Barnie_P | 28.02.2015 22:02 | und da zu lang hier der Rest:
Addition Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-02-2015 01
Ran by Malte at 2015-02-28 19:43:50
Running from C:\Users\Malte\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avira Desktop (Disabled - Out of date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AV: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
AS: Avira Desktop (Enabled - Out of date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
FW: McAfee Firewall (Enabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
abDocs (HKLM-x32\...\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.05.2005 - Acer Incorporated)
abDocs Office AddIn (HKLM-x32\...\{DCBF3379-246B-47E1-8173-639B63940838}) (Version: 3.01.2006 - Acer Incorporated)
abFiles (HKLM-x32\...\{13885028-098C-4799-9B71-27DAC96502D5}) (Version: 2.00.3002 - Acer Incorporated)
abMedia (HKLM-x32\...\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 2.06.2003.0 - Acer Incorporated)
abPhoto (HKLM-x32\...\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 3.01.2005.1 - Acer Incorporated)
Acer Care Center (HKLM\...\{A424844F-CDB3-45E2-BB77-1DDE4A091E76}) (Version: 1.00.3013 - Acer Incorporated)
Acer Explorer Agent (HKLM\...\{4D0F42CF-1693-43D9-BDC8-19141D023EE0}) (Version: 2.00.3000 - Acer Incorporated)
Acer Launch Manager (HKLM\...\{C18D55BD-1EC6-466D-B763-8EEDDDA9100E}) (Version: 8.00.8107 - Acer Incorporated)
Acer Portal (HKLM-x32\...\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 3.04.2002 - Acer Incorporated)
Acer Power Management (HKLM\...\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.8105 - Acer Incorporated)
Acer Quick Access (HKLM\...\{C1FA525F-D701-4B31-9D32-504FC0CF0B98}) (Version: 1.01.3016.0 - Acer Incorporated)
Acer Recovery Management (HKLM\...\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.8108 - Acer Incorporated)
Acer User Experience Improvement Program App Monitor Plugin (HKLM\...\{978724F6-1863-4DD5-9E66-FB77F5AB5613}) (Version: 1.02.3005 - Acer Incorporated)
Acer User Experience Improvement Program Framework (HKLM\...\{12A718F2-2357-4D41-9E1F-18583A4745F7}) (Version: 1.02.3005 - Acer Incorporated)
Acer Video Player (HKLM-x32\...\{B6846F20-4821-11E3-8F96-0800200C9A66}) (Version: 1.00.2005.0 - Acer Incorporated)
Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden
AMD Catalyst Install Manager (HKLM\...\{E043161E-A691-B3C2-E60C-2FBBD8CFF720}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
AOP Framework (HKLM-x32\...\{4A37A114-702F-4055-A4B6-16571D4A5353}) (Version: 3.04.2001.2 - Acer Incorporated)
Apple Application Support (32-Bit) (HKLM-x32\...\{447CDCE5-F555-429B-BFA6-642C3C6D684F}) (Version: 3.1.2 - Apple Inc.)
Apple Application Support (64-Bit) (HKLM\...\{0DF7096B-715A-4233-8633-C7A16ED6D616}) (Version: 3.1.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.2.344 - Avira)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.4917 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.4220 - CyberLink Corp.)
CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.4609.02 - CyberLink Corp.)
Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment)
eBay Worldwide (HKLM-x32\...\{91589413-6675-4C27-8AFC-EFB9103B90A5}) (Version: 2.4.0105 - OEM)
EPSON SX430 Series Printer Uninstall (HKLM\...\EPSON SX430 Series) (Version: - SEIKO EPSON Corporation)
Farm to Fork Collector's Edition (x32 Version: 3.0.2.59 - WildTangent) Hidden
Foxit PhantomPDF (HKLM-x32\...\{D4DF5498-C95C-4A02-9951-725FB2D7BC0D}) (Version: 6.0.121.624 - Foxit Corporation)
Game Explorer Categories - genres (HKLM-x32\...\WildTangentGameProvider-acer-genres) (Version: 11.0.0.7 - WildTangent, Inc.)
Game Explorer Categories - main (HKLM-x32\...\WildTangentGameProvider-acer-main) (Version: 11.0.0.7 - WildTangent, Inc.)
Governor of Poker 2 Premium Edition (x32 Version: 3.0.2.59 - WildTangent) Hidden
GPS Master 2.0.14 (HKLM-x32\...\GPS Master_is1) (Version: 1.0 - GPS Master)
Intel(R) Technology Access (HKLM-x32\...\{1c3caad7-d0ad-4f7c-87e0-f47627304993}) (Version: 1.3.3.1036 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\...\{43FA4AC8-46F8-423F-96FD-9A7D67048F1C}) (Version: 2.5.1634 - Intel Corporation)
iTunes (HKLM\...\{D227565A-0033-40AD-89BA-653A205CDC11}) (Version: 12.1.1.4 - Apple Inc.)
Jewel Match 3 (x32 Version: 3.0.2.59 - WildTangent) Hidden
King Oddball (x32 Version: 3.0.2.48 - WildTangent) Hidden
LUXOR Evolved (x32 Version: 2.2.0.98 - WildTangent) Hidden
Magic Academy (x32 Version: 2.2.0.98 - WildTangent) Hidden
McAfee LiveSafe – Internet Security (HKLM-x32\...\MSC) (Version: 13.6.1492 - McAfee, Inc.)
Microsoft Office 365 - de-de (HKLM\...\O365HomePremRetail - de-de) (Version: 15.0.4693.1002 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM-x32\...\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3703547061-3376583011-1854771401-1001\...\OneDriveSetup.exe) (Version: 17.3.1171.0714 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{d491dd9d-2eda-4d75-b504-1a201436e7fd}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Mozilla Firefox 35.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 35.0.1 - Mozilla)
OEM Application Profile (HKLM-x32\...\{C01EB132-6707-740E-6ED9-EAC3943918DB}) (Version: 1.00.0000 - Ihr Firmenname)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4693.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4693.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4693.1002 - Microsoft Corporation) Hidden
Outils de vérification linguistique 2013 de Microsoft Office*- Français (x32 Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 3.0.2.59 - WildTangent) Hidden
Pokki Start Menu (HKU\S-1-5-21-3703547061-3376583011-1854771401-1001\...\Pokki_Start_Menu) (Version: 0.269.7.513 - Pokki)
Polar Bowler 1st Frame (x32 Version: 3.0.2.59 - WildTangent) Hidden
PSP Application (Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.318 - Qualcomm Atheros Communications)
Qualcomm Atheros WLAN and Bluetooth Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 12.29 - Qualcomm Atheros)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.21250 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.20.815.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7209 - Realtek Semiconductor Corp.)
Silicon Laboratories CP210x USB to UART Bridge (Driver Removal) (HKLM-x32\...\SLABCOMM&10C4&EA60) (Version: - Silicon Laboratories)
Spotify (HKLM-x32\...\Spotify) (Version: 0.9.6.81.gd359a796 - Spotify AB)
The Chronicles of Emerland Solitaire (x32 Version: 3.0.2.51 - WildTangent) Hidden
Trinklit Supreme (x32 Version: 2.2.0.98 - WildTangent) Hidden
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App (x32 Version: 4.0.11.13 - WildTangent) Hidden
Windows-Treiberpaket - Sunplus (SPCP825K) Ports (07/01/2010 1.0.9.0) (HKLM\...\20986CDBFBCA238AA12329A115B1CC9D88E9C06C) (Version: 07/01/2010 1.0.9.0 - Sunplus)
Zuma's Revenge (x32 Version: 2.2.0.97 - WildTangent) Hidden
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-3703547061-3376583011-1854771401-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Malte\AppData\Local\Microsoft\SkyDrive\17.3.1171.0714\amd64\FileSyncApi64.dll (Microsoft Corporation)
==================== Restore Points =========================
21-02-2015 16:29:23 Neuer PC
24-02-2015 18:23:13 Intel(R) Technology Access
24-02-2015 18:24:40 Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005
28-02-2015 14:21:37 Installed Microsoft Office Professional Plus 2013
28-02-2015 14:22:35 PROPLUS
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 14:25 - 2013-08-22 14:25 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {2923779E-6EEB-48BE-A74D-8C074541E151} - System32\Tasks\ACCAgent => C:\Program Files (x86)\Acer\Care Center\LiveUpdateAgent.exe [2014-08-29] ()
Task: {2C2FA82F-1114-4426-8B2D-F369790B6C38} - System32\Tasks\Recovery Management\Notification => C:\Program Files\Acer\Acer Recovery Management\Notification\Notification.exe [2014-06-17] (Acer Incorporated)
Task: {308B71A7-DE03-4681-B049-048A505CB9EC} - System32\Tasks\Launch Manager => C:\Program Files\Acer\Acer Launch Manager\LMLauncher.exe [2014-06-10] (Acer Incorporate)
Task: {311FCA89-D9D8-4896-A247-F1BAF861D18F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-12-30] (Microsoft Corporation)
Task: {34EBBBA5-1818-4B57-B66C-2C3B1267E0A3} - System32\Tasks\avayvaxvaa => C:\Users\Malte\AppData\Local\avayvaxvaa\avayvaxvaa.exe [2015-02-19] () <==== ATTENTION
