Rheingold | 31.01.2013 17:48 | Habe ich gemacht. Hier das Ergebnis!
Uuups, das sind zu viele Zeichen. Ich poste das jetzt einfach in zwei Teilen.
:dankeschoen: Code:
GMER 2.0.18454 - http://www.gmer.net
Rootkit scan 2013-01-31 17:41:07
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST9500420AS rev.D005SDM1 465,76GB
Running: gmer_2.0.18454.exe; Driver: C:\Users\JASMIN~1.NIC\AppData\Local\Temp\awliyfob.sys
---- Kernel code sections - GMER 2.0 ----
.text C:\Windows\system32\DRIVERS\USBPORT.SYS!DllUnload fffff8800ff6fd64 12 bytes {MOV RAX, 0xfffffa80055422a0; JMP RAX}
---- User code sections - GMER 2.0 ----
.text C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075811401 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe[1860] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075811419 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075811431 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007581144a 2 bytes [81, 75]
.text ... * 9
.text C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe[1860] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000758114dd 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000758114f5 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe[1860] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007581150d 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075811525 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007581153d 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe[1860] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075811555 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007581156d 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075811585 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe[1860] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007581159d 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000758115b5 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000758115cd 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000758116b2 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe[1860] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000758116bd 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075811401 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe[1928] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075811419 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075811431 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007581144a 2 bytes [81, 75]
.text ... * 9
.text C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe[1928] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000758114dd 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000758114f5 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe[1928] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007581150d 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075811525 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007581153d 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe[1928] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075811555 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007581156d 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075811585 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe[1928] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007581159d 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000758115b5 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000758115cd 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000758116b2 2 bytes [81, 75]
.text C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe[1928] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000758116bd 2 bytes [81, 75]
.text D:\Tobit Radio.fx\Server\rfx-server.exe[1520] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000075fd87b1 5 bytes JMP 0000000100641870
.text D:\Tobit Radio.fx\Server\rfx-server.exe[1520] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075811401 2 bytes [81, 75]
.text D:\Tobit Radio.fx\Server\rfx-server.exe[1520] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075811419 2 bytes [81, 75]
.text D:\Tobit Radio.fx\Server\rfx-server.exe[1520] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075811431 2 bytes [81, 75]
.text D:\Tobit Radio.fx\Server\rfx-server.exe[1520] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007581144a 2 bytes [81, 75]
.text ... * 9
.text D:\Tobit Radio.fx\Server\rfx-server.exe[1520] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000758114dd 2 bytes [81, 75]
.text D:\Tobit Radio.fx\Server\rfx-server.exe[1520] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000758114f5 2 bytes [81, 75]
.text D:\Tobit Radio.fx\Server\rfx-server.exe[1520] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007581150d 2 bytes [81, 75]
.text D:\Tobit Radio.fx\Server\rfx-server.exe[1520] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075811525 2 bytes [81, 75]
.text D:\Tobit Radio.fx\Server\rfx-server.exe[1520] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007581153d 2 bytes [81, 75]
.text D:\Tobit Radio.fx\Server\rfx-server.exe[1520] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075811555 2 bytes [81, 75]
.text D:\Tobit Radio.fx\Server\rfx-server.exe[1520] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007581156d 2 bytes [81, 75]
.text D:\Tobit Radio.fx\Server\rfx-server.exe[1520] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075811585 2 bytes [81, 75]
.text D:\Tobit Radio.fx\Server\rfx-server.exe[1520] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007581159d 2 bytes [81, 75]
.text D:\Tobit Radio.fx\Server\rfx-server.exe[1520] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000758115b5 2 bytes [81, 75]
.text D:\Tobit Radio.fx\Server\rfx-server.exe[1520] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000758115cd 2 bytes [81, 75]
.text D:\Tobit Radio.fx\Server\rfx-server.exe[1520] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000758116b2 2 bytes [81, 75]
.text D:\Tobit Radio.fx\Server\rfx-server.exe[1520] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000758116bd 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075811401 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[1732] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075811419 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075811431 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007581144a 2 bytes [81, 75]
