logs Teil 2:
FRST Additions Logfile: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 11-03-2015
Ran by Administrator at 2015-03-24 15:08:16
Running from C:\Dokumente und Einstellungen\Administrator\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Enabled - Up to date) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Emsisoft Anti-Malware (Enabled - Up to date) {0F8591BB-342B-4493-91C3-4E948ED21255}
FW: Online Armor Firewall (Disabled) {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.9.0.1030 - Adobe Systems Incorporated)
Adobe Flash Player 17 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Flash Player 17 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 17.0.0.134 - Adobe Systems Incorporated)
Adobe Media Player (HKLM\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.1 - Adobe Systems Incorporated)
Adobe Photoshop CS4 (HKLM\...\Adobe_faf656ef605427ee2f42989c3ad31b8) (Version: 11.0 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.08) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Avant Browser (remove only) (HKLM\...\AvantBrowser) (Version: - )
BitTorrent (HKU\S-1-5-21-1614895754-2111687655-839522115-500\...\BitTorrent) (Version: 7.9.2.38657 - BitTorrent Inc.)
BlogDesk 2.8 (HKLM\...\BlogDesk_is1) (Version: 2.8 - BlogDesk)
BPM-Studio 4 Profi (HKLM\...\BPM-Studio 4 Profi) (Version: - )
Browse3D Uninstall (HKLM\...\Browse3D_is1) (Version: v3.5 - Browse3D Corporation)
Canon i250 (HKLM\...\CANONBJ_Deinstall_CNMCP50.DLL) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 4.04 - Piriform)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.5306 - CDBurnerXP)
Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Connect (Version: 1.0.0.1 - Adobe Systems Incorporated) Hidden
D-i-v-X AVI Codec Pack Pro 2.4.0 (HKLM\...\D-i-v-X - AVI Codec Pack Pro) (Version: - D-i-v-X AVI Codec Pack Pro)
Emsisoft Anti-Malware (HKLM\...\{BC30E5E7-047D-4232-A7E8-F2CB7CC7B2E0}_is1) (Version: 8.0 - Emsisoft GmbH)
ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version: - )
FileASSASSIN (HKLM\...\FileASSASSIN) (Version: 1.06 - Malwarebytes)
Flock (2.5.6) (HKLM\...\Flock (2.5.6)) (Version: 2.5.6 (en-US) - Flock)
Foto Sprechblase 1 (HKLM\...\Foto Sprechblase 1) (Version: - )
Free Video Converter V 3.2 (HKLM\...\Free Video Converter_is1) (Version: 3.2.0.0 - Koyote Soft)
GIMP 2.8.6 (HKLM\...\GIMP-2_is1) (Version: 2.8.6 - The GIMP Team)
Google Chrome (HKU\S-1-5-21-1614895754-2111687655-839522115-500\...\Google Chrome) (Version: 41.0.2272.101 - Google Inc.)
Hotfix für Windows XP (KB2633952) (HKLM\...\KB2633952) (Version: 1 - Microsoft Corporation)
Hotfix für Windows XP (KB2756822) (HKLM\...\KB2756822) (Version: 1 - Microsoft Corporation)
Hotfix für Windows XP (KB2779562) (HKLM\...\KB2779562) (Version: 1 - Microsoft Corporation)
Hotfix für Windows XP (KB942288-v3) (HKLM\...\KB942288-v3) (Version: 3 - Microsoft Corporation)
Hotfix für Windows XP (KB952287) (HKLM\...\KB952287) (Version: 1 - Microsoft Corporation)
Hotfix für Windows XP (KB961118) (HKLM\...\KB961118) (Version: 1 - Microsoft Corporation)
Installation Stellwerk Hannover (HKLM\...\Installation Stellwerk Hannover) (Version: - Gunnar Blumert Softwareentwicklung)
Intel(R) PROSet/Wireless WiFi-Software (HKLM\...\{35C0A1E4-D02A-412C-841F-266DBB116ABB}) (Version: 12.02.0000 - Intel(R) Corporation)
IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.36 - Irfan Skiljan)
ISOBURN 1.8 (HKLM\...\ISOBURN) (Version: 1.8 - Dirk Paehl)
IsoBuster 3.0 (HKLM\...\IsoBuster_is1) (Version: 3.0 - Smart Projects)
IZArc 4.1.7 (HKLM\...\{97C82B44-D408-4F14-9252-47FC1636D23E}_is1) (Version: 4.1.7 - Ivan Zahariev)
Java 7 Update 45 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.450 - Oracle)
K-Meleon 1.5.4 de-DE (nur entfernen) (HKLM\...\K-Meleon) (Version: 1.5.4 - K-Meleon Team)
kuler (Version: 2.0 - Adobe Systems Incorporated) Hidden
Malwarebytes Anti-Malware Version 2.1.4.1018 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation)
Maxthon2 (HKLM\...\Maxthon2) (Version: - Maxthon International Limited)
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DEU (HKLM\...\{C314CE45-3392-3B73-B4E1-139CD41CA933}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DEU (HKLM\...\{C2C284D2-6BD7-3B34-B0C5-B2CAED168DF7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Office Word Viewer 2003 (HKLM\...\{90850407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Works 6-9 Converter (HKLM\...\{172423F9-522A-483A-AD65-03600CE4CA4F}) (Version: 9.7.0000 - Microsoft Corporation)
Microsoft Works 6-9 Converter (HKLM\...\{95140000-0137-0407-0000-0000000FF1CE}) (Version: 14.0.6120.5002 - Microsoft Corporation)
Mozilla Firefox 36.0.4 (x86 de) (HKLM\...\Mozilla Firefox 36.0.4 (x86 de)) (Version: 36.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 24.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero Suite (HKLM\...\NeroMultiInstaller!UninstallKey) (Version: - )
No23 Recorder (HKLM\...\{22B0E143-2B0B-435B-9F56-136A3D16065F}) (Version: 2.1.0.3 - No23)
Notepad++ (HKLM\...\Notepad++) (Version: 5.4.5 - )
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - NVIDIA Corporation)
Online Armor 6.0 (HKLM\...\OnlineArmor_is1) (Version: 6.0 - Emsisoft GmbH)
OpenOffice.org 3.1 (HKLM\...\{99E862CC-6F69-4D39-99AA-DBF71BF3B585}) (Version: 3.1.9420 - OpenOffice.org)
OpenVPN 2.1_rc19 (HKLM\...\OpenVPN) (Version: 2.1_rc19 - )
Opera 10.00 (HKLM\...\{2085F05D-24C5-4E27-B7B4-A51DE890FFC9}) (Version: 10.00 - Opera Software ASA)
Opera Stable 17.0.1241.53 (HKLM\...\Opera 17.0.1241.53) (Version: 17.0.1241.53 - Opera Software ASA)
PDF Editor 3 (HKLM\...\PDF Editor 3) (Version: - )
PDF Settings CS4 (Version: 9.0 - Adobe Systems Incorporated) Hidden
Photoshop Camera Raw (Version: 5.0 - Adobe Systems Incorporated) Hidden
PTBSync (Atomuhr Synchronisation & Terminkalender) (HKLM\...\PTBSync) (Version: 5.6 - ElmueSoft)
QuickTime (HKLM\...\{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}) (Version: 7.64.17.73 - Apple Inc.)
Real Alternative 1.9.0 (HKLM\...\RealAlt_is1) (Version: 1.9.0 - )
REALTEK GbE & FE Ethernet PCI-E NIC Driver (HKLM\...\{C9BED750-1211-4480-B1A5-718A3BE15525}) (Version: 1.20.0000 - Realtek)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 5.10.0.5783 - Realtek Semiconductor Corp.)
Rechnungsverwalter (HKU\S-1-5-21-1614895754-2111687655-839522115-500\...\Rechnungsverwalter) (Version: 2.10.30 - Temia Consulting)
RICOH R5C83x/84x Flash Media Controller Driver Ver.3.55.03 (HKLM\...\{59F6A514-9813-47A3-948C-8A155460CC2A}) (Version: 3.55.03 - RICOH)
Safari (HKLM\...\{E56D39F8-2A9F-44B4-B068-A72E45A073E6}) (Version: 4.31.9.1 - Apple Inc.)