Task: {4621F24C-2B09-4415-A9B5-59E80B23B1ED} - System32\Tasks\ACC => C:\Program Files (x86)\Acer\Care Center\LiveUpdateChecker.exe [2014-08-29] ()
Task: {5614C184-72C4-40F5-A755-12F542788543} - System32\Tasks\GEQQXB => C:\ProgramData\c7c84291db714fdf8d05f80181f5f2cc\c7c84291db714fdf8d05f80181f5f2cc.exe
Task: {606ABF8C-366D-4A76-B803-248DC0E6E732} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-3703547061-3376583011-1854771401-1001 => %localappdata%\Microsoft\SkyDrive\SkyDrive.exe
Task: {906C6A98-1283-4904-9BD1-5EB9DD9DE95B} - System32\Tasks\Quick Access Quick Launcher => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-06-26] (Acer Incorporate)
Task: {98275CD5-8666-411E-8DF8-27795E34E6C6} - System32\Tasks\Quick Access => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-06-26] (Acer Incorporate)
Task: {9BF19265-D1DB-4E15-93D4-8D09F193ED8A} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {A0E186C4-F55A-4D93-9309-23CDAB1A5D91} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-06-09] ()
Task: {A2000DAB-2A86-4227-B10E-DE780BAAC78D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {AA9F1F0F-147D-4013-A93A-B1C5D81C0680} - System32\Tasks\Software Update Application => C:\ProgramData\OEM\UpgradeTool\ListCheck.exe [2014-06-08] (Acer Incorporated)
Task: {CB3FFA78-D2E6-4EF4-98EB-EB5D7DE21F8D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {D2510E3F-F687-4E1D-BACD-341ACA69BA2A} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {D2CD4AB2-BA9C-47F2-86D8-0AE27D621D80} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTrayLauncher.exe [2014-06-12] (Acer Incorporated)
Task: {D797C792-ECA8-4A69-86AE-B84D7A39117E} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2014-12-30] (Microsoft Corporation)
Task: {E00B3FAD-661D-49B9-A7DC-39C705503DA6} - System32\Tasks\AcerCloud => C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe [2014-12-19] (Acer)
Task: {EB0F2C10-C941-4A3A-AE3C-3E11A32EF15C} - System32\Tasks\gtaUpt => C:\Program Files\shopperz\zaeed.bat
Task: {EC60EE7E-941C-4A0B-91BB-5716C36237B3} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {F69239AC-BF10-463C-8CAE-7FD508923AE7} - System32\Tasks\UbtFrameworkService => C:\Program Files\Acer\User Experience Improvement Program\Framework\TriggerFramework.exe [2014-03-13] (TODO: <Company name>)
Task: {F791B659-6C21-47EE-BA4F-2B78F8320C17} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-06-09] ()
Task: {F7C39EA8-855E-4AB7-BE50-91554F4D3542} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-01-29] (Microsoft Corporation)
==================== Loaded Modules (whitelisted) ==============
2015-02-13 04:20 - 2015-02-13 04:20 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-02-13 04:20 - 2015-02-13 04:20 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-02-28 14:52 - 2015-02-28 14:52 - 00174592 _____ () C:\Users\Malte\AppData\Roaming\BD428936-1425135095-E411-85C7-F0761C3E0316\jnsqE207.tmp
2015-02-22 12:59 - 2014-05-20 08:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2015-02-28 14:51 - 2015-02-28 14:51 - 00123904 _____ () C:\Users\Malte\AppData\Roaming\BD428936-1425135095-E411-85C7-F0761C3E0316\nsqB071.tmpfs
2015-02-08 11:06 - 2015-02-08 11:06 - 00087552 _____ () C:\Program Files\Intel Corporation\Intel(R) Technology Access\libglog.dll
2015-02-08 11:20 - 2015-02-08 11:20 - 01793248 _____ () C:\Program Files\Intel Corporation\Intel(R) Technology Access\cpprest120_1_4.dll
2015-02-08 11:20 - 2015-02-08 11:20 - 00355040 _____ () C:\Program Files\Intel Corporation\Intel(R) Technology Access\JsonCpp.dll
2014-07-25 22:23 - 2012-04-24 11:43 - 00254512 ____N () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
2014-02-25 22:14 - 2014-02-25 22:14 - 00011264 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\ActivateDesktopDebugger\ActivateDesktopDebugger.dll
2014-02-25 22:11 - 2014-02-25 22:11 - 00086016 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\Map\MAP.dll
2014-02-25 22:17 - 2014-02-25 22:17 - 00012928 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
2014-12-19 21:59 - 2014-12-19 21:59 - 00090880 _____ () C:\Program Files (x86)\Acer\abDocs\abDocsDllLoader.exe
2014-12-19 21:59 - 2014-12-19 21:59 - 00089344 _____ () C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe
2015-02-26 13:45 - 2015-02-26 13:45 - 01459712 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.UI\4bd80968bf666252841ca7792faaff11\Windows.UI.ni.dll
2012-08-31 11:28 - 2012-08-31 11:28 - 00005120 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MetroNotifications.dll
2015-02-26 13:45 - 2015-02-26 13:45 - 00521216 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Data\fae2b750f87849ca11806d20b2504bf2\Windows.Data.ni.dll
2015-02-26 13:45 - 2015-02-26 13:45 - 00363520 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_64\Windows.Foundation\6382e6f5ad8b7a9db4f5cd4817e70319\Windows.Foundation.ni.dll
2015-02-28 15:10 - 2013-12-18 09:32 - 00394808 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2015-02-21 14:54 - 2015-02-21 14:54 - 00015616 _____ () C:\Windows\assembly\GAC_MSIL\MyService\1.0.0.1__2dfa3f50f0bed57d\MyService.dll
2014-12-19 21:16 - 2014-12-19 21:16 - 00013568 _____ () C:\Program Files (x86)\Acer\AOP Framework\ServiceInterface.dll
2014-12-29 13:25 - 2014-12-29 13:25 - 00203008 _____ () C:\Program Files (x86)\Acer\abPhoto\curllib.dll
2014-12-29 13:26 - 2014-12-29 13:26 - 00654552 _____ () C:\Program Files (x86)\Acer\abPhoto\sqlite3.dll
2014-12-29 13:26 - 2014-12-29 13:26 - 00630528 _____ () C:\Program Files (x86)\Acer\abPhoto\tag.dll
2014-12-29 13:26 - 2014-12-29 13:26 - 00119552 _____ () C:\Program Files (x86)\Acer\abPhoto\OpenLDAP.dll
2014-12-19 21:10 - 2014-12-19 21:10 - 00277096 _____ () C:\Program Files (x86)\Acer\AOP Framework\libcurl.dll
2014-12-19 22:00 - 2014-12-19 22:00 - 00279296 _____ () C:\Program Files (x86)\Acer\abDocs\libcurl.dll
2015-02-21 15:18 - 2015-01-23 11:37 - 03925104 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2014-11-04 15:57 - 2014-11-04 15:57 - 00149760 _____ () C:\Program Files (x86)\Acer\abDocs Office AddIn\AcerWordAddin.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Users\Malte\OneDrive:ms-properties
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3703547061-3376583011-1854771401-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Malte\AppData\Roaming\Mozilla\Firefox\Desktop-Hintergrund.bmp
DNS Servers: 192.168.178.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== Accounts: =============================
Administrator (S-1-5-21-3703547061-3376583011-1854771401-500 - Administrator - Disabled)
Gast (S-1-5-21-3703547061-3376583011-1854771401-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3703547061-3376583011-1854771401-1003 - Limited - Enabled)
Malte (S-1-5-21-3703547061-3376583011-1854771401-1001 - Administrator - Enabled) => C:\Users\Malte
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (02/28/2015 06:59:38 PM) (Source: Perflib) (EventID: 1017) (User: )
Description: Outlook
Error: (02/28/2015 06:59:38 PM) (Source: Perflib) (EventID: 1021) (User: )
Description: Outlook8
Error: (02/28/2015 04:55:47 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: BackgroundAgent.exe, Version: 1.0.1.6, Zeitstempel: 0x5494253a
Name des fehlerhaften Moduls: MSVCR90.dll, Version: 9.0.30729.8387, Zeitstempel: 0x51ea24a5
Ausnahmecode: 0x80000001
Fehleroffset: 0x00056b1d
ID des fehlerhaften Prozesses: 0x1688
Startzeit der fehlerhaften Anwendung: 0xBackgroundAgent.exe0
Pfad der fehlerhaften Anwendung: BackgroundAgent.exe1
Pfad des fehlerhaften Moduls: BackgroundAgent.exe2
Berichtskennung: BackgroundAgent.exe3
Vollständiger Name des fehlerhaften Pakets: BackgroundAgent.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: BackgroundAgent.exe5
Error: (02/28/2015 04:11:24 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: IntelTechnologyAccessService.exe, Version: 1.3.3.1036, Zeitstempel: 0x54d7a6cb
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.3.9600.17278, Zeitstempel: 0x53eebf2e
Ausnahmecode: 0x40000015
Fehleroffset: 0x000000000000606c
ID des fehlerhaften Prozesses: 0x978
Startzeit der fehlerhaften Anwendung: 0xIntelTechnologyAccessService.exe0
Pfad der fehlerhaften Anwendung: IntelTechnologyAccessService.exe1
Pfad des fehlerhaften Moduls: IntelTechnologyAccessService.exe2
