Ergebnis Log mit GMER: Code:
GMER 2.0.18454 - hxxp://www.gmer.net
Rootkit scan 2013-02-07 16:27:36
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 C300-CTF rev.0006 119,24GB
Running: gmer_2.0.18454.exe; Driver: C:\Users\*****\AppData\Local\Temp\ugloypod.sys
---- Kernel code sections - GMER 2.0 ----
.text C:\Windows\System32\win32k.sys!W32pServiceTable fffff96000193c00 7 bytes [C0, A0, F3, FF, 01, AC, F0]
.text C:\Windows\System32\win32k.sys!W32pServiceTable + 9 fffff96000193c09 2 bytes [06, 02]
---- User code sections - GMER 2.0 ----
.text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[2924] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074c81401 2 bytes [C8, 74]
.text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[2924] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074c81419 2 bytes [C8, 74]
.text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[2924] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074c81431 2 bytes [C8, 74]
.text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[2924] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074c8144a 2 bytes [C8, 74]
.text ... * 9
.text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[2924] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074c814dd 2 bytes [C8, 74]
.text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[2924] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074c814f5 2 bytes [C8, 74]
.text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[2924] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074c8150d 2 bytes [C8, 74]
.text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[2924] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074c81525 2 bytes [C8, 74]
.text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[2924] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074c8153d 2 bytes [C8, 74]
.text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[2924] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074c81555 2 bytes [C8, 74]
.text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[2924] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074c8156d 2 bytes [C8, 74]
.text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[2924] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074c81585 2 bytes [C8, 74]
.text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[2924] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074c8159d 2 bytes [C8, 74]
.text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[2924] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074c815b5 2 bytes [C8, 74]
.text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[2924] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074c815cd 2 bytes [C8, 74]
.text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[2924] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074c816b2 2 bytes [C8, 74]
.text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[2924] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074c816bd 2 bytes [C8, 74]
.text C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074c81401 2 bytes [C8, 74]
.text C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe[2228] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074c81419 2 bytes [C8, 74]
.text C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074c81431 2 bytes [C8, 74]
.text C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074c8144a 2 bytes [C8, 74]
.text ... * 9
.text C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe[2228] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074c814dd 2 bytes [C8, 74]
.text C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074c814f5 2 bytes [C8, 74]
.text C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe[2228] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074c8150d 2 bytes [C8, 74]
.text C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074c81525 2 bytes [C8, 74]
.text C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074c8153d 2 bytes [C8, 74]
.text C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe[2228] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074c81555 2 bytes [C8, 74]
.text C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074c8156d 2 bytes [C8, 74]
.text C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074c81585 2 bytes [C8, 74]
.text C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe[2228] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074c8159d 2 bytes [C8, 74]
.text C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074c815b5 2 bytes [C8, 74]
.text C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074c815cd 2 bytes [C8, 74]
.text C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074c816b2 2 bytes [C8, 74]
.text C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe[2228] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074c816bd 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2664] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExW + 17 0000000074c81401 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2664] C:\Windows\syswow64\psapi.dll!EnumProcessModules + 17 0000000074c81419 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2664] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 17 0000000074c81431 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2664] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 42 0000000074c8144a 2 bytes [C8, 74]
.text ... * 9
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2664] C:\Windows\syswow64\psapi.dll!EnumDeviceDrivers + 17 0000000074c814dd 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2664] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameA + 17 0000000074c814f5 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2664] C:\Windows\syswow64\psapi.dll!QueryWorkingSetEx + 17 0000000074c8150d 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2664] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameW + 17 0000000074c81525 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2664] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameW + 17 0000000074c8153d 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2664] C:\Windows\syswow64\psapi.dll!EnumProcesses + 17 0000000074c81555 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2664] C:\Windows\syswow64\psapi.dll!GetProcessMemoryInfo + 17 0000000074c8156d 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2664] C:\Windows\syswow64\psapi.dll!GetPerformanceInfo + 17 0000000074c81585 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2664] C:\Windows\syswow64\psapi.dll!QueryWorkingSet + 17 0000000074c8159d 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2664] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameA + 17 0000000074c815b5 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2664] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExA + 17 0000000074c815cd 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2664] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 20 0000000074c816b2 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2664] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 31 0000000074c816bd 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3484] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074c81401 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3484] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074c81419 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3484] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074c81431 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3484] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074c8144a 2 bytes [C8, 74]
.text ... * 9
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3484] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074c814dd 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3484] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074c814f5 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3484] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074c8150d 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3484] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074c81525 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3484] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074c8153d 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3484] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074c81555 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3484] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074c8156d 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3484] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074c81585 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3484] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074c8159d 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3484] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074c815b5 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3484] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074c815cd 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3484] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074c816b2 2 bytes [C8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3484] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074c816bd 2 bytes [C8, 74]
.text C:\Program Files\TPFanControl\TPFanControl.exe[5108] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074c81401 2 bytes [C8, 74]
.text C:\Program Files\TPFanControl\TPFanControl.exe[5108] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074c81419 2 bytes [C8, 74]
.text C:\Program Files\TPFanControl\TPFanControl.exe[5108] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074c81431 2 bytes [C8, 74]
.text C:\Program Files\TPFanControl\TPFanControl.exe[5108] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074c8144a 2 bytes [C8, 74]
.text ... * 9
.text C:\Program Files\TPFanControl\TPFanControl.exe[5108] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074c814dd 2 bytes [C8, 74]
.text C:\Program Files\TPFanControl\TPFanControl.exe[5108] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074c814f5 2 bytes [C8, 74]
.text C:\Program Files\TPFanControl\TPFanControl.exe[5108] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074c8150d 2 bytes [C8, 74]
.text C:\Program Files\TPFanControl\TPFanControl.exe[5108] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074c81525 2 bytes [C8, 74]
.text C:\Program Files\TPFanControl\TPFanControl.exe[5108] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074c8153d 2 bytes [C8, 74]
.text C:\Program Files\TPFanControl\TPFanControl.exe[5108] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074c81555 2 bytes [C8, 74]
.text C:\Program Files\TPFanControl\TPFanControl.exe[5108] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074c8156d 2 bytes [C8, 74]
.text C:\Program Files\TPFanControl\TPFanControl.exe[5108] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074c81585 2 bytes [C8, 74]
.text C:\Program Files\TPFanControl\TPFanControl.exe[5108] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074c8159d 2 bytes [C8, 74]
.text C:\Program Files\TPFanControl\TPFanControl.exe[5108] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074c815b5 2 bytes [C8, 74]
.text C:\Program Files\TPFanControl\TPFanControl.exe[5108] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074c815cd 2 bytes [C8, 74]
.text C:\Program Files\TPFanControl\TPFanControl.exe[5108] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074c816b2 2 bytes [C8, 74]
.text C:\Program Files\TPFanControl\TPFanControl.exe[5108] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074c816bd 2 bytes [C8, 74]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4904] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074c81401 2 bytes [C8, 74]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4904] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074c81419 2 bytes [C8, 74]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4904] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074c81431 2 bytes [C8, 74]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4904] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074c8144a 2 bytes [C8, 74]
.text ... * 9
