![]() |
| |||||||
Log-Analyse und Auswertung: Flash Installation infiziertWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
| | #1 |
| | Flash Installation infiziert Hallo liebes TB-Team, als ich gestern an meinem PC arbeitete kam plötzlich ein Popup von Kaspersky Internet security 2013, dass mir mitteilte das in Datei "install_flashplayer11x32au_mssd_aih.exe" ein Malware sei, obwohl diese Datei schon länger da sein dürfte, sicher bin ich mir aber nicht, genauso wenig sicher bin ich mir ob Kaspersky jetzt die Datei desinfiziert hat. Deshalb möchte ich hier nochmal nachschauen lassen. Vorweg schon mal sorry für die fehlende Gmer.txt, aber jedesmal wenn ich damit scannen wollte stürzte mein ganzer PC ab und startete neu. Vielleicht weiß jemand wie ich dennoch einen Scan hin bekomme oder woran es liegen könnte. Edit: Gmer hängt sich beim Scan von sich selber auf... Warum auch immer. Die Defrogger, otl und extras hab ich in den Anhang gepackt. Ich hoffe mir kann weitergeholfen werden. Martin Geändert von Plex1234 (06.02.2013 um 13:45 Uhr) |
| | #2 |
| | Flash Installation infiziert Sorry wegen dem Doppelpost, aber ich hab jetzt nach 10x Absturz von GMER im Abgesicherten Modus versucht GMER ans laufen zu bringen und siehe da es klappte. Anbei der Log:
__________________Code:
ATTFilter GMER 2.0.18454 - hxxp://www.gmer.net
Rootkit scan 2013-02-06 15:23:25
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 ST925031 rev.0001 232,89GB
Running: gmer_2.0.18454.exe; Driver: C:\Users\MYPC\AppData\Local\Temp\agdiypow.sys
---- User IAT/EAT - GMER 2.0 ----
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\SHLWAPI.dll[KERNEL32.dll!FreeLibraryAndExitThread] [10002350] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\psdprotect.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\SHLWAPI.dll[KERNEL32.dll!CreateThread] [10003450] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\psdprotect.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\SHELL32.dll[KERNEL32.dll!LoadLibraryA] [100011e0] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\psdprotect.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!free] [10000000000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!??_U@YAPEAX_K@Z] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!??_V@YAXPEAX@Z] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!_XcptFilter] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!malloc] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!_initterm] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!realloc] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!_unlock] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!__dllonexit] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!memcpy] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!memset] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!_ultow_s] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!_vsnwprintf] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!_amsg_exit] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!memcmp] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!_lock] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!_onexit] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[msvcrt.dll!_ui64tow_s] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ntdll.dll!RtlLookupFunctionEntry] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ntdll.dll!RtlCaptureContext] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ntdll.dll!RtlInitUnicodeString] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ntdll.dll!RtlMapGenericMask] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ntdll.dll!RtlCreateAcl] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ntdll.dll!RtlAddAccessAllowedAce] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ntdll.dll!RtlCreateSecurityDescriptor] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ntdll.dll!RtlSetDaclSecurityDescriptor] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ntdll.dll!NtQueryInformationFile] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ntdll.dll!RtlVirtualUnwind] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!LsaOpenPolicy] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!CopySid] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!LsaLookupNames2] [4754710564d]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!LsaClose] [fffffb8ab8efa9b2]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!GetTokenInformation] [7fef9c85ec0] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!GetAclInformation] [7fef9c72ed0] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!GetAce] [7fef9c745e0] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!OpenProcessToken] [7fef9c80ce8] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!RegOpenKeyExW] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!RegCloseKey] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!RegQueryValueExW] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!GetNamedSecurityInfoW] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!GetSecurityDescriptorControl] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!IsValidSid] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!EqualSid] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!GetLengthSid] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[ADVAPI32.dll!LsaFreeMemory] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[USER32.dll!CopyImage] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[USER32.dll!LoadStringW] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[USER32.dll!ReleaseDC] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[USER32.dll!GetDC] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[GDI32.dll!CreateDIBSection] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[GDI32.dll!DeleteDC] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[GDI32.dll!GetBitmapBits] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[GDI32.dll!CreateCompatibleDC] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[GDI32.dll!SelectObject] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[GDI32.dll!BitBlt] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[GDI32.dll!GetObjectW] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[GDI32.dll!DeleteObject] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHELL32.dll!SHGetTemporaryPropertyForItem] [7fef9c745b0] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHELL32.dll!SHGetFolderPathAndSubDirW] [7fef9c80d3c] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHELL32.dll!SHChangeNotify] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!StrCmpNIW] [7fef9c745f0] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!PathFindExtensionW] [7fef9c80d18] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!SHRegGetValueW] [7fef9c73360] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!SHCreateStreamOnFileW] [7fef9c80ce8] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!PathCombineW] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!PathRemoveFileSpecW] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!PathIsNetworkPathW] [7fef9c73650] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!PathStripToRootW] [7fef9c745a0] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!PathSkipRootW] [7fef9c80ce8] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!PathAppendW] [7fef9c80d18] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!SHGetValueW] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!PathIsRootW] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!PathIsUNCW] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[SHLWAPI.dll!SHStrDupW] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetProcessHeap] [7fef9c80d3c] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!HeapFree] [7fef9c80d18] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!DisableThreadLibraryCalls] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!LoadLibraryW] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetProcAddress] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!FreeLibrary] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetLastError] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!LoadLibraryExA] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!DelayLoadFailureHook] [ffffffffffffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!CloseHandle] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!lstrlenW] [7fef9c757f8] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!LCMapStringW] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetCurrentThreadId] [7fef9c756d8] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetFileAttributesW] [7fef9c756a8] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!CreateDirectoryW] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!FindFirstFileW] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!DeleteFileW] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!FindNextFileW] [7fef9c756d8] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!FindClose] [7fef9c75690] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!RemoveDirectoryW] [1]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetDiskFreeSpaceExW] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetTempFileNameW] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!MoveFileExW] [7fef9c75680] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetVolumeInformationW] [7fef9c75660] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetDriveTypeW] [2]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!MulDiv] [1]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!CreateFileW] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetFileSize] [7fef9c75680] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!RaiseException] [7fef9c75630] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!SetFilePointer] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!WriteFile] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!SetEndOfFile] [7fef9c756d8] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetTickCount] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!SetFileAttributesW] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!UnmapViewOfFile] [7fef9c756d8] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!Sleep] [7fef9c755f0] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!QueryPerformanceCounter] [7]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetCurrentProcessId] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetSystemTimeAsFileTime] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!TerminateProcess] [7fef9c756d8] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetCurrentProcess] [7fef9c755c8] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!UnhandledExceptionFilter] [8]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!SetUnhandledExceptionFilter] [1]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!LocalAlloc] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!DuplicateHandle] [7fef9c756d8] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!LocalFree] [7fef9c755a8] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetModuleHandleW] [9]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!SystemTimeToFileTime] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!OpenProcess] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetProcessId] [7fef9c756d8] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!CreateMutexW] [7fef9c75588] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!CreateEventW] [a]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!ReleaseMutex] [32]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!SetEvent] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!ResetEvent] [7fef9c756d8] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!CreateFileMappingW] [7fef9c75568] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!MapViewOfFile] [b]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetFileInformationByHandleEx] [1f4]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!SetFileInformationByHandle] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!WaitForSingleObject] [7fef9c756d8] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[KERNEL32.dll!GetSystemInfo] [7fef9c75550] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[PSAPI.DLL!QueryWorkingSetEx] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\thumbcache.dll[PROPSYS.dll!PropVariantToUInt64] [7fef9c756d8] C:\Windows\system32\thumbcache.