Berichtskennung: IntelTechnologyAccessService.exe3
Vollständiger Name des fehlerhaften Pakets: IntelTechnologyAccessService.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: IntelTechnologyAccessService.exe5
Error: (02/28/2015 04:10:25 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: qrsvc.exe, Version: 1.10.0.9, Zeitstempel: 0x54d51cc7
Name des fehlerhaften Moduls: qrsvc.exe, Version: 1.10.0.9, Zeitstempel: 0x54d51cc7
Ausnahmecode: 0xc0000409
Fehleroffset: 0x000250ec
ID des fehlerhaften Prozesses: 0xab0
Startzeit der fehlerhaften Anwendung: 0xqrsvc.exe0
Pfad der fehlerhaften Anwendung: qrsvc.exe1
Pfad des fehlerhaften Moduls: qrsvc.exe2
Berichtskennung: qrsvc.exe3
Vollständiger Name des fehlerhaften Pakets: qrsvc.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: qrsvc.exe5
Error: (02/28/2015 03:49:05 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: mqWwmwEj.exe, Version: 1.0.0.0, Zeitstempel: 0x54f016b8
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.3.9600.17278, Zeitstempel: 0x53eeb460
Ausnahmecode: 0xc06d007e
Fehleroffset: 0x00012f71
ID des fehlerhaften Prozesses: 0x1814
Startzeit der fehlerhaften Anwendung: 0xmqWwmwEj.exe0
Pfad der fehlerhaften Anwendung: mqWwmwEj.exe1
Pfad des fehlerhaften Moduls: mqWwmwEj.exe2
Berichtskennung: mqWwmwEj.exe3
Vollständiger Name des fehlerhaften Pakets: mqWwmwEj.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: mqWwmwEj.exe5
Error: (02/28/2015 03:46:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: ccicabfcebce.exe, Version: 2015.226.1329.32, Zeitstempel: 0x54ef1fd3
Name des fehlerhaften Moduls: ccicabfcebce.exe, Version: 2015.226.1329.32, Zeitstempel: 0x54ef1fd3
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00001c5d
ID des fehlerhaften Prozesses: 0x2bd8
Startzeit der fehlerhaften Anwendung: 0xccicabfcebce.exe0
Pfad der fehlerhaften Anwendung: ccicabfcebce.exe1
Pfad des fehlerhaften Moduls: ccicabfcebce.exe2
Berichtskennung: ccicabfcebce.exe3
Vollständiger Name des fehlerhaften Pakets: ccicabfcebce.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ccicabfcebce.exe5
Error: (02/28/2015 03:40:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: ccicabfcebce.exe, Version: 2015.226.1329.32, Zeitstempel: 0x54ef1fd3
Name des fehlerhaften Moduls: ccicabfcebce.exe, Version: 2015.226.1329.32, Zeitstempel: 0x54ef1fd3
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00001c5d
ID des fehlerhaften Prozesses: 0xfb0
Startzeit der fehlerhaften Anwendung: 0xccicabfcebce.exe0
Pfad der fehlerhaften Anwendung: ccicabfcebce.exe1
Pfad des fehlerhaften Moduls: ccicabfcebce.exe2
Berichtskennung: ccicabfcebce.exe3
Vollständiger Name des fehlerhaften Pakets: ccicabfcebce.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ccicabfcebce.exe5
Error: (02/28/2015 03:39:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: ccicabfcebce.exe, Version: 2015.226.1329.32, Zeitstempel: 0x54ef1fd3
Name des fehlerhaften Moduls: ccicabfcebce.exe, Version: 2015.226.1329.32, Zeitstempel: 0x54ef1fd3
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00001c5d
ID des fehlerhaften Prozesses: 0x231c
Startzeit der fehlerhaften Anwendung: 0xccicabfcebce.exe0
Pfad der fehlerhaften Anwendung: ccicabfcebce.exe1
Pfad des fehlerhaften Moduls: ccicabfcebce.exe2
Berichtskennung: ccicabfcebce.exe3
Vollständiger Name des fehlerhaften Pakets: ccicabfcebce.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ccicabfcebce.exe5
Error: (02/28/2015 03:35:25 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: ccicabfcebce.exe, Version: 2015.226.1329.32, Zeitstempel: 0x54ef1fd3
Name des fehlerhaften Moduls: ccicabfcebce.exe, Version: 2015.226.1329.32, Zeitstempel: 0x54ef1fd3
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00001c5d
ID des fehlerhaften Prozesses: 0x2974
Startzeit der fehlerhaften Anwendung: 0xccicabfcebce.exe0
Pfad der fehlerhaften Anwendung: ccicabfcebce.exe1
Pfad des fehlerhaften Moduls: ccicabfcebce.exe2
Berichtskennung: ccicabfcebce.exe3
Vollständiger Name des fehlerhaften Pakets: ccicabfcebce.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: ccicabfcebce.exe5
System errors:
=============
