
Zaraza. Jeden program pobrałem z chip.pl i komputer sam instaluje sobie wredne oprogramowanie. Wystarczy odejść od kompa na 30 min, i przegladarka, system maja 10 programów więcej. Usuwanie ich z panelu sterowania nic nie daje. Oczywiście, usunie program na jakieś 10 minut.
Mowa o programach: Istartsurf w przegladarce, Gamesdesktop i VOPacket (chyba) - bo aktualnie go nie ma.
Dodatkowo aliexpress. Korzystałem z tego serwisu. Podczas stukania haseł w google.com, przekierowuje czasem automatycznie na stronę aliexpress.com.
Międzygalaktyczni obróncy systemu windows wzywam Was o pomoc.
PS: Za chwilę dodam logi z gmera.
Dodano 05.09.2015 13:23:24:
- Kod: Zaznacz wszystko
GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2015-09-05 14:22:53
Windows 6.1.7600 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST3160811AS rev.3.AAE 149,05GB
Running: co7n632x.exe; Driver: S:\Users\Lucky\AppData\Local\Temp\awrdqkow.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG S:\Windows\system32\ntoskrnl.exe suspicious modification
---- User code sections - GMER 2.1 ----
.text S:\Windows\Explorer.EXE[1628] S:\Windows\system32\kernel32.dll!CreateProcessW 00000000775fe7b0 5 bytes JMP 00000001046a0018
.text S:\Program Files (x86)\CB687660-1441386074-11DF-8D96-485B3933B2E0\jnsvF142.tmp[1084] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000779b1401 2 bytes JMP 76e9eb26 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\CB687660-1441386074-11DF-8D96-485B3933B2E0\jnsvF142.tmp[1084] S:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000779b1419 2 bytes JMP 76eab513 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\CB687660-1441386074-11DF-8D96-485B3933B2E0\jnsvF142.tmp[1084] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000779b1431 2 bytes JMP 76f28609 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\CB687660-1441386074-11DF-8D96-485B3933B2E0\jnsvF142.tmp[1084] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000779b144a 2 bytes CALL 76e81dfa S:\Windows\syswow64\kernel32.dll
.text ... * 9
.text S:\Program Files (x86)\CB687660-1441386074-11DF-8D96-485B3933B2E0\jnsvF142.tmp[1084] S:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000779b14dd 2 bytes JMP 76f27efe S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\CB687660-1441386074-11DF-8D96-485B3933B2E0\jnsvF142.tmp[1084] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000779b14f5 2 bytes JMP 76f280d8 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\CB687660-1441386074-11DF-8D96-485B3933B2E0\jnsvF142.tmp[1084] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000779b150d 2 bytes JMP 76f27df4 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\CB687660-1441386074-11DF-8D96-485B3933B2E0\jnsvF142.tmp[1084] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000779b1525 2 bytes JMP 76f281c2 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\CB687660-1441386074-11DF-8D96-485B3933B2E0\jnsvF142.tmp[1084] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000779b153d 2 bytes JMP 76e9f088 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\CB687660-1441386074-11DF-8D96-485B3933B2E0\jnsvF142.tmp[1084] S:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000779b1555 2 bytes JMP 76eab885 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\CB687660-1441386074-11DF-8D96-485B3933B2E0\jnsvF142.tmp[1084] S:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000779b156d 2 bytes JMP 76f286c1 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\CB687660-1441386074-11DF-8D96-485B3933B2E0\jnsvF142.tmp[1084] S:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000779b1585 2 bytes JMP 76f28222 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\CB687660-1441386074-11DF-8D96-485B3933B2E0\jnsvF142.tmp[1084] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000779b159d 2 bytes JMP 76f27db8 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\CB687660-1441386074-11DF-8D96-485B3933B2E0\jnsvF142.tmp[1084] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000779b15b5 2 bytes JMP 76e9f121 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\CB687660-1441386074-11DF-8D96-485B3933B2E0\jnsvF142.tmp[1084] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000779b15cd 2 bytes JMP 76eab29f S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\CB687660-1441386074-11DF-8D96-485B3933B2E0\jnsvF142.tmp[1084] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000779b16b2 2 bytes JMP 76f28584 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\CB687660-1441386074-11DF-8D96-485B3933B2E0\jnsvF142.tmp[1084] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000779b16bd 2 bytes JMP 76f27d4d S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[1728] S:\Windows\syswow64\psapi.dll!GetModuleFileNameExW + 17 00000000779b1401 2 bytes JMP 76e9eb26 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[1728] S:\Windows\syswow64\psapi.dll!EnumProcessModules + 17 00000000779b1419 2 bytes JMP 76eab513 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[1728] S:\Windows\syswow64\psapi.dll!GetModuleInformation + 17 00000000779b1431 2 bytes JMP 76f28609 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[1728] S:\Windows\syswow64\psapi.dll!GetModuleInformation + 42 00000000779b144a 2 bytes CALL 76e81dfa S:\Windows\syswow64\kernel32.dll
.text ... * 9
.text S:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[1728] S:\Windows\syswow64\psapi.dll!EnumDeviceDrivers + 17 00000000779b14dd 2 bytes JMP 76f27efe S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[1728] S:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameA + 17 00000000779b14f5 2 bytes JMP 76f280d8 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[1728] S:\Windows\syswow64\psapi.dll!QueryWorkingSetEx + 17 00000000779b150d 2 bytes JMP 76f27df4 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[1728] S:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameW + 17 00000000779b1525 2 bytes JMP 76f281c2 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[1728] S:\Windows\syswow64\psapi.dll!GetModuleBaseNameW + 17 00000000779b153d 2 bytes JMP 76e9f088 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[1728] S:\Windows\syswow64\psapi.dll!EnumProcesses + 17 00000000779b1555 2 bytes JMP 76eab885 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[1728] S:\Windows\syswow64\psapi.dll!GetProcessMemoryInfo + 17 00000000779b156d 2 bytes JMP 76f286c1 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[1728] S:\Windows\syswow64\psapi.dll!GetPerformanceInfo + 17 00000000779b1585 2 bytes JMP 76f28222 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[1728] S:\Windows\syswow64\psapi.dll!QueryWorkingSet + 17 00000000779b159d 2 bytes JMP 76f27db8 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[1728] S:\Windows\syswow64\psapi.dll!GetModuleBaseNameA + 17 00000000779b15b5 2 bytes JMP 76e9f121 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[1728] S:\Windows\syswow64\psapi.dll!GetModuleFileNameExA + 17 00000000779b15cd 2 bytes JMP 76eab29f S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[1728] S:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 20 00000000779b16b2 2 bytes JMP 76f28584 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[1728] S:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 31 00000000779b16bd 2 bytes JMP 76f27d4d S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe[2056] S:\Windows\syswow64\kernel32.dll!CreateThread 0000000076e81ea8 5 bytes JMP 0000000102470770
