| Cellschock |  01.02.2015 10:58 |        Windows Vista - Internet wird lahmgelegt, sobald sich Windows 7 Pc in den Router wählt    Liste der Anhänge anzeigen (Anzahl: 1)  Hallo,  
erstmal finde ich es toll, dass es so ein Forum gibt. Vielen Dank schon mal für die Hilfe!  
Das Problem fing bereits vor einem Jahr an. Mein Hauptrechner (Windows 7) machte faxen. Sobald er ins Internet ging, wurde das komplette Internet lahmgelegt. Jedoch nicht nur an diesem Rechner, sondern auch an allen anderen von meinen Geräten (Tablet, Handy, Notebook).  
Dann hab ich was Dummes gemacht und Registry Einträge gelöscht, obwohl ich davon eigentlich keine Ahnung habe. Als nichts mehr so richtig funktionierte, habe ich dann nacheinander Laufwerke des Rechners formatiert und Antivirenscans durchgeführt. Wobei ich mir nicht ganz sicher bin, ob ich das richtig gemacht habe. Hatte keine Recovery DVD, sondern nur ne ganz normale WIN7 Version, die ich mir mal bei Fritz bestellt hatte.   
Zu allem Übel funktionierte der PC nie wieder richtig und plötzlich wurde mir auch angezeigt, dass ich keine Original Windows Version hätte. Und gerade an dem Punkt bin ich mir unsicher. Das kann nämlich tatsächlich sein, da diese Firma Fritz oder Hardware-Fritz oder so ähnlich, damals sogar in den Medien war und beschuldigt wurde, illegale Kopien von Microsoft verkauft zu haben. Mein Internet ging jedenfalls wieder, wenn auch mehr schlecht als recht und obwohl mein Bildschirmschoner immer wieder auf einen schwarzen Bildschirm umgestellt wurde (Virus oder weil ich die Originalversion nicht habe?), war das ok für mich.   
Jetzt bin ich umgezogen, habe zwei neue WG-Mitbewohnerinnen und als ich mich mit dem besagten PC in den Router eingeloggt habe, gingen plötzlich wieder keine Geräte mehr. Ich habe den Rechner sofort vom Internet genommen und siehe, da...die Mädels meinen es funktioniert wieder alles. Ich habe ein wenig Angst, dass ich da jetzt ein Virus auf den Router übertragen haben könnte. Also mein Tablet läuft immer noch recht langsam, wobei auch 3 Wände bis zum Router verlaufen. Könnte also auch die Entfernung sein. Das Routerpasswort ist das standardmäßig eingestellte...was ja eigentlich auch nicht so gut ist, gerade wenn man evtl einen Virus drauf hat.  
Ich poste jetzt hier die Log-Files meines Notebooks mit Windows Vista...soll ich die Log-Files auch von meinem verursachendem Rechner posten? Ist das notwendig? Wollte ihn nämlich eh nicht mehr ins Internet lassen und komplett formatieren mit einer neuen Windows 7 DVD. Normalerweise müsste dann dort doch auch alles runtergelöscht sein (auch Viren usw oder?).   
Und jetzt für mich die wichtigste und unangenehmste Angelegenheit: Ist es möglich, dass der Virus, den mein PC auf den Router übertragen haben könnte, wiederum auf die Rechner meiner Mitbewohnerinen übergeht?    Code:  
 defogger_disable by jpshortstuff (23.02.10.1) 
Log created at 10:01 on 01/02/2015 (admin)   
Checking for autostart values... 
HKCU\~\Run values retrieved. 
HKLM\~\Run values retrieved.   
Checking for services/drivers...     
-=E.O.F=-   
---------------------------   
FRST Logfile:  
FRST Logfile:   Code:  
 Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-02-2015 
Ran by admin (administrator) on USER-PC on 01-02-2015 10:03:07 
Running from C:\Users\admin\Desktop\Antivirus 
Loaded Profiles: admin (Available profiles: admin & user) 
Platform: Microsoft® Windows Vista™ Business  Service Pack 2 (X86) OS Language: Deutsch (Deutschland) 
Internet Explorer Version 9 (Default browser: Chrome) 
Boot Mode: Normal 
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/   
==================== Processes (Whitelisted) =================   
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)   
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe 
(Dell Inc.) C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE 
(Dell Inc.) C:\Program Files\Dell\DW WLAN Card\BCMWLTRY.EXE 
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe 
(Microsoft Corporation) C:\Windows\System32\wlanext.exe 
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe 
(Intel Corporation) C:\Windows\System32\hkcmd.exe 
(Intel Corporation) C:\Windows\System32\igfxpers.exe 
(Dell Inc.) C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE 
(Elaborate Bytes AG) C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe 
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe 
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe 
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe 
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe 
() C:\Program Files\Lexmark S800 Series\lxefmon.exe 
() C:\Program Files\Lexmark S800 Series\ezprint.exe 
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe 
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe 
(SlySoft, Inc.) C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe 
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe 
(Akamai Technologies, Inc.) C:\Users\admin\AppData\Local\Akamai\netsession_win.exe 
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe 
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe 
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe 
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe 
( ) C:\Windows\System32\lxefcoms.exe 
(Akamai Technologies, Inc.) C:\Users\admin\AppData\Local\Akamai\netsession_win.exe 
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe 
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe 
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe 
(Hewlett-Packard Co.) C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe 
(Hewlett-Packard) C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe 
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe 
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe 
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe 
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe 
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe 
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe 
(Microsoft Corporation) C:\Windows\System32\conime.exe 
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe 
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jucheck.exe 
(AceBIT GmbH) C:\Program Files\AceBIT\Password Depot 7\PasswordDepot.exe 
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe 
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe     
==================== Registry (Whitelisted) ==================   
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)   
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) 
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [5955072 2011-01-18] (Dell Inc.) 
HKLM\...\Run: [AnyProtect Scanner] => "C:\Program Files\AnyProtectEx\AnyProtect.exe" 
HKLM\...\Run: [VirtualCloneDrive] => C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG) 
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) 
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) 
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-09-11] (AVAST Software) 
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) 
HKLM\...\Run: [] => [X] 
HKLM\...\Run: [lxefmon.exe] => C:\Program Files\Lexmark S800 Series\lxefmon.exe [715368 2013-01-23] () 
HKLM\...\Run: [EzPrint] => C:\Program Files\Lexmark S800 Series\ezprint.exe [150272 2013-01-23] () 
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.) 
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) 
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation) 
HKLM\...\Run: [CloneCDTray] => C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe [57344 2009-01-29] (SlySoft, Inc.) 
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter 
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter 
HKU\S-1-5-21-2596615060-55448930-4252937802-1000\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter 
HKU\S-1-5-21-2596615060-55448930-4252937802-1000\...\Run: [Akamai NetSession Interface] => C:\Users\admin\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-29] (Akamai Technologies, Inc.) 
HKU\S-1-5-21-2596615060-55448930-4252937802-1000\...\Run: [Password Depot] => C:\Program Files\AceBIT\Password Depot 7\PasswordDepot.exe [12274336 2014-07-31] (AceBIT GmbH) 
HKU\S-1-5-21-2596615060-55448930-4252937802-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) 
HKU\S-1-5-21-2596615060-55448930-4252937802-1000\...\MountPoints2: {be5c1451-1f8e-11e4-863c-904ce51b9a26} - G:\LGAutoRun.exe 
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk 
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) 
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll (AVAST Software) 
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION 
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION   
==================== Internet (Whitelisted) ====================   
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)   
AutoConfigURL: [S-1-5-21-2596615060-55448930-4252937802-1000] => httP://gate-03.network.hs-anhalt/proxy.pac 
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank 
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.sweet-page.com/web/?type=ds&ts=1405815776&from=cor&uid=ST9160412ASG_5VG24J1DXXXX5VG24J1D&q={searchTerms} 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.sweet-page.com/web/?type=ds&ts=1405815776&from=cor&uid=ST9160412ASG_5VG24J1DXXXX5VG24J1D&q={searchTerms} 
HKU\S-1-5-21-2596615060-55448930-4252937802-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?publisher=YahooTU&dpid=YahooTU&co=DE&userid=c973019d-b8c5-4084-b4fc-2dc10698f54a&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp18000 
HKU\S-1-5-21-2596615060-55448930-4252937802-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank 
HKU\S-1-5-21-2596615060-55448930-4252937802-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.helperbar.com/?publisher=YahooTU&dpid=YahooTU&co=DE&userid=c973019d-b8c5-4084-b4fc-2dc10698f54a&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp18000 
SearchScopes: HKU\S-1-5-21-2596615060-55448930-4252937802-1000 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=YahooTU&dpid=YahooTU&co=DE&userid=c973019d-b8c5-4084-b4fc-2dc10698f54a&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp18000 
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} ->  No File 
BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) 
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) 
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation) 
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) 
BHO: Password Depot 7 -> {9F79B165-70F7-4C46-B1A5-8828E2FF21F9} -> C:\Program Files\AceBIT\Password Depot 7\pdIEAddOn32.dll (AceBIT) 
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) 
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation) 
BHO: No Name -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} ->  No File 
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) 
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1   
FireFox: 
======== 
FF ProfilePath: C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ze5vckjl.default 
FF DefaultSearchEngine: Google (avast) 
FF DefaultSearchUrl: https://www.google.com/search/?trackid=sp-006 
FF SearchEngineOrder.1: Google (avast) 
FF SelectedSearchEngine: Google (avast) 
FF Homepage: https://www.google.com/?trackid=sp-006 
FF Keyword.URL: https://www.google.com/search/?trackid=sp-006 
FF NetworkProxy: "autoconfig_url", "hxxp://gate-03.network.hs-anhalt.de/proxy.pac" 
FF NetworkProxy: "type", 2 
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () 
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) 
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation) 
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) 
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) 
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) 
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) 
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) 
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) 
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) 
FF SearchPlugin: C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ze5vckjl.default\searchplugins\google-avast.xml 
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension 
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-01-17] 
FF HKLM\...\Firefox\Extensions: [passworddepot@acebit.com] - C:\Program Files\AceBIT\Password Depot 7\Firefox 
FF Extension: Password Depot Extension - C:\Program Files\AceBIT\Password Depot 7\Firefox [2014-08-18] 
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF 
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-09-11] 
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-10-08] 
FF HKU\S-1-5-21-2596615060-55448930-4252937802-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3   
Chrome:  
======= 
CHR DefaultSuggestURL: Default -> hxxp://ssmsp.ask.com/query?sstype=prefix&li=ff&q={searchTerms} 
CHR Profile: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default 
CHR Extension: (Google Docs) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-07-20] 
CHR Extension: (Google Drive) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-07-20] 
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-10-20] 
CHR Extension: (YouTube) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-20] 
CHR Extension: (Adblock Plus) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-07-20] 
CHR Extension: (Google-Suche) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-20] 
CHR Extension: (Avast Online Security) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-09-11] 
CHR Extension: (Password Depot Add-On) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcgmdbhgeplifgopfnmafmhfmoekiekn [2014-08-05] 
CHR Extension: (Google Wallet) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-20] 
CHR Extension: (Bitdefender QuickScan) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie [2014-08-17] 
CHR Extension: (Google Mail) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-20] 
CHR HKLM\...\Chrome\Extension: [aaaaaiabcopkplhgaedhbloeejhhankf] - C:\ProgramData\AskPartnerNetwork\Toolbar\Shared\CRX\aaaaaiabcopkplhgaedhbloeejhhankf.crx [2014-11-24] 
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-09-11] 
CHR HKLM\...\Chrome\Extension: [mcgmdbhgeplifgopfnmafmhfmoekiekn] - C:\Program Files\AceBIT\Password Depot 7\crx.crx [2014-08-18] 
CHR HKLM\...\Chrome\Extension: [ocbnpbkmjpgbdcgiflkgkpnkinifpgpj] - C:\Users\admin\ChromeExtensions\ocbnpbkmjpgbdcgiflkgkpnkinifpgpj\amazon-icon-2.crx [2014-08-08]   
========================== Services (Whitelisted) =================   
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)   
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-09-11] (AVAST Software) 
S2 lxefCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxefserv.exe [189096 2010-09-09] (Lexmark International, Inc.) 
