Re: nejde spustit centrum zabezpečení ve win 7 a activex prv
Napsal: 25 črc 2011 21:41
Logy z mbr
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.1.7601 Disk: Hitachi_HTS542516K9SA00 rev.BBCOC31P -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
1 ntkrnlpa!IofCallDriver[0x8307652F] -> \Device\Harddisk0\DR0[0x8659B030]
3 CLASSPNP[0x89AF359E] -> ntkrnlpa!IofCallDriver[0x8307652F] -> [0x864CA7E0]
5 ACPI[0x895AE3D4] -> ntkrnlpa!IofCallDriver[0x8307652F] -> \Device\Ide\IdeDeviceP0T0L0-0[0x864AB908]
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; MOV CX, 0x4; MOV BP, 0x7be; CMP BYTE [BP+0x0], 0x0; }
user & kernel MBR OK
log s gmer první
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2011-07-25 21:53:50
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Hitachi_HTS542516K9SA00 rev.BBCOC31P
Running: gmer.exe; Driver: C:\Users\CHEVYO~1\AppData\Local\Temp\kwtyqkow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
gmer druhý log
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-07-25 22:41:28
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Hitachi_HTS542516K9SA00 rev.BBCOC31P
Running: gmer.exe; Driver: C:\Users\CHEVYO~1\AppData\Local\Temp\kwtyqkow.sys
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13C1 8307D339 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 830B6D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
? system32\DRIVERS\71903405.sys Systém nemůže nalézt uvedenou cestu. !
? C:\Users\CHEVYO~1\AppData\Local\Temp\mbr.sys Systém nemůže nalézt uvedený soubor. !
---- User code sections - GMER 1.0.15 ----
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtCreateFile + 6 779255CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtCreateFile + B 779255D3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtMapViewOfSection + 6 77925C2E 1 Byte [28]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtMapViewOfSection + 6 77925C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtMapViewOfSection + B 77925C33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenFile + 6 77925CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenFile + B 77925CE3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenProcess + 6 77925D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenProcess + B 77925D93 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenProcessToken + 6 77925D9E 4 Bytes CALL 769264A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenProcessToken + B 77925DA3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenProcessTokenEx + 6 77925DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenProcessTokenEx + B 77925DB3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenThread + 6 77925E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenThread + B 77925E13 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenThreadToken + 6 77925E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenThreadToken + B 77925E23 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenThreadTokenEx + 6 77925E2E 4 Bytes CALL 76926535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenThreadTokenEx + B 77925E33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtQueryAttributesFile + 6 77925F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtQueryAttributesFile + B 77925F43 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtQueryFullAttributesFile + 6 77925FEE 4 Bytes CALL 769266F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtQueryFullAttributesFile + B 77925FF3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtSetInformationFile + 6 7792663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtSetInformationFile + B 77926643 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtSetInformationThread + 6 7792669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtSetInformationThread + B 779266A3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 1 Byte [68]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtUnmapViewOfSection + B 779269C3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtCreateFile + 6 779255CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtCreateFile + B 779255D3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtMapViewOfSection + 6 77925C2E 1 Byte [28]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtMapViewOfSection + 6 77925C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtMapViewOfSection + B 77925C33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenFile + 6 77925CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenFile + B 77925CE3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenProcess + 6 77925D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenProcess + B 77925D93 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenProcessToken + 6 77925D9E 4 Bytes CALL 769264A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenProcessToken + B 77925DA3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenProcessTokenEx + 6 77925DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenProcessTokenEx + B 77925DB3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenThread + 6 77925E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenThread + B 77925E13 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenThreadToken + 6 77925E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenThreadToken + B 77925E23 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenThreadTokenEx + 6 77925E2E 4 Bytes CALL 76926535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenThreadTokenEx + B 77925E33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtQueryAttributesFile + 6 77925F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtQueryAttributesFile + B 77925F43 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtQueryFullAttributesFile + 6 77925FEE 4 Bytes CALL 769266F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtQueryFullAttributesFile + B 77925FF3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtSetInformationFile + 6 7792663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtSetInformationFile + B 77926643 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtSetInformationThread + 6 7792669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtSetInformationThread + B 779266A3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 1 Byte [68]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtUnmapViewOfSection + B 779269C3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtCreateFile + 6 779255CE 4 Bytes [28, 00, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtCreateFile + B 779255D3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtMapViewOfSection + 6 77925C2E 1 Byte [28]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtMapViewOfSection + 6 77925C2E 4 Bytes [28, 03, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtMapViewOfSection + B 77925C33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenFile + 6 77925CDE 4 Bytes [68, 00, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenFile + B 77925CE3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenProcess + 6 77925D8E 4 Bytes [A8, 01, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenProcess + B 77925D93 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenProcessToken + 6 77925D9E 4 Bytes CALL 769274A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenProcessToken + B 77925DA3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenProcessTokenEx + 6 77925DAE 4 Bytes [A8, 02, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenProcessTokenEx + B 77925DB3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenThread + 6 77925E0E 4 Bytes [68, 01, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenThread + B 77925E13 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenThreadToken + 6 77925E1E 4 Bytes [68, 02, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenThreadToken + B 77925E23 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenThreadTokenEx + 6 77925E2E 4 Bytes CALL 76927535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenThreadTokenEx + B 77925E33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtQueryAttributesFile + 6 77925F3E 4 Bytes [A8, 00, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtQueryAttributesFile + B 77925F43 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtQueryFullAttributesFile + 6 77925FEE 4 Bytes CALL 769276F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtQueryFullAttributesFile + B 77925FF3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtSetInformationFile + 6 7792663E 4 Bytes [28, 01, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtSetInformationFile + B 77926643 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtSetInformationThread + 6 7792669E 4 Bytes [28, 02, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtSetInformationThread + B 779266A3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 1 Byte [68]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 4 Bytes [68, 03, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtUnmapViewOfSection + B 779269C3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtCreateFile + 6 779255CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtCreateFile + B 779255D3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtMapViewOfSection + 6 77925C2E 1 Byte [28]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtMapViewOfSection + 6 77925C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtMapViewOfSection + B 77925C33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenFