Hallo,
Ich war die letzten paar Tage weg. Nun habe ich aber die Logs beider Scans. Code:
GMER 1.0.15.15640 - hxxp://www.gmer.net
Rootkit scan 2011-07-14 12:39:46
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Hitachi_HTS545025B9A300 rev.PB2OC60F
Running: 87hyv2pp.exe; Driver: C:\Users\***\AppData\Local\Temp\awdoqpoc.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0x8AF7D202]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0x90A2CD8C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0x8AF7F7F0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0x8AF7F848]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0x8AF7F95E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0x8AF7F746]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0x8AF7F898]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0x8AF7F79A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0x8AF7F90C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0x8AF7D226]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0x90A2CE3C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0x8AF7CFF0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0x8AF7D24A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0x8AF7FD56]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0x8AF7DCDA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0x8AF7F820]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0x8AF7F870]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0x8AF7F988]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0x8AF7F772]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0x8AF7F8D8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0x8AF7F7C8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0x8AF7F936]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0x90A2CED4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0x8AF7DBA0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0x8AF7D26E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0x8AF7D292]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0x8AF7D04A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0x8AF7D186]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0x8AF7D162]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0x8AF7D1AA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0x8AF7D2B6]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0x90A42398]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13C1 8348C339 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 834C5D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10CB 834CCDC0 4 Bytes [02, D2, F7, 8A]
.text ntkrnlpa.exe!KeRemoveQueueEx + 10F3 834CCDE8 4 Bytes [8C, CD, A2, 90]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11A7 834CCE9C 8 Bytes [F0, F7, F7, 8A, 48, F8, F7, ...]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11B3 834CCEA8 4 Bytes [5E, F9, F7, 8A]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11CF 834CCEC4 4 Bytes [46, F7, F7, 8A]
.text ...
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 83659B72 5 Bytes JMP 90A3DD4C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ObInsertObject + 27 8367215E 5 Bytes JMP 90A3F80A \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 108 8368725D 4 Bytes CALL 8AF7E34B \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 122 836A102F 4 Bytes CALL 8AF7E361 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 8372AE6E 7 Bytes JMP 90A4239C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x91A09000, 0x2D5378, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\svchost.exe[280] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[280] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[280] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe[324] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe[324] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe[324] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe[324] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00100A08
.text C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe[324] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001003FC
.text C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe[324] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00100804
.text C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe[324] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001001F8
.text C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe[324] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00100600
.text C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe[344] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 001603FC
.text C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe[344] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 001601F8
.text C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe[344] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe[344] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00190A08
.text C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe[344] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001903FC
.text C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe[344] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00190804
.text C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe[344] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001901F8
.text C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe[344] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00190600
.text C:\Windows\system32\csrss.exe[404] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\wininit.exe[480] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000303FC
.text C:\Windows\system32\wininit.exe[480] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000301F8
.text C:\Windows\system32\wininit.exe[480] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\wininit.exe[480] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 000C0A08
.text C:\Windows\system32\wininit.exe[480] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 000C03FC
.text C:\Windows\system32\wininit.exe[480] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 000C0804
.text C:\Windows\system32\wininit.exe[480] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 000C01F8
.text C:\Windows\system32\wininit.exe[480] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 000C0600
.text C:\Windows\system32\csrss.exe[492] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\services.exe[528] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\services.exe[528] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\services.exe[528] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\lsass.exe[552] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\lsass.exe[552] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\lsass.exe[552] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\lsass.exe[552] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 000D0A08
.text C:\Windows\system32\lsass.exe[552] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 000D03FC
.text C:\Windows\system32\lsass.exe[552] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 000D0804
.text C:\Windows\system32\lsass.exe[552] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 000D01F8
.text C:\Windows\system32\lsass.exe[552] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 000D0600
.text C:\Windows\system32\lsm.exe[560] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\lsm.exe[560] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\lsm.exe[560] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[596] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000303FC
.text C:\Windows\system32\winlogon.exe[596] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000301F8
.text C:\Windows\system32\winlogon.exe[596] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[596] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00050A08
.text C:\Windows\system32\winlogon.exe[596] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 000503FC
.text C:\Windows\system32\winlogon.exe[596] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00050804
.text C:\Windows\system32\winlogon.exe[596] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 000501F8
.text C:\Windows\system32\winlogon.exe[596] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00050600
.text C:\Windows\system32\svchost.exe[712] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[712] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[712] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\svchost.exe[808] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[808] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[808] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\atiesrxx.exe[856] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 001603FC
.text C:\Windows\system32\atiesrxx.exe[856] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 001601F8
.text C:\Windows\system32\atiesrxx.exe[856] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\atiesrxx.exe[856] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 001F0A08
.text C:\Windows\system32\atiesrxx.exe[856] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001F03FC
.text C:\Windows\system32\atiesrxx.exe[856] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 001F0804
.text C:\Windows\system32\atiesrxx.exe[856] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001F01F8
.text C:\Windows\system32\atiesrxx.exe[856] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 001F0600
.text C:\Windows\System32\svchost.exe[952] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[952] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[952] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\System32\svchost.exe[952] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00870A08
.text C:\Windows\System32\svchost.exe[952] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 008703FC
.text C:\Windows\System32\svchost.exe[952] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00870804
.text C:\Windows\System32\svchost.exe[952] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 008701F8
.text C:\Windows\System32\svchost.exe[952] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00870600
.text C:\Windows\System32\svchost.exe[1000] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[1000] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[1000] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1000] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 003C0A08
.text C:\Windows\System32\svchost.exe[1000] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 003C03FC
.text C:\Windows\System32\svchost.exe[1000] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 003C0804
.text C:\Windows\System32\svchost.exe[1000] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 003C01F8
.text C:\Windows\System32\svchost.exe[1000] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 003C0600
.text C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe[1036] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 001603FC
.text C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe[1036] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 001601F8
.text C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe[1036] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe[1036] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 001F0A08
.text C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe[1036] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001F03FC
.text C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe[1036] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 001F0804
.text C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe[1036] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001F01F8
.text C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe[1036] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 001F0600
.text C:\Windows\system32\svchost.exe[1044] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1044] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1044] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1044] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00C10A08
.text C:\Windows\system32\svchost.exe[1044] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 00C103FC
.text C:\Windows\system32\svchost.exe[1044] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00C10804
.text C:\Windows\system32\svchost.exe[1044] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 00C101F8
.text C:\Windows\system32\svchost.exe[1044] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00C10600
.text C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\capiws.exe[1152] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 001603FC
.text C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\capiws.exe[1152] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 001601F8
.text C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\capiws.exe[1152] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1172] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1172] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1172] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1172] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00900A08
.text C:\Windows\system32\svchost.exe[1172] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 009003FC
.text C:\Windows\system32\svchost.exe[1172] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00900804
.text C:\Windows\system32\svchost.exe[1172] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 009001F8
.text C:\Windows\system32\svchost.exe[1172] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00900600
.text C:\Windows\system32\atieclxx.exe[1256] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 001603FC
.text C:\Windows\system32\atieclxx.exe[1256] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 001601F8
.text C:\Windows\system32\atieclxx.exe[1256] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\atieclxx.exe[1256] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 001F0A08
.text C:\Windows\system32\atieclxx.exe[1256] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001F03FC
.text C:\Windows\system32\atieclxx.exe[1256] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 001F0804
.text C:\Windows\system32\atieclxx.exe[1256] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001F01F8
.text C:\Windows\system32\atieclxx.exe[1256] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 001F0600
.text C:\Windows\system32\svchost.exe[1276] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[1276] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[1276] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1276] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 008F0A08
.text C:\Windows\system32\svchost.exe[1276] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 008F03FC
.text C:\Windows\system32\svchost.exe[1276] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 008F0804
.text C:\Windows\system32\svchost.exe[1276] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 008F01F8
.text C:\Windows\system32\svchost.exe[1276] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 008F0600
.text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1400] kernel32.dll!SetUnhandledExceptionFilter 75F13D01 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP }
.text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1400] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Program Files\Secunia\PSI\PSIA.exe[1472] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Program Files\Secunia\PSI\PSIA.exe[1472] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Program Files\Secunia\PSI\PSIA.exe[1472] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Program Files\Secunia\PSI\PSIA.exe[1472] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00100A08
.text C:\Program Files\Secunia\PSI\PSIA.exe[1472] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001003FC
.text C:\Program Files\Secunia\PSI\PSIA.exe[1472] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00100804
.text C:\Program Files\Secunia\PSI\PSIA.exe[1472] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001001F8
.text C:\Program Files\Secunia\PSI\PSIA.exe[1472] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00100600
.text C:\Windows\System32\spoolsv.exe[1732] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\System32\spoolsv.exe[1732] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\System32\spoolsv.exe[1732] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\System32\spoolsv.exe[1732] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00140A08
.text C:\Windows\System32\spoolsv.exe[1732] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001403FC
.text C:\Windows\System32\spoolsv.exe[1732] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00140804
.text C:\Windows\System32\spoolsv.exe[1732] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001401F8
.text C:\Windows\System32\spoolsv.exe[1732] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00140600
.text C:\Windows\system32\svchost.exe[1760] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000A03FC
.text C:\Windows\system32\svchost.exe[1760] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000A01F8
.text C:\Windows\system32\svchost.exe[1760] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1760] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 003D0A08
.text C:\Windows\system32\svchost.exe[1760] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 003D03FC
.text C:\Windows\system32\svchost.exe[1760] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 003D0804
.text C:\Windows\system32\svchost.exe[1760] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 003D01F8
.text C:\Windows\system32\svchost.exe[1760] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 003D0600
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1840] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000703FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1840] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000701F8
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1840] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1840] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00100A08
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1840] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001003FC
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1840] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00100804
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1840] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001001F8
.text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[1840] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00100600
.text C:\Windows\System32\svchost.exe[1880] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[1880] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[1880] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\System32\svchost.exe[1880] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00310A08
.text C:\Windows\System32\svchost.exe[1880] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 003103FC
.text C:\Windows\System32\svchost.exe[1880] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00310804
.text C:\Windows\System32\svchost.exe[1880] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 003101F8
.text C:\Windows\System32\svchost.exe[1880] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00310600
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1904] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1904] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1904] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1904] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00100A08
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1904] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001003FC
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1904] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00100804
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1904] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001001F8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1904] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00100600
.text C:\Program Files\Bonjour\mDNSResponder.exe[1952] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Program Files\Bonjour\mDNSResponder.exe[1952] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Program Files\Bonjour\mDNSResponder.exe[1952] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1952] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00100A08
.text C:\Program Files\Bonjour\mDNSResponder.exe[1952] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001003FC
.text C:\Program Files\Bonjour\mDNSResponder.exe[1952] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00100804
.text C:\Program Files\Bonjour\mDNSResponder.exe[1952] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001001F8
.text C:\Program Files\Bonjour\mDNSResponder.exe[1952] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00100600
.text C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe[1980] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 001603FC
.text C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe[1980] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 001601F8
.text C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe[1980] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe[1980] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00180A08
.text C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe[1980] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001803FC
.text C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe[1980] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00180804
.text C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe[1980] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001801F8
.text C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe[1980] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00180600
.text C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe[2016] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 001603FC
.text C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe[2016] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 001601F8
.text C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe[2016] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe[2016] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00200A08
.text C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe[2016] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 002003FC
.text C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe[2016] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00200804
.text C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe[2016] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 002001F8
.text C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe[2016] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00200600
.text C:\Windows\system32\Dwm.exe[2056] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\Dwm.exe[2056] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\Dwm.exe[2056] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\Dwm.exe[2056] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00100A08
.text C:\Windows\system32\Dwm.exe[2056] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001003FC
.text C:\Windows\system32\Dwm.exe[2056] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00100804
.text C:\Windows\system32\Dwm.exe[2056] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001001F8
.text C:\Windows\system32\Dwm.exe[2056] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00100600
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[2340] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 001603FC
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[2340] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 001601F8
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[2340] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[2340] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 002F0A08
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[2340] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 002F03FC
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[2340] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 002F0804
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[2340] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 002F01F8
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[2340] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 002F0600
.text C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe[2528] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe[2528] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe[2528] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe[2528] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 000F0A08
.text C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe[2528] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 000F03FC
.text C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe[2528] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 000F0804
.text C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe[2528] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 000F01F8
.text C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe[2528] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 000F0600
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2640] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 001703FC
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2640] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 001701F8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2640] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2640] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00210A08
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2640] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 002103FC
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2640] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00210804
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2640] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 002101F8
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[2640] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00210600
.text C:\Windows\System32\alg.exe[2680] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\System32\alg.exe[2680] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\System32\alg.exe[2680] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\System32\alg.exe[2680] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00100A08
.text C:\Windows\System32\alg.exe[2680] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001003FC
.text C:\Windows\System32\alg.exe[2680] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00100804
.text C:\Windows\System32\alg.exe[2680] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001001F8
.text C:\Windows\System32\alg.exe[2680] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00100600
.text C:\Windows\system32\svchost.exe[2788] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[2788] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[2788] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\svchost.exe[2788] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 008D0A08
.text C:\Windows\system32\svchost.exe[2788] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 008D03FC
.text C:\Windows\system32\svchost.exe[2788] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 008D0804
.text C:\Windows\system32\svchost.exe[2788] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 008D01F8
.text C:\Windows\system32\svchost.exe[2788] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 008D0600
.text C:\Windows\system32\svchost.exe[2912] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\svchost.exe[2912] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\svchost.exe[2912] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\svchost.exe[2912] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00210A08
.text C:\Windows\system32\svchost.exe[2912] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 002103FC
.text C:\Windows\system32\svchost.exe[2912] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00210804
.text C:\Windows\system32\svchost.exe[2912] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 002101F8
.text C:\Windows\system32\svchost.exe[2912] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00210600
.text C:\Program Files\Alwil Software\Avast5\AvastUI.exe[2968] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2992] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 001603FC
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2992] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 001601F8
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2992] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2992] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 001F0A08
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2992] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001F03FC
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2992] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 001F0804
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2992] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001F01F8
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[2992] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 001F0600
.text C:\Windows\system32\wuauclt.exe[3032] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000703FC
.text C:\Windows\system32\wuauclt.exe[3032] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000701F8
.text C:\Windows\system32\wuauclt.exe[3032] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\wuauclt.exe[3032] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00100A08
.text C:\Windows\system32\wuauclt.exe[3032] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001003FC
.text C:\Windows\system32\wuauclt.exe[3032] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00100804
.text C:\Windows\system32\wuauclt.exe[3032] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001001F8
.text C:\Windows\system32\wuauclt.exe[3032] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00100600
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3168] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 001603FC
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3168] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 001601F8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3168] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3168] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 001F0A08
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3168] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001F03FC
