Advertisement
Advertisement
| | |
|
21-Nov-2011, 01:27 AM
#1 |
| First off, I'm working in Safe Mode, so if I'm not supposed to, sorry. But when I don't, I get some weird glitched patches and lines randomly appearing on my screen. Running some programs seems to freeze my computer, too (I tries to run Microsoft Security Essentials and SpyBot on separate occasions, and after a bit of scanning, the screen became messed up and the computer froze both times). This makes it very hard to get anything done, so I'm trying all the scanning in Safe Mode. All this started today. I've checked my cables and they're connected correctly. I've tried restarting already, and doing System Restore only gives me one restore point that takes me to a point after this all started. I don't know if anyone downloaded anything here recently that could have caused this (it's a family computer). I don't know what else to try, so I came here for help. I tried running the SysInfo program that's suggested here, but I get an error: "the instruction at 0x00af2597 referenced memory at 0x0575c08d. The memory could not be read." According to my Control Panel System menu, my computer is: Compaq, Hewlett-Packard Model SR5050NX Vista OS 32-bit Memory is 2 GB Processors are 2 Intel Pentium D CPU 3.00 GHz, from what the device manager tells me, anyway I don't know if any other info is necessary, but I'll look for anything you might need. Also, I tried running the DDS from the sticky thread, but nothing happens. A window pops up for a split second, then disappears without making any files. I don't know if I have any script blockers like it says in that thread (I don't remember getting any), or if this is from Safe Mode? Whatever it is, I can't get those files. Sorry. Here's the HijackThis log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:19:31 PM, on 11/20/2011 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v8.00 (8.00.6001.19088) Boot mode: Safe mode with network support Running processes: C:\Windows\Explorer.EXE C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.att.net R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...rio&pf=desktop R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?Link...rio&pf=desktop R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8118 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll O3 - Toolbar: Veoh Video Compass - {52836EB0-631A-47B1-94A6-61F9D9112DAE} - C:\Program Files\Veoh Networks\Veoh Video Compass\SearchRecsPlugin.dll O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini" O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon O4 - HKLM\..\Run: [CanonSolutionMenuEx] C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE /logon O4 - HKLM\..\Run: [IJNetworkScannerSelectorEX] C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe O4 - HKCU\..\Run: [Google Update] "C:\Users\compaq\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [cacaoweb] "C:\Users\compaq\AppData\Roaming\cacaoweb\cacaoweb.exe" -noplayer O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files\Logitech\Vid HD\Vid.exe" -bootmode O4 - HKCU\..\Run: [55928A3D53542EC1ED1B488888610BCD43BE3267._service_run] "C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe" --type=service O4 - HKCU\..\RunServices: [ExtraoAmor] c:\users\compaq\music\itunes\itunes music\compilations\leo dan antología vol. 1\amorextrao.exe O4 - HKCU\..\RunServices: [GoogleChrome] c:\users\compaq\appdata\local\google\chrome\application\5.0.375.70\installe r\chromesetup.exe O4 - HKCU\..\RunServices: [AmorExtrao] C:\Users\compaq\Music\iTunes\iTunes Music\Compilations\LEO DAN Antología Vol. 1\AmorExtrao.exe O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil10v_Plugin.exe -update plugin O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User '?') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User '?') O4 - HKUS\S-1-5-21-3819488228-4141541852-1189369466-1001\..\Run: [Google Update] "C:\Users\compaq\AppData\Local\Google\Update\GoogleUpdate.exe" /c (User '?') O4 - HKUS\S-1-5-21-3819488228-4141541852-1189369466-1001\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" (User '?') O4 - HKUS\S-1-5-21-3819488228-4141541852-1189369466-1001\..\Run: [Logitech Vid] "C:\Program Files\Logitech\Vid HD\Vid.exe" -bootmode (User '?') O4 - HKUS\S-1-5-21-3819488228-4141541852-1189369466-1001\..\Run: [55928A3D53542EC1ED1B488888610BCD43BE3267._service_run] "C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe" --type=service (User '?') O4 - HKUS\S-1-5-21-3819488228-4141541852-1189369466-1001\..\RunOnce: [FlashPlayerUpdate] C:\Windows\system32\Macromed\Flash\FlashUtil10v_Plugin.exe -update plugin (User '?') O4 - HKUS\S-1-5-21-3819488228-4141541852-1189369466-1001\..\RunServices: [ExtraoAmor] c:\users\compaq\music\itunes\itunes music\compilations\leo dan antología vol. 1\amorextrao.exe (User '?') O4 - S-1-5-21-3819488228-4141541852-1189369466-1001 Startup: Dropbox.lnk = C:\Users\compaq\AppData\Roaming\Dropbox\bin\Dropbox.exe (User '?') O4 - Startup: Dropbox.lnk = C:\Users\compaq\AppData\Roaming\Dropbox\bin\Dropbox.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O13 - Gopher Prefix: O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O18 - Filter: video/x-flv - {08C72DD4-19AD-49f1-83DA-8542B4D302C5} - (no file) O23 - Service: Access Utility Service - SprintNextel - C:\Program Files\Sprint\Mobile Broadband\SMBAUtilSvc.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\DfsdkS.exe O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe O23 - Service: Google Update Service (gupdate1c99873ba0a360e) (gupdate1c99873ba0a360e) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: MODXGFBEIB - Unknown owner - C:\Users\compaq\AppData\Local\Temp\MODXGFBEIB.exe (file missing) O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 13750 bytes Here's the GMER log: GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2011-11-20 21:51:36 Windows 6.0.6001 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 Hitachi_ rev.V5DO Running: 9dkh6m3d.exe; Driver: C:\Users\compaq\AppData\Local\Temp\pwloapow.sys ---- System - GMER 1.0.15 ---- INT 0x51 ? 85031BF8 INT 0x82 ? 85BECBF8 INT 0x92 ? 85BECBF8 INT 0xB2 ? 85035BF8 ---- Kernel code sections - GMER 1.0.15 ---- ? System32\Drivers\spjb.sys The system cannot find the path specified. ! .text USBPORT.SYS!DllUnload 8873746F 5 Bytes JMP 85BEC1D8 .text a611la6s.SYS 8839C000 22 Bytes [26, 82, 5C, 82, 10, 81, 5C, ...] .text a611la6s.SYS 8839C017 145 Bytes [00, 32, 27, 19, 88, 3D, 25, ...] .text a611la6s.SYS 8839C0A9 35 Bytes [B0, 25, 82, 60, A7, 25, 82, ...] .text a611la6s.SYS 8839C0CE 10 Bytes [00, 00, 00, 00, 00, 00, 6D, ...] {ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; INSD ; POPF ; SCASB ; DEC EAX} .text a611la6s.SYS 8839C0DA 12 Bytes [00, 00, 02, 00, 00, 00, 26, ...] .text ... ---- User code sections - GMER 1.0.15 ---- .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtCreateFile + 6 77C97C7E 4 Bytes [28, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtCreateFile + B 77C97C83 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtMapViewOfSection + 6 77C983CE 1 Byte [28] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtMapViewOfSection + 6 77C983CE 4 Bytes [28, 03, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtMapViewOfSection + B 77C983D3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtOpenFile + 6 77C9845E 4 Bytes [68, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtOpenFile + B 77C98463 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtOpenProcess + 6 77C984DE 4 Bytes [A8, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtOpenProcess + B 77C984E3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtOpenProcessToken + 6 77C984EE 4 Bytes CALL 76C98AF4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtOpenProcessToken + B 77C984F3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtOpenProcessTokenEx + 6 77C984FE 4 Bytes [A8, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtOpenProcessTokenEx + B 77C98503 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtOpenThread + 6 77C9854E 4 Bytes [68, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtOpenThread + B 77C98553 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtOpenThreadToken + 6 77C9855E 4 Bytes [68, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtOpenThreadToken + B 77C98563 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtOpenThreadTokenEx + 6 77C9856E 4 Bytes CALL 76C98B75 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtOpenThreadTokenEx + B 77C98573 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtQueryAttributesFile + 6 77C985FE 4 Bytes [A8, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtQueryAttributesFile + B 77C98603 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtQueryFullAttributesFile + 6 77C986AE 4 Bytes CALL 76C98CB3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtQueryFullAttributesFile + B 77C986B3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtSetInformationFile + 6 77C98B8E 4 Bytes [28, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtSetInformationFile + B 77C98B93 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtSetInformationThread + 6 77C98BDE 4 Bytes [28, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtSetInformationThread + B 77C98BE3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 1 Byte [68] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 4 Bytes [68, 03, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[680] ntdll.dll!NtUnmapViewOfSection + B 77C98E83 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtCreateFile + 6 77C97C7E 4 Bytes [28, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtCreateFile + B 77C97C83 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtMapViewOfSection + 6 77C983CE 1 Byte [28] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtMapViewOfSection + 6 77C983CE 4 Bytes [28, 03, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtMapViewOfSection + B 77C983D3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtOpenFile + 6 77C9845E 4 Bytes [68, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtOpenFile + B 77C98463 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtOpenProcess + 6 77C984DE 4 Bytes [A8, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtOpenProcess + B 77C984E3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtOpenProcessToken + 6 77C984EE 4 Bytes CALL 76C98AF4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtOpenProcessToken + B 77C984F3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtOpenProcessTokenEx + 6 77C984FE 4 Bytes [A8, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtOpenProcessTokenEx + B 77C98503 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtOpenThread + 6 77C9854E 4 Bytes [68, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtOpenThread + B 77C98553 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtOpenThreadToken + 6 77C9855E 4 Bytes [68, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtOpenThreadToken + B 77C98563 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtOpenThreadTokenEx + 6 77C9856E 4 Bytes CALL 76C98B75 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtOpenThreadTokenEx + B 77C98573 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtQueryAttributesFile + 6 77C985FE 4 Bytes [A8, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtQueryAttributesFile + B 77C98603 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtQueryFullAttributesFile + 6 77C986AE 4 Bytes CALL 76C98CB3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtQueryFullAttributesFile + B 77C986B3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtSetInformationFile + 6 77C98B8E 4 Bytes [28, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtSetInformationFile + B 77C98B93 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtSetInformationThread + 6 77C98BDE 4 Bytes [28, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtSetInformationThread + B 77C98BE3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 1 Byte [68] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 4 Bytes [68, 03, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[840] ntdll.dll!NtUnmapViewOfSection + B 77C98E83 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtCreateFile + 6 77C97C7E 4 Bytes [28, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtCreateFile + B 77C97C83 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtMapViewOfSection + 6 77C983CE 1 Byte [28] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtMapViewOfSection + 6 77C983CE 4 Bytes [28, 03, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtMapViewOfSection + B 77C983D3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtOpenFile + 6 77C9845E 4 Bytes [68, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtOpenFile + B 77C98463 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtOpenProcess + 6 77C984DE 4 Bytes [A8, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtOpenProcess + B 77C984E3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtOpenProcessToken + 6 77C984EE 4 Bytes CALL 76C98AF4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtOpenProcessToken + B 77C984F3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtOpenProcessTokenEx + 6 77C984FE 4 Bytes [A8, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtOpenProcessTokenEx + B 77C98503 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtOpenThread + 6 77C9854E 4 Bytes [68, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtOpenThread + B 77C98553 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtOpenThreadToken + 6 77C9855E 4 Bytes [68, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtOpenThreadToken + B 77C98563 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtOpenThreadTokenEx + 6 77C9856E 4 Bytes CALL 76C98B75 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtOpenThreadTokenEx + B 77C98573 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtQueryAttributesFile + 6 77C985FE 4 Bytes [A8, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtQueryAttributesFile + B 77C98603 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtQueryFullAttributesFile + 6 77C986AE 4 Bytes CALL 76C98CB3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtQueryFullAttributesFile + B 77C986B3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtSetInformationFile + 6 77C98B8E 4 Bytes [28, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtSetInformationFile + B 77C98B93 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtSetInformationThread + 6 77C98BDE 4 Bytes [28, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtSetInformationThread + B 77C98BE3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 1 Byte [68] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 4 Bytes [68, 03, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[908] ntdll.dll!NtUnmapViewOfSection + B 77C98E83 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtCreateFile + 6 77C97C7E 4 Bytes [28, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtCreateFile + B 77C97C83 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtMapViewOfSection + 6 77C983CE 1 Byte [28] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtMapViewOfSection + 6 77C983CE 4 Bytes [28, 03, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtMapViewOfSection + B 77C983D3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtOpenFile + 6 77C9845E 4 Bytes [68, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtOpenFile + B 77C98463 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtOpenProcess + 6 77C984DE 4 Bytes [A8, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtOpenProcess + B 77C984E3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtOpenProcessToken + 6 77C984EE 4 Bytes CALL 76C98AF4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtOpenProcessToken + B 77C984F3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtOpenProcessTokenEx + 6 77C984FE 4 Bytes [A8, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtOpenProcessTokenEx + B 77C98503 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtOpenThread + 6 77C9854E 4 Bytes [68, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtOpenThread + B 77C98553 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtOpenThreadToken + 6 77C9855E 4 Bytes [68, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtOpenThreadToken + B 77C98563 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtOpenThreadTokenEx + 6 77C9856E 4 Bytes CALL 76C98B75 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtOpenThreadTokenEx + B 77C98573 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtQueryAttributesFile + 6 77C985FE 4 Bytes [A8, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtQueryAttributesFile + B 77C98603 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtQueryFullAttributesFile + 6 77C986AE 4 Bytes CALL 76C98CB3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtQueryFullAttributesFile + B 77C986B3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtSetInformationFile + 6 77C98B8E 4 Bytes [28, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtSetInformationFile + B 77C98B93 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtSetInformationThread + 6 77C98BDE 4 Bytes [28, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtSetInformationThread + B 77C98BE3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 1 Byte [68] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 4 Bytes [68, 03, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1076] ntdll.dll!NtUnmapViewOfSection + B 77C98E83 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtCreateFile + 6 77C97C7E 4 Bytes [28, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtCreateFile + B 77C97C83 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtMapViewOfSection + 6 77C983CE 1 Byte [28] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtMapViewOfSection + 6 77C983CE 4 Bytes [28, 03, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtMapViewOfSection + B 77C983D3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtOpenFile + 6 77C9845E 4 Bytes [68, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtOpenFile + B 77C98463 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtOpenProcess + 6 77C984DE 4 Bytes [A8, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtOpenProcess + B 77C984E3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtOpenProcessToken + 6 77C984EE 4 Bytes CALL 76C98AF4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtOpenProcessToken + B 77C984F3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtOpenProcessTokenEx + 6 77C984FE 4 Bytes [A8, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtOpenProcessTokenEx + B 77C98503 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtOpenThread + 6 77C9854E 4 Bytes [68, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtOpenThread + B 77C98553 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtOpenThreadToken + 6 77C9855E 4 Bytes [68, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtOpenThreadToken + B 77C98563 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtOpenThreadTokenEx + 6 77C9856E 4 Bytes CALL 76C98B75 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtOpenThreadTokenEx + B 77C98573 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtQueryAttributesFile + 6 77C985FE 4 Bytes [A8, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtQueryAttributesFile + B 77C98603 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtQueryFullAttributesFile + 6 77C986AE 4 Bytes CALL 76C98CB3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtQueryFullAttributesFile + B 77C986B3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtSetInformationFile + 6 77C98B8E 4 Bytes [28, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtSetInformationFile + B 77C98B93 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtSetInformationThread + 6 77C98BDE 4 Bytes [28, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtSetInformationThread + B 77C98BE3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 1 Byte [68] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 4 Bytes [68, 03, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1100] ntdll.dll!NtUnmapViewOfSection + B 77C98E83 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtCreateFile + 6 77C97C7E 4 Bytes [28, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtCreateFile + B 77C97C83 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtMapViewOfSection + 6 77C983CE 1 Byte [28] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtMapViewOfSection + 6 77C983CE 4 Bytes [28, 03, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtMapViewOfSection + B 77C983D3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenFile + 6 77C9845E 4 Bytes [68, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenFile + B 77C98463 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenProcess + 6 77C984DE 4 Bytes [A8, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenProcess + B 77C984E3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenProcessToken + 6 77C984EE 4 Bytes CALL 76C98AF4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenProcessToken + B 77C984F3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenProcessTokenEx + 6 77C984FE 4 Bytes [A8, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenProcessTokenEx + B 77C98503 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenThread + 6 77C9854E 4 Bytes [68, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenThread + B 77C98553 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenThreadToken + 6 77C9855E 4 Bytes [68, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenThreadToken + B 77C98563 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenThreadTokenEx + 6 77C9856E 4 Bytes CALL 76C98B75 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtOpenThreadTokenEx + B 77C98573 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtQueryAttributesFile + 6 77C985FE 4 Bytes [A8, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtQueryAttributesFile + B 77C98603 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtQueryFullAttributesFile + 6 77C986AE 4 Bytes CALL 76C98CB3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtQueryFullAttributesFile + B 77C986B3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtSetInformationFile + 6 77C98B8E 4 Bytes [28, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtSetInformationFile + B 77C98B93 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtSetInformationThread + 6 77C98BDE 4 Bytes [28, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtSetInformationThread + B 77C98BE3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 1 Byte [68] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 4 Bytes [68, 03, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1188] ntdll.dll!NtUnmapViewOfSection + B 77C98E83 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtCreateFile + 6 77C97C7E 4 Bytes [28, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtCreateFile + B 77C97C83 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtMapViewOfSection + 6 77C983CE 1 Byte [28] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtMapViewOfSection + 6 77C983CE 4 Bytes [28, 03, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtMapViewOfSection + B 77C983D3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtOpenFile + 6 77C9845E 4 Bytes [68, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtOpenFile + B 77C98463 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtOpenProcess + 6 77C984DE 4 Bytes [A8, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtOpenProcess + B 77C984E3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtOpenProcessToken + 6 77C984EE 4 Bytes CALL 76C98AF4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtOpenProcessToken + B 77C984F3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtOpenProcessTokenEx + 6 77C984FE 4 Bytes [A8, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtOpenProcessTokenEx + B 77C98503 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtOpenThread + 6 77C9854E 4 Bytes [68, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtOpenThread + B 77C98553 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtOpenThreadToken + 6 77C9855E 4 Bytes [68, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtOpenThreadToken + B 77C98563 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtOpenThreadTokenEx + 6 77C9856E 4 Bytes CALL 76C98B75 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtOpenThreadTokenEx + B 77C98573 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtQueryAttributesFile + 6 77C985FE 4 Bytes [A8, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtQueryAttributesFile + B 77C98603 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtQueryFullAttributesFile + 6 77C986AE 4 Bytes CALL 76C98CB3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtQueryFullAttributesFile + B 77C986B3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtSetInformationFile + 6 77C98B8E 4 Bytes [28, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtSetInformationFile + B 77C98B93 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtSetInformationThread + 6 77C98BDE 4 Bytes [28, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtSetInformationThread + B 77C98BE3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 1 Byte [68] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 4 Bytes [68, 03, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1296] ntdll.dll!NtUnmapViewOfSection + B 77C98E83 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtCreateFile + 6 77C97C7E 4 Bytes [28, 00, 16, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtCreateFile + B 77C97C83 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtMapViewOfSection + 6 77C983CE 1 Byte [28] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtMapViewOfSection + 6 77C983CE 4 Bytes [28, 03, 16, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtMapViewOfSection + B 77C983D3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenFile + 6 77C9845E 4 Bytes [68, 00, 16, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenFile + B 77C98463 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenProcess + 6 77C984DE 4 Bytes [A8, 01, 16, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenProcess + B 77C984E3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenProcessToken + 6 77C984EE 4 Bytes CALL 76C99AF4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenProcessToken + B 77C984F3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenProcessTokenEx + 6 77C984FE 4 Bytes [A8, 02, 16, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenProcessTokenEx + B 77C98503 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenThread + 6 77C9854E 4 Bytes [68, 01, 16, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenThread + B 77C98553 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenThreadToken + 6 77C9855E 4 Bytes [68, 02, 16, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenThreadToken + B 77C98563 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenThreadTokenEx + 6 77C9856E 4 Bytes CALL 76C99B75 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenThreadTokenEx + B 77C98573 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtQueryAttributesFile + 6 77C985FE 4 Bytes [A8, 00, 16, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtQueryAttributesFile + B 77C98603 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtQueryFullAttributesFile + 6 77C986AE 4 Bytes CALL 76C99CB3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtQueryFullAttributesFile + B 77C986B3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtSetInformationFile + 6 77C98B8E 4 Bytes [28, 01, 16, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtSetInformationFile + B 77C98B93 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtSetInformationThread + 6 77C98BDE 4 Bytes [28, 02, 16, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtSetInformationThread + B 77C98BE3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 1 Byte [68] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 4 Bytes [68, 03, 16, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtUnmapViewOfSection + B 77C98E83 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtCreateFile + 6 77C97C7E 4 Bytes [28, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtCreateFile + B 77C97C83 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtMapViewOfSection + 6 77C983CE 1 Byte [28] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtMapViewOfSection + 6 77C983CE 4 Bytes [28, 03, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtMapViewOfSection + B 77C983D3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtOpenFile + 6 77C9845E 4 Bytes [68, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtOpenFile + B 77C98463 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtOpenProcess + 6 77C984DE 4 Bytes [A8, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtOpenProcess + B 77C984E3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtOpenProcessToken + 6 77C984EE 4 Bytes CALL 76C98AF4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtOpenProcessToken + B 77C984F3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtOpenProcessTokenEx + 6 77C984FE 4 Bytes [A8, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtOpenProcessTokenEx + B 77C98503 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtOpenThread + 6 77C9854E 4 Bytes [68, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtOpenThread + B 77C98553 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtOpenThreadToken + 6 77C9855E 4 Bytes [68, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtOpenThreadToken + B 77C98563 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtOpenThreadTokenEx + 6 77C9856E 4 Bytes CALL 76C98B75 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtOpenThreadTokenEx + B 77C98573 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtQueryAttributesFile + 6 77C985FE 4 Bytes [A8, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtQueryAttributesFile + B 77C98603 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtQueryFullAttributesFile + 6 77C986AE 4 Bytes CALL 76C98CB3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtQueryFullAttributesFile + B 77C986B3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtSetInformationFile + 6 77C98B8E 4 Bytes [28, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtSetInformationFile + B 77C98B93 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtSetInformationThread + 6 77C98BDE 4 Bytes [28, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtSetInformationThread + B 77C98BE3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 1 Byte [68] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 4 Bytes [68, 03, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1840] ntdll.dll!NtUnmapViewOfSection + B 77C98E83 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtCreateFile + 6 77C97C7E 4 Bytes [28, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtCreateFile + B 77C97C83 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtMapViewOfSection + 6 77C983CE 1 Byte [28] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtMapViewOfSection + 6 77C983CE 4 Bytes [28, 03, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtMapViewOfSection + B 77C983D3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtOpenFile + 6 77C9845E 4 Bytes [68, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtOpenFile + B 77C98463 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtOpenProcess + 6 77C984DE 4 Bytes [A8, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtOpenProcess + B 77C984E3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtOpenProcessToken + 6 77C984EE 4 Bytes CALL 76C98AF4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtOpenProcessToken + B 77C984F3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtOpenProcessTokenEx + 6 77C984FE 4 Bytes [A8, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtOpenProcessTokenEx + B 77C98503 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtOpenThread + 6 77C9854E 4 Bytes [68, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtOpenThread + B 77C98553 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtOpenThreadToken + 6 77C9855E 4 Bytes [68, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtOpenThreadToken + B 77C98563 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtOpenThreadTokenEx + 6 77C9856E 4 Bytes CALL 76C98B75 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtOpenThreadTokenEx + B 77C98573 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtQueryAttributesFile + 6 77C985FE 4 Bytes [A8, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtQueryAttributesFile + B 77C98603 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtQueryFullAttributesFile + 6 77C986AE 4 Bytes CALL 76C98CB3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtQueryFullAttributesFile + B 77C986B3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtSetInformationFile + 6 77C98B8E 4 Bytes [28, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtSetInformationFile + B 77C98B93 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtSetInformationThread + 6 77C98BDE 4 Bytes [28, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtSetInformationThread + B 77C98BE3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 1 Byte [68] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 4 Bytes [68, 03, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1924] ntdll.dll!NtUnmapViewOfSection + B 77C98E83 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtCreateFile + 6 77C97C7E 4 Bytes [28, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtCreateFile + B 77C97C83 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtMapViewOfSection + 6 77C983CE 1 Byte [28] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtMapViewOfSection + 6 77C983CE 4 Bytes [28, 03, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtMapViewOfSection + B 77C983D3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtOpenFile + 6 77C9845E 4 Bytes [68, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtOpenFile + B 77C98463 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtOpenProcess + 6 77C984DE 4 Bytes [A8, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtOpenProcess + B 77C984E3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtOpenProcessToken + 6 77C984EE 4 Bytes CALL 76C98AF4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtOpenProcessToken + B 77C984F3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtOpenProcessTokenEx + 6 77C984FE 4 Bytes [A8, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtOpenProcessTokenEx + B 77C98503 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtOpenThread + 6 77C9854E 4 Bytes [68, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtOpenThread + B 77C98553 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtOpenThreadToken + 6 77C9855E 4 Bytes [68, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtOpenThreadToken + B 77C98563 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtOpenThreadTokenEx + 6 77C9856E 4 Bytes CALL 76C98B75 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtOpenThreadTokenEx + B 77C98573 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtQueryAttributesFile + 6 77C985FE 4 Bytes [A8, 00, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtQueryAttributesFile + B 77C98603 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtQueryFullAttributesFile + 6 77C986AE 4 Bytes CALL 76C98CB3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation) .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtQueryFullAttributesFile + B 77C986B3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtSetInformationFile + 6 77C98B8E 4 Bytes [28, 01, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtSetInformationFile + B 77C98B93 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtSetInformationThread + 6 77C98BDE 4 Bytes [28, 02, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtSetInformationThread + B 77C98BE3 1 Byte [E2] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 1 Byte [68] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtUnmapViewOfSection + 6 77C98E7E 4 Bytes [68, 03, 06, 00] .text C:\Users\compaq\AppData\Local\Google\Chrome\Application\chrome.exe[1936] ntdll.dll!NtUnmapViewOfSection + B 77C98E83 1 Byte [E2] ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs 850371F8 Device \Driver\USBSTOR \Device\0000008f 85F64500 Device \Driver\netbt \Device\NetBT_Tcpip_{EADBAC64-E116-44EA-B078-8E5721F1B929} 85EBF1F8 Device \Driver\volmgr \Device\VolMgrControl 850331F8 Device \Driver\usbuhci \Device\USBPDO-0 85BED1F8 Device \Driver\usbuhci \Device\USBPDO-1 85BED1F8 Device \Driver\usbuhci \Device\USBPDO-2 85BED1F8 Device \Driver\usbuhci \Device\USBPDO-3 85BED1F8 Device \Driver\usbehci \Device\USBPDO-4 85BEE1F8 Device \Driver\volmgr \Device\HarddiskVolume1 850331F8 Device \Driver\volmgr \Device\HarddiskVolume2 850331F8 Device \Driver\cdrom \Device\CdRom0 85C281F8 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 850361F8 Device \Driver\iaStor \Device\Ide\iaStor0 [882AAFA0] \SystemRoot\system32\drivers\iastor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort0 850361F8 Device \Driver\iaStor \Device\Ide\IAAStorageDevice-0 [882AAFA0] \SystemRoot\system32\drivers\iastor.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\cdrom \Device\CdRom1 85C281F8 Device \Driver\volmgr \Device\HarddiskVolume3 850331F8 Device \Driver\volmgr \Device\HarddiskVolume4 850331F8 Device \Driver\volmgr \Device\HarddiskVolume5 850331F8 Device \Driver\volmgr \Device\HarddiskVolume6 850331F8 Device \Driver\netbt \Device\NetBt_Wins_Export 85EBF1F8 Device \Driver\sptd \Device\641483757 spjb.sys Device \Driver\USBSTOR \Device\00000092 85F64500 Device \Driver\Smb \Device\NetbiosSmb 85EBE1F8 Device \Driver\USBSTOR \Device\00000093 85F64500 Device \Driver\USBSTOR \Device\00000094 85F64500 Device \Driver\USBSTOR \Device\00000095 85F64500 Device \Driver\iScsiPrt \Device\RaidPort0 85C321F8 Device \Driver\usbuhci \Device\USBFDO-0 85BED1F8 Device \Driver\PCI_PNP7746 \Device\0000006d spjb.sys Device \Driver\usbuhci \Device\USBFDO-1 85BED1F8 Device \Driver\usbuhci \Device\USBFDO-2 85BED1F8 Device \Driver\usbuhci \Device\USBFDO-3 85BED1F8 Device \Driver\usbehci \Device\USBFDO-4 85BEE1F8 Device \Driver\a611la6s \Device\Scsi\a611la6s1 85C2E1F8 Device \Driver\a611la6s \Device\Scsi\a611la6s1Port3Path0Target0Lun0 85C2E1F8 Device \FileSystem\cdfs \Cdfs 864761F8 ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application@Sources MSDMine?DfSdk?Df?DfS Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C 90D04 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C 90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\ Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C 