Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Lyricxeeker entfernt, aber Laptop immer noch langsam

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 03.11.2013, 12:09   #1
Segonji
 
Lyricxeeker entfernt, aber Laptop immer noch langsam - Standard

Lyricxeeker entfernt, aber Laptop immer noch langsam



Hiho,

bin neu hier. Auch wenn ich euer Engagement schätze, hatte ich natürlich gehofft es nie in Anspruch nehmen zu müssen

Jetzt habe ich seit etwa 2 Tagen ein kleines Problem. Mein Laptop fing während eines Computerspiels (WoW) an langsamer zu werden. Sobald ich zwischen Spiel und Internetbrowser (Chrome) hin und her wechselte, stürzte das Spiel ab. Das passierte dann mehrmals, bis der Laptop gleich mit hängenblieb. Nach dem Neustart viel mir auch auf dass Kaspersky nicht mehr automatisch gestartet wurde.
Am nächsten Tag war er dann sehr langsam. Geöffnete Dateien brauchten ewig um aufzugehen und Spiele hatten viel längere Ladezeiten, besonders wenn ich zwischen Spiel und Desktop getabbed habe. Ich hab dann Kaspersky laufen lassen. Zunächst hat er mir nichts angezeigt, aber als ich wieder in den Startbildschirm zurück bin waren da 3 Bedrohungen. 2 von Lyricxeeker und eine andere. Wenn ich mich recht entsinne hatte ich von Lyricxeeker vor einigen Wochen schon mal was, aber nachdem ich die entfernt hatte gab es keine Probleme. Hab dann über die Systemsteuerung Lyricxeeker sowie die 3 Bedrohungen entfernt. Dadurch wurde er etwas schneller aber kaum merklich. Hab dann noch adwcleaner laufen lassen und da auch noch einiges gefunden und entfernt. Das hat auch ein wenig bewirkt, aber so richtig schnell fühlt es sich noch nicht an.

Bevor ich jetzt noch weiteren Unsinn treibe, habe ich mich dann doch entschieden hier mal reinzuschauen. Hab hier zwar schon ein paar Threats gefunden aber möchte jetzt lieber nicht noch mehr kaputt machen.

Einen schönen Sonntag wünsche ich noch

mfg Segonji

Edit: Sorry die Logs vergessen

Frst.txt

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-10-2013
Ran by Grigorij (administrator) on GRIGORIJ-PC on 03-11-2013 12:37:47
Running from C:\Users\Grigorij\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
() C:\Program Files (x86)\PHotkey\ASLDRSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
() C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
(UPEK Inc.) C:\Program Files\Protector Suite\upeksvr.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
( ) C:\Windows\system32\lxdicoms.exe
(Motorola Mobility LLC) C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Motorola Mobility LLC) C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Motorola) C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe
() C:\Program Files (x86)\PHotkey\PHotkey.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
() C:\Program Files (x86)\PHotkey\ATouch64.exe
() C:\Program Files (x86)\PHotkey\PVDesktop.exe
() C:\Program Files (x86)\PHotkey\PVDAgent.exe
() C:\Program Files (x86)\PHotkey\POSD.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(TODO: <Company name>) C:\Program Files (x86)\PHotkey\HCSynApi.exe
(UPEK Inc.) C:\Program Files\Protector Suite\psqltray.exe
() C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe
() C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Expert System S.p.A.) C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Dropbox, Inc.) C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Curse) C:\Users\Grigorij\AppData\Local\Apps\2.0\0ORLJQ1P.L82\839WC6XQ.G08\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\CurseClient.exe
(Bibliographisches Institut GmbH) C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
(Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe
(Blizzard Entertainment) C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11817576 2011-04-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2209896 2011-04-18] (Realtek Semiconductor)
HKLM\...\Run: [PSQLLauncher] - C:\Program Files\Protector Suite\launcher.exe [84816 2010-12-10] (UPEK Inc.)
HKLM\...\Run: [IntelPAN] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation)
HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2028328 2010-01-22] (Synaptics Incorporated)
HKLM\...\Run: [MedionReminder] - C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe [443688 2011-05-26] (CyberLink)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1012000 2013-05-16] (NVIDIA Corporation)
HKLM\...\Run: [lxdimon.exe] - C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe [434856 2009-04-27] ()
HKLM\...\Run: [lxdiamon] - C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe [25256 2009-04-27] ()
HKLM\...\RunOnce: [MedionReminder] - C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe /DeleteRunKey [443688 2011-05-26] (CyberLink)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\psfus: C:\Program Files\Protector Suite\psqlpwd.dll (UPEK Inc.)
HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1820584 2013-10-30] (Valve Corporation)
HKCU\...\Run: [icq] - C:\Users\Grigorij\AppData\Roaming\ICQM\icq.exe [27598184 2013-06-02] (ICQ)
HKCU\...\Run: [Duden Korrektor SysTray] - C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe [332432 2011-07-04] (Expert System S.p.A.)
HKCU\...\Run: [GoogleDriveSync] - C:\Program Files (x86)\Google\Drive\googledrivesync.exe [20133824 2013-09-25] (Google)
HKCU\...\RunOnce: [Application Restart #1] - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe  --flag-switches-begin --flag-switches-end -- "hxxp://www.kaspersky-help.com/?hl=de-DE&link=error&type=OLA&error=2303168600&syst=Microsoft Windows 7 Home x64 Edition Service Pack 1 (build 7601)&pid=kis&version=11.0.2.556&hotfix=a.b&installid={445ED99A-846C-4BED-B7ED-51049BD84E0D}&serial=0000-000000-00000000&ktype=0&kcount=0&kcreat=&kexp=&kinst=&serror=4&sserror=7" --restore-last-session [844752 2013-10-09] (Google Inc.)
MountPoints2: {712801c0-cbc4-11e2-b0d2-806e6f6e6963} - E:\autorun.exe
MountPoints2: {7fa61f71-cb7d-11e2-a3c3-386077cba43f} - F:\MotorolaDeviceManagerSetup.exe -a
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\...\Run: [Dolby Home Theater v4] - C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-03] (CyberLink)
HKLM-x32\...\Run: [YouCam Mirage] - C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488 2011-04-15] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] - C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe [228448 2011-04-15] (CyberLink Corp.)
HKLM-x32\...\Run: [BDRegion] - C:\Program Files (x86)\CyberLink\Shared files\brs.exe [75048 2011-03-21] (cyberlink)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll [266448 2013-05-12] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [214448 2013-05-12] (NVIDIA Corporation)
Lsa: [Notification Packages] scecli C:\Program Files\Protector Suite\psqlpwd.dll
Startup: C:\Users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
Startup: C:\Users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

==================== Internet (Whitelisted) ====================

SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKCU - {676DEF01-FA5E-42DD-BE75-9CD4179EDE19} URL = hxxp://search.softonic.com/MOY00621/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=204c3cc00000000000004c809307ab58&r=506
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Extension: trtv3 - C:\Users\Grigorij\AppData\Roaming\Mozilla\Firefox\profiles\extensions\trtv3@trtv.com.xpi
FF HKLM-x32\...\Firefox\Extensions:  - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com

Chrome: 
=======
CHR HomePage: hxxp://www.kicker.de/
CHR RestoreOnStartup: "chrome://newtab/", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=48&cc=&mi=204c3cc00000000000004c809307ab58", "hxxp://www.google.com"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.260.3) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U26) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File
CHR Extension: (Google Docs) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (AdBlock) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.11_0
CHR Extension: (Dangerous Websites Blocker) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\14.0.0.4651_0
CHR Extension: (WEB.DE MailCheck) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaogepninmlbinccpbiakcgiolijlllo\1.2_0
CHR Extension: (WordPress.com) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\khjnjifipfkgglficmipimgjpbmlbemd\1.1.1_0
CHR Extension: (DVDVideoSoft) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.3.0.0_0
CHR Extension: (Google Wallet) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (365Scores - Live Scores,Sports News & Alerts) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmpppefjehmjbiplimkfjeamnohldmko\1.8.1_0
CHR Extension: (Gmail) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx

==================== Services (Whitelisted) =================

R2 ASLDRService; C:\Program Files (x86)\PHotkey\ASLDRSrv.exe [104968 2009-12-18] ()
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-01] (Kaspersky Lab ZAO)
S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [241648 2011-02-25] (CyberLink)
R2 GFNEXSrv; C:\Program Files (x86)\PHotkey\GFNEXSrv.exe [159752 2010-10-07] ()
R2 lxdi_device; C:\Windows\system32\lxdicoms.exe [876976 2007-06-11] ( )
R2 lxdi_device; C:\Windows\SysWow64\lxdicoms.exe [517040 2007-06-11] ( )
R2 Motorola Device Manager; C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [137528 2013-07-31] (Motorola Mobility LLC)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2013-10-25] ()

==================== Drivers (Whitelisted) ====================

R3 InputFilter_Hid_FlexDef2b; C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys [17920 2010-06-18] (Siliten)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [7717984 2013-10-01] (Kaspersky Lab ZAO)
S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [112224 2013-06-08] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [620640 2013-10-01] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-01] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-01] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-01] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178784 2013-06-06] (Kaspersky Lab ZAO)
R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2009-09-11] (PEGATRON)
S3 motccgpfl; system32\DRIVERS\motccgpfl.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-03 12:37 - 2013-11-03 12:37 - 00000000 ____D C:\FRST
2013-11-03 12:36 - 2013-11-03 12:35 - 01957098 _____ (Farbar) C:\Users\Grigorij\Desktop\FRST64.exe
2013-11-03 12:35 - 2013-11-03 12:35 - 01957098 _____ (Farbar) C:\Users\Grigorij\Downloads\FRST64.exe
2013-11-02 23:51 - 2013-11-02 23:53 - 00000000 ____D C:\AdwCleaner
2013-11-02 23:51 - 2013-11-02 23:51 - 01060070 _____ C:\Users\Grigorij\Downloads\adwcleaner-3.010.exe
2013-11-02 11:59 - 2013-11-02 11:59 - 00001540 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2013-11-02 11:58 - 2013-11-02 11:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-02 11:57 - 2013-11-02 11:57 - 00001444 _____ C:\Users\Public\Desktop\Free YouTube Download.lnk
2013-11-02 11:55 - 2013-11-02 11:56 - 32132232 _____ (DVDVideoSoft Ltd.                                           ) C:\Users\Grigorij\Downloads\FreeYouTubeToMP3Converter3.2.16.1028.exe
2013-11-02 11:47 - 2013-11-02 11:47 - 30445872 _____ (DVDVideoSoft Ltd.                                           ) C:\Users\Grigorij\Downloads\FreeYouTubeDownload (1).exe
2013-11-02 11:44 - 2013-11-02 11:44 - 00000000 ____D C:\ProgramData\Oracle
2013-11-02 11:44 - 2013-10-08 07:50 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-02 11:44 - 2013-10-08 07:46 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-11-02 11:44 - 2013-10-08 07:46 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-11-02 11:44 - 2013-10-08 07:46 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-11-02 11:43 - 2013-11-02 11:44 - 00004886 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-29 13:21 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-10-29 13:21 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-10-29 13:21 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-10-29 13:21 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-10-29 13:21 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-10-29 13:21 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-10-29 13:21 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-10-28 17:57 - 2013-10-28 17:57 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Ubisoft
2013-10-28 17:49 - 2013-10-28 17:49 - 00001730 _____ C:\Users\Grigorij\Desktop\Assassin's Creed.lnk
2013-10-28 17:41 - 2013-10-28 17:41 - 00000000 ____D C:\ProgramData\Ubisoft
2013-10-27 12:33 - 2013-10-27 12:33 - 01872114 _____ C:\Users\Grigorij\Downloads\pj64_1_6.zip
2013-10-27 12:31 - 2013-10-27 12:31 - 07362734 _____ C:\Users\Grigorij\Downloads\Vigilante 8.zip
2013-10-27 11:33 - 2013-10-27 11:34 - 11340380 _____ C:\Users\Grigorij\Downloads\vigilante 8 - 2nd offence (e) [!].zip
2013-10-27 11:33 - 2013-10-27 11:33 - 07486064 _____ C:\Users\Grigorij\Downloads\vigilante 8 (e) [!].zip
2013-10-27 11:27 - 2013-10-27 11:27 - 11368658 _____ C:\Users\Grigorij\Downloads\1080 snowboarding (e) (m4) [!].zip
2013-10-27 11:19 - 2013-10-27 11:20 - 27597639 _____ C:\Users\Grigorij\Downloads\starcraft 64 (e) [!].zip
2013-10-25 18:36 - 2013-10-26 21:30 - 00000000 ____D C:\Fraps
2013-10-25 18:36 - 2013-10-25 18:36 - 00000566 _____ C:\Users\Public\Desktop\Fraps.lnk
2013-10-25 18:11 - 2013-10-25 18:11 - 00614816 _____ C:\Users\Grigorij\Downloads\FRAPS - CHIP-Downloader.exe
2013-10-25 16:23 - 2013-10-25 16:23 - 00000939 _____ C:\Users\Grigorij\Desktop\Steam.lnk
2013-10-25 16:05 - 2013-10-25 16:30 - 00000000 ____D C:\Users\Grigorij\Documents\Assassin's Creed III
2013-10-25 15:58 - 2013-10-25 16:06 - 00000000 ____D C:\Users\Grigorij\AppData\Local\Ubisoft Game Launcher
2013-10-25 15:31 - 2013-10-28 17:20 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2013-10-25 15:31 - 2013-10-25 15:31 - 00189248 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-10-25 15:31 - 2013-10-25 15:31 - 00075136 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2013-10-25 15:31 - 2013-10-25 15:31 - 00001209 _____ C:\Users\Grigorij\Desktop\Uplay.lnk
2013-10-25 15:31 - 2013-10-25 15:31 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2013-10-25 15:31 - 2013-10-25 15:26 - 03123272 _____ C:\Windows\SysWOW64\pbsvc.exe
2013-10-25 14:11 - 2013-10-25 14:11 - 00000081 _____ C:\Users\Grigorij\gri.cp
2013-10-25 13:59 - 2013-10-25 13:59 - 10545441 _____ C:\Users\Grigorij\Downloads\LEGO Racers (D, F, E).zip
2013-10-25 13:58 - 2013-10-25 13:59 - 04840302 _____ C:\Users\Grigorij\Downloads\Snowboard Kids (E).zip
2013-10-25 13:57 - 2013-10-25 13:59 - 25675994 _____ C:\Users\Grigorij\Downloads\Star Wars Episode I - Racer (D, F, E).zip
2013-10-25 13:54 - 2013-10-25 13:55 - 10323803 _____ C:\Users\Grigorij\Downloads\Destruction Derby 64 (E).zip
2013-10-25 13:54 - 2013-10-25 13:55 - 10084676 _____ C:\Users\Grigorij\Downloads\Diddy Kong Racing (D, F, E).zip
2013-10-25 13:53 - 2013-10-25 13:54 - 16086013 _____ C:\Users\Grigorij\Downloads\Super Smash Bros (D, F, E).zip
2013-10-25 13:50 - 2013-10-25 13:51 - 16490258 _____ C:\Users\Grigorij\Downloads\Banjo-Kazooie (D, F, E).zip
2013-10-25 13:50 - 2013-10-25 13:50 - 22161948 _____ C:\Users\Grigorij\Downloads\Mario Party (D, F, E).zip
2013-10-25 13:50 - 2013-10-25 13:50 - 13896929 _____ C:\Users\Grigorij\Downloads\Southpark (D).zip
2013-10-25 13:48 - 2013-10-25 13:48 - 00001496 _____ C:\Users\Grigorij\Desktop\Project64.lnk
2013-10-25 13:45 - 2013-10-25 13:45 - 10186459 _____ C:\Users\Grigorij\Downloads\Star Fox 64 (D, F, E).zip
2013-10-25 13:38 - 2013-10-25 13:42 - 61310559 _____ C:\Users\Grigorij\Downloads\Conkers Bad Fur Day (E).zip
2013-10-25 13:34 - 2013-10-27 12:34 - 00000000 ____D C:\Program Files (x86)\Project64 2.1
2013-10-25 13:34 - 2013-10-25 13:34 - 04603228 _____ (                                                            ) C:\Users\Grigorij\Downloads\setup_Project64_2.1.exe
2013-10-25 09:54 - 2013-10-25 09:54 - 01038704 _____ (Amazon Services LLC) C:\Users\Grigorij\Downloads\Assassin_s_Creed_3_Digital_Deluxe_Edition_Downloader.exe
2013-10-21 18:06 - 2013-11-03 11:23 - 00000000 ___RD C:\Users\Grigorij\Google Drive
2013-10-21 18:06 - 2013-10-21 18:06 - 00709023 _____ C:\Users\Grigorij\Downloads\documents-export-2013-10-21.zip
2013-10-21 18:03 - 2013-10-21 18:03 - 00819136 _____ (Google Inc.) C:\Users\Grigorij\Downloads\googledrivesync.exe
2013-10-20 11:38 - 2013-10-20 11:38 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_ssadadb_01005.Wdf
2013-10-19 17:22 - 2013-10-19 17:22 - 00003186 _____ C:\Windows\System32\Tasks\{F81AA872-BD9F-4779-9147-A636F768F844}
2013-10-19 17:20 - 2013-10-19 17:20 - 11180128 _____ (Irfan Skiljan) C:\Users\Grigorij\Downloads\irfanview_plugins_436_setup.exe
2013-10-19 16:58 - 2013-10-19 16:58 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
2013-10-19 16:58 - 2013-10-19 16:58 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\IrfanView
2013-10-19 16:58 - 2013-10-19 16:58 - 00000000 ____D C:\Program Files (x86)\IrfanView
2013-10-19 16:56 - 2013-10-19 16:56 - 02145888 _____ (Irfan Skiljan) C:\Users\Grigorij\Downloads\iview436g_setup.exe
2013-10-10 13:44 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-10-10 13:44 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-10-10 13:44 - 2013-09-22 23:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-10 13:44 - 2013-09-22 23:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-10 13:44 - 2013-09-22 23:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-10-10 13:44 - 2013-09-22 23:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-10-10 13:44 - 2013-09-21 04:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-10 13:44 - 2013-09-21 04:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-10-10 13:44 - 2013-09-21 03:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-10-10 13:44 - 2013-09-21 03:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-10-10 12:47 - 2013-07-12 11:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2013-10-10 12:47 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2013-10-10 12:47 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-10 12:47 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-10-10 12:47 - 2013-07-03 05:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys
2013-10-10 12:47 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2013-10-10 12:47 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-10 12:47 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-10 12:47 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2013-10-10 12:47 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2013-10-10 12:47 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2013-10-10 12:47 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-10 12:47 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2013-10-10 12:47 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2013-10-10 12:47 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2013-10-10 12:47 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-10 12:47 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-10-10 12:47 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-10-10 12:46 - 2013-09-14 02:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-10-10 12:46 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-10-10 12:46 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2013-10-10 12:46 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2013-10-10 12:46 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-10-10 12:46 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-10-10 12:46 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2013-10-10 12:46 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-10-10 12:46 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2013-10-10 12:46 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-10-10 12:46 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-10-10 12:46 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-10-10 12:46 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2013-10-10 12:46 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-10-10 12:46 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2013-10-10 12:46 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-10-10 12:46 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-10-10 12:46 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-10-10 12:46 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-10-10 12:46 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-10 12:46 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2013-10-10 12:46 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2013-10-10 12:46 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2013-10-10 12:46 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2013-10-10 12:46 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2013-10-10 12:45 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2013-10-10 12:45 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-10 12:45 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 12:45 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2013-10-07 21:04 - 2013-10-07 21:04 - 00000000 ____D C:\Users\Grigorij\AppData\Local\Blizzard
2013-10-07 20:23 - 2013-10-18 20:25 - 00000000 ____D C:\Program Files (x86)\Hearthstone
2013-10-07 20:19 - 2013-10-07 20:19 - 05906904 _____ (Blizzard Entertainment) C:\Users\Grigorij\Downloads\Hearthstone-Beta-Setup-deDE.exe
2013-10-06 13:29 - 2013-10-06 13:30 - 01529890 _____ C:\Users\Grigorij\Downloads\deutsch_DW_v517.zip
2013-10-05 13:58 - 2013-10-05 14:49 - 00002226 _____ C:\Users\Public\Desktop\Europa Universalis III.lnk
2013-10-05 13:48 - 2013-10-05 13:48 - 00000000 ____D C:\Program Files (x86)\Paradox Interactive
2013-10-04 19:58 - 2013-11-03 12:37 - 00000000 ____D C:\Users\Grigorij\AppData\Local\Battle.net
2013-10-04 19:58 - 2013-10-04 19:59 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Battle.net
2013-10-04 19:58 - 2013-10-04 19:58 - 00001128 _____ C:\Users\Public\Desktop\Battle.net.lnk
2013-10-04 19:57 - 2013-10-16 14:12 - 00000000 ____D C:\Program Files (x86)\Battle.net
2013-10-04 19:54 - 2013-10-04 19:54 - 05690328 _____ (Blizzard Entertainment) C:\Users\Grigorij\Downloads\Battle.net-Beta-Setup-deDE.exe

==================== One Month Modified Files and Folders =======

2013-11-03 12:39 - 2009-07-14 05:45 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-03 12:39 - 2009-07-14 05:45 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-03 12:37 - 2013-11-03 12:37 - 00000000 ____D C:\FRST
2013-11-03 12:37 - 2013-10-04 19:58 - 00000000 ____D C:\Users\Grigorij\AppData\Local\Battle.net
2013-11-03 12:35 - 2013-11-03 12:36 - 01957098 _____ (Farbar) C:\Users\Grigorij\Desktop\FRST64.exe
2013-11-03 12:35 - 2013-11-03 12:35 - 01957098 _____ (Farbar) C:\Users\Grigorij\Downloads\FRST64.exe
2013-11-03 12:24 - 2013-06-02 14:08 - 00000000 ____D C:\Users\Grigorij\AppData\Local\Deployment
2013-11-03 12:06 - 2013-07-18 22:39 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-03 11:44 - 2013-08-05 12:32 - 00001114 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-03 11:41 - 2013-06-02 13:09 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-11-03 11:40 - 2013-06-02 14:43 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Dropbox
2013-11-03 11:28 - 2013-06-02 12:43 - 01910817 _____ C:\Windows\WindowsUpdate.log
2013-11-03 11:28 - 2011-05-16 15:04 - 00697082 _____ C:\Windows\system32\perfh007.dat
2013-11-03 11:28 - 2011-05-16 15:04 - 00148346 _____ C:\Windows\system32\perfc007.dat
2013-11-03 11:28 - 2009-07-14 06:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-03 11:28 - 2009-07-14 05:51 - 00100771 _____ C:\Windows\setupact.log
2013-11-03 11:25 - 2013-06-02 13:42 - 00000000 ____D C:\Program Files (x86)\Steam
2013-11-03 11:23 - 2013-10-21 18:06 - 00000000 ___RD C:\Users\Grigorij\Google Drive
2013-11-03 11:23 - 2013-06-02 14:44 - 00000000 ___RD C:\Users\Grigorij\Dropbox
2013-11-03 11:21 - 2013-08-05 12:32 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-03 11:21 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-03 11:20 - 2013-06-11 17:33 - 00000000 ____D C:\ProgramData\NVIDIA
2013-11-02 23:55 - 2010-11-21 04:47 - 00021338 _____ C:\Windows\PFRO.log
2013-11-02 23:53 - 2013-11-02 23:51 - 00000000 ____D C:\AdwCleaner
2013-11-02 23:51 - 2013-11-02 23:51 - 01060070 _____ C:\Users\Grigorij\Downloads\adwcleaner-3.010.exe
2013-11-02 23:34 - 2013-06-02 14:12 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Skype
2013-11-02 16:23 - 2013-08-17 19:09 - 00000000 ____D C:\Program Files (x86)\JDownloader
2013-11-02 16:20 - 2013-08-04 19:07 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\uTorrent
2013-11-02 11:59 - 2013-11-02 11:59 - 00001540 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2013-11-02 11:59 - 2013-06-15 18:13 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\DVDVideoSoft
2013-11-02 11:59 - 2013-06-15 18:13 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
2013-11-02 11:58 - 2013-11-02 11:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-02 11:57 - 2013-11-02 11:57 - 00001444 _____ C:\Users\Public\Desktop\Free YouTube Download.lnk
2013-11-02 11:56 - 2013-11-02 11:55 - 32132232 _____ (DVDVideoSoft Ltd.                                           ) C:\Users\Grigorij\Downloads\FreeYouTubeToMP3Converter3.2.16.1028.exe
2013-11-02 11:47 - 2013-11-02 11:47 - 30445872 _____ (DVDVideoSoft Ltd.                                           ) C:\Users\Grigorij\Downloads\FreeYouTubeDownload (1).exe
2013-11-02 11:44 - 2013-11-02 11:44 - 00000000 ____D C:\ProgramData\Oracle
2013-11-02 11:44 - 2013-11-02 11:43 - 00004886 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-11-02 11:44 - 2011-07-18 22:13 - 00000000 ____D C:\Program Files (x86)\Java
2013-10-31 18:07 - 2013-06-02 14:06 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2013-10-28 17:57 - 2013-10-28 17:57 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Ubisoft
2013-10-28 17:49 - 2013-10-28 17:49 - 00001730 _____ C:\Users\Grigorij\Desktop\Assassin's Creed.lnk
2013-10-28 17:41 - 2013-10-28 17:41 - 00000000 ____D C:\ProgramData\Ubisoft
2013-10-28 17:39 - 2011-07-18 21:49 - 00550829 _____ C:\Windows\DirectX.log
2013-10-28 17:20 - 2013-10-25 15:31 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2013-10-28 17:20 - 2011-07-18 22:23 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-10-27 12:34 - 2013-10-25 13:34 - 00000000 ____D C:\Program Files (x86)\Project64 2.1
2013-10-27 12:33 - 2013-10-27 12:33 - 01872114 _____ C:\Users\Grigorij\Downloads\pj64_1_6.zip
2013-10-27 12:31 - 2013-10-27 12:31 - 07362734 _____ C:\Users\Grigorij\Downloads\Vigilante 8.zip
2013-10-27 11:34 - 2013-10-27 11:33 - 11340380 _____ C:\Users\Grigorij\Downloads\vigilante 8 - 2nd offence (e) [!].zip
2013-10-27 11:33 - 2013-10-27 11:33 - 07486064 _____ C:\Users\Grigorij\Downloads\vigilante 8 (e) [!].zip
2013-10-27 11:27 - 2013-10-27 11:27 - 11368658 _____ C:\Users\Grigorij\Downloads\1080 snowboarding (e) (m4) [!].zip
2013-10-27 11:20 - 2013-10-27 11:19 - 27597639 _____ C:\Users\Grigorij\Downloads\starcraft 64 (e) [!].zip
2013-10-26 21:30 - 2013-10-25 18:36 - 00000000 ____D C:\Fraps
2013-10-26 11:07 - 2013-06-02 14:12 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-10-26 11:07 - 2013-06-02 14:12 - 00000000 ____D C:\ProgramData\Skype
2013-10-25 18:36 - 2013-10-25 18:36 - 00000566 _____ C:\Users\Public\Desktop\Fraps.lnk
2013-10-25 18:11 - 2013-10-25 18:11 - 00614816 _____ C:\Users\Grigorij\Downloads\FRAPS - CHIP-Downloader.exe
2013-10-25 16:30 - 2013-10-25 16:05 - 00000000 ____D C:\Users\Grigorij\Documents\Assassin's Creed III
2013-10-25 16:23 - 2013-10-25 16:23 - 00000939 _____ C:\Users\Grigorij\Desktop\Steam.lnk
2013-10-25 16:06 - 2013-10-25 15:58 - 00000000 ____D C:\Users\Grigorij\AppData\Local\Ubisoft Game Launcher
2013-10-25 15:31 - 2013-10-25 15:31 - 00189248 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-10-25 15:31 - 2013-10-25 15:31 - 00075136 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2013-10-25 15:31 - 2013-10-25 15:31 - 00001209 _____ C:\Users\Grigorij\Desktop\Uplay.lnk
2013-10-25 15:31 - 2013-10-25 15:31 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2013-10-25 15:26 - 2013-10-25 15:31 - 03123272 _____ C:\Windows\SysWOW64\pbsvc.exe
2013-10-25 14:11 - 2013-10-25 14:11 - 00000081 _____ C:\Users\Grigorij\gri.cp
2013-10-25 14:11 - 2013-06-02 12:48 - 00000000 ____D C:\Users\Grigorij
2013-10-25 13:59 - 2013-10-25 13:59 - 10545441 _____ C:\Users\Grigorij\Downloads\LEGO Racers (D, F, E).zip
2013-10-25 13:59 - 2013-10-25 13:58 - 04840302 _____ C:\Users\Grigorij\Downloads\Snowboard Kids (E).zip
2013-10-25 13:59 - 2013-10-25 13:57 - 25675994 _____ C:\Users\Grigorij\Downloads\Star Wars Episode I - Racer (D, F, E).zip
2013-10-25 13:55 - 2013-10-25 13:54 - 10323803 _____ C:\Users\Grigorij\Downloads\Destruction Derby 64 (E).zip
2013-10-25 13:55 - 2013-10-25 13:54 - 10084676 _____ C:\Users\Grigorij\Downloads\Diddy Kong Racing (D, F, E).zip
2013-10-25 13:54 - 2013-10-25 13:53 - 16086013 _____ C:\Users\Grigorij\Downloads\Super Smash Bros (D, F, E).zip
2013-10-25 13:51 - 2013-10-25 13:50 - 16490258 _____ C:\Users\Grigorij\Downloads\Banjo-Kazooie (D, F, E).zip
2013-10-25 13:50 - 2013-10-25 13:50 - 22161948 _____ C:\Users\Grigorij\Downloads\Mario Party (D, F, E).zip
2013-10-25 13:50 - 2013-10-25 13:50 - 13896929 _____ C:\Users\Grigorij\Downloads\Southpark (D).zip
2013-10-25 13:48 - 2013-10-25 13:48 - 00001496 _____ C:\Users\Grigorij\Desktop\Project64.lnk
2013-10-25 13:45 - 2013-10-25 13:45 - 10186459 _____ C:\Users\Grigorij\Downloads\Star Fox 64 (D, F, E).zip
2013-10-25 13:42 - 2013-10-25 13:38 - 61310559 _____ C:\Users\Grigorij\Downloads\Conkers Bad Fur Day (E).zip
2013-10-25 13:34 - 2013-10-25 13:34 - 04603228 _____ (                                                            ) C:\Users\Grigorij\Downloads\setup_Project64_2.1.exe
2013-10-25 09:54 - 2013-10-25 09:54 - 01038704 _____ (Amazon Services LLC) C:\Users\Grigorij\Downloads\Assassin_s_Creed_3_Digital_Deluxe_Edition_Downloader.exe
2013-10-23 19:10 - 2013-07-29 15:11 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\vlc
2013-10-23 19:08 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF
2013-10-21 18:06 - 2013-10-21 18:06 - 00709023 _____ C:\Users\Grigorij\Downloads\documents-export-2013-10-21.zip
2013-10-21 18:04 - 2013-06-02 12:53 - 00000000 ____D C:\Users\Grigorij\AppData\Local\Google
2013-10-21 18:04 - 2013-06-02 12:46 - 00000000 ____D C:\Program Files (x86)\Google
2013-10-21 18:03 - 2013-10-21 18:03 - 00819136 _____ (Google Inc.) C:\Users\Grigorij\Downloads\googledrivesync.exe
2013-10-20 11:38 - 2013-10-20 11:38 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_ssadadb_01005.Wdf
2013-10-19 17:22 - 2013-10-19 17:22 - 00003186 _____ C:\Windows\System32\Tasks\{F81AA872-BD9F-4779-9147-A636F768F844}
2013-10-19 17:20 - 2013-10-19 17:20 - 11180128 _____ (Irfan Skiljan) C:\Users\Grigorij\Downloads\irfanview_plugins_436_setup.exe
2013-10-19 16:58 - 2013-10-19 16:58 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
2013-10-19 16:58 - 2013-10-19 16:58 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\IrfanView
2013-10-19 16:58 - 2013-10-19 16:58 - 00000000 ____D C:\Program Files (x86)\IrfanView
2013-10-19 16:56 - 2013-10-19 16:56 - 02145888 _____ (Irfan Skiljan) C:\Users\Grigorij\Downloads\iview436g_setup.exe
2013-10-18 20:25 - 2013-10-07 20:23 - 00000000 ____D C:\Program Files (x86)\Hearthstone
2013-10-17 21:38 - 2013-08-05 12:32 - 00004110 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-17 21:38 - 2013-08-05 12:32 - 00003858 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-16 14:12 - 2013-10-04 19:57 - 00000000 ____D C:\Program Files (x86)\Battle.net
2013-10-11 16:10 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-10-10 13:54 - 2009-07-14 05:45 - 00339536 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-10 13:49 - 2013-06-07 16:27 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-10-10 13:47 - 2009-07-14 03:34 - 00000499 _____ C:\Windows\win.ini
2013-10-10 13:41 - 2013-06-07 16:27 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-10 13:34 - 2013-06-11 17:28 - 01591234 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-10-10 13:24 - 2013-07-19 20:16 - 00000000 ____D C:\Windows\system32\MRT
2013-10-10 13:15 - 2011-07-18 21:31 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-10-09 16:07 - 2013-07-18 22:39 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-09 16:07 - 2013-06-17 21:26 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-09 16:07 - 2011-08-10 20:09 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-10-08 07:50 - 2013-11-02 11:44 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-10-08 07:46 - 2013-11-02 11:44 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-10-08 07:46 - 2013-11-02 11:44 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-10-08 07:46 - 2013-11-02 11:44 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-10-07 21:04 - 2013-10-07 21:04 - 00000000 ____D C:\Users\Grigorij\AppData\Local\Blizzard
2013-10-07 20:19 - 2013-10-07 20:19 - 05906904 _____ (Blizzard Entertainment) C:\Users\Grigorij\Downloads\Hearthstone-Beta-Setup-deDE.exe
2013-10-06 13:30 - 2013-10-06 13:29 - 01529890 _____ C:\Users\Grigorij\Downloads\deutsch_DW_v517.zip
2013-10-05 14:49 - 2013-10-05 13:58 - 00002226 _____ C:\Users\Public\Desktop\Europa Universalis III.lnk
2013-10-05 13:48 - 2013-10-05 13:48 - 00000000 ____D C:\Program Files (x86)\Paradox Interactive
2013-10-04 19:59 - 2013-10-04 19:58 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Battle.net
2013-10-04 19:58 - 2013-10-04 19:58 - 00001128 _____ C:\Users\Public\Desktop\Battle.net.lnk
2013-10-04 19:54 - 2013-10-04 19:54 - 05690328 _____ (Blizzard Entertainment) C:\Users\Grigorij\Downloads\Battle.net-Beta-Setup-deDE.exe

Some content of TEMP:
====================
C:\Users\Grigorij\AppData\Local\Temp\COMAP.EXE
C:\Users\Grigorij\AppData\Local\Temp\drm_dialogs.dll
C:\Users\Grigorij\AppData\Local\Temp\drm_dyndata_7330017.dll
C:\Users\Grigorij\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\Grigorij\AppData\Local\Temp\MotoCast_Installer_2.0309.exe
C:\Users\Grigorij\AppData\Local\Temp\MotorolaDeviceManager_2.0403.exe
C:\Users\Grigorij\AppData\Local\Temp\nvStInst.exe
C:\Users\Grigorij\AppData\Local\Temp\SHSetup.exe
C:\Users\Grigorij\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Grigorij\AppData\Local\Temp\_is231C.exe
C:\Users\Grigorij\AppData\Local\Temp\_is3A53.exe
C:\Users\Grigorij\AppData\Local\Temp\_is3E6B.exe
C:\Users\Grigorij\AppData\Local\Temp\_is45B7.exe
C:\Users\Grigorij\AppData\Local\Temp\_is8C2D.exe
C:\Users\Grigorij\AppData\Local\Temp\_is8DBD.exe
C:\Users\Grigorij\AppData\Local\Temp\_is9A70.exe
C:\Users\Grigorij\AppData\Local\Temp\_is9C62.exe
C:\Users\Grigorij\AppData\Local\Temp\_isA3CF.exe
C:\Users\Grigorij\AppData\Local\Temp\_isB0EC.exe
C:\Users\Grigorij\AppData\Local\Temp\_isCC84.exe
C:\Users\Grigorij\AppData\Local\Temp\_isCE1C.exe
C:\Users\Grigorij\AppData\Local\Temp\_isD2DD.exe
C:\Users\Grigorij\AppData\Local\Temp\_isD30C.exe
C:\Users\Grigorij\AppData\Local\Temp\_isE71.exe
C:\Users\Grigorij\AppData\Local\Temp\_isE87F.exe
C:\Users\Grigorij\AppData\Local\Temp\_isF06B.exe
C:\Users\Grigorij\AppData\Local\Temp\_isF6CF.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-10-31 16:00

==================== End Of Log ============================
         
--- --- ---


Addtion.txt
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-10-2013
Ran by Grigorij at 2013-11-03 12:42:17
Running from C:\Users\Grigorij\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}

==================== Installed Programs ======================

7-Zip 9.20 (x32)
Adobe AIR (x32 Version: 2.7.1.19610)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117)
Adobe Reader X (10.1.8) MUI (x32 Version: 10.1.8)
Age of Empires® III: Complete Collection (x32)
Alan Wake (x32)
Alan Wake's American Nightmare (x32)
Assassin's Creed (x32 Version: 1.02)
Assassin's Creed(R) III v1.06 (x32 Version: 1.06)
Baldur's Gate: Enhanced Edition (x32)
Barbarian Invasion (x32 Version: 1.4)
Battle.net (x32)
Bully: Scholarship Edition (x32)
Compatibility Pack für 2007 Office System (x32 Version: 12.0.6612.1000)
Control ActiveX de Windows Live Mesh para conexiones remotas (x32 Version: 15.4.5722.2)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (x32 Version: 15.4.5722.2)
Controlo ActiveX do Windows Live Mesh para Ligações Remotas (x32 Version: 15.4.5722.2)
Curse Client (HKCU Version: 5.1.1.792)
CyberLink LabelPrint (x32 Version: 2.5.3624)
CyberLink Power2Go (x32 Version: 7.0.0.1327)
CyberLink PowerDVD 10 (x32 Version: 10.0.2731.52)
CyberLink PowerDVD Copy (x32 Version: 1.5.1306)
CyberLink PowerProducer (x32 Version: 5.0.2.3503)
CyberLink PowerRecover (x32 Version: 5.5.4125)
CyberLink YouCam (x32 Version: 3.1.4013)
D3DX10 (x32 Version: 15.4.2368.0902)
Darksiders II (x32)
Diablo III (x32)
Divine Wind Version 5.1 (x32 Version: 5.1)
Dolby Home Theater v4 (x32 Version: 7.2.7000.4)
Dropbox (HKCU Version: 2.0.22)
Duden-Rechtschreibprüfung kompakt (x32 Version: 8.0)
Dungeon Keeper 2 (x32 Version: 2.0.0.32)
Empire: Total War (x32)
Europa Universalis III (x32)
FINAL FANTASY VII (x32)
Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (x32 Version: 15.4.5722.2)
Fotogalerija Windows Live (x32 Version: 15.4.3502.0922)
Fraps (x32)
Free YouTube Download version 3.2.16.1030 (x32 Version: 3.2.16.1030)
Free YouTube to MP3 Converter version 3.12.16.1028 (x32 Version: 3.12.16.1028)
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922)
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922)
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922)
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922)
GOG.com Dungeon Keeper 2
Google Chrome (x32 Version: 30.0.1599.101)
Google Drive (x32 Version: 1.12.5329.1887)
Google Update Helper (x32 Version: 1.3.21.165)
Hearthstone (x32)
ICQ 8.0 (build 6017) (HKCU Version: 8.0.6017.0)
Intel PROSet Wireless
Intel PROSet Wireless (x32)
Intel(R) Processor Graphics (x32 Version: 8.15.10.2345)
Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (Version: 1.0.0.0135)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: 1.0.2.0518)
Intel(R) PROSet/Wireless WiFi Software (Version: 14.01.1000)
Intel(R) Rapid Storage Technology (x32 Version: 10.1.0.1008)
IrfanView (remove only) (x32 Version: 4.36)
Java 7 Update 45 (x32 Version: 7.0.450)
Java Auto Updater (x32 Version: 2.1.9.8)
Java(TM) 6 Update 26 (64-bit) (Version: 6.0.260)
Java(TM) 6 Update 26 (x32 Version: 6.0.260)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
Kaspersky Internet Security (x32 Version: 14.0.0.4651)
Kontrolnik Windows Live Mesh ActiveX za oddaljene povezave (x32 Version: 15.4.5722.2)
Left 4 Dead (x32)
Left 4 Dead 2 (x32)
Lexmark 3500-4500 Series
Medieval II Total War (x32 Version: 1.03.000)
Medieval II Total War : Kingdoms : Americas (x32 Version: 1.03.000)
Medieval II Total War : Kingdoms : Crusades (x32 Version: 1.03.000)
Medieval II Total War : Kingdoms : Teutonic (x32 Version: 1.03.000)
Medion Home Cinema (x32 Version: 8.0.2608)
Mesh Runtime (x32 Version: 15.4.5722.2)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office 2010 (x32 Version: 14.0.4763.1000)
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003)
Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1)
Microsoft Office Standard Edition 2003 (x32 Version: 11.0.8173.0)
Microsoft Silverlight (Version: 5.1.20913.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (Version: 10.0.30319)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Motorola Device Manager (x32 Version: 2.4.3)
Motorola Device Software Update (x32 Version: 13.07.3101)
Motorola Mobile Drivers Installation 6.2.0 (Version: 6.2.0)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0)
MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0)
Neverwinter (x32)
NVIDIA 3D Vision Treiber 320.18 (Version: 320.18)
NVIDIA GeForce Experience 1.5 (Version: 1.5)
NVIDIA Grafiktreiber 320.18 (Version: 320.18)
NVIDIA Install Application (Version: 2.1002.124.810)
NVIDIA Optimus 4.11.9 (Version: 4.11.9)
NVIDIA PhysX (x32 Version: 9.12.1031)
NVIDIA PhysX-Systemsoftware 9.12.1031 (Version: 9.12.1031)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.2018)
NVIDIA Systemsteuerung 320.18 (Version: 320.18)
NVIDIA Update 4.11.9 (Version: 4.11.9)
NVIDIA Update Components (Version: 4.11.9)
OpenAL (x32)
OpenOffice.org 3.4.1 (x32 Version: 3.41.9593)
PHotkey (x32 Version: 1.00.0038)
PlayReady PC Runtime amd64 (Version: 1.3.0)
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922)
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922)
Pošta Windows Live (x32 Version: 15.4.3502.0922)
Project 64 version 2.1.0.1 (x32 Version: 2.1.0.1)
Protector Suite 2011 (Version: 5.9.4.6894)
PunkBuster Services (x32 Version: 0.991)
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922)
Realtek Ethernet Controller Driver (x32 Version: 7.41.216.2011)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6353)
Realtek USB 2.0 Card Reader (x32 Version: 6.1.7600.30127)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.34.0)
Rome - Total War(TM) (x32 Version: 1.0)
Skype™ 6.9 (x32 Version: 6.9.106)
Spelling Dictionaries Support For Adobe Reader X (x32 Version: 10.0.0)
StarCraft II (x32)
Steam (x32 Version: 1.0.0.0)
Synaptics Pointing Device Driver (Version: 15.0.4.0)
Total War: ROME II (x32)
Total War: SHOGUN 2 (x32)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3)
Uplay (x32 Version: 2.0)
Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi (x32 Version: 15.4.5722.2)
VLC media player 2.0.8 (x32 Version: 2.0.8)
Warhammer 40,000 Space Marine (x32)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3538.0513)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922)
Windows Live Fotótár (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3538.0513)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (x32 Version: 15.4.5722.2)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX-objekt til fjernforbindelser (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz (x32 Version: 15.4.5722.2)
Windows Live Messenger (x32 Version: 15.4.3538.0513)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
World of Tanks (x32)
World of Warcraft (x32)
Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (x32 Version: 15.4.5722.2)
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922)

==================== Restore Points  =========================

29-10-2013 12:17:04 Geplanter Prüfpunkt
29-10-2013 21:55:42 Windows Update
02-11-2013 10:41:41 Installed Java 7 Update 45

==================== Hosts content: ==========================

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {4E622C2B-5E85-4949-AE5A-45C858E384CB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-05] (Google Inc.)
Task: {4EF22204-ED95-4DAD-84A8-D37B1C9B1F70} - System32\Tasks\Motorola Device Manager Engine => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2013-07-31] ()
Task: {89F65ADF-851A-4BD0-B0F1-D79030836679} - \Desk 365 RunAsStdUser No Task File
Task: {909C1320-8F08-42E3-8DAB-D7732B37CBF9} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-10-09] (Adobe Systems Incorporated)
Task: {95D26503-FF23-4F6B-AEFD-D1A2236CACFD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-05] (Google Inc.)
Task: {9E084E6C-0CD1-417D-BC3D-A67A283869B1} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-21] (Microsoft Corporation)
Task: {AE123183-93FE-44E7-838F-6B9E869DFE76} - System32\Tasks\Motorola Device Manager Update => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2013-07-31] ()
Task: {BEBD57B5-2758-4AC2-90D8-F5B40DE6420B} - System32\Tasks\Motorola Device Manager Initial Update => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2013-07-31] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2011-05-02 21:41 - 2011-05-02 21:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2011-08-30 23:07 - 2011-03-26 14:29 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2013-06-02 14:10 - 2013-06-02 14:09 - 00014848 _____ () C:\Users\Grigorij\AppData\Local\Apps\2.0\0ORLJQ1P.L82\839WC6XQ.G08\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\Curse.CurseClient.WowDb.dll
2013-06-02 14:10 - 2013-06-02 14:09 - 00035840 _____ () C:\Users\Grigorij\AppData\Local\Apps\2.0\0ORLJQ1P.L82\839WC6XQ.G08\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\Curse.Advertising.dll
2013-06-02 14:10 - 2013-06-02 14:09 - 00099840 _____ () C:\Users\Grigorij\AppData\Local\Apps\2.0\0ORLJQ1P.L82\839WC6XQ.G08\curs..tion_9e9e83ddf3ed3ead_0005.0001_181b5e0542e9eb6c\Curse.CurseClient.CMOD2.dll
2007-03-15 22:10 - 2007-03-15 22:10 - 00214016 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\lxdidr.dll
2007-02-07 02:31 - 2007-02-07 02:31 - 01389568 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\lxdiptpc.dll
2007-03-15 22:12 - 2007-03-15 22:12 - 00180224 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\lxdidrui.dll
2013-06-17 11:35 - 2013-06-17 11:35 - 00478400 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\dblite.dll
2013-05-08 13:52 - 2013-05-08 13:52 - 01270464 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\kpcengine.2.3.dll
2013-06-20 22:35 - 2013-06-20 22:35 - 00172032 _____ () C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\css_core.dll
2011-08-30 23:31 - 2009-12-18 23:36 - 00973432 ____R () C:\Program Files (x86)\PHotkey\acAuth.dll
2011-08-30 23:31 - 2009-12-18 23:41 - 00129544 ____R () C:\Program Files (x86)\PHotkey\GFNEX.dll
2013-08-13 14:16 - 2007-03-23 14:41 - 00278528 _____ () C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiscw.dll
2013-08-13 14:16 - 2007-03-05 09:45 - 00589824 _____ () C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdidatr.dll
2013-08-13 14:16 - 2006-12-28 10:47 - 00073728 _____ () C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdicats.dll
2013-08-13 14:16 - 2007-05-02 04:11 - 00040960 _____ () C:\Program Files (x86)\Lexmark 3500-4500 Series\App4R.Monitor.Core.dll
2013-08-13 14:16 - 2007-05-02 04:11 - 00028672 _____ () C:\Program Files (x86)\Lexmark 3500-4500 Series\App4R.Monitor.Common.dll
2013-08-13 14:16 - 2007-05-02 04:10 - 00057344 _____ () C:\Program Files (x86)\Lexmark 3500-4500 Series\App4R.DevMons.MCMDevMon.dll
2013-08-13 14:16 - 2007-04-30 07:19 - 00020480 _____ () C:\Program Files (x86)\Lexmark 3500-4500 Series\App4R.DevMons.NetworkCardDevMon.dll
2013-08-13 14:16 - 2007-04-30 07:19 - 00020480 _____ () C:\Program Files (x86)\Lexmark 3500-4500 Series\App4R.DevMons.ScanDevMon.dll
2013-08-13 14:16 - 2007-04-30 07:20 - 00011776 _____ () C:\Program Files (x86)\Lexmark 3500-4500 Series\App4R.DevMons.MCMDevMon.AutoPlayUtil.dll
2011-07-01 10:37 - 2011-07-01 10:37 - 00116736 _____ () C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\MBControls.dll
2013-03-13 21:48 - 2013-03-13 21:48 - 24978944 _____ () C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\libcef.dll
2010-08-03 23:39 - 2010-08-03 23:39 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2010-08-03 23:39 - 2010-08-03 23:39 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2012-08-10 15:51 - 2012-08-10 15:51 - 00985088 _____ () C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
2013-11-03 11:22 - 2013-11-03 11:22 - 00098816 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\win32api.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00110080 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\pywintypes27.dll
2013-11-03 11:22 - 2013-11-03 11:22 - 00364544 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\pythoncom27.dll
2013-11-03 11:22 - 2013-11-03 11:22 - 00044032 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\_socket.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 01153024 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\_ssl.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00320512 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\win32com.shell.shell.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00711680 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\_hashlib.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 01175040 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\wx._core_.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00805888 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\wx._gdi_.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00811008 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\wx._windows_.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 01062400 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\wx._controls_.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00735232 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\wx._misc_.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00128512 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\_elementtree.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00127488 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\pyexpat.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00557056 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\pysqlite2._sqlite.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00087040 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\_ctypes.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00119808 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\win32file.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00108544 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\win32security.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00018432 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\win32event.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00038912 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\win32inet.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00122368 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\wx._wizard.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00686080 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\unicodedata.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00026624 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\_multiprocessing.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00070656 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\wx._html2.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00010240 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\select.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00025600 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\win32pdh.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00504832 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\windows._cacheinvalidation.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00011264 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\win32crypt.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00035840 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\win32process.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00017408 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\win32profile.pyd
2013-11-03 11:22 - 2013-11-03 11:22 - 00022528 _____ () C:\Users\Grigorij\AppData\Local\Temp\_MEI37402\win32ts.pyd
2011-08-30 23:15 - 2010-11-06 07:50 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2013-04-23 17:30 - 2013-10-24 18:45 - 00691200 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2013-05-03 14:35 - 2013-10-30 20:25 - 01123240 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2013-03-26 15:16 - 2013-10-23 21:07 - 20625832 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll
2012-12-11 08:51 - 2013-06-15 00:49 - 01100800 _____ () C:\Program Files (x86)\Steam\bin\avcodec-53.dll
2012-12-11 08:51 - 2013-06-15 00:49 - 00124416 _____ () C:\Program Files (x86)\Steam\bin\avutil-51.dll
2012-12-11 08:51 - 2013-06-15 00:49 - 00192000 _____ () C:\Program Files (x86)\Steam\bin\avformat-53.dll
2013-10-19 10:46 - 2013-10-09 01:01 - 00698832 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\libglesv2.dll
2013-10-19 10:46 - 2013-10-09 01:01 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\libegl.dll
2013-10-19 10:46 - 2013-10-09 01:02 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll
2013-10-19 10:46 - 2013-10-09 01:02 - 00415184 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll
2013-10-19 10:46 - 2013-10-09 01:01 - 01604560 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ffmpegsumo.dll
2013-10-16 14:12 - 2013-10-16 14:12 - 26118656 _____ () C:\Program Files (x86)\Battle.net\Battle.net.3823\libcef.dll
2013-10-16 14:12 - 2013-10-16 14:12 - 00739840 _____ () C:\Program Files (x86)\Battle.net\Battle.net.3823\libglesv2.dll
2013-10-16 14:12 - 2013-10-16 14:12 - 00130048 _____ () C:\Program Files (x86)\Battle.net\Battle.net.3823\libegl.dll
2013-10-19 10:46 - 2013-10-09 01:02 - 13584336 _____ () C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (whitelisted) =========


==================== Safe Mode (whitelisted) ===================


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (11/03/2013 00:12:18 AM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: MotoHelperService.exe, Version: 2.3.7.0, Zeitstempel: 0x51f930eb
Name des fehlerhaften Moduls: MotoHelperService.exe, Version: 2.3.7.0, Zeitstempel: 0x51f930eb
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00010612
ID des fehlerhaften Prozesses: 0x9f8
Startzeit der fehlerhaften Anwendung: 0xMotoHelperService.exe0
Pfad der fehlerhaften Anwendung: MotoHelperService.exe1
Pfad des fehlerhaften Moduls: MotoHelperService.exe2
Berichtskennung: MotoHelperService.exe3

Error: (11/03/2013 00:11:24 AM) (Source: Application Hang) (User: )
Description: Programm eu3game.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 4a0

Startzeit: 01ced820994db834

Endzeit: 6

Anwendungspfad: C:\Program Files (x86)\Paradox Interactive\Europa Universalis III\eu3game.exe

Berichts-ID:

Error: (11/02/2013 11:53:33 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: MotoHelperService.exe, Version: 2.3.7.0, Zeitstempel: 0x51f930eb
Name des fehlerhaften Moduls: MotoHelperService.exe, Version: 2.3.7.0, Zeitstempel: 0x51f930eb
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00010612
ID des fehlerhaften Prozesses: 0xa1c
Startzeit der fehlerhaften Anwendung: 0xMotoHelperService.exe0
Pfad der fehlerhaften Anwendung: MotoHelperService.exe1
Pfad des fehlerhaften Moduls: MotoHelperService.exe2
Berichtskennung: MotoHelperService.exe3

Error: (11/02/2013 11:31:18 PM) (Source: Application Hang) (User: )
Description: Programm Wow-64.exe, Version 5.4.1.17538 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 15f0

Startzeit: 01ced81ae7bd09ee

Endzeit: 80

Anwendungspfad: C:\Program Files (x86)\World of Warcraft\Wow-64.exe

Berichts-ID: 7a80812c-440e-11e3-9233-386077cba43f

Error: (11/02/2013 11:28:36 PM) (Source: Application Hang) (User: )
Description: Programm Wow-64.exe, Version 5.4.1.17538 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 16c8

Startzeit: 01ced804d2e12a30

Endzeit: 1461

Anwendungspfad: C:\Program Files (x86)\World of Warcraft\Wow-64.exe

Berichts-ID: 09caecf0-440e-11e3-9233-386077cba43f

Error: (11/02/2013 03:34:07 PM) (Source: Application Hang) (User: )
Description: Programm eu3game.exe, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 15dc

Startzeit: 01ced7c04453fea7

Endzeit: 2355

Anwendungspfad: C:\Program Files (x86)\Paradox Interactive\Europa Universalis III\eu3game.exe

Berichts-ID:

Error: (11/02/2013 00:10:02 AM) (Source: Application Hang) (User: )
Description: Programm Wow-64.exe, Version 5.4.1.17538 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1768

Startzeit: 01ced754a47208ae

Endzeit: 690

Anwendungspfad: C:\Program Files (x86)\World of Warcraft\Wow-64.exe

Berichts-ID: abc8ec4a-434a-11e3-9b9c-386077cba43f

Error: (11/01/2013 11:28:37 PM) (Source: Application Hang) (User: )
Description: Programm Wow-64.exe, Version 5.4.1.17538 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 2fa4

Startzeit: 01ced751a52fe9c6

Endzeit: 18

Anwendungspfad: C:\Program Files (x86)\World of Warcraft\Wow-64.exe

Berichts-ID: f16bb074-4344-11e3-bbe0-386077cba43f

Error: (11/01/2013 11:28:37 PM) (Source: Application Hang) (User: )
Description: Programm Wow-64.exe, Version 5.4.1.17538 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 149c

Startzeit: 01ced7519b20b151

Endzeit: 18

Anwendungspfad: C:\Program Files (x86)\World of Warcraft\Wow-64.exe

Berichts-ID: ebc3da40-4344-11e3-bbe0-386077cba43f

Error: (11/01/2013 10:12:01 PM) (Source: Application Hang) (User: )
Description: Programm Wow-64.exe, Version 5.4.1.17538 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 15f8

Startzeit: 01ced716af97e4c6

Endzeit: 438

Anwendungspfad: C:\Program Files (x86)\World of Warcraft\Wow-64.exe

Berichts-ID: 132c2329-433a-11e3-bbe0-386077cba43f


System errors:
=============
Error: (11/03/2013 11:21:17 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "lxdiCATSCustConnectService" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (11/03/2013 11:21:17 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst lxdiCATSCustConnectService erreicht.

