Weiter gehts mit FRST - Addition.txt Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-09-2014 02
Ran by Clara at 2014-09-09 23:54:41
Running from C:\Users\Clara\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - )
7-Zip 9.30 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0930-000001000000}) (Version: 9.30.00.0 - Igor Pavlov)
ABBYY FineReader 9.0 Sprint (HKLM-x32\...\ABBYY FineReader 9.0 Sprint) (Version: 9.01.513.58212 - ABBYY)
ABBYY FineReader 9.0 Sprint (x32 Version: 9.01.513.58212 - ABBYY) Hidden
Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.179 - Adobe Systems Incorporated)
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.152 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.08) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Akamai NetSession Interface (HKCU\...\Akamai) (Version: - Akamai Technologies, Inc)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 1.8.1217.36096 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 1.8.1217.36096 - Alcor Micro Corp.) Hidden
AMI VR-pulse OS Switcher (HKLM\...\{EC1369CF-15BD-4FAF-BA84-65E4788C682E}) (Version: 1.1 - American Megatrends Inc.)
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{6AF2AC2A-3532-43FD-9F4D-BDC9C0D724C7}) (Version: 7.1.2.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Ashampoo Burning Studio (HKLM-x32\...\Ashampoo Burning Studio_is1) (Version: 10.0.10 - Ashampoo GmbH & Co. KG)
Ashampoo Photo Commander (HKLM-x32\...\Ashampoo Photo Commander_is1) (Version: 9.2.0 - Ashampoo GmbH & Co. KG)
Ashampoo Photo Optimizer (HKLM-x32\...\Ashampoo Photo Optimizer_is1) (Version: 4.0.0 - Ashampoo GmbH & Co. KG)
Ashampoo Snap (HKLM-x32\...\Ashampoo Snap_is1) (Version: 4.3.0 - Ashampoo GmbH & Co. KG)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 1.0.0.35 - Atheros Communications Inc.)
Audials (HKLM-x32\...\{2E5052A2-8E3D-4229-A5EB-2465B260D917}) (Version: 8.0.54900.0 - RapidSolution Software AG)
Audials TV (HKLM-x32\...\{24EE4523-711A-4BD1-95EA-F73A8A6950D3}) (Version: 1.3.10803.300 - RapidSolution Software AG)
avast! Free Antivirus (HKLM-x32\...\avast) (Version: 9.0.2021 - AVAST Software)
Benutzerhandbuch - Grundlagen EPSON XP-302 303 305 306 Series (HKLM-x32\...\EPSON XP-302 303 305 306 Series Bog) (Version: - )
Benutzerhandbuch EPSON XP-302 303 305 306 Series (HKLM-x32\...\EPSON XP-302 303 305 306 Series Useg) (Version: - )
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.54.14.50 - Conexant)
Corel Graphics - Windows Shell Extension (HKLM-x32\...\_{B6BFCD02-BA0E-41A9-9C9C-6624C4BB475F}) (Version: 15.2.0.686 - Corel Corporation)
Corel Graphics - Windows Shell Extension (x32 Version: 15.2.686 - Corel Corporation) Hidden
Corel Graphics - Windows Shell Extension 64 Bit (Version: 15.2.686 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Common (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Connect (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Custom Data (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - DE (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Draw (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - EN (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - ES (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Extra Content (HKLM-x32\...\_{5A10CFDA-FA2B-453C-B561-AE864E62EAC8}) (Version: - Corel Corporation)
CorelDRAW Essentials X5 - Extra Content (x32 Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Filters (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - FR (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - IPM (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - IT (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - PHOTO-PAINT (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Redist (x32 Version: 15.0 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - Setup Files (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 - WT (x32 Version: 15.3 - Corel Corporation) Hidden
CorelDRAW Essentials X5 (HKLM-x32\...\_{EDBEBF07-F880-48FB-9AA5-0E8E71E02D83}) (Version: 15.2.0.686 - Corel Corporation)
CorelDRAW Essentials X5 (x32 Version: 15.3 - Corel Corporation) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Deponia (HKLM-x32\...\Deponia) (Version: 1.0 - Daedalic Entertainment)
Die Sims™ 2 Deluxe (HKLM-x32\...\{9C244239-ED8E-40f1-937F-51C706CD2160}) (Version: - )
Die Sims™ 2 Gute Reise (HKLM-x32\...\{F248ADFA-64E0-4b03-8A83-059078BED6A0}) (Version: - Electronic Arts)
Die Sims™ 2 Haustiere (HKLM-x32\...\{4817189D-1785-4627-A33C-39FD90919300}) (Version: - )
Die Sims™ 2 Küchen- und Bad-Einrichtungs-Accessoires (HKLM-x32\...\{6522C636-B04C-4333-9BEB-9E0C0B6350D6}) (Version: - Electronic Arts)
Die Sims™ 2 Teen Style-Accessoires (HKLM-x32\...\{5C648FDB-0138-4619-B66E-230EF53E8E2C}) (Version: - Electronic Arts)
dm Digi Foto (HKLM-x32\...\dm Digi Foto) (Version: 2.3.0.93 - Imaxel Lab S.L)
Dolby Advanced Audio v2 (HKLM-x32\...\{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}) (Version: 7.2.7000.4 - Dolby Laboratories Inc)
Download Navigator (HKLM-x32\...\{E728441A-7820-4B1C-87C9-DE7BE37B2953}) (Version: 1.1.0 - SEIKO EPSON CORPORATION)
Dropbox (HKCU\...\Dropbox) (Version: 2.10.28 - Dropbox, Inc.)
Druckerdeinstallation für EPSON XP-302 303 305 306 Series (HKLM\...\EPSON XP-302 303 305 306 Series) (Version: - SEIKO EPSON Corporation)
Edna & Harvey: Harvey's New Eyes (HKLM-x32\...\Steam App 219910) (Version: - Daedalic Entertainment)
Epson Connect Printer Setup (HKLM-x32\...\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.1.1 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print 2 (HKLM-x32\...\{30E01116-5666-4807-8EF1-D80E9FF16717}) (Version: 2.3.2.0 - SEIKO EPSON CORPORATION)
Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser) (HKLM-x32\...\{B2D55EB8-32C5-4B43-9006-9E97DECBA178}) (Version: 1.00.0000 - SEIKO EPSON CORPORATION2)
Epson Event Manager (HKLM-x32\...\{BECE9CCD-83F6-4BAA-9B26-227DF7D2E932}) (Version: 3.01.0000 - Seiko Epson Corporation)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation)
EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.5.00 - SEIKO EPSON CORPORATION)
Fashion Factory (HKLM-x32\...\{BAE02E8D-9B2C-4C71-AB30-DADD141849D4}) (Version: 1.00.0000 - GedonSoft)
Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Fotogalerija (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
FOTOParadies (HKLM-x32\...\{FD838798-E2CB-45FA-AF79-6011519031E2}}_is1) (Version: 3.5.7.1 - Foto Online Service GmbH)
Fotótár (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Free Pascal 2.6.2 (HKLM-x32\...\FreePascal_is1) (Version: - Free Pascal Team)
Free YouTube to MP3 Converter version 3.10.15.1228 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: - DVDVideoSoft Ltd.)
Galería de fotos (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Gameforge Live 2.0.0 "Baby Genius" (HKLM-x32\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 2.0.0 - Gameforge)
GeoGebra 4.4 (HKLM-x32\...\GeoGebra 4.4) (Version: 4.4.10.0 - International GeoGebra Institute)
GIMP 2.8.4 (HKLM\...\GIMP-2_is1) (Version: 2.8.4 - The GIMP Team)
Google Chrome (HKCU\...\Google Chrome) (Version: 37.0.2062.103 - Google Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.103 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
Google+ Auto Backup (HKCU\...\Google+ Auto Backup) (Version: 1.0.26.151 - Google, Inc.)
Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
Grand Fantasia (HKLM-x32\...\Grand Fantasia) (Version: - )
iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.)
Icy Tower v1.5 (HKLM-x32\...\Icy Tower v1.5_is1) (Version: - Free Lunch Design)
Intel PROSet Wireless (Version: - ) Hidden
Intel PROSet Wireless (x32 Version: - ) Hidden
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3347 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{7CE8BE79-ABC3-4B2C-9543-28ED2B0A9EA8}) (Version: 1.2.0.0587 - Intel Corporation)
Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{295AEB79-B53A-4F1B-860F-7800BB7E3681}) (Version: 14.2.1000 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.6.0.1002 - Intel Corporation)
Intel(R) WiDi (HKLM-x32\...\{E1B934BB-6AFA-429F-98E4-76F9CBC72BF6}) (Version: 2.2.14.0 - Intel Corporation)
Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - )
iTunes (HKLM\...\{77DE5105-D05E-448C-96CB-7FA381903753}) (Version: 11.3.1.2 - Apple Inc.)
Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217055FF}) (Version: 7.0.550 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
KeePass Password Safe 2.27 (HKLM-x32\...\KeePassPasswordSafe2_is1) (Version: 2.27 - Dominik Reichl)
KODAK Create@Home Software (für dm) (HKLM-x32\...\{098E5A44-AB95-428B-BA4C-A263C693E1AC}) (Version: 6.0.8392 - Digilabs)
Lazarus 1.0.14 (HKLM\...\Lazarus_is1) (Version: 1.0.14 - Lazarus Team)
LibreOffice 3.6 Help Pack (German) (HKLM-x32\...\{C77157BC-EC21-422F-8901-64B3D34ED67D}) (Version: 3.6.4.3 - The Document Foundation)
LibreOffice 4.2.6.3 (HKLM-x32\...\{14DB1822-00B5-4820-86B5-EF893CA46B53}) (Version: 4.2.6.3 - The Document Foundation)
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Memeo Instant Backup (HKLM-x32\...\{8E666407-AC41-46a2-9692-6C7BFCBFDD37}) (Version: 4.60.0.7943 - Memeo Inc.)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Mathematics (64-Bit) (HKLM\...\{E57B7E0A-8BE5-42E2-BE60-C07ED680A063}) (Version: 4.0 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft OneDrive (HKCU\...\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
My Horse and Me (HKLM-x32\...\InstallShield_{6B86AB79-5FC2-4746-94D7-9CA8D3C91170}) (Version: 1.00.0000 - W! Games)
My Horse and Me (x32 Version: 1.00.0000 - W! Games) Hidden
Netzwerkhandbuch EPSON XP-302 303 305 306 Series (HKLM-x32\...\EPSON XP-302 303 305 306 Series Netg) (Version: - )
NVIDIA 3D Vision Treiber 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 331.65 - NVIDIA Corporation)
NVIDIA Grafiktreiber 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.65 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden
NVIDIA Optimus 1.15.2 (Version: 1.15.2 - NVIDIA Corporation) Hidden
NVIDIA PhysX (HKLM-x32\...\{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}) (Version: 9.10.0513 - NVIDIA Corporation)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3165 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 331.65 (Version: 331.65 - NVIDIA Corporation) Hidden
NVIDIA Update 1.15.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.15.2 - NVIDIA Corporation)
NVIDIA Update Components (Version: 1.15.2 - NVIDIA Corporation) Hidden
Origin (HKLM-x32\...\Origin) (Version: 9.4.12.2807 - Electronic Arts, Inc.)
PCSUITE SHREDDER (HKLM-x32\...\PCSUITE_SHREDDER_PRO_is1) (Version: - Markement GmbH)
Peggle (HKLM-x32\...\{715AD72D-887A-459E-988B-D4F3E87FA24B}) (Version: 1.04.0.0 - PopCap Games)
phase-6 2.3.2b (HKLM-x32\...\phase-6) (Version: 2.3.2b - phase-6)
PHotkey (HKLM-x32\...\{E50C224A-BBF2-428D-9DCF-DBF9DF85C40E}) (Version: 1.00.0045 - Pegatron Corporation)
Photo Common (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Photo Gallery (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Portal (HKLM-x32\...\Steam App 400) (Version: - Valve)
Portal 2 (HKLM-x32\...\Steam App 620) (Version: - Valve)
Portal 2 Publishing Tool (HKLM-x32\...\Steam App 644) (Version: - )
Pošta Windows Live (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Raccolta foto (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.1.16.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.1.16.0 - Renesas Electronics Corporation) Hidden
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Secunia PSI (3.0.0.9016) (HKLM-x32\...\Secunia PSI) (Version: 3.0.0.9016 - Secunia)
Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.)
Spelling Dictionaries Support For Adobe Reader X (HKLM-x32\...\{AC76BA86-7AD7-5464-3428-A00000000004}) (Version: 10.0.0 - Adobe Systems Incorporated)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.27.1 - Synaptics Incorporated)
Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version: - Valve)
The Sims 2: Ultimate Collection (HKLM-x32\...\{04450C18-F039-4B81-A621-70C3B0F523D5}) (Version: 1.0.0.0 - Electronic Arts)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
WD SmartWare (HKLM\...\{07179D37-D5FE-4373-90D9-A25B992EFB3E}) (Version: 1.4.5.5 - Western Digital)
Windows Live Communications Platform (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-2971180534-3307857154-2361156270-1002_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Clara\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2971180534-3307857154-2361156270-1002_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Clara\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll No File
CustomCLSID: HKU\S-1-5-21-2971180534-3307857154-2361156270-1002_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Clara\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2971180534-3307857154-2361156270-1002_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Clara\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2971180534-3307857154-2361156270-1002_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Clara\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2971180534-3307857154-2361156270-1002_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Clara\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2971180534-3307857154-2361156270-1002_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Clara\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2971180534-3307857154-2361156270-1002_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Clara\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2971180534-3307857154-2361156270-1002_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Clara\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2971180534-3307857154-2361156270-1002_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Clara\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2971180534-3307857154-2361156270-1002_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Clara\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2971180534-3307857154-2361156270-1002_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Clara\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2971180534-3307857154-2361156270-1002_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Clara\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2971180534-3307857154-2361156270-1002_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Clara\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2971180534-3307857154-2361156270-1002_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Clara\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2971180534-3307857154-2361156270-1002_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Clara\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2971180534-3307857154-2361156270-1002_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Clara\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2971180534-3307857154-2361156270-1002_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Clara\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll No File
==================== Restore Points =========================
02-09-2014 21:18:53 Windows Update
04-09-2014 23:35:37 Windows Update
08-09-2014 18:25:06 Windows Update
08-09-2014 20:37:43 Windows Live Essentials
08-09-2014 20:40:24 DirectX wurde installiert
08-09-2014 20:40:53 DirectX wurde installiert
08-09-2014 20:41:50 WLSetup
08-09-2014 21:10:50 Installed iTunes
08-09-2014 21:28:57 Installed LibreOffice 4.2.6.3
08-09-2014 21:38:04 Windows Update
09-09-2014 20:57:44 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2013-03-29 17:33 - 00000027 ____N C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {20DFC9C0-A1D3-4230-AF81-8DA9ACC0FAF0} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-08-18] (AVAST Software)
Task: {42B946E9-114B-44C3-8A25-FAF7763EE29B} - System32\Tasks\DSite => C:\Users\Clara\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: {4A306C99-ACC0-420F-A7B7-92CF3FD63683} - \DealPly No Task File <==== ATTENTION
Task: {AD9D9278-89A5-4888-A7A2-6314E2AD264F} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {B506B27E-9412-43DC-98AD-72D5769DEE45} - System32\Tasks\{ABC52F34-3B10-4182-842B-10A59CFA82A1} => Chrome.exe hxxp://www.skype.com/go/downloading?source=lightinstaller&ver=5.1.0.104&LastError=404
Task: {C538C7C3-D158-4D17-9FD4-84554833738B} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2971180534-3307857154-2361156270-1002UA => C:\Users\Clara\AppData\Local\Google\Update\GoogleUpdate.exe [2013-01-14] (Google Inc.)
Task: {DED55E6E-7C1F-48B6-BB4C-577CA530A861} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-14] (Google Inc.)
Task: {E54EEBDA-B88A-4FDE-8EF9-AD8670F488B3} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe <==== ATTENTION
Task: {EDBFD3A7-21E6-4CB5-A009-B5EE279F5585} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {F572A1FA-AD53-48CB-868E-0DE7EB49AFEA} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2971180534-3307857154-2361156270-1002Core => C:\Users\Clara\AppData\Local\Google\Update\GoogleUpdate.exe [2013-01-14] (Google Inc.)
Task: {F67B7B9F-C6E6-4138-BF0B-CD4A5A370669} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-07-14] (Google Inc.)
Task: {FB545AD8-C41E-42DD-9190-EA6B702D8B0F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-09-09] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DSite.job => C:\Users\Clara\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2971180534-3307857154-2361156270-1002Core.job => C:\Users\Clara\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2971180534-3307857154-2361156270-1002UA.job => C:\Users\Clara\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2011-09-16 03:46 - 2011-09-16 03:46 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2011-11-10 22:15 - 2009-12-19 01:40 - 00104968 _____ () C:\Program Files (x86)\PHotkey\ASLDRSrv.exe
2011-11-10 22:15 - 2011-10-14 00:38 - 00156672 _____ () C:\Program Files (x86)\PHotkey\GFNEXSrv.exe
2011-03-09 11:41 - 2011-03-09 11:41 - 01066896 _____ () C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe
2011-03-09 11:41 - 2011-03-09 11:41 - 00491920 _____ () C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSC.exe
2011-11-10 21:16 - 2013-10-23 10:20 - 00102176 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2011-11-10 22:15 - 2011-10-14 21:06 - 00818688 _____ () C:\Program Files (x86)\PHotkey\PHotkey.exe
2011-11-10 22:15 - 2010-01-13 03:36 - 00117256 _____ () C:\Program Files (x86)\PHotkey\MsgTranAgt.exe
2011-11-10 22:15 - 2010-01-13 03:36 - 00121864 _____ () C:\Program Files (x86)\PHotkey\MsgTranAgt64.exe
2011-11-10 22:15 - 2010-12-18 00:04 - 00449032 _____ () C:\Program Files (x86)\PHotkey\ATouch64.exe
2011-11-10 22:15 - 2010-12-28 00:14 - 00776200 _____ () C:\Program Files (x86)\PHotkey\PVDesktop.exe
2011-11-10 22:15 - 2011-04-13 00:32 - 00483336 _____ () C:\Program Files (x86)\PHotkey\PVDAgent.exe
2011-09-16 03:46 - 2011-09-16 03:46 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2011-11-10 01:32 - 2011-09-26 00:36 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-11-10 22:15 - 2011-10-24 23:59 - 03420160 _____ () C:\Program Files (x86)\PHotkey\POSD.exe
2014-08-18 17:15 - 2014-08-18 17:15 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll
2014-09-09 22:33 - 2014-09-09 22:33 - 02847744 _____ () C:\Program Files\AVAST Software\Avast\defs\14090902\algo.dll
2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2010-03-05 09:24 - 2010-03-05 09:24 - 00886272 _____ () C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\System.Data.SQLite.dll
2011-11-10 22:15 - 2009-12-19 01:36 - 00973432 _____ () C:\Program Files (x86)\PHotkey\acAuth.dll
2011-11-10 22:15 - 2009-12-19 01:41 - 00129544 _____ () C:\Program Files (x86)\PHotkey\GFNEX.dll
2013-09-14 07:51 - 2013-09-14 07:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\zlib1.dll
2013-09-14 07:50 - 2013-09-14 07:50 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\libxml2.dll
2014-08-18 17:15 - 2014-08-18 17:15 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-09-09 23:33 - 2014-09-09 23:33 - 00043008 _____ () c:\users\clara\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpjbmqem.dll
2013-08-23 21:01 - 2013-08-23 21:01 - 25100288 _____ () C:\Users\Clara\AppData\Roaming\Dropbox\bin\libcef.dll
2011-11-10 20:17 - 2011-05-20 20:05 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2014-09-04 21:45 - 2014-08-30 04:49 - 01098056 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.103\libglesv2.dll
2014-09-04 21:44 - 2014-08-30 04:49 - 00174408 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.103\libegl.dll
2014-09-04 21:45 - 2014-08-30 04:49 - 08577864 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.103\pdf.dll
2014-09-04 21:47 - 2014-08-30 04:49 - 00331592 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.103\ppGoogleNaClPluginChrome.dll
2014-09-04 21:44 - 2014-08-30 04:49 - 01660232 _____ () C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.103\ffmpegsumo.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
MSCONFIG\startupreg: Akamai NetSession Interface => "C:\Users\Clara\AppData\Local\Akamai\netsession_win.exe"
MSCONFIG\startupreg: BTMTrayAgent => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
MSCONFIG\startupreg: EPLTarget =>
MSCONFIG\startupreg: Google Update => "C:\Users\Clara\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (09/09/2014 11:30:35 PM) (Source: MemeoBackgroundService) (EventID: 0) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
--- Ende der internen Ausnahmestapelüberwachung ---
bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)
Error: (09/09/2014 10:32:01 PM) (Source: MemeoBackgroundService) (EventID: 0) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
--- Ende der internen Ausnahmestapelüberwachung ---
bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)
Error: (09/08/2014 11:10:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AppleMobileDeviceService.exe, Version: 17.327.4.35, Zeitstempel: 0x52fa24ee
Name des fehlerhaften Moduls: AppleMobileDeviceService_main.dll, Version: 17.327.4.35, Zeitstempel: 0x539a62a9
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00009ae0
ID des fehlerhaften Prozesses: 0xa0c
Startzeit der fehlerhaften Anwendung: 0xAppleMobileDeviceService.exe0
Pfad der fehlerhaften Anwendung: AppleMobileDeviceService.exe1
Pfad des fehlerhaften Moduls: AppleMobileDeviceService.exe2
Berichtskennung: AppleMobileDeviceService.exe3
Error: (09/08/2014 10:40:19 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Program Files (x86)\Common Files\Windows Live\.cache\825495cf1ce2f1003\DXSETUP.exe Files (x86)\Common Files\Windows Live\.cache\825495cf1ce2f1003\DXSETUP.exe" /silent ; Beschreibung = DirectX wurde installiert; Fehler = 0x80042319).
Error: (09/08/2014 10:39:15 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: Clara-Computer)
Description: Die Anwendung oder der Dienst "Windows Search" konnte nicht heruntergefahren werden.
Error: (09/08/2014 08:26:09 PM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: Die Sicherung wurde aufgrund eines Fehlers beim Schreiben am Sicherungsspeicherort "F:\" nicht abgeschlossen. Fehler: "Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)"
Error: (09/05/2014 01:35:24 AM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Nur zur Information.
Error: Falscher Parameter.
ErrorCode: 14007(0x36b7).
Error: (09/05/2014 01:23:10 AM) (Source: MsiInstaller) (EventID: 1023) (User: Clara-Computer)
Description: Produkt: Adobe Reader XI (11.0.07) - Update "{AC76BA86-7AD7-0000-2550-7A8C40011008}" konnte nicht installiert werden. Fehlercode 1625. Weitere Informationen sind in der Protokolldatei C:\Users\Clara\AppData\Local\Temp\MSI3d2d8.LOG enthalten.
Error: (09/05/2014 01:20:08 AM) (Source: MemeoBackgroundService) (EventID: 0) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
--- Ende der internen Ausnahmestapelüberwachung ---
bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)
Error: (09/04/2014 09:10:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: WDFME.exe, Version: 1.4.5.2, Zeitstempel: 0x4d77d26b
Name des fehlerhaften Moduls: MSVCR90.dll, Version: 9.0.30729.6161, Zeitstempel: 0x4dace5b9
Ausnahmecode: 0xc0000417
Fehleroffset: 0x0006ccd5
ID des fehlerhaften Prozesses: 0xf40
Startzeit der fehlerhaften Anwendung: 0xWDFME.exe0
Pfad der fehlerhaften Anwendung: WDFME.exe1
Pfad des fehlerhaften Moduls: WDFME.exe2
Berichtskennung: WDFME.exe3
System errors:
=============
Error: (09/09/2014 11:37:53 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {9E6E74C7-0E85-4D14-8851-7635E2C1C528}
Error: (09/09/2014 11:27:39 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}
Error: (09/09/2014 10:32:45 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "WD File Management Shadow Engine" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (09/09/2014 10:32:45 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst WD File Management Shadow Engine erreicht.
Error: (09/09/2014 10:31:46 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am 08.09.2014 um 23:44:36 unerwartet heruntergefahren.
Error: (09/08/2014 10:36:43 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden.
Error: (09/08/2014 10:36:42 PM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden.
Error: (09/08/2014 08:29:31 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Definition Update for Windows Defender - KB915597 (Definition 1.183.1682.0)
Error: (09/08/2014 08:23:04 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "NVIDIA Update Service Daemon" wurde nicht richtig gestartet.
Error: (09/08/2014 08:16:02 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "MemeoBackgroundService" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Microsoft Office Sessions:
=========================
Error: (09/09/2014 11:30:35 PM) (Source: MemeoBackgroundService) (EventID: 0) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
--- Ende der internen Ausnahmestapelüberwachung ---
bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)
Error: (09/09/2014 10:32:01 PM) (Source: MemeoBackgroundService) (EventID: 0) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
--- Ende der internen Ausnahmestapelüberwachung ---
bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)
Error: (09/08/2014 11:10:00 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: AppleMobileDeviceService.exe17.327.4.3552fa24eeAppleMobileDeviceService_main.dll17.327.4.35539a62a9c000000500009ae0a0c01cfcb90dd43cdf0C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exeC:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService_main.dll7dd3ca03-379c-11e4-a27a-4c809337333a
Error: (09/08/2014 10:40:19 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: C:\Program Files (x86)\Common Files\Windows Live\.cache\825495cf1ce2f1003\DXSETUP.exe Files (x86)\Common Files\Windows Live\.cache\825495cf1ce2f1003\DXSETUP.exe" /silent DirectX wurde installiert0x80042319
Error: (09/08/2014 10:39:15 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: Clara-Computer)
Description: 1SearchIndexer.exeWindows Search0302621614360
Error: (09/08/2014 08:26:09 PM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: F:\Der Sicherungsort wurde nicht gefunden oder ist ungültig. Überprüfen Sie die Sicherungseinstellungen und den Sicherungsort. (0x81000006)
Error: (09/05/2014 01:35:24 AM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Error: Falscher Parameter.
ErrorCode: 14007(0x36b7).
Error: (09/05/2014 01:23:10 AM) (Source: MsiInstaller) (EventID: 1023) (User: Clara-Computer)
Description: Adobe Reader XI (11.0.07){AC76BA86-7AD7-0000-2550-7A8C40011008}1625C:\Users\Clara\AppData\Local\Temp\MSI3d2d8.LOG(NULL)(NULL)
Error: (09/05/2014 01:20:08 AM) (Source: MemeoBackgroundService) (EventID: 0) (User: )
Description: Problem starting Memeo Background Service :Ausnahmefehler "System.Reflection.TargetInvocationException: Ein Aufrufziel hat einen Ausnahmefehler verursacht. ---> System.Security.Principal.IdentityNotMappedException: Manche oder alle Identitätsverweise konnten nicht übersetzt werden.
bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel.StartListening(Object data)
bei System.Runtime.Remoting.Channels.Ipc.IpcServerChannel..ctor(IDictionary properties, IServerChannelSinkProvider sinkProvider, CommonSecurityDescriptor securityDescriptor)
bei System.Runtime.Remoting.Channels.Ipc.IpcChannel..ctor(IDictionary properties, IClientChannelSinkProvider clientSinkProvider, IServerChannelSinkProvider serverSinkProvider)
--- Ende der internen Ausnahmestapelüberwachung ---
bei System.RuntimeMethodHandle._InvokeConstructor(Object[] args, SignatureStruct& signature, IntPtr declaringType)
bei System.Reflection.RuntimeConstructorInfo.Invoke(BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)
bei System.RuntimeType.CreateInstanceImpl(BindingFlags bindingAttr, Binder binder, Object[] args, CultureInfo culture, Object[] activationAttributes)
bei System.Runtime.Remoting.RemotingConfigHandler.CreateChannelFromConfigEntry(ChannelEntry entry)
bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureChannels(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)" bei der Remotekonfiguration. bei System.Runtime.Remoting.RemotingConfigHandler.ConfigureRemoting(RemotingXmlConfigFileData configData, Boolean ensureSecurity)
bei System.Runtime.Remoting.RemotingConfiguration.Configure(String filename, Boolean ensureSecurity)
bei RemoteServerService.MemeoBackgroundService.OnStart(String[] args)
Error: (09/04/2014 09:10:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: WDFME.exe1.4.5.24d77d26bMSVCR90.dll9.0.30729.61614dace5b9c00004170006ccd5f4001cfc871a2853f2cC:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exeC:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll2d285f25-3467-11e4-a7f5-4c809337333a
CodeIntegrity Errors:
===================================
Date: 2013-03-29 16:29:01.287
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
Date: 2013-03-29 16:29:01.240
Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3-2350M CPU @ 2.30GHz
Percentage of memory in use: 57%
Total physical RAM: 4007.05 MB
Available physical RAM: 1702.46 MB
Total Pagefile: 8012.29 MB
Available Pagefile: 5393.26 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB
==================== Drives ================================
Drive c: (Boot) (Fixed) (Total:404.66 GB) (Free:63.64 GB) NTFS
Drive d: (Recover) (Fixed) (Total:60 GB) (Free:29.93 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 2BD2C32A)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=404.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=60 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=1 GB) - (Type=12)
Und nun noch GMER Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-09-10 00:13:26
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST950042 rev.0002 465,76GB
Running: Gmer-19357.exe; Driver: C:\Users\Clara\AppData\Local\Temp\kwldykoc.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80002ffd000 45 bytes [00, 10, 00, 00, 00, 00, 00, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575 fffff80002ffd02f 23 bytes [00, 00, 10, 00, 00, 00, 00, ...]
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\winlogon.exe[696] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076bfef8d 1 byte [62]
.text C:\Windows\System32\svchost.exe[540] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076bfef8d 1 byte [62]
.text C:\Windows\system32\svchost.exe[768] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076bfef8d 1 byte [62]
.text C:\Windows\system32\svchost.exe[1272] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076bfef8d 1 byte [62]
.text C:\Windows\system32\WLANExt.exe[1448] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076bfef8d 1 byte [62]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1196] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007600a2fd 1 byte [62]
.text C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe[2192] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007600a2fd 1 byte [62]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2484] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076bfef8d 1 byte [62]
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[2952] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007600a2fd 1 byte [62]
.text C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe[3316] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 000000007600a2fd 1 byte [62]
.text C:\Windows\System32\svchost.exe[3800] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076bfef8d 1 byte [62]
.text C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe[4016] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007600a2fd 1 byte [62]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[4344] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007600a2fd 1 byte [62]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[3396] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076bfef8d 1 byte [62]
.text C:\Windows\Explorer.EXE[3152] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076bfef8d 1 byte [62]
.text C:\Program Files (x86)\PHotkey\PHotkey.exe[4596] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000075fe1f0e 7 bytes JMP 0000000166fc168b
.text C:\Program Files (x86)\PHotkey\PHotkey.exe[4596] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000075fe5bad 7 bytes JMP 0000000166fc11a4
.text C:\Program Files (x86)\PHotkey\PHotkey.exe[4596] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000075ff1409 7 bytes JMP 0000000166fc1280
.text C:\Program Files (x86)\PHotkey\PHotkey.exe[4596] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000075ffea45 7 bytes JMP 0000000166fc123a
.text C:\Program Files (x86)\PHotkey\PHotkey.exe[4596] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007600a2fd 1 byte [62]
.text C:\Program Files (x86)\PHotkey\PHotkey.exe[4596] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007600b21b 5 bytes JMP 0000000166fc15a0
.text C:\Program Files (x86)\PHotkey\PHotkey.exe[4596] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076088e24 7 bytes JMP 0000000166fc132f
.text C:\Program Files (x86)\PHotkey\PHotkey.exe[4596] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076088ea9 5 bytes JMP 0000000166fc16cc
.text C:\Program Files (x86)\PHotkey\PHotkey.exe[4596] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000760891ff 1 byte JMP 0000000166fc1703
.text C:\Program Files (x86)\PHotkey\PHotkey.exe[4596] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW + 2 0000000076089201 3 bytes {JMP 0xfffffffff0f38504}
.text C:\Program Files (x86)\PHotkey\PHotkey.exe[4596] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000074c28a29 5 bytes JMP 0000000166fc171c
.text C:\Program Files (x86)\PHotkey\PHotkey.exe[4596] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000074c34572 5 bytes JMP 0000000166fc10a0
.text C:\Program Files (x86)\PHotkey\PHotkey.exe[4596] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000074c4e567 5 bytes JMP 0000000166fc140b
.text C:\Program Files (x86)\PHotkey\PHotkey.exe[4596] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000074c87a5c 5 bytes JMP 0000000166fc15c8
.text C:\Program Files (x86)\PHotkey\PHotkey.exe[4596] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000074a85ea5 5 bytes JMP 0000000166fc15f0
.text C:\Program Files (x86)\PHotkey\PHotkey.exe[4596] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000074ab9d0b 5 bytes JMP 0000000166fc1217
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[5288] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076bfef8d 1 byte [62]
.text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[5420] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076bfef8d 1 byte [62]
.text C:\Program Files\Windows Sidebar\sidebar.exe[5588] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076bfef8d 1 byte [62]
.text C:\Program Files (x86)\PHotkey\HCSynApi.exe[5732] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000074a85ea5 5 bytes JMP 0000000166fc15f0
.text C:\Program Files (x86)\PHotkey\HCSynApi.exe[5732] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000074ab9d0b 5 bytes JMP 0000000166fc1217
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5840] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000075fe1f0e 7 bytes JMP 0000000166fc168b
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5840] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000075fe5bad 7 bytes JMP 0000000166fc11a4
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5840] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000075ff1409 7 bytes JMP 0000000166fc1280
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5840] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000075ffea45 7 bytes JMP 0000000166fc123a
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5840] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007600a2fd 1 byte [62]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5840] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007600b21b 5 bytes JMP 0000000166fc15a0
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5840] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076088e24 7 bytes JMP 0000000166fc132f
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5840] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076088ea9 5 bytes JMP 0000000166fc16cc
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5840] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000760891ff 1 byte JMP 0000000166fc1703
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5840] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW + 2 0000000076089201 3 bytes {JMP 0xfffffffff0f38504}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5840] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000074c28a29 5 bytes JMP 0000000166fc171c
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5840] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000074c34572 5 bytes JMP 0000000166fc10a0
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5840] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000074c4e567 5 bytes JMP 0000000166fc140b
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[5840] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000074c87a5c 5 bytes JMP 0000000166fc15c8
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[5876] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000075fe1f0e 7 bytes JMP 0000000166fc168b
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[5876] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000075fe5bad 7 bytes JMP 0000000166fc11a4
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[5876] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000075ff1409 7 bytes JMP 0000000166fc1280
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[5876] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000075ffea45 7 bytes JMP 0000000166fc123a
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[5876] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007600a2fd 1 byte [62]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[5876] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007600b21b 5 bytes JMP 0000000166fc15a0
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[5876] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076088e24 7 bytes JMP 0000000166fc132f
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[5876] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076088ea9 5 bytes JMP 0000000166fc16cc
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[5876] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000760891ff 1 byte JMP 0000000166fc1703
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[5876] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW + 2 0000000076089201 3 bytes {JMP 0xfffffffff0f38504}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[5876] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000760f1d29 5 bytes JMP 0000000166fc11bd
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[5876] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000760f1dd7 5 bytes JMP 0000000166fc1014
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[5876] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000760f2ab1 5 bytes JMP 0000000166fc154b
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[5876] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000760f2d17 5 bytes JMP 0000000166fc1267
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[5876] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000074c28a29 5 bytes JMP 0000000166fc171c
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[5876] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000074c34572 5 bytes JMP 0000000166fc10a0
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[5876] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000074c4e567 5 bytes JMP 0000000166fc140b
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[5876] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000074c87a5c 5 bytes JMP 0000000166fc15c8
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[4328] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076bfef8d 1 byte [62]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[6224] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076bfef8d 1 byte [62]
.text C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe[6244] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000075fe1f0e 7 bytes JMP 0000000166fc168b
.text C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe[6244] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000075fe5bad 7 bytes JMP 0000000166fc11a4
.text C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe[6244] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000075ff1409 7 bytes JMP 0000000166fc1280
.text C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe[6244] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000075ffea45 7 bytes JMP 0000000166fc123a
.text C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe[6244] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007600a2fd 1 byte [62]
.text C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe[6244] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007600b21b 5 bytes JMP 0000000166fc15a0
.text C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe[6244] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076088e24 7 bytes JMP 0000000166fc132f
.text C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe[6244] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076088ea9 5 bytes JMP 0000000166fc16cc
.text C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe[6244] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000760891ff 1 byte JMP 0000000166fc1703
.text C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe[6244] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW + 2 0000000076089201 3 bytes {JMP 0xfffffffff0f38504}
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[6644] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000075fe1f0e 7 bytes JMP 0000000166fc168b
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[6644] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000075fe5bad 7 bytes JMP 0000000166fc11a4
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[6644] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000075fe8791 8 bytes [31, C0, C2, 04, 00, 90, 90, ...]
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[6644] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000075ff1409 7 bytes JMP 0000000166fc1280
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[6644] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000075ffea45 7 bytes JMP 0000000166fc123a
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[6644] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007600a2fd 1 byte [62]
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[6644] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007600b21b 5 bytes JMP 0000000166fc15a0
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[6644] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076088e24 7 bytes JMP 0000000166fc132f
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[6644] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076088ea9 5 bytes JMP 0000000166fc16cc
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[6644] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000760891ff 1 byte JMP 0000000166fc1703
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[6644] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW + 2 0000000076089201 3 bytes {JMP 0xfffffffff0f38504}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[6660] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000075fe1f0e 7 bytes JMP 0000000166fc168b
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[6660] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000075fe5bad 7 bytes JMP 0000000166fc11a4
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[6660] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000075ff1409 7 bytes JMP 0000000166fc1280
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[6660] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000075ffea45 7 bytes JMP 0000000166fc123a
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[6660] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007600a2fd 1 byte [62]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[6660] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007600b21b 5 bytes JMP 0000000166fc15a0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[6660] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076088e24 7 bytes JMP 0000000166fc132f
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[6660] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076088ea9 5 bytes JMP 0000000166fc16cc
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[6660] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000760891ff 1 byte JMP 0000000166fc1703
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[6660] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW + 2 0000000076089201 3 bytes {JMP 0xfffffffff0f38504}
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[6748] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000074c28a29 5 bytes JMP 0000000166fc171c
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[6748] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000074c34572 5 bytes JMP 0000000166fc10a0
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[6748] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000074c4e567 5 bytes JMP 0000000166fc140b
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[6748] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000074c87a5c 5 bytes JMP 0000000166fc15c8
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe[7056] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000075fe1f0e 7 bytes JMP 0000000166fc168b
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe[7056] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000075fe5bad 7 bytes JMP 0000000166fc11a4
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe[7056] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000075ff1409 7 bytes JMP 0000000166fc1280
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe[7056] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000075ffea45 7 bytes JMP 0000000166fc123a
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe[7056] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007600a2fd 1 byte [62]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe[7056] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007600b21b 5 bytes JMP 0000000166fc15a0
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe[7056] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076088e24 7 bytes JMP 0000000166fc132f
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe[7056] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076088ea9 5 bytes JMP 0000000166fc16cc
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe[7056] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000760891ff 1 byte JMP 0000000166fc1703
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe[7056] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW + 2 0000000076089201 3 bytes {JMP 0xfffffffff0f38504}
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe[7056] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000074c28a29 5 bytes JMP 0000000166fc171c
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe[7056] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000074c34572 5 bytes JMP 0000000166fc10a0
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe[7056] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000074c4e567 5 bytes JMP 0000000166fc140b
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe[7056] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000074c87a5c 5 bytes JMP 0000000166fc15c8
.text C:\Users\Clara\AppData\Roaming\Dropbox\bin\Dropbox.exe[5772] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000075fe1f0e 7 bytes JMP 0000000166fc168b
.text C:\Users\Clara\AppData\Roaming\Dropbox\bin\Dropbox.exe[5772] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000075fe5bad 7 bytes JMP 0000000166fc11a4
.text C:\Users\Clara\AppData\Roaming\Dropbox\bin\Dropbox.exe[5772] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000075ff1409 7 bytes JMP 0000000166fc1280
.text C:\Users\Clara\AppData\Roaming\Dropbox\bin\Dropbox.exe[5772] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000075ffea45 7 bytes JMP 0000000166fc123a
.text C:\Users\Clara\AppData\Roaming\Dropbox\bin\Dropbox.exe[5772] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007600a2fd 1 byte [62]
.text C:\Users\Clara\AppData\Roaming\Dropbox\bin\Dropbox.exe[5772] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007600b21b 5 bytes JMP 0000000166fc15a0
.text C:\Users\Clara\AppData\Roaming\Dropbox\bin\Dropbox.exe[5772] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076088e24 7 bytes JMP 0000000166fc132f
.text C:\Users\Clara\AppData\Roaming\Dropbox\bin\Dropbox.exe[5772] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076088ea9 5 bytes JMP 0000000166fc16cc
.text C:\Users\Clara\AppData\Roaming\Dropbox\bin\Dropbox.exe[5772] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000760891ff 1 byte JMP 0000000166fc1703
.text C:\Users\Clara\AppData\Roaming\Dropbox\bin\Dropbox.exe[5772] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW + 2 0000000076089201 3 bytes {JMP 0xfffffffff0f38504}
.text C:\Users\Clara\AppData\Roaming\Dropbox\bin\Dropbox.exe[5772] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000760f1d29 5 bytes JMP 0000000166fc11bd
.text C:\Users\Clara\AppData\Roaming\Dropbox\bin\Dropbox.exe[5772] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000760f1dd7 5 bytes JMP 0000000166fc1014
.text C:\Users\Clara\AppData\Roaming\Dropbox\bin\Dropbox.exe[5772] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000760f2ab1 5 bytes JMP 0000000166fc154b
.text C:\Users\Clara\AppData\Roaming\Dropbox\bin\Dropbox.exe[5772] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000760f2d17 5 bytes JMP 0000000166fc1267
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[7472] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 000000007600a2fd 1 byte [62]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[720] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007600a2fd 1 byte [62]
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000075fe1f0e 7 bytes JMP 0000000166fc168b
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000075fe5bad 7 bytes JMP 0000000166fc11a4
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000075ff1409 7 bytes JMP 0000000166fc1280
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000075ffea45 7 bytes JMP 0000000166fc123a
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007600a2fd 1 byte [62]
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007600b21b 5 bytes JMP 0000000166fc15a0
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076088e24 7 bytes JMP 0000000166fc132f
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076088ea9 5 bytes JMP 0000000166fc16cc
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000760891ff 1 byte JMP 0000000166fc1703
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW + 2 0000000076089201 3 bytes {JMP 0xfffffffff0f38504}
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000760f1d29 5 bytes JMP 0000000166fc11bd
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000760f1dd7 5 bytes JMP 0000000166fc1014
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000760f2ab1 5 bytes JMP 0000000166fc154b
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000760f2d17 5 bytes JMP 0000000166fc1267
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 00000000762ee96b 5 bytes JMP 0000000166fc15b9
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 00000000762eeba5 5 bytes JMP 0000000166fc1181
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000074c28a29 5 bytes JMP 0000000166fc171c
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000074c34572 5 bytes JMP 0000000166fc10a0
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000074c4e567 5 bytes JMP 0000000166fc140b
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000074c87a5c 5 bytes JMP 0000000166fc15c8
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000074a85ea5 5 bytes JMP 0000000166fc15f0
.text C:\Users\Clara\Desktop\Gmer-19357.exe[6100] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000074ab9d0b 5 bytes JMP 0000000166fc1217
---- Threads - GMER 2.1 ----
Thread C:\Windows\System32\svchost.exe [3800:7756] 000007fef2779688
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3696:1556] 0000000075cb7587
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3696:3116] 0000000069c47712
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3696:3312] 0000000076ff2e65
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3696:8028] 0000000074a9d864
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3696:5944] 0000000076ff3e85
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3696:8076] 0000000076ff3e85
Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3696:4516] 0000000076ff3e85
---- Processes - GMER 2.1 ----
Library C:\Users\Clara\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll (*** suspicious ***) @ C:\Users\Clara\AppData\Roaming\Dropbox\bin\Dropbox.exe [5772](2014-08-15 18:46:08) 0000000003c00000
Library c:\users\clara\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpjbmqem.dll (*** suspicious ***) @ C:\Users\Clara\AppData\Roaming\Dropbox\bin\Dropbox.exe [5772](2014-09-09 21:33:47) 0000000004110000
Library C:\Users\Clara\AppData\Roaming\Dropbox\bin\libcef.dll (*** suspicious ***) @ C:\Users\Clara\AppData\Roaming\Dropbox\bin\Dropbox.exe [5772](2013-08-23 19:01:44) 000000005bd70000
Library C:\Users\Clara\AppData\Roaming\Dropbox\bin\icudt.dll (*** suspicious ***) @ C:\Users\Clara\AppData\Roaming\Dropbox\bin\Dropbox.exe [5772] (ICU Data DLL/The ICU Project)(2013-08-23 19:01:42) 000000005a240000
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00150080283d
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\4c809337333a
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\4c809337333a@d0176ac84815 0x32 0x90 0x47 0x78 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00150080283d (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\4c809337333a (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\4c809337333a@d0176ac84815 0x32 0x90 0x47 0x78 ...
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- |