.text S:\ProgramData\Voltit\Voltit.exe[2472] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000779b1401 2 bytes JMP 76e9eb26 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Voltit.exe[2472] S:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000779b1419 2 bytes JMP 76eab513 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Voltit.exe[2472] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000779b1431 2 bytes JMP 76f28609 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Voltit.exe[2472] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000779b144a 2 bytes CALL 76e81dfa S:\Windows\syswow64\KERNEL32.dll
.text ... * 9
.text S:\ProgramData\Voltit\Voltit.exe[2472] S:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000779b14dd 2 bytes JMP 76f27efe S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Voltit.exe[2472] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000779b14f5 2 bytes JMP 76f280d8 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Voltit.exe[2472] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000779b150d 2 bytes JMP 76f27df4 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Voltit.exe[2472] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000779b1525 2 bytes JMP 76f281c2 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Voltit.exe[2472] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000779b153d 2 bytes JMP 76e9f088 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Voltit.exe[2472] S:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000779b1555 2 bytes JMP 76eab885 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Voltit.exe[2472] S:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000779b156d 2 bytes JMP 76f286c1 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Voltit.exe[2472] S:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000779b1585 2 bytes JMP 76f28222 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Voltit.exe[2472] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000779b159d 2 bytes JMP 76f27db8 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Voltit.exe[2472] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000779b15b5 2 bytes JMP 76e9f121 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Voltit.exe[2472] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000779b15cd 2 bytes JMP 76eab29f S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Voltit.exe[2472] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000779b16b2 2 bytes JMP 76f28584 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Voltit.exe[2472] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000779b16bd 2 bytes JMP 76f27d4d S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\pWdsManProp\WdsManPro.exe[2548] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000779b1401 2 bytes JMP 76e9eb26 S:\Windows\syswow64\kernel32.dll
.text S:\ProgramData\pWdsManProp\WdsManPro.exe[2548] S:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000779b1419 2 bytes JMP 76eab513 S:\Windows\syswow64\kernel32.dll
.text S:\ProgramData\pWdsManProp\WdsManPro.exe[2548] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000779b1431 2 bytes JMP 76f28609 S:\Windows\syswow64\kernel32.dll
.text S:\ProgramData\pWdsManProp\WdsManPro.exe[2548] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000779b144a 2 bytes CALL 76e81dfa S:\Windows\syswow64\kernel32.dll
.text ... * 9
.text S:\ProgramData\pWdsManProp\WdsManPro.exe[2548] S:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000779b14dd 2 bytes JMP 76f27efe S:\Windows\syswow64\kernel32.dll
.text S:\ProgramData\pWdsManProp\WdsManPro.exe[2548] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000779b14f5 2 bytes JMP 76f280d8 S:\Windows\syswow64\kernel32.dll
.text S:\ProgramData\pWdsManProp\WdsManPro.exe[2548] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000779b150d 2 bytes JMP 76f27df4 S:\Windows\syswow64\kernel32.dll
.text S:\ProgramData\pWdsManProp\WdsManPro.exe[2548] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000779b1525 2 bytes JMP 76f281c2 S:\Windows\syswow64\kernel32.dll
.text S:\ProgramData\pWdsManProp\WdsManPro.exe[2548] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000779b153d 2 bytes JMP 76e9f088 S:\Windows\syswow64\kernel32.dll
.text S:\ProgramData\pWdsManProp\WdsManPro.exe[2548] S:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000779b1555 2 bytes JMP 76eab885 S:\Windows\syswow64\kernel32.dll
.text S:\ProgramData\pWdsManProp\WdsManPro.exe[2548] S:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000779b156d 2 bytes JMP 76f286c1 S:\Windows\syswow64\kernel32.dll
.text S:\ProgramData\pWdsManProp\WdsManPro.exe[2548] S:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000779b1585 2 bytes JMP 76f28222 S:\Windows\syswow64\kernel32.dll
.text S:\ProgramData\pWdsManProp\WdsManPro.exe[2548] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000779b159d 2 bytes JMP 76f27db8 S:\Windows\syswow64\kernel32.dll
.text S:\ProgramData\pWdsManProp\WdsManPro.exe[2548] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000779b15b5 2 bytes JMP 76e9f121 S:\Windows\syswow64\kernel32.dll
.text S:\ProgramData\pWdsManProp\WdsManPro.exe[2548] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000779b15cd 2 bytes JMP 76eab29f S:\Windows\syswow64\kernel32.dll
.text S:\ProgramData\pWdsManProp\WdsManPro.exe[2548] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000779b16b2 2 bytes JMP 76f28584 S:\Windows\syswow64\kernel32.dll
.text S:\ProgramData\pWdsManProp\WdsManPro.exe[2548] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000779b16bd 2 bytes JMP 76f27d4d S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Roaming\uTorrent\uTorrent.exe[3512] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000779b1401 2 bytes JMP 76e9eb26 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Roaming\uTorrent\uTorrent.exe[3512] S:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000779b1419 2 bytes JMP 76eab513 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Roaming\uTorrent\uTorrent.exe[3512] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000779b1431 2 bytes JMP 76f28609 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Roaming\uTorrent\uTorrent.exe[3512] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000779b144a 2 bytes CALL 76e81dfa S:\Windows\syswow64\kernel32.dll
