Mystrix847 | 13.05.2013 19:44 | Hier ist die GMER Logfile: Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-05-13 17:03:37
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.JE4O 698.64GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\Kilian\AppData\Local\Temp\agdiqkoc.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1816] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1816] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1816] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1816] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2000] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2000] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2000] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2000] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe[1656] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe[1656] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe[1656] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe[1656] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe[1172] C:\Windows\syswow64\user32.DLL!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe[1172] C:\Windows\syswow64\user32.DLL!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe[1172] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe[1172] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Users\Kilian\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe[1920] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Users\Kilian\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe[1920] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Users\Kilian\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe[1920] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Users\Kilian\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe[1920] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\Launch Manager\dsiwmis.exe[1940] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\Launch Manager\dsiwmis.exe[1940] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\Launch Manager\dsiwmis.exe[1940] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\Launch Manager\dsiwmis.exe[1940] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1832] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1832] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1832] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1832] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbguard.exe[1644] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbguard.exe[1644] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbguard.exe[1644] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbguard.exe[1644] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\Acer\Registration\GREGsvc.exe[1284] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\Acer\Registration\GREGsvc.exe[1284] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\Acer\Registration\GREGsvc.exe[1284] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\Acer\Registration\GREGsvc.exe[1284] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[2124] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[2124] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[2124] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[2124] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files\Acer\Acer Updater\UpdaterService.exe[2164] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files\Acer\Acer Updater\UpdaterService.exe[2164] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files\Acer\Acer Updater\UpdaterService.exe[2164] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files\Acer\Acer Updater\UpdaterService.exe[2164] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[2292] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[2292] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[2292] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[2292] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Windows\SysWOW64\PnkBstrA.exe[2324] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Windows\SysWOW64\PnkBstrA.exe[2324] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2324] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 322 0000000072901a22 2 bytes [90, 72]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2324] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 496 0000000072901ad0 2 bytes [90, 72]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2324] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 552 0000000072901b08 2 bytes [90, 72]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2324] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 730 0000000072901bba 2 bytes [90, 72]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2324] C:\Windows\SysWOW64\WSOCK32.dll!setsockopt + 762 0000000072901bda 2 bytes [90, 72]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2324] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Windows\SysWOW64\PnkBstrA.exe[2324] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2352] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2352] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2352] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe[2352] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe[2384] C:\Windows\syswow64\user32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe[2384] C:\Windows\syswow64\user32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe[2384] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe[2384] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2488] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2488] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2488] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe[2488] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files\Web Assistant\ExtensionUpdaterService.exe[2652] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files\Web Assistant\ExtensionUpdaterService.exe[2652] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files\Web Assistant\ExtensionUpdaterService.exe[2652] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files\Web Assistant\ExtensionUpdaterService.exe[2652] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe[3328] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe[3328] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe[3328] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\ProgramData\BrowserProtect\2.6.1249.132\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserProtect.exe[3328] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbserver.exe[3748] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbserver.exe[3748] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbserver.exe[3748] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbserver.exe[3748] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Windows\SysWOW64\jmdp\stij.exe[3080] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Windows\SysWOW64\jmdp\stij.exe[3080] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Windows\SysWOW64\jmdp\stij.exe[3080] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Windows\SysWOW64\jmdp\stij.exe[3080] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Users\Kilian\AppData\Local\Akamai\netsession_win.exe[4692] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Users\Kilian\AppData\Local\Akamai\netsession_win.exe[4692] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Users\Kilian\AppData\Local\Akamai\netsession_win.exe[4692] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Users\Kilian\AppData\Local\Akamai\netsession_win.exe[4692] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Users\Kilian\AppData\Local\Akamai\netsession_win.exe[1296] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Users\Kilian\AppData\Local\Akamai\netsession_win.exe[1296] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Users\Kilian\AppData\Local\Akamai\netsession_win.exe[1296] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Users\Kilian\AppData\Local\Akamai\netsession_win.exe[1296] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe[5012] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe[5012] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe[5012] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe[5012] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[1412] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[1412] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[1412] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[1412] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\Launch Manager\LManager.exe[4964] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\Launch Manager\LManager.exe[4964] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\Launch Manager\LManager.exe[4964] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\Launch Manager\LManager.exe[4964] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[5192] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[5192] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[5192] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[5192] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[5348] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[5348] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[5348] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[5348] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5432] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5432] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5432] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[5432] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[5648] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[5648] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[5648] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[5648] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[6080] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[6080] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[6080] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[6080] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe[2620] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe[2620] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe[2620] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe[2620] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5204] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5204] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5204] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5204] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\Nero\Update\NASvc.exe[2752] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\Nero\Update\NASvc.exe[2752] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\Nero\Update\NASvc.exe[2752] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\Nero\Update\NASvc.exe[2752] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6224] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6224] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6224] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[6224] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
.text C:\Users\Kilian\Desktop\gmer_2.1.19163.exe[6360] C:\Windows\syswow64\USER32.dll!DialogBoxParamW 000000007560cfca 3 bytes JMP 0000000172ec4720
.text C:\Users\Kilian\Desktop\gmer_2.1.19163.exe[6360] C:\Windows\syswow64\USER32.dll!DialogBoxParamW + 4 000000007560cfce 1 byte [FD]
.text C:\Users\Kilian\Desktop\gmer_2.1.19163.exe[6360] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075b21465 2 bytes [B2, 75]
.text C:\Users\Kilian\Desktop\gmer_2.1.19163.exe[6360] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000075b214bb 2 bytes [B2, 75]
.text ... * 2
---- Threads - GMER 2.1 ----
Thread C:\Windows\System32\svchost.exe [1348:6352] 000007fee5ec9688
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{059CA8FF-5492-40BE-B2CC-AB05F720ED30}\Connection@Name isatap.{02554915-0FBE-4626-93F6-B2DEED71CCF7}
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Bind \Device\{810F9C15-C0C2-4A7C-994D-C50FAA5273B3}?\Device\{7F0F642A-EDEB-43E1-ADD6-102BD2690CC4}?\Device\{EB9A7391-A053-4F50-8472-33537D6ECA9C}?\Device\{059CA8FF-5492-40BE-B2CC-AB05F720ED30}?\Device\{F3140A2B-1A7B-43DE-B21D-4BD8296E28E0}?\Device\{24EB0572-4FA3-43F7-B941-2812E1F7DDC8}?\Device\{B6AB53D4-258D-4247-9608-006FD886CD71}?\Device\{8DED5B8B-0327-4302-BCEA-43673C21CDF7}?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Route "{810F9C15-C0C2-4A7C-994D-C50FAA5273B3}"?"{7F0F642A-EDEB-43E1-ADD6-102BD2690CC4}"?"{EB9A7391-A053-4F50-8472-33537D6ECA9C}"?"{059CA8FF-5492-40BE-B2CC-AB05F720ED30}"?"{F3140A2B-1A7B-43DE-B21D-4BD8296E28E0}"?"{24EB0572-4FA3-43F7-B941-2812E1F7DDC8}"?"{B6AB53D4-258D-4247-9608-006FD886CD71}"?"{8DED5B8B-0327-4302-BCEA-43673C21CDF7}"?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Export \Device\TCPIP6TUNNEL_{810F9C15-C0C2-4A7C-994D-C50FAA5273B3}?\Device\TCPIP6TUNNEL_{7F0F642A-EDEB-43E1-ADD6-102BD2690CC4}?\Device\TCPIP6TUNNEL_{EB9A7391-A053-4F50-8472-33537D6ECA9C}?\Device\TCPIP6TUNNEL_{059CA8FF-5492-40BE-B2CC-AB05F720ED30}?\Device\TCPIP6TUNNEL_{F3140A2B-1A7B-43DE-B21D-4BD8296E28E0}?\Device\TCPIP6TUNNEL_{24EB0572-4FA3-43F7-B941-2812E1F7DDC8}?\Device\TCPIP6TUNNEL_{B6AB53D4-258D-4247-9608-006FD886CD71}?\Device\TCPIP6TUNNEL_{8DED5B8B-0327-4302-BCEA-43673C21CDF7}?
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\60d8198591a7
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\60d8198591a7@64995de83b29 0x98 0xD0 0xDC 0x59 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\60d8198591a7@58170c952e00 0x1F 0xCE 0x15 0x5E ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\60d8198591a7@945103fcde7d 0xE4 0x70 0x3F 0xD8 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\60d8198591a7@68ebae3d6ed5 0xA6 0xF2 0x22 0x80 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\60d8198591a7@4cbca5886c2c 0x50 0xC4 0x06 0x93 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{059CA8FF-5492-40BE-B2CC-AB05F720ED30}@InterfaceName isatap.{02554915-0FBE-4626-93F6-B2DEED71CCF7}
Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{059CA8FF-5492-40BE-B2CC-AB05F720ED30}@ReusableType 0
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\60d8198591a7 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\60d8198591a7@64995de83b29 0x98 0xD0 0xDC 0x59 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\60d8198591a7@58170c952e00 0x1F 0xCE 0x15 0x5E ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\60d8198591a7@945103fcde7d 0xE4 0x70 0x3F 0xD8 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\60d8198591a7@68ebae3d6ed5 0xA6 0xF2 0x22 0x80 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\60d8198591a7@4cbca5886c2c 0x50 0xC4 0x06 0x93 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4D00282C-2899-9BEE-497F-DB1BBC7C8498}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4D00282C-2899-9BEE-497F-DB1BBC7C8498}@haklcgfhmhjnecpf 0x6B 0x61 0x69 0x6B ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4D00282C-2899-9BEE-497F-DB1BBC7C8498}@iaiemimglmbjlbnbdl 0x63 0x61 0x62 0x6B ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4D00282C-2899-9BEE-497F-DB1BBC7C8498}@iaelehihbejfbdlgdd 0x6B 0x61 0x69 0x6B ...
---- EOF - GMER 2.1 ---- Gruß Kilian |