Sicherheitsupdate für Microsoft Windows (KB2564958) (HKLM\...\KB2564958) (Version: - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2510531) (HKLM\...\KB2510531-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2544521) (HKLM\...\KB2544521-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2647516) (HKLM\...\KB2647516-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2675157) (HKLM\...\KB2675157-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2699988) (HKLM\...\KB2699988-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2722913) (HKLM\...\KB2722913-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2744842) (HKLM\...\KB2744842-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2761465) (HKLM\...\KB2761465-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2792100) (HKLM\...\KB2792100-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2797052) (HKLM\...\KB2797052-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2799329) (HKLM\...\KB2799329-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2809289) (HKLM\...\KB2809289-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2817183) (HKLM\...\KB2817183-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2829530) (HKLM\...\KB2829530-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2838727) (HKLM\...\KB2838727-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2846071) (HKLM\...\KB2846071-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2847204) (HKLM\...\KB2847204-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2862772) (HKLM\...\KB2862772-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2870699) (HKLM\...\KB2870699-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2879017) (HKLM\...\KB2879017-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2888505) (HKLM\...\KB2888505-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2898785) (HKLM\...\KB2898785-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2909210) (HKLM\...\KB2909210-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2909921) (HKLM\...\KB2909921-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2925418) (HKLM\...\KB2925418-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2936068) (HKLM\...\KB2936068-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Internet Explorer 8 (KB2964358) (HKLM\...\KB2964358-IE8) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows Media Player (KB2378111) (HKLM\...\KB2378111_WM9) (Version: - Microsoft Corporation)
Sicherheitsupdate für Windows Media Player (KB2834902) (HKLM\...\KB2834902_WM10) (Version: - Microsoft Corporation)
Sicherheitsupdate für Windows Media Player (KB2834902-v2) (HKLM\...\KB2834902-v2_WM10) (Version: - Microsoft Corporation)
Sicherheitsupdate für Windows Media Player (KB952069) (HKLM\...\KB952069_WM9) (Version: - Microsoft Corporation)
Sicherheitsupdate für Windows Media Player (KB954155) (HKLM\...\KB954155_WM9) (Version: - Microsoft Corporation)
Sicherheitsupdate für Windows Media Player (KB973540) (HKLM\...\KB973540_WM9) (Version: - Microsoft Corporation)
Sicherheitsupdate für Windows Media Player (KB975558) (HKLM\...\KB975558_WM8) (Version: - Microsoft Corporation)
Sicherheitsupdate für Windows Media Player (KB978695) (HKLM\...\KB978695_WM9) (Version: - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2079403) (HKLM\...\KB2079403) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2115168) (HKLM\...\KB2115168) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2229593) (HKLM\...\KB2229593) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2296011) (HKLM\...\KB2296011) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2347290) (HKLM\...\KB2347290) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2360937) (HKLM\...\KB2360937) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2387149) (HKLM\...\KB2387149) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2393802) (HKLM\...\KB2393802) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2412687) (HKLM\...\KB2412687) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2419632) (HKLM\...\KB2419632) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2423089) (HKLM\...\KB2423089) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2440591) (HKLM\...\KB2440591) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2443105) (HKLM\...\KB2443105) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2476490) (HKLM\...\KB2476490) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2478960) (HKLM\...\KB2478960) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2478971) (HKLM\...\KB2478971) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2481109) (HKLM\...\KB2481109) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2483185) (HKLM\...\KB2483185) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2485663) (HKLM\...\KB2485663) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2506212) (HKLM\...\KB2506212) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2507618) (HKLM\...\KB2507618) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2507938) (HKLM\...\KB2507938) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2508429) (HKLM\...\KB2508429) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2509553) (HKLM\...\KB2509553) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2535512) (HKLM\...\KB2535512) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2536276-v2) (HKLM\...\KB2536276-v2) (Version: 2 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2544893-v2) (HKLM\...\KB2544893-v2) (Version: 2 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2566454) (HKLM\...\KB2566454) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2570222) (HKLM\...\KB2570222) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2570947) (HKLM\...\KB2570947) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2584146) (HKLM\...\KB2584146) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2585542) (HKLM\...\KB2585542) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2592799) (HKLM\...\KB2592799) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2598479) (HKLM\...\KB2598479) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2603381) (HKLM\...\KB2603381) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2618451) (HKLM\...\KB2618451) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2620712) (HKLM\...\KB2620712) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2621440) (HKLM\...\KB2621440) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2624667) (HKLM\...\KB2624667) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2631813) (HKLM\...\KB2631813) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2633171) (HKLM\...\KB2633171) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2641653) (HKLM\...\KB2641653) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2646524) (HKLM\...\KB2646524) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2647518) (HKLM\...\KB2647518) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2653956) (HKLM\...\KB2653956) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2655992) (HKLM\...\KB2655992) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2659262) (HKLM\...\KB2659262) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2660465) (HKLM\...\KB2660465) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2661637) (HKLM\...\KB2661637) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2676562) (HKLM\...\KB2676562) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2685939) (HKLM\...\KB2685939) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2686509) (HKLM\...\KB2686509) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2691442) (HKLM\...\KB2691442) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2695962) (HKLM\...\KB2695962) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2698365) (HKLM\...\KB2698365) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2705219) (HKLM\...\KB2705219) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2707511) (HKLM\...\KB2707511) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2709162) (HKLM\...\KB2709162) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2712808) (HKLM\...\KB2712808) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2719985) (HKLM\...\KB2719985) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2723135) (HKLM\...\KB2723135) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2724197) (HKLM\...\KB2724197) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2727528) (HKLM\...\KB2727528) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2731847) (HKLM\...\KB2731847) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2753842) (HKLM\...\KB2753842) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2753842-v2) (HKLM\...\KB2753842-v2) (Version: 2 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2757638) (HKLM\...\KB2757638) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2758857) (HKLM\...\KB2758857) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2761226) (HKLM\...\KB2761226) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2770660) (HKLM\...\KB2770660) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2778344) (HKLM\...\KB2778344) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2779030) (HKLM\...\KB2779030) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2780091) (HKLM\...\KB2780091) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2799494) (HKLM\...\KB2799494) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2802968) (HKLM\...\KB2802968) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2807986) (HKLM\...\KB2807986) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2808735) (HKLM\...\KB2808735) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2813170) (HKLM\...\KB2813170) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2813345) (HKLM\...\KB2813345) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2820197) (HKLM\...\KB2820197) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2820917) (HKLM\...\KB2820917) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2829361) (HKLM\...\KB2829361) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2834886) (HKLM\...\KB2834886) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2839229) (HKLM\...\KB2839229) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2845187) (HKLM\...\KB2845187) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2847311) (HKLM\...\KB2847311) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2849470) (HKLM\...\KB2849470) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2850851) (HKLM\...\KB2850851) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2850869) (HKLM\...\KB2850869) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2859537) (HKLM\...\KB2859537) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2862152) (HKLM\...\KB2862152) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2862330) (HKLM\...\KB2862330) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2862335) (HKLM\...\KB2862335) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2864063) (HKLM\...\KB2864063) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2868038) (HKLM\...\KB2868038) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2868626) (HKLM\...\KB2868626) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2876217) (HKLM\...\KB2876217) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2876315) (HKLM\...\KB2876315) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2876331) (HKLM\...\KB2876331) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2883150) (HKLM\...\KB2883150) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2892075) (HKLM\...\KB2892075) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2893294) (HKLM\...\KB2893294) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2893984) (HKLM\...\KB2893984) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2898715) (HKLM\...\KB2898715) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2900986) (HKLM\...