.text ... * 9
.text S:\Users\Lucky\AppData\Roaming\uTorrent\uTorrent.exe[3512] S:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000779b14dd 2 bytes JMP 76f27efe S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Roaming\uTorrent\uTorrent.exe[3512] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000779b14f5 2 bytes JMP 76f280d8 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Roaming\uTorrent\uTorrent.exe[3512] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000779b150d 2 bytes JMP 76f27df4 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Roaming\uTorrent\uTorrent.exe[3512] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000779b1525 2 bytes JMP 76f281c2 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Roaming\uTorrent\uTorrent.exe[3512] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000779b153d 2 bytes JMP 76e9f088 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Roaming\uTorrent\uTorrent.exe[3512] S:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000779b1555 2 bytes JMP 76eab885 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Roaming\uTorrent\uTorrent.exe[3512] S:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000779b156d 2 bytes JMP 76f286c1 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Roaming\uTorrent\uTorrent.exe[3512] S:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000779b1585 2 bytes JMP 76f28222 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Roaming\uTorrent\uTorrent.exe[3512] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000779b159d 2 bytes JMP 76f27db8 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Roaming\uTorrent\uTorrent.exe[3512] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000779b15b5 2 bytes JMP 76e9f121 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Roaming\uTorrent\uTorrent.exe[3512] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000779b15cd 2 bytes JMP 76eab29f S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Roaming\uTorrent\uTorrent.exe[3512] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000779b16b2 2 bytes JMP 76f28584 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Roaming\uTorrent\uTorrent.exe[3512] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000779b16bd 2 bytes JMP 76f27d4d S:\Windows\syswow64\kernel32.dll
.text S:\ProgramData\Voltit\Plusing.exe[4872] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000779b1401 2 bytes JMP 76e9eb26 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Plusing.exe[4872] S:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000779b1419 2 bytes JMP 76eab513 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Plusing.exe[4872] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000779b1431 2 bytes JMP 76f28609 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Plusing.exe[4872] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000779b144a 2 bytes CALL 76e81dfa S:\Windows\syswow64\KERNEL32.dll
.text ... * 9
.text S:\ProgramData\Voltit\Plusing.exe[4872] S:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000779b14dd 2 bytes JMP 76f27efe S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Plusing.exe[4872] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000779b14f5 2 bytes JMP 76f280d8 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Plusing.exe[4872] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000779b150d 2 bytes JMP 76f27df4 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Plusing.exe[4872] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000779b1525 2 bytes JMP 76f281c2 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Plusing.exe[4872] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000779b153d 2 bytes JMP 76e9f088 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Plusing.exe[4872] S:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000779b1555 2 bytes JMP 76eab885 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Plusing.exe[4872] S:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000779b156d 2 bytes JMP 76f286c1 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Plusing.exe[4872] S:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000779b1585 2 bytes JMP 76f28222 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Plusing.exe[4872] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000779b159d 2 bytes JMP 76f27db8 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Plusing.exe[4872] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000779b15b5 2 bytes JMP 76e9f121 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Plusing.exe[4872] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000779b15cd 2 bytes JMP 76eab29f S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Plusing.exe[4872] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000779b16b2 2 bytes JMP 76f28584 S:\Windows\syswow64\KERNEL32.dll
.text S:\ProgramData\Voltit\Plusing.exe[4872] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000779b16bd 2 bytes JMP 76f27d4d S:\Windows\syswow64\KERNEL32.dll
.text S:\Program Files (x86)\Skype\Phone\Skype.exe[3648] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000779b1401 2 bytes JMP 76e9eb26 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Skype\Phone\Skype.exe[3648] S:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000779b1419 2 bytes JMP 76eab513 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Skype\Phone\Skype.exe[3648] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000779b1431 2 bytes JMP 76f28609 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Skype\Phone\Skype.exe[3648] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000779b144a 2 bytes CALL 76e81dfa S:\Windows\syswow64\kernel32.dll
.text ... * 9
