Spanferkel | 06.08.2014 17:48 | FRST Addition Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-08-2014
Ran by Andre at 2014-08-06 17:25:36
Running from C:\Users\Andre\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
AccelerometerP11 (HKLM-x32\...\{87434D51-51DB-4109-B68F-A829ECDCF380}) (Version: 2.00.11.22 - STMicroelectronics)
Adobe Flash Player 14 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Photoshop Lightroom 5 64-bit (HKLM\...\{6C1A010F-9108-4162-A26F-9FEC4AC0F0F0}) (Version: 5.0.1 - Adobe)
Adobe Reader X (10.1.10) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.10 - Adobe Systems Incorporated)
Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
ANNO 1404 (HKLM-x32\...\{3D9CF3CA-3AB0-4A82-9853-D7C43FD1D775}) (Version: 1.03.0000 - Ubisoft)
Anno 1404 (x32 Version: 1.00.0000 - Ubisoft) Hidden
Auto Shutdown (HKLM-x32\...\{220688FD-4E64-4810-B31A-32C3895DFDFA}_is1) (Version: 1.0.0 - Entru)
Avira (HKLM-x32\...\{9590977b-7b6f-467e-a11a-efa1fae804da}) (Version: 1.1.18.30000 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.1.18.30000 - Avira Operations GmbH & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.6.552 - Avira)
Battlefield: Bad Company™ 2 (HKLM-x32\...\{3AC8457C-0385-4BEA-A959-E095F05D6D67}) (Version: 1.0.0.0 - Electronic Arts)
calibre (HKLM-x32\...\{48C84341-E4F7-42EC-BED5-7A5CAA3291F5}) (Version: 1.33.0 - Kovid Goyal)
CCleaner (HKLM\...\CCleaner) (Version: 4.14 - Piriform)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.4.0.2838 - CDBurnerXP)
Chivalry: Medieval Warfare (HKLM-x32\...\Steam App 219640) (Version: - Torn Banner Studios)
Cisco Systems VPN Client 5.0.07.0440 (HKLM\...\{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}) (Version: 5.0.7 - Cisco Systems, Inc.)
Company of Heroes - FAKEMSI (x32 Version: 2.0.0.0 - THQ Inc.) Hidden
Company of Heroes (HKLM-x32\...\Company of Heroes) (Version: 2.601.0 - THQ Inc.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.47.1.0335 - Disc Soft Ltd)
DayZ (HKLM-x32\...\Steam App 221100) (Version: - Bohemia Interactive)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{5C78021E-3C8E-4EDF-97EA-E9B8D808FD6D}) (Version: - Microsoft)
Dell DataSafe Local Backup - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: - Dell)
Dell DataSafe Local Backup (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.47 - Dell)
Dell DataSafe Online (HKLM-x32\...\{7EC66A95-AC2D-4127-940B-0445A526AB2F}) (Version: 2.1.19634 - Dell)
Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
Dell Getting Started Guide (HKLM-x32\...\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell Support Center (HKLM\...\Dell Support Center) (Version: 3.0.5621.01 - Dell Inc.)
Dell Support Center (Version: 3.0.5621.01 - PC-Doctor, Inc.) Hidden
Dell Webcam Central (HKLM-x32\...\Dell Webcam Central) (Version: 2.00.35 - Creative Technology Ltd)
Diablo II (HKLM-x32\...\Diablo II) (Version: - )
DirectX 9 Runtime (x32 Version: 1.00.0000 - Sonic Solutions) Hidden
Don't Starve (HKLM-x32\...\Steam App 219740) (Version: - Klei Entertainment)
Druckerdeinstallation für EPSON SX410 Series (HKLM\...\EPSON SX410 Series) (Version: - SEIKO EPSON Corporation)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - )
EPSON-Drucker-Software (HKLM\...\EPSON Printer and Utilities) (Version: - SEIKO EPSON Corporation)
FileZilla Client 3.5.3 (HKLM-x32\...\FileZilla Client) (Version: 3.5.3 - FileZilla Project)
Free PDF to Word Doc Converter v1.1 (HKLM-x32\...\Free PDF to Word Doc Converter_is1) (Version: 1.1 - www.hellopdf.com)
GIMP 2.6.11 (HKLM-x32\...\WinGimp-2.0_is1) (Version: 2.6.11 - The GIMP Team)
Google Books Downloader version 2.1 (HKLM-x32\...\{216729B6-014A-F413-814F-F17F74FBA113}_is1) (Version: 2.1 - GBOOKSDOWNLOADER.COM)
HP Officejet Pro 8600 - Grundlegende Software für das Gerät (HKLM\...\{D2D05FDB-4EDA-462D-8DB6-E0B9AD4FA25F}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Photosmart 5510 series - Grundlegende Software für das Gerät (HKLM\...\{5409411D-CD72-432D-B823-1B520B24BD3C}) (Version: 25.0.621.0 - Hewlett-Packard Co.)
IL-2 Sturmovik: Cliffs of Dover (HKLM-x32\...\Steam App 63950) (Version: - 1C: Maddox Games)
Image Data Converter (HKLM-x32\...\{87998E4E-6D9C-411B-AAE9-B8523FFE357D}) (Version: 4.2.02.10112 - Sony Corporation)
Intel PROSet Wireless (Version: - ) Hidden
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2291 - Intel Corporation)
Intel(R) PROSet/Wireless WiFi-Software (HKLM\...\{290D4DB2-F1B4-4B8E-918D-D71EF29A001B}) (Version: 14.00.1000 - Intel Corporation)
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.32 - Irfan Skiljan)
Java 7 Update 17 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217017FF}) (Version: 7.0.170 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.0 - Sun Microsystems, Inc.) Hidden
Java(TM) 6 Update 23 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416023FF}) (Version: 6.0.230 - Oracle)
Java(TM) 6 Update 26 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216023FF}) (Version: 6.0.260 - Oracle)
JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Age of Empires II (HKLM-x32\...\Age of Empires 2.0) (Version: - )
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (HKLM-x32\...\{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}) (Version: 9.0.30729.5570 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Mozilla Firefox 31.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyFreeCodec (HKCU\...\MyFreeCodec) (Version: - )
Nether (HKLM-x32\...\Steam App 247730) (Version: - Phosphor Games)
NetObjects Fusion Essentials (HKLM-x32\...\NetObjects Fusion Essentials) (Version: - )
NVIDIA 3D Vision Treiber 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 340.52 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.0.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.0.1 - NVIDIA Corporation)
NVIDIA Grafiktreiber 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.157.1165 - NVIDIA Corporation) Hidden
NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA Optimus Update 12.4.67 (Version: 12.4.67 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
NVIDIA ShadowPlay 12.4.67 (Version: 12.4.67 - NVIDIA Corporation) Hidden
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.12.6514 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 340.52 (Version: 340.52 - NVIDIA Corporation) Hidden
NVIDIA Update 12.4.67 (Version: 12.4.67 - NVIDIA Corporation) Hidden
NVIDIA Update Core (Version: 12.4.67 - NVIDIA Corporation) Hidden
NVIDIA Virtual Audio 1.2.23 (Version: 1.2.23 - NVIDIA Corporation) Hidden
OpenRA (HKLM-x32\...\OpenRA) (Version: - OpenRA developers)
PDF24 Creator 6.3.2 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org)
PhotoShowExpress (x32 Version: 2.0.028 - Sonic Solutions) Hidden
Power Tab Editor 1.7 (HKLM-x32\...\{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}) (Version: 1.7.0 - Power Tab Software)
Project Zomboid (HKLM-x32\...\Steam App 108600) (Version: - The Indie Stone)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.988 - Even Balance, Inc.)
Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 11.0.10 - Dell Inc.)
QuickTime (HKLM-x32\...\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}) (Version: 7.73.80.64 - Apple Inc.)
RBVirtualFolder64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6267 - Realtek Semiconductor Corp.)
Roxio Activation Module (x32 Version: 1.0 - Roxio) Hidden
Roxio BackOnTrack (x32 Version: 1.3.3 - Roxio) Hidden
Roxio Burn (HKLM-x32\...\{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}) (Version: 1.8.57.4 - Roxio)
Roxio Burn (x32 Version: 1.8 - Roxio) Hidden
Roxio Creator Starter (HKLM-x32\...\{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}) (Version: 12.1.40.0 - Roxio)
Roxio Creator Starter (x32 Version: 1.0.311 - Roxio) Hidden
Roxio Creator Starter (x32 Version: 5.0.0 - Roxio) Hidden
Roxio Express Labeler 3 (x32 Version: 3.2.2 - Roxio) Hidden
Roxio File Backup (Version: 1.3.2 - Roxio) Hidden
Saitek SD6 Programming Software 6.6.6.9 (HKLM\...\{899FCA36-ADAF-4612-8579-B37DDB0C092F}) (Version: 6.6.6.9 - Saitek)
Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.1.1.11124_17 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.1.1.11124_17 - Samsung Electronics Co., Ltd.) Hidden
Samsung Story Album Viewer (HKLM-x32\...\InstallShield_{698BBAD8-B116-495D-B879-0F07A533E57F}) (Version: 1.0.0.13054_1 - Samsung Electronics Co., Ltd.)
Samsung Story Album Viewer (x32 Version: 1.0.0.13054_1 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.45.0 - SAMSUNG Electronics Co., Ltd.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (x32 Version: - Microsoft) Hidden
SHIELD Streaming (Version: 2.1.108 - NVIDIA Corporation) Hidden
Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0 - Sonic Solutions) Hidden
Space Engineers (HKLM-x32\...\Steam App 244850) (Version: - )
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.2.6.0 - Synaptics Incorporated)
System Requirements Lab (HKLM-x32\...\SystemRequirementsLab) (Version: - )
Tales of Monkey Island (HKLM-x32\...\Tales of Monkey Island) (Version: 3.0.0.0 - Daedalic Entertainment)
TeamSpeak 3 Client (HKCU\...\TeamSpeak 3 Client) (Version: 3.0.8.1 - TeamSpeak Systems GmbH)
The Forest (HKLM-x32\...\Steam App 242760) (Version: - Endnight Games Ltd)
TrackIR5 (HKLM-x32\...\{F3CA05B7-B4C0-4C9B-AAA6-16B868B35DF2}) (Version: - )
Überwachungstool für die Intel® Turbo-Boost-Technik 2.0 (HKLM\...\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.1.23.0 - Intel)
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft)
Update for Microsoft Excel 2010 (KB2837600) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{4ACD847E-547D-493F-9A86-F73EAE1B5174}) (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2878281) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{302A8FE3-EBF5-486C-A431-16A1CD914443}) (Version: - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817369) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{4EEA3D3E-989C-4DF4-AB0A-3042C0C12AA3}) (Version: - Microsoft)
Update for Microsoft InfoPath 2010 (KB2817396) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{39767ECA-1731-45DB-AB5B-6BF40E151D66}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2825635) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{F1A20C69-9FE5-40FD-9CD5-84EABC2EF64A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{BA610006-2C39-4419-9834-CF61AB24810A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2837581) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{334FB202-28D7-4BA4-8BC9-4FE4AB233EA0}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2837606) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{B0D672F7-883E-4279-8E75-D97A5445AB46}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2878252) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{B0DB9F71-E0F7-4FE6-8925-35B860CAC0C4}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{EAD7BEF9-B28C-425F-B2C5-538CB27EF013}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{C0BDC1DE-C35E-422B-8CBD-C1D555468720}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2881028) 32-Bit Edition (HKLM-x32\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{089DBFD7-8211-43B2-AAAE-5BDD8C23E3A8}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2837595) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{51CCA922-A0CC-47C4-8910-6936D97CAC2E}) (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{90140000-001A-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{A0657506-69DC-44AE-8DC1-58E7C6F5B1C9}) (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687567) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{2AB483F1-C86E-427A-83B4-23889B03512D}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.PROPLUSR_{40EC8FB1-5202-469D-9232-C28FB1C6FC64}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2837579) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{2BA40F82-F3A4-441C-BF1A-ED4C42FF4872}) (Version: - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2760601) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{F9F5A080-AF38-4966-9A6B-C43DCA465035}) (Version: - Microsoft)
Update for Microsoft Visio 2010 (KB2880526) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{7B29D8B8-6A87-496C-A65E-B935E740448A}) (Version: - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2837587) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{38CF30E4-3348-4BD1-A859-B630C355A56F}) (Version: - Microsoft)
Update for Microsoft Word 2010 (KB2880529) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{B9B89E01-5B6B-4F73-BC34-B2C0D8ACB4CD}) (Version: - Microsoft)
VLC media player 1.1.8 (HKLM-x32\...\VLC media player) (Version: 1.1.8 - VideoLAN)
Winamp (HKLM-x32\...\Winamp) (Version: 5.61 - Nullsoft, Inc)
Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
WinRAR 4.00 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 4.00.0 - win.rar GmbH)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
25-07-2014 10:51:47 Windows Update
01-08-2014 18:42:04 Windows Update
06-08-2014 14:45:10 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2014-08-01 21:00 - 00450967 ____N C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 im.adtech.de
127.0.0.1 adserver.adtech.de
127.0.0.1 adtech.de
127.0.0.1 ar.atwola.com
127.0.0.1 atwola.com
127.0.0.1 adserver.71i.de
127.0.0.1 adicqserver.71i.de
127.0.0.1 71i.de
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
There are 1000 more lines.
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {2E98B1A1-946F-440D-BFC3-B3996A9D474B} - System32\Tasks\ScanToPCActivationApp.exe_{4932F1D8-B6CD-445C-8099-19236F92CCE5} => C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe [2011-09-16] (Hewlett-Packard Co.)
Task: {5E1CE6EC-7BB3-4FC8-B027-5F3698C3FDDF} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
Task: {6682BDB8-D29A-4C43-98BA-D5D02ACE4019} - System32\Tasks\{F78213ED-E344-4095-A425-0CC2743E7AD5} => C:\Program Files (x86)\Xider\Ankh - HdO\bin\release\StartGame.exe
Task: {7798740E-CEE4-4FA5-9272-AD4A8C783FE5} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-12] (Adobe Systems Incorporated)
Task: {78F3A25F-31A8-4313-BDB6-3F053BC1F201} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
Task: {98BE9020-7EC3-4C67-A280-4978845631BA} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-05-20] (Piriform Ltd)
Task: {AD8F20F9-15C3-44D7-B92E-7F9339A5DD26} - System32\Tasks\SidebarExecute => C:\Program Files (x86)\Windows Sidebar\sidebar.exe [2010-11-20] (Microsoft Corporation)
Task: {E1F303FE-628C-4CB8-B1E5-90FE228C95D6} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2012-10-18 22:45 - 2014-07-02 22:48 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll
2012-10-18 22:52 - 2014-07-02 20:55 - 00116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2010-12-17 20:53 - 2010-12-17 20:53 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2011-03-28 16:38 - 2012-07-13 13:27 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-01-02 16:42 - 2010-01-02 16:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2011-03-24 18:33 - 2010-08-12 01:19 - 00781536 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
2011-03-24 20:49 - 2010-11-29 14:34 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2010-11-29 22:04 - 2010-11-29 22:04 - 00403968 _____ () C:\Program Files\Intel\TurboBoost\de\SignalIslandUi.resources.dll
2014-05-29 15:40 - 2014-04-30 20:28 - 00094040 _____ () C:\Program Files\NVIDIA Corporation\ShadowPlay\gamecaster64.dll
2014-05-29 15:40 - 2014-04-30 20:28 - 00871712 _____ () C:\Program Files\NVIDIA Corporation\ShadowPlay\twitchsdk64.dll
2011-03-04 13:49 - 2011-03-04 13:49 - 00202752 _____ () C:\Program Files (x86)\Cisco Systems\VPN Client\vpnapi.dll
2014-07-13 12:52 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2014-07-13 12:52 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2014-07-13 12:52 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2014-07-13 12:52 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2014-07-13 12:52 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2011-03-24 18:32 - 2010-08-12 01:19 - 00056544 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STCoreXml.dll
2011-03-24 18:32 - 2010-08-12 01:19 - 00113888 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\PSTVdsDisk.dll
2011-03-24 18:32 - 2010-08-12 01:19 - 00126176 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll
2014-07-24 11:50 - 2014-07-24 11:50 - 00137296 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.NativeCore.dll
2014-07-24 11:49 - 2014-07-24 11:49 - 00065104 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.AvConnectorNative.dll
2012-10-18 22:45 - 2014-07-02 22:48 - 00013272 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll
2011-03-24 18:32 - 2010-08-12 01:19 - 01121504 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\LibXml2.dll
2011-03-24 18:32 - 2010-08-12 01:19 - 00077024 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll
2011-03-24 18:32 - 2010-08-12 01:19 - 00232672 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll
2011-03-24 18:32 - 2010-08-12 01:19 - 00072928 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll
2011-03-24 18:32 - 2010-08-12 01:19 - 00109792 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll
2011-03-24 18:32 - 2010-08-12 01:19 - 00119008 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll
2014-08-06 11:47 - 2014-07-24 11:50 - 00049744 _____ () C:\Users\Andre\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^vpngui.exe.lnk => C:\Windows\pss\vpngui.exe.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Andre^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Auto Shutdown.lnk => C:\Windows\pss\Auto Shutdown.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Andre^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: BCSSync => "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: Dell DataSafe Online => C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe
MSCONFIG\startupreg: Dell Webcam Central => "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
MSCONFIG\startupreg: DellStage => "C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj" --startup
MSCONFIG\startupreg: Desktop Disc Tool => "C:\Program Files (x86)\Roxio\oem\Roxio Burn\RoxioBurnLauncher.exe"
MSCONFIG\startupreg: EPSON Stylus DX4400 Series => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATICAE.EXE /FU "C:\Windows\TEMP\E_S774.tmp" /EF "HKCU"
MSCONFIG\startupreg: EPSON SX410 Series => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFCE.EXE /FU "C:\Windows\TEMP\E_SC535.tmp" /EF "HKCU"
MSCONFIG\startupreg: FreeFallProtection => C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
MSCONFIG\startupreg: ICQ => "C:\Program Files (x86)\ICQ7.4\ICQ.exe" silent loginmode=4
MSCONFIG\startupreg: IntelTBRunOnce => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
MSCONFIG\startupreg: IntelWireless => "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray
MSCONFIG\startupreg: KiesHelper => C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe /s
MSCONFIG\startupreg: KiesPDLR => C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
MSCONFIG\startupreg: KiesPDLR.exe => C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe Run
MSCONFIG\startupreg: KiesPreload => C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
MSCONFIG\startupreg: Malwarebytes' Anti-Malware => "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
MSCONFIG\startupreg: NVHotkey => rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
MSCONFIG\startupreg: PDFPrint => C:\Program Files (x86)\PDF24\pdf24.exe
MSCONFIG\startupreg: ProfilerU => C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
MSCONFIG\startupreg: QuickSet => c:\Program Files\Dell\QuickSet\QuickSet.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RoxWatchTray => "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
MSCONFIG\startupreg: SaiMfd => C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
MSCONFIG\startupreg: SDTray => "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
MSCONFIG\startupreg: Start WingMan Profiler => C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
==================== Faulty Device Manager Devices =============
Name: Cisco Systems VPN Adapter for 64-bit Windows
Description: Cisco Systems VPN Adapter for 64-bit Windows
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Cisco Systems
Service: CVirtA
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (08/06/2014 00:04:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: GFExperience.exe, Version: 12.4.67.0, Zeitstempel: 0x535faf22
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18409, Zeitstempel: 0x53159a86
Ausnahmecode: 0xe0434352
Fehleroffset: 0x0000c42d
ID des fehlerhaften Prozesses: 0x9f4
Startzeit der fehlerhaften Anwendung: 0xGFExperience.exe0
Pfad der fehlerhaften Anwendung: GFExperience.exe1
Pfad des fehlerhaften Moduls: GFExperience.exe2
Berichtskennung: GFExperience.exe3
Error: (08/06/2014 00:04:31 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: GFExperience.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.NullReferenceException
Stapel:
bei GFEClient.Model.Update.UpdateInstaller+<>c__DisplayClassc.<BuildProcInfo>b__a(System.Object, System.EventArgs)
bei System.Diagnostics.Process.OnExited()
bei System.Diagnostics.Process.RaiseOnExited()
bei System.Diagnostics.Process.CompletionCallback(System.Object, Boolean)
bei System.Threading._ThreadPoolWaitOrTimerCallback.WaitOrTimerCallback_Context(System.Object, Boolean)
bei System.Threading._ThreadPoolWaitOrTimerCallback.WaitOrTimerCallback_Context_f(System.Object)
bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
bei System.Threading._ThreadPoolWaitOrTimerCallback.PerformWaitOrTimerCallback(System.Object, Boolean)
Error: (08/01/2014 09:06:31 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: C:\Program Files (x86)\Samsung\Kies\Kies.exe . Error code = 0x80131f07
Error: (08/01/2014 09:06:31 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: C:\Program Files (x86)\Samsung\Kies\Kies.exe . Error code = 0x80131f07
Error: (07/13/2014 00:38:53 PM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )
Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008]
Error: (07/13/2014 00:10:41 AM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )
Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008]
Error: (06/09/2014 11:20:21 AM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )
Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008]
Error: (06/08/2014 05:13:59 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: C:\Program Files (x86)\Samsung\Kies\Kies.exe . Error code = 0x80131f07
Error: (06/08/2014 05:13:58 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: C:\Program Files (x86)\Samsung\Kies\Kies.exe . Error code = 0x80131f07
Error: (05/29/2014 04:11:39 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AoM.eXe, Version: 3.2002.10.700, Zeitstempel: 0x3da1d5e0
Name des fehlerhaften Moduls: AcLayers.DLL, Version: 6.1.7601.17974, Zeitstempel: 0x507d0f4c
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00010bd6
ID des fehlerhaften Prozesses: 0x9f4
Startzeit der fehlerhaften Anwendung: 0xAoM.eXe0
Pfad der fehlerhaften Anwendung: AoM.eXe1
Pfad des fehlerhaften Moduls: AoM.eXe2
Berichtskennung: AoM.eXe3
System errors:
=============
Error: (08/06/2014 05:19:05 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)
Error: (08/06/2014 04:33:16 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)
Error: (08/06/2014 04:32:40 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (08/06/2014 04:32:40 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht.
Error: (08/06/2014 04:27:06 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)
Error: (08/06/2014 04:26:40 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (08/06/2014 04:26:40 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht.
Error: (08/06/2014 04:08:36 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC)
Error: (08/06/2014 04:08:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Spybot-S&D 2 Updating Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (08/06/2014 04:08:34 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Updating Service erreicht.
