Thank you NoodleTech for volunteering to help me, I really appreciate your assistance. I will do whatever you want in order to succeed. I will also ask questions if available.
----------------------------------------------------------------------------------------------------------------
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-07-09 17:25:38
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST3160815AS rev.4.AAA
Running: gmer.exe; Driver: C:\DOCUME~1\too\LOCALS~1\Temp\pxtdypob.sys
---- System - GMER 1.0.15 ----
SSDT 869C4968 ZwAlertResumeThread
SSDT 869C4C38 ZwAlertThread
SSDT 86857920 ZwAllocateVirtualMemory
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xA8F286B8]
SSDT 86957BB8 ZwConnectPort
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xA8F28574]
SSDT 86864330 ZwCreateMutant
SSDT \??\C:\Program Files\Anti Trojan Elite\ATEPMon.sys ZwCreateSection [0xA87F68C6]
SSDT 8683EF00 ZwCreateThread
SSDT 86A128E0 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xA917E2A0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xA8F28A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xA8F2814C]
SSDT 868412F8 ZwFreeVirtualMemory
SSDT 869D76B0 ZwImpersonateAnonymousToken
SSDT 869C48A8 ZwImpersonateThread
SSDT 86841218 ZwMapViewOfSection
SSDT 868642B0 ZwOpenEvent
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xA8F2864E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xA8F2808C]
SSDT 869FFDA0 ZwOpenProcessToken
SSDT 869193C0 ZwOpenSection
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xA8F280F0]
SSDT 86271670 ZwOpenThreadToken
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xA8F2876E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xA8F2872E]
SSDT 86A57C48 ZwResumeThread
SSDT 861EF378 ZwSetContextThread
SSDT 86A0C820 ZwSetInformationProcess
SSDT 8687B358 ZwSetInformationThread
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xA8F288AE]
SSDT 86919480 ZwSuspendProcess
SSDT 869C4CB8 ZwSuspendThread
SSDT 869581F0 ZwTerminateProcess
SSDT 868343A0 ZwTerminateThread
SSDT 861EF3F8 ZwUnmapViewOfSection
SSDT 86938200 ZwWriteVirtualMemory
INT 0x62 ? 86BCDCB8
INT 0x63 ? 869BCCB8
INT 0x82 ? 86BCDCB8
INT 0x83 ? 869BCCB8
INT 0x94 ? 869BCCB8
INT 0xA4 ? 869BCCB8
INT 0xA4 ? 869BCCB8
INT 0xA4 ? 869BCCB8
INT 0xA4 ? 869BCCB8
INT 0xB4 ? 86BCDCB8
INT 0xB4 ? 86BCDCB8
INT 0xB4 ? 869BCCB8
INT 0xB4 ? 86BCDCB8
---- Kernel code sections - GMER 1.0.15 ----
.sptd1 C:\WINDOWS\system32\drivers\sptd.sys entry point in ".sptd1" section [0xF7540089]
.text USBPORT.SYS!DllUnload F6BD980C 5 Bytes JMP 869BC1C8
.text a424jami.SYS!A0DB34FC6FE35D429A28ADDE5467D4D7 F6B0E900 48 Bytes [05, 39, EF, 49, 77, 28, 94, ...]
? C:\WINDOWS\System32\Drivers\a424jami.SYS suspicious PE modification
pnidata C:\WINDOWS\system32\DRIVERS\secdrv.sys unknown last section [0xA8449F00, 0x24000, 0x48000000]
---- User code sections - GMER 1.0.15 ----
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtCreateFile + 6 7C91D0B4 4 Bytes [28, 00, 18, 00] {SUB [EAX], AL; SBB [EAX], AL}
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtCreateFile + B 7C91D0B9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtMapViewOfSection + 6 7C91D524 1 Byte [28]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtMapViewOfSection + 6 7C91D524 4 Bytes [28, 03, 18, 00] {SUB [EBX], AL; SBB [EAX], AL}
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtMapViewOfSection + B 7C91D529 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenFile + 6 7C91D5A4 4 Bytes [68, 00, 18, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenFile + B 7C91D5A9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenProcess + 6 7C91D604 4 Bytes [A8, 01, 18, 00] {TEST AL, 0x1; SBB [EAX], AL}
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenProcess + B 7C91D609 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenProcessToken + 6 7C91D614 4 Bytes CALL 7B91EE1A
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenProcessToken + B 7C91D619 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenProcessTokenEx + 6 7C91D624 4 Bytes [A8, 02, 18, 00] {TEST AL, 0x2; SBB [EAX], AL}
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenProcessTokenEx + B 7C91D629 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenThread + 6 7C91D664 4 Bytes [68, 01, 18, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenThread + B 7C91D669 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenThreadToken + 6 7C91D674 4 Bytes [68, 02, 18, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenThreadToken + B 7C91D679 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenThreadTokenEx + 6 7C91D684 4 Bytes CALL 7B91EE8B
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtOpenThreadTokenEx + B 7C91D689 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtQueryAttributesFile + 6 7C91D714 4 Bytes [A8, 00, 18, 00] {TEST AL, 0x0; SBB [EAX], AL}
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtQueryAttributesFile + B 7C91D719 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtQueryFullAttributesFile + 6 7C91D7B4 4 Bytes CALL 7B91EFB9
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtQueryFullAttributesFile + B 7C91D7B9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtSetInformationFile + 6 7C91DC64 4 Bytes [28, 01, 18, 00] {SUB [ECX], AL; SBB [EAX], AL}
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtSetInformationFile + B 7C91DC69 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtSetInformationThread + 6 7C91DCB4 4 Bytes [28, 02, 18, 00] {SUB [EDX], AL; SBB [EAX], AL}
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtSetInformationThread + B 7C91DCB9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 1 Byte [68]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 4 Bytes [68, 03, 18, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1612] ntdll.dll!NtUnmapViewOfSection + B 7C91DF19 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtCreateFile + 6 7C91D0B4 4 Bytes [28, 00, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtCreateFile + B 7C91D0B9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtMapViewOfSection + 6 7C91D524 1 Byte [28]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtMapViewOfSection + 6 7C91D524 4 Bytes [28, 03, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtMapViewOfSection + B 7C91D529 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtOpenFile + 6 7C91D5A4 4 Bytes [68, 00, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtOpenFile + B 7C91D5A9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtOpenProcess + 6 7C91D604 4 Bytes [A8, 01, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtOpenProcess + B 7C91D609 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtOpenProcessToken + 6 7C91D614 4 Bytes CALL 7B91F41A
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtOpenProcessToken + B 7C91D619 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtOpenProcessTokenEx + 6 7C91D624 4 Bytes [A8, 02, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtOpenProcessTokenEx + B 7C91D629 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtOpenThread + 6 7C91D664 4 Bytes [68, 01, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtOpenThread + B 7C91D669 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtOpenThreadToken + 6 7C91D674 4 Bytes [68, 02, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtOpenThreadToken + B 7C91D679 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtOpenThreadTokenEx + 6 7C91D684 4 Bytes CALL 7B91F48B
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtOpenThreadTokenEx + B 7C91D689 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtQueryAttributesFile + 6 7C91D714 4 Bytes [A8, 00, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtQueryAttributesFile + B 7C91D719 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtQueryFullAttributesFile + 6 7C91D7B4 4 Bytes CALL 7B91F5B9
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtQueryFullAttributesFile + B 7C91D7B9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtSetInformationFile + 6 7C91DC64 4 Bytes [28, 01, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtSetInformationFile + B 7C91DC69 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtSetInformationThread + 6 7C91DCB4 4 Bytes [28, 02, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtSetInformationThread + B 7C91DCB9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 1 Byte [68]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 4 Bytes [68, 03, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1636] ntdll.dll!NtUnmapViewOfSection + B 7C91DF19 1 Byte [E2]
.text C:\Program Files\Mozilla Firefox\firefox.exe[3552] ntdll.dll!LdrLoadDll 7C925CBB 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtCreateFile + 6 7C91D0B4 4 Bytes [28, 00, 38, 00] {SUB [EAX], AL; CMP [EAX], AL}
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtCreateFile + B 7C91D0B9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtMapViewOfSection + 6 7C91D524 1 Byte [28]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtMapViewOfSection + 6 7C91D524 4 Bytes [28, 03, 38, 00] {SUB [EBX], AL; CMP [EAX], AL}
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtMapViewOfSection + B 7C91D529 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenFile + 6 7C91D5A4 4 Bytes [68, 00, 38, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenFile + B 7C91D5A9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenProcess + 6 7C91D604 4 Bytes [A8, 01, 38, 00] {TEST AL, 0x1; CMP [EAX], AL}
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenProcess + B 7C91D609 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenProcessToken + 6 7C91D614 4 Bytes CALL 7B920E1A
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenProcessToken + B 7C91D619 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenProcessTokenEx + 6 7C91D624 4 Bytes [A8, 02, 38, 00] {TEST AL, 0x2; CMP [EAX], AL}
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenProcessTokenEx + B 7C91D629 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenThread + 6 7C91D664 4 Bytes [68, 01, 38, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenThread + B 7C91D669 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenThreadToken + 6 7C91D674 4 Bytes [68, 02, 38, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenThreadToken + B 7C91D679 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenThreadTokenEx + 6 7C91D684 4 Bytes CALL 7B920E8B
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenThreadTokenEx + B 7C91D689 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtQueryAttributesFile + 6 7C91D714 4 Bytes [A8, 00, 38, 00] {TEST AL, 0x0; CMP [EAX], AL}
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtQueryAttributesFile + B 7C91D719 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtQueryFullAttributesFile + 6 7C91D7B4 4 Bytes CALL 7B920FB9
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtQueryFullAttributesFile + B 7C91D7B9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtSetInformationFile + 6 7C91DC64 4 Bytes [28, 01, 38, 00] {SUB [ECX], AL; CMP [EAX], AL}
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtSetInformationFile + B 7C91DC69 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtSetInformationThread + 6 7C91DCB4 4 Bytes [28, 02, 38, 00] {SUB [EDX], AL; CMP [EAX], AL}
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtSetInformationThread + B 7C91DCB9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 1 Byte [68]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 4 Bytes [68, 03, 38, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtUnmapViewOfSection + B 7C91DF19 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtCreateFile + 6 7C91D0B4 4 Bytes [28, 00, 54, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtCreateFile + B 7C91D0B9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtMapViewOfSection + 6 7C91D524 1 Byte [28]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtMapViewOfSection + 6 7C91D524 4 Bytes [28, 03, 54, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtMapViewOfSection + B 7C91D529 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtOpenFile + 6 7C91D5A4 4 Bytes [68, 00, 54, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtOpenFile + B 7C91D5A9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtOpenProcess + 6 7C91D604 4 Bytes [A8, 01, 54, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtOpenProcess + B 7C91D609 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtOpenProcessToken + 6 7C91D614 4 Bytes CALL 7B922A1A
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtOpenProcessToken + B 7C91D619 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtOpenProcessTokenEx + 6 7C91D624 4 Bytes [A8, 02, 54, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtOpenProcessTokenEx + B 7C91D629 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtOpenThread + 6 7C91D664 4 Bytes [68, 01, 54, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtOpenThread + B 7C91D669 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtOpenThreadToken + 6 7C91D674 4 Bytes [68, 02, 54, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtOpenThreadToken + B 7C91D679 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtOpenThreadTokenEx + 6 7C91D684 4 Bytes CALL 7B922A8B
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtOpenThreadTokenEx + B 7C91D689 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtQueryAttributesFile + 6 7C91D714 4 Bytes [A8, 00, 54, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtQueryAttributesFile + B 7C91D719 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtQueryFullAttributesFile + 6 7C91D7B4 4 Bytes CALL 7B922BB9
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtQueryFullAttributesFile + B 7C91D7B9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtSetInformationFile + 6 7C91DC64 4 Bytes [28, 01, 54, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtSetInformationFile + B 7C91DC69 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtSetInformationThread + 6 7C91DCB4 4 Bytes [28, 02, 54, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtSetInformationThread + B 7C91DCB9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 1 Byte [68]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 4 Bytes [68, 03, 54, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4432] ntdll.dll!NtUnmapViewOfSection + B 7C91DF19 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtCreateFile + 6 7C91D0B4 4 Bytes [28, 00, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtCreateFile + B 7C91D0B9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtMapViewOfSection + 6 7C91D524 1 Byte [28]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtMapViewOfSection + 6 7C91D524 4 Bytes [28, 03, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtMapViewOfSection + B 7C91D529 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtOpenFile + 6 7C91D5A4 4 Bytes [68, 00, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtOpenFile + B 7C91D5A9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtOpenProcess + 6 7C91D604 4 Bytes [A8, 01, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtOpenProcess + B 7C91D609 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtOpenProcessToken + 6 7C91D614 4 Bytes CALL 7B91F41A
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtOpenProcessToken + B 7C91D619 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtOpenProcessTokenEx + 6 7C91D624 4 Bytes [A8, 02, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtOpenProcessTokenEx + B 7C91D629 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtOpenThread + 6 7C91D664 4 Bytes [68, 01, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtOpenThread + B 7C91D669 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtOpenThreadToken + 6 7C91D674 4 Bytes [68, 02, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtOpenThreadToken + B 7C91D679 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtOpenThreadTokenEx + 6 7C91D684 4 Bytes CALL 7B91F48B
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtOpenThreadTokenEx + B 7C91D689 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtQueryAttributesFile + 6 7C91D714 4 Bytes [A8, 00, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtQueryAttributesFile + B 7C91D719 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtQueryFullAttributesFile + 6 7C91D7B4 4 Bytes CALL 7B91F5B9
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtQueryFullAttributesFile + B 7C91D7B9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtSetInformationFile + 6 7C91DC64 4 Bytes [28, 01, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtSetInformationFile + B 7C91DC69 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtSetInformationThread + 6 7C91DCB4 4 Bytes [28, 02, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtSetInformationThread + B 7C91DCB9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 1 Byte [68]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 4 Bytes [68, 03, 1E, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[4508] ntdll.dll!NtUnmapViewOfSection + B 7C91DF19 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtCreateFile + 6 7C91D0B4 4 Bytes [28, 00, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtCreateFile + B 7C91D0B9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtMapViewOfSection + 6 7C91D524 1 Byte [28]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtMapViewOfSection + 6 7C91D524 4 Bytes [28, 03, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtMapViewOfSection + B 7C91D529 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtOpenFile + 6 7C91D5A4 4 Bytes [68, 00, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtOpenFile + B 7C91D5A9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtOpenProcess + 6 7C91D604 4 Bytes [A8, 01, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtOpenProcess + B 7C91D609 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtOpenProcessToken + 6 7C91D614 4 Bytes CALL 7B91ED1A
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtOpenProcessToken + B 7C91D619 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtOpenProcessTokenEx + 6 7C91D624 4 Bytes [A8, 02, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtOpenProcessTokenEx + B 7C91D629 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtOpenThread + 6 7C91D664 4 Bytes [68, 01, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtOpenThread + B 7C91D669 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtOpenThreadToken + 6 7C91D674 4 Bytes [68, 02, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtOpenThreadToken + B 7C91D679 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtOpenThreadTokenEx + 6 7C91D684 4 Bytes CALL 7B91ED8B
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtOpenThreadTokenEx + B 7C91D689 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtQueryAttributesFile + 6 7C91D714 4 Bytes [A8, 00, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtQueryAttributesFile + B 7C91D719 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtQueryFullAttributesFile + 6 7C91D7B4 4 Bytes CALL 7B91EEB9
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtQueryFullAttributesFile + B 7C91D7B9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtSetInformationFile + 6 7C91DC64 4 Bytes [28, 01, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtSetInformationFile + B 7C91DC69 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtSetInformationThread + 6 7C91DCB4 4 Bytes [28, 02, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtSetInformationThread + B 7C91DCB9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 1 Byte [68]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 4 Bytes [68, 03, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5536] ntdll.dll!NtUnmapViewOfSection + B 7C91DF19 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtCreateFile + 6 7C91D0B4 4 Bytes [28, 00, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtCreateFile + B 7C91D0B9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtMapViewOfSection + 6 7C91D524 1 Byte [28]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtMapViewOfSection + 6 7C91D524 4 Bytes [28, 03, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtMapViewOfSection + B 7C91D529 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtOpenFile + 6 7C91D5A4 4 Bytes [68, 00, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtOpenFile + B 7C91D5A9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtOpenProcess + 6 7C91D604 4 Bytes [A8, 01, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtOpenProcess + B 7C91D609 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtOpenProcessToken + 6 7C91D614 4 Bytes CALL 7B91ED1A
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtOpenProcessToken + B 7C91D619 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtOpenProcessTokenEx + 6 7C91D624 4 Bytes [A8, 02, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtOpenProcessTokenEx + B 7C91D629 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtOpenThread + 6 7C91D664 4 Bytes [68, 01, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtOpenThread + B 7C91D669 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtOpenThreadToken + 6 7C91D674 4 Bytes [68, 02, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtOpenThreadToken + B 7C91D679 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtOpenThreadTokenEx + 6 7C91D684 4 Bytes CALL 7B91ED8B
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtOpenThreadTokenEx + B 7C91D689 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtQueryAttributesFile + 6 7C91D714 4 Bytes [A8, 00, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtQueryAttributesFile + B 7C91D719 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtQueryFullAttributesFile + 6 7C91D7B4 4 Bytes CALL 7B91EEB9
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtQueryFullAttributesFile + B 7C91D7B9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtSetInformationFile + 6 7C91DC64 4 Bytes [28, 01, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtSetInformationFile + B 7C91DC69 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtSetInformationThread + 6 7C91DCB4 4 Bytes [28, 02, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtSetInformationThread + B 7C91DCB9 1 Byte [E2]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 1 Byte [68]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 4 Bytes [68, 03, 17, 00]
.text C:\Documents and Settings\too\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[5636] ntdll.dll!NtUnmapViewOfSection + B 7C91DF19 1 Byte [E2]
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 86BCC1E8
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip aswRdr.SYS (avast! TDI RDR Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \Driver\NetBT \Device\NetBT_Tcpip_{613204EE-298B-4D65-9383-CB5087F42D50} 86A1C430
Device \Driver\usbuhci \Device\USBPDO-0 868BC1E8
Device \Driver\usbuhci \Device\USBPDO-1 868BC1E8
Device \Driver\usbuhci \Device\USBPDO-2 868BC1E8
Device \Driver\usbehci \Device\USBPDO-3 869AD1E8
Device \Driver\usbuhci \Device\USBPDO-4 868BC1E8
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp aswRdr.SYS (avast! TDI RDR Driver/ALWIL Software)
Device \Driver\usbuhci \Device\USBPDO-5 868BC1E8
Device \Driver\usbuhci \Device\USBPDO-6 868BC1E8
Device \Driver\PCI_PNP5164 \Device\00000057 sptd.sys (SCSI Pass Through Direct Host/Duplex Secure Ltd.)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 snapman.sys (Acronis Snapshot API/Acronis)
Device \Driver\usbehci \Device\USBPDO-7 869AD1E8
Device \Driver\Cdrom \Device\CdRom0 869881E8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 86BCD1E8
Device \Driver\atapi \Device\Ide\IdePort0 86BCD1E8
Device \Driver\atapi \Device\Ide\IdePort1 86BCD1E8
Device \Driver\atapi \Device\Ide\IdePort2 86BCD1E8
Device \Driver\atapi \Device\Ide\IdePort3 86BCD1E8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-12 86BCD1E8
Device \Driver\Cdrom \Device\CdRom1 869881E8
Device \Driver\NetBT \Device\NetBt_Wins_Export 86A1C430
Device \Driver\NetBT \Device\NetBT_Tcpip_{FB9CD8EC-1988-48E9-953C-88B70A14CA0E} 86A1C430
Device \Driver\NetBT \Device\NetbiosSmb 86A1C430
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp aswRdr.SYS (avast! TDI RDR Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\usbuhci \Device\USBFDO-0 868BC1E8
Device \Driver\usbuhci \Device\USBFDO-1 868BC1E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 86A14430
Device \Driver\usbuhci \Device\USBFDO-2 868BC1E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 86A14430
Device \Driver\usbehci \Device\USBFDO-3 869AD1E8
Device \Driver\usbuhci \Device\USBFDO-4 868BC1E8
Device \Driver\usbuhci \Device\USBFDO-5 868BC1E8
Device \Driver\usbuhci \Device\USBFDO-6 868BC1E8
Device \Driver\usbehci \Device\USBFDO-7 869AD1E8
Device \Driver\a424jami \Device\Scsi\a424jami1Port4Path0Target0Lun0 8687A1E8
Device \Driver\a424jami \Device\Scsi\a424jami1 8687A1E8
Device \FileSystem\Cdfs \Cdfs 854AB430
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xAB 0xCA 0xF6 0x1E ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x8A 0x8C 0x57 0xDA ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x2E 0x9A 0xAD 0x9C ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x88 0xA5 0x2C 0x26 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x8A 0x8C 0x57 0xDA ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x2E 0x9A 0xAD 0x9C ...
---- Files - GMER 1.0.15 ----
File C:\Documents and Settings\Ghali\Application Data\Macromedia\Flash Player\#SharedObjects\TE798RBT\simply-land.com.\main.swf 0 bytes
File C:\Documents and Settings\Ghali\Application Data\Macromedia\Flash Player\#SharedObjects\TE798RBT\simply-land.com.\main.swf\gael.sound.Engine.root.volume.sol 65 bytes
File C:\Documents and Settings\Ghali\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#simply-land.com.\settings.sol 86 bytes
---- EOF - GMER 1.0.15 ----