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4904] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074c814dd 2 bytes [C8, 74]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4904] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074c814f5 2 bytes [C8, 74]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4904] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074c8150d 2 bytes [C8, 74]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4904] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074c81525 2 bytes [C8, 74]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4904] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074c8153d 2 bytes [C8, 74]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4904] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074c81555 2 bytes [C8, 74]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4904] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074c8156d 2 bytes [C8, 74]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4904] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074c81585 2 bytes [C8, 74]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4904] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074c8159d 2 bytes [C8, 74]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4904] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074c815b5 2 bytes [C8, 74]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4904] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074c815cd 2 bytes [C8, 74]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4904] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074c816b2 2 bytes [C8, 74]
.text C:\Program Files (x86)\RocketDock\RocketDock.exe[4904] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074c816bd 2 bytes [C8, 74]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5708] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074c81401 2 bytes [C8, 74]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5708] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074c81419 2 bytes [C8, 74]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5708] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074c81431 2 bytes [C8, 74]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5708] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074c8144a 2 bytes [C8, 74]
.text ... * 9
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5708] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074c814dd 2 bytes [C8, 74]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5708] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074c814f5 2 bytes [C8, 74]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5708] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074c8150d 2 bytes [C8, 74]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5708] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074c81525 2 bytes [C8, 74]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5708] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074c8153d 2 bytes [C8, 74]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5708] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074c81555 2 bytes [C8, 74]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5708] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074c8156d 2 bytes [C8, 74]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5708] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074c81585 2 bytes [C8, 74]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5708] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074c8159d 2 bytes [C8, 74]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5708] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074c815b5 2 bytes [C8, 74]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5708] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074c815cd 2 bytes [C8, 74]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5708] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074c816b2 2 bytes [C8, 74]
.text C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe[5708] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074c816bd 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074c81401 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[6076] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074c81419 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074c81431 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074c8144a 2 bytes [C8, 74]
.text ... * 9
.text C:\Windows\SysWOW64\RunDll32.exe[6076] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074c814dd 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074c814f5 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[6076] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074c8150d 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074c81525 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074c8153d 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[6076] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074c81555 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074c8156d 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074c81585 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[6076] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074c8159d 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074c815b5 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074c815cd 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074c816b2 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074c816bd 2 bytes [C8, 74]
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[6416] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074c81401 2 bytes [C8, 74]
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[6416] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074c81419 2 bytes [C8, 74]
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[6416] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074c81431 2 bytes [C8, 74]
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[6416] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074c8144a 2 bytes [C8, 74]
.text ... * 9
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[6416] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074c814dd 2 bytes [C8, 74]
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[6416] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074c814f5 2 bytes [C8, 74]
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[6416] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074c8150d 2 bytes [C8, 74]
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[6416] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074c81525 2 bytes [C8, 74]
