offline
- Dubara
- Prijatelj foruma
- Pridružio: 26 Jul 2007
- Poruke: 1080
- Gde živiš: u blizini
|
Napisano: 21 Feb 2012 12:15
Na jedvite jade sam uspio da napravim log Gmer1, a prije nego li nastavim i ispratim sva uputstva, okačiću ovo što sam uspio do sada da prikupim.
Dobijam obavještenja kao na slikama:
Problem je počeo iznenada, danas dok sam na FB pregledao jednu aplikaciju na kojoj sam navodno označen. Bio je neki sajt nemanja0 ili sl.
Non-stop mi iskaču upozorenja kao na slikama i čak sam moram da izlazim iz njih dok sam na ovom dijelu foruma pokušavao da zakačim slike, toliko je naporno, kao u onoj prahistorijskoj igrici kada iskaču prozori sa dosadnim pitanjima koje je nemoguće zatvoriti.
Win je 32 - bita.
Evo prvog loga a okačiću i ostale:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-02-21 11:44:31
Windows 6.1.7600 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD50 rev.01.0
Running: e45lq7k7.exe; Driver: C:\Users\Druid\AppData\Local\Temp\pgloapod.sys
---- System - GMER 1.0.15 ----
SSDT 9173073E ZwCreateSection
SSDT 91730743 ZwSetContextThread
SSDT 917306DF ZwTerminateProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKeyEx + 13BD 83484569 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 834A9092 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!RtlSidHashLookup + 340 834B0950 4 Bytes [3E, 07, 73, 91]
.text ntkrnlpa.exe!RtlSidHashLookup + 6E0 834B0CF0 4 Bytes [43, 07, 73, 91] {INC EBX; POP ES; JAE 0xffffffffffffff95}
.text ntkrnlpa.exe!RtlSidHashLookup + 7B8 834B0DC8 4 Bytes [DF, 06, 73, 91] {FILD WORD [ESI]; JAE 0xffffffffffffff95}
? C:\Users\Druid\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtCreateFile + 6 77CE4876 4 Bytes [28, 00, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtCreateFile + B 77CE487B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtMapViewOfSection + 6 77CE4ED6 1 Byte [28]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtMapViewOfSection + 6 77CE4ED6 4 Bytes [28, 03, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtMapViewOfSection + B 77CE4EDB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtOpenFile + 6 77CE4F86 4 Bytes [68, 00, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtOpenFile + B 77CE4F8B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtOpenProcess + 6 77CE5036 4 Bytes [A8, 01, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtOpenProcess + B 77CE503B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtOpenProcessToken + B 77CE504B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtOpenProcessTokenEx + 6 77CE5056 4 Bytes [A8, 02, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtOpenProcessTokenEx + B 77CE505B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtOpenThread + 6 77CE50B6 4 Bytes [68, 01, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtOpenThread + B 77CE50BB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtOpenThreadToken + 6 77CE50C6 4 Bytes [68, 02, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtOpenThreadToken + B 77CE50CB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtOpenThreadTokenEx + B 77CE50DB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtQueryAttributesFile + 6 77CE51E6 4 Bytes [A8, 00, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtQueryAttributesFile + B 77CE51EB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtQueryFullAttributesFile + B 77CE529B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtSetInformationFile + 6 77CE58E6 4 Bytes [28, 01, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtSetInformationFile + B 77CE58EB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtSetInformationThread + 6 77CE5946 4 Bytes [28, 02, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtSetInformationThread + B 77CE594B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtUnmapViewOfSection + 6 77CE5C66 1 Byte [68]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtUnmapViewOfSection + 6 77CE5C66 4 Bytes [68, 03, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3376] ntdll.dll!NtUnmapViewOfSection + B 77CE5C6B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtCreateFile + 6 77CE4876 4 Bytes [28, 00, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtCreateFile + B 77CE487B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtMapViewOfSection + 6 77CE4ED6 1 Byte [28]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtMapViewOfSection + 6 77CE4ED6 4 Bytes [28, 03, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtMapViewOfSection + B 77CE4EDB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtOpenFile + 6 77CE4F86 4 Bytes [68, 00, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtOpenFile + B 77CE4F8B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtOpenProcess + 6 77CE5036 4 Bytes [A8, 01, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtOpenProcess + B 77CE503B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtOpenProcessToken + B 77CE504B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtOpenProcessTokenEx + 6 77CE5056 4 Bytes [A8, 02, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtOpenProcessTokenEx + B 77CE505B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtOpenThread + 6 77CE50B6 4 Bytes [68, 01, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtOpenThread + B 77CE50BB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtOpenThreadToken + 6 77CE50C6 4 Bytes [68, 02, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtOpenThreadToken + B 77CE50CB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtOpenThreadTokenEx + B 77CE50DB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtQueryAttributesFile + 6 77CE51E6 4 Bytes [A8, 00, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtQueryAttributesFile + B 77CE51EB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtQueryFullAttributesFile + B 77CE529B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtSetInformationFile + 6 77CE58E6 4 Bytes [28, 01, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtSetInformationFile + B 77CE58EB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtSetInformationThread + 6 77CE5946 4 Bytes [28, 02, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtSetInformationThread + B 77CE594B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtUnmapViewOfSection + 6 77CE5C66 1 Byte [68]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtUnmapViewOfSection + 6 77CE5C66 4 Bytes [68, 03, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3704] ntdll.dll!NtUnmapViewOfSection + B 77CE5C6B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtCreateFile + 6 77CE4876 4 Bytes [28, 00, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtCreateFile + B 77CE487B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtMapViewOfSection + 6 77CE4ED6 1 Byte [28]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtMapViewOfSection + 6 77CE4ED6 4 Bytes [28, 03, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtMapViewOfSection + B 77CE4EDB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtOpenFile + 6 77CE4F86 4 Bytes [68, 00, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtOpenFile + B 77CE4F8B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtOpenProcess + 6 77CE5036 4 Bytes [A8, 01, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtOpenProcess + B 77CE503B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtOpenProcessToken + B 77CE504B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtOpenProcessTokenEx + 6 77CE5056 4 Bytes [A8, 02, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtOpenProcessTokenEx + B 77CE505B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtOpenThread + 6 77CE50B6 4 Bytes [68, 01, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtOpenThread + B 77CE50BB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtOpenThreadToken + 6 77CE50C6 4 Bytes [68, 02, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtOpenThreadToken + B 77CE50CB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtOpenThreadTokenEx + B 77CE50DB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtQueryAttributesFile + 6 77CE51E6 4 Bytes [A8, 00, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtQueryAttributesFile + B 77CE51EB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtQueryFullAttributesFile + B 77CE529B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtSetInformationFile + 6 77CE58E6 4 Bytes [28, 01, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtSetInformationFile + B 77CE58EB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtSetInformationThread + 6 77CE5946 4 Bytes [28, 02, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtSetInformationThread + B 77CE594B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtUnmapViewOfSection + 6 77CE5C66 1 Byte [68]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtUnmapViewOfSection + 6 77CE5C66 4 Bytes [68, 03, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4544] ntdll.dll!NtUnmapViewOfSection + B 77CE5C6B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtCreateFile + 6 77CE4876 4 Bytes [28, 00, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtCreateFile + B 77CE487B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtMapViewOfSection + 6 77CE4ED6 1 Byte [28]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtMapViewOfSection + 6 77CE4ED6 4 Bytes [28, 03, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtMapViewOfSection + B 77CE4EDB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenFile + 6 77CE4F86 4 Bytes [68, 00, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenFile + B 77CE4F8B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenProcess + 6 77CE5036 4 Bytes [A8, 01, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenProcess + B 77CE503B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenProcessToken + B 77CE504B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenProcessTokenEx + 6 77CE5056 4 Bytes [A8, 02, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenProcessTokenEx + B 77CE505B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenThread + 6 77CE50B6 4 Bytes [68, 01, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenThread + B 77CE50BB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenThreadToken + 6 77CE50C6 4 Bytes [68, 02, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenThreadToken + B 77CE50CB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenThreadTokenEx + B 77CE50DB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtQueryAttributesFile + 6 77CE51E6 4 Bytes [A8, 00, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtQueryAttributesFile + B 77CE51EB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtQueryFullAttributesFile + B 77CE529B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtSetInformationFile + 6 77CE58E6 4 Bytes [28, 01, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtSetInformationFile + B 77CE58EB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtSetInformationThread + 6 77CE5946 4 Bytes [28, 02, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtSetInformationThread + B 77CE594B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtUnmapViewOfSection + 6 77CE5C66 1 Byte [68]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtUnmapViewOfSection + 6 77CE5C66 4 Bytes [68, 03, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtUnmapViewOfSection + B 77CE5C6B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtCreateFile + 6 77CE4876 4 Bytes [28, 00, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtCreateFile + B 77CE487B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtMapViewOfSection + 6 77CE4ED6 1 Byte [28]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtMapViewOfSection + 6 77CE4ED6 4 Bytes [28, 03, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtMapViewOfSection + B 77CE4EDB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtOpenFile + 6 77CE4F86 4 Bytes [68, 00, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtOpenFile + B 77CE4F8B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtOpenProcess + 6 77CE5036 4 Bytes [A8, 01, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtOpenProcess + B 77CE503B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtOpenProcessToken + B 77CE504B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtOpenProcessTokenEx + 6 77CE5056 4 Bytes [A8, 02, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtOpenProcessTokenEx + B 77CE505B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtOpenThread + 6 77CE50B6 4 Bytes [68, 01, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtOpenThread + B 77CE50BB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtOpenThreadToken + 6 77CE50C6 4 Bytes [68, 02, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtOpenThreadToken + B 77CE50CB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtOpenThreadTokenEx + B 77CE50DB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtQueryAttributesFile + 6 77CE51E6 4 Bytes [A8, 00, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtQueryAttributesFile + B 77CE51EB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtQueryFullAttributesFile + B 77CE529B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtSetInformationFile + 6 77CE58E6 4 Bytes [28, 01, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtSetInformationFile + B 77CE58EB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtSetInformationThread + 6 77CE5946 4 Bytes [28, 02, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtSetInformationThread + B 77CE594B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtUnmapViewOfSection + 6 77CE5C66 1 Byte [68]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtUnmapViewOfSection + 6 77CE5C66 4 Bytes [68, 03, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5020] ntdll.dll!NtUnmapViewOfSection + B 77CE5C6B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtCreateFile + 6 77CE4876 4 Bytes [28, 00, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtCreateFile + B 77CE487B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtMapViewOfSection + 6 77CE4ED6 1 Byte [28]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtMapViewOfSection + 6 77CE4ED6 4 Bytes [28, 03, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtMapViewOfSection + B 77CE4EDB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtOpenFile + 6 77CE4F86 4 Bytes [68, 00, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtOpenFile + B 77CE4F8B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtOpenProcess + 6 77CE5036 4 Bytes [A8, 01, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtOpenProcess + B 77CE503B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtOpenProcessToken + B 77CE504B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtOpenProcessTokenEx + 6 77CE5056 4 Bytes [A8, 02, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtOpenProcessTokenEx + B 77CE505B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtOpenThread + 6 77CE50B6 4 Bytes [68, 01, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtOpenThread + B 77CE50BB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtOpenThreadToken + 6 77CE50C6 4 Bytes [68, 02, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtOpenThreadToken + B 77CE50CB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtOpenThreadTokenEx + B 77CE50DB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtQueryAttributesFile + 6 77CE51E6 4 Bytes [A8, 00, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtQueryAttributesFile + B 77CE51EB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtQueryFullAttributesFile + B 77CE529B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtSetInformationFile + 6 77CE58E6 4 Bytes [28, 01, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtSetInformationFile + B 77CE58EB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtSetInformationThread + 6 77CE5946 4 Bytes [28, 02, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtSetInformationThread + B 77CE594B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtUnmapViewOfSection + 6 77CE5C66 1 Byte [68]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtUnmapViewOfSection + 6 77CE5C66 4 Bytes [68, 03, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5072] ntdll.dll!NtUnmapViewOfSection + B 77CE5C6B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtCreateFile + 6 77CE4876 4 Bytes [28, 00, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtCreateFile + B 77CE487B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtMapViewOfSection + 6 77CE4ED6 1 Byte [28]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtMapViewOfSection + 6 77CE4ED6 4 Bytes [28, 03, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtMapViewOfSection + B 77CE4EDB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtOpenFile + 6 77CE4F86 4 Bytes [68, 00, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtOpenFile + B 77CE4F8B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtOpenProcess + 6 77CE5036 4 Bytes [A8, 01, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtOpenProcess + B 77CE503B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtOpenProcessToken + B 77CE504B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtOpenProcessTokenEx + 6 77CE5056 4 Bytes [A8, 02, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtOpenProcessTokenEx + B 77CE505B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtOpenThread + 6 77CE50B6 4 Bytes [68, 01, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtOpenThread + B 77CE50BB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtOpenThreadToken + 6 77CE50C6 4 Bytes [68, 02, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtOpenThreadToken + B 77CE50CB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtOpenThreadTokenEx + B 77CE50DB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtQueryAttributesFile + 6 77CE51E6 4 Bytes [A8, 00, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtQueryAttributesFile + B 77CE51EB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtQueryFullAttributesFile + B 77CE529B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtSetInformationFile + 6 77CE58E6 4 Bytes [28, 01, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtSetInformationFile + B 77CE58EB 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtSetInformationThread + 6 77CE5946 4 Bytes [28, 02, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtSetInformationThread + B 77CE594B 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtUnmapViewOfSection + 6 77CE5C66 1 Byte [68]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtUnmapViewOfSection + 6 77CE5C66 4 Bytes [68, 03, 07, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[5256] ntdll.dll!NtUnmapViewOfSection + B 77CE5C6B 1 Byte [E2]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\system32\HPSIsvc.exe[864] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\HPSIsvc.exe[864] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\HPSIsvc.exe[864] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\HPSIsvc.exe[864] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\HPSIsvc.exe[864] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\HPSIsvc.exe[864] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2192] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2192] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2192] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe[2192] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[2492] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[2492] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[2492] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[2492] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[2492] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3628] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3628] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3628] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\System32\rundll32.exe[3628] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [74592494] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [74575624] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [745756E2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [7459250F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [74588573] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [74584D27] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [745850CE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [745851A3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [745866D0] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [745882CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74588819] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7458907A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7458E21D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[3972] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74584C59] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_72fc7cbf861225ca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[5476] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[5476] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[5476] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[5476] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[5476] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[5476] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\RunDll32.exe[6044] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\RunDll32.exe[6044] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\RunDll32.exe[6044] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\RunDll32.exe[6044] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\RunDll32.exe[6044] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\RunDll32.exe[6044] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Windows\system32\RunDll32.exe[6044] @ C:\Windows\system32\secur32.dll [KERNEL32.dll!GetProcAddress] [75D95E25] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs szkgfs.sys (STOPzilla Kernel Guard File System, x86-32 /iS3, Inc.)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00247e377657
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00247e377657@001bee45bf09 0x24 0x41 0x06 0x27 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00247e377657@0cddefe0a4d2 0x9E 0x08 0x22 0x89 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00247e377657@0017e4c21884 0x5F 0x6A 0xB1 0xB9 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00247e377657@a87e33171021 0x53 0x2F 0xC5 0x11 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00247e377657@002345af7a32 0xC2 0xF2 0x8F 0x1E ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00247e377657@70f395f67b44 0x74 0x1E 0x0C 0xF1 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00247e377657@002265952984 0xFA 0x8B 0x30 0xE3 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00247e377657@0018138a6a4a 0x06 0xD8 0x80 0x24 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00247e377657 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00247e377657@001bee45bf09 0x24 0x41 0x06 0x27 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00247e377657@0cddefe0a4d2 0x9E 0x08 0x22 0x89 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00247e377657@0017e4c21884 0x5F 0x6A 0xB1 0xB9 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00247e377657@a87e33171021 0x53 0x2F 0xC5 0x11 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00247e377657@002345af7a32 0xC2 0xF2 0x8F 0x1E ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00247e377657@70f395f67b44 0x74 0x1E 0x0C 0xF1 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00247e377657@002265952984 0xFA 0x8B 0x30 0xE3 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00247e377657@0018138a6a4a 0x06 0xD8 0x80 0x24 ...
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 malicious Win32:MBRoot code @ sector 947464195
Disk \Device\Harddisk0\DR0 PE file @ sector 947464217
Dopuna: 21 Feb 2012 12:18
I da ne griješim dušu da je infekcija stigla sa FB, prije će biti sa nekog drugog sajta do kojeg sam došao sa FB.
Dopuna: 21 Feb 2012 12:27
I da prijatelji mi telefonom javljaju da ih na FB obilježavam (prije pet sekundi) a kunem se da na FB nisam bio nekoliko sati.
Dopuna: 21 Feb 2012 12:34
Vidim da mi se na FB zaista, bez moje želje, umnožava ova aplikacija pogledajte svoju provalu: nemanjan00.binhoster.com
|