast (S-1-5-21-2596615060-55448930-4252937802-501 - Limited - Disabled)
user (S-1-5-21-2596615060-55448930-4252937802-1001 - Administrator - Enabled) => C:\Users\user.user-PC
==================== Faulty Device Manager Devices =============
Name: Broadcom USH
Description: Broadcom USH
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Deskjet F4500 series
Description: Deskjet F4500 series
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: HP
Service: StillCam
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: Deskjet F4500 series
Description: Deskjet F4500 series
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: Officejet Pro 8500 A909g
Description: Officejet Pro 8500 A909g
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (02/01/2015 09:42:05 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/01/2015 01:00:59 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/31/2015 11:55:23 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/31/2015 10:46:35 PM) (Source: EventSystem) (EventID: 4621) (User: )
Description: 80070005EventSystem.EventSubscription{AA44355E-6911-4447-BA5D-6720480579AF}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}
Error: (01/31/2015 07:37:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 394869
Error: (01/31/2015 07:37:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 394869
Error: (01/31/2015 07:37:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (01/31/2015 07:37:44 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 393278
Error: (01/31/2015 07:37:44 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 393278
Error: (01/31/2015 07:37:44 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
System errors:
=============
Error: (02/01/2015 09:44:40 AM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032
Error: (02/01/2015 09:42:06 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: lxefCATSCustConnectService%%1053
Error: (02/01/2015 09:42:06 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: 30000lxefCATSCustConnectService
Error: (02/01/2015 01:01:44 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Error: (02/01/2015 01:01:20 AM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032
Error: (02/01/2015 01:01:00 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: lxefCATSCustConnectService%%1053
Error: (02/01/2015 01:01:00 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: 30000lxefCATSCustConnectService
Error: (02/01/2015 00:59:21 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am 01.02.2015 um 00:56:34 unerwartet heruntergefahren.
Error: (01/31/2015 11:57:39 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT)
Description: 0x80070032
Error: (01/31/2015 11:55:24 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: lxefCATSCustConnectService%%1053
Microsoft Office Sessions:
=========================
Error: (02/01/2015 09:42:05 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/01/2015 01:00:59 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/31/2015 11:55:23 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/31/2015 10:46:35 PM) (Source: EventSystem) (EventID: 4621) (User: )
Description: 80070005EventSystem.EventSubscription{AA44355E-6911-4447-BA5D-6720480579AF}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}
Error: (01/31/2015 07:37:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 394869
Error: (01/31/2015 07:37:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 394869
Error: (01/31/2015 07:37:45 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (01/31/2015 07:37:44 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 393278
Error: (01/31/2015 07:37:44 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 393278
Error: (01/31/2015 07:37:44 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
CodeIntegrity Errors:
===================================
Date: 2014-08-08 16:14:42.366
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-08-08 16:14:42.307
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-08-08 16:14:42.216
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-08-08 16:14:42.142
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-08-08 16:14:42.070
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Duo CPU P8700 @ 2.53GHz
Percentage of memory in use: 50%
Total physical RAM: 3535 MB
Available physical RAM: 1762.69 MB
Total Pagefile: 7294.96 MB
Available Pagefile: 5313.88 MB
Total Virtual: 2047.88 MB
Available Virtual: 1897.57 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:149.05 GB) (Free:31.2 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 149.1 GB) (Disk ID: CB972C64)
Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS)
==================== End Of Log ============================ -------------------------------------------------- Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-02-01 10:34:49
Windows 6.0.6002 Service Pack 2 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST916041 rev.0004 149,05GB
Running: Gmer-19357.exe; Driver: C:\Users\admin\AppData\Local\Temp\kxldapob.sys
---- System - GMER 2.1 ----
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAddBootEntry [0x93220BA6]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAssignProcessToJobObject [0x93221684]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEvent [0x9322D6F8]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEventPair [0x9322D744]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateIoCompletion [0x9322D8DE]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateMutant [0x9322D666]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwCreateSection [0x932D7DF0]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateSemaphore [0x9322D6AE]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwCreateThread [0x932D8080]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateTimer [0x9322D898]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDebugActiveProcess [0x93222472]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteBootEntry [0x93220C0C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDuplicateObject [0x93225C68]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwLoadDriver [0x932207F8]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwMapViewOfSection [0x932D7ED0]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwModifyBootEntry [0x93220C72]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeKey [0x9322605E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeMultipleKeys [0x93222F5A]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEvent [0x9322D722]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEventPair [0x9322D766]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenIoCompletion [0x9322D902]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenMutant [0x9322D68C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenProcess [0x93225560]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSection [0x9322D816]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSemaphore [0x9322D6D6]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenThread [0x9322594C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenTimer [0x9322D8BC]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwProtectVirtualMemory [0x932D7C6E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryObject [0x93222DCE]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueueApcThread [0x93222924]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootEntryOrder [0x93220CD8]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootOptions [0x93220D3E]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwSetContextThread [0x932D7FCC]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemInformation [0x93220892]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemPowerState [0x93220A64]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwShutdownSystem [0x932209F2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendProcess [0x9322263C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendThread [0x9322279E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSystemDebugControl [0x93220AEC]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwTerminateProcess [0x932D7D3C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwTerminateThread [0x932222CC]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwVdmControl [0x93220DA4]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwWriteVirtualMemory [0x932D7BA0]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwCreateThreadEx [0x932D816A]
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!KeSetEvent + 10D 82ABE758 4 Bytes [A6, 0B, 22, 93] {CMPSB ; OR ESP, [EDX]; XCHG EBX, EAX}
.text ntkrnlpa.exe!KeSetEvent + 191 82ABE7DC 4 Bytes [84, 16, 22, 93]
.text ntkrnlpa.exe!KeSetEvent + 1D1 82ABE81C 8 Bytes [F8, D6, 22, 93, 44, D7, 22, ...] {CLC ; SALC ; AND DL, [EBX-0x6cdd28bc]}
.text ntkrnlpa.exe!KeSetEvent + 1DD 82ABE828 4 Bytes [DE, D8, 22, 93]
.text ntkrnlpa.exe!KeSetEvent + 1F5 82ABE840 4 Bytes [66, D6, 22, 93]
.text ...
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 110 82C4C00F 4 Bytes CALL 93223641 \SystemRoot\system32\drivers\aswSnx.sys
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 121 82C4FC83 4 Bytes CALL 93223657 \SystemRoot\system32\drivers\aswSnx.sys
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\csrss.exe[620] KERNEL32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Windows\system32\wininit.exe[664] kernel32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Windows\system32\csrss.exe[676] KERNEL32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Windows\system32\services.exe[708] kernel32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Windows\system32\lsass.exe[724] kernel32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text ...
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1764] kernel32.dll!SetUnhandledExceptionFilter 764FA9BD 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP }
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1764] kernel32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Windows\system32\WLANExt.exe[1848] kernel32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Windows\System32\spoolsv.exe[1900] kernel32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Windows\system32\taskeng.exe[1908] kernel32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1984] kernel32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text ...
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2548] kernel32.dll!SetUnhandledExceptionFilter 764FA9BD 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP }
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2548] kernel32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Windows\system32\igfxsrvc.exe[2564] kernel32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[2580] kernel32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Program Files\Lexmark S800 Series\lxefmon.exe[2600] kernel32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Program Files\Lexmark S800 Series\ezprint.exe[2608] kernel32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text ...
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!LdrLoadDll 77019378 5 Bytes JMP 00F801F8
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!LdrUnloadDll 7702B680 5 Bytes JMP 00F803FC
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtCreateFile + 6 7705426A 4 Bytes [28, 10, F2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtCreateFile + B 7705426F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtMapViewOfSection + 6 770549BA 4 Bytes [28, 13, F2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtMapViewOfSection + B 770549BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenFile + 6 77054A4A 4 Bytes [68, 10, F2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenFile + B 77054A4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenProcess + 6 77054ACA 4 Bytes [A8, 11, F2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenProcess + B 77054ACF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenProcessToken + B 77054ADF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenProcessTokenEx + 6 77054AEA 4 Bytes [A8, 12, F2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenProcessTokenEx + B 77054AEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenThread + 6 77054B3A 4 Bytes [68, 11, F2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenThread + B 77054B3F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenThreadToken + 6 77054B4A 4 Bytes [68, 12, F2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenThreadToken + B 77054B4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenThreadTokenEx + B 77054B5F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtQueryAttributesFile + 6 77054BEA 4 Bytes [A8, 10, F2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtQueryAttributesFile + B 77054BEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtQueryFullAttributesFile + B 77054C9F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtSetInformationFile + 6 7705517A 4 Bytes [28, 11, F2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtSetInformationFile + B 7705517F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtSetInformationThread + 6 770551CA 4 Bytes [28, 12, F2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtSetInformationThread + B 770551CF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtUnmapViewOfSection + 6 7705546A 4 Bytes [68, 13, F2, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtUnmapViewOfSection + B 7705546F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4208] KERNEL32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!LdrLoadDll 77019378 5 Bytes JMP 006A01F8
