
- Kod: Zaznacz wszystko
-
GMER 2.1.19355 - http://www.gmer.net
Rootkit scan 2014-01-24 14:22:28
Windows 6.0.6002 Service Pack 2 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 TOSHIBA_MK1237GSX rev.DL130M 111,79GB
Running: 5lthwjij.exe; Driver: C:\Users\kasia\AppData\Local\Temp\kwtoqpod.sys
--- Kernel code sections - GMER 2.1 ----
? C:\Windows\system32\cpuvis.sys Nie można odnaleźć określonego pliku. !
---- User code sections - GMER 2.1 ----
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtCreateFile + 6 76EE426A 4 Bytes [28, 54, 81, 00] {SUB [ECX+EAX*4+0x0], DL}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtCreateFile + B 76EE426F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtMapViewOfSection + 6 76EE49BA 4 Bytes [28, 57, 81, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtMapViewOfSection + B 76EE49BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenFile + 6 76EE4A4A 4 Bytes [68, 54, 81, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenFile + B 76EE4A4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenProcess + 6 76EE4ACA 4 Bytes [A8, 55, 81, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenProcess + B 76EE4ACF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenProcessToken + 6 76EE4ADA 4 Bytes CALL 75EECC34
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenProcessToken + B 76EE4ADF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenProcessTokenEx + 6 76EE4AEA 4 Bytes [A8, 56, 81, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenProcessTokenEx + B 76EE4AEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenThread + 6 76EE4B3A 4 Bytes [68, 55, 81, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenThread + B 76EE4B3F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenThreadToken + 6 76EE4B4A 4 Bytes [68, 56, 81, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenThreadToken + B 76EE4B4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenThreadTokenEx + 6 76EE4B5A 4 Bytes CALL 75EECCB5
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtOpenThreadTokenEx + B 76EE4B5F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtQueryAttributesFile + 6 76EE4BEA 4 Bytes [A8, 54, 81, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtQueryAttributesFile + B 76EE4BEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtQueryFullAttributesFile + 6 76EE4C9A 4 Bytes CALL 75EECDF3
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtQueryFullAttributesFile + B 76EE4C9F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtSetInformationFile + 6 76EE517A 4 Bytes [28, 55, 81, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtSetInformationFile + B 76EE517F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtSetInformationThread + 6 76EE51CA 4 Bytes [28, 56, 81, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtSetInformationThread + B 76EE51CF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtUnmapViewOfSection + 6 76EE546A 4 Bytes [68, 57, 81, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1224] ntdll.dll!NtUnmapViewOfSection + B 76EE546F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtCreateFile + 6 76EE426A 4 Bytes [28, D8, 3E, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtCreateFile + B 76EE426F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtMapViewOfSection + 6 76EE49BA 4 Bytes [28, DB, 3E, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtMapViewOfSection + B 76EE49BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtOpenFile + 6 76EE4A4A 4 Bytes [68, D8, 3E, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtOpenFile + B 76EE4A4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtOpenProcess + 6 76EE4ACA 4 Bytes [A8, D9, 3E, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtOpenProcess + B 76EE4ACF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtOpenProcessToken + 6 76EE4ADA 4 Bytes CALL 75EE89B8 C:\Windows\system32\SHLWAPI.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtOpenProcessToken + B 76EE4ADF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtOpenProcessTokenEx + 6 76EE4AEA 4 Bytes [A8, DA, 3E, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtOpenProcessTokenEx + B 76EE4AEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtOpenThread + 6 76EE4B3A 4 Bytes [68, D9, 3E, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtOpenThread + B 76EE4B3F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtOpenThreadToken + 6 76EE4B4A 4 Bytes [68, DA, 3E, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtOpenThreadToken + B 76EE4B4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtOpenThreadTokenEx + 6 76EE4B5A 4 Bytes CALL 75EE8A39 C:\Windows\system32\SHLWAPI.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtOpenThreadTokenEx + B 76EE4B5F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtQueryAttributesFile + 6 76EE4BEA 4 Bytes [A8, D8, 3E, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtQueryAttributesFile + B 76EE4BEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtQueryFullAttributesFile + 6 76EE4C9A 4 Bytes CALL 75EE8B77 C:\Windows\system32\SHLWAPI.