\KB2900986) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2914368) (HKLM\...\KB2914368) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2916036) (HKLM\...\KB2916036) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2922229) (HKLM\...\KB2922229) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2929961) (HKLM\...\KB2929961) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB2930275) (HKLM\...\KB2930275) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB923561) (HKLM\...\KB923561) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB941569) (HKLM\...\KB941569) (Version: - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB946648) (HKLM\...\KB946648) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB950762) (HKLM\...\KB950762) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB950974) (HKLM\...\KB950974) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB951376-v2) (HKLM\...\KB951376-v2) (Version: 2 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB952004) (HKLM\...\KB952004) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB952954) (HKLM\...\KB952954) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB954459) (HKLM\...\KB954459) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB956572) (HKLM\...\KB956572) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB956744) (HKLM\...\KB956744) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB956802) (HKLM\...\KB956802) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB956844) (HKLM\...\KB956844) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB958644) (HKLM\...\KB958644) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB959426) (HKLM\...\KB959426) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB960803) (HKLM\...\KB960803) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB960859) (HKLM\...\KB960859) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB961501) (HKLM\...\KB961501) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB969059) (HKLM\...\KB969059) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB970430) (HKLM\...\KB970430) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB971657) (HKLM\...\KB971657) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB972270) (HKLM\...\KB972270) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB973507) (HKLM\...\KB973507) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB973869) (HKLM\...\KB973869) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB973904) (HKLM\...\KB973904) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB974112) (HKLM\...\KB974112) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB974318) (HKLM\...\KB974318) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB974392) (HKLM\...\KB974392) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB974571) (HKLM\...\KB974571) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB975025) (HKLM\...\KB975025) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB975467) (HKLM\...\KB975467) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB975560) (HKLM\...\KB975560) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB975713) (HKLM\...\KB975713) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB977816) (HKLM\...\KB977816) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB977914) (HKLM\...\KB977914) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB978338) (HKLM\...\KB978338) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB978542) (HKLM\...\KB978542) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB978601) (HKLM\...\KB978601) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB978706) (HKLM\...\KB978706) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB979309) (HKLM\...\KB979309) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB979482) (HKLM\...\KB979482) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB979687) (HKLM\...\KB979687) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB981322) (HKLM\...\KB981322) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB981997) (HKLM\...\KB981997) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB982132) (HKLM\...\KB982132) (Version: 1 - Microsoft Corporation)
Sicherheitsupdate für Windows XP (KB982665) (HKLM\...\KB982665) (Version: 1 - Microsoft Corporation)
Spelling Dictionaries Support For Adobe Reader 9 (HKLM\...\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
Suite Shared Configuration CS4 (Version: 1.0 - Adobe Systems Incorporated) Hidden
Update für Windows XP (KB2345886) (HKLM\...\KB2345886) (Version: 1 - Microsoft Corporation)
Update für Windows XP (KB2641690) (HKLM\...\KB2641690) (Version: 1 - Microsoft Corporation)
Update für Windows XP (KB2661254-v2) (HKLM\...\KB2661254-v2) (Version: 2 - Microsoft Corporation)
Update für Windows XP (KB2718704) (HKLM\...\KB2718704) (Version: 1 - Microsoft Corporation)
Update für Windows XP (KB2736233) (HKLM\...\KB2736233) (Version: 1 - Microsoft Corporation)
Update für Windows XP (KB2749655) (HKLM\...\KB2749655) (Version: 1 - Microsoft Corporation)
Update für Windows XP (KB2863058) (HKLM\...\KB2863058) (Version: 1 - Microsoft Corporation)
Update für Windows XP (KB2904266) (HKLM\...\KB2904266) (Version: 1 - Microsoft Corporation)
Update für Windows XP (KB2934207) (HKLM\...\KB2934207) (Version: 1 - Microsoft Corporation)
Update für Windows XP (KB898461) (HKLM\...\KB898461) (Version: 1 - Microsoft Corporation)
Update für Windows XP (KB951978) (HKLM\...\KB951978) (Version: 1 - Microsoft Corporation)
Update für Windows XP (KB955759) (HKLM\...\KB955759) (Version: 1 - Microsoft Corporation)
Update für Windows XP (KB968389) (HKLM\...\KB968389) (Version: 1 - Microsoft Corporation)
Update für Windows XP (KB971029) (HKLM\...\KB971029) (Version: 1 - Microsoft Corporation)
Update für Windows XP (KB973687) (HKLM\...\KB973687) (Version: 1 - Microsoft Corporation)
Update für Windows XP (KB973815) (HKLM\...\KB973815) (Version: 1 - Microsoft Corporation)
USB 2.0 2.0M UVC WebCam (HKLM\...\USB 2.0 2.0M UVC WebCam) (Version: - )
VLC media player 1.1.5 (HKLM\...\VLC media player) (Version: 1.1.5 - VideoLAN)
VSO Downloader 4.0.0.18 (HKLM\...\{A0D0BA9E-F1A6-44FF-AA14-03ED96B3D56D}_is1) (Version: 4.0.0.18 - VSO Software)
VSO EVE Network Driver version 1.0.0.26 (HKLM\...\{AC0AFDC9-4FB1-44FE-B3E1-82300BF3D756}_is1) (Version: 1.0.0.26 - VSO Software)
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray (HKLM\...\KB952011) (Version: 1.0 - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows XP Service Pack 3 (HKLM\...\Windows XP Service Pack) (Version: 20080414.031514 - Microsoft Corporation)
WinPcap 4.1.2 (HKLM\...\WinPcapInst) (Version: 4.1.0.2001 - CACE Technologies)
WinPDFEditor V2.0.4 (HKLM\...\WinPDFEditor_is1) (Version: - hxxp://www.WinPDFEditor.com)
WinRAR (HKLM\...\WinRAR archiver) (Version: - )
WinSetupFromUSB (HKU\S-1-5-21-1614895754-2111687655-839522115-500\...\WinSetupFromUSB) (Version: - )
XML Paper Specification Shared Components Language Pack 1.0 (Version: - Microsoft Corporation) Hidden
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{022105BD-948A-40C9-AB42-A3300DDF097F}\localserver32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{035FBE31-3755-450A-A775-5E6BBD43D344}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3. (the data entry has 25 more characters).
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> C:\Programme\Skype\Plugin Manager\ezPMUtils.dll No File
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{095A2EEC-F7FE-42E8-96FB-C20E53081908}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3. (the data entry has 24 more characters).
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{0E55CBE1-B06A-49B6-AD8D-9EFAA0160C6F}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3. (the data entry has 24 more characters).
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3. (the data entry has 23 more characters).
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{1B56A1D1-D2BD-4277-A286-51AAD7CBE87F}\InprocServer32 -> C:\WINDOWS\system32\kernel32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{218D2740-5A50-42A8-AB9F-62FF1B168782}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3. (the data entry has 24 more characters).
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{22181302-A8A6-4F84-A541-E5CBFC70CC43}\localserver32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.26.9\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{29A96789-9595-4947-BEDB-0FCC776F7DB8}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.2. (the data entry has 27 more characters).
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{2F0E2680-9FF5-43C0-B76E-114A56E93598}\localserver32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.26.9\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{320F0FDB-BE0A-4648-9D18-4A2C3448C007}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3. (the data entry has 24 more characters).
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3. (the data entry has 23 more characters).
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 -> C:\Programme\Skype\Plugin Manager\ezPMUtils.dll No File
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{51F9E8EF-59D7-475B-A106-C7EA6F30C119}\localserver32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.26.9\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}\localserver32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Chrome\Application\41.0.2272.101\delegate_execute.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{62A0D750-DED9-448C-B693-406B34BB0892}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3. (the data entry has 25 more characters).
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{634059C0-D264-4B2C-AE80-F73E48D33E5B}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3. (the data entry has 25 more characters).
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3. (the data entry has 25 more characters).
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3. (the data entry has 24 more characters).
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{A45426FB-E444-42B2-AA56-419F8FBEEC61}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3. (the data entry has 23 more characters).
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.26.9\psuser.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{C5A2122B-A05B-4FD8-AE49-91990AE10998}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3. (the data entry has 25 more characters).
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3. (the data entry has 24 more characters).
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 -> C:\Programme\Skype\Plugin Manager\ezPMUtils.dll No File
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{DB25D157-76D4-41C1-97B5-359E4A4CECEB}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3. (the data entry has 24 more characters).
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{E67BE843-BBBE-4484-95FB-05271AE86750}\localserver32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.26.9\GoogleUpdateOnDemand.exe (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3.26.9\psuser.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{EB06378B-ABB6-4B3C-9B40-D488DD8A6E93}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3. (the data entry has 23 more characters).
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\localserver32 -> C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\B320\temp\VSO Downloader 4.2.6.2 Full Crack Keygen.exe No Fil (the data entry has 1 more characters).
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{FB994D36-B312-46CE-A40B-CF63980641F9}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3. (the data entry has 25 more characters).
CustomCLSID: HKU\S-1-5-21-1614895754-2111687655-839522115-500_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\1.3. (the data entry has 23 more characters).