.text S:\Program Files (x86)\Skype\Phone\Skype.exe[3648] S:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000779b14dd 2 bytes JMP 76f27efe S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Skype\Phone\Skype.exe[3648] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000779b14f5 2 bytes JMP 76f280d8 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Skype\Phone\Skype.exe[3648] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000779b150d 2 bytes JMP 76f27df4 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Skype\Phone\Skype.exe[3648] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000779b1525 2 bytes JMP 76f281c2 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Skype\Phone\Skype.exe[3648] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000779b153d 2 bytes JMP 76e9f088 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Skype\Phone\Skype.exe[3648] S:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000779b1555 2 bytes JMP 76eab885 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Skype\Phone\Skype.exe[3648] S:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000779b156d 2 bytes JMP 76f286c1 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Skype\Phone\Skype.exe[3648] S:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000779b1585 2 bytes JMP 76f28222 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Skype\Phone\Skype.exe[3648] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000779b159d 2 bytes JMP 76f27db8 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Skype\Phone\Skype.exe[3648] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000779b15b5 2 bytes JMP 76e9f121 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Skype\Phone\Skype.exe[3648] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000779b15cd 2 bytes JMP 76eab29f S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Skype\Phone\Skype.exe[3648] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000779b16b2 2 bytes JMP 76f28584 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\Skype\Phone\Skype.exe[3648] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000779b16bd 2 bytes JMP 76f27d4d S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsb75CF.tmp[5252] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000779b1401 2 bytes JMP 76e9eb26 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsb75CF.tmp[5252] S:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000779b1419 2 bytes JMP 76eab513 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsb75CF.tmp[5252] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000779b1431 2 bytes JMP 76f28609 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsb75CF.tmp[5252] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000779b144a 2 bytes CALL 76e81dfa S:\Windows\syswow64\kernel32.dll
.text ... * 9
.text S:\Users\Lucky\AppData\Local\Temp\nsb75CF.tmp[5252] S:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000779b14dd 2 bytes JMP 76f27efe S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsb75CF.tmp[5252] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000779b14f5 2 bytes JMP 76f280d8 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsb75CF.tmp[5252] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000779b150d 2 bytes JMP 76f27df4 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsb75CF.tmp[5252] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000779b1525 2 bytes JMP 76f281c2 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsb75CF.tmp[5252] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000779b153d 2 bytes JMP 76e9f088 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsb75CF.tmp[5252] S:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000779b1555 2 bytes JMP 76eab885 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsb75CF.tmp[5252] S:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000779b156d 2 bytes JMP 76f286c1 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsb75CF.tmp[5252] S:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000779b1585 2 bytes JMP 76f28222 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsb75CF.tmp[5252] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000779b159d 2 bytes JMP 76f27db8 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsb75CF.tmp[5252] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000779b15b5 2 bytes JMP 76e9f121 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsb75CF.tmp[5252] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000779b15cd 2 bytes JMP 76eab29f S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsb75CF.tmp[5252] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000779b16b2 2 bytes JMP 76f28584 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsb75CF.tmp[5252] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000779b16bd 2 bytes JMP 76f27d4d S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebHelper.exe[3196] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000779b1401 2 bytes JMP 76e9eb26 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebHelper.exe[3196] S:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000779b1419 2 bytes JMP 76eab513 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebHelper.exe[3196] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000779b1431 2 bytes JMP 76f28609 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebHelper.exe[3196] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000779b144a 2 bytes CALL 76e81dfa S:\Windows\syswow64\kernel32.dll
.text ... * 9
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebHelper.exe[3196] S:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000779b14dd 2 bytes JMP 76f27efe S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebHelper.exe[3196] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000779b14f5 2 bytes JMP 76f280d8 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebHelper.exe[3196] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000779b150d 2 bytes JMP 76f27df4 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebHelper.exe[3196] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000779b1525 2 bytes JMP 76f281c2 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebHelper.exe[3196] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000779b153d 2 bytes JMP 76e9f088 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebHelper.exe[3196] S:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000779b1555 2 bytes JMP 76eab885 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebHelper.exe[3196] S:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000779b156d 2 bytes JMP 76f286c1 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebHelper.exe[3196] S:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000779b1585 2 bytes JMP 76f28222 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebHelper.exe[3196] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000779b159d 2 bytes JMP 76f27db8 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebHelper.exe[3196] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000779b15b5 2 bytes JMP 76e9f121 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebHelper.exe[3196] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000779b15cd 2 bytes JMP 76eab29f S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebHelper.exe[3196] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000779b16b2 2 bytes JMP 76f28584 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebHelper.exe[3196] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000779b16bd 2 bytes JMP 76f27d4d S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebApp.exe[5780] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000779b1401 2 bytes JMP 76e9eb26 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebApp.exe[5780] S:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000779b1419 2 bytes JMP 76eab513 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebApp.exe[5780] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000779b1431 2 bytes JMP 76f28609 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebApp.exe[5780] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000779b144a 2 bytes CALL 76e81dfa S:\Windows\syswow64\kernel32.dll