Error: (11/03/2013 00:12:34 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Motorola Device Manager Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 1000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (11/02/2013 11:55:53 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "lxdiCATSCustConnectService" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (11/02/2013 11:55:53 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst lxdiCATSCustConnectService erreicht.

Error: (11/02/2013 11:53:44 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Motorola Device Manager Service" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 1000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (11/02/2013 03:41:04 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "lxdiCATSCustConnectService" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (11/02/2013 03:41:04 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst lxdiCATSCustConnectService erreicht.

Error: (11/02/2013 11:31:52 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "lxdiCATSCustConnectService" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (11/02/2013 11:31:52 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst lxdiCATSCustConnectService erreicht.


Microsoft Office Sessions:
=========================
Error: (11/03/2013 00:12:18 AM) (Source: Application Error)(User: )
Description: MotoHelperService.exe2.3.7.051f930ebMotoHelperService.exe2.3.7.051f930ebc0000005000106129f801ced81eaf2d15aeC:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exeC:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe37a31676-4414-11e3-b50b-386077cba43f

Error: (11/03/2013 00:11:24 AM) (Source: Application Hang)(User: )
Description: eu3game.exe0.0.0.04a001ced820994db8346C:\Program Files (x86)\Paradox Interactive\Europa Universalis III\eu3game.exe

Error: (11/02/2013 11:53:33 PM) (Source: Application Error)(User: )
Description: MotoHelperService.exe2.3.7.051f930ebMotoHelperService.exe2.3.7.051f930ebc000000500010612a1c01ced7d98ecd818cC:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exeC:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe9823faca-4411-11e3-9233-386077cba43f

Error: (11/02/2013 11:31:18 PM) (Source: Application Hang)(User: )
Description: Wow-64.exe5.4.1.1753815f001ced81ae7bd09ee80C:\Program Files (x86)\World of Warcraft\Wow-64.exe7a80812c-440e-11e3-9233-386077cba43f

Error: (11/02/2013 11:28:36 PM) (Source: Application Hang)(User: )
Description: Wow-64.exe5.4.1.1753816c801ced804d2e12a301461C:\Program Files (x86)\World of Warcraft\Wow-64.exe09caecf0-440e-11e3-9233-386077cba43f

Error: (11/02/2013 03:34:07 PM) (Source: Application Hang)(User: )
Description: eu3game.exe0.0.0.015dc01ced7c04453fea72355C:\Program Files (x86)\Paradox Interactive\Europa Universalis III\eu3game.exe

Error: (11/02/2013 00:10:02 AM) (Source: Application Hang)(User: )
Description: Wow-64.exe5.4.1.17538176801ced754a47208ae690C:\Program Files (x86)\World of Warcraft\Wow-64.exeabc8ec4a-434a-11e3-9b9c-386077cba43f

Error: (11/01/2013 11:28:37 PM) (Source: Application Hang)(User: )
Description: Wow-64.exe5.4.1.175382fa401ced751a52fe9c618C:\Program Files (x86)\World of Warcraft\Wow-64.exef16bb074-4344-11e3-bbe0-386077cba43f

Error: (11/01/2013 11:28:37 PM) (Source: Application Hang)(User: )
Description: Wow-64.exe5.4.1.17538149c01ced7519b20b15118C:\Program Files (x86)\World of Warcraft\Wow-64.exeebc3da40-4344-11e3-bbe0-386077cba43f

Error: (11/01/2013 10:12:01 PM) (Source: Application Hang)(User: )
Description: Wow-64.exe5.4.1.1753815f801ced716af97e4c6438C:\Program Files (x86)\World of Warcraft\Wow-64.exe132c2329-433a-11e3-bbe0-386077cba43f


CodeIntegrity Errors:
===================================
  Date: 2013-10-31 16:03:16.183
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-10-31 16:03:16.181
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-10-31 16:03:16.178
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-10-31 16:03:16.146
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-10-31 16:03:16.144
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-10-31 16:03:16.141
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-10-29 19:05:51.482
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-10-29 19:05:51.479
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-10-29 19:05:51.475
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2013-10-29 19:05:51.452
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info =========================== 

Percentage of memory in use: 39%
Total physical RAM: 8103.05 MB
Available physical RAM: 4890.12 MB
Total Pagefile: 16204.29 MB
Available Pagefile: 12351.31 MB
Total Virtual: 8192 MB
Available Virtual: 8191.79 MB

==================== Drives ================================

Drive c: (Boot) (Fixed) (Total:647.54 GB) (Free:320.32 GB) NTFS
Drive d: (Recover) (Fixed) (Total:50 GB) (Free:28.97 GB) NTFS
Drive e: (AssassinsCreed) (CDROM) (Total:6.36 GB) (Free:0 GB) UDF

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 699 GB) (Disk ID: 97BE5B6A)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=648 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=50 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=1 GB) - (Type=12)

==================== End Of Log ============================
         

Geändert von Segonji (03.11.2013 um 12:46 Uhr)

Alt 03.11.2013, 13:47   #2
Segonji
 
Lyricxeeker entfernt, aber Laptop immer noch langsam - Standard

Lyricxeeker entfernt, aber Laptop immer noch langsam



Sorry weiß nciht wie man das GMER sonst hochläd.
__________________


Alt 03.11.2013, 20:18   #3
Segonji
 
Lyricxeeker entfernt, aber Laptop immer noch langsam - Standard

Lyricxeeker entfernt, aber Laptop immer noch langsam



Hab erst jetzt gesehen, dass ich die dann getrennt posten soll. Sorry ist nicht als Push gedacht
Code:
ATTFilter
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-11-03 13:16:50
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.JE4O 698,64GB
Running: 7j0c9k42.exe; Driver: C:\Users\Grigorij\AppData\Local\Temp\uxldrkod.sys


---- Kernel code sections - GMER 2.1 ----

INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528                                                                                                  fffff80003200000 54 bytes [B7, 44, 7D, 04, 8D, 47, FF, ...]
INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 583                                                                                                  fffff80003200037 21 bytes [0F, 43, C8, 8A, 01, 49, 8B, ...]

---- User code sections - GMER 2.1 ----

.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1600] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                      0000000076c3af40 7 bytes JMP 000000016fff0260
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1600] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                    0000000076c44a60 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1600] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                     0000000076c62990 5 bytes JMP 000000016fff01f0
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1600] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                               0000000076c6efe0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1600] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                             0000000076c999b0 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1600] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                             0000000076ca94d0 5 bytes JMP 000000016fff0180
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1600] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW                                             0000000076ca9640 5 bytes JMP 000000016fff0110
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1600] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                      0000000076cca500 7 bytes JMP 000000016fff0228
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1600] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                       000007fefcbe2db0 5 bytes JMP 000007fffcbd0180
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1600] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                  000007fefcbe37d0 7 bytes JMP 000007fffcbd00d8
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1600] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                    000007fefcbe8ef0 6 bytes JMP 000007fffcbd0148
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1600] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                000007fefcbfaf60 5 bytes JMP 000007fffcbd0110
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1600] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                 000007fefe8c89e0 8 bytes JMP 000007fffcbd01f0
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1600] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                               000007fefe8cbe40 8 bytes JMP 000007fffcbd01b8
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1600] C:\Windows\system32\ole32.dll!CoCreateInstance                                                       000007fefe137490 11 bytes JMP 000007fffcbd0228
.text     C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1600] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                      000007fefe14bf00 7 bytes JMP 000007fffcbd0260
.text     C:\Program Files\Protector Suite\upeksvr.exe[1996] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                                  0000000076c3af40 7 bytes JMP 000000016fff0260
.text     C:\Program Files\Protector Suite\upeksvr.exe[1996] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                                0000000076c44a60 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\Protector Suite\upeksvr.exe[1996] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                                 0000000076c62990 5 bytes JMP 000000016fff01f0
.text     C:\Program Files\Protector Suite\upeksvr.exe[1996] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                           0000000076c6efe0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\Protector Suite\upeksvr.exe[1996] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                         0000000076c999b0 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\Protector Suite\upeksvr.exe[1996] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                         0000000076ca94d0 5 bytes JMP 000000016fff0180
.text     C:\Program Files\Protector Suite\upeksvr.exe[1996] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW                                                         0000000076ca9640 5 bytes JMP 000000016fff0110
.text     C:\Program Files\Protector Suite\upeksvr.exe[1996] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                                  0000000076cca500 7 bytes JMP 000000016fff0228
.text     C:\Program Files\Protector Suite\upeksvr.exe[1996] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                   000007fefcbe2db0 5 bytes JMP 000007fffcbd0180
.text     C:\Program Files\Protector Suite\upeksvr.exe[1996] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                              000007fefcbe37d0 7 bytes JMP 000007fffcbd00d8
.text     C:\Program Files\Protector Suite\upeksvr.exe[1996] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                000007fefcbe8ef0 6 bytes JMP 000007fffcbd0148
.text     C:\Program Files\Protector Suite\upeksvr.exe[1996] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                            000007fefcbfaf60 5 bytes JMP 000007fffcbd0110
.text     C:\Program Files\Protector Suite\upeksvr.exe[1996] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                             000007fefe8c89e0 8 bytes JMP 000007fffcbd01f0
.text     C:\Program Files\Protector Suite\upeksvr.exe[1996] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                           000007fefe8cbe40 8 bytes JMP 000007fffcbd01b8
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe[2464] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                0000000076f01465 2 bytes [F0, 76]
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe[2464] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155               0000000076f014bb 2 bytes [F0, 76]
.text     ...                                                                                                                                                                 * 2
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2724] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                              0000000076f01465 2 bytes [F0, 76]
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[2724] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                             0000000076f014bb 2 bytes [F0, 76]
.text     ...                                                                                                                                                                 * 2
.text     C:\Windows\system32\Dwm.exe[2952] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                                    000007fefcbe2db0 5 bytes JMP 000007fffcbd0180
.text     C:\Windows\system32\Dwm.exe[2952] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                               000007fefcbe37d0 7 bytes JMP 000007fffcbd00d8
.text     C:\Windows\system32\Dwm.exe[2952] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                                 000007fefcbe8ef0 6 bytes JMP 000007fffcbd0148
.text     C:\Windows\system32\Dwm.exe[2952] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                                             000007fefcbfaf60 5 bytes JMP 000007fffcbd0110
.text     C:\Windows\system32\Dwm.exe[2952] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                              000007fefe8c89e0 8 bytes JMP 000007fffcbd01f0
.text     C:\Windows\system32\Dwm.exe[2952] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                                            000007fefe8cbe40 8 bytes JMP 000007fffcbd01b8
.text     C:\Windows\system32\Dwm.exe[2952] C:\Windows\system32\dxgi.dll!CreateDXGIFactory                                                                                    000007fef705dc88 5 bytes JMP 000007fff6e500d8
.text     C:\Windows\system32\Dwm.exe[2952] C:\Windows\system32\dxgi.dll!CreateDXGIFactory1                                                                                   000007fef705de10 5 bytes JMP 000007fff6e50110
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                        00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                          00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                          00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                         00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                 00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                 00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                 0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                   0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                      0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                    0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                        0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                           0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\user32.DLL!CreateWindowExW                           0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\user32.DLL!EnumDisplayDevicesA                       0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\user32.DLL!EnumDisplayDevicesW                       0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\user32.DLL!EnumDisplayDevicesW + 4                   0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\user32.DLL!DisplayConfigGetDeviceInfo                0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                   000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                     000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                  0000000076f01465 2 bytes [F0, 76]
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                 0000000076f014bb 2 bytes [F0, 76]
.text     ...                                                                                                                                                                 * 2
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                          0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[1912] C:\Windows\syswow64\ole32.dll!CoCreateInstance                           0000000076739d0b 5 bytes JMP 00000001703c123f
.text     C:\Windows\SysWOW64\PnkBstrA.exe[2568] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322                                                                             00000000714f1a22 2 bytes [4F, 71]
.text     C:\Windows\SysWOW64\PnkBstrA.exe[2568] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496                                                                             00000000714f1ad0 2 bytes [4F, 71]
.text     C:\Windows\SysWOW64\PnkBstrA.exe[2568] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552                                                                             00000000714f1b08 2 bytes [4F, 71]
.text     C:\Windows\SysWOW64\PnkBstrA.exe[2568] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730                                                                             00000000714f1bba 2 bytes [4F, 71]
.text     C:\Windows\SysWOW64\PnkBstrA.exe[2568] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762                                                                             00000000714f1bda 2 bytes [4F, 71]
.text     C:\Program Files (x86)\PHotkey\PHotkey.exe[2748] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                                  00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\PHotkey\PHotkey.exe[2748] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                                    00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\PHotkey\PHotkey.exe[2748] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                                    00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\PHotkey\PHotkey.exe[2748] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                                   00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\PHotkey\PHotkey.exe[2748] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                                                           00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\PHotkey\PHotkey.exe[2748] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                           00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\PHotkey\PHotkey.exe[2748] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                           0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\PHotkey\PHotkey.exe[2748] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                             0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\PHotkey\PHotkey.exe[2748] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                                0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\PHotkey\PHotkey.exe[2748] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                              0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\PHotkey\PHotkey.exe[2748] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                                  0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\PHotkey\PHotkey.exe[2748] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                                     0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\PHotkey\PHotkey.exe[2748] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                                     0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\PHotkey\PHotkey.exe[2748] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                                 0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\PHotkey\PHotkey.exe[2748] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                                 0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\PHotkey\PHotkey.exe[2748] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                                             0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\PHotkey\PHotkey.exe[2748] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                          0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\PHotkey\PHotkey.exe[2748] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                             000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\PHotkey\PHotkey.exe[2748] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                               000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\PHotkey\PHotkey.exe[2748] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                                    0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Program Files (x86)\PHotkey\PHotkey.exe[2748] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                                     0000000076739d0b 5 bytes JMP 00000001703c123f
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt.exe[2740] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                               00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt.exe[2740] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                                 00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt.exe[2740] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                                 00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt.exe[2740] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                                00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt.exe[2740] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                                                        00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt.exe[2740] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                        00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt.exe[2740] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                        0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt.exe[2740] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                          0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt.exe[2740] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                             0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt.exe[2740] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                           0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt.exe[2740] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                               0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt.exe[2740] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                                  0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt.exe[2740] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                                  0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt.exe[2740] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                              0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt.exe[2740] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                              0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt.exe[2740] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                                          0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt.exe[2740] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                       0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt.exe[2740] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                          000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt.exe[2740] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                            000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt.exe[2740] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                                 0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt.exe[2740] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                                  0000000076739d0b 5 bytes JMP 00000001703c123f
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe[2852] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                000007fefcbe2db0 5 bytes JMP 000007fffcbd0180
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe[2852] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                           000007fefcbe37d0 7 bytes JMP 000007fffcbd00d8
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe[2852] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                             000007fefcbe8ef0 6 bytes JMP 000007fffcbd0148
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe[2852] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                         000007fefcbfaf60 5 bytes JMP 000007fffcbd0110
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe[2852] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                          000007fefe8c89e0 8 bytes JMP 000007fffcbd01f0
.text     C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe[2852] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                        000007fefe8cbe40 8 bytes JMP 000007fffcbd01b8
.text     C:\Program Files (x86)\PHotkey\ATouch64.exe[3904] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                                   0000000076c3af40 7 bytes JMP 000000016fff0260
.text     C:\Program Files (x86)\PHotkey\ATouch64.exe[3904] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                                 0000000076c44a60 5 bytes JMP 000000016fff01b8
.text     C:\Program Files (x86)\PHotkey\ATouch64.exe[3904] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                                  0000000076c62990 5 bytes JMP 000000016fff01f0
.text     C:\Program Files (x86)\PHotkey\ATouch64.exe[3904] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                            0000000076c6efe0 5 bytes JMP 000000016fff0148
.text     C:\Program Files (x86)\PHotkey\ATouch64.exe[3904] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                          0000000076c999b0 7 bytes JMP 000000016fff00d8
.text     C:\Program Files (x86)\PHotkey\ATouch64.exe[3904] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                          0000000076ca94d0 5 bytes JMP 000000016fff0180
.text     C:\Program Files (x86)\PHotkey\ATouch64.exe[3904] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW                                                          0000000076ca9640 5 bytes JMP 000000016fff0110
.text     C:\Program Files (x86)\PHotkey\ATouch64.exe[3904] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                                   0000000076cca500 7 bytes JMP 000000016fff0228
.text     C:\Program Files (x86)\PHotkey\ATouch64.exe[3904] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                    000007fefcbe2db0 5 bytes JMP 000007fffcbd0180
.text     C:\Program Files (x86)\PHotkey\ATouch64.exe[3904] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                               000007fefcbe37d0 7 bytes JMP 000007fffcbd00d8
.text     C:\Program Files (x86)\PHotkey\ATouch64.exe[3904] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                 000007fefcbe8ef0 6 bytes JMP 000007fffcbd0148
.text     C:\Program Files (x86)\PHotkey\ATouch64.exe[3904] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                             000007fefcbfaf60 5 bytes JMP 000007fffcbd0110
.text     C:\Program Files (x86)\PHotkey\ATouch64.exe[3904] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                              000007fefe8c89e0 8 bytes JMP 000007fffcbd01f0
.text     C:\Program Files (x86)\PHotkey\ATouch64.exe[3904] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                            000007fefe8cbe40 8 bytes JMP 000007fffcbd01b8
.text     C:\Program Files (x86)\PHotkey\PVDesktop.exe[3948] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                   000007fefcbe2db0 5 bytes JMP 000007fffcbd0180
.text     C:\Program Files (x86)\PHotkey\PVDesktop.exe[3948] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                              000007fefcbe37d0 7 bytes JMP 000007fffcbd00d8
.text     C:\Program Files (x86)\PHotkey\PVDesktop.exe[3948] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                000007fefcbe8ef0 6 bytes JMP 000007fffcbd0148
.text     C:\Program Files (x86)\PHotkey\PVDesktop.exe[3948] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                            000007fefcbfaf60 5 bytes JMP 000007fffcbd0110
.text     C:\Program Files (x86)\PHotkey\PVDesktop.exe[3948] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                             000007fefe8c89e0 8 bytes JMP 000007fffcbd01f0
.text     C:\Program Files (x86)\PHotkey\PVDesktop.exe[3948] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                           000007fefe8cbe40 8 bytes JMP 000007fffcbd01b8
.text     C:\Program Files (x86)\PHotkey\PVDAgent.exe[3968] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                    000007fefcbe2db0 5 bytes JMP 000007fffcbd0180
.text     C:\Program Files (x86)\PHotkey\PVDAgent.exe[3968] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                               000007fefcbe37d0 7 bytes JMP 000007fffcbd00d8
.text     C:\Program Files (x86)\PHotkey\PVDAgent.exe[3968] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                 000007fefcbe8ef0 6 bytes JMP 000007fffcbd0148
.text     C:\Program Files (x86)\PHotkey\PVDAgent.exe[3968] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                             000007fefcbfaf60 5 bytes JMP 000007fffcbd0110
.text     C:\Program Files (x86)\PHotkey\PVDAgent.exe[3968] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                              000007fefe8c89e0 8 bytes JMP 000007fffcbd01f0
.text     C:\Program Files (x86)\PHotkey\PVDAgent.exe[3968] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                            000007fefe8cbe40 8 bytes JMP 000007fffcbd01b8
.text     C:\Program Files (x86)\PHotkey\POSD.exe[2700] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                                     00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\PHotkey\POSD.exe[2700] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                                       00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\PHotkey\POSD.exe[2700] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                                       00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\PHotkey\POSD.exe[2700] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                                      00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\PHotkey\POSD.exe[2700] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                                                              00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\PHotkey\POSD.exe[2700] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                              00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\PHotkey\POSD.exe[2700] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                              0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\PHotkey\POSD.exe[2700] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                                0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\PHotkey\POSD.exe[2700] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                                   0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\PHotkey\POSD.exe[2700] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                                 0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\PHotkey\POSD.exe[2700] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                                     0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\PHotkey\POSD.exe[2700] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                                        0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\PHotkey\POSD.exe[2700] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                                        0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\PHotkey\POSD.exe[2700] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                                    0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\PHotkey\POSD.exe[2700] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                                    0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\PHotkey\POSD.exe[2700] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                                                0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\PHotkey\POSD.exe[2700] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                             0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\PHotkey\POSD.exe[2700] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                                000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\PHotkey\POSD.exe[2700] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                                  000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\PHotkey\POSD.exe[2700] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                                       0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Program Files (x86)\PHotkey\POSD.exe[2700] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                                        0000000076739d0b 5 bytes JMP 00000001703c123f
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4224] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                               0000000076c3af40 7 bytes JMP 000000016fff0260
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4224] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                             0000000076c44a60 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4224] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                              0000000076c62990 5 bytes JMP 000000016fff01f0
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4224] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                        0000000076c6efe0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4224] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                      0000000076c999b0 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4224] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                      0000000076ca94d0 5 bytes JMP 000000016fff0180
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4224] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW                                                      0000000076ca9640 5 bytes JMP 000000016fff0110
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4224] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                               0000000076cca500 7 bytes JMP 000000016fff0228
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4224] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                000007fefcbe2db0 5 bytes JMP 000007fffcbd0180
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4224] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                           000007fefcbe37d0 7 bytes JMP 000007fffcbd00d8
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4224] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                             000007fefcbe8ef0 6 bytes JMP 000007fffcbd0148
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4224] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                         000007fefcbfaf60 5 bytes JMP 000007fffcbd0110
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4224] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                          000007fefe8c89e0 8 bytes JMP 000007fffcbd01f0
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4224] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                        000007fefe8cbe40 8 bytes JMP 000007fffcbd01b8
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4224] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                000007fefe137490 11 bytes JMP 000007fffcbd0228
.text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4224] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                               000007fefe14bf00 7 bytes JMP 000007fffcbd0260
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4232] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                                0000000076c3af40 7 bytes JMP 000000016fff0260
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4232] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                              0000000076c44a60 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4232] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                               0000000076c62990 5 bytes JMP 000000016fff01f0
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4232] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                         0000000076c6efe0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4232] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                       0000000076c999b0 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4232] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                       0000000076ca94d0 5 bytes JMP 000000016fff0180
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4232] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW                                                       0000000076ca9640 5 bytes JMP 000000016fff0110
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4232] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                                0000000076cca500 7 bytes JMP 000000016fff0228
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4232] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                 000007fefcbe2db0 5 bytes JMP 000007fffcbd0180
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4232] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                            000007fefcbe37d0 7 bytes JMP 000007fffcbd00d8
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4232] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                              000007fefcbe8ef0 6 bytes JMP 000007fffcbd0148
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4232] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                          000007fefcbfaf60 5 bytes JMP 000007fffcbd0110
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4232] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                 000007fefe137490 11 bytes JMP 000007fffcbd0228
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4232] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                000007fefe14bf00 7 bytes JMP 000007fffcbd0260
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4232] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                           000007fefe8c89e0 8 bytes JMP 000007fffcbd01f0
.text     C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4232] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                         000007fefe8cbe40 8 bytes JMP 000007fffcbd01b8
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4248] C:\Windows\system32\kernel32.dll!RegSetValueExW                                               0000000076c3af40 7 bytes JMP 000000016fff0260
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4248] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                             0000000076c44a60 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4248] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                              0000000076c62990 5 bytes JMP 000000016fff01f0
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4248] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                        0000000076c6efe0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4248] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                      0000000076c999b0 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4248] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                      0000000076ca94d0 5 bytes JMP 000000016fff0180
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4248] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW                                      0000000076ca9640 5 bytes JMP 000000016fff0110
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4248] C:\Windows\system32\kernel32.dll!RegSetValueExA                                               0000000076cca500 7 bytes JMP 000000016fff0228
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4248] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                000007fefcbe2db0 5 bytes JMP 000007fffcbd0180
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4248] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                           000007fefcbe37d0 7 bytes JMP 000007fffcbd00d8
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4248] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                             000007fefcbe8ef0 6 bytes JMP 000007fffcbd0148
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4248] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                         000007fefcbfaf60 5 bytes JMP 000007fffcbd0110
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4248] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                          000007fefe8c89e0 8 bytes JMP 000007fffcbd01f0
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4248] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                        000007fefe8cbe40 8 bytes JMP 000007fffcbd01b8
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4248] C:\Windows\system32\ole32.dll!CoCreateInstance                                                000007fefe137490 11 bytes JMP 000007fffcbd0228
.text     C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4248] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                               000007fefe14bf00 7 bytes JMP 000007fffcbd0260
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4300] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                                 0000000076c3af40 7 bytes JMP 000000016fff0260
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4300] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                               0000000076c44a60 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4300] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                                0000000076c62990 5 bytes JMP 000000016fff01f0
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4300] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                          0000000076c6efe0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4300] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                        0000000076c999b0 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4300] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                        0000000076ca94d0 5 bytes JMP 000000016fff0180
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4300] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW                                                        0000000076ca9640 5 bytes JMP 000000016fff0110
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4300] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                                 0000000076cca500 7 bytes JMP 000000016fff0228
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4300] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                  000007fefcbe2db0 5 bytes JMP 000007fffcbd0180
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4300] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                             000007fefcbe37d0 7 bytes JMP 000007fffcbd00d8
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4300] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                               000007fefcbe8ef0 6 bytes JMP 000007fffcbd0148
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4300] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                           000007fefcbfaf60 5 bytes JMP 000007fffcbd0110
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4300] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                            000007fefe8c89e0 8 bytes JMP 000007fffcbd01f0
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4300] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                          000007fefe8cbe40 8 bytes JMP 000007fffcbd01b8
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4300] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                  000007fefe137490 11 bytes JMP 000007fffcbd0228
.text     C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4300] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                 000007fefe14bf00 7 bytes JMP 000007fffcbd0260
.text     C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe[4328] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                  00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe[4328] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                    00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe[4328] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                    00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe[4328] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                   00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe[4328] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                                           00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe[4328] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                           00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe[4328] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                           0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe[4328] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                             0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe[4328] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe[4328] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                              0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe[4328] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                  0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe[4328] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                     0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe[4328] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                     0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe[4328] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                 0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe[4328] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                 0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe[4328] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                             0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe[4328] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                          0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe[4328] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                             000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe[4328] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                               000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe[4328] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                    0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe[4328] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                     0000000076739d0b 5 bytes JMP 00000001703c123f
.text     C:\Windows\System32\igfxpers.exe[4504] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                                              0000000076c3af40 7 bytes JMP 000000016fff0260
.text     C:\Windows\System32\igfxpers.exe[4504] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                                            0000000076c44a60 5 bytes JMP 000000016fff01b8
.text     C:\Windows\System32\igfxpers.exe[4504] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                                             0000000076c62990 5 bytes JMP 000000016fff01f0
.text     C:\Windows\System32\igfxpers.exe[4504] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                                       0000000076c6efe0 5 bytes JMP 000000016fff0148
.text     C:\Windows\System32\igfxpers.exe[4504] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                                     0000000076c999b0 7 bytes JMP 000000016fff00d8
.text     C:\Windows\System32\igfxpers.exe[4504] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                                     0000000076ca94d0 5 bytes JMP 000000016fff0180
.text     C:\Windows\System32\igfxpers.exe[4504] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW                                                                     0000000076ca9640 5 bytes JMP 000000016fff0110
.text     C:\Windows\System32\igfxpers.exe[4504] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                                              0000000076cca500 7 bytes JMP 000000016fff0228
.text     C:\Windows\System32\igfxpers.exe[4504] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                               000007fefcbe2db0 5 bytes JMP 000007fffcbd0180
.text     C:\Windows\System32\igfxpers.exe[4504] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                          000007fefcbe37d0 7 bytes JMP 000007fffcbd00d8
.text     C:\Windows\System32\igfxpers.exe[4504] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                            000007fefcbe8ef0 6 bytes JMP 000007fffcbd0148
.text     C:\Windows\System32\igfxpers.exe[4504] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                                        000007fefcbfaf60 5 bytes JMP 000007fffcbd0110
.text     C:\Windows\System32\igfxpers.exe[4504] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                         000007fefe8c89e0 8 bytes JMP 000007fffcbd01f0
.text     C:\Windows\System32\igfxpers.exe[4504] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                                       000007fefe8cbe40 8 bytes JMP 000007fffcbd01b8
.text     C:\Windows\System32\igfxpers.exe[4504] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                               000007fefe137490 11 bytes JMP 000007fffcbd0228
.text     C:\Windows\System32\igfxpers.exe[4504] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                              000007fefe14bf00 7 bytes JMP 000007fffcbd0260
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4512] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                        0000000076c3af40 7 bytes JMP 000000016fff0260
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4512] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                      0000000076c44a60 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4512] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                       0000000076c62990 5 bytes JMP 000000016fff01f0
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4512] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                 0000000076c6efe0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4512] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                               0000000076c999b0 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4512] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                               0000000076ca94d0 5 bytes JMP 000000016fff0180
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4512] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW                                               0000000076ca9640 5 bytes JMP 000000016fff0110
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4512] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                        0000000076cca500 7 bytes JMP 000000016fff0228
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4512] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                         000007fefcbe2db0 5 bytes JMP 000007fffcbd0180
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4512] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                    000007fefcbe37d0 7 bytes JMP 000007fffcbd00d8
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4512] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                      000007fefcbe8ef0 6 bytes JMP 000007fffcbd0148
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4512] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                  000007fefcbfaf60 5 bytes JMP 000007fffcbd0110
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4512] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                   000007fefe8c89e0 8 bytes JMP 000007fffcbd01f0
.text     C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4512] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                 000007fefe8cbe40 8 bytes JMP 000007fffcbd01b8
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                     00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                       00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                       00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                      00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                              00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                              00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                              0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                   0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                 0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                     0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                        0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                  000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                        0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                    0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                    0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                             0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                       0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                        0000000076739d0b 5 bytes JMP 00000001703c123f
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                               0000000076f01465 2 bytes [F0, 76]
.text     C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[4660] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                              0000000076f014bb 2 bytes [F0, 76]
.text     ...                                                                                                                                                                 * 2
.text     C:\Program Files (x86)\PHotkey\HCSynApi.exe[4668] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                                 00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\PHotkey\HCSynApi.exe[4668] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                                   00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\PHotkey\HCSynApi.exe[4668] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                                   00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\PHotkey\HCSynApi.exe[4668] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                                  00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\PHotkey\HCSynApi.exe[4668] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                                                          00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\PHotkey\HCSynApi.exe[4668] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                          00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\PHotkey\HCSynApi.exe[4668] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                          0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\PHotkey\HCSynApi.exe[4668] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                            0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\PHotkey\HCSynApi.exe[4668] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                               0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\PHotkey\HCSynApi.exe[4668] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                             0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\PHotkey\HCSynApi.exe[4668] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                                 0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\PHotkey\HCSynApi.exe[4668] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                                    0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\PHotkey\HCSynApi.exe[4668] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                                    0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\PHotkey\HCSynApi.exe[4668] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                                0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\PHotkey\HCSynApi.exe[4668] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                                0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\PHotkey\HCSynApi.exe[4668] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                                            0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\PHotkey\HCSynApi.exe[4668] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                         0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\PHotkey\HCSynApi.exe[4668] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                            000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\PHotkey\HCSynApi.exe[4668] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                              000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\PHotkey\HCSynApi.exe[4668] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                                   0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Program Files (x86)\PHotkey\HCSynApi.exe[4668] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                                    0000000076739d0b 5 bytes JMP 00000001703c123f
.text     C:\Program Files\Protector Suite\psqltray.exe[4856] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                                 0000000076c3af40 7 bytes JMP 000000016fff0260
.text     C:\Program Files\Protector Suite\psqltray.exe[4856] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                               0000000076c44a60 5 bytes JMP 000000016fff01b8
.text     C:\Program Files\Protector Suite\psqltray.exe[4856] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                                0000000076c62990 5 bytes JMP 000000016fff01f0
.text     C:\Program Files\Protector Suite\psqltray.exe[4856] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                          0000000076c6efe0 5 bytes JMP 000000016fff0148
.text     C:\Program Files\Protector Suite\psqltray.exe[4856] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                        0000000076c999b0 7 bytes JMP 000000016fff00d8
.text     C:\Program Files\Protector Suite\psqltray.exe[4856] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                        0000000076ca94d0 5 bytes JMP 000000016fff0180
.text     C:\Program Files\Protector Suite\psqltray.exe[4856] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW                                                        0000000076ca9640 5 bytes JMP 000000016fff0110
.text     C:\Program Files\Protector Suite\psqltray.exe[4856] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                                 0000000076cca500 7 bytes JMP 000000016fff0228
.text     C:\Program Files\Protector Suite\psqltray.exe[4856] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                  000007fefcbe2db0 5 bytes JMP 000007fffcbd0180
.text     C:\Program Files\Protector Suite\psqltray.exe[4856] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                             000007fefcbe37d0 7 bytes JMP 000007fffcbd00d8
.text     C:\Program Files\Protector Suite\psqltray.exe[4856] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                               000007fefcbe8ef0 6 bytes JMP 000007fffcbd0148
.text     C:\Program Files\Protector Suite\psqltray.exe[4856] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                           000007fefcbfaf60 5 bytes JMP 000007fffcbd0110
.text     C:\Program Files\Protector Suite\psqltray.exe[4856] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                            000007fefe8c89e0 8 bytes JMP 000007fffcbd01f0
.text     C:\Program Files\Protector Suite\psqltray.exe[4856] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                          000007fefe8cbe40 8 bytes JMP 000007fffcbd01b8
.text     C:\Program Files\Protector Suite\psqltray.exe[4856] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                  000007fefe137490 11 bytes JMP 000007fffcbd0228
.text     C:\Program Files\Protector Suite\psqltray.exe[4856] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                 000007fefe14bf00 7 bytes JMP 000007fffcbd0260
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe[4876] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                 00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe[4876] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                   00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe[4876] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                   00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe[4876] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                  00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe[4876] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                                          00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe[4876] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                          00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe[4876] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                          0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe[4876] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                            0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe[4876] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                               0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe[4876] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                             0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe[4876] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                 0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe[4876] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                    0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe[4876] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                    0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe[4876] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe[4876] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe[4876] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                            0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe[4876] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                         0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe[4876] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                            000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe[4876] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                              000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe[4876] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                   0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe[4876] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                    0000000076739d0b 5 bytes JMP 00000001703c123f
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\KERNEL32.dll!RegQueryValueExW                                                00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExW                                                  00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA                                                  00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\KERNEL32.dll!RegDeleteValueW                                                 00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleFileNameExW                                         00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx                                         00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation                                         0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW                                           0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                              0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                            0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                   0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                           000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                             000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                   0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                               0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                               0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                           0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                        0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                  0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                   0000000076739d0b 5 bytes JMP 00000001703c123f
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                          0000000076f01465 2 bytes [F0, 76]
.text     C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe[4920] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                         0000000076f014bb 2 bytes [F0, 76]
.text     ...                                                                                                                                                                 * 2
.text     C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[5020] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                               000007fefcbe2db0 5 bytes JMP 000007fffcbd0180
.text     C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[5020] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                          000007fefcbe37d0 7 bytes JMP 000007fffcbd00d8
.text     C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[5020] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                            000007fefcbe8ef0 6 bytes JMP 000007fffcbd0148
.text     C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[5020] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                        000007fefcbfaf60 5 bytes JMP 000007fffcbd0110
.text     C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[5020] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                         000007fefe8c89e0 8 bytes JMP 000007fffcbd01f0
.text     C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[5020] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                       000007fefe8cbe40 8 bytes JMP 000007fffcbd01b8
.text     C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[5092] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                   0000000076f01465 2 bytes [F0, 76]
.text     C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[5092] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                  0000000076f014bb 2 bytes [F0, 76]
.text     ...                                                                                                                                                                 * 2
.text     C:\Windows\system32\wbem\unsecapp.exe[5016] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                          000007fefcbe2db0 5 bytes JMP 000007fffcbd0180
.text     C:\Windows\system32\wbem\unsecapp.exe[5016] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                     000007fefcbe37d0 7 bytes JMP 000007fffcbd00d8
.text     C:\Windows\system32\wbem\unsecapp.exe[5016] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                       000007fefcbe8ef0 6 bytes JMP 000007fffcbd0148
.text     C:\Windows\system32\wbem\unsecapp.exe[5016] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                                   000007fefcbfaf60 5 bytes JMP 000007fffcbd0110
.text     C:\Windows\system32\wbem\unsecapp.exe[5016] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                          000007fefe137490 11 bytes JMP 000007fffcbd0228
.text     C:\Windows\system32\wbem\unsecapp.exe[5016] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                         000007fefe14bf00 7 bytes JMP 000007fffcbd0260
.text     C:\Windows\system32\wbem\unsecapp.exe[5016] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                    000007fefe8c89e0 8 bytes JMP 000007fffcbd01f0
.text     C:\Windows\system32\wbem\unsecapp.exe[5016] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                                  000007fefe8cbe40 8 bytes JMP 000007fffcbd01b8
.text     C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe[4480] C:\Windows\syswow64\KERNEL32.dll!RegQueryValueExW                                           00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe[4480] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExW                                             00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe[4480] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA                                             00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe[4480] C:\Windows\syswow64\KERNEL32.dll!RegDeleteValueW                                            00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe[4480] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleFileNameExW                                    00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe[4480] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx                                    00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe[4480] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation                                    0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe[4480] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW                                      0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe[4480] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                         0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe[4480] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                       0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe[4480] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                           0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe[4480] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                              0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe[4480] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                      000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe[4480] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                        000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe[4480] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                              0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe[4480] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                          0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe[4480] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                          0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe[4480] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                      0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe[4480] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                   0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe[4480] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                             0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe[4480] C:\Windows\syswow64\ole32.dll!CoCreateInstance
         
