GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2011-11-18 14:48:30
Windows 5.1.2600 Service Pack 3
Running: fmf7xn83.exe; Driver: I:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\kgryifob.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0xB08CB374]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0xB09322B8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwClose [0xB08EF829]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0xB08CD996]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0xB08CD9EE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0xB08CDB04]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateKey [0xB08EF1DD]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0xB08CD8EC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0xB08CDA3E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0xB08CD940]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0xB08CDAB2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0xB08CB398]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteKey [0xB08EFEEF]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteValueKey [0xB08F01A5]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDuplicateObject [0xB08CDD88]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateKey [0xB08EFD5A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateValueKey [0xB08EFBC5]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0xB0932368]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0xB08CB162]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0xB08CB3BC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0xB08CDEFC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0xB08CBE54]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0xB08CD9C6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0xB08CDA16]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0xB08CDB2E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenKey [0xB08EF539]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0xB08CD918]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenProcess [0xB08CDBC0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0xB08CDA7E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0xB08CD96E]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenThread [0xB08CDCA4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0xB08CDADC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0xB0932400]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryKey [0xB08EFA40]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0xB08CBD1A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryValueKey [0xB08EF892]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwRenameKey [0xB093A6E2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwRestoreKey [0xB08EE850]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0xB08CB3E0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0xB08CB404]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0xB08CB1BC]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0xB08CB2F8]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetValueKey [0xB08EFFF6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0xB08CB2D4]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0xB08CB31C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0xB08CB428]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0xB09479A6]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2F14 805047B0 4 Bytes CALL CB28F843
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 5EC 805A64A8 4 Bytes CALL B08CC4AF \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE ntkrnlpa.exe!ObMakeTemporaryObject 805BC556 5 Bytes JMP B09433DE \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ObInsertObject 805C2FDA 5 Bytes JMP B0944E84 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx 805D117A 2 Bytes JMP B09479AA \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE ntkrnlpa.exe!ZwCreateProcessEx + 3 805D117D 4 Bytes [37, 30, CC, CC] {AAA ; XOR AH, CL; INT 3 }
.text I:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB712F360, 0x24BB1D, 0xE8000020]
.text win32k.sys!EngFreeUserMem + 674 BF80996D 5 Bytes JMP B08CEE48 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngDeleteSurface + 45 BF81395C 5 Bytes JMP B08CED54 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngSetLastError + 7690 BF823FF7 5 Bytes JMP B08CE0DA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngPaint + 118C2 BF839930 5 Bytes JMP B08CE326 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngPaint + 1194D BF8399BB 5 Bytes JMP B08CE4CC \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!XLATEOBJ_iXlate + 33C8 BF83D961 5 Bytes JMP B08CE016 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateBitmap + 698 BF847820 5 Bytes JMP B08CEFB2 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateBitmap + 3A66 BF84ABEE 5 Bytes JMP B08CF1BA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngTextOut + 1DB5 BF85352E 5 Bytes JMP B08CECC4 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStretchBlt + 3629 BF8578AB 5 Bytes JMP B08CDFFE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngStretchBlt + A0E7 BF85E369 5 Bytes JMP B08CED7E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngUnicodeToMultiByteN + 2ED7 BF861C8A 5 Bytes JMP B08CF118 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngGetCurrentCodePage + 411E BF87C6BE 5 Bytes JMP B08CE4A4 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!FONTOBJ_pxoGetXform + 9219 BF8B0165 5 Bytes JMP B08CE14A \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreatePalette + ABB BF8B9773 5 Bytes JMP B08CEEFA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngAlphaBlend + 4CA2 BF8C3290 5 Bytes JMP B08CE1E4 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngFillPath + 1517 BF8EB8E7 5 Bytes JMP B08CE254 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngFillPath + 1797 BF8EBB67 5 Bytes JMP B08CE28E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!PATHOBJ_bCloseFigure + 19EF BF8F99C1 5 Bytes JMP B08CDF32 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateClip + 1A0A BF913BA8 5 Bytes JMP B08CE096 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateClip + 25DE BF91477C 5 Bytes JMP B08CE1AE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngCreateClip + 4F3D BF9170DB 5 Bytes JMP B08CE5E6 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text win32k.sys!EngPlgBlt + 190E BF9454A3 5 Bytes JMP B08CF070 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
---- User code sections - GMER 1.0.15 ----
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001801F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001803FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00521014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00520804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00520A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00520C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00520E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 005201F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 005203FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00520600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00530804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00530A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00530600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 005301F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 005303FC
.text I:\WINDOWS\system32\nvsvc32.exe[324] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001401F8
.text I:\WINDOWS\system32\nvsvc32.exe[324] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\WINDOWS\system32\nvsvc32.exe[324] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001403FC
.text I:\WINDOWS\system32\nvsvc32.exe[324] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\WINDOWS\system32\nvsvc32.exe[324] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00380804
.text I:\WINDOWS\system32\nvsvc32.exe[324] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00380A08
.text I:\WINDOWS\system32\nvsvc32.exe[324] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00380600
.text I:\WINDOWS\system32\nvsvc32.exe[324] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003801F8
.text I:\WINDOWS\system32\nvsvc32.exe[324] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003803FC
.text I:\WINDOWS\system32\nvsvc32.exe[324] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014
.text I:\WINDOWS\system32\nvsvc32.exe[324] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804
.text I:\WINDOWS\system32\nvsvc32.exe[324] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08
.text I:\WINDOWS\system32\nvsvc32.exe[324] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C