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtQueryFullAttributesFile + B 76EE4C9F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtSetInformationFile + 6 76EE517A 4 Bytes [28, D9, 3E, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtSetInformationFile + B 76EE517F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtSetInformationThread + 6 76EE51CA 4 Bytes [28, DA, 3E, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtSetInformationThread + B 76EE51CF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtUnmapViewOfSection + 6 76EE546A 4 Bytes [68, DB, 3E, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[1944] ntdll.dll!NtUnmapViewOfSection + B 76EE546F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtCreateFile + 6 76EE426A 4 Bytes [28, 48, FF, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtCreateFile + B 76EE426F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtMapViewOfSection + 6 76EE49BA 4 Bytes [28, 4B, FF, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtMapViewOfSection + B 76EE49BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtOpenFile + 6 76EE4A4A 4 Bytes [68, 48, FF, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtOpenFile + B 76EE4A4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtOpenProcess + 6 76EE4ACA 4 Bytes [A8, 49, FF, 00] {TEST AL, 0x49; INC DWORD [EAX]}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtOpenProcess + B 76EE4ACF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtOpenProcessToken + 6 76EE4ADA 4 Bytes CALL 75EF4A28 C:\Windows\system32\urlmon.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtOpenProcessToken + B 76EE4ADF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtOpenProcessTokenEx + 6 76EE4AEA 4 Bytes [A8, 4A, FF, 00] {TEST AL, 0x4a; INC DWORD [EAX]}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtOpenProcessTokenEx + B 76EE4AEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtOpenThread + 6 76EE4B3A 4 Bytes [68, 49, FF, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtOpenThread + B 76EE4B3F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtOpenThreadToken + 6 76EE4B4A 4 Bytes [68, 4A, FF, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtOpenThreadToken + B 76EE4B4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtOpenThreadTokenEx + 6 76EE4B5A 4 Bytes CALL 75EF4AA9 C:\Windows\system32\urlmon.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtOpenThreadTokenEx + B 76EE4B5F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtQueryAttributesFile + 6 76EE4BEA 4 Bytes [A8, 48, FF, 00] {TEST AL, 0x48; INC DWORD [EAX]}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtQueryAttributesFile + B 76EE4BEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtQueryFullAttributesFile + 6 76EE4C9A 4 Bytes CALL 75EF4BE7 C:\Windows\system32\urlmon.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtQueryFullAttributesFile + B 76EE4C9F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtSetInformationFile + 6 76EE517A 4 Bytes [28, 49, FF, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtSetInformationFile + B 76EE517F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtSetInformationThread + 6 76EE51CA 4 Bytes [28, 4A, FF, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtSetInformationThread + B 76EE51CF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtUnmapViewOfSection + 6 76EE546A 4 Bytes [68, 4B, FF, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2696] ntdll.dll!NtUnmapViewOfSection + B 76EE546F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtCreateFile + 6 76EE426A 4 Bytes [28, 2C, 99, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtCreateFile + B 76EE426F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtMapViewOfSection + 6 76EE49BA 4 Bytes [28, 2F, 99, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtMapViewOfSection + B 76EE49BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtOpenFile + 6 76EE4A4A 4 Bytes [68, 2C, 99, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtOpenFile + B 76EE4A4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtOpenProcess + 6 76EE4ACA 4 Bytes [A8, 2D, 99, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtOpenProcess + B 76EE4ACF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtOpenProcessToken + 6 76EE4ADA 4 Bytes CALL 75EEE40C
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtOpenProcessToken + B 76EE4ADF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtOpenProcessTokenEx + 6 76EE4AEA 4 Bytes [A8, 2E, 99, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtOpenProcessTokenEx + B 76EE4AEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtOpenThread + 6 76EE4B3A 4 Bytes [68, 2D, 99, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtOpenThread + B 76EE4B3F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtOpenThreadToken + 6 76EE4B4A 4 Bytes [68, 2E, 99, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtOpenThreadToken + B 76EE4B4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtOpenThreadTokenEx + 6 76EE4B5A 4 Bytes CALL 75EEE48D
