FRST - Addition Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015
Ran by HSZ at 2015-03-12 23:03:51
Running from C:\Users\HSZ\Desktop\Virus_Bekämpfung
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 16.0.0.273 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 2.6.0.393 - Adobe Systems Incorporated)
Adobe Creative Suite 6 Master Collection (HKLM-x32\...\{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}) (Version: 6 - Adobe Systems Incorporated)
Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Photoshop CC (HKLM-x32\...\{2D99B50E-431D-4AA8-85C1-172A6F8BCF09}) (Version: 14.0 - Adobe Systems Incorporated)
Adobe Photoshop Lightroom 5.2 64-bit (HKLM\...\{54E6C675-3AD4-42E4-957F-31666ABF1603}) (Version: 5.2.1 - Adobe)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{C8807716-1F6F-5C43-3C32-7295A45CF060}) (Version: 8.0.911.0 - Advanced Micro Devices, Inc.)
Ashampoo Burning Studio FREE v.1.12.0 (HKLM-x32\...\{91B33C97-91F8-FFB3-581B-BC952C901685}_is1) (Version: 1.12.0 - Ashampoo GmbH & Co. KG)
Asmedia ASM106x SATA Host Controller Driver (HKLM-x32\...\{61942EF5-2CD8-47D4-869C-2E9A8BB085F1}) (Version: 1.3.1.000 - Asmedia Technology)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.0.2208 - AVAST Software)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
dm-Fotowelt (HKLM-x32\...\dm-Fotowelt) (Version: 5.1.3 - CEWE Stiftung u Co. KGaA)
Dropbox (HKU\S-1-5-21-124959178-3558452043-2407712191-1000\...\Dropbox) (Version: 3.0.3 - Dropbox, Inc.)
FileZilla Client 3.2.7.1 (HKLM-x32\...\FileZilla Client) (Version: 3.2.7.1 - )
Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Foxy Secure (HKLM-x32\...\Foxy Secure) (Version: 6 - ) <==== ATTENTION
Google Chrome (HKLM-x32\...\{6B82E0C6-A4AE-33D0-AE21-E2FE19E7CB32}) (Version: 65.107.16478 - Google, Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.5111.1712 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.3.214 - Intel Corporation)
Java 7 Update 76 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217076FF}) (Version: 7.0.760 - Oracle)
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
Junk Mail filter update (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
K-Lite Codec Pack 9.9.5 (Standard) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 9.9.5 - )
Mein CEWE FOTOBUCH (HKLM-x32\...\Mein CEWE FOTOBUCH) (Version: 5.1.3 - CEWE Stiftung u Co. KGaA)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Outlook Hotmail Connector 64-Bit (HKLM\...\{95140000-007A-0407-1000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Outlook Social Connector Provider for Windows Live Messenger 64-bit (HKLM\...\{95140000-007D-0409-1000-0000000FF1CE}) (Version: 14.0.5120.5000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-124959178-3558452043-2407712191-1000\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010-Tools für Office-Laufzeit (x64) Language Pack - DEU (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DEU) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mozilla Firefox 35.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 33.1.1 - Mozilla)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.3.3 - Notepad++ Team)
Opera Stable 28.0.1750.40 (HKLM-x32\...\Opera 28.0.1750.40) (Version: 28.0.1750.40 - Opera Software ASA)
PDF Settings CC (x32 Version: 12.0 - Adobe Systems Incorporated) Hidden
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
Performance Optimizer (HKLM-x32\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{892cc6a3}) (Version: - Linker Ltd) <==== ATTENTION
PhotoScape (HKLM-x32\...\PhotoScape) (Version: - )
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.48.823.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6482 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform)
Saal Design Software (HKLM-x32\...\SaalDesignSoftware) (Version: 3.2.43 - Saal Digital Fotoservice GmbH)
Saal Design Software (x32 Version: 3.2.43 - Saal Digital Fotoservice GmbH) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (HKLM\...\{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{A3364707-2F53-4C83-8F68-C9877A9080C7}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden
Skype™ 6.3 (HKLM-x32\...\{1845470B-EB14-4ABC-835B-E36C693DC07D}) (Version: 6.3.107 - Skype Technologies S.A.)