.text ... * 9
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[1732] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000758114dd 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000758114f5 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[1732] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007581150d 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075811525 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007581153d 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[1732] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075811555 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007581156d 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075811585 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[1732] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007581159d 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000758115b5 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000758115cd 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000758116b2 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\PSIA.exe[1732] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000758116bd 2 bytes [81, 75]
.text C:\Windows\system32\taskhost.exe[2368] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 357 000007fefd349aa5 3 bytes [65, 65, 06]
.text C:\Windows\SysWOW64\cchservice.exe[2648] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075811401 2 bytes [81, 75]
.text C:\Windows\SysWOW64\cchservice.exe[2648] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075811419 2 bytes [81, 75]
.text C:\Windows\SysWOW64\cchservice.exe[2648] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075811431 2 bytes [81, 75]
.text C:\Windows\SysWOW64\cchservice.exe[2648] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007581144a 2 bytes [81, 75]
.text ... * 9
.text C:\Windows\SysWOW64\cchservice.exe[2648] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000758114dd 2 bytes [81, 75]
.text C:\Windows\SysWOW64\cchservice.exe[2648] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000758114f5 2 bytes [81, 75]
.text C:\Windows\SysWOW64\cchservice.exe[2648] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007581150d 2 bytes [81, 75]
.text C:\Windows\SysWOW64\cchservice.exe[2648] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075811525 2 bytes [81, 75]
.text C:\Windows\SysWOW64\cchservice.exe[2648] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007581153d 2 bytes [81, 75]
.text C:\Windows\SysWOW64\cchservice.exe[2648] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075811555 2 bytes [81, 75]
.text C:\Windows\SysWOW64\cchservice.exe[2648] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007581156d 2 bytes [81, 75]
.text C:\Windows\SysWOW64\cchservice.exe[2648] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075811585 2 bytes [81, 75]
.text C:\Windows\SysWOW64\cchservice.exe[2648] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007581159d 2 bytes [81, 75]
.text C:\Windows\SysWOW64\cchservice.exe[2648] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000758115b5 2 bytes [81, 75]
.text C:\Windows\SysWOW64\cchservice.exe[2648] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000758115cd 2 bytes [81, 75]
.text C:\Windows\SysWOW64\cchservice.exe[2648] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000758116b2 2 bytes [81, 75]
.text C:\Windows\SysWOW64\cchservice.exe[2648] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000758116bd 2 bytes [81, 75]
.text C:\Windows\system32\Dwm.exe[2708] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 357 000007fefd349aa5 3 bytes [65, 65, 21]
.text C:\Windows\Explorer.EXE[2704] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 357 000007fefd349aa5 3 bytes [65, 65, 06]
.text C:\Windows\System32\hkcmd.exe[3452] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 357 000007fefd349aa5 3 bytes [65, 65, 06]
.text C:\Windows\System32\igfxpers.exe[3460] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 357 000007fefd349aa5 3 bytes [65, 65, 82]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3528] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 357 000007fefd349aa5 3 bytes [65, 65, 06]
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[3640] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 357 000007fefd349aa5 3 bytes [65, 65, 06]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3888] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 357 000007fefd349aa5 3 bytes [65, 65, 06]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3268] C:\Windows\syswow64\kernel32.dll!TerminateThread 0000000075fd7a17 6 bytes {JMP QWORD [RIP+0x71a6001e]}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3268] C:\Windows\syswow64\kernel32.dll!TerminateProcess 0000000075fed7ea 6 bytes {JMP QWORD [RIP+0x71ac001e]}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3268] C:\Windows\syswow64\kernel32.dll!SuspendThread 0000000075ff7d66 6 bytes {JMP QWORD [RIP+0x71a3001e]}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3268] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW + 493 0000000075312c91 4 bytes {CALL QWORD [RIP+0x1e000a]}
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3268] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075811401 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3268] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075811419 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3268] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075811431 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3268] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007581144a 2 bytes [81, 75]
.text ... * 9