__________________

Alt 03.11.2013, 20:20   #4
Segonji
 
Lyricxeeker entfernt, aber Laptop immer noch langsam - Standard

Lyricxeeker entfernt, aber Laptop immer noch langsam



Code:
ATTFilter
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                     00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                       00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                       00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                      00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                                              00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                              00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                              0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                   0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                 0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                     0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                        0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                        0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                    0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                    0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                                0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                             0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                  000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                       0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                        0000000076739d0b 5 bytes JMP 00000001703c123f
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                   00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                     00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                     00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                    00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                                            00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                            00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                            0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                              0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                 0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                               0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                   0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                      0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                      0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                  0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                  0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                              0000000075b0e56b 1 byte [FA]
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                           0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                              000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                     0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                      0000000076739d0b 5 bytes JMP 00000001703c123f
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 69                                             0000000076f01465 2 bytes [F0, 76]
.text     C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 155                                            0000000076f014bb 2 bytes [F0, 76]
.text     ...                                                                                                                                                                 * 2
.text     C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNEL32.dll!RegQueryValueExW                               00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExW                                 00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA                                 00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNEL32.dll!RegDeleteValueW                                00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleFileNameExW                        00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx                        00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation                        0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW                          0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                             0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                           0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                               0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                  0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                          000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                            000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                  0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                              0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                              0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                          0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                       0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                 0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                  0000000076739d0b 5 bytes JMP 00000001703c123f
.text     C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNEL32.dll!RegSetValueExW                                                        0000000076c3af40 7 bytes JMP 000000016fff0260
.text     C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNEL32.dll!RegQueryValueExW                                                      0000000076c44a60 5 bytes JMP 000000016fff01b8
.text     C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNEL32.dll!RegDeleteValueW                                                       0000000076c62990 5 bytes JMP 000000016fff01f0
.text     C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW                                                 0000000076c6efe0 5 bytes JMP 000000016fff0148
.text     C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx                                               0000000076c999b0 7 bytes JMP 000000016fff00d8
.text     C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation                                               0000000076ca94d0 5 bytes JMP 000000016fff0180
.text     C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNEL32.dll!K32GetModuleFileNameExW                                               0000000076ca9640 5 bytes JMP 000000016fff0110
.text     C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNEL32.dll!RegSetValueExA                                                        0000000076cca500 7 bytes JMP 000000016fff0228
.text     C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                         000007fefcbe2db0 5 bytes JMP 000007fffcbd0180
.text     C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                    000007fefcbe37d0 7 bytes JMP 000007fffcbd00d8
.text     C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                      000007fefcbe8ef0 6 bytes JMP 000007fffcbd0148
.text     C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                  000007fefcbfaf60 5 bytes JMP 000007fffcbd0110
.text     C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                   000007fefe8c89e0 8 bytes JMP 000007fffcbd01f0
.text     C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                 000007fefe8cbe40 8 bytes JMP 000007fffcbd01b8
.text     C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\ole32.dll!CoCreateInstance                                                         000007fefe137490 11 bytes JMP 000007fffcbd0228
.text     C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                        000007fefe14bf00 7 bytes JMP 000007fffcbd0260
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                 00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                   00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                   00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                  00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                                          00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                          00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                          0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                            0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                               0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                             0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                 0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                    0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                    0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                            0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                         0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                            000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                              000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                   0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                    0000000076739d0b 5 bytes JMP 00000001703c123f
.text     C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW          00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\kernel32.dll!RegSetValueExW            00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\kernel32.dll!RegSetValueExA            00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW           00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW   00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx   00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation   0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW     0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW        0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW      0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW          0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary             0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList     000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo       000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\USER32.dll!CreateWindowExW             0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA         0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW         0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4     0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo  0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket            0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\ole32.dll!CoCreateInstance             0000000076739d0b 5 bytes JMP 00000001703c123f
.text     C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                       00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                         00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                         00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                        00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                                                00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                  0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                     0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                   0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                       0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                          0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                          0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                      0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                      0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                                  0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                               0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                  000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                    000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                         0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                          0000000076739d0b 5 bytes JMP 00000001703c123f
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                 00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                   00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                   00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                  00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                                          00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                          00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                          0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                            0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                               0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                             0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                 0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                    0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                    0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                            0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                         0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                            000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                              000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                   0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                    0000000076739d0b 5 bytes JMP 00000001703c123f
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                           0000000076f01465 2 bytes [F0, 76]
.text     C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                          0000000076f014bb 2 bytes [F0, 76]
.text     ...                                                                                                                                                                 * 2
.text     C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                     00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                       00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                       00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                      00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                                              00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                              00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                              0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                   0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                 0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                     0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                        0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                        0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                    0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                    0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                                0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                             0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                  000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                       0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                        0000000076739d0b 5 bytes JMP 00000001703c123f
.text     C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                       00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                         00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                         00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                        00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                                                00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                  0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                     0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                   0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                       0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                          0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                  000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                    000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                          0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                      0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                      0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                                  0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                               0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                         0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                          0000000076739d0b 5 bytes JMP 00000001703c123f
.text     C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                       00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                         00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                         00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                        00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                                                00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                  0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                     0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                   0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                       0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                          0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                          0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                      0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                      0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                                  0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                               0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                  000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                    000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                         0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                          0000000076739d0b 5 bytes JMP 00000001703c123f
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                            00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                              00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                              00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                             00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                                     00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                     00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                     0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                       0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                          0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                        0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                            0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                               0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                       000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                         000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                               0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                           0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                           0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                       0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                    0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                              0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                               0000000076739d0b 5 bytes JMP 00000001703c123f
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                     00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                       00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                       00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                      00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                                              00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                              00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                              0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                   0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                 0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                     0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                        0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                        0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                    0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                    0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                                0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                             0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                  000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                               0000000076f01465 2 bytes [F0, 76]
.text     C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                              0000000076f014bb 2 bytes [F0, 76]
.text     ...                                                                                                                                                                 * 2
.text     C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                  00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                    00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                    00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                   00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                                           00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                           00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                           0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                             0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                              0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                  0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                     0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                             000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                               000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                     0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                 0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                 0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                             0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                          0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                    0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                     0000000076739d0b 5 bytes JMP 00000001703c123f
.text     C:\Windows\splwow64.exe[1772] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                                                       0000000076c3af40 7 bytes JMP 000000016fff0260
.text     C:\Windows\splwow64.exe[1772] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                                                     0000000076c44a60 5 bytes JMP 000000016fff01b8
.text     C:\Windows\splwow64.exe[1772] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                                                      0000000076c62990 5 bytes JMP 000000016fff01f0
.text     C:\Windows\splwow64.exe[1772] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                                                0000000076c6efe0 5 bytes JMP 000000016fff0148
.text     C:\Windows\splwow64.exe[1772] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                                              0000000076c999b0 7 bytes JMP 000000016fff00d8
.text     C:\Windows\splwow64.exe[1772] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                                              0000000076ca94d0 5 bytes JMP 000000016fff0180
.text     C:\Windows\splwow64.exe[1772] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW                                                                              0000000076ca9640 5 bytes JMP 000000016fff0110
.text     C:\Windows\splwow64.exe[1772] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                                                       0000000076cca500 7 bytes JMP 000000016fff0228
.text     C:\Windows\splwow64.exe[1772] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                                        000007fefcbe2db0 5 bytes JMP 000007fffcbd0180
.text     C:\Windows\splwow64.exe[1772] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                                   000007fefcbe37d0 7 bytes JMP 000007fffcbd00d8
.text     C:\Windows\splwow64.exe[1772] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                                     000007fefcbe8ef0 6 bytes JMP 000007fffcbd0148
.text     C:\Windows\splwow64.exe[1772] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                                                 000007fefcbfaf60 5 bytes JMP 000007fffcbd0110
.text     C:\Windows\splwow64.exe[1772] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                                  000007fefe8c89e0 8 bytes JMP 000007fffcbd01f0
.text     C:\Windows\splwow64.exe[1772] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                                                000007fefe8cbe40 8 bytes JMP 000007fffcbd01b8
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312                                                     00000000747e13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471                                                     00000000747e146b 8 bytes {JMP 0xffffffffffffffb0}
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611                                                                  00000000747e16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessTerm + 3                                                                    00000000747e16e3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23                                                               00000000747e19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23                                                               00000000747e19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetInstructionPointer + 23                                                         00000000747e1a1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\SYSTEM32\wow64cpu.dll!CpuNotifyAffinityChange + 3                                                           00000000747e1a27 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23                                                         00000000747e1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessDebugEvent + 3                                                              00000000747e1a6f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                                      00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                                        00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                                        00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                                       00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                                                               00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                               00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                               0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                                 0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                                    0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                                  0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                                      0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                                         0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\KERNELBASE.dll!HeapCreate                                                                          0000000075c2549c 5 bytes JMP 0000000100170800
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 5                                                      0000000076d511f5 8 bytes {JMP 0xd}
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 416                                                    0000000076d51390 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159                                           0000000076d5143f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 492                                           0000000076d5158c 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126                                                   0000000076d5191e 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 636                                                   0000000076d51b1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 204                                                  0000000076d51bf0 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373                                     0000000076d51d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 691                                     0000000076d51eb3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31                                                         0000000076d51edf 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!_ui64toa + 84                                                        0000000076d51f64 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 81                                                       0000000076d51fbd 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelf + 7                                               0000000076d51fd7 8 bytes {JMP 0xb}
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 658                                           0000000076d52272 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 801                                           0000000076d52301 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlInstallFunctionTableCallback + 578                                0000000076d52792 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16                                       0000000076d527b0 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18                                     0000000076d527d2 8 bytes {JMP 0x10}
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79                      0000000076d5282f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 176                     0000000076d52890 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     ...                                                                                                                                                                 * 2
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299                             0000000076d52d1b 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 367                             0000000076d52d5f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     ...                                                                                                                                                                 * 3
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlCutoverTimeToSystemTime + 483                                     0000000076d53023 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523                                         0000000076d5323b 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 912                                         0000000076d533c0 16 bytes {JMP 0x4e}
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318                                                        0000000076d53a5e 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403                                                        0000000076d53ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197                            0000000076d53b85 8 bytes [10, 6A, F8, 7E, 00, 00, 00, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 611                            0000000076d53d23 8 bytes [00, 6A, F8, 7E, 00, 00, 00, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80                                     0000000076d54190 8 bytes [A0, 69, F8, 7E, 00, 00, 00, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread                                               0000000076da1380 8 bytes {JMP QWORD [RIP-0x4d4cf]}
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread                                             0000000076da1500 8 bytes {JMP QWORD [RIP-0x4d498]}
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection                                                   0000000076da1530 8 bytes {JMP QWORD [RIP-0x4d9b1]}
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                 0000000076da1650 8 bytes {JMP QWORD [RIP-0x4d7a7]}
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread                                                     0000000076da1700 8 bytes {JMP QWORD [RIP-0x4d9e3]}
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                     0000000076da1d30 8 bytes {JMP QWORD [RIP-0x4dba6]}
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread                                                   0000000076da1f80 8 bytes {JMP QWORD [RIP-0x4de55]}
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                   0000000076da27e0 8 bytes {JMP QWORD [RIP-0x4e770]}
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312                                 00000000747e13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471                                 00000000747e146b 8 bytes {JMP 0xffffffffffffffb0}
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611                                              00000000747e16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessTerm + 3                                                00000000747e16e3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23                                           00000000747e19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23                                           00000000747e19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetInstructionPointer + 23                                     00000000747e1a1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\wow64cpu.dll!CpuNotifyAffinityChange + 3                                       00000000747e1a27 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23                                     00000000747e1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessDebugEvent + 3                                          00000000747e1a6f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\syswow64\KERNELBASE.dll!HeapCreate                                                      0000000075c2549c 5 bytes JMP 00000001003d0800
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69                                            0000000076f01465 2 bytes [F0, 76]
.text     C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155                                           0000000076f014bb 2 bytes [F0, 76]
.text     ...                                                                                                                                                                 * 2
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 5                                                            0000000076d511f5 8 bytes {JMP 0xd}
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 416                                                          0000000076d51390 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159                                                 0000000076d5143f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 492                                                 0000000076d5158c 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126                                                         0000000076d5191e 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 636                                                         0000000076d51b1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 204                                                        0000000076d51bf0 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373                                           0000000076d51d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 691                                           0000000076d51eb3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31                                                               0000000076d51edf 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!_ui64toa + 84                                                              0000000076d51f64 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 81                                                             0000000076d51fbd 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelf + 7                                                     0000000076d51fd7 8 bytes {JMP 0xb}
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 658                                                 0000000076d52272 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 801                                                 0000000076d52301 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlInstallFunctionTableCallback + 578                                      0000000076d52792 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16                                             0000000076d527b0 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18                                           0000000076d527d2 8 bytes {JMP 0x10}
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79                            0000000076d5282f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 176                           0000000076d52890 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     ...                                                                                                                                                                 * 2
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299                                   0000000076d52d1b 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 367                                   0000000076d52d5f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     ...                                                                                                                                                                 * 3
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlCutoverTimeToSystemTime + 483                                           0000000076d53023 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523                                               0000000076d5323b 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 912                                               0000000076d533c0 16 bytes {JMP 0x4e}
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318                                                              0000000076d53a5e 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403                                                              0000000076d53ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197                                  0000000076d53b85 8 bytes [10, 6A, F8, 7E, 00, 00, 00, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 611                                  0000000076d53d23 8 bytes [00, 6A, F8, 7E, 00, 00, 00, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80                                           0000000076d54190 8 bytes [A0, 69, F8, 7E, 00, 00, 00, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread                                                     0000000076da1380 8 bytes {JMP QWORD [RIP-0x4d4cf]}
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread                                                   0000000076da1500 8 bytes {JMP QWORD [RIP-0x4d498]}
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection                                                         0000000076da1530 8 bytes {JMP QWORD [RIP-0x4d9b1]}
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                       0000000076da1650 8 bytes {JMP QWORD [RIP-0x4d7a7]}
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread                                                           0000000076da1700 8 bytes {JMP QWORD [RIP-0x4d9e3]}
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                           0000000076da1d30 8 bytes {JMP QWORD [RIP-0x4dba6]}
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread                                                         0000000076da1f80 8 bytes {JMP QWORD [RIP-0x4de55]}
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                         0000000076da27e0 8 bytes {JMP QWORD [RIP-0x4e770]}
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312                                       00000000747e13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471                                       00000000747e146b 8 bytes {JMP 0xffffffffffffffb0}
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611                                                    00000000747e16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessTerm + 3                                                      00000000747e16e3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23                                                 00000000747e19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23                                                 00000000747e19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetInstructionPointer + 23                                           00000000747e1a1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\wow64cpu.dll!CpuNotifyAffinityChange + 3                                             00000000747e1a27 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23                                           00000000747e1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessDebugEvent + 3                                                00000000747e1a6f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                        00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                          00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                          00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                         00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                                                 00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                 00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                 0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                   0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                      0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                    0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                        0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                           0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\user32.DLL!CreateWindowExW                                                           0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\user32.DLL!EnumDisplayDevicesA                                                       0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\user32.DLL!EnumDisplayDevicesW                                                       0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\user32.DLL!EnumDisplayDevicesW + 4                                                   0000000075b0e56b 1 byte [FA]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\user32.DLL!DisplayConfigGetDeviceInfo                                                0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                   000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                     000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                  0000000076f01465 2 bytes [F0, 76]
.text     C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                 0000000076f014bb 2 bytes [F0, 76]
.text     ...                                                                                                                                                                 * 2
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 5                                                0000000076d511f5 8 bytes {JMP 0xd}
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 416                                              0000000076d51390 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159                                     0000000076d5143f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 492                                     0000000076d5158c 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126                                             0000000076d5191e 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 636                                             0000000076d51b1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 204                                            0000000076d51bf0 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373                               0000000076d51d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 691                               0000000076d51eb3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31                                                   0000000076d51edf 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!_ui64toa + 84                                                  0000000076d51f64 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 81                                                 0000000076d51fbd 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelf + 7                                         0000000076d51fd7 8 bytes {JMP 0xb}
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 658                                     0000000076d52272 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 801                                     0000000076d52301 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlInstallFunctionTableCallback + 578                          0000000076d52792 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16                                 0000000076d527b0 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18                               0000000076d527d2 8 bytes {JMP 0x10}
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79                0000000076d5282f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 176               0000000076d52890 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     ...                                                                                                                                                                 * 2
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299                       0000000076d52d1b 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 367                       0000000076d52d5f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     ...                                                                                                                                                                 * 3
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlCutoverTimeToSystemTime + 483                               0000000076d53023 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523                                   0000000076d5323b 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 912                                   0000000076d533c0 16 bytes {JMP 0x4e}
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318                                                  0000000076d53a5e 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403                                                  0000000076d53ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197                      0000000076d53b85 8 bytes [10, 6A, F8, 7E, 00, 00, 00, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 611                      0000000076d53d23 8 bytes [00, 6A, F8, 7E, 00, 00, 00, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80                               0000000076d54190 8 bytes [A0, 69, F8, 7E, 00, 00, 00, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread                                         0000000076da1380 8 bytes {JMP QWORD [RIP-0x4d4cf]}
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread                                       0000000076da1500 8 bytes {JMP QWORD [RIP-0x4d498]}
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection                                             0000000076da1530 8 bytes {JMP QWORD [RIP-0x4d9b1]}
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                           0000000076da1650 8 bytes {JMP QWORD [RIP-0x4d7a7]}
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread                                               0000000076da1700 8 bytes {JMP QWORD [RIP-0x4d9e3]}
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                               0000000076da1d30 8 bytes {JMP QWORD [RIP-0x4dba6]}
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread                                             0000000076da1f80 8 bytes {JMP QWORD [RIP-0x4de55]}
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                             0000000076da27e0 8 bytes {JMP QWORD [RIP-0x4e770]}
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312                           00000000747e13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471                           00000000747e146b 8 bytes {JMP 0xffffffffffffffb0}
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611                                        00000000747e16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessTerm + 3                                          00000000747e16e3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23                                     00000000747e19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23                                     00000000747e19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetInstructionPointer + 23                               00000000747e1a1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\wow64cpu.dll!CpuNotifyAffinityChange + 3                                 00000000747e1a27 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23                               00000000747e1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessDebugEvent + 3                                    00000000747e1a6f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                            00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                              00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                              00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                             00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                                     00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                     00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                     0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                       0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                          0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                        0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                            0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                               0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                               0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                           0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                           0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                       0000000075b0e56b 1 byte [FA]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                    0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                       000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                         000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                      0000000076f01465 2 bytes [F0, 76]
.text     C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                     0000000076f014bb 2 bytes [F0, 76]
.text     ...                                                                                                                                                                 * 2
         

Alt 03.11.2013, 20:22   #5
Segonji
 
Lyricxeeker entfernt, aber Laptop immer noch langsam - Standard

Lyricxeeker entfernt, aber Laptop immer noch langsam



Code:
ATTFilter
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 5                                                                        0000000076d511f5 8 bytes {JMP 0xd}
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 416                                                                      0000000076d51390 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159                                                             0000000076d5143f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 492                                                             0000000076d5158c 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126                                                                     0000000076d5191e 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 636                                                                     0000000076d51b1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 204                                                                    0000000076d51bf0 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373                                                       0000000076d51d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 691                                                       0000000076d51eb3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31                                                                           0000000076d51edf 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!_ui64toa + 84                                                                          0000000076d51f64 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 81                                                                         0000000076d51fbd 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelf + 7                                                                 0000000076d51fd7 8 bytes {JMP 0xb}
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 658                                                             0000000076d52272 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 801                                                             0000000076d52301 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlInstallFunctionTableCallback + 578                                                  0000000076d52792 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16                                                         0000000076d527b0 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18                                                       0000000076d527d2 8 bytes {JMP 0x10}
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79                                        0000000076d5282f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 176                                       0000000076d52890 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     ...                                                                                                                                                                 * 2
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299                                               0000000076d52d1b 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 367                                               0000000076d52d5f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     ...                                                                                                                                                                 * 3
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlCutoverTimeToSystemTime + 483                                                       0000000076d53023 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523                                                           0000000076d5323b 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 912                                                           0000000076d533c0 16 bytes {JMP 0x4e}
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318                                                                          0000000076d53a5e 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403                                                                          0000000076d53ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197                                              0000000076d53b85 8 bytes [10, 6A, F8, 7E, 00, 00, 00, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 611                                              0000000076d53d23 8 bytes [00, 6A, F8, 7E, 00, 00, 00, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80                                                       0000000076d54190 8 bytes [A0, 69, F8, 7E, 00, 00, 00, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread                                                                 0000000076da1380 8 bytes {JMP QWORD [RIP-0x4d4cf]}
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread                                                               0000000076da1500 8 bytes {JMP QWORD [RIP-0x4d498]}
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection                                                                     0000000076da1530 8 bytes {JMP QWORD [RIP-0x4d9b1]}
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                                                                   0000000076da1650 8 bytes {JMP QWORD [RIP-0x4d7a7]}
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread                                                                       0000000076da1700 8 bytes {JMP QWORD [RIP-0x4d9e3]}
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                                                       0000000076da1d30 8 bytes {JMP QWORD [RIP-0x4dba6]}
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread                                                                     0000000076da1f80 8 bytes {JMP QWORD [RIP-0x4de55]}
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                                                     0000000076da27e0 8 bytes {JMP QWORD [RIP-0x4e770]}
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312                                                   00000000747e13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471                                                   00000000747e146b 8 bytes {JMP 0xffffffffffffffb0}
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611                                                                00000000747e16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessTerm + 3                                                                  00000000747e16e3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23                                                             00000000747e19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23                                                             00000000747e19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetInstructionPointer + 23                                                       00000000747e1a1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\wow64cpu.dll!CpuNotifyAffinityChange + 3                                                         00000000747e1a27 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23                                                       00000000747e1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessDebugEvent + 3                                                            00000000747e1a6f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                                    00000000765d1eee 7 bytes JMP 00000001703c16b3
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                                      00000000765d5b85 7 bytes JMP 00000001703c11cc
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                                      00000000765e13e1 7 bytes JMP 00000001703c12a8
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                                     00000000765eea0d 7 bytes JMP 00000001703c1262
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW                                                             00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                             00000000766788b4 7 bytes JMP 00000001703c1357
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                             0000000076678939 5 bytes JMP 00000001703c16f4
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                               0000000076678c8f 5 bytes JMP 00000001703c101e
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                                  0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                                0000000075c21dc9 5 bytes JMP 00000001703c1019
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                                    0000000075c22aa4 5 bytes JMP 00000001703c1573
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                                       0000000075c22d0a 5 bytes JMP 00000001703c128f
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                               000000007586e9a2 5 bytes JMP 00000001703c15e1
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                                 000000007586ebdc 5 bytes JMP 00000001703c11a9
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                                       0000000075ae8a29 5 bytes JMP 00000001703c1046
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                                   0000000075af4572 5 bytes JMP 00000001703c10c8
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                                   0000000075b0e567 3 bytes JMP 00000001703c1433
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4                                                               0000000075b0e56b 1 byte [FA]
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                            0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                                      0000000076705ea5 5 bytes JMP 00000001703c1618
.text     C:\Users\Grigorij\Downloads\7j0c9k42.exe[2260] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                                       0000000076739d0b 5 bytes JMP 00000001703c123f

---- Registry - GMER 2.1 ----

Reg       HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0015008015d7                                                                                         
Reg       HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\4c809307ab5b                                                                                         
Reg       HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\bc7737240c29                                                                                         
Reg       HKLM\SYSTEM\CurrentControlSet\services\KLIF\Parameters@LastProcessedRevision                                                                                        58161964
Reg       HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Epoch@Epoch                                                                                                     5029
Reg       HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0015008015d7 (not active ControlSet)                                                                     
Reg       HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\4c809307ab5b (not active ControlSet)                                                                     
Reg       HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\bc7737240c29 (not active ControlSet)                                                                     

---- Disk sectors - GMER 2.1 ----

Disk      \Device\Harddisk0\DR0                                                                                                                                               unknown MBR code

---- EOF - GMER 2.1 ----
         


Alt 06.11.2013, 21:55   #6
schrauber
/// the machine
/// TB-Ausbilder
 

Lyricxeeker entfernt, aber Laptop immer noch langsam - Standard

Lyricxeeker entfernt, aber Laptop immer noch langsam



hi,
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!
Downloade dir bitte Combofix vom folgenden Downloadspiegel

Link 1


WICHTIG - Speichere Combofix auf deinem Desktop
  • Deaktiviere bitte all deine Anti Viren sowie Anti Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören.
Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.

Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.


Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Zitat:
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.
__________________
--> Lyricxeeker entfernt, aber Laptop immer noch langsam

Alt 07.11.2013, 12:54   #7
Segonji
 
Lyricxeeker entfernt, aber Laptop immer noch langsam - Standard

Lyricxeeker entfernt, aber Laptop immer noch langsam



Code:
ATTFilter
ComboFix 13-11-04.01 - Grigorij 06.11.2013  23:48:21.1.8 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.8103.5311 [GMT 1:00]
ausgeführt von:: c:\users\Grigorij\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {179979E8-273D-D14E-0543-2861940E4886}
FW: Kaspersky Internet Security *Disabled* {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
SP: Kaspersky Internet Security *Disabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\ntuser.dat
c:\programdata\Roaming
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\_ctypes.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\_elementtree.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\_hashlib.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\_multiprocessing.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\_socket.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\_ssl.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\msvcp100.dll
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\msvcr100.dll
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\pyexpat.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\pysqlite2._sqlite.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\python27.dll
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\pythoncom27.dll
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\PyWinTypes27.dll
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\select.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\unicodedata.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\win32api.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\win32com.shell.shell.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\win32crypt.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\win32event.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\win32file.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\win32inet.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\win32pdh.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\win32process.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\win32profile.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\win32security.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\win32ts.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\windows._cacheinvalidation.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\wx._controls_.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\wx._core_.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\wx._gdi_.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\wx._html2.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\wx._misc_.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\wx._windows_.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\wx._wizard.pyd
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\wxbase294u_net_vc90.dll
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\wxbase294u_vc90.dll
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\wxmsw294u_adv_vc90.dll
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\wxmsw294u_core_vc90.dll
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\wxmsw294u_html_vc90.dll
c:\users\Grigorij\AppData\Local\Temp\_MEI49762\wxmsw294u_webview_vc90.dll
c:\windows\SysWow64\frapsvid.dll
.
.
(((((((((((((((((((((((   Dateien erstellt von 2013-10-06 bis 2013-11-06  ))))))))))))))))))))))))))))))
.
.
2013-11-03 11:37 . 2013-11-03 11:37	--------	d-----w-	C:\FRST
2013-11-02 22:51 . 2013-11-02 22:53	--------	d-----w-	C:\AdwCleaner
2013-11-02 10:57 . 2013-11-02 10:59	--------	d-----w-	c:\program files (x86)\Common Files\DVDVideoSoft
2013-11-02 10:44 . 2013-11-02 10:44	--------	d-----w-	c:\programdata\Oracle
2013-11-02 10:44 . 2013-11-02 10:44	--------	d-----w-	c:\program files (x86)\Common Files\Java
2013-11-02 10:44 . 2013-10-08 06:50	96168	----a-w-	c:\windows\SysWow64\WindowsAccessBridge-32.dll
2013-10-29 12:21 . 2013-09-04 12:12	343040	----a-w-	c:\windows\system32\drivers\usbhub.sys
2013-10-29 12:21 . 2013-09-04 12:11	325120	----a-w-	c:\windows\system32\drivers\usbport.sys
2013-10-29 12:21 . 2013-09-04 12:11	99840	----a-w-	c:\windows\system32\drivers\usbccgp.sys
2013-10-29 12:21 . 2013-09-04 12:11	52736	----a-w-	c:\windows\system32\drivers\usbehci.sys
2013-10-29 12:21 . 2013-09-04 12:11	30720	----a-w-	c:\windows\system32\drivers\usbuhci.sys
2013-10-29 12:21 . 2013-09-04 12:11	25600	----a-w-	c:\windows\system32\drivers\usbohci.sys
2013-10-29 12:21 . 2013-09-04 12:11	7808	----a-w-	c:\windows\system32\drivers\usbd.sys
2013-10-28 16:57 . 2013-10-28 16:57	--------	d-----w-	c:\users\Grigorij\AppData\Roaming\Ubisoft
2013-10-28 16:41 . 2013-10-28 16:41	--------	d-----w-	c:\programdata\Ubisoft
2013-10-25 17:36 . 2013-10-26 20:30	--------	d-----w-	C:\Fraps
2013-10-25 14:58 . 2013-10-25 15:06	--------	d-----w-	c:\users\Grigorij\AppData\Local\Ubisoft Game Launcher
2013-10-25 14:31 . 2013-10-25 14:31	189248	----a-w-	c:\windows\SysWow64\PnkBstrB.exe
2013-10-25 14:31 . 2013-10-25 14:31	75136	----a-w-	c:\windows\SysWow64\PnkBstrA.exe
2013-10-25 14:31 . 2013-10-25 14:26	3123272	----a-w-	c:\windows\SysWow64\pbsvc.exe
2013-10-25 14:31 . 2013-10-28 16:20	--------	d-----w-	c:\program files (x86)\Ubisoft
2013-10-25 12:34 . 2013-10-27 11:34	--------	d-----w-	c:\program files (x86)\Project64 2.1
2013-10-21 17:06 . 2013-11-06 22:39	--------	d-----r-	c:\users\Grigorij\Google Drive
2013-10-19 15:58 . 2013-10-19 15:58	--------	d-----w-	c:\users\Grigorij\AppData\Roaming\IrfanView
2013-10-19 15:58 . 2013-10-19 15:58	--------	d-----w-	c:\program files (x86)\IrfanView
2013-10-10 11:47 . 2013-07-04 12:50	633856	----a-w-	c:\windows\system32\comctl32.dll
2013-10-10 11:46 . 2013-07-04 12:57	259584	----a-w-	c:\windows\system32\WebClnt.dll
2013-10-10 11:45 . 2013-08-01 12:09	983488	----a-w-	c:\windows\system32\drivers\dxgkrnl.sys
2013-10-10 11:45 . 2013-07-20 10:33	102608	----a-w-	c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 11:45 . 2013-07-20 10:33	124112	----a-w-	c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 11:45 . 2013-08-28 01:12	461312	----a-w-	c:\windows\system32\scavengeui.dll
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-11-06 22:42 . 2013-09-24 11:46	623200	----a-w-	c:\windows\system32\drivers\klif.sys
2013-11-06 22:42 . 2013-05-06 07:22	458336	----a-w-	c:\windows\system32\drivers\kl1.sys
2013-10-10 12:15 . 2011-07-18 20:31	80541720	----a-w-	c:\windows\system32\MRT.exe
2013-10-09 15:07 . 2013-06-17 20:26	692616	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2013-10-09 15:07 . 2011-08-10 19:09	71048	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-10-01 15:39 . 2013-06-10 10:27	29792	----a-w-	c:\windows\system32\drivers\klim6.sys
2013-10-01 15:39 . 2013-05-05 20:42	29280	----a-w-	c:\windows\system32\drivers\klkbdflt.sys
2013-10-01 15:39 . 2013-05-05 20:42	29280	----a-w-	c:\windows\system32\drivers\klmouflt.sys
2013-08-29 01:48 . 2013-10-10 11:46	44032	----a-w-	c:\windows\apppatch\acwow64.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	130736	----a-w-	c:\users\Grigorij\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	130736	----a-w-	c:\users\Grigorij\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	130736	----a-w-	c:\users\Grigorij\AppData\Roaming\Dropbox\bin\DropboxExt.19.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\Steam.exe" [2013-10-30 1820584]
"icq"="c:\users\Grigorij\AppData\Roaming\ICQM\icq.exe" [2013-06-02 27598184]
"Duden Korrektor SysTray"="c:\program files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe" [2011-07-04 332432]
"GoogleDriveSync"="c:\program files (x86)\Google\Drive\googledrivesync.exe" [2013-09-25 20133824]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-11-06 283160]
"Dolby Home Theater v4"="c:\program files (x86)\Dolby Home Theater v4\pcee4.exe" [2011-02-03 506712]
"NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 113288]
"CLMLServer"="c:\program files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [2010-08-03 107816]
"YouCam Mirage"="c:\program files (x86)\CyberLink\YouCam\YCMMirage.exe" [2011-04-14 136488]
"YouCam Tray"="c:\program files (x86)\CyberLink\YouCam\YouCam.exe" [2011-04-14 228448]
"BDRegion"="c:\program files (x86)\Cyberlink\Shared files\brs.exe" [2011-03-21 75048]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Duden Korrektor SysTray"="c:\program files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe" [2011-07-04 332432]
.
c:\users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
CurseClientStartup.ccip [2013-6-2 0]
Dropbox.lnk - c:\users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2013-5-25 27776968]
OpenOffice.org 3.4.1.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2012-8-13 1199104]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages	REG_MULTI_SZ   	scecli c:\program files\Protector Suite\psqlpwd.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R2 CLKMSVC10_38F51D56;CyberLink Product - 2011/10/10 23:45;c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe;c:\program files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 lxdiCATSCustConnectService;lxdiCATSCustConnectService;c:\windows\system32\spool\DRIVERS\x64\3\\lxdiserv.exe;c:\windows\SYSNATIVE\spool\DRIVERS\x64\3\\lxdiserv.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AMPPALP;Intel(R) Centrino(R) Bluetooth 3.0 + High Speed Protocol;c:\windows\system32\DRIVERS\amppal.sys;c:\windows\SYSNATIVE\DRIVERS\amppal.sys [x]
R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys;c:\windows\SYSNATIVE\Drivers\ssadadb.sys [x]
R3 Bluetooth Media Service;Bluetooth Media Service;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe;c:\program files (x86)\Intel\Bluetooth\mediasrv.exe [x]
R3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\DRIVERS\motfilt.sys;c:\windows\SYSNATIVE\DRIVERS\motfilt.sys [x]
R3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x]
R3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x]
R3 fspad_wlh64;Finger Sensing Pad Driver for Windows 2000/XP/Vista/Win7_wlh64;c:\windows\system32\drivers\fspad_wlh64.sys;c:\windows\SYSNATIVE\drivers\fspad_wlh64.sys [x]
R3 fspad_xp64;Finger Sensing Pad Driver for Windows 2000/XP/Vista/Win7_xp64;c:\windows\system32\drivers\fspad_xp64.sys;c:\windows\SYSNATIVE\drivers\fspad_xp64.sys [x]
R3 iBtFltCoex;iBtFltCoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x]
R3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys;c:\windows\SYSNATIVE\DRIVERS\motccgp.sys [x]
R3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys;c:\windows\SYSNATIVE\DRIVERS\motccgpfl.sys [x]
R3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\DRIVERS\Motousbnet.sys;c:\windows\SYSNATIVE\DRIVERS\Motousbnet.sys [x]
R3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\DRIVERS\motusbdevice.sys;c:\windows\SYSNATIVE\DRIVERS\motusbdevice.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys;c:\windows\SYSNATIVE\DRIVERS\RTL8192su.sys [x]
R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssadbus.sys [x]
R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdfl.sys [x]
R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdm.sys [x]
R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys;c:\windows\SYSNATIVE\DRIVERS\ssadserd.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys;c:\windows\SYSNATIVE\DRIVERS\wsvd.sys [x]
R4 klflt;klflt;c:\windows\system32\DRIVERS\klflt.sys;c:\windows\SYSNATIVE\DRIVERS\klflt.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
S1 klpd;klpd;c:\windows\system32\DRIVERS\klpd.sys;c:\windows\SYSNATIVE\DRIVERS\klpd.sys [x]
S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x]
S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x]
S2 AMPPALR3;Intel® Centrino® Bluetooth 3.0 + High Speed Service;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe;c:\program files\Intel\BluetoothHS\BTHSAmpPalService.exe [x]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x]
S2 BTHSSecurityMgr;Intel(R) Centrino(R) Wireless Bluetooth(R) 3.0 + High Speed Security Service;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe;c:\program files\Intel\BluetoothHS\BTHSSecurityMgr.exe [x]
S2 GFNEXSrv;GFNEX Service;c:\program files (x86)\PHotkey\GFNEXSrv.exe;c:\program files (x86)\PHotkey\GFNEXSrv.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 lxdi_device;lxdi_device;c:\windows\system32\lxdicoms.exe;c:\windows\SYSNATIVE\lxdicoms.exe [x]
S2 Motorola Device Manager;Motorola Device Manager Service;c:\program files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe;c:\program files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [x]
S2 PEGAGFN;PEGAGFN;c:\program files (x86)\PHotkey\PEGAGFN.sys;c:\program files (x86)\PHotkey\PEGAGFN.sys [x]
S2 PST Service;PST Service;c:\program files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe;c:\program files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S3 AMPPAL;Intel(R) Centrino(R) Bluetooth 3.0 + High Speed Virtual Adapter;c:\windows\system32\DRIVERS\AMPPAL.sys;c:\windows\SYSNATIVE\DRIVERS\AMPPAL.sys [x]
S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x]
S3 InputFilter_Hid_FlexDef2b;Siliten HID Devices(FlexDef2b) Driver Service;c:\windows\system32\DRIVERS\InputFilter_FlexDef2b.sys;c:\windows\SYSNATIVE\DRIVERS\InputFilter_FlexDef2b.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys;c:\windows\SYSNATIVE\drivers\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys;c:\windows\SYSNATIVE\drivers\nusb3xhc.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
*Deregistered* - CLKMDRV10_38F51D56
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\6de2ed6f-0b56-4d57-b0f0-551ec8cbb27f]
2011-07-01 09:38	153232	---ha-w-	c:\programdata\Duden\DKReg.exe
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-10-19 09:44	1185744	----a-w-	c:\program files (x86)\Google\Chrome\Application\30.0.1599.101\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2013-11-06 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-17 15:07]
.
2013-11-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-05 11:32]
.
2013-11-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-08-05 11:32]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	164016	----a-w-	c:\users\Grigorij\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	164016	----a-w-	c:\users\Grigorij\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	164016	----a-w-	c:\users\Grigorij\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36	164016	----a-w-	c:\users\Grigorij\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2013-09-25 15:37	778704	----a-w-	c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2013-09-25 15:37	778704	----a-w-	c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2013-09-25 15:37	778704	----a-w-	c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2013-09-25 15:37	778704	----a-w-	c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2013-09-25 15:37	778704	----a-w-	c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2010-12-10 09:59	5267792	----a-w-	c:\program files\Protector Suite\farchns.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2010-12-10 09:59	5267792	----a-w-	c:\program files\Protector Suite\farchns.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-04-19 11817576]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-04-18 2209896]
"PSQLLauncher"="c:\program files\Protector Suite\launcher.exe" [2010-12-10 84816]
"IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-05-02 1935120]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshell.dll" [2011-02-11 10361616]
"MedionReminder"="c:\program files (x86)\CyberLink\PowerRecover\Reminder.exe" [2011-05-25 443688]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-14 172144]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-12-14 399984]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-12-14 441968]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [2013-05-16 1012000]
"lxdimon.exe"="c:\program files (x86)\Lexmark 3500-4500 Series\lxdimon.exe" [2009-04-27 434856]
"lxdiamon"="c:\program files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe" [2009-04-27 25256]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"MedionReminder"="c:\program files (x86)\CyberLink\PowerRecover\Reminder.exe" [2011-05-25 443688]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Free YouTube Download - c:\program files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
IE: Nach Microsoft &Excel exportieren - c:\progra~2\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Zu Anti-Banner hinzufügen - c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ie_banner_deny.htm
IE: {{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - hxxp://rover.ebay.com/rover/1/707-37276-17534-31/4
TCP: DhcpNameServer = 192.168.178.1
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="ChromeHTML"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_9_900_117_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_117.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\PHotkey\ASLDRSrv.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
c:\program files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe
c:\program files (x86)\PHotkey\PHotkey.exe
c:\program files (x86)\PHotkey\MsgTranAgt.exe
c:\program files (x86)\PHotkey\POSD.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2013-11-07  00:06:57 - PC wurde neu gestartet
ComboFix-quarantined-files.txt  2013-11-06 23:06
.
Vor Suchlauf: 16 Verzeichnis(se), 341.005.287.424 Bytes frei
Nach Suchlauf: 20 Verzeichnis(se), 352.295.317.504 Bytes frei
.
- - End Of File - - 43A280658A14EFA563ECA1846F1D5D49
         
Ist das eigentlich normal, dass Combofix Programme deinstalliert? Und viel wichtiger ist, sollte ich davon absehen sie wieder drauf zu machen?

Alt 08.11.2013, 09:30   #8
schrauber
/// the machine
/// TB-Ausbilder
 

Lyricxeeker entfernt, aber Laptop immer noch langsam - Standard

Lyricxeeker entfernt, aber Laptop immer noch langsam



welche Programme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 08.11.2013, 12:33   #9
Segonji
 
Lyricxeeker entfernt, aber Laptop immer noch langsam - Standard

Lyricxeeker entfernt, aber Laptop immer noch langsam



Also aufgefallen ist mir bisher nur der Curse Client (Verwaltungsprogramm für Addons bei WoW und co.). Hab festgestellt, dass der nicht mehr im Autostart war und dann konnte ich in der Systemsteuerung nur noch das Symbol entfernen.
Nach einem Neustart versucht er es neu zu installieren.
Alles andere scheint noch da zu sein.