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtOpenThreadTokenEx + B 76EE4B5F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtQueryAttributesFile + 6 76EE4BEA 4 Bytes [A8, 2C, 99, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtQueryAttributesFile + B 76EE4BEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtQueryFullAttributesFile + 6 76EE4C9A 4 Bytes CALL 75EEE5CB
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtQueryFullAttributesFile + B 76EE4C9F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtSetInformationFile + 6 76EE517A 4 Bytes [28, 2D, 99, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtSetInformationFile + B 76EE517F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtSetInformationThread + 6 76EE51CA 4 Bytes [28, 2E, 99, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtSetInformationThread + B 76EE51CF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtUnmapViewOfSection + 6 76EE546A 4 Bytes [68, 2F, 99, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[2784] ntdll.dll!NtUnmapViewOfSection + B 76EE546F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtCreateFile + 6 76EE426A 4 Bytes [28, 68, 1C, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtCreateFile + B 76EE426F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtMapViewOfSection + 6 76EE49BA 4 Bytes [28, 6B, 1C, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtMapViewOfSection + B 76EE49BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtOpenFile + 6 76EE4A4A 4 Bytes [68, 68, 1C, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtOpenFile + B 76EE4A4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtOpenProcess + 6 76EE4ACA 4 Bytes [A8, 69, 1C, 00] {TEST AL, 0x69; SBB AL, 0x0}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtOpenProcess + B 76EE4ACF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtOpenProcessToken + 6 76EE4ADA 4 Bytes CALL 75EE6748 C:\Windows\system32\SHLWAPI.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtOpenProcessToken + B 76EE4ADF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtOpenProcessTokenEx + 6 76EE4AEA 4 Bytes [A8, 6A, 1C, 00] {TEST AL, 0x6a; SBB AL, 0x0}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtOpenProcessTokenEx + B 76EE4AEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtOpenThread + 6 76EE4B3A 4 Bytes [68, 69, 1C, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtOpenThread + B 76EE4B3F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtOpenThreadToken + 6 76EE4B4A 4 Bytes [68, 6A, 1C, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtOpenThreadToken + B 76EE4B4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtOpenThreadTokenEx + 6 76EE4B5A 4 Bytes CALL 75EE67C9 C:\Windows\system32\SHLWAPI.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtOpenThreadTokenEx + B 76EE4B5F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtQueryAttributesFile + 6 76EE4BEA 4 Bytes [A8, 68, 1C, 00] {TEST AL, 0x68; SBB AL, 0x0}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtQueryAttributesFile + B 76EE4BEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtQueryFullAttributesFile + 6 76EE4C9A 4 Bytes CALL 75EE6907 C:\Windows\system32\SHLWAPI.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtQueryFullAttributesFile + B 76EE4C9F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtSetInformationFile + 6 76EE517A 4 Bytes [28, 69, 1C, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtSetInformationFile + B 76EE517F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtSetInformationThread + 6 76EE51CA 4 Bytes [28, 6A, 1C, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtSetInformationThread + B 76EE51CF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtUnmapViewOfSection + 6 76EE546A 4 Bytes [68, 6B, 1C, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3400] ntdll.dll!NtUnmapViewOfSection + B 76EE546F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtCreateFile + 6 76EE426A 4 Bytes [28, 9C, DA, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtCreateFile + B 76EE426F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtMapViewOfSection + 6 76EE49BA 4 Bytes [28, 9F, DA, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtMapViewOfSection + B 76EE49BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtOpenFile + 6 76EE4A4A 4 Bytes [68, 9C, DA, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtOpenFile + B 76EE4A4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtOpenProcess + 6 76EE4ACA 4 Bytes [A8, 9D, DA, 00] {TEST AL, 0x9d; FIADD DWORD [EAX]}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtOpenProcess + B 76EE4ACF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtOpenProcessToken + 6 76EE4ADA 4 Bytes CALL 75EF257C C:\Windows\system32\urlmon.