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!wcsstr] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!wcschr] [90900000946a25ff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!wcsrchr] [956e25ff90909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!_vsnwprintf] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!memcmp] [90900000955a25ff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!memcpy] [954625ff90909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!memset] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!iswalpha] [90900000953225ff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!_XcptFilter] [951e25ff90909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!malloc] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!_initterm] [90900000950a25ff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!free] [94f625ff90909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!memmove] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!_onexit] [9090000094e225ff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!_lock] [94ce25ff90909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!__dllonexit] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!_unlock] [9090000094ba25ff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[msvcrt.dll!_amsg_exit] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[ntdll.dll!RtlVirtualUnwind] [950625ff90909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[ntdll.dll!RtlLookupFunctionEntry] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[ntdll.dll!RtlCaptureContext] [90900000946a25ff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[ntdll.dll!RtlNtStatusToDosError] [945625ff90909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[ntdll.dll!NtFsControlFile] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[ntdll.dll!NtQueryInformationFile] [90900000944225ff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[ntdll.dll!WinSqmAddToStream] [942e25ff90909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!FindResourceExW] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!SystemTimeToTzSpecificLocalTime] [9090000090d225ff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!TzSpecificLocalTimeToSystemTime] [90ae25ff90909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!FileTimeToSystemTime] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetProcessHeap] [907625ff90909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!HeapFree] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!DisableThreadLibraryCalls] [90900000906225ff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!LocalFree] [904625ff90909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!CompareFileTime] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!lstrlenW] [90900000902a25ff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetFileAttributesW] [901625ff90909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetLastError] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!MulDiv] [90900000900225ff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetFileAttributesExW] [8fee25ff90909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!LocalAlloc] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetVolumePathNameW] [909000008fd225ff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!SystemTimeToFileTime] [8348f3ff90909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!FreeLibrary] [da8b48188b4520ec]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetProcAddress] [41f8e38341c98b4c]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!LoadLibraryExA] [1374d18b4c0400f6]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!DelayLoadFailureHook] [450634d08408b41]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!Sleep] [c86348d1034cd8f7]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!QueryPerformanceCounter] [8b4ac36349d1234c]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetTickCount] [488b10438b481014]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetCurrentThreadId] [341f6084b034808]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetCurrentProcessId] [830341b60f0c740f]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetSystemTimeAsFileTime] [4cc8034c9848f0e0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!TerminateProcess] [c48348c98b49ca33]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetCurrentProcess] [90fff6ff41e95b20]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!UnhandledExceptionFilter] [9090909090909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!SetUnhandledExceptionFilter] [38418b4d28ec8348]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetVersionExW] [81e8d18b49ca8b48]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!FormatMessageW] [1b8ffffff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!MultiByteToWideChar] [909090c328c48348]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetDriveTypeW] [48c48b4890909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!LoadResource] [4810688948085889]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!LockResource] [4120788948187089]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetComputerNameW] [518b4d20ec834854]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetComputerNameExW] [41e08b4df28b4838]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetFileInformationByHandle] [d18b49e98b48028b]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!lstrcmpiW] [8b49ce8b48c00348]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!CreateEventW] [8b4c04c25c8d49f9]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!WaitForSingleObject] [8b44ffffff2ee8c3]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!lstrcmpA] [c38b4104558b441b]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!RegCloseKey] [1ba02e38341]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!LoadLibraryW] [245c8b48d08b0000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!CreateFileW] [8b4838246c8b4830]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!lstrlenA] [48247c8b48402474]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!CloseHandle] [5c4120c48348c28b]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetModuleFileNameW] [90909090909090c3]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!DeactivateActCtx] [909000008e9225ff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!ActivateActCtx] [9090909090909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!ReleaseActCtx] [9090909090909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!CreateActCtxW] [5a4db9c18b48]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[KERNEL32.dll!GetModuleHandleW] [c3c0330374083966]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!SetMenuItemInfoW] [38ec834890909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!GetMenuItemInfoW] [4489486024448b48]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!GetMenuItemCount] [48ffffff45e82024]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!DeleteMenu] [90909090c338c483]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!RedrawWindow] [8b5625ff90909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!SetWindowLongPtrW] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!GetWindowLongPtrW] [909000008d3225ff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!EnableWindow] [8d3625ff90909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!GetFocus] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!MoveWindow] [909000008d4225ff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!MapWindowPoints] [8d3e25ff90909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!GetWindowRect] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!KillTimer] [909000008d3a25ff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!GetSystemMetrics] [8d3625ff90909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!GetClientRect] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!SetTimer] [909000008d3225ff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!PostMessageW] [8d4625ff90909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!GetDlgItem] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!SetWindowPos] [909000008d4225ff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!GetWindowLongW] [8df625ff90909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!SetWindowLongW] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!SetDlgItemTextW] [909000008dfa25ff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!LoadStringA] [8df625ff90909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!InsertMenuItemW] [9090909090900000]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[USER32.dll!LoadStringW] [909000008df225ff]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHCreateDefaultExtractIcon] [9090c3c18b48c3c0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHGetIDListFromObject] [ff5ee8c98b49fff6]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHBindToParent] [f71fe8c124408b0f]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHGetItemFromDataObject] [c03302eb01e083d0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!ShellExecuteExW] [909090c328c48348]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHGetKnownFolderPath] [9090909090909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHCreateShellItemArray] [244c894890909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHBindToObject] [3de858244c8b4860]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHParseDisplayName] [5024448948000002]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHCreateItemFromIDList] [41740050247c8348]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHCreateItemFromParsingName] [382444c748]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHBindToFolderIDListParentEx] [4024448d48302444]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHELL32.dll!SHCreateDefaultContextMenu] [8b4c50244c8b4c20]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!PSGetPropertyDescriptionListFromString] [75000045503981c0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!PSCreateMultiplexPropertyStore] [39660000020bba0c]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!InitPropVariantFromResource] [90c3f3c0940f1851]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!PSCreateMemoryPropertyStore] [9090909090909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!InitVariantFromFileTime] [9090909090909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!PropVariantToStringAlloc] [4cc933453c41634c]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!PropVariantCompareEx] [b70f41c1034cd28b]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!VariantCompare] [4a0658b70f451440]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!VariantToPropVariant] [74db854518004c8d]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!PSFormatForDisplay] [72d23b4c0c518b1e]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!VariantToBuffer] [3b4cc20308418b0a]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[PROPSYS.dll!PSPropertyBag_WriteStr] [8348c1ff410f72d0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!StrDupW] [eb000001e5e8c933]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!SHRegGetValueW] [612e058b48000460]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!PathBuildRootW] [45f9f0589480004]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!StrChrW] [460a005894800]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!StrIsIntlEqualW] [40900045f7605c7]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!StrRetToBufW] [c5058b4800000001]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!SHStrDupW] [682444894800045c]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!SHSkipJunction] [15ffc93370244489]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!StrPBrkW] [ba0000920115ff00]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!StrCmpIW] [ffc88b48c0000409]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!PathRemoveFileSpecW] [9090909090909090]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!PathFindFileNameW] [158249c8b48]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!PathGetDriveNumberW] [894848244c8d4840]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!PathIsUNCW] [50244c8d4830244c]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!PathIsNetworkPathW] [28244c8948c88b4c]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!StrRetToStrW] [480000053824848b]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!PathRemoveBackslashW] [480000053824848d]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\system32\twext.dll[SHLWAPI.dll!PathIsUNCServerW] [15ff00010aca0d8d]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!