Von DDS:DDS Logfile:
DDS Logfile: Code:
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 10.0.9200.16576 BrowserJavaVersion: 10.17.2
Run by Franz at 20:46:53 on 2013-06-06
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8137.6439 [GMT 2:00]
.
AV: Avira Desktop *Enabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Enabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\atieclxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\taskhost.exe
E:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\PROGRA~2\TELEVI~2\bar\1.bin\64barsvc.exe
C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe
C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe
C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe
C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files (x86)\D-Link\DWA-140 revB\AirNCFG.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
E:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
E:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
E:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Windows\System32\svchost.exe -k secsvcs
E:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
E:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\Macromed\Flash\FlashUtil64_11_7_700_169_ActiveX.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.de/
mWinlogon: Userinit = userinit.exe
BHO: PriceGong - Price Comparison: {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files (x86)\PriceGong\2.6.11\PriceGongIE.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Wajam: {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\priam_bho.dll
BHO: Logitech SetPoint: {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: Yontoo: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRun: [Yontoo Desktop] "C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe"
uRun: [Izosmex] C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe
uRun: [Deroeskoh] C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe
mRun: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [D-Link D-Link DWA-140] C:\Program Files (x86)\D-Link\DWA-140 revB\AirNCFG.exe
mRun: [TelevisionFanatic Search Scope Monitor] "C:\PROGRA~2\TELEVI~2\bar\1.bin\64srchmn.exe" /m=2 /w /h
mRun: [iTunesHelper] "E:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [StartCCC] "E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [avgnt] "E:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
StartupFolder: C:\Users\Franz\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - E:\Program Files (x86)\Open Office\program\quickstart.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Bild in &Microsoft PhotoDraw öffnen - E:\PROGRA~2\MICROS~1\Office\1031\phdintl.dll/phdContext.htm
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxp://www.battlefieldheroes.com/static/updater/BFHUpdater_5.0.203.0.cab
TCP: NameServer = 192.168.178.1
TCP: Interfaces\{4615087B-B1A8-4D47-B88F-3A8645CB4A82} : DHCPNameServer = 192.168.178.1
TCP: Interfaces\{4615087B-B1A8-4D47-B88F-3A8645CB4A82}\577756026416568627D60264279647A70224F687022556075616475627 : DHCPNameServer = 192.168.178.1
TCP: Interfaces\{4615087B-B1A8-4D47-B88F-3A8645CB4A82}\64259445A51275C414E402255607561647562702E4F274 : DHCPNameServer = 192.168.178.2
TCP: Interfaces\{F271B764-14C9-4CE7-BD62-0BE98F989DB3} : DHCPNameServer = 192.168.178.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
SSODL: WebCheck - <orphaned>
x64-BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
x64-Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
x64-SSODL: WebCheck - <orphaned>
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Franz\AppData\Roaming\Mozilla\Firefox\Profiles\aa1r13wa.default-1368456930541\
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\NP64Stub.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
FF - plugin: E:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
R0 amd_sata;amd_sata;C:\Windows\System32\drivers\amd_sata.sys [2012-12-25 78976]
R0 amd_xata;amd_xata;C:\Windows\System32\drivers\amd_xata.sys [2012-12-25 38528]
R1 anodlwf;ANOD Network Security Filter driver;C:\Windows\System32\drivers\anodlwfx.sys [2012-12-28 15872]
R1 avkmgr;avkmgr;C:\Windows\System32\drivers\avkmgr.sys [2013-6-6 28600]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-12-19 240640]
R2 AMD FUEL Service;AMD FUEL Service;E:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-3-28 361984]
R2 AntiVirSchedulerService;Avira Planer;E:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2013-6-6 86752]
R2 AntiVirService;Avira Echtzeit-Scanner;E:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2013-6-6 110816]
R2 AODDriver4.2;AODDriver4.2;E:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2012-4-9 57472]
R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgntflt.sys [2013-6-6 100712]
R2 TelevisionFanaticService;TelevisionFanaticService;C:\PROGRA~2\TELEVI~2\bar\1.bin\64barsvc.exe [2013-1-5 42504]
R2 WajamUpdater;WajamUpdater;C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe [2013-4-4 109064]
R2 Yontoo Desktop Updater;Yontoo Desktop Updater;C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe [2013-4-5 23552]
R3 asmthub3;ASMedia USB3 Hub Service;C:\Windows\System32\drivers\asmthub3.sys [2011-9-14 129000]
R3 asmtxhci;ASMEDIA XHCI Service;C:\Windows\System32\drivers\asmtxhci.sys [2011-9-14 394216]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2012-11-6 96256]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;C:\Windows\System32\drivers\LEqdUsb.sys [2012-9-18 78648]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;C:\Windows\System32\drivers\LHidEqd.sys [2012-9-18 15160]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-12-25 565352]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2012-12-25 47232]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-2-28 161384]
S3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys [2012-12-25 46136]
S3 avmeject;AVM Eject;C:\Windows\System32\drivers\avmeject.sys [2010-10-22 14120]
S3 FWLANUSB;AVM FRITZ!WLAN;C:\Windows\System32\drivers\fwlanusb.sys [2010-10-22 460800]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-12-26 19456]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2012-12-26 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2012-12-26 30208]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-9-28 53760]
.
=============== Created Last 30 ================
.