Softonic Assistant (HKU\S-1-5-21-124959178-3558452043-2407712191-1000\...\SoftonicAssistant) (Version: 0.1.6 - Softonic International S.A.) <==== ATTENTION
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
Spotify (HKU\S-1-5-21-124959178-3558452043-2407712191-1000\...\Spotify) (Version: 0.9.15.27.g87efe634 - Spotify AB)
SurveillancePlugin (HKLM-x32\...\{34FA3664-65C3-4F5F-9D27-E4957BA84F92}) (Version: 1.0.0.418 - Synology)
Synology Assistant (remove only) (HKLM-x32\...\Synology Assistant) (Version: - )
Synology Cloud Station (remove only) (HKU\S-1-5-21-124959178-3558452043-2407712191-1000\...\Synology CloudStation) (Version: - )
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.31064 - TeamViewer)
VideoPad Video-Editor (HKLM-x32\...\VideoPad) (Version: 3.59 - NCH Software)
VLC media player 2.0.6 (HKLM-x32\...\VLC media player) (Version: 2.0.6 - VideoLAN)
Wacom Tablett (HKLM\...\Wacom Tablet Driver) (Version: 6.3.8-3 - Wacom Technology Corp.)
WebTablet FB Plugin 32 bit (HKLM-x32\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
WebTablet FB Plugin 64 bit (HKLM\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Windows Movie Maker 2.6 (HKLM-x32\...\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}) (Version: 2.6.4037.0 - Microsoft Corporation)
WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
WinZip 19.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E7}) (Version: 19.0.11294 - WinZip Computing, S.L. )
WPM18.8.0.304 (HKLM-x32\...\WPM) (Version: 18.8.0.304 - Cherished Technololgy LIMITED) <==== ATTENTION
XMedia Recode Version 3.2.0.3 (HKLM-x32\...\{DDA3C325-47B2-4730-9672-BF3771C08799}_is1) (Version: 3.2.0.3 - XMedia Recode)
XnView 2.03 (HKLM-x32\...\XnView_is1) (Version: 2.03 - Gougelet Pierre-e)
YASA MOV to MPEG WMV AVI Converter v3.4 (build 0061) (HKLM-x32\...\YASA MOV to MPEG WMV AVI Converter v3.4 (build 0061)) (Version: - )
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-124959178-3558452043-2407712191-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\HSZ\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-124959178-3558452043-2407712191-1000_Classes\CLSID\{2C4A5D61-009C-4561-9A33-6AFD542FD237}\InprocServer32 -> C:\Users\HSZ\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\ContextMenu.dll ()
CustomCLSID: HKU\S-1-5-21-124959178-3558452043-2407712191-1000_Classes\CLSID\{472CE1AD-5D53-4BCF-A1FB-3982A5F55138}\InprocServer32 -> C:\Users\HSZ\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-124959178-3558452043-2407712191-1000_Classes\CLSID\{48AB5ADA-36B1-4137-99C9-2BD97F8788AB}\InprocServer32 -> C:\Users\HSZ\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-124959178-3558452043-2407712191-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\HSZ\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-124959178-3558452043-2407712191-1000_Classes\CLSID\{A433C3E0-8B24-40EB-93C3-4B10D9959F58}\InprocServer32 -> C:\Users\HSZ\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-124959178-3558452043-2407712191-1000_Classes\CLSID\{AEB16659-2125-4ADA-A4AB-45EE21E86469}\InprocServer32 -> C:\Users\HSZ\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\iconOverlay.dll (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-124959178-3558452043-2407712191-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\HSZ\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-124959178-3558452043-2407712191-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\HSZ\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-124959178-3558452043-2407712191-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\HSZ\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64\FileSyncApi64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-124959178-3558452043-2407712191-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\HSZ\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-124959178-3558452043-2407712191-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\HSZ\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-124959178-3558452043-2407712191-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\HSZ\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-124959178-3558452043-2407712191-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\HSZ\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-124959178-3558452043-2407712191-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\HSZ\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-124959178-3558452043-2407712191-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\HSZ\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-124959178-3558452043-2407712191-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\HSZ\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-124959178-3558452043-2407712191-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\HSZ\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
==================== Restore Points =========================
27-01-2015 00:21:45 Geplanter Prüfpunkt
27-01-2015 11:14:08 Windows Update
03-02-2015 10:36:46 Windows Update
06-02-2015 17:56:08 Windows Update
16-02-2015 15:32:31 Windows Update
16-02-2015 19:20:29 Windows Update
17-02-2015 19:45:52 Windows Update
24-02-2015 18:16:38 Windows Update
25-02-2015 16:51:26 Windows Update
05-03-2015 18:47:09 Windows Update
11-03-2015 19:08:38 Windows Update
11-03-2015 23:18:18 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:34 - 2013-05-31 20:57 - 00000889 ____N C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {028C4E71-F477-4AD6-A74B-0E01A2A8B81C} - System32\Tasks\AdobeAAMUpdater-1.0-HSZ-PC-HSZ => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-02-27] (Adobe Systems Incorporated)
Task: {13F44971-72A2-4FD0-86BB-FDB6EC7E009E} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc
Task: {1554635E-445D-4E5D-9A9C-ECA531C2E875} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-31] (Google Inc.)
Task: {42D51D7D-B5A9-4AA7-A10F-956ADDC9C601} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-12-06] (AVAST Software)
Task: {84B643DF-E248-4D7D-BAC4-19A400A43296} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-05-31] (Google Inc.)
Task: {952018AF-075F-4BA5-94B7-9D7C53E31B61} - System32\Tasks\BitGuard => Sc.exe start BitGuard <==== ATTENTION
Task: {98ADAAA8-E270-4FCA-A2A9-F767CC4F45D8} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-09] (Adobe Systems Incorporated)
Task: {CAE6D572-D296-44C6-818E-62D55F728B7E} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation)
Task: {E4C4CDA6-00DE-44D3-A301-75763E208E79} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {FA102645-EA89-4B3D-849D-47987D310240} - System32\Tasks\Opera scheduled Autoupdate 1398205180 => C:\Program Files (x86)\Opera\launcher.exe [2015-03-10] (Opera Software)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) ==============
2014-02-25 02:28 - 2014-02-25 02:28 - 00248736 _____ () C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe
2014-12-06 15:02 - 2014-12-06 15:02 - 00388208 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxDDU.dll
2014-12-06 15:02 - 2014-12-06 15:02 - 05851328 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxRT.dll
2014-04-22 06:14 - 2014-04-04 00:55 - 01356568 _____ () C:\Program Files\Tablet\Wacom\libxml2.dll
2014-05-23 01:10 - 2014-05-23 01:10 - 00671904 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll
2009-08-23 18:24 - 2009-08-23 18:24 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2014-06-11 15:08 - 2014-06-11 15:08 - 00909312 _____ () C:\Users\HSZ\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\ContextMenu.dll
2012-06-18 16:24 - 2012-06-18 16:24 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_05.dll
2014-06-11 15:08 - 2014-06-11 15:08 - 03774880 _____ () C:\Users\HSZ\AppData\Local\CloudStation\bin\cloud.exe
2014-06-11 15:09 - 2014-06-11 15:09 - 10111448 _____ () C:\Users\HSZ\AppData\Local\CloudStation\bin\client-win.exe
2014-05-23 01:10 - 2014-05-23 01:10 - 05341856 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
2015-03-11 23:12 - 2015-03-11 23:12 - 02921984 _____ () C:\Program Files\AVAST Software\Avast\defs\15031101\algo.dll
2014-12-06 15:02 - 2014-12-06 15:02 - 04495336 _____ () C:\Program Files\AVAST Software\Avast\ng\vbox\x86\VBoxRT-x86.dll
2015-03-12 22:37 - 2015-03-12 22:37 - 02922496 _____ () C:\Program Files\AVAST Software\Avast\defs\15031201\algo.dll
2013-05-31 10:15 - 2013-05-31 10:15 - 01259320 _____ () C:\Users\HSZ\AppData\Local\CloudStation\bin\libsqlite3-0.dll