.text ... * 9
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebApp.exe[5780] S:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000779b14dd 2 bytes JMP 76f27efe S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebApp.exe[5780] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000779b14f5 2 bytes JMP 76f280d8 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebApp.exe[5780] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000779b150d 2 bytes JMP 76f27df4 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebApp.exe[5780] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000779b1525 2 bytes JMP 76f281c2 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebApp.exe[5780] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000779b153d 2 bytes JMP 76e9f088 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebApp.exe[5780] S:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000779b1555 2 bytes JMP 76eab885 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebApp.exe[5780] S:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000779b156d 2 bytes JMP 76f286c1 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebApp.exe[5780] S:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000779b1585 2 bytes JMP 76f28222 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebApp.exe[5780] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000779b159d 2 bytes JMP 76f27db8 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebApp.exe[5780] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000779b15b5 2 bytes JMP 76e9f121 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebApp.exe[5780] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000779b15cd 2 bytes JMP 76eab29f S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebApp.exe[5780] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000779b16b2 2 bytes JMP 76f28584 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebApp.exe[5780] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000779b16bd 2 bytes JMP 76f27d4d S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\gmsd_pl_005010080\upgmsd_pl_005010080.exe[3208] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000779b1401 2 bytes JMP 76e9eb26 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\gmsd_pl_005010080\upgmsd_pl_005010080.exe[3208] S:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000779b1419 2 bytes JMP 76eab513 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\gmsd_pl_005010080\upgmsd_pl_005010080.exe[3208] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000779b1431 2 bytes JMP 76f28609 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\gmsd_pl_005010080\upgmsd_pl_005010080.exe[3208] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000779b144a 2 bytes CALL 76e81dfa S:\Windows\syswow64\kernel32.dll
.text ... * 9
.text S:\Users\Lucky\AppData\Local\gmsd_pl_005010080\upgmsd_pl_005010080.exe[3208] S:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000779b14dd 2 bytes JMP 76f27efe S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\gmsd_pl_005010080\upgmsd_pl_005010080.exe[3208] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000779b14f5 2 bytes JMP 76f280d8 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\gmsd_pl_005010080\upgmsd_pl_005010080.exe[3208] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000779b150d 2 bytes JMP 76f27df4 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\gmsd_pl_005010080\upgmsd_pl_005010080.exe[3208] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000779b1525 2 bytes JMP 76f281c2 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\gmsd_pl_005010080\upgmsd_pl_005010080.exe[3208] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000779b153d 2 bytes JMP 76e9f088 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\gmsd_pl_005010080\upgmsd_pl_005010080.exe[3208] S:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000779b1555 2 bytes JMP 76eab885 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\gmsd_pl_005010080\upgmsd_pl_005010080.exe[3208] S:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000779b156d 2 bytes JMP 76f286c1 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\gmsd_pl_005010080\upgmsd_pl_005010080.exe[3208] S:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000779b1585 2 bytes JMP 76f28222 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\gmsd_pl_005010080\upgmsd_pl_005010080.exe[3208] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000779b159d 2 bytes JMP 76f27db8 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\gmsd_pl_005010080\upgmsd_pl_005010080.exe[3208] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000779b15b5 2 bytes JMP 76e9f121 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\gmsd_pl_005010080\upgmsd_pl_005010080.exe[3208] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000779b15cd 2 bytes JMP 76eab29f S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\gmsd_pl_005010080\upgmsd_pl_005010080.exe[3208] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000779b16b2 2 bytes JMP 76f28584 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\gmsd_pl_005010080\upgmsd_pl_005010080.exe[3208] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000779b16bd 2 bytes JMP 76f27d4d S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\gmsd_pl_005010080\gmsd_pl_005010080.exe[5348] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000779b1401 2 bytes JMP 76e9eb26 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\gmsd_pl_005010080\gmsd_pl_005010080.exe[5348] S:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000779b1419 2 bytes JMP 76eab513 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\gmsd_pl_005010080\gmsd_pl_005010080.exe[5348] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000779b1431 2 bytes JMP 76f28609 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\gmsd_pl_005010080\gmsd_pl_005010080.exe[5348] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000779b144a 2 bytes CALL 76e81dfa S:\Windows\syswow64\kernel32.dll
.text ... * 9
.text S:\Program Files (x86)\gmsd_pl_005010080\gmsd_pl_005010080.exe[5348] S:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000779b14dd 2 bytes JMP 76f27efe S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\gmsd_pl_005010080\gmsd_pl_005010080.exe[5348] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000779b14f5 2 bytes JMP 76f280d8 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\gmsd_pl_005010080\gmsd_pl_005010080.exe[5348] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000779b150d 2 bytes JMP 76f27df4 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\gmsd_pl_005010080\gmsd_pl_005010080.exe[5348] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000779b1525 2 bytes JMP 76f281c2 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\gmsd_pl_005010080\gmsd_pl_005010080.exe[5348] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000779b153d 2 bytes JMP 76e9f088 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\gmsd_pl_005010080\gmsd_pl_005010080.exe[5348] S:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000779b1555 2 bytes JMP 76eab885 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\gmsd_pl_005010080\gmsd_pl_005010080.exe[5348] S:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000779b156d 2 bytes JMP 76f286c1 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\gmsd_pl_005010080\gmsd_pl_005010080.exe[5348] S:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000779b1585 2 bytes JMP 76f28222 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\gmsd_pl_005010080\gmsd_pl_005010080.exe[5348] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000779b159d 2 bytes JMP 76f27db8 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\gmsd_pl_005010080\gmsd_pl_005010080.exe[5348] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000779b15b5 2 bytes JMP 76e9f121 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\gmsd_pl_005010080\gmsd_pl_005010080.exe[5348] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000779b15cd 2 bytes JMP 76eab29f S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\gmsd_pl_005010080\gmsd_pl_005010080.exe[5348] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000779b16b2 2 bytes JMP 76f28584 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\gmsd_pl_005010080\gmsd_pl_005010080.exe[5348] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000779b16bd 2 bytes JMP 76f27d4d S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\SFK\SSFK.exe[3816] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000779b1401 2 bytes JMP 76e9eb26 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\SFK\SSFK.exe[3816] S:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000779b1419 2 bytes JMP 76eab513 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\SFK\SSFK.exe[3816] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000779b1431 2 bytes JMP 76f28609 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\SFK\SSFK.exe[3816] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000779b144a 2 bytes CALL 76e81dfa S:\Windows\syswow64\kernel32.dll
.text ... * 9
.text S:\Program Files (x86)\SFK\SSFK.exe[3816] S:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000779b14dd 2 bytes JMP 76f27efe S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\SFK\SSFK.exe[3816] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000779b14f5 2 bytes JMP 76f280d8 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\SFK\SSFK.exe[3816] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000779b150d 2 bytes JMP 76f27df4 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\SFK\SSFK.exe[3816] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000779b1525 2 bytes JMP 76f281c2 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\SFK\SSFK.exe[3816] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000779b153d 2 bytes JMP 76e9f088 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\SFK\SSFK.exe[3816] S:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000779b1555 2 bytes JMP 76eab885 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\SFK\SSFK.exe[3816] S:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000779b156d 2 bytes JMP 76f286c1 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\SFK\SSFK.exe[3816] S:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000779b1585 2 bytes JMP 76f28222 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\SFK\SSFK.exe[3816] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000779b159d 2 bytes JMP 76f27db8 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\SFK\SSFK.exe[3816] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000779b15b5 2 bytes JMP 76e9f121 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\SFK\SSFK.exe[3816] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000779b15cd 2 bytes JMP 76eab29f S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\SFK\SSFK.exe[3816] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000779b16b2 2 bytes JMP 76f28584 S:\Windows\syswow64\kernel32.dll
.text S:\Program Files (x86)\SFK\SSFK.exe[3816] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000779b16bd 2 bytes JMP 76f27d4d S:\Windows\syswow64\kernel32.dll
? S:\Windows\system32\mssprxy.dll [3816] entry point in ".rdata" section 00000000752c71e6
.text S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp[6244] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000779b1401 2 bytes JMP 76e9eb26 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp[6244] S:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000779b1419 2 bytes JMP 76eab513 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp[6244] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000779b1431 2 bytes JMP 76f28609 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp[6244] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000779b144a 2 bytes CALL 76e81dfa S:\Windows\syswow64\kernel32.dll
.text ... * 9
.text S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp[6244] S:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000779b14dd 2 bytes JMP 76f27efe S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp[6244] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000779b14f5 2 bytes JMP 76f280d8 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp[6244] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000779b150d 2 bytes JMP 76f27df4 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp[6244] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000779b1525 2 bytes JMP 76f281c2 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp[6244] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000779b153d 2 bytes JMP 76e9f088 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp[6244] S:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000779b1555 2 bytes JMP 76eab885 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp[6244] S:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000779b156d 2 bytes JMP 76f286c1 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp[6244] S:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000779b1585 2 bytes JMP 76f28222 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp[6244] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000779b159d 2 bytes JMP 76f27db8 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp[6244] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000779b15b5 2 bytes JMP 76e9f121 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp[6244] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000779b15cd 2 bytes JMP 76eab29f S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp[6244] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000779b16b2 2 bytes JMP 76f28584 S:\Windows\syswow64\kernel32.dll