2013-06-06 17:08:22 -------- d-----w- C:\Program Files\CCleaner
2013-06-06 16:44:05 -------- d-sh--w- C:\$$PendingFiles
2013-06-06 16:04:20 -------- d-----w- C:\Users\Franz\AppData\Roaming\Avira
2013-06-06 16:01:49 83160 ----a-w- C:\Windows\System32\drivers\avnetflt.sys
2013-06-06 15:59:07 28600 ----a-w- C:\Windows\System32\drivers\avkmgr.sys
2013-06-06 15:59:07 100712 ----a-w- C:\Windows\System32\drivers\avgntflt.sys
2013-06-06 15:59:06 -------- d-----w- C:\ProgramData\Avira
2013-06-06 15:49:53 9460464 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{FC62DBE2-2544-430E-86EE-DF0EA2E5112F}\mpengine.dll
2013-06-06 14:20:20 -------- d-----w- C:\AMD
2013-06-02 10:56:07 14848 ----a-w- C:\Windows\System32\Spool\prtprocs\x64\MIMFPR0H.DLL
2013-06-02 10:55:49 -------- d-----w- C:\Program Files\KONICA MINOLTA
2013-05-15 14:14:59 -------- d-----w- C:\Users\Franz\AppData\Roaming\Upic
2013-05-15 14:14:59 -------- d-----w- C:\Users\Franz\AppData\Roaming\Ihloat
2013-05-15 14:14:59 -------- d-----w- C:\Users\Franz\AppData\Roaming\Anotod
2013-05-13 14:49:37 -------- d-----w- C:\Users\Franz\AppData\Roaming\Ypbaow
2013-05-13 14:49:37 -------- d-----w- C:\Users\Franz\AppData\Roaming\Utig
2013-05-13 14:49:37 -------- d-----w- C:\Users\Franz\AppData\Roaming\Egheed
2013-05-11 16:32:05 971680 ----a-w- C:\Windows\System32\deployJava1.dll
2013-05-11 16:32:05 1092512 ----a-w- C:\Windows\System32\npDeployJava1.dll
2013-05-11 16:32:03 108448 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2013-05-07 19:55:13 283032 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2013-05-07 19:55:10 -------- d-----w- C:\Users\Franz\AppData\Local\PunkBuster
2013-05-07 19:55:10 -------- d-----w- C:\Users\Franz\AppData\Local\Chromium
2013-05-07 19:28:11 519000 ----a-w- C:\Windows\System32\d3dx10_40.dll
2013-05-07 19:28:11 452440 ----a-w- C:\Windows\SysWow64\d3dx10_40.dll
2013-05-07 19:28:11 2605920 ----a-w- C:\Windows\System32\D3DCompiler_40.dll
2013-05-07 19:28:11 2036576 ----a-w- C:\Windows\SysWow64\D3DCompiler_40.dll
2013-05-07 19:28:10 5631312 ----a-w- C:\Windows\System32\D3DX9_40.dll
2013-05-07 19:28:10 4379984 ----a-w- C:\Windows\SysWow64\D3DX9_40.dll
2013-05-07 19:25:39 -------- d-----w- C:\Program Files (x86)\NVIDIA Corporation
2013-05-07 19:25:33 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2013-05-07 19:25:00 283032 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2013-05-07 19:25:00 283032 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2013-05-07 19:24:59 76888 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2013-05-07 19:24:58 3130440 ----a-w- C:\Windows\SysWow64\pbsvc_blr.exe
.
==================== Find3M ====================
.
2013-05-13 15:03:52 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-05-13 15:03:52 691592 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-05-02 00:06:08 278800 ------w- C:\Windows\System32\MpSigStub.exe
2013-04-13 05:49:23 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2013-04-13 05:49:19 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2013-04-13 05:49:19 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2013-04-13 05:49:19 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
2013-04-13 04:45:16 474624 ----a-w- C:\Windows\apppatch\AcSpecfc.dll
2013-04-13 04:45:15 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll
2013-04-12 14:45:08 1656680 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2013-04-10 06:01:54 265064 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys
2013-04-10 06:01:53 983400 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2013-04-10 03:30:50 3153920 ----a-w- C:\Windows\System32\win32k.sys
2013-04-05 06:52:14 2242048 ----a-w- C:\Windows\System32\wininet.dll
2013-04-05 06:50:36 3958784 ----a-w- C:\Windows\System32\jscript9.dll
2013-04-05 06:50:31 67072 ----a-w- C:\Windows\System32\iesetup.dll
2013-04-05 06:50:31 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2013-04-05 05:28:24 1767424 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-04-05 05:26:26 2877440 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-04-05 05:26:21 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2013-04-05 05:26:21 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2013-04-05 04:43:00 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2013-04-05 04:29:45 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-04-05 03:51:11 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-04-05 03:38:25 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-03-19 06:04:06 5550424 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-03-19 05:53:58 48640 ----a-w- C:\Windows\System32\wwanprotdim.dll
2013-03-19 05:53:58 230400 ----a-w- C:\Windows\System32\wwansvc.dll
2013-03-19 05:46:56 43520 ----a-w- C:\Windows\System32\csrsrv.dll
2013-03-19 05:04:13 3968856 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-03-19 05:04:10 3913560 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-03-19 04:47:50 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll
2013-03-19 03:06:33 112640 ----a-w- C:\Windows\System32\smss.exe
2013-03-08 19:42:49 95648 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-03-08 19:42:48 861088 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-03-08 19:42:48 782240 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2006-05-03 09:06:54 163328 --sha-r- C:\Windows\SysWOW64\flvDX.dll
2007-02-21 10:47:16 31232 --sha-r- C:\Windows\SysWOW64\msfDX.dll
2008-03-16 12:30:52 216064 --sha-r- C:\Windows\SysWOW64\nbDX.dll
2010-01-06 22:00:00 107520 --sha-r- C:\Windows\SysWOW64\TAKDSDecoder.dll
.
============= FINISH: 20:47:00.81 =============== [/CODE]
--- --- ---
--- --- ---
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 24.12.2012 22:21:03
System Uptime: 06.06.2013 17:46:18 (3 hours ago)
.
Motherboard: ASUSTeK COMPUTER INC. | | M5A99X EVO
Processor: AMD FX(tm)-4100 Quad-Core Processor | AM3r2 | 3600/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 60 GiB total, 23.246 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 466 GiB total, 352.75 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Description: AODDriver4.01
Device ID: ROOT\LEGACY_AODDRIVER4.01\0000
Manufacturer:
Name: AODDriver4.01
PNP Device ID: ROOT\LEGACY_AODDRIVER4.01\0000
Service: AODDriver4.01
.
==== System Restore Points ===================
.
RP91: 06.06.2013 17:49:47 - Windows Update
.
==== Installed Programs ======================
.
7-Zip 9.20 (x64 edition)
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader XI (11.0.03) - Deutsch
AMD Accelerated Video Transcoding
AMD APP SDK Runtime
AMD Catalyst Install Manager
AMD Drag and Drop Transcoding
AMD Fuel
AMD Media Foundation Decoders
AMD VISION Engine Control Center
AnotherLife Client Version 1.0.1
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Asmedia ASM104x USB 3.0 Host Controller Driver
aTube Catcher
Audacity 2.0.3
Avira Free Antivirus
Battlefield Heroes
Blacklight Retribution
Bonjour
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-utility64
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
CCleaner
CPUID HWMonitor 1.21
D-Link DWA-140
DVD Flick 1.3.0.7
eReg
Euro Truck Simulator 1.00
Free Video to DVD Converter version 5.0.22.128
FreeRIP 3.92
Funkyplot 1.1.0-pre1
GeoGebra 4.2
Grand Theft Auto San Andreas
IrfanView (remove only)
iTunes
Java 7 Update 17
Java 7 Update 21 (64-bit)
Java Auto Updater
Java SE Development Kit 7 Update 21 (64-bit)
JMicron JMB36X Driver
KONICA MINOLTA magicolor 1600W
Logitech SetPoint 6.51
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Client Profile DEU Language Pack
Microsoft .NET Framework 4 Extended
Microsoft .NET Framework 4 Extended DEU Language Pack
Microsoft Office 2000 SR-1 Disc 2
Microsoft PhotoDraw 2000 V2
Microsoft Silverlight
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Mozilla Firefox 21.0 (x86 de)
Nero 7 Essentials
Nightly 23.0a1 (x64 en-US)
NVIDIA PhysX
OpenOffice.org 3.4.1
PriceGong 2.6.11
PunkBuster Services
Qtrax Player
Realtek Ethernet Controller Driver
Realtek High Definition Audio Driver
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2736428)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Skype™ 6.3
SUPER © v2012.build.54 (Nov 18, 2012) Version v2012.build.54
Synthesia
TeamSpeak 3 Client
TelevisionFanatic Toolbar
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Microsoft .NET Framework 4 Extended (KB2468871)
Update for Microsoft .NET Framework 4 Extended (KB2533523)
Update for Microsoft .NET Framework 4 Extended (KB2600217)
Update for Video Converter
Video Converter Packages
VirtualDJ Home FREE
VLC media player 2.0.5
Wajam
World of Tanks
XMedia Recode Version 3.1.4.8
Yontoo 2.051
.
==== End Of File ===========================
Defogger:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 20:47 on 06/06/2013 (Franz)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-
Von Gmer:
GMER Logfile: Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-06-06 20:56:31
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\00000065 SAMSUNG_ rev.CXM0 59.63GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\Franz\AppData\Local\Temp\pgloypog.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 560 fffff80002fa4000 45 bytes [00, 00, 00, 00, 00, 00, 00, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 607 fffff80002fa402f 16 bytes [00, 00, 00, 00, 00, 00, 00, ...]
---- User code sections - GMER 2.1 ----
.text C:\Windows\SysWOW64\PnkBstrA.exe[1792] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 0000000073cf1a22 2 bytes [CF, 73]
.text C:\Windows\SysWOW64\PnkBstrA.exe[1792] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 0000000073cf1ad0 2 bytes [CF, 73]
.text C:\Windows\SysWOW64\PnkBstrA.exe[1792] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 0000000073cf1b08 2 bytes [CF, 73]
.text C:\Windows\SysWOW64\PnkBstrA.exe[1792] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 0000000073cf1bba 2 bytes [CF, 73]
.text C:\Windows\SysWOW64\PnkBstrA.exe[1792] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 0000000073cf1bda 2 bytes [CF, 73]
.text C:\Windows\SysWOW64\PnkBstrA.exe[1792] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000759b1465 2 bytes [9B, 75]
.text C:\Windows\SysWOW64\PnkBstrA.exe[1792] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000759b14bb 2 bytes [9B, 75]
.text ... * 2
.text C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe[2012] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 00000000759b1465 2 bytes [9B, 75]
.text C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe[2012] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 00000000759b14bb 2 bytes [9B, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 0000000077dc25fd 6 bytes [68, 04, 69, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077dd2a63 6 bytes [68, 4A, 69, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077df4128 6 bytes [68, 90, 69, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 0000000077dfe659 6 bytes [68, D6, 69, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!GetDC 00000000759d72c4 6 bytes [68, 84, F9, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000759d7446 6 bytes [68, 02, FA, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000759d7809 6 bytes [68, 1D, A4, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000759d78e2 6 bytes [68, 2E, 00, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000759d7bd3 6 bytes [68, 56, 00, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000759d8048 6 bytes [68, C3, F9, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000759d8a65 6 bytes [68, 08, 6C, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000759db17d 6 bytes [68, A2, 6C, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000759ddb98 6 bytes [68, F4, 6C, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000759e05ba 6 bytes [68, 7E, 00, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!CallWindowProcW 00000000759e0d32 6 bytes [68, 3A, 6B, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!GetCursorPos 00000000759e1218 6 bytes [68, 61, FE, D6, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!EndPaint 00000000759e1341 6 bytes [68, E9, F8, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!BeginPaint 00000000759e1361 6 bytes [68, 79, F8, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!GetMessagePos 00000000759e2a8d 6 bytes [68, 2F, FE, D6, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!GetCapture 00000000759e2aac 6 bytes [68, 8F, FF, D6, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!GetDCEx 00000000759e3391 6 bytes [68, 29, F9, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!RegisterClassA 00000000759e434b 6 bytes [68, 55, 6C, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!PeekMessageA 00000000759e5f74 6 bytes [68, A9, 00, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 00000000759e6222 6 bytes [68, D5, FA, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!CallWindowProcA 00000000759e792f 6 bytes [68, 83, 6B, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!DefFrameProcA 00000000759e7fbb 6 bytes [68, 65, 6A, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000759e810c 6 bytes [68, F4, 6A, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000759e85c1 6 bytes [68, 1C, 6A, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000759e86b4 6 bytes [68, AE, 6A, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!GetUpdateRect 00000000759fd41f 6 bytes [68, 42, FA, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!ReleaseCapture 00000000759fed49 6 bytes [68, 3F, FF, D6, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!SetCapture 00000000759fed56 6 bytes [68, E5, FE, D6, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000075a19854 6 bytes [68, E6, 68, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000075a19cfd 6 bytes [68, A8, FE, D6, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000075a19f1d 6 bytes [68, CC, A5, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 0000000075a387cb 6 bytes [68, 96, 68, D7, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000076e53918 6 bytes [68, 7B, F5, D6, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000076e54296 6 bytes [68, 8C, F1, D6, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000076e54406 6 bytes [68, D4, F5, D6, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\WS2_32.dll!send 0000000076e56f01 6 bytes [68, B3, F5, D6, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000076e67673 6 bytes [68, 1C, F1, D6, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000077423cc2 6 bytes [68, 36, 19, D8, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000077426ab7 6 bytes [68, D6, 1A, D8, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 00000000774276e6 6 bytes [68, BC, 16, D8, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000077427e1d 6 bytes [68, 34, 16, D8, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 000000007747a1ad 6 bytes [68, AA, 1A, D8, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\WININET.dll!InternetReadFile 000000007747a5ef 6 bytes [68, A3, 19, D8, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000077481aa2 6 bytes [68, D1, 19, D8, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 000000007748a74d 6 bytes [68, 66, 17, D8, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 000000007748ad40 6 bytes [68, A0, 18, D8, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 00000000774aad1d 6 bytes [68, 50, 1A, D8, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 00000000774f56ed 6 bytes [68, EB, 18, D8, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 00000000774f57a6 6 bytes [68, 03, 18, D8, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 00000000774f5876 6 bytes [68, 11, 17, D8, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000774f5b15 6 bytes [68, 78, 16, D8, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe[2504] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 00000000776d1224 6 bytes [68, 51, 1D, D8, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 0000000077db08fc 6 bytes [68, A0, CF, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 0000000077dc25fd 6 bytes [68, BD, 57, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077dcc45a 6 bytes [68, CB, D0, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077dd2a63 6 bytes [68, 03, 58, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077df4128 6 bytes [68, 49, 58, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 0000000077dfe659 6 bytes [68, 8F, 58, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\KERNEL32.dll!GetFileAttributesExW 0000000076d5455c 6 bytes [68, 34, D3, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\KERNEL32.dll!ExitProcess 0000000076d579f8 6 bytes [68, F3, D2, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 00000000778fc592 6 bytes [68, B1, D3, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000077932538 6 bytes [68, 9A, D3, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!GetDC 00000000759d72c4 6 bytes [68, 92, 18, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000759d7446 6 bytes [68, 10, 19, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000759d7809 6 bytes [68, A5, 5D, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000759d78e2 6 bytes [68, 22, DE, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000759d7bd3 6 bytes [68, 4A, DE, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000759d8048 6 bytes [68, D1, 18, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000759d8a65 6 bytes [68, C1, 5A, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000759db17d 6 bytes [68, 5B, 5B, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000759ddb98 6 bytes [68, AD, 5B, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000759e05ba 6 bytes [68, 72, DE, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!CallWindowProcW 00000000759e0d32 6 bytes [68, F3, 59, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!GetCursorPos 00000000759e1218 6 bytes [68, 55, DC, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!EndPaint 00000000759e1341 6 bytes [68, F7, 17, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!BeginPaint 00000000759e1361 6 bytes [68, 87, 17, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!GetMessagePos 00000000759e2a8d 6 bytes [68, 23, DC, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!GetCapture 00000000759e2aac 6 bytes [68, 83, DD, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!GetDCEx 00000000759e3391 6 bytes [68, 37, 18, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!RegisterClassA 00000000759e434b 6 bytes [68, 0E, 5B, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!PeekMessageA 00000000759e5f74 6 bytes [68, 9D, DE, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 00000000759e6222 6 bytes [68, E3, 19, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!CallWindowProcA 00000000759e792f 6 bytes [68, 3C, 5A, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!DefFrameProcA 00000000759e7fbb 6 bytes [68, 1E, 59, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000759e810c 6 bytes [68, AD, 59, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000759e85c1 6 bytes [68, D5, 58, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000759e86b4 6 bytes [68, 67, 59, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!GetUpdateRect 00000000759fd41f 6 bytes [68, 50, 19, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!ReleaseCapture 00000000759fed49 6 bytes [68, 33, DD, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!SetCapture 00000000759fed56 6 bytes [68, D9, DC, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000075a19854 6 bytes [68, 9F, 57, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000075a19cfd 6 bytes [68, 9C, DC, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000075a19f1d 6 bytes [68, 54, 5F, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 0000000075a387cb 6 bytes [68, 4F, 57, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 00000000776d1224 6 bytes [68, 89, 7E, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000076e53918 6 bytes [68, 27, E3, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000076e54296 6 bytes [68, 38, DF, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000076e54406 6 bytes [68, 80, E3, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\WS2_32.dll!send 0000000076e56f01 6 bytes [68, 5F, E3, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000076e67673 6 bytes [68, C8, DE, 31, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000077423cc2 6 bytes [68, DC, 08, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000077426ab7 6 bytes [68, 7C, 0A, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 00000000774276e6 6 bytes [68, 62, 06, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000077427e1d 6 bytes [68, DA, 05, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 000000007747a1ad 6 bytes [68, 50, 0A, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\WININET.dll!InternetReadFile 000000007747a5ef 6 bytes [68, 49, 09, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000077481aa2 6 bytes [68, 77, 09, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 000000007748a74d 6 bytes [68, 0C, 07, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 000000007748ad40 6 bytes [68, 46, 08, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 00000000774aad1d 6 bytes [68, F6, 09, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 00000000774f56ed 6 bytes [68, 91, 08, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 00000000774f57a6 6 bytes [68, A9, 07, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 00000000774f5876 6 bytes [68, B7, 06, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Yontoo\YontooDesktop.exe[2584] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000774f5b15 6 bytes [68, 1E, 06, 32, 05, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 0000000077db08fc 4 bytes [68, A0, CF, 4F]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 0000000077db0901 1 byte [C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 0000000077dc25fd 6 bytes [68, BD, 57, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077dcc45a 6 bytes [68, CB, D0, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077dd2a63 