2013-05-31 10:15 - 2013-05-31 10:15 - 00043008 _____ () C:\Users\HSZ\AppData\Local\CloudStation\bin\libgcc_s_dw2-1.dll
2014-03-24 04:18 - 2014-03-24 04:18 - 02554368 _____ () C:\Users\HSZ\AppData\Local\CloudStation\bin\QtCore4.dll
2014-03-24 04:18 - 2014-03-24 04:18 - 09824768 _____ () C:\Users\HSZ\AppData\Local\CloudStation\bin\QtGui4.dll
2014-03-24 04:18 - 2014-03-24 04:18 - 01218048 _____ () C:\Users\HSZ\AppData\Local\CloudStation\bin\QtNetwork4.dll
2013-05-31 10:15 - 2013-05-31 10:15 - 01599298 _____ () C:\Users\HSZ\AppData\Local\CloudStation\bin\icuuc50.dll
2013-05-31 10:15 - 2013-05-31 10:15 - 00879630 _____ () C:\Users\HSZ\AppData\Local\CloudStation\bin\libstdc++-6.dll
2013-05-31 10:15 - 2013-05-31 10:15 - 20803927 _____ () C:\Users\HSZ\AppData\Local\CloudStation\bin\icudt50.dll
2014-05-26 04:52 - 2014-05-26 04:52 - 32733088 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libcef.dll
2014-12-06 15:02 - 2014-12-06 15:02 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-05-12 21:22 - 2014-05-12 21:22 - 02217128 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\plugins\ExchangePlugin\ExManCoreLib\ExManZxpSign.dll
2014-05-26 04:52 - 2014-05-26 04:52 - 00742816 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libglesv2.dll
2014-05-26 04:52 - 2014-05-26 04:52 - 00136608 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libegl.dll
2009-08-23 18:58 - 2009-08-23 18:58 - 00094208 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
2015-01-24 15:45 - 2015-01-21 04:50 - 01117512 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.91\libglesv2.dll
2015-01-24 15:45 - 2015-01-21 04:50 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.91\libegl.dll
2015-01-24 15:45 - 2015-01-21 04:50 - 09171272 _____ () C:\Program Files (x86)\Google\Chrome\Application\40.0.2214.91\pdf.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\ProgramData\Microsoft:G0vkmvoCpamg87Qb1PnE08M3h
AlternateDataStreams: C:\Users\HSZ\AppData\Local\GSzQ2wZx:qH2gBg4OAYQUWf8stK0
AlternateDataStreams: C:\Users\HSZ\AppData\Local\HglfFLhS:jyTNoTuBCkR63jInu
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-124959178-3558452043-2407712191-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\HSZ\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.178.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== Accounts: =============================
Administrator (S-1-5-21-124959178-3558452043-2407712191-500 - Administrator - Disabled)
Gast (S-1-5-21-124959178-3558452043-2407712191-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-124959178-3558452043-2407712191-1016 - Limited - Enabled)
HSZ (S-1-5-21-124959178-3558452043-2407712191-1000 - Administrator - Enabled) => C:\Users\HSZ
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name: Atheros AR922X Wireless Network Adapter
Description: Atheros AR922X Wireless Network Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Atheros Communications Inc.
Service: athr
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (03/12/2015 10:37:11 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/11/2015 07:03:37 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/08/2015 09:07:46 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/07/2015 02:05:35 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/05/2015 06:43:23 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/01/2015 08:05:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/28/2015 11:23:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/27/2015 11:37:36 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/27/2015 10:19:17 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/26/2015 00:24:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (03/07/2015 02:07:38 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Funktionssuche-Ressourcenveröffentlichung" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler:
%%1056
Error: (03/07/2015 02:05:38 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "SSDP-Suche" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 100 Millisekunden durchgeführt: Neustart des Diensts.
Error: (03/07/2015 02:05:38 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (03/02/2015 02:36:11 AM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk5\DR5 gefunden.
Error: (02/25/2015 06:53:57 PM) (Source: Ntfs) (EventID: 137) (User: )
Description: Auf dem Volume "G:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.
Error: (02/17/2015 02:59:59 PM) (Source: Ntfs) (EventID: 137) (User: )
Description: Auf dem Volume "G:" konnte der Transaktionsressourcen-Manager aufgrund eines nicht wiederholbaren Fehlers nicht gestartet werden. Der Fehlercode ist in den Daten enthalten.
Error: (02/06/2015 05:52:33 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Funktionssuche-Ressourcenveröffentlichung" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler:
%%1056
Error: (02/06/2015 05:50:33 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "SSDP-Suche" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 100 Millisekunden durchgeführt: Neustart des Diensts.
Error: (02/06/2015 05:50:33 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (01/26/2015 10:34:28 PM) (Source: volsnap) (EventID: 29) (User: )
Description: Die Schattenkopien von Volume "C:" wurde während der Ermittlung abgebrochen.
Microsoft Office Sessions:
=========================
Error: (03/12/2015 10:37:11 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/11/2015 07:03:37 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/08/2015 09:07:46 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/07/2015 02:05:35 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/05/2015 06:43:23 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (03/01/2015 08:05:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/28/2015 11:23:06 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/27/2015 11:37:36 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/27/2015 10:19:17 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/26/2015 00:24:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
==================== Memory info ===========================
Processor: Intel(R) Xeon(R) CPU E3-1230 V2 @ 3.30GHz
Percentage of memory in use: 30%
Total physical RAM: 8138.48 MB
Available physical RAM: 5621.14 MB
Total Pagefile: 16275.14 MB
Available Pagefile: 13331.98 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:119.14 GB) (Free:26.2 GB) NTFS
Drive f: () (Fixed) (Total:931.51 GB) (Free:502.97 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 119.2 GB) (Disk ID: 69714E4E)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=119.1 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 7A9E1C99)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)
==================== End Of Log ============================ GMER Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-03-12 23:26:29
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP6T0L0-6 Samsung_SSD_840_PRO_Series rev.DXM05B0Q 119,24GB
Running: Gmer-19357.exe; Driver: C:\Users\HSZ\AppData\Local\Temp\uwldipow.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[2004] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077041401 2 bytes JMP 7627b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[2004] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077041419 2 bytes JMP 7627b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[2004] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077041431 2 bytes JMP 762f8ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[2004] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007704144a 2 bytes CALL 762548ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[2004] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000770414dd 2 bytes JMP 762f87a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[2004] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000770414f5 2 bytes JMP 762f8978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[2004] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007704150d 2 bytes JMP 762f8698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[2004] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077041525 2 bytes JMP 762f8a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[2004] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007704153d 2 bytes JMP 7626fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[2004] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077041555 2 bytes JMP 762768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[2004] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007704156d 2 bytes JMP 762f8f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[2004] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077041585 2 bytes JMP 762f8ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[2004] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007704159d 2 bytes JMP 762f865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[2004] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000770415b5 2 bytes JMP 7626fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[2004] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000770415cd 2 bytes JMP 7627b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[2004] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000770416b2 2 bytes JMP 762f8e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[2004] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000770416bd 2 bytes JMP 762f85f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[3960] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077041401 2 bytes JMP 7627b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[3960] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077041419 2 bytes JMP 7627b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[3960] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077041431 2 bytes JMP 762f8ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[3960] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007704144a 2 bytes CALL 762548ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[3960] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000770414dd 2 bytes JMP 762f87a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[3960] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000770414f5 2 bytes JMP 762f8978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[3960] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007704150d 2 bytes JMP 762f8698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[3960] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077041525 2 bytes JMP 762f8a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[3960] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007704153d 2 bytes JMP 7626fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[3960] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077041555 2 bytes JMP 762768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[3960] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007704156d 2 bytes JMP 762f8f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[3960] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077041585 2 bytes JMP 762f8ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[3960] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007704159d 2 bytes JMP 762f865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[3960] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000770415b5 2 bytes JMP 7626fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[3960] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000770415cd 2 bytes JMP 7627b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[3960] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000770416b2 2 bytes JMP 762f8e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[3960] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000770416bd 2 bytes JMP 762f85f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4788] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077041401 2 bytes JMP 7627b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4788] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077041419 2 bytes JMP 7627b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4788] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077041431 2 bytes JMP 762f8ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4788] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007704144a 2 bytes CALL 762548ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4788] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000770414dd 2 bytes JMP 762f87a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4788] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000770414f5 2 bytes JMP 762f8978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4788] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007704150d 2 bytes JMP 762f8698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4788] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077041525 2 bytes JMP 762f8a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4788] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007704153d 2 bytes JMP 7626fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4788] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077041555 2 bytes JMP 762768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4788] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007704156d 2 bytes JMP 762f8f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4788] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077041585 2 bytes JMP 762f8ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4788] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007704159d 2 bytes JMP 762f865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4788] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000770415b5 2 bytes JMP 7626fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4788] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000770415cd 2 bytes JMP 7627b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4788] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000770416b2 2 bytes JMP 762f8e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[4788] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000770416bd 2 bytes JMP 762f85f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[4796] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000076258791 8 bytes [31, C0, C2, 04, 00, 90, 90, ...]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4804] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077041401 2 bytes JMP 7627b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4804] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077041419 2 bytes JMP 7627b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4804] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077041431 2 bytes JMP 762f8ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4804] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007704144a 2 bytes CALL 762548ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4804] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000770414dd 2 bytes JMP 762f87a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4804] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000770414f5 2 bytes JMP 762f8978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4804] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007704150d 2 bytes JMP 762f8698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4804] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077041525 2 bytes JMP 762f8a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4804] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007704153d 2 bytes JMP 7626fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4804] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077041555 2 bytes JMP 762768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4804] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007704156d 2 bytes JMP 762f8f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4804] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077041585 2 bytes JMP 762f8ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4804] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007704159d 2 bytes JMP 762f865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4804] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000770415b5 2 bytes JMP 7626fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4804] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000770415cd 2 bytes JMP 7627b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4804] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000770416b2 2 bytes JMP 762f8e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4804] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000770416bd 2 bytes JMP 762f85f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5456] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077041401 2 bytes JMP 7627b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5456] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077041419 2 bytes JMP 7627b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5456] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077041431 2 bytes JMP 762f8ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5456] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007704144a 2 bytes CALL 762548ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5456] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000770414dd 