Microsoft Office Sessions:
=========================
Error: (08/06/2014 00:04:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: GFExperience.exe12.4.67.0535faf22KERNELBASE.dll6.1.7601.1840953159a86e04343520000c42d9f401cfb159704c0c8cC:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\GFExperience.exeC:\Windows\syswow64\KERNELBASE.dll0f979b2b-1d51-11e4-87bd-14feb59e0371
Error: (08/06/2014 00:04:31 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Anwendung: GFExperience.exe
Frameworkversion: v4.0.30319
Beschreibung: Der Prozess wurde aufgrund eines Ausnahmefehlers beendet.
Ausnahmeinformationen: System.NullReferenceException
Stapel:
bei GFEClient.Model.Update.UpdateInstaller+<>c__DisplayClassc.<BuildProcInfo>b__a(System.Object, System.EventArgs)
bei System.Diagnostics.Process.OnExited()
bei System.Diagnostics.Process.RaiseOnExited()
bei System.Diagnostics.Process.CompletionCallback(System.Object, Boolean)
bei System.Threading._ThreadPoolWaitOrTimerCallback.WaitOrTimerCallback_Context(System.Object, Boolean)
bei System.Threading._ThreadPoolWaitOrTimerCallback.WaitOrTimerCallback_Context_f(System.Object)
bei System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
bei System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
bei System.Threading._ThreadPoolWaitOrTimerCallback.PerformWaitOrTimerCallback(System.Object, Boolean)
Error: (08/01/2014 09:06:31 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: C:\Program Files (x86)\Samsung\Kies\Kies.exe . Error code = 0x80131f07
C:\Program Files (x86)\Samsung\Kies\Kies.exe
Error: (08/01/2014 09:06:31 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: C:\Program Files (x86)\Samsung\Kies\Kies.exe . Error code = 0x80131f07
C:\Program Files (x86)\Samsung\Kies\Kies.exe
Error: (07/13/2014 00:38:53 PM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )
Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008]
Error: (07/13/2014 00:10:41 AM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )
Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008]
Error: (06/09/2014 11:20:21 AM) (Source: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe) (EventID: 1) (User: )
Description: C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exeCan't get user token [1008]
Error: (06/08/2014 05:13:59 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: C:\Program Files (x86)\Samsung\Kies\Kies.exe . Error code = 0x80131f07
C:\Program Files (x86)\Samsung\Kies\Kies.exe
Error: (06/08/2014 05:13:58 PM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - 1>Failed to compile: C:\Program Files (x86)\Samsung\Kies\Kies.exe . Error code = 0x80131f07
C:\Program Files (x86)\Samsung\Kies\Kies.exe
Error: (05/29/2014 04:11:39 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: AoM.eXe3.2002.10.7003da1d5e0AcLayers.DLL6.1.7601.17974507d0f4cc000000500010bd69f401cf7b47d7df8fecC:\Users\Andre\Downloads\Games\Portable LAN Game Collection\Age of Mythology [Portable]\AoM\AoM.eXeC:\Windows\AppPatch\AcLayers.DLL2631ca73-e73b-11e3-868e-14feb59e0371
CodeIntegrity Errors:
===================================
Date: 2013-02-23 18:17:20.519
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-02-23 18:17:20.423
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-02-23 18:17:17.893
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-02-23 18:17:17.797
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-02-23 18:17:15.226
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-02-23 18:17:15.119
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-02-23 18:17:11.437
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-02-23 18:17:11.341
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-02-23 18:17:08.917
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-02-23 18:17:08.819
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\SysWOW64\FsUsbExDisk.Sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Percentage of memory in use: 50%
Total physical RAM: 4010.17 MB
Available physical RAM: 1976.48 MB
Total Pagefile: 8018.52 MB
Available Pagefile: 5805.91 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:451.01 GB) (Free:230.94 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 07F2837E)
Partition 1: (Not Active) - (Size=102 MB) - (Type=DE)
Partition 2: (Active) - (Size=15 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=451 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Gmer Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-08-06 17:48:12
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST950042 rev.D005 465,76GB
Running: Gmer-19357.exe; Driver: C:\Users\Andre\AppData\Local\Temp\uwliqpob.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff800039f3000 45 bytes [4D, 6D, 52, 65, 01, 00, 00, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575 fffff800039f302f 16 bytes [00, 00, 00, 00, 00, 00, 00, ...]