==================== Restore Points =========================
25-12-2014 02:54:04 Software Distribution Service 3.0
26-12-2014 07:50:01 Systemprüfpunkt
27-12-2014 08:13:00 Systemprüfpunkt
28-12-2014 08:24:27 Systemprüfpunkt
29-12-2014 09:11:58 Systemprüfpunkt
30-12-2014 09:31:47 Systemprüfpunkt
31-12-2014 10:43:51 Systemprüfpunkt
01-01-2015 11:18:28 Systemprüfpunkt
02-01-2015 11:19:31 Systemprüfpunkt
03-01-2015 11:22:26 Systemprüfpunkt
04-01-2015 12:18:26 Systemprüfpunkt
05-01-2015 16:20:07 Systemprüfpunkt
06-01-2015 17:14:10 Systemprüfpunkt
07-01-2015 19:28:25 Systemprüfpunkt
09-01-2015 12:17:49 Systemprüfpunkt
11-01-2015 09:14:57 Systemprüfpunkt
13-01-2015 10:41:05 Systemprüfpunkt
14-01-2015 12:39:12 Software Distribution Service 3.0
16-01-2015 01:36:20 Systemprüfpunkt
17-01-2015 12:47:59 Systemprüfpunkt
18-01-2015 18:01:54 Systemprüfpunkt
19-01-2015 18:38:25 Systemprüfpunkt
20-01-2015 20:18:10 Systemprüfpunkt
21-01-2015 22:44:22 Systemprüfpunkt
22-01-2015 11:56:04 Wiederherstellungsvorgang
22-01-2015 12:04:49 Wiederherstellungsvorgang
23-01-2015 13:15:47 Systemprüfpunkt
24-01-2015 21:07:52 Systemprüfpunkt
25-01-2015 21:33:50 Systemprüfpunkt
27-01-2015 00:29:13 Systemprüfpunkt
28-01-2015 04:05:01 Systemprüfpunkt
29-01-2015 04:27:59 Systemprüfpunkt
30-01-2015 05:27:58 Systemprüfpunkt
31-01-2015 05:30:55 Systemprüfpunkt
01-02-2015 08:14:42 Systemprüfpunkt
03-02-2015 18:29:27 Systemprüfpunkt
04-02-2015 19:38:37 Systemprüfpunkt
06-02-2015 07:20:18 Systemprüfpunkt
07-02-2015 07:43:37 Systemprüfpunkt
08-02-2015 10:18:02 Systemprüfpunkt
09-02-2015 20:33:47 Systemprüfpunkt
11-02-2015 04:11:58 Systemprüfpunkt
12-02-2015 04:43:28 Systemprüfpunkt
13-02-2015 06:17:02 Systemprüfpunkt
13-02-2015 16:10:18 Software Distribution Service 3.0
14-02-2015 16:59:35 Systemprüfpunkt
16-02-2015 04:48:30 Systemprüfpunkt
17-02-2015 05:08:39 Systemprüfpunkt
18-02-2015 06:20:39 Systemprüfpunkt
19-02-2015 07:55:41 Systemprüfpunkt
20-02-2015 08:33:30 Systemprüfpunkt
21-02-2015 09:01:58 Systemprüfpunkt
22-02-2015 09:27:29 Systemprüfpunkt
23-02-2015 09:32:32 Systemprüfpunkt
24-02-2015 10:44:00 Systemprüfpunkt
25-02-2015 14:25:02 Systemprüfpunkt
26-02-2015 19:57:31 Wiederherstellungsvorgang
27-02-2015 22:50:10 Systemprüfpunkt
01-03-2015 08:18:50 Systemprüfpunkt
02-03-2015 13:10:57 Systemprüfpunkt
03-03-2015 20:46:56 Systemprüfpunkt
04-03-2015 21:34:05 Systemprüfpunkt
06-03-2015 03:55:45 Systemprüfpunkt
07-03-2015 11:11:51 Systemprüfpunkt
08-03-2015 22:47:56 Systemprüfpunkt
10-03-2015 07:47:51 Systemprüfpunkt
11-03-2015 08:30:08 Systemprüfpunkt
11-03-2015 12:53:44 Software Distribution Service 3.0
12-03-2015 15:52:03 Systemprüfpunkt
14-03-2015 02:30:38 Systemprüfpunkt
15-03-2015 04:27:49 Systemprüfpunkt
16-03-2015 08:01:50 Systemprüfpunkt
17-03-2015 08:07:48 Systemprüfpunkt
18-03-2015 09:19:18 Systemprüfpunkt
18-03-2015 15:30:36 M
18-03-2015 16:11:13 Wiederherstellungsvorgang
20-03-2015 03:24:31 Systemprüfpunkt
21-03-2015 03:51:21 Systemprüfpunkt
21-03-2015 20:54:31 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
21-03-2015 20:57:00 Nero BurningROM 2015 wurde installiert.
21-03-2015 21:07:49 Nero Prerequisite Installer 4.0 wurde installiert.
21-03-2015 21:25:10 Nero Info wurde entfernt.
21-03-2015 21:25:39 Nero Prerequisite Installer 4.0 wurde entfernt.
21-03-2015 21:26:20 Nero BurningROM 2015 wurde entfernt.
22-03-2015 22:44:02 Systemprüfpunkt
23-03-2015 13:41:55 M
24-03-2015 01:32:05 Wiederherstellungsvorgang
24-03-2015 01:42:59 Wiederherstellungsvorgang
24-03-2015 13:05:58 M vor avast
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2004-11-11 13:00 - 2013-10-29 11:47 - 00000027 ____N C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Ad-Aware Antivirus Scheduled Scan.job => C:\PROGRA~1\AD-AWA~1\AdAwareLauncher.exe
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\Ende des Supports für Microsoft Windows XP – Benachrichtigung – Anmeldung.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Ende des Supports für Microsoft Windows XP – Monatliche Benachrichtigung.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1614895754-2111687655-839522115-500Core.job => C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1614895754-2111687655-839522115-500UA.job => C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{0CEFF4B8-E96E-4120-A390-3E269CFA52BD}.job => C:\WINDOWS\system32\msfeedssync.exe
==================== Loaded Modules (whitelisted) ==============
2009-01-10 23:15 - 2009-01-10 23:15 - 00159744 _____ () C:\WINDOWS\system32\mmfinfo.dll
2009-01-10 23:14 - 2009-01-10 23:14 - 00023552 _____ () C:\WINDOWS\system32\mkunicode.dll
2009-08-23 10:17 - 2009-08-16 16:06 - 00141312 _____ () C:\Programme\WinRAR\rarext.dll
2012-12-19 03:52 - 2012-07-20 14:42 - 00652800 _____ () C:\Programme\IZArc\IZArcCM.dll
2015-03-13 18:21 - 2015-03-13 18:21 - 16858288 _____ () C:\WINDOWS\system32\Macromed\Flash\NPSWF32_17_0_0_134.dll
2015-03-24 15:00 - 2015-03-24 15:00 - 00050477 _____ () C:\Dokumente und Einstellungen\Administrator\Desktop\Defogger.exe
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1614895754-2111687655-839522115-500\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 83.169.186.161 - 83.169.186.225
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
MSCONFIG\startupreg: Ad-Aware Browsing Protection => "C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Ad-Aware Browsing Protection\adawarebp.exe"
MSCONFIG\startupreg: Adobe ARM => "C:\Programme\Gemeinsame Dateien\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: BitTorrent => "C:\Programme\BitTorrent.exe" /MINIMIZED
MSCONFIG\startupreg: ctfmon.exe => C:\WINDOWS\system32\ctfmon.exe
MSCONFIG\startupreg: Google Update => "C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: PDFPrint => C:\Programme\PDF24\pdf24.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Programme\QuickTime\qttask.exe" -atboottime
MSCONFIG\startupreg: RTHDCPL => RTHDCPL.EXE
MSCONFIG\startupreg: UnlockerAssistant => "C:\Programme\Unlocker\UnlockerAssistant.exe"
==================== Accounts: =============================
Administrator (S-1-5-21-1614895754-2111687655-839522115-500 - Administrator - Enabled) => %SystemDrive%\Dokumente und Einstellungen\Administrator
fbwuser (S-1-5-21-1614895754-2111687655-839522115-1003 - Limited - Enabled)
Gast (S-1-5-21-1614895754-2111687655-839522115-501 - Limited - Enabled)
Hilfeassistent (S-1-5-21-1614895754-2111687655-839522115-1000 - Limited - Disabled)
SUPPORT_388945a0 (S-1-5-21-1614895754-2111687655-839522115-1002 - Limited - Disabled)
==================== Faulty Device Manager Devices =============
Name:
Description:
Class Guid: {4D36E972-E325-11CE-BFC1-08002BE10318}
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (03/24/2015 01:31:54 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlgeschlagene Anwendung plugin-container.exe, Version 36.0.4.5557, fehlgeschlagenes Modul mozalloc.dll, Version 36.0.4.5557, Fehleradresse 0x00001e02.
Das medienspezifische Ereignis für [plugin-container.exe!ws!] wird verarbeitet.
Error: (03/24/2015 02:48:17 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlgeschlagene Anwendung plugin-container.exe, Version 36.0.4.5557, fehlgeschlagenes Modul mozalloc.dll, Version 36.0.4.5557, Fehleradresse 0x00001e02.
Das medienspezifische Ereignis für [plugin-container.exe!ws!] wird verarbeitet.
Error: (03/22/2015 10:28:13 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Stillstehende Anwendung Studio.exe, Version 1.0.0.488, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error: (03/21/2015 11:22:36 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Stillstehende Anwendung plugin-container.exe, Version 36.0.3.5556, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error: (03/21/2015 09:50:34 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Stillstehende Anwendung nero.exe, Version 6.6.0.8, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error: (03/21/2015 09:38:24 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Stillstehende Anwendung msiexec.exe, Version 4.5.6001.22159, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000.
Error: (03/21/2015 09:25:55 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlgeschlagene Anwendung nerolauncher.exe, Version 16.0.14.0, fehlgeschlagenes Modul unknown, Version 0.0.0.0, Fehleradresse 0xf8093e46.
Das medienspezifische Ereignis für [nerolauncher.exe!ws!] wird verarbeitet.