Geändert von Segonji (08.11.2013 um 12:47 Uhr)

Alt 08.11.2013, 12:58   #10
schrauber
/// the machine
/// TB-Ausbilder
 

Lyricxeeker entfernt, aber Laptop immer noch langsam - Standard

Lyricxeeker entfernt, aber Laptop immer noch langsam



Combofix deinstalliert aber nix.


Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 08.11.2013, 13:54   #11
Segonji
 
Lyricxeeker entfernt, aber Laptop immer noch langsam - Standard

Lyricxeeker entfernt, aber Laptop immer noch langsam



Code:
ATTFilter
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.11.08.04

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16721
Grigorij :: GRIGORIJ-PC [Administrator]

08.11.2013 13:09:00
mbam-log-2013-11-08 (13-09-00).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 231436
Laufzeit: 6 Minute(n), 14 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 3
C:\Users\Grigorij\Downloads\DownloadSetup.exe (PUP.Optional.OneClickDownloader.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Grigorij\Downloads\FRAPS - CHIP-Downloader.exe (PUP.Optional.DownloadSponsor.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Grigorij\Downloads\FreeYouTubeDownload (1).exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.

(Ende)
         
AdwCleaner Logfile:
Code:
ATTFilter
# AdwCleaner v3.010 - Bericht erstellt am 02/11/2013 um 23:53:11
# Updated 20/10/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Grigorij - GRIGORIJ-PC
# Gestartet von : C:\Users\Grigorij\Downloads\adwcleaner-3.010.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\Program Files (x86)\LyriXeeker
Ordner Gelöscht : C:\Users\Grigorij\AppData\Local\Temp\OCS
Ordner Gelöscht : C:\Users\Grigorij\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Grigorij\AppData\Roaming\OpenCandy
Datei Gelöscht : C:\Windows\System32\Tasks\Desk 365 RunAsStdUser

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bicnnkjibmphdeigoodpjlcklcnaobdj
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\DeskSvc
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WsysSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\InstallCore
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\lyrixeeker

***** [ Browser ] *****

-\\ Internet Explorer v10.0.9200.16720

Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]

-\\ Mozilla Firefox v

-\\ Google Chrome v30.0.1599.101

[ Datei : C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Gelöscht : urls_to_restore_on_startup

*************************

AdwCleaner[R0].txt - [2811 octets] - [02/11/2013 23:51:45]
AdwCleaner[S0].txt - [2541 octets] - [02/11/2013 23:53:11]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2601 octets] ##########
         
--- --- ---
AdwCleaner Logfile:
Code:
ATTFilter
# AdwCleaner v3.011 - Bericht erstellt am 08/11/2013 um 13:31:20
# Updated 03/11/2013 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Grigorij - GRIGORIJ-PC
# Gestartet von : C:\Users\Grigorij\Desktop\adwcleaner.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****


***** [ Browser ] *****

-\\ Internet Explorer v10.0.9200.16720


-\\ Mozilla Firefox v

-\\ Google Chrome v30.0.1599.101

[ Datei : C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Gelöscht : urls_to_restore_on_startup

*************************

AdwCleaner[R0].txt - [3740 octets] - [02/11/2013 23:51:45]
AdwCleaner[S0].txt - [3479 octets] - [02/11/2013 23:53:11]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3539 octets] ##########
         
--- --- ---

Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.8 (11.05.2013:1)
OS: Windows 7 Home Premium x64
Ran by Grigorij on 08.11.2013 at 13:41:52,45
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{676DEF01-FA5E-42DD-BE75-9CD4179EDE19}



~~~ Files



~~~ Folders

Successfully deleted: [Empty Folder] C:\Users\Grigorij\appdata\local\{40A57BC0-A459-4401-8737-775147BD28CA}
Successfully deleted: [Empty Folder] C:\Users\Grigorij\appdata\local\{77C03A6A-CB47-4535-B250-39E459FC8155}
Successfully deleted: [Empty Folder] C:\Users\Grigorij\appdata\local\{800A6040-B48F-4DE3-9162-A66EAF03F113}



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 08.11.2013 at 13:48:56,07
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         

FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-10-2013
Ran by Grigorij (administrator) on GRIGORIJ-PC on 08-11-2013 13:52:56
Running from C:\Users\Grigorij\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
() C:\Program Files (x86)\PHotkey\ASLDRSrv.exe
() C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(UPEK Inc.) C:\Program Files\Protector Suite\upeksvr.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
( ) C:\Windows\system32\lxdicoms.exe
(Motorola Mobility LLC) C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Motorola) C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
() C:\Program Files (x86)\PHotkey\PHotkey.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
() C:\Program Files (x86)\PHotkey\ATouch64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe
() C:\Program Files (x86)\PHotkey\PVDesktop.exe
(Motorola Mobility LLC) C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
() C:\Program Files (x86)\PHotkey\PVDAgent.exe
(UPEK Inc.) C:\Program Files\Protector Suite\psqltray.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files (x86)\PHotkey\POSD.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TODO: <Company name>) C:\Program Files (x86)\PHotkey\HCSynApi.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
() C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe
() C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Expert System S.p.A.) C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Dropbox, Inc.) C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Bibliographisches Institut GmbH) C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11817576 2011-04-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2209896 2011-04-18] (Realtek Semiconductor)
HKLM\...\Run: [PSQLLauncher] - C:\Program Files\Protector Suite\launcher.exe [84816 2010-12-10] (UPEK Inc.)
HKLM\...\Run: [IntelPAN] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation)
HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2028328 2010-01-22] (Synaptics Incorporated)
HKLM\...\Run: [MedionReminder] - C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe [443688 2011-05-26] (CyberLink)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1012000 2013-05-16] (NVIDIA Corporation)
HKLM\...\Run: [lxdimon.exe] - C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe [434856 2009-04-27] ()
HKLM\...\Run: [lxdiamon] - C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe [25256 2009-04-27] ()
HKLM\...\RunOnce: [MedionReminder] - C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe /DeleteRunKey [443688 2011-05-26] (CyberLink)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\psfus: C:\Program Files\Protector Suite\psqlpwd.dll (UPEK Inc.)
HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1820584 2013-10-30] (Valve Corporation)
HKCU\...\Run: [icq] - C:\Users\Grigorij\AppData\Roaming\ICQM\icq.exe [27598184 2013-06-02] (ICQ)
HKCU\...\Run: [Duden Korrektor SysTray] - C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe [332432 2011-07-04] (Expert System S.p.A.)
HKCU\...\Run: [GoogleDriveSync] - C:\Program Files (x86)\Google\Drive\googledrivesync.exe [20133824 2013-09-25] (Google)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\...\Run: [Dolby Home Theater v4] - C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-03] (CyberLink)
HKLM-x32\...\Run: [YouCam Mirage] - C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488 2011-04-15] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] - C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe [228448 2011-04-15] (CyberLink Corp.)
HKLM-x32\...\Run: [BDRegion] - C:\Program Files (x86)\CyberLink\Shared files\brs.exe [75048 2011-03-21] (cyberlink)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll [266448 2013-05-12] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [214448 2013-05-12] (NVIDIA Corporation)
Lsa: [Notification Packages] scecli C:\Program Files\Protector Suite\psqlpwd.dll
Startup: C:\Users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
Startup: C:\Users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Extension: trtv3 - C:\Users\Grigorij\AppData\Roaming\Mozilla\Firefox\profiles\extensions\trtv3@trtv.com.xpi
FF HKLM-x32\...\Firefox\Extensions:  - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com

Chrome: 
=======
CHR HomePage: hxxp://www.kicker.de/
CHR RestoreOnStartup: "chrome://newtab/", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=48&cc=&mi=204c3cc00000000000004c809307ab58", "hxxp://www.google.com"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.260.3) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U26) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File
CHR Extension: (Google Docs) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (AdBlock) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.13_0
CHR Extension: (Dangerous Websites Blocker) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\14.0.0.4651_0
CHR Extension: (WEB.DE MailCheck) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaogepninmlbinccpbiakcgiolijlllo\1.2_0
CHR Extension: (WordPress.com) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\khjnjifipfkgglficmipimgjpbmlbemd\1.1.1_0
CHR Extension: (DVDVideoSoft) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.3.0.0_0
CHR Extension: (Google Wallet) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (365Scores - Live Scores,Sports News & Alerts) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmpppefjehmjbiplimkfjeamnohldmko\1.8.1_0
CHR Extension: (Gmail) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx

==================== Services (Whitelisted) =================

R2 ASLDRService; C:\Program Files (x86)\PHotkey\ASLDRSrv.exe [104968 2009-12-18] ()
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-01] (Kaspersky Lab ZAO)
S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [241648 2011-02-25] (CyberLink)
R2 GFNEXSrv; C:\Program Files (x86)\PHotkey\GFNEXSrv.exe [159752 2010-10-07] ()
R2 lxdi_device; C:\Windows\system32\lxdicoms.exe [876976 2007-06-11] ( )
R2 lxdi_device; C:\Windows\SysWow64\lxdicoms.exe [517040 2007-06-11] ( )
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 Motorola Device Manager; C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [137528 2013-07-31] (Motorola Mobility LLC)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2013-10-25] ()

==================== Drivers (Whitelisted) ====================

R3 InputFilter_Hid_FlexDef2b; C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys [17920 2010-06-18] (Siliten)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-11-06] (Kaspersky Lab ZAO)
S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [112224 2013-06-08] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [623200 2013-11-06] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-01] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-01] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-01] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178784 2013-06-06] (Kaspersky Lab ZAO)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2009-09-11] (PEGATRON)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 motccgpfl; system32\DRIVERS\motccgpfl.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-08 13:41 - 2013-11-08 13:41 - 00000000 ____D C:\Windows\ERUNT
2013-11-08 13:39 - 2013-11-08 13:39 - 01034531 _____ (Thisisu) C:\Users\Grigorij\Desktop\JRT.exe
2013-11-08 13:28 - 2013-11-08 13:28 - 01073262 _____ C:\Users\Grigorij\Desktop\adwcleaner.exe
2013-11-08 13:04 - 2013-11-08 13:04 - 01073262 _____ C:\Users\Grigorij\Downloads\adwcleaner.exe
2013-11-08 13:04 - 2013-11-08 13:04 - 00001117 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-11-08 13:04 - 2013-11-08 13:04 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-08 13:04 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-11-08 13:03 - 2013-11-08 13:03 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Grigorij\Downloads\mbam-setup-1.75.0.1300.exe
2013-11-07 00:06 - 2013-11-07 00:06 - 00033120 _____ C:\ComboFix.txt
2013-11-06 23:46 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2013-11-06 23:46 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2013-11-06 23:46 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-11-06 23:46 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-11-06 23:46 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-11-06 23:46 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2013-11-06 23:46 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2013-11-06 23:46 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2013-11-06 23:45 - 2013-11-07 00:07 - 00000000 ____D C:\Qoobox
2013-11-06 23:45 - 2013-11-07 00:05 - 00000000 ____D C:\Windows\erdnt
2013-11-06 23:44 - 2013-11-06 23:44 - 05144303 ____R (Swearware) C:\Users\Grigorij\Desktop\ComboFix.exe
2013-11-06 23:44 - 2013-11-06 23:44 - 05144303 _____ (Swearware) C:\Users\Grigorij\Downloads\ComboFix.exe
2013-11-05 20:49 - 2013-11-05 20:50 - 28001847 _____ (Paradox Interactive                                         ) C:\Users\Grigorij\Downloads\eu3dw5_2.exe
2013-11-03 20:15 - 2013-11-03 20:16 - 00013681 _____ C:\Users\Grigorij\Downloads\gmer (2).zip
2013-11-03 20:15 - 2013-11-03 20:16 - 00013681 _____ C:\Users\Grigorij\Downloads\gmer (1).zip
2013-11-03 19:17 - 2013-11-03 19:18 - 00519264 _____ C:\Windows\Minidump\110313-32853-01.dmp
2013-11-03 13:47 - 2013-11-03 13:47 - 00013681 _____ C:\Users\Grigorij\Downloads\gmer.zip
2013-11-03 13:22 - 2013-11-03 13:22 - 00013681 _____ C:\Users\Grigorij\Desktop\gmer.zip
2013-11-03 12:47 - 2013-11-03 12:47 - 00377856 _____ C:\Users\Grigorij\Downloads\7j0c9k42.exe
2013-11-03 12:42 - 2013-11-03 12:43 - 00036841 _____ C:\Users\Grigorij\Desktop\Addition.txt
2013-11-03 12:37 - 2013-11-03 12:37 - 00000000 ____D C:\FRST
2013-11-03 12:36 - 2013-11-03 12:35 - 01957098 _____ (Farbar) C:\Users\Grigorij\Desktop\FRST64.exe
2013-11-03 12:35 - 2013-11-03 12:35 - 01957098 _____ (Farbar) C:\Users\Grigorij\Downloads\FRST64.exe
2013-11-02 23:51 - 2013-11-08 13:31 - 00000000 ____D C:\AdwCleaner
2013-11-02 23:51 - 2013-11-02 23:51 - 01060070 _____ C:\Users\Grigorij\Downloads\adwcleaner-3.010.exe
2013-11-02 11:59 - 2013-11-02 11:59 - 00001540 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2013-11-02 11:58 - 2013-11-02 11:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-02 11:57 - 2013-11-02 11:57 - 00001444 _____ C:\Users\Public\Desktop\Free YouTube Download.lnk
2013-11-02 11:55 - 2013-11-02 11:56 - 32132232 _____ (DVDVideoSoft Ltd.                                           ) C:\Users\Grigorij\Downloads\FreeYouTubeToMP3Converter3.2.16.1028.exe
2013-11-02 11:44 - 2013-11-02 11:44 - 00000000 ____D C:\ProgramData\Oracle
2013-11-02 11:44 - 2013-10-08 07:50 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-02 11:44 - 2013-10-08 07:46 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-11-02 11:44 - 2013-10-08 07:46 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-11-02 11:44 - 2013-10-08 07:46 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-11-02 11:43 - 2013-11-02 11:44 - 00004886 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-29 13:21 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-10-29 13:21 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-10-29 13:21 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-10-29 13:21 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-10-29 13:21 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-10-29 13:21 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-10-29 13:21 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-10-28 17:57 - 2013-10-28 17:57 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Ubisoft
2013-10-28 17:49 - 2013-10-28 17:49 - 00001730 _____ C:\Users\Grigorij\Desktop\Assassin's Creed.lnk
2013-10-28 17:41 - 2013-10-28 17:41 - 00000000 ____D C:\ProgramData\Ubisoft
2013-10-27 12:33 - 2013-10-27 12:33 - 01872114 _____ C:\Users\Grigorij\Downloads\pj64_1_6.zip
2013-10-27 12:31 - 2013-10-27 12:31 - 07362734 _____ C:\Users\Grigorij\Downloads\Vigilante 8.zip
2013-10-27 11:33 - 2013-10-27 11:34 - 11340380 _____ C:\Users\Grigorij\Downloads\vigilante 8 - 2nd offence (e) [!].zip
2013-10-27 11:33 - 2013-10-27 11:33 - 07486064 _____ C:\Users\Grigorij\Downloads\vigilante 8 (e) [!].zip
2013-10-27 11:27 - 2013-10-27 11:27 - 11368658 _____ C:\Users\Grigorij\Downloads\1080 snowboarding (e) (m4) [!].zip
2013-10-27 11:19 - 2013-10-27 11:20 - 27597639 _____ C:\Users\Grigorij\Downloads\starcraft 64 (e) [!].zip
2013-10-25 18:36 - 2013-10-26 21:30 - 00000000 ____D C:\Fraps
2013-10-25 18:36 - 2013-10-25 18:36 - 00000566 _____ C:\Users\Public\Desktop\Fraps.lnk
2013-10-25 16:23 - 2013-10-25 16:23 - 00000939 _____ C:\Users\Grigorij\Desktop\Steam.lnk
2013-10-25 16:05 - 2013-10-25 16:30 - 00000000 ____D C:\Users\Grigorij\Documents\Assassin's Creed III
2013-10-25 15:58 - 2013-10-25 16:06 - 00000000 ____D C:\Users\Grigorij\AppData\Local\Ubisoft Game Launcher
2013-10-25 15:31 - 2013-10-28 17:20 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2013-10-25 15:31 - 2013-10-25 15:31 - 00189248 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-10-25 15:31 - 2013-10-25 15:31 - 00075136 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2013-10-25 15:31 - 2013-10-25 15:31 - 00001209 _____ C:\Users\Grigorij\Desktop\Uplay.lnk
2013-10-25 15:31 - 2013-10-25 15:31 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2013-10-25 15:31 - 2013-10-25 15:26 - 03123272 _____ C:\Windows\SysWOW64\pbsvc.exe
2013-10-25 14:11 - 2013-10-25 14:11 - 00000081 _____ C:\Users\Grigorij\gri.cp
2013-10-25 13:59 - 2013-10-25 13:59 - 10545441 _____ C:\Users\Grigorij\Downloads\LEGO Racers (D, F, E).zip
2013-10-25 13:58 - 2013-10-25 13:59 - 04840302 _____ C:\Users\Grigorij\Downloads\Snowboard Kids (E).zip
2013-10-25 13:57 - 2013-10-25 13:59 - 25675994 _____ C:\Users\Grigorij\Downloads\Star Wars Episode I - Racer (D, F, E).zip
2013-10-25 13:54 - 2013-10-25 13:55 - 10323803 _____ C:\Users\Grigorij\Downloads\Destruction Derby 64 (E).zip
2013-10-25 13:54 - 2013-10-25 13:55 - 10084676 _____ C:\Users\Grigorij\Downloads\Diddy Kong Racing (D, F, E).zip
2013-10-25 13:53 - 2013-10-25 13:54 - 16086013 _____ C:\Users\Grigorij\Downloads\Super Smash Bros (D, F, E).zip
2013-10-25 13:50 - 2013-10-25 13:51 - 16490258 _____ C:\Users\Grigorij\Downloads\Banjo-Kazooie (D, F, E).zip
2013-10-25 13:50 - 2013-10-25 13:50 - 22161948 _____ C:\Users\Grigorij\Downloads\Mario Party (D, F, E).zip
2013-10-25 13:50 - 2013-10-25 13:50 - 13896929 _____ C:\Users\Grigorij\Downloads\Southpark (D).zip
2013-10-25 13:48 - 2013-10-25 13:48 - 00001496 _____ C:\Users\Grigorij\Desktop\Project64.lnk
2013-10-25 13:45 - 2013-10-25 13:45 - 10186459 _____ C:\Users\Grigorij\Downloads\Star Fox 64 (D, F, E).zip
2013-10-25 13:38 - 2013-10-25 13:42 - 61310559 _____ C:\Users\Grigorij\Downloads\Conkers Bad Fur Day (E).zip
2013-10-25 13:34 - 2013-10-27 12:34 - 00000000 ____D C:\Program Files (x86)\Project64 2.1
2013-10-25 13:34 - 2013-10-25 13:34 - 04603228 _____ (                                                            ) C:\Users\Grigorij\Downloads\setup_Project64_2.1.exe
2013-10-25 09:54 - 2013-10-25 09:54 - 01038704 _____ (Amazon Services LLC) C:\Users\Grigorij\Downloads\Assassin_s_Creed_3_Digital_Deluxe_Edition_Downloader.exe
2013-10-21 18:06 - 2013-11-08 13:34 - 00000000 ___RD C:\Users\Grigorij\Google Drive
2013-10-21 18:06 - 2013-10-21 18:06 - 00709023 _____ C:\Users\Grigorij\Downloads\documents-export-2013-10-21.zip
2013-10-21 18:03 - 2013-10-21 18:03 - 00819136 _____ (Google Inc.) C:\Users\Grigorij\Downloads\googledrivesync.exe
2013-10-20 11:38 - 2013-10-20 11:38 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_ssadadb_01005.Wdf
2013-10-19 17:22 - 2013-10-19 17:22 - 00003186 _____ C:\Windows\System32\Tasks\{F81AA872-BD9F-4779-9147-A636F768F844}
2013-10-19 17:20 - 2013-10-19 17:20 - 11180128 _____ (Irfan Skiljan) C:\Users\Grigorij\Downloads\irfanview_plugins_436_setup.exe
2013-10-19 16:58 - 2013-10-19 16:58 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
2013-10-19 16:58 - 2013-10-19 16:58 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\IrfanView
2013-10-19 16:58 - 2013-10-19 16:58 - 00000000 ____D C:\Program Files (x86)\IrfanView
2013-10-19 16:56 - 2013-10-19 16:56 - 02145888 _____ (Irfan Skiljan) C:\Users\Grigorij\Downloads\iview436g_setup.exe
2013-10-10 13:44 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-10-10 13:44 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-10-10 13:44 - 2013-09-22 23:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-10 13:44 - 2013-09-22 23:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-10 13:44 - 2013-09-22 23:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-10-10 13:44 - 2013-09-22 23:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-10-10 13:44 - 2013-09-21 04:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-10 13:44 - 2013-09-21 04:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-10-10 13:44 - 2013-09-21 03:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-10-10 13:44 - 2013-09-21 03:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-10-10 12:47 - 2013-07-12 11:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2013-10-10 12:47 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2013-10-10 12:47 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-10 12:47 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-10-10 12:47 - 2013-07-03 05:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys
2013-10-10 12:47 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2013-10-10 12:47 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-10 12:47 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-10 12:47 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2013-10-10 12:47 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2013-10-10 12:47 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2013-10-10 12:47 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-10 12:47 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2013-10-10 12:47 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2013-10-10 12:47 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2013-10-10 12:47 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-10 12:47 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-10-10 12:47 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-10-10 12:46 - 2013-09-14 02:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-10-10 12:46 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-10-10 12:46 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2013-10-10 12:46 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2013-10-10 12:46 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-10-10 12:46 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-10-10 12:46 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2013-10-10 12:46 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-10-10 12:46 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2013-10-10 12:46 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-10-10 12:46 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-10-10 12:46 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-10-10 12:46 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2013-10-10 12:46 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-10-10 12:46 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2013-10-10 12:46 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-10-10 12:46 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-10-10 12:46 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-10-10 12:46 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-10-10 12:46 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-10 12:46 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2013-10-10 12:46 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2013-10-10 12:46 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2013-10-10 12:46 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2013-10-10 12:46 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2013-10-10 12:45 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2013-10-10 12:45 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-10 12:45 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 12:45 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll

==================== One Month Modified Files and Folders =======

2013-11-08 13:49 - 2013-06-02 13:09 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-11-08 13:43 - 2013-08-05 12:32 - 00001114 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-08 13:41 - 2013-11-08 13:41 - 00000000 ____D C:\Windows\ERUNT
2013-11-08 13:41 - 2009-07-14 05:45 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-08 13:41 - 2009-07-14 05:45 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-08 13:39 - 2013-11-08 13:39 - 01034531 _____ (Thisisu) C:\Users\Grigorij\Desktop\JRT.exe
2013-11-08 13:38 - 2013-06-02 12:43 - 02025774 _____ C:\Windows\WindowsUpdate.log
2013-11-08 13:35 - 2013-06-02 13:42 - 00000000 ____D C:\Program Files (x86)\Steam
2013-11-08 13:34 - 2013-10-21 18:06 - 00000000 ___RD C:\Users\Grigorij\Google Drive
2013-11-08 13:34 - 2013-06-02 14:44 - 00000000 ___RD C:\Users\Grigorij\Dropbox
2013-11-08 13:34 - 2013-06-02 14:43 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Dropbox
2013-11-08 13:34 - 2013-06-02 14:08 - 00000000 ____D C:\Users\Grigorij\AppData\Local\Deployment
2013-11-08 13:33 - 2013-08-05 12:32 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-08 13:32 - 2013-06-11 17:33 - 00000000 ____D C:\ProgramData\NVIDIA
2013-11-08 13:32 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-08 13:32 - 2009-07-14 05:51 - 00101387 _____ C:\Windows\setupact.log
2013-11-08 13:31 - 2013-11-02 23:51 - 00000000 ____D C:\AdwCleaner
2013-11-08 13:28 - 2013-11-08 13:28 - 01073262 _____ C:\Users\Grigorij\Desktop\adwcleaner.exe
2013-11-08 13:21 - 2010-11-21 04:47 - 00022726 _____ C:\Windows\PFRO.log
2013-11-08 13:06 - 2013-07-18 22:39 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-08 13:04 - 2013-11-08 13:04 - 01073262 _____ C:\Users\Grigorij\Downloads\adwcleaner.exe
2013-11-08 13:04 - 2013-11-08 13:04 - 00001117 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-11-08 13:04 - 2013-11-08 13:04 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-08 13:03 - 2013-11-08 13:03 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Grigorij\Downloads\mbam-setup-1.75.0.1300.exe
2013-11-07 19:30 - 2011-05-16 15:04 - 00697082 _____ C:\Windows\system32\perfh007.dat
2013-11-07 19:30 - 2011-05-16 15:04 - 00148346 _____ C:\Windows\system32\perfc007.dat
2013-11-07 19:30 - 2009-07-14 06:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-07 15:21 - 2013-06-02 14:12 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Skype
2013-11-07 00:21 - 2013-10-04 19:58 - 00000000 ____D C:\Users\Grigorij\AppData\Local\Battle.net
2013-11-07 00:09 - 2013-06-02 14:08 - 00000000 ____D C:\Users\Grigorij\AppData\Local\Apps\2.0
2013-11-07 00:07 - 2013-11-06 23:45 - 00000000 ____D C:\Qoobox
2013-11-07 00:06 - 2013-11-07 00:06 - 00033120 _____ C:\ComboFix.txt
2013-11-07 00:05 - 2013-11-06 23:45 - 00000000 ____D C:\Windows\erdnt
2013-11-06 23:59 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2013-11-06 23:44 - 2013-11-06 23:44 - 05144303 ____R (Swearware) C:\Users\Grigorij\Desktop\ComboFix.exe
2013-11-06 23:44 - 2013-11-06 23:44 - 05144303 _____ (Swearware) C:\Users\Grigorij\Downloads\ComboFix.exe
2013-11-06 23:42 - 2013-09-24 12:46 - 00623200 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2013-11-06 23:42 - 2013-05-06 08:22 - 00458336 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys
2013-11-06 17:59 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-05 20:50 - 2013-11-05 20:49 - 28001847 _____ (Paradox Interactive                                         ) C:\Users\Grigorij\Downloads\eu3dw5_2.exe
2013-11-03 20:16 - 2013-11-03 20:15 - 00013681 _____ C:\Users\Grigorij\Downloads\gmer (2).zip
2013-11-03 20:16 - 2013-11-03 20:15 - 00013681 _____ C:\Users\Grigorij\Downloads\gmer (1).zip
2013-11-03 19:18 - 2013-11-03 19:17 - 00519264 _____ C:\Windows\Minidump\110313-32853-01.dmp
2013-11-03 19:17 - 2013-06-07 21:58 - 605910832 _____ C:\Windows\MEMORY.DMP
2013-11-03 19:17 - 2013-06-07 21:58 - 00000000 ____D C:\Windows\Minidump
2013-11-03 13:47 - 2013-11-03 13:47 - 00013681 _____ C:\Users\Grigorij\Downloads\gmer.zip
2013-11-03 13:22 - 2013-11-03 13:22 - 00013681 _____ C:\Users\Grigorij\Desktop\gmer.zip
2013-11-03 12:47 - 2013-11-03 12:47 - 00377856 _____ C:\Users\Grigorij\Downloads\7j0c9k42.exe
2013-11-03 12:43 - 2013-11-03 12:42 - 00036841 _____ C:\Users\Grigorij\Desktop\Addition.txt
2013-11-03 12:37 - 2013-11-03 12:37 - 00000000 ____D C:\FRST
2013-11-03 12:35 - 2013-11-03 12:36 - 01957098 _____ (Farbar) C:\Users\Grigorij\Desktop\FRST64.exe
2013-11-03 12:35 - 2013-11-03 12:35 - 01957098 _____ (Farbar) C:\Users\Grigorij\Downloads\FRST64.exe
2013-11-02 23:51 - 2013-11-02 23:51 - 01060070 _____ C:\Users\Grigorij\Downloads\adwcleaner-3.010.exe
2013-11-02 16:23 - 2013-08-17 19:09 - 00000000 ____D C:\Program Files (x86)\JDownloader
2013-11-02 16:20 - 2013-08-04 19:07 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\uTorrent
2013-11-02 11:59 - 2013-11-02 11:59 - 00001540 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2013-11-02 11:59 - 2013-06-15 18:13 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\DVDVideoSoft
2013-11-02 11:59 - 2013-06-15 18:13 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
2013-11-02 11:58 - 2013-11-02 11:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-02 11:57 - 2013-11-02 11:57 - 00001444 _____ C:\Users\Public\Desktop\Free YouTube Download.lnk
2013-11-02 11:56 - 2013-11-02 11:55 - 32132232 _____ (DVDVideoSoft Ltd.                                           ) C:\Users\Grigorij\Downloads\FreeYouTubeToMP3Converter3.2.16.1028.exe
2013-11-02 11:44 - 2013-11-02 11:44 - 00000000 ____D C:\ProgramData\Oracle
2013-11-02 11:44 - 2013-11-02 11:43 - 00004886 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-11-02 11:44 - 2011-07-18 22:13 - 00000000 ____D C:\Program Files (x86)\Java
2013-10-31 18:07 - 2013-06-02 14:06 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2013-10-28 17:57 - 2013-10-28 17:57 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Ubisoft
2013-10-28 17:49 - 2013-10-28 17:49 - 00001730 _____ C:\Users\Grigorij\Desktop\Assassin's Creed.lnk
2013-10-28 17:41 - 2013-10-28 17:41 - 00000000 ____D C:\ProgramData\Ubisoft
2013-10-28 17:39 - 2011-07-18 21:49 - 00550829 _____ C:\Windows\DirectX.log
2013-10-28 17:20 - 2013-10-25 15:31 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2013-10-28 17:20 - 2011-07-18 22:23 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-10-27 12:34 - 2013-10-25 13:34 - 00000000 ____D C:\Program Files (x86)\Project64 2.1
2013-10-27 12:33 - 2013-10-27 12:33 - 01872114 _____ C:\Users\Grigorij\Downloads\pj64_1_6.zip
2013-10-27 12:31 - 2013-10-27 12:31 - 07362734 _____ C:\Users\Grigorij\Downloads\Vigilante 8.zip
2013-10-27 11:34 - 2013-10-27 11:33 - 11340380 _____ C:\Users\Grigorij\Downloads\vigilante 8 - 2nd offence (e) [!].zip
2013-10-27 11:33 - 2013-10-27 11:33 - 07486064 _____ C:\Users\Grigorij\Downloads\vigilante 8 (e) [!].zip
2013-10-27 11:27 - 2013-10-27 11:27 - 11368658 _____ C:\Users\Grigorij\Downloads\1080 snowboarding (e) (m4) [!].zip
2013-10-27 11:20 - 2013-10-27 11:19 - 27597639 _____ C:\Users\Grigorij\Downloads\starcraft 64 (e) [!].zip
2013-10-26 21:30 - 2013-10-25 18:36 - 00000000 ____D C:\Fraps
2013-10-26 11:07 - 2013-06-02 14:12 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-10-26 11:07 - 2013-06-02 14:12 - 00000000 ____D C:\ProgramData\Skype
2013-10-25 18:36 - 2013-10-25 18:36 - 00000566 _____ C:\Users\Public\Desktop\Fraps.lnk
2013-10-25 16:30 - 2013-10-25 16:05 - 00000000 ____D C:\Users\Grigorij\Documents\Assassin's Creed III
2013-10-25 16:23 - 2013-10-25 16:23 - 00000939 _____ C:\Users\Grigorij\Desktop\Steam.lnk
2013-10-25 16:06 - 2013-10-25 15:58 - 00000000 ____D C:\Users\Grigorij\AppData\Local\Ubisoft Game Launcher
2013-10-25 15:31 - 2013-10-25 15:31 - 00189248 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-10-25 15:31 - 2013-10-25 15:31 - 00075136 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2013-10-25 15:31 - 2013-10-25 15:31 - 00001209 _____ C:\Users\Grigorij\Desktop\Uplay.lnk
2013-10-25 15:31 - 2013-10-25 15:31 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2013-10-25 15:26 - 2013-10-25 15:31 - 03123272 _____ C:\Windows\SysWOW64\pbsvc.exe
2013-10-25 14:11 - 2013-10-25 14:11 - 00000081 _____ C:\Users\Grigorij\gri.cp
2013-10-25 14:11 - 2013-06-02 12:48 - 00000000 ____D C:\Users\Grigorij
2013-10-25 13:59 - 2013-10-25 13:59 - 10545441 _____ C:\Users\Grigorij\Downloads\LEGO Racers (D, F, E).zip
2013-10-25 13:59 - 2013-10-25 13:58 - 04840302 _____ C:\Users\Grigorij\Downloads\Snowboard Kids (E).zip
2013-10-25 13:59 - 2013-10-25 13:57 - 25675994 _____ C:\Users\Grigorij\Downloads\Star Wars Episode I - Racer (D, F, E).zip
2013-10-25 13:55 - 2013-10-25 13:54 - 10323803 _____ C:\Users\Grigorij\Downloads\Destruction Derby 64 (E).zip
2013-10-25 13:55 - 2013-10-25 13:54 - 10084676 _____ C:\Users\Grigorij\Downloads\Diddy Kong Racing (D, F, E).zip
2013-10-25 13:54 - 2013-10-25 13:53 - 16086013 _____ C:\Users\Grigorij\Downloads\Super Smash Bros (D, F, E).zip
2013-10-25 13:51 - 2013-10-25 13:50 - 16490258 _____ C:\Users\Grigorij\Downloads\Banjo-Kazooie (D, F, E).zip
2013-10-25 13:50 - 2013-10-25 13:50 - 22161948 _____ C:\Users\Grigorij\Downloads\Mario Party (D, F, E).zip
2013-10-25 13:50 - 2013-10-25 13:50 - 13896929 _____ C:\Users\Grigorij\Downloads\Southpark (D).zip
2013-10-25 13:48 - 2013-10-25 13:48 - 00001496 _____ C:\Users\Grigorij\Desktop\Project64.lnk
2013-10-25 13:45 - 2013-10-25 13:45 - 10186459 _____ C:\Users\Grigorij\Downloads\Star Fox 64 (D, F, E).zip
2013-10-25 13:42 - 2013-10-25 13:38 - 61310559 _____ C:\Users\Grigorij\Downloads\Conkers Bad Fur Day (E).zip
2013-10-25 13:34 - 2013-10-25 13:34 - 04603228 _____ (                                                            ) C:\Users\Grigorij\Downloads\setup_Project64_2.1.exe
2013-10-25 09:54 - 2013-10-25 09:54 - 01038704 _____ (Amazon Services LLC) C:\Users\Grigorij\Downloads\Assassin_s_Creed_3_Digital_Deluxe_Edition_Downloader.exe
2013-10-23 19:10 - 2013-07-29 15:11 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\vlc
2013-10-23 19:08 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF
2013-10-21 18:06 - 2013-10-21 18:06 - 00709023 _____ C:\Users\Grigorij\Downloads\documents-export-2013-10-21.zip
2013-10-21 18:04 - 2013-06-02 12:53 - 00000000 ____D C:\Users\Grigorij\AppData\Local\Google
2013-10-21 18:04 - 2013-06-02 12:46 - 00000000 ____D C:\Program Files (x86)\Google
2013-10-21 18:03 - 2013-10-21 18:03 - 00819136 _____ (Google Inc.) C:\Users\Grigorij\Downloads\googledrivesync.exe
2013-10-20 11:38 - 2013-10-20 11:38 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_ssadadb_01005.Wdf
2013-10-19 17:22 - 2013-10-19 17:22 - 00003186 _____ C:\Windows\System32\Tasks\{F81AA872-BD9F-4779-9147-A636F768F844}
2013-10-19 17:20 - 2013-10-19 17:20 - 11180128 _____ (Irfan Skiljan) C:\Users\Grigorij\Downloads\irfanview_plugins_436_setup.exe
2013-10-19 16:58 - 2013-10-19 16:58 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
2013-10-19 16:58 - 2013-10-19 16:58 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\IrfanView
2013-10-19 16:58 - 2013-10-19 16:58 - 00000000 ____D C:\Program Files (x86)\IrfanView
2013-10-19 16:56 - 2013-10-19 16:56 - 02145888 _____ (Irfan Skiljan) C:\Users\Grigorij\Downloads\iview436g_setup.exe
2013-10-18 20:25 - 2013-10-07 20:23 - 00000000 ____D C:\Program Files (x86)\Hearthstone
2013-10-17 21:38 - 2013-08-05 12:32 - 00004110 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-17 21:38 - 2013-08-05 12:32 - 00003858 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-16 14:12 - 2013-10-04 19:57 - 00000000 ____D C:\Program Files (x86)\Battle.net
2013-10-11 16:10 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-10-10 13:54 - 2009-07-14 05:45 - 00339536 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-10 13:49 - 2013-06-07 16:27 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-10-10 13:47 - 2009-07-14 03:34 - 00000499 _____ C:\Windows\win.ini
2013-10-10 13:41 - 2013-06-07 16:27 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-10 13:34 - 2013-06-11 17:28 - 01591234 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-10-10 13:24 - 2013-07-19 20:16 - 00000000 ____D C:\Windows\system32\MRT
2013-10-10 13:15 - 2011-07-18 21:31 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-10-09 16:07 - 2013-07-18 22:39 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-10-09 16:07 - 2013-06-17 21:26 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-10-09 16:07 - 2011-08-10 20:09 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

Some content of TEMP:
====================
C:\Users\Grigorij\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-10-31 16:00

==================== End Of Log ============================
         
--- --- ---

--- --- ---

Geändert von Segonji (08.11.2013 um 13:50 Uhr)

Alt 09.11.2013, 13:07   #12
schrauber
/// the machine
/// TB-Ausbilder
 

Lyricxeeker entfernt, aber Laptop immer noch langsam - Standard

Lyricxeeker entfernt, aber Laptop immer noch langsam




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 09.11.2013, 16:19   #13
Segonji
 
Lyricxeeker entfernt, aber Laptop immer noch langsam - Standard

Lyricxeeker entfernt, aber Laptop immer noch langsam



Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=400b49764cda0d4091a7190b1fde5f49
# engine=15820
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-11-09 03:18:33
# local_time=2013-11-09 04:18:33 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776574 100 94 10383182 135640163 0 0
# scanned=317090
# found=1
# cleaned=0
# scan_time=11020
sh=EE51BC65E632624027E2DD83F44A75784323D247 ft=1 fh=6e4c94e45ea75834 vn="Win32/Adware.Lollipop.D application" ac=I fn="C:\Users\Grigorij\Downloads\setup_Project64_2.1.exe"
         