---- User code sections - GMER 2.1 ----
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1412] C:\Windows\system32\kernel32.dll!RegSetValueExW 000000007732a400 7 bytes JMP 000000016fff0228
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1412] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077333f20 5 bytes JMP 000000016fff0180
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1412] C:\Windows\system32\kernel32.dll!RegDeleteValueW 000000007734ffb0 5 bytes JMP 000000016fff01b8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1412] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007735f2e0 5 bytes JMP 000000016fff0110
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1412] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077389a30 7 bytes JMP 000000016fff00d8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1412] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000773994c0 5 bytes JMP 000000016fff0148
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1412] C:\Windows\system32\kernel32.dll!RegSetValueExA 00000000773b87e0 7 bytes JMP 000000016fff01f0
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1412] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdd02db0 5 bytes JMP 000007fffdc90180
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1412] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdd037d0 7 bytes JMP 000007fffdc900d8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1412] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdd08ef0 6 bytes JMP 000007fffdc90148
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1412] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdd1af60 5 bytes JMP 000007fffdc90110
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1412] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff4b89e0 8 bytes JMP 000007fffdc901f0
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1412] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff4bbe40 8 bytes JMP 000007fffdc901b8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1412] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefed67490 11 bytes JMP 000007fffdc90228
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1412] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefed7bf00 7 bytes JMP 000007fffdc90260
.text C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe[2016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075011465 2 bytes [01, 75]
.text C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe[2016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000750114bb 2 bytes [01, 75]
.text ... * 2
.text C:\Windows\SysWOW64\PnkBstrA.exe[2320] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 0000000071d71a22 2 bytes [D7, 71]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2320] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 0000000071d71ad0 2 bytes [D7, 71]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2320] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 0000000071d71b08 2 bytes [D7, 71]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2320] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 0000000071d71bba 2 bytes [D7, 71]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2320] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 0000000071d71bda 2 bytes [D7, 71]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2320] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075011465 2 bytes [01, 75]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2320] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000750114bb 2 bytes [01, 75]
.text ... * 2
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2380] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000075011465 2 bytes [01, 75]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2380] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 00000000750114bb 2 bytes [01, 75]
.text ... * 2
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[2812] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075011465 2 bytes [01, 75]
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[2812] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000750114bb 2 bytes [01, 75]
.text ... * 2
.text C:\Windows\system32\Dwm.exe[2944] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdd02db0 5 bytes JMP 000007fffdc90180
.text C:\Windows\system32\Dwm.exe[2944] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdd037d0 7 bytes JMP 000007fffdc900d8
.text C:\Windows\system32\Dwm.exe[2944] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdd08ef0 6 bytes JMP 000007fffdc90148
.text C:\Windows\system32\Dwm.exe[2944] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdd1af60 5 bytes JMP 000007fffdc90110
.text C:\Windows\system32\Dwm.exe[2944] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff4b89e0 8 bytes JMP 000007fffdc901f0
.text C:\Windows\system32\Dwm.exe[2944] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff4bbe40 8 bytes JMP 000007fffdc901b8
.text C:\Windows\system32\Dwm.exe[2944] C:\Windows\system32\dxgi.dll!CreateDXGIFactory 000007fef81f4da4 7 bytes JMP 000007fff81e00d8
.text C:\Windows\system32\Dwm.exe[2944] C:\Windows\system32\dxgi.dll!CreateDXGIFactory1 000007fef8219af4 7 bytes JMP 000007fff81e0110
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2488] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075011465 2 bytes [01, 75]
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe[2488] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000750114bb 2 bytes [01, 75]
.text ... * 2
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3956] C:\Windows\system32\kernel32.dll!RegSetValueExW 000000007732a400 7 bytes JMP 000000016fff0228
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3956] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077333f20 5 bytes JMP 000000016fff0180
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3956] C:\Windows\system32\kernel32.dll!RegDeleteValueW 000000007734ffb0 5 bytes JMP 000000016fff01b8
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3956] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007735f2e0 5 bytes JMP 000000016fff0110
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3956] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077389a30 7 bytes JMP 000000016fff00d8
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3956] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000773994c0 5 bytes JMP 000000016fff0148
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3956] C:\Windows\system32\kernel32.dll!RegSetValueExA 00000000773b87e0 7 bytes JMP 000000016fff01f0
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3956] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdd02db0 5 bytes JMP 000007fffdc90180
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3956] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdd037d0 7 bytes JMP 000007fffdc900d8
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3956] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdd08ef0 6 bytes JMP 000007fffdc90148
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3956] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdd1af60 5 bytes JMP 000007fffdc90110
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3956] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefed67490 11 bytes JMP 000007fffdc90228
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3956] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefed7bf00 7 bytes JMP 000007fffdc90260
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3956] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff4b89e0 8 bytes JMP 000007fffdc901f0
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3956] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff4bbe40 8 bytes JMP 000007fffdc901b8
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3956] C:\Windows\system32\d3d9.dll!Direct3DCreate9Ex 000007fef8ea2460 5 bytes JMP 000007fefdc902d0
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3956] C:\Windows\system32\d3d9.dll!Direct3DCreate9 000007fef8ed96b0 6 bytes JMP 000007fefdc90298
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\kernel32.dll!RegSetValueExW 000000007732a400 7 bytes JMP 000000016fff0228
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077333f20 5 bytes JMP 000000016fff0180
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\kernel32.dll!RegDeleteValueW 000000007734ffb0 5 bytes JMP 000000016fff01b8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007735f2e0 5 bytes JMP 000000016fff0110
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077389a30 7 bytes JMP 000000016fff00d8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000773994c0 5 bytes JMP 000000016fff0148
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\kernel32.dll!RegSetValueExA 00000000773b87e0 7 bytes JMP 000000016fff01f0
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdd02db0 5 bytes JMP 000007fffdc90180
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdd037d0 7 bytes JMP 000007fffdc900d8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdd08ef0 6 bytes JMP 000007fffdc90148
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdd1af60 5 bytes JMP 000007fffdc90110
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff4b89e0 8 bytes JMP 000007fffdc901f0
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff4bbe40 8 bytes JMP 000007fffdc901b8