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!LdrUnloadDll 7702B680 5 Bytes JMP 006A03FC
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtCreateFile + 6 7705426A 4 Bytes [28, 18, 64, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtCreateFile + B 7705426F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtMapViewOfSection + 6 770549BA 4 Bytes [28, 1B, 64, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtMapViewOfSection + B 770549BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenFile + 6 77054A4A 4 Bytes [68, 18, 64, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenFile + B 77054A4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenProcess + 6 77054ACA 4 Bytes [A8, 19, 64, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenProcess + B 77054ACF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenProcessToken + B 77054ADF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenProcessTokenEx + 6 77054AEA 4 Bytes [A8, 1A, 64, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenProcessTokenEx + B 77054AEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenThread + 6 77054B3A 4 Bytes [68, 19, 64, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenThread + B 77054B3F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenThreadToken + 6 77054B4A 4 Bytes [68, 1A, 64, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenThreadToken + B 77054B4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenThreadTokenEx + B 77054B5F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtQueryAttributesFile + 6 77054BEA 4 Bytes [A8, 18, 64, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtQueryAttributesFile + B 77054BEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtQueryFullAttributesFile + B 77054C9F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtSetInformationFile + 6 7705517A 4 Bytes [28, 19, 64, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtSetInformationFile + B 7705517F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtSetInformationThread + 6 770551CA 4 Bytes [28, 1A, 64, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtSetInformationThread + B 770551CF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtUnmapViewOfSection + 6 7705546A 4 Bytes [68, 1B, 64, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtUnmapViewOfSection + B 7705546F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4216] KERNEL32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Windows\system32\svchost.exe[4252] kernel32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!LdrLoadDll 77019378 5 Bytes JMP 00F601F8
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!LdrUnloadDll 7702B680 5 Bytes JMP 00F603FC
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtCreateFile + 6 7705426A 4 Bytes [28, 10, F0, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtCreateFile + B 7705426F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtMapViewOfSection + 6 770549BA 4 Bytes [28, 13, F0, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtMapViewOfSection + B 770549BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenFile + 6 77054A4A 4 Bytes [68, 10, F0, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenFile + B 77054A4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenProcess + 6 77054ACA 4 Bytes [A8, 11, F0, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenProcess + B 77054ACF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenProcessToken + B 77054ADF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenProcessTokenEx + 6 77054AEA 4 Bytes [A8, 12, F0, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenProcessTokenEx + B 77054AEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenThread + 6 77054B3A 4 Bytes [68, 11, F0, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenThread + B 77054B3F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenThreadToken + 6 77054B4A 4 Bytes [68, 12, F0, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenThreadToken + B 77054B4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenThreadTokenEx + B 77054B5F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtQueryAttributesFile + 6 77054BEA 4 Bytes [A8, 10, F0, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtQueryAttributesFile + B 77054BEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtQueryFullAttributesFile + B 77054C9F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtSetInformationFile + 6 7705517A 4 Bytes [28, 11, F0, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtSetInformationFile + B 7705517F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtSetInformationThread + 6 770551CA 4 Bytes [28, 12, F0, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtSetInformationThread + B 770551CF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtUnmapViewOfSection + 6 7705546A 4 Bytes [68, 13, F0, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtUnmapViewOfSection + B 7705546F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4276] KERNEL32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!LdrLoadDll 77019378 5 Bytes JMP 00C501F8
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!LdrUnloadDll 7702B680 5 Bytes JMP 00C503FC