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3268] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000758114dd 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3268] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000758114f5 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3268] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007581150d 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3268] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075811525 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3268] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007581153d 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3268] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075811555 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3268] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007581156d 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3268] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075811585 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3268] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007581159d 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3268] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000758115b5 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3268] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000758115cd 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3268] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000758116b2 2 bytes [81, 75]
.text C:\Program Files (x86)\Secunia\PSI\psi_tray.exe[3268] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000758116bd 2 bytes [81, 75]
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[3480] C:\Windows\syswow64\kernel32.dll!TerminateThread 0000000075fd7a17 6 bytes {JMP QWORD [RIP+0x71a6001e]}
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[3480] C:\Windows\syswow64\kernel32.dll!TerminateProcess 0000000075fed7ea 6 bytes {JMP QWORD [RIP+0x71ac001e]}
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[3480] C:\Windows\syswow64\kernel32.dll!SuspendThread 0000000075ff7d66 6 bytes {JMP QWORD [RIP+0x71a3001e]}
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[3480] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW + 493 0000000075312c91 4 bytes {CALL QWORD [RIP+0x26000a]}
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[2912] C:\Windows\syswow64\kernel32.dll!TerminateThread 0000000075fd7a17 6 bytes {JMP QWORD [RIP+0x71a7001e]}
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[2912] C:\Windows\syswow64\kernel32.dll!TerminateProcess 0000000075fed7ea 6 bytes {JMP QWORD [RIP+0x71ad001e]}
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[2912] C:\Windows\syswow64\kernel32.dll!SuspendThread 0000000075ff7d66 6 bytes {JMP QWORD [RIP+0x71a4001e]}
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[2912] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW + 493 0000000075312c91 4 bytes {CALL QWORD [RIP+0x2fc000a]}
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[2912] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075811401 2 bytes [81, 75]
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[2912] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075811419 2 bytes [81, 75]
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[2912] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075811431 2 bytes [81, 75]
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[2912] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007581144a 2 bytes [81, 75]
.text ... * 9
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[2912] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000758114dd 2 bytes [81, 75]
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[2912] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000758114f5 2 bytes [81, 75]
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[2912] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007581150d 2 bytes [81, 75]
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[2912] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075811525 2 bytes [81, 75]
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[2912] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007581153d 2 bytes [81, 75]
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[2912] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075811555 2 bytes [81, 75]
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[2912] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007581156d 2 bytes [81, 75]
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[2912] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075811585 2 bytes [81, 75]
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[2912] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007581159d 2 bytes [81, 75]
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[2912] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000758115b5 2 bytes [81, 75]
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[2912] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000758115cd 2 bytes [81, 75]
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[2912] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000758116b2 2 bytes [81, 75]
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[2912] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000758116bd 2 bytes [81, 75]
.text C:\Program Files\Update\realsched.exe[3232] C:\Windows\syswow64\kernel32.dll!TerminateThread 0000000075fd7a17 6 bytes {JMP QWORD [RIP+0x71a8001e]}
.text C:\Program Files\Update\realsched.exe[3232] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000075fd87b1 5 bytes [33, C0, C2, 04, 00]
.text C:\Program Files\Update\realsched.exe[3232] C:\Windows\syswow64\kernel32.dll!TerminateProcess 0000000075fed7ea 6 bytes {JMP QWORD [RIP+0x71ae001e]}
.text C:\Program Files\Update\realsched.exe[3232] C:\Windows\syswow64\kernel32.dll!SuspendThread 0000000075ff7d66 6 bytes {JMP QWORD [RIP+0x71a5001e]}
.text C:\Windows\System32\spool\drivers\x64\3\EKIJ5000MUI.exe[148] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 357 000007fefd349aa5 3 bytes [65, 65, 06]
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[3704] C:\Windows\syswow64\kernel32.dll!TerminateThread 0000000075fd7a17 6 bytes {JMP QWORD [RIP+0x71a8001e]}
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[3704] C:\Windows\syswow64\kernel32.dll!TerminateProcess 0000000075fed7ea 6 bytes {JMP QWORD [RIP+0x71ae001e]}
.text C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe[3704] C:\Windows\syswow64\kernel32.dll!SuspendThread 0000000075ff7d66 6 bytes {JMP QWORD [RIP+0x71a5001e]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4616] C:\Windows\syswow64\kernel32.dll!TerminateThread 0000000075fd7a17 6 bytes {JMP QWORD [RIP+0x71a0001e]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4616] C:\Windows\syswow64\kernel32.dll!TerminateProcess 0000000075fed7ea 6 bytes {JMP QWORD [RIP+0x71ac001e]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4616] C:\Windows\syswow64\kernel32.dll!SuspendThread 0000000075ff7d66 6 bytes {JMP QWORD [RIP+0x719d001e]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4616] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW + 493 0000000075312c91 4 bytes {CALL QWORD [RIP+0x57000a]}
