|
Plagegeister aller Art und deren Bekämpfung: Ich bräuchte Hilfe zum Thema CryptoWall.Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
23.08.2016, 08:45 | #16 |
/// Malwareteam | Ich bräuchte Hilfe zum Thema CryptoWall. Was ist den in dem HDDRecovery Ordner drin? Scan mit Farbar's Recovery Scan Tool (Recovery Mode - Windows Vista, 7, 8) Hinweise für Windows 8-Nutzer: Anleitung 1 (FRST-Variante) und Anleitung 2 (zweiter Teil) |
23.08.2016, 08:48 | #17 |
| Ich bräuchte Hilfe zum Thema CryptoWall. Hallo Dennis,
__________________In dem Ordner befindet sich die HTML-Datei und .txt-Datei mit dem Namen HELP_DECRYPT_YOUR_FILES. Mfg Scripit |
23.08.2016, 08:49 | #18 |
/// Malwareteam | Ich bräuchte Hilfe zum Thema CryptoWall. Ja die Dateien können wir nicht mehr Decrypten wenn sie gelöscht wurden, also kannst dus einfach löschen. Bitte mit FRSTRE weitermachen.
__________________
__________________ |
23.08.2016, 09:03 | #19 |
| Ich bräuchte Hilfe zum Thema CryptoWall. Hallo Dennis, Bei mir steht " ERROR: No configuration file found" Mfg Scripit |
23.08.2016, 09:04 | #20 |
/// Malwareteam | Ich bräuchte Hilfe zum Thema CryptoWall. Hi, wo genau steht das denn? |
23.08.2016, 09:06 | #21 |
| Ich bräuchte Hilfe zum Thema CryptoWall. Hallo Dennis, Nachdem ich F8 gedrückt habe schwarzer Hintergrund und weiße Schrift. Mfg Scripit |
23.08.2016, 11:49 | #22 |
/// Malwareteam | Ich bräuchte Hilfe zum Thema CryptoWall. Hi, jetzt bin ich aber doch sehr verwundert. Schritt # 1: GMER Bitte lade dir GMER herunter: (Dateiname zufällig)
Tauchen Probleme auf?
Schritt # 2: TDSS-Killer Downloade dir bitte TDSSKiller.exe und speichere diese Datei auf dem Desktop
Schritt # 3: Bitte Posten
|
23.08.2016, 12:23 | #23 |
| Ich bräuchte Hilfe zum Thema CryptoWall. Hallo Dennis, hier wird seit 5 Minuten nichts gefunden. Es gibt zwar in der Anleitung einen ähnlichen Fall, aber ich schicke es dir mal. |
23.08.2016, 12:26 | #25 |
| Ich bräuchte Hilfe zum Thema CryptoWall. Hallo Dennis, Hier das Gmer-Log: Code:
ATTFilter GMER 2.2.19882 - hxxp://www.gmer.net Rootkit scan 2016-08-23 13:12:13 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 TOSHIBA_ rev.GT00 465,76GB Running: gmer-2.2.19882.exe; Driver: C:\Users\ADMINI~1\AppData\Local\Temp\awliypog.sys ---- User code sections - GMER 2.2 ---- .text C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe[1088] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076661401 2 bytes JMP 76e9b263 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe[1088] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076661419 2 bytes JMP 76e9b38e C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe[1088] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076661431 2 bytes JMP 76f190f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe[1088] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007666144a 2 bytes CALL 76e748ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe[1088] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000766614dd 2 bytes JMP 76f189ea C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe[1088] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000766614f5 2 bytes JMP 76f18bc0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe[1088] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007666150d 2 bytes JMP 76f188e0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe[1088] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076661525 2 bytes JMP 76f18caa C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe[1088] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007666153d 2 bytes JMP 76e8fce8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe[1088] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076661555 2 bytes JMP 76e96937 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe[1088] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007666156d 2 bytes JMP 76f191a9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe[1088] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076661585 2 bytes JMP 76f18d0a C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe[1088] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007666159d 2 bytes JMP 76f188a4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe[1088] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000766615b5 2 bytes JMP 76e8fd81 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe[1088] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000766615cd 2 bytes JMP 76e9b324 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe[1088] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000766616b2 2 bytes JMP 76f1906c C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe[1088] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000766616bd 2 bytes JMP 76f18839 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1852] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076661401 2 bytes JMP 76e9b263 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1852] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076661419 2 bytes JMP 76e9b38e C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1852] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076661431 2 bytes JMP 76f190f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1852] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007666144a 2 bytes CALL 76e748ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1852] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000766614dd 2 bytes JMP 76f189ea C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1852] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000766614f5 2 bytes JMP 76f18bc0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1852] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007666150d 2 bytes JMP 76f188e0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1852] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076661525 2 bytes JMP 76f18caa C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1852] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007666153d 2 bytes JMP 