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtOpenProcessToken + B 76EE4ADF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtOpenProcessTokenEx + 6 76EE4AEA 4 Bytes [A8, 9E, DA, 00] {TEST AL, 0x9e; FIADD DWORD [EAX]}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtOpenProcessTokenEx + B 76EE4AEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtOpenThread + 6 76EE4B3A 4 Bytes [68, 9D, DA, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtOpenThread + B 76EE4B3F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtOpenThreadToken + 6 76EE4B4A 4 Bytes [68, 9E, DA, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtOpenThreadToken + B 76EE4B4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtOpenThreadTokenEx + 6 76EE4B5A 4 Bytes CALL 75EF25FD C:\Windows\system32\urlmon.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtOpenThreadTokenEx + B 76EE4B5F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtQueryAttributesFile + 6 76EE4BEA 4 Bytes [A8, 9C, DA, 00] {TEST AL, 0x9c; FIADD DWORD [EAX]}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtQueryAttributesFile + B 76EE4BEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtQueryFullAttributesFile + 6 76EE4C9A 4 Bytes CALL 75EF273B C:\Windows\system32\urlmon.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtQueryFullAttributesFile + B 76EE4C9F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtSetInformationFile + 6 76EE517A 4 Bytes [28, 9D, DA, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtSetInformationFile + B 76EE517F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtSetInformationThread + 6 76EE51CA 4 Bytes [28, 9E, DA, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtSetInformationThread + B 76EE51CF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtUnmapViewOfSection + 6 76EE546A 4 Bytes [68, 9F, DA, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3572] ntdll.dll!NtUnmapViewOfSection + B 76EE546F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtCreateFile + 6 76EE426A 4 Bytes [28, 34, C9, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtCreateFile + B 76EE426F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtMapViewOfSection + 6 76EE49BA 4 Bytes [28, 37, C9, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtMapViewOfSection + B 76EE49BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtOpenFile + 6 76EE4A4A 4 Bytes [68, 34, C9, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtOpenFile + B 76EE4A4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtOpenProcess + 6 76EE4ACA 4 Bytes [A8, 35, C9, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtOpenProcess + B 76EE4ACF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtOpenProcessToken + 6 76EE4ADA 4 Bytes CALL 75EF1414 C:\Windows\system32\urlmon.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtOpenProcessToken + B 76EE4ADF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtOpenProcessTokenEx + 6 76EE4AEA 4 Bytes [A8, 36, C9, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtOpenProcessTokenEx + B 76EE4AEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtOpenThread + 6 76EE4B3A 4 Bytes [68, 35, C9, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtOpenThread + B 76EE4B3F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtOpenThreadToken + 6 76EE4B4A 4 Bytes [68, 36, C9, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtOpenThreadToken + B 76EE4B4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtOpenThreadTokenEx + 6 76EE4B5A 4 Bytes CALL 75EF1495 C:\Windows\system32\urlmon.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtOpenThreadTokenEx + B 76EE4B5F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtQueryAttributesFile + 6 76EE4BEA 4 Bytes [A8, 34, C9, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtQueryAttributesFile + B 76EE4BEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtQueryFullAttributesFile + 6 76EE4C9A 4 Bytes CALL 75EF15D3 C:\Windows\system32\urlmon.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtQueryFullAttributesFile + B 76EE4C9F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtSetInformationFile + 6 76EE517A 4 Bytes [28, 35, C9, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtSetInformationFile + B 76EE517F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtSetInformationThread + 6 76EE51CA 4 Bytes [28, 36, C9, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtSetInformationThread + B 76EE51CF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtUnmapViewOfSection + 6 76EE546A 4 Bytes [68, 37, C9, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4688] ntdll.dll!NtUnmapViewOfSection + B 76EE546F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtCreateFile + 6 76EE426A 4 Bytes [28, 64, 07, 01] {SUB [EDI+EAX+0x1], AH}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtCreateFile + B 76EE426F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtMapViewOfSection + 6 76EE49BA 4 Bytes [28, 67, 07, 01]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtMapViewOfSection + B 76EE49BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtOpenFile + 6 76EE4A4A 4 Bytes [68, 64, 07, 01]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtOpenFile + B 76EE4A4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtOpenProcess + 6 76EE4ACA 4 Bytes [A8, 65, 07, 01]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtOpenProcess + B 76EE4ACF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtOpenProcessToken + 6 76EE4ADA 4 Bytes CALL 75EF5244 C:\Windows\system32\urlmon.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtOpenProcessToken + B 76EE4ADF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtOpenProcessTokenEx + 6 76EE4AEA 4 Bytes [A8, 66, 07, 01]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtOpenProcessTokenEx + B 76EE4AEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtOpenThread + 6 76EE4B3A 4 Bytes [68, 65, 07, 01]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtOpenThread + B 76EE4B3F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtOpenThreadToken + 6 76EE4B4A 4 Bytes [68, 66, 07, 01]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtOpenThreadToken + B 76EE4B4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtOpenThreadTokenEx + 6 76EE4B5A 4 Bytes CALL 75EF52C5 C:\Windows\system32\urlmon.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtOpenThreadTokenEx + B 76EE4B5F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtQueryAttributesFile + 6 76EE4BEA 4 Bytes [A8, 64, 07, 01]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtQueryAttributesFile + B 76EE4BEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtQueryFullAttributesFile + 6 76EE4C9A 4 Bytes CALL 75EF5403 C:\Windows\system32\urlmon.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtQueryFullAttributesFile + B 76EE4C9F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtSetInformationFile + 6 76EE517A 4 Bytes [28, 65, 07, 01]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtSetInformationFile + B 76EE517F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtSetInformationThread + 6 76EE51CA 4 Bytes [28, 66, 07, 01]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtSetInformationThread + B 76EE51CF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtUnmapViewOfSection + 6 76EE546A 4 Bytes [68, 67, 07, 01]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4908] ntdll.dll!NtUnmapViewOfSection + B 76EE546F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtCreateFile + 6 76EE426A 4 Bytes [28, 74, AB, 00] {SUB [EBX+EBP*4+0x0], DH}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtCreateFile + B 76EE426F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtMapViewOfSection + 6 76EE49BA 4 Bytes [28, 77, AB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtMapViewOfSection + B 76EE49BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtOpenFile + 6 76EE4A4A 4 Bytes [68, 74, AB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtOpenFile + B 76EE4A4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtOpenProcess + 6 76EE4ACA 4 Bytes [A8, 75, AB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtOpenProcess + B 76EE4ACF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtOpenProcessToken + 6 76EE4ADA 4 Bytes CALL 75EEF654
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtOpenProcessToken + B 76EE4ADF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtOpenProcessTokenEx + 6 76EE4AEA 4 Bytes [A8, 76, AB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtOpenProcessTokenEx + B 76EE4AEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtOpenThread + 6 76EE4B3A 4 Bytes [68, 75, AB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtOpenThread + B 76EE4B3F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtOpenThreadToken + 6 76EE4B4A 4 Bytes [68, 76, AB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtOpenThreadToken + B 76EE4B4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtOpenThreadTokenEx + 6 76EE4B5A 4 Bytes CALL 75EEF6D5
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtOpenThreadTokenEx + B 76EE4B5F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtQueryAttributesFile + 6 76EE4BEA 4 Bytes [A8, 74, AB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtQueryAttributesFile + B 76EE4BEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtQueryFullAttributesFile + 6 76EE4C9A 4 Bytes CALL 75EEF813
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtQueryFullAttributesFile + B 76EE4C9F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtSetInformationFile + 6 76EE517A 4 Bytes [28, 75, AB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtSetInformationFile + B 76EE517F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtSetInformationThread + 6 76EE51CA 4 Bytes [28, 76, AB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtSetInformationThread + B 76EE51CF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtUnmapViewOfSection + 6 76EE546A 4 Bytes [68, 77, AB, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4928] ntdll.dll!NtUnmapViewOfSection + B 76EE546F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtCreateFile + 6 76EE426A 4 Bytes [28, 78, E1, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtCreateFile + B 76EE426F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtMapViewOfSection + 6 76EE49BA 4 Bytes [28, 7B, E1, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtMapViewOfSection + B 76EE49BF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtOpenFile + 6 76EE4A4A 4 Bytes [68, 78, E1, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtOpenFile + B 76EE4A4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtOpenProcess + 6 76EE4ACA 4 Bytes [A8, 79, E1, 00] {TEST AL, 0x79; LOOPZ 0x4}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtOpenProcess + B 76EE4ACF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtOpenProcessToken + 6 76EE4ADA 4 Bytes CALL 75EF2C58 C:\Windows\system32\urlmon.