Hi,
I received the BSOD whilst browsing the web this afternoon and each time I restart my computer in normal mode I get another blue screen. Initially I thought it was a hardware problem, however, having successfully booted into safe mode (with networking) my browser seems to be redirecting me to sites like eBay (and some dodgy looking ‘virus removal’ software) - leading me to think that this could be a malware issue.
Does this sound plausible? I'm not sure how common it is for malware to affect computers in this way. If it’s more likely to be a hardware problem then I could head across to the forum for that.
See attached logs below. They have all be obtained in Safe Mode as I can’t run normal mode without crashing.
Malware Log:
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8403
Windows 6.1.7601 Service Pack 1 (Safe Mode)
Internet Explorer 9.0.8112.16421
20/12/2011 19:31:10
mbam-log-2011-12-20 (19-31-10).txt
Scan type: Quick scan
Objects scanned: 163049
Time elapsed: 4 minute(s), 38 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER Log:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-12-20 19:58:02
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\iaStor0 Hitachi_ rev.SBDO
Running: i33ofei6.exe; Driver: C:\Users\Ben\AppData\Local\Temp\uwldqpow.sys
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13D1 82251369 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 8228AD52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
---- User code sections - GMER 1.0.15 ----
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtCreateFile + 6 76FE55CE 4 Bytes [28, 00, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtCreateFile + B 76FE55D3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 1 Byte [28]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 4 Bytes [28, 03, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtMapViewOfSection + B 76FE5C33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenFile + 6 76FE5CDE 4 Bytes [68, 00, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenFile + B 76FE5CE3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenProcess + 6 76FE5D8E 4 Bytes [A8, 01, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenProcess + B 76FE5D93 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenProcessToken + 6 76FE5D9E 4 Bytes CALL 75FE74A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenProcessToken + B 76FE5DA3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenProcessTokenEx + 6 76FE5DAE 4 Bytes [A8, 02, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenProcessTokenEx + B 76FE5DB3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenThread + 6 76FE5E0E 4 Bytes [68, 01, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenThread + B 76FE5E13 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenThreadToken + 6 76FE5E1E 4 Bytes [68, 02, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenThreadToken + B 76FE5E23 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenThreadTokenEx + 6 76FE5E2E 4 Bytes CALL 75FE7535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenThreadTokenEx + B 76FE5E33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtQueryAttributesFile + 6 76FE5F3E 4 Bytes [A8, 00, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtQueryAttributesFile + B 76FE5F43 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtQueryFullAttributesFile + 6 76FE5FEE 4 Bytes CALL 75FE76F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtQueryFullAttributesFile + B 76FE5FF3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtSetInformationFile + 6 76FE663E 4 Bytes [28, 01, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtSetInformationFile + B 76FE6643 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtSetInformationThread + 6 76FE669E 4 Bytes [28, 02, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtSetInformationThread + B 76FE66A3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 1 Byte [68]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 4 Bytes [68, 03, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtUnmapViewOfSection + B 76FE69C3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtCreateFile + 6 76FE55CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtCreateFile + B 76FE55D3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 1 Byte [28]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtMapViewOfSection + B 76FE5C33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenFile + 6 76FE5CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenFile + B 76FE5CE3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenProcess + 6 76FE5D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenProcess + B 76FE5D93 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenProcessToken + 6 76FE5D9E 4 Bytes CALL 75FE64A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenProcessToken + B 76FE5DA3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenProcessTokenEx + 6 76FE5DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenProcessTokenEx + B 76FE5DB3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenThread + 6 76FE5E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenThread + B 76FE5E13 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenThreadToken + 6 76FE5E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenThreadToken + B 76FE5E23 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenThreadTokenEx + 6 76FE5E2E 4 Bytes CALL 75FE6535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenThreadTokenEx + B 76FE5E33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtQueryAttributesFile + 6 76FE5F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtQueryAttributesFile + B 76FE5F43 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtQueryFullAttributesFile + 6 76FE5FEE 4 Bytes CALL 75FE66F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtQueryFullAttributesFile + B 76FE5FF3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtSetInformationFile + 6 76FE663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtSetInformationFile + B 76FE6643 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtSetInformationThread + 6 76FE669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtSetInformationThread + B 76FE66A3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 1 Byte [68]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtUnmapViewOfSection + B 76FE69C3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtCreateFile + 6 76FE55CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtCreateFile + B 76FE55D3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 1 Byte [28]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtMapViewOfSection + B 76FE5C33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenFile + 6 76FE5CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenFile + B 76FE5CE3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenProcess + 6 76FE5D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenProcess + B 76FE5D93 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenProcessToken + 6 76FE5D9E 4 Bytes CALL 75FE64A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenProcessToken + B 76FE5DA3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenProcessTokenEx + 6 76FE5DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenProcessTokenEx + B 76FE5DB3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenThread + 6 76FE5E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenThread + B 76FE5E13 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenThreadToken + 6 76FE5E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenThreadToken + B 76FE5E23 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenThreadTokenEx + 6 76FE5E2E 4 Bytes CALL 75FE6535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenThreadTokenEx + B 76FE5E33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtQueryAttributesFile + 6 76FE5F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtQueryAttributesFile + B 76FE5F43 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtQueryFullAttributesFile + 6 76FE5FEE 4 Bytes CALL 75FE66F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtQueryFullAttributesFile + B 76FE5FF3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtSetInformationFile + 6 76FE663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtSetInformationFile + B 76FE6643 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtSetInformationThread + 6 76FE669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtSetInformationThread + B 76FE66A3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 1 Byte [68]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtUnmapViewOfSection + B 76FE69C3 1 Byte [E2]
.text C:\Windows\system32\svchost.exe[980] ntdll.dll!NtProtectVirtualMemory 76FE5F18 5 Bytes JMP 001B000A
.text C:\Windows\system32\svchost.exe[980] ntdll.dll!NtWriteVirtualMemory 76FE6A98 5 Bytes JMP 0045000A
.text C:\Windows\system32\svchost.exe[980] ntdll.dll!KiUserExceptionDispatcher 76FE7008 5 Bytes JMP 001A000A
.text C:\Windows\Explorer.EXE[1224] ntdll.dll!NtProtectVirtualMemory 76FE5F18 5 Bytes JMP 0071000A
.text C:\Windows\Explorer.EXE[1224] ntdll.dll!NtWriteVirtualMemory 76FE6A98 5 Bytes JMP 0072000A
.text C:\Windows\Explorer.EXE[1224] ntdll.dll!KiUserExceptionDispatcher 76FE7008 5 Bytes JMP 005C000A
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtCreateFile + 6 76FE55CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtCreateFile + B 76FE55D3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 1 Byte [28]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtMapViewOfSection + B 76FE5C33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenFile + 6 76FE5CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenFile + B 76FE5CE3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenProcess + 6 76FE5D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenProcess + B 76FE5D93 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenProcessToken + 6 76FE5D9E 4 Bytes CALL 75FE64A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenProcessToken + B 76FE5DA3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenProcessTokenEx + 6 76FE5DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenProcessTokenEx + B 76FE5DB3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenThread + 6 76FE5E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenThread + B 76FE5E13 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenThreadToken + 6 76FE5E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenThreadToken + B 76FE5E23 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenThreadTokenEx + 6 76FE5E2E 4 Bytes CALL 75FE6535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenThreadTokenEx + B 76FE5E33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtQueryAttributesFile + 6 76FE5F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtQueryAttributesFile + B 76FE5F43 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtQueryFullAttributesFile + 6 76FE5FEE 4 Bytes CALL 75FE66F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtQueryFullAttributesFile + B 76FE5FF3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtSetInformationFile + 6 76FE663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtSetInformationFile + B 76FE6643 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtSetInformationThread + 6 76FE669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtSetInformationThread + B 76FE66A3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 1 Byte [68]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtUnmapViewOfSection + B 76FE69C3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtCreateFile + 6 76FE55CE 4 Bytes [28, 00, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtCreateFile + B 76FE55D3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 1 Byte [28]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 4 Bytes [28, 03, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtMapViewOfSection + B 76FE5C33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenFile + 6 76FE5CDE 4 Bytes [68, 00, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenFile + B 76FE5CE3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenProcess + 6 76FE5D8E 4 Bytes [A8, 01, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenProcess + B 76FE5D93 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenProcessToken + 6 76FE5D9E 4 Bytes CALL 75FE74A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenProcessToken + B 76FE5DA3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenProcessTokenEx + 6 76FE5DAE 4 Bytes [A8, 02, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenProcessTokenEx + B 76FE5DB3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenThread + 6 76FE5E0E 4 Bytes [68, 01, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenThread + B 76FE5E13 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenThreadToken + 6 76FE5E1E 4 Bytes [68, 02, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenThreadToken + B 76FE5E23 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenThreadTokenEx + 6 76FE5E2E 4 Bytes CALL 75FE7535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenThreadTokenEx + B 76FE5E33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtQueryAttributesFile + 6 76FE5F3E 4 Bytes [A8, 00, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtQueryAttributesFile + B 76FE5F43 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtQueryFullAttributesFile + 6 76FE5FEE 4 Bytes CALL 75FE76F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtQueryFullAttributesFile + B 76FE5FF3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtSetInformationFile + 6 76FE663E 4 Bytes [28, 01, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtSetInformationFile + B 76FE6643 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtSetInformationThread + 6 76FE669E 4 Bytes [28, 02, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtSetInformationThread + B 76FE66A3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 1 Byte [68]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 4 Bytes [68, 03, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtUnmapViewOfSection + B 76FE69C3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtCreateFile + 6 76FE55CE 4 Bytes [28, 00, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtCreateFile + B 76FE55D3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 1 Byte [28]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 4 Bytes [28, 03, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtMapViewOfSection + B 76FE5C33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenFile + 6 76FE5CDE 4 Bytes [68, 00, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenFile + B 76FE5CE3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenProcess + 6 76FE5D8E 4 Bytes [A8, 01, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenProcess + B 76FE5D93 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenProcessToken + 6 76FE5D9E 4 Bytes CALL 75FE74A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenProcessToken + B 76FE5DA3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenProcessTokenEx + 6 76FE5DAE 4 Bytes [A8, 02, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenProcessTokenEx + B 76FE5DB3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenThread + 6 76FE5E0E 4 Bytes [68, 01, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenThread + B 76FE5E13 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenThreadToken + 6 76FE5E1E 4 Bytes [68, 02, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenThreadToken + B 76FE5E23 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenThreadTokenEx + 6 76FE5E2E 4 Bytes CALL 75FE7535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenThreadTokenEx + B 76FE5E33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtQueryAttributesFile + 6 76FE5F3E 4 Bytes [A8, 00, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtQueryAttributesFile + B 76FE5F43 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtQueryFullAttributesFile + 6 76FE5FEE 4 Bytes CALL 75FE76F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtQueryFullAttributesFile + B 76FE5FF3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtSetInformationFile + 6 76FE663E 4 Bytes [28, 01, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtSetInformationFile + B 76FE6643 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtSetInformationThread + 6 76FE669E 4 Bytes [28, 02, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtSetInformationThread + B 76FE66A3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 1 Byte [68]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 4 Bytes [68, 03, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtUnmapViewOfSection + B 76FE69C3 1 Byte [E2]
.text C:\Windows\System32\ping.exe[3960] ntdll.dll!NtCreateProcess 76FE5698 5 Bytes JMP 005B000A
.text C:\Windows\System32\ping.exe[3960] ntdll.dll!NtCreateProcessEx 76FE56A8 5 Bytes JMP 0060000A
.text C:\Windows\System32\ping.exe[3960] ntdll.dll!NtCreateUserProcess 76FE5778 5 Bytes JMP 0065000A
.text C:\Windows\System32\ping.exe[3960] ntdll.dll!NtProtectVirtualMemory 76FE5F18 5 Bytes JMP 0026000A
.text C:\Windows\System32\ping.exe[3960] ntdll.dll!NtWriteVirtualMemory 76FE6A98 5 Bytes JMP 0054000A
.text C:\Windows\System32\ping.exe[3960] ntdll.dll!KiUserExceptionDispatcher 76FE7008 5 Bytes JMP 000D000A
.text C:\Windows\System32\ping.exe[3960] USER32.dll!GetCursorPos 7543A4B3 5 Bytes JMP 0068000A
.text C:\Windows\System32\ping.exe[3960] USER32.dll!GetForegroundWindow 7544335D 5 Bytes JMP 007A000A
.text C:\Windows\System32\ping.exe[3960] USER32.dll!WindowFromPoint 75466BE9 5 Bytes JMP 0079000A
.text C:\Windows\System32\ping.exe[3960] ole32.dll!CoCreateInstance 759B9D0B 5 Bytes JMP 0067000A
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp aswRdr.SYS (avast! TDI RDR Driver/AVAST Software)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\00000071 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 MBR read error
Disk \Device\Harddisk0\DR0 MBR BIOS signature not found 0
---- Files - GMER 1.0.15 ----
File C:\Windows\$NtUninstallKB188$\104013258 0 bytes
File C:\Windows\$NtUninstallKB188$\2782373227 0 bytes
File C:\Windows\$NtUninstallKB188$\2782373227\L 0 bytes
File C:\Windows\$NtUninstallKB188$\2782373227\U 0 bytes
---- EOF - GMER 1.0.15 ----
I received the BSOD whilst browsing the web this afternoon and each time I restart my computer in normal mode I get another blue screen. Initially I thought it was a hardware problem, however, having successfully booted into safe mode (with networking) my browser seems to be redirecting me to sites like eBay (and some dodgy looking ‘virus removal’ software) - leading me to think that this could be a malware issue.
Does this sound plausible? I'm not sure how common it is for malware to affect computers in this way. If it’s more likely to be a hardware problem then I could head across to the forum for that.
See attached logs below. They have all be obtained in Safe Mode as I can’t run normal mode without crashing.
Malware Log:
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8403
Windows 6.1.7601 Service Pack 1 (Safe Mode)
Internet Explorer 9.0.8112.16421
20/12/2011 19:31:10
mbam-log-2011-12-20 (19-31-10).txt
Scan type: Quick scan
Objects scanned: 163049
Time elapsed: 4 minute(s), 38 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER Log:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-12-20 19:58:02
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\iaStor0 Hitachi_ rev.SBDO
Running: i33ofei6.exe; Driver: C:\Users\Ben\AppData\Local\Temp\uwldqpow.sys
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13D1 82251369 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 8228AD52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
---- User code sections - GMER 1.0.15 ----
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtCreateFile + 6 76FE55CE 4 Bytes [28, 00, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtCreateFile + B 76FE55D3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 1 Byte [28]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 4 Bytes [28, 03, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtMapViewOfSection + B 76FE5C33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenFile + 6 76FE5CDE 4 Bytes [68, 00, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenFile + B 76FE5CE3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenProcess + 6 76FE5D8E 4 Bytes [A8, 01, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenProcess + B 76FE5D93 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenProcessToken + 6 76FE5D9E 4 Bytes CALL 75FE74A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenProcessToken + B 76FE5DA3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenProcessTokenEx + 6 76FE5DAE 4 Bytes [A8, 02, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenProcessTokenEx + B 76FE5DB3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenThread + 6 76FE5E0E 4 Bytes [68, 01, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenThread + B 76FE5E13 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenThreadToken + 6 76FE5E1E 4 Bytes [68, 02, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenThreadToken + B 76FE5E23 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenThreadTokenEx + 6 76FE5E2E 4 Bytes CALL 75FE7535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtOpenThreadTokenEx + B 76FE5E33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtQueryAttributesFile + 6 76FE5F3E 4 Bytes [A8, 00, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtQueryAttributesFile + B 76FE5F43 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtQueryFullAttributesFile + 6 76FE5FEE 4 Bytes CALL 75FE76F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtQueryFullAttributesFile + B 76FE5FF3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtSetInformationFile + 6 76FE663E 4 Bytes [28, 01, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtSetInformationFile + B 76FE6643 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtSetInformationThread + 6 76FE669E 4 Bytes [28, 02, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtSetInformationThread + B 76FE66A3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 1 Byte [68]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 4 Bytes [68, 03, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[152] ntdll.dll!NtUnmapViewOfSection + B 76FE69C3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtCreateFile + 6 76FE55CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtCreateFile + B 76FE55D3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 1 Byte [28]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtMapViewOfSection + B 76FE5C33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenFile + 6 76FE5CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenFile + B 76FE5CE3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenProcess + 6 76FE5D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenProcess + B 76FE5D93 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenProcessToken + 6 76FE5D9E 4 Bytes CALL 75FE64A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenProcessToken + B 76FE5DA3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenProcessTokenEx + 6 76FE5DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenProcessTokenEx + B 76FE5DB3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenThread + 6 76FE5E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenThread + B 76FE5E13 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenThreadToken + 6 76FE5E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenThreadToken + B 76FE5E23 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenThreadTokenEx + 6 76FE5E2E 4 Bytes CALL 75FE6535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtOpenThreadTokenEx + B 76FE5E33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtQueryAttributesFile + 6 76FE5F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtQueryAttributesFile + B 76FE5F43 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtQueryFullAttributesFile + 6 76FE5FEE 4 Bytes CALL 75FE66F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtQueryFullAttributesFile + B 76FE5FF3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtSetInformationFile + 6 76FE663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtSetInformationFile + B 76FE6643 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtSetInformationThread + 6 76FE669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtSetInformationThread + B 76FE66A3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 1 Byte [68]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[328] ntdll.dll!NtUnmapViewOfSection + B 76FE69C3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtCreateFile + 6 76FE55CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtCreateFile + B 76FE55D3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 1 Byte [28]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtMapViewOfSection + B 76FE5C33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenFile + 6 76FE5CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenFile + B 76FE5CE3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenProcess + 6 76FE5D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenProcess + B 76FE5D93 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenProcessToken + 6 76FE5D9E 4 Bytes CALL 75FE64A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenProcessToken + B 76FE5DA3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenProcessTokenEx + 6 76FE5DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenProcessTokenEx + B 76FE5DB3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenThread + 6 76FE5E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenThread + B 76FE5E13 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenThreadToken + 6 76FE5E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenThreadToken + B 76FE5E23 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenThreadTokenEx + 6 76FE5E2E 4 Bytes CALL 75FE6535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtOpenThreadTokenEx + B 76FE5E33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtQueryAttributesFile + 6 76FE5F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtQueryAttributesFile + B 76FE5F43 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtQueryFullAttributesFile + 6 76FE5FEE 4 Bytes CALL 75FE66F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtQueryFullAttributesFile + B 76FE5FF3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtSetInformationFile + 6 76FE663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtSetInformationFile + B 76FE6643 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtSetInformationThread + 6 76FE669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtSetInformationThread + B 76FE66A3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 1 Byte [68]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[424] ntdll.dll!NtUnmapViewOfSection + B 76FE69C3 1 Byte [E2]
.text C:\Windows\system32\svchost.exe[980] ntdll.dll!NtProtectVirtualMemory 76FE5F18 5 Bytes JMP 001B000A
.text C:\Windows\system32\svchost.exe[980] ntdll.dll!NtWriteVirtualMemory 76FE6A98 5 Bytes JMP 0045000A
.text C:\Windows\system32\svchost.exe[980] ntdll.dll!KiUserExceptionDispatcher 76FE7008 5 Bytes JMP 001A000A
.text C:\Windows\Explorer.EXE[1224] ntdll.dll!NtProtectVirtualMemory 76FE5F18 5 Bytes JMP 0071000A
.text C:\Windows\Explorer.EXE[1224] ntdll.dll!NtWriteVirtualMemory 76FE6A98 5 Bytes JMP 0072000A
.text C:\Windows\Explorer.EXE[1224] ntdll.dll!KiUserExceptionDispatcher 76FE7008 5 Bytes JMP 005C000A
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtCreateFile + 6 76FE55CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtCreateFile + B 76FE55D3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 1 Byte [28]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtMapViewOfSection + B 76FE5C33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenFile + 6 76FE5CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenFile + B 76FE5CE3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenProcess + 6 76FE5D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenProcess + B 76FE5D93 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenProcessToken + 6 76FE5D9E 4 Bytes CALL 75FE64A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenProcessToken + B 76FE5DA3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenProcessTokenEx + 6 76FE5DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenProcessTokenEx + B 76FE5DB3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenThread + 6 76FE5E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenThread + B 76FE5E13 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenThreadToken + 6 76FE5E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenThreadToken + B 76FE5E23 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenThreadTokenEx + 6 76FE5E2E 4 Bytes CALL 75FE6535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtOpenThreadTokenEx + B 76FE5E33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtQueryAttributesFile + 6 76FE5F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtQueryAttributesFile + B 76FE5F43 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtQueryFullAttributesFile + 6 76FE5FEE 4 Bytes CALL 75FE66F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtQueryFullAttributesFile + B 76FE5FF3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtSetInformationFile + 6 76FE663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtSetInformationFile + B 76FE6643 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtSetInformationThread + 6 76FE669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtSetInformationThread + B 76FE66A3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 1 Byte [68]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[1404] ntdll.dll!NtUnmapViewOfSection + B 76FE69C3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtCreateFile + 6 76FE55CE 4 Bytes [28, 00, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtCreateFile + B 76FE55D3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 1 Byte [28]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 4 Bytes [28, 03, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtMapViewOfSection + B 76FE5C33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenFile + 6 76FE5CDE 4 Bytes [68, 00, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenFile + B 76FE5CE3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenProcess + 6 76FE5D8E 4 Bytes [A8, 01, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenProcess + B 76FE5D93 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenProcessToken + 6 76FE5D9E 4 Bytes CALL 75FE74A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenProcessToken + B 76FE5DA3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenProcessTokenEx + 6 76FE5DAE 4 Bytes [A8, 02, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenProcessTokenEx + B 76FE5DB3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenThread + 6 76FE5E0E 4 Bytes [68, 01, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenThread + B 76FE5E13 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenThreadToken + 6 76FE5E1E 4 Bytes [68, 02, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenThreadToken + B 76FE5E23 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenThreadTokenEx + 6 76FE5E2E 4 Bytes CALL 75FE7535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtOpenThreadTokenEx + B 76FE5E33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtQueryAttributesFile + 6 76FE5F3E 4 Bytes [A8, 00, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtQueryAttributesFile + B 76FE5F43 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtQueryFullAttributesFile + 6 76FE5FEE 4 Bytes CALL 75FE76F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtQueryFullAttributesFile + B 76FE5FF3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtSetInformationFile + 6 76FE663E 4 Bytes [28, 01, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtSetInformationFile + B 76FE6643 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtSetInformationThread + 6 76FE669E 4 Bytes [28, 02, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtSetInformationThread + B 76FE66A3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 1 Byte [68]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 4 Bytes [68, 03, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2028] ntdll.dll!NtUnmapViewOfSection + B 76FE69C3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtCreateFile + 6 76FE55CE 4 Bytes [28, 00, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtCreateFile + B 76FE55D3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 1 Byte [28]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtMapViewOfSection + 6 76FE5C2E 4 Bytes [28, 03, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtMapViewOfSection + B 76FE5C33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenFile + 6 76FE5CDE 4 Bytes [68, 00, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenFile + B 76FE5CE3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenProcess + 6 76FE5D8E 4 Bytes [A8, 01, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenProcess + B 76FE5D93 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenProcessToken + 6 76FE5D9E 4 Bytes CALL 75FE74A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenProcessToken + B 76FE5DA3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenProcessTokenEx + 6 76FE5DAE 4 Bytes [A8, 02, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenProcessTokenEx + B 76FE5DB3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenThread + 6 76FE5E0E 4 Bytes [68, 01, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenThread + B 76FE5E13 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenThreadToken + 6 76FE5E1E 4 Bytes [68, 02, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenThreadToken + B 76FE5E23 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenThreadTokenEx + 6 76FE5E2E 4 Bytes CALL 75FE7535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtOpenThreadTokenEx + B 76FE5E33 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtQueryAttributesFile + 6 76FE5F3E 4 Bytes [A8, 00, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtQueryAttributesFile + B 76FE5F43 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtQueryFullAttributesFile + 6 76FE5FEE 4 Bytes CALL 75FE76F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtQueryFullAttributesFile + B 76FE5FF3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtSetInformationFile + 6 76FE663E 4 Bytes [28, 01, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtSetInformationFile + B 76FE6643 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtSetInformationThread + 6 76FE669E 4 Bytes [28, 02, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtSetInformationThread + B 76FE66A3 1 Byte [E2]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 1 Byte [68]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtUnmapViewOfSection + 6 76FE69BE 4 Bytes [68, 03, 17, 00]
.text C:\Users\Ben\AppData\Local\Google\Chrome\Application\chrome.exe[2552] ntdll.dll!NtUnmapViewOfSection + B 76FE69C3 1 Byte [E2]
.text C:\Windows\System32\ping.exe[3960] ntdll.dll!NtCreateProcess 76FE5698 5 Bytes JMP 005B000A
.text C:\Windows\System32\ping.exe[3960] ntdll.dll!NtCreateProcessEx 76FE56A8 5 Bytes JMP 0060000A
.text C:\Windows\System32\ping.exe[3960] ntdll.dll!NtCreateUserProcess 76FE5778 5 Bytes JMP 0065000A
.text C:\Windows\System32\ping.exe[3960] ntdll.dll!NtProtectVirtualMemory 76FE5F18 5 Bytes JMP 0026000A
.text C:\Windows\System32\ping.exe[3960] ntdll.dll!NtWriteVirtualMemory 76FE6A98 5 Bytes JMP 0054000A
.text C:\Windows\System32\ping.exe[3960] ntdll.dll!KiUserExceptionDispatcher 76FE7008 5 Bytes JMP 000D000A
.text C:\Windows\System32\ping.exe[3960] USER32.dll!GetCursorPos 7543A4B3 5 Bytes JMP 0068000A
.text C:\Windows\System32\ping.exe[3960] USER32.dll!GetForegroundWindow 7544335D 5 Bytes JMP 007A000A
.text C:\Windows\System32\ping.exe[3960] USER32.dll!WindowFromPoint 75466BE9 5 Bytes JMP 0079000A
.text C:\Windows\System32\ping.exe[3960] ole32.dll!CoCreateInstance 759B9D0B 5 Bytes JMP 0067000A
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp aswRdr.SYS (avast! TDI RDR Driver/AVAST Software)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\00000071 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 MBR read error
Disk \Device\Harddisk0\DR0 MBR BIOS signature not found 0
---- Files - GMER 1.0.15 ----
File C:\Windows\$NtUninstallKB188$\104013258 0 bytes
File C:\Windows\$NtUninstallKB188$\2782373227 0 bytes
File C:\Windows\$NtUninstallKB188$\2782373227\L 0 bytes
File C:\Windows\$NtUninstallKB188$\2782373227\U 0 bytes
---- EOF - GMER 1.0.15 ----