76e8fce8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1852] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076661555 2 bytes JMP 76e96937 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1852] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007666156d 2 bytes JMP 76f191a9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1852] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076661585 2 bytes JMP 76f18d0a C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1852] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007666159d 2 bytes JMP 76f188a4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1852] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000766615b5 2 bytes JMP 76e8fd81 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1852] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000766615cd 2 bytes JMP 76e9b324 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1852] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000766616b2 2 bytes JMP 76f1906c C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1852] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000766616bd 2 bytes JMP 76f18839 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe[2040] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076661401 2 bytes JMP 76e9b263 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe[2040] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076661419 2 bytes JMP 76e9b38e C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe[2040] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076661431 2 bytes JMP 76f190f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe[2040] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007666144a 2 bytes CALL 76e748ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe[2040] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000766614dd 2 bytes JMP 76f189ea C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe[2040] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000766614f5 2 bytes JMP 76f18bc0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe[2040] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007666150d 2 bytes JMP 76f188e0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe[2040] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076661525 2 bytes JMP 76f18caa C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe[2040] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007666153d 2 bytes JMP 76e8fce8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe[2040] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076661555 2 bytes JMP 76e96937 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe[2040] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007666156d 2 bytes JMP 76f191a9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe[2040] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076661585 2 bytes JMP 76f18d0a C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe[2040] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007666159d 2 bytes JMP 76f188a4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe[2040] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000766615b5 2 bytes JMP 76e8fd81 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe[2040] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000766615cd 2 bytes JMP 76e9b324 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe[2040] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000766616b2 2 bytes JMP 76f1906c C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe[2040] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000766616bd 2 bytes JMP 76f18839 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe[988] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076661401 2 bytes JMP 76e9b263 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe[988] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076661419 2 bytes JMP 76e9b38e C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe[988] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076661431 2 bytes JMP 76f190f1 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe[988] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007666144a 2 bytes CALL 76e748ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe[988] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000766614dd 2 bytes JMP 76f189ea C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe[988] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000766614f5 2 bytes JMP 76f18bc0 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe[988] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007666150d 2 bytes JMP 76f188e0 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe[988] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076661525 2 bytes JMP 76f18caa C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe[988] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007666153d 2 bytes JMP 76e8fce8 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe[988] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076661555 2 bytes JMP 76e96937 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe[988] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007666156d 2 bytes JMP 76f191a9 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe[988] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076661585 2 bytes JMP 76f18d0a C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe[988] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007666159d 2 bytes JMP 76f188a4 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe[988] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000766615b5 2 bytes JMP 76e8fd81 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe[988] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000766615cd 2 bytes JMP 76e9b324 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe[988] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000766616b2 2 bytes JMP 76f1906c C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe[988] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000766616bd 2 bytes JMP 76f18839 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076661401 2 bytes JMP 76e9b263 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe[2096] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076661419 2 bytes JMP 76e9b38e C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076661431 2 bytes JMP 76f190f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007666144a 2 bytes CALL 76e748ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe[2096] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000766614dd 2 bytes JMP 76f189ea C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000766614f5 2 bytes JMP 76f18bc0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe[2096] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007666150d 2 bytes JMP 76f188e0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076661525 2 bytes JMP 76f18caa C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007666153d 2 bytes JMP 76e8fce8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe[2096] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076661555 2 bytes JMP 76e96937 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007666156d 2 bytes JMP 76f191a9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076661585 2 bytes JMP 76f18d0a C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe[2096] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007666159d 2 bytes JMP 76f188a4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000766615b5 2 bytes JMP 76e8fd81 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000766615cd 2 bytes JMP 76e9b324 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000766616b2 2 bytes JMP 76f1906c C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\Umbrella\umbrella.exe[2096] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000766616bd 2 bytes JMP 76f18839 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe[2384] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076661401 2 bytes JMP 76e9b263 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe[2384] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076661419 2 bytes JMP 76e9b38e C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe[2384] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076661431 2 bytes JMP 76f190f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe[2384] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007666144a 2 bytes CALL 76e748ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe[2384] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000766614dd 2 bytes JMP 76f189ea C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe[2384] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000766614f5 2 bytes JMP 76f18bc0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe[2384] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007666150d 2 bytes JMP 76f188e0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe[2384] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076661525 2 bytes JMP 76f18caa C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe[2384] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007666153d 2 bytes JMP 76e8fce8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe[2384] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076661555 2 bytes JMP 76e96937 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe[2384] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007666156d 2 bytes JMP 76f191a9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe[2384] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076661585 2 bytes JMP 76f18d0a C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe[2384] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007666159d 2 bytes JMP 76f188a4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe[2384] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000766615b5 2 bytes JMP 76e8fd81 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe[2384] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000766615cd 2 bytes JMP 76e9b324 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe[2384] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000766616b2 2 bytes JMP 76f1906c C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe[2384] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000766616bd 2 bytes JMP 76f18839 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[2784] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076661401 2 bytes JMP 76e9b263 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[2784] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076661419 2 bytes JMP 76e9b38e C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[2784] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076661431 2 bytes JMP 76f190f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[2784] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007666144a 2 bytes CALL 76e748ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[2784] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000766614dd 2 bytes JMP 76f189ea C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[2784] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000766614f5 2 bytes JMP 76f18bc0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[2784] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007666150d 2 bytes JMP 76f188e0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[2784] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076661525 2 bytes JMP 76f18caa C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[2784] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007666153d 2 bytes JMP 76e8fce8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[2784] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076661555 2 bytes JMP 76e96937 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[2784] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007666156d 2 bytes JMP 76f191a9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[2784] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076661585 2 bytes JMP 76f18d0a