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[6416] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074c8153d 2 bytes [C8, 74]
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[6416] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074c81555 2 bytes [C8, 74]
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[6416] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074c8156d 2 bytes [C8, 74]
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[6416] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074c81585 2 bytes [C8, 74]
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[6416] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074c8159d 2 bytes [C8, 74]
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[6416] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074c815b5 2 bytes [C8, 74]
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[6416] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074c815cd 2 bytes [C8, 74]
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[6416] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074c816b2 2 bytes [C8, 74]
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[6416] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074c816bd 2 bytes [C8, 74]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[6528] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074c81401 2 bytes [C8, 74]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[6528] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074c81419 2 bytes [C8, 74]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[6528] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074c81431 2 bytes [C8, 74]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[6528] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074c8144a 2 bytes [C8, 74]
.text ... * 9
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[6528] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074c814dd 2 bytes [C8, 74]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[6528] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074c814f5 2 bytes [C8, 74]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[6528] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074c8150d 2 bytes [C8, 74]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[6528] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074c81525 2 bytes [C8, 74]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[6528] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074c8153d 2 bytes [C8, 74]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[6528] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074c81555 2 bytes [C8, 74]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[6528] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074c8156d 2 bytes [C8, 74]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[6528] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074c81585 2 bytes [C8, 74]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[6528] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074c8159d 2 bytes [C8, 74]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[6528] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074c815b5 2 bytes [C8, 74]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[6528] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074c815cd 2 bytes [C8, 74]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[6528] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074c816b2 2 bytes [C8, 74]
.text C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe[6528] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074c816bd 2 bytes [C8, 74]
.text C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe[6728] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074c81401 2 bytes [C8, 74]
.text C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe[6728] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074c81419 2 bytes [C8, 74]
.text C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe[6728] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074c81431 2 bytes [C8, 74]
.text C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe[6728] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074c8144a 2 bytes [C8, 74]
.text ... * 9
.text C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe[6728] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074c814dd 2 bytes [C8, 74]
.text C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe[6728] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074c814f5 2 bytes [C8, 74]
.text C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe[6728] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074c8150d 2 bytes [C8, 74]
.text C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe[6728] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074c81525 2 bytes [C8, 74]
.text C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe[6728] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074c8153d 2 bytes [C8, 74]
.text C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe[6728] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074c81555 2 bytes [C8, 74]
.text C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe[6728] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074c8156d 2 bytes [C8, 74]
.text C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe[6728] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074c81585 2 bytes [C8, 74]
.text C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe[6728] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074c8159d 2 bytes [C8, 74]
.text C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe[6728] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074c815b5 2 bytes [C8, 74]
.text C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe[6728] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074c815cd 2 bytes [C8, 74]
.text C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe[6728] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074c816b2 2 bytes [C8, 74]
.text C:\PROGRA~2\ThinkPad\UTILIT~1\SCHTASK.exe[6728] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074c816bd 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\DllHost.exe[6504] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074c81401 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\DllHost.exe[6504] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074c81419 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\DllHost.exe[6504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074c81431 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\DllHost.exe[6504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074c8144a 2 bytes [C8, 74]
.text ... * 9
.text C:\Windows\SysWOW64\DllHost.exe[6504] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074c814dd 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\DllHost.exe[6504] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074c814f5 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\DllHost.exe[6504] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074c8150d 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\DllHost.exe[6504] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074c81525 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\DllHost.exe[6504] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074c8153d 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\DllHost.exe[6504] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074c81555 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\DllHost.exe[6504] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074c8156d 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\DllHost.exe[6504] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074c81585 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\DllHost.exe[6504] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074c8159d 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\DllHost.exe[6504] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074c815b5 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\DllHost.exe[6504] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074c815cd 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\DllHost.exe[6504] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074c816b2 2 bytes [C8, 74]
.text C:\Windows\SysWOW64\DllHost.exe[6504] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074c816bd 2 bytes [C8, 74]
---- User IAT/EAT - GMER 2.0 ----
IAT C:\Windows\system32\winlogon.exe[1076] @ C:\Windows\system32\UxTheme.dll[KERNEL32.dll!ReadFile] [55580002700] c:\windows\system32\uxtuneup.dll
IAT C:\Windows\system32\winlogon.exe[1076] @ C:\Windows\system32\themeservice.dll[KERNEL32.dll!GetProcAddress] [55580002820] c:\windows\system32\uxtuneup.dll
IAT C:\Windows\system32\winlogon.exe[1076] @ C:\Windows\system32\themeservice.dll[KERNEL32.dll!ReadFile] [55580002700] c:\windows\system32\uxtuneup.dll
IAT C:\Windows\system32\svchost.exe[1360] @ c:\windows\system32\themeservice.dll[KERNEL32.dll!GetProcAddress] [55580002820] c:\windows\system32\uxtuneup.dll
IAT C:\Windows\system32\svchost.exe[1360] @ c:\windows\system32\themeservice.dll[KERNEL32.dll!ReadFile] [55580002700] c:\windows\system32\uxtuneup.dll
IAT C:\Windows\system32\svchost.exe[1360] @ C:\Windows\system32\uxtheme.dll[KERNEL32.dll!GetProcAddress] [55580002820] c:\windows\system32\uxtuneup.dll
IAT C:\Windows\system32\svchost.exe[1360] @ C:\Windows\system32\uxtheme.dll[KERNEL32.dll!ReadFile] [55580002700] c:\windows\system32\uxtuneup.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppId] [7fef48c2750] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetMachineId] [7fef48c2b98] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmWriteSharedMachineId] [7fef48c7de0] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmCreateNewId] [7fef48c8130] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmReadSharedMachineId] [7fef48c1908] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmGetSession] [7fef48c1c00] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartUpload] [7fef48c81d8] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSet] [7fef48c2878] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamString] [7fef48c7a5c] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmIncrement] [7fef48c6c48] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamDWord] [7fef48c77bc] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppVersion] [7fef48c7064] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartSession] [7fef48c6544] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3324] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmEndSession] [7fef48c5e30] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ C:\Program Files\Microsoft IntelliPoint\ipoint.exe[sqmapi.dll!SqmStartUpload] [7feef3a81d8] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ C:\Program Files\Microsoft IntelliPoint\ipoint.exe[sqmapi.dll!SqmWaitForUploadComplete] [7feef3a86fc] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ C:\Program Files\Microsoft IntelliPoint\ipoint.exe[sqmapi.dll!SqmStartSession] [7feef3a6544] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ C:\Program Files\Microsoft IntelliPoint\ipoint.exe[sqmapi.dll!SqmEndSession] [7feef3a5e30] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ C:\Program Files\Microsoft IntelliPoint\ipoint.exe[sqmapi.dll!SqmSetUserId] [7feef3a2c90] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ C:\Program Files\Microsoft IntelliPoint\ipoint.exe[sqmapi.dll!SqmWriteSharedUserId] [7feef3a7fcc] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ C:\Program Files\Microsoft IntelliPoint\ipoint.exe[sqmapi.dll!SqmReadSharedUserId] [7feef3a22c8] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ C:\Program Files\Microsoft IntelliPoint\ipoint.exe[sqmapi.dll!SqmSetMachineId] [7feef3a2b98] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ C:\Program Files\Microsoft IntelliPoint\ipoint.exe[sqmapi.dll!SqmWriteSharedMachineId] [7feef3a7de0] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ C:\Program Files\Microsoft IntelliPoint\ipoint.exe[sqmapi.dll!SqmCreateNewId] [7feef3a8130] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ C:\Program Files\Microsoft IntelliPoint\ipoint.exe[sqmapi.dll!SqmReadSharedMachineId] [7feef3a1908] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ C:\Program Files\Microsoft IntelliPoint\ipoint.exe[sqmapi.dll!SqmSetAppVersion] [7feef3a7064] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ C:\Program Files\Microsoft IntelliPoint\ipoint.exe[sqmapi.dll!SqmSetAppId] [7feef3a2750] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ C:\Program Files\Microsoft IntelliPoint\ipoint.exe[sqmapi.dll!SqmIncrement] [7feef3a6c48] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ C:\Program Files\Microsoft IntelliPoint\ipoint.exe[sqmapi.dll!SqmAddToStreamDWord] [7feef3a77bc] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ C:\Program Files\Microsoft IntelliPoint\ipoint.exe[sqmapi.dll!SqmSetBool] [7feef3a6830] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ C:\Program Files\Microsoft IntelliPoint\ipoint.exe[sqmapi.dll!SqmSet] [7feef3a2878] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ C:\Program Files\Microsoft IntelliPoint\ipoint.exe[sqmapi.dll!SqmAddToStreamString] [7feef3a7a5c] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ C:\Program Files\Microsoft IntelliPoint\ipoint.exe[sqmapi.dll!SqmGetSession] [7feef3a1c00] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ c:\Program Files\Microsoft IntelliPoint\dpgcmd.dll[sqmapi.dll!SqmIncrement] [7feef3a6c48] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ c:\Program Files\Microsoft IntelliPoint\dpgcmd.dll[sqmapi.dll!SqmStartUpload] [7feef3a81d8] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ c:\Program Files\Microsoft IntelliPoint\dpgcmd.dll[sqmapi.dll!SqmStartSession] [7feef3a6544] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ c:\Program Files\Microsoft IntelliPoint\dpgcmd.dll[sqmapi.dll!SqmEndSession] [7feef3a5e30] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ c:\Program Files\Microsoft IntelliPoint\dpgcmd.dll[sqmapi.dll!SqmSetUserId] [7feef3a2c90] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ c:\Program Files\Microsoft IntelliPoint\dpgcmd.dll[sqmapi.dll!SqmWriteSharedUserId] [7feef3a7fcc] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ c:\Program Files\Microsoft IntelliPoint\dpgcmd.dll[sqmapi.dll!SqmReadSharedUserId] [7feef3a22c8] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ c:\Program Files\Microsoft IntelliPoint\dpgcmd.dll[sqmapi.dll!SqmSetMachineId] [7feef3a2b98] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ c:\Program Files\Microsoft IntelliPoint\dpgcmd.dll[sqmapi.dll!SqmWriteSharedMachineId] [7feef3a7de0] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ c:\Program Files\Microsoft IntelliPoint\dpgcmd.dll[sqmapi.dll!SqmCreateNewId] [7feef3a8130] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ c:\Program Files\Microsoft IntelliPoint\dpgcmd.dll[sqmapi.dll!SqmReadSharedMachineId] [7feef3a1908] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ c:\Program Files\Microsoft IntelliPoint\dpgcmd.dll[sqmapi.dll!SqmSetAppVersion] [7feef3a7064] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ c:\Program Files\Microsoft IntelliPoint\dpgcmd.dll[sqmapi.dll!SqmSetAppId] [7feef3a2750] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
IAT C:\Program Files\Microsoft IntelliPoint\ipoint.exe[4784] @ c:\Program Files\Microsoft IntelliPoint\dpgcmd.dll[sqmapi.dll!SqmGetSession] [7feef3a1c00] C:\Program Files\Microsoft IntelliPoint\sqmapi.dll
---- Registry - GMER 2.0 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00242cbb75ec
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00242cbb75ec@5056638792b6 0x5D 0xF9 0x0B 0xBD ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00242cbb75ec@c884470ebca1 0x58 0x06 0x74 0xE4 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00242cbb75ec@20689deb8878 0x08 0xA9 0x4A 0xC7 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00242cbb75ec (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00242cbb75ec@5056638792b6 0x5D 0xF9 0x0B 0xBD ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00242cbb75ec@c884470ebca1 0x58 0x06 0x74 0xE4 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00242cbb75ec@20689deb8878 0x08 0xA9 0x4A 0xC7 ...
Reg HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@C:\Users\*****\Documents\06_Handys\1.) HTC HD2\App\3.) App\xb4s gekauft\SPBBackup2.1\8_200912031319_SPBBackup2.1.exe 1
Reg HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@C:\Users\*****\Documents\06_Handys\1.) HTC HD2\App\5.) App\xb4s freeware\Communikation\mobexp200b100betasetup.exe 1
Reg HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@C:\Users\*****\Documents\04_Auto alles\OBD I+II\Prog\xb4s getestet\Scanmaster\ScanMasterProDEMO1.1.0.0.exe 1
Reg HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@C:\Users\*****\Documents\07_Handys\1.) HTC HD2\App\5.) App\xb4s freeware\Communikation\SkypeMobile3.exe 1
---- EOF - GMER 2.0 ---- Ergebnis MBR: Code:
aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2013-02-07 16:50:25
-----------------------------
16:50:25.508 OS Version: Windows x64 6.1.7601 Service Pack 1
16:50:25.508 Number of processors: 2 586 0x170A
16:50:25.509 ComputerName: *****-PC UserName: *****
16:50:25.865 Initialize success
16:50:31.714 AVAST engine defs: 13020700
16:51:17.879 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
16:51:17.885 Disk 0 Vendor: C300-CTF 0006 Size: 122104MB BusType: 3
16:51:17.893 Disk 0 MBR read successfully
16:51:17.896 Disk 0 MBR scan
16:51:17.903 Disk 0 Windows 7 default MBR code
16:51:17.907 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
16:51:17.914 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 122002 MB offset 206848
16:51:17.927 Disk 0 scanning C:\Windows\system32\drivers
16:51:23.724 Service scanning
16:51:38.523 Modules scanning
16:51:38.547 Disk 0 trace - called modules:
16:51:38.560 ntoskrnl.exe CLASSPNP.SYS disk.sys Sahdad64.sys ACPI.sys iaStor.sys hal.dll
16:51:38.568 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800823a170]
16:51:38.575 3 CLASSPNP.SYS[fffff8800162c43f] -> nt!IofCallDriver -> [0xfffffa800823aa20]
16:51:38.799 5 Sahdad64.sys[fffff88001de4e25] -> nt!IofCallDriver -> [0xfffffa8007c6ce40]
16:51:38.816 7 ACPI.sys[fffff88000f707a1] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8007c72050]
16:51:38.830 Scan finished successfully
16:52:17.354 Disk 0 MBR has been saved successfully to "C:\Users\*****\Desktop\Virensuche Ich\07.02.2013\2\MBR.dat"
16:52:17.360 The log file has been saved successfully to "C:\Users\*****\Desktop\Virensuche Ich\07.02.2013\2\aswMBR.txt" |