Huhu,
hier dann der richtige Post. Danke für den Hinweis:
(Kurze Wiederholung zu meinem Anliegen:
kannst du mir sagen, was meinen Arbeitsspeicher dauerhaft zu ca. 80 % auslastet?) Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 14:20 on 06/04/2014 (Kazuya)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01
Ran by Kazuya (administrator) on KOICHI on 06-04-2014 14:30:20
Running from C:\Users\Kazuya\Downloads\Schritt für Schritt
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\windows\system32\WLANExt.exe
(Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
(Seiko Epson Corporation) C:\windows\system32\EscSvc.exe
(IObit) C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Vodafone) C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\Event Manager\EEventManager.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIJAE.EXE
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(Microsoft Corporation) C:\windows\system32\wuauclt.exe
(Intel Corporation) C:\windows\system32\igfxsrvc.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [FUFAXRCV] - C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe [502952 2012-07-09] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [FUFAXSTM] - C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe [863400 2012-07-09] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [EEventManager] - C:\Program Files\Epson Software\Event Manager\EEventManager.exe [1058912 2012-04-02] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3854640 2014-04-05] (AVAST Software)
HKU\.DEFAULT\...\RunOnce: [WLStart] - C:\Program Files\Windows Live\Installer\wlstart.exe [786760 2009-07-26] (Microsoft Corporation)
HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\Run: [EPLTarget\P0000000000000000] - C:\windows\system32\spool\DRIVERS\W32X86\3\E_FATIJAE.EXE [249440 2012-02-29] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\MountPoints2: {10f43e9d-bb56-11df-a143-806e6f6e6963} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\MountPoints2: {1b8f9919-b087-11e0-bbb2-705ab658f2fe} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\MountPoints2: {1b8f9923-b087-11e0-bbb2-705ab658f2fe} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\MountPoints2: {2f3f4fe1-a70b-11e0-a1f6-705ab658f2fe} - F:\Install.exe
HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\MountPoints2: {61a25b02-bb94-11df-b98d-705ab658f2fe} - F:\setup_vmc_lite.exe /checkApplicationPresence
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
URLSearchHook: HKCU - (No Name) - {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - No File
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll No File
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - No Name - {8DBB6D8E-E4A6-4E3B-9753-AF78B226441C} - No File
Toolbar: HKCU - No Name - {30F9B915-B755-4826-820B-08FBA6BD249D} - No File
Toolbar: HKCU - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Kazuya\AppData\Roaming\Mozilla\Firefox\Profiles\miuov82a.default-1388595698206
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-04-05]
========================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-05] (AVAST Software)
R2 EpsonScanSvc; C:\windows\system32\EscSvc.exe [122000 2011-12-12] (Seiko Epson Corporation)
R2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2151744 2013-12-31] (IObit)
S4 MSSQLServerADHelper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation)
R2 VMCService; C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [14336 2008-07-04] (Vodafone)
S4 AntiVirWebService; "C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe" [X]
==================== Drivers (Whitelisted) ====================
R3 ACPIVPC; C:\windows\System32\DRIVERS\AcpiVpc.sys [21520 2009-05-19] (Lenovo Corporation)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [67824 2014-04-05] (AVAST Software)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [81768 2014-04-05] (AVAST Software)
R0 aswRvrt; C:\windows\system32\Drivers\aswRvrt.sys [49944 2014-04-05] ()
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [776976 2014-04-05] (AVAST Software)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [411552 2014-04-05] (AVAST Software)
R3 aswStm; C:\windows\system32\drivers\aswStm.sys [67264 2014-04-05] (AVAST Software)