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3168] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 001F0804
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3168] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001F01F8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3168] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 001F0600
.text C:\Program Files\Secunia\PSI\sua.exe[3172] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000703FC
.text C:\Program Files\Secunia\PSI\sua.exe[3172] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000701F8
.text C:\Program Files\Secunia\PSI\sua.exe[3172] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\taskeng.exe[3284] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\taskeng.exe[3284] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\taskeng.exe[3284] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\taskeng.exe[3284] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00130A08
.text C:\Windows\system32\taskeng.exe[3284] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001303FC
.text C:\Windows\system32\taskeng.exe[3284] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00130804
.text C:\Windows\system32\taskeng.exe[3284] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001301F8
.text C:\Windows\system32\taskeng.exe[3284] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00130600
.text C:\Windows\System32\svchost.exe[3544] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[3544] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[3544] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\System32\svchost.exe[3544] user32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 001D0A08
.text C:\Windows\System32\svchost.exe[3544] user32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001D03FC
.text C:\Windows\System32\svchost.exe[3544] user32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 001D0804
.text C:\Windows\System32\svchost.exe[3544] user32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001D01F8
.text C:\Windows\System32\svchost.exe[3544] user32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 001D0600
.text C:\Windows\System32\svchost.exe[3628] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\System32\svchost.exe[3628] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\System32\svchost.exe[3628] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\System32\svchost.exe[3628] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00150A08
.text C:\Windows\System32\svchost.exe[3628] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001503FC
.text C:\Windows\System32\svchost.exe[3628] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00150804
.text C:\Windows\System32\svchost.exe[3628] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001501F8
.text C:\Windows\System32\svchost.exe[3628] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00150600
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3672] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000A03FC
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3672] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000A01F8
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3672] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3672] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00150A08
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3672] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001503FC
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3672] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00150804
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3672] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001501F8
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3672] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00150600
.text C:\Windows\system32\SearchIndexer.exe[3704] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\system32\SearchIndexer.exe[3704] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\system32\SearchIndexer.exe[3704] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\SearchIndexer.exe[3704] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00140A08
.text C:\Windows\system32\SearchIndexer.exe[3704] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001403FC
.text C:\Windows\system32\SearchIndexer.exe[3704] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00140804
.text C:\Windows\system32\SearchIndexer.exe[3704] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001401F8
.text C:\Windows\system32\SearchIndexer.exe[3704] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00140600
.text C:\Windows\system32\taskhost.exe[4068] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000503FC
.text C:\Windows\system32\taskhost.exe[4068] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000501F8
.text C:\Windows\system32\taskhost.exe[4068] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\system32\taskhost.exe[4068] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 000E0A08
.text C:\Windows\system32\taskhost.exe[4068] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 000E03FC
.text C:\Windows\system32\taskhost.exe[4068] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 000E0804
.text C:\Windows\system32\taskhost.exe[4068] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 000E01F8
.text C:\Windows\system32\taskhost.exe[4068] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 000E0600
.text C:\Windows\Explorer.EXE[4080] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 000603FC
.text C:\Windows\Explorer.EXE[4080] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 000601F8
.text C:\Windows\Explorer.EXE[4080] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text C:\Windows\Explorer.EXE[4080] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00150A08
.text C:\Windows\Explorer.EXE[4080] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 001503FC
.text C:\Windows\Explorer.EXE[4080] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00150804
.text C:\Windows\Explorer.EXE[4080] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 001501F8
.text C:\Windows\Explorer.EXE[4080] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00150600
.text C:\Windows\system32\ctfmon.exe[4124] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text E:\Freeware\87hyv2pp.exe[5700] ntdll.dll!LdrUnloadDll 779EC8DE 5 Bytes JMP 001603FC
.text E:\Freeware\87hyv2pp.exe[5700] ntdll.dll!LdrLoadDll 779F22B8 5 Bytes JMP 001601F8
.text E:\Freeware\87hyv2pp.exe[5700] kernel32.dll!GetBinaryTypeW + 70 75F24F63 1 Byte [62]
.text E:\Freeware\87hyv2pp.exe[5700] USER32.dll!UnhookWindowsHookEx 7671ADF9 5 Bytes JMP 00210A08
.text E:\Freeware\87hyv2pp.exe[5700] USER32.dll!UnhookWinEvent 7671B750 5 Bytes JMP 002103FC
.text E:\Freeware\87hyv2pp.exe[5700] USER32.dll!SetWindowsHookExW 7671E30C 5 Bytes JMP 00210804
.text E:\Freeware\87hyv2pp.exe[5700] USER32.dll!SetWinEventHook 767224DC 5 Bytes JMP 002101F8
.text E:\Freeware\87hyv2pp.exe[5700] USER32.dll!SetWindowsHookExA 76746D0C 5 Bytes JMP 00210600
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe[324] @ C:\Windows\system32\SHELL32.dll [USER32.dll!ExitWindowsEx] [00701210] C:\Program Files\NewTech Infosystems\Acer Backup Manager\Pehook.DLL (Backup Manager Module/NewTech Infosystems, Inc.)
IAT C:\Windows\Explorer.EXE[4080] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibraryAndExitThread] [10001DA0] C:\Program Files\EgisTec\MyWinLocker 3\x86\psdprotect.dll (PSD DragDrop Protection/EgisTec Inc.)
IAT C:\Windows\Explorer.EXE[4080] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] [10002480] C:\Program Files\EgisTec\MyWinLocker 3\x86\psdprotect.dll (PSD DragDrop Protection/EgisTec Inc.)