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtCreateFile + 6 7705426A 4 Bytes [28, A4, BF, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtCreateFile + B 7705426F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtMapViewOfSection + 6 770549BA 4 Bytes [28, A7, BF, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtMapViewOfSection + B 770549BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenFile + 6 77054A4A 4 Bytes [68, A4, BF, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenFile + B 77054A4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenProcess + 6 77054ACA 4 Bytes [A8, A5, BF, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenProcess + B 77054ACF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenProcessToken + B 77054ADF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenProcessTokenEx + 6 77054AEA 4 Bytes [A8, A6, BF, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenProcessTokenEx + B 77054AEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenThread + 6 77054B3A 4 Bytes [68, A5, BF, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenThread + B 77054B3F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenThreadToken + 6 77054B4A 4 Bytes [68, A6, BF, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenThreadToken + B 77054B4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenThreadTokenEx + B 77054B5F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtQueryAttributesFile + 6 77054BEA 4 Bytes [A8, A4, BF, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtQueryAttributesFile + B 77054BEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtQueryFullAttributesFile + B 77054C9F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtSetInformationFile + 6 7705517A 4 Bytes [28, A5, BF, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtSetInformationFile + B 7705517F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtSetInformationThread + 6 770551CA 4 Bytes [28, A6, BF, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtSetInformationThread + B 770551CF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtUnmapViewOfSection + 6 7705546A 4 Bytes [68, A7, BF, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtUnmapViewOfSection + B 7705546F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4364] KERNEL32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!LdrLoadDll 77019378 5 Bytes JMP 006601F8
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!LdrUnloadDll 7702B680 5 Bytes JMP 006603FC
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtCreateFile + 6 7705426A 4 Bytes [28, F4, 60, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtCreateFile + B 7705426F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtMapViewOfSection + 6 770549BA 4 Bytes [28, F7, 60, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtMapViewOfSection + B 770549BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenFile + 6 77054A4A 4 Bytes [68, F4, 60, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenFile + B 77054A4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenProcess + 6 77054ACA 4 Bytes [A8, F5, 60, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenProcess + B 77054ACF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenProcessToken + B 77054ADF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenProcessTokenEx + 6 77054AEA 4 Bytes [A8, F6, 60, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenProcessTokenEx + B 77054AEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenThread + 6 77054B3A 4 Bytes [68, F5, 60, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenThread + B 77054B3F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenThreadToken + 6 77054B4A 4 Bytes [68, F6, 60, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenThreadToken + B 77054B4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenThreadTokenEx + B 77054B5F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtQueryAttributesFile + 6 77054BEA 4 Bytes [A8, F4, 60, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtQueryAttributesFile + B 77054BEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtQueryFullAttributesFile + B 77054C9F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtSetInformationFile + 6 7705517A 4 Bytes [28, F5, 60, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtSetInformationFile + B 7705517F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtSetInformationThread + 6 770551CA 4 Bytes [28, F6, 60, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtSetInformationThread + B 770551CF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtUnmapViewOfSection + 6 7705546A 4 Bytes [68, F7, 60, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtUnmapViewOfSection + B 7705546F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4496] KERNEL32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Windows\system32\conime.exe[4728] kernel32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Windows\system32\wbem\unsecapp.exe[4812] kernel32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Windows\system32\wbem\wmiprvse.exe[4864] kernel32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[4968] kernel32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text ...
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!LdrLoadDll 77019378 5 Bytes JMP 002201F8
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!LdrUnloadDll 7702B680 5 Bytes JMP 002203FC
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtCreateFile + 6 7705426A 4 Bytes [28, 14, 1C, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtCreateFile + B 7705426F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtMapViewOfSection + 6 770549BA 4 Bytes [28, 17, 1C, 00] {SUB [EDI], DL; SBB AL, 0x0}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtMapViewOfSection + B 770549BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenFile + 6 77054A4A 4 Bytes [68, 14, 1C, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenFile + B 77054A4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenProcess + 6 77054ACA 4 Bytes [A8, 15, 1C, 00] {TEST AL, 0x15; SBB AL, 0x0}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenProcess + B 77054ACF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenProcessToken + B 77054ADF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenProcessTokenEx + 6 77054AEA 4 Bytes [A8, 16, 1C, 00] {TEST AL, 0x16; SBB AL, 0x0}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenProcessTokenEx + B 77054AEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenThread + 6 77054B3A 4 Bytes [68, 15, 1C, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenThread + B 77054B3F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenThreadToken + 6 77054B4A 4 Bytes [68, 16, 1C, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenThreadToken + B 77054B4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenThreadTokenEx + B 77054B5F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtQueryAttributesFile + 6 77054BEA 4 Bytes [A8, 14, 1C, 00] {TEST AL, 0x14; SBB AL, 0x0}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtQueryAttributesFile + B 77054BEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtQueryFullAttributesFile + B 77054C9F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtSetInformationFile + 6 7705517A 4 Bytes [28, 15, 1C, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtSetInformationFile + B 7705517F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtSetInformationThread + 6 770551CA 4 Bytes [28, 16, 1C, 00] {SUB [ESI], DL; SBB AL, 0x0}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtSetInformationThread + B 770551CF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtUnmapViewOfSection + 6 7705546A 4 Bytes [68, 17, 1C, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtUnmapViewOfSection + B 7705546F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5276] KERNEL32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!LdrLoadDll 77019378 5 Bytes JMP 010401F8