Error: (02/28/2015 07:16:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "70F4EEDB-1367-4b4f-8247-3133551A7415" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (02/28/2015 07:07:46 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "70F4EEDB-1367-4b4f-8247-3133551A7415" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (02/28/2015 07:06:21 PM) (Source: DCOM) (EventID: 10010) (User: Maltes-PC)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}
Error: (02/28/2015 07:06:21 PM) (Source: DCOM) (EventID: 10010) (User: Maltes-PC)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}
Error: (02/28/2015 07:06:21 PM) (Source: DCOM) (EventID: 10010) (User: Maltes-PC)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}
Error: (02/28/2015 07:06:20 PM) (Source: DCOM) (EventID: 10010) (User: Maltes-PC)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}
Error: (02/28/2015 04:34:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "70F4EEDB-1367-4b4f-8247-3133551A7415" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (02/28/2015 04:32:42 PM) (Source: DCOM) (EventID: 10010) (User: Maltes-PC)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}
Error: (02/28/2015 04:30:06 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "ePower Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (02/28/2015 04:30:06 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Cyberlink RichVideo Service(CRVS)" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Microsoft Office Sessions:
=========================
Error: (02/28/2015 06:59:38 PM) (Source: Perflib) (EventID: 1017) (User: )
Description: Outlook
Error: (02/28/2015 06:59:38 PM) (Source: Perflib) (EventID: 1021) (User: )
Description: Outlook8
Error: (02/28/2015 04:55:47 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: BackgroundAgent.exe1.0.1.65494253aMSVCR90.dll9.0.30729.838751ea24a58000000100056b1d168801d0536c513fd775C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exeC:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.8387_none_5094ca96bcb6b2bb\MSVCR90.dll42036767-bf62-11e4-8264-f0761c3e0316
Error: (02/28/2015 04:11:24 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: IntelTechnologyAccessService.exe1.3.3.103654d7a6cbKERNELBASE.dll6.3.9600.1727853eebf2e40000015000000000000606c97801d053677c4bc097C:\Program Files\Intel Corporation\Intel(R) Technology Access\IntelTechnologyAccessService.exeC:\Windows\system32\KERNELBASE.dll0ecff8ce-bf5c-11e4-8263-f0761c3e0316
Error: (02/28/2015 04:10:25 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: qrsvc.exe1.10.0.954d51cc7qrsvc.exe1.10.0.954d51cc7c0000409000250ecab001d053677db4c3b0C:\Program Files (x86)\QuickRef_1.10.0.9\Service\qrsvc.exeC:\Program Files (x86)\QuickRef_1.10.0.9\Service\qrsvc.exeebab1ff1-bf5b-11e4-8263-f0761c3e0316
Error: (02/28/2015 03:49:05 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: mqWwmwEj.exe1.0.0.054f016b8KERNELBASE.dll6.3.9600.1727853eeb460c06d007e00012f71181401d05365b3155db5C:\ProgramData\HLxNbaMdad\dat\mqWwmwEj.exeC:\Windows\SYSTEM32\KERNELBASE.dllf0d0f99c-bf58-11e4-8262-f0761c3e0316
Error: (02/28/2015 03:46:27 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: ccicabfcebce.exe2015.226.1329.3254ef1fd3ccicabfcebce.exe2015.226.1329.3254ef1fd3c000000500001c5d2bd801d0536553063eccC:\Users\Malte\AppData\Local\Temp\ccicabfcebce.exeC:\Users\Malte\AppData\Local\Temp\ccicabfcebce.exe927708e5-bf58-11e4-8262-f0761c3e0316
Error: (02/28/2015 03:40:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: ccicabfcebce.exe2015.226.1329.3254ef1fd3ccicabfcebce.exe2015.226.1329.3254ef1fd3c000000500001c5dfb001d0536487a52e4cC:\Users\Malte\AppData\Local\Temp\ccicabfcebce.exeC:\Users\Malte\AppData\Local\Temp\ccicabfcebce.exec71b9352-bf57-11e4-8262-f0761c3e0316
Error: (02/28/2015 03:39:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: ccicabfcebce.exe2015.226.1329.3254ef1fd3ccicabfcebce.exe2015.226.1329.3254ef1fd3c000000500001c5d231c01d053644c44c41eC:\Users\Malte\AppData\Local\Temp\ccicabfcebce.exeC:\Users\Malte\AppData\Local\Temp\ccicabfcebce.exe8c7309d7-bf57-11e4-8262-f0761c3e0316