IAT C:\Windows\Explorer.EXE[4080] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [10001290] C:\Program Files\EgisTec\MyWinLocker 3\x86\psdprotect.dll (PSD DragDrop Protection/EgisTec Inc.)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 hotcore3.sys (A part of Paragon System Utilities/Paragon Software Group)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 hotcore3.sys (A part of Paragon System Utilities/Paragon Software Group)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 hotcore3.sys (A part of Paragon System Utilities/Paragon Software Group)
Device \Driver\ACPI_HAL \Device\0000004f halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ---- Code:
Report of OSAM: Autorun Manager v5.0.11926.0
hxxp://www.online-solutions.ru/en/
Saved at 18:20:48 on 19.07.2011
OS: Windows 7 Home Premium Edition Service Pack 1 (Build 7601), 32-bit
Default Browser: Mozilla Corporation Firefox 5.0
Scanner Settings
[x] Rootkits detection (hidden registry)
[x] Rootkits detection (hidden files)
[x] Retrieve files information
[x] Check Microsoft signatures
Filters
[ ] Trusted entries
[ ] Empty entries
[x] Hidden registry entries (rootkit activity)
[x] Exclusively opened files
[x] Not found files
[x] Files without detailed information
[x] Existing files
[ ] Non-startable services
[ ] Non-startable drivers
[x] Active entries
[x] Disabled entries
[AppInit DLLs]
-----( HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows )-----
"AppInit_DLLs" - "Google" - C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
[Control Panel Objects]
-----( %SystemRoot%\system32 )-----
"FlashPlayerCPLApp.cpl" - "Adobe Systems Incorporated" - C:\Windows\system32\FlashPlayerCPLApp.cpl
"ISUSPM.cpl" - "Macrovision Corporation" - C:\Windows\system32\ISUSPM.cpl
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls )-----
"QuickTime" - "Apple Inc." - C:\Program Files\QuickTime\QTSystem\QuickTime.cpl
"SMARTBoardCPL" - "SMART Technologies ULC" - C:\Program Files\SMART Technologies\SMART Board Drivers\SMARTBoardCPL.cpl
[Drivers]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"AMD USB Filter Driver" (usbfilter) - "Advanced Micro Devices Inc." - C:\Windows\System32\DRIVERS\usbfilter.sys
"Apple Mobile USB Driver" (USBAAPL) - "Apple, Inc." - C:\Windows\System32\Drivers\usbaapl.sys
"aswFsBlk" (aswFsBlk) - "AVAST Software" - C:\Windows\system32\drivers\aswFsBlk.sys
"aswMonFlt" (aswMonFlt) - "AVAST Software" - C:\Windows\system32\drivers\aswMonFlt.sys
"aswRdr" (aswRdr) - "AVAST Software" - C:\Windows\system32\drivers\aswRdr.sys
"aswSnx" (aswSnx) - "AVAST Software" - C:\Windows\system32\drivers\aswSnx.sys
"aswSP" (aswSP) - "AVAST Software" - C:\Windows\system32\drivers\aswSP.sys
"avast! Network Shield Support" (aswTdi) - "AVAST Software" - C:\Windows\system32\drivers\aswTdi.sys
"catchme" (catchme) - ? - C:\Users\***\AppData\Local\Temp\catchme.sys (File not found)
"epmntdrv" (epmntdrv) - ? - C:\Windows\system32\epmntdrv.sys (File found, but it contains no detailed information)
"EuGdiDrv" (EuGdiDrv) - ? - C:\Windows\system32\EuGdiDrv.sys (File found, but it contains no detailed information)
"hc3ServiceName" (hotcore3) - "Paragon Software Group" - C:\Windows\System32\DRIVERS\hotcore3.sys
"mwlPSDFilter" (mwlPSDFilter) - "Egis Incorporated." - C:\Windows\System32\DRIVERS\mwlPSDFilter.sys
"mwlPSDNServ" (mwlPSDNServ) - "Egis Incorporated." - C:\Windows\System32\DRIVERS\mwlPSDNServ.sys
"mwlPSDVDisk" (mwlPSDVDisk) - "Egis Incorporated." - C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys
"PSI" (PSI) - "Secunia" - C:\Windows\System32\DRIVERS\psi_mf.sys
"UBHelper" (UBHelper) - "NewTech Infosystems Corporation" - C:\Windows\system32\drivers\UBHelper.sys
"Upper Class Filter Driver" (NTIDrvr) - "NewTech Infosystems, Inc." - C:\Windows\System32\Drivers\NTIDrvr.sys
[Explorer]
-----( HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? - (File not found | COM-object registry key not found)
{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? - (File not found | COM-object registry key not found)
{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? - (File not found | COM-object registry key not found)
{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} "DropboxExt" - ? - (File not found | COM-object registry key not found)
-----( HKLM\Software\Classes\Folder\shellex\ColumnHandlers )-----