C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[2784] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007666159d 2 bytes JMP 76f188a4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[2784] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000766615b5 2 bytes JMP 76e8fd81 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[2784] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000766615cd 2 bytes JMP 76e9b324 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[2784] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000766616b2 2 bytes JMP 76f1906c C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[2784] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000766616bd 2 bytes JMP 76f18839 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\SearchProtect\bin\cltmng.exe[3564] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076661401 2 bytes JMP 76e9b263 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\SearchProtect\bin\cltmng.exe[3564] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076661419 2 bytes JMP 76e9b38e C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\SearchProtect\bin\cltmng.exe[3564] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076661431 2 bytes JMP 76f190f1 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\SearchProtect\bin\cltmng.exe[3564] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007666144a 2 bytes CALL 76e748ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Users\Administrator\AppData\Roaming\SearchProtect\bin\cltmng.exe[3564] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000766614dd 2 bytes JMP 76f189ea C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\SearchProtect\bin\cltmng.exe[3564] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000766614f5 2 bytes JMP 76f18bc0 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\SearchProtect\bin\cltmng.exe[3564] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007666150d 2 bytes JMP 76f188e0 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\SearchProtect\bin\cltmng.exe[3564] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076661525 2 bytes JMP 76f18caa C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\SearchProtect\bin\cltmng.exe[3564] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007666153d 2 bytes JMP 76e8fce8 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\SearchProtect\bin\cltmng.exe[3564] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076661555 2 bytes JMP 76e96937 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\SearchProtect\bin\cltmng.exe[3564] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007666156d 2 bytes JMP 76f191a9 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\SearchProtect\bin\cltmng.exe[3564] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076661585 2 bytes JMP 76f18d0a C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\SearchProtect\bin\cltmng.exe[3564] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007666159d 2 bytes JMP 76f188a4 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\SearchProtect\bin\cltmng.exe[3564] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000766615b5 2 bytes JMP 76e8fd81 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\SearchProtect\bin\cltmng.exe[3564] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000766615cd 2 bytes JMP 76e9b324 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\SearchProtect\bin\cltmng.exe[3564] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000766616b2 2 bytes JMP 76f1906c C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\SearchProtect\bin\cltmng.exe[3564] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000766616bd 2 bytes JMP 76f18839 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\{6445005D-6779-C85B-F810-78A56EA5BF33}\fontview.exe[3608] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076661401 2 bytes JMP 76e9b263 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\{6445005D-6779-C85B-F810-78A56EA5BF33}\fontview.exe[3608] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076661419 2 bytes JMP 76e9b38e C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\{6445005D-6779-C85B-F810-78A56EA5BF33}\fontview.exe[3608] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076661431 2 bytes JMP 76f190f1 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\{6445005D-6779-C85B-F810-78A56EA5BF33}\fontview.exe[3608] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007666144a 2 bytes CALL 76e748ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Users\Administrator\AppData\Roaming\{6445005D-6779-C85B-F810-78A56EA5BF33}\fontview.exe[3608] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000766614dd 2 bytes JMP 76f189ea C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\{6445005D-6779-C85B-F810-78A56EA5BF33}\fontview.exe[3608] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000766614f5 2 bytes JMP 76f18bc0 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\{6445005D-6779-C85B-F810-78A56EA5BF33}\fontview.exe[3608] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007666150d 2 bytes JMP 76f188e0 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\{6445005D-6779-C85B-F810-78A56EA5BF33}\fontview.exe[3608] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076661525 2 bytes JMP 76f18caa C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\{6445005D-6779-C85B-F810-78A56EA5BF33}\fontview.exe[3608] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007666153d 2 bytes JMP 76e8fce8 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\{6445005D-6779-C85B-F810-78A56EA5BF33}\fontview.exe[3608] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076661555 2 bytes JMP 76e96937 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\{6445005D-6779-C85B-F810-78A56EA5BF33}\fontview.exe[3608] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007666156d 2 bytes JMP 76f191a9 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\{6445005D-6779-C85B-F810-78A56EA5BF33}\fontview.exe[3608] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076661585 