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtOpenProcessToken + B 76EE4ADF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtOpenProcessTokenEx + 6 76EE4AEA 4 Bytes [A8, 7A, E1, 00] {TEST AL, 0x7a; LOOPZ 0x4}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtOpenProcessTokenEx + B 76EE4AEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtOpenThread + 6 76EE4B3A 4 Bytes [68, 79, E1, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtOpenThread + B 76EE4B3F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtOpenThreadToken + 6 76EE4B4A 4 Bytes [68, 7A, E1, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtOpenThreadToken + B 76EE4B4F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtOpenThreadTokenEx + 6 76EE4B5A 4 Bytes CALL 75EF2CD9 C:\Windows\system32\urlmon.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtOpenThreadTokenEx + B 76EE4B5F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtQueryAttributesFile + 6 76EE4BEA 4 Bytes [A8, 78, E1, 00] {TEST AL, 0x78; LOOPZ 0x4}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtQueryAttributesFile + B 76EE4BEF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtQueryFullAttributesFile + 6 76EE4C9A 4 Bytes CALL 75EF2E17 C:\Windows\system32\urlmon.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtQueryFullAttributesFile + B 76EE4C9F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtSetInformationFile + 6 76EE517A 4 Bytes [28, 79, E1, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtSetInformationFile + B 76EE517F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtSetInformationThread + 6 76EE51CA 4 Bytes [28, 7A, E1, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtSetInformationThread + B 76EE51CF 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtUnmapViewOfSection + 6 76EE546A 4 Bytes [68, 7B, E1, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5036] ntdll.dll!NtUnmapViewOfSection + B 76EE546F 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtCreateFile + 6 76EE426A 2 Bytes [28, 44]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtCreateFile + 9 76EE426D 1 Byte [00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtCreateFile + 9 76EE426D 3 Bytes [00, FF, E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtMapViewOfSection + 6 76EE49BA 2 Bytes [28, 47]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtMapViewOfSection + 9 76EE49BD 1 Byte [00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtMapViewOfSection + 9 76EE49BD 3 Bytes [00, FF, E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtOpenFile + 6 76EE4A4A 2 Bytes [68, 44]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtOpenFile + 9 76EE4A4D 1 Byte [00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtOpenFile + 9 76EE4A4D 3 Bytes [00, FF, E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtOpenProcess + 6 76EE4ACA 2 Bytes [A8, 45] {TEST AL, 0x45}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtOpenProcess + 9 76EE4ACD 1 Byte [00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtOpenProcess + 9 76EE4ACD 3 Bytes [00, FF, E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtOpenProcessToken + 6 76EE4ADA 2 Bytes CALL 75EF4924 C:\Windows\system32\urlmon.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtOpenProcessToken + 9 76EE4ADD 1 Byte [00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtOpenProcessToken + 9 76EE4ADD 3 Bytes [00, FF, E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtOpenProcessTokenEx + 6 76EE4AEA 2 Bytes [A8, 46] {TEST AL, 0x46}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtOpenProcessTokenEx + 9 76EE4AED 1 Byte [00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtOpenProcessTokenEx + 9 76EE4AED 3 Bytes [00, FF, E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtOpenThread + 6 76EE4B3A 2 Bytes [68, 45]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtOpenThread + 9 76EE4B3D 1 Byte [00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtOpenThread + 9 76EE4B3D 3 Bytes [00, FF, E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtOpenThreadToken + 6 76EE4B4A 2 Bytes [68, 46]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtOpenThreadToken + 9 76EE4B4D 1 Byte [00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtOpenThreadToken + 9 76EE4B4D 3 Bytes [00, FF, E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtOpenThreadTokenEx + 6 76EE4B5A 2 Bytes CALL 75EF49A5 C:\Windows\system32\urlmon.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtOpenThreadTokenEx + 9 76EE4B5D 1 Byte [00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtOpenThreadTokenEx + 9 76EE4B5D 3 Bytes [00, FF, E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtQueryAttributesFile + 6 76EE4BEA 2 Bytes [A8, 44] {TEST AL, 0x44}
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtQueryAttributesFile + 9 76EE4BED 1 Byte [00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtQueryAttributesFile + 9 76EE4BED 3 Bytes [00, FF, E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtQueryFullAttributesFile + 6 76EE4C9A 2 Bytes CALL 75EF4AE3 C:\Windows\system32\urlmon.dll
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtQueryFullAttributesFile + 9 76EE4C9D 1 Byte [00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtQueryFullAttributesFile + 9 76EE4C9D 3 Bytes [00, FF, E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtSetInformationFile + 6 76EE517A 2 Bytes [28, 45]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtSetInformationFile + 9 76EE517D 1 Byte [00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtSetInformationFile + 9 76EE517D 3 Bytes [00, FF, E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtSetInformationThread + 6 76EE51CA 2 Bytes [28, 46]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtSetInformationThread + 9 76EE51CD 1 Byte [00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtSetInformationThread + 9 76EE51CD 3 Bytes [00, FF, E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtUnmapViewOfSection + 6 76EE546A 2 Bytes [68, 47]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtUnmapViewOfSection + 9 76EE546D 1 Byte [00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5896] ntdll.dll!NtUnmapViewOfSection + 9 76EE546D 3 Bytes [00, FF, E2]
---- User IAT/EAT - GMER 2.1 ----
IAT C:\Windows\Explorer.EXE[3152] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [72F57817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3152] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [72F9B4F1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3152] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [72F5BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3152] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [72F4F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3152] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [72F575E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3152] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [72F4E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3152] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [72F873F5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3152] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [72F5DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3152] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [72F4FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3152] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [72F4FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3152] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [72F471CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3152] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [72FDCB00] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3152] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [72F7C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3152] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [72F4D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3152] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [72F46853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3152] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [72F4687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a4\gdiplus.dll
IAT C:\Windows\Explorer.EXE[3152] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [72F52AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18813_none_9e51e050ca1696a4\gdiplus.dll
---- Processes - GMER 2.1 ----
Process C:\Program Files\My applications\Windows Defender Apps Control.exe (*** hidden *** ) 3164
Process C:\Program Files\My applications\Windows Defender Apps Control.exe (*** hidden *** ) 3780
---- Registry - GMER 2.1 ----
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\System@OODEFRAG12.00.00.01PROFESSIONAL 4E604DAF0AB029093149D006284255855E6EABB6DAB2D827E340A4B9E44A39533FBF57532EA8FEAC46302BB6607D967E685816BCCF4D7D3440C7B01EAFC9BAE4F5C21D509CB4306FEBA03B5EF7DBB12440DBA9E10C99F7FE21101E8307F0D76E68A5080D4430CFB78D77860ADF276757E617A901A6F2D6FEBB960CAB484D0AA29FEAB35464F6E590A9D6C4AF5E2FE91A6F6E8CD389B89A53D721CE3B22ED3E57BC5670D392EB6CA756A565258CC6E19604897CFCF4CE37BA55366D3D98E7D805EEF2C21FB6F3D1D1B78D09A458436B165E52D8807A1C179B23A2A49C83552E4BFD8C64AC0FF9F9840BFBFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C5D575E7D6A3B9808A2D97226D213B5558EDD5E5BE2F6E667FEBC9E127BECC74C349556FCB87341C7E05996D6AF92AABB7469447D4E9C016E7B940CA542A89C812B0610F9E69392A902DCAB4152DDA3E33B4A9095B09003B118472C29F33CE066EFD3E0214A7D4B8697CD8FF5F1A1E3B692CE71EE5145D93A1C22BA27E01AC000764518A171A6AAC314FAF8F4AA2B9C39886F217C76024E4ED0E596A1A0233B76E3035AB15D29818A1A17ED450C6D9436DD06AC355EB1BAF9B5B774223CDC6135951B9F0904C2B8478238CC6F1800293C0852F513B765120DFD1ED8322F70D7ED9AFD33E4D05
---- EOF - GMER 2.1 ----