{F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" - "Adobe Systems, Inc." - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
{B2F55D43-C7A4-4B7C-90D7-7A860DFA9F2A} "PXCInfoShlExt Class" - "Tracker Software Products Ltd." - C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
-----( HKLM\Software\Classes\Protocols\Handler )-----
{0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" - "Microsoft Corporation" - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved )-----
{911051fa-c21c-4246-b470-070cd8df6dc4} ".cab or .zip files" - ? - (File not found | COM-object registry key not found)
{23170F69-40C1-278A-1000-000100020000} "7-Zip Shell Extension" - "Igor Pavlov" - C:\Program Files\7-Zip\7-zip.dll
{1b24a030-9b20-49bc-97ac-1be4426f9e59} "ActiveDirectory Folder" - ? - (File not found | COM-object registry key not found)
{34449847-FD14-4fc8-A75A-7432F5181EFB} "ActiveDirectory Folder" - ? - (File not found | COM-object registry key not found)
{472083B0-C522-11CF-8763-00608CC02F24} "avast" - "AVAST Software" - C:\Program Files\Alwil Software\Avast5\ashShell.dll
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48} "Contacts folder" - ? - (File not found | COM-object registry key not found)
{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} "DragDropProtect Class" - "EgisTec Inc." - C:\Program Files\EgisTec\MyWinLocker 3\x86\psdprotect.dll
{2C2577C2-63A7-40e3-9B7F-586602617ECB} "Explorer Query Band" - ? - (File not found | COM-object registry key not found)
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} "IE User Assist" - ? - (File not found | COM-object registry key not found)
{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} "iTunes" - "Apple Inc." - C:\Program Files\iTunes\iTunesMiniPlayer.dll
{00020d75-0000-0000-c000-000000000046} "lnkfile" - ? - (File not found | COM-object registry key not found)
{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} "Microsoft Office Metadata Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} "Microsoft Office Thumbnail Handler" - "Microsoft Corporation" - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} "OpenOffice.org Column Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{087B3AE3-E237-4467-B8DB-5A38AB959AC9} "OpenOffice.org Infotip Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{AE424E85-F6DF-4910-A6A9-438797986431} "OpenOffice.org Property Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\propertyhdl.dll
{63542C48-9552-494A-84F7-73AA6A7C99C1} "OpenOffice.org Property Sheet Handler" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{3B092F0C-7696-40E3-A80F-68D74DA84210} "OpenOffice.org Thumbnail Viewer" - ? - C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
{CF822AB4-6DB5-4FDA-BC28-E61DF36D2583} "PDF-XChange PDF Preview Provider" - "Tracker Software Products Ltd." - C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.dll
{67EB453C-1BE1-48EC-AAF3-23B10277FCC1} "PDF-XChange PDF Property Handler" - "Tracker Software Products Ltd." - C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.dll
{EBD0B8F4-A9A0-41B7-9695-030CD264D9C8} "PDF-XChange PDF Thumbnail Provider" - "Tracker Software Products Ltd." - C:\Program Files\Tracker Software\Shell Extensions\XCShInfo.dll
{C8494E42-ACDD-4739-B0FB-217361E4894F} "Sam Account Folder" - ? - (File not found | COM-object registry key not found)
{E29F9716-5C08-4FCD-955A-119FDB5A522D} "Sam Account Folder" - ? - (File not found | COM-object registry key not found)
{da67b8ad-e81b-4c70-9b91b417b5e33527} "Windows Search Shell Service" - ? - (File not found | COM-object registry key not found)
XCShInfo "{B2F55D43-C7A4-4B7C-90D7-7A860DFA9F2A}" - ? - (File not found | COM-object registry key not found)
[Internet Explorer]
-----( HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units )-----
{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} "Java Plug-in 1.6.0_22" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
{8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2iexp.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_26" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\npjpi160_26.dll / hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
-----( HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions )-----
{53707962-6F74-2D53-2644-206D7942484F} "ClsidExtension" - "Safer Networking Limited" - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects )-----