Error: (03/21/2015 09:22:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlgeschlagene Anwendung nerolauncher.exe, Version 16.0.14.0, fehlgeschlagenes Modul unknown, Version 0.0.0.0, Fehleradresse 0xf8093e46.
Das medienspezifische Ereignis für [nerolauncher.exe!ws!] wird verarbeitet.
Error: (03/21/2015 09:22:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlgeschlagene Anwendung nerolauncher.exe, Version 16.0.14.0, fehlgeschlagenes Modul unknown, Version 0.0.0.0, Fehleradresse 0xf8093e46.
Das medienspezifische Ereignis für [nerolauncher.exe!ws!] wird verarbeitet.
Error: (03/21/2015 09:21:44 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlgeschlagene Anwendung nerolauncher.exe, Version 16.0.14.0, fehlgeschlagenes Modul unknown, Version 0.0.0.0, Fehleradresse 0xf8093e46.
Das medienspezifische Ereignis für [nerolauncher.exe!ws!] wird verarbeitet.
System errors:
=============
Error: (03/24/2015 02:45:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Nero BackItUp Scheduler 4.0" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (03/24/2015 02:45:43 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Hotspot Shield Routing Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (03/24/2015 02:45:43 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Zeitüberschreitung (30000 ms) beim Verbindungsversuch mit Dienst DeltaFix.
Error: (03/24/2015 02:17:17 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Intel® PROSet/Wireless Event Log" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (03/24/2015 02:17:17 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Atomuhr Synchronisation" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (03/24/2015 02:17:17 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Druckwarteschlange" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (03/24/2015 02:17:17 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Online Armor Helper Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (03/24/2015 02:12:12 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Nero BackItUp Scheduler 4.0" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (03/24/2015 02:12:12 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Hotspot Shield Routing Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (03/24/2015 02:12:12 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Zeitüberschreitung (30000 ms) beim Verbindungsversuch mit Dienst DeltaFix.
Microsoft Office Sessions:
=========================
Error: (03/24/2015 01:31:54 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe36.0.4.5557mozalloc.dll36.0.4.555700001e02
Error: (03/24/2015 02:48:17 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe36.0.4.5557mozalloc.dll36.0.4.555700001e02
Error: (03/22/2015 10:28:13 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Studio.exe1.0.0.488hungapp0.0.0.000000000
Error: (03/21/2015 11:22:36 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: plugin-container.exe36.0.3.5556hungapp0.0.0.000000000
Error: (03/21/2015 09:50:34 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: nero.exe6.6.0.8hungapp0.0.0.000000000
Error: (03/21/2015 09:38:24 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: msiexec.exe4.5.6001.22159hungapp0.0.0.000000000
Error: (03/21/2015 09:25:55 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: nerolauncher.exe16.0.14.0unknown0.0.0.0f8093e46
Error: (03/21/2015 09:22:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: nerolauncher.exe16.0.14.0unknown0.0.0.0f8093e46
Error: (03/21/2015 09:22:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: nerolauncher.exe16.0.14.0unknown0.0.0.0f8093e46
Error: (03/21/2015 09:21:44 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: nerolauncher.exe16.0.14.0unknown0.0.0.0f8093e46
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Duo CPU T5900 @ 2.20GHz
Percentage of memory in use: 45%
Total physical RAM: 2047.04 MB
Available physical RAM: 1123.89 MB
Total Pagefile: 4963.95 MB
Available Pagefile: 3814.55 MB
Total Virtual: 2047.88 MB
Available Virtual: 1918.05 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:202.17 GB) (Free:109.8 GB) NTFS ==>[Drive with boot components (Windows XP)]
Drive d: (Daten) (Fixed) (Total:30.72 GB) (Free:9.16 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 232.9 GB) (Disk ID: 552D552D)
Partition 1: (Active) - (Size=202.2 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=30.7 GB) - (Type=OF Extended)
==================== End Of Log ============================ --- --- ---
GMER Logfile: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-03-24 15:53:41
Windows 5.1.2600 Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST9250320AS rev.0303 232,89GB
Running: Gmer-19357.exe; Driver: C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\pxtdapow.sys
---- System - GMER 2.1 ----
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwAllocateVirtualMemory [0xB5325464]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwAssignProcessToJobObject [0xB532495E]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwConnectPort [0xB5323682]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateFile [0xB532A3A6]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateKey [0xB532C77C]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreatePort [0xB53234A0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateProcess [0xB5324F20]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateProcessEx [0xB5321940]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateSection [0xB53214BA]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwCreateThread [0xB5322662]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwDebugActiveProcess [0xB5322D54]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwDuplicateObject [0xB5323362]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwLoadDriver [0xB5324386]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwOpenFile [0xB532A724]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwOpenProcess [0xB53222D0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwOpenSection [0xB532177C]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwOpenThread [0xB53228DE]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwProtectVirtualMemory [0xB5324710]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwQueueApcThread [0xB5324A7A]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwRequestPort [0xB5323CE6]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwRequestWaitReplyPort [0xB532404E]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwRestoreKey [0xB532A19E]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwResumeThread [0xB5323102]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSecureConnectPort [0xB53238A4]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSetContextThread [0xB5322BFC]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSetSystemInformation [0xB5325118]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwShutdownSystem [0xB53242C0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSuspendProcess [0xB5323234]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSuspendThread [0xB5322FAC]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwSystemDebugControl [0xB5322E72]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwTerminateProcess [0xB53224A0]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwTerminateThread [0xB5322A94]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwUnloadDriver [0xB532454E]
SSDT \??\C:\WINDOWS\system32\drivers\OADriver.sys ZwWriteVirtualMemory [0xB532483A]
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2D40 80504628 12 Bytes [A0, 34, 32, B5, 20, 4F, 32, ...] {MOV AL, [0x20b53234]; DEC EDI; XOR DH, [EBP-0x4acde6c0]}
.text ntkrnlpa.exe!ZwCallbackReturn + 307C 80504964 12 Bytes [34, 32, 32, B5, AC, 2F, 32, ...]
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB70FC360, 0x33A1AD, 0xE8000020]
init C:\WINDOWS\system32\drivers\mmrtkrnl.sys entry point in "init" section [0xB8230CA0]
---- User code sections - GMER 2.1 ----
.text C:\Programme\PTBSync\PTBSync.exe[396] ntdll.dll!NtCreateFile 7C91D0AE 1 Byte [FF]
.text C:\Programme\PTBSync\PTBSync.exe[396] ntdll.dll!NtCreateFile 7C91D0AE 3 Bytes [FF, 25, 1E]
.text C:\Programme\PTBSync\PTBSync.exe[396] ntdll.dll!NtCreateFile + 4 7C91D0B2 2 Bytes [76, 71] {JBE 0x73}
.text C:\Programme\PTBSync\PTBSync.exe[396] ntdll.dll!NtDeleteValueKey 7C91D26E 3 Bytes [FF, 25, 1E]