.text I:\WINDOWS\system32\nvsvc32.exe[324] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10
.text I:\WINDOWS\system32\nvsvc32.exe[324] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8
.text I:\WINDOWS\system32\nvsvc32.exe[324] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC
.text I:\WINDOWS\system32\nvsvc32.exe[324] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600
.text I:\WINDOWS\system32\svchost.exe[380] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text I:\WINDOWS\system32\svchost.exe[380] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\WINDOWS\system32\svchost.exe[380] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text I:\WINDOWS\system32\svchost.exe[380] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\WINDOWS\system32\svchost.exe[380] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text I:\WINDOWS\system32\svchost.exe[380] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text I:\WINDOWS\system32\svchost.exe[380] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text I:\WINDOWS\system32\svchost.exe[380] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text I:\WINDOWS\system32\svchost.exe[380] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text I:\WINDOWS\system32\svchost.exe[380] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text I:\WINDOWS\system32\svchost.exe[380] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text I:\WINDOWS\system32\svchost.exe[380] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text I:\WINDOWS\system32\svchost.exe[380] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text I:\WINDOWS\system32\svchost.exe[380] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text I:\WINDOWS\system32\svchost.exe[380] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text I:\WINDOWS\system32\svchost.exe[380] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text I:\WINDOWS\system32\svchost.exe[380] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text I:\WINDOWS\system32\svchost.exe[440] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text I:\WINDOWS\system32\svchost.exe[440] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\WINDOWS\system32\svchost.exe[440] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text I:\WINDOWS\system32\svchost.exe[440] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text I:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text I:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text I:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text I:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text I:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text I:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text I:\WINDOWS\system32\svchost.exe[440] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text I:\WINDOWS\system32\svchost.exe[440] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text I:\WINDOWS\system32\svchost.exe[440] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text I:\WINDOWS\system32\svchost.exe[440] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text I:\WINDOWS\system32\svchost.exe[440] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text I:\WINDOWS\system32\svchost.exe[440] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text I:\WINDOWS\System32\svchost.exe[532] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text I:\WINDOWS\System32\svchost.exe[532] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\WINDOWS\System32\svchost.exe[532] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text I:\WINDOWS\System32\svchost.exe[532] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\WINDOWS\System32\svchost.exe[532] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text I:\WINDOWS\System32\svchost.exe[532] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text I:\WINDOWS\System32\svchost.exe[532] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text I:\WINDOWS\System32\svchost.exe[532] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text I:\WINDOWS\System32\svchost.exe[532] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text I:\WINDOWS\System32\svchost.exe[532] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text I:\WINDOWS\System32\svchost.exe[532] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text I:\WINDOWS\System32\svchost.exe[532] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text I:\WINDOWS\System32\svchost.exe[532] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text I:\WINDOWS\System32\svchost.exe[532] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text I:\WINDOWS\System32\svchost.exe[532] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text I:\WINDOWS\System32\svchost.exe[532] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text I:\WINDOWS\System32\svchost.exe[532] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text I:\Program Files\Java\jre6\bin\jqs.exe[564] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text I:\Program Files\Java\jre6\bin\jqs.exe[564] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Program Files\Java\jre6\bin\jqs.exe[564] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text I:\Program Files\Java\jre6\bin\jqs.exe[564] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Program Files\Java\jre6\bin\jqs.exe[564] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014
.text I:\Program Files\Java\jre6\bin\jqs.exe[564] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804
.text I:\Program Files\Java\jre6\bin\jqs.exe[564] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08
.text I:\Program Files\Java\jre6\bin\jqs.exe[564] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C
.text I:\Program Files\Java\jre6\bin\jqs.exe[564] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10
.text I:\Program Files\Java\jre6\bin\jqs.exe[564] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8
.text I:\Program Files\Java\jre6\bin\jqs.exe[564] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC
.text I:\Program Files\Java\jre6\bin\jqs.exe[564] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600
.text I:\Program Files\Java\jre6\bin\jqs.exe[564] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A0804
.text I:\Program Files\Java\jre6\bin\jqs.exe[564] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0A08
.text I:\Program Files\Java\jre6\bin\jqs.exe[564] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A0600
.text I:\Program Files\Java\jre6\bin\jqs.exe[564] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A01F8
.text I:\Program Files\Java\jre6\bin\jqs.exe[564] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A03FC
.text I:\WINDOWS\System32\smss.exe[676] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\WINDOWS\system32\svchost.exe[688] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text I:\WINDOWS\system32\svchost.exe[688] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\WINDOWS\system32\svchost.exe[688] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text I:\WINDOWS\system32\svchost.exe[688] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\WINDOWS\system32\svchost.exe[688] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C1014
.text I:\WINDOWS\system32\svchost.exe[688] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C0804
.text I:\WINDOWS\system32\svchost.exe[688] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0A08
.text I:\WINDOWS\system32\svchost.exe[688] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C0C0C
.text I:\WINDOWS\system32\svchost.exe[688] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0E10
.text I:\WINDOWS\system32\svchost.exe[688] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C01F8
.text I:\WINDOWS\system32\svchost.exe[688] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C03FC
.text I:\WINDOWS\system32\svchost.exe[688] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C0600
.text I:\WINDOWS\system32\svchost.exe[688] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002D0804
.text I:\WINDOWS\system32\svchost.exe[688] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002D0A08
.text I:\WINDOWS\system32\svchost.exe[688] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002D0600
.text I:\WINDOWS\system32\svchost.exe[688] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002D01F8
.text I:\WINDOWS\system32\svchost.exe[688] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002D03FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001801F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001803FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00521014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00520804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00520A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00520C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00520E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 005201F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 005203FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00520600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00530804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00530A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00530600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 005301F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 005303FC
.text I:\WINDOWS\system32\svchost.exe[780] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text I:\WINDOWS\system32\svchost.exe[780] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\WINDOWS\system32\svchost.exe[780] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text I:\WINDOWS\system32\svchost.exe[780] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\WINDOWS\system32\svchost.exe[780] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text I:\WINDOWS\system32\svchost.exe[780] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text I:\WINDOWS\system32\svchost.exe[780] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text I:\WINDOWS\system32\svchost.exe[780] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text I:\WINDOWS\system32\svchost.exe[780] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text I:\WINDOWS\system32\svchost.exe[780] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text I:\WINDOWS\system32\svchost.exe[780] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text I:\WINDOWS\system32\svchost.exe[780] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text I:\WINDOWS\system32\svchost.exe[780] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text I:\WINDOWS\system32\svchost.exe[780] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text I:\WINDOWS\system32\svchost.exe[780] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text I:\WINDOWS\system32\svchost.exe[780] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text I:\WINDOWS\system32\svchost.exe[780] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text I:\WINDOWS\System32\svchost.exe[888] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text I:\WINDOWS\System32\svchost.exe[888] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\WINDOWS\System32\svchost.exe[888] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text I:\WINDOWS\System32\svchost.exe[888] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\WINDOWS\System32\svchost.exe[888] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text I:\WINDOWS\System32\svchost.exe[888] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text I:\WINDOWS\System32\svchost.exe[888] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text I:\WINDOWS\System32\svchost.exe[888] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text I:\WINDOWS\System32\svchost.exe[888] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text I:\WINDOWS\System32\svchost.exe[888] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text I:\WINDOWS\System32\svchost.exe[888] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text I:\WINDOWS\System32\svchost.exe[888] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text I:\WINDOWS\System32\svchost.exe[888] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text I:\WINDOWS\System32\svchost.exe[888] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text I:\WINDOWS\System32\svchost.exe[888] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text I:\WINDOWS\System32\svchost.exe[888] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text I:\WINDOWS\System32\svchost.exe[888] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001801F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001803FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00521014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00520804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00520A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00520C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00520E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 005201F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 005203FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00520600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00530804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00530A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00530600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 005301F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 005303FC
.text I:\WINDOWS\System32\svchost.exe[1036] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text I:\WINDOWS\System32\svchost.exe[1036] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\WINDOWS\System32\svchost.exe[1036] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text I:\WINDOWS\System32\svchost.exe[1036] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\WINDOWS\System32\svchost.exe[1036] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text I:\WINDOWS\System32\svchost.exe[1036] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text I:\WINDOWS\System32\svchost.exe[1036] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text I:\WINDOWS\System32\svchost.exe[1036] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text I:\WINDOWS\System32\svchost.exe[1036] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text I:\WINDOWS\System32\svchost.exe[1036] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text I:\WINDOWS\System32\svchost.exe[1036] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text I:\WINDOWS\System32\svchost.exe[1036] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text I:\WINDOWS\System32\svchost.exe[1036] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text I:\WINDOWS\System32\svchost.exe[1036] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text I:\WINDOWS\System32\svchost.exe[1036] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text I:\WINDOWS\System32\svchost.exe[1036] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text I:\WINDOWS\System32\svchost.exe[1036] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text I:\WINDOWS\Explorer.EXE[1088] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text I:\WINDOWS\Explorer.EXE[1088] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\WINDOWS\Explorer.EXE[1088] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text I:\WINDOWS\Explorer.EXE[1088] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\WINDOWS\Explorer.EXE[1088] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C1014
.text I:\WINDOWS\Explorer.EXE[1088] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C0804
.text I:\WINDOWS\Explorer.EXE[1088] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0A08
.text I:\WINDOWS\Explorer.EXE[1088] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C0C0C
.text I:\WINDOWS\Explorer.EXE[1088] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0E10
.text I:\WINDOWS\Explorer.EXE[1088] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C01F8
.text I:\WINDOWS\Explorer.EXE[1088] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C03FC
.text I:\WINDOWS\Explorer.EXE[1088] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C0600
.text I:\WINDOWS\Explorer.EXE[1088] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002D0804
.text I:\WINDOWS\Explorer.EXE[1088] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002D0A08
.text I:\WINDOWS\Explorer.EXE[1088] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002D0600
.text I:\WINDOWS\Explorer.EXE[1088] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002D01F8
.text I:\WINDOWS\Explorer.EXE[1088] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002D03FC
.text I:\WINDOWS\system32\svchost.exe[1356] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text I:\WINDOWS\system32\svchost.exe[1356] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\WINDOWS\system32\svchost.exe[1356] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text I:\WINDOWS\system32\svchost.exe[1356] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\WINDOWS\system32\svchost.exe[1356] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text I:\WINDOWS\system32\svchost.exe[1356] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text I:\WINDOWS\system32\svchost.exe[1356] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text I:\WINDOWS\system32\svchost.exe[1356] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text I:\WINDOWS\system32\svchost.exe[1356] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text I:\WINDOWS\system32\svchost.exe[1356] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text I:\WINDOWS\system32\svchost.exe[1356] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text I:\WINDOWS\system32\svchost.exe[1356] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text I:\WINDOWS\system32\svchost.exe[1356] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text I:\WINDOWS\system32\svchost.exe[1356] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text I:\WINDOWS\system32\svchost.exe[1356] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text I:\WINDOWS\system32\svchost.exe[1356] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text I:\WINDOWS\system32\svchost.exe[1356] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text I:\WINDOWS\system32\spoolsv.exe[1572] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text I:\WINDOWS\system32\spoolsv.exe[1572] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\WINDOWS\system32\spoolsv.exe[1572] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text I:\WINDOWS\system32\spoolsv.exe[1572] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\WINDOWS\system32\spoolsv.exe[1572] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text I:\WINDOWS\system32\spoolsv.exe[1572] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text I:\WINDOWS\system32\spoolsv.exe[1572] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text I:\WINDOWS\system32\spoolsv.exe[1572] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text I:\WINDOWS\system32\spoolsv.exe[1572] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text I:\WINDOWS\system32\spoolsv.exe[1572] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text I:\WINDOWS\system32\spoolsv.exe[1572] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text I:\WINDOWS\system32\spoolsv.exe[1572] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text I:\WINDOWS\system32\spoolsv.exe[1572] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text I:\WINDOWS\system32\spoolsv.exe[1572] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text I:\WINDOWS\system32\spoolsv.exe[1572] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text I:\WINDOWS\system32\spoolsv.exe[1572] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text I:\WINDOWS\system32\spoolsv.exe[1572] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001801F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001803FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00521014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00520804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00520A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00520C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00520E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 005201F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 005203FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00520600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00530804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00530A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00530600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 005301F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 005303FC
.text I:\WINDOWS\system32\svchost.exe[1804] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text I:\WINDOWS\system32\svchost.exe[1804] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\WINDOWS\system32\svchost.exe[1804] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text I:\WINDOWS\system32\svchost.exe[1804] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\WINDOWS\system32\svchost.exe[1804] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text I:\WINDOWS\system32\svchost.exe[1804] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text I:\WINDOWS\system32\svchost.exe[1804] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text I:\WINDOWS\system32\svchost.exe[1804] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text I:\WINDOWS\system32\svchost.exe[1804] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text I:\WINDOWS\system32\svchost.exe[1804] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text I:\WINDOWS\system32\svchost.exe[1804] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text I:\WINDOWS\system32\svchost.exe[1804] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text I:\WINDOWS\system32\svchost.exe[1804] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text I:\WINDOWS\system32\svchost.exe[1804] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text I:\WINDOWS\system32\svchost.exe[1804] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text I:\WINDOWS\system32\svchost.exe[1804] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text I:\WINDOWS\system32\svchost.exe[1804] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text I:\Program Files\SUPERAntiSpyware\SASCORE.EXE[1840] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text I:\Program Files\SUPERAntiSpyware\SASCORE.EXE[1840] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Program Files\SUPERAntiSpyware\SASCORE.EXE[1840] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text I:\Program Files\SUPERAntiSpyware\SASCORE.EXE[1840] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Program Files\SUPERAntiSpyware\SASCORE.EXE[1840] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00390804
.text I:\Program Files\SUPERAntiSpyware\SASCORE.EXE[1840] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00390A08
.text I:\Program Files\SUPERAntiSpyware\SASCORE.EXE[1840] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00390600
.text I:\Program Files\SUPERAntiSpyware\SASCORE.EXE[1840] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003901F8
.text I:\Program Files\SUPERAntiSpyware\SASCORE.EXE[1840] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003903FC
.text I:\Program Files\SUPERAntiSpyware\SASCORE.EXE[1840] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003A1014
.text I:\Program Files\SUPERAntiSpyware\SASCORE.EXE[1840] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003A0804
.text I:\Program Files\SUPERAntiSpyware\SASCORE.EXE[1840] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003A0A08
.text I:\Program Files\SUPERAntiSpyware\SASCORE.EXE[1840] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003A0C0C
.text I:\Program Files\SUPERAntiSpyware\SASCORE.EXE[1840] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003A0E10
.text I:\Program Files\SUPERAntiSpyware\SASCORE.EXE[1840] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003A01F8
.text I:\Program Files\SUPERAntiSpyware\SASCORE.EXE[1840] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003A03FC
.text I:\Program Files\SUPERAntiSpyware\SASCORE.EXE[1840] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003A0600
.text I:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1852] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text I:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1852] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1852] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text I:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1852] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1852] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014
.text I:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1852] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804
.text I:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1852] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08
.text I:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1852] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C
.text I:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1852] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10
.text I:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1852] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8
.text I:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1852] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC
.text I:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1852] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600
.text I:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1852] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A0804
.text I:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1852] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0A08
.text I:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1852] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A0600
.text I:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1852] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A01F8