6 bytes [68, 03, 58, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077df4128 6 bytes [68, 49, 58, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 0000000077dfe659 6 bytes [68, 8F, 58, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 0000000076d5455c 6 bytes [68, 34, D3, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\kernel32.dll!ExitProcess 0000000076d579f8 6 bytes [68, F3, D2, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!GetDC 00000000759d72c4 4 bytes [68, 92, 18, 4F]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!GetDC + 5 00000000759d72c9 1 byte [C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000759d7446 6 bytes [68, 10, 19, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000759d7809 6 bytes [68, A5, 5D, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000759d78e2 6 bytes [68, 22, DE, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000759d7bd3 6 bytes [68, 4A, DE, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000759d8048 4 bytes [68, D1, 18, 4F]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 00000000759d804d 1 byte [C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000759d8a65 6 bytes [68, C1, 5A, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000759db17d 6 bytes [68, 5B, 5B, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000759ddb98 6 bytes [68, AD, 5B, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000759e05ba 6 bytes [68, 72, DE, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!CallWindowProcW 00000000759e0d32 6 bytes [68, F3, 59, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!GetCursorPos 00000000759e1218 6 bytes [68, 55, DC, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!EndPaint 00000000759e1341 4 bytes [68, F7, 17, 4F]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!EndPaint + 5 00000000759e1346 1 byte [C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!BeginPaint 00000000759e1361 4 bytes [68, 87, 17, 4F]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 00000000759e1366 1 byte [C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!GetMessagePos 00000000759e2a8d 6 bytes [68, 23, DC, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!GetCapture 00000000759e2aac 6 bytes [68, 83, DD, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!GetDCEx 00000000759e3391 4 bytes [68, 37, 18, 4F]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 00000000759e3396 1 byte [C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!RegisterClassA 00000000759e434b 6 bytes [68, 0E, 5B, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!PeekMessageA 00000000759e5f74 6 bytes [68, 9D, DE, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 00000000759e6222 6 bytes [68, E3, 19, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!CallWindowProcA 00000000759e792f 6 bytes [68, 3C, 5A, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!DefFrameProcA 00000000759e7fbb 6 bytes [68, 1E, 59, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000759e810c 6 bytes [68, AD, 59, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000759e85c1 6 bytes [68, D5, 58, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000759e86b4 6 bytes [68, 67, 59, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!GetUpdateRect 00000000759fd41f 6 bytes [68, 50, 19, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!ReleaseCapture 00000000759fed49 6 bytes [68, 33, DD, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!SetCapture 00000000759fed56 4 bytes [68, D9, DC, 4F]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!SetCapture + 5 00000000759fed5b 1 byte [C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000075a19854 6 bytes [68, 9F, 57, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000075a19cfd 6 bytes [68, 9C, DC, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000075a19f1d 6 bytes [68, 54, 5F, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 0000000075a387cb 4 bytes [68, 4F, 57, 50]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 0000000075a387d0 1 byte [C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 00000000778fc592 6 bytes [68, B1, D3, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000077932538 6 bytes [68, 9A, D3, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000076e53918 6 bytes [68, 27, E3, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000076e54296 6 bytes [68, 38, DF, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000076e54406 6 bytes [68, 80, E3, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\WS2_32.dll!send 0000000076e56f01 6 bytes [68, 5F, E3, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000076e67673 6 bytes [68, C8, DE, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 00000000776d1224 6 bytes [68, 89, 7E, 4F, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000077423cc2 6 bytes [68, DC, 08, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000077426ab7 6 bytes [68, 7C, 0A, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 00000000774276e6 6 bytes [68, 62, 06, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000077427e1d 6 bytes [68, DA, 05, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 000000007747a1ad 6 bytes [68, 50, 0A, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\WININET.dll!InternetReadFile 000000007747a5ef 6 bytes [68, 49, 09, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000077481aa2 6 bytes [68, 77, 09, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 000000007748a74d 6 bytes [68, 0C, 07, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 000000007748ad40 6 bytes [68, 46, 08, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 00000000774aad1d 6 bytes [68, F6, 09, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 00000000774f56ed 6 bytes [68, 91, 08, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 00000000774f57a6 6 bytes [68, A9, 07, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 00000000774f5876 6 bytes [68, B7, 06, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Ypbaow\oqmua.exe[2608] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000774f5b15 6 bytes [68, 1E, 06, 50, 00, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 0000000077db08fc 6 bytes [68, BC, 38, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 0000000077dc25fd 6 bytes [68, 04, 69, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077dcc45a 6 bytes [68, E1, 39, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077dd2a63 6 bytes [68, 4A, 69, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077df4128 6 bytes [68, 90, 69, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 0000000077dfe659 6 bytes [68, D6, 69, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 0000000076d5455c 6 bytes [68, 4A, 3C, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\kernel32.dll!ExitProcess 0000000076d579f8 6 bytes [68, 09, 3C, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!GetDC 00000000759d72c4 6 bytes [68, 84, F9, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000759d7446 6 bytes [68, 02, FA, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000759d7809 6 bytes [68, 1D, A4, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000759d78e2 6 bytes [68, 2E, 00, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000759d7bd3 6 bytes [68, 56, 00, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000759d8048 6 bytes [68, C3, F9, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000759d8a65 6 bytes [68, 08, 6C, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000759db17d 6 bytes [68, A2, 6C, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000759ddb98 6 bytes [68, F4, 6C, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000759e05ba 6 bytes [68, 7E, 00, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!CallWindowProcW 00000000759e0d32 6 bytes [68, 3A, 6B, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!GetCursorPos 00000000759e1218 6 bytes [68, 