Error: (02/28/2015 03:35:25 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: ccicabfcebce.exe2015.226.1329.3254ef1fd3ccicabfcebce.exe2015.226.1329.3254ef1fd3c000000500001c5d297401d05363c76a9315C:\Users\Malte\AppData\Local\Temp\ccicabfcebce.exeC:\Users\Malte\AppData\Local\Temp\ccicabfcebce.exe07c23368-bf57-11e4-8262-f0761c3e0316
==================== Memory info ===========================
Processor: AMD A8-6410 APU with AMD Radeon R5 Graphics
Percentage of memory in use: 50%
Total physical RAM: 3288.23 MB
Available physical RAM: 1633.07 MB
Total Pagefile: 4632.23 MB
Available Pagefile: 2436.96 MB
Total Virtual: 131072 MB
Available Virtual: 131071.8 MB
==================== Drives ================================
Drive c: (Acer) (Fixed) (Total:915.09 GB) (Free:810.76 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 95034244)
Partition: GPT Partition Type.
==================== End Of Log ============================ GMER: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-02-28 20:10:54
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000022 WDC_WD10JPVX-22JC3T0 rev.01.01A01 931,51GB
Running: Gmer-19357.exe; Driver: C:\Users\Malte\AppData\Local\Temp\kxdiypow.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\Windows\System32\win32k.sys!W32pServiceTable fffff96000216200 15 bytes [00, 65, F4, 01, 80, 7D, 6A, ...]
.text C:\Windows\System32\win32k.sys!W32pServiceTable + 17 fffff96000216211 10 bytes [F3, FB, FF, 00, 17, C7, 00, ...]
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\atiesrxx.exe[76] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffe5fb1169a 4 bytes [B1, 5F, FE, 7F]
.text C:\Windows\system32\atiesrxx.exe[76] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffe5fb116a2 4 bytes [B1, 5F, FE, 7F]
.text C:\Windows\system32\atiesrxx.exe[76] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffe5fb1181a 4 bytes [B1, 5F, FE, 7F]
.text C:\Windows\system32\atiesrxx.exe[76] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffe5fb11832 4 bytes [B1, 5F, FE, 7F]
.text C:\Windows\system32\atieclxx.exe[1080] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffe5fb1169a 4 bytes [B1, 5F, FE, 7F]
.text C:\Windows\system32\atieclxx.exe[1080] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffe5fb116a2 4 bytes [B1, 5F, FE, 7F]
.text C:\Windows\system32\atieclxx.exe[1080] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffe5fb1181a 4 bytes [B1, 5F, FE, 7F]
.text C:\Windows\system32\atieclxx.exe[1080] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffe5fb11832 4 bytes [B1, 5F, FE, 7F]
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1740] C:\Windows\SYSTEM32\WSOCK32.dll!setsockopt + 194 00007ffe57df1f6a 4 bytes [DF, 57, FE, 7F]
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1740] C:\Windows\SYSTEM32\WSOCK32.dll!setsockopt + 218 00007ffe57df1f82 4 bytes [DF, 57, FE, 7F]
.text C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe[1884] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffe5fb1169a 4 bytes [B1, 5F, FE, 7F]
.text C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe[1884] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffe5fb116a2 4 bytes [B1, 5F, FE, 7F]
.text C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe[1884] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffe5fb1181a 4 bytes [B1, 5F, FE, 7F]
.text C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe[1884] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffe5fb11832 4 bytes [B1, 5F, FE, 7F]
.text C:\Windows\system32\mfevtps.exe[2080] C:\Windows\system32\psapi.dll!GetModuleBaseNameA + 506 00007ffe5fb1169a 4 bytes [B1, 5F, FE, 7F]
.text C:\Windows\system32\mfevtps.exe[2080] C:\Windows\system32\psapi.dll!GetModuleBaseNameA + 514 00007ffe5fb116a2 4 bytes [B1, 5F, FE, 7F]
.text C:\Windows\system32\mfevtps.exe[2080] C:\Windows\system32\psapi.dll!QueryWorkingSet + 118 00007ffe5fb1181a 4 bytes [B1, 5F, FE, 7F]
.text C:\Windows\system32\mfevtps.exe[2080] C:\Windows\system32\psapi.dll!QueryWorkingSet + 142 00007ffe5fb11832 4 bytes [B1, 5F, FE, 7F]
.text C:\Windows\Explorer.EXE[3016] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffe5fb1169a 4 bytes [B1, 5F, FE, 7F]
