GMER 1.0.14.14536 -
http://www.gmer.net
Rootkit scan 2011-08-13 09:01:55
Windows 6.0.6002 Service Pack 2
---- User code sections - GMER 1.0.14 ----
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtCreateFile + 6 77DA422A 4 Bytes [ 28, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtCreateFile + B 77DA422F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtMapViewOfSection + 6 77DA497A 1 Byte [ 28 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtMapViewOfSection + 8 77DA497C 2 Bytes [ 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtMapViewOfSection + B 77DA497F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtOpenFile + 6 77DA4A0A 4 Bytes [ 68, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtOpenFile + B 77DA4A0F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtOpenProcess + 6 77DA4A8A 4 Bytes [ A8, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtOpenProcess + B 77DA4A8F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtOpenProcessToken + 6 77DA4A9A 4 Bytes CALL 76DA50A0 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtOpenProcessToken + B 77DA4A9F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtOpenProcessTokenEx + 6 77DA4AAA 4 Bytes [ A8, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtOpenProcessTokenEx + B 77DA4AAF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtOpenThread + 6 77DA4AFA 4 Bytes [ 68, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtOpenThread + B 77DA4AFF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtOpenThreadToken + 6 77DA4B0A 4 Bytes [ 68, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtOpenThreadToken + B 77DA4B0F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtOpenThreadTokenEx + 6 77DA4B1A 4 Bytes CALL 76DA5121 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtOpenThreadTokenEx + B 77DA4B1F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtQueryAttributesFile + 6 77DA4BAA 4 Bytes [ A8, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtQueryAttributesFile + B 77DA4BAF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtQueryFullAttributesFile + 6 77DA4C5A 4 Bytes CALL 76DA525F C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtQueryFullAttributesFile + B 77DA4C5F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtSetInformationFile + 6 77DA513A 4 Bytes [ 28, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtSetInformationFile + B 77DA513F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtSetInformationThread + 6 77DA518A 4 Bytes [ 28, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtSetInformationThread + B 77DA518F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtUnmapViewOfSection + 6 77DA542A 1 Byte [ 68 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtUnmapViewOfSection + 8 77DA542C 2 Bytes [ 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4020] ntdll.dll!NtUnmapViewOfSection + B 77DA542F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtCreateFile + 6 77DA422A 4 Bytes [ 28, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtCreateFile + B 77DA422F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtMapViewOfSection + 6 77DA497A 1 Byte [ 28 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtMapViewOfSection + 8 77DA497C 2 Bytes [ 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtMapViewOfSection + B 77DA497F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtOpenFile + 6 77DA4A0A 4 Bytes [ 68, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtOpenFile + B 77DA4A0F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtOpenProcess + 6 77DA4A8A 4 Bytes [ A8, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtOpenProcess + B 77DA4A8F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtOpenProcessToken + 6 77DA4A9A 4 Bytes CALL 76DA50A0 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtOpenProcessToken + B 77DA4A9F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtOpenProcessTokenEx + 6 77DA4AAA 4 Bytes [ A8, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtOpenProcessTokenEx + B 77DA4AAF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtOpenThread + 6 77DA4AFA 4 Bytes [ 68, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtOpenThread + B 77DA4AFF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtOpenThreadToken + 6 77DA4B0A 4 Bytes [ 68, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtOpenThreadToken + B 77DA4B0F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtOpenThreadTokenEx + 6 77DA4B1A 4 Bytes CALL 76DA5121 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtOpenThreadTokenEx + B 77DA4B1F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtQueryAttributesFile + 6 77DA4BAA 4 Bytes [ A8, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtQueryAttributesFile + B 77DA4BAF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtQueryFullAttributesFile + 6 77DA4C5A 4 Bytes CALL 76DA525F C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtQueryFullAttributesFile + B 77DA4C5F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtSetInformationFile + 6 77DA513A 4 Bytes [ 28, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtSetInformationFile + B 77DA513F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtSetInformationThread + 6 77DA518A 4 Bytes [ 28, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtSetInformationThread + B 77DA518F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtUnmapViewOfSection + 6 77DA542A 1 Byte [ 68 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtUnmapViewOfSection + 8 77DA542C 2 Bytes [ 