.text C:\Programme\PTBSync\PTBSync.exe[396] ntdll.dll!NtDeleteValueKey + 4 7C91D272 2 Bytes [7C, 71] {JL 0x73}
.text C:\Programme\PTBSync\PTBSync.exe[396] ntdll.dll!NtOpenFile 7C91D59E 3 Bytes [FF, 25, 1E]
.text C:\Programme\PTBSync\PTBSync.exe[396] ntdll.dll!NtOpenFile + 4 7C91D5A2 2 Bytes [73, 71] {JAE 0x73}
.text C:\Programme\PTBSync\PTBSync.exe[396] ntdll.dll!NtOpenProcess 7C91D5FE 3 Bytes [FF, 25, 1E]
.text C:\Programme\PTBSync\PTBSync.exe[396] ntdll.dll!NtOpenProcess + 4 7C91D602 2 Bytes [79, 71] {JNS 0x73}
.text C:\Programme\PTBSync\PTBSync.exe[396] ntdll.dll!NtSetContextThread 7C91DBAE 3 Bytes [FF, 25, 1E]
.text C:\Programme\PTBSync\PTBSync.exe[396] ntdll.dll!NtSetContextThread + 4 7C91DBB2 2 Bytes [6D, 71]
.text C:\Programme\PTBSync\PTBSync.exe[396] ntdll.dll!NtSetInformationFile 7C91DC5E 3 Bytes [FF, 25, 1E]
.text C:\Programme\PTBSync\PTBSync.exe[396] ntdll.dll!NtSetInformationFile + 4 7C91DC62 2 Bytes [70, 71] {JO 0x73}
.text C:\Programme\PTBSync\PTBSync.exe[396] ntdll.dll!NtSetValueKey 7C91DDCE 3 Bytes [FF, 25, 1E]
.text C:\Programme\PTBSync\PTBSync.exe[396] ntdll.dll!NtSetValueKey + 4 7C91DDD2 2 Bytes [7F, 71] {JG 0x73}
.text C:\Programme\PTBSync\PTBSync.exe[396] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AF0001
.text C:\Programme\PTBSync\PTBSync.exe[396] kernel32.dll!CreateProcessInternalW 7C8185EC 3 Bytes [FF, 25, 1E]
.text C:\Programme\PTBSync\PTBSync.exe[396] kernel32.dll!CreateProcessInternalW + 4 7C8185F0 2 Bytes [6A, 71] {PUSH 0x71}
.text C:\Programme\PTBSync\PTBSync.exe[396] ADVAPI32.dll!CreateServiceA 77E07211 6 Bytes JMP 7186000A
.text C:\Programme\PTBSync\PTBSync.exe[396] ADVAPI32.dll!CreateServiceW 77E073A9 6 Bytes JMP 7183000A
.text C:\Programme\PTBSync\PTBSync.exe[396] USER32.dll!PostMessageW 7E368CCB 6 Bytes JMP 7189000A
.text C:\Programme\PTBSync\PTBSync.exe[396] USER32.dll!SendMessageW 7E37929A 6 Bytes JMP 718F000A
.text C:\Programme\PTBSync\PTBSync.exe[396] USER32.dll!PostMessageA 7E37AAFD 6 Bytes JMP 718C000A
.text C:\Programme\PTBSync\PTBSync.exe[396] USER32.dll!SendInput 7E37F140 3 Bytes [FF, 25, 1E]
.text C:\Programme\PTBSync\PTBSync.exe[396] USER32.dll!SendInput + 4 7E37F144 2 Bytes [94, 71]
.text C:\Programme\PTBSync\PTBSync.exe[396] USER32.dll!SendMessageA 7E37F3C2 6 Bytes JMP 7192000A
.text C:\Programme\PTBSync\PTBSync.exe[396] USER32.dll!mouse_event 7E3B673F 6 Bytes JMP 719B000A
.text C:\Programme\PTBSync\PTBSync.exe[396] USER32.dll!keybd_event 7E3B6783 6 Bytes JMP 7198000A
.text C:\Programme\PTBSync\PTBSync.exe[396] WS2_32.dll!WSALookupServiceBeginW 71A135EF 6 Bytes JMP 719E000A
.text C:\Programme\PTBSync\PTBSync.exe[396] WS2_32.dll!connect 71A14A07 6 Bytes JMP 71AB000A
.text C:\Programme\PTBSync\PTBSync.exe[396] WS2_32.dll!listen 71A18CD3 6 Bytes JMP 71A5000A
.text C:\Programme\PTBSync\PTBSync.exe[396] WS2_32.dll!WSAConnect 71A20C81 6 Bytes JMP 71A8000A
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] ntdll.dll!NtCreateFile 7C91D0AE 1 Byte [FF]
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] ntdll.dll!NtCreateFile 7C91D0AE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] ntdll.dll!NtCreateFile + 4 7C91D0B2 2 Bytes [86, 71]
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] ntdll.dll!NtDeleteValueKey 7C91D26E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] ntdll.dll!NtDeleteValueKey + 4 7C91D272 2 Bytes [8C, 71]
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] ntdll.dll!NtOpenFile 7C91D59E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] ntdll.dll!NtOpenFile + 4 7C91D5A2 2 Bytes [83, 71]
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] ntdll.dll!NtOpenProcess 7C91D5FE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] ntdll.dll!NtOpenProcess + 4 7C91D602 2 Bytes [89, 71]
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] ntdll.dll!NtSetContextThread 7C91DBAE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] ntdll.dll!NtSetContextThread + 4 7C91DBB2 2 Bytes [7D, 71] {JGE 0x73}
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] ntdll.dll!NtSetInformationFile 7C91DC5E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] ntdll.dll!NtSetInformationFile + 4 7C91DC62 2 Bytes [80, 71]
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] ntdll.dll!NtSetValueKey 7C91DDCE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] ntdll.dll!NtSetValueKey + 4 7C91DDD2 2 Bytes [8F, 71]
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AF0001
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] kernel32.dll!CreateProcessInternalW 7C8185EC 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] kernel32.dll!CreateProcessInternalW + 4 7C8185F0 2 Bytes [7A, 71] {JP 0x73}
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] USER32.dll!PostMessageW 7E368CCB 6 Bytes JMP 7199000A
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] USER32.dll!SendMessageW 7E37929A 6 Bytes JMP 719F000A
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] USER32.dll!PostMessageA 7E37AAFD 6 Bytes JMP 719C000A
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] USER32.dll!SendInput 7E37F140 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] USER32.dll!SendInput + 4 7E37F144 2 Bytes [A4, 71]
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] USER32.dll!SendMessageA 7E37F3C2 6 Bytes JMP 71A2000A
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] USER32.dll!mouse_event 7E3B673F 6 Bytes JMP 71AB000A
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] USER32.dll!keybd_event 7E3B6783 6 Bytes JMP 71A8000A
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] ADVAPI32.dll!CreateServiceA 77E07211 6 Bytes JMP 7196000A
.text C:\WINDOWS\system32\RUNDLL32.EXE[424] ADVAPI32.dll!CreateServiceW 77E073A9 6 Bytes JMP 7193000A
.text C:\WINDOWS\system32\ctfmon.exe[548] ntdll.dll!NtCreateFile 7C91D0AE 1 Byte [FF]
.text C:\WINDOWS\system32\ctfmon.exe[548] ntdll.dll!NtCreateFile 7C91D0AE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[548] ntdll.dll!NtCreateFile + 4 7C91D0B2 2 Bytes [86, 71]
.text C:\WINDOWS\system32\ctfmon.exe[548] ntdll.dll!NtDeleteValueKey 7C91D26E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[548] ntdll.dll!NtDeleteValueKey + 4 7C91D272 2 Bytes [8C, 71]
.text C:\WINDOWS\system32\ctfmon.exe[548] ntdll.dll!NtOpenFile 7C91D59E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[548] ntdll.dll!NtOpenFile + 4 7C91D5A2 2 Bytes [83, 71]
.text C:\WINDOWS\system32\ctfmon.exe[548] ntdll.dll!NtOpenProcess 7C91D5FE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[548] ntdll.dll!NtOpenProcess + 4 7C91D602 2 Bytes [89, 71]
.text C:\WINDOWS\system32\ctfmon.exe[548] ntdll.dll!NtSetContextThread 7C91DBAE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[548] ntdll.dll!NtSetContextThread + 4 7C91DBB2 2 Bytes [7D, 71] {JGE 0x73}
.text C:\WINDOWS\system32\ctfmon.exe[548] ntdll.dll!NtSetInformationFile 7C91DC5E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[548] ntdll.dll!NtSetInformationFile + 4 7C91DC62 2 Bytes [80, 71]
.text C:\WINDOWS\system32\ctfmon.exe[548] ntdll.dll!NtSetValueKey 7C91DDCE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[548] ntdll.dll!NtSetValueKey + 4 7C91DDD2 2 Bytes [8F, 71]
.text C:\WINDOWS\system32\ctfmon.exe[548] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AF0001
.text C:\WINDOWS\system32\ctfmon.exe[548] kernel32.dll!CreateProcessInternalW 7C8185EC 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[548] kernel32.dll!CreateProcessInternalW + 4 7C8185F0 2 Bytes [7A, 71] {JP 0x73}
.text C:\WINDOWS\system32\ctfmon.exe[548] ADVAPI32.dll!CreateServiceA 77E07211 6 Bytes JMP 7196000A
.text C:\WINDOWS\system32\ctfmon.exe[548] ADVAPI32.dll!CreateServiceW 77E073A9 6 Bytes JMP 7193000A
.text C:\WINDOWS\system32\ctfmon.exe[548] USER32.dll!PostMessageW 7E368CCB 6 Bytes JMP 7199000A
.text C:\WINDOWS\system32\ctfmon.exe[548] USER32.dll!SendMessageW 7E37929A 6 Bytes JMP 719F000A
.text C:\WINDOWS\system32\ctfmon.exe[548] USER32.dll!PostMessageA 7E37AAFD 6 Bytes JMP 719C000A
.text C:\WINDOWS\system32\ctfmon.exe[548] USER32.dll!SendInput 7E37F140 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[548] USER32.dll!SendInput + 4 7E37F144 2 Bytes [A4, 71]
.text C:\WINDOWS\system32\ctfmon.exe[548] USER32.dll!SendMessageA 7E37F3C2 6 Bytes JMP 71A2000A
.text C:\WINDOWS\system32\ctfmon.exe[548] USER32.dll!mouse_event 7E3B673F 6 Bytes JMP 71AB000A
.text C:\WINDOWS\system32\ctfmon.exe[548] USER32.dll!keybd_event 7E3B6783 6 Bytes JMP 71A8000A
.text C:\Programme\Emsisoft Anti-Malware\a2service.exe[1104] kernel32.dll!ReadFile + 211 7C801A23 7 Bytes JMP 061881B4 C:\Programme\Emsisoft Anti-Malware\a2update.dll