61, FE, D2, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!EndPaint 00000000759e1341 6 bytes [68, E9, F8, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!BeginPaint 00000000759e1361 6 bytes [68, 79, F8, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!GetMessagePos 00000000759e2a8d 6 bytes [68, 2F, FE, D2, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!GetCapture 00000000759e2aac 6 bytes [68, 8F, FF, D2, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!GetDCEx 00000000759e3391 6 bytes [68, 29, F9, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!RegisterClassA 00000000759e434b 6 bytes [68, 55, 6C, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!PeekMessageA 00000000759e5f74 6 bytes [68, A9, 00, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 00000000759e6222 6 bytes [68, D5, FA, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!CallWindowProcA 00000000759e792f 6 bytes [68, 83, 6B, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!DefFrameProcA 00000000759e7fbb 6 bytes [68, 65, 6A, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000759e810c 6 bytes [68, F4, 6A, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000759e85c1 6 bytes [68, 1C, 6A, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000759e86b4 6 bytes [68, AE, 6A, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!GetUpdateRect 00000000759fd41f 6 bytes [68, 42, FA, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!ReleaseCapture 00000000759fed49 6 bytes [68, 3F, FF, D2, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!SetCapture 00000000759fed56 6 bytes [68, E5, FE, D2, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000075a19854 6 bytes [68, E6, 68, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000075a19cfd 6 bytes [68, A8, FE, D2, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000075a19f1d 6 bytes [68, CC, A5, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 0000000075a387cb 6 bytes [68, 96, 68, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 00000000778fc592 6 bytes [68, C7, 3C, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000077932538 6 bytes [68, B0, 3C, D3, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000076e53918 6 bytes [68, 7B, F5, D2, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000076e54296 6 bytes [68, 8C, F1, D2, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000076e54406 6 bytes [68, D4, F5, D2, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\WS2_32.dll!send 0000000076e56f01 6 bytes [68, B3, F5, D2, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000076e67673 6 bytes [68, 1C, F1, D2, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 00000000776d1224 6 bytes [68, 51, 1D, D4, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000077423cc2 6 bytes [68, 36, 19, D4, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000077426ab7 6 bytes [68, D6, 1A, D4, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 00000000774276e6 6 bytes [68, BC, 16, D4, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000077427e1d 6 bytes [68, 34, 16, D4, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 000000007747a1ad 6 bytes [68, AA, 1A, D4, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\WININET.dll!InternetReadFile 000000007747a5ef 6 bytes [68, A3, 19, D4, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000077481aa2 6 bytes [68, D1, 19, D4, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 000000007748a74d 6 bytes [68, 66, 17, D4, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 000000007748ad40 6 bytes [68, A0, 18, D4, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 00000000774aad1d 6 bytes [68, 50, 1A, D4, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 00000000774f56ed 6 bytes [68, EB, 18, D4, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 00000000774f57a6 6 bytes [68, 03, 18, D4, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 00000000774f5876 6 bytes [68, 11, 17, D4, 01, C3]
.text C:\Users\Franz\AppData\Roaming\Upic\ysiwy.exe[2640] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000774f5b15 6 bytes [68, 78, 16, D4, 01, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 0000000077db08fc 6 bytes {ADD [RAX-0x60], CH; IRET ; JMP 0x9}
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 0000000077dc25fd 6 bytes [68, BD, 57, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077dcc45a 6 bytes [68, CB, D0, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077dd2a63 6 bytes [68, 03, 58, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077df4128 6 bytes [68, 49, 58, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 0000000077dfe659 6 bytes [68, 8F, 58, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 0000000076d5455c 6 bytes [68, 34, D3, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\kernel32.dll!ExitProcess 0000000076d579f8 6 bytes [68, F3, D2, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!GetDC 00000000759d72c4 6 bytes [68, 92, 18, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000759d7446 6 bytes [68, 10, 19, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000759d7809 6 bytes [68, A5, 5D, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000759d78e2 6 bytes [68, 22, DE, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000759d7bd3 6 bytes [68, 4A, DE, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000759d8048 6 bytes [68, D1, 18, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000759d8a65 6 bytes [68, C1, 5A, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000759db17d 6 bytes [68, 5B, 5B, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000759ddb98 6 bytes [68, AD, 5B, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000759e05ba 6 bytes [68, 72, DE, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!CallWindowProcW 00000000759e0d32 6 bytes [68, F3, 59, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!GetCursorPos 00000000759e1218 6 bytes [68, 55, DC, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!EndPaint 00000000759e1341 6 bytes [68, F7, 17, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!BeginPaint 00000000759e1361 6 bytes [68, 87, 17, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!GetMessagePos 00000000759e2a8d 6 bytes [68, 23, DC, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!GetCapture 00000000759e2aac 6 bytes [68, 83, DD, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!GetDCEx 00000000759e3391 6 bytes [68, 37, 18, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!RegisterClassA 00000000759e434b 6 bytes [68, 0E, 5B, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!PeekMessageA 00000000759e5f74 6 bytes [68, 9D, DE, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 00000000759e6222 6 bytes [68, E3, 19, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!CallWindowProcA 00000000759e792f 6 bytes [68, 3C, 5A, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!DefFrameProcA 00000000759e7fbb 6 bytes [68, 1E, 59, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000759e810c 6 bytes [68, AD, 59, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000759e85c1 6 bytes [68, D5, 58, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000759e86b4 6 bytes [68, 67, 59, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!GetUpdateRect 00000000759fd41f 6 bytes [68, 50, 19, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!ReleaseCapture 00000000759fed49 6 bytes [68, 33, DD, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!SetCapture 00000000759fed56 6 bytes [68, D9, DC, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000075a19854 6 bytes [68, 9F, 57, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000075a19cfd 6 bytes [68, 9C, DC, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000075a19f1d 6 bytes [68, 54, 5F, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 0000000075a387cb 6 bytes [68, 4F, 57, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 00000000778fc592 