.text S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp[6244] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000779b16bd 2 bytes JMP 76f27d4d S:\Windows\syswow64\kernel32.dll
? S:\Windows\system32\mssprxy.dll [6244] entry point in ".rdata" section 00000000752c71e6
.text G:\Lol\RADS\system\rads_user_kernel.exe[6184] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000779b1401 2 bytes JMP 76e9eb26 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\system\rads_user_kernel.exe[6184] S:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000779b1419 2 bytes JMP 76eab513 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\system\rads_user_kernel.exe[6184] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000779b1431 2 bytes JMP 76f28609 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\system\rads_user_kernel.exe[6184] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000779b144a 2 bytes CALL 76e81dfa S:\Windows\syswow64\kernel32.dll
.text ... * 9
.text G:\Lol\RADS\system\rads_user_kernel.exe[6184] S:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000779b14dd 2 bytes JMP 76f27efe S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\system\rads_user_kernel.exe[6184] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000779b14f5 2 bytes JMP 76f280d8 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\system\rads_user_kernel.exe[6184] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000779b150d 2 bytes JMP 76f27df4 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\system\rads_user_kernel.exe[6184] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000779b1525 2 bytes JMP 76f281c2 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\system\rads_user_kernel.exe[6184] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000779b153d 2 bytes JMP 76e9f088 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\system\rads_user_kernel.exe[6184] S:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000779b1555 2 bytes JMP 76eab885 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\system\rads_user_kernel.exe[6184] S:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000779b156d 2 bytes JMP 76f286c1 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\system\rads_user_kernel.exe[6184] S:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000779b1585 2 bytes JMP 76f28222 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\system\rads_user_kernel.exe[6184] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000779b159d 2 bytes JMP 76f27db8 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\system\rads_user_kernel.exe[6184] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000779b15b5 2 bytes JMP 76e9f121 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\system\rads_user_kernel.exe[6184] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000779b15cd 2 bytes JMP 76eab29f S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\system\rads_user_kernel.exe[6184] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000779b16b2 2 bytes JMP 76f28584 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\system\rads_user_kernel.exe[6184] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000779b16bd 2 bytes JMP 76f27d4d S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_launcher\releases\0.0.0.254\deploy\LoLLauncher.exe[4728] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000779b1401 2 bytes JMP 76e9eb26 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_launcher\releases\0.0.0.254\deploy\LoLLauncher.exe[4728] S:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000779b1419 2 bytes JMP 76eab513 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_launcher\releases\0.0.0.254\deploy\LoLLauncher.exe[4728] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000779b1431 2 bytes JMP 76f28609 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_launcher\releases\0.0.0.254\deploy\LoLLauncher.exe[4728] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000779b144a 2 bytes CALL 76e81dfa S:\Windows\syswow64\kernel32.dll
.text ... * 9
.text G:\Lol\RADS\projects\lol_launcher\releases\0.0.0.254\deploy\LoLLauncher.exe[4728] S:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000779b14dd 2 bytes JMP 76f27efe S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_launcher\releases\0.0.0.254\deploy\LoLLauncher.exe[4728] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000779b14f5 2 bytes JMP 76f280d8 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_launcher\releases\0.0.0.254\deploy\LoLLauncher.exe[4728] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000779b150d 2 bytes JMP 76f27df4 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_launcher\releases\0.0.0.254\deploy\LoLLauncher.exe[4728] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000779b1525 2 bytes JMP 76f281c2 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_launcher\releases\0.0.0.254\deploy\LoLLauncher.exe[4728] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000779b153d 2 bytes JMP 76e9f088 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_launcher\releases\0.0.0.254\deploy\LoLLauncher.exe[4728] S:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000779b1555 2 bytes JMP 76eab885 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_launcher\releases\0.0.0.254\deploy\LoLLauncher.exe[4728] S:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000779b156d 2 bytes JMP 76f286c1 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_launcher\releases\0.0.0.254\deploy\LoLLauncher.exe[4728] S:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000779b1585 2 bytes JMP 76f28222 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_launcher\releases\0.0.0.254\deploy\LoLLauncher.exe[4728] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000779b159d 2 bytes JMP 76f27db8 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_launcher\releases\0.0.0.254\deploy\LoLLauncher.exe[4728] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000779b15b5 2 bytes JMP 76e9f121 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_launcher\releases\0.0.0.254\deploy\LoLLauncher.exe[4728] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000779b15cd 2 bytes JMP 76eab29f S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_launcher\releases\0.0.0.254\deploy\LoLLauncher.exe[4728] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000779b16b2 2 bytes JMP 76f28584 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_launcher\releases\0.0.0.254\deploy\LoLLauncher.exe[4728] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000779b16bd 2 bytes JMP 76f27d4d S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_patcher\releases\0.0.0.38\deploy\LoLPatcher.exe[3456] S:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000076e8d03c 5 bytes [33, C0, C2, 04, 00]