.text I:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1852] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A03FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1864] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1864] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1864] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1864] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1864] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1864] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1864] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1864] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1864] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1864] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1864] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1864] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1864] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A0804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1864] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1864] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A0600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1864] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A01F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1864] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A03FC
.text I:\Program Files\Bonjour\mDNSResponder.exe[1884] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text I:\Program Files\Bonjour\mDNSResponder.exe[1884] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Program Files\Bonjour\mDNSResponder.exe[1884] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text I:\Program Files\Bonjour\mDNSResponder.exe[1884] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Program Files\Bonjour\mDNSResponder.exe[1884] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014
.text I:\Program Files\Bonjour\mDNSResponder.exe[1884] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804
.text I:\Program Files\Bonjour\mDNSResponder.exe[1884] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08
.text I:\Program Files\Bonjour\mDNSResponder.exe[1884] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C
.text I:\Program Files\Bonjour\mDNSResponder.exe[1884] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10
.text I:\Program Files\Bonjour\mDNSResponder.exe[1884] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8
.text I:\Program Files\Bonjour\mDNSResponder.exe[1884] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC
.text I:\Program Files\Bonjour\mDNSResponder.exe[1884] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600
.text I:\Program Files\Bonjour\mDNSResponder.exe[1884] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A0804
.text I:\Program Files\Bonjour\mDNSResponder.exe[1884] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0A08
.text I:\Program Files\Bonjour\mDNSResponder.exe[1884] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A0600
.text I:\Program Files\Bonjour\mDNSResponder.exe[1884] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A01F8
.text I:\Program Files\Bonjour\mDNSResponder.exe[1884] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A03FC
.text I:\WINDOWS\system32\csrss.exe[1956] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\WINDOWS\system32\csrss.exe[1956] KERNEL32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\WINDOWS\system32\winlogon.exe[1980] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000701F8
.text I:\WINDOWS\system32\winlogon.exe[1980] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\WINDOWS\system32\winlogon.exe[1980] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000703FC
.text I:\WINDOWS\system32\winlogon.exe[1980] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\WINDOWS\system32\winlogon.exe[1980] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text I:\WINDOWS\system32\winlogon.exe[1980] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text I:\WINDOWS\system32\winlogon.exe[1980] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text I:\WINDOWS\system32\winlogon.exe[1980] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text I:\WINDOWS\system32\winlogon.exe[1980] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text I:\WINDOWS\system32\winlogon.exe[1980] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text I:\WINDOWS\system32\winlogon.exe[1980] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text I:\WINDOWS\system32\winlogon.exe[1980] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text I:\WINDOWS\system32\winlogon.exe[1980] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text I:\WINDOWS\system32\winlogon.exe[1980] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text I:\WINDOWS\system32\winlogon.exe[1980] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text I:\WINDOWS\system32\winlogon.exe[1980] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text I:\WINDOWS\system32\winlogon.exe[1980] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text I:\WINDOWS\system32\services.exe[2024] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text I:\WINDOWS\system32\services.exe[2024] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\WINDOWS\system32\services.exe[2024] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text I:\WINDOWS\system32\services.exe[2024] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\WINDOWS\system32\services.exe[2024] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text I:\WINDOWS\system32\services.exe[2024] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text I:\WINDOWS\system32\services.exe[2024] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text I:\WINDOWS\system32\services.exe[2024] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text I:\WINDOWS\system32\services.exe[2024] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text I:\WINDOWS\system32\services.exe[2024] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text I:\WINDOWS\system32\services.exe[2024] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text I:\WINDOWS\system32\services.exe[2024] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text I:\WINDOWS\system32\services.exe[2024] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text I:\WINDOWS\system32\services.exe[2024] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text I:\WINDOWS\system32\services.exe[2024] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text I:\WINDOWS\system32\services.exe[2024] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text I:\WINDOWS\system32\services.exe[2024] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text I:\WINDOWS\system32\lsass.exe[2036] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text I:\WINDOWS\system32\lsass.exe[2036] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\WINDOWS\system32\lsass.exe[2036] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text I:\WINDOWS\system32\lsass.exe[2036] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\WINDOWS\system32\lsass.exe[2036] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002B1014
.text I:\WINDOWS\system32\lsass.exe[2036] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002B0804
.text I:\WINDOWS\system32\lsass.exe[2036] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002B0A08
.text I:\WINDOWS\system32\lsass.exe[2036] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002B0C0C
.text I:\WINDOWS\system32\lsass.exe[2036] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002B0E10
.text I:\WINDOWS\system32\lsass.exe[2036] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002B01F8
.text I:\WINDOWS\system32\lsass.exe[2036] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002B03FC
.text I:\WINDOWS\system32\lsass.exe[2036] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002B0600
.text I:\WINDOWS\system32\lsass.exe[2036] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002C0804
.text I:\WINDOWS\system32\lsass.exe[2036] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002C0A08
.text I:\WINDOWS\system32\lsass.exe[2036] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002C0600
.text I:\WINDOWS\system32\lsass.exe[2036] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002C01F8
.text I:\WINDOWS\system32\lsass.exe[2036] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002C03FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001801F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001803FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00521014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00520804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00520A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00520C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00520E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 005201F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 005203FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00520600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00530804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00530A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00530600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 005301F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 005303FC
