GMER Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-07-30 15:10:26
Windows 5.1.2600 Service Pack 3 \Device\Harddisk2\DR2 -> \Device\Scsi\nvgts1Port2Path0Target0Lun0 KINGSTON rev.502A 83,85GB
Running: gmer_2.1.19163.exe; Driver: R:\z_temp\TEMP\kwlyrpoc.sys
---- System - GMER 2.1 ----
SSDT \??\C:\WINDOWS\system32\Drivers\uphcleanhlp.sys ZwUnloadKey [0xB6FEF75C]
---- Kernel code sections - GMER 2.1 ----
? imofugc.sys Das System kann die angegebene Datei nicht finden. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF525E3C0, 0x74AA7A, 0xE8000020]
? C:\WINDOWS\system32\Drivers\uphcleanhlp.sys Das System kann die angegebene Datei nicht finden. !
---- User code sections - GMER 2.1 ----
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] ntdll.dll!NtCreateFile 7C91D0AE 1 Byte [FF]
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] ntdll.dll!NtCreateFile 7C91D0AE 3 Bytes [FF, 25, 1E]
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] ntdll.dll!NtCreateFile + 4 7C91D0B2 2 Bytes [7A, 71] {JP 0x73}
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] ntdll.dll!NtDeleteValueKey 7C91D26E 3 Bytes [FF, 25, 1E]
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] ntdll.dll!NtDeleteValueKey + 4 7C91D272 2 Bytes [80, 71]
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] ntdll.dll!NtOpenFile 7C91D59E 3 Bytes [FF, 25, 1E]
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] ntdll.dll!NtOpenFile + 4 7C91D5A2 2 Bytes [77, 71] {JA 0x73}
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] ntdll.dll!NtOpenProcess 7C91D5FE 3 Bytes [FF, 25, 1E]
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] ntdll.dll!NtOpenProcess + 4 7C91D602 2 Bytes [7D, 71] {JGE 0x73}
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] ntdll.dll!NtSetContextThread 7C91DBAE 3 Bytes [FF, 25, 1E]
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] ntdll.dll!NtSetContextThread + 4 7C91DBB2 2 Bytes [74, 71] {JZ 0x73}
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] ntdll.dll!NtSetValueKey 7C91DDCE 3 Bytes [FF, 25, 1E]
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] ntdll.dll!NtSetValueKey + 4 7C91DDD2 2 Bytes [83, 71]
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AF0001
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] kernel32.dll!CreateProcessInternalW 7C819EA8 3 Bytes [FF, 25, 1E]
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] kernel32.dll!CreateProcessInternalW + 4 7C819EAC 2 Bytes [71, 71] {JNO 0x73}
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] WS2_32.dll!WSALookupServiceBeginW 71A135EF 6 Bytes JMP 71A5000A
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] WS2_32.dll!connect 71A14A07 6 Bytes JMP 71AB000A
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] WS2_32.dll!listen 71A18CD3 6 Bytes JMP 71A8000A
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] ADVAPI32.dll!CreateServiceA 77E07219 6 Bytes JMP 718A000A
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] ADVAPI32.dll!CreateServiceW 77E073B1 6 Bytes JMP 7187000A
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] USER32.dll!PostMessageW 7E368CCB 6 Bytes JMP 718D000A
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] USER32.dll!SendMessageW 7E37929A 6 Bytes JMP 7193000A
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] USER32.dll!PostMessageA 7E37AAFD 6 Bytes JMP 7190000A
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] USER32.dll!SendInput 7E37F140 3 Bytes [FF, 25, 1E]
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] USER32.dll!SendInput + 4 7E37F144 2 Bytes [98, 71]
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] USER32.dll!SendMessageA 7E37F3C2 6 Bytes JMP 7196000A
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] USER32.dll!mouse_event 7E3B673F 6 Bytes JMP 719F000A
.text D:\_improve system\Free Extended Task Manager\Extensions\TaskManager\ExtensionsTaskManager32.exe[796] USER32.dll!keybd_event 7E3B6783 6 Bytes JMP 719C000A
.text C:\WINDOWS\Explorer.EXE[972] ntdll.dll!NtCreateFile 7C91D0AE 1 Byte [FF]
.text C:\WINDOWS\Explorer.EXE[972] ntdll.dll!NtCreateFile 7C91D0AE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[972] ntdll.dll!NtCreateFile + 4 7C91D0B2 2 Bytes [86, 71]
.text C:\WINDOWS\Explorer.EXE[972] ntdll.dll!NtDeleteValueKey 7C91D26E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[972] ntdll.dll!NtDeleteValueKey + 4 7C91D272 2 Bytes [8C, 71]
.text C:\WINDOWS\Explorer.EXE[972] ntdll.dll!NtOpenFile 7C91D59E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[972] ntdll.dll!NtOpenFile + 4 7C91D5A2 2 Bytes [83, 71]
.text C:\WINDOWS\Explorer.EXE[972] ntdll.dll!NtOpenProcess 7C91D5FE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[972] ntdll.dll!NtOpenProcess + 4 7C91D602 2 Bytes [89, 71]
.text C:\WINDOWS\Explorer.EXE[972] ntdll.dll!NtSetContextThread 7C91DBAE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[972] ntdll.dll!NtSetContextThread + 4 7C91DBB2 2 Bytes [80, 71]
.text C:\WINDOWS\Explorer.EXE[972] ntdll.dll!NtSetValueKey 7C91DDCE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[972] ntdll.dll!NtSetValueKey + 4 7C91DDD2 2 Bytes [8F, 71]
.text C:\WINDOWS\Explorer.EXE[972] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AF0001
.text C:\WINDOWS\Explorer.EXE[972] kernel32.dll!CreateProcessInternalW 7C819EA8 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[972] kernel32.dll!CreateProcessInternalW + 4 7C819EAC 2 Bytes [7D, 71] {JGE 0x73}
.text C:\WINDOWS\Explorer.EXE[972] ADVAPI32.dll!CreateServiceA 77E07219 6 Bytes JMP 7196000A
.text C:\WINDOWS\Explorer.EXE[972] ADVAPI32.dll!CreateServiceW 77E073B1 6 Bytes JMP 7193000A
.text C:\WINDOWS\Explorer.EXE[972] USER32.dll!PostMessageW 7E368CCB 6 Bytes JMP 7199000A
.text C:\WINDOWS\Explorer.EXE[972] USER32.dll!SendMessageW 7E37929A 6 Bytes JMP 719F000A
.text C:\WINDOWS\Explorer.EXE[972] USER32.dll!PostMessageA 7E37AAFD 6 Bytes JMP 719C000A
.text C:\WINDOWS\Explorer.EXE[972] USER32.dll!SendInput 7E37F140 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\Explorer.EXE[972] USER32.dll!SendInput + 4 7E37F144 2 Bytes [A4, 71]
.text C:\WINDOWS\Explorer.EXE[972] USER32.dll!SendMessageA 7E37F3C2 6 Bytes JMP 71A2000A
.text C:\WINDOWS\Explorer.EXE[972] USER32.dll!mouse_event 7E3B673F 6 Bytes JMP 71AB000A
.text C:\WINDOWS\Explorer.EXE[972] USER32.dll!keybd_event 7E3B6783 6 Bytes JMP 71A8000A
.text C:\WINDOWS\Explorer.EXE[972] WS2_32.dll!WSALookupServiceBeginW 038A35EF 6 Bytes JMP 716C000A
.text C:\WINDOWS\Explorer.EXE[972] WS2_32.dll!connect 038A4A07 6 Bytes JMP 7172000A
.text C:\WINDOWS\Explorer.EXE[972] WS2_32.dll!listen 038A8CD3 6 Bytes JMP 716F000A
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] ntdll.dll!NtCreateFile 7C91D0AE 1 Byte [FF]
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] ntdll.dll!NtCreateFile 7C91D0AE 3 Bytes [FF, 25, 1E]
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] ntdll.dll!NtCreateFile + 4 7C91D0B2 2 Bytes [70, 71] {JO 0x73}
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] ntdll.dll!NtDeleteValueKey 7C91D26E 3 Bytes [FF, 25, 1E]
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] ntdll.dll!NtDeleteValueKey + 4 7C91D272 2 Bytes [76, 71] {JBE 0x73}
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] ntdll.dll!NtOpenFile 7C91D59E 3 Bytes [FF, 25, 1E]
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] ntdll.dll!NtOpenFile + 4 7C91D5A2 2 Bytes [6D, 71]
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] ntdll.dll!NtOpenProcess 7C91D5FE 3 Bytes [FF, 25, 1E]
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] ntdll.dll!NtOpenProcess + 4 7C91D602 2 Bytes [73, 71] {JAE 0x73}
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] ntdll.dll!NtSetContextThread 7C91DBAE 3 Bytes [FF, 25, 1E]
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] ntdll.dll!NtSetContextThread + 4 7C91DBB2 2 Bytes [6A, 71] {PUSH 0x71}
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] ntdll.dll!NtSetValueKey 7C91DDCE 3 Bytes [FF, 25, 1E]
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] ntdll.dll!NtSetValueKey + 4 7C91DDD2 2 Bytes [79, 71] {JNS 0x73}
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AC0001
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] kernel32.dll!CreateProcessInternalW 7C819EA8 3 Bytes [FF, 25, 1E]
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] kernel32.dll!CreateProcessInternalW + 4 7C819EAC 2 Bytes [67, 71]
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] ADVAPI32.dll!CreateServiceA 77E07219 6 Bytes JMP 7180000A
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] ADVAPI32.dll!CreateServiceW 77E073B1 6 Bytes JMP 717D000A
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] USER32.dll!PostMessageW 7E368CCB 6 Bytes JMP 7183000A
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] USER32.dll!SendMessageW 7E37929A 6 Bytes JMP 7189000A
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] USER32.dll!PostMessageA 7E37AAFD 6 Bytes JMP 7186000A
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] USER32.dll!SendInput 7E37F140 3 Bytes [FF, 25, 1E]
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] USER32.dll!SendInput + 4 7E37F144 2 Bytes [8E, 71]
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] USER32.dll!SendMessageA 7E37F3C2 6 Bytes JMP 718C000A
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] USER32.dll!mouse_event 7E3B673F 6 Bytes JMP 7195000A
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] USER32.dll!keybd_event 7E3B6783 6 Bytes JMP 7192000A
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] WS2_32.dll!WSALookupServiceBeginW 71A135EF 6 Bytes JMP 7198000A
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] WS2_32.dll!connect 71A14A07 6 Bytes JMP 719E000A
.text C:\Programme\Microsoft IntelliType Pro\itype.exe[1592] WS2_32.dll!listen 71A18CD3 6 Bytes JMP 719B000A
.text C:\WINDOWS\system32\RunDLL32.exe[1940] ntdll.dll!NtCreateFile 7C91D0AE 1 Byte [FF]
.text C:\WINDOWS\system32\RunDLL32.exe[1940] ntdll.dll!NtCreateFile 7C91D0AE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RunDLL32.exe[1940] ntdll.dll!NtCreateFile + 4 7C91D0B2 2 Bytes [86, 71]
.text C:\WINDOWS\system32\RunDLL32.exe[1940] ntdll.dll!NtDeleteValueKey 7C91D26E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RunDLL32.exe[1940] ntdll.dll!NtDeleteValueKey + 4 7C91D272 2 Bytes [8C, 71]
.text C:\WINDOWS\system32\RunDLL32.exe[1940] ntdll.dll!NtOpenFile 7C91D59E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RunDLL32.exe[1940] ntdll.dll!NtOpenFile + 4 7C91D5A2 2 Bytes [83, 71]
.text C:\WINDOWS\system32\RunDLL32.exe[1940] ntdll.dll!NtOpenProcess 7C91D5FE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RunDLL32.exe[1940] ntdll.dll!NtOpenProcess + 4 7C91D602 2 Bytes [89, 71]
.text C:\WINDOWS\system32\RunDLL32.exe[1940] ntdll.dll!NtSetContextThread 7C91DBAE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RunDLL32.exe[1940] ntdll.dll!NtSetContextThread + 4 7C91DBB2 2 Bytes [80, 71]
.text C:\WINDOWS\system32\RunDLL32.exe[1940] ntdll.dll!NtSetValueKey 7C91DDCE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RunDLL32.exe[1940] ntdll.dll!NtSetValueKey + 4 7C91DDD2 2 Bytes [8F, 71]
.text C:\WINDOWS\system32\RunDLL32.exe[1940] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AF0001
.text C:\WINDOWS\system32\RunDLL32.exe[1940] kernel32.dll!CreateProcessInternalW 7C819EA8 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RunDLL32.exe[1940] kernel32.dll!CreateProcessInternalW + 4 7C819EAC 2 Bytes [7D, 71] {JGE 0x73}
.text C:\WINDOWS\system32\RunDLL32.exe[1940] USER32.dll!PostMessageW 7E368CCB 6 Bytes JMP 7199000A
.text C:\WINDOWS\system32\RunDLL32.exe[1940] USER32.dll!SendMessageW 7E37929A 6 Bytes JMP 719F000A
.text C:\WINDOWS\system32\RunDLL32.exe[1940] USER32.dll!PostMessageA 7E37AAFD 6 Bytes JMP 719C000A
.text C:\WINDOWS\system32\RunDLL32.exe[1940] USER32.dll!SendInput 7E37F140 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RunDLL32.exe[1940] USER32.dll!SendInput + 4 7E37F144 2 Bytes [A4, 71]
.text C:\WINDOWS\system32\RunDLL32.exe[1940] USER32.dll!SendMessageA 7E37F3C2 6 Bytes JMP 71A2000A
.text C:\WINDOWS\system32\RunDLL32.exe[1940] USER32.dll!mouse_event 7E3B673F 6 Bytes JMP 71AB000A
.text C:\WINDOWS\system32\RunDLL32.exe[1940] USER32.dll!keybd_event 7E3B6783 6 Bytes JMP 71A8000A
.text C:\WINDOWS\system32\RunDLL32.exe[1940] ADVAPI32.dll!CreateServiceA 77E07219 6 Bytes JMP 7196000A
.text C:\WINDOWS\system32\RunDLL32.exe[1940] ADVAPI32.dll!CreateServiceW 77E073B1 6 Bytes JMP 7193000A
.text C:\WINDOWS\system32\RunDLL32.exe[1940] WS2_32.dll!WSALookupServiceBeginW 00BD35EF 6 Bytes JMP 716A000A
.text C:\WINDOWS\system32\RunDLL32.exe[1940] WS2_32.dll!connect 00BD4A07 6 Bytes JMP 7172000A
.text C:\WINDOWS\system32\RunDLL32.exe[1940] WS2_32.dll!listen 00BD8CD3 6 Bytes JMP 716D000A
.text C:\WINDOWS\system32\rundll32.exe[2052] ntdll.dll!NtCreateFile 7C91D0AE 1 Byte [FF]
.text C:\WINDOWS\system32\rundll32.exe[2052] ntdll.dll!NtCreateFile 7C91D0AE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\rundll32.exe[2052] ntdll.dll!NtCreateFile + 4 7C91D0B2 2 Bytes [86, 71]
.text C:\WINDOWS\system32\rundll32.exe[2052] ntdll.dll!NtDeleteValueKey 7C91D26E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\rundll32.exe[2052] ntdll.dll!NtDeleteValueKey + 4 7C91D272 2 Bytes [8C, 71]
.text C:\WINDOWS\system32\rundll32.exe[2052] ntdll.dll!NtOpenFile 7C91D59E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\rundll32.exe[2052] ntdll.dll!NtOpenFile + 4 7C91D5A2 2 Bytes [83, 71]
.text C:\WINDOWS\system32\rundll32.exe[2052] ntdll.dll!NtOpenProcess 7C91D5FE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\rundll32.exe[2052] ntdll.dll!NtOpenProcess + 4 7C91D602 2 Bytes [89, 71]
.text C:\WINDOWS\system32\rundll32.exe[2052] ntdll.dll!NtSetContextThread 7C91DBAE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\rundll32.exe[2052] ntdll.dll!NtSetContextThread + 4 7C91DBB2 2 Bytes [80, 71]
.text C:\WINDOWS\system32\rundll32.exe[2052] ntdll.dll!NtSetValueKey 7C91DDCE 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\rundll32.exe[2052] ntdll.dll!NtSetValueKey + 4 7C91DDD2 2 Bytes [8F, 71]
.text C:\WINDOWS\system32\rundll32.exe[2052] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AF0001
.text C:\WINDOWS\system32\rundll32.exe[2052] kernel32.dll!CreateProcessInternalW 7C819EA8 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\rundll32.exe[2052] kernel32.dll!CreateProcessInternalW + 4 7C819EAC 2 Bytes [7D, 71] {JGE 0x73}
.text C:\WINDOWS\system32\rundll32.exe[2052] USER32.dll!PostMessageW 7E368CCB 6 Bytes JMP 7199000A
.text C:\WINDOWS\system32\rundll32.exe[2052] USER32.dll!SendMessageW 7E37929A 6 Bytes JMP 719F000A
.text C:\WINDOWS\system32\rundll32.exe[2052] USER32.dll!PostMessageA 7E37AAFD 6 Bytes JMP 719C000A
.text C:\WINDOWS\system32\rundll32.exe[2052] USER32.dll!SendInput 7E37F140 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\rundll32.exe[2052] USER32.dll!SendInput + 4 7E37F144 2 Bytes [A4, 71]
.text C:\WINDOWS\system32\rundll32.exe[2052] USER32.dll!SendMessageA 7E37F3C2 6 Bytes JMP 71A2000A
.text C:\WINDOWS\system32\rundll32.exe[2052] USER32.dll!mouse_event 7E3B673F 6 Bytes JMP 71AB000A
.text C:\WINDOWS\system32\rundll32.exe[2052] USER32.dll!keybd_event 7E3B6783 6 Bytes JMP 71A8000A
.text C:\WINDOWS\system32\rundll32.exe[2052] ADVAPI32.dll!CreateServiceA 77E07219 6 Bytes JMP 7196000A
.text C:\WINDOWS\system32\rundll32.exe[2052] ADVAPI32.dll!CreateServiceW 77E073B1 6 Bytes JMP 7193000A
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] ntdll.dll!NtCreateFile 7C91D0AE 1 Byte [FF]
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] ntdll.dll!NtCreateFile 7C91D0AE 3 Bytes [FF, 25, 1E]
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] ntdll.dll!NtCreateFile + 4 7C91D0B2 2 Bytes [80, 71]
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] ntdll.dll!NtDeleteValueKey 7C91D26E 3 Bytes [FF, 25, 1E]
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] ntdll.dll!NtDeleteValueKey + 4 7C91D272 2 Bytes [86, 71]
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] ntdll.dll!NtOpenFile 7C91D59E 3 Bytes [FF, 25, 1E]
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] ntdll.dll!NtOpenFile + 4 7C91D5A2 2 Bytes [7D, 71] {JGE 0x73}
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] ntdll.dll!NtOpenProcess 7C91D5FE 3 Bytes [FF, 25, 1E]
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] ntdll.dll!NtOpenProcess + 4 7C91D602 2 Bytes [83, 71]
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] ntdll.dll!NtSetContextThread 7C91DBAE 3 Bytes [FF, 25, 1E]
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] ntdll.dll!NtSetContextThread + 4 7C91DBB2 2 Bytes [7A, 71] {JP 0x73}
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] ntdll.dll!NtSetValueKey 7C91DDCE 3 Bytes [FF, 25, 1E]
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] ntdll.dll!NtSetValueKey + 4 7C91DDD2 2 Bytes [89, 71]
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AF0001
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] kernel32.dll!CreateProcessInternalW 7C819EA8 3 Bytes [FF, 25, 1E]
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] kernel32.dll!CreateProcessInternalW + 4 7C819EAC 2 Bytes [77, 71] {JA 0x73}
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] USER32.dll!PostMessageW 7E368CCB 6 Bytes JMP 7193000A
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] USER32.dll!SendMessageW 7E37929A 6 Bytes JMP 7199000A
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] USER32.dll!PostMessageA 7E37AAFD 6 Bytes JMP 7196000A
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] USER32.dll!SendInput 7E37F140 3 Bytes [FF, 25, 1E]
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] USER32.dll!SendInput + 4 7E37F144 2 Bytes [9E, 71]
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] USER32.dll!SendMessageA 7E37F3C2 6 Bytes JMP 719C000A
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] USER32.dll!mouse_event 7E3B673F 6 Bytes JMP 71A5000A
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] USER32.dll!keybd_event 7E3B6783 6 Bytes JMP 71A2000A
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] ADVAPI32.dll!CreateServiceA 77E07219 6 Bytes JMP 7190000A
.text D:\_improve system\MMTaskbar 3.0\MultiMon.exe[2072] ADVAPI32.dll!CreateServiceW 77E073B1 6 Bytes JMP 718D000A
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] ntdll.dll!NtCreateFile 7C91D0AE 1 Byte [FF]
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] ntdll.dll!NtCreateFile 7C91D0AE 3 Bytes [FF, 25, 1E]
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] ntdll.dll!NtCreateFile + 4 7C91D0B2 2 Bytes [84, 71]
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] ntdll.dll!NtDeleteValueKey 7C91D26E 3 Bytes [FF, 25, 1E]
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] ntdll.dll!NtDeleteValueKey + 4 7C91D272 2 Bytes [8A, 71]
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] ntdll.dll!NtOpenFile 7C91D59E 3 Bytes [FF, 25, 1E]
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] ntdll.dll!NtOpenFile + 4 7C91D5A2 2 Bytes [81, 71]
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] ntdll.dll!NtOpenProcess 7C91D5FE 3 Bytes [FF, 25, 1E]
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] ntdll.dll!NtOpenProcess + 4 7C91D602 2 Bytes [87, 71]
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] ntdll.dll!NtSetContextThread 7C91DBAE 3 Bytes [FF, 25, 1E]
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] ntdll.dll!NtSetContextThread + 4 7C91DBB2 2 Bytes [7E, 71] {JLE 0x73}
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] ntdll.dll!NtSetValueKey 7C91DDCE 3 Bytes [FF, 25, 1E]
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] ntdll.dll!NtSetValueKey + 4 7C91DDD2 2 Bytes [8D, 71]
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AF0001
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] kernel32.dll!CreateProcessInternalW 7C819EA8 3 Bytes [FF, 25, 1E]
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] kernel32.dll!CreateProcessInternalW + 4 7C819EAC 2 Bytes [7B, 71] {JNP 0x73}
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] ADVAPI32.dll!CreateServiceA 77E07219 6 Bytes JMP 7194000A
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] ADVAPI32.dll!CreateServiceW 77E073B1 6 Bytes JMP 7191000A
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] USER32.dll!PostMessageW 7E368CCB 6 Bytes JMP 7197000A
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] USER32.dll!SendMessageW 7E37929A 6 Bytes JMP 719D000A
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] USER32.dll!PostMessageA 7E37AAFD 6 Bytes JMP 719A000A
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] USER32.dll!SendInput 7E37F140 3 Bytes [FF, 25, 1E]
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] USER32.dll!SendInput + 4 7E37F144 2 Bytes [A2, 71]
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] USER32.dll!SendMessageA 7E37F3C2 6 Bytes JMP 71A0000A
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] USER32.dll!mouse_event 7E3B673F 6 Bytes JMP 71AB000A
.text D:\_filemanagement\xplorer² pro\xplorer2_UC.exe[2788] USER32.dll!keybd_event 7E3B6783 6 Bytes JMP 71A6000A
.text C:\Programme\Launchy\Launchy.exe[3008] ntdll.dll!NtCreateFile 7C91D0AE 1 Byte [FF]
.text C:\Programme\Launchy\Launchy.exe[3008] ntdll.dll!NtCreateFile 7C91D0AE 3 Bytes [FF, 25, 1E]
.text C:\Programme\Launchy\Launchy.exe[3008] ntdll.dll!NtCreateFile + 4 7C91D0B2 2 Bytes [74, 71] {JZ 0x73}
.text C:\Programme\Launchy\Launchy.exe[3008] ntdll.dll!NtDeleteValueKey 7C91D26E 3 Bytes [FF, 25, 1E]
.text C:\Programme\Launchy\Launchy.exe[3008] ntdll.dll!NtDeleteValueKey + 4 7C91D272 2 Bytes [7A, 71] {JP 0x73}
.text C:\Programme\Launchy\Launchy.exe[3008] ntdll.dll!NtOpenFile 7C91D59E 3 Bytes [FF, 25, 1E]
.text C:\Programme\Launchy\Launchy.exe[3008] ntdll.dll!NtOpenFile + 4 7C91D5A2 2 Bytes [71, 71] {JNO 0x73}
.text C:\Programme\Launchy\Launchy.exe[3008] ntdll.dll!NtOpenProcess 7C91D5FE 3 Bytes [FF, 25, 1E]
.text C:\Programme\Launchy\Launchy.exe[3008] ntdll.dll!NtOpenProcess + 4 7C91D602 2 Bytes [77, 71] {JA 0x73}
.text C:\Programme\Launchy\Launchy.exe[3008] ntdll.dll!NtSetContextThread 7C91DBAE 3 Bytes [FF, 25, 1E]
.text C:\Programme\Launchy\Launchy.exe[3008] ntdll.dll!NtSetContextThread + 4 7C91DBB2 2 Bytes [6E, 71]
.text C:\Programme\Launchy\Launchy.exe[3008] ntdll.dll!NtSetValueKey 7C91DDCE 3 Bytes [FF, 25, 1E]
.text C:\Programme\Launchy\Launchy.exe[3008] ntdll.dll!NtSetValueKey + 4 7C91DDD2 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Programme\Launchy\Launchy.exe[3008] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AF0001
.text C:\Programme\Launchy\Launchy.exe[3008] kernel32.dll!CreateProcessInternalW 7C819EA8 3 Bytes [FF, 25, 1E]
.text C:\Programme\Launchy\Launchy.exe[3008] kernel32.dll!CreateProcessInternalW + 4 7C819EAC 2 Bytes [6B, 71]
.text C:\Programme\Launchy\Launchy.exe[3008] ADVAPI32.dll!CreateServiceA 77E07219 6 Bytes JMP 7184000A
.text C:\Programme\Launchy\Launchy.exe[3008] ADVAPI32.dll!CreateServiceW 77E073B1 6 Bytes JMP 7181000A
.text C:\Programme\Launchy\Launchy.exe[3008] USER32.dll!PostMessageW 7E368CCB 6 Bytes JMP 7187000A
.text C:\Programme\Launchy\Launchy.exe[3008] USER32.dll!SendMessageW 7E37929A 6 Bytes JMP 718D000A
.text C:\Programme\Launchy\Launchy.exe[3008] USER32.dll!PostMessageA 7E37AAFD 6 Bytes JMP 718A000A
.text C:\Programme\Launchy\Launchy.exe[3008] USER32.dll!SendInput 7E37F140 3 Bytes [FF, 25, 1E]
.text C:\Programme\Launchy\Launchy.exe[3008] USER32.dll!SendInput + 4 7E37F144 2 Bytes [92, 71]
.text C:\Programme\Launchy\Launchy.exe[3008] USER32.dll!SendMessageA 7E37F3C2 6 Bytes JMP 7190000A
.text C:\Programme\Launchy\Launchy.exe[3008] USER32.dll!mouse_event 7E3B673F 6 Bytes JMP 7199000A
.text C:\Programme\Launchy\Launchy.exe[3008] USER32.dll!keybd_event 7E3B6783 6 Bytes JMP 7196000A
.text C:\Programme\Launchy\Launchy.exe[3008] WS2_32.dll!WSALookupServiceBeginW 71A135EF 6 Bytes JMP 719C000A
.text C:\Programme\Launchy\Launchy.exe[3008] WS2_32.dll!connect 71A14A07 6 Bytes JMP 71A5000A
.text C:\Programme\Launchy\Launchy.exe[3008] WS2_32.dll!listen 71A18CD3 6 Bytes JMP 719F000A
.text D:\_improve system\WindowManager\WindowManager.exe[3028] ntdll.dll!NtCreateFile 7C91D0AE 1 Byte [FF]
.text D:\_improve system\WindowManager\WindowManager.exe[3028] ntdll.dll!NtCreateFile 7C91D0AE 3 Bytes [FF, 25, 1E]
.text D:\_improve system\WindowManager\WindowManager.exe[3028] ntdll.dll!NtCreateFile + 4 7C91D0B2 2 Bytes [79, 71] {JNS 0x73}
.text D:\_improve system\WindowManager\WindowManager.exe[3028] ntdll.dll!NtDeleteValueKey 7C91D26E 3 Bytes [FF, 25, 1E]
.text D:\_improve system\WindowManager\WindowManager.exe[3028] ntdll.dll!NtDeleteValueKey + 4 7C91D272 2 Bytes [7F, 71] {JG 0x73}
.text D:\_improve system\WindowManager\WindowManager.exe[3028] ntdll.dll!NtOpenFile 7C91D59E 3 Bytes [FF, 25, 1E]
.text D:\_improve system\WindowManager\WindowManager.exe[3028] ntdll.dll!NtOpenFile + 4 7C91D5A2 2 Bytes [76, 71] {JBE 0x73}
.text D:\_improve system\WindowManager\WindowManager.exe[3028] ntdll.dll!NtOpenProcess 7C91D5FE 3 Bytes [FF, 25, 1E]
.text D:\_improve system\WindowManager\WindowManager.exe[3028] ntdll.dll!NtOpenProcess + 4 7C91D602 2 Bytes [7C, 71] {JL 0x73}
.text D:\_improve system\WindowManager\WindowManager.exe[3028] ntdll.dll!NtSetContextThread 7C91DBAE 3 Bytes [FF, 25, 1E]
.text D:\_improve system\WindowManager\WindowManager.exe[3028] ntdll.dll!NtSetContextThread + 4 7C91DBB2 2 Bytes [73, 71] {JAE 0x73}
.text D:\_improve system\WindowManager\WindowManager.exe[3028] ntdll.dll!NtSetValueKey 7C91DDCE 3 Bytes [FF, 25, 1E]
.text D:\_improve system\WindowManager\WindowManager.exe[3028] ntdll.dll!NtSetValueKey + 4 7C91DDD2 2 Bytes [82, 71]
.text D:\_improve system\WindowManager\WindowManager.exe[3028] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AF0001
.text D:\_improve system\WindowManager\WindowManager.exe[3028] kernel32.dll!CreateProcessInternalW 7C819EA8 3 Bytes [FF, 25, 1E]
.text D:\_improve system\WindowManager\WindowManager.exe[3028] kernel32.dll!CreateProcessInternalW + 4 7C819EAC 2 Bytes [70, 71] {JO 0x73}
.text D:\_improve system\WindowManager\WindowManager.exe[3028] USER32.dll!PostMessageW 7E368CCB 6 Bytes JMP 718C000A
.text D:\_improve system\WindowManager\WindowManager.exe[3028] USER32.dll!SendMessageW 7E37929A 6 Bytes JMP 7192000A
.text D:\_improve system\WindowManager\WindowManager.exe[3028] USER32.dll!PostMessageA 7E37AAFD 6 Bytes JMP 718F000A
.text D:\_improve system\WindowManager\WindowManager.exe[3028] USER32.dll!SendInput 7E37F140 3 Bytes [FF, 25, 1E]
.text D:\_improve system\WindowManager\WindowManager.exe[3028] USER32.dll!SendInput + 4 7E37F144 2 Bytes [97, 71]
.text D:\_improve system\WindowManager\WindowManager.exe[3028] USER32.dll!SendMessageA 7E37F3C2 6 Bytes JMP 7195000A
.text D:\_improve system\WindowManager\WindowManager.exe[3028] USER32.dll!mouse_event 7E3B673F 6 Bytes JMP 719E000A
.text D:\_improve system\WindowManager\WindowManager.exe[3028] USER32.dll!keybd_event 7E3B6783 6 Bytes JMP 719B000A
.text D:\_improve system\WindowManager\WindowManager.exe[3028] ADVAPI32.dll!CreateServiceA 77E07219 6 Bytes JMP 7189000A
.text D:\_improve system\WindowManager\WindowManager.exe[3028] ADVAPI32.dll!CreateServiceW 77E073B1 6 Bytes JMP 7186000A
.text D:\_improve system\WindowManager\WindowManager.exe[3028] WS2_32.dll!WSALookupServiceBeginW 71A135EF 6 Bytes JMP 71A5000A
.text D:\_improve system\WindowManager\WindowManager.exe[3028] WS2_32.dll!connect 71A14A07 6 Bytes JMP 71AB000A
.text D:\_improve system\WindowManager\WindowManager.exe[3028] WS2_32.dll!listen 71A18CD3 6 Bytes JMP 71A8000A
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] ntdll.dll!NtCreateFile 7C91D0AE 1 Byte [FF]
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] ntdll.dll!NtCreateFile 7C91D0AE 3 Bytes [FF, 25, 1E]
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] ntdll.dll!NtCreateFile + 4 7C91D0B2 2 Bytes [7E, 71] {JLE 0x73}
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] ntdll.dll!NtDeleteValueKey 7C91D26E 3 Bytes [FF, 25, 1E]
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] ntdll.dll!NtDeleteValueKey + 4 7C91D272 2 Bytes [84, 71]
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] ntdll.dll!NtOpenFile 7C91D59E 3 Bytes [FF, 25, 1E]
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] ntdll.dll!NtOpenFile + 4 7C91D5A2 2 Bytes [7B, 71] {JNP 0x73}
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] ntdll.dll!NtOpenProcess 7C91D5FE 3 Bytes [FF, 25, 1E]
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] ntdll.dll!NtOpenProcess + 4 7C91D602 2 Bytes [81, 71]
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] ntdll.dll!NtSetContextThread 7C91DBAE 3 Bytes [FF, 25, 1E]
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] ntdll.dll!NtSetContextThread + 4 7C91DBB2 2 Bytes [78, 71] {JS 0x73}
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] ntdll.dll!NtSetValueKey 7C91DDCE 3 Bytes [FF, 25, 1E]
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] ntdll.dll!NtSetValueKey + 4 7C91DDD2 2 Bytes [87, 71]
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AF0001
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] kernel32.dll!CreateProcessInternalW 7C819EA8 3 Bytes [FF, 25, 1E]
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] kernel32.dll!CreateProcessInternalW + 4 7C819EAC 2 Bytes [75, 71] {JNZ 0x73}
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] user32.dll!PostMessageW 7E368CCB 6 Bytes JMP 7191000A
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] user32.dll!SendMessageW 7E37929A 6 Bytes JMP 7197000A
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] user32.dll!PostMessageA 7E37AAFD 6 Bytes JMP 7194000A
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] user32.dll!SendInput 7E37F140 3 Bytes [FF, 25, 1E]
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] user32.dll!SendInput + 4 7E37F144 2 Bytes [9C, 71]
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] user32.dll!SendMessageA 7E37F3C2 6 Bytes JMP 719A000A
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] user32.dll!mouse_event 7E3B673F 6 Bytes JMP 71A3000A
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] user32.dll!keybd_event 7E3B6783 6 Bytes JMP 71A0000A
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] advapi32.dll!CreateServiceA 77E07219 6 Bytes JMP 718E000A
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] advapi32.dll!CreateServiceW 77E073B1 6 Bytes JMP 718B000A
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] WS2_32.dll!WSALookupServiceBeginW 010535EF 6 Bytes JMP 716D000A
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] WS2_32.dll!connect 01054A07 6 Bytes JMP 7173000A
.text C:\Programme\TweakRAM\TweakRAM.exe[3568] WS2_32.dll!listen 01058CD3 6 Bytes JMP 7170000A
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] ntdll.dll!NtCreateFile 7C91D0AE 1 Byte [FF]
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] ntdll.dll!NtCreateFile 7C91D0AE 3 Bytes [FF, 25, 1E]
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] ntdll.dll!NtCreateFile + 4 7C91D0B2 2 Bytes [86, 71]
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] ntdll.dll!NtDeleteValueKey 7C91D26E 3 Bytes [FF, 25, 1E]
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] ntdll.dll!NtDeleteValueKey + 4 7C91D272 2 Bytes [8C, 71]
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] ntdll.dll!NtOpenFile 7C91D59E 3 Bytes [FF, 25, 1E]
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] ntdll.dll!NtOpenFile + 4 7C91D5A2 2 Bytes [83, 71]
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] ntdll.dll!NtOpenProcess 7C91D5FE 3 Bytes [FF, 25, 1E]
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] ntdll.dll!NtOpenProcess + 4 7C91D602 2 Bytes [89, 71]
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] ntdll.dll!NtSetContextThread 7C91DBAE 3 Bytes [FF, 25, 1E]
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] ntdll.dll!NtSetContextThread + 4 7C91DBB2 2 Bytes [80, 71]
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] ntdll.dll!NtSetValueKey 7C91DDCE 3 Bytes [FF, 25, 1E]
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] ntdll.dll!NtSetValueKey + 4 7C91DDD2 2 Bytes [8F, 71]
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] kernel32.dll!LoadLibraryExW + C4 7C801BB9 4 Bytes CALL 71AF0001
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] kernel32.dll!CreateProcessInternalW 7C819EA8 3 Bytes [FF, 25, 1E]
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] kernel32.dll!CreateProcessInternalW + 4 7C819EAC 2 Bytes [7D, 71] {JGE 0x73}
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] USER32.dll!PostMessageW 7E368CCB 6 Bytes JMP 7199000A
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] USER32.dll!SendMessageW 7E37929A 6 Bytes JMP 719F000A
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] USER32.dll!PostMessageA 7E37AAFD 6 Bytes JMP 719C000A
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] USER32.dll!SendInput 7E37F140 3 Bytes [FF, 25, 1E]
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] USER32.dll!SendInput + 4 7E37F144 2 Bytes [A4, 71]
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] USER32.dll!SendMessageA 7E37F3C2 6 Bytes JMP 71A2000A
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] USER32.dll!mouse_event 7E3B673F 6 Bytes JMP 71AB000A
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] USER32.dll!keybd_event 7E3B6783 6 Bytes JMP 71A8000A
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] ADVAPI32.dll!CreateServiceA 77E07219 6 Bytes JMP 7196000A
.text E:\_ dropbox _\Dropbox\_ install new\__new\z_security\gmer_2.1.19163.exe[3880] ADVAPI32.dll!CreateServiceW 77E073B1 6 Bytes JMP 7193000A
---- Devices - GMER 2.1 ----
AttachedDevice \FileSystem\Ntfs \Ntfs tdrpman.sys
Device \FileSystem\Fastfat \FatCdrom B6C0BD20
Device \Driver\Ftdisk \Device\HarddiskVolume12 fltsrv.sys
Device \Driver\Ftdisk \Device\HarddiskVolume13 fltsrv.sys
Device \FileSystem\mbamchameleon \Device\devmbamchameleon B7C48690
Device \Driver\Ftdisk \Device\HarddiskVolume1 fltsrv.sys
Device \Driver\Ftdisk \Device\HarddiskVolume2 fltsrv.sys
Device \Driver\Ftdisk \Device\HarddiskVolume3 fltsrv.sys
Device \Driver\Ftdisk \Device\HarddiskVolume4 fltsrv.sys
Device \Driver\Ftdisk \Device\HarddiskVolume5 fltsrv.sys
Device \Driver\Ftdisk \Device\HarddiskVolume6 fltsrv.sys
Device \Driver\Ftdisk \Device\HarddiskVolume7 fltsrv.sys
Device \Driver\Ftdisk \Device\HarddiskVolume8 fltsrv.sys
Device \Driver\Ftdisk \Device\HarddiskVolume9 fltsrv.sys
Device \Driver\Disk \Device\Harddisk0\DR0 fltsrv.sys
Device \Driver\Disk \Device\Harddisk1\DR1 fltsrv.sys
Device \Driver\Disk \Device\Harddisk2\DR2 fltsrv.sys
Device \Driver\Disk \Device\Harddisk3\DR3 fltsrv.sys
Device \Driver\Disk \Device\Harddisk4\DR15 fltsrv.sys
Device \Driver\Disk \Device\Harddisk5\DR17 fltsrv.sys
Device \Driver\Disk \Device\Harddisk6\DR18 fltsrv.sys
Device \Driver\Disk \Device\Harddisk6\DP(1)0-0+14 fltsrv.sys
Device \Driver\Ftdisk \Device\FtControl fltsrv.sys
Device \Driver\Ftdisk \Device\HarddiskVolume10 fltsrv.sys
Device \Driver\Ftdisk \Device\HarddiskVolume11 fltsrv.sys
Device \FileSystem\Fastfat \Fat B6C0BD20
AttachedDevice \FileSystem\Fastfat \Fat tdrpman.sys
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Video\{ACF7F00A-9B7C-4D40-AAED-C312A9DDBC3F}\0000@D3D_\x3332\x3331 2089309684
Reg HKLM\SYSTEM\CurrentControlSet\Control\Video\{ACF7F00A-9B7C-4D40-AAED-C312A9DDBC3F}\0001@D3D_\x3332\x3331 2089309684
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODLED04.00.00.01PRO F7C90C2AC8D53403A2FB679DB2ADB952034760D4970E4B5D902751551A7F82C05576423479BF298BCB4DD9353F413F46D1266931F87B01462FD3FCDC80898F55A15087C9DB2114A004D096CD21490884002F1825F3F3FD9952A2B2F71259811F15C72BA1EAA8072BAEFA5DCB4B0BE8B3BAFD3DE19673F4DB8F72F2C793BB0E21D0A27E644699D84A15166F87D65E77AD10022B0D9205DE4460F8C1DA70132E0FD5F756332F4B224EDFC095CCFEAF1001F6FCBA3DBA4A783D223B28B9B4559FD10CB58CA10E2AC23C216B185CA47FD1714586C7818AF940E6961733DD138E6204BB1DFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA9C6AECB7A5D1407BA7FD869164D6794A6171C11EC38DE3DA2D97226D213B555A99332BF30528C42E977DA8E1C6D6CBB24E314FB4BAC987BAD52806BA8192D7C8EB8A3B8068BA828D483649581123E5F0064303DEC9FB6CF716D9F725597601D767F3452089F995DDF839EF13941D95BA8799FD1AD625AB225566F9DF806443A54ABB2B8CE667AB6AF2891A55FD1E2E812E2453248E5CEE33278C9770F926CB3A17697ACB469C75B6C976CC6CECA5E15395327683A51C3F2803431A2579ECF42D88C7A05DAE9E146C26D0100A868384018F07094467CCCC602DDC75255C1CA6FF89096AAA55B8F49E235C410531
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OOCC7.00.00.01PROSTATION AB867CD6552FEDAC1F1E44BDFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA9C6AECB7A5D1407A2D97226D213B555FEBC9E127BECC74CA9C6AECB7A5D14072B2ADC3BF16A3C3468F6FB8565377C9DC0043D8F39596D3EA801DFC2BDBABBBA2DEE702F1A4ED291979DE9288569C559B5EAEC270E6E465522D97B086C4FB6D4257351916AD2BC63A27DC24B5DB8EE469880B028A89E12542F990C7ED6C2DD8ED220E551BD8ADE15681B93643665D8668884612D6476C6F04E5DD283898E6471B512792DF0FA46268A32D1B75F24074CE7EF3B9EA07683F4C4F9764316219D9D1399393B6620A0AAEFAE54DE2C9C2322DE6DDD3BBF1508BB9A767EC48FDD064375BB39E2826940C841B1D5C7F1E9F522D6594F96AC3A39B79C0ED85E1019B82AA8AEED63B0B99D3DEE9275B40B9D721E01C7F6174FC2A06ED93158BB349D7AAB3EE1B24BDD6752D5A95838BAD8BA2A78507F21F71A01EA79270330DC1AA9AEB58B75C600FABD9E75E7C384C33AB956AB7AFA7EC67E37E8851D5AFA16E96EE14C293B4ABA7EFCE315E343260F998653C27AE7A367F6228FD29644B68EC992BF8475BE46086155A9BE1B7ECB2CDD019FDD91290891FCEBF7B9347E44C268AF9B888F3C24C722711B93D04D8A0279FCDF32C1D4094E11375E205AFDE701745469175E22B0B
---- EOF - GMER 2.1 ---- MBAR 1 Code:
Malwarebytes Anti-Rootkit BETA 1.06.0.1004
www.malwarebytes.org
Database version: v2013.07.30.05
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Elmar-Admin :: ASUS-A8N [administrator]
30.07.13 14:00:24
mbar-log-2013-07-30 (14-00-24).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P
Scan options disabled: PUP
Objects scanned: 328107
Time elapsed: 9 minute(s), 59 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 1
HKLM\SOFTWARE\CLASSES\CLSID\{CA4520F3-AE13-4FB1-A513-58E23991C86D} (Trojan.Downloader) -> Delete on reboot.
Registry Values Detected: 2
HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER|ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Data: 1 -> No action taken.
HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER|NoFolderOptions (Hijack.FolderOptions) -> Data: 1 -> No action taken.
Registry Data Items Detected: 1
HKLM\SOFTWARE\CLASSES\DRIVE\SHELL| (Hijack.Drives) -> Bad: (open) Good: (none) -> Replace on reboot.
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
c:\windows\kb971513.log (Extension.Mismatch) -> Delete on reboot.
Physical Sectors Detected: 2
Physical Sector #64 on Drive #1 (Unknown.Rootkit.VBR) -> Replace on reboot.
Master Boot Record on Drive #1 (Unknown.Rootkit.VBR) -> Replace on reboot.
(end)
MBAR2 Code:
Malwarebytes Anti-Rootkit BETA 1.06.0.1004
www.malwarebytes.org
Database version: v2013.07.30.05
Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Elmar-Admin :: ASUS-A8N [administrator]
30.07.13 14:27:15
mbar-log-2013-07-30 (14-27-15).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P
Scan options disabled: PUP
Objects scanned: 325185
Time elapsed: 7 minute(s), 11 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 2
HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER|ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Data: 1 -> No action taken.
HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER|NoFolderOptions (Hijack.FolderOptions) -> Data: 1 -> No action taken.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end)
VIELEN DANK für Deine Mühen!!!
Elmar |