2 bytes JMP 76f18d0a C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\{6445005D-6779-C85B-F810-78A56EA5BF33}\fontview.exe[3608] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007666159d 2 bytes JMP 76f188a4 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\{6445005D-6779-C85B-F810-78A56EA5BF33}\fontview.exe[3608] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000766615b5 2 bytes JMP 76e8fd81 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\{6445005D-6779-C85B-F810-78A56EA5BF33}\fontview.exe[3608] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000766615cd 2 bytes JMP 76e9b324 C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\{6445005D-6779-C85B-F810-78A56EA5BF33}\fontview.exe[3608] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000766616b2 2 bytes JMP 76f1906c C:\Windows\syswow64\kernel32.dll .text C:\Users\Administrator\AppData\Roaming\{6445005D-6779-C85B-F810-78A56EA5BF33}\fontview.exe[3608] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000766616bd 2 bytes JMP 76f18839 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[5036] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076661401 2 bytes JMP 76e9b263 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[5036] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076661419 2 bytes JMP 76e9b38e C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[5036] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076661431 2 bytes JMP 76f190f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[5036] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007666144a 2 bytes CALL 76e748ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[5036] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000766614dd 2 bytes JMP 76f189ea C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[5036] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000766614f5 2 bytes JMP 76f18bc0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[5036] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007666150d 2 bytes JMP 76f188e0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[5036] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076661525 2 bytes JMP 76f18caa C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[5036] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007666153d 2 bytes JMP 76e8fce8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[5036] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076661555 2 bytes JMP 76e96937 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[5036] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007666156d 2 bytes JMP 76f191a9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[5036] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076661585 2 bytes JMP 76f18d0a C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[5036] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007666159d 2 bytes JMP 76f188a4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[5036] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000766615b5 2 bytes JMP 76e8fd81 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[5036] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000766615cd 2 bytes JMP 76e9b324 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[5036] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000766616b2 2 bytes JMP 76f1906c C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Google\Update\GoogleUpdate.exe[5036] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000766616bd 2 bytes JMP 76f18839 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\AVG Secure Search\vprot.exe[1952] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076661401 2 bytes JMP 76e9b263 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\AVG Secure Search\vprot.exe[1952] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076661419 2 bytes JMP 76e9b38e C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\AVG Secure Search\vprot.exe[1952] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076661431 2 bytes JMP 76f190f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\AVG Secure Search\vprot.exe[1952] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007666144a 2 bytes CALL 76e748ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\AVG Secure Search\vprot.exe[1952] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000766614dd 2 bytes JMP 76f189ea C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\AVG Secure Search\vprot.exe[1952] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000766614f5 2 bytes JMP 76f18bc0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\AVG Secure Search\vprot.exe[1952] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007666150d 2 bytes JMP 76f188e0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\AVG Secure Search\vprot.exe[1952] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076661525 2 bytes JMP 76f18caa C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\AVG Secure Search\vprot.exe[1952] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007666153d 2 bytes JMP 76e8fce8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\AVG Secure Search\vprot.exe[1952] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076661555 2 bytes JMP 76e96937 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\AVG Secure Search\vprot.exe[1952] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007666156d 2 bytes JMP 76f191a9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\AVG Secure Search\vprot.exe[1952] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076661585 2 bytes JMP 76f18d0a C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\AVG Secure Search\vprot.exe[1952] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007666159d 2 bytes JMP 76f188a4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\AVG Secure Search\vprot.exe[1952] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000766615b5 2 bytes JMP 76e8fd81 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\AVG Secure Search\vprot.exe[1952] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000766615cd 