GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-05-23 01:15:47 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD32 rev.01.0 298,09GB Running: jhnmqgsg.exe; Driver: C:\Users\Ania\AppData\Local\Temp\kwlyiuod.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1916] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074e21401 2 bytes JMP 769cb21b C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1916] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074e21419 2 bytes JMP 769cb346 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1916] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074e21431 2 bytes JMP 76a48f29 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1916] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074e2144a 2 bytes CALL 769a489d C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1916] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074e214dd 2 bytes JMP 76a48822 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1916] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074e214f5 2 bytes JMP 76a489f8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1916] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074e2150d 2 bytes JMP 76a48718 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1916] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074e21525 2 bytes JMP 76a48ae2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1916] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074e2153d 2 bytes JMP 769bfca8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1916] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074e21555 2 bytes JMP 769c68ef C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1916] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074e2156d 2 bytes JMP 76a48fe3 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1916] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074e21585 2 bytes JMP 76a48b42 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1916] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074e2159d 2 bytes JMP 76a486dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1916] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074e215b5 2 bytes JMP 769bfd41 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1916] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074e215cd 2 bytes JMP 769cb2dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1916] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074e216b2 2 bytes JMP 76a48ea4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[1916] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074e216bd 2 bytes JMP 76a48671 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[1096] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074e21401 2 bytes JMP 769cb21b C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[1096] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074e21419 2 bytes JMP 769cb346 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[1096] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074e21431 2 bytes JMP 76a48f29 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[1096] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074e2144a 2 bytes CALL 769a489d C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[1096] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074e214dd 2 bytes JMP 76a48822 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[1096] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074e214f5 2 bytes JMP 76a489f8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[1096] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074e2150d 2 bytes JMP 76a48718 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[1096] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074e21525 2 bytes JMP 76a48ae2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[1096] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074e2153d 2 bytes JMP 769bfca8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[1096] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074e21555 2 bytes JMP 769c68ef C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[1096] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074e2156d 2 bytes JMP 76a48fe3 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[1096] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074e21585 2 bytes JMP 76a48b42 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[1096] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074e2159d 2 bytes JMP 76a486dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[1096] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074e215b5 2 bytes JMP 769bfd41 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[1096] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074e215cd 2 bytes JMP 769cb2dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[1096] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074e216b2 2 bytes JMP 76a48ea4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe[1096] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074e216bd 2 bytes JMP 76a48671 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugincontainer.exe[4612] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074e21401 2 bytes JMP 769cb21b C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugincontainer.exe[4612] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074e21419 2 bytes JMP 769cb346 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugincontainer.exe[4612] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074e21431 2 bytes JMP 76a48f29 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugincontainer.exe[4612] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074e2144a 2 bytes CALL 769a489d C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugincontainer.exe[4612] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074e214dd 2 bytes JMP 76a48822 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugincontainer.exe[4612] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074e214f5 2 bytes JMP 76a489f8 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugincontainer.exe[4612] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074e2150d 2 bytes JMP 76a48718 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugincontainer.exe[4612] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074e21525 2 bytes JMP 76a48ae2 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugincontainer.exe[4612] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074e2153d 2 bytes JMP 769bfca8 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugincontainer.exe[4612] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074e21555 2 bytes JMP 769c68ef C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugincontainer.exe[4612] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074e2156d 2 bytes JMP 76a48fe3 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugincontainer.exe[4612] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074e21585 2 bytes JMP 76a48b42 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugincontainer.exe[4612] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074e2159d 2 bytes JMP 76a486dc C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugincontainer.exe[4612] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074e215b5 2 bytes JMP 769bfd41 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugincontainer.exe[4612] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074e215cd 2 bytes JMP 769cb2dc C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugincontainer.exe[4612] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074e216b2 2 bytes JMP 76a48ea4 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugincontainer.exe[4612] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074e216bd 2 bytes JMP 76a48671 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[4152] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074e21401 2 bytes JMP 769cb21b C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[4152] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074e21419 2 bytes JMP 769cb346 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[4152] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074e21431 2 bytes JMP 76a48f29 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[4152] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074e2144a 2 bytes CALL 769a489d C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[4152] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074e214dd 2 bytes JMP 76a48822 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[4152] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074e214f5 2 bytes JMP 76a489f8 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[4152] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074e2150d 2 bytes JMP 76a48718 