.text C:\Programme\Emsisoft Anti-Malware\a2service.exe[1104] kernel32.dll!ExitThread 7C80C0F8 7 Bytes JMP 004F97FC C:\Programme\Emsisoft Anti-Malware\a2service.exe
.text C:\Programme\Emsisoft Anti-Malware\a2service.exe[1104] kernel32.dll!CreateRemoteThread + 206 7C810702 7 Bytes JMP 061D866C C:\Programme\Emsisoft Anti-Malware\a2update.dll
.text C:\WINDOWS\Explorer.EXE[1952] ntdll.dll!NtCreateFile 7C91D0AE 1 Byte [FF]
.text C:\WINDOWS\Explorer.EXE[1952] ntdll.dll!NtCreateFile 7C91D0AE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[1952] ntdll.dll!NtCreateFile + 4 7C91D0B2 2 Bytes [86, 71]
.text C:\WINDOWS\Explorer.EXE[1952] ntdll.dll!NtDeleteValueKey 7C91D26E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[1952] ntdll.dll!NtDeleteValueKey + 4 7C91D272 2 Bytes [8C, 71]
.text C:\WINDOWS\Explorer.EXE[1952] ntdll.dll!NtOpenFile 7C91D59E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[1952] ntdll.dll!NtOpenFile + 4 7C91D5A2 2 Bytes [83, 71]
.text C:\WINDOWS\Explorer.EXE[1952] ntdll.dll!NtOpenProcess 7C91D5FE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[1952] ntdll.dll!NtOpenProcess + 4 7C91D602 2 Bytes [89, 71]
.text C:\WINDOWS\Explorer.EXE[1952] ntdll.dll!NtSetContextThread 7C91DBAE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[1952] ntdll.dll!NtSetContextThread + 4 7C91DBB2 2 Bytes [7D, 71] {JGE 0x73}
.text C:\WINDOWS\Explorer.EXE[1952] ntdll.dll!NtSetInformationFile 7C91DC5E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[1952] ntdll.dll!NtSetInformationFile + 4 7C91DC62 2 Bytes [80, 71]
.text C:\WINDOWS\Explorer.EXE[1952] ntdll.dll!NtSetValueKey 7C91DDCE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[1952] ntdll.dll!NtSetValueKey + 4 7C91DDD2 2 Bytes [8F, 71]
.text C:\WINDOWS\Explorer.EXE[1952] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AF0001
.text C:\WINDOWS\Explorer.EXE[1952] kernel32.dll!CreateProcessInternalW 7C8185EC 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[1952] kernel32.dll!CreateProcessInternalW + 4 7C8185F0 2 Bytes [7A, 71] {JP 0x73}
.text C:\WINDOWS\Explorer.EXE[1952] ADVAPI32.dll!CreateServiceA 77E07211 6 Bytes JMP 7196000A
.text C:\WINDOWS\Explorer.EXE[1952] ADVAPI32.dll!CreateServiceW 77E073A9 6 Bytes JMP 7193000A
.text C:\WINDOWS\Explorer.EXE[1952] USER32.dll!PostMessageW 7E368CCB 6 Bytes JMP 7199000A
.text C:\WINDOWS\Explorer.EXE[1952] USER32.dll!SendMessageW 7E37929A 6 Bytes JMP 719F000A
.text C:\WINDOWS\Explorer.EXE[1952] USER32.dll!PostMessageA 7E37AAFD 6 Bytes JMP 719C000A
.text C:\WINDOWS\Explorer.EXE[1952] USER32.dll!SendInput 7E37F140 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[1952] USER32.dll!SendInput + 4 7E37F144 2 Bytes [A4, 71]
.text C:\WINDOWS\Explorer.EXE[1952] USER32.dll!SendMessageA 7E37F3C2 6 Bytes JMP 71A2000A
.text C:\WINDOWS\Explorer.EXE[1952] USER32.dll!mouse_event 7E3B673F 6 Bytes JMP 71AB000A
.text C:\WINDOWS\Explorer.EXE[1952] USER32.dll!keybd_event 7E3B6783 6 Bytes JMP 71A8000A
.text C:\WINDOWS\Explorer.EXE[1952] WS2_32.dll!WSALookupServiceBeginW 00F235EF 6 Bytes JMP 716F000A
.text C:\WINDOWS\Explorer.EXE[1952] WS2_32.dll!connect 00F24A07 6 Bytes JMP 7178000A
.text C:\WINDOWS\Explorer.EXE[1952] WS2_32.dll!listen 00F28CD3 6 Bytes JMP 7172000A
.text C:\WINDOWS\Explorer.EXE[1952] WS2_32.dll!WSAConnect 00F30C81 6 Bytes JMP 7175000A
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!NtCreateFile 7C91D0AE 1 Byte [FF]
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!NtCreateFile 7C91D0AE 3 Bytes [FF, 25, 1E]
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!NtCreateFile + 4 7C91D0B2 2 Bytes [86, 71]
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!NtDeleteValueKey 7C91D26E 3 Bytes [FF, 25, 1E]
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!NtDeleteValueKey + 4 7C91D272 2 Bytes [8C, 71]
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!NtFlushBuffersFile 7C91D32E 5 Bytes JMP 013DF0A2 C:\Programme\Mozilla Firefox\xul.dll
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!NtOpenFile 7C91D59E 3 Bytes [FF, 25, 1E]
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!NtOpenFile + 4 7C91D5A2 2 Bytes [83, 71]
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!NtOpenProcess 7C91D5FE 3 Bytes [FF, 25, 1E]
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!NtOpenProcess + 4 7C91D602 2 Bytes [89, 71]
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!NtQueryFullAttributesFile 7C91D7AE 5 Bytes JMP 013DF157 C:\Programme\Mozilla Firefox\xul.dll
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!NtReadFile 7C91D9CE 5 Bytes JMP 013DF2DF C:\Programme\Mozilla Firefox\xul.dll
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!NtReadFileScatter 7C91D9DE 5 Bytes JMP 01869BC8 C:\Programme\Mozilla Firefox\xul.dll
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!NtSetContextThread 7C91DBAE 3 Bytes [FF, 25, 1E]
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!NtSetContextThread + 4 7C91DBB2 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!NtSetInformationFile 7C91DC5E 3 Bytes [FF, 25, 1E]
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!NtSetInformationFile + 4 7C91DC62 2 Bytes [80, 71]
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!NtSetValueKey 7C91DDCE 3 Bytes [FF, 25, 1E]
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!NtSetValueKey + 4 7C91DDD2 2 Bytes [8F, 71]
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!NtWriteFile 7C91DF7E 5 Bytes JMP 013DF53E C:\Programme\Mozilla Firefox\xul.dll
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!NtWriteFileGather 7C91DF8E 5 Bytes JMP 01869C18 C:\Programme\Mozilla Firefox\xul.dll
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ntdll.dll!LdrLoadDll 7C92632D 5 Bytes JMP 00A998D2 C:\Programme\Mozilla Firefox\mozglue.dll
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AF0001
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] kernel32.dll!lstrlenW + 43 7C809AEC 7 Bytes JMP 01856171 C:\Programme\Mozilla Firefox\xul.dll
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] kernel32.dll!MapViewOfFileEx + 6A 7C80B9A0 7 Bytes JMP 01854446 C:\Programme\Mozilla Firefox\xul.dll
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] kernel32.dll!CreateProcessInternalW 7C8185EC 3 Bytes [FF, 25, 1E]
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] kernel32.dll!CreateProcessInternalW + 4 7C8185F0 2 Bytes [7A, 71] {JP 0x73}
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] kernel32.dll!ValidateLocale + B648 7C844EE0 7 Bytes JMP 015FEECB C:\Programme\Mozilla Firefox\xul.dll
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] USER32.dll!PostMessageW 7E368CCB 6 Bytes JMP 7199000A
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] USER32.dll!SendMessageW 7E37929A 6 Bytes JMP 719F000A
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] USER32.dll!PostMessageA 7E37AAFD 6 Bytes JMP 719C000A
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] USER32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 0236A419 C:\Programme\Mozilla Firefox\xul.dll
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] USER32.dll!SendInput 7E37F140 3 Bytes [FF, 25, 1E]
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] USER32.dll!SendInput + 4 7E37F144 2 Bytes [A4, 71]
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] USER32.dll!SendMessageA 7E37F3C2 6 Bytes JMP 71A2000A
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] USER32.dll!mouse_event 7E3B673F 6 Bytes JMP 71AB000A
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] USER32.dll!keybd_event 7E3B6783 6 Bytes JMP 71A8000A
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] GDI32.dll!SetDIBitsToDevice + 20A 77EF9E14 7 Bytes JMP 018529F1 C:\Programme\Mozilla Firefox\xul.dll
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ADVAPI32.dll!CreateServiceA 77E07211 6 Bytes JMP 7196000A
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] ADVAPI32.dll!CreateServiceW 77E073A9 6 Bytes JMP 7193000A
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] WS2_32.dll!WSALookupServiceBeginW 00C435EF 6 Bytes JMP 716F000A
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] WS2_32.dll!connect 00C44A07 6 Bytes JMP 7178000A
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] WS2_32.dll!listen 00C48CD3 6 Bytes JMP 7172000A
.text C:\Programme\Mozilla Firefox\firefox.exe[2172] WS2_32.dll!WSAConnect 00C50C81 6 Bytes JMP 7175000A