Code:
ATTFilter
 Results of screen317's Security Check version 0.99.74  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 10  
``````````````Antivirus/Firewall Check:`````````````` 
Kaspersky Internet Security   
 Antivirus up to date!  (On Access scanning disabled!) 
`````````Anti-malware/Other Utilities Check:````````` 
 Malwarebytes Anti-Malware Version 1.75.0.1300  
 Java(TM) 6 Update 26  
 Java 7 Update 45  
 Java version out of Date! 
 Adobe Flash Player 11.9.900.117  
 Adobe Reader 10.1.8 Adobe Reader out of Date!  
 Google Chrome 30.0.1599.101  
 Google Chrome 30.0.1599.69  
````````Process Check: objlist.exe by Laurent````````  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log``````````````````````
         

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 31-10-2013
Ran by Grigorij (administrator) on GRIGORIJ-PC on 09-11-2013 16:26:31
Running from C:\Users\Grigorij\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
() C:\Program Files (x86)\PHotkey\ASLDRSrv.exe
() C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
(UPEK Inc.) C:\Program Files\Protector Suite\upeksvr.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
( ) C:\Windows\system32\lxdicoms.exe
(Motorola Mobility LLC) C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Motorola) C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
() C:\Program Files (x86)\PHotkey\PHotkey.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
() C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
() C:\Program Files (x86)\PHotkey\ATouch64.exe
() C:\Program Files (x86)\PHotkey\PVDesktop.exe
() C:\Program Files (x86)\PHotkey\PVDAgent.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files (x86)\PHotkey\POSD.exe
(Motorola Mobility LLC) C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(UPEK Inc.) C:\Program Files\Protector Suite\psqltray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(TODO: <Company name>) C:\Program Files (x86)\PHotkey\HCSynApi.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
() C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe
() C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Expert System S.p.A.) C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Dropbox, Inc.) C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Bibliographisches Institut GmbH) C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe
(cyberlink) C:\Program Files (x86)\CyberLink\Shared files\brs.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe
(Blizzard Entertainment) C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11817576 2011-04-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2209896 2011-04-18] (Realtek Semiconductor)
HKLM\...\Run: [PSQLLauncher] - C:\Program Files\Protector Suite\launcher.exe [84816 2010-12-10] (UPEK Inc.)
HKLM\...\Run: [IntelPAN] - C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-02] (Intel(R) Corporation)
HKLM\...\Run: [BTMTrayAgent] - rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2028328 2010-01-22] (Synaptics Incorporated)
HKLM\...\Run: [MedionReminder] - C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe [443688 2011-05-26] (CyberLink)
HKLM\...\Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1012000 2013-05-16] (NVIDIA Corporation)
HKLM\...\Run: [lxdimon.exe] - C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdimon.exe [434856 2009-04-27] ()
HKLM\...\Run: [lxdiamon] - C:\Program Files (x86)\Lexmark 3500-4500 Series\lxdiamon.exe [25256 2009-04-27] ()
HKLM\...\RunOnce: [MedionReminder] - C:\Program Files (x86)\CyberLink\PowerRecover\Reminder.exe /DeleteRunKey [443688 2011-05-26] (CyberLink)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\psfus: C:\Program Files\Protector Suite\psqlpwd.dll (UPEK Inc.)
HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1820584 2013-10-30] (Valve Corporation)
HKCU\...\Run: [icq] - C:\Users\Grigorij\AppData\Roaming\ICQM\icq.exe [27598184 2013-06-02] (ICQ)
HKCU\...\Run: [Duden Korrektor SysTray] - C:\Program Files (x86)\Duden\Duden-Rechtschreibprüfung\DKTray.exe [332432 2011-07-04] (Expert System S.p.A.)
HKCU\...\Run: [GoogleDriveSync] - C:\Program Files (x86)\Google\Drive\googledrivesync.exe [20133824 2013-09-25] (Google)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-06] (Intel Corporation)
HKLM-x32\...\Run: [Dolby Home Theater v4] - C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [CLMLServer] - C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-03] (CyberLink)
HKLM-x32\...\Run: [YouCam Mirage] - C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [136488 2011-04-15] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] - C:\Program Files (x86)\CyberLink\YouCam\YouCam.exe [228448 2011-04-15] (CyberLink Corp.)
HKLM-x32\...\Run: [BDRegion] - C:\Program Files (x86)\CyberLink\Shared files\brs.exe [75048 2011-03-21] (cyberlink)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll [266448 2013-05-12] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [214448 2013-05-12] (NVIDIA Corporation)
Lsa: [Notification Packages] scecli C:\Program Files\Protector Suite\psqlpwd.dll
Startup: C:\Users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()
Startup: C:\Users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll ()
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Extension: trtv3 - C:\Users\Grigorij\AppData\Roaming\Mozilla\Firefox\profiles\extensions\trtv3@trtv.com.xpi
FF HKLM-x32\...\Firefox\Extensions:  - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com

Chrome: 
=======
CHR HomePage: hxxp://www.kicker.de/
CHR RestoreOnStartup: "chrome://newtab/", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=48&cc=&mi=204c3cc00000000000004c809307ab58", "hxxp://www.google.com"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 6.0.260.3) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U26) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File
CHR Extension: (Google Docs) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (AdBlock) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.13_0
CHR Extension: (Dangerous Websites Blocker) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail\14.0.0.4651_0
CHR Extension: (WEB.DE MailCheck) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaogepninmlbinccpbiakcgiolijlllo\1.2_0
CHR Extension: (WordPress.com) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\khjnjifipfkgglficmipimgjpbmlbemd\1.1.1_0
CHR Extension: (DVDVideoSoft) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.3.0.0_0
CHR Extension: (Google Wallet) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (365Scores - Live Scores,Sports News & Alerts) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmpppefjehmjbiplimkfjeamnohldmko\1.8.1_0
CHR Extension: (Gmail) - C:\Users\Grigorij\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx

==================== Services (Whitelisted) =================

R2 ASLDRService; C:\Program Files (x86)\PHotkey\ASLDRSrv.exe [104968 2009-12-18] ()
S2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-01] (Kaspersky Lab ZAO)
S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [241648 2011-02-25] (CyberLink)
R2 GFNEXSrv; C:\Program Files (x86)\PHotkey\GFNEXSrv.exe [159752 2010-10-07] ()
R2 lxdi_device; C:\Windows\system32\lxdicoms.exe [876976 2007-06-11] ( )
R2 lxdi_device; C:\Windows\SysWow64\lxdicoms.exe [517040 2007-06-11] ( )
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 Motorola Device Manager; C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [137528 2013-07-31] (Motorola Mobility LLC)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-02] ()
R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2013-10-25] ()

==================== Drivers (Whitelisted) ====================

R3 InputFilter_Hid_FlexDef2b; C:\Windows\System32\DRIVERS\InputFilter_FlexDef2b.sys [17920 2010-06-18] (Siliten)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-11-06] (Kaspersky Lab ZAO)
S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [112224 2013-06-08] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [623200 2013-11-06] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-01] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-01] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-01] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178784 2013-06-06] (Kaspersky Lab ZAO)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R2 PEGAGFN; C:\Program Files (x86)\PHotkey\PEGAGFN.sys [14344 2009-09-11] (PEGATRON)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 motccgpfl; system32\DRIVERS\motccgpfl.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-11-09 16:20 - 2013-11-09 16:20 - 00891167 _____ C:\Users\Grigorij\Desktop\SecurityCheck.exe
2013-11-09 13:08 - 2013-11-09 13:08 - 02347384 _____ (ESET) C:\Users\Grigorij\Downloads\esetsmartinstaller_enu.exe
2013-11-08 13:41 - 2013-11-08 13:41 - 00000000 ____D C:\Windows\ERUNT
2013-11-08 13:39 - 2013-11-08 13:39 - 01034531 _____ (Thisisu) C:\Users\Grigorij\Desktop\JRT.exe
2013-11-08 13:28 - 2013-11-08 13:28 - 01073262 _____ C:\Users\Grigorij\Desktop\adwcleaner.exe
2013-11-08 13:04 - 2013-11-08 13:04 - 01073262 _____ C:\Users\Grigorij\Downloads\adwcleaner.exe
2013-11-08 13:04 - 2013-11-08 13:04 - 00001117 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-11-08 13:04 - 2013-11-08 13:04 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-08 13:04 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-11-08 13:03 - 2013-11-08 13:03 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Grigorij\Downloads\mbam-setup-1.75.0.1300.exe
2013-11-07 00:06 - 2013-11-07 00:06 - 00033120 _____ C:\ComboFix.txt
2013-11-06 23:46 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2013-11-06 23:46 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2013-11-06 23:46 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-11-06 23:46 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-11-06 23:46 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-11-06 23:46 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2013-11-06 23:46 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2013-11-06 23:46 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2013-11-06 23:45 - 2013-11-07 00:07 - 00000000 ____D C:\Qoobox
2013-11-06 23:45 - 2013-11-07 00:05 - 00000000 ____D C:\Windows\erdnt
2013-11-06 23:44 - 2013-11-06 23:44 - 05144303 ____R (Swearware) C:\Users\Grigorij\Desktop\ComboFix.exe
2013-11-06 23:44 - 2013-11-06 23:44 - 05144303 _____ (Swearware) C:\Users\Grigorij\Downloads\ComboFix.exe
2013-11-05 20:49 - 2013-11-05 20:50 - 28001847 _____ (Paradox Interactive                                         ) C:\Users\Grigorij\Downloads\eu3dw5_2.exe
2013-11-03 20:15 - 2013-11-03 20:16 - 00013681 _____ C:\Users\Grigorij\Downloads\gmer (2).zip
2013-11-03 20:15 - 2013-11-03 20:16 - 00013681 _____ C:\Users\Grigorij\Downloads\gmer (1).zip
2013-11-03 19:17 - 2013-11-03 19:18 - 00519264 _____ C:\Windows\Minidump\110313-32853-01.dmp
2013-11-03 13:47 - 2013-11-03 13:47 - 00013681 _____ C:\Users\Grigorij\Downloads\gmer.zip
2013-11-03 12:47 - 2013-11-03 12:47 - 00377856 _____ C:\Users\Grigorij\Downloads\7j0c9k42.exe
2013-11-03 12:37 - 2013-11-03 12:37 - 00000000 ____D C:\FRST
2013-11-03 12:36 - 2013-11-03 12:35 - 01957098 _____ (Farbar) C:\Users\Grigorij\Desktop\FRST64.exe
2013-11-03 12:35 - 2013-11-03 12:35 - 01957098 _____ (Farbar) C:\Users\Grigorij\Downloads\FRST64.exe
2013-11-02 23:51 - 2013-11-08 13:31 - 00000000 ____D C:\AdwCleaner
2013-11-02 23:51 - 2013-11-02 23:51 - 01060070 _____ C:\Users\Grigorij\Downloads\adwcleaner-3.010.exe
2013-11-02 11:59 - 2013-11-02 11:59 - 00001540 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2013-11-02 11:58 - 2013-11-02 11:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-02 11:57 - 2013-11-02 11:57 - 00001444 _____ C:\Users\Public\Desktop\Free YouTube Download.lnk
2013-11-02 11:55 - 2013-11-02 11:56 - 32132232 _____ (DVDVideoSoft Ltd.                                           ) C:\Users\Grigorij\Downloads\FreeYouTubeToMP3Converter3.2.16.1028.exe
2013-11-02 11:44 - 2013-11-02 11:44 - 00000000 ____D C:\ProgramData\Oracle
2013-11-02 11:44 - 2013-10-08 07:50 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-02 11:44 - 2013-10-08 07:46 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-11-02 11:44 - 2013-10-08 07:46 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-11-02 11:44 - 2013-10-08 07:46 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-11-02 11:43 - 2013-11-02 11:44 - 00004886 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-10-29 13:21 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2013-10-29 13:21 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2013-10-29 13:21 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2013-10-29 13:21 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2013-10-29 13:21 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2013-10-29 13:21 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2013-10-29 13:21 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2013-10-28 17:57 - 2013-10-28 17:57 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Ubisoft
2013-10-28 17:49 - 2013-10-28 17:49 - 00001730 _____ C:\Users\Grigorij\Desktop\Assassin's Creed.lnk
2013-10-28 17:41 - 2013-10-28 17:41 - 00000000 ____D C:\ProgramData\Ubisoft
2013-10-27 12:33 - 2013-10-27 12:33 - 01872114 _____ C:\Users\Grigorij\Downloads\pj64_1_6.zip
2013-10-27 12:31 - 2013-10-27 12:31 - 07362734 _____ C:\Users\Grigorij\Downloads\Vigilante 8.zip
2013-10-27 11:33 - 2013-10-27 11:34 - 11340380 _____ C:\Users\Grigorij\Downloads\vigilante 8 - 2nd offence (e) [!].zip
2013-10-27 11:33 - 2013-10-27 11:33 - 07486064 _____ C:\Users\Grigorij\Downloads\vigilante 8 (e) [!].zip
2013-10-27 11:27 - 2013-10-27 11:27 - 11368658 _____ C:\Users\Grigorij\Downloads\1080 snowboarding (e) (m4) [!].zip
2013-10-27 11:19 - 2013-10-27 11:20 - 27597639 _____ C:\Users\Grigorij\Downloads\starcraft 64 (e) [!].zip
2013-10-25 18:36 - 2013-10-26 21:30 - 00000000 ____D C:\Fraps
2013-10-25 18:36 - 2013-10-25 18:36 - 00000566 _____ C:\Users\Public\Desktop\Fraps.lnk
2013-10-25 16:23 - 2013-10-25 16:23 - 00000939 _____ C:\Users\Grigorij\Desktop\Steam.lnk
2013-10-25 16:05 - 2013-10-25 16:30 - 00000000 ____D C:\Users\Grigorij\Documents\Assassin's Creed III
2013-10-25 15:58 - 2013-10-25 16:06 - 00000000 ____D C:\Users\Grigorij\AppData\Local\Ubisoft Game Launcher
2013-10-25 15:31 - 2013-10-28 17:20 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2013-10-25 15:31 - 2013-10-25 15:31 - 00189248 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-10-25 15:31 - 2013-10-25 15:31 - 00075136 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2013-10-25 15:31 - 2013-10-25 15:31 - 00001209 _____ C:\Users\Grigorij\Desktop\Uplay.lnk
2013-10-25 15:31 - 2013-10-25 15:31 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2013-10-25 15:31 - 2013-10-25 15:26 - 03123272 _____ C:\Windows\SysWOW64\pbsvc.exe
2013-10-25 14:11 - 2013-10-25 14:11 - 00000081 _____ C:\Users\Grigorij\gri.cp
2013-10-25 13:59 - 2013-10-25 13:59 - 10545441 _____ C:\Users\Grigorij\Downloads\LEGO Racers (D, F, E).zip
2013-10-25 13:58 - 2013-10-25 13:59 - 04840302 _____ C:\Users\Grigorij\Downloads\Snowboard Kids (E).zip
2013-10-25 13:57 - 2013-10-25 13:59 - 25675994 _____ C:\Users\Grigorij\Downloads\Star Wars Episode I - Racer (D, F, E).zip
2013-10-25 13:54 - 2013-10-25 13:55 - 10323803 _____ C:\Users\Grigorij\Downloads\Destruction Derby 64 (E).zip
2013-10-25 13:54 - 2013-10-25 13:55 - 10084676 _____ C:\Users\Grigorij\Downloads\Diddy Kong Racing (D, F, E).zip
2013-10-25 13:53 - 2013-10-25 13:54 - 16086013 _____ C:\Users\Grigorij\Downloads\Super Smash Bros (D, F, E).zip
2013-10-25 13:50 - 2013-10-25 13:51 - 16490258 _____ C:\Users\Grigorij\Downloads\Banjo-Kazooie (D, F, E).zip
2013-10-25 13:50 - 2013-10-25 13:50 - 22161948 _____ C:\Users\Grigorij\Downloads\Mario Party (D, F, E).zip
2013-10-25 13:50 - 2013-10-25 13:50 - 13896929 _____ C:\Users\Grigorij\Downloads\Southpark (D).zip
2013-10-25 13:48 - 2013-10-25 13:48 - 00001496 _____ C:\Users\Grigorij\Desktop\Project64.lnk
2013-10-25 13:45 - 2013-10-25 13:45 - 10186459 _____ C:\Users\Grigorij\Downloads\Star Fox 64 (D, F, E).zip
2013-10-25 13:38 - 2013-10-25 13:42 - 61310559 _____ C:\Users\Grigorij\Downloads\Conkers Bad Fur Day (E).zip
2013-10-25 13:34 - 2013-10-27 12:34 - 00000000 ____D C:\Program Files (x86)\Project64 2.1
2013-10-25 13:34 - 2013-10-25 13:34 - 04603228 _____ (                                                            ) C:\Users\Grigorij\Downloads\setup_Project64_2.1.exe
2013-10-25 09:54 - 2013-10-25 09:54 - 01038704 _____ (Amazon Services LLC) C:\Users\Grigorij\Downloads\Assassin_s_Creed_3_Digital_Deluxe_Edition_Downloader.exe
2013-10-21 18:06 - 2013-11-09 11:57 - 00000000 ___RD C:\Users\Grigorij\Google Drive
2013-10-21 18:06 - 2013-10-21 18:06 - 00709023 _____ C:\Users\Grigorij\Downloads\documents-export-2013-10-21.zip
2013-10-21 18:03 - 2013-10-21 18:03 - 00819136 _____ (Google Inc.) C:\Users\Grigorij\Downloads\googledrivesync.exe
2013-10-20 11:38 - 2013-10-20 11:38 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_ssadadb_01005.Wdf
2013-10-19 17:22 - 2013-10-19 17:22 - 00003186 _____ C:\Windows\System32\Tasks\{F81AA872-BD9F-4779-9147-A636F768F844}
2013-10-19 17:20 - 2013-10-19 17:20 - 11180128 _____ (Irfan Skiljan) C:\Users\Grigorij\Downloads\irfanview_plugins_436_setup.exe
2013-10-19 16:58 - 2013-10-19 16:58 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
2013-10-19 16:58 - 2013-10-19 16:58 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\IrfanView
2013-10-19 16:58 - 2013-10-19 16:58 - 00000000 ____D C:\Program Files (x86)\IrfanView
2013-10-19 16:56 - 2013-10-19 16:56 - 02145888 _____ (Irfan Skiljan) C:\Users\Grigorij\Downloads\iview436g_setup.exe
2013-10-10 13:44 - 2013-09-23 00:28 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-10-10 13:44 - 2013-09-23 00:28 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 14335488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 02876928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 02048512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-10-10 13:44 - 2013-09-23 00:27 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-10-10 13:44 - 2013-09-22 23:55 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-10-10 13:44 - 2013-09-22 23:55 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-10-10 13:44 - 2013-09-22 23:55 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-10-10 13:44 - 2013-09-22 23:54 - 19252224 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 02647552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-10-10 13:44 - 2013-09-22 23:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-10-10 13:44 - 2013-09-21 04:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-10-10 13:44 - 2013-09-21 04:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-10-10 13:44 - 2013-09-21 03:48 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-10-10 13:44 - 2013-09-21 03:39 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-10-10 12:47 - 2013-07-12 11:41 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2013-10-10 12:47 - 2013-07-12 11:41 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2013-10-10 12:47 - 2013-07-04 13:50 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2013-10-10 12:47 - 2013-07-04 12:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2013-10-10 12:47 - 2013-07-03 05:40 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys
2013-10-10 12:47 - 2013-07-03 05:05 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2013-10-10 12:47 - 2013-07-03 05:05 - 00032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2013-10-10 12:47 - 2013-06-25 23:55 - 00785624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2013-10-10 12:47 - 2013-06-06 06:50 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2013-10-10 12:47 - 2013-06-06 06:49 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2013-10-10 12:47 - 2013-06-06 06:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2013-10-10 12:47 - 2013-06-06 06:47 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2013-10-10 12:47 - 2013-06-06 05:57 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2013-10-10 12:47 - 2013-06-06 05:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2013-10-10 12:47 - 2013-06-06 05:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2013-10-10 12:47 - 2013-06-06 04:30 - 00368128 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2013-10-10 12:47 - 2013-06-06 04:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2013-10-10 12:47 - 2013-06-06 04:01 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2013-10-10 12:46 - 2013-09-14 02:10 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-10-10 12:46 - 2013-09-08 03:30 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-10-10 12:46 - 2013-09-08 03:27 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2013-10-10 12:46 - 2013-09-08 03:03 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2013-10-10 12:46 - 2013-08-29 03:17 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-10-10 12:46 - 2013-08-29 03:16 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-10-10 12:46 - 2013-08-29 03:16 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2013-10-10 12:46 - 2013-08-29 03:16 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2013-10-10 12:46 - 2013-08-29 03:13 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2013-10-10 12:46 - 2013-08-29 02:51 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2013-10-10 12:46 - 2013-08-29 02:51 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2013-10-10 12:46 - 2013-08-29 02:50 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2013-10-10 12:46 - 2013-08-29 02:50 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2013-10-10 12:46 - 2013-08-29 02:50 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2013-10-10 12:46 - 2013-08-29 02:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2013-10-10 12:46 - 2013-08-29 01:49 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2013-10-10 12:46 - 2013-08-29 01:49 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2013-10-10 12:46 - 2013-08-29 01:49 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2013-10-10 12:46 - 2013-08-29 01:49 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2013-10-10 12:46 - 2013-08-28 02:21 - 03155968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-10-10 12:46 - 2013-07-04 13:57 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2013-10-10 12:46 - 2013-07-04 13:50 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2013-10-10 12:46 - 2013-07-04 12:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2013-10-10 12:46 - 2013-07-04 12:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2013-10-10 12:46 - 2013-07-04 11:11 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2013-10-10 12:45 - 2013-08-28 02:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2013-10-10 12:45 - 2013-08-01 13:09 - 00983488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2013-10-10 12:45 - 2013-07-20 11:33 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2013-10-10 12:45 - 2013-07-20 11:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll

==================== One Month Modified Files and Folders =======

2013-11-09 16:26 - 2013-10-04 19:58 - 00000000 ____D C:\Users\Grigorij\AppData\Local\Battle.net
2013-11-09 16:20 - 2013-11-09 16:20 - 00891167 _____ C:\Users\Grigorij\Desktop\SecurityCheck.exe
2013-11-09 16:07 - 2013-06-02 12:43 - 02044031 _____ C:\Windows\WindowsUpdate.log
2013-11-09 16:06 - 2013-07-18 22:39 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-11-09 15:43 - 2013-08-05 12:32 - 00001114 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-11-09 15:09 - 2013-06-02 14:43 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Dropbox
2013-11-09 14:51 - 2013-06-02 14:12 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Skype
2013-11-09 13:08 - 2013-11-09 13:08 - 02347384 _____ (ESET) C:\Users\Grigorij\Downloads\esetsmartinstaller_enu.exe
2013-11-09 12:36 - 2009-07-14 05:51 - 00101611 _____ C:\Windows\setupact.log
2013-11-09 12:09 - 2013-06-02 13:09 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2013-11-09 12:02 - 2009-07-14 05:45 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-11-09 12:02 - 2009-07-14 05:45 - 00016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-11-09 11:57 - 2013-10-21 18:06 - 00000000 ___RD C:\Users\Grigorij\Google Drive
2013-11-09 11:56 - 2013-06-02 14:44 - 00000000 ___RD C:\Users\Grigorij\Dropbox
2013-11-09 11:56 - 2013-06-02 13:42 - 00000000 ____D C:\Program Files (x86)\Steam
2013-11-09 11:55 - 2013-08-05 12:32 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-11-09 11:53 - 2013-06-11 17:33 - 00000000 ____D C:\ProgramData\NVIDIA
2013-11-09 11:53 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-11-08 19:09 - 2013-06-02 14:06 - 00000000 ____D C:\Program Files (x86)\World of Warcraft
2013-11-08 14:00 - 2013-06-02 14:08 - 00000000 ____D C:\Users\Grigorij\AppData\Local\Deployment
2013-11-08 13:41 - 2013-11-08 13:41 - 00000000 ____D C:\Windows\ERUNT
2013-11-08 13:39 - 2013-11-08 13:39 - 01034531 _____ (Thisisu) C:\Users\Grigorij\Desktop\JRT.exe
2013-11-08 13:31 - 2013-11-02 23:51 - 00000000 ____D C:\AdwCleaner
2013-11-08 13:28 - 2013-11-08 13:28 - 01073262 _____ C:\Users\Grigorij\Desktop\adwcleaner.exe
2013-11-08 13:21 - 2010-11-21 04:47 - 00022726 _____ C:\Windows\PFRO.log
2013-11-08 13:04 - 2013-11-08 13:04 - 01073262 _____ C:\Users\Grigorij\Downloads\adwcleaner.exe
2013-11-08 13:04 - 2013-11-08 13:04 - 00001117 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2013-11-08 13:04 - 2013-11-08 13:04 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-11-08 13:03 - 2013-11-08 13:03 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Grigorij\Downloads\mbam-setup-1.75.0.1300.exe
2013-11-07 19:30 - 2011-05-16 15:04 - 00697082 _____ C:\Windows\system32\perfh007.dat
2013-11-07 19:30 - 2011-05-16 15:04 - 00148346 _____ C:\Windows\system32\perfc007.dat
2013-11-07 19:30 - 2009-07-14 06:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI
2013-11-07 00:09 - 2013-06-02 14:08 - 00000000 ____D C:\Users\Grigorij\AppData\Local\Apps\2.0
2013-11-07 00:07 - 2013-11-06 23:45 - 00000000 ____D C:\Qoobox
2013-11-07 00:06 - 2013-11-07 00:06 - 00033120 _____ C:\ComboFix.txt
2013-11-07 00:05 - 2013-11-06 23:45 - 00000000 ____D C:\Windows\erdnt
2013-11-06 23:59 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2013-11-06 23:44 - 2013-11-06 23:44 - 05144303 ____R (Swearware) C:\Users\Grigorij\Desktop\ComboFix.exe
2013-11-06 23:44 - 2013-11-06 23:44 - 05144303 _____ (Swearware) C:\Users\Grigorij\Downloads\ComboFix.exe
2013-11-06 23:42 - 2013-09-24 12:46 - 00623200 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2013-11-06 23:42 - 2013-05-06 08:22 - 00458336 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys
2013-11-06 17:59 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-11-05 20:50 - 2013-11-05 20:49 - 28001847 _____ (Paradox Interactive                                         ) C:\Users\Grigorij\Downloads\eu3dw5_2.exe
2013-11-03 20:16 - 2013-11-03 20:15 - 00013681 _____ C:\Users\Grigorij\Downloads\gmer (2).zip
2013-11-03 20:16 - 2013-11-03 20:15 - 00013681 _____ C:\Users\Grigorij\Downloads\gmer (1).zip
2013-11-03 19:18 - 2013-11-03 19:17 - 00519264 _____ C:\Windows\Minidump\110313-32853-01.dmp
2013-11-03 19:17 - 2013-06-07 21:58 - 605910832 _____ C:\Windows\MEMORY.DMP
2013-11-03 19:17 - 2013-06-07 21:58 - 00000000 ____D C:\Windows\Minidump
2013-11-03 13:47 - 2013-11-03 13:47 - 00013681 _____ C:\Users\Grigorij\Downloads\gmer.zip
2013-11-03 12:47 - 2013-11-03 12:47 - 00377856 _____ C:\Users\Grigorij\Downloads\7j0c9k42.exe
2013-11-03 12:37 - 2013-11-03 12:37 - 00000000 ____D C:\FRST
2013-11-03 12:35 - 2013-11-03 12:36 - 01957098 _____ (Farbar) C:\Users\Grigorij\Desktop\FRST64.exe
2013-11-03 12:35 - 2013-11-03 12:35 - 01957098 _____ (Farbar) C:\Users\Grigorij\Downloads\FRST64.exe
2013-11-02 23:51 - 2013-11-02 23:51 - 01060070 _____ C:\Users\Grigorij\Downloads\adwcleaner-3.010.exe
2013-11-02 16:23 - 2013-08-17 19:09 - 00000000 ____D C:\Program Files (x86)\JDownloader
2013-11-02 16:20 - 2013-08-04 19:07 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\uTorrent
2013-11-02 11:59 - 2013-11-02 11:59 - 00001540 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2013-11-02 11:59 - 2013-06-15 18:13 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\DVDVideoSoft
2013-11-02 11:59 - 2013-06-15 18:13 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
2013-11-02 11:58 - 2013-11-02 11:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-11-02 11:57 - 2013-11-02 11:57 - 00001444 _____ C:\Users\Public\Desktop\Free YouTube Download.lnk
2013-11-02 11:56 - 2013-11-02 11:55 - 32132232 _____ (DVDVideoSoft Ltd.                                           ) C:\Users\Grigorij\Downloads\FreeYouTubeToMP3Converter3.2.16.1028.exe
2013-11-02 11:44 - 2013-11-02 11:44 - 00000000 ____D C:\ProgramData\Oracle
2013-11-02 11:44 - 2013-11-02 11:43 - 00004886 _____ C:\Windows\SysWOW64\jupdate-1.7.0_45-b18.log
2013-11-02 11:44 - 2011-07-18 22:13 - 00000000 ____D C:\Program Files (x86)\Java
2013-10-28 17:57 - 2013-10-28 17:57 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Ubisoft
2013-10-28 17:49 - 2013-10-28 17:49 - 00001730 _____ C:\Users\Grigorij\Desktop\Assassin's Creed.lnk
2013-10-28 17:41 - 2013-10-28 17:41 - 00000000 ____D C:\ProgramData\Ubisoft
2013-10-28 17:39 - 2011-07-18 21:49 - 00550829 _____ C:\Windows\DirectX.log
2013-10-28 17:20 - 2013-10-25 15:31 - 00000000 ____D C:\Program Files (x86)\Ubisoft
2013-10-28 17:20 - 2011-07-18 22:23 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-10-27 12:34 - 2013-10-25 13:34 - 00000000 ____D C:\Program Files (x86)\Project64 2.1
2013-10-27 12:33 - 2013-10-27 12:33 - 01872114 _____ C:\Users\Grigorij\Downloads\pj64_1_6.zip
2013-10-27 12:31 - 2013-10-27 12:31 - 07362734 _____ C:\Users\Grigorij\Downloads\Vigilante 8.zip
2013-10-27 11:34 - 2013-10-27 11:33 - 11340380 _____ C:\Users\Grigorij\Downloads\vigilante 8 - 2nd offence (e) [!].zip
2013-10-27 11:33 - 2013-10-27 11:33 - 07486064 _____ C:\Users\Grigorij\Downloads\vigilante 8 (e) [!].zip
2013-10-27 11:27 - 2013-10-27 11:27 - 11368658 _____ C:\Users\Grigorij\Downloads\1080 snowboarding (e) (m4) [!].zip
2013-10-27 11:20 - 2013-10-27 11:19 - 27597639 _____ C:\Users\Grigorij\Downloads\starcraft 64 (e) [!].zip
2013-10-26 21:30 - 2013-10-25 18:36 - 00000000 ____D C:\Fraps
2013-10-26 11:07 - 2013-06-02 14:12 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-10-26 11:07 - 2013-06-02 14:12 - 00000000 ____D C:\ProgramData\Skype
2013-10-25 18:36 - 2013-10-25 18:36 - 00000566 _____ C:\Users\Public\Desktop\Fraps.lnk
2013-10-25 16:30 - 2013-10-25 16:05 - 00000000 ____D C:\Users\Grigorij\Documents\Assassin's Creed III
2013-10-25 16:23 - 2013-10-25 16:23 - 00000939 _____ C:\Users\Grigorij\Desktop\Steam.lnk
2013-10-25 16:06 - 2013-10-25 15:58 - 00000000 ____D C:\Users\Grigorij\AppData\Local\Ubisoft Game Launcher
2013-10-25 15:31 - 2013-10-25 15:31 - 00189248 _____ C:\Windows\SysWOW64\PnkBstrB.exe
2013-10-25 15:31 - 2013-10-25 15:31 - 00075136 _____ C:\Windows\SysWOW64\PnkBstrA.exe
2013-10-25 15:31 - 2013-10-25 15:31 - 00001209 _____ C:\Users\Grigorij\Desktop\Uplay.lnk
2013-10-25 15:31 - 2013-10-25 15:31 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2013-10-25 15:26 - 2013-10-25 15:31 - 03123272 _____ C:\Windows\SysWOW64\pbsvc.exe
2013-10-25 14:11 - 2013-10-25 14:11 - 00000081 _____ C:\Users\Grigorij\gri.cp
2013-10-25 14:11 - 2013-06-02 12:48 - 00000000 ____D C:\Users\Grigorij
2013-10-25 13:59 - 2013-10-25 13:59 - 10545441 _____ C:\Users\Grigorij\Downloads\LEGO Racers (D, F, E).zip
2013-10-25 13:59 - 2013-10-25 13:58 - 04840302 _____ C:\Users\Grigorij\Downloads\Snowboard Kids (E).zip
2013-10-25 13:59 - 2013-10-25 13:57 - 25675994 _____ C:\Users\Grigorij\Downloads\Star Wars Episode I - Racer (D, F, E).zip
2013-10-25 13:55 - 2013-10-25 13:54 - 10323803 _____ C:\Users\Grigorij\Downloads\Destruction Derby 64 (E).zip
2013-10-25 13:55 - 2013-10-25 13:54 - 10084676 _____ C:\Users\Grigorij\Downloads\Diddy Kong Racing (D, F, E).zip
2013-10-25 13:54 - 2013-10-25 13:53 - 16086013 _____ C:\Users\Grigorij\Downloads\Super Smash Bros (D, F, E).zip
2013-10-25 13:51 - 2013-10-25 13:50 - 16490258 _____ C:\Users\Grigorij\Downloads\Banjo-Kazooie (D, F, E).zip
2013-10-25 13:50 - 2013-10-25 13:50 - 22161948 _____ C:\Users\Grigorij\Downloads\Mario Party (D, F, E).zip
2013-10-25 13:50 - 2013-10-25 13:50 - 13896929 _____ C:\Users\Grigorij\Downloads\Southpark (D).zip
2013-10-25 13:48 - 2013-10-25 13:48 - 00001496 _____ C:\Users\Grigorij\Desktop\Project64.lnk
2013-10-25 13:45 - 2013-10-25 13:45 - 10186459 _____ C:\Users\Grigorij\Downloads\Star Fox 64 (D, F, E).zip
2013-10-25 13:42 - 2013-10-25 13:38 - 61310559 _____ C:\Users\Grigorij\Downloads\Conkers Bad Fur Day (E).zip
2013-10-25 13:34 - 2013-10-25 13:34 - 04603228 _____ (                                                            ) C:\Users\Grigorij\Downloads\setup_Project64_2.1.exe
2013-10-25 09:54 - 2013-10-25 09:54 - 01038704 _____ (Amazon Services LLC) C:\Users\Grigorij\Downloads\Assassin_s_Creed_3_Digital_Deluxe_Edition_Downloader.exe
2013-10-23 19:10 - 2013-07-29 15:11 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\vlc
2013-10-23 19:08 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF
2013-10-21 18:06 - 2013-10-21 18:06 - 00709023 _____ C:\Users\Grigorij\Downloads\documents-export-2013-10-21.zip
2013-10-21 18:04 - 2013-06-02 12:53 - 00000000 ____D C:\Users\Grigorij\AppData\Local\Google
2013-10-21 18:04 - 2013-06-02 12:46 - 00000000 ____D C:\Program Files (x86)\Google
2013-10-21 18:03 - 2013-10-21 18:03 - 00819136 _____ (Google Inc.) C:\Users\Grigorij\Downloads\googledrivesync.exe
2013-10-20 11:38 - 2013-10-20 11:38 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_ssadadb_01005.Wdf
2013-10-19 17:22 - 2013-10-19 17:22 - 00003186 _____ C:\Windows\System32\Tasks\{F81AA872-BD9F-4779-9147-A636F768F844}
2013-10-19 17:20 - 2013-10-19 17:20 - 11180128 _____ (Irfan Skiljan) C:\Users\Grigorij\Downloads\irfanview_plugins_436_setup.exe
2013-10-19 16:58 - 2013-10-19 16:58 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IrfanView
2013-10-19 16:58 - 2013-10-19 16:58 - 00000000 ____D C:\Users\Grigorij\AppData\Roaming\IrfanView
2013-10-19 16:58 - 2013-10-19 16:58 - 00000000 ____D C:\Program Files (x86)\IrfanView
2013-10-19 16:56 - 2013-10-19 16:56 - 02145888 _____ (Irfan Skiljan) C:\Users\Grigorij\Downloads\iview436g_setup.exe
2013-10-18 20:25 - 2013-10-07 20:23 - 00000000 ____D C:\Program Files (x86)\Hearthstone
2013-10-17 21:38 - 2013-08-05 12:32 - 00004110 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-10-17 21:38 - 2013-08-05 12:32 - 00003858 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-10-16 14:12 - 2013-10-04 19:57 - 00000000 ____D C:\Program Files (x86)\Battle.net
2013-10-11 16:10 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2013-10-10 13:54 - 2009-07-14 05:45 - 00339536 _____ C:\Windows\system32\FNTCACHE.DAT
2013-10-10 13:49 - 2013-06-07 16:27 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-10-10 13:47 - 2009-07-14 03:34 - 00000499 _____ C:\Windows\win.ini
2013-10-10 13:41 - 2013-06-07 16:27 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-10-10 13:34 - 2013-06-11 17:28 - 01591234 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2013-10-10 13:24 - 2013-07-19 20:16 - 00000000 ____D C:\Windows\system32\MRT
2013-10-10 13:15 - 2011-07-18 21:31 - 80541720 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

Some content of TEMP:
====================
C:\Users\Grigorij\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-10-31 16:00

==================== End Of Log ============================
         
--- --- ---


Läuft bisher wieder flott und flüssig. Kann/soll ich malwarbytes eigentlich wieder deinstallieren? Das nervt rum dass es keine Vollversion ist ^_^

Geändert von Segonji (09.11.2013 um 16:30 Uhr)

Alt 10.11.2013, 07:13   #14
schrauber
/// the machine
/// TB-Ausbilder
 

Lyricxeeker entfernt, aber Laptop immer noch langsam - Standard

Lyricxeeker entfernt, aber Laptop immer noch langsam



Kannste machen

Adobe updaten.

Fertig

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.


Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 10.11.2013, 14:53   #15
Segonji
 
Lyricxeeker entfernt, aber Laptop immer noch langsam - Standard

Lyricxeeker entfernt, aber Laptop immer noch langsam



Soweit ich das beurteilen kann scheint jetzt alles wieder sauber zu laufen. Denke damit bist du dann von mir befreit

Vielen vielen Dank

Antwort

Themen zu Lyricxeeker entfernt, aber Laptop immer noch langsam
adblock, automatisch, battle.net, bewirkt, bildschirm, brauch, browser, curse, dateien, desktop, device driver, dvdvideosoft ltd., ebanking, entfernt, farbar, farbar recovery scan tool, internetbrowser, kaputt, kaspersky, kleines, klelam.sys, langsam, langsamer, laptop, neu, neustart, nicht mehr, nichts, plug-in, recht, sonntag, spiele, startbildschirm, super, systemsteuerung, unsinn, woche




Ähnliche Themen: Lyricxeeker entfernt, aber Laptop immer noch langsam


  1. Mystartsearch mit Malewarebytes entfernt aber immer noch da im internet explorer
    Plagegeister aller Art und deren Bekämpfung - 08.06.2015 (13)
  2. Windows 7: Win32/Tugspay.A entfernt, Laptop immer noch langsam
    Log-Analyse und Auswertung - 19.11.2014 (9)
  3. Win7 - Tojaner gefunden und entfernt, aber immer noch Probleme mit Internet Explorer 11
    Log-Analyse und Auswertung - 11.02.2014 (5)
  4. Trojan p2p worm entfernt, aber immer noch Probleme
    Plagegeister aller Art und deren Bekämpfung - 13.12.2013 (3)
  5. DealPly und Co. entfernt aber immer noch seltsame Werbepopups im Chrome Browser
    Plagegeister aller Art und deren Bekämpfung - 22.09.2013 (15)
  6. Mein Laptop fährt nur noch langsam hoch bzw. ist während des Gebrauchs sehr langsam
    Plagegeister aller Art und deren Bekämpfung - 07.05.2013 (21)
  7. Bundespolizeitrojaner entfernt aber irgendwie habe ich einige Funktionen immer noch nicht
    Plagegeister aller Art und deren Bekämpfung - 27.04.2012 (1)
  8. Trojaner gefunden und angeblich entfernt aber ist mein Laptop nun sicher?
    Log-Analyse und Auswertung - 24.03.2012 (5)
  9. System Check Malware entfernt, aber immer noch Probleme
    Log-Analyse und Auswertung - 13.02.2012 (37)
  10. Win 7 Security 2012 zwar entfernt aber trotzdem noch Probleme!
    Log-Analyse und Auswertung - 24.06.2011 (9)
  11. Windows recovery entfernt aber die Ordner sind noch durchsichtig
    Log-Analyse und Auswertung - 05.06.2011 (21)
  12. Virus entfernt, Computer aber trotzdem noch langsam......
    Log-Analyse und Auswertung - 31.07.2010 (3)
  13. b.exe entfernt, aber im HijackThis log-file immer noch ein Eintrag
    Plagegeister aller Art und deren Bekämpfung - 19.11.2009 (1)
  14. Vundo anscheinend entfernt...aber Rechner ist trotzdem noch langsam?!?!
    Log-Analyse und Auswertung - 08.04.2009 (5)
  15. virtumonde.dll entfernt.... pc immer noch am ende
    Log-Analyse und Auswertung - 06.02.2009 (1)
  16. nur noch firefox - IE soll entfernt werden aber wie????
    Mülltonne - 02.12.2008 (0)
  17. smid.fraud.c entfernt, aber Reste noch da
    Log-Analyse und Auswertung - 16.07.2005 (3)

Zum Thema Lyricxeeker entfernt, aber Laptop immer noch langsam - Hiho, bin neu hier. Auch wenn ich euer Engagement schätze, hatte ich natürlich gehofft es nie in Anspruch nehmen zu müssen Jetzt habe ich seit etwa 2 Tagen ein kleines - Lyricxeeker entfernt, aber Laptop immer noch langsam...
Archiv
Du betrachtest: Lyricxeeker entfernt, aber Laptop immer noch langsam auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.