90D04@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C 90D04@ujdew 0x59 0x1A 0x02 0x0C ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C 90D04\00000001 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C 90D04\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C 90D04\00000001@ujdew 0x3A 0xAC 0x4F 0x47 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C 90D04\00000001\jdgg40 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C 90D04\00000001\jdgg40@ujdew 0x8E 0xCA 0xD6 0x8E ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C 53EA4 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C 53EA4@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C 53EA4@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C 53EA4@khjeh 0x22 0xD4 0x05 0xF0 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C 53EA4\00000001 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C 53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C 53EA4\00000001@khjeh 0x2B 0xC1 0x35 0x1B ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C 53EA4\00000001\0Jf40 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C 53EA4\00000001\0Jf40@khjeh 0xDC 0xC3 0x18 0x99 ... Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\Application@Sources MSDMine?DfSdk?Df?DfS Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D0 4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D0 4@p0 C:\Program Files\Alcohol Soft\Alcohol 120\ Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D0 4@h0 1 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D0 4@ujdew 0x59 0x1A 0x02 0x0C ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D0 4\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D0 4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D0 4\00000001@ujdew 0x3A 0xAC 0x4F 0x47 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D0 4\00000001\jdgg40 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D0 4\00000001\jdgg40@ujdew 0x8E 0xCA 0xD6 0x8E ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4@h0 0 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4@khjeh 0x22 0xD4 0x05 0xF0 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4\00000001@khjeh 0x2B 0xC1 0x35 0x1B ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4\00000001\0Jf40 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA 4\00000001\0Jf40@khjeh 0xDC 0xC3 0x18 0x99 ... Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32 Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\Windows\system32\OLE32.DLL Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xE2 0x63 0x26 0xF1 ... Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32 Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\Windows\system32\OLE32.DLL Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x71 0x3B 0x04 0x66 ... Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32 Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\Windows\system32\OLE32.DLL Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0x25 0xDA 0xEC 0x7E ... Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32 Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\Windows\system32\OLE32.DLL Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 ... Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32 Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\Windows\system32\OLE32.DLL Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 ... Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32 Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\Windows\system32\OLE32.DLL Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xDF 0x20 0x58 0x62 ... Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32 Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\Windows\system32\OLE32.DLL Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0xFB 0xA7 0x78 0xE6 ... Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32 Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\Windows\system32\OLE32.DLL Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x01 0x3A 0x48 0xFC ... Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32 Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\Windows\system32\OLE32.DLL Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xF6 0x0F 0x4E 0x58 ... Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32 Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\Windows\system32\OLE32.DLL Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0xB1 0xCD 0x45 0x5A ... Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32 Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\Windows\system32\OLE32.DLL Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0x2A 0xB7 0xCC 0xB5 ... Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32 Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\Windows\system32\OLE32.DLL Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ... ---- EOF - GMER 1.0.15 ---- This is all I can give you right now, I think. I hope you can tell me what's wrong, and whether or not I can fix this particular problem. |
|
21-Nov-2011, 02:44 AM
#2 |
| I just noticed how long that post is. That is terribly long. Anyway, I wanted to give an update: I can't use the normal Windows node now. It freezes on the Welcome screen. I haven't done anything but restart after the scans. Guess I shouldn't have. |
Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.
If you're not already familiar with forums, watch our Welcome Guide to get started.
| Tags |
| display issues, freeze, glitches |

| |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| |


Email 