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076b41f0e 7 bytes JMP 00000001740b3dd0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076b45bad 7 bytes JMP 00000001740b40e0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000076b51409 7 bytes JMP 00000001740b3f10
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000076b5ea45 7 bytes JMP 00000001740b3dc0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076be8e24 7 bytes JMP 00000001740b3b50
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076be8ea9 5 bytes JMP 00000001740b3c00
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076be91ff 5 bytes JMP 00000001740b3b60
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076771d29 5 bytes JMP 00000001740b3b00
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076771dd7 5 bytes JMP 00000001740b3ab0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076772ab1 5 bytes JMP 00000001740b3c10
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076772d17 5 bytes JMP 00000001740b3890
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076448a29 5 bytes JMP 00000001740b3370
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000076454572 5 bytes JMP 00000001740b3810
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007646e567 5 bytes JMP 00000001740b3880
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000764907d7 5 bytes JMP 00000001740b3280
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000764a7a5c 5 bytes JMP 00000001740b3800
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 00000000767de96b 5 bytes JMP 00000001740b33e0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 00000000767deba5 5 bytes JMP 00000001740b33f0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075045ea5 5 bytes JMP 00000001740b3320
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075079d0b 5 bytes JMP 00000001740b32b0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075011465 2 bytes [01, 75]
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[600] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000750114bb 2 bytes [01, 75]
.text ... * 2
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4824] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076b41f0e 7 bytes JMP 00000001740b3dd0
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4824] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076b45bad 7 bytes JMP 00000001740b40e0
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4824] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000076b51409 7 bytes JMP 00000001740b3f10
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4824] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000076b5ea45 7 bytes JMP 00000001740b3dc0
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4824] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076be8e24 7 bytes JMP 00000001740b3b50
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4824] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076be8ea9 5 bytes JMP 00000001740b3c00
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4824] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076be91ff 5 bytes JMP 00000001740b3b60
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4824] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076771d29 5 bytes JMP 00000001740b3b00
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4824] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076771dd7 5 bytes JMP 00000001740b3ab0
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4824] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076772ab1 5 bytes JMP 00000001740b3c10
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4824] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076772d17 5 bytes JMP 00000001740b3890
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4824] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 00000000767de96b 5 bytes JMP 00000001740b33e0
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4824] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 00000000767deba5 5 bytes JMP 00000001740b33f0
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4824] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076448a29 5 bytes JMP 00000001740b3370
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4824] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000076454572 5 bytes JMP 00000001740b3810
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4824] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007646e567 5 bytes JMP 00000001740b3880
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4824] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000764907d7 5 bytes JMP 00000001740b3280
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4824] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000764a7a5c 5 bytes JMP 00000001740b3800
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4824] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075045ea5 5 bytes JMP 00000001740b3320
.text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4824] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075079d0b 5 bytes JMP 00000001740b32b0
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3968] C:\Windows\system32\kernel32.dll!RegSetValueExW 000000007732a400 7 bytes JMP 000000016fff0228
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3968] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077333f20 5 bytes JMP 000000016fff0180
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3968] C:\Windows\system32\kernel32.dll!RegDeleteValueW 000000007734ffb0 5 bytes JMP 000000016fff01b8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3968] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007735f2e0 5 bytes JMP 000000016fff0110
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3968] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077389a30 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3968] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000773994c0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3968] C:\Windows\system32\kernel32.dll!RegSetValueExA 00000000773b87e0 7 bytes JMP 000000016fff01f0
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3968] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdd02db0 5 bytes JMP 000007fffdc90180
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3968] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdd037d0 7 bytes JMP 000007fffdc900d8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3968] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdd08ef0 6 bytes JMP 000007fffdc90148
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3968] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdd1af60 5 bytes JMP 000007fffdc90110
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3968] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff4b89e0 8 bytes JMP 000007fffdc901f0
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3968] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff4bbe40 8 bytes JMP 000007fffdc901b8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3968] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefed67490 11 bytes JMP 000007fffdc90228
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3968] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefed7bf00 7 bytes JMP 000007fffdc90260
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4276] C:\Windows\system32\kernel32.dll!RegSetValueExW 000000007732a400 7 bytes JMP 000000016fff0228
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4276] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077333f20 5 bytes JMP 000000016fff0180
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4276] C:\Windows\system32\kernel32.dll!RegDeleteValueW 000000007734ffb0 5 bytes JMP 000000016fff01b8
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4276] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007735f2e0 5 bytes JMP 000000016fff0110
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4276] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077389a30 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4276] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000773994c0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4276] C:\Windows\system32\kernel32.dll!RegSetValueExA 00000000773b87e0 7 bytes JMP 000000016fff01f0
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4276] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdd02db0 5 bytes JMP 000007fffdc90180
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4276] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdd037d0 7 bytes JMP 000007fffdc900d8
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4276] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdd08ef0 6 bytes JMP 000007fffdc90148
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4276] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdd1af60 5 bytes JMP 000007fffdc90110
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4276] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff4b89e0 8 bytes JMP 000007fffdc901f0
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4276] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff4bbe40 8 bytes JMP 000007fffdc901b8
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4276] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefed67490 11 bytes JMP 000007fffdc90228
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[4276] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefed7bf00 7 bytes JMP 000007fffdc90260
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4328] C:\Windows\system32\kernel32.dll!RegSetValueExW 000000007732a400 7 bytes JMP 000000016fff0228
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4328] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077333f20 5 bytes JMP 000000016fff0180
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4328] C:\Windows\system32\kernel32.dll!RegDeleteValueW 000000007734ffb0 5 bytes JMP 000000016fff01b8
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4328] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007735f2e0 5 bytes JMP 000000016fff0110
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4328] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077389a30 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4328] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000773994c0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4328] C:\Windows\system32\kernel32.dll!RegSetValueExA 00000000773b87e0 7 bytes JMP 000000016fff01f0
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4328] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdd02db0 5 bytes JMP 000007fffdc90180
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4328] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdd037d0 7 bytes JMP 000007fffdc900d8
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4328] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdd08ef0 6 bytes JMP 000007fffdc90148
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4328] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdd1af60 5 bytes JMP 000007fffdc90110
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4328] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefed67490 11 bytes JMP 000007fffdc90228
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4328] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefed7bf00 7 bytes JMP 000007fffdc90260
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4328] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff4b89e0 8 bytes JMP 000007fffdc901f0
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4328] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff4bbe40 8 bytes JMP 000007fffdc901b8
.text C:\Windows\System32\igfxpers.exe[1396] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdd02db0 5 bytes JMP 000007fffdc90180
.text C:\Windows\System32\igfxpers.exe[1396] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdd037d0 7 bytes JMP 000007fffdc900d8
.text C:\Windows\System32\igfxpers.exe[1396] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdd08ef0 6 bytes JMP 000007fffdc90148
.text C:\Windows\System32\igfxpers.exe[1396] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdd1af60 5 bytes JMP 000007fffdc90110
.text C:\Windows\System32\igfxpers.exe[1396] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff4b89e0 8 bytes JMP 000007fffdc901f0
.text C:\Windows\System32\igfxpers.exe[1396] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff4bbe40 8 bytes JMP 000007fffdc901b8
.text C:\Windows\System32\igfxpers.exe[1396] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefed67490 11 bytes JMP 000007fffdc90228
.text C:\Windows\System32\igfxpers.exe[1396] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefed7bf00 7 bytes JMP 000007fffdc90260
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\KERNEL32.dll!RegQueryValueExW 0000000076b41f0e 7 bytes JMP 00000001740b3dd0
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExW 0000000076b45bad 7 bytes JMP 00000001740b40e0
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA 0000000076b51409 7 bytes JMP 00000001740b3f10
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\KERNEL32.dll!RegDeleteValueW 0000000076b5ea45 7 bytes JMP 00000001740b3dc0
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx 0000000076be8e24 7 bytes JMP 00000001740b3b50
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation 0000000076be8ea9 5 bytes JMP 00000001740b3c00
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW 0000000076be91ff 5 bytes JMP 00000001740b3b60
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076771d29 5 bytes JMP 00000001740b3b00
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076771dd7 5 bytes JMP 00000001740b3ab0
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076772ab1 5 bytes JMP 00000001740b3c10
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076772d17 5 bytes JMP 00000001740b3890
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 00000000767de96b 5 bytes JMP 00000001740b33e0
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 00000000767deba5 5 bytes JMP 00000001740b33f0
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076448a29 5 bytes JMP 00000001740b3370
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000076454572 5 bytes JMP 00000001740b3810
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007646e567 5 bytes JMP 00000001740b3880
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000764907d7 5 bytes JMP 00000001740b3280
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000764a7a5c 5 bytes JMP 00000001740b3800
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075045ea5 5 bytes JMP 00000001740b3320
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075079d0b 5 bytes JMP 00000001740b32b0
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000075011465 2 bytes [01, 75]
.text C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe[4820] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 00000000750114bb 2 bytes [01, 75]
.text ... * 2
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4984] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdd02db0 5 bytes JMP 000007fffdc90180
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4984] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdd037d0 7 bytes JMP 000007fffdc900d8
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4984] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdd08ef0 6 bytes JMP 000007fffdc90148
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4984] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdd1af60 5 bytes JMP 000007fffdc90110
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4984] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff4b89e0 8 bytes JMP 000007fffdc901f0
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4984] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff4bbe40 8 bytes JMP 000007fffdc901b8
.text C:\Users\Andre\Desktop\Gmer-19357.exe[2660] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076b41f0e 7 bytes JMP 00000001740b3dd0
.text C:\Users\Andre\Desktop\Gmer-19357.exe[2660] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076b45bad 7 bytes JMP 00000001740b40e0
.text C:\Users\Andre\Desktop\Gmer-19357.exe[2660] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000076b51409 7 bytes JMP 00000001740b3f10
.text C:\Users\Andre\Desktop\Gmer-19357.exe[2660] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000076b5ea45 7 bytes JMP 00000001740b3dc0
.text C:\Users\Andre\Desktop\Gmer-19357.exe[2660] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076be8e24 7 bytes JMP 00000001740b3b50
.text C:\Users\Andre\Desktop\Gmer-19357.exe[2660] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076be8ea9 5 bytes JMP 00000001740b3c00
.text C:\Users\Andre\Desktop\Gmer-19357.exe[2660] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076be91ff 5 bytes JMP 00000001740b3b60
.text C:\Users\Andre\Desktop\Gmer-19357.exe[2660] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076771d29 5 bytes JMP 00000001740b3b00
.text C:\Users\Andre\Desktop\Gmer-19357.exe[2660] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076771dd7 5 bytes JMP 00000001740b3ab0
.text C:\Users\Andre\Desktop\Gmer-19357.exe[2660] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076772ab1 5 bytes JMP 00000001740b3c10
.text C:\Users\Andre\Desktop\Gmer-19357.exe[2660] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076772d17 5 bytes JMP 00000001740b3890
.text C:\Users\Andre\Desktop\Gmer-19357.exe[2660] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 00000000767de96b 5 bytes JMP 00000001740b33e0
.text C:\Users\Andre\Desktop\Gmer-19357.exe[2660] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 00000000767deba5 5 bytes JMP 00000001740b33f0
.text C:\Users\Andre\Desktop\Gmer-19357.exe[2660] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076448a29 5 bytes JMP 00000001740b3370
.text C:\Users\Andre\Desktop\Gmer-19357.exe[2660] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000076454572 5 bytes JMP 00000001740b3810
.text C:\Users\Andre\Desktop\Gmer-19357.exe[2660] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007646e567 5 bytes JMP 00000001740b3880
.text C:\Users\Andre\Desktop\Gmer-19357.exe[2660] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000764907d7 5 bytes JMP 00000001740b3280
.text C:\Users\Andre\Desktop\Gmer-19357.exe[2660] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000764a7a5c 5 bytes JMP 00000001740b3800
---- Threads - GMER 2.1 ----
Thread C:\Windows\System32\svchost.exe [4652:5364] 000007fee9af9688
---- Processes - GMER 2.1 ----
Process C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE (*** suspicious ***) @ C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE [1232] (EPSON Status Monitor 3/SEIKO EPSON CORPORATION)(2011-04-18 20:42:06) 0000000100000000
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
---- EOF - GMER 2.1 ---- Ich hoffe so ist es besser! :-) |