Sunny_1987 | 18.03.2013 18:50 | So hier die nächsten Logs
Gmer: Code:
GMER 2.1.19155 - hxxp://www.gmer.net
Rootkit scan 2013-03-18 17:19:16
Windows 6.1.7600 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST950032 rev.0006 465,76GB
Running: gmer_2.1.19155.exe; Driver: C:\Users\***\AppData\Local\Temp\fgtyrpog.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe[1704] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000751f1465 2 bytes [1F, 75]
.text C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe[1704] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751f14bb 2 bytes [1F, 75]
.text ... * 2
.text C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe[3080] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000751f1465 2 bytes [1F, 75]
.text C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe[3080] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751f14bb 2 bytes [1F, 75]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000775508ac 4 bytes [68, A0, CF, 63]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 00000000775508b1 1 byte [C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 000000007756260d 6 bytes [68, BD, 57, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007756c4aa 6 bytes [68, CB, D0, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077572a93 6 bytes [68, 03, 58, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077594170 6 bytes [68, 49, 58, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007759e6b5 6 bytes [68, 8F, 58, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\KERNEL32.dll!GetFileAttributesExW 0000000076c132f2 6 bytes [68, 34, D3, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\KERNEL32.dll!ExitProcess 0000000076c1734e 6 bytes [68, F3, D2, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 0000000076a5bbdb 6 bytes [68, B1, D3, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000076a914fd 6 bytes [68, 9A, D3, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!GetDC 0000000075107246 4 bytes [68, 92, 18, 63]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!GetDC + 5 000000007510724b 1 byte [C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!ReleaseDC 000000007510730e 6 bytes [68, 10, 19, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000751079d8 4 bytes [68, D1, 18, 63]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 00000000751079dd 1 byte [C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!TranslateMessage 0000000075107d79 6 bytes [68, A5, 5D, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075107e92 6 bytes [68, 22, DE, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!GetMessageA 000000007510811b 6 bytes [68, 4A, DE, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!RegisterClassW 0000000075108bd6 6 bytes [68, C1, 5A, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!RegisterClassExW 0000000075109ed3 6 bytes [68, 5B, 5B, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!RegisterClassExA 000000007510dd6d 6 bytes [68, AD, 5B, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075110112 6 bytes [68, 72, DE, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!CallWindowProcW 0000000075110abb 6 bytes [68, F3, 59, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!GetCursorPos 0000000075110e0d 6 bytes [68, 55, DC, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!EndPaint 0000000075110e9a 4 bytes [68, F7, 17, 63]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!EndPaint + 5 0000000075110e9f 1 byte [C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!BeginPaint 0000000075110eba 4 bytes [68, 87, 17, 63]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 0000000075110ebf 1 byte [C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!GetMessagePos 0000000075112bc7 6 bytes [68, 23, DC, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!GetCapture 0000000075112dbd 6 bytes [68, 83, DD, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!ReleaseCapture 0000000075112ec4 6 bytes [68, 33, DD, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!SetCapture 0000000075112ed1 4 bytes [68, D9, DC, 63]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!SetCapture + 5 0000000075112ed6 1 byte [C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!GetDCEx 0000000075113001 4 bytes [68, 37, 18, 63]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 0000000075113006 1 byte [C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!RegisterClassA 0000000075114b80 6 bytes [68, 0E, 5B, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!CallWindowProcA 0000000075117af4 6 bytes [68, 3C, 5A, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!DefFrameProcA 000000007511808f 6 bytes [68, 1E, 59, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000751181e0 6 bytes [68, AD, 59, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!DefFrameProcW 0000000075118632 6 bytes [68, D5, 58, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 0000000075118807 6 bytes [68, 67, 59, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!PeekMessageA 000000007512ed58 6 bytes [68, 9D, DE, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 000000007512f1fe 6 bytes [68, E3, 19, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!GetUpdateRect 000000007513011b 6 bytes [68, 50, 19, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!SwitchDesktop 00000000751497e4 6 bytes [68, 9F, 57, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000075149c8d 6 bytes [68, 9C, DC, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000075149f3b 6 bytes [68, 54, 5F, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 000000007516895b 4 bytes [68, 4F, 57, 64]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 0000000075168960 1 byte [C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\WS2_32.dll!closesocket 00000000760e3bed 6 bytes [68, 27, E3, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 00000000760e6737 6 bytes [68, 38, DF, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\WS2_32.dll!WSASend 00000000760e68a7 6 bytes [68, 80, E3, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\WS2_32.dll!send 00000000760ec4c8 6 bytes [68, 5F, E3, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\WS2_32.dll!gethostbyname 00000000760f7133 6 bytes [68, C8, DE, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 00000000766112b0 6 bytes [68, 89, 7E, 63, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 000000007670c83e 6 bytes [68, DC, 08, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 000000007670cbc2 6 bytes [68, 7C, 0A, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\WININET.dll!InternetReadFile 000000007670e264 6 bytes [68, 49, 09, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 000000007670eeb3 6 bytes [68, 62, 06, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 0000000076710352 6 bytes [68, 1E, 06, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 000000007671052b 6 bytes [68, DA, 05, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 00000000767140df 6 bytes [68, 50, 0A, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000076728e24 6 bytes [68, 0C, 07, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 0000000076728f4f 6 bytes [68, 46, 08, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000076731301 6 bytes [68, 77, 09, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 000000007676d2b3 6 bytes [68, F6, 09, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 000000007678059a 6 bytes [68, A9, 07, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 000000007678061d 6 bytes [68, 91, 08, 64, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3440] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000076780680 6 bytes [68, B7, 06, 64, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000775508ac 4 bytes [68, A0, CF, 84]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 00000000775508b1 1 byte [C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 000000007756260d 6 bytes [68, BD, 57, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007756c4aa 6 bytes [68, CB, D0, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077572a93 6 bytes [68, 03, 58, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077594170 6 bytes [68, 49, 58, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007759e6b5 6 bytes [68, 8F, 58, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 0000000076c132f2 6 bytes [68, 34, D3, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\kernel32.dll!ExitProcess 0000000076c1734e 6 bytes [68, F3, D2, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 0000000076a5bbdb 6 bytes [68, B1, D3, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000076a914fd 6 bytes [68, 9A, D3, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!GetDC 0000000075107246 4 bytes [68, 92, 18, 84]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!GetDC + 5 000000007510724b 1 byte [C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!ReleaseDC 000000007510730e 6 bytes [68, 10, 19, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000751079d8 4 bytes [68, D1, 18, 84]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 00000000751079dd 1 byte [C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!TranslateMessage 0000000075107d79 6 bytes [68, A5, 5D, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075107e92 6 bytes [68, 22, DE, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!GetMessageA 000000007510811b 6 bytes [68, 4A, DE, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!RegisterClassW 0000000075108bd6 6 bytes [68, C1, 5A, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!RegisterClassExW 0000000075109ed3 6 bytes [68, 5B, 5B, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!RegisterClassExA 000000007510dd6d 6 bytes [68, AD, 5B, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075110112 6 bytes [68, 72, DE, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!CallWindowProcW 0000000075110abb 6 bytes [68, F3, 59, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!GetCursorPos 0000000075110e0d 6 bytes [68, 55, DC, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!EndPaint 0000000075110e9a 4 bytes [68, F7, 17, 84]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!EndPaint + 5 0000000075110e9f 1 byte [C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!BeginPaint 0000000075110eba 4 bytes [68, 87, 17, 84]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 0000000075110ebf 1 byte [C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!GetMessagePos 0000000075112bc7 6 bytes [68, 23, DC, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!GetCapture 0000000075112dbd 6 bytes [68, 83, DD, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!ReleaseCapture 0000000075112ec4 6 bytes [68, 33, DD, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!SetCapture 0000000075112ed1 4 bytes [68, D9, DC, 84]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!SetCapture + 5 0000000075112ed6 1 byte [C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!GetDCEx 0000000075113001 4 bytes [68, 37, 18, 84]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 0000000075113006 1 byte [C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!RegisterClassA 0000000075114b80 6 bytes [68, 0E, 5B, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!CallWindowProcA 0000000075117af4 6 bytes [68, 3C, 5A, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!DefFrameProcA 000000007511808f 6 bytes [68, 1E, 59, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000751181e0 6 bytes [68, AD, 59, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!DefFrameProcW 0000000075118632 6 bytes [68, D5, 58, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 0000000075118807 6 bytes [68, 67, 59, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!PeekMessageA 000000007512ed58 6 bytes [68, 9D, DE, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 000000007512f1fe 6 bytes [68, E3, 19, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!GetUpdateRect 000000007513011b 6 bytes [68, 50, 19, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!SwitchDesktop 00000000751497e4 6 bytes [68, 9F, 57, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000075149c8d 6 bytes [68, 9C, DC, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000075149f3b 6 bytes [68, 54, 5F, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 000000007516895b 4 bytes [68, 4F, 57, 85]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 0000000075168960 1 byte [C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 00000000766112b0 6 bytes [68, 89, 7E, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\WS2_32.dll!closesocket 00000000760e3bed 6 bytes [68, 27, E3, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 00000000760e6737 6 bytes [68, 38, DF, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\WS2_32.dll!WSASend 00000000760e68a7 6 bytes [68, 80, E3, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\WS2_32.dll!send 00000000760ec4c8 6 bytes [68, 5F, E3, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\WS2_32.dll!gethostbyname 00000000760f7133 6 bytes [68, C8, DE, 84, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 000000007670c83e 6 bytes [68, DC, 08, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 000000007670cbc2 6 bytes [68, 7C, 0A, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\WININET.dll!InternetReadFile 000000007670e264 6 bytes [68, 49, 09, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 000000007670eeb3 6 bytes [68, 62, 06, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 0000000076710352 6 bytes [68, 1E, 06, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 000000007671052b 6 bytes [68, DA, 05, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 00000000767140df 6 bytes [68, 50, 0A, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000076728e24 6 bytes [68, 0C, 07, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 0000000076728f4f 6 bytes [68, 46, 08, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000076731301 6 bytes [68, 77, 09, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 000000007676d2b3 6 bytes [68, F6, 09, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 000000007678059a 6 bytes [68, A9, 07, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 000000007678061d 6 bytes [68, 91, 08, 85, 00, C3]
.text C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe[3292] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000076780680 6 bytes [68, B7, 06, 85, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000775508ac 4 bytes [68, A0, CF, 98]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 00000000775508b1 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 000000007756260d 6 bytes [68, BD, 57, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007756c4aa 6 bytes [68, CB, D0, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077572a93 6 bytes [68, 03, 58, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077594170 6 bytes [68, 49, 58, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007759e6b5 6 bytes [68, 8F, 58, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 0000000076c132f2 6 bytes [68, 34, D3, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\kernel32.dll!ExitProcess 0000000076c1734e 6 bytes [68, F3, D2, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 0000000076a5bbdb 6 bytes [68, B1, D3, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000076a914fd 6 bytes [68, 9A, D3, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!GetDC 0000000075107246 4 bytes [68, 92, 18, 98]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!GetDC + 5 000000007510724b 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!ReleaseDC 000000007510730e 6 bytes [68, 10, 19, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000751079d8 4 bytes [68, D1, 18, 98]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 00000000751079dd 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!TranslateMessage 0000000075107d79 6 bytes [68, A5, 5D, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075107e92 6 bytes [68, 22, DE, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!GetMessageA 000000007510811b 6 bytes [68, 4A, DE, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!RegisterClassW 0000000075108bd6 6 bytes [68, C1, 5A, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!RegisterClassExW 0000000075109ed3 6 bytes [68, 5B, 5B, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!RegisterClassExA 000000007510dd6d 6 bytes [68, AD, 5B, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075110112 6 bytes [68, 72, DE, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!CallWindowProcW 0000000075110abb 6 bytes [68, F3, 59, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!GetCursorPos 0000000075110e0d 6 bytes [68, 55, DC, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!EndPaint 0000000075110e9a 4 bytes [68, F7, 17, 98]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!EndPaint + 5 0000000075110e9f 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!BeginPaint 0000000075110eba 4 bytes [68, 87, 17, 98]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 0000000075110ebf 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!GetMessagePos 0000000075112bc7 6 bytes [68, 23, DC, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!GetCapture 0000000075112dbd 6 bytes [68, 83, DD, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!ReleaseCapture 0000000075112ec4 6 bytes [68, 33, DD, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!SetCapture 0000000075112ed1 4 bytes [68, D9, DC, 98]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!SetCapture + 5 0000000075112ed6 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!GetDCEx 0000000075113001 4 bytes [68, 37, 18, 98]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 0000000075113006 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!RegisterClassA 0000000075114b80 6 bytes [68, 0E, 5B, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!CallWindowProcA 0000000075117af4 6 bytes [68, 3C, 5A, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!DefFrameProcA 000000007511808f 6 bytes [68, 1E, 59, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000751181e0 6 bytes [68, AD, 59, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!DefFrameProcW 0000000075118632 6 bytes [68, D5, 58, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 0000000075118807 6 bytes [68, 67, 59, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!PeekMessageA 000000007512ed58 6 bytes [68, 9D, DE, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 000000007512f1fe 6 bytes [68, E3, 19, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!GetUpdateRect 000000007513011b 6 bytes [68, 50, 19, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!SwitchDesktop 00000000751497e4 6 bytes [68, 9F, 57, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000075149c8d 6 bytes [68, 9C, DC, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000075149f3b 6 bytes [68, 54, 5F, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 000000007516895b 4 bytes [68, 4F, 57, 99]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 0000000075168960 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000751f1465 2 bytes [1F, 75]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751f14bb 2 bytes [1F, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 000000007670c83e 6 bytes [68, DC, 08, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 000000007670cbc2 6 bytes [68, 7C, 0A, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\WININET.dll!InternetReadFile 000000007670e264 6 bytes [68, 49, 09, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 000000007670eeb3 6 bytes [68, 62, 06, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 0000000076710352 6 bytes [68, 1E, 06, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 000000007671052b 6 bytes [68, DA, 05, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 00000000767140df 6 bytes [68, 50, 0A, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000076728e24 6 bytes [68, 0C, 07, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 0000000076728f4f 6 bytes [68, 46, 08, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000076731301 6 bytes [68, 77, 09, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 000000007676d2b3 6 bytes [68, F6, 09, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 000000007678059a 6 bytes [68, A9, 07, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 000000007678061d 6 bytes [68, 91, 08, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000076780680 6 bytes [68, B7, 06, 99, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 00000000766112b0 6 bytes [68, 89, 7E, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\WS2_32.dll!closesocket 00000000760e3bed 6 bytes [68, 27, E3, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 00000000760e6737 6 bytes [68, 38, DF, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\WS2_32.dll!WSASend 00000000760e68a7 6 bytes [68, 80, E3, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\WS2_32.dll!send 00000000760ec4c8 6 bytes [68, 5F, E3, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[1700] C:\Windows\syswow64\WS2_32.dll!gethostbyname 00000000760f7133 6 bytes [68, C8, DE, 98, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000775508ac 4 bytes [68, A0, CF, 3D]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 00000000775508b1 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 000000007756260d 6 bytes [68, BD, 57, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007756c4aa 6 bytes [68, CB, D0, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077572a93 6 bytes [68, 03, 58, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077594170 6 bytes [68, 49, 58, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007759e6b5 6 bytes [68, 8F, 58, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 0000000076c132f2 6 bytes [68, 34, D3, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\kernel32.dll!ExitProcess 0000000076c1734e 6 bytes [68, F3, D2, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 0000000076a5bbdb 6 bytes [68, B1, D3, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000076a914fd 6 bytes [68, 9A, D3, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!GetDC 0000000075107246 4 bytes [68, 92, 18, 3D]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!GetDC + 5 000000007510724b 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!ReleaseDC 000000007510730e 6 bytes [68, 10, 19, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000751079d8 4 bytes [68, D1, 18, 3D]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 00000000751079dd 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!TranslateMessage 0000000075107d79 6 bytes [68, A5, 5D, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075107e92 6 bytes [68, 22, DE, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!GetMessageA 000000007510811b 6 bytes [68, 4A, DE, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!RegisterClassW 0000000075108bd6 6 bytes [68, C1, 5A, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!RegisterClassExW 0000000075109ed3 6 bytes [68, 5B, 5B, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!RegisterClassExA 000000007510dd6d 6 bytes [68, AD, 5B, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075110112 6 bytes [68, 72, DE, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!CallWindowProcW 0000000075110abb 6 bytes [68, F3, 59, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!GetCursorPos 0000000075110e0d 6 bytes [68, 55, DC, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!EndPaint 0000000075110e9a 4 bytes [68, F7, 17, 3D]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!EndPaint + 5 0000000075110e9f 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!BeginPaint 0000000075110eba 4 bytes [68, 87, 17, 3D]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 0000000075110ebf 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!GetMessagePos 0000000075112bc7 6 bytes [68, 23, DC, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!GetCapture 0000000075112dbd 6 bytes [68, 83, DD, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!ReleaseCapture 0000000075112ec4 6 bytes [68, 33, DD, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!SetCapture 0000000075112ed1 4 bytes [68, D9, DC, 3D]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!SetCapture + 5 0000000075112ed6 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!GetDCEx 0000000075113001 4 bytes [68, 37, 18, 3D]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 0000000075113006 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!RegisterClassA 0000000075114b80 6 bytes [68, 0E, 5B, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!CallWindowProcA 0000000075117af4 6 bytes [68, 3C, 5A, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!DefFrameProcA 000000007511808f 6 bytes [68, 1E, 59, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000751181e0 6 bytes [68, AD, 59, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!DefFrameProcW 0000000075118632 6 bytes [68, D5, 58, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 0000000075118807 6 bytes [68, 67, 59, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!PeekMessageA 000000007512ed58 6 bytes [68, 9D, DE, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 000000007512f1fe 6 bytes [68, E3, 19, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!GetUpdateRect 000000007513011b 6 bytes [68, 50, 19, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!SwitchDesktop 00000000751497e4 6 bytes [68, 9F, 57, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000075149c8d 6 bytes [68, 9C, DC, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000075149f3b 6 bytes [68, 54, 5F, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 000000007516895b 4 bytes [68, 4F, 57, 3E]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 0000000075168960 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 000000007670c83e 6 bytes [68, DC, 08, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 000000007670cbc2 6 bytes [68, 7C, 0A, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\WININET.dll!InternetReadFile 000000007670e264 6 bytes [68, 49, 09, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 000000007670eeb3 6 bytes [68, 62, 06, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 0000000076710352 6 bytes [68, 1E, 06, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 000000007671052b 6 bytes [68, DA, 05, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 00000000767140df 6 bytes [68, 50, 0A, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000076728e24 6 bytes [68, 0C, 07, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 0000000076728f4f 6 bytes [68, 46, 08, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000076731301 6 bytes [68, 77, 09, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 000000007676d2b3 6 bytes [68, F6, 09, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 000000007678059a 6 bytes [68, A9, 07, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 000000007678061d 6 bytes [68, 91, 08, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000076780680 6 bytes [68, B7, 06, 3E, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 00000000766112b0 6 bytes [68, 89, 7E, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\WS2_32.dll!closesocket 00000000760e3bed 6 bytes [68, 27, E3, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 00000000760e6737 6 bytes [68, 38, DF, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\WS2_32.dll!WSASend 00000000760e68a7 6 bytes [68, 80, E3, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\WS2_32.dll!send 00000000760ec4c8 6 bytes [68, 5F, E3, 3D, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3952] C:\Windows\syswow64\WS2_32.dll!gethostbyname 00000000760f7133 6 bytes [68, C8, DE, 3D, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4100] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000751f1465 2 bytes [1F, 75]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[4100] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000751f14bb 2 bytes [1F, 75]
.text ... * 2
---- Threads - GMER 2.1 ----
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4704:5396] 000007fefb962a88
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4704:5412] 000007feec4dc0b0
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4704:5216] 000007fef9345124
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4704:2612] 000007feec449e68
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [4704:3068] 000007feec4dc0b0
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0c6076a27b11
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\889ffaddf14e
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\889ffaddf14e@f8db7ff96252 0xFC 0x76 0xF8 0x1A ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c0cb38ed02c9
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0c6076a27b11 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\889ffaddf14e (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\889ffaddf14e@f8db7ff96252 0xFC 0x76 0xF8 0x1A ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c0cb38ed02c9 (not active ControlSet)
---- EOF - GMER 2.1 ---- mbar 1. Durchgang: Code:
Malwarebytes Anti-Rootkit BETA 1.01.0.1021
www.malwarebytes.org
Database version: v2013.03.18.10
Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
*** :: ***-VAIO [administrator]
18.03.2013 17:42:35
mbar-log-2013-03-18 (17-42-35).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 31359
Time elapsed: 19 minute(s), 10 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Ywizanl (Trojan.Zbot) -> Data: C:\Users\***\AppData\Roaming\Qoeg\ysow.exe -> Delete on reboot.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
c:\Users\***\AppData\Roaming\Qoeg\ysow.exe (Trojan.Zbot) -> Delete on reboot.
(end) mbar 2. Durchgang: Code:
Malwarebytes Anti-Rootkit BETA 1.01.0.1021
www.malwarebytes.org
Database version: v2013.03.18.10
Windows 7 x64 NTFS
Internet Explorer 8.0.7600.16385
*** :: ***-VAIO [administrator]
18.03.2013 18:35:58
mbar-log-2013-03-18 (18-35-58).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 31323
Time elapsed: 21 minute(s), 30 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end) |