BernhardK | 11.08.2015 07:54 | Hallo Cosinus,
sende dir nun die Logfiles, hoffe es klappt... Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 07.08.2015
Suchlaufzeit: 17:48
Protokolldatei: Malwarebytes Anti-Malware.txt
Administrator: Ja
Version: 2.1.8.1057
Malware-Datenbank: v2015.08.07.04
Rootkit-Datenbank: v2015.08.06.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: thorsten
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 429596
Abgelaufene Zeit: 26 Min., 10 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 6
PUP.Optional.Snapdo.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [dd23689e98f3a78f669d22ac8d7510f0],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\Tree\Dealply, Löschen bei Neustart, [bf41b5519bf01521bfdc1df733d0a15f],
PUP.Optional.Babylon.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\Tree\EPUpdater, Löschen bei Neustart, [e11fc73f8efd96a02614d53f729120e0],
PUP.Optional.PositiveFinds.A, HKLM\SOFTWARE\WOW6432NODE\PositiveFinds, In Quarantäne, [d0303fc74f3c66d08133f72d4eb58977],
PUP.Optional.Spigot.A, HKU\S-1-5-21-2964402223-2653800504-1609740198-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BDBD1EF-A852-46BF-81FF-D222D796D329}, In Quarantäne, [ec14df270f7c93a3b79b0f0c9c677d83],
PUP.Optional.Spigot.A, HKU\S-1-5-21-2964402223-2653800504-1609740198-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E2C4D431-E211-4960-8219-C290E994A73A}, In Quarantäne, [cc34897d4e3df83eb1a15ac1956e6e92],
Registrierungswerte: 3
PUP.Optional.Spigot.A, HKU\S-1-5-21-2964402223-2653800504-1609740198-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BDBD1EF-A852-46BF-81FF-D222D796D329}|URL, hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=937811&p={searchTerms}, In Quarantäne, [ec14df270f7c93a3b79b0f0c9c677d83]
PUP.Optional.Spigot.A, HKU\S-1-5-21-2964402223-2653800504-1609740198-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E2C4D431-E211-4960-8219-C290E994A73A}|URL, hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=302398&p={searchTerms}, In Quarantäne, [cc34897d4e3df83eb1a15ac1956e6e92]
PUP.Optional.Spigot.A, HKU\S-1-5-21-2964402223-2653800504-1609740198-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E2C4D431-E211-4960-8219-C290E994A73A}|OSDFileURL, file:///C:/Program%20Files%20(x86)/Common%20Files/Spigot/Search%20Settings/yahoo_ie.xml, In Quarantäne, [10f02bdbc5c60f27ddd4e0c122e21ee2]
Registrierungsdaten: 1
PUP.Optional.Spigot.A, HKU\S-1-5-21-2964402223-2653800504-1609740198-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://de.search.yahoo.com/?type=937811&fr=spigot-yhp-ie, Gut: (www.google.com), Schlecht: (hxxp://de.search.yahoo.com/?type=937811&fr=spigot-yhp-ie),Ersetzt,[5ca49670acdfd06624a1f24fbe477b85]
Ordner: 0
(keine bösartigen Elemente erkannt)
Dateien: 9
PUP.Optional.Spigot.SID, C:\ProgramData\Comodo\Cis\Quarantine\data\{12C6DD13-105B-4169-9735-506AA4ECFCF6}, In Quarantäne, [d62a7b8b6a2164d285c383fc0cf92ed2],
PUP.Optional.Spigot.SID, C:\ProgramData\Comodo\Cis\Quarantine\data\{2B774652-06D1-435F-B501-4A519A28258D}, In Quarantäne, [fb05986e1972af87be8a0d7203029f61],
PUP.Optional.BabSolution.A, C:\ProgramData\Comodo\Cis\Quarantine\data\{443E1469-5DB9-4B7C-807F-1788E47F3874}, In Quarantäne, [3fc19b6b92f935011aa8df0b768a6898],
PUP.Optional.Spigot.SID, C:\ProgramData\Comodo\Cis\Quarantine\data\{83D81DB5-D175-4A5B-886C-3C2FB12AEC47}, In Quarantäne, [32cee81e4f3ca294b8908cf3c540f10f],
PUP.Optional.Babylon.A, C:\ProgramData\Comodo\Cis\Quarantine\data\{9020A868-3881-4A85-B87B-D8772A28BB20}, In Quarantäne, [04fc7d89f497e74f14f0c72b30d4fd03],
PUP.Optional.Spigot.SID, C:\ProgramData\Comodo\Cis\Quarantine\data\{AF0914C8-7613-44E1-B047-11B8880F7E31}, In Quarantäne, [9d6336d04c3f082eed5bd6a9897c19e7],
PUP.Optional.Spigot.SID, C:\ProgramData\Comodo\Cis\Quarantine\data\{DD25BABE-C869-4CF5-8EDA-4A6EE141B3F3}, In Quarantäne, [5da32bdbaae18caa38100a755baa2bd5],
PUP.Optional.Spigot.A, C:\Users\thorsten\AppData\Roaming\Mozilla\Firefox\Profiles\ee4b0i08.default\searchplugins\yahoo_ff.xml, In Quarantäne, [6d937e88355652e49856fc2d52b1af51],
PUP.Optional.Spigot.A, C:\Users\thorsten\AppData\Roaming\Mozilla\Firefox\Profiles\ee4b0i08.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=937811&p=");), Ersetzt,[b34d8e78b4d78da97c3bf98b9b6a58a8]
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 21:16 on 10/08/2015 (thorsten)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=- Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-08-10 22:25:19
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.PC3O 298,09GB
Running: Gmer-19357.exe; Driver: C:\Users\thorsten\AppData\Local\Temp\kgdcrkob.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077281401 2 bytes JMP 7768b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe[1732] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077281419 2 bytes JMP 7768b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077281431 2 bytes JMP 77708f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007728144a 2 bytes CALL 7766489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe[1732] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000772814dd 2 bytes JMP 77708822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000772814f5 2 bytes JMP 777089f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe[1732] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007728150d 2 bytes JMP 77708718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077281525 2 bytes JMP 77708ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007728153d 2 bytes JMP 7767fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe[1732] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077281555 2 bytes JMP 776868ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007728156d 2 bytes JMP 77708fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077281585 2 bytes JMP 77708b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe[1732] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007728159d 2 bytes JMP 777086dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000772815b5 2 bytes JMP 7767fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000772815cd 2 bytes JMP 7768b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000772816b2 2 bytes JMP 77708ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000772816bd 2 bytes JMP 77708671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe[2280] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExW + 17 0000000077281401 2 bytes JMP 7768b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe[2280] C:\Windows\syswow64\psapi.dll!EnumProcessModules + 17 0000000077281419 2 bytes JMP 7768b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe[2280] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 17 0000000077281431 2 bytes JMP 77708f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe[2280] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 42 000000007728144a 2 bytes CALL 7766489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe[2280] C:\Windows\syswow64\psapi.dll!EnumDeviceDrivers + 17 00000000772814dd 2 bytes JMP 77708822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe[2280] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameA + 17 00000000772814f5 2 bytes JMP 777089f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe[2280] C:\Windows\syswow64\psapi.dll!QueryWorkingSetEx + 17 000000007728150d 2 bytes JMP 77708718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe[2280] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameW + 17 0000000077281525 2 bytes JMP 77708ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe[2280] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameW + 17 000000007728153d 2 bytes JMP 7767fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe[2280] C:\Windows\syswow64\psapi.dll!EnumProcesses + 17 0000000077281555 2 bytes JMP 776868ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe[2280] C:\Windows\syswow64\psapi.dll!GetProcessMemoryInfo + 17 000000007728156d 2 bytes JMP 77708fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe[2280] C:\Windows\syswow64\psapi.dll!GetPerformanceInfo + 17 0000000077281585 2 bytes JMP 77708b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe[2280] C:\Windows\syswow64\psapi.dll!QueryWorkingSet + 17 000000007728159d 2 bytes JMP 777086dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe[2280] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameA + 17 00000000772815b5 2 bytes JMP 7767fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe[2280] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExA + 17 00000000772815cd 2 bytes JMP 7768b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe[2280] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 20 00000000772816b2 2 bytes JMP 77708ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe[2280] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 31 00000000772816bd 2 bytes JMP 77708671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AviraSpeedup\avira_system_speedup.exe[2524] C:\Windows\syswow64\kernel32.dll!CreateThread + 28 00000000776634a1 4 bytes {CALL 0xffffffff88e4aa08}
