Schritt 3
gmer
Code:
Alles auswählen Aufklappen ATTFilter
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-07-07 15:31:54
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD3200BEKT-60V5T1 rev.12.01A12 298,09GB
Running: Gmer-19357.exe; Driver: C:\Users\Anwender\AppData\Local\Temp\awddqkow.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe[1780] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075fd1401 2 bytes JMP 7601b1ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe[1780] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075fd1419 2 bytes JMP 7601b31a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe[1780] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075fd1431 2 bytes JMP 76098f09 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe[1780] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075fd144a 2 bytes CALL 75ff4885 C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe[1780] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075fd14dd 2 bytes JMP 76098802 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe[1780] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075fd14f5 2 bytes JMP 760989d8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe[1780] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075fd150d 2 bytes JMP 760986f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe[1780] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075fd1525 2 bytes JMP 76098ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe[1780] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075fd153d 2 bytes JMP 7600fc78 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe[1780] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075fd1555 2 bytes JMP 760168bf C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe[1780] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075fd156d 2 bytes JMP 76098fc1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe[1780] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075fd1585 2 bytes JMP 76098b22 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe[1780] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075fd159d 2 bytes JMP 760986bc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe[1780] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075fd15b5 2 bytes JMP 7600fd11 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe[1780] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075fd15cd 2 bytes JMP 7601b2b0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe[1780] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075fd16b2 2 bytes JMP 76098e84 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe[1780] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075fd16bd 2 bytes JMP 76098651 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe[1896] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075fd1401 2 bytes JMP 7601b1ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe[1896] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075fd1419 2 bytes JMP 7601b31a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe[1896] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075fd1431 2 bytes JMP 76098f09 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe[1896] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075fd144a 2 bytes CALL 75ff4885 C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe[1896] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075fd14dd 2 bytes JMP 76098802 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe[1896] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075fd14f5 2 bytes JMP 760989d8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe[1896] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075fd150d 2 bytes JMP 760986f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe[1896] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075fd1525 2 bytes JMP 76098ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe[1896] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075fd153d 2 bytes JMP 7600fc78 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe[1896] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075fd1555 2 bytes JMP 760168bf C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe[1896] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075fd156d 2 bytes JMP 76098fc1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe[1896] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075fd1585 2 bytes JMP 76098b22 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe[1896] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075fd159d 2 bytes JMP 760986bc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe[1896] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075fd15b5 2 bytes JMP 7600fd11 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe[1896] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075fd15cd 2 bytes JMP 7601b2b0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe[1896] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075fd16b2 2 bytes JMP 76098e84 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe[1896] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075fd16bd 2 bytes JMP 76098651 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Infonaut_1.10.0.14\Service\insvc.exe[2132] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075fd1401 2 bytes JMP 7601b1ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Infonaut_1.10.0.14\Service\insvc.exe[2132] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075fd1419 2 bytes JMP 7601b31a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Infonaut_1.10.0.14\Service\insvc.exe[2132] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075fd1431 2 bytes JMP 76098f09 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Infonaut_1.10.0.14\Service\insvc.exe[2132] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075fd144a 2 bytes CALL 75ff4885 C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Infonaut_1.10.0.14\Service\insvc.exe[2132] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075fd14dd 2 bytes JMP 76098802 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Infonaut_1.10.0.14\Service\insvc.exe[2132] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075fd14f5 2 bytes JMP 760989d8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Infonaut_1.10.0.14\Service\insvc.exe[2132] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075fd150d 2 bytes JMP 760986f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Infonaut_1.10.0.14\Service\insvc.exe[2132] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075fd1525 2 bytes JMP 76098ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Infonaut_1.10.0.14\Service\insvc.exe[2132] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075fd153d 2 bytes JMP 7600fc78 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Infonaut_1.10.0.14\Service\insvc.exe[2132] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075fd1555 2 bytes JMP 760168bf C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Infonaut_1.10.0.14\Service\insvc.exe[2132] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075fd156d 2 bytes JMP 76098fc1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Infonaut_1.10.0.14\Service\insvc.exe[2132] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075fd1585 2 bytes JMP 76098b22 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Infonaut_1.10.0.14\Service\insvc.exe[2132] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075fd159d 2 bytes JMP 760986bc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Infonaut_1.10.0.14\Service\insvc.exe[2132] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075fd15b5 2 bytes JMP 7600fd11 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Infonaut_1.10.0.14\Service\insvc.exe[2132] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075fd15cd 2 bytes JMP 7601b2b0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Infonaut_1.10.0.14\Service\insvc.exe[2132] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075fd16b2 2 bytes JMP 76098e84 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Infonaut_1.10.0.14\Service\insvc.exe[2132] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075fd16bd 2 bytes JMP 76098651 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Local\DE8134D4-1430960677-4C1F-0500-E0CB4E29E6BA\snsr1319.tmp[2228] C:\Windows\syswow64\Psapi.dll!GetModuleFileNameExW + 17 0000000075fd1401 2 bytes JMP 7601b1ef C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Local\DE8134D4-1430960677-4C1F-0500-E0CB4E29E6BA\snsr1319.tmp[2228] C:\Windows\syswow64\Psapi.dll!EnumProcessModules + 17 0000000075fd1419 2 bytes JMP 7601b31a C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Local\DE8134D4-1430960677-4C1F-0500-E0CB4E29E6BA\snsr1319.tmp[2228] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 17 0000000075fd1431 2 bytes JMP 76098f09 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Local\DE8134D4-1430960677-4C1F-0500-E0CB4E29E6BA\snsr1319.tmp[2228] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 42 0000000075fd144a 2 bytes CALL 75ff4885 C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Users\Anwender\AppData\Local\DE8134D4-1430960677-4C1F-0500-E0CB4E29E6BA\snsr1319.tmp[2228] C:\Windows\syswow64\Psapi.dll!EnumDeviceDrivers + 17 0000000075fd14dd 2 bytes JMP 76098802 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Local\DE8134D4-1430960677-4C1F-0500-E0CB4E29E6BA\snsr1319.tmp[2228] C:\Windows\syswow64\Psapi.dll!GetDeviceDriverBaseNameA + 17 0000000075fd14f5 2 bytes JMP 760989d8 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Local\DE8134D4-1430960677-4C1F-0500-E0CB4E29E6BA\snsr1319.tmp[2228] C:\Windows\syswow64\Psapi.dll!QueryWorkingSetEx + 17 0000000075fd150d 2 bytes JMP 760986f8 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Local\DE8134D4-1430960677-4C1F-0500-E0CB4E29E6BA\snsr1319.tmp[2228] C:\Windows\syswow64\Psapi.dll!GetDeviceDriverBaseNameW + 17 0000000075fd1525 2 bytes JMP 76098ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Local\DE8134D4-1430960677-4C1F-0500-E0CB4E29E6BA\snsr1319.tmp[2228] C:\Windows\syswow64\Psapi.dll!GetModuleBaseNameW + 17 0000000075fd153d 2 bytes JMP 7600fc78 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Local\DE8134D4-1430960677-4C1F-0500-E0CB4E29E6BA\snsr1319.tmp[2228] C:\Windows\syswow64\Psapi.dll!EnumProcesses + 17 0000000075fd1555 2 bytes JMP 760168bf C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Local\DE8134D4-1430960677-4C1F-0500-E0CB4E29E6BA\snsr1319.tmp[2228] C:\Windows\syswow64\Psapi.dll!GetProcessMemoryInfo + 17 0000000075fd156d 2 bytes JMP 76098fc1 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Local\DE8134D4-1430960677-4C1F-0500-E0CB4E29E6BA\snsr1319.tmp[2228] C:\Windows\syswow64\Psapi.dll!GetPerformanceInfo + 17 0000000075fd1585 2 bytes JMP 76098b22 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Local\DE8134D4-1430960677-4C1F-0500-E0CB4E29E6BA\snsr1319.tmp[2228] C:\Windows\syswow64\Psapi.dll!QueryWorkingSet + 17 0000000075fd159d 2 bytes JMP 760986bc C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Local\DE8134D4-1430960677-4C1F-0500-E0CB4E29E6BA\snsr1319.tmp[2228] C:\Windows\syswow64\Psapi.dll!GetModuleBaseNameA + 17 0000000075fd15b5 2 bytes JMP 7600fd11 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Local\DE8134D4-1430960677-4C1F-0500-E0CB4E29E6BA\snsr1319.tmp[2228] C:\Windows\syswow64\Psapi.dll!GetModuleFileNameExA + 17 0000000075fd15cd 2 bytes JMP 7601b2b0 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Local\DE8134D4-1430960677-4C1F-0500-E0CB4E29E6BA\snsr1319.tmp[2228] C:\Windows\syswow64\Psapi.dll!GetProcessImageFileNameW + 20 0000000075fd16b2 2 bytes JMP 76098e84 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Local\DE8134D4-1430960677-4C1F-0500-E0CB4E29E6BA\snsr1319.tmp[2228] C:\Windows\syswow64\Psapi.dll!GetProcessImageFileNameW + 31 0000000075fd16bd 2 bytes JMP 76098651 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\nstEFC.tmp[2324] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075fd1401 2 bytes JMP 7601b1ef C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\nstEFC.tmp[2324] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075fd1419 2 bytes JMP 7601b31a C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\nstEFC.tmp[2324] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075fd1431 2 bytes JMP 76098f09 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\nstEFC.tmp[2324] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075fd144a 2 bytes CALL 75ff4885 C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\nstEFC.tmp[2324] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075fd14dd 2 bytes JMP 76098802 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\nstEFC.tmp[2324] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075fd14f5 2 bytes JMP 760989d8 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\nstEFC.tmp[2324] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075fd150d 2 bytes JMP 760986f8 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\nstEFC.tmp[2324] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075fd1525 2 bytes JMP 76098ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\nstEFC.tmp[2324] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075fd153d 2 bytes JMP 7600fc78 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\nstEFC.tmp[2324] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075fd1555 2 bytes JMP 760168bf C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\nstEFC.tmp[2324] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075fd156d 2 bytes JMP 76098fc1 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\nstEFC.tmp[2324] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075fd1585 2 bytes JMP 76098b22 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\nstEFC.tmp[2324] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075fd159d 2 bytes JMP 760986bc C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\nstEFC.tmp[2324] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075fd15b5 2 bytes JMP 7600fd11 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\nstEFC.tmp[2324] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075fd15cd 2 bytes JMP 7601b2b0 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\nstEFC.tmp[2324] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075fd16b2 2 bytes JMP 76098e84 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\nstEFC.tmp[2324] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075fd16bd 2 bytes JMP 76098651 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancerService.exe[2720] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075fd1401 2 bytes JMP 7601b1ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancerService.exe[2720] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075fd1419 2 bytes JMP 7601b31a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancerService.exe[2720] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075fd1431 2 bytes JMP 76098f09 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancerService.exe[2720] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075fd144a 2 bytes CALL 75ff4885 C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancerService.exe[2720] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075fd14dd 2 bytes JMP 76098802 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancerService.exe[2720] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075fd14f5 2 bytes JMP 760989d8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancerService.exe[2720] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075fd150d 2 bytes JMP 760986f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancerService.exe[2720] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075fd1525 2 bytes JMP 76098ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancerService.exe[2720] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075fd153d 2 bytes JMP 7600fc78 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancerService.exe[2720] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075fd1555 2 bytes JMP 760168bf C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancerService.exe[2720] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075fd156d 2 bytes JMP 76098fc1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancerService.exe[2720] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075fd1585 2 bytes JMP 76098b22 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancerService.exe[2720] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075fd159d 2 bytes JMP 760986bc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancerService.exe[2720] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075fd15b5 2 bytes JMP 7600fd11 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancerService.exe[2720] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075fd15cd 2 bytes JMP 7601b2b0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancerService.exe[2720] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075fd16b2 2 bytes JMP 76098e84 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancerService.exe[2720] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075fd16bd 2 bytes JMP 76098651 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\MaxComputerCleaner_v17.391\MaxComputerCleaner_Maintenance.exe[3384] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075fd1401 2 bytes JMP 7601b1ef C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\MaxComputerCleaner_v17.391\MaxComputerCleaner_Maintenance.exe[3384] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075fd1419 2 bytes JMP 7601b31a C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\MaxComputerCleaner_v17.391\MaxComputerCleaner_Maintenance.exe[3384] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075fd1431 2 bytes JMP 76098f09 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\MaxComputerCleaner_v17.391\MaxComputerCleaner_Maintenance.exe[3384] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075fd144a 2 bytes CALL 75ff4885 C:\Windows\syswow64\KERNEL32.dll
.text ... * 9
.text C:\Program Files (x86)\MaxComputerCleaner_v17.391\MaxComputerCleaner_Maintenance.exe[3384] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075fd14dd 2 bytes JMP 76098802 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\MaxComputerCleaner_v17.391\MaxComputerCleaner_Maintenance.exe[3384] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075fd14f5 2 bytes JMP 760989d8 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\MaxComputerCleaner_v17.391\MaxComputerCleaner_Maintenance.exe[3384] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075fd150d 2 bytes JMP 760986f8 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\MaxComputerCleaner_v17.391\MaxComputerCleaner_Maintenance.exe[3384] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075fd1525 2 bytes JMP 76098ac2 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\MaxComputerCleaner_v17.391\MaxComputerCleaner_Maintenance.exe[3384] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075fd153d 2 bytes JMP 7600fc78 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\MaxComputerCleaner_v17.391\MaxComputerCleaner_Maintenance.exe[3384] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075fd1555 2 bytes JMP 760168bf C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\MaxComputerCleaner_v17.391\MaxComputerCleaner_Maintenance.exe[3384] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075fd156d 2 bytes JMP 76098fc1 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\MaxComputerCleaner_v17.391\MaxComputerCleaner_Maintenance.exe[3384] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075fd1585 2 bytes JMP 76098b22 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\MaxComputerCleaner_v17.391\MaxComputerCleaner_Maintenance.exe[3384] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075fd159d 2 bytes JMP 760986bc C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\MaxComputerCleaner_v17.391\MaxComputerCleaner_Maintenance.exe[3384] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075fd15b5 2 bytes JMP 7600fd11 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\MaxComputerCleaner_v17.391\MaxComputerCleaner_Maintenance.exe[3384] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075fd15cd 2 bytes JMP 7601b2b0 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\MaxComputerCleaner_v17.391\MaxComputerCleaner_Maintenance.exe[3384] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075fd16b2 2 bytes JMP 76098e84 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\MaxComputerCleaner_v17.391\MaxComputerCleaner_Maintenance.exe[3384] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075fd16bd 2 bytes JMP 76098651 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe[3572] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075fd1401 2 bytes JMP 7601b1ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe[3572] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075fd1419 2 bytes JMP 7601b31a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe[3572] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075fd1431 2 bytes JMP 76098f09 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe[3572] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075fd144a 2 bytes CALL 75ff4885 C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe[3572] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075fd14dd 2 bytes JMP 76098802 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe[3572] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075fd14f5 2 bytes JMP 760989d8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe[3572] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075fd150d 2 bytes JMP 760986f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe[3572] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075fd1525 2 bytes JMP 76098ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe[3572] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075fd153d 2 bytes JMP 7600fc78 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe[3572] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075fd1555 2 bytes JMP 760168bf C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe[3572] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075fd156d 2 bytes JMP 76098fc1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe[3572] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075fd1585 2 bytes JMP 76098b22 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe[3572] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075fd159d 2 bytes JMP 760986bc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe[3572] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075fd15b5 2 bytes JMP 7600fd11 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe[3572] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075fd15cd 2 bytes JMP 7601b2b0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe[3572] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075fd16b2 2 bytes JMP 76098e84 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe[3572] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075fd16bd 2 bytes JMP 76098651 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[4200] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075fd1401 2 bytes JMP 7601b1ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[4200] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075fd1419 2 bytes JMP 7601b31a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[4200] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075fd1431 2 bytes JMP 76098f09 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[4200] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075fd144a 2 bytes CALL 75ff4885 C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[4200] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075fd14dd 2 bytes JMP 76098802 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[4200] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075fd14f5 2 bytes JMP 760989d8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[4200] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075fd150d 2 bytes JMP 760986f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[4200] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075fd1525 2 bytes JMP 76098ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[4200] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075fd153d 2 bytes JMP 7600fc78 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[4200] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075fd1555 2 bytes JMP 760168bf C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[4200] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075fd156d 2 bytes JMP 76098fc1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[4200] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075fd1585 2 bytes JMP 76098b22 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[4200] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075fd159d 2 bytes JMP 760986bc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[4200] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075fd15b5 2 bytes JMP 7600fd11 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[4200] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075fd15cd 2 bytes JMP 7601b2b0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[4200] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075fd16b2 2 bytes JMP 76098e84 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[4200] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075fd16bd 2 bytes JMP 76098651 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4296] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075fd1401 2 bytes JMP 7601b1ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4296] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075fd1419 2 bytes JMP 7601b31a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4296] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075fd1431 2 bytes JMP 76098f09 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4296] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075fd144a 2 bytes CALL 75ff4885 C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4296] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075fd14dd 2 bytes JMP 76098802 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4296] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075fd14f5 2 bytes JMP 760989d8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4296] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075fd150d 2 bytes JMP 760986f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4296] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075fd1525 2 bytes JMP 76098ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4296] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075fd153d 2 bytes JMP 7600fc78 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4296] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075fd1555 2 bytes JMP 760168bf C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4296] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075fd156d 2 bytes JMP 76098fc1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4296] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075fd1585 2 bytes JMP 76098b22 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4296] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075fd159d 2 bytes JMP 760986bc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4296] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075fd15b5 2 bytes JMP 7600fd11 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4296] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075fd15cd 2 bytes JMP 7601b2b0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4296] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075fd16b2 2 bytes JMP 76098e84 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4296] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075fd16bd 2 bytes JMP 76098651 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\{f40376ff-34b3-b8a9-f403-376ff34bdbfc}\hqghumeaylnlf.exe[4568] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075fd1401 2 bytes JMP 7601b1ef C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\{f40376ff-34b3-b8a9-f403-376ff34bdbfc}\hqghumeaylnlf.exe[4568] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075fd1419 2 bytes JMP 7601b31a C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\{f40376ff-34b3-b8a9-f403-376ff34bdbfc}\hqghumeaylnlf.exe[4568] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075fd1431 2 bytes JMP 76098f09 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\{f40376ff-34b3-b8a9-f403-376ff34bdbfc}\hqghumeaylnlf.exe[4568] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075fd144a 2 bytes CALL 75ff4885 C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\ProgramData\{f40376ff-34b3-b8a9-f403-376ff34bdbfc}\hqghumeaylnlf.exe[4568] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075fd14dd 2 bytes JMP 76098802 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\{f40376ff-34b3-b8a9-f403-376ff34bdbfc}\hqghumeaylnlf.exe[4568] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075fd14f5 2 bytes JMP 760989d8 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\{f40376ff-34b3-b8a9-f403-376ff34bdbfc}\hqghumeaylnlf.exe[4568] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075fd150d 2 bytes JMP 760986f8 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\{f40376ff-34b3-b8a9-f403-376ff34bdbfc}\hqghumeaylnlf.exe[4568] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075fd1525 2 bytes JMP 76098ac2 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\{f40376ff-34b3-b8a9-f403-376ff34bdbfc}\hqghumeaylnlf.exe[4568] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075fd153d 2 bytes JMP 7600fc78 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\{f40376ff-34b3-b8a9-f403-376ff34bdbfc}\hqghumeaylnlf.exe[4568] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075fd1555 2 bytes JMP 760168bf C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\{f40376ff-34b3-b8a9-f403-376ff34bdbfc}\hqghumeaylnlf.exe[4568] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075fd156d 2 bytes JMP 76098fc1 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\{f40376ff-34b3-b8a9-f403-376ff34bdbfc}\hqghumeaylnlf.exe[4568] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075fd1585 2 bytes JMP 76098b22 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\{f40376ff-34b3-b8a9-f403-376ff34bdbfc}\hqghumeaylnlf.exe[4568] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075fd159d 2 bytes JMP 760986bc C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\{f40376ff-34b3-b8a9-f403-376ff34bdbfc}\hqghumeaylnlf.exe[4568] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075fd15b5 2 bytes JMP 7600fd11 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\{f40376ff-34b3-b8a9-f403-376ff34bdbfc}\hqghumeaylnlf.exe[4568] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075fd15cd 2 bytes JMP 7601b2b0 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\{f40376ff-34b3-b8a9-f403-376ff34bdbfc}\hqghumeaylnlf.exe[4568] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075fd16b2 2 bytes JMP 76098e84 C:\Windows\syswow64\kernel32.dll
.text C:\ProgramData\{f40376ff-34b3-b8a9-f403-376ff34bdbfc}\hqghumeaylnlf.exe[4568] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075fd16bd 2 bytes JMP 76098651 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\vnst9E35.tmp[5776] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075fd1401 2 bytes JMP 7601b1ef C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\vnst9E35.tmp[5776] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075fd1419 2 bytes JMP 7601b31a C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\vnst9E35.tmp[5776] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075fd1431 2 bytes JMP 76098f09 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\vnst9E35.tmp[5776] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075fd144a 2 bytes CALL 75ff4885 C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\vnst9E35.tmp[5776] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075fd14dd 2 bytes JMP 76098802 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\vnst9E35.tmp[5776] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075fd14f5 2 bytes JMP 760989d8 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\vnst9E35.tmp[5776] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075fd150d 2 bytes JMP 760986f8 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\vnst9E35.tmp[5776] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075fd1525 2 bytes JMP 76098ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\vnst9E35.tmp[5776] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075fd153d 2 bytes JMP 7600fc78 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\vnst9E35.tmp[5776] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075fd1555 2 bytes JMP 760168bf C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\vnst9E35.tmp[5776] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075fd156d 2 bytes JMP 76098fc1 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\vnst9E35.tmp[5776] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075fd1585 2 bytes JMP 76098b22 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\vnst9E35.tmp[5776] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075fd159d 2 bytes JMP 760986bc C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\vnst9E35.tmp[5776] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075fd15b5 2 bytes JMP 7600fd11 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\vnst9E35.tmp[5776] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075fd15cd 2 bytes JMP 7601b2b0 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\vnst9E35.tmp[5776] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075fd16b2 2 bytes JMP 76098e84 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\vnst9E35.tmp[5776] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075fd16bd 2 bytes JMP 76098651 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancer.exe[1164] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075fd1401 2 bytes JMP 7601b1ef C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancer.exe[1164] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075fd1419 2 bytes JMP 7601b31a C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancer.exe[1164] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075fd1431 2 bytes JMP 76098f09 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancer.exe[1164] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075fd144a 2 bytes CALL 75ff4885 C:\Windows\syswow64\KERNEL32.dll
.text ... * 9
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancer.exe[1164] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075fd14dd 2 bytes JMP 76098802 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancer.exe[1164] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075fd14f5 2 bytes JMP 760989d8 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancer.exe[1164] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075fd150d 2 bytes JMP 760986f8 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancer.exe[1164] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075fd1525 2 bytes JMP 76098ac2 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancer.exe[1164] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075fd153d 2 bytes JMP 7600fc78 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancer.exe[1164] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075fd1555 2 bytes JMP 760168bf C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancer.exe[1164] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075fd156d 2 bytes JMP 76098fc1 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancer.exe[1164] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075fd1585 2 bytes JMP 76098b22 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancer.exe[1164] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075fd159d 2 bytes JMP 760986bc C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancer.exe[1164] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075fd15b5 2 bytes JMP 7600fd11 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancer.exe[1164] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075fd15cd 2 bytes JMP 7601b2b0 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancer.exe[1164] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075fd16b2 2 bytes JMP 76098e84 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\WajWebEnhance\WajWebEnhance Internet Enhancer\InternetEnhancer.exe[1164] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075fd16bd 2 bytes JMP 76098651 C:\Windows\syswow64\KERNEL32.dll
---- Processes - GMER 2.1 ----
Process C:\Users\Anwender\AppData\Local\DE8134D4-1430960677-4C1F-0500-E0CB4E29E6BA\snsr1319.tmp (*** suspicious ***) @ C:\Users\Anwender\AppData\Local\DE8134D4-1430960677-4C1F-0500-E0CB4E29E6BA\snsr1319.tmp [2228](2015-05-06 23:10:48) 0000000001130000
Process C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\nstEFC.tmp (*** suspicious ***) @ C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\nstEFC.tmp [2324](2015-05-10 01:18:39) 0000000000850000
Process C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\vnst9E35.tmp (*** suspicious ***) @ C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\vnst9E35.tmp [5776] (install/ )(2015-05-06 22:55:29) 0000000000400000
Library C:\Users\Anwender\AppData\Local\Temp\nsg1D42.tmp\System.dll (*** suspicious ***) @ C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\vnst9E35.tmp [5776](2015-07-07 12:17:52) 0000000010000000
Library C:\Users\Anwender\AppData\Local\Temp\nsg1D42.tmp\IpConfig.dll (*** suspicious ***) @ C:\Users\Anwender\AppData\Roaming\DE8134D4-1430952928-4C1F-0500-E0CB4E29E6BA\vnst9E35.tmp [5776](2015-07-07 12:17:52) 0000000002930000
---- EOF - GMER 2.1 ----
__________________