6 bytes [68, B1, D3, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000077932538 6 bytes [68, 9A, D3, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000076e53918 6 bytes [68, 27, E3, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000076e54296 6 bytes [68, 38, DF, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000076e54406 6 bytes [68, 80, E3, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\WS2_32.dll!send 0000000076e56f01 6 bytes [68, 5F, E3, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000076e67673 6 bytes [68, C8, DE, EB, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000077423cc2 6 bytes [68, DC, 08, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000077426ab7 6 bytes [68, 7C, 0A, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 00000000774276e6 6 bytes [68, 62, 06, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000077427e1d 6 bytes [68, DA, 05, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 000000007747a1ad 6 bytes [68, 50, 0A, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\WININET.dll!InternetReadFile 000000007747a5ef 6 bytes [68, 49, 09, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000077481aa2 6 bytes [68, 77, 09, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 000000007748a74d 6 bytes [68, 0C, 07, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 000000007748ad40 6 bytes [68, 46, 08, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 00000000774aad1d 6 bytes [68, F6, 09, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 00000000774f56ed 6 bytes [68, 91, 08, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 00000000774f57a6 6 bytes [68, A9, 07, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 00000000774f5876 6 bytes [68, B7, 06, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000774f5b15 6 bytes [68, 1E, 06, EC, 03, C3]
.text C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[2896] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 00000000776d1224 6 bytes [68, 89, 7E, EB, 03, C3]
.text C:\Program Files (x86)\D-Link\DWA-140 revB\AirNCFG.exe[3000] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 0000000076d5455c 6 bytes [68, 34, D3, FB, 01, C3]
.text C:\Program Files (x86)\D-Link\DWA-140 revB\AirNCFG.exe[3000] C:\Windows\syswow64\kernel32.dll!ExitProcess 0000000076d579f8 6 bytes [68, F3, D2, FB, 01, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 0000000077db08fc 6 bytes [68, A0, CF, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 0000000077dc25fd 6 bytes [68, BD, 57, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077dcc45a 6 bytes [68, CB, D0, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077dd2a63 6 bytes [68, 03, 58, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077df4128 6 bytes [68, 49, 58, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 0000000077dfe659 6 bytes [68, 8F, 58, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 0000000076d5455c 6 bytes [68, 34, D3, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\kernel32.dll!ExitProcess 0000000076d579f8 6 bytes [68, F3, D2, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 00000000778fc592 6 bytes [68, B1, D3, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000077932538 6 bytes [68, 9A, D3, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!GetDC 00000000759d72c4 6 bytes [68, 92, 18, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000759d7446 6 bytes [68, 10, 19, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000759d7809 6 bytes [68, A5, 5D, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000759d78e2 6 bytes [68, 22, DE, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000759d7bd3 6 bytes [68, 4A, DE, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000759d8048 6 bytes [68, D1, 18, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000759d8a65 6 bytes [68, C1, 5A, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000759db17d 6 bytes [68, 5B, 5B, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000759ddb98 6 bytes [68, AD, 5B, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000759e05ba 6 bytes [68, 72, DE, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!CallWindowProcW 00000000759e0d32 6 bytes [68, F3, 59, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!GetCursorPos 00000000759e1218 6 bytes [68, 55, DC, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!EndPaint 00000000759e1341 6 bytes [68, F7, 17, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!BeginPaint 00000000759e1361 6 bytes [68, 87, 17, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!GetMessagePos 00000000759e2a8d 6 bytes [68, 23, DC, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!GetCapture 00000000759e2aac 6 bytes [68, 83, DD, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!GetDCEx 00000000759e3391 6 bytes [68, 37, 18, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!RegisterClassA 00000000759e434b 6 bytes [68, 0E, 5B, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!PeekMessageA 00000000759e5f74 6 bytes [68, 9D, DE, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 00000000759e6222 6 bytes [68, E3, 19, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!CallWindowProcA 00000000759e792f 6 bytes [68, 3C, 5A, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!DefFrameProcA 00000000759e7fbb 6 bytes [68, 1E, 59, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000759e810c 6 bytes [68, AD, 59, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000759e85c1 6 bytes [68, D5, 58, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000759e86b4 6 bytes [68, 67, 59, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!GetUpdateRect 00000000759fd41f 6 bytes [68, 50, 19, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!ReleaseCapture 00000000759fed49 6 bytes [68, 33, DD, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!SetCapture 00000000759fed56 6 bytes [68, D9, DC, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000075a19854 6 bytes [68, 9F, 57, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000075a19cfd 6 bytes [68, 9C, DC, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000075a19f1d 6 bytes [68, 54, 5F, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 0000000075a387cb 6 bytes [68, 4F, 57, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000076e53918 6 bytes [68, 27, E3, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000076e54296 6 bytes [68, 38, DF, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000076e54406 6 bytes [68, 80, E3, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\WS2_32.dll!send 0000000076e56f01 6 bytes [68, 5F, E3, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000076e67673 6 bytes [68, C8, DE, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 00000000776d1224 6 bytes [68, 89, 7E, B3, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000077423cc2 6 bytes [68, DC, 08, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000077426ab7 6 bytes [68, 7C, 0A, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 00000000774276e6 6 bytes [68, 62, 06, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000077427e1d 6 bytes [68, DA, 05, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 000000007747a1ad 6 bytes [68, 50, 0A, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\WININET.dll!InternetReadFile 000000007747a5ef 6 bytes [68, 49, 09, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000077481aa2 6 bytes [68, 77, 09, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 000000007748a74d 6 bytes [68, 0C, 07, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 000000007748ad40 6 bytes [68, 46, 08, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 00000000774aad1d 6 bytes [68, F6, 09, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 00000000774f56ed 6 bytes [68, 91, 08, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 00000000774f57a6 6 bytes [68, A9, 07, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 00000000774f5876 6 bytes [68, B7, 06, B4, 02, C3]
.text E:\Program Files (x86)\iTunes\iTunesHelper.exe[3308] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000774f5b15 6 bytes [68, 1E, 06, B4, 02, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 0000000077db08fc 4 bytes [68, A0, CF, 1E]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 0000000077db0901 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 0000000077dc25fd 6 bytes [68, BD, 57, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000077dcc45a 6 bytes [68, CB, D0, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077dd2a63 6 bytes [68, 03, 58, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077df4128 6 bytes [68, 49, 58, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 0000000077dfe659 6 bytes [68, 8F, 58, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 0000000076d5455c 6 bytes [68, 34, D3, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\kernel32.dll!ExitProcess 0000000076d579f8 6 bytes [68, F3, D2, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 00000000778fc592 6 bytes [68, B1, D3, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000077932538 6 bytes [68, 9A, D3, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!GetDC 00000000759d72c4 4 bytes [68, 92, 18, 1E]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!GetDC + 5 00000000759d72c9 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000759d7446 6 bytes [68, 10, 19, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000759d7809 6 bytes [68, A5, 5D, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000759d78e2 6 bytes [68, 22, DE, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000759d7bd3 6 bytes [68, 4A, DE, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000759d8048 4 bytes [68, D1, 18, 1E]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 00000000759d804d 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000759d8a65 6 bytes [68, C1, 5A, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000759db17d 6 bytes [68, 5B, 5B, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000759ddb98 6 bytes [68, AD, 5B, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000759e05ba 6 bytes [68, 72, DE, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!CallWindowProcW 00000000759e0d32 6 bytes [68, F3, 59, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!GetCursorPos 00000000759e1218 6 bytes [68, 55, DC, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!EndPaint 00000000759e1341 4 bytes [68, F7, 17, 1E]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!EndPaint + 5 00000000759e1346 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!BeginPaint 00000000759e1361 4 bytes [68, 87, 17, 1E]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 00000000759e1366 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!GetMessagePos 00000000759e2a8d 6 bytes [68, 23, DC, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!GetCapture 00000000759e2aac 6 bytes [68, 83, DD, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!GetDCEx 00000000759e3391 4 bytes [68, 37, 18, 1E]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 00000000759e3396 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!RegisterClassA 00000000759e434b 6 bytes [68, 0E, 5B, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!PeekMessageA 00000000759e5f74 6 bytes [68, 9D, DE, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 00000000759e6222 6 bytes [68, E3, 19, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!CallWindowProcA 00000000759e792f 6 bytes [68, 3C, 5A, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!DefFrameProcA 00000000759e7fbb 6 bytes [68, 1E, 59, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000759e810c 6 bytes [68, AD, 59, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000759e85c1 6 bytes [68, D5, 58, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000759e86b4 6 bytes [68, 67, 59, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!GetUpdateRect 00000000759fd41f 6 bytes [68, 50, 19, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!ReleaseCapture 00000000759fed49 6 bytes [68, 33, DD, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!SetCapture 00000000759fed56 4 bytes [68, D9, DC, 1E]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!SetCapture + 5 00000000759fed5b 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000075a19854 6 bytes [68, 9F, 57, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000075a19cfd 6 bytes [68, 9C, DC, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000075a19f1d 6 bytes [68, 54, 5F, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 0000000075a387cb 4 bytes [68, 4F, 57, 1F]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 0000000075a387d0 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000077423cc2 6 bytes [68, DC, 08, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000077426ab7 6 bytes [68, 7C, 0A, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 00000000774276e6 6 bytes [68, 62, 06, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000077427e1d 6 bytes [68, DA, 05, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 000000007747a1ad 6 bytes [68, 50, 0A, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\WININET.dll!InternetReadFile 000000007747a5ef 6 bytes [68, 49, 09, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000077481aa2 6 bytes [68, 77, 09, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 000000007748a74d 6 bytes [68, 0C, 07, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 000000007748ad40 6 bytes [68, 46, 08, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 00000000774aad1d 6 bytes [68, F6, 09, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 00000000774f56ed 6 bytes [68, 91, 08, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 00000000774f57a6 6 bytes [68, A9, 07, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 00000000774f5876 6 bytes [68, B7, 06, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000774f5b15 6 bytes [68, 1E, 06, 1F, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000076e53918 6 bytes [68, 27, E3, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000076e54296 6 bytes [68, 38, DF, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000076e54406 6 bytes [68, 80, E3, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\WS2_32.dll!send 0000000076e56f01 6 bytes [68, 5F, E3, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000076e67673 6 bytes [68, C8, DE, 1E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3772] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 00000000776d1224 6 bytes [68, 89, 7E, 1E, 00, C3]
---- Threads - GMER 2.1 ----
Thread C:\Windows\System32\svchost.exe [4044:3576] 000007fee9c79688
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@PendingFileRenameOperations ????????? ???????????????????e?0????????????????????????????????????????{4d36e972-e325-11ce-bfc1-08002be10318}??????????????? ???????a???????????j?,??????(??????????????T??@cpu.inf,%amdppm.devicedesc%;AMD-Prozessor?MEM??@cpu.inf,%amdppm.devicedesc%;AMD-Prozessor??????????????nettun.inf??????@monitor.inf,%generic%;(Standardmonitortypen)????e?e?e?e?e?e?/?e?????e???e?f?f??@oem7.inf,%amd%;AMD?;Standard AHCI 1.0 Serieller-ATA-Controller?????{36fc9e60-c465-11cf-8056-444553540000}\0003?????{36fc9e60-c465-11cf-8056-444553540000}\0004?????{36fc9e60-c465-11cf-8056-444553540000}\0005?????320500?)????????????????????{4d36e972-e325-11ce-bfc1-08002be10318}??????@%SystemRoot%\system32\drivers\fileinfo.sys,-100????@%systemroot%\system32\drivers\RDPENCDD.sys,-101?????i?j?j?i?j?????????i????????ch??????? ???????????????????????????j????????????r????????gBD??? ???????m???????? ???????"?????n???????????????????????????????????????????????????????????????????????????{00000000-0000-0000-0000-000000000000}??????{71a27cdd-812a-11d0
---- EOF - GMER 2.1 ---- --- --- --- |