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] ntdll.dll!NtCreateFile 7C91D0AE 1 Byte [FF]
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] ntdll.dll!NtCreateFile 7C91D0AE 3 Bytes [FF, 25, 1E]
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] ntdll.dll!NtCreateFile + 4 7C91D0B2 2 Bytes [86, 71]
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] ntdll.dll!NtDeleteValueKey 7C91D26E 3 Bytes [FF, 25, 1E]
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] ntdll.dll!NtDeleteValueKey + 4 7C91D272 2 Bytes [8C, 71]
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] ntdll.dll!NtOpenFile 7C91D59E 3 Bytes [FF, 25, 1E]
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] ntdll.dll!NtOpenFile + 4 7C91D5A2 2 Bytes [83, 71]
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] ntdll.dll!NtOpenProcess 7C91D5FE 3 Bytes [FF, 25, 1E]
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] ntdll.dll!NtOpenProcess + 4 7C91D602 2 Bytes [89, 71]
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] ntdll.dll!NtSetContextThread 7C91DBAE 3 Bytes [FF, 25, 1E]
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] ntdll.dll!NtSetContextThread + 4 7C91DBB2 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] ntdll.dll!NtSetInformationFile 7C91DC5E 3 Bytes [FF, 25, 1E]
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] ntdll.dll!NtSetInformationFile + 4 7C91DC62 2 Bytes [80, 71]
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] ntdll.dll!NtSetValueKey 7C91DDCE 3 Bytes [FF, 25, 1E]
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] ntdll.dll!NtSetValueKey + 4 7C91DDD2 2 Bytes [8F, 71]
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AF0001
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] kernel32.dll!CreateProcessInternalW 7C8185EC 3 Bytes [FF, 25, 1E]
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] kernel32.dll!CreateProcessInternalW + 4 7C8185F0 2 Bytes [7A, 71] {JP 0x73}
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] USER32.dll!PostMessageW 7E368CCB 6 Bytes JMP 7199000A
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] USER32.dll!SendMessageW 7E37929A 6 Bytes JMP 719F000A
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] USER32.dll!PostMessageA 7E37AAFD 6 Bytes JMP 719C000A
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] USER32.dll!SendInput 7E37F140 3 Bytes [FF, 25, 1E]
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] USER32.dll!SendInput + 4 7E37F144 2 Bytes [A4, 71]
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] USER32.dll!SendMessageA 7E37F3C2 6 Bytes JMP 71A2000A
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] USER32.dll!mouse_event 7E3B673F 6 Bytes JMP 71AB000A
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] USER32.dll!keybd_event 7E3B6783 6 Bytes JMP 71A8000A
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] ADVAPI32.dll!CreateServiceA 77E07211 6 Bytes JMP 7196000A
.text C:\Dokumente und Einstellungen\Administrator\Desktop\Gmer-19357.exe[2324] ADVAPI32.dll!CreateServiceW 77E073A9 6 Bytes JMP 7193000A
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] ntdll.dll!NtCreateFile 7C91D0AE 1 Byte [FF]
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] ntdll.dll!NtCreateFile 7C91D0AE 3 Bytes [FF, 25, 1E]
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] ntdll.dll!NtCreateFile + 4 7C91D0B2 2 Bytes [86, 71]
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] ntdll.dll!NtDeleteValueKey 7C91D26E 3 Bytes [FF, 25, 1E]
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] ntdll.dll!NtDeleteValueKey + 4 7C91D272 2 Bytes [8C, 71]
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] ntdll.dll!NtOpenFile 7C91D59E 3 Bytes [FF, 25, 1E]
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] ntdll.dll!NtOpenFile + 4 7C91D5A2 2 Bytes [83, 71]
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] ntdll.dll!NtOpenProcess 7C91D5FE 3 Bytes [FF, 25, 1E]
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] ntdll.dll!NtOpenProcess + 4 7C91D602 2 Bytes [89, 71]
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] ntdll.dll!NtSetContextThread 7C91DBAE 3 Bytes [FF, 25, 1E]
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] ntdll.dll!NtSetContextThread + 4 7C91DBB2 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] ntdll.dll!NtSetInformationFile 7C91DC5E 3 Bytes [FF, 25, 1E]
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] ntdll.dll!NtSetInformationFile + 4 7C91DC62 2 Bytes [80, 71]
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] ntdll.dll!NtSetValueKey 7C91DDCE 3 Bytes [FF, 25, 1E]
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] ntdll.dll!NtSetValueKey + 4 7C91DDD2 2 Bytes [8F, 71]
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AF0001
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] kernel32.dll!CreateProcessInternalW 7C8185EC 3 Bytes [FF, 25, 1E]
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] kernel32.dll!CreateProcessInternalW + 4 7C8185F0 2 Bytes [7A, 71] {JP 0x73}
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] ADVAPI32.dll!CreateServiceA 77E07211 6 Bytes JMP 7196000A
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] ADVAPI32.dll!CreateServiceW 77E073A9 6 Bytes JMP 7193000A
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] USER32.dll!PostMessageW 7E368CCB 6 Bytes JMP 7199000A
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] USER32.dll!SendMessageW 7E37929A 6 Bytes JMP 719F000A
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] USER32.dll!PostMessageA 7E37AAFD 6 Bytes JMP 719C000A
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] USER32.dll!DefWindowProcA + 11A 7E37C298 7 Bytes JMP 022BEFF1 C:\Programme\Mozilla Firefox\xul.dll
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] USER32.dll!SetWindowLongA + 19 7E37C2B6 7 Bytes JMP 022BF0C3 C:\Programme\Mozilla Firefox\xul.dll
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] USER32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 022C1371 C:\Programme\Mozilla Firefox\xul.dll
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] USER32.dll!SendInput 7E37F140 3 Bytes [FF, 25, 1E]
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] USER32.dll!SendInput + 4 7E37F144 2 Bytes [A4, 71]
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] USER32.dll!SendMessageA 7E37F3C2 6 Bytes JMP 71A2000A
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] USER32.dll!GetMenuContextHelpId + 1A 7E3B5319 7 Bytes JMP 022BF997 C:\Programme\Mozilla Firefox\xul.dll
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] USER32.dll!mouse_event 7E3B673F 6 Bytes JMP 71AB000A
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] USER32.dll!keybd_event 7E3B6783 6 Bytes JMP 71A8000A
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] WS2_32.dll!WSALookupServiceBeginW 00CA35EF 6 Bytes JMP 716F000A
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] WS2_32.dll!connect 00CA4A07 6 Bytes JMP 7178000A
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] WS2_32.dll!listen 00CA8CD3 6 Bytes JMP 7172000A
.text C:\Programme\Mozilla Firefox\plugin-container.exe[3848] WS2_32.dll!WSAConnect 00CB0C81 6 Bytes JMP 7175000A
---- Devices - GMER 2.1 ----
Device \Driver\Tcpip \Device\Ip OAmon.sys
Device \Driver\Tcpip \Device\Tcp OAmon.sys
Device \Driver\Tcpip \Device\Udp OAmon.sys
Device \Driver\Tcpip \Device\RawIp OAmon.sys
Device \Driver\Tcpip \Device\IPMULTICAST OAmon.sys
---- Registry - GMER 2.1 ----
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xE2 0x63 0x26 0xF1 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x6A 0x9C 0xD6 0x61 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0xFF 0x7C 0x85 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x3E 0x1E 0x9E 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xB0 0x18 0xED 0xA7 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0xFB 0xA7 0x78 0xE6 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x83 0x6C 0x56 0x8B ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xB2 0x46 0x9A 0xE2 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x3D 0xCE 0xEA 0x26 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0x2A 0xB7 0xCC 0xB5 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0x05 0x73 0x21 0xDD ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{B5329CD5-A797-622D-DBD3-E0E69A4DA343}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{B5329CD5-A797-622D-DBD3-E0E69A4DA343}@gaeanndfclomfa 0x61 0x63 0x61 0x62 ...
---- EOF - GMER 2.1 ---- --- --- --- |