.text C:\Windows\Explorer.EXE[3016] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffe5fb116a2 4 bytes [B1, 5F, FE, 7F]
.text C:\Windows\Explorer.EXE[3016] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffe5fb1181a 4 bytes [B1, 5F, FE, 7F]
.text C:\Windows\Explorer.EXE[3016] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffe5fb11832 4 bytes [B1, 5F, FE, 7F]
.text C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe[4624] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffe5fb1169a 4 bytes [B1, 5F, FE, 7F]
.text C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe[4624] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffe5fb116a2 4 bytes [B1, 5F, FE, 7F]
.text C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe[4624] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffe5fb1181a 4 bytes [B1, 5F, FE, 7F]
.text C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe[4624] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffe5fb11832 4 bytes [B1, 5F, FE, 7F]
.text C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe[4008] C:\Windows\SYSTEM32\WSOCK32.dll!setsockopt + 194 00007ffe57df1f6a 4 bytes [DF, 57, FE, 7F]
.text C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe[4008] C:\Windows\SYSTEM32\WSOCK32.dll!setsockopt + 218 00007ffe57df1f82 4 bytes [DF, 57, FE, 7F]
.text C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe[4700] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffe5fb1169a 4 bytes [B1, 5F, FE, 7F]
.text C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe[4700] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffe5fb116a2 4 bytes [B1, 5F, FE, 7F]
.text C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe[4700] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffe5fb1181a 4 bytes [B1, 5F, FE, 7F]
.text C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe[4700] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffe5fb11832 4 bytes [B1, 5F, FE, 7F]
.text C:\Program Files\iTunes\iTunesHelper.exe[5260] C:\Windows\SYSTEM32\WSOCK32.dll!setsockopt + 194 00007ffe57df1f6a 4 bytes [DF, 57, FE, 7F]
.text C:\Program Files\iTunes\iTunesHelper.exe[5260] C:\Windows\SYSTEM32\WSOCK32.dll!setsockopt + 218 00007ffe57df1f82 4 bytes [DF, 57, FE, 7F]
.text C:\Program Files\Common Files\mcafee\platform\McUICnt.exe[5736] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffe5fb1169a 4 bytes [B1, 5F, FE, 7F]
.text C:\Program Files\Common Files\mcafee\platform\McUICnt.exe[5736] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffe5fb116a2 4 bytes [B1, 5F, FE, 7F]
.text C:\Program Files\Common Files\mcafee\platform\McUICnt.exe[5736] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffe5fb1181a 4 bytes [B1, 5F, FE, 7F]
.text C:\Program Files\Common Files\mcafee\platform\McUICnt.exe[5736] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffe5fb11832 4 bytes [B1, 5F, FE, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe[4372] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffe5fb1169a 4 bytes [B1, 5F, FE, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe[4372] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffe5fb116a2 4 bytes [B1, 5F, FE, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe[4372] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffe5fb1181a 4 bytes [B1, 5F, FE, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe[4372] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffe5fb11832 4 bytes [B1, 5F, FE, 7F]
---- Threads - GMER 2.1 ----
Thread C:\Windows\system32\csrss.exe [732:756] fffff96000892b90
Thread C:\Windows\Explorer.EXE [3016:7068] 00007ffe4c2cd73c
---- Processes - GMER 2.1 ----
Process C:\Users\Malte\AppData\Roaming\BD428936-1425135095-E411-85C7-F0761C3E0316\jnsqE207.tmp (*** suspicious ***) @ C:\Users\Malte\AppData\Roaming\BD428936-1425135095-E411-85C7-F0761C3E0316\jnsqE207.tmp [1816](2015-02-28 13:52:10) 0000000000840000
Process C:\Users\Malte\AppData\Roaming\BD428936-1425135095-E411-85C7-F0761C3E0316\nsqB071.tmpfs (*** suspicious ***) @ C:\Users\Malte\AppData\Roaming\BD428936-1425135095-E411-85C7-F0761C3E0316\nsqB071.tmpfs [2012](2015-02-28 13:51:58) 0000000000d20000
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- |