.text G:\Lol\RADS\projects\lol_patcher\releases\0.0.0.38\deploy\LoLPatcher.exe[3456] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000779b1401 2 bytes JMP 76e9eb26 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_patcher\releases\0.0.0.38\deploy\LoLPatcher.exe[3456] S:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000779b1419 2 bytes JMP 76eab513 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_patcher\releases\0.0.0.38\deploy\LoLPatcher.exe[3456] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000779b1431 2 bytes JMP 76f28609 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_patcher\releases\0.0.0.38\deploy\LoLPatcher.exe[3456] S:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000779b144a 2 bytes CALL 76e81dfa S:\Windows\syswow64\kernel32.dll
.text ... * 9
.text G:\Lol\RADS\projects\lol_patcher\releases\0.0.0.38\deploy\LoLPatcher.exe[3456] S:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000779b14dd 2 bytes JMP 76f27efe S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_patcher\releases\0.0.0.38\deploy\LoLPatcher.exe[3456] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000779b14f5 2 bytes JMP 76f280d8 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_patcher\releases\0.0.0.38\deploy\LoLPatcher.exe[3456] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000779b150d 2 bytes JMP 76f27df4 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_patcher\releases\0.0.0.38\deploy\LoLPatcher.exe[3456] S:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000779b1525 2 bytes JMP 76f281c2 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_patcher\releases\0.0.0.38\deploy\LoLPatcher.exe[3456] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000779b153d 2 bytes JMP 76e9f088 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_patcher\releases\0.0.0.38\deploy\LoLPatcher.exe[3456] S:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000779b1555 2 bytes JMP 76eab885 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_patcher\releases\0.0.0.38\deploy\LoLPatcher.exe[3456] S:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000779b156d 2 bytes JMP 76f286c1 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_patcher\releases\0.0.0.38\deploy\LoLPatcher.exe[3456] S:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000779b1585 2 bytes JMP 76f28222 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_patcher\releases\0.0.0.38\deploy\LoLPatcher.exe[3456] S:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000779b159d 2 bytes JMP 76f27db8 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_patcher\releases\0.0.0.38\deploy\LoLPatcher.exe[3456] S:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000779b15b5 2 bytes JMP 76e9f121 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_patcher\releases\0.0.0.38\deploy\LoLPatcher.exe[3456] S:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000779b15cd 2 bytes JMP 76eab29f S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_patcher\releases\0.0.0.38\deploy\LoLPatcher.exe[3456] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000779b16b2 2 bytes JMP 76f28584 S:\Windows\syswow64\kernel32.dll
.text G:\Lol\RADS\projects\lol_patcher\releases\0.0.0.38\deploy\LoLPatcher.exe[3456] S:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000779b16bd 2 bytes JMP 76f27d4d S:\Windows\syswow64\kernel32.dll
---- Kernel code sections - GMER 2.1 ----
INITKDBG S:\Windows\system32\ntoskrnl.exe suspicious modification
INITKDBG S:\Windows\system32\ntoskrnl.exe suspicious modification
INITKDBG S:\Windows\system32\ntoskrnl.exe suspicious modification
INITKDBG S:\Windows\system32\ntoskrnl.exe suspicious modification
---- Threads - GMER 2.1 ----
Thread S:\Windows\system32\svchost.exe [1220:1756] 000007feff80a808
---- Processes - GMER 2.1 ----
Process S:\Users\Lucky\AppData\Roaming\uTorrent\uTorrent.exe (*** suspicious ***) @ S:\Users\Lucky\AppData\Roaming\uTorrent\uTorrent.exe [3512] (µTorrent/BitTorrent Inc.)(2014-04-19 22:30:51) 0000000000400000
Process S:\Users\Lucky\AppData\Local\Temp\nsb75CF.tmp (*** suspicious ***) @ S:\Users\Lucky\AppData\Local\Temp\nsb75CF.tmp [5252](2015-09-04 16:13: 0000000000400000
Process S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebHelper.exe (*** suspicious ***) @ S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebHelper.exe [3196] (SmartWeb helper/SoftBrain Technologies Ltd.)(2015-02-17 11:00:10) 0000000001180000
Process S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebApp.exe (*** suspicious ***) @ S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebApp.exe [5780] (SmartWeb Application/SoftBrain Technologies Ltd.)(2015-02-17 11:00:06) 0000000001380000
Library S:\Users\Lucky\AppData\Local\SmartWeb\swhk.dll (*** suspicious ***) @ S:\Users\Lucky\AppData\Local\SmartWeb\SmartWebApp.exe [5780] (SoftBrain Technologies Ltd.)(2015-02-17 11:00:06) 000000006d010000
Process S:\Users\Lucky\AppData\Local\gmsd_pl_005010080\upgmsd_pl_005010080.exe (*** suspicious ***) @ S:\Users\Lucky\AppData\Local\gmsd_pl_005010080\upgmsd_pl_005010080.exe [3208](2015-09-05 09:20:20) 0000000000bb0000
Process S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp (*** suspicious ***) @ S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp [6244] (Setup/CMI Limited)(2015-09-05 11:10:00) 0000000000400000
Library S:\Users\Lucky\AppData\Local\Temp\nsr1575.tmp\System.dll (*** suspicious ***) @ S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp [6244](2015-09-05 11:10:01) 0000000010000000
Library S:\Users\Lucky\AppData\Local\Temp\nsr1575.tmp\ProcessKiller.dll (*** suspicious ***) @ S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp [6244](2015-09-05 11:10:03) 00000000752d0000
Library S:\Users\Lucky\AppData\Local\Temp\nsr1575.tmp\nsis-progressbar.dll (*** suspicious ***) @ S:\Users\Lucky\AppData\Local\Temp\nsx1037.tmp [6244](2015-09-05 11:10:03) 00000000734a0000
---- Registry - GMER 2.1 ----
Reg HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted@\24:\Users\Lucky\Desktop\ComboFix.exe 1
---- EOF - GMER 2.1 ----