.text I:\WINDOWS\System32\alg.exe[2604] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000901F8
.text I:\WINDOWS\System32\alg.exe[2604] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\WINDOWS\System32\alg.exe[2604] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000903FC
.text I:\WINDOWS\System32\alg.exe[2604] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\WINDOWS\System32\alg.exe[2604] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002B0804
.text I:\WINDOWS\System32\alg.exe[2604] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002B0A08
.text I:\WINDOWS\System32\alg.exe[2604] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002B0600
.text I:\WINDOWS\System32\alg.exe[2604] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002B01F8
.text I:\WINDOWS\System32\alg.exe[2604] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002B03FC
.text I:\WINDOWS\System32\alg.exe[2604] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C1014
.text I:\WINDOWS\System32\alg.exe[2604] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C0804
.text I:\WINDOWS\System32\alg.exe[2604] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0A08
.text I:\WINDOWS\System32\alg.exe[2604] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C0C0C
.text I:\WINDOWS\System32\alg.exe[2604] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0E10
.text I:\WINDOWS\System32\alg.exe[2604] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C01F8
.text I:\WINDOWS\System32\alg.exe[2604] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C03FC
.text I:\WINDOWS\System32\alg.exe[2604] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C0600
.text I:\WINDOWS\system32\NOTEPAD.EXE[2756] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000A01F8
.text I:\WINDOWS\system32\NOTEPAD.EXE[2756] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\WINDOWS\system32\NOTEPAD.EXE[2756] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000A03FC
.text I:\WINDOWS\system32\NOTEPAD.EXE[2756] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\WINDOWS\system32\NOTEPAD.EXE[2756] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C1014
.text I:\WINDOWS\system32\NOTEPAD.EXE[2756] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C0804
.text I:\WINDOWS\system32\NOTEPAD.EXE[2756] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0A08
.text I:\WINDOWS\system32\NOTEPAD.EXE[2756] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C0C0C
.text I:\WINDOWS\system32\NOTEPAD.EXE[2756] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0E10
.text I:\WINDOWS\system32\NOTEPAD.EXE[2756] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C01F8
.text I:\WINDOWS\system32\NOTEPAD.EXE[2756] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C03FC
.text I:\WINDOWS\system32\NOTEPAD.EXE[2756] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C0600
.text I:\WINDOWS\system32\NOTEPAD.EXE[2756] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002D0804
.text I:\WINDOWS\system32\NOTEPAD.EXE[2756] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002D0A08
.text I:\WINDOWS\system32\NOTEPAD.EXE[2756] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002D0600
.text I:\WINDOWS\system32\NOTEPAD.EXE[2756] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002D01F8
.text I:\WINDOWS\system32\NOTEPAD.EXE[2756] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002D03FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2888] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2888] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2888] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2888] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2888] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00391014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2888] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00390804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2888] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00390A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2888] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00390C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2888] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00390E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2888] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003901F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2888] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003903FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2888] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00390600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2888] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 003A0804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2888] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 003A0A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2888] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 003A0600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2888] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 003A01F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2888] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 003A03FC
.text I:\WINDOWS\system32\ctfmon.exe[2916] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 000A01F8
.text I:\WINDOWS\system32\ctfmon.exe[2916] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\WINDOWS\system32\ctfmon.exe[2916] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 000A03FC
.text I:\WINDOWS\system32\ctfmon.exe[2916] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\WINDOWS\system32\ctfmon.exe[2916] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 002C1014
.text I:\WINDOWS\system32\ctfmon.exe[2916] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 002C0804
.text I:\WINDOWS\system32\ctfmon.exe[2916] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 002C0A08
.text I:\WINDOWS\system32\ctfmon.exe[2916] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 002C0C0C
.text I:\WINDOWS\system32\ctfmon.exe[2916] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 002C0E10
.text I:\WINDOWS\system32\ctfmon.exe[2916] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 002C01F8
.text I:\WINDOWS\system32\ctfmon.exe[2916] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 002C03FC
.text I:\WINDOWS\system32\ctfmon.exe[2916] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 002C0600
.text I:\WINDOWS\system32\ctfmon.exe[2916] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 002D0804
.text I:\WINDOWS\system32\ctfmon.exe[2916] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 002D0A08
.text I:\WINDOWS\system32\ctfmon.exe[2916] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 002D0600
.text I:\WINDOWS\system32\ctfmon.exe[2916] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 002D01F8
.text I:\WINDOWS\system32\ctfmon.exe[2916] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 002D03FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001801F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001803FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00521014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00520804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00520A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00520C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00520E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 005201F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 005203FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00520600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00530804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00530A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00530600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 005301F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 005303FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001801F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001803FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00521014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00520804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00520A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00520C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00520E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 005201F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 005203FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00520600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00530804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00530A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00530600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 005301F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 005303FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001801F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001803FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00521014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00520804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00520A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00520C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00520E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 005201F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 005203FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00520600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00530804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00530A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00530600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 005301F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 005303FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001801F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001803FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00521014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00520804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00520A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00520C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00520E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 005201F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 005203FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00520600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00530804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00530A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00530600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 005301F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 005303FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001801F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001803FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00521014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00520804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00520A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00520C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00520E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 005201F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 005203FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00520600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00530804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00530A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00530600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 005301F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 005303FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001801F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001803FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00521014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00520804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00520A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00520C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00520E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 005201F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 005203FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00520600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00530804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00530A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00530600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 005301F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 005303FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001801F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001803FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00521014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00520804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00520A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00520C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00520E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 005201F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 005203FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00520600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00530804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00530A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00530600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 005301F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 005303FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001801F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001803FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00521014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00520804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00520A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00520C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00520E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 005201F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 005203FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00520600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00530804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00530A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00530600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 005301F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 005303FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001801F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001803FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00521014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00520804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00520A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00520C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00520E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 005201F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 005203FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00520600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00530804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00530A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00530600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 005301F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 005303FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001801F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001803FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00521014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00520804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00520A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00520C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00520E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 005201F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 005203FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00520600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00530804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00530A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00530600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 005301F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 005303FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001801F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001803FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00521014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00520804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00520A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00520C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00520E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 005201F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 005203FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00520600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00530804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00530A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00530600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 005301F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 005303FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001801F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001803FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00521014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00520804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00520A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00520C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00520E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 