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[4152] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074e21525 2 bytes JMP 76a48ae2 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[4152] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074e2153d 2 bytes JMP 769bfca8 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[4152] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074e21555 2 bytes JMP 769c68ef C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[4152] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074e2156d 2 bytes JMP 76a48fe3 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[4152] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074e21585 2 bytes JMP 76a48b42 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[4152] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074e2159d 2 bytes JMP 76a486dc C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[4152] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074e215b5 2 bytes JMP 769bfd41 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[4152] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074e215cd 2 bytes JMP 769cb2dc C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[4152] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074e216b2 2 bytes JMP 76a48ea4 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[4152] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074e216bd 2 bytes JMP 76a48671 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[3480] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074e21401 2 bytes JMP 769cb21b C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[3480] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074e21419 2 bytes JMP 769cb346 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[3480] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074e21431 2 bytes JMP 76a48f29 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[3480] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074e2144a 2 bytes CALL 769a489d C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[3480] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074e214dd 2 bytes JMP 76a48822 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[3480] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074e214f5 2 bytes JMP 76a489f8 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[3480] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074e2150d 2 bytes JMP 76a48718 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[3480] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074e21525 2 bytes JMP 76a48ae2 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[3480] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074e2153d 2 bytes JMP 769bfca8 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[3480] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074e21555 2 bytes JMP 769c68ef C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[3480] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074e2156d 2 bytes JMP 76a48fe3 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[3480] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074e21585 2 bytes JMP 76a48b42 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[3480] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074e2159d 2 bytes JMP 76a486dc C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[3480] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074e215b5 2 bytes JMP 769bfd41 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[3480] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074e215cd 2 bytes JMP 769cb2dc C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[3480] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074e216b2 2 bytes JMP 76a48ea4 C:\Windows\syswow64\kernel32.dll .text C:\ProgramData\322cb724-1680-423d-8862-1b52ca5027ad\plugins\3\plugin.exe[3480] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074e216bd 2 bytes JMP 76a48671 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\322cb724-1680-423d-8862-1b52ca5027ad\updater.exe[4324] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000074e21401 2 bytes JMP 769cb21b C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\322cb724-1680-423d-8862-1b52ca5027ad\updater.exe[4324] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000074e21419 2 bytes JMP 769cb346 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\322cb724-1680-423d-8862-1b52ca5027ad\updater.exe[4324] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000074e21431 2 bytes JMP 76a48f29 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\322cb724-1680-423d-8862-1b52ca5027ad\updater.exe[4324] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000074e2144a 2 bytes CALL 769a489d C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Common Files\322cb724-1680-423d-8862-1b52ca5027ad\updater.exe[4324] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000074e214dd 2 bytes JMP 76a48822 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\322cb724-1680-423d-8862-1b52ca5027ad\updater.exe[4324] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000074e214f5 2 bytes JMP 76a489f8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\322cb724-1680-423d-8862-1b52ca5027ad\updater.exe[4324] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000074e2150d 2 bytes JMP 76a48718 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\322cb724-1680-423d-8862-1b52ca5027ad\updater.exe[4324] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000074e21525 2 bytes JMP 76a48ae2 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\322cb724-1680-423d-8862-1b52ca5027ad\updater.exe[4324] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000074e2153d 2 bytes JMP 769bfca8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\322cb724-1680-423d-8862-1b52ca5027ad\updater.exe[4324] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000074e21555 2 bytes JMP 769c68ef C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\322cb724-1680-423d-8862-1b52ca5027ad\updater.exe[4324] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000074e2156d 2 bytes JMP 76a48fe3 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\322cb724-1680-423d-8862-1b52ca5027ad\updater.exe[4324] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000074e21585 2 bytes JMP 76a48b42 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\322cb724-1680-423d-8862-1b52ca5027ad\updater.exe[4324] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000074e2159d 2 bytes JMP 76a486dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\322cb724-1680-423d-8862-1b52ca5027ad\updater.exe[4324] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000074e215b5 2 bytes JMP 769bfd41 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\322cb724-1680-423d-8862-1b52ca5027ad\updater.exe[4324] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000074e215cd 2 bytes JMP 769cb2dc C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\322cb724-1680-423d-8862-1b52ca5027ad\updater.exe[4324] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000074e216b2 2 bytes JMP 76a48ea4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Common Files\322cb724-1680-423d-8862-1b52ca5027ad\updater.exe[4324] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000074e216bd 2 bytes JMP 76a48671 C:\Windows\syswow64\kernel32.dll ---- Processes - GMER 2.1 ---- Library C:\ProgramData\Mobile Partner\OnlineUpdate\mingwm10.dll (*** suspicious ***) @ C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe [1836](2014-07-12 10:58:57) 000000006fbc0000 Library C:\ProgramData\Mobile Partner\OnlineUpdate\libgcc_s_dw2-1.dll (*** suspicious ***) @ C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe [1836](2014-07-12 10:58:57) 000000006e940000 Library C:\ProgramData\Mobile Partner\OnlineUpdate\QtCore4.dll (*** suspicious ***) @ C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe [1836](2014-07-12 10:58:57) 000000006a1c0000 Library C:\ProgramData\Mobile Partner\OnlineUpdate\QtNetwork4.dll (*** suspicious ***) @ C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe [1836](2014-07-12 10:58:57) 000000006ff00000 Library C:\ProgramData\Mobile Partner\OnlineUpdate\QueryStrategy.dll (*** suspicious ***) @ C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe [1836](2014-07-12 10:58:57) 000000006efc0000 Library C:\ProgramData\Mobile Partner\OnlineUpdate\QtXml4.dll (*** suspicious ***) @ C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe [1836](2014-07-12 10:58:57) 000000006ed40000 Process C:\Users\Ania\AppData\Local\Temp\system.exe (*** suspicious ***) @ C:\Users\Ania\AppData\Local\Temp\system.exe [3988](2015-01-28 23:30:40) 0000000000400000 Process C:\Users\Ania\AppData\Local\Temp\Rar$EXa0.530\jhnmqgsg.exe (*** suspicious ***) @ C:\Users\Ania\AppData\Local\Temp\Rar$EXa0.530\jhnmqgsg.exe [2304](2015-02-04 12:59:56) 0000000000400000 ---- EOF - GMER 2.1 ----