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4256] ntdll.dll!NtUnmapViewOfSection + B 77DA542F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtCreateFile + 6 77DA422A 4 Bytes [ 28, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtCreateFile + B 77DA422F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtMapViewOfSection + 6 77DA497A 1 Byte [ 28 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtMapViewOfSection + 8 77DA497C 2 Bytes [ 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtMapViewOfSection + B 77DA497F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtOpenFile + 6 77DA4A0A 4 Bytes [ 68, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtOpenFile + B 77DA4A0F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtOpenProcess + 6 77DA4A8A 4 Bytes [ A8, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtOpenProcess + B 77DA4A8F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtOpenProcessToken + 6 77DA4A9A 4 Bytes CALL 76DA50A0 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtOpenProcessToken + B 77DA4A9F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtOpenProcessTokenEx + 6 77DA4AAA 4 Bytes [ A8, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtOpenProcessTokenEx + B 77DA4AAF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtOpenThread + 6 77DA4AFA 4 Bytes [ 68, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtOpenThread + B 77DA4AFF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtOpenThreadToken + 6 77DA4B0A 4 Bytes [ 68, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtOpenThreadToken + B 77DA4B0F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtOpenThreadTokenEx + 6 77DA4B1A 4 Bytes CALL 76DA5121 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtOpenThreadTokenEx + B 77DA4B1F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtQueryAttributesFile + 6 77DA4BAA 4 Bytes [ A8, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtQueryAttributesFile + B 77DA4BAF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtQueryFullAttributesFile + 6 77DA4C5A 4 Bytes CALL 76DA525F C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtQueryFullAttributesFile + B 77DA4C5F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtSetInformationFile + 6 77DA513A 4 Bytes [ 28, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtSetInformationFile + B 77DA513F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtSetInformationThread + 6 77DA518A 4 Bytes [ 28, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtSetInformationThread + B 77DA518F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtUnmapViewOfSection + 6 77DA542A 1 Byte [ 68 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtUnmapViewOfSection + 8 77DA542C 2 Bytes [ 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4300] ntdll.dll!NtUnmapViewOfSection + B 77DA542F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtCreateFile + 6 77DA422A 4 Bytes [ 28, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtCreateFile + B 77DA422F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtMapViewOfSection + 6 77DA497A 1 Byte [ 28 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtMapViewOfSection + 8 77DA497C 2 Bytes [ 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtMapViewOfSection + B 77DA497F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtOpenFile + 6 77DA4A0A 4 Bytes [ 68, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtOpenFile + B 77DA4A0F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtOpenProcess + 6 77DA4A8A 4 Bytes [ A8, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtOpenProcess + B 77DA4A8F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtOpenProcessToken + 6 77DA4A9A 4 Bytes CALL 76DA50A0 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtOpenProcessToken + B 77DA4A9F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtOpenProcessTokenEx + 6 77DA4AAA 4 Bytes [ A8, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtOpenProcessTokenEx + B 77DA4AAF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtOpenThread + 6 77DA4AFA 4 Bytes [ 68, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtOpenThread + B 77DA4AFF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtOpenThreadToken + 6 77DA4B0A 4 Bytes [ 68, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtOpenThreadToken + B 77DA4B0F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtOpenThreadTokenEx + 6 77DA4B1A 4 Bytes CALL 76DA5121 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtOpenThreadTokenEx + B 77DA4B1F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtQueryAttributesFile + 6 77DA4BAA 4 Bytes [ A8, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtQueryAttributesFile + B 77DA4BAF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtQueryFullAttributesFile + 6 77DA4C5A 4 Bytes CALL 76DA525F C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtQueryFullAttributesFile + B 77DA4C5F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtSetInformationFile + 6 77DA513A 4 Bytes [ 28, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtSetInformationFile + B 77DA513F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtSetInformationThread + 6 77DA518A 4 Bytes [ 28, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtSetInformationThread + B 77DA518F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtUnmapViewOfSection + 6 77DA542A 1 Byte [ 68 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtUnmapViewOfSection + 8 77DA542C 2 Bytes [ 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4328] ntdll.dll!NtUnmapViewOfSection + B 77DA542F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtCreateFile + 6 77DA422A 4 Bytes [ 28, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtCreateFile + B 77DA422F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtMapViewOfSection + 6 77DA497A 1 Byte [ 28 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtMapViewOfSection + 8 77DA497C 2 Bytes [ 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtMapViewOfSection + B 77DA497F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtOpenFile + 6 77DA4A0A 4 Bytes [ 68, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtOpenFile + B 77DA4A0F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtOpenProcess + 6 77DA4A8A 4 Bytes [ A8, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtOpenProcess + B 77DA4A8F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtOpenProcessToken + 6 77DA4A9A 4 Bytes CALL 76DA50A0 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtOpenProcessToken + B 77DA4A9F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtOpenProcessTokenEx + 6 77DA4AAA 4 Bytes [ A8, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtOpenProcessTokenEx + B 77DA4AAF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtOpenThread + 6 77DA4AFA 4 Bytes [ 68, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtOpenThread + B 77DA4AFF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtOpenThreadToken + 6 77DA4B0A 4 Bytes [ 68, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtOpenThreadToken + B 77DA4B0F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtOpenThreadTokenEx + 6 77DA4B1A 4 Bytes CALL 76DA5121 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtOpenThreadTokenEx + B 77DA4B1F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtQueryAttributesFile + 6 77DA4BAA 4 Bytes [ A8, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtQueryAttributesFile + B 77DA4BAF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtQueryFullAttributesFile + 6 77DA4C5A 4 Bytes CALL 76DA525F C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtQueryFullAttributesFile + B 77DA4C5F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtSetInformationFile + 6 77DA513A 4 Bytes [ 28, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtSetInformationFile + B 77DA513F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtSetInformationThread + 6 77DA518A 4 Bytes [ 28, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtSetInformationThread + B 77DA518F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtUnmapViewOfSection + 6 77DA542A 1 Byte [ 68 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtUnmapViewOfSection + 8 77DA542C 2 Bytes [ 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4336] ntdll.dll!NtUnmapViewOfSection + B 77DA542F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtCreateFile + 6 77DA422A 4 Bytes [ 28, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtCreateFile + B 77DA422F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtMapViewOfSection + 6 77DA497A 1 Byte [ 28 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtMapViewOfSection + 8 77DA497C 2 Bytes [ 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtMapViewOfSection + B 77DA497F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtOpenFile + 6 77DA4A0A 4 Bytes [ 68, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtOpenFile + B 77DA4A0F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtOpenProcess + 6 77DA4A8A 4 Bytes [ A8, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtOpenProcess + B 77DA4A8F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtOpenProcessToken + 6 77DA4A9A 4 Bytes CALL 76DA50A0 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtOpenProcessToken + B 77DA4A9F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtOpenProcessTokenEx + 6 77DA4AAA 4 Bytes [ A8, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtOpenProcessTokenEx + B 77DA4AAF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtOpenThread + 6 77DA4AFA 4 Bytes [ 68, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtOpenThread + B 77DA4AFF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtOpenThreadToken + 6 77DA4B0A 4 Bytes [ 68, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtOpenThreadToken + B 77DA4B0F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtOpenThreadTokenEx + 6 77DA4B1A 4 Bytes CALL 76DA5121 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtOpenThreadTokenEx + B 77DA4B1F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtQueryAttributesFile + 6 77DA4BAA 4 Bytes [ A8, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtQueryAttributesFile + B 77DA4BAF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtQueryFullAttributesFile + 6 77DA4C5A 4 Bytes CALL 76DA525F C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtQueryFullAttributesFile + B 77DA4C5F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtSetInformationFile + 6 77DA513A 4 Bytes [ 28, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtSetInformationFile + B 77DA513F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtSetInformationThread + 6 77DA518A 4 Bytes [ 28, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtSetInformationThread + B 77DA518F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtUnmapViewOfSection + 6 77DA542A 1 Byte [ 68 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtUnmapViewOfSection + 8 77DA542C 2 Bytes [ 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4348] ntdll.dll!NtUnmapViewOfSection + B 