005201F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 005203FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00520600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00530804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00530A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00530600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 005301F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 005303FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001801F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001803FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00521014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00520804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00520A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00520C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00520E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 005201F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 005203FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00520600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00530804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00530A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00530600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 005301F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 005303FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001801F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001803FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00521014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00520804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00520A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00520C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00520E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 005201F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 005203FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00520600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00530804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00530A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00530600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 005301F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 005303FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001801F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001803FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 00521014
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 00520804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 00520A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 00520C0C
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 00520E10
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 005201F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 005203FC
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 00520600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00530804
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00530A08
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00530600
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 005301F8
.text I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 005303FC
.text I:\Documents and Settings\Administrator\Desktop\fmf7xn83.exe[3984] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 001501F8
.text I:\Documents and Settings\Administrator\Desktop\fmf7xn83.exe[3984] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Documents and Settings\Administrator\Desktop\fmf7xn83.exe[3984] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 001503FC
.text I:\Documents and Settings\Administrator\Desktop\fmf7xn83.exe[3984] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
.text I:\Documents and Settings\Administrator\Desktop\fmf7xn83.exe[3984] ADVAPI32.dll!SetServiceObjectSecurity 77E36D81 5 Bytes JMP 003F1014
.text I:\Documents and Settings\Administrator\Desktop\fmf7xn83.exe[3984] ADVAPI32.dll!ChangeServiceConfigA 77E36E69 5 Bytes JMP 003F0804
.text I:\Documents and Settings\Administrator\Desktop\fmf7xn83.exe[3984] ADVAPI32.dll!ChangeServiceConfigW 77E37001 5 Bytes JMP 003F0A08
.text I:\Documents and Settings\Administrator\Desktop\fmf7xn83.exe[3984] ADVAPI32.dll!ChangeServiceConfig2A 77E37101 5 Bytes JMP 003F0C0C
.text I:\Documents and Settings\Administrator\Desktop\fmf7xn83.exe[3984] ADVAPI32.dll!ChangeServiceConfig2W 77E37189 5 Bytes JMP 003F0E10
.text I:\Documents and Settings\Administrator\Desktop\fmf7xn83.exe[3984] ADVAPI32.dll!CreateServiceA 77E37211 5 Bytes JMP 003F01F8
.text I:\Documents and Settings\Administrator\Desktop\fmf7xn83.exe[3984] ADVAPI32.dll!CreateServiceW 77E373A9 5 Bytes JMP 003F03FC
.text I:\Documents and Settings\Administrator\Desktop\fmf7xn83.exe[3984] ADVAPI32.dll!DeleteService 77E374B1 5 Bytes JMP 003F0600
.text I:\Documents and Settings\Administrator\Desktop\fmf7xn83.exe[3984] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 00AA0804
.text I:\Documents and Settings\Administrator\Desktop\fmf7xn83.exe[3984] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 00AA0A08
.text I:\Documents and Settings\Administrator\Desktop\fmf7xn83.exe[3984] USER32.dll!SetWindowsHookExA 7E431211 5 Bytes JMP 00AA0600
.text I:\Documents and Settings\Administrator\Desktop\fmf7xn83.exe[3984] USER32.dll!SetWinEventHook 7E4317F7 5 Bytes JMP 00AA01F8
.text I:\Documents and Settings\Administrator\Desktop\fmf7xn83.exe[3984] USER32.dll!UnhookWinEvent 7E4318AC 5 Bytes JMP 00AA03FC
.text I:\Program Files\AVAST Software\Avast\AvastUI.exe[4068] ntdll.dll!RtlDosSearchPath_U + 186 7C916865 1 Byte [62]
.text I:\Program Files\AVAST Software\Avast\AvastUI.exe[4068] kernel32.dll!GetBinaryTypeW + 80 7C868D8C 1 Byte [62]
---- User IAT/EAT - GMER 1.0.15 ----
IAT I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[300] @ I:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002E0010
IAT I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[756] @ I:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002A0010
IAT I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1016] @ I:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002E0010
IAT I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1744] @ I:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002E0010
IAT I:\WINDOWS\system32\services.exe[2024] @ I:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00610002
IAT I:\WINDOWS\system32\services.exe[2024] @ I:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00610000
IAT I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[2144] @ I:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002F0010
IAT I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3020] @ I:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002E0010
IAT I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3056] @ I:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002F0010
IAT I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3060] @ I:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002E0010
IAT I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3100] @ I:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002E0010
IAT I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3152] @ I:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002F0010
IAT I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3248] @ I:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002A0010
IAT I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3340] @ I:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002F0010
IAT I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3412] @ I:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002E0010
IAT I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3512] @ I:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002F0010
IAT I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3532] @ I:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002A0010
IAT I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3592] @ I:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002E0010
IAT I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3632] @ I:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002E0010
IAT I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3640] @ I:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002E0010
IAT I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3876] @ I:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002F0010
IAT I:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[3960] @ I:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002E0010
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/AVAST Software)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
---- EOF - GMER 1.0.15 ----