2 bytes JMP 76e9b324 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\AVG Secure Search\vprot.exe[1952] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000766616b2 2 bytes JMP 76f1906c C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\AVG Secure Search\vprot.exe[1952] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000766616bd 2 bytes JMP 76f18839 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[4960] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076661401 2 bytes JMP 76e9b263 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[4960] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076661419 2 bytes JMP 76e9b38e C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[4960] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076661431 2 bytes JMP 76f190f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[4960] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007666144a 2 bytes CALL 76e748ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[4960] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000766614dd 2 bytes JMP 76f189ea C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[4960] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000766614f5 2 bytes JMP 76f18bc0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[4960] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007666150d 2 bytes JMP 76f188e0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[4960] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076661525 2 bytes JMP 76f18caa C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[4960] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007666153d 2 bytes JMP 76e8fce8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[4960] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076661555 2 bytes JMP 76e96937 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[4960] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007666156d 2 bytes JMP 76f191a9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[4960] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076661585 2 bytes JMP 76f18d0a C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[4960] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007666159d 2 bytes JMP 76f188a4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[4960] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000766615b5 2 bytes JMP 76e8fd81 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[4960] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000766615cd 2 bytes JMP 76e9b324 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[4960] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000766616b2 2 bytes JMP 76f1906c C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Ask.com\Updater\Updater.exe[4960] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000766616bd 2 bytes JMP 76f18839 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Iminent\Iminent.Messengers.exe[4204] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076661401 2 bytes JMP 76e9b263 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Iminent\Iminent.Messengers.exe[4204] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076661419 2 bytes JMP 76e9b38e C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Iminent\Iminent.Messengers.exe[4204] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076661431 2 bytes JMP 76f190f1 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Iminent\Iminent.Messengers.exe[4204] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007666144a 2 bytes CALL 76e748ad C:\Windows\syswow64\KERNEL32.dll .text ... * 9 .text C:\Program Files (x86)\Iminent\Iminent.Messengers.exe[4204] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000766614dd 2 bytes JMP 76f189ea C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Iminent\Iminent.Messengers.exe[4204] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000766614f5 2 bytes JMP 76f18bc0 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Iminent\Iminent.Messengers.exe[4204] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007666150d 2 bytes JMP 76f188e0 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Iminent\Iminent.Messengers.exe[4204] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076661525 2 bytes JMP 76f18caa C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Iminent\Iminent.Messengers.exe[4204] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007666153d 2 bytes JMP 76e8fce8 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Iminent\Iminent.Messengers.exe[4204] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076661555 2 bytes JMP 76e96937 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Iminent\Iminent.Messengers.exe[4204] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007666156d 2 bytes JMP 76f191a9 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Iminent\Iminent.Messengers.exe[4204] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076661585 2 bytes JMP 76f18d0a C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Iminent\Iminent.Messengers.exe[4204] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007666159d 2 bytes JMP 76f188a4 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Iminent\Iminent.Messengers.exe[4204] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000766615b5 2 bytes JMP 76e8fd81 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Iminent\Iminent.Messengers.exe[4204] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000766615cd 2 bytes JMP 76e9b324 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Iminent\Iminent.Messengers.exe[4204] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000766616b2 2 bytes JMP 76f1906c C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\Iminent\Iminent.Messengers.exe[4204] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000766616bd 2 bytes JMP 76f18839 C:\Windows\syswow64\KERNEL32.dll .