77DA542F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtCreateFile + 6 77DA422A 4 Bytes [ 28, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtCreateFile + B 77DA422F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtMapViewOfSection + 6 77DA497A 1 Byte [ 28 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtMapViewOfSection + 8 77DA497C 2 Bytes [ 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtMapViewOfSection + B 77DA497F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenFile + 6 77DA4A0A 4 Bytes [ 68, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenFile + B 77DA4A0F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenProcess + 6 77DA4A8A 4 Bytes [ A8, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenProcess + B 77DA4A8F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenProcessToken + 6 77DA4A9A 4 Bytes CALL 76DA50A0 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenProcessToken + B 77DA4A9F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenProcessTokenEx + 6 77DA4AAA 4 Bytes [ A8, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenProcessTokenEx + B 77DA4AAF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenThread + 6 77DA4AFA 4 Bytes [ 68, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenThread + B 77DA4AFF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenThreadToken + 6 77DA4B0A 4 Bytes [ 68, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenThreadToken + B 77DA4B0F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenThreadTokenEx + 6 77DA4B1A 4 Bytes CALL 76DA5121 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenThreadTokenEx + B 77DA4B1F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtQueryAttributesFile + 6 77DA4BAA 4 Bytes [ A8, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtQueryAttributesFile + B 77DA4BAF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtQueryFullAttributesFile + 6 77DA4C5A 4 Bytes CALL 76DA525F C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtQueryFullAttributesFile + B 77DA4C5F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtSetInformationFile + 6 77DA513A 4 Bytes [ 28, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtSetInformationFile + B 77DA513F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtSetInformationThread + 6 77DA518A 4 Bytes [ 28, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtSetInformationThread + B 77DA518F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtUnmapViewOfSection + 6 77DA542A 1 Byte [ 68 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtUnmapViewOfSection + 8 77DA542C 2 Bytes [ 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtUnmapViewOfSection + B 77DA542F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtCreateFile + 6 77DA422A 4 Bytes [ 28, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtCreateFile + B 77DA422F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtMapViewOfSection + 6 77DA497A 1 Byte [ 28 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtMapViewOfSection + 8 77DA497C 2 Bytes [ 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtMapViewOfSection + B 77DA497F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtOpenFile + 6 77DA4A0A 4 Bytes [ 68, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtOpenFile + B 77DA4A0F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtOpenProcess + 6 77DA4A8A 4 Bytes [ A8, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtOpenProcess + B 77DA4A8F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtOpenProcessToken + 6 77DA4A9A 4 Bytes CALL 76DA50A0 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtOpenProcessToken + B 77DA4A9F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtOpenProcessTokenEx + 6 77DA4AAA 4 Bytes [ A8, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtOpenProcessTokenEx + B 77DA4AAF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtOpenThread + 6 77DA4AFA 4 Bytes [ 68, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtOpenThread + B 77DA4AFF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtOpenThreadToken + 6 77DA4B0A 4 Bytes [ 68, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtOpenThreadToken + B 77DA4B0F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtOpenThreadTokenEx + 6 77DA4B1A 4 Bytes CALL 76DA5121 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtOpenThreadTokenEx + B 77DA4B1F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtQueryAttributesFile + 6 77DA4BAA 4 Bytes [ A8, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtQueryAttributesFile + B 77DA4BAF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtQueryFullAttributesFile + 6 77DA4C5A 4 Bytes CALL 76DA525F C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtQueryFullAttributesFile + B 77DA4C5F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtSetInformationFile + 6 77DA513A 4 Bytes [ 28, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtSetInformationFile + B 77DA513F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtSetInformationThread + 6 77DA518A 4 Bytes [ 28, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtSetInformationThread + B 77DA518F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtUnmapViewOfSection + 6 77DA542A 1 Byte [ 68 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtUnmapViewOfSection + 8 77DA542C 2 Bytes [ 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5024] ntdll.dll!NtUnmapViewOfSection + B 77DA542F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtCreateFile + 6 77DA422A 4 Bytes [ 28, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtCreateFile + B 77DA422F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtMapViewOfSection + 6 77DA497A 1 Byte [ 28 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtMapViewOfSection + 8 77DA497C 2 Bytes [ 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtMapViewOfSection + B 77DA497F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtOpenFile + 6 77DA4A0A 4 Bytes [ 68, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtOpenFile + B 77DA4A0F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtOpenProcess + 6 77DA4A8A 4 Bytes [ A8, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtOpenProcess + B 77DA4A8F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtOpenProcessToken + 6 77DA4A9A 4 Bytes CALL 76DA50A0 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtOpenProcessToken + B 77DA4A9F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtOpenProcessTokenEx + 6 77DA4AAA 4 Bytes [ A8, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtOpenProcessTokenEx + B 77DA4AAF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtOpenThread + 6 77DA4AFA 4 Bytes [ 68, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtOpenThread + B 77DA4AFF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtOpenThreadToken + 6 77DA4B0A 4 Bytes [ 68, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtOpenThreadToken + B 77DA4B0F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtOpenThreadTokenEx + 6 77DA4B1A 4 Bytes CALL 76DA5121 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtOpenThreadTokenEx + B 77DA4B1F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtQueryAttributesFile + 6 77DA4BAA 4 Bytes [ A8, 00, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtQueryAttributesFile + B 77DA4BAF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtQueryFullAttributesFile + 6 77DA4C5A 4 Bytes CALL 76DA525F C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtQueryFullAttributesFile + B 77DA4C5F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtSetInformationFile + 6 77DA513A 4 Bytes [ 28, 01, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtSetInformationFile + B 77DA513F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtSetInformationThread + 6 77DA518A 4 Bytes [ 28, 02, 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtSetInformationThread + B 77DA518F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtUnmapViewOfSection + 6 77DA542A 1 Byte [ 68 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtUnmapViewOfSection + 8 77DA542C 2 Bytes [ 06, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[5828] ntdll.dll!NtUnmapViewOfSection + B 77DA542F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtCreateFile + 6 77DA422A 4 Bytes [ 28, 00, 16, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtCreateFile + B 77DA422F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtMapViewOfSection + 6 77DA497A 1 Byte [ 28 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtMapViewOfSection + 8 77DA497C 2 Bytes [ 16, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtMapViewOfSection + B 77DA497F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtOpenFile + 6 77DA4A0A 4 Bytes [ 68, 00, 16, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtOpenFile + B 77DA4A0F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtOpenProcess + 6 77DA4A8A 4 Bytes [ A8, 01, 16, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtOpenProcess + B 77DA4A8F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtOpenProcessToken + 6 77DA4A9A 4 Bytes CALL 76DA60A0 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtOpenProcessToken + B 77DA4A9F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtOpenProcessTokenEx + 6 77DA4AAA 4 Bytes [ A8, 02, 16, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtOpenProcessTokenEx + B 77DA4AAF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtOpenThread + 6 77DA4AFA 4 Bytes [ 68, 01, 16, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtOpenThread + B 77DA4AFF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtOpenThreadToken + 6 77DA4B0A 4 Bytes [ 68, 02, 16, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtOpenThreadToken + B 77DA4B0F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtOpenThreadTokenEx + 6 77DA4B1A 4 Bytes CALL 76DA6121 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtOpenThreadTokenEx + B 77DA4B1F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtQueryAttributesFile + 6 77DA4BAA 4 Bytes [ A8, 00, 16, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtQueryAttributesFile + B 77DA4BAF 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtQueryFullAttributesFile + 6 77DA4C5A 4 Bytes CALL 76DA625F C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtQueryFullAttributesFile + B 77DA4C5F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtSetInformationFile + 6 77DA513A 4 Bytes [ 28, 01, 16, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtSetInformationFile + B 77DA513F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtSetInformationThread + 6 77DA518A 4 Bytes [ 28, 02, 16, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtSetInformationThread + B 77DA518F 1 Byte [ E2 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtUnmapViewOfSection + 6 77DA542A 1 Byte [ 68 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtUnmapViewOfSection + 8 77DA542C 2 Bytes [ 16, 00 ]
.text C:\Users\Vozka\AppData\Local\Google\Chrome\Application\chrome.exe[6064] ntdll.dll!NtUnmapViewOfSection + B 77DA542F 1 Byte [ E2 ]