Mededeling

Collapse
No announcement yet.

Trojan horse en malware infectie

Collapse
X
  •  
  • Filter
  • Tijd
  • Show
Clear All
new posts

  • Trojan horse en malware infectie

    AVG vond een aantal trojan horses. Toen aan de slag gegaan met malwarebytes en die vond ook eea. Hieronder de logfiles:

    Malwarebytes Anti-Malware
    www.malwarebytes.org

    Scandatum: 11-6-2015
    Scantijd: 18:01:32
    Logbestand: Malwarebytesscan.txt
    Beheerder: Ja

    Versie: 2.01.6.1022
    Malware Gegevensbestand: v2015.06.11.03
    Rootkit Gegevensbestand: v2015.06.02.01
    Licentie: Gratis
    Malwarebescherming: Uitgeschakeld
    Kwaadaardige Website Bescherming: Uitgeschakeld
    Zelfbescherming: Uitgeschakeld

    Besturingssysteem: Windows 7 Service Pack 1
    Processor: x64
    Bestandssysteem: NTFS
    Gebruiker: RamonXP

    Scantype: Aangepaste Scan
    Resultaat: Voltooid
    Objecten Gescand: 603869
    Verstreken Tijd: 3 u, 11 m, 26 s

    Geheugen: Ingeschakeld
    Opstarten: Ingeschakeld
    Bestandssysteem: Ingeschakeld
    Archieven: Ingeschakeld
    Rootkits: Ingeschakeld
    Heuristiek: Ingeschakeld
    POP: Ingeschakeld
    POA: Ingeschakeld

    Processen: 0
    (Geen kwaadaardige items gedetecteerd)

    Modules: 0
    (Geen kwaadaardige items gedetecteerd)

    Registersleutels: 0
    (Geen kwaadaardige items gedetecteerd)

    Registerwaardes: 4
    Rootkit.Fileless.MTGen, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN|^84f266d4, In Quarantaine, [0c63d4e56a20da5c70542d57f015867a],
    Rootkit.Fileless.MTGen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN|^84f266d4, In Quarantaine, [a0cf94252f5b82b4358f4341b64fc739],
    Rootkit.Fileless.MTGen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|^123e2ce4, In Quarantaine, [92ddf0c929611e18daca0b7993727e82],
    Rootkit.Fileless.MTGen, HKU\S-1-5-21-3479862513-3837734466-614173103-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|^123e2ce4, In Quarantaine, [2a45d8e16525f93d1b88453fc24347b9],

    Registerdata: 0
    (Geen kwaadaardige items gedetecteerd)

    Mappen: 5
    Trojan.Sathurbot, C:\ProgramData\Microsoft\Performance\Monitor, In Quarantaine, [75fa2a8fe5a51a1c3601e6041de68e72],
    Trojan.Sathurbot, C:\ProgramData\Microsoft\Performance\Monitor\SecurityCache, In Quarantaine, [75fa2a8fe5a51a1c3601e6041de68e72],
    Trojan.Sathurbot, C:\ProgramData\Microsoft\Performance\Monitor\SecurityCache\cache, In Quarantaine, [75fa2a8fe5a51a1c3601e6041de68e72],
    Trojan.Sathurbot, C:\ProgramData\Microsoft\Performance\Monitor\SecurityCache\data, In Quarantaine, [75fa2a8fe5a51a1c3601e6041de68e72],
    Trojan.Sathurbot, C:\ProgramData\Microsoft\Performance\Monitor\temp, In Quarantaine, [75fa2a8fe5a51a1c3601e6041de68e72],

    Bestanden: 11
    Trojan.Agent.AI, C:\Users\RamonXP\AppData\Local\Temp\Quarantine.exe, In Quarantaine, [670895245e2c6bcb6b539ad342c0847c],
    Trojan.Sathurbot, C:\ProgramData\Microsoft\Performance\Monitor\SecurityCache\zepplauncher.mif, In Quarantaine, [75fa2a8fe5a51a1c3601e6041de68e72],
    Trojan.Sathurbot, C:\ProgramData\Microsoft\Performance\Monitor\temp\tmp146A.tmp, In Quarantaine, [75fa2a8fe5a51a1c3601e6041de68e72],
    Trojan.Sathurbot, C:\ProgramData\Microsoft\Performance\Monitor\temp\tmp2FB9.tmp, In Quarantaine, [75fa2a8fe5a51a1c3601e6041de68e72],
    Trojan.Sathurbot, C:\ProgramData\Microsoft\Performance\Monitor\temp\tmp3D7E.tmp, In Quarantaine, [75fa2a8fe5a51a1c3601e6041de68e72],
    Trojan.Sathurbot, C:\ProgramData\Microsoft\Performance\Monitor\temp\tmp54F8.tmp, In Quarantaine, [75fa2a8fe5a51a1c3601e6041de68e72],
    Trojan.Sathurbot, C:\ProgramData\Microsoft\Performance\Monitor\temp\tmp61DF.tmp, In Quarantaine, [75fa2a8fe5a51a1c3601e6041de68e72],
    Trojan.Sathurbot, C:\ProgramData\Microsoft\Performance\Monitor\temp\tmp6B91.tmp, In Quarantaine, [75fa2a8fe5a51a1c3601e6041de68e72],
    Trojan.Sathurbot, C:\ProgramData\Microsoft\Performance\Monitor\temp\tmp7964.tmp, In Quarantaine, [75fa2a8fe5a51a1c3601e6041de68e72],
    Trojan.Sathurbot, C:\ProgramData\Microsoft\Performance\Monitor\temp\tmp87BA.tmp, In Quarantaine, [75fa2a8fe5a51a1c3601e6041de68e72],
    Trojan.Sathurbot, C:\ProgramData\Microsoft\Performance\Monitor\temp\{00F0D54E-B94E-EAE2-A9E8-8F105A3FF686}, In Quarantaine, [75fa2a8fe5a51a1c3601e6041de68e72],

    Fysieke Sectoren: 0
    (Geen kwaadaardige items gedetecteerd)


    (end)

    Adwcleaner:

    # AdwCleaner v4.206 - Logbestand aangemaakt 11/06/2015 op 21:30:08
    # Laatste update 01/06/2015 door Xplode
    # Database : 2015-06-09.1 [Server]
    # Besturingssysteem : Windows 7 Home Premium Service Pack 1 (x64)
    # Gebruikersnaam : RamonXP - RAMONXP-PC
    # Gestart vanuit : C:\Users\RamonXP\Desktop\antivirus\adwcleaner_4.206.exe
    # Optie : Verwijderen

    ***** [ Services ] *****


    ***** [ Bestanden / Mappen ] *****


    ***** [ Geplande taken ] *****


    ***** [ Snelkoppelingen ] *****


    ***** [ Register ] *****

    Sleutel Verwijderd : HKU\.DEFAULT\Software\Avg Secure Update
    Gegevens Verwijderd : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - <local>

    ***** [ Webbrowsers ] *****

    -\\ Internet Explorer v11.0.9600.17840


    -\\ Google Chrome v43.0.2357.124


    -\\ Chromium v


    *************************

    AdwCleaner[R0].txt - [1909 bytes] - [10/06/2015 08:05:33]
    AdwCleaner[R1].txt - [1112 bytes] - [11/06/2015 21:21:01]
    AdwCleaner[S0].txt - [1892 bytes] - [10/06/2015 08:11:25]
    AdwCleaner[S1].txt - [1042 bytes] - [11/06/2015 21:30:08]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1101 bytes] ##########

    DDS

    DDS (Ver_2012-11-20.01) - NTFS_AMD64
    Internet Explorer: 11.0.9600.17840 BrowserJavaVersion: 11.31.2
    Run by RamonXP at 21:37:07 on 2015-06-11
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3828.1056 [GMT 2:00]
    .
    AV: AVG AntiVirus Free Edition 2015 *Enabled/Updated* {4D41356F-32AD-7C42-C820-63775EE4F413}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    SP: AVG AntiVirus Free Edition 2015 *Enabled/Updated* {F620D48B-1497-73CC-F290-58052563BEAE}
    .
    ============== Running Processes ===============
    .
    c:\PROGRA~2\AVG\AVG2015\avgrsa.exe
    C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\WLANExt.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
    C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
    C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
    C:\Windows\System32\svchost.exe -k utcsvc
    C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\Foxit Cloud\FCUpdateService.exe
    C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
    C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\taskhost.exe
    C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
    C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
    C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
    C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Windows\system32\GWX\GWX.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\sppsvc.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
    C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Users\RamonXP\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
    C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
    C:\Windows\System32\vds.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\System32\igfxtray.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\WINDOWS\System32\igfxpers.exe
    C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
    C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
    C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe
    C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
    C:\WINDOWS\System32\regsvr32.exe
    C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
    C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
    C:\Program Files (x86)\AVG\AVG2015\avgui.exe
    C:\Windows\SysWOW64\regsvr32.exe
    C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\SysWOW64\ctfmon.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\System32\svchost.exe -k LocalServicePeerNet
    C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Windows\System32\cscript.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uProxyOverride = <local>
    mWinlogon: Userinit = userinit.exe,
    BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll
    BHO: Aanmeldhulp voor Windows Live ID: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
    BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll
    uRun: [Akamai NetSession Interface] "C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe"
    uRun: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
    uRun: [Xvid] C:\Program Files (x86)\Xvid\CheckUpdate.exe
    uRun: [Ubjjmedia] regsvr32.exe C:\Users\RamonXP\AppData\Local\Ubjjmedia\Ggzinf32.dll
    mRun: [NUSB3MON] "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
    mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" /mode2
    mRun: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe"
    mRun: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe"
    mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
    mRunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe
    dRunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
    mPolicies-Explorer: NoActiveDesktop = dword:1
    mPolicies-Explorer: NoActiveDesktopChanges = dword:1
    mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
    mPolicies-System: ConsentPromptBehaviorUser = dword:3
    mPolicies-System: EnableUIADesktopToggle = dword:0
    IE: &Verzenden naar OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
    IE: E&xporteren naar Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
    IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    TCP: NameServer = 62.179.104.196 213.46.228.196
    TCP: Interfaces\{5F2F4E63-5A0D-4E3D-B30B-6D585AC1D35D} : DHCPNameServer = 62.179.104.196 213.46.228.196
    TCP: Interfaces\{5F2F4E63-5A0D-4E3D-B30B-6D585AC1D35D}\255746F6C666028656470225F6F646E65657370225567656E646965627 : DHCPNameServer = 192.168.1.1
    TCP: Interfaces\{5F2F4E63-5A0D-4E3D-B30B-6D585AC1D35D}\2757D27657563747 : DHCPNameServer = 131.174.78.16 131.174.78.17
    TCP: Interfaces\{5F2F4E63-5A0D-4E3D-B30B-6D585AC1D35D}\56465727F616D6 : DHCPNameServer = 131.174.117.20
    TCP: Interfaces\{5F2F4E63-5A0D-4E3D-B30B-6D585AC1D35D}\75C414E4D2C49343745593 : DHCPNameServer = 192.168.2.1
    TCP: Interfaces\{B063B1D6-DF51-4225-AB4F-2D083E169197} : DHCPNameServer = 62.179.104.196 213.46.228.196
    TCP: Interfaces\{EC73D709-AD05-4DB1-ABA3-4CE4763BB6F2} : DHCPNameServer = 7.254.254.254
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
    Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
    AppInit_DLLs= C:\Windows\SysWOW64\nvinit.dll
    SSODL: WebCheck - <orphaned>
    mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.124\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
    x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
    x64-BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9} - <orphaned>
    x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
    x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
    x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
    x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
    x64-Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray
    x64-Run: [QuickSet] c:\Program Files\Dell\QuickSet\QuickSet.exe
    x64-Run: [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe
    x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s
    x64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /MAXX3
    x64-Run: [NvBackend] "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
    x64-Run: [ShadowPlay] C:\Windows\System32\rundll32.exe C:\Windows\System32\nvspcap64.dll,ShadowPlayOnSystemStart
    x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
    x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
    x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
    x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
    x64-Notify: igfxcui - igfxdev.dll
    x64-SSODL: WebCheck - <orphaned>
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2015-5-7 253920]
    R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2015-5-7 378336]
    R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2015-5-7 220128]
    R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2015-3-20 40928]
    R0 nvpciflt;nvpciflt;C:\Windows\System32\drivers\nvpciflt.sys [2015-5-19 31376]
    R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2010-12-31 55856]
    R0 stdcfltn;Disk Class Filter Driver for Accelerometer;C:\Windows\System32\drivers\stdcfltn.sys [2010-12-30 21616]
    R1 Avgdiska;AVG Disk Driver;C:\Windows\System32\drivers\avgdiska.sys [2015-3-11 162784]
    R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2015-4-27 284128]
    R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2015-4-15 256992]
    R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2015-5-4 291296]
    R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\System32\drivers\dtsoftbus01.sys [2014-3-6 283064]
    R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2013-4-7 98208]
    R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [2015-5-18 3438544]
    R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [2015-5-18 311792]
    R2 DiagTrack;Diagnostics Tracking Service;C:\Windows\System32\svchost.exe -k utcsvc [2009-7-14 27136]
    R2 FoxitCloudUpdateService;Foxit Cloud Safe Update Service;C:\Program Files (x86)\FOXIT SOFTWARE\FOXIT READER\Foxit Cloud\FCUpdateService.exe [2014-11-2 244392]
    R2 GfExperienceService;NVIDIA GeForce Experience Service;C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2015-5-19 1152656]
    R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-12-31 13336]
    R2 NvNetworkService;NVIDIA Network Service;C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2015-5-19 1893008]
    R2 NvStreamSvc;NVIDIA Streamer Service;C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2015-5-19 23006864]
    R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2010-12-31 689472]
    R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-5-19 410768]
    R2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\System32\drivers\TurboB.sys [2009-11-2 13784]
    R2 UNS;Intel(R) Management & Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-12-31 2533400]
    R3 Acceler;Accelerometer Service;C:\Windows\System32\drivers\Accelern.sys [2010-11-27 27760]
    R3 CtClsFlt;Creative Camera Class Upper Filter Driver;C:\Windows\System32\drivers\CtClsFlt.sys [2010-12-31 175168]
    R3 HECIx64;Intel(R) Management Engine Interface;C:\Windows\System32\drivers\HECIx64.sys [2010-11-27 56344]
    R3 Impcd;Impcd;C:\Windows\System32\drivers\Impcd.sys [2010-11-27 158976]
    R3 IntcDAud;Intel(R) Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2010-11-27 287232]
    R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2014-9-13 25816]
    R3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series adapter stuurprogramma onder Windows 7 64 Bit;C:\Windows\System32\drivers\NETw5s64.sys [2010-11-27 7689216]
    R3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\System32\drivers\nusb3hub.sys [2010-11-27 83080]
    R3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\System32\drivers\nusb3xhc.sys [2010-11-27 184968]
    R3 NvStreamKms;NvStreamKms;C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2015-5-19 19600]
    R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);C:\Windows\System32\drivers\nvvad64v.sys [2015-5-29 38032]
    R3 qicflt;upper Device Filter Driver;C:\Windows\System32\drivers\qicflt.sys [2010-11-27 29288]
    R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-6-10 539240]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-4-11 103608]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-4-11 124088]
    S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2014-9-13 1080120]
    S2 RoxWatch12;Roxio Hard Drive Watcher 12;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [2010-9-4 219632]
    S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-2-18 315488]
    S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2015-6-9 114688]
    S3 JMCR;JMCR;C:\Windows\System32\drivers\jmcr.sys [2010-11-27 169048]
    S3 MBAMWebAccessControl;MBAMWebAccessControl;C:\Windows\System32\drivers\mwac.sys [2014-9-13 63704]
    S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2010-3-5 340240]
    S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-4-10 19456]
    S3 RoxMediaDB12OEM;RoxMediaDB12OEM;C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [2010-9-4 1116656]
    S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2015-4-10 56832]
    S3 TurboBoost;TurboBoost;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [2009-11-2 126352]
    S3 WatAdminSvc;Windows Activation Technologies-service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-4-6 1255736]
    .
    =============== Created Last 30 ================
    .
    2015-06-10 06:05:16 -------- d-----w- C:\AdwCleaner
    2015-06-09 18:46:28 633856 ----a-w- C:\Windows\System32\comctl32.dll
    2015-06-09 18:45:59 2426880 ----a-w- C:\Windows\System32\wininet.dll
    2015-06-09 18:45:58 950784 ----a-w- C:\Program Files\Internet Explorer\iedvtool.dll
    2015-06-09 18:45:58 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll
    2015-06-09 18:45:58 417792 ----a-w- C:\Windows\System32\html.iec
    2015-06-09 18:45:58 382976 ----a-w- C:\Program Files\Internet Explorer\IEShims.dll
    2015-06-09 18:45:57 293072 ----a-w- C:\Program Files\Internet Explorer\sqmapi.dll
    2015-06-09 18:45:57 1016832 ----a-w- C:\Program Files\Common Files\Microsoft Shared\VGX\VGX.dll
    2015-06-09 18:45:56 10949120 ----a-w- C:\Program Files\Internet Explorer\F12Resources.dll
    2015-06-09 18:36:40 -------- d-----w- C:\Users\RamonXP\AppData\Roaming\ChromeUpdate
    2015-06-07 17:56:08 -------- d-----w- C:\Users\RamonXP\AppData\Local\Ubjjmedia
    2015-06-07 17:55:58 -------- d-----w- C:\Users\RamonXP\AppData\Local\Epqtion
    2015-06-02 07:22:55 -------- d-----w- C:\Program Files (x86)\Heroes of the Storm
    2015-06-02 06:49:44 -------- d-----w- C:\Users\RamonXP\AppData\Local\GWX
    2015-05-30 09:39:47 -------- d-----w- C:\Program Files (x86)\Microsoft ASP.NET
    2015-05-29 11:16:06 -------- d-----w- C:\ProgramData\boost_interprocess
    2015-05-29 11:16:02 48784 ----a-w- C:\Windows\SysWow64\nvaudcap32v.dll
    2015-05-29 11:16:02 38032 ----a-w- C:\Windows\System32\drivers\nvvad64v.sys
    2015-05-22 17:16:46 18652352 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSO.DLL
    2015-05-20 17:08:16 -------- d-----w- C:\Users\RamonXP\AppData\Local\Avg
    2015-05-20 17:00:23 -------- d-----w- C:\Windows\SysWow64\NV
    2015-05-20 17:00:23 -------- d-----w- C:\Windows\System32\NV
    2015-05-19 20:56:19 -------- d-----w- C:\Users\RamonXP\AppData\Local\NVIDIA Corporation
    2015-05-19 20:55:15 -------- d-----w- C:\Users\RamonXP\AppData\Local\NVIDIA
    2015-05-19 20:05:42 1756424 ----a-w- C:\Windows\System32\nvspbridge64.dll
    2015-05-19 20:05:42 1571696 ----a-w- C:\Windows\System32\nvspcap64.dll
    2015-05-19 20:05:39 1316000 ----a-w- C:\Windows\SysWow64\nvspbridge.dll
    2015-05-19 20:05:38 1320304 ----a-w- C:\Windows\SysWow64\nvspcap.dll
    2015-05-19 20:04:03 571024 ----a-w- C:\Windows\SysWow64\nvStreaming.exe
    2015-05-19 20:03:42 937288 ----a-w- C:\Windows\System32\nvvsvc.exe
    2015-05-19 20:03:42 75080 ----a-w- C:\Windows\System32\nv3dappshextr.dll
    2015-05-19 20:03:42 62608 ----a-w- C:\Windows\System32\nvshext.dll
    2015-05-19 20:03:42 3490448 ----a-w- C:\Windows\System32\nvsvc64.dll
    2015-05-19 20:03:42 1059984 ----a-w- C:\Windows\System32\nv3dappshext.dll
    2015-05-19 20:03:41 4391871 ----a-w- C:\Windows\System32\nvcoproc.bin
    2015-05-19 20:03:41 2558608 ----a-w- C:\Windows\System32\nvsvcr.dll
    2015-05-19 20:03:40 6872392 ----a-w- C:\Windows\System32\nvcpl.dll
    2015-05-19 20:03:40 385352 ----a-w- C:\Windows\System32\nvmctray.dll
    2015-05-19 19:49:14 52880 ----a-w- C:\Windows\System32\nvaudcap64v.dll
    2015-05-12 21:14:26 124112 ----a-w- C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
    2015-05-12 21:14:26 102608 ----a-w- C:\Windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
    2015-05-12 19:40:30 460800 ----a-w- C:\Windows\System32\certcli.dll
    2015-05-12 19:40:30 342016 ----a-w- C:\Windows\SysWow64\certcli.dll
    2015-05-12 19:40:11 328704 ----a-w- C:\Windows\System32\services.exe
    .
    ==================== Find3M ====================
    .
    2015-06-11 16:00:31 136408 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
    2015-05-25 18:24:00 5569984 ----a-w- C:\Windows\System32\ntoskrnl.exe
    2015-05-25 18:23:59 95680 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
    2015-05-25 18:23:59 155584 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
    2015-05-25 18:21:21 1728960 ----a-w- C:\Windows\System32\ntdll.dll
    2015-05-25 18:18:56 43520 ----a-w- C:\Windows\System32\csrsrv.dll
    2015-05-25 18:18:56 22016 ----a-w- C:\Windows\System32\credssp.dll
    2015-05-25 18:18:54 879104 ----a-w- C:\Windows\System32\advapi32.dll
    2015-05-25 18:18:45 47104 ----a-w- C:\Windows\System32\typeperf.exe
    2015-05-25 18:18:45 404992 ----a-w- C:\Windows\System32\tracerpt.exe
    2015-05-25 18:18:39 112640 ----a-w- C:\Windows\System32\smss.exe
    2015-05-25 18:18:32 296960 ----a-w- C:\Windows\System32\rstrui.exe
    2015-05-25 18:18:30 43008 ----a-w- C:\Windows\System32\relog.exe
    2015-05-25 18:18:19 31232 ----a-w- C:\Windows\System32\lsass.exe
    2015-05-25 18:18:19 104448 ----a-w- C:\Windows\System32\logman.exe
    2015-05-25 18:18:11 19456 ----a-w- C:\Windows\System32\diskperf.exe
    2015-05-25 18:18:08 338432 ----a-w- C:\Windows\System32\conhost.exe
    2015-05-25 18:18:04 64000 ----a-w- C:\Windows\System32\auditpol.exe
    2015-05-25 18:14:26 60416 ----a-w- C:\Windows\System32\msobjs.dll
    2015-05-25 18:14:04 146432 ----a-w- C:\Windows\System32\msaudite.dll
    2015-05-25 18:07:34 3989440 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
    2015-05-25 18:07:34 3934144 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
    2015-05-25 18:04:08 1310744 ----a-w- C:\Windows\SysWow64\ntdll.dll
    2015-05-25 18:00:44 40448 ----a-w- C:\Windows\SysWow64\typeperf.exe
    2015-05-25 18:00:40 364544 ----a-w- C:\Windows\SysWow64\tracerpt.exe
    2015-05-25 18:00:28 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
    2015-05-25 18:00:25 37888 ----a-w- C:\Windows\SysWow64\relog.exe
    2015-05-25 18:00:17 82944 ----a-w- C:\Windows\SysWow64\logman.exe
    2015-05-25 18:00:09 17408 ----a-w- C:\Windows\SysWow64\diskperf.exe
    2015-05-25 18:00:04 50176 ----a-w- C:\Windows\SysWow64\auditpol.exe
    2015-05-25 17:59:52 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
    2015-05-25 17:59:52 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
    2015-05-25 17:59:51 274944 ----a-w- C:\Windows\SysWow64\KernelBase.dll
    2015-05-25 17:57:31 60416 ----a-w- C:\Windows\SysWow64\msobjs.dll
    2015-05-25 17:57:15 146432 ----a-w- C:\Windows\SysWow64\msaudite.dll
    2015-05-25 17:08:39 3206144 ----a-w- C:\Windows\System32\win32k.sys
    2015-05-25 17:00:56 36864 ----a-w- C:\Windows\System32\UtcResources.dll
    2015-05-25 16:50:38 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
    2015-05-25 16:50:36 2048 ----a-w- C:\Windows\SysWow64\user.exe
    2015-05-25 16:48:25 6144 ---ha-w- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
    2015-05-25 16:48:25 4608 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
    2015-05-25 16:48:25 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
    2015-05-25 16:48:25 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
    2015-05-23 03:28:17 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
    2015-05-23 03:15:54 503808 ----a-w- C:\Windows\SysWow64\vbscript.dll
    2015-05-23 03:15:40 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll
    2015-05-23 03:15:02 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
    2015-05-23 03:14:51 341504 ----a-w- C:\Windows\SysWow64\html.iec
    2015-05-23 03:13:48 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
    2015-05-23 03:05:21 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
    2015-05-23 03:04:50 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
    2015-05-23 02:52:43 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
    2015-05-23 02:47:31 4305920 ----a-w- C:\Windows\SysWow64\jscript9.dll
    2015-05-23 02:37:45 2052608 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
    2015-05-23 02:37:25 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
    2015-05-23 02:20:35 1950720 ----a-w- C:\Windows\SysWow64\wininet.dll
    2015-05-22 19:16:55 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
    2015-05-22 19:16:44 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
    2015-05-22 19:01:42 66560 ----a-w- C:\Windows\System32\iesetup.dll
    2015-05-22 19:00:54 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
    2015-05-22 19:00:25 584192 ----a-w- C:\Windows\System32\vbscript.dll
    2015-05-22 18:52:21 6026240 ----a-w- C:\Windows\System32\jscript9.dll
    2015-05-22 18:47:49 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
    2015-05-22 18:47:34 114688 ----a-w- C:\Windows\System32\ieetwcollector.exe
    2015-05-22 18:47:03 814080 ----a-w- C:\Windows\System32\jscript9diag.dll
    2015-05-22 18:40:17 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
    2015-05-22 18:29:31 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
    2015-05-22 18:18:41 700416 ----a-w- C:\Windows\System32\generaltel.dll
    2015-05-22 18:18:29 757248 ----a-w- C:\Windows\System32\invagent.dll
    2015-05-22 18:18:24 423424 ----a-w- C:\Windows\System32\devinv.dll
    2015-05-22 18:18:22 1021440 ----a-w- C:\Windows\System32\appraiser.dll
    2015-05-22 18:18:21 45568 ----a-w- C:\Windows\System32\acmigration.dll
    2015-05-22 18:18:21 227328 ----a-w- C:\Windows\System32\aepdu.dll
    2015-05-22 18:13:03 1119232 ----a-w- C:\Windows\System32\aeinv.dll
    2015-05-22 18:05:28 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll
    2015-05-22 18:05:06 2125824 ----a-w- C:\Windows\System32\inetcpl.cpl
    2015-05-21 13:19:52 193536 ----a-w- C:\Windows\System32\aepic.dll
    2015-05-17 13:26:20 778416 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
    2015-05-17 13:26:20 142512 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2015-05-07 11:50:22 378336 ----a-w- C:\Windows\System32\drivers\avgloga.sys
    2015-05-07 11:49:24 253920 ----a-w- C:\Windows\System32\drivers\avgidsha.sys
    2015-05-07 11:49:22 220128 ----a-w- C:\Windows\System32\drivers\avgmfx64.sys
    2015-05-04 12:14:30 291296 ----a-w- C:\Windows\System32\drivers\avgtdia.sys
    2015-04-29 18:21:50 5120 ----a-w- C:\Windows\System32\msdxm.ocx
    2015-04-29 18:21:50 5120 ----a-w- C:\Windows\System32\dxmasf.dll
    2015-04-29 18:21:46 9728 ----a-w- C:\Windows\System32\spwmp.dll
    2015-04-29 18:19:43 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
    2015-04-29 18:07:12 4096 ----a-w- C:\Windows\SysWow64\msdxm.ocx
    2015-04-29 18:07:12 4096 ----a-w- C:\Windows\SysWow64\dxmasf.dll
    2015-04-29 18:07:07 8192 ----a-w- C:\Windows\SysWow64\spwmp.dll
    2015-04-29 18:05:19 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
    2015-04-27 11:19:16 284128 ----a-w- C:\Windows\System32\drivers\avgidsdrivera.sys
    2015-04-24 17:56:58 530432 ----a-w- C:\Windows\SysWow64\comctl32.dll
    2015-04-20 03:17:07 1647104 ----a-w- C:\Windows\System32\DWrite.dll
    2015-04-20 03:17:07 1179136 ----a-w- C:\Windows\System32\FntCache.dll
    2015-04-20 02:56:29 1250816 ----a-w- C:\Windows\SysWow64\DWrite.dll
    2015-04-15 11:06:02 256992 ----a-w- C:\Windows\System32\drivers\avgldx64.sys
    2015-04-14 07:37:56 63704 ----a-w- C:\Windows\System32\drivers\mwac.sys
    2015-04-14 07:37:46 107736 ----a-w- C:\Windows\System32\drivers\mbamchameleon.sys
    2015-04-14 07:37:42 25816 ----a-w- C:\Windows\System32\drivers\mbam.sys
    .
    ============= FINISH: 21:45:01,31 ===============

  • #2
    GMER 2.1.19357 - http://www.gmer.net
    Rootkit scan 2015-06-11 21:55:15
    Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST950042 rev.D005 465,76GB
    Running: n9g51dpu.exe; Driver: C:\Users\RamonXP\AppData\Local\Temp\pxliqfog.sys


    ---- User code sections - GMER 2.1 ----

    .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\kernel32.dll!RegSetValueExW 0000000076f4a3e0 7 bytes JMP 000000016fff0228
    .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000076f53f00 5 bytes JMP 000000016fff0180
    .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\kernel32.dll!RegDeleteValueW 0000000076f6ffd0 5 bytes JMP 000000016fff01b8
    .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000076f7f350 5 bytes JMP 000000016fff0110
    .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000076fa9aa0 7 bytes JMP 000000016fff00d8
    .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000076fb9530 5 bytes JMP 000000016fff0148
    .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000076fd8850 7 bytes JMP 000000016fff01f0
    .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefbd32db0 5 bytes JMP 000007fffbd20180
    .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefbd337d0 7 bytes JMP 000007fffbd200d8
    .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefbd3a410 2 bytes JMP 000007fffbd20110
    .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefbd3a413 2 bytes [FE, FF]
    .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefbd3aec0 6 bytes JMP 000007fffbd20148
    .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefc2689e0 8 bytes JMP 000007fffbd201f0
    .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefc26be40 8 bytes JMP 000007fffbd201b8
    .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefcc07490 11 bytes JMP 000007fffbd20228
    .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1620] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefcc1bf00 7 bytes JMP 000007fffbd20260
    .text C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe[1512] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075591401 2 bytes JMP 76e6b21b C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe[1512] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075591419 2 bytes JMP 76e6b346 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe[1512] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075591431 2 bytes JMP 76ee8f29 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe[1512] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007559144a 2 bytes CALL 76e4489d C:\Windows\syswow64\kernel32.dll
    .text ... * 9
    .text C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe[1512] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000755914dd 2 bytes JMP 76ee8822 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe[1512] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000755914f5 2 bytes JMP 76ee89f8 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe[1512] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007559150d 2 bytes JMP 76ee8718 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe[1512] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075591525 2 bytes JMP 76ee8ae2 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe[1512] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007559153d 2 bytes JMP 76e5fca8 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe[1512] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075591555 2 bytes JMP 76e668ef C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe[1512] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007559156d 2 bytes JMP 76ee8fe3 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe[1512] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075591585 2 bytes JMP 76ee8b42 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe[1512] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007559159d 2 bytes JMP 76ee86dc C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe[1512] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000755915b5 2 bytes JMP 76e5fd41 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe[1512] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000755915cd 2 bytes JMP 76e6b2dc C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe[1512] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000755916b2 2 bytes JMP 76ee8ea4 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe[1512] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000755916bd 2 bytes JMP 76ee8671 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2388] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075591401 2 bytes JMP 76e6b21b C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2388] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075591419 2 bytes JMP 76e6b346 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2388] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075591431 2 bytes JMP 76ee8f29 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2388] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007559144a 2 bytes CALL 76e4489d C:\Windows\syswow64\kernel32.dll
    .text ... * 9
    .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2388] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000755914dd 2 bytes JMP 76ee8822 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2388] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000755914f5 2 bytes JMP 76ee89f8 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2388] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007559150d 2 bytes JMP 76ee8718 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2388] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075591525 2 bytes JMP 76ee8ae2 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2388] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007559153d 2 bytes JMP 76e5fca8 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2388] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075591555 2 bytes JMP 76e668ef C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2388] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007559156d 2 bytes JMP 76ee8fe3 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2388] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075591585 2 bytes JMP 76ee8b42 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2388] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007559159d 2 bytes JMP 76ee86dc C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2388] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000755915b5 2 bytes JMP 76e5fd41 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2388] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000755915cd 2 bytes JMP 76e6b2dc C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2388] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000755916b2 2 bytes JMP 76ee8ea4 C:\Windows\syswow64\kernel32.dll
    .text C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2388] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000755916bd 2 bytes JMP 76ee8671 C:\Windows\syswow64\kernel32.dll
    .text C:\Windows\system32\Dwm.exe[2776] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefbd32db0 5 bytes JMP 000007fffbd20180
    .text C:\Windows\system32\Dwm.exe[2776] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefbd337d0 7 bytes JMP 000007fffbd200d8
    .text C:\Windows\system32\Dwm.exe[2776] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefbd3a410 2 bytes JMP 000007fffbd20110
    .text C:\Windows\system32\Dwm.exe[2776] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefbd3a413 2 bytes [FE, FF]
    .text C:\Windows\system32\Dwm.exe[2776] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefbd3aec0 6 bytes JMP 000007fffbd20148
    .text C:\Windows\system32\Dwm.exe[2776] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefc2689e0 8 bytes JMP 000007fffbd201f0
    .text C:\Windows\system32\Dwm.exe[2776] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefc26be40 8 bytes JMP 000007fffbd201b8
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[2148] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection 000000007735fc9c 5 bytes JMP 000000016f9b1460
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[2148] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory 000000007735fe60 5 bytes JMP 000000016f9b1120
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[2148] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW 0000000076e53bab 5 bytes JMP 000000016f9b1260
    .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2368] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000771ade30 5 bytes JMP 0000000077310128
    .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe[2368] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000771adf50 5 bytes JMP 0000000077310018
    .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000771ade30 5 bytes JMP 0000000077310128
    .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2004] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000771adf50 5 bytes JMP 0000000077310018
    .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2004] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefbd32db0 5 bytes JMP 000007fffbd20180
    .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2004] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefbd337d0 7 bytes JMP 000007fffbd200d8
    .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2004] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefbd3a410 2 bytes JMP 000007fffbd20110
    .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2004] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefbd3a413 2 bytes [FE, FF]
    .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2004] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefbd3aec0 6 bytes JMP 000007fffbd20148
    .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3192] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000771ade30 5 bytes JMP 0000000077310128
    .text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3192] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000771adf50 5 bytes JMP 0000000077310018
    .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000771ade30 5 bytes JMP 0000000077310128
    .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[3256] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000771adf50 5 bytes JMP 0000000077310018
    .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[3256] C:\Windows\system32\kernel32.dll!CreateProcessInternalW 0000000076f5dbc0 5 bytes JMP 00000000773100a0
    .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000771ade30 5 bytes JMP 0000000077310128
    .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3980] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000771adf50 5 bytes JMP 0000000077310018
    .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3980] C:\Windows\system32\kernel32.dll!RegSetValueExW 0000000076f4a3e0 7 bytes JMP 000000016fff0228
    .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3980] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000076f53f00 5 bytes JMP 000000016fff0180
    .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3980] C:\Windows\system32\kernel32.dll!CreateProcessInternalW 0000000076f5dbc0 5 bytes JMP 00000000773100a0
    .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3980] C:\Windows\system32\kernel32.dll!RegDeleteValueW 0000000076f6ffd0 5 bytes JMP 000000016fff01b8
    .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3980] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000076f7f350 5 bytes JMP 000000016fff0110
    .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3980] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000076fa9aa0 7 bytes JMP 000000016fff00d8
    .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3980] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000076fb9530 5 bytes JMP 000000016fff0148
    .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3980] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000076fd8850 7 bytes JMP 000000016fff01f0
    .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3980] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefbd32db0 5 bytes JMP 000007fffbd20180
    .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3980] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefbd337d0 7 bytes JMP 000007fffbd200d8
    .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3980] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefbd3a410 2 bytes JMP 000007fffbd20110
    .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3980] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefbd3a413 2 bytes [FE, FF]
    .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3980] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefbd3aec0 6 bytes JMP 000007fffbd20148
    .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3980] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefc2689e0 8 bytes JMP 000007fffbd201f0
    .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3980] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefc26be40 8 bytes JMP 000007fffbd201b8
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection 000000007735fc9c 5 bytes JMP 000000016f9b1460
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory 000000007735fe60 5 bytes JMP 000000016f9b1120
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076e41efe 7 bytes JMP 0000000173e13880
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076e45b9d 7 bytes JMP 0000000173e13ec0
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000076e513f9 7 bytes JMP 0000000173e13ad0
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW 0000000076e53bab 5 bytes JMP 000000016f9b1260
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000076e5ea45 7 bytes JMP 0000000173e13870
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076ee8ea4 7 bytes JMP 0000000173e133c0
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076ee8f29 5 bytes JMP 0000000173e13470
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076ee9281 5 bytes JMP 0000000173e133d0
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076ac1d29 5 bytes JMP 0000000173e13380
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076ac1dd7 5 bytes JMP 0000000173e13340
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076ac2ab1 5 bytes JMP 0000000100b8f046
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076ac2d1d 5 bytes JMP 0000000173e13190
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076468a29 5 bytes JMP 0000000173e12880
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000076474572 5 bytes JMP 0000000173e13110
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007648e567 5 bytes JMP 0000000173e13180
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000764b07d7 5 bytes JMP 0000000173e12700
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000764c7a5c 5 bytes JMP 0000000173e13100
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000074d3e96b 5 bytes JMP 0000000173e129a0
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000074d3eba5 5 bytes JMP 0000000173e129c0
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076b15ea5 5 bytes JMP 0000000173e12840
    .text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3992] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076b49d0b 5 bytes JMP 0000000173e127d0
    .text C:\Windows\system32\svchost.exe[3324] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000771ade30 5 bytes JMP 0000000177150128
    .text C:\Windows\system32\svchost.exe[3324] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000771adf50 5 bytes JMP 0000000177150018
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection 000000007735fc9c 5 bytes JMP 000000016f9b1460
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4432] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory 000000007735fe60 5 bytes JMP 000000016f9b1120
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4432] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076e41efe 7 bytes JMP 0000000173e13880
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4432] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076e45b9d 7 bytes JMP 0000000173e13ec0
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4432] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000076e513f9 7 bytes JMP 0000000173e13ad0
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4432] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW 0000000076e53bab 5 bytes JMP 000000016f9b1260
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4432] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000076e5ea45 7 bytes JMP 0000000173e13870
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4432] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076ee8ea4 7 bytes JMP 0000000173e133c0
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4432] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076ee8f29 5 bytes JMP 0000000173e13470
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4432] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076ee9281 5 bytes JMP 0000000173e133d0
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4432] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076ac1d29 5 bytes JMP 0000000173e13380
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4432] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076ac1dd7 5 bytes JMP 0000000173e13340
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4432] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076ac2ab1 5 bytes JMP 0000000173e13480
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4432] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076ac2d1d 5 bytes JMP 0000000173e13190
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4432] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076468a29 5 bytes JMP 0000000173e12880
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4432] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000076474572 5 bytes JMP 0000000173e13110
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4432] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007648e567 5 bytes JMP 0000000173e13180
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4432] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000764b07d7 5 bytes JMP 0000000173e12700
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4432] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000764c7a5c 5 bytes JMP 0000000173e13100
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4432] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076b15ea5 5 bytes JMP 0000000173e12840
    .text C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe[4432] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076b49d0b 5 bytes JMP 0000000173e127d0
    .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4812] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000771ade30 5 bytes JMP 0000000077310128
    .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4812] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000771adf50 5 bytes JMP 0000000077310018
    .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4812] C:\Windows\system32\kernel32.dll!RegSetValueExW 0000000076f4a3e0 7 bytes JMP 000000016fff0228
    .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4812] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000076f53f00 5 bytes JMP 000000016fff0180
    .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4812] C:\Windows\system32\kernel32.dll!CreateProcessInternalW 0000000076f5dbc0 5 bytes JMP 00000000773100a0
    .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4812] C:\Windows\system32\kernel32.dll!RegDeleteValueW 0000000076f6ffd0 5 bytes JMP 000000016fff01b8
    .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4812] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000076f7f350 5 bytes JMP 000000016fff0110
    .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4812] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000076fa9aa0 7 bytes JMP 000000016fff00d8
    .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4812] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000076fb9530 5 bytes JMP 000000016fff0148
    .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4812] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000076fd8850 7 bytes JMP 000000016fff01f0
    .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4812] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefbd32db0 5 bytes JMP 000007fffbd20180
    .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4812] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefbd337d0 7 bytes JMP 000007fffbd200d8
    .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4812] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefbd3a410 2 bytes JMP 000007fffbd20110
    .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4812] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefbd3a413 2 bytes [FE, FF]
    .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4812] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefbd3aec0 6 bytes JMP 000007fffbd20148
    .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4812] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefc2689e0 8 bytes JMP 000007fffbd201f0
    .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4812] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefc26be40 8 bytes JMP 000007fffbd201b8
    .text C:\WINDOWS\System32\hkcmd.exe[4836] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000771ade30 5 bytes JMP 0000000077310128
    .text C:\WINDOWS\System32\hkcmd.exe[4836] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000771adf50 5 bytes JMP 0000000077310018
    .text C:\WINDOWS\System32\igfxpers.exe[4852] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000771ade30 5 bytes JMP 0000000077310128
    .text C:\WINDOWS\System32\igfxpers.exe[4852] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000771adf50 5 bytes JMP 0000000077310018
    .text C:\WINDOWS\System32\igfxpers.exe[4852] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefbd32db0 5 bytes JMP 000007fffbd20180
    .text C:\WINDOWS\System32\igfxpers.exe[4852] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefbd337d0 7 bytes JMP 000007fffbd200d8
    .text C:\WINDOWS\System32\igfxpers.exe[4852] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefbd3a410 2 bytes JMP 000007fffbd20110
    .text C:\WINDOWS\System32\igfxpers.exe[4852] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefbd3a413 2 bytes [FE, FF]
    .text C:\WINDOWS\System32\igfxpers.exe[4852] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefbd3aec0 6 bytes JMP 000007fffbd20148
    .text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4888] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000771ade30 5 bytes JMP 0000000077310128
    .text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4888] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000771adf50 5 bytes JMP 0000000077310018
    .text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4888] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefbd32db0 5 bytes JMP 000007fffbd20180
    .text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4888] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefbd337d0 7 bytes JMP 000007fffbd200d8
    .text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4888] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefbd3a410 2 bytes JMP 000007fffbd20110
    .text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4888] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefbd3a413 2 bytes [FE, FF]
    .text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4888] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefbd3aec0 6 bytes JMP 000007fffbd20148
    .text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4888] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefc2689e0 8 bytes JMP 000007fffbd201f0
    .text C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[4888] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefc26be40 8 bytes JMP 000007fffbd201b8
    .text C:\Program Files\Dell\QuickSet\quickset.exe[4924] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefbd32db0 5 bytes JMP 000007fffbd20180
    .text C:\Program Files\Dell\QuickSet\quickset.exe[4924] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefbd337d0 7 bytes JMP 000007fffbd200d8
    .text C:\Program Files\Dell\QuickSet\quickset.exe[4924] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefbd3a410 2 bytes JMP 000007fffbd20110
    .text C:\Program Files\Dell\QuickSet\quickset.exe[4924] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefbd3a413 2 bytes [FE, FF]
    .text C:\Program Files\Dell\QuickSet\quickset.exe[4924] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefbd3aec0 6 bytes JMP 000007fffbd20148

    Comment


    • #3
      .text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[5004] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076468a29 5 bytes JMP 0000000173e12880
      .text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[5004] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000076474572 5 bytes JMP 0000000173e13110
      .text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[5004] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007648e567 5 bytes JMP 0000000173e13180
      .text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[5004] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000764b07d7 5 bytes JMP 0000000173e12700
      .text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[5004] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000764c7a5c 5 bytes JMP 0000000173e13100
      .text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[5004] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076b15ea5 5 bytes JMP 0000000173e12840
      .text C:\Program Files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe[5004] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076b49d0b 5 bytes JMP 0000000173e127d0
      .text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000771ade30 5 bytes JMP 0000000077310128
      .text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[5100] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000771adf50 5 bytes JMP 0000000077310018
      .text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[5100] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefbd32db0 5 bytes JMP 000007fffbd20180
      .text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[5100] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefbd337d0 7 bytes JMP 000007fffbd200d8
      .text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[5100] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefbd3a410 2 bytes JMP 000007fffbd20110
      .text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[5100] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefbd3a413 2 bytes [FE, FF]
      .text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[5100] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefbd3aec0 6 bytes JMP 000007fffbd20148
      .text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4124] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000771ade30 5 bytes JMP 0000000077310128
      .text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4124] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000771adf50 5 bytes JMP 0000000077310018
      .text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4464] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefbd32db0 5 bytes JMP 000007fffbd20180
      .text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4464] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefbd337d0 7 bytes JMP 000007fffbd200d8
      .text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4464] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefbd3a410 2 bytes JMP 000007fffbd20110
      .text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4464] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefbd3a413 2 bytes [FE, FF]
      .text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4464] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefbd3aec0 6 bytes JMP 000007fffbd20148
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[4308] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection 000000007735fc9c 5 bytes JMP 000000016f9b1460
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[4308] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory 000000007735fe60 5 bytes JMP 000000016f9b1120
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[4308] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076e41efe 7 bytes JMP 0000000173e13880
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[4308] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076e45b9d 7 bytes JMP 0000000173e13ec0
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[4308] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000076e513f9 7 bytes JMP 0000000173e13ad0
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[4308] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW 0000000076e53bab 5 bytes JMP 000000016f9b1260
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[4308] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000076e5ea45 7 bytes JMP 0000000173e13870
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[4308] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076ee8ea4 7 bytes JMP 0000000173e133c0
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[4308] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076ee8f29 5 bytes JMP 0000000173e13470
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[4308] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076ee9281 5 bytes JMP 0000000173e133d0
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[4308] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076468a29 5 bytes JMP 0000000173e12880
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[4308] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000076474572 5 bytes JMP 0000000173e13110
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[4308] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007648e567 5 bytes JMP 0000000173e13180
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[4308] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000764b07d7 5 bytes JMP 0000000173e12700
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[4308] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000764c7a5c 5 bytes JMP 0000000173e13100
      .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2184] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection 000000007735fc9c 5 bytes JMP 000000016f9b1460
      .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2184] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory 000000007735fe60 5 bytes JMP 000000016f9b1120
      .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2184] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076e41efe 7 bytes JMP 0000000173e13880
      .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2184] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076e45b9d 7 bytes JMP 0000000173e13ec0
      .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2184] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000076e48781 5 bytes [33, C0, C2, 04, 00]
      .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2184] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000076e513f9 7 bytes JMP 0000000173e13ad0
      .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2184] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW 0000000076e53bab 5 bytes JMP 000000016f9b1260
      .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2184] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000076e5ea45 7 bytes JMP 0000000173e13870
      .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2184] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076ee8ea4 7 bytes JMP 0000000173e133c0
      .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2184] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076ee8f29 5 bytes JMP 0000000173e13470
      .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2184] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076ee9281 5 bytes JMP 0000000173e133d0
      .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2184] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076ac1d29 5 bytes JMP 0000000173e13380
      .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2184] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076ac1dd7 5 bytes JMP 0000000173e13340
      .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2184] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076ac2ab1 5 bytes JMP 0000000173e13480
      .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2184] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076ac2d1d 5 bytes JMP 0000000173e13190
      .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2184] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076468a29 5 bytes JMP 0000000173e12880
      .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2184] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000076474572 5 bytes JMP 0000000173e13110
      .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2184] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007648e567 5 bytes JMP 0000000173e13180
      .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2184] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000764b07d7 5 bytes JMP 0000000173e12700
      .text C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe[2184] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000764c7a5c 5 bytes JMP 0000000173e13100
      .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4444] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection 000000007735fc9c 5 bytes JMP 000000016f9b1460
      .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4444] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory 000000007735fe60 5 bytes JMP 000000016f9b1120
      .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4444] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076e41efe 7 bytes JMP 0000000173e13880
      .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4444] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076e45b9d 7 bytes JMP 0000000173e13ec0
      .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4444] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000076e513f9 7 bytes JMP 0000000173e13ad0
      .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4444] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW 0000000076e53bab 5 bytes JMP 000000016f9b1260
      .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4444] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000076e5ea45 7 bytes JMP 0000000173e13870
      .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4444] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076ee8ea4 7 bytes JMP 0000000173e133c0
      .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4444] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076ee8f29 5 bytes JMP 0000000173e13470
      .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4444] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076ee9281 5 bytes JMP 0000000173e133d0
      .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4444] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076ac1d29 5 bytes JMP 0000000173e13380
      .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4444] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076ac1dd7 5 bytes JMP 0000000173e13340
      .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4444] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076ac2ab1 5 bytes JMP 0000000173e13480
      .text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4444] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076ac2d1d 5 bytes JMP 0000000173e13190
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[304] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection 000000007735fc9c 5 bytes JMP 000000016f9b1460
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[304] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory 000000007735fe60 5 bytes JMP 000000016f9b1120
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[304] C:\Windows\syswow64\KERNEL32.dll!RegQueryValueExW 0000000076e41efe 7 bytes JMP 0000000173e13880
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[304] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExW 0000000076e45b9d 7 bytes JMP 0000000173e13ec0
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[304] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA 0000000076e513f9 7 bytes JMP 0000000173e13ad0
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[304] C:\Windows\syswow64\KERNEL32.dll!CreateProcessInternalW 0000000076e53bab 5 bytes JMP 000000016f9b1260
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[304] C:\Windows\syswow64\KERNEL32.dll!RegDeleteValueW 0000000076e5ea45 7 bytes JMP 0000000173e13870
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[304] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx 0000000076ee8ea4 7 bytes JMP 0000000173e133c0
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[304] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation 0000000076ee8f29 5 bytes JMP 0000000173e13470
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[304] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW 0000000076ee9281 5 bytes JMP 0000000173e133d0
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[304] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076ac1d29 5 bytes JMP 0000000173e13380
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[304] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076ac1dd7 5 bytes JMP 0000000173e13340
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[304] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076ac2ab1 5 bytes JMP 0000000173e13480
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[304] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076ac2d1d 5 bytes JMP 0000000173e13190
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[304] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000074d3e96b 5 bytes JMP 0000000173e129a0
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[304] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000074d3eba5 5 bytes JMP 0000000173e129c0
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[304] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076468a29 5 bytes JMP 0000000173e12880
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[304] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000076474572 5 bytes JMP 0000000173e13110
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[304] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007648e567 5 bytes JMP 0000000173e13180
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[304] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000764b07d7 5 bytes JMP 0000000173e12700
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[304] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000764c7a5c 5 bytes JMP 0000000173e13100
      .text C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe[4560] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection 000000007735fc9c 5 bytes JMP 000000016f9b1460
      .text C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe[4560] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory 000000007735fe60 5 bytes JMP 000000016f9b1120
      .text C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe[4560] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076e41efe 7 bytes JMP 0000000173e13880
      .text C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe[4560] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076e45b9d 7 bytes JMP 0000000173e13ec0
      .text C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe[4560] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000076e513f9 7 bytes JMP 0000000173e13ad0
      .text C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe[4560] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW 0000000076e53bab 5 bytes JMP 000000016f9b1260
      .text C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe[4560] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000076e5ea45 7 bytes JMP 0000000173e13870
      .text C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe[4560] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076ee8ea4 7 bytes JMP 0000000173e133c0
      .text C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe[4560] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076ee8f29 5 bytes JMP 0000000173e13470
      .text C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe[4560] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076ee9281 5 bytes JMP 0000000173e133d0
      .text C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe[4560] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076ac1d29 5 bytes JMP 0000000173e13380
      .text C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe[4560] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076ac1dd7 5 bytes JMP 0000000173e13340
      .text C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe[4560] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076ac2ab1 5 bytes JMP 0000000173e13480
      .text C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe[4560] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076ac2d1d 5 bytes JMP 0000000173e13190
      .text C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe[4560] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076468a29 5 bytes JMP 0000000173e12880
      .text C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe[4560] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000076474572 5 bytes JMP 0000000173e13110
      .text C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe[4560] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007648e567 5 bytes JMP 0000000173e13180
      .text C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe[4560] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000764b07d7 5 bytes JMP 0000000173e12700
      .text C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe[4560] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000764c7a5c 5 bytes JMP 0000000173e13100
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection 000000007735fc9c 5 bytes JMP 000000016f9b1460
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory 000000007735fe60 5 bytes JMP 000000016f9b1120
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076e41efe 7 bytes JMP 0000000173e13880
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076e45b9d 7 bytes JMP 0000000173e13ec0
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000076e513f9 7 bytes JMP 0000000173e13ad0
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW 0000000076e53bab 5 bytes JMP 000000016f9b1260
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000076e5ea45 7 bytes JMP 0000000173e13870
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076ee8ea4 7 bytes JMP 0000000173e133c0
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076ee8f29 5 bytes JMP 0000000173e13470
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076ee9281 5 bytes JMP 0000000173e133d0
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076ac1d29 5 bytes JMP 0000000173e13380
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076ac1dd7 5 bytes JMP 0000000173e13340
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076ac2ab1 5 bytes JMP 0000000173e13480
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076ac2d1d 5 bytes JMP 0000000173e13190
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076468a29 5 bytes JMP 0000000173e12880
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000076474572 5 bytes JMP 0000000173e13110
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007648e567 5 bytes JMP 0000000173e13180
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000764b07d7 5 bytes JMP 0000000173e12700
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000764c7a5c 5 bytes JMP 0000000173e13100
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000074d3e96b 5 bytes JMP 0000000173e129a0
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000074d3eba5 5 bytes JMP 0000000173e129c0
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076b15ea5 5 bytes JMP 0000000173e12840
      .text C:\Program Files (x86)\AVG\AVG2015\avgui.exe[4136] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076b49d0b 5 bytes JMP 0000000173e127d0
      .text C:\Windows\SysWOW64\regsvr32.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection 000000007735fc9c 5 bytes JMP 000000016f9b1460
      .text C:\Windows\SysWOW64\regsvr32.exe[5164] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory 000000007735fe60 5 bytes JMP 000000016f9b1120
      .text C:\Windows\SysWOW64\regsvr32.exe[5164] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW 0000000076e53bab 5 bytes JMP 000000016f9b1260
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[5240] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection 000000007735fc9c 5 bytes JMP 000000016f9b1460
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[5240] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory 000000007735fe60 5 bytes JMP 000000016f9b1120
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[5240] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076e41efe 7 bytes JMP 0000000173e13880
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[5240] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076e45b9d 7 bytes JMP 0000000173e13ec0
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[5240] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000076e513f9 7 bytes JMP 0000000173e13ad0
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[5240] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW 0000000076e53bab 5 bytes JMP 000000016f9b1260
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[5240] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000076e5ea45 7 bytes JMP 0000000173e13870
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[5240] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076ee8ea4 7 bytes JMP 0000000173e133c0
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[5240] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076ee8f29 5 bytes JMP 0000000173e13470
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[5240] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076ee9281 5 bytes JMP 0000000173e133d0
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[5240] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076ac1d29 5 bytes JMP 0000000173e13380
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[5240] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076ac1dd7 5 bytes JMP 0000000173e13340
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[5240] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076ac2ab1 5 bytes JMP 0000000173e13480
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[5240] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076ac2d1d 5 bytes JMP 0000000173e13190
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[5240] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076468a29 5 bytes JMP 0000000173e12880
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[5240] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000076474572 5 bytes JMP 0000000173e13110
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[5240] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007648e567 5 bytes JMP 0000000173e13180
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[5240] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000764b07d7 5 bytes JMP 0000000173e12700
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[5240] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000764c7a5c 5 bytes JMP 0000000173e13100
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[5240] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076b15ea5 5 bytes JMP 0000000173e12840
      .text C:\Users\RamonXP\AppData\Local\Akamai\netsession_win.exe[5240] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076b49d0b 5 bytes JMP 0000000173e127d0
      .text C:\Windows\SysWOW64\ctfmon.exe[5856] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection 000000007735fc9c 5 bytes JMP 000000016f9b1460
      .text C:\Windows\SysWOW64\ctfmon.exe[5856] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory 000000007735fe60 5 bytes JMP 000000016f9b1120
      .text C:\Windows\SysWOW64\ctfmon.exe[5856] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076e41efe 7 bytes JMP 0000000173e13880
      .text C:\Windows\SysWOW64\ctfmon.exe[5856] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076e45b9d 7 bytes JMP 0000000173e13ec0
      .text C:\Windows\SysWOW64\ctfmon.exe[5856] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000076e513f9 7 bytes JMP 0000000173e13ad0
      .text C:\Windows\SysWOW64\ctfmon.exe[5856] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW 0000000076e53bab 5 bytes JMP 000000016f9b1260
      .text C:\Windows\SysWOW64\ctfmon.exe[5856] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000076e5ea45 7 bytes JMP 0000000173e13870
      .text C:\Windows\SysWOW64\ctfmon.exe[5856] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076ee8ea4 7 bytes JMP 0000000173e133c0
      .text C:\Windows\SysWOW64\ctfmon.exe[5856] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076ee8f29 5 bytes JMP 0000000173e13470
      .text C:\Windows\SysWOW64\ctfmon.exe[5856] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076ee9281 5 bytes JMP 0000000173e133d0
      .text C:\Windows\SysWOW64\ctfmon.exe[5856] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076ac1d29 5 bytes JMP 0000000173e13380
      .text C:\Windows\SysWOW64\ctfmon.exe[5856] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076ac1dd7 5 bytes JMP 0000000173e13340
      .text C:\Windows\SysWOW64\ctfmon.exe[5856] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076ac2ab1 5 bytes JMP 0000000173e13480
      .text C:\Windows\SysWOW64\ctfmon.exe[5856] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076ac2d1d 5 bytes JMP 0000000173e13190
      .text C:\Windows\SysWOW64\ctfmon.exe[5856] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076b15ea5 5 bytes JMP 0000000173e12840
      .text C:\Windows\SysWOW64\ctfmon.exe[5856] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076b49d0b 5 bytes JMP 0000000173e127d0
      .text C:\Windows\system32\SearchIndexer.exe[6004] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000771ade30 5 bytes JMP 0000000077310128
      .text C:\Windows\system32\SearchIndexer.exe[6004] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000771adf50 5 bytes JMP 0000000077310018
      .text C:\Windows\System32\svchost.exe[5740] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000771ade30 5 bytes JMP 0000000177150128
      .text C:\Windows\System32\svchost.exe[5740] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000771adf50 5 bytes JMP 0000000177150018
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5352] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection 000000007735fc9c 5 bytes JMP 000000016f9b1460
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5352] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory 000000007735fe60 5 bytes JMP 000000016f9b1120
      .text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5352] C:\Windows\syswow64\KERNEL32.dll!CreateProcessInternalW 0000000076e53bab 5 bytes JMP 000000016f9b1260

      Comment


      • #4
        .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[6000] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW 0000000076e53bab 5 bytes JMP 000000016f9b1260
        .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[1172] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection 000000007735fc9c 5 bytes JMP 000000016f9b1460
        .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[1172] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory 000000007735fe60 5 bytes JMP 000000016f9b1120
        .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[1172] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW 0000000076e53bab 5 bytes JMP 000000016f9b1260
        .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[1172] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075591401 2 bytes JMP 76e6b21b C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[1172] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075591419 2 bytes JMP 76e6b346 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[1172] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075591431 2 bytes JMP 76ee8f29 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[1172] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007559144a 2 bytes CALL 76e4489d C:\Windows\syswow64\kernel32.dll
        .text ... * 9
        .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[1172] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000755914dd 2 bytes JMP 76ee8822 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[1172] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000755914f5 2 bytes JMP 76ee89f8 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[1172] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007559150d 2 bytes JMP 76ee8718 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[1172] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075591525 2 bytes JMP 76ee8ae2 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[1172] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007559153d 2 bytes JMP 76e5fca8 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[1172] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075591555 2 bytes JMP 76e668ef C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[1172] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007559156d 2 bytes JMP 76ee8fe3 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[1172] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075591585 2 bytes JMP 76ee8b42 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[1172] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007559159d 2 bytes JMP 76ee86dc C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[1172] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000755915b5 2 bytes JMP 76e5fd41 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[1172] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000755915cd 2 bytes JMP 76e6b2dc C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[1172] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000755916b2 2 bytes JMP 76ee8ea4 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[1172] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000755916bd 2 bytes JMP 76ee8671 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files\Internet Explorer\iexplore.exe[6956] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000771ade30 5 bytes JMP 0000000077310128
        .text C:\Program Files\Internet Explorer\iexplore.exe[6956] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000771adf50 5 bytes JMP 0000000077310018
        .text C:\Program Files\Internet Explorer\iexplore.exe[6956] C:\Windows\system32\kernel32.dll!RegSetValueExW 0000000076f4a3e0 7 bytes JMP 000000016fff0228
        .text C:\Program Files\Internet Explorer\iexplore.exe[6956] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000076f53f00 5 bytes JMP 000000016fff0180
        .text C:\Program Files\Internet Explorer\iexplore.exe[6956] C:\Windows\system32\kernel32.dll!CreateProcessInternalW 0000000076f5dbc0 5 bytes JMP 00000000773100a0
        .text C:\Program Files\Internet Explorer\iexplore.exe[6956] C:\Windows\system32\kernel32.dll!RegDeleteValueW 0000000076f6ffd0 5 bytes JMP 000000016fff01b8
        .text C:\Program Files\Internet Explorer\iexplore.exe[6956] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000076f7f350 5 bytes JMP 000000016fff0110
        .text C:\Program Files\Internet Explorer\iexplore.exe[6956] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000076fa9aa0 7 bytes JMP 000000016fff00d8
        .text C:\Program Files\Internet Explorer\iexplore.exe[6956] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000076fb9530 5 bytes JMP 000000016fff0148
        .text C:\Program Files\Internet Explorer\iexplore.exe[6956] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000076fd8850 7 bytes JMP 000000016fff01f0
        .text C:\Program Files\Internet Explorer\iexplore.exe[6956] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefbd32db0 5 bytes JMP 000007fffbd20180
        .text C:\Program Files\Internet Explorer\iexplore.exe[6956] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefbd337d0 7 bytes JMP 000007fffbd200d8
        .text C:\Program Files\Internet Explorer\iexplore.exe[6956] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefbd3a410 2 bytes JMP 000007fffbd20110
        .text C:\Program Files\Internet Explorer\iexplore.exe[6956] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefbd3a413 2 bytes [FE, FF]
        .text C:\Program Files\Internet Explorer\iexplore.exe[6956] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefbd3aec0 6 bytes JMP 000007fffbd20148
        .text C:\Program Files\Internet Explorer\iexplore.exe[6956] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefc2689e0 8 bytes JMP 000007fffbd201f0
        .text C:\Program Files\Internet Explorer\iexplore.exe[6956] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefc26be40 8 bytes JMP 000007fffbd201b8
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection 000000007735fc9c 5 bytes JMP 000000016f9b1460
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory 000000007735fe60 5 bytes JMP 000000016f9b1120
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076e41efe 7 bytes JMP 0000000173e13880
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076e45b9d 7 bytes JMP 0000000173e13ec0
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000076e513f9 7 bytes JMP 0000000173e13ad0
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW 0000000076e53bab 5 bytes JMP 000000016f9b1260
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000076e5ea45 7 bytes JMP 0000000173e13870
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076ee8ea4 7 bytes JMP 0000000173e133c0
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076ee8f29 5 bytes JMP 0000000173e13470
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076ee9281 5 bytes JMP 0000000173e133d0
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076ac1d29 5 bytes JMP 0000000173e13380
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076ac1dd7 5 bytes JMP 0000000173e13340
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076ac2ab1 5 bytes JMP 0000000173e13480
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076ac2d1d 5 bytes JMP 0000000173e13190
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\user32.DLL!CreateWindowExW 0000000076468a29 5 bytes JMP 0000000173e12880
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\user32.DLL!DrawTextExW 000000007647149e 6 bytes [68, 34, C0, E7, 03, C3]
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\user32.DLL!DrawTextW 00000000764725cf 6 bytes [68, E4, B4, E7, 03, C3]
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\user32.DLL!EnumDisplayDevicesA 0000000076474572 5 bytes JMP 0000000173e13110
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\user32.DLL!MessageBeep 000000007647c036 6 bytes [68, 8C, 6C, EC, 03, C3]
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\user32.DLL!EnumDisplayDevicesW 000000007648e567 5 bytes JMP 0000000173e13180
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\user32.DLL!ChangeDisplaySettingsExW 00000000764b07d7 5 bytes JMP 0000000173e12700
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\user32.DLL!DisplayConfigGetDeviceInfo 00000000764c7a5c 5 bytes JMP 0000000173e13100
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000074d3e96b 5 bytes JMP 0000000173e129a0
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000074d3eba5 5 bytes JMP 0000000173e129c0
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000074e24406 6 bytes [68, C4, 6E, E7, 03, C3]
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\WS2_32.dll!send 0000000074e26f01 6 bytes [68, 74, 63, E7, 03, C3]
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000075265ab0 6 bytes [68, 0C, 12, EC, 03, C3]
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000752e41a0 6 bytes [68, 84, DB, E7, 03, C3]
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075591401 2 bytes JMP 76e6b21b C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075591419 2 bytes JMP 76e6b346 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075591431 2 bytes JMP 76ee8f29 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007559144a 2 bytes CALL 76e4489d C:\Windows\syswow64\kernel32.dll
        .text ... * 9
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000755914dd 2 bytes JMP 76ee8822 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000755914f5 2 bytes JMP 76ee89f8 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007559150d 2 bytes JMP 76ee8718 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075591525 2 bytes JMP 76ee8ae2 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007559153d 2 bytes JMP 76e5fca8 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075591555 2 bytes JMP 76e668ef C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007559156d 2 bytes JMP 76ee8fe3 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075591585 2 bytes JMP 76ee8b42 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007559159d 2 bytes JMP 76ee86dc C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000755915b5 2 bytes JMP 76e5fd41 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000755915cd 2 bytes JMP 76e6b2dc C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000755916b2 2 bytes JMP 76ee8ea4 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[6288] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000755916bd 2 bytes JMP 76ee8671 C:\Windows\syswow64\kernel32.dll
        .text C:\Windows\servicing\TrustedInstaller.exe[4848] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000771ade30 5 bytes JMP 0000000077310128
        .text C:\Windows\servicing\TrustedInstaller.exe[4848] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000771adf50 5 bytes JMP 0000000077310018
        .text C:\Windows\servicing\TrustedInstaller.exe[4848] C:\Windows\system32\kernel32.dll!CreateProcessInternalW 0000000076f5dbc0 5 bytes JMP 00000000773100a0
        .text C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_188_ActiveX.exe[2628] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000771ade30 5 bytes JMP 0000000077310128
        .text C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_188_ActiveX.exe[2628] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000771adf50 5 bytes JMP 0000000077310018
        .text C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_188_ActiveX.exe[2628] C:\Windows\system32\kernel32.dll!RegSetValueExW 0000000076f4a3e0 7 bytes JMP 000000016fff0228
        .text C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_188_ActiveX.exe[2628] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000076f53f00 5 bytes JMP 000000016fff0180
        .text C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_188_ActiveX.exe[2628] C:\Windows\system32\kernel32.dll!CreateProcessInternalW 0000000076f5dbc0 5 bytes JMP 00000000773100a0
        .text C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_188_ActiveX.exe[2628] C:\Windows\system32\kernel32.dll!RegDeleteValueW 0000000076f6ffd0 5 bytes JMP 000000016fff01b8
        .text C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_188_ActiveX.exe[2628] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000076f7f350 5 bytes JMP 000000016fff0110
        .text C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_188_ActiveX.exe[2628] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000076fa9aa0 7 bytes JMP 000000016fff00d8
        .text C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_188_ActiveX.exe[2628] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000076fb9530 5 bytes JMP 000000016fff0148
        .text C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_188_ActiveX.exe[2628] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000076fd8850 7 bytes JMP 000000016fff01f0
        .text C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_188_ActiveX.exe[2628] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefbd32db0 5 bytes JMP 000007fffbd20180
        .text C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_188_ActiveX.exe[2628] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefbd337d0 7 bytes JMP 000007fffbd200d8
        .text C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_188_ActiveX.exe[2628] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefbd3a410 2 bytes JMP 000007fffbd20110
        .text C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_188_ActiveX.exe[2628] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefbd3a413 2 bytes [FE, FF]
        .text C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_188_ActiveX.exe[2628] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefbd3aec0 6 bytes JMP 000007fffbd20148
        .text C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_188_ActiveX.exe[2628] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefc2689e0 8 bytes JMP 000007fffbd201f0
        .text C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_188_ActiveX.exe[2628] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefc26be40 8 bytes JMP 000007fffbd201b8
        .text C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_188_ActiveX.exe[2628] C:\Windows\system32\d3d9.dll!Direct3DCreate9Ex 000007fef5512460 5 bytes JMP 000007fefbd202d0
        .text C:\Windows\system32\Macromed\Flash\FlashUtil64_17_0_0_188_ActiveX.exe[2628] C:\Windows\system32\d3d9.dll!Direct3DCreate9 000007fef55496b0 6 bytes JMP 000007fefbd20298
        .text C:\Program Files\Internet Explorer\iexplore.exe[6844] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000771ade30 5 bytes JMP 0000000077310128
        .text C:\Program Files\Internet Explorer\iexplore.exe[6844] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000771adf50 5 bytes JMP 0000000077310018
        .text C:\Program Files\Internet Explorer\iexplore.exe[6844] C:\Windows\system32\kernel32.dll!RegSetValueExW 0000000076f4a3e0 7 bytes JMP 000000016fff0228
        .text C:\Program Files\Internet Explorer\iexplore.exe[6844] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000076f53f00 5 bytes JMP 000000016fff0180
        .text C:\Program Files\Internet Explorer\iexplore.exe[6844] C:\Windows\system32\kernel32.dll!CreateProcessInternalW 0000000076f5dbc0 5 bytes JMP 00000000773100a0
        .text C:\Program Files\Internet Explorer\iexplore.exe[6844] C:\Windows\system32\kernel32.dll!RegDeleteValueW 0000000076f6ffd0 5 bytes JMP 000000016fff01b8
        .text C:\Program Files\Internet Explorer\iexplore.exe[6844] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000076f7f350 5 bytes JMP 000000016fff0110
        .text C:\Program Files\Internet Explorer\iexplore.exe[6844] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000076fa9aa0 7 bytes JMP 000000016fff00d8
        .text C:\Program Files\Internet Explorer\iexplore.exe[6844] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000076fb9530 5 bytes JMP 000000016fff0148
        .text C:\Program Files\Internet Explorer\iexplore.exe[6844] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000076fd8850 7 bytes JMP 000000016fff01f0
        .text C:\Program Files\Internet Explorer\iexplore.exe[6844] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefbd32db0 5 bytes JMP 000007fffbd20180
        .text C:\Program Files\Internet Explorer\iexplore.exe[6844] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefbd337d0 7 bytes JMP 000007fffbd200d8
        .text C:\Program Files\Internet Explorer\iexplore.exe[6844] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefbd3a410 2 bytes JMP 000007fffbd20110
        .text C:\Program Files\Internet Explorer\iexplore.exe[6844] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefbd3a413 2 bytes [FE, FF]
        .text C:\Program Files\Internet Explorer\iexplore.exe[6844] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefbd3aec0 6 bytes JMP 000007fffbd20148
        .text C:\Program Files\Internet Explorer\iexplore.exe[6844] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefc2689e0 8 bytes JMP 000007fffbd201f0
        .text C:\Program Files\Internet Explorer\iexplore.exe[6844] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefc26be40 8 bytes JMP 000007fffbd201b8
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection 000000007735fc9c 5 bytes JMP 000000016f9b1460
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory 000000007735fe60 5 bytes JMP 000000016f9b1120
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076e41efe 7 bytes JMP 0000000173e13880
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076e45b9d 7 bytes JMP 0000000173e13ec0
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000076e513f9 7 bytes JMP 0000000173e13ad0
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW 0000000076e53bab 5 bytes JMP 000000016f9b1260
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000076e5ea45 7 bytes JMP 0000000173e13870
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076ee8ea4 7 bytes JMP 0000000173e133c0
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076ee8f29 5 bytes JMP 0000000173e13470
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076ee9281 5 bytes JMP 0000000173e133d0
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076ac1d29 5 bytes JMP 0000000173e13380
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076ac1dd7 5 bytes JMP 0000000173e13340
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076ac2ab1 5 bytes JMP 0000000173e13480
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076ac2d1d 5 bytes JMP 0000000173e13190
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\user32.DLL!CreateWindowExW 0000000076468a29 5 bytes JMP 0000000173e12880
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\user32.DLL!DrawTextExW 000000007647149e 6 bytes [68, 84, B1, 00, 04, C3]
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\user32.DLL!DrawTextW 00000000764725cf 6 bytes [68, D4, CD, 00, 04, C3]
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\user32.DLL!EnumDisplayDevicesA 0000000076474572 5 bytes JMP 0000000173e13110
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\user32.DLL!MessageBeep 000000007647c036 6 bytes [68, 4C, 67, 05, 04, C3]
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\user32.DLL!EnumDisplayDevicesW 000000007648e567 5 bytes JMP 0000000173e13180
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\user32.DLL!ChangeDisplaySettingsExW 00000000764b07d7 5 bytes JMP 0000000173e12700
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\user32.DLL!DisplayConfigGetDeviceInfo 00000000764c7a5c 5 bytes JMP 0000000173e13100
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000074d3e96b 5 bytes JMP 0000000173e129a0
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000074d3eba5 5 bytes JMP 0000000173e129c0
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000074e24406 6 bytes [68, C4, 6E, 00, 04, C3]
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\WS2_32.dll!send 0000000074e26f01 6 bytes [68, 74, 63, 00, 04, C3]
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000075265ab0 6 bytes [68, CC, 0C, 01, 04, C3]
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000752e41a0 6 bytes [68, D4, BC, 00, 04, C3]
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075591401 2 bytes JMP 76e6b21b C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075591419 2 bytes JMP 76e6b346 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075591431 2 bytes JMP 76ee8f29 C:\Windows\syswow64\kernel32.dll
        .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007559144a 2 bytes CALL 76e4489d C:\Windows\syswow64\kernel32.dll
        .text ... * 9

        Comment


        • #5
          .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000755914dd 2 bytes JMP 76ee8822 C:\Windows\syswow64\kernel32.dll
          .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000755914f5 2 bytes JMP 76ee89f8 C:\Windows\syswow64\kernel32.dll
          .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007559150d 2 bytes JMP 76ee8718 C:\Windows\syswow64\kernel32.dll
          .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075591525 2 bytes JMP 76ee8ae2 C:\Windows\syswow64\kernel32.dll
          .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007559153d 2 bytes JMP 76e5fca8 C:\Windows\syswow64\kernel32.dll
          .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075591555 2 bytes JMP 76e668ef C:\Windows\syswow64\kernel32.dll
          .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007559156d 2 bytes JMP 76ee8fe3 C:\Windows\syswow64\kernel32.dll
          .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075591585 2 bytes JMP 76ee8b42 C:\Windows\syswow64\kernel32.dll
          .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007559159d 2 bytes JMP 76ee86dc C:\Windows\syswow64\kernel32.dll
          .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000755915b5 2 bytes JMP 76e5fd41 C:\Windows\syswow64\kernel32.dll
          .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000755915cd 2 bytes JMP 76e6b2dc C:\Windows\syswow64\kernel32.dll
          .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000755916b2 2 bytes JMP 76ee8ea4 C:\Windows\syswow64\kernel32.dll
          .text C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4380] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000755916bd 2 bytes JMP 76ee8671 C:\Windows\syswow64\kernel32.dll
          .text C:\Windows\System32\svchost.exe[6452] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000771ade30 5 bytes JMP 0000000177150128
          .text C:\Windows\System32\svchost.exe[6452] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000771adf50 5 bytes JMP 0000000177150018
          .text C:\Windows\System32\svchost.exe[6452] C:\Windows\system32\kernel32.dll!CreateProcessInternalW 0000000076f5dbc0 5 bytes JMP 00000000771500a0
          .text C:\Windows\system32\DllHost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00000000771ade30 5 bytes JMP 0000000077310128
          .text C:\Windows\system32\DllHost.exe[1196] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00000000771adf50 5 bytes JMP 0000000077310018
          .text C:\Windows\system32\DllHost.exe[1196] C:\Windows\system32\kernel32.dll!RegSetValueExW 0000000076f4a3e0 7 bytes JMP 000000016fff0228
          .text C:\Windows\system32\DllHost.exe[1196] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000076f53f00 5 bytes JMP 000000016fff0180
          .text C:\Windows\system32\DllHost.exe[1196] C:\Windows\system32\kernel32.dll!CreateProcessInternalW 0000000076f5dbc0 5 bytes JMP 00000000773100a0
          .text C:\Windows\system32\DllHost.exe[1196] C:\Windows\system32\kernel32.dll!RegDeleteValueW 0000000076f6ffd0 5 bytes JMP 000000016fff01b8
          .text C:\Windows\system32\DllHost.exe[1196] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000076f7f350 5 bytes JMP 000000016fff0110
          .text C:\Windows\system32\DllHost.exe[1196] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000076fa9aa0 7 bytes JMP 000000016fff00d8
          .text C:\Windows\system32\DllHost.exe[1196] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000076fb9530 5 bytes JMP 000000016fff0148
          .text C:\Windows\system32\DllHost.exe[1196] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000076fd8850 7 bytes JMP 000000016fff01f0
          .text C:\Windows\system32\DllHost.exe[1196] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefbd32db0 5 bytes JMP 000007fffbd20180
          .text C:\Windows\system32\DllHost.exe[1196] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefbd337d0 7 bytes JMP 000007fffbd200d8
          .text C:\Windows\system32\DllHost.exe[1196] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefbd3a410 2 bytes JMP 000007fffbd20110
          .text C:\Windows\system32\DllHost.exe[1196] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefbd3a413 2 bytes [FE, FF]
          .text C:\Windows\system32\DllHost.exe[1196] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefbd3aec0 6 bytes JMP 000007fffbd20148
          .text C:\Windows\system32\DllHost.exe[1196] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefcc07490 11 bytes JMP 000007fffbd20228
          .text C:\Windows\system32\DllHost.exe[1196] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefcc1bf00 7 bytes JMP 000007fffbd20260
          .text C:\Windows\system32\DllHost.exe[1196] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefc2689e0 8 bytes JMP 000007fffbd201f0
          .text C:\Windows\system32\DllHost.exe[1196] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefc26be40 8 bytes JMP 000007fffbd201b8
          .text C:\Users\RamonXP\Desktop\antivirus\n9g51dpu.exe[4660] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection 000000007735fc9c 5 bytes JMP 000000016f9b1460
          .text C:\Users\RamonXP\Desktop\antivirus\n9g51dpu.exe[4660] C:\Windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory 000000007735fe60 5 bytes JMP 000000016f9b1120
          .text C:\Users\RamonXP\Desktop\antivirus\n9g51dpu.exe[4660] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000076e41efe 7 bytes JMP 0000000173e13880
          .text C:\Users\RamonXP\Desktop\antivirus\n9g51dpu.exe[4660] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000076e45b9d 7 bytes JMP 0000000173e13ec0
          .text C:\Users\RamonXP\Desktop\antivirus\n9g51dpu.exe[4660] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000076e513f9 7 bytes JMP 0000000173e13ad0
          .text C:\Users\RamonXP\Desktop\antivirus\n9g51dpu.exe[4660] C:\Windows\syswow64\kernel32.dll!CreateProcessInternalW 0000000076e53bab 5 bytes JMP 000000016f9b1260
          .text C:\Users\RamonXP\Desktop\antivirus\n9g51dpu.exe[4660] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 0000000076e5ea45 7 bytes JMP 0000000173e13870
          .text C:\Users\RamonXP\Desktop\antivirus\n9g51dpu.exe[4660] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000076ee8ea4 7 bytes JMP 0000000173e133c0
          .text C:\Users\RamonXP\Desktop\antivirus\n9g51dpu.exe[4660] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076ee8f29 5 bytes JMP 0000000173e13470
          .text C:\Users\RamonXP\Desktop\antivirus\n9g51dpu.exe[4660] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076ee9281 5 bytes JMP 0000000173e133d0
          .text C:\Users\RamonXP\Desktop\antivirus\n9g51dpu.exe[4660] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076ac1d29 5 bytes JMP 0000000173e13380
          .text C:\Users\RamonXP\Desktop\antivirus\n9g51dpu.exe[4660] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076ac1dd7 5 bytes JMP 0000000173e13340
          .text C:\Users\RamonXP\Desktop\antivirus\n9g51dpu.exe[4660] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076ac2ab1 5 bytes JMP 0000000173e13480
          .text C:\Users\RamonXP\Desktop\antivirus\n9g51dpu.exe[4660] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076ac2d1d 5 bytes JMP 0000000173e13190
          .text C:\Users\RamonXP\Desktop\antivirus\n9g51dpu.exe[4660] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000074d3e96b 5 bytes JMP 0000000173e129a0
          .text C:\Users\RamonXP\Desktop\antivirus\n9g51dpu.exe[4660] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000074d3eba5 5 bytes JMP 0000000173e129c0
          .text C:\Users\RamonXP\Desktop\antivirus\n9g51dpu.exe[4660] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076468a29 5 bytes JMP 0000000173e12880
          .text C:\Users\RamonXP\Desktop\antivirus\n9g51dpu.exe[4660] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000076474572 5 bytes JMP 0000000173e13110
          .text C:\Users\RamonXP\Desktop\antivirus\n9g51dpu.exe[4660] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007648e567 5 bytes JMP 0000000173e13180
          .text C:\Users\RamonXP\Desktop\antivirus\n9g51dpu.exe[4660] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000764b07d7 5 bytes JMP 0000000173e12700
          .text C:\Users\RamonXP\Desktop\antivirus\n9g51dpu.exe[4660] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000764c7a5c 5 bytes JMP 0000000173e13100

          ---- User IAT/EAT - GMER 2.1 ----

          IAT C:\WINDOWS\System32\regsvr32.exe[3340] @ C:\Windows\system32\ADVAPI32.dll[KERNEL32.dll!CopyFileW] [7fef238a184]
          IAT C:\WINDOWS\System32\regsvr32.exe[3340] @ C:\Windows\system32\ADVAPI32.dll[KERNEL32.dll!GetProcAddress] [7fefba84230] C:\Windows\system32\apphelp.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Program Files\Internet Explorer\iexplore.exe[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\USER32.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\GDI32.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\advapi32.DLL[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\shell32.DLL[USER32.dll!MessageBoxW] [7feef356a70] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\shell32.DLL[USER32.dll!DialogBoxParamW] [7feef3564e0] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\shell32.DLL[USER32.dll!MessageBoxIndirectW] [7feef32d840] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\shell32.DLL[USER32.dll!EnableWindow] [7feef313370] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\SHLWAPI.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\SHLWAPI.dll[USER32.dll!DialogBoxParamW] [7feef3564e0] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\SHLWAPI.dll[USER32.dll!DialogBoxParamA] [7feef3563e0] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\SHLWAPI.dll[USER32.dll!MessageBoxW] [7feef356a70] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\iertutil.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\version.DLL[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\IMM32.DLL[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\MSCTF.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\SETUPAPI.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\SETUPAPI.dll[USER32.dll!DialogBoxParamW] [7feef3564e0] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\SETUPAPI.dll[USER32.dll!EnableWindow] [7feef313370] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\SETUPAPI.dll[USER32.dll!MessageBoxW] [7feef356a70] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\CFGMGR32.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\OLEAUT32.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\OLEAUT32.dll[USER32.dll!EnableWindow] [7feef313370] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\ole32.dll[USER32.dll!EnableWindow] [7feef313370] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\ole32.dll[USER32.dll!DialogBoxParamW] [7feef3564e0] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\ole32.dll[USER32.dll!MessageBoxW] [7feef356a70] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\IEFRAME.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\IEFRAME.dll[USER32.dll!EnableWindow] [7feef313370] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\IEFRAME.dll[USER32.dll!DialogBoxParamW] [7feef3564e0] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\IEFRAME.dll[USER32.dll!MessageBoxW] [7feef356a70] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\IEFRAME.dll[USER32.dll!MessageBoxIndirectW] [7feef32d840] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll[USER32.dll!EnableWindow] [7feef313370] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll[USER32.dll!DialogBoxIndirectParamW] [7feef356300] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\comdlg32.dll[USER32.dll!EnableWindow] [7feef313370] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\comdlg32.dll[USER32.dll!DialogBoxIndirectParamW] [7feef356300] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\comdlg32.dll[USER32.dll!MessageBoxW] [7feef356a70] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\comdlg32.dll[COMCTL32.dll!PropertySheetW] [7feef357160] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\comdlg32.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\uxtheme.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\urlmon.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\urlmon.dll[USER32.dll!EnableWindow] [7feef313370] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\urlmon.dll[USER32.dll!DialogBoxParamW] [7feef3564e0] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\WININET.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\dwmapi.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\Secur32.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\CLBCatQ.DLL[USER32.dll!DialogBoxParamW] [7feef3564e0] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\CLBCatQ.DLL[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\rsaenh.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\System32\netprofm.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\System32\nlaapi.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\System32\Wpc.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\System32\wevtapi.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Program Files\Internet Explorer\ieproxy.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\System32\fwpuclnt.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\apphelp.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\CRYPT32.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\IEUI.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\PROPSYS.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\windowscodecs.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\oleacc.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\explorerframe.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\explorerframe.dll[USER32.dll!EnableWindow] [7feef313370] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\DUser.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\DUI70.dll[USER32.dll!EnableWindow] [7feef313370] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\DUI70.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\ntmarta.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6956] @ C:\Windows\system32\WLDAP32.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Program Files\Internet Explorer\iexplore.exe[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\USER32.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\GDI32.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\advapi32.DLL[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\shell32.DLL[USER32.dll!MessageBoxW] [7feef356a70] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\shell32.DLL[USER32.dll!DialogBoxParamW] [7feef3564e0] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\shell32.DLL[USER32.dll!MessageBoxIndirectW] [7feef32d840] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\shell32.DLL[USER32.dll!EnableWindow] [7feef313370] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\SHLWAPI.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\SHLWAPI.dll[USER32.dll!DialogBoxParamW] [7feef3564e0] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\SHLWAPI.dll[USER32.dll!DialogBoxParamA] [7feef3563e0] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\SHLWAPI.dll[USER32.dll!MessageBoxW] [7feef356a70] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\iertutil.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\version.DLL[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\IMM32.DLL[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\MSCTF.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\SETUPAPI.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\SETUPAPI.dll[USER32.dll!DialogBoxParamW] [7feef3564e0] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\SETUPAPI.dll[USER32.dll!EnableWindow] [7feef313370] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\SETUPAPI.dll[USER32.dll!MessageBoxW] [7feef356a70] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\CFGMGR32.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\OLEAUT32.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\OLEAUT32.dll[USER32.dll!EnableWindow] [7feef313370] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\ole32.dll[USER32.dll!EnableWindow] [7feef313370] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\ole32.dll[USER32.dll!DialogBoxParamW] [7feef3564e0] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\ole32.dll[USER32.dll!MessageBoxW] [7feef356a70] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\IEFRAME.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\IEFRAME.dll[USER32.dll!EnableWindow] [7feef313370] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\IEFRAME.dll[USER32.dll!DialogBoxParamW] [7feef3564e0] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\IEFRAME.dll[USER32.dll!MessageBoxW] [7feef356a70] C:\Program Files\Internet Explorer\IEShims.dll
          IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\IEFRAME.dll[USER32.dll!MessageBoxIndirectW] [7feef32d840] C:\Program Files\Internet Explorer\IEShims.dll

          Comment


          • #6
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll[USER32.dll!EnableWindow] [7feef313370] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll[USER32.dll!DialogBoxIndirectParamW] [7feef356300] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\comdlg32.dll[USER32.dll!EnableWindow] [7feef313370] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\comdlg32.dll[USER32.dll!DialogBoxIndirectParamW] [7feef356300] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\comdlg32.dll[USER32.dll!MessageBoxW] [7feef356a70] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\comdlg32.dll[COMCTL32.dll!PropertySheetW] [7feef357160] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\comdlg32.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\uxtheme.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\urlmon.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\urlmon.dll[USER32.dll!EnableWindow] [7feef313370] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\urlmon.dll[USER32.dll!DialogBoxParamW] [7feef3564e0] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\WININET.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\dwmapi.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\Secur32.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\CLBCatQ.DLL[USER32.dll!DialogBoxParamW] [7feef3564e0] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\CLBCatQ.DLL[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\System32\netprofm.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\System32\nlaapi.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\rsaenh.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\System32\Wpc.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\System32\wevtapi.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\System32\fwpuclnt.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Program Files\Internet Explorer\ieproxy.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\apphelp.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\CRYPT32.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\IEUI.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\PROPSYS.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\windowscodecs.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\oleacc.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\explorerframe.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\explorerframe.dll[USER32.dll!EnableWindow] [7feef313370] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\DUser.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\DUI70.dll[USER32.dll!EnableWindow] [7feef313370] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\DUI70.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\ntmarta.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll
            IAT C:\Program Files\Internet Explorer\iexplore.exe[6844] @ C:\Windows\system32\WLDAP32.dll[KERNEL32.dll!GetProcAddress] [7feef311800] C:\Program Files\Internet Explorer\IEShims.dll

            ---- Threads - GMER 2.1 ----

            Thread C:\Windows\system32\svchost.exe [1276:4388] 000007fef3ed506c
            Thread C:\Windows\system32\svchost.exe [1276:5160] 000007feeb8c1ab0
            Thread C:\Windows\system32\svchost.exe [1276:932] 000007fef6c95124
            Thread C:\Windows\system32\svchost.exe [1276:3240] 000007feef7ba1a0
            Thread C:\Windows\system32\svchost.exe [1276:4024] 000007feef7ba1a0
            Thread C:\Windows\system32\svchost.exe [1276:5636] 000007fefa9a4164
            Thread C:\Windows\system32\svchost.exe [1404:1612] 000007fef9ad8274
            Thread C:\Windows\system32\svchost.exe [1404:2652] 000007fef9ad8274
            Thread C:\Windows\system32\svchost.exe [1864:2088] 000007fef74d35c0
            Thread C:\Windows\system32\svchost.exe [1864:3164] 000007fef74d5600
            Thread C:\Windows\system32\svchost.exe [1864:3460] 000007fef9872940
            Thread C:\Windows\system32\svchost.exe [1864:2248] 000007fef9792888
            Thread C:\Windows\system32\svchost.exe [1864:6352] 000007fef9792a40
            Thread C:\Windows\system32\taskhost.exe [2672:2900] 000007fef64a1f38
            Thread C:\Windows\system32\taskhost.exe [2672:2904] 000007fef6442740
            Thread C:\Windows\system32\taskhost.exe [2672:2912] 000007fef9a51010
            Thread C:\Windows\system32\Dwm.exe [2776:2944] 000000000206abf0
            Thread C:\Windows\system32\wbem\wmiprvse.exe [4288:4384] 0000000180006e60
            Thread C:\Windows\SysWOW64\regsvr32.exe [5164:5336] 0000000000242f08
            Thread C:\Windows\SysWOW64\regsvr32.exe [5164:5344] 0000000000242f08
            Thread C:\Windows\SysWOW64\regsvr32.exe [5164:5360] 0000000000242f08
            Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [5132:2376] 000007fef9fe2bf8
            Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [5132:2952] 000007fef0855648
            Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [5132:3948] 000007fef6c95124
            Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [5132:2868] 000007fef07b6590
            Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [5132:6100] 000007fef0855648
            Thread C:\Windows\System32\svchost.exe [5740:5452] 000007fef64e5170
            Thread C:\Windows\system32\DllHost.exe [5468:5940] 000007feeb80ae40
            Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [6288:6504] 0000000003462f08
            Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [6288:3220] 0000000003462f08
            Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [6288:3884] 0000000003462f08
            Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [6288:5200] 0000000003462f08
            Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4380:6380] 0000000003672f08
            Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4380:6368] 0000000003672f08
            Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4380:2608] 0000000003672f08
            Thread C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE [4380:6764] 0000000003672f08

            ---- Registry - GMER 2.1 ----

            Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{0BCA85EC-4491-405C-9FB4-25A256D593AC}\[email protected] isatap.{813FD530-BFF5-4075-97D8-B9EA8DCC523C}
            Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{967CB980-B1D4-4947-A98C-50ACE1D5C55D}\[email protected] isatap.{9E5A5509-8DA0-4C51-A023-AAA19CD295A7}
            Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\[email protected] \Device\{967CB980-B1D4-4947-A98C-50ACE1D5C55D}?\Device\{FC136497-8ED9-44A1-90FB-C9705E03E3C1}?\Device\{0BCA85EC-4491-405C-9FB4-25A256D593AC}?\Device\{B90BD4A9-79E3-4E10-BCDD-D5151377E996}?
            Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\[email protected] "{967CB980-B1D4-4947-A98C-50ACE1D5C55D}"?"{FC136497-8ED9-44A1-90FB-C9705E03E3C1}"?"{0BCA85EC-4491-405C-9FB4-25A256D593AC}"?"{B90BD4A9-79E3-4E10-BCDD-D5151377E996}"?
            Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\[email protected] \Device\TCPIP6TUNNEL_{967CB980-B1D4-4947-A98C-50ACE1D5C55D}?\Device\TCPIP6TUNNEL_{FC136497-8ED9-44A1-90FB-C9705E03E3C1}?\Device\TCPIP6TUNNEL_{0BCA85EC-4491-405C-9FB4-25A256D593AC}?\Device\TCPIP6TUNNEL_{B90BD4A9-79E3-4E10-BCDD-D5151377E996}?
            Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{0BCA85EC-4491-405C-9FB4-25A256D593AC}@InterfaceName isatap.{813FD530-BFF5-4075-97D8-B9EA8DCC523C}
            Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{0BCA85EC-4491-405C-9FB4-25A256D593AC}@ReusableType 0
            Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{967CB980-B1D4-4947-A98C-50ACE1D5C55D}@InterfaceName isatap.{9E5A5509-8DA0-4C51-A023-AAA19CD295A7}
            Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{967CB980-B1D4-4947-A98C-50ACE1D5C55D}@ReusableType 0

            ---- EOF - GMER 2.1 ----

            Comment


            • #7
              Download of Update Ccleaner

              Start CCleaner op.
              • Run Ccleaner en klik in de linkse kolom op Opties
              • Selecteer het tabblad Geavanceerd
              • Haal het vinkje weg voor Verwijder alleen bestanden in Windows Temp-systeemmap die ouder zijn dan 24 uur
              • Selecteer het tabblad Instellingen
              • Haal het vinkje weg bij "Computer automatisch schoonmaken...."
              • Klik in de linkse kolom op Cleaner.
              • Klik dan achtereenvolgens op Analyseer en Schoonmaken.
              • Klik vervolgens in de linkse kolom op Register
              • Klik op Scan naar problemen.
              • Op de vraag of je een backup wil maken van het register, klik je "Ja".
              • Als er fouten gevonden worden klik je op de middelste knop: Herstel alle geselecteerde fouten en OK



              Download Combofix naar je bureaublad.
              (Dus niet naar een download map of temp map)

              Extra nota... Zorg ervoor dat je Security software uitgeschakeld is tijdens het gebruik van Combofix.
              Dit omdat deze scanners bepaalde componenten die Combofix gebruikt, onterecht zien als geïnfecteerd en Combofix zullen blokkeren.

              Kijk hier indien je niet weet hoe je je Antivirus, Firewall en/of Antispywarescanner moet uitschakelen.

              Sluit ALLE vensters, ook je browser en laat Combofix rustig zijn werk doen.
              Open dus geen andere applicaties totdat Combofix de log heeft gepresenteert.

              Als Combofix vraagt om een update, dan staat je dit toe.

              Wanneer ComboFix klaar is met scannen, dit kan eventueel na een reboot zijn, opent er een logfile (combofix.txt).
              Deze kan je vinden als C:\combofix.txt.

              Post het Combofixlogje

              * OPMERKING: Indien je één van de onderstaande meldingen krijgt na het gebruik van ComboFix, herstart dan de computer.
              • Er is geprobeerd een ongeldige bewerking uit te voeren op een registersleutel die is gemarkeerd voor verwijdering.
              • Illegal operation attempted on a registry key that has been marked for deletion.
              Malware Research [email protected] (MBAM) ..... ASAP & Unite Member
              E Dev * McAfee verwijderen. * Ccleaner * E-Peek

              Comment


              • #8
                Resultaten Combofix:

                ComboFix 15-06-09.01 - RamonXP 12-06-2015 7:35.1.4 - x64
                Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3828.2276 [GMT 2:00]
                Gestart vanuit: c:\users\RamonXP\Desktop\antivirus\ComboFix.exe
                AV: AVG AntiVirus Free Edition 2015 *Disabled/Updated* {4D41356F-32AD-7C42-C820-63775EE4F413}
                SP: AVG AntiVirus Free Edition 2015 *Disabled/Updated* {F620D48B-1497-73CC-F290-58052563BEAE}
                SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
                * Nieuw herstelpunt werd aangemaakt
                .
                .
                (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                C:\install.exe
                c:\windows\msdownld.tmp
                .
                .
                (((((((((((((((((((( Bestanden Gemaakt van 2015-05-12 to 2015-06-12 ))))))))))))))))))))))))))))))
                .
                .
                2015-06-12 06:09 . 2015-06-12 06:09 -------- d-----w- c:\users\Default\AppData\Local\temp
                2015-06-10 06:05 . 2015-06-11 19:30 -------- d-----w- C:\AdwCleaner
                2015-06-09 18:46 . 2015-04-24 18:17 633856 ----a-w- c:\windows\system32\comctl32.dll
                2015-06-09 18:45 . 2015-05-22 17:50 2426880 ----a-w- c:\windows\system32\wininet.dll
                2015-06-09 18:45 . 2015-05-22 19:22 950784 ----a-w- c:\program files\Internet Explorer\iedvtool.dll
                2015-06-09 18:45 . 2015-05-22 19:00 417792 ----a-w- c:\windows\system32\html.iec
                2015-06-09 18:45 . 2015-05-22 18:59 88064 ----a-w- c:\windows\system32\MshtmlDac.dll
                2015-06-09 18:45 . 2015-05-22 18:25 199680 ----a-w- c:\windows\system32\msrating.dll
                2015-06-09 18:45 . 2015-05-22 17:31 382976 ----a-w- c:\program files\Internet Explorer\IEShims.dll
                2015-06-09 18:45 . 2015-06-01 19:16 293072 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
                2015-06-09 18:45 . 2015-05-27 14:35 24917504 ----a-w- c:\windows\system32\mshtml.dll
                2015-06-09 18:45 . 2015-05-22 18:24 1016832 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
                2015-06-09 18:45 . 2015-05-22 19:12 10949120 ----a-w- c:\program files\Internet Explorer\F12Resources.dll
                2015-06-09 18:36 . 2015-06-09 18:37 -------- d-----w- c:\users\RamonXP\AppData\Roaming\ChromeUpdate
                2015-06-07 17:56 . 2015-06-07 17:56 -------- d-----w- c:\users\RamonXP\AppData\Local\Ubjjmedia
                2015-06-07 17:55 . 2015-06-09 18:21 -------- d-----w- c:\users\RamonXP\AppData\Local\Epqtion
                2015-06-02 07:22 . 2015-06-08 16:43 -------- d-----w- c:\program files (x86)\Heroes of the Storm
                2015-06-02 06:49 . 2015-06-02 06:49 -------- d-----w- c:\users\RamonXP\AppData\Local\GWX
                2015-05-30 09:39 . 2015-05-30 09:39 -------- d-----w- c:\program files (x86)\Microsoft ASP.NET
                2015-05-29 11:16 . 2015-05-29 11:16 -------- d-----w- c:\programdata\boost_interprocess
                2015-05-29 11:16 . 2015-04-03 13:21 48784 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
                2015-05-29 11:16 . 2015-04-03 13:21 38032 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
                2015-05-22 17:16 . 2015-05-22 17:16 18652352 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\MSO.DLL
                2015-05-20 17:08 . 2015-05-20 17:08 -------- d-----w- c:\users\RamonXP\AppData\Local\Avg
                2015-05-20 17:00 . 2015-05-20 17:00 -------- d-----w- c:\windows\SysWow64\NV
                2015-05-20 17:00 . 2015-05-20 17:00 -------- d-----w- c:\windows\system32\NV
                2015-05-19 20:56 . 2015-05-29 11:17 -------- d-----w- c:\users\RamonXP\AppData\Local\NVIDIA Corporation
                2015-05-19 20:55 . 2015-05-29 11:17 -------- d-----w- c:\users\RamonXP\AppData\Local\NVIDIA
                2015-05-19 20:05 . 2015-05-23 01:47 1756424 ----a-w- c:\windows\system32\nvspbridge64.dll
                2015-05-19 20:05 . 2015-05-23 01:47 1571696 ----a-w- c:\windows\system32\nvspcap64.dll
                2015-05-19 20:05 . 2015-05-23 01:47 1316000 ----a-w- c:\windows\SysWow64\nvspbridge.dll
                2015-05-19 20:05 . 2015-05-23 01:47 1320304 ----a-w- c:\windows\SysWow64\nvspcap.dll
                2015-05-19 20:04 . 2015-06-12 05:19 -------- d-----w- c:\programdata\NVIDIA
                2015-05-19 20:04 . 2015-05-12 02:34 571024 ----a-w- c:\windows\SysWow64\nvStreaming.exe
                2015-05-19 20:03 . 2015-05-12 03:30 937288 ----a-w- c:\windows\system32\nvvsvc.exe
                2015-05-19 20:03 . 2015-05-12 03:30 75080 ----a-w- c:\windows\system32\nv3dappshextr.dll
                2015-05-19 20:03 . 2015-05-12 03:30 62608 ----a-w- c:\windows\system32\nvshext.dll
                2015-05-19 20:03 . 2015-05-12 03:30 1059984 ----a-w- c:\windows\system32\nv3dappshext.dll
                2015-05-19 20:03 . 2015-05-12 03:30 3490448 ----a-w- c:\windows\system32\nvsvc64.dll
                2015-05-19 20:03 . 2015-05-12 03:30 2558608 ----a-w- c:\windows\system32\nvsvcr.dll
                2015-05-19 20:03 . 2015-05-11 17:01 4391871 ----a-w- c:\windows\system32\nvcoproc.bin
                2015-05-19 20:03 . 2015-05-12 03:30 385352 ----a-w- c:\windows\system32\nvmctray.dll
                2015-05-19 20:03 . 2015-05-12 03:30 6872392 ----a-w- c:\windows\system32\nvcpl.dll
                2015-05-19 19:49 . 2015-04-03 13:21 52880 ----a-w- c:\windows\system32\nvaudcap64v.dll
                .
                .
                .
                ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
                .
                2015-06-11 19:51 . 2014-09-13 20:49 136408 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
                2015-06-10 01:03 . 2013-04-06 14:43 140135120 ----a-w- c:\windows\system32\MRT.exe
                2015-05-25 18:01 . 2015-06-09 18:47 44032 ----a-w- c:\windows\apppatch\acwow64.dll
                2015-05-17 13:26 . 2013-05-02 10:17 778416 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
                2015-05-17 13:26 . 2013-05-02 10:17 142512 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
                2015-05-07 11:50 . 2015-05-07 11:50 378336 ----a-w- c:\windows\system32\drivers\avgloga.sys
                2015-05-07 11:49 . 2015-05-07 11:49 253920 ----a-w- c:\windows\system32\drivers\avgidsha.sys
                2015-05-07 11:49 . 2015-05-07 11:49 220128 ----a-w- c:\windows\system32\drivers\avgmfx64.sys
                2015-05-04 12:14 . 2015-05-04 12:14 291296 ----a-w- c:\windows\system32\drivers\avgtdia.sys
                2015-05-01 13:17 . 2015-05-12 21:14 124112 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
                2015-05-01 13:16 . 2015-05-12 21:14 102608 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
                2015-04-27 11:19 . 2015-04-27 11:19 284128 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys
                2015-04-20 03:17 . 2015-05-12 19:39 1179136 ----a-w- c:\windows\system32\FntCache.dll
                2015-04-20 03:17 . 2015-05-12 19:39 1647104 ----a-w- c:\windows\system32\DWrite.dll
                2015-04-20 02:56 . 2015-05-12 19:39 1250816 ----a-w- c:\windows\SysWow64\DWrite.dll
                2015-04-18 03:10 . 2015-05-12 19:40 460800 ----a-w- c:\windows\system32\certcli.dll
                2015-04-18 02:56 . 2015-05-12 19:40 342016 ----a-w- c:\windows\SysWow64\certcli.dll
                2015-04-15 11:06 . 2015-04-15 11:06 256992 ----a-w- c:\windows\system32\drivers\avgldx64.sys
                2015-04-14 07:37 . 2014-09-13 20:49 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
                2015-04-14 07:37 . 2014-09-13 20:49 107736 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
                2015-04-14 07:37 . 2014-09-13 20:49 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
                2015-04-14 01:38 . 2015-04-14 01:38 1217192 ----a-w- c:\windows\SysWow64\FM20.DLL
                2015-04-13 03:28 . 2015-05-12 19:40 328704 ----a-w- c:\windows\system32\services.exe
                2015-04-08 03:29 . 2015-05-12 19:39 275456 ----a-w- c:\windows\system32\InkEd.dll
                2015-04-08 03:29 . 2015-05-12 19:39 24576 ----a-w- c:\windows\system32\jnwmon.dll
                2015-04-08 03:14 . 2015-05-12 19:39 216064 ----a-w- c:\windows\SysWow64\InkEd.dll
                2015-03-25 03:24 . 2015-04-14 18:44 3298816 ----a-w- c:\windows\system32\wucltux.dll
                2015-03-25 03:24 . 2015-04-14 18:44 98304 ----a-w- c:\windows\system32\wudriver.dll
                2015-03-25 03:24 . 2015-04-14 18:44 37376 ----a-w- c:\windows\system32\wups2.dll
                2015-03-25 03:24 . 2015-04-14 18:44 35328 ----a-w- c:\windows\system32\wups.dll
                2015-03-25 03:24 . 2015-04-14 18:44 2553856 ----a-w- c:\windows\system32\wuaueng.dll
                2015-03-25 03:24 . 2015-04-14 18:44 191488 ----a-w- c:\windows\system32\wuwebv.dll
                2015-03-25 03:24 . 2015-04-14 18:44 696320 ----a-w- c:\windows\system32\wuapi.dll
                2015-03-25 03:24 . 2015-04-14 18:44 60416 ----a-w- c:\windows\system32\WinSetupUI.dll
                2015-03-25 03:23 . 2015-04-14 18:44 12288 ----a-w- c:\windows\system32\wu.upgrade.ps.dll
                2015-03-25 03:23 . 2015-04-14 18:44 36864 ----a-w- c:\windows\system32\wuapp.exe
                2015-03-25 03:23 . 2015-04-14 18:44 135168 ----a-w- c:\windows\system32\wuauclt.exe
                2015-03-25 03:00 . 2015-04-14 18:44 92672 ----a-w- c:\windows\SysWow64\wudriver.dll
                2015-03-25 03:00 . 2015-04-14 18:44 566784 ----a-w- c:\windows\SysWow64\wuapi.dll
                2015-03-25 03:00 . 2015-04-14 18:44 29696 ----a-w- c:\windows\SysWow64\wups.dll
                2015-03-25 03:00 . 2015-04-14 18:44 173056 ----a-w- c:\windows\SysWow64\wuwebv.dll
                2015-03-25 03:00 . 2015-04-14 18:44 33792 ----a-w- c:\windows\SysWow64\wuapp.exe
                2015-03-20 10:18 . 2015-03-20 10:18 40928 ----a-w- c:\windows\system32\drivers\avgrkx64.sys
                2013-10-12 22:10 . 2013-11-14 15:26 224 ----a-w- c:\program files (x86)\update-FIFA14.bat
                .
                .
                ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
                REGEDIT4
                .
                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "Akamai NetSession Interface"="c:\users\RamonXP\AppData\Local\Akamai\netsession_win.exe" [2014-10-29 4673432]
                "Pando Media Booster"="c:\program files (x86)\Pando Networks\Media Booster\PMB.exe" [2013-10-04 4287536]
                "Xvid"="c:\program files (x86)\Xvid\CheckUpdate.exe" [2011-01-17 8192]
                "Ubjjmedia"="c:\users\RamonXP\AppData\Local\Ubjjmedia\Ggzinf32.dll" [2015-06-07 74752]
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
                "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-04-27 113288]
                "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696]
                "Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2010-08-20 487562]
                "RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-09-04 240112]
                "Desktop Disc Tool"="c:\program files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-09-03 518640]
                "AVG_UI"="c:\program files (x86)\AVG\AVG2015\avgui.exe" [2015-05-18 3745744]
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
                "Launcher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe" [2010-08-12 163040]
                .
                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                "ConsentPromptBehaviorAdmin"= 5 (0x5)
                "ConsentPromptBehaviorUser"= 3 (0x3)
                "EnableUIADesktopToggle"= 0 (0x0)
                .
                [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
                "LoadAppInit_DLLs"=1 (0x1)
                "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
                .
                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
                @=""
                .
                R2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2015\avgidsagent.exe;c:\program files (x86)\AVG\AVG2015\avgidsagent.exe [x]
                R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET \Framework64\v4.0.30319\mscorsvw.exe [x]
                R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
                R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [x]
                R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
                R3 Generalusbserialser20679;Legacy Serial Communication 20679;c:\windows\system32\DRIVERS\CT_U_USBSER.sys;c:\windows\SYSNATIVE\DRIVERS\CT_U_USBSER.sys [x]
                R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
                R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
                R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\ drivers\mwac.sys [x]
                R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
                R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominipor t.sys [x]
                R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [x]
                R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
                R3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x]
                R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
                S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsha.sys [x]
                S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys;c:\windows\SYSNATIVE\DRIVERS\avgloga.sys [x]
                S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgmfx64.sys [x]
                S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgrkx64.sys [x]
                S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
                S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
                S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys;c:\windows\SYSNATIVE\DRIVERS\stdcfltn.sys [x]
                S1 Avgdiska;AVG Disk Driver;c:\windows\system32\DRIVERS\avgdiska.sys;c:\windows\SYSNATIVE\DRIVERS\avgdiska.sys [x]
                S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys;c:\windows\SYSNATIVE\DRIVERS \avgidsdrivera.sys [x]
                S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgldx64.sys [x]
                S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys;c:\windows\SYSNATIVE\DRIVERS\avgtdia.sys [x]
                S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
                S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [x]
                S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2015\avgwdsvc.exe;c:\program files (x86)\AVG\AVG2015\avgwdsvc.exe [x]
                S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
                S2 FoxitCloudUpdateService;Foxit Cloud Safe Update Service;c:\program files (x86)\FOXIT SOFTWARE\FOXIT READER\Foxit Cloud\FCUpdateService.exe;c:\program files (x86)\FOXIT SOFTWARE\FOXIT READER\Foxit Cloud\FCUpdateService.exe [x]
                S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [x]
                S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
                S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
                S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
                S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [x]
                S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
                S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x]
                S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
                S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys;c:\windows\SYSNATIVE\DRIVERS\Accelern.sys [x]
                S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys;c:\windows\SYSNATIVE\DRIVERS\CtClsFlt.sys [x]
                S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
                S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x]
                S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
                S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.s ys [x]
                S3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series adapter stuurprogramma onder Windows 7 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys;c:\windows\SYSNATIVE\DRIVERS\NETw5s64.sys [x]
                S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
                S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
                S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
                S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
                S3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys;c:\windows\SYSNATIVE\DRIVERS\qicflt.sys [x]
                S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
                .
                .
                [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
                2015-06-10 06:13 986440 ----a-w- c:\program files (x86)\Google\Chrome\Application\43.0.2357.124\Installer\chrmstp.exe
                .
                Inhoud van de 'Gedeelde Taken' map
                .
                2015-05-04 c:\windows\Tasks\0415avUpdateInfo.job
                - c:\programdata\Avg_Update_0415av\0415av_AVG-Secure-Search-Update.exe [2015-05-04 08:32]
                .
                2015-06-12 c:\windows\Tasks\Adobe Flash Player Updater.job
                - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-02 13:26]
                .
                2015-06-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-04-06 12:46]
                .
                2015-06-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-04-06 12:46]
                .
                .
                --------- X64 Entries -----------
                .
                .
                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"D ropboxExt1"]
                @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
                [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
                2015-02-03 19:01 185824 ---ha-w- c:\users\RamonXP\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
                .
                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"D ropboxExt2"]
                @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
                [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
                2015-02-03 19:01 185824 ---ha-w- c:\users\RamonXP\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
                .
                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"D ropboxExt3"]
                @="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
                [HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
                2015-02-03 19:01 185824 ---ha-w- c:\users\RamonXP\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
                .
                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"D ropboxExt4"]
                @="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
                [HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
                2015-02-03 19:01 185824 ---ha-w- c:\users\RamonXP\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
                .
                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"D ropboxExt5"]
                @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
                [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
                2015-02-03 19:01 185824 ---ha-w- c:\users\RamonXP\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
                .
                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"D ropboxExt6"]
                @="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
                [HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
                2015-02-03 19:01 185824 ---ha-w- c:\users\RamonXP\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
                .
                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"D ropboxExt7"]
                @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
                [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
                2015-02-03 19:01 185824 ---ha-w- c:\users\RamonXP\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
                .
                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"D ropboxExt8"]
                @="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
                [HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
                2015-02-03 19:01 185824 ---ha-w- c:\users\RamonXP\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-09-03 161304]
                "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-09-03 386584]
                "Persistence"="c:\windows\system32\igfxpers.exe" [2010-09-03 415256]
                "IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-03-05 1928976]
                "FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-09-24 727664]
                "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-02-18 6611048]
                "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-01-18 2188904]
                "NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2015-05-23 2754704]
                "ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2015-05-23 1571696]
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                "AppInit_DLLs"=c:\windows\System32\nvinitx.dll
                .
                ------- Bijkomende Scan -------
                .
                uLocal Page = c:\windows\system32\blank.htm
                mLocal Page = c:\windows\SysWOW64\blank.htm
                uInternet Settings,ProxyOverride = <local>
                IE: &Verzenden naar OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
                IE: E&xporteren naar Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
                TCP: DhcpNameServer = 62.179.104.196 213.46.228.196
                .
                - - - - ORPHANS VERWIJDERD - - - -
                .
                Toolbar-Locked - (no file)
                Wow6432Node-HKLM-Run-<NO NAME> - (no file)
                Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe
                c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe /firstrun
                HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
                Toolbar-Locked - (no file)
                ShellIconOverlayIdentifiers-{3B5B973C-92A4-4855-9D3F-0F3D23332208} - (no file)
                HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
                AddRemove-{C73A3942-84C8-4597-9F9B-EE227DCBA758} - c:\programdata\{04A07C23-5821-4F25-BF46-1188636AE238}\delldock.exe
                .
                .
                .
                --------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
                @Denied: (A 2) (Everyone)
                @="FlashBroker"
                "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_188_ActiveX.exe,-101"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
                "Enabled"=dword:00000001
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
                @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_188_ActiveX.exe"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
                @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
                @Denied: (A 2) (Everyone)
                @="IFlashBroker6"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
                @="{00020424-0000-0000-C000-000000000046}"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
                @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                "Version"="1.0"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
                @Denied: (A 2) (Everyone)
                @="FlashBroker"
                "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_17_0_0_188_ActiveX.exe,-101"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
                "Enabled"=dword:00000001
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
                @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_17_0_0_188_ActiveX.exe"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
                @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
                @Denied: (A 2) (Everyone)
                @="Shockwave Flash Object"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
                @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx"
                "ThreadingModel"="Apartment"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
                @="0"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
                @="ShockwaveFlash.ShockwaveFlash.17"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
                @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx, 1"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
                @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
                @="1.0"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
                @="ShockwaveFlash.ShockwaveFlash"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
                @Denied: (A 2) (Everyone)
                @="Macromedia Flash Factory Object"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
                @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx"
                "ThreadingModel"="Apartment"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
                @="FlashFactory.FlashFactory.1"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
                @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx, 1"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
                @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
                @="1.0"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
                @="FlashFactory.FlashFactory"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
                @Denied: (A 2) (Everyone)
                @="IFlashBroker6"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
                @="{00020424-0000-0000-C000-000000000046}"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
                @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                "Version"="1.0"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
                "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
                00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
                @Denied: (A) (Everyone)
                "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
                @Denied: (A) (Everyone)
                .
                [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
                "Key"="ActionsPane3"
                "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
                .
                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
                @Denied: (Full) (Everyone)
                .
                Voltooingstijd: 2015-06-12 08:15:23
                ComboFix-quarantined-files.txt 2015-06-12 06:15
                .
                Pre-Run: 114.702.925.824 bytes beschikbaar
                Post-Run: 114.160.132.096 bytes beschikbaar
                .
                - - End Of File - - AF521ED866E91E81ABA07B294879BE3F

                Comment


                • #9
                  Geef je verborgen bestanden en mappen weer.

                  Ga naar Virus Total en upload de volgende file:

                  c:\users\RamonXP\AppData\Local\Ubjjmedia\Ggzinf32.dll

                  Druk op verzenden en wacht tot de resultaten verschijnen.
                  Indien het bestand reeds gescant is, laat je deze heranalyseren.(Je klikt dan op Re Analyse)

                  Uit het rapport, koppieer je het volgende:

                  KLIK HIER voor een vergroting! 
                  .
                  Plaats ook even de link naar dat rapport.
                  Malware Research [email protected] (MBAM) ..... ASAP & Unite Member
                  E Dev * McAfee verwijderen. * Ccleaner * E-Peek

                  Comment


                  • #10
                    SHA256: 810fb2f7f786758910e570491756e90938dc8b2243de83e78ebddc99686c676e
                    Bestandsnaam: Ggzinf32.dll
                    Detectieverhouding: 8 / 56
                    Datum van analyse: 2015-06-13 06:09:55 UTC (1 minuut geleden)


                    https://www.virustotal.com/nl/file/8...is/1434175795/

                    Comment


                    • #11
                      We gaan deze file even nader onderzoek. Combofix zal een messagebox tonen om deze file te uploaden.
                      Sta dit aub toe.

                      Schakel je beveiligingssoftware uit.

                      Note: Dit script is speciaal bedoeld voor deze PC,
                      gebruik dit dan ook niet op andere PC's met een gelijkwaardig probleem.


                      Open een kladblokbestand.
                      Kopieer het onderstaande en plak dit in het kladblokbestand.
                      Sla het kladblokbestand op als CFScript.txt
                      Code:
                      KillAll::
                      ClearJavaCache::
                      Suspect::
                      c:\users\RamonXP\AppData\Local\Ubjjmedia\Ggzinf32.dll
                      Sleep nu het bestand CFScript.txt in het bestand ComboFix.exe



                      ComboFix zal opnieuw starten.
                      Als Combofix vraagt om een update, dan staat je dit toe.

                      Wanneer ComboFix klaar is, dit kan na een herstart zijn, opent er een logfile.
                      Post de inhoud van de logfile.
                      Malware Research [email protected] (MBAM) ..... ASAP & Unite Member
                      E Dev * McAfee verwijderen. * Ccleaner * E-Peek

                      Comment


                      • #12
                        Na afloop gaf Combofix aan de resultaten te willen oploaden. uiteindelijk is dit niet gelukt omdat de server onbereikbaar was. Is het de bedoeling dat ik die later probeer manueel te uploaden?

                        Hierbij de logfile:

                        ComboFix 15-06-09.01 - RamonXP 13-06-2015 14:45:38.2.4 - x64
                        Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1043.18.3828.2692 [GMT 2:00]
                        Gestart vanuit: c:\users\RamonXP\Desktop\antivirus\ComboFix.exe
                        gebruikte Opdracht switches :: c:\users\RamonXP\Desktop\antivirus\CFScript.txt
                        AV: AVG AntiVirus Free Edition 2015 *Disabled/Updated* {4D41356F-32AD-7C42-C820-63775EE4F413}
                        SP: AVG AntiVirus Free Edition 2015 *Disabled/Updated* {F620D48B-1497-73CC-F290-58052563BEAE}
                        SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
                        .
                        .
                        .
                        (((((((((((((((((((( Bestanden Gemaakt van 2015-05-13 to 2015-06-13 ))))))))))))))))))))))))))))))
                        .
                        .
                        2015-06-10 06:05 . 2015-06-11 19:30 -------- d-----w- C:\AdwCleaner
                        2015-06-09 18:46 . 2015-04-24 18:17 633856 ----a-w- c:\windows\system32\comctl32.dll
                        2015-06-09 18:45 . 2015-05-22 17:50 2426880 ----a-w- c:\windows\system32\wininet.dll
                        2015-06-09 18:45 . 2015-05-22 19:22 950784 ----a-w- c:\program files\Internet Explorer\iedvtool.dll
                        2015-06-09 18:45 . 2015-05-22 19:00 417792 ----a-w- c:\windows\system32\html.iec
                        2015-06-09 18:45 . 2015-05-22 18:59 88064 ----a-w- c:\windows\system32\MshtmlDac.dll
                        2015-06-09 18:45 . 2015-05-22 18:25 199680 ----a-w- c:\windows\system32\msrating.dll
                        2015-06-09 18:45 . 2015-05-22 17:31 382976 ----a-w- c:\program files\Internet Explorer\IEShims.dll
                        2015-06-09 18:45 . 2015-06-01 19:16 293072 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
                        2015-06-09 18:45 . 2015-05-27 14:35 24917504 ----a-w- c:\windows\system32\mshtml.dll
                        2015-06-09 18:45 . 2015-05-22 18:24 1016832 ----a-w- c:\program files\Common Files\Microsoft Shared\VGX\VGX.dll
                        2015-06-09 18:45 . 2015-05-22 19:12 10949120 ----a-w- c:\program files\Internet Explorer\F12Resources.dll
                        2015-06-09 18:36 . 2015-06-09 18:37 -------- d-----w- c:\users\RamonXP\AppData\Roaming\ChromeUpdate
                        2015-06-07 17:56 . 2015-06-07 17:56 -------- d-----w- c:\users\RamonXP\AppData\Local\Ubjjmedia
                        2015-06-07 17:55 . 2015-06-09 18:21 -------- d-----w- c:\users\RamonXP\AppData\Local\Epqtion
                        2015-06-02 07:22 . 2015-06-13 11:51 -------- d-----w- c:\program files (x86)\Heroes of the Storm
                        2015-06-02 06:49 . 2015-06-02 06:49 -------- d-----w- c:\users\RamonXP\AppData\Local\GWX
                        2015-05-30 09:39 . 2015-05-30 09:39 -------- d-----w- c:\program files (x86)\Microsoft ASP.NET
                        2015-05-29 11:16 . 2015-05-29 11:16 -------- d-----w- c:\programdata\boost_interprocess
                        2015-05-29 11:16 . 2015-04-03 13:21 48784 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
                        2015-05-29 11:16 . 2015-04-03 13:21 38032 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
                        2015-05-22 17:16 . 2015-05-22 17:16 18652352 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\MSO.DLL
                        2015-05-20 17:08 . 2015-05-20 17:08 -------- d-----w- c:\users\RamonXP\AppData\Local\Avg
                        2015-05-20 17:00 . 2015-05-20 17:00 -------- d-----w- c:\windows\SysWow64\NV
                        2015-05-20 17:00 . 2015-05-20 17:00 -------- d-----w- c:\windows\system32\NV
                        2015-05-19 20:56 . 2015-05-29 11:17 -------- d-----w- c:\users\RamonXP\AppData\Local\NVIDIA Corporation
                        2015-05-19 20:55 . 2015-05-29 11:17 -------- d-----w- c:\users\RamonXP\AppData\Local\NVIDIA
                        2015-05-19 20:05 . 2015-05-23 01:47 1756424 ----a-w- c:\windows\system32\nvspbridge64.dll
                        2015-05-19 20:05 . 2015-05-23 01:47 1571696 ----a-w- c:\windows\system32\nvspcap64.dll
                        2015-05-19 20:05 . 2015-05-23 01:47 1316000 ----a-w- c:\windows\SysWow64\nvspbridge.dll
                        2015-05-19 20:05 . 2015-05-23 01:47 1320304 ----a-w- c:\windows\SysWow64\nvspcap.dll
                        2015-05-19 20:04 . 2015-06-13 12:56 -------- d-----w- c:\programdata\NVIDIA
                        2015-05-19 20:04 . 2015-05-12 02:34 571024 ----a-w- c:\windows\SysWow64\nvStreaming.exe
                        2015-05-19 20:03 . 2015-05-12 03:30 937288 ----a-w- c:\windows\system32\nvvsvc.exe
                        2015-05-19 20:03 . 2015-05-12 03:30 75080 ----a-w- c:\windows\system32\nv3dappshextr.dll
                        2015-05-19 20:03 . 2015-05-12 03:30 62608 ----a-w- c:\windows\system32\nvshext.dll
                        2015-05-19 20:03 . 2015-05-12 03:30 1059984 ----a-w- c:\windows\system32\nv3dappshext.dll
                        2015-05-19 20:03 . 2015-05-12 03:30 3490448 ----a-w- c:\windows\system32\nvsvc64.dll
                        2015-05-19 20:03 . 2015-05-12 03:30 2558608 ----a-w- c:\windows\system32\nvsvcr.dll
                        2015-05-19 20:03 . 2015-05-11 17:01 4391871 ----a-w- c:\windows\system32\nvcoproc.bin
                        2015-05-19 20:03 . 2015-05-12 03:30 385352 ----a-w- c:\windows\system32\nvmctray.dll
                        2015-05-19 20:03 . 2015-05-12 03:30 6872392 ----a-w- c:\windows\system32\nvcpl.dll
                        2015-05-19 19:49 . 2015-04-03 13:21 52880 ----a-w- c:\windows\system32\nvaudcap64v.dll
                        .
                        .
                        .
                        ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        2015-06-11 19:51 . 2014-09-13 20:49 136408 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
                        2015-06-10 01:03 . 2013-04-06 14:43 140135120 ----a-w- c:\windows\system32\MRT.exe
                        2015-05-25 18:01 . 2015-06-09 18:47 44032 ----a-w- c:\windows\apppatch\acwow64.dll
                        2015-05-17 13:26 . 2013-05-02 10:17 778416 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
                        2015-05-17 13:26 . 2013-05-02 10:17 142512 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
                        2015-05-07 11:50 . 2015-05-07 11:50 378336 ----a-w- c:\windows\system32\drivers\avgloga.sys
                        2015-05-07 11:49 . 2015-05-07 11:49 253920 ----a-w- c:\windows\system32\drivers\avgidsha.sys
                        2015-05-07 11:49 . 2015-05-07 11:49 220128 ----a-w- c:\windows\system32\drivers\avgmfx64.sys
                        2015-05-04 12:14 . 2015-05-04 12:14 291296 ----a-w- c:\windows\system32\drivers\avgtdia.sys
                        2015-05-01 13:17 . 2015-05-12 21:14 124112 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
                        2015-05-01 13:16 . 2015-05-12 21:14 102608 ----a-w- c:\windows\SysWow64\PresentationCFFRasterizerNative_v0300.dll
                        2015-04-27 11:19 . 2015-04-27 11:19 284128 ----a-w- c:\windows\system32\drivers\avgidsdrivera.sys
                        2015-04-20 03:17 . 2015-05-12 19:39 1179136 ----a-w- c:\windows\system32\FntCache.dll
                        2015-04-20 03:17 . 2015-05-12 19:39 1647104 ----a-w- c:\windows\system32\DWrite.dll
                        2015-04-20 02:56 . 2015-05-12 19:39 1250816 ----a-w- c:\windows\SysWow64\DWrite.dll
                        2015-04-18 03:10 . 2015-05-12 19:40 460800 ----a-w- c:\windows\system32\certcli.dll
                        2015-04-18 02:56 . 2015-05-12 19:40 342016 ----a-w- c:\windows\SysWow64\certcli.dll
                        2015-04-15 11:06 . 2015-04-15 11:06 256992 ----a-w- c:\windows\system32\drivers\avgldx64.sys
                        2015-04-14 07:37 . 2014-09-13 20:49 63704 ----a-w- c:\windows\system32\drivers\mwac.sys
                        2015-04-14 07:37 . 2014-09-13 20:49 107736 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
                        2015-04-14 07:37 . 2014-09-13 20:49 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
                        2015-04-14 01:38 . 2015-04-14 01:38 1217192 ----a-w- c:\windows\SysWow64\FM20.DLL
                        2015-04-13 03:28 . 2015-05-12 19:40 328704 ----a-w- c:\windows\system32\services.exe
                        2015-04-08 03:29 . 2015-05-12 19:39 275456 ----a-w- c:\windows\system32\InkEd.dll
                        2015-04-08 03:29 . 2015-05-12 19:39 24576 ----a-w- c:\windows\system32\jnwmon.dll
                        2015-04-08 03:14 . 2015-05-12 19:39 216064 ----a-w- c:\windows\SysWow64\InkEd.dll
                        2015-03-25 03:24 . 2015-04-14 18:44 3298816 ----a-w- c:\windows\system32\wucltux.dll
                        2015-03-25 03:24 . 2015-04-14 18:44 98304 ----a-w- c:\windows\system32\wudriver.dll
                        2015-03-25 03:24 . 2015-04-14 18:44 37376 ----a-w- c:\windows\system32\wups2.dll
                        2015-03-25 03:24 . 2015-04-14 18:44 35328 ----a-w- c:\windows\system32\wups.dll
                        2015-03-25 03:24 . 2015-04-14 18:44 2553856 ----a-w- c:\windows\system32\wuaueng.dll
                        2015-03-25 03:24 . 2015-04-14 18:44 191488 ----a-w- c:\windows\system32\wuwebv.dll
                        2015-03-25 03:24 . 2015-04-14 18:44 696320 ----a-w- c:\windows\system32\wuapi.dll
                        2015-03-25 03:24 . 2015-04-14 18:44 60416 ----a-w- c:\windows\system32\WinSetupUI.dll
                        2015-03-25 03:23 . 2015-04-14 18:44 12288 ----a-w- c:\windows\system32\wu.upgrade.ps.dll
                        2015-03-25 03:23 . 2015-04-14 18:44 36864 ----a-w- c:\windows\system32\wuapp.exe
                        2015-03-25 03:23 . 2015-04-14 18:44 135168 ----a-w- c:\windows\system32\wuauclt.exe
                        2015-03-25 03:00 . 2015-04-14 18:44 92672 ----a-w- c:\windows\SysWow64\wudriver.dll
                        2015-03-25 03:00 . 2015-04-14 18:44 566784 ----a-w- c:\windows\SysWow64\wuapi.dll
                        2015-03-25 03:00 . 2015-04-14 18:44 29696 ----a-w- c:\windows\SysWow64\wups.dll
                        2015-03-25 03:00 . 2015-04-14 18:44 173056 ----a-w- c:\windows\SysWow64\wuwebv.dll
                        2015-03-25 03:00 . 2015-04-14 18:44 33792 ----a-w- c:\windows\SysWow64\wuapp.exe
                        2015-03-20 10:18 . 2015-03-20 10:18 40928 ----a-w- c:\windows\system32\drivers\avgrkx64.sys
                        2013-10-12 22:10 . 2013-11-14 15:26 224 ----a-w- c:\program files (x86)\update-FIFA14.bat
                        .
                        .
                        ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        .
                        *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
                        REGEDIT4
                        .
                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "Akamai NetSession Interface"="c:\users\RamonXP\AppData\Local\Akamai\netsession_win.exe" [2014-10-29 4673432]
                        "Pando Media Booster"="c:\program files (x86)\Pando Networks\Media Booster\PMB.exe" [2013-10-04 4287536]
                        "Xvid"="c:\program files (x86)\Xvid\CheckUpdate.exe" [2011-01-17 8192]
                        "Ubjjmedia"="c:\users\RamonXP\AppData\Local\Ubjjmedia\Ggzinf32.dll" [2015-06-07 74752]
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
                        "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-04-27 113288]
                        "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-03-04 284696]
                        "Dell Webcam Central"="c:\program files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe" [2010-08-20 487562]
                        "RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [2010-09-04 240112]
                        "Desktop Disc Tool"="c:\program files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [2010-09-03 518640]
                        "AVG_UI"="c:\program files (x86)\AVG\AVG2015\avgui.exe" [2015-05-18 3745744]
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
                        "Launcher"="c:\program files (x86)\Dell DataSafe Local Backup\Components\Scheduler\Launcher.exe" [2010-08-12 163040]
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                        "ConsentPromptBehaviorAdmin"= 5 (0x5)
                        "ConsentPromptBehaviorUser"= 3 (0x3)
                        "EnableUIADesktopToggle"= 0 (0x0)
                        .
                        [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
                        "LoadAppInit_DLLs"=1 (0x1)
                        "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll c:\windows\SysWOW64\nvinit.dll c:\windows\SysWOW64\nvinit.dll
                        .
                        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
                        @=""
                        .
                        R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET \Framework64\v4.0.30319\mscorsvw.exe [x]
                        R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
                        R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe [x]
                        R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
                        R3 Generalusbserialser20679;Legacy Serial Communication 20679;c:\windows\system32\DRIVERS\CT_U_USBSER.sys;c:\windows\SYSNATIVE\DRIVERS\CT_U_USBSER.sys [x]
                        R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
                        R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x]
                        R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\ drivers\mwac.sys [x]
                        R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
                        R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominipor t.sys [x]
                        R3 RoxMediaDB12OEM;RoxMediaDB12OEM;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe;c:\program files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe [x]
                        R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
                        R3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x]
                        R3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
                        S0 AVGIDSHA;AVGIDSHA;c:\windows\system32\DRIVERS\avgidsha.sys;c:\windows\SYSNATIVE\DRIVERS\avgidsha.sys [x]
                        S0 Avgloga;AVG Logging Driver;c:\windows\system32\DRIVERS\avgloga.sys;c:\windows\SYSNATIVE\DRIVERS\avgloga.sys [x]
                        S0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\DRIVERS\avgmfx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgmfx64.sys [x]
                        S0 Avgrkx64;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgrkx64.sys [x]
                        S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
                        S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys;c:\windows\SYSNATIVE\Drivers\PxHlpa64.sys [x]
                        S0 stdcfltn;Disk Class Filter Driver for Accelerometer;c:\windows\system32\DRIVERS\stdcfltn.sys;c:\windows\SYSNATIVE\DRIVERS\stdcfltn.sys [x]
                        S1 Avgdiska;AVG Disk Driver;c:\windows\system32\DRIVERS\avgdiska.sys;c:\windows\SYSNATIVE\DRIVERS\avgdiska.sys [x]
                        S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdrivera.sys;c:\windows\SYSNATIVE\DRIVERS \avgidsdrivera.sys [x]
                        S1 Avgldx64;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx64.sys;c:\windows\SYSNATIVE\DRIVERS\avgldx64.sys [x]
                        S1 Avgtdia;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdia.sys;c:\windows\SYSNATIVE\DRIVERS\avgtdia.sys [x]
                        S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
                        S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSr64.exe;c:\program files\Realtek\Audio\HDA\AERTSr64.exe [x]
                        S2 AVGIDSAgent;AVGIDSAgent;c:\program files (x86)\AVG\AVG2015\avgidsagent.exe;c:\program files (x86)\AVG\AVG2015\avgidsagent.exe [x]
                        S2 avgwd;AVG WatchDog;c:\program files (x86)\AVG\AVG2015\avgwdsvc.exe;c:\program files (x86)\AVG\AVG2015\avgwdsvc.exe [x]
                        S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
                        S2 FoxitCloudUpdateService;Foxit Cloud Safe Update Service;c:\program files (x86)\FOXIT SOFTWARE\FOXIT READER\Foxit Cloud\FCUpdateService.exe;c:\program files (x86)\FOXIT SOFTWARE\FOXIT READER\Foxit Cloud\FCUpdateService.exe [x]
                        S2 GfExperienceService;NVIDIA GeForce Experience Service;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe;c:\program files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [x]
                        S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
                        S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
                        S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
                        S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [x]
                        S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
                        S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x]
                        S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
                        S3 Acceler;Accelerometer Service;c:\windows\system32\DRIVERS\Accelern.sys;c:\windows\SYSNATIVE\DRIVERS\Accelern.sys [x]
                        S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt.sys;c:\windows\SYSNATIVE\DRIVERS\CtClsFlt.sys [x]
                        S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
                        S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x]
                        S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
                        S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.s ys [x]
                        S3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series adapter stuurprogramma onder Windows 7 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys;c:\windows\SYSNATIVE\DRIVERS\NETw5s64.sys [x]
                        S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
                        S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
                        S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
                        S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
                        S3 qicflt;upper Device Filter Driver;c:\windows\system32\DRIVERS\qicflt.sys;c:\windows\SYSNATIVE\DRIVERS\qicflt.sys [x]
                        S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
                        .
                        .
                        [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
                        2015-06-10 06:13 986440 ----a-w- c:\program files (x86)\Google\Chrome\Application\43.0.2357.124\Installer\chrmstp.exe
                        .
                        Inhoud van de 'Gedeelde Taken' map
                        .
                        2015-05-04 c:\windows\Tasks\0415avUpdateInfo.job
                        - c:\programdata\Avg_Update_0415av\0415av_AVG-Secure-Search-Update.exe [2015-05-04 08:32]
                        .
                        2015-06-13 c:\windows\Tasks\Adobe Flash Player Updater.job
                        - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-02 13:26]
                        .
                        2015-06-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                        - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-04-06 12:46]
                        .
                        2015-06-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                        - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-04-06 12:46]
                        .
                        .
                        --------- X64 Entries -----------
                        .
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"D ropboxExt1"]
                        @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
                        [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
                        2015-02-03 19:01 185824 ----a-w- c:\users\RamonXP\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"D ropboxExt2"]
                        @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
                        [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
                        2015-02-03 19:01 185824 ----a-w- c:\users\RamonXP\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"D ropboxExt3"]
                        @="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
                        [HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
                        2015-02-03 19:01 185824 ----a-w- c:\users\RamonXP\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"D ropboxExt4"]
                        @="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
                        [HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
                        2015-02-03 19:01 185824 ----a-w- c:\users\RamonXP\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"D ropboxExt5"]
                        @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
                        [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
                        2015-02-03 19:01 185824 ----a-w- c:\users\RamonXP\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"D ropboxExt6"]
                        @="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
                        [HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
                        2015-02-03 19:01 185824 ----a-w- c:\users\RamonXP\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"D ropboxExt7"]
                        @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
                        [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
                        2015-02-03 19:01 185824 ----a-w- c:\users\RamonXP\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"D ropboxExt8"]
                        @="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
                        [HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
                        2015-02-03 19:01 185824 ----a-w- c:\users\RamonXP\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
                        "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-09-03 161304]
                        "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-09-03 386584]
                        "Persistence"="c:\windows\system32\igfxpers.exe" [2010-09-03 415256]
                        "IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-03-05 1928976]
                        "FreeFallProtection"="c:\program files (x86)\STMicroelectronics\AccelerometerP11\FF_Protection.exe" [2010-09-24 727664]
                        "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2011-02-18 6611048]
                        "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-01-18 2188904]
                        "NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2015-05-23 2754704]
                        "ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2015-05-23 1571696]
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                        "AppInit_DLLs"=c:\windows\System32\nvinitx.dll c:\windows\System32\nvinitx.dll
                        .
                        ------- Bijkomende Scan -------
                        .
                        uLocal Page = c:\windows\system32\blank.htm
                        mLocal Page = c:\windows\SysWOW64\blank.htm
                        uInternet Settings,ProxyOverride = <local>
                        IE: &Verzenden naar OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
                        IE: E&xporteren naar Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
                        TCP: DhcpNameServer = 212.54.40.25 212.54.44.54
                        .
                        - - - - ORPHANS VERWIJDERD - - - -
                        .
                        Toolbar-Locked - (no file)
                        Wow6432Node-HKLM-Run-<NO NAME> - (no file)
                        ShellIconOverlayIdentifiers-{3B5B973C-92A4-4855-9D3F-0F3D23332208} - (no file)
                        AddRemove-{C73A3942-84C8-4597-9F9B-EE227DCBA758} - c:\programdata\{04A07C23-5821-4F25-BF46-1188636AE238}\delldock.exe
                        .
                        .
                        .
                        --------------------- VERGRENDELDE REGISTER SLEUTELS ---------------------
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
                        @Denied: (A 2) (Everyone)
                        @="FlashBroker"
                        "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_188_ActiveX.exe,-101"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
                        "Enabled"=dword:00000001
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
                        @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_17_0_0_188_ActiveX.exe"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
                        @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
                        @Denied: (A 2) (Everyone)
                        @="IFlashBroker6"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
                        @="{00020424-0000-0000-C000-000000000046}"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
                        @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                        "Version"="1.0"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
                        @Denied: (A 2) (Everyone)
                        @="FlashBroker"
                        "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_17_0_0_188_ActiveX.exe,-101"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
                        "Enabled"=dword:00000001
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
                        @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_17_0_0_188_ActiveX.exe"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
                        @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
                        @Denied: (A 2) (Everyone)
                        @="Shockwave Flash Object"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
                        @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx"
                        "ThreadingModel"="Apartment"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
                        @="0"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
                        @="ShockwaveFlash.ShockwaveFlash.17"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
                        @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx, 1"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
                        @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
                        @="1.0"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
                        @="ShockwaveFlash.ShockwaveFlash"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
                        @Denied: (A 2) (Everyone)
                        @="Macromedia Flash Factory Object"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
                        @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx"
                        "ThreadingModel"="Apartment"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
                        @="FlashFactory.FlashFactory.1"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
                        @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_17_0_0_188.ocx, 1"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
                        @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
                        @="1.0"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
                        @="FlashFactory.FlashFactory"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
                        @Denied: (A 2) (Everyone)
                        @="IFlashBroker6"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
                        @="{00020424-0000-0000-C000-000000000046}"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
                        @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                        "Version"="1.0"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
                        "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
                        00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
                        @Denied: (A) (Everyone)
                        "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
                        @Denied: (A) (Everyone)
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
                        "Key"="ActionsPane3"
                        "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
                        .
                        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
                        @Denied: (Full) (Everyone)
                        .
                        ------------------------ Andere Aktieve Processen ------------------------
                        .
                        c:\program files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
                        c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
                        .
                        **************************************************************************
                        .
                        Voltooingstijd: 2015-06-13 15:04:27 - machine werd herstart
                        ComboFix-quarantined-files.txt 2015-06-13 13:04
                        ComboFix2.txt 2015-06-12 06:15
                        .
                        Pre-Run: 113.173.241.856 bytes beschikbaar
                        Post-Run: 112.857.219.072 bytes beschikbaar
                        .
                        - - End Of File - - C55DD0CC9B04FB2737A8D2663D93E594

                        Comment


                        • #13
                          Momentje aub.
                          Ik heb contact genomen met de CF Developer en wacht op antwoord.
                          Malware Research [email protected] (MBAM) ..... ASAP & Unite Member
                          E Dev * McAfee verwijderen. * Ccleaner * E-Peek

                          Comment


                          • #14
                            Open een kladblokbestand.
                            Kopieer onderstaande in dit kladblokbestand.

                            Code:
                            @ECHO OFF
                            DIR /s "c:\users\RamonXP\AppData\Local\Ubjjmedia" >log.txt
                            START NOTEPAD.EXE log.txt
                            DEL %0
                            Ga naar Bestand - Opslaan als.
                            Bij "Opslaan in" kies je: Bureaublad
                            Bij "Bestandsnaam" zet je: nucia.bat
                            Bij "Opslaan als type" selecteer je: Alle bestanden .
                            Klik op de knop Opslaan.
                            Rechtsklikken op del.bat en Uitvoeren als Administrator.
                            Post de inhoud van de logfile die opent.
                            Malware Research [email protected] (MBAM) ..... ASAP & Unite Member
                            E Dev * McAfee verwijderen. * Ccleaner * E-Peek

                            Comment


                            • #15
                              De volumenaam van station C is OS
                              Het volumenummer is 1292-C4F7

                              Map van c:\users\RamonXP\AppData\Local\Ubjjmedia

                              07-06-2015 19:56 <DIR> .
                              07-06-2015 19:56 <DIR> ..
                              07-06-2015 19:56 158.740 Ggzinf32.2
                              07-06-2015 19:56 74.752 Ggzinf32.dll
                              2 bestand(en) 233.492 bytes

                              Totaal aantal weergegeven bestanden:
                              2 bestand(en) 233.492 bytes
                              2 map(pen) 112.934.879.232 bytes beschikbaar

                              Comment

                              Sorry, you are not authorized to view this page
                              Working...
                              X