R2 lxef_device; C:\Windows\system32\lxefcoms.exe [598696 2010-09-09] ( ) 
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44032 2009-05-14] (Hewlett-Packard) [File not signed] 
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2009-05-14] (Hewlett-Packard) [File not signed] 
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation) 
R2 wltrysvc; C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe [5210112 2011-01-18] (Dell Inc.) [File not signed] 
S2 APNMCP; "C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe" [X]   
==================== Drivers (Whitelisted) ====================   
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)   
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-09-11] () 
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-09-11] (AVAST Software) 
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [55112 2014-09-11] (AVAST Software) 
R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-09-11] () 
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [779536 2014-11-22] (AVAST Software) 
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [414520 2014-09-11] (AVAST Software) 
R1 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [57800 2014-09-11] (AVAST Software) 
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [192352 2014-09-11] () 
R3 BCM42RLY; C:\Windows\System32\drivers\BCM42RLY.sys [18496 2011-01-18] (Broadcom Corporation) 
R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [34760 2007-02-16] (SlySoft, Inc.) 
R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [30616 2013-03-04] (Elaborate Bytes AG) 
R0 fsbts; C:\Windows\System32\Drivers\fsbts.sys [44240 2015-02-01] () 
S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project) 
S3 IpInIp; system32\DRIVERS\ipinip.sys [X] 
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] 
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]   
==================== NetSvcs (Whitelisted) ===================   
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)     
==================== One Month Created Files and Folders ========   
(If an entry is included in the fixlist, the file\folder will be moved.)   
2015-02-01 10:03 - 2015-02-01 10:03 - 00000000 ____D () C:\FRST 
2015-02-01 10:01 - 2015-02-01 10:01 - 00000000 _____ () C:\Users\admin\defogger_reenable 
2015-02-01 09:59 - 2015-02-01 10:03 - 00000000 ____D () C:\Users\admin\Desktop\Antivirus 
2015-02-01 00:47 - 2015-02-01 00:47 - 00044240 _____ () C:\Windows\system32\Drivers\fsbts.sys 
2015-02-01 00:36 - 2015-02-01 00:36 - 00002317 _____ () C:\Users\admin\Desktop\Windows 7 USB DVD Download Tool.lnk 
2015-02-01 00:36 - 2015-02-01 00:36 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool 
2015-02-01 00:36 - 2015-02-01 00:36 - 00000000 ____D () C:\Users\admin\AppData\Local\Apps\Windows 7 USB DVD Download Tool 
2015-02-01 00:35 - 2015-02-01 00:35 - 175000563 _____ () C:\Users\admin\Downloads\X17-59885.iso.crdownload 
2015-02-01 00:34 - 2015-02-01 00:34 - 02721168 _____ (Microsoft Corporation) C:\Users\admin\Downloads\Windows7-USB-DVD1024-tool.exe 
2015-02-01 00:22 - 2015-02-01 00:22 - 00000000 ____D () C:\ProgramData\F-Secure 
2015-02-01 00:16 - 2015-02-01 00:20 - 05176232 _____ (F-Secure Corporation) C:\Users\admin\Downloads\F-SecureOnlineScanner.exe 
2015-01-16 23:06 - 2015-01-16 23:06 - 00000000 ____D () C:\ProgramData\WindowsSearch 
2015-01-16 22:10 - 2015-01-16 22:10 - 00000000 ____D () C:\Windows\system32\X86 
2015-01-16 22:10 - 2015-01-16 22:10 - 00000000 ____D () C:\Windows\system32\AMD64 
2015-01-16 22:10 - 2015-01-16 22:10 - 00000000 ____D () C:\Program Files\EZDownloader 
2015-01-16 22:09 - 2015-01-16 22:09 - 00000000 ____D () C:\Program Files\youtubeadblocker 
2015-01-16 22:09 - 2015-01-16 22:09 - 00000000 ____D () C:\Program Files\User Agent Switcher 
2015-01-16 22:09 - 2015-01-16 22:09 - 00000000 ____D () C:\Program Files\unaisales 
2015-01-16 22:08 - 2015-01-16 22:08 - 00000000 ____D () C:\Program Files\unisaaleoS 
2015-01-16 22:07 - 2015-01-16 22:07 - 00000000 ____D () C:\ProgramData\jobcoaaahncbpmlbjligbdccnogkefol 
2015-01-16 22:06 - 2015-01-16 22:06 - 00000000 ____D () C:\ProgramData\{1e804cbe-bd44-9afd-1e80-04cbebd432fa} 
2015-01-16 22:06 - 2015-01-16 22:06 - 00000000 ____D () C:\Program Files\WinRAR 
2015-01-16 21:18 - 2015-01-16 21:31 - 00000006 _____ () C:\ScrubRetValFile.txt 
2015-01-15 23:05 - 2015-01-15 23:05 - 00251954 _____ () C:\Users\admin\Downloads\Spektren (2).xlsx 
2015-01-15 22:55 - 2015-01-16 02:26 - 00252029 _____ () C:\Users\admin\Downloads\Spektren (1).xlsx 
2015-01-15 14:11 - 2015-01-15 14:11 - 00000000 ____D () C:\Users\user.user-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP 
2015-01-15 10:24 - 2014-12-19 01:25 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 
2015-01-15 10:10 - 2014-12-06 04:14 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 
2015-01-15 10:10 - 2014-12-06 04:14 - 00153600 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 
2015-01-15 10:10 - 2014-12-06 04:14 - 00093184 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 
2015-01-15 10:10 - 2014-12-06 04:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 
2015-01-14 23:39 - 2015-01-14 23:39 - 00000000 ____D () C:\Program Files\Mozilla Firefox 
2015-01-13 23:15 - 2015-01-13 23:20 - 150363880 _____ () C:\Users\admin\Downloads\DJ_AIO_06_F4500_USW_Full_Win_WW_140_175-4 (1).exe 
2015-01-13 22:45 - 2015-01-13 22:57 - 150363880 _____ () C:\Users\admin\Downloads\DJ_AIO_06_F4500_USW_Full_Win_WW_140_175-4.exe 
2015-01-13 20:32 - 2015-01-13 20:34 - 00000000 ____D () C:\Users\admin\Desktop\Turtles 
2015-01-11 10:11 - 2015-01-11 10:11 - 00000000 ____D () C:\ProgramData\Canneverbe Limited 
2015-01-11 10:10 - 2015-01-11 10:10 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Canneverbe Limited 
2015-01-11 10:09 - 2015-01-11 10:09 - 05409016 _____ (Canneverbe Limited ) C:\Users\admin\Downloads\cdbxp_setup_4.5.4.5306_minimal.exe 
2015-01-11 10:09 - 2015-01-11 10:09 - 05409016 _____ (Canneverbe Limited ) C:\Users\admin\Downloads\cdbxp_setup_4.5.4.5306_minimal (1).exe 
2015-01-11 10:02 - 2015-01-11 10:22 - 00000000 ____D () C:\Users\admin\Documents\Nero Burning Rom 
2015-01-11 09:58 - 2015-01-11 09:58 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Nero 
2015-01-10 15:34 - 2015-01-10 15:34 - 00000072 _____ () C:\Windows\7889428C51A50091.log 
2015-01-10 11:54 - 2015-01-15 10:39 - 00000000 ____D () C:\ProgramData\Nero 
2015-01-10 11:49 - 2015-01-10 11:50 - 85828344 _____ (Nero AG) C:\Users\admin\Downloads\Nero_BurningROM2015_setup-16.0.02000_3p_trial.exe 
2015-01-10 11:45 - 2015-01-10 11:45 - 05185720 _____ () C:\Users\admin\Downloads\SetupCloneDVD2_CB-DL-Manager [1].exe 
2015-01-10 11:45 - 2015-01-10 11:45 - 00823792 _____ ( ) C:\Users\admin\Downloads\SetupCloneDVD2_CB-DL-Manager.exe 
2015-01-10 11:45 - 2015-01-10 11:45 - 00000000 ____D () C:\Users\admin\AppData\Local\Pirates 
2015-01-10 11:26 - 2015-01-10 11:33 - 648366432 _____ () C:\Users\admin\Desktop\IMAGE.img 
2015-01-10 11:26 - 2015-01-10 11:33 - 26463936 _____ () C:\Users\admin\Desktop\IMAGE.sub 
2015-01-10 11:26 - 2015-01-10 11:33 - 00002452 _____ () C:\Users\admin\Desktop\IMAGE.ccd 
2015-01-10 11:21 - 2015-01-10 11:49 - 00000126 ___SH () C:\ProgramData\.zreglib 
2015-01-10 11:21 - 2015-01-10 11:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlySoft 
2015-01-10 11:21 - 2015-01-10 11:21 - 00000000 ____D () C:\Program Files\SlySoft 
2015-01-10 11:19 - 2015-01-10 11:19 - 02734688 _____ () C:\Users\admin\Downloads\SetupCloneCD5314.exe 
2015-01-09 18:27 - 2015-01-09 18:27 - 00000000 ____D () C:\BIING! 
2015-01-09 18:19 - 2015-01-09 18:19 - 00000000 ____D () C:\Users\admin\AppData\Local\WinZip 
2015-01-09 18:18 - 2015-01-09 18:19 - 00000000 ____D () C:\ProgramData\WinZip 
2015-01-09 18:17 - 2015-01-09 18:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip 
2015-01-09 18:17 - 2015-01-09 18:18 - 00000000 ____D () C:\Program Files\WinZip 
2015-01-09 18:15 - 2015-01-09 18:16 - 60529152 _____ () C:\Users\admin\Downloads\wz190gev-32.msi 
2015-01-09 18:13 - 2015-01-09 18:25 - 00000000 ____D () C:\Biing 
2015-01-08 17:34 - 2015-01-08 17:34 - 00008590 _____ () C:\Users\admin\Downloads\winmail.dat   
==================== One Month Modified Files and Folders =======   
(If an entry is included in the fixlist, the file\folder will be moved.)   
2015-02-01 10:01 - 2014-03-28 15:23 - 00000000 ____D () C:\Users\admin 
2015-02-01 09:50 - 2008-01-21 02:39 - 01840225 _____ () C:\Windows\WindowsUpdate.log 
2015-02-01 09:40 - 2014-07-20 01:12 - 00002224 _____ () C:\Windows\Tasks\44f0d4e0-73bd-4bc1-a0b9-50e135daab47-4.job 
2015-02-01 09:40 - 2014-07-20 01:12 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 
2015-02-01 09:40 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 
2015-02-01 09:40 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 
2015-02-01 09:40 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 
2015-02-01 01:04 - 2006-11-02 14:01 - 00032514 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 
2015-02-01 00:26 - 2014-07-20 01:12 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 
2015-01-27 09:36 - 2014-07-20 03:11 - 00001963 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 
2015-01-27 09:33 - 2014-08-08 19:49 - 00000000 ____D () C:\ProgramData\Microsoft Help 
2015-01-26 17:29 - 2014-10-08 18:13 - 00000000 ____D () C:\Users\admin\AppData\Roaming\HpUpdate 
2015-01-26 17:16 - 2006-11-02 11:33 - 01565124 _____ () C:\Windows\system32\PerfStringBackup.INI 
2015-01-26 17:14 - 2006-11-02 13:52 - 00116742 _____ () C:\Windows\setupact.log 
2015-01-21 18:23 - 2014-11-29 11:28 - 00000000 ____D () C:\Users\admin\Desktop\Uni 
2015-01-18 12:03 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\Microsoft.NET 
2015-01-17 12:07 - 2014-08-18 10:07 - 00000000 ____D () C:\Users\admin\Documents\Password Depot 
2015-01-17 01:49 - 2014-09-23 16:42 - 18356934 _____ () C:\Users\admin\Downloads\s25rttr_20140724-9484_windows.i386.tar.bz2 
2015-01-17 01:49 - 2014-09-23 16:40 - 17321176 _____ () C:\Users\admin\Downloads\s25rttr_0.8.1-9016_windows.i386.tar.bz2 
2015-01-17 00:27 - 2014-07-20 01:23 - 00000000 ____D () C:\ProgramData\IePluginServices 
2015-01-16 23:14 - 2014-08-08 17:09 - 00000000 ____D () C:\ProgramData\KMSAutoS 
2015-01-16 23:14 - 2014-08-08 17:00 - 00008240 _____ () C:\Windows\certutil.log 
2015-01-16 22:37 - 2014-09-11 07:07 - 00001873 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 
2015-01-16 22:34 - 2014-03-28 15:24 - 00107216 _____ () C:\Users\admin\AppData\Local\GDIPFONTCACHEV1.DAT 
2015-01-16 22:32 - 2014-08-08 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 
2015-01-16 22:32 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\Msdtc 
2015-01-16 22:31 - 2014-08-08 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint 
2015-01-16 22:31 - 2014-08-08 19:49 - 00000000 __RHD () C:\MSOCache 
2015-01-16 22:31 - 2014-08-08 19:49 - 00000000 ____D () C:\Program Files\Microsoft Office 
2015-01-16 22:31 - 2014-08-08 15:04 - 00000000 ____D () C:\Users\admin\AppData\Local\Akamai 
2015-01-16 22:31 - 2014-07-20 10:05 - 00000000 ____D () C:\Users\user.user-PC 
2015-01-16 22:31 - 2006-11-02 13:37 - 00000000 ____D () C:\Windows\ShellNew 
2015-01-16 22:31 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\system32\spool 
2015-01-16 22:31 - 2006-11-02 12:18 - 00000000 ____D () C:\Windows\registration 
2015-01-16 22:31 - 2006-11-02 12:18 - 00000000 ____D () C:\Program Files\Common Files\System 
2015-01-16 22:31 - 2006-11-02 12:18 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 
2015-01-16 22:31 - 2006-11-02 11:22 - 48234496 _____ () C:\Windows\system32\config\software_previous 
2015-01-16 22:31 - 2006-11-02 11:22 - 38273024 _____ () C:\Windows\system32\config\components_previous 
2015-01-16 22:31 - 2006-11-02 11:22 - 30932992 _____ () C:\Windows\system32\config\system_previous 
2015-01-16 22:31 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\security_previous 
2015-01-16 22:31 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\sam_previous 
2015-01-16 22:31 - 2006-11-02 11:22 - 00262144 _____ () C:\Windows\system32\config\default_previous 
2015-01-16 22:11 - 2014-08-17 18:16 - 00000000 ____D () C:\Users\admin\AppData\Roaming\QuickScan 
2015-01-16 21:25 - 2014-08-07 08:23 - 00000000 ____D () C:\ProgramData\Microsoft Toolkit 
2015-01-16 21:22 - 2014-08-08 19:52 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 8 
2015-01-16 17:06 - 2014-10-14 10:45 - 00000000 ____D () C:\Users\admin\AppData\Local\Apple Computer 
2015-01-16 07:38 - 2014-11-20 11:53 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 
2015-01-15 14:10 - 2014-07-20 10:06 - 00107216 _____ () C:\Users\user.user-PC\AppData\Local\GDIPFONTCACHEV1.DAT 
2015-01-15 10:32 - 2014-07-20 00:29 - 00000000 ____D () C:\ProgramData\Package Cache 
2015-01-15 10:24 - 2014-08-14 22:59 - 00000000 ____D () C:\Windows\system32\MRT 
2015-01-15 10:11 - 2006-11-02 11:24 - 110348472 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 
2015-01-14 11:22 - 2014-10-19 16:54 - 00000000 ____D () C:\ProgramData\Lx_cats 
2015-01-13 23:53 - 2014-07-20 01:17 - 00000000 ____D () C:\Users\admin\Documents\Eigene Scans 
2015-01-13 23:25 - 2014-07-20 01:07 - 00230583 _____ () C:\Windows\hpoins46.dat 
2015-01-13 23:25 - 2014-07-20 01:07 - 00002447 _____ () C:\ProgramData\hpzinstall.log 
2015-01-12 12:45 - 2014-08-08 16:00 - 00000000 ____D () C:\Users\admin\Desktop\Sonstiges 
2015-01-10 18:25 - 2006-11-02 14:00 - 00238336 _____ () C:\Windows\PFRO.log 
2015-01-10 11:50 - 2014-08-08 19:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes 
2015-01-10 11:50 - 2014-08-08 19:22 - 00000000 ____D () C:\Program Files\Elaborate Bytes 
2015-01-07 23:12 - 2014-08-16 20:11 - 00000000 ____D () C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP 
2015-01-06 04:36 - 2014-07-20 01:14 - 00249488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 
2015-01-05 12:51 - 2014-08-08 19:49 - 00000000 ____D () C:\Users\admin\AppData\Local\Microsoft Help 
2015-01-04 22:53 - 2014-12-28 20:12 - 00000000 ____D () C:\starcraft   
==================== Files in the root of some directories =======   
2014-07-20 01:22 - 2014-07-16 14:41 - 0573339 _____ (ClickMeIn Limited) C:\Users\admin\AppData\Local\AnyProtectScannerSetup.exe 
2014-07-20 01:54 - 2014-07-20 01:54 - 2580480 _____ () C:\Users\admin\AppData\Local\bpckxdre.exe 
2014-03-28 15:24 - 2014-03-28 15:28 - 0000680 _____ () C:\Users\admin\AppData\Local\d3d9caps.dat 
2014-11-24 20:18 - 2014-12-28 19:49 - 0013312 _____ () C:\Users\admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 
2015-01-10 11:21 - 2015-01-10 11:49 - 0000126 ___SH () C:\ProgramData\.zreglib 
2014-10-19 16:55 - 2014-10-19 16:55 - 0000252 _____ () C:\ProgramData\FastPics.log 
2014-07-20 01:07 - 2015-01-13 23:25 - 0002447 _____ () C:\ProgramData\hpzinstall.log 
2014-10-19 16:49 - 2014-10-19 16:49 - 0000000 _____ () C:\ProgramData\UpdaterLog.txt   
Some content of TEMP: 
==================== 
C:\Users\admin\AppData\Local\Temp\amazonicon_v8.exe 
C:\Users\admin\AppData\Local\Temp\amazoninstallernircmdc.exe 
C:\Users\admin\AppData\Local\Temp\APNSetup.exe 
C:\Users\admin\AppData\Local\Temp\avgnt.exe 
C:\Users\admin\AppData\Local\Temp\bitool.dll 
C:\Users\admin\AppData\Local\Temp\FP_AX_MSI_INSTALLER.exe 
C:\Users\admin\AppData\Local\Temp\FreeWebMVideoConverter.exe 
C:\Users\admin\AppData\Local\Temp\PidGenX.dll 
C:\Users\admin\AppData\Local\Temp\sdanircmdc.exe 
C:\Users\admin\AppData\Local\Temp\sdapskill.exe 
C:\Users\admin\AppData\Local\Temp\sdaspwn.exe 
C:\Users\admin\AppData\Local\Temp\uninst.exe 
C:\Users\admin\AppData\Local\Temp\{05C319F9-4634-4C79-977F-29DE30EA5283}-36.0.1985.125_chrome_installer.exe 
C:\Users\user.user-PC\AppData\Local\Temp\avgnt.exe     
==================== Bamital & volsnap Check =================   
(There is no automatic fix for files that do not pass verification.)   
C:\Windows\explorer.exe => File is digitally signed 
C:\Windows\system32\winlogon.exe => File is digitally signed 
C:\Windows\system32\wininit.exe => File is digitally signed 
C:\Windows\system32\svchost.exe => File is digitally signed 
C:\Windows\system32\services.exe => File is digitally signed 
C:\Windows\system32\User32.dll => File is digitally signed 
C:\Windows\system32\userinit.exe => File is digitally signed 
C:\Windows\system32\rpcss.dll => File is digitally signed 
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed     
LastRegBack: 2015-02-01 09:46   
==================== End Of Log ============================   --- --- ---  
--- --- ---   
--------------------------------------------    Code:  
 Additional scan result of Farbar Recovery Scan Tool (x86) Version: 01-02-2015 
Ran by admin at 2015-02-01 10:04:58 
Running from C:\Users\admin\Desktop\Antivirus 
Boot Mode: Normal 
==========================================================     
==================== Security Center ========================   
(If an entry is included in the fixlist, it will be removed.)   
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} 
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} 
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}   
==================== Installed Programs ======================   
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)   
32 Bit HP CIO Components Installer (Version: 6.1.2 - Hewlett-Packard) Hidden 
7-Zip 9.20 (HKLM\...\7-Zip) (Version:  - ) 
Adobe Reader X (10.1.12) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.12 - Adobe Systems Incorporated) 
Akamai NetSession Interface (HKU\S-1-5-21-2596615060-55448930-4252937802-1000\...\Akamai) (Version:  - Akamai Technologies, Inc) 
Apple Application Support (HKLM\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.) 
Apple Mobile Device Support (HKLM\...\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.) 
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) 
avast! Free Antivirus (HKLM\...\Avast) (Version: 9.0.2021 - AVAST Software) 
Blender (HKLM\...\Blender) (Version: 2.71 - Blender Foundation) 
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) 
BufferChm (Version: 140.0.212.000 - Hewlett-Packard) Hidden 
Capitalism II (remove only) (HKLM\...\Capitalism II) (Version:  - ) 
Chaos Overlords (HKLM\...\GOGPACKCHAOSOVERLORDS_is1) (Version: 2.1.0.17 - GOG.com) 
chaosoverlords (HKLM\...\{16bdccc0-b956-42de-a044-27446f036f99}.sdb) (Version:  - ) 
Cisco EAP-FAST Module (Version: 2.2.14 - Cisco Systems, Inc.) Hidden 
Cisco LEAP Module (Version: 1.0.19 - Cisco Systems, Inc.) Hidden 
Cisco PEAP Module (Version: 1.1.6 - Cisco Systems, Inc.) Hidden 
CloneCD (HKLM\...\CloneCD) (Version:  - SlySoft) 
Copy (Version: 140.0.212.000 - Hewlett-Packard) Hidden 
DeviceDiscovery (Version: 140.0.212.000 - Hewlett-Packard) Hidden 
D-Fend Reloaded 1.4.2 (deinstallieren) (HKLM\...\D-Fend Reloaded) (Version: 1.4.2 - Alexander Herzog) 
DJ_AIO_06_F4500_SW_MIN (Version: 140.0.690.000 - Hewlett-Packard) Hidden 
DW WLAN Card Utility (HKLM\...\DW WLAN Card Utility) (Version: 5.100.235.13 - Dell Inc.) 
Edna Bricht Aus 6.3 (HKLM\...\{0D00CD3F-AEDC-45F1-A2DD-DADF74407D7B}_is1) (Version:  - ) 
Europäisches Arzneibuch (HKLM\...\Deutscher Apotheker Verlag_Arzneibuch_D) (Version:  - Deutscher Apotheker Verlag) 
Europäisches Arzneibuch 7 (HKLM\...\Deutscher Apotheker Verlag_Arzneibuch7_D_isbn_978_3_7692_5416_7_D) (Version:  - Deutscher Apotheker Verlag) 
F4500 (Version: 140.0.690.000 - Hewlett-Packard) Hidden 
FTL version 1.5.13 (HKLM\...\{20E23A40-38E5-4DD6-B738-BC8097AE66B6}_is1) (Version: 1.5.13 - Subset Games) 
Google Chrome (HKLM\...\Google Chrome) (Version: 40.0.2214.93 - Google Inc.) 
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden 
GPBaseService2 (Version: 140.0.211.000 - Hewlett-Packard) Hidden 
Hotline Miami version v1.0 (HKLM\...\{BA30996C-FB03-4395-BB50-727008597E5B}_is1) (Version: v1.0 - ) 
HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP) 
HP Deskjet F4500 All-in-One Driver Software 14.0 Rel. 6 (HKLM\...\{0AFFEA39-60AF-4C4F-BB47-4A1F7CB12129}) (Version: 14.0 - HP) 
HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP) 
HP Print Projects 1.0 (HKLM\...\HP Print Projects) (Version: 1.0 - HP) 
HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP) 
HP Update (HKLM\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard) 
hpPrintProjects (Version: 130.0.303.000 - Hewlett-Packard) Hidden 
HPProductAssistant (Version: 140.0.212.000 - Hewlett-Packard) Hidden 
HPSSupply (Version: 130.0.371.000 - Hewlett-Packard) Hidden 
hpWLPGInstaller (Version: 130.0.303.000 - Hewlett-Packard) Hidden 
Intel(R) Graphics Media Accelerator Driver (HKLM\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2555 - Intel Corporation) 
Intel(R) Network Connections Drivers (HKLM\...\PROSet) (Version: 14.5 - Intel) 
iTunes (HKLM\...\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.) 
Java 8 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation) 
Lexmark S800 Series (HKLM\...\Lexmark S800 Series) (Version:  - Lexmark International, Inc.) 
MarketResearch (Version: 140.0.212.000 - Hewlett-Packard) Hidden 
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version:  - Microsoft Corporation) 
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation) 
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) 
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) 
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation) 
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) 
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) 
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) 
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) 
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) 
Mozilla Firefox 34.0.5 (x86 de) (HKLM\...\Mozilla Firefox 34.0.5 (x86 de)) (Version: 34.0.5 - Mozilla) 
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 33.1.1 - Mozilla) 
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) 
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) 
Network (Version: 140.0.215.000 - Hewlett-Packard) Hidden 
OpenAL (HKLM\...\OpenAL) (Version:  - ) 
OpenOffice 4.1.0 (HKLM\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation) 
Papers, Please (HKLM\...\{428CF694-7D31-4C42-8F7D-7187F5EF6937}) (Version: 1.1.65 - 3909 LLC) 
Password Depot 7 (HKLM\...\{500F4898-C705-4B91-9C98-3D125330A022}_is1) (Version: 7.5.9 - AceBIT GmbH) 
QuickTime 7 (HKLM\...\{3D2CBC2C-65D4-4463-87AB-BB2C859C1F3E}) (Version: 7.76.80.95 - Apple Inc.) 
RICOH R5U241 / R5C847 Media Driver ver.2.04.01.00 (HKLM\...\{2B818257-E6C7-4841-8C29-C5C9A982BCE5}) (Version: 2.04.01.00 - RICOH) 
Scan (Version: 140.0.80.000 - Hewlett-Packard) Hidden 
Search App by Ask (HKLM\...\{4F524A2D-5350-4500-76A7-A758B70C1500}) (Version: 12.21.0.114 - APN, LLC) <==== ATTENTION 
SEGA Bass Fishing (HKLM\...\Steam App 71240) (Version:  - SEGA) 
SEGA Genesis & Mega Drive Classics (HKLM\...\Steam App 34270) (Version:  - Sega) 
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft) 
Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 13.0 - HP) 
SmartWebPrinting (Version: 140.0.186.000 - Hewlett-Packard) Hidden 
SolutionCenter (Version: 140.0.213.000 - Hewlett-Packard) Hidden 
Sonic & All-Stars Racing Transformed (HKLM\...\Steam App 212480) (Version:  - Sumo Digital) 
Status (Version: 140.0.212.000 - Hewlett-Packard) Hidden 
Steam (HKLM\...\Steam) (Version: 2.10.91.91 - Valve Corporation) 
StuffIt Expander 2011 (HKLM\...\{59E98F3F-48D6-42A9-8250-079671E02B2D}) (Version: 15.0.1.17 - Smith Micro Software, Inc.) 
Supporter 1.80 (HKLM\...\{5F189DF5-2D05-472B-9091-84D9848AE48B}{40030ae4}) (Version:  - Costmin) <==== ATTENTION 
Toolbox (Version: 140.0.428.000 - Hewlett-Packard) Hidden 
TrayApp (Version: 140.0.212.000 - Hewlett-Packard) Hidden 
VirtualCloneDrive (HKLM\...\VirtualCloneDrive) (Version: 5.4.7.0 - Elaborate Bytes) 
WebReg (Version: 140.0.212.017 - Hewlett-Packard) Hidden 
Windows 7 USB/DVD Download Tool (HKLM\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation) 
WinZip 19.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E4}) (Version: 19.0.11293 - WinZip Computing, S.L. ) 
Zip Motion Block Video codec (Remove Only) (HKLM\...\ZMBV) (Version:  - DOSBox Team)   
==================== Custom CLSID (selected items): ==========================   
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)   
CustomCLSID: HKU\S-1-5-21-2596615060-55448930-4252937802-1000_Classes\CLSID\{32C15893-74C0-4478-879B-FE14EB684AB4}\InprocServer32 -> C:\Users\admin\AppData\Local\Microsoft\Windows Sidebar\Gadgets\HPPhoto.gadget\x86\hpqgps01.dll (Hewlett-Packard Co.) 
CustomCLSID: HKU\S-1-5-21-2596615060-55448930-4252937802-1000_Classes\CLSID\{39C26CEE-9070-4B47-9261-6743499AFBF7}\InprocServer32 -> C:\Users\admin\AppData\Local\Microsoft\Windows Sidebar\Gadgets\HPPhoto.gadget\x86\hpqgutil.dll (Hewlett-Packard Co.) 
CustomCLSID: HKU\S-1-5-21-2596615060-55448930-4252937802-1000_Classes\CLSID\{9CC1FE07-02F9-49A6-A3F4-63AD8BAE9E49}\InprocServer32 -> C:\Users\admin\AppData\Local\Microsoft\Windows Sidebar\Gadgets\HPPhoto.gadget\x86\hpqgps01.dll (Hewlett-Packard Co.)   
==================== Restore Points  =========================   
16-01-2015 22:22:06 Wiederherstellungsvorgang 
16-01-2015 22:32:59 avast! antivirus system restore point 
17-01-2015 03:43:05 Windows Update 
17-01-2015 12:58:53 Windows Update 
18-01-2015 12:38:22 Geplanter Prüfpunkt 
19-01-2015 16:35:55 Geplanter Prüfpunkt 
21-01-2015 00:11:09 Geplanter Prüfpunkt 
21-01-2015 08:28:42 Windows Update 
22-01-2015 00:00:00 Geplanter Prüfpunkt 
27-01-2015 09:27:06 Windows Update 
31-01-2015 10:51:39 Windows Update 
01-02-2015 00:35:41 Installed Windows 7 USB/DVD Download Tool   
==================== Hosts content: ==========================   
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)   
2006-11-02 11:23 - 2006-09-18 22:41 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts 
127.0.0.1       localhost 
::1             localhost   
==================== Scheduled Tasks (whitelisted) =============   
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)   
Task: {2DA74EB2-7952-4EB7-AE07-8D1D0997A082} - System32\Tasks\PC Speed Maximizer Schedule => C:\Program Files\PC Speed Maximizer\SPMLauncher.exe 
Task: {39819532-D6E9-4798-B958-43E6DFE203DA} - System32\Tasks\KMSAutoNet => C:\ProgramData\KMSAutoS\KMSAuto Net.exe [2014-08-08] (MSfree Inc.) 
Task: {5457BDAE-3284-48E1-9A80-9023D90FD386} - System32\Tasks\Microsoft\Windows\WindowsCalendar\Reminders - admin => C:\Program Files\Windows Calendar\WinCal.exe [2009-04-11] (Microsoft Corporation) 
Task: {68B445DB-1619-42BC-BFD5-82449AE10683} - System32\Tasks\{1984A371-E849-4C67-A4D1-20FF1DB52C87} => pcalua.exe -a D:\INSTALL.EXE -d D:\ 
Task: {69C02AC9-5D7D-40FF-82B0-416548A28613} - System32\Tasks\{EDF8CAA6-25C9-439F-854B-9505D3B41C3A} => pcalua.exe -a C:\Users\admin\Downloads\tasten.exe -d C:\Users\admin\Downloads 
Task: {6F6E53CF-AC1F-4A93-8E04-D03B24821A1C} - System32\Tasks\44f0d4e0-73bd-4bc1-a0b9-50e135daab47-4 => C:\Program Files\HQual-V1.8\44f0d4e0-73bd-4bc1-a0b9-50e135daab47-4.exe <==== ATTENTION 
Task: {81C8DBAA-74DC-4D7F-B2E7-6BCFC12B96F4} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) 
Task: {9C86938D-A7FD-4231-8DCA-B6682878F206} - System32\Tasks\temp_44f0d4e0-73bd-4bc1-a0b9-50e135daab47-2 => C:\Program Files\HQual-V1.8\44f0d4e0-73bd-4bc1-a0b9-50e135daab47-2.exe <==== ATTENTION 
Task: {C852BB05-ADA3-4131-93A9-0CAA53FC2CD5} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-09-11] (AVAST Software) 
Task: {CA0E35E8-578C-4AF2-9A95-B09BCAAA70EF} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-07-20] (Google Inc.) 
Task: {D266B74C-89B7-4961-95F0-7A8B16A55D2B} - System32\Tasks\{7FF9D8C5-AC68-4694-B83F-D56E4487CDE1} => pcalua.exe -a C:\Users\admin\Desktop\ja1\INSTALL.EXE -d C:\Users\admin\Desktop\ja1 
Task: {E985FEF6-56AB-40A2-A778-380146EBDDF9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-07-20] (Google Inc.) 
Task: {ED3251B2-12E1-43B8-B700-FCFA7310B0D6} - System32\Tasks\OfficeSoftwareProtectionPlatform\SvcRestartTask => Sc.exe start osppsvc   
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)   
Task: C:\Windows\Tasks\44f0d4e0-73bd-4bc1-a0b9-50e135daab47-4.job => C:\Program Files\HQual-V1.8\44f0d4e0-73bd-4bc1-a0b9-50e135daab47-4.exe <==== ATTENTION 
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe 
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe 
Task: C:\Windows\Tasks\temp_44f0d4e0-73bd-4bc1-a0b9-50e135daab47-2.job => C:\Program Files\HQual-V1.8\44f0d4e0-73bd-4bc1-a0b9-50e135daab47-2.exe <==== ATTENTION   
==================== Loaded Modules (whitelisted) =============   
2014-09-11 07:06 - 2014-09-11 07:06 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll 
2015-01-31 23:56 - 2015-01-31 23:56 - 02913280 _____ () C:\Program Files\AVAST Software\Avast\defs\15013101\algo.dll 
2014-10-19 16:50 - 2010-07-20 06:55 - 00181248 _____ () C:\Windows\system32\spool\PRTPROCS\W32X86\lxefdrpp.dll 
2013-09-04 23:14 - 2013-09-04 23:14 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 
2014-09-11 07:06 - 2014-09-11 07:06 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 
2014-10-19 16:50 - 2013-01-23 09:47 - 00715368 _____ () C:\Program Files\Lexmark S800 Series\lxefmon.exe 
2014-10-19 16:50 - 2010-08-26 14:55 - 01847296 _____ () C:\Program Files\Lexmark S800 Series\lxefdrs.dll 
2014-10-19 16:50 - 2010-08-03 03:17 - 00155648 _____ () C:\Program Files\Lexmark S800 Series\lxefcaps.dll 
2014-10-19 16:49 - 2013-01-23 09:47 - 00150272 _____ () C:\Program Files\Lexmark S800 Series\ezprint.exe 
2014-10-19 16:49 - 2010-01-11 01:43 - 00716961 _____ () C:\Program Files\Lexmark S800 Series\Epwizard.DLL 
2014-10-19 16:49 - 2010-01-11 01:42 - 00159897 _____ () C:\Program Files\Lexmark S800 Series\customui.dll 
2014-10-19 16:49 - 2010-01-11 01:42 - 00123040 _____ () C:\Program Files\Lexmark S800 Series\Eputil.DLL 
2014-10-19 16:49 - 2010-01-11 01:42 - 00143509 _____ () C:\Program Files\Lexmark S800 Series\Imagutil.DLL 
2014-10-19 16:49 - 2010-01-11 01:42 - 00061611 _____ () C:\Program Files\Lexmark S800 Series\Epfunct.DLL 
2014-10-19 16:49 - 2010-03-22 07:24 - 02203794 _____ () C:\Program Files\Lexmark S800 Series\EPWizRes.dll 
2014-10-19 16:49 - 2010-03-22 07:25 - 00045212 _____ () C:\Program Files\Lexmark S800 Series\epstring.dll 
2014-10-19 16:49 - 2010-03-22 07:26 - 00102542 _____ () C:\Program Files\Lexmark S800 Series\EPOEMDll.dll 
2014-10-19 16:49 - 2010-03-29 12:15 - 00512000 _____ () C:\Program Files\Lexmark S800 Series\iptk.dll 
2014-10-19 16:50 - 2010-01-18 00:34 - 00159849 _____ () C:\Program Files\Lexmark S800 Series\lxefptp.dll 
2014-07-31 11:16 - 2014-07-31 11:16 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 
2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 
2015-01-27 09:33 - 2015-01-25 22:08 - 09170760 _____ () C:\Program Files\Google\Chrome\Application\40.0.2214.93\pdf.dll   
==================== Alternate Data Streams (whitelisted) =========   
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)     
==================== Safe Mode (whitelisted) ===================   
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)     
==================== EXE Association (whitelisted) =============   
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)     
==================== MSCONFIG/TASK MANAGER disabled items =========   
(Currently there is no automatic fix for this section.)     
========================= Accounts: ==========================   
admin (S-1-5-21-2596615060-55448930-4252937802-1000 - Administrator - Enabled) => C:\Users\admin 
Administrator (S-1-5-21-2596615060-55448930-4252937802-500 - Administrator - Disabled) 
Gast (S-1-5-21-2596615060-55448930-4252937802-501 - Limited - Disabled) 
user (S-1-5-21-2596615060-55448930-4252937802-1001 - Administrator - Enabled) => C:\Users\user.user-PC   
==================== Faulty Device Manager Devices =============   
Name: Broadcom USH 
Description: Broadcom USH 
Class Guid:  
Manufacturer:  
Service:  
Problem: : The drivers for this device are not installed. (Code 28) 
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.   
Name: Deskjet F4500 series 
Description: Deskjet F4500 series 
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f} 
Manufacturer: HP 
Service: StillCam 
Problem: : This device is disabled. (Code 22) 
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.   
Name: Deskjet F4500 series 
Description: Deskjet F4500 series 
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318} 
Manufacturer: HP 
Service:  
Problem: : This device is disabled. (Code 22) 
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.   
Name: Officejet Pro 8500 A909g 
Description: Officejet Pro 8500 A909g 
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318} 
Manufacturer: HP 
Service:  
Problem: : This device is disabled. (Code 22) 
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.     
==================== Event log errors: =========================   
Application errors: 
================== 
Error: (02/01/2015 09:42:05 AM) (Source: WinMgmt) (EventID: 10) (User: ) 
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003   
Error: (02/01/2015 01:00:59 AM) (Source: WinMgmt) (EventID: 10) (User: ) 
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003   
Error: (01/31/2015 11:55:23 PM) (Source: WinMgmt) (EventID: 10) (User: ) 
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003   
Error: (01/31/2015 10:46:35 PM) (Source: EventSystem) (EventID: 4621) (User: ) 
Description: 80070005EventSystem.EventSubscription{AA44355E-6911-4447-BA5D-6720480579AF}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}   
Error: (01/31/2015 07:37:45 PM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: m->NextScheduledSPRetry 394869   
Error: (01/31/2015 07:37:45 PM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: m->NextScheduledEvent 394869   
Error: (01/31/2015 07:37:45 PM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: Continuously busy for more than a second   
Error: (01/31/2015 07:37:44 PM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: m->NextScheduledSPRetry 393278   
Error: (01/31/2015 07:37:44 PM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: m->NextScheduledEvent 393278   
Error: (01/31/2015 07:37:44 PM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: Continuously busy for more than a second     
System errors: 
============= 
Error: (02/01/2015 09:44:40 AM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT) 
Description: 0x80070032   
Error: (02/01/2015 09:42:06 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) 
Description: lxefCATSCustConnectService%%1053   
Error: (02/01/2015 09:42:06 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) 
Description: 30000lxefCATSCustConnectService   
Error: (02/01/2015 01:01:44 AM) (Source: DCOM) (EventID: 10010) (User: ) 
Description: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}   
Error: (02/01/2015 01:01:20 AM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT) 
Description: 0x80070032   
Error: (02/01/2015 01:01:00 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) 
Description: lxefCATSCustConnectService%%1053   
Error: (02/01/2015 01:01:00 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) 
Description: 30000lxefCATSCustConnectService   
Error: (02/01/2015 00:59:21 AM) (Source: EventLog) (EventID: 6008) (User: ) 
Description: Das System wurde zuvor am 01.02.2015 um 00:56:34 unerwartet heruntergefahren.   
Error: (01/31/2015 11:57:39 PM) (Source: Microsoft-Windows-LanguagePackSetup) (EventID: 1001) (User: NT-AUTORITÄT) 
Description: 0x80070032   
Error: (01/31/2015 11:55:24 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) 
Description: lxefCATSCustConnectService%%1053     
Microsoft Office Sessions: 
========================= 
Error: (02/01/2015 09:42:05 AM) (Source: WinMgmt) (EventID: 10) (User: ) 
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003   
Error: (02/01/2015 01:00:59 AM) (Source: WinMgmt) (EventID: 10) (User: ) 
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003   
Error: (01/31/2015 11:55:23 PM) (Source: WinMgmt) (EventID: 10) (User: ) 
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003   
Error: (01/31/2015 10:46:35 PM) (Source: EventSystem) (EventID: 4621) (User: ) 
Description: 80070005EventSystem.EventSubscription{AA44355E-6911-4447-BA5D-6720480579AF}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}   
Error: (01/31/2015 07:37:45 PM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: m->NextScheduledSPRetry 394869   
Error: (01/31/2015 07:37:45 PM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: m->NextScheduledEvent 394869   
Error: (01/31/2015 07:37:45 PM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: Continuously busy for more than a second   
Error: (01/31/2015 07:37:44 PM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: m->NextScheduledSPRetry 393278   
Error: (01/31/2015 07:37:44 PM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: m->NextScheduledEvent 393278   
Error: (01/31/2015 07:37:44 PM) (Source: Bonjour Service) (EventID: 100) (User: ) 
Description: Task Scheduling Error: Continuously busy for more than a second     
CodeIntegrity Errors: 
=================================== 
  Date: 2014-08-08 16:14:42.366 
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.   
  Date: 2014-08-08 16:14:42.307 
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.   
  Date: 2014-08-08 16:14:42.216 
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.   
  Date: 2014-08-08 16:14:42.142 
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.   
  Date: 2014-08-08 16:14:42.070 
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.     
==================== Memory info ===========================    
Processor: Intel(R) Core(TM)2 Duo CPU P8700 @ 2.53GHz 
Percentage of memory in use: 50% 
Total physical RAM: 3535 MB 
Available physical RAM: 1762.69 MB 
Total Pagefile: 7294.96 MB 
Available Pagefile: 5313.88 MB 
Total Virtual: 2047.88 MB 
Available Virtual: 1897.57 MB   
==================== Drives ================================   
Drive c: () (Fixed) (Total:149.05 GB) (Free:31.2 GB) NTFS ==>[Drive with boot components (obtained from BCD)]   
==================== MBR & Partition Table ==================   
======================================================== 
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 149.1 GB) (Disk ID: CB972C64) 
Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS)   
==================== End Of Log ============================   --------------------------------------------------    Code:  
 GMER 2.1.19357 - hxxp://www.gmer.net 
Rootkit scan 2015-02-01 10:34:49 
Windows 6.0.6002 Service Pack 2 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST916041 rev.0004 149,05GB 
Running: Gmer-19357.exe; Driver: C:\Users\admin\AppData\Local\Temp\kxldapob.sys     
---- System - GMER 2.1 ----   
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwAddBootEntry [0x93220BA6] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwAssignProcessToJobObject [0x93221684] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwCreateEvent [0x9322D6F8] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwCreateEventPair [0x9322D744] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwCreateIoCompletion [0x9322D8DE] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwCreateMutant [0x9322D666] 
SSDT            \SystemRoot\system32\drivers\aswSP.sys                                                               ZwCreateSection [0x932D7DF0] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwCreateSemaphore [0x9322D6AE] 
SSDT            \SystemRoot\system32\drivers\aswSP.sys                                                               ZwCreateThread [0x932D8080] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwCreateTimer [0x9322D898] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwDebugActiveProcess [0x93222472] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwDeleteBootEntry [0x93220C0C] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwDuplicateObject [0x93225C68] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwLoadDriver [0x932207F8] 
SSDT            \SystemRoot\system32\drivers\aswSP.sys                                                               ZwMapViewOfSection [0x932D7ED0] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwModifyBootEntry [0x93220C72] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwNotifyChangeKey [0x9322605E] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwNotifyChangeMultipleKeys [0x93222F5A] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwOpenEvent [0x9322D722] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwOpenEventPair [0x9322D766] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwOpenIoCompletion [0x9322D902] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwOpenMutant [0x9322D68C] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwOpenProcess [0x93225560] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwOpenSection [0x9322D816] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwOpenSemaphore [0x9322D6D6] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwOpenThread [0x9322594C] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwOpenTimer [0x9322D8BC] 
SSDT            \SystemRoot\system32\drivers\aswSP.sys                                                               ZwProtectVirtualMemory [0x932D7C6E] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwQueryObject [0x93222DCE] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwQueueApcThread [0x93222924] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwSetBootEntryOrder [0x93220CD8] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwSetBootOptions [0x93220D3E] 
SSDT            \SystemRoot\system32\drivers\aswSP.sys                                                               ZwSetContextThread [0x932D7FCC] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwSetSystemInformation [0x93220892] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwSetSystemPowerState [0x93220A64] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwShutdownSystem [0x932209F2] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwSuspendProcess [0x9322263C] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwSuspendThread [0x9322279E] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwSystemDebugControl [0x93220AEC] 
SSDT            \SystemRoot\system32\drivers\aswSP.sys                                                               ZwTerminateProcess [0x932D7D3C] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwTerminateThread [0x932222CC] 
SSDT            \SystemRoot\system32\drivers\aswSnx.sys                                                              ZwVdmControl [0x93220DA4] 
SSDT            \SystemRoot\system32\drivers\aswSP.sys                                                               ZwWriteVirtualMemory [0x932D7BA0] 
SSDT            \SystemRoot\system32\drivers\aswSP.sys                                                               ZwCreateThreadEx [0x932D816A]   
---- Kernel code sections - GMER 2.1 ----   
.text           ntkrnlpa.exe!KeSetEvent + 10D                                                                        82ABE758 4 Bytes  [A6, 0B, 22, 93] {CMPSB ; OR ESP, [EDX]; XCHG EBX, EAX} 
.text           ntkrnlpa.exe!KeSetEvent + 191                                                                        82ABE7DC 4 Bytes  [84, 16, 22, 93] 
.text           ntkrnlpa.exe!KeSetEvent + 1D1                                                                        82ABE81C 8 Bytes  [F8, D6, 22, 93, 44, D7, 22, ...] {CLC ; SALC ; AND DL, [EBX-0x6cdd28bc]} 
.text           ntkrnlpa.exe!KeSetEvent + 1DD                                                                        82ABE828 4 Bytes  [DE, D8, 22, 93] 
.text           ntkrnlpa.exe!KeSetEvent + 1F5                                                                        82ABE840 4 Bytes  [66, D6, 22, 93] 
.text           ...                                                                                                   
PAGE            ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 110                                                          82C4C00F 4 Bytes  CALL 93223641 \SystemRoot\system32\drivers\aswSnx.sys 
PAGE            ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 121                                                         82C4FC83 4 Bytes  CALL 93223657 \SystemRoot\system32\drivers\aswSnx.sys   
---- User code sections - GMER 2.1 ----   
.text           C:\Windows\system32\csrss.exe[620] KERNEL32.dll!GetBinaryTypeW + 70                                  7652252F 1 Byte  [62] 
.text           C:\Windows\system32\wininit.exe[664] kernel32.dll!GetBinaryTypeW + 70                                7652252F 1 Byte  [62] 
.text           C:\Windows\system32\csrss.exe[676] KERNEL32.dll!GetBinaryTypeW + 70                                  7652252F 1 Byte  [62] 
.text           C:\Windows\system32\services.exe[708] kernel32.dll!GetBinaryTypeW + 70                               7652252F 1 Byte  [62] 
.text           C:\Windows\system32\lsass.exe[724] kernel32.dll!GetBinaryTypeW + 70                                  7652252F 1 Byte  [62] 
.text           ...                                                                                                   
.text           C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1764] kernel32.dll!SetUnhandledExceptionFilter    764FA9BD 8 Bytes  [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP } 
.text           C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1764] kernel32.dll!GetBinaryTypeW + 70            7652252F 1 Byte  [62] 
.text           C:\Windows\system32\WLANExt.exe[1848] kernel32.dll!GetBinaryTypeW + 70                               7652252F 1 Byte  [62] 
.text           C:\Windows\System32\spoolsv.exe[1900] kernel32.dll!GetBinaryTypeW + 70                               7652252F 1 Byte  [62] 
.text           C:\Windows\system32\taskeng.exe[1908] kernel32.dll!GetBinaryTypeW + 70                               7652252F 1 Byte  [62] 
.text           C:\Windows\system32\svchost.exe[1984] kernel32.dll!GetBinaryTypeW + 70                               7652252F 1 Byte  [62] 
.text           ...                                                                                                   
.text           C:\Program Files\AVAST Software\Avast\avastui.exe[2548] kernel32.dll!SetUnhandledExceptionFilter     764FA9BD 8 Bytes  [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP } 
.text           C:\Program Files\AVAST Software\Avast\avastui.exe[2548] kernel32.dll!GetBinaryTypeW + 70             7652252F 1 Byte  [62] 
.text           C:\Windows\system32\igfxsrvc.exe[2564] kernel32.dll!GetBinaryTypeW + 70                              7652252F 1 Byte  [62] 
.text           C:\Program Files\HP\HP Software Update\hpwuschd2.exe[2580] kernel32.dll!GetBinaryTypeW + 70          7652252F 1 Byte  [62] 
.text           C:\Program Files\Lexmark S800 Series\lxefmon.exe[2600] kernel32.dll!GetBinaryTypeW + 70              7652252F 1 Byte  [62] 
.text           C:\Program Files\Lexmark S800 Series\ezprint.exe[2608] kernel32.dll!GetBinaryTypeW + 70              7652252F 1 Byte  [62] 
.text           ...                                                                                                   
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!LdrLoadDll                     77019378 5 Bytes  JMP 00F801F8  
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!LdrUnloadDll                   7702B680 5 Bytes  JMP 00F803FC  
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtCreateFile + 6               7705426A 4 Bytes  [28, 10, F2, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtCreateFile + B               7705426F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtMapViewOfSection + 6         770549BA 4 Bytes  [28, 13, F2, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtMapViewOfSection + B         770549BF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenFile + 6                 77054A4A 4 Bytes  [68, 10, F2, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenFile + B                 77054A4F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenProcess + 6              77054ACA 4 Bytes  [A8, 11, F2, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenProcess + B              77054ACF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenProcessToken + B         77054ADF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenProcessTokenEx + 6       77054AEA 4 Bytes  [A8, 12, F2, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenProcessTokenEx + B       77054AEF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenThread + 6               77054B3A 4 Bytes  [68, 11, F2, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenThread + B               77054B3F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenThreadToken + 6          77054B4A 4 Bytes  [68, 12, F2, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenThreadToken + B          77054B4F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtOpenThreadTokenEx + B        77054B5F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtQueryAttributesFile + 6      77054BEA 4 Bytes  [A8, 10, F2, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtQueryAttributesFile + B      77054BEF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtQueryFullAttributesFile + B  77054C9F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtSetInformationFile + 6       7705517A 4 Bytes  [28, 11, F2, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtSetInformationFile + B       7705517F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtSetInformationThread + 6     770551CA 4 Bytes  [28, 12, F2, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtSetInformationThread + B     770551CF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtUnmapViewOfSection + 6       7705546A 4 Bytes  [68, 13, F2, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] ntdll.dll!NtUnmapViewOfSection + B       7705546F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4208] KERNEL32.dll!GetBinaryTypeW + 70         7652252F 1 Byte  [62] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!LdrLoadDll                     77019378 5 Bytes  JMP 006A01F8  
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!LdrUnloadDll                   7702B680 5 Bytes  JMP 006A03FC  
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtCreateFile + 6               7705426A 4 Bytes  [28, 18, 64, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtCreateFile + B               7705426F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtMapViewOfSection + 6         770549BA 4 Bytes  [28, 1B, 64, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtMapViewOfSection + B         770549BF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenFile + 6                 77054A4A 4 Bytes  [68, 18, 64, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenFile + B                 77054A4F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenProcess + 6              77054ACA 4 Bytes  [A8, 19, 64, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenProcess + B              77054ACF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenProcessToken + B         77054ADF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenProcessTokenEx + 6       77054AEA 4 Bytes  [A8, 1A, 64, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenProcessTokenEx + B       77054AEF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenThread + 6               77054B3A 4 Bytes  [68, 19, 64, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenThread + B               77054B3F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenThreadToken + 6          77054B4A 4 Bytes  [68, 1A, 64, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenThreadToken + B          77054B4F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtOpenThreadTokenEx + B        77054B5F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtQueryAttributesFile + 6      77054BEA 4 Bytes  [A8, 18, 64, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtQueryAttributesFile + B      77054BEF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtQueryFullAttributesFile + B  77054C9F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtSetInformationFile + 6       7705517A 4 Bytes  [28, 19, 64, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtSetInformationFile + B       7705517F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtSetInformationThread + 6     770551CA 4 Bytes  [28, 1A, 64, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtSetInformationThread + B     770551CF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtUnmapViewOfSection + 6       7705546A 4 Bytes  [68, 1B, 64, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] ntdll.dll!NtUnmapViewOfSection + B       7705546F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4216] KERNEL32.dll!GetBinaryTypeW + 70         7652252F 1 Byte  [62] 
.text           C:\Windows\system32\svchost.exe[4252] kernel32.dll!GetBinaryTypeW + 70                               7652252F 1 Byte  [62] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!LdrLoadDll                     77019378 5 Bytes  JMP 00F601F8  
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!LdrUnloadDll                   7702B680 5 Bytes  JMP 00F603FC  
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtCreateFile + 6               7705426A 4 Bytes  [28, 10, F0, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtCreateFile + B               7705426F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtMapViewOfSection + 6         770549BA 4 Bytes  [28, 13, F0, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtMapViewOfSection + B         770549BF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenFile + 6                 77054A4A 4 Bytes  [68, 10, F0, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenFile + B                 77054A4F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenProcess + 6              77054ACA 4 Bytes  [A8, 11, F0, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenProcess + B              77054ACF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenProcessToken + B         77054ADF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenProcessTokenEx + 6       77054AEA 4 Bytes  [A8, 12, F0, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenProcessTokenEx + B       77054AEF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenThread + 6               77054B3A 4 Bytes  [68, 11, F0, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenThread + B               77054B3F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenThreadToken + 6          77054B4A 4 Bytes  [68, 12, F0, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenThreadToken + B          77054B4F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtOpenThreadTokenEx + B        77054B5F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtQueryAttributesFile + 6      77054BEA 4 Bytes  [A8, 10, F0, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtQueryAttributesFile + B      77054BEF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtQueryFullAttributesFile + B  77054C9F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtSetInformationFile + 6       7705517A 4 Bytes  [28, 11, F0, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtSetInformationFile + B       7705517F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtSetInformationThread + 6     770551CA 4 Bytes  [28, 12, F0, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtSetInformationThread + B     770551CF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtUnmapViewOfSection + 6       7705546A 4 Bytes  [68, 13, F0, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] ntdll.dll!NtUnmapViewOfSection + B       7705546F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4276] KERNEL32.dll!GetBinaryTypeW + 70         7652252F 1 Byte  [62] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!LdrLoadDll                     77019378 5 Bytes  JMP 00C501F8  
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!LdrUnloadDll                   7702B680 5 Bytes  JMP 00C503FC  
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtCreateFile + 6               7705426A 4 Bytes  [28, A4, BF, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtCreateFile + B               7705426F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtMapViewOfSection + 6         770549BA 4 Bytes  [28, A7, BF, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtMapViewOfSection + B         770549BF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenFile + 6                 77054A4A 4 Bytes  [68, A4, BF, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenFile + B                 77054A4F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenProcess + 6              77054ACA 4 Bytes  [A8, A5, BF, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenProcess + B              77054ACF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenProcessToken + B         77054ADF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenProcessTokenEx + 6       77054AEA 4 Bytes  [A8, A6, BF, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenProcessTokenEx + B       77054AEF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenThread + 6               77054B3A 4 Bytes  [68, A5, BF, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenThread + B               77054B3F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenThreadToken + 6          77054B4A 4 Bytes  [68, A6, BF, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenThreadToken + B          77054B4F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtOpenThreadTokenEx + B        77054B5F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtQueryAttributesFile + 6      77054BEA 4 Bytes  [A8, A4, BF, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtQueryAttributesFile + B      77054BEF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtQueryFullAttributesFile + B  77054C9F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtSetInformationFile + 6       7705517A 4 Bytes  [28, A5, BF, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtSetInformationFile + B       7705517F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtSetInformationThread + 6     770551CA 4 Bytes  [28, A6, BF, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtSetInformationThread + B     770551CF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtUnmapViewOfSection + 6       7705546A 4 Bytes  [68, A7, BF, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] ntdll.dll!NtUnmapViewOfSection + B       7705546F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4364] KERNEL32.dll!GetBinaryTypeW + 70         7652252F 1 Byte  [62] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!LdrLoadDll                     77019378 5 Bytes  JMP 006601F8  
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!LdrUnloadDll                   7702B680 5 Bytes  JMP 006603FC  
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtCreateFile + 6               7705426A 4 Bytes  [28, F4, 60, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtCreateFile + B               7705426F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtMapViewOfSection + 6         770549BA 4 Bytes  [28, F7, 60, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtMapViewOfSection + B         770549BF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenFile + 6                 77054A4A 4 Bytes  [68, F4, 60, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenFile + B                 77054A4F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenProcess + 6              77054ACA 4 Bytes  [A8, F5, 60, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenProcess + B              77054ACF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenProcessToken + B         77054ADF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenProcessTokenEx + 6       77054AEA 4 Bytes  [A8, F6, 60, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenProcessTokenEx + B       77054AEF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenThread + 6               77054B3A 4 Bytes  [68, F5, 60, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenThread + B               77054B3F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenThreadToken + 6          77054B4A 4 Bytes  [68, F6, 60, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenThreadToken + B          77054B4F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtOpenThreadTokenEx + B        77054B5F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtQueryAttributesFile + 6      77054BEA 4 Bytes  [A8, F4, 60, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtQueryAttributesFile + B      77054BEF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtQueryFullAttributesFile + B  77054C9F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtSetInformationFile + 6       7705517A 4 Bytes  [28, F5, 60, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtSetInformationFile + B       7705517F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtSetInformationThread + 6     770551CA 4 Bytes  [28, F6, 60, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtSetInformationThread + B     770551CF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtUnmapViewOfSection + 6       7705546A 4 Bytes  [68, F7, 60, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] ntdll.dll!NtUnmapViewOfSection + B       7705546F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[4496] KERNEL32.dll!GetBinaryTypeW + 70         7652252F 1 Byte  [62] 
.text           C:\Windows\system32\conime.exe[4728] kernel32.dll!GetBinaryTypeW + 70                                7652252F 1 Byte  [62] 
.text           C:\Windows\system32\wbem\unsecapp.exe[4812] kernel32.dll!GetBinaryTypeW + 70                         7652252F 1 Byte  [62] 
.text           C:\Windows\system32\wbem\wmiprvse.exe[4864] kernel32.dll!GetBinaryTypeW + 70                         7652252F 1 Byte  [62] 
.text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[4968] kernel32.dll!GetBinaryTypeW + 70          7652252F 1 Byte  [62] 
.text           ...                                                                                                   
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!LdrLoadDll                     77019378 5 Bytes  JMP 002201F8  
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!LdrUnloadDll                   7702B680 5 Bytes  JMP 002203FC  
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtCreateFile + 6               7705426A 4 Bytes  [28, 14, 1C, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtCreateFile + B               7705426F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtMapViewOfSection + 6         770549BA 4 Bytes  [28, 17, 1C, 00] {SUB [EDI], DL; SBB AL, 0x0} 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtMapViewOfSection + B         770549BF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenFile + 6                 77054A4A 4 Bytes  [68, 14, 1C, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenFile + B                 77054A4F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenProcess + 6              77054ACA 4 Bytes  [A8, 15, 1C, 00] {TEST AL, 0x15; SBB AL, 0x0} 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenProcess + B              77054ACF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenProcessToken + B         77054ADF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenProcessTokenEx + 6       77054AEA 4 Bytes  [A8, 16, 1C, 00] {TEST AL, 0x16; SBB AL, 0x0} 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenProcessTokenEx + B       77054AEF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenThread + 6               77054B3A 4 Bytes  [68, 15, 1C, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenThread + B               77054B3F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenThreadToken + 6          77054B4A 4 Bytes  [68, 16, 1C, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenThreadToken + B          77054B4F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtOpenThreadTokenEx + B        77054B5F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtQueryAttributesFile + 6      77054BEA 4 Bytes  [A8, 14, 1C, 00] {TEST AL, 0x14; SBB AL, 0x0} 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtQueryAttributesFile + B      77054BEF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtQueryFullAttributesFile + B  77054C9F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtSetInformationFile + 6       7705517A 4 Bytes  [28, 15, 1C, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtSetInformationFile + B       7705517F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtSetInformationThread + 6     770551CA 4 Bytes  [28, 16, 1C, 00] {SUB [ESI], DL; SBB AL, 0x0} 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtSetInformationThread + B     770551CF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtUnmapViewOfSection + 6       7705546A 4 Bytes  [68, 17, 1C, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] ntdll.dll!NtUnmapViewOfSection + B       7705546F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5276] KERNEL32.dll!GetBinaryTypeW + 70         7652252F 1 Byte  [62] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!LdrLoadDll                     77019378 5 Bytes  JMP 010401F8  
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!LdrUnloadDll                   7702B680 5 Bytes  JMP 010403FC  
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtCreateFile + 6               7705426A 4 Bytes  [28, 98, EE, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtCreateFile + B               7705426F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtMapViewOfSection + 6         770549BA 4 Bytes  [28, 9B, EE, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtMapViewOfSection + B         770549BF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenFile + 6                 77054A4A 4 Bytes  [68, 98, EE, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenFile + B                 77054A4F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenProcess + 6              77054ACA 4 Bytes  [A8, 99, EE, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenProcess + B              77054ACF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenProcessToken + B         77054ADF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenProcessTokenEx + 6       77054AEA 4 Bytes  [A8, 9A, EE, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenProcessTokenEx + B       77054AEF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenThread + 6               77054B3A 4 Bytes  [68, 99, EE, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenThread + B               77054B3F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenThreadToken + 6          77054B4A 4 Bytes  [68, 9A, EE, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenThreadToken + B          77054B4F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtOpenThreadTokenEx + B        77054B5F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtQueryAttributesFile + 6      77054BEA 4 Bytes  [A8, 98, EE, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtQueryAttributesFile + B      77054BEF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtQueryFullAttributesFile + B  77054C9F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtSetInformationFile + 6       7705517A 4 Bytes  [28, 99, EE, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtSetInformationFile + B       7705517F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtSetInformationThread + 6     770551CA 4 Bytes  [28, 9A, EE, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtSetInformationThread + B     770551CF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtUnmapViewOfSection + 6       7705546A 4 Bytes  [68, 9B, EE, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] ntdll.dll!NtUnmapViewOfSection + B       7705546F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5336] KERNEL32.dll!GetBinaryTypeW + 70         7652252F 1 Byte  [62] 
.text           C:\Program Files\Common Files\Java\Java Update\jucheck.exe[5476] kernel32.dll!GetBinaryTypeW + 70    7652252F 1 Byte  [62] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5788] ntdll.dll!LdrLoadDll                     77019378 5 Bytes  JMP 001601F8  
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5788] ntdll.dll!LdrUnloadDll                   7702B680 5 Bytes  JMP 001603FC  
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5788] ntdll.dll!NtMapViewOfSection + 6         770549BA 4 Bytes  [18, 20, 96, 65] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5788] ntdll.dll!NtMapViewOfSection + B         770549BF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[5788] KERNEL32.dll!GetBinaryTypeW + 70         7652252F 1 Byte  [62] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!LdrLoadDll                     77019378 5 Bytes  JMP 00DB01F8  
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!LdrUnloadDll                   7702B680 5 Bytes  JMP 00DB03FC  
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtCreateFile + 6               7705426A 4 Bytes  [28, 58, D5, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtCreateFile + B               7705426F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtMapViewOfSection + 6         770549BA 4 Bytes  [28, 5B, D5, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtMapViewOfSection + B         770549BF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenFile + 6                 77054A4A 4 Bytes  [68, 58, D5, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenFile + B                 77054A4F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenProcess + 6              77054ACA 4 Bytes  [A8, 59, D5, 00] {TEST AL, 0x59; AAD 0x0} 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenProcess + B              77054ACF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenProcessToken + B         77054ADF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenProcessTokenEx + 6       77054AEA 4 Bytes  [A8, 5A, D5, 00] {TEST AL, 0x5a; AAD 0x0} 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenProcessTokenEx + B       77054AEF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenThread + 6               77054B3A 4 Bytes  [68, 59, D5, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenThread + B               77054B3F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenThreadToken + 6          77054B4A 4 Bytes  [68, 5A, D5, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenThreadToken + B          77054B4F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtOpenThreadTokenEx + B        77054B5F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtQueryAttributesFile + 6      77054BEA 4 Bytes  [A8, 58, D5, 00] {TEST AL, 0x58; AAD 0x0} 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtQueryAttributesFile + B      77054BEF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtQueryFullAttributesFile + B  77054C9F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtSetInformationFile + 6       7705517A 4 Bytes  [28, 59, D5, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtSetInformationFile + B       7705517F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtSetInformationThread + 6     770551CA 4 Bytes  [28, 5A, D5, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtSetInformationThread + B     770551CF 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtUnmapViewOfSection + 6       7705546A 4 Bytes  [68, 5B, D5, 00] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] ntdll.dll!NtUnmapViewOfSection + B       7705546F 1 Byte  [E2] 
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[6116] KERNEL32.dll!GetBinaryTypeW + 70         7652252F 1 Byte  [62]   
---- Devices - GMER 2.1 ----   
AttachedDevice  \Driver\tdx \Device\Tcp                                                                              aswTdi.sys 
AttachedDevice  \Driver\tdx \Device\Udp                                                                              aswTdi.sys   
---- EOF - GMER 2.1 ----      |