_amsg_exit] [76e23bd0] C:\Windows\SYSTEM32\ntdll.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!free] [767336c0] C:\Windows\SYSTEM32\kernel32.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!_initterm] [76733620] C:\Windows\SYSTEM32\kernel32.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!malloc] [76e18050] C:\Windows\SYSTEM32\ntdll.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!_XcptFilter] [76e18020] C:\Windows\SYSTEM32\ntdll.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!wcsncmp] [76e154b0] C:\Windows\SYSTEM32\ntdll.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!wcstoul] [76e154e0] C:\Windows\SYSTEM32\ntdll.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!iswctype] [76729b80] C:\Windows\SYSTEM32\kernel32.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!_vsnwprintf] [767a9300] C:\Windows\SYSTEM32\kernel32.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!strtoul] [76725cf0] C:\Windows\SYSTEM32\kernel32.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!isdigit] [7675bca0] C:\Windows\SYSTEM32\kernel32.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[msvcrt.dll!memcpy] [76723f40] C:\Windows\SYSTEM32\kernel32.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ntdll.dll!RtlLookupFunctionEntry] [76723ee0] C:\Windows\SYSTEM32\kernel32.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ntdll.dll!RtlVirtualUnwind] [76e284f0] C:\Windows\SYSTEM32\ntdll.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ntdll.dll!RtlCaptureContext] [76e19c50] C:\Windows\SYSTEM32\ntdll.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[KERNEL32.dll!GetCurrentThreadId] [0]
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[KERNEL32.dll!GetTickCount] [76723f00] C:\Windows\SYSTEM32\kernel32.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[KERNEL32.dll!GetCurrentProcess] [76732d60] C:\Windows\SYSTEM32\kernel32.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[KERNEL32.dll!SetUnhandledExceptionFilter] [76732f10] C:\Windows\SYSTEM32\kernel32.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[KERNEL32.dll!UnhandledExceptionFilter] [7671d9a0] C:\Windows\SYSTEM32\kernel32.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[KERNEL32.dll!DisableThreadLibraryCalls] [76dfc540] C:\Windows\SYSTEM32\ntdll.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[KERNEL32.dll!GetProcessHeap] [76e0e170] C:\Windows\SYSTEM32\ntdll.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[KERNEL32.dll!QueryPerformanceCounter] [76716650] C:\Windows\SYSTEM32\kernel32.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[KERNEL32.dll!Sleep] [76e02330] C:\Windows\SYSTEM32\ntdll.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[KERNEL32.dll!HeapFree] [76e021f0] C:\Windows\SYSTEM32\ntdll.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ADVAPI32.dll!RegEnumKeyExW] [7fefe3c1820] C:\Windows\system32\ADVAPI32.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ADVAPI32.dll!RegQueryValueExW] [7fefe3cb9e0] C:\Windows\system32\ADVAPI32.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ADVAPI32.dll!RegOpenKeyExW] [7fefe3cb9b0] C:\Windows\system32\ADVAPI32.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ADVAPI32.dll!RegQueryMultipleValuesA] [7fefe3bd980] C:\Windows\system32\ADVAPI32.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ADVAPI32.dll!RegCloseKey] [7fefe3bdd34] C:\Windows\system32\ADVAPI32.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ADVAPI32.dll!RegEnumKeyExA] [7fefe3cbd70] C:\Windows\system32\ADVAPI32.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ADVAPI32.dll!RegQueryValueExA] [7fefe3d0710] C:\Windows\system32\ADVAPI32.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ADVAPI32.dll!RegOpenKeyExA] [7fefe3d06f0] C:\Windows\system32\ADVAPI32.dll
IAT C:\Windows\Explorer.EXE[624] @ C:\Windows\System32\osbaseln.dll[ADVAPI32.dll!RegDeleteValueW] [0]
---- EOF - GMER 2.0 ----
|
| | #3 |
| /// Helfer-Team ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Flash Installation infiziert![]() Die Bereinigung besteht aus mehreren Schritten, die ausgefuehrt werden muessen. Diese Nacheinander abarbeiten und die 3 Logs, die dabei erstellt werden bitte in deine naechste Antwort einfuegen. Sollte der OTL-FIX nicht richig durchgelaufen sein. Fahre nicht fort, sondern melde dies bitte. 1. Schritt Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Ersetze die verwendeten Platzhalter wieder in den Benutzernamen zurück! Code:
ATTFilter :OTL
SRV - [2012.11.30 10:24:48 | 000,008,192 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\srvany.exe -- (KMService)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
[2009.08.20 06:17:47 | 000,036,136 | ---- | C] (Oberon Media) -- C:\ProgramData\FullRemove.exe
[2012.11.30 10:25:16 | 000,077,824 | ---- | C] () -- C:\Windows\KMService.exe
[2012.11.30 10:25:16 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\srvany.exe
:Files
C:\ProgramData\*.exe
C:\ProgramData\*.dll
C:\ProgramData\*.tmp
C:\ProgramData\TEMP
C:\Users\MYNAME\*.tmp
C:\Users\MYNAME\AppData\Local\Temp\*.exe
C:\Users\MYNAME\AppData\LocalLow\Sun\Java\Deployment\cache
ipconfig /flushdns /c
:Commands
[emptytemp]
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! 2. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 3. Schritt Downloade Dir bitte
__________________ |
| | #4 |
| /// Helfer-Team ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Flash Installation infiziert Fehlende Rückmeldung Gibt es Probleme beim Abarbeiten obiger Anleitung? Um Kapazitäten für andere Hilfesuchende freizumachen, lösche ich dieses Thema aus meinen Benachrichtigungen. Solltest Du weitermachen wollen, schreibe mir eine PN oder eröffne ein neues Thema. http://www.trojaner-board.de/69886-a...-beachten.html Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner sauber ist. |
![]() |
| Themen zu Flash Installation infiziert |
| anhang, datei, desinfiziert, fehlende, flash, flashplayer, gestern, hoffe, infiziert, install, installation, interne, internet, internet security 2013, kaspersky, kaspersky internet security 2013, länger, malware, plötzlich, popup, scan, scanne, scannen, security, starte, warum, wenig, woran |