2 bytes JMP 762f87a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5456] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000770414f5 2 bytes JMP 762f8978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5456] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007704150d 2 bytes JMP 762f8698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5456] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077041525 2 bytes JMP 762f8a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5456] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007704153d 2 bytes JMP 7626fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5456] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077041555 2 bytes JMP 762768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5456] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007704156d 2 bytes JMP 762f8f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5456] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077041585 2 bytes JMP 762f8ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5456] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007704159d 2 bytes JMP 762f865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5456] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000770415b5 2 bytes JMP 7626fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5456] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000770415cd 2 bytes JMP 7627b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5456] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000770416b2 2 bytes JMP 762f8e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[5456] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000770416bd 2 bytes JMP 762f85f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5924] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077041401 2 bytes JMP 7627b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5924] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077041419 2 bytes JMP 7627b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5924] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077041431 2 bytes JMP 762f8ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5924] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007704144a 2 bytes CALL 762548ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5924] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000770414dd 2 bytes JMP 762f87a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5924] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000770414f5 2 bytes JMP 762f8978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5924] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007704150d 2 bytes JMP 762f8698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5924] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077041525 2 bytes JMP 762f8a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5924] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007704153d 2 bytes JMP 7626fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5924] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077041555 2 bytes JMP 762768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5924] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007704156d 2 bytes JMP 762f8f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5924] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077041585 2 bytes JMP 762f8ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5924] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007704159d 2 bytes JMP 762f865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5924] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000770415b5 2 bytes JMP 7626fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5924] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000770415cd 2 bytes JMP 7627b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5924] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000770416b2 2 bytes JMP 762f8e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[5924] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000770416bd 2 bytes JMP 762f85f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[6104] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077041401 2 bytes JMP 7627b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[6104] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077041419 2 bytes JMP 7627b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[6104] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077041431 2 bytes JMP 762f8ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[6104] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007704144a 2 bytes CALL 762548ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[6104] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000770414dd 2 bytes JMP 762f87a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[6104] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000770414f5 2 bytes JMP 762f8978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[6104] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007704150d 2 bytes JMP 762f8698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[6104] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077041525 2 bytes JMP 762f8a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[6104] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007704153d 2 bytes JMP 7626fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[6104] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077041555 2 bytes JMP 762768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[6104] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007704156d 2 bytes JMP 762f8f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[6104] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077041585 2 bytes JMP 762f8ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[6104] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007704159d 2 bytes JMP 762f865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[6104] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000770415b5 2 bytes JMP 7626fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[6104] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000770415cd 2 bytes JMP 7627b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[6104] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000770416b2 2 bytes JMP 762f8e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[6104] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000770416bd 2 bytes JMP 762f85f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[5204] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077041401 