GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-02-07 09:44:04
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD32 rev.02.0
Running: rcv3jvsq.exe; Driver: C:\Users\Toby\AppData\Local\Temp\kxlcrkoc.sys
---- System - GMER 1.0.15 ----
SSDT 87D33130 ZwConnectPort
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13D1 82A49369 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82A82D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 1193 82A89E48 4 Bytes [30, 31, D3, 87]
---- User code sections - GMER 1.0.15 ----
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtCreateFile + 6 774855CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtCreateFile + B 774855D3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtMapViewOfSection + 6 77485C2E 1 Byte [28]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtMapViewOfSection + 6 77485C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtMapViewOfSection + B 77485C33 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtOpenFile + 6 77485CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtOpenFile + B 77485CE3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtOpenProcess + 6 77485D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtOpenProcess + B 77485D93 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtOpenProcessToken + 6 77485D9E 4 Bytes CALL 764864A4 C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation)
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtOpenProcessToken + B 77485DA3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtOpenProcessTokenEx + 6 77485DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtOpenProcessTokenEx + B 77485DB3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtOpenThread + 6 77485E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtOpenThread + B 77485E13 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtOpenThreadToken + 6 77485E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtOpenThreadToken + B 77485E23 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtOpenThreadTokenEx + 6 77485E2E 4 Bytes CALL 76486535 C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation)
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtOpenThreadTokenEx + B 77485E33 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtQueryAttributesFile + 6 77485F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtQueryAttributesFile + B 77485F43 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtQueryFullAttributesFile + 6 77485FEE 4 Bytes CALL 764866F3 C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation)
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtQueryFullAttributesFile + B 77485FF3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtSetInformationFile + 6 7748663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtSetInformationFile + B 77486643 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtSetInformationThread + 6 7748669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtSetInformationThread + B 774866A3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtUnmapViewOfSection + 6 774869BE 1 Byte [68]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtUnmapViewOfSection + 6 774869BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4788] ntdll.dll!NtUnmapViewOfSection + B 774869C3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtCreateFile + 6 774855CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtCreateFile + B 774855D3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtMapViewOfSection + 6 77485C2E 1 Byte [28]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtMapViewOfSection + 6 77485C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtMapViewOfSection + B 77485C33 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtOpenFile + 6 77485CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtOpenFile + B 77485CE3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtOpenProcess + 6 77485D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtOpenProcess + B 77485D93 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtOpenProcessToken + 6 77485D9E 4 Bytes CALL 764864A4 C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation)
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtOpenProcessToken + B 77485DA3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtOpenProcessTokenEx + 6 77485DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtOpenProcessTokenEx + B 77485DB3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtOpenThread + 6 77485E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtOpenThread + B 77485E13 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtOpenThreadToken + 6 77485E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtOpenThreadToken + B 77485E23 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtOpenThreadTokenEx + 6 77485E2E 4 Bytes CALL 76486535 C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation)
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtOpenThreadTokenEx + B 77485E33 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtQueryAttributesFile + 6 77485F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtQueryAttributesFile + B 77485F43 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtQueryFullAttributesFile + 6 77485FEE 4 Bytes CALL 764866F3 C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation)
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtQueryFullAttributesFile + B 77485FF3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtSetInformationFile + 6 7748663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtSetInformationFile + B 77486643 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtSetInformationThread + 6 7748669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtSetInformationThread + B 774866A3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtUnmapViewOfSection + 6 774869BE 1 Byte [68]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtUnmapViewOfSection + 6 774869BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4872] ntdll.dll!NtUnmapViewOfSection + B 774869C3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtCreateFile + 6 774855CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtCreateFile + B 774855D3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtMapViewOfSection + 6 77485C2E 1 Byte [28]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtMapViewOfSection + 6 77485C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtMapViewOfSection + B 77485C33 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtOpenFile + 6 77485CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtOpenFile + B 77485CE3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtOpenProcess + 6 77485D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtOpenProcess + B 77485D93 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtOpenProcessToken + 6 77485D9E 4 Bytes CALL 764864A4 C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation)
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtOpenProcessToken + B 77485DA3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtOpenProcessTokenEx + 6 77485DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtOpenProcessTokenEx + B 77485DB3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtOpenThread + 6 77485E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtOpenThread + B 77485E13 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtOpenThreadToken + 6 77485E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtOpenThreadToken + B 77485E23 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtOpenThreadTokenEx + 6 77485E2E 4 Bytes CALL 76486535 C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation)
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtOpenThreadTokenEx + B 77485E33 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtQueryAttributesFile + 6 77485F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtQueryAttributesFile + B 77485F43 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtQueryFullAttributesFile + 6 77485FEE 4 Bytes CALL 764866F3 C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation)
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtQueryFullAttributesFile + B 77485FF3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtSetInformationFile + 6 7748663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtSetInformationFile + B 77486643 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtSetInformationThread + 6 7748669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtSetInformationThread + B 774866A3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtUnmapViewOfSection + 6 774869BE 1 Byte [68]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtUnmapViewOfSection + 6 774869BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[4880] ntdll.dll!NtUnmapViewOfSection + B 774869C3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtCreateFile + 6 774855CE 4 Bytes [28, 00, 17, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtCreateFile + B 774855D3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtMapViewOfSection + 6 77485C2E 1 Byte [28]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtMapViewOfSection + 6 77485C2E 4 Bytes [28, 03, 17, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtMapViewOfSection + B 77485C33 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtOpenFile + 6 77485CDE 4 Bytes [68, 00, 17, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtOpenFile + B 77485CE3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtOpenProcess + 6 77485D8E 4 Bytes [A8, 01, 17, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtOpenProcess + B 77485D93 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtOpenProcessToken + 6 77485D9E 4 Bytes CALL 764874A4 C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation)
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtOpenProcessToken + B 77485DA3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtOpenProcessTokenEx + 6 77485DAE 4 Bytes [A8, 02, 17, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtOpenProcessTokenEx + B 77485DB3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtOpenThread + 6 77485E0E 4 Bytes [68, 01, 17, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtOpenThread + B 77485E13 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtOpenThreadToken + 6 77485E1E 4 Bytes [68, 02, 17, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtOpenThreadToken + B 77485E23 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtOpenThreadTokenEx + 6 77485E2E 4 Bytes CALL 76487535 C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation)
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtOpenThreadTokenEx + B 77485E33 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtQueryAttributesFile + 6 77485F3E 4 Bytes [A8, 00, 17, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtQueryAttributesFile + B 77485F43 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtQueryFullAttributesFile + 6 77485FEE 4 Bytes CALL 764876F3 C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation)
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtQueryFullAttributesFile + B 77485FF3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtSetInformationFile + 6 7748663E 4 Bytes [28, 01, 17, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtSetInformationFile + B 77486643 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtSetInformationThread + 6 7748669E 4 Bytes [28, 02, 17, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtSetInformationThread + B 774866A3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtUnmapViewOfSection + 6 774869BE 1 Byte [68]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtUnmapViewOfSection + 6 774869BE 4 Bytes [68, 03, 17, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[6748] ntdll.dll!NtUnmapViewOfSection + B 774869C3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtCreateFile + 6 774855CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtCreateFile + B 774855D3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtMapViewOfSection + 6 77485C2E 1 Byte [28]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtMapViewOfSection + 6 77485C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtMapViewOfSection + B 77485C33 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtOpenFile + 6 77485CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtOpenFile + B 77485CE3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtOpenProcess + 6 77485D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtOpenProcess + B 77485D93 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtOpenProcessToken + 6 77485D9E 4 Bytes CALL 764864A4 C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation)
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtOpenProcessToken + B 77485DA3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtOpenProcessTokenEx + 6 77485DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtOpenProcessTokenEx + B 77485DB3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtOpenThread + 6 77485E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtOpenThread + B 77485E13 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtOpenThreadToken + 6 77485E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtOpenThreadToken + B 77485E23 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtOpenThreadTokenEx + 6 77485E2E 4 Bytes CALL 76486535 C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation)
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtOpenThreadTokenEx + B 77485E33 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtQueryAttributesFile + 6 77485F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtQueryAttributesFile + B 77485F43 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtQueryFullAttributesFile + 6 77485FEE 4 Bytes CALL 764866F3 C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation)
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtQueryFullAttributesFile + B 77485FF3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtSetInformationFile + 6 7748663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtSetInformationFile + B 77486643 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtSetInformationThread + 6 7748669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtSetInformationThread + B 774866A3 1 Byte [E2]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtUnmapViewOfSection + 6 774869BE 1 Byte [68]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtUnmapViewOfSection + 6 774869BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Toby\AppData\Local\Google\Chrome\Application\chrome.exe[7096] ntdll.dll!NtUnmapViewOfSection + B 774869C3 1 Byte [E2]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\System32\rundll32.exe[1564] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [7548FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[1564] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [7548FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[1564] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [7548FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[1564] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [7548FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[1564] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [7548FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[2532] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [7548FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[2532] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [7548FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[2532] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [7548FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[2532] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [7548FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[2532] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [7548FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[2532] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [7548FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3176] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [7548FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3176] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [7548FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3176] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [7548FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3176] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [7548FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Lenovo\System Update\SUService.exe[4520] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [7548FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Lenovo\System Update\SUService.exe[4520] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [7548FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Lenovo\System Update\SUService.exe[4520] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [7548FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Lenovo\System Update\SUService.exe[4520] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [7548FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Lenovo\System Update\SUService.exe[4520] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [7548FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Lenovo\System Update\SUService.exe[4520] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [7548FFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\00000059 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\889ffaec58f9
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\889ffaec58f9 (not active ControlSet)
---- Files - GMER 1.0.15 ----
File C:\Windows\$NtUninstallKB43229$\4139144665 0 bytes
File C:\Windows\$NtUninstallKB43229$\4274476570 0 bytes
File C:\Windows\$NtUninstallKB43229$\4274476570\@ 2048 bytes
File C:\Windows\$NtUninstallKB43229$\4274476570\bckfg.tmp 842 bytes
File C:\Windows\$NtUninstallKB43229$\4274476570\cfg.ini 208 bytes
File C:\Windows\$NtUninstallKB43229$\4274476570\Desktop.ini 4608 bytes
File C:\Windows\$NtUninstallKB43229$\4274476570\keywords 178 bytes
File C:\Windows\$NtUninstallKB43229$\4274476570\kwrd.dll 223744 bytes
File C:\Windows\$NtUninstallKB43229$\4274476570\L 0 bytes
File C:\Windows\$NtUninstallKB43229$\4274476570\L\xadqgnnk 78336 bytes
File C:\Windows\$NtUninstallKB43229$\4274476570\lsflt7.ver 5176 bytes
File C:\Windows\$NtUninstallKB43229$\4274476570\U 0 bytes
File C:\Windows\$NtUninstallKB43229$\4274476570\U\00000001.@ 2048 bytes
File C:\Windows\$NtUninstallKB43229$\4274476570\U\00000002.@ 224768 bytes
File C:\Windows\$NtUninstallKB43229$\4274476570\U\00000004.@ 1024 bytes
File C:\Windows\$NtUninstallKB43229$\4274476570\U\80000000.@ 1024 bytes
File C:\Windows\$NtUninstallKB43229$\4274476570\U\80000004.@ 12800 bytes
File C:\Windows\$NtUninstallKB43229$\4274476570\U\80000032.@ 98304 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{6CAC07DB-515B-11E1-9713-F0DEF1758608}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{6CAC07DC-515B-11E1-9713-F0DEF1758608}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{6CAC07DD-515B-11E1-9713-F0DEF1758608}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{6CAC07DE-515B-11E1-9713-F0DEF1758608}.dat 4096 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{6CAC07DF-515B-11E1-9713-F0DEF1758608}.dat 4096 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{FA68174C-515B-11E1-9713-F0DEF1758608}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{FA68174D-515B-11E1-9713-F0DEF1758608}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{FA68174E-515B-11E1-9713-F0DEF1758608}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{FA68174F-515B-11E1-9713-F0DEF1758608}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{0E06AECE-515C-11E1-9713-F0DEF1758608}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{0E06AECF-515C-11E1-9713-F0DEF1758608}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{0E06AED0-515C-11E1-9713-F0DEF1758608}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{0E06AED1-515C-11E1-9713-F0DEF1758608}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{B1C34EC3-515C-11E1-9713-F0DEF1758608}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{B1C34EC4-515C-11E1-9713-F0DEF1758608}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{B1C34EC5-515C-11E1-9713-F0DEF1758608}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{B1C34EC6-515C-11E1-9713-F0DEF1758608}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{07122981-515C-11E1-9713-F0DEF1758608}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{07122982-515C-11E1-9713-F0DEF1758608}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{07122983-515C-11E1-9713-F0DEF1758608}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{07122984-515C-11E1-9713-F0DEF1758608}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{48ACD113-515C-11E1-9713-F0DEF1758608}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{48ACD114-515C-11E1-9713-F0DEF1758608}.dat 4608 bytes
File C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{48ACD115-515C-11E1-9713-F0DEF1758608}.dat 4608 bytes