{18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
{67BCF957-85FC-4036-8DC4-D4D80E00A77B} "CIEDownload Object" - "SMART Technologies ULC." - C:\Program Files\SMART Technologies\SMART Notebook\NotebookPlugin.dll
{DBC80044-A445-435b-BC74-9C25C1C588A9} "Java(tm) Plug-In 2 SSV Helper" - "Sun Microsystems, Inc." - C:\Program Files\Java\jre6\bin\jp2ssv.dll
{53707962-6F74-2D53-2644-206D7942484F} "Spybot-S&D IE Protection" - "Safer Networking Limited" - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
[Logon]
-----( %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\Users\Moritz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Dropbox.lnk" - "Dropbox, Inc." - C:\Users\Moritz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Shortcut exists | File exists)
-----( %AllUsersProfile%\Microsoft\Windows\Start Menu\Programs\Startup )-----
"desktop.ini" - ? - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
"Secunia PSI Tray.lnk" - "Secunia" - C:\Program Files\Secunia\PSI\psi_tray.exe (Shortcut exists | File exists)
-----( HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run )-----
"Rapportexe" - "Trusteer Ltd." - "C:\Users\Moritz\AppData\Roaming\Trusteer\Rapport\app\bin\RapportService.exe" -start -after_boot
-----( HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\Wds\rdpwd )-----
"StartupPrograms" - ? - rdpclip (File not found)
-----( HKLM\Software\Microsoft\Windows\CurrentVersion\Run )-----
"Google Desktop Search" - "Google" - "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
"KeePass 2 PreLoad" - "Dominik Reichl" - "C:\Program Files\KeePass Password Safe 2\KeePass.exe" --preload
"SunJavaUpdateSched" - "Sun Microsystems, Inc." - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
[Print Monitors]
-----( HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors )-----
"Bullzip PDF Print Monitor" - "Bullzip" - C:\Windows\system32\bzpdf.dll
"SMART Local Port" - "SMART Technologies" - C:\Windows\system32\smrtlocalmon.dll
[Services]
-----( HKLM\SYSTEM\CurrentControlSet\Services )-----
"Acer ePower Service" (ePowerSvc) - "Acer Incorporated" - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
"Adobe Acrobat Update Service" (AdobeARMservice) - "Adobe Systems Incorporated" - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
"Akamai NetSession Interface" (Akamai) - ? - c:\program files\common files\akamai\netsession_win_e477fed.dll (File found, but it contains no detailed information)
"Apple Mobile Device" (Apple Mobile Device) - "Apple Inc." - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
"avast! Antivirus" (avast! Antivirus) - "AVAST Software" - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
"Bonjour Service" (Bonjour Service) - "Apple Inc." - C:\Program Files\Bonjour\mDNSResponder.exe
"CLHNService" (CLHNService) - ? - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
"Google Desktop Manager 5.9.1005.12335" (GoogleDesktopManager-051210-111108) - "Google" - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
"iPod Service" (iPod Service) - "Apple Inc." - C:\Program Files\iPod\bin\iPodService.exe
"MyWinLocker Service" (MWLService) - "EgisTec Inc." - C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe
"NTI Backup Now 5 Backup Service" (NTIBackupSvc) - "NewTech InfoSystems, Inc." - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
"NTI Backup Now 5 Scheduler Service" (NTISchedulerSvc) - "NewTech Infosystems, Inc." - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
"NTI IScheduleSvc" (NTI IScheduleSvc) - "NewTech Infosystems, Inc." - C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
"OpenVPN Access Client" (OpenVPNAccessClient) - ? - C:\Program Files\OpenVPN Technologies\OpenVPN Client\core\capiws.exe (File found, but it contains no detailed information)
"SBSD Security Center Service" (SBSDWSCService) - "Safer Networking Ltd." - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
"Secunia PSI Agent" (Secunia PSI Agent) - "Secunia" - C:\Program Files\Secunia\PSI\PSIA.exe
"Secunia Update Agent" (Secunia Update Agent) - "Secunia" - C:\Program Files\Secunia\PSI\sua.exe
[Winsock Providers]
-----( HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries )-----
"mdnsNSP" - "Apple Inc." - C:\Program Files\Bonjour\mdnsNSP.dll
===[ Logfile end ]=========================================[ Logfile end ]===
If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru |