Code:
Alles auswählen Aufklappen ATTFilter
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-12-01 19:12:16
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD10 rev.01.0 931,51GB
Running: Gmer-19357.exe; Driver: C:\Users\***\AppData\Local\Temp\kwdiipow.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3120] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075a21401 2 bytes JMP 7712b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3120] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075a21419 2 bytes JMP 7712b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3120] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075a21431 2 bytes JMP 771a8fd1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3120] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075a2144a 2 bytes CALL 7710489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3120] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075a214dd 2 bytes JMP 771a88c4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3120] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075a214f5 2 bytes JMP 771a8aa0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3120] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075a2150d 2 bytes JMP 771a87ba C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3120] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075a21525 2 bytes JMP 771a8b8a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3120] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075a2153d 2 bytes JMP 7711fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3120] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075a21555 2 bytes JMP 771268ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3120] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075a2156d 2 bytes JMP 771a9089 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3120] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075a21585 2 bytes JMP 771a8bea C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3120] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075a2159d 2 bytes JMP 771a877e C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3120] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075a215b5 2 bytes JMP 7711fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3120] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075a215cd 2 bytes JMP 7712b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3120] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075a216b2 2 bytes JMP 771a8f4c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3120] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075a216bd 2 bytes JMP 771a8713 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3300] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075a21401 2 bytes JMP 7712b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3300] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075a21419 2 bytes JMP 7712b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3300] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075a21431 2 bytes JMP 771a8fd1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3300] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075a2144a 2 bytes CALL 7710489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3300] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075a214dd 2 bytes JMP 771a88c4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3300] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075a214f5 2 bytes JMP 771a8aa0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3300] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075a2150d 2 bytes JMP 771a87ba C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3300] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075a21525 2 bytes JMP 771a8b8a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3300] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075a2153d 2 bytes JMP 7711fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3300] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075a21555 2 bytes JMP 771268ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3300] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075a2156d 2 bytes JMP 771a9089 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3300] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075a21585 2 bytes JMP 771a8bea C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3300] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075a2159d 2 bytes JMP 771a877e C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3300] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075a215b5 2 bytes JMP 7711fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3300] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075a215cd 2 bytes JMP 7712b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3300] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075a216b2 2 bytes JMP 771a8f4c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3300] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075a216bd 2 bytes JMP 771a8713 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[3324] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075a21401 2 bytes JMP 7712b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[3324] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075a21419 2 bytes JMP 7712b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[3324] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075a21431 2 bytes JMP 771a8fd1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[3324] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075a2144a 2 bytes CALL 7710489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[3324] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075a214dd 2 bytes JMP 771a88c4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[3324] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075a214f5 2 bytes JMP 771a8aa0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[3324] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075a2150d 2 bytes JMP 771a87ba C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[3324] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075a21525 2 bytes JMP 771a8b8a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[3324] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075a2153d 2 bytes JMP 7711fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[3324] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075a21555 2 bytes JMP 771268ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[3324] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075a2156d 2 bytes JMP 771a9089 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[3324] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075a21585 2 bytes JMP 771a8bea C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[3324] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075a2159d 2 bytes JMP 771a877e C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[3324] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075a215b5 2 bytes JMP 7711fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[3324] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075a215cd 2 bytes JMP 7712b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[3324] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075a216b2 2 bytes JMP 771a8f4c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[3324] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075a216bd 2 bytes JMP 771a8713 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[3588] C:\Windows\syswow64\Psapi.dll!GetModuleFileNameExW + 17 0000000075a21401 2 bytes JMP 7712b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[3588] C:\Windows\syswow64\Psapi.dll!EnumProcessModules + 17 0000000075a21419 2 bytes JMP 7712b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[3588] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 17 0000000075a21431 2 bytes JMP 771a8fd1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[3588] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 42 0000000075a2144a 2 bytes CALL 7710489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[3588] C:\Windows\syswow64\Psapi.dll!EnumDeviceDrivers + 17 0000000075a214dd 2 bytes JMP 771a88c4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[3588] C:\Windows\syswow64\Psapi.dll!GetDeviceDriverBaseNameA + 17 0000000075a214f5 2 bytes JMP 771a8aa0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[3588] C:\Windows\syswow64\Psapi.dll!QueryWorkingSetEx + 17 0000000075a2150d 2 bytes JMP 771a87ba C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[3588] C:\Windows\syswow64\Psapi.dll!GetDeviceDriverBaseNameW + 17 0000000075a21525 2 bytes JMP 771a8b8a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[3588] C:\Windows\syswow64\Psapi.dll!GetModuleBaseNameW + 17 0000000075a2153d 2 bytes JMP 7711fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[3588] C:\Windows\syswow64\Psapi.dll!EnumProcesses + 17 0000000075a21555 2 bytes JMP 771268ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[3588] C:\Windows\syswow64\Psapi.dll!GetProcessMemoryInfo + 17 0000000075a2156d 2 bytes JMP 771a9089 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[3588] C:\Windows\syswow64\Psapi.dll!GetPerformanceInfo + 17 0000000075a21585 2 bytes JMP 771a8bea C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[3588] C:\Windows\syswow64\Psapi.dll!QueryWorkingSet + 17 0000000075a2159d 2 bytes JMP 771a877e C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[3588] C:\Windows\syswow64\Psapi.dll!GetModuleBaseNameA + 17 0000000075a215b5 2 bytes JMP 7711fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[3588] C:\Windows\syswow64\Psapi.dll!GetModuleFileNameExA + 17 0000000075a215cd 2 bytes JMP 7712b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[3588] C:\Windows\syswow64\Psapi.dll!GetProcessImageFileNameW + 20 0000000075a216b2 2 bytes JMP 771a8f4c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dropbox\Client\Dropbox.exe[3588] C:\Windows\syswow64\Psapi.dll!GetProcessImageFileNameW + 31 0000000075a216bd 2 bytes JMP 771a8713 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[3952] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075a21401 2 bytes JMP 7712b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[3952] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075a21419 2 bytes JMP 7712b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[3952] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075a21431 2 bytes JMP 771a8fd1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[3952] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075a2144a 2 bytes CALL 7710489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[3952] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075a214dd 2 bytes JMP 771a88c4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[3952] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075a214f5 2 bytes JMP 771a8aa0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[3952] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075a2150d 2 bytes JMP 771a87ba C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[3952] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075a21525 2 bytes JMP 771a8b8a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[3952] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075a2153d 2 bytes JMP 7711fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[3952] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075a21555 2 bytes JMP 771268ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[3952] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075a2156d 2 bytes JMP 771a9089 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[3952] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075a21585 2 bytes JMP 771a8bea C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[3952] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075a2159d 2 bytes JMP 771a877e C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[3952] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075a215b5 2 bytes JMP 7711fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[3952] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075a215cd 2 bytes JMP 7712b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[3952] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075a216b2 2 bytes JMP 771a8f4c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe[3952] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075a216bd 2 bytes JMP 771a8713 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[4080] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075a21401 2 bytes JMP 7712b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[4080] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075a21419 2 bytes JMP 7712b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[4080] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075a21431 2 bytes JMP 771a8fd1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[4080] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075a2144a 2 bytes CALL 7710489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[4080] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075a214dd 2 bytes JMP 771a88c4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[4080] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075a214f5 2 bytes JMP 771a8aa0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[4080] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075a2150d 2 bytes JMP 771a87ba C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[4080] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075a21525 2 bytes JMP 771a8b8a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[4080] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075a2153d 2 bytes JMP 7711fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[4080] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075a21555 2 bytes JMP 771268ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[4080] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075a2156d 2 bytes JMP 771a9089 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[4080] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075a21585 2 bytes JMP 771a8bea C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[4080] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075a2159d 2 bytes JMP 771a877e C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[4080] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075a215b5 2 bytes JMP 7711fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[4080] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075a215cd 2 bytes JMP 7712b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[4080] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075a216b2 2 bytes JMP 771a8f4c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe[4080] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075a216bd 2 bytes JMP 771a8713 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075a21401 2 bytes JMP 7712b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2608] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075a21419 2 bytes JMP 7712b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075a21431 2 bytes JMP 771a8fd1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075a2144a 2 bytes CALL 7710489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2608] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075a214dd 2 bytes JMP 771a88c4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075a214f5 2 bytes JMP 771a8aa0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2608] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075a2150d 2 bytes JMP 771a87ba C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075a21525 2 bytes JMP 771a8b8a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075a2153d 2 bytes JMP 7711fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2608] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075a21555 2 bytes JMP 771268ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075a2156d 2 bytes JMP 771a9089 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075a21585 2 bytes JMP 771a8bea C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2608] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075a2159d 2 bytes JMP 771a877e C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075a215b5 2 bytes JMP 7711fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075a215cd 2 bytes JMP 7712b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075a216b2 2 bytes JMP 771a8f4c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075a216bd 2 bytes JMP 771a8713 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[500] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075a21401 2 bytes JMP 7712b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[500] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075a21419 2 bytes JMP 7712b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[500] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075a21431 2 bytes JMP 771a8fd1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[500] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075a2144a 2 bytes CALL 7710489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[500] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075a214dd 2 bytes JMP 771a88c4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[500] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075a214f5 2 bytes JMP 771a8aa0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[500] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075a2150d 2 bytes JMP 771a87ba C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[500] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075a21525 2 bytes JMP 771a8b8a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[500] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075a2153d 2 bytes JMP 7711fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[500] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075a21555 2 bytes JMP 771268ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[500] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075a2156d 2 bytes JMP 771a9089 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[500] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075a21585 2 bytes JMP 771a8bea C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[500] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075a2159d 2 bytes JMP 771a877e C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[500] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075a215b5 2 bytes JMP 7711fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[500] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075a215cd 2 bytes JMP 7712b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[500] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075a216b2 2 bytes JMP 771a8f4c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE[500] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075a216bd 2 bytes JMP 771a8713 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[4192] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075a21401 2 bytes JMP 7712b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[4192] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075a21419 2 bytes JMP 7712b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[4192] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075a21431 2 bytes JMP 771a8fd1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[4192] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075a2144a 2 bytes CALL 7710489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[4192] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075a214dd 2 bytes JMP 771a88c4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[4192] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075a214f5 2 bytes JMP 771a8aa0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[4192] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075a2150d 2 bytes JMP 771a87ba C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[4192] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075a21525 2 bytes JMP 771a8b8a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[4192] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075a2153d 2 bytes JMP 7711fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[4192] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075a21555 2 bytes JMP 771268ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[4192] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075a2156d 2 bytes JMP 771a9089 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[4192] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075a21585 2 bytes JMP 771a8bea C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[4192] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075a2159d 2 bytes JMP 771a877e C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[4192] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075a215b5 2 bytes JMP 7711fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[4192] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075a215cd 2 bytes JMP 7712b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[4192] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075a216b2 2 bytes JMP 771a8f4c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe[4192] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075a216bd 2 bytes JMP 771a8713 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4372] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075a21401 2 bytes JMP 7712b21b C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4372] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075a21419 2 bytes JMP 7712b346 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4372] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075a21431 2 bytes JMP 771a8fd1 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4372] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075a2144a 2 bytes CALL 7710489d C:\Windows\syswow64\KERNEL32.dll
.text ... * 9
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4372] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075a214dd 2 bytes JMP 771a88c4 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4372] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075a214f5 2 bytes JMP 771a8aa0 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4372] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075a2150d 2 bytes JMP 771a87ba C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4372] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075a21525 2 bytes JMP 771a8b8a C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4372] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075a2153d 2 bytes JMP 7711fca8 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4372] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075a21555 2 bytes JMP 771268ef C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4372] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075a2156d 2 bytes JMP 771a9089 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4372] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075a21585 2 bytes JMP 771a8bea C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4372] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075a2159d 2 bytes JMP 771a877e C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4372] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075a215b5 2 bytes JMP 7711fd41 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4372] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075a215cd 2 bytes JMP 7712b2dc C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4372] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075a216b2 2 bytes JMP 771a8f4c C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\Dell DataSafe Local Backup\TOASTER.EXE[4372] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075a216bd 2 bytes JMP 771a8713 C:\Windows\syswow64\KERNEL32.dll
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[5016] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075a21401 2 bytes JMP 7712b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[5016] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075a21419 2 bytes JMP 7712b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[5016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075a21431 2 bytes JMP 771a8fd1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[5016] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075a2144a 2 bytes CALL 7710489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[5016] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075a214dd 2 bytes JMP 771a88c4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[5016] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075a214f5 2 bytes JMP 771a8aa0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[5016] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075a2150d 2 bytes JMP 771a87ba C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[5016] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075a21525 2 bytes JMP 771a8b8a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[5016] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075a2153d 2 bytes JMP 7711fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[5016] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075a21555 2 bytes JMP 771268ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[5016] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075a2156d 2 bytes JMP 771a9089 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[5016] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075a21585 2 bytes JMP 771a8bea C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[5016] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075a2159d 2 bytes JMP 771a877e C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[5016] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075a215b5 2 bytes JMP 7711fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[5016] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075a215cd 2 bytes JMP 7712b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[5016] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075a216b2 2 bytes JMP 771a8f4c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe[5016] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075a216bd 2 bytes JMP 771a8713 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[7556] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075a21401 2 bytes JMP 7712b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[7556] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075a21419 2 bytes JMP 7712b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[7556] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075a21431 2 bytes JMP 771a8fd1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[7556] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075a2144a 2 bytes CALL 7710489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[7556] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075a214dd 2 bytes JMP 771a88c4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[7556] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075a214f5 2 bytes JMP 771a8aa0 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[7556] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075a2150d 2 bytes JMP 771a87ba C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[7556] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075a21525 2 bytes JMP 771a8b8a C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[7556] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075a2153d 2 bytes JMP 7711fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[7556] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075a21555 2 bytes JMP 771268ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[7556] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075a2156d 2 bytes JMP 771a9089 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[7556] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075a21585 2 bytes JMP 771a8bea C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[7556] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075a2159d 2 bytes JMP 771a877e C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[7556] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075a215b5 2 bytes JMP 7711fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[7556] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075a215cd 2 bytes JMP 7712b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[7556] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075a216b2 2 bytes JMP 771a8f4c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Secunia\PSI\sua.exe[7556] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075a216bd 2 bytes JMP 771a8713 C:\Windows\syswow64\kernel32.dll
---- Processes - GMER 2.1 ----
Library c:\users\***\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmprf_y8x.dll (*** suspicious ***) @ C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3588](2015-12-01 17:58:45) 0000000071120000
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\685d43e3102e
Reg HKLM\SYSTEM\CurrentControlSet\services\WinUsb\Parameters\Wdf@TimeOfLastSqmLog 0xE2 0x64 0x55 0xFB ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\685d43e3102e (not active ControlSet)
---- EOF - GMER 2.1 ----
Ich danke euch vielmals.
Sandra
__________________