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4616] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075811401 2 bytes [81, 75]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4616] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075811419 2 bytes [81, 75]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4616] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075811431 2 bytes [81, 75]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4616] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007581144a 2 bytes [81, 75]
.text ... * 9
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4616] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000758114dd 2 bytes [81, 75]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4616] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000758114f5 2 bytes [81, 75]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4616] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007581150d 2 bytes [81, 75]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4616] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075811525 2 bytes [81, 75]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4616] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007581153d 2 bytes [81, 75]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4616] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075811555 2 bytes [81, 75]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4616] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007581156d 2 bytes [81, 75]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4616] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075811585 2 bytes [81, 75]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4616] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007581159d 2 bytes [81, 75]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4616] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000758115b5 2 bytes [81, 75]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4616] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000758115cd 2 bytes [81, 75]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4616] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000758116b2 2 bytes [81, 75]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[4616] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000758116bd 2 bytes [81, 75]
---- Kernel IAT/EAT - GMER 2.0 ----
IAT C:\Windows\system32\drivers\pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [fffff880010bb650] \SystemRoot\System32\Drivers\sprn.sys [unknown section]
IAT C:\Windows\system32\drivers\pci.sys[ntoskrnl.exe!IoDetachDevice] [fffff880010bb5dc] \SystemRoot\System32\Drivers\sprn.sys [unknown section]
IAT C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [fffff8800108635c] \SystemRoot\System32\Drivers\sprn.sys [unknown section]
IAT C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [fffff88001086224] \SystemRoot\System32\Drivers\sprn.sys [unknown section]
IAT C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [fffff88001086a24] \SystemRoot\System32\Drivers\sprn.sys [unknown section]
IAT C:\Windows\system32\drivers\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [fffff88001086ba0] \SystemRoot\System32\Drivers\sprn.sys [unknown section]
---- User IAT/EAT - GMER 2.0 ----
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\system32\taskhost.exe[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\system32\GDI32.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\system32\USER32.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\system32\OLEAUT32.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\system32\OLEAUT32.dll[KERNEL32.dll!TerminateThread] [80030000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\system32\IMM32.DLL[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\system32\dwmapi.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\system32\dwmapi.dll[KERNEL32.dll!TerminateThread] [80030000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\system32\CLBCatQ.DLL[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\system32\WINSTA.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\System32\PlaySndSrv.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\system32\WINMM.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\system32\SHLWAPI.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\System32\nlaapi.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\system32\rsaenh.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\system32\dsrole.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\system32\MMDevAPI.DLL[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\system32\PROPSYS.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\system32\wdmaud.drv[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\system32\CFGMGR32.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\system32\AUDIOSES.DLL[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\system32\msacm32.drv[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\taskhost.exe[2368] @ C:\Windows\system32\midimap.