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!LdrUnloadDll 7702B680 5 Bytes JMP 010403FC
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtCreateFile + 6 7705426A 4 Bytes [28, 98, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtCreateFile + B 7705426F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtMapViewOfSection + 6 770549BA 4 Bytes [28, 9B, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtMapViewOfSection + B 770549BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenFile + 6 77054A4A 4 Bytes [68, 98, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenFile + B 77054A4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenProcess + 6 77054ACA 4 Bytes [A8, 99, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenProcess + B 77054ACF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenProcessToken + B 77054ADF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenProcessTokenEx + 6 77054AEA 4 Bytes [A8, 9A, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenProcessTokenEx + B 77054AEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenThread + 6 77054B3A 4 Bytes [68, 99, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenThread + B 77054B3F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenThreadToken + 6 77054B4A 4 Bytes [68, 9A, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenThreadToken + B 77054B4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenThreadTokenEx + B 77054B5F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtQueryAttributesFile + 6 77054BEA 4 Bytes [A8, 98, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtQueryAttributesFile + B 77054BEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtQueryFullAttributesFile + B 77054C9F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtSetInformationFile + 6 7705517A 4 Bytes [28, 99, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtSetInformationFile + B 7705517F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtSetInformationThread + 6 770551CA 4 Bytes [28, 9A, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtSetInformationThread + B 770551CF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtUnmapViewOfSection + 6 7705546A 4 Bytes [68, 9B, EE, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtUnmapViewOfSection + B 7705546F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5336] KERNEL32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[5476] kernel32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5788] ntdll.dll!LdrLoadDll 77019378 5 Bytes JMP 001601F8
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5788] ntdll.dll!LdrUnloadDll 7702B680 5 Bytes JMP 001603FC
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5788] ntdll.dll!NtMapViewOfSection + 6 770549BA 4 Bytes [18, 20, 96, 65]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5788] ntdll.dll!NtMapViewOfSection + B 770549BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5788] KERNEL32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!LdrLoadDll 77019378 5 Bytes JMP 00DB01F8
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!LdrUnloadDll 7702B680 5 Bytes JMP 00DB03FC
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtCreateFile + 6 7705426A 4 Bytes [28, 58, D5, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtCreateFile + B 7705426F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtMapViewOfSection + 6 770549BA 4 Bytes [28, 5B, D5, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtMapViewOfSection + B 770549BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenFile + 6 77054A4A 4 Bytes [68, 58, D5, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenFile + B 77054A4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenProcess + 6 77054ACA 4 Bytes [A8, 59, D5, 00] {TEST AL, 0x59; AAD 0x0}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenProcess + B 77054ACF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenProcessToken + B 77054ADF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenProcessTokenEx + 6 77054AEA 4 Bytes [A8, 5A, D5, 00] {TEST AL, 0x5a; AAD 0x0}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenProcessTokenEx + B 77054AEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenThread + 6 77054B3A 4 Bytes [68, 59, D5, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenThread + B 77054B3F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenThreadToken + 6 77054B4A 4 Bytes [68, 5A, D5, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenThreadToken + B 77054B4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenThreadTokenEx + B 77054B5F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtQueryAttributesFile + 6 77054BEA 4 Bytes [A8, 58, D5, 00] {TEST AL, 0x58; AAD 0x0}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtQueryAttributesFile + B 77054BEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtQueryFullAttributesFile + B 77054C9F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtSetInformationFile + 6 7705517A 4 Bytes [28, 59, D5, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtSetInformationFile + B 7705517F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtSetInformationThread + 6 770551CA 4 Bytes [28, 5A, D5, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtSetInformationThread + B 770551CF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtUnmapViewOfSection + 6 7705546A 4 Bytes [68, 5B, D5, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtUnmapViewOfSection + B 7705546F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[6116] KERNEL32.dll!GetBinaryTypeW + 70 7652252F 1 Byte [62]
---- Devices - GMER 2.1 ----
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.sys
AttachedDevice \Driver\tdx \Device\Udp aswTdi.sys
---- EOF - GMER 2.1 ---- |