R0 aswVmm; C:\windows\system32\Drivers\aswVmm.sys [180760 2014-04-05] ()
R1 funfrm; C:\windows\system32\Drivers\funfrm.sys [54800 2010-02-09] ()
S3 wdmirror; C:\windows\System32\DRIVERS\WDMirror.sys [11792 2009-07-16] (Windows (R) Codename Longhorn DDK provider)
S3 wsvd; C:\windows\System32\DRIVERS\wsvd.sys [81704 2009-07-21] (CyberLink)
S3 ApfiltrService; system32\DRIVERS\Apfiltr.sys [X]
S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
S3 WinRing0_1_2_0; \??\D:\test\ECECECEC\WinRing0.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-06 14:28 - 2014-04-06 14:30 - 00000000 ____D () C:\FRST
2014-04-06 14:20 - 2014-04-06 14:21 - 00000474 _____ () C:\Users\Kazuya\Desktop\defogger_disable.log
2014-04-06 14:20 - 2014-04-06 14:20 - 00000000 _____ () C:\Users\Kazuya\defogger_reenable
2014-04-06 14:17 - 2014-04-06 14:30 - 00000000 ____D () C:\Users\Kazuya\Downloads\Schritt für Schritt
2014-04-06 14:16 - 2014-04-06 14:16 - 00050477 _____ () C:\Users\Kazuya\Desktop\Defogger.exe
2014-04-05 22:42 - 2014-04-05 22:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Local\Macromedia
2014-04-05 22:39 - 2014-04-05 22:39 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-04-05 22:25 - 2014-04-05 22:25 - 00001028 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-04-05 22:10 - 2014-04-06 13:57 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-04-05 21:58 - 2014-04-05 21:58 - 00002123 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-04-05 21:58 - 2014-04-05 21:58 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\AVAST Software
2014-04-05 21:57 - 2014-04-05 21:57 - 00776976 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00271264 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2014-04-05 21:57 - 2014-04-05 21:57 - 00180760 _____ () C:\windows\system32\Drivers\aswVmm.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00081768 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00067824 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00067264 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00049944 _____ () C:\windows\system32\Drivers\aswRvrt.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2014-04-05 21:56 - 2014-04-05 21:56 - 00000000 ____D () C:\Program Files\AVAST Software
2014-04-05 21:51 - 2014-04-05 21:51 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\rtgdysgh.sys
2014-04-05 21:50 - 2014-04-05 21:54 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-04-05 21:50 - 2014-04-05 21:50 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\ptzlzhni.sys
2014-04-05 21:37 - 2014-04-05 21:38 - 88551496 _____ (AVAST Software) C:\Users\Kazuya\Downloads\avast_free_antivirus_setup.exe
2014-03-31 08:50 - 2014-03-31 08:53 - 00004979 _____ () C:\Users\Kazuya\Downloads\Statistik Konzeptverkäufer HRO 4 2014.ods
2014-03-25 20:14 - 2014-03-25 20:15 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-03-25 20:14 - 2014-03-25 20:14 - 00000000 ____D () C:\Program Files\Adobe
2014-03-16 19:32 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-03-16 19:32 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-03-16 19:32 - 2014-03-01 06:10 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-03-16 19:32 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-03-16 19:32 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-03-16 19:32 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-03-16 19:32 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-03-16 19:32 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-03-16 19:32 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-03-16 19:32 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-03-16 19:32 - 2014-03-01 05:38 - 00108032 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-03-16 19:32 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-03-16 19:32 - 2014-03-01 05:31 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-03-16 19:32 - 2014-03-01 05:25 - 00208896 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-03-16 19:32 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-03-16 19:32 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-03-16 19:32 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-03-16 19:32 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-03-16 19:32 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-03-16 19:32 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-03-16 19:32 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-03-16 19:32 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-03-16 19:26 - 2014-02-07 03:07 - 02349056 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-03-16 19:26 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2014-03-16 19:26 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2014-03-16 19:26 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2014-03-16 19:26 - 2014-01-28 04:07 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
2014-03-11 13:59 - 2014-03-21 23:56 - 00010532 _____ () C:\Users\Kazuya\Desktop\autoabzahlung dez12-dez14.xlsx
2014-03-11 13:57 - 2014-03-25 20:23 - 00000000 ____D () C:\Users\Kazuya\Desktop\stuff
2014-03-11 13:56 - 2014-03-11 13:56 - 00011350 _____ () C:\Users\Kazuya\Desktop\Kostenaufstellung.xlsx
==================== One Month Modified Files and Folders =======
2014-04-06 14:30 - 2014-04-06 14:28 - 00000000 ____D () C:\FRST
2014-04-06 14:30 - 2014-04-06 14:17 - 00000000 ____D () C:\Users\Kazuya\Downloads\Schritt für Schritt
2014-04-06 14:28 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-06 14:28 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-06 14:21 - 2014-04-06 14:20 - 00000474 _____ () C:\Users\Kazuya\Desktop\defogger_disable.log
2014-04-06 14:20 - 2014-04-06 14:20 - 00000000 _____ () C:\Users\Kazuya\defogger_reenable
2014-04-06 14:20 - 2010-09-08 16:02 - 00000000 ____D () C:\Users\Kazuya
2014-04-06 14:16 - 2014-04-06 14:16 - 00050477 _____ () C:\Users\Kazuya\Desktop\Defogger.exe
2014-04-06 14:15 - 2010-02-09 10:45 - 01912579 _____ () C:\windows\WindowsUpdate.log
2014-04-06 14:09 - 2013-09-24 19:27 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-04-06 14:09 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-04-06 14:09 - 2009-07-14 06:39 - 00113231 _____ () C:\windows\setupact.log
2014-04-06 13:57 - 2014-04-05 22:10 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-04-06 13:56 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\tracing
2014-04-06 00:41 - 2010-01-18 19:03 - 01765534 _____ () C:\windows\system32\PerfStringBackup.INI
2014-04-05 22:42 - 2014-04-05 22:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Local\Macromedia
2014-04-05 22:39 - 2014-04-05 22:39 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-04-05 22:25 - 2014-04-05 22:25 - 00001028 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-04-05 22:16 - 2013-09-24 18:58 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2014-04-05 22:16 - 2013-04-07 17:59 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
2014-04-05 21:58 - 2014-04-05 21:58 - 00002123 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-04-05 21:58 - 2014-04-05 21:58 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\AVAST Software
2014-04-05 21:57 - 2014-04-05 21:57 - 00776976 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00271264 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2014-04-05 21:57 - 2014-04-05 21:57 - 00180760 _____ () C:\windows\system32\Drivers\aswVmm.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00081768 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00067824 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00067264 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00049944 _____ () C:\windows\system32\Drivers\aswRvrt.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2014-04-05 21:56 - 2014-04-05 21:56 - 00000000 ____D () C:\Program Files\AVAST Software
2014-04-05 21:54 - 2014-04-05 21:50 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-04-05 21:51 - 2014-04-05 21:51 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\rtgdysgh.sys
2014-04-05 21:50 - 2014-04-05 21:50 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\ptzlzhni.sys
2014-04-05 21:49 - 2010-01-18 19:12 - 00631348 _____ () C:\windows\PFRO.log
2014-04-05 21:48 - 2013-09-28 21:38 - 00000000 ____D () C:\ProgramData\Avira
2014-04-05 21:38 - 2014-04-05 21:37 - 88551496 _____ (AVAST Software) C:\Users\Kazuya\Downloads\avast_free_antivirus_setup.exe
2014-04-05 21:29 - 2009-07-14 06:52 - 00000000 ____D () C:\windows\system32\FxsTmp
2014-04-05 20:27 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\wfp
2014-04-05 20:26 - 2011-01-28 17:09 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\vlc
2014-04-05 20:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\NDF
2014-04-05 20:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\AppCompat
2014-04-05 20:25 - 2010-01-18 18:57 - 00000000 __RHD () C:\MSOCache
2014-04-05 20:25 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\registration
2014-04-01 01:53 - 2009-07-29 12:50 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-03-31 08:53 - 2014-03-31 08:50 - 00004979 _____ () C:\Users\Kazuya\Downloads\Statistik Konzeptverkäufer HRO 4 2014.ods
2014-03-26 21:26 - 2013-12-31 19:52 - 00000000 ____D () C:\ProgramData\ProductData
2014-03-25 20:23 - 2014-03-11 13:57 - 00000000 ____D () C:\Users\Kazuya\Desktop\stuff
2014-03-25 20:19 - 2010-01-18 19:13 - 00000000 ____D () C:\ProgramData\Adobe
2014-03-25 20:18 - 2010-09-15 15:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\Adobe
2014-03-25 20:17 - 2010-09-15 15:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Local\Adobe
2014-03-25 20:15 - 2014-03-25 20:14 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-03-25 20:14 - 2014-03-25 20:14 - 00000000 ____D () C:\Program Files\Adobe
2014-03-21 23:56 - 2014-03-11 13:59 - 00010532 _____ () C:\Users\Kazuya\Desktop\autoabzahlung dez12-dez14.xlsx
2014-03-16 19:41 - 2009-07-14 06:33 - 00414320 _____ () C:\windows\system32\FNTCACHE.DAT
2014-03-16 19:36 - 2013-09-30 15:36 - 00000000 ____D () C:\windows\system32\MRT
2014-03-16 19:33 - 2013-09-30 15:36 - 87350280 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-03-11 13:59 - 2010-09-13 21:36 - 00000000 ____D () C:\Users\Public\Documents\texte
2014-03-11 13:56 - 2014-03-11 13:56 - 00011350 _____ () C:\Users\Kazuya\Desktop\Kostenaufstellung.xlsx
Some content of TEMP:
====================
C:\Users\Kazuya\AppData\Local\Temp\0kzpwa6k.dll
C:\Users\Kazuya\AppData\Local\Temp\2f5dddvp.dll
C:\Users\Kazuya\AppData\Local\Temp\33972uninstall.exe
C:\Users\Kazuya\AppData\Local\Temp\3im0mncd.dll
C:\Users\Kazuya\AppData\Local\Temp\4vtwgrfo.dll
C:\Users\Kazuya\AppData\Local\Temp\6vuldinv.dll
C:\Users\Kazuya\AppData\Local\Temp\7xcn6fpl.dll
C:\Users\Kazuya\AppData\Local\Temp\7z916.exe
C:\Users\Kazuya\AppData\Local\Temp\8ceuvc6z.dll
C:\Users\Kazuya\AppData\Local\Temp\agtp5wny.dll
C:\Users\Kazuya\AppData\Local\Temp\app.exe
C:\Users\Kazuya\AppData\Local\Temp\avgnt.exe
C:\Users\Kazuya\AppData\Local\Temp\BackupSetup.exe
C:\Users\Kazuya\AppData\Local\Temp\BundleSweetIMSetup.exe
C:\Users\Kazuya\AppData\Local\Temp\cbyaagar.dll
C:\Users\Kazuya\AppData\Local\Temp\DeleteEcUninstall.exe
C:\Users\Kazuya\AppData\Local\Temp\donw3fx6.dll
C:\Users\Kazuya\AppData\Local\Temp\drm_dyndata_7400005.dll
C:\Users\Kazuya\AppData\Local\Temp\eq1x7zjn.dll
C:\Users\Kazuya\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe
C:\Users\Kazuya\AppData\Local\Temp\g3-rymre.dll
C:\Users\Kazuya\AppData\Local\Temp\GLF848F.tmp.ConduitEngineSetup.exe
C:\Users\Kazuya\AppData\Local\Temp\i399ol3f.dll
C:\Users\Kazuya\AppData\Local\Temp\ilsqm4bc.dll
C:\Users\Kazuya\AppData\Local\Temp\l6wk4tg7.dll
C:\Users\Kazuya\AppData\Local\Temp\lrun8vok.dll
C:\Users\Kazuya\AppData\Local\Temp\mg02ea0h.dll
C:\Users\Kazuya\AppData\Local\Temp\MybabylonTB.exe
C:\Users\Kazuya\AppData\Local\Temp\ncq7qzzc.dll
C:\Users\Kazuya\AppData\Local\Temp\ndtdsia_.dll
C:\Users\Kazuya\AppData\Local\Temp\nf_lag8i.dll
C:\Users\Kazuya\AppData\Local\Temp\p9jdhxwr.dll
C:\Users\Kazuya\AppData\Local\Temp\promote-upx.exe
C:\Users\Kazuya\AppData\Local\Temp\propsys.dll
C:\Users\Kazuya\AppData\Local\Temp\pzcx1s-o.dll
C:\Users\Kazuya\AppData\Local\Temp\SIntf16.dll
C:\Users\Kazuya\AppData\Local\Temp\SIntf32.dll
C:\Users\Kazuya\AppData\Local\Temp\SIntfNT.dll
C:\Users\Kazuya\AppData\Local\Temp\Softonic_Deutsch.exe
C:\Users\Kazuya\AppData\Local\Temp\Sqlite3.dll
C:\Users\Kazuya\AppData\Local\Temp\tbSoft.dll
C:\Users\Kazuya\AppData\Local\Temp\tbu15B1.exe
C:\Users\Kazuya\AppData\Local\Temp\tbu17B5.exe
C:\Users\Kazuya\AppData\Local\Temp\tbuF4BA.exe
C:\Users\Kazuya\AppData\Local\Temp\uchhlufn.dll
C:\Users\Kazuya\AppData\Local\Temp\uninst1.exe
C:\Users\Kazuya\AppData\Local\Temp\uninstall.exe
C:\Users\Kazuya\AppData\Local\Temp\vbxb5orq.dll
C:\Users\Kazuya\AppData\Local\Temp\vcredist_x86.exe
C:\Users\Kazuya\AppData\Local\Temp\w8dqhfu5.dll
C:\Users\Kazuya\AppData\Local\Temp\wm4bjeyn.dll
C:\Users\Kazuya\AppData\Local\Temp\wtr2y8ud.dll
C:\Users\Kazuya\AppData\Local\Temp\yfejxr3f.dll
C:\Users\Kazuya\AppData\Local\Temp\yg6mvt_-.dll
C:\Users\Kazuya\AppData\Local\Temp\yurmxiym.dll
C:\Users\Kazuya\AppData\Local\Temp\_isC2A3.exe
C:\Users\Kazuya\AppData\Local\Temp\_isE780.exe
==================== Bamital & volsnap Check =================
C:\windows\explorer.exe => MD5 is legit
C:\windows\system32\winlogon.exe => MD5 is legit
C:\windows\system32\wininit.exe => MD5 is legit
C:\windows\system32\svchost.exe => MD5 is legit
C:\windows\system32\services.exe => MD5 is legit
C:\windows\system32\User32.dll => MD5 is legit
C:\windows\system32\userinit.exe => MD5 is legit
C:\windows\system32\rpcss.dll => MD5 is legit
C:\windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-31 03:14
==================== End Of Log ============================ --- --- --- Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 13-03-2014 01
Ran by Kazuya at 2014-04-06 14:31:13
Running from C:\Users\Kazuya\Downloads\Schritt für Schritt
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden
Adobe Flash Player 12 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
avast! Free Antivirus (HKLM\...\Avast) (Version: 9.0.2016 - Avast Software)
Broadcom 802.11 Wireless Driver (HKLM\...\{8991E763-21F5-4DEA-A938-5D9D77DCB488}) (Version: 1.0.0.0 - )
Business Contact Manager für Outlook 2007 SP2 (HKLM\...\Business Contact Manager) (Version: 3.0.8619.1 - Microsoft Corporation)
Business Contact Manager für Outlook 2007 SP2 (Version: 3.0.8619.1 - Microsoft Corporation) Hidden
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 4.98.4.0 - Conexant)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{81FB7C60-565A-4869-9D90-3BE1D270E8B7}) (Version: - Microsoft)
Energy Management (HKLM\...\{AE1E24C2-E720-42D5-B8E1-48F71A97B4DB}) (Version: 4.3.1.5 - Lenovo)
Epson Benutzerhandbuch XP-800 Series (HKLM\...\XP-800 Series Useg) (Version: - )
Epson Connect Guide (HKLM\...\Epson Connect Guide) (Version: - )
Epson Event Manager (HKLM\...\{8F01524C-0676-4CC1-B4AE-64753C723391}) (Version: 3.01.0005 - Seiko Epson Corporation)
Epson FAX Utility (HKLM\...\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 1.31.00 - SEIKO EPSON CORPORATION)
Epson Netzwerkhandbuch XP-800 Series (HKLM\...\XP-800 Series Netg) (Version: - )
Epson PC-FAX Driver (HKLM\...\EPSON PC-FAX Driver 2) (Version: - )
EPSON Scan (HKLM\...\EPSON Scanner) (Version: - Seiko Epson Corporation)
EPSON XP-800 Series Printer Uninstall (HKLM\...\EPSON XP-800 Series) (Version: - SEIKO EPSON Corporation)
EpsonNet Print (HKLM\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.5.00 - SEIKO EPSON CORPORATION)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: - Intel Corporation)
Intel(R) TV Wizard (HKLM\...\TVWiz) (Version: - Intel Corporation)
Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation)
Junk Mail filter update (Version: 14.0.8089.726 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
Microsoft Choice Guard (Version: 2.0.48.0 - Microsoft Corporation) Hidden
Microsoft Office 2003 Web Components (HKLM\...\{90A40407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8003.0 - Microsoft Corporation)
Microsoft Office 2007 Primary Interop Assemblies (HKLM\...\{50120000-1105-0000-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Student 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Small Business Connectivity Components (HKLM\...\{A939D341-5A04-4E0A-BB55-3E65B386432D}) (Version: 2.0.7024.0 - Microsoft Corporation)
Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft SQL Server 2005 (HKLM\...\Microsoft SQL Server 2005) (Version: - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) (Version: 9.4.5000.00 - Microsoft Corporation) Hidden
Microsoft SQL Server Native Client (HKLM\...\{7670D32F-DAE6-4E49-8C8B-B3F08B5B1686}) (Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft SQL Server Setup Support Files (English) (HKLM\...\{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}) (Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft SQL Server VSS Writer (HKLM\...\{E7084B89-69E0-46B3-A118-8F99D06988CD}) (Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Sync Framework Services Native v1.0 (x86) (HKLM\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 28.0 (x86 de) (HKLM\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla)
MSVCRT (Version: 14.0.1468.721 - Microsoft) Hidden
Power2Go (HKLM\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.4809d4 - CyberLink Corp.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (Version: - Microsoft) Hidden
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{001E8BF3-EDC3-4D5E-9C11-1D0E599B6497}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{D7D96A96-F61F-48AD-B2DC-4F4B6938D2AB}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{B5C70C99-B109-42FD-B219-FF12CA543F19}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{3EFF1957-7DEA-4C7A-8E9C-2D6D58E4B2ED}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (HKLM\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{81812245-FC84-426A-BC02-6659C88CC7B2}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{190EC86F-5867-4D7A-B9F3-D14D82C26F3D}) (Version: - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{8C55AA83-54C2-4236-A622-78440A411DC5}) (Version: - Microsoft)
Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{E78E2B68-8FD1-42EE-BB74-99A4D9E6222D}) (Version: - Microsoft)
VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Vodafone Mobile Connect Lite (HKLM\...\{C656142F-EFE1-44CD-BFAD-6CBC6DCB9860}) (Version: 9.3.3.10523 - Vodafone)
Windows Live Call (Version: 14.0.8064.0206 - Microsoft Corporation) Hidden
Windows Live Communications Platform (Version: 14.0.8064.206 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation)
Windows Live Essentials (Version: 14.0.8089.726 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (Version: 14.0.8081.709 - Microsoft Corporation) Hidden
Windows Live Mail (Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live Messenger (Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live Movie Maker (Version: 14.0.8091.0730 - Microsoft Corporation) Hidden
Windows Live Sync (HKLM\...\{76618402-179D-4699-A66B-D351C59436BC}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Live Writer (Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live-Uploadtool (HKLM\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
WinRAR 5.01 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
==================== Restore Points =========================
16-03-2014 17:32:50 Windows Update
21-03-2014 21:40:57 Windows Update
30-03-2014 19:20:30 Windows Update
31-03-2014 23:50:43 Wiederherstellungsvorgang
03-04-2014 17:52:58 Windows Update
05-04-2014 18:11:15 Wiederherstellungsvorgang
05-04-2014 19:56:02 avast! antivirus system restore point
==================== Hosts content: ==========================
2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {2F88FC51-99EC-417F-A32F-C4FEE72D7DF6} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-04-05] (AVAST Software)
Task: {5134E82E-2A0D-4C9F-9736-29215B99C6C9} - System32\Tasks\{70EC7443-1025-4672-BBD2-4F8A7C694DCE} => C:\Program Files\Ablaze\ablaze_v106.exe
Task: {5A517D2E-F200-4FF2-A957-EEB67D57964D} - System32\Tasks\Adobe Flash Player Updater => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-05] (Adobe Systems Incorporated)
Task: {93A6E725-6732-4B51-9BF7-89AD55373E9C} - System32\Tasks\{2D5CFE77-0C81-42B1-B938-1A843BEF1831} => C:\Program Files\Ablaze\ablaze_v106.exe
Task: {A2B5D60B-552E-4F64-B5B1-4C15B48D83FF} - System32\Tasks\{089487B7-4BEA-4417-B583-30CDBA1402C3} => C:\Program Files\Ablaze\ablaze_v106.exe
Task: {B2A1CFFD-E741-47CE-92FC-EC8B3332D205} - System32\Tasks\{C7C8E65B-5D02-4ABA-95EB-BA64C2D24D5E} => C:\Program Files\Ablaze\ablaze_v106.exe
Task: {BB2F5FE5-7D8B-4571-9178-D91B49A53A0D} - System32\Tasks\{8EF0B629-6E06-40A5-8B8D-1B74D49EBD5C} => C:\Program Files\Ablaze\ablaze_v106.exe
Task: {C76794B6-1B4F-4332-8489-3C42ED98A25C} - System32\Tasks\{BB7A5E64-78D6-4D3C-9F15-1899A5E8C355} => C:\Program Files\Ablaze\ablaze_v106.exe
Task: {C8DD6C9E-6149-40EF-B2A1-018EA0C02921} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {E3C06A89-3FF8-421A-A1E3-27030FBD2837} - System32\Tasks\{C056EB45-A940-48FF-A65A-1D3D68FDFFD4} => C:\Program Files\Ablaze\ablaze_v106.exe
Task: {FD9171C0-7AAF-443F-83CF-28E5E2562BE3} - System32\Tasks\{0619CB49-03E9-470F-A041-410D67E10D97} => C:\Program Files\Ablaze\ablaze_v106.exe
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2014-04-06 13:56 - 2014-04-06 13:56 - 02189824 _____ () C:\Program Files\AVAST Software\Avast\defs\14040600\algo.dll
2014-04-05 21:57 - 2014-04-05 21:57 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-04-05 22:39 - 2014-04-05 22:39 - 03642480 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== Disabled items from MSCONFIG ==============
MSCONFIG\startupreg: avgnt => "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
MSCONFIG\startupreg: Energy Management => C:\Program Files\Lenovo\Energy Management\Energy Management.exe
MSCONFIG\startupreg: EnergyUtility => C:\Program Files\Lenovo\Energy Management\utility.exe
MSCONFIG\startupreg: HotKeysCmds => C:\windows\system32\hkcmd.exe
MSCONFIG\startupreg: IAAnotif => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
MSCONFIG\startupreg: IgfxTray => C:\windows\system32\igfxtray.exe
MSCONFIG\startupreg: MobileConnect => %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
MSCONFIG\startupreg: mobilegeni daemon => C:\Program Files\Mobogenie\DaemonProcess.exe
MSCONFIG\startupreg: Persistence => C:\windows\system32\igfxpers.exe
MSCONFIG\startupreg: SmartAudio => C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
MSCONFIG\startupreg: UpdateP2GShortCut => "C:\Program Files\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (04/06/2014 02:10:12 PM) (Source: VMCService) (User: )
Description: conflictManagerTypeValue
Error: (04/06/2014 01:54:47 PM) (Source: VMCService) (User: )
Description: conflictManagerTypeValue
Error: (04/06/2014 00:37:14 AM) (Source: VMCService) (User: )
Description: conflictManagerTypeValue
Error: (04/05/2014 09:56:12 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddLegacyDriverFiles: Unable to back up image of binary xpvzlpga.
System Error:
Das System kann die angegebene Datei nicht finden.
.
Error: (04/05/2014 09:56:01 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {777785d9-4bbc-4c2b-8619-a7e65b0de15b}
Error: (04/05/2014 09:52:54 PM) (Source: VMCService) (User: )
Description: conflictManagerTypeValue
Error: (04/05/2014 08:27:25 PM) (Source: Avira Antivirus) (User: NT-AUTORITÄT)
Description: 0x0
Error: (04/05/2014 08:15:51 PM) (Source: VMCService) (User: )
Description: conflictManagerTypeValue
Error: (04/05/2014 08:07:44 PM) (Source: VMCService) (User: )
Description: conflictManagerTypeValue
Error: (04/05/2014 07:44:03 PM) (Source: VMCService) (User: )
Description: conflictManagerTypeValue
System errors:
=============
Error: (04/05/2014 09:51:22 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (04/05/2014 09:51:01 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (04/05/2014 09:50:12 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (04/05/2014 09:50:12 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (04/05/2014 09:50:12 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (04/05/2014 09:50:12 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (04/05/2014 09:50:12 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (04/05/2014 09:50:12 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (04/05/2014 09:50:10 PM) (Source: DCOM) (User: )
Description: 1084WSearch{9E175B6D-F52A-11D8-B9A5-505054503030}
Error: (04/05/2014 09:50:10 PM) (Source: DCOM) (User: )
Description: 1084WSearch{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Microsoft Office Sessions:
=========================
Error: (04/06/2014 02:10:12 PM) (Source: VMCService)(User: )
Description: conflictManagerTypeValue
Error: (04/06/2014 01:54:47 PM) (Source: VMCService)(User: )
Description: conflictManagerTypeValue
Error: (04/06/2014 00:37:14 AM) (Source: VMCService)(User: )
Description: conflictManagerTypeValue
Error: (04/05/2014 09:56:12 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddLegacyDriverFiles: Unable to back up image of binary xpvzlpga.
System Error:
Das System kann die angegebene Datei nicht finden.
Error: (04/05/2014 09:56:01 PM) (Source: VSS)(User: )
Description: 0x80070005, Zugriff verweigert
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {777785d9-4bbc-4c2b-8619-a7e65b0de15b}
Error: (04/05/2014 09:52:54 PM) (Source: VMCService)(User: )
Description: conflictManagerTypeValue
Error: (04/05/2014 08:27:25 PM) (Source: Avira Antivirus)(User: NT-AUTORITÄT)
Description: 0x0
Error: (04/05/2014 08:15:51 PM) (Source: VMCService)(User: )
Description: conflictManagerTypeValue
Error: (04/05/2014 08:07:44 PM) (Source: VMCService)(User: )
Description: conflictManagerTypeValue
Error: (04/05/2014 07:44:03 PM) (Source: VMCService)(User: )
Description: conflictManagerTypeValue
==================== Memory info ===========================
Percentage of memory in use: 77%
Total physical RAM: 984.6 MB
Available physical RAM: 216.92 MB
Total Pagefile: 2008.6 MB
Available Pagefile: 931.06 MB
Total Virtual: 2047.88 MB
Available Virtual: 1903.04 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:187.69 GB) (Free:156.28 GB) NTFS
Drive d: (Lenovo) (Fixed) (Total:30.25 GB) (Free:28.5 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: BEC90B8D)
Partition: GPT Partition Type.
==================== End Of Log ============================ Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-04-06 15:40:57
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD25 rev.01.0 232,89GB
Running: k23zf1j3.exe; Driver: C:\Users\Kazuya\AppData\Local\Temp\fxldqpog.sys
---- System - GMER 2.1 ----
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAddBootEntry [0x8D24FA9C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAssignProcessToJobObject [0x8D25057A]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEvent [0x8D25C5C4]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEventPair [0x8D25C610]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateIoCompletion [0x8D25C7AA]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateMutant [0x8D25C532]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwCreateSection [0x8D3066C2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateSemaphore [0x8D25C57A]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateThread [0x8D250AB0]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateThreadEx [0x8D250CCC]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateTimer [0x8D25C764]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDebugActiveProcess [0x8D251368]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteBootEntry [0x8D24FB02]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDuplicateObject [0x8D254B3C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwLoadDriver [0x8D24F6EE]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwMapViewOfSection [0x8D3067A2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwModifyBootEntry [0x8D24FB68]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeKey [0x8D254F32]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeMultipleKeys [0x8D251E50]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEvent [0x8D25C5EE]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEventPair [0x8D25C632]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenIoCompletion [0x8D25C7CE]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenMutant [0x8D25C558]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenProcess [0x8D254436]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSection [0x8D25C6E2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSemaphore [0x8D25C5A2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenThread [0x8D25481E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenTimer [0x8D25C788]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwProtectVirtualMemory [0x8D306546]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryObject [0x8D251CC4]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueueApcThreadEx [0x8D2519D2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootEntryOrder [0x8D24FBCE]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootOptions [0x8D24FC34]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwSetContextThread [0x8D30689E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemInformation [0x8D24F788]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemPowerState [0x8D24F95A]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwShutdownSystem [0x8D24F8E8]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendProcess [0x8D251532]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendThread [0x8D251694]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSystemDebugControl [0x8D24F9E2]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwTerminateProcess [0x8D306614]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwTerminateThread [0x8D2511C2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwVdmControl [0x8D24FC9A]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwWriteVirtualMemory [0x8D2505D6]
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 142D 82E8AA15 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82EC4212 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10CB 82ECB460 4 Bytes [9C, FA, 24, 8D] {PUSHF ; CLI ; AND AL, 0x8d}
.text ntkrnlpa.exe!KeRemoveQueueEx + 1153 82ECB4E8 4 Bytes [7A, 05, 25, 8D]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11A7 82ECB53C 8 Bytes [C4, C5, 25, 8D, 10, C6, 25, ...]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11B3 82ECB548 4 Bytes [AA, C7, 25, 8D]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11CF 82ECB564 4 Bytes [32, C5, 25, 8D]
.text ...
---- User code sections - GMER 2.1 ----
.text C:\windows\system32\EscSvc.exe[348] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe[388] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\windows\system32\csrss.exe[444] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\windows\system32\wininit.exe[496] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\windows\system32\csrss.exe[504] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text ...
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1392] kernel32.dll!SetUnhandledExceptionFilter 7601F4EB 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP }
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1392] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\windows\system32\svchost.exe[1512] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\windows\system32\Dwm.exe[1528] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\windows\Explorer.EXE[1540] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\windows\System32\svchost.exe[1604] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text ...
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[3108] kernel32.dll!SetUnhandledExceptionFilter 7601F4EB 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP }
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[3108] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\Program Files\Windows Sidebar\sidebar.exe[3124] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\Windows\System32\spool\drivers\w32x86\3\E_FATIJAE.EXE[3144] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\windows\system32\wuauclt.exe[3172] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\windows\system32\wbem\wmiprvse.exe[3624] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text ...
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002269ec2d88
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002269ec2d88 (not active ControlSet)
---- EOF - GMER 2.1 ---- |