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2664] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppId] [7fef71a2750] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2664] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetMachineId] [7fef71a2b98] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2664] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmWriteSharedMachineId] [7fef71a7de0] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2664] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmCreateNewId] [7fef71a8130] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2664] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmReadSharedMachineId] [7fef71a1908] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2664] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmGetSession] [7fef71a1c00] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2664] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartUpload] [7fef71a81d8] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2664] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSet] [7fef71a2878] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2664] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamString] [7fef71a7a5c] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2664] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmIncrement] [7fef71a6c48] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2664] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmAddToStreamDWord] [7fef71a77bc] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2664] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmSetAppVersion] [7fef71a7064] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2664] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmStartSession] [7fef71a6544] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[2664] @ C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[sqmapi.dll!SqmEndSession] [7fef71a5e30] C:\Program Files\Common Files\Microsoft Shared\Windows Live\sqmapi.dll
IAT C:\Windows\system32\Dwm.exe[2708] @ C:\Windows\system32\Dwm.exe[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\Dwm.exe[2708] @ C:\Windows\system32\Dwm.exe[KERNEL32.dll!TerminateThread] [80030000]
IAT C:\Windows\system32\Dwm.exe[2708] @ C:\Windows\system32\GDI32.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\Dwm.exe[2708] @ C:\Windows\system32\USER32.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\Dwm.exe[2708] @ C:\Windows\system32\IMM32.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\Dwm.exe[2708] @ C:\Windows\system32\dwmredir.dll[KERNEL32.dll!TerminateThread] [80030000]
IAT C:\Windows\system32\Dwm.exe[2708] @ C:\Windows\system32\dwmredir.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\Dwm.exe[2708] @ C:\Windows\system32\dwmcore.dll[KERNEL32.dll!TerminateThread] [80030000]
IAT C:\Windows\system32\Dwm.exe[2708] @ C:\Windows\system32\dwmcore.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\Dwm.exe[2708] @ C:\Windows\system32\WindowsCodecs.dll[KERNEL32.dll!TerminateThread] [80030000]
IAT C:\Windows\system32\Dwm.exe[2708] @ C:\Windows\system32\WindowsCodecs.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\Dwm.exe[2708] @ C:\Windows\system32\d3d10_1.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\Dwm.exe[2708] @ C:\Windows\system32\d3d10_1core.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\Dwm.exe[2708] @ C:\Windows\system32\dxgi.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\Dwm.exe[2708] @ C:\Windows\system32\VERSION.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\Dwm.exe[2708] @ C:\Windows\system32\dwmapi.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\Dwm.exe[2708] @ C:\Windows\system32\dwmapi.dll[KERNEL32.dll!TerminateThread] [80030000]
IAT C:\Windows\system32\Dwm.exe[2708] @ C:\Windows\system32\PSAPI.DLL[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\Dwm.exe[2708] @ C:\Windows\system32\uDWM.dll[KERNEL32.dll!TerminateThread] [80030000]
IAT C:\Windows\system32\Dwm.exe[2708] @ C:\Windows\system32\uDWM.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\system32\Dwm.exe[2708] @ C:\Windows\system32\SHLWAPI.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\Explorer.EXE[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\Explorer.EXE[KERNEL32.dll!TerminateThread] [80030000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\GDI32.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\USER32.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\SHLWAPI.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\OLEAUT32.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\OLEAUT32.dll[KERNEL32.dll!TerminateThread] [80030000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\EXPLORERFRAME.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\DUser.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\DUI70.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\IMM32.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\CFGMGR32.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\dwmapi.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\dwmapi.dll[KERNEL32.dll!TerminateThread] [80030000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_2b253c8271ec7765\gdiplus.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\Secur32.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\PROPSYS.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\WINSTA.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\WindowsCodecs.dll[KERNEL32.dll!TerminateThread] [80030000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\WindowsCodecs.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\apphelp.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\CLBCatQ.DLL[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\EhStorShell.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\ntshrui.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\srvcli.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\IconCodecService.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\rsaenh.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\SndVolSSO.DLL[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\HID.DLL[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\System32\MMDevApi.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\timedate.cpl[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\ATL.DLL[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\actxprxy.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\ntmarta.dll[KERNEL32.dll!TerminateThread] [80030000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\ntmarta.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\WLDAP32.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\System32\shdocvw.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\LINKINFO.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\System32\gameux.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\System32\XmlLite.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\System32\wer.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Windows\system32\msls31.dll[KERNEL32.dll!TerminateProcess] [80000000]
IAT C:\Windows\Explorer.EXE[2704] @ C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll[KERNEL32.dll!TerminateProcess] |