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[2916] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077281401 2 bytes JMP 7768b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[2916] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077281419 2 bytes JMP 7768b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[2916] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077281431 2 bytes JMP 77708f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[2916] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007728144a 2 bytes CALL 7766489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[2916] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000772814dd 2 bytes JMP 77708822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[2916] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000772814f5 2 bytes JMP 777089f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[2916] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007728150d 2 bytes JMP 77708718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[2916] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077281525 2 bytes JMP 77708ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[2916] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007728153d 2 bytes JMP 7767fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[2916] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077281555 2 bytes JMP 776868ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[2916] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007728156d 2 bytes JMP 77708fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[2916] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077281585 2 bytes JMP 77708b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[2916] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007728159d 2 bytes JMP 777086dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[2916] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000772815b5 2 bytes JMP 7767fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[2916] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000772815cd 2 bytes JMP 7768b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[2916] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000772816b2 2 bytes JMP 77708ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[2916] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000772816bd 2 bytes JMP 77708671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1864] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077281401 2 bytes JMP 7768b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1864] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077281419 2 bytes JMP 7768b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1864] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077281431 2 bytes JMP 77708f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1864] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007728144a 2 bytes CALL 7766489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1864] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000772814dd 2 bytes JMP 77708822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1864] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000772814f5 2 bytes JMP 777089f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1864] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007728150d 2 bytes JMP 77708718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1864] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077281525 2 bytes JMP 77708ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1864] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007728153d 2 bytes JMP 7767fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1864] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077281555 2 bytes JMP 776868ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1864] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007728156d 2 bytes JMP 77708fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1864] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077281585 2 bytes JMP 77708b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1864] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007728159d 2 bytes JMP 777086dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1864] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000772815b5 2 bytes JMP 7767fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1864] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000772815cd 2 bytes JMP 7768b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1864] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000772816b2 2 bytes JMP 77708ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe[1864] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000772816bd 2 bytes JMP 77708671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2500] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077281401 2 bytes JMP 7768b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2500] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077281419 2 bytes JMP 7768b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2500] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077281431 2 bytes JMP 77708f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2500] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007728144a 2 bytes CALL 7766489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2500] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000772814dd 2 bytes JMP 77708822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2500] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000772814f5 2 bytes JMP 777089f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2500] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007728150d 2 bytes JMP 77708718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2500] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077281525 2 bytes JMP 77708ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2500] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007728153d 2 bytes JMP 7767fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2500] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077281555 2 bytes JMP 776868ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2500] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007728156d 2 bytes JMP 77708fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2500] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077281585 2 bytes JMP 77708b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2500] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007728159d 2 bytes JMP 777086dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2500] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000772815b5 2 bytes JMP 7767fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2500] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000772815cd 2 bytes JMP 7768b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2500] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000772816b2 2 bytes JMP 77708ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2500] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000772816bd 2 bytes JMP 77708671 C:\Windows\syswow64\kernel32.dll
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ----
Gruß
BernhardK |