2 bytes JMP 7627b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[5204] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077041419 2 bytes JMP 7627b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[5204] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077041431 2 bytes JMP 762f8ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[5204] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007704144a 2 bytes CALL 762548ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[5204] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000770414dd 2 bytes JMP 762f87a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[5204] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000770414f5 2 bytes JMP 762f8978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[5204] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007704150d 2 bytes JMP 762f8698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[5204] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077041525 2 bytes JMP 762f8a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[5204] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007704153d 2 bytes JMP 7626fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[5204] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077041555 2 bytes JMP 762768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[5204] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007704156d 2 bytes JMP 762f8f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[5204] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077041585 2 bytes JMP 762f8ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[5204] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007704159d 2 bytes JMP 762f865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[5204] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000770415b5 2 bytes JMP 7626fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[5204] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000770415cd 2 bytes JMP 7627b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[5204] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000770416b2 2 bytes JMP 762f8e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe[5204] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000770416bd 2 bytes JMP 762f85f1 C:\Windows\syswow64\kernel32.dll
---- Processes - GMER 2.1 ----
Library C:\Users\HSZ\AppData\Local\CloudStation\iconoverlay_v7\IconOverlayDLLs_x64\ContextMenu.dll (*** suspicious ***) @ C:\Windows\Explorer.EXE [1580](2014-06-11 14:08:52) 0000000014270000
Library C:\Users\HSZ\AppData\Local\CloudStation\bin\libsqlite3-0.dll (*** suspicious ***) @ C:\Users\HSZ\AppData\Local\CloudStation\bin\cloud.exe [4616](2013-05-31 09:15:42) 0000000066380000
Library C:\Users\HSZ\AppData\Local\CloudStation\bin\LIBEAY32.dll (*** suspicious ***) @ C:\Users\HSZ\AppData\Local\CloudStation\bin\cloud.exe [4616] (OpenSSL shared library/The OpenSSL Project, hxxp://www.openssl.org/)(2013-05-31 09:15:42) 0000000063000000
Library C:\Users\HSZ\AppData\Local\CloudStation\bin\SSLEAY32.dll (*** suspicious ***) @ C:\Users\HSZ\AppData\Local\CloudStation\bin\cloud.exe [4616] (OpenSSL shared library/The OpenSSL Project, hxxp://www.openssl.org/)(2013-05-31 09:15:42) 000000006e400000
Library C:\Users\HSZ\AppData\Local\CloudStation\bin\pthreadGC2.dll (*** suspicious ***) @ C:\Users\HSZ\AppData\Local\CloudStation\bin\cloud.exe [4616] (Open Source Software community project)(2013-05-31 09:15:42) 0000000061180000
Library C:\Users\HSZ\AppData\Local\CloudStation\bin\libgcc_s_dw2-1.dll (*** suspicious ***) @ C:\Users\HSZ\AppData\Local\CloudStation\bin\cloud.exe [4616](2013-05-31 09:15:42) 000000006e940000
Library C:\Users\HSZ\AppData\Local\CloudStation\bin\QtCore4.dll (*** suspicious ***) @ C:\Users\HSZ\AppData\Local\CloudStation\bin\cloud.exe [4616](2014-03-24 03:18:40) 000000006e0c0000
Library C:\Users\HSZ\AppData\Local\CloudStation\bin\QtGui4.dll (*** suspicious ***) @ C:\Users\HSZ\AppData\Local\CloudStation\bin\cloud.exe [4616](2014-03-24 03:18:40) 0000000067700000
Library C:\Users\HSZ\AppData\Local\CloudStation\bin\QtNetwork4.dll (*** suspicious ***) @ C:\Users\HSZ\AppData\Local\CloudStation\bin\cloud.exe [4616](2014-03-24 03:18:42) 0000000065c80000
Library C:\Users\HSZ\AppData\Local\CloudStation\bin\icuuc50.dll (*** suspicious ***) @ C:\Users\HSZ\AppData\Local\CloudStation\bin\cloud.exe [4616](2013-05-31 09:15:16) 00000000682c0000
Library C:\Users\HSZ\AppData\Local\CloudStation\bin\libstdc++-6.dll (*** suspicious ***) @ C:\Users\HSZ\AppData\Local\CloudStation\bin\cloud.exe [4616](2013-05-31 09:15:40) 000000006fc40000
Library C:\Users\HSZ\AppData\Local\CloudStation\bin\icudt50.dll (*** suspicious ***) @ C:\Users\HSZ\AppData\Local\CloudStation\bin\cloud.exe [4616](2013-05-31 09:15:16) 00000000008c0000
Library C:\Users\HSZ\AppData\Local\CloudStation\bin\libsqlite3-0.dll (*** suspicious ***) @ C:\Users\HSZ\AppData\Local\CloudStation\bin\client-win.exe [5000](2013-05-31 09:15:42) 0000000066380000
Library C:\Users\HSZ\AppData\Local\CloudStation\bin\LIBEAY32.dll (*** suspicious ***) @ C:\Users\HSZ\AppData\Local\CloudStation\bin\client-win.exe [5000] (OpenSSL shared library/The OpenSSL Project, hxxp://www.openssl.org/)(2013-05-31 09:15:42) 0000000063000000
Library C:\Users\HSZ\AppData\Local\CloudStation\bin\SSLEAY32.dll (*** suspicious ***) @ C:\Users\HSZ\AppData\Local\CloudStation\bin\client-win.exe [5000] (OpenSSL shared library/The OpenSSL Project, hxxp://www.openssl.org/)(2013-05-31 09:15:42) 000000006e400000
Library C:\Users\HSZ\AppData\Local\CloudStation\bin\pthreadGC2.dll (*** suspicious ***) @ C:\Users\HSZ\AppData\Local\CloudStation\bin\client-win.exe [5000] (Open Source Software community project)(2013-05-31 09:15:42) 0000000061180000
Library C:\Users\HSZ\AppData\Local\CloudStation\bin\libgcc_s_dw2-1.dll (*** suspicious ***) @ C:\Users\HSZ\AppData\Local\CloudStation\bin\client-win.exe [5000](2013-05-31 09:15:42) 000000006e940000
Library C:\Users\HSZ\AppData\Local\CloudStation\bin\icuuc50.dll (*** suspicious ***) @ C:\Users\HSZ\AppData\Local\CloudStation\bin\client-win.exe [5000](2013-05-31 09:15:16) 00000000682c0000
Library C:\Users\HSZ\AppData\Local\CloudStation\bin\libstdc++-6.dll (*** suspicious ***) @ C:\Users\HSZ\AppData\Local\CloudStation\bin\client-win.exe [5000](2013-05-31 09:15:40) 000000006fc40000
Library C:\Users\HSZ\AppData\Local\CloudStation\bin\icudt50.dll (*** suspicious ***) @ C:\Users\HSZ\AppData\Local\CloudStation\bin\client-win.exe [5000](2013-05-31 09:15:16) 0000000066b40000
---- EOF - GMER 2.1 ----
VIELEN DANKE EUCH!!! :daumenhoc |