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076661401 2 bytes JMP 76e9b263 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[6076] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076661419 2 bytes JMP 76e9b38e C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076661431 2 bytes JMP 76f190f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007666144a 2 bytes CALL 76e748ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[6076] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000766614dd 2 bytes JMP 76f189ea C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000766614f5 2 bytes JMP 76f18bc0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[6076] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007666150d 2 bytes JMP 76f188e0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076661525 2 bytes JMP 76f18caa C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007666153d 2 bytes JMP 76e8fce8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[6076] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076661555 2 bytes JMP 76e96937 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007666156d 2 bytes JMP 76f191a9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076661585 2 bytes JMP 76f18d0a C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[6076] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007666159d 2 bytes JMP 76f188a4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000766615b5 2 bytes JMP 76e8fd81 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000766615cd 2 bytes JMP 76e9b324 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000766616b2 2 bytes JMP 76f1906c C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe[6076] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000766616bd 2 bytes JMP 76f18839 C:\Windows\syswow64\kernel32.dll ? C:\Windows\system32\mssprxy.dll [6076] entry point in ".rdata" section 00000000729571e6 .text C:\program files (x86)\avira\antivir desktop\ipmGui.exe[5948] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076661401 2 bytes JMP 76e9b263 C:\Windows\syswow64\kernel32.dll .text C:\program files (x86)\avira\antivir desktop\ipmGui.exe[5948] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076661419 2 bytes JMP 76e9b38e C:\Windows\syswow64\kernel32.dll .text C:\program files (x86)\avira\antivir desktop\ipmGui.exe[5948] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076661431 2 bytes JMP 76f190f1 C:\Windows\syswow64\kernel32.dll .text C:\program files (x86)\avira\antivir desktop\ipmGui.exe[5948] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007666144a 2 bytes CALL 76e748ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\program files (x86)\avira\antivir desktop\ipmGui.exe[5948] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000766614dd 2 bytes JMP 76f189ea C:\Windows\syswow64\kernel32.dll .text C:\program files (x86)\avira\antivir desktop\ipmGui.exe[5948] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000766614f5 2 bytes JMP 76f18bc0 C:\Windows\syswow64\kernel32.dll .text C:\program files (x86)\avira\antivir desktop\ipmGui.exe[5948] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007666150d 2 bytes JMP 76f188e0 C:\Windows\syswow64\kernel32.dll .text C:\program files (x86)\avira\antivir desktop\ipmGui.exe[5948] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076661525 2 bytes JMP 76f18caa C:\Windows\syswow64\kernel32.dll .text C:\program files (x86)\avira\antivir desktop\ipmGui.exe[5948] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007666153d 2 bytes JMP 76e8fce8 C:\Windows\syswow64\kernel32.dll .text C:\program files (x86)\avira\antivir desktop\ipmGui.exe[5948] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076661555 2 bytes JMP 76e96937 C:\Windows\syswow64\kernel32.dll .text C:\program files (x86)\avira\antivir desktop\ipmGui.exe[5948] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007666156d 2 bytes JMP 76f191a9 C:\Windows\syswow64\kernel32.dll .text C:\program files (x86)\avira\antivir desktop\ipmGui.exe[5948] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076661585 2 bytes JMP 76f18d0a C:\Windows\syswow64\kernel32.dll .text C:\program files (x86)\avira\antivir desktop\ipmGui.exe[5948] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007666159d 2 bytes JMP 76f188a4 C:\Windows\syswow64\kernel32.dll .text C:\program files (x86)\avira\antivir desktop\ipmGui.exe[5948] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000766615b5 2 bytes JMP 76e8fd81 C:\Windows\syswow64\kernel32.dll .text C:\program files (x86)\avira\antivir desktop\ipmGui.exe[5948] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000766615cd 2 bytes JMP 76e9b324 C:\Windows\syswow64\kernel32.dll .text C:\program files (x86)\avira\antivir desktop\ipmGui.exe[5948] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000766616b2 2 bytes JMP 76f1906c C:\Windows\syswow64\kernel32.dll .text C:\program files (x86)\avira\antivir desktop\ipmGui.exe[5948] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000766616bd 2 bytes JMP 76f18839 C:\Windows\syswow64\kernel32.dll ---- EOF - GMER 2.2 ---- Scripit |
23.08.2016, 14:05 | #26 |
/// Malwareteam | Ich bräuchte Hilfe zum Thema CryptoWall. Hi, also irgendwas scheint da noch draufzusein und ich kann dir nicht garantieren, dass wir das runterbekommen. Die einfachere und schnellere Variante wäre ein Neuaufsetzen des Systems, da sind dann dafür alle Programme weg. Wenn du trotzdem bereinigen möchtest können wir das natürlich gerne tun. Schritt # 1: Dr.Web CureIt! Wir probieren mal Dr. Web CureIt!.
Schritt # 2: Bitte Posten
|
23.08.2016, 14:16 | #27 |
| Ich bräuchte Hilfe zum Thema CryptoWall. Hallo Dennis, ich werde nochmal meine Schwester fragen, ob sie es dann neu aufsetzen würde. Mfg Scripit |
23.08.2016, 14:23 | #28 |
/// Malwareteam | Ich bräuchte Hilfe zum Thema CryptoWall. OK. |
Themen zu Ich bräuchte Hilfe zum Thema CryptoWall. |
abgesicherte, abgesicherten, antiviren, bräuchte, cryptowall, dateien, dateien durch trojaner "locked", datum, entdeck, entferne, funktioniert, gen, gesuch, interne, internet, komplett, kurzer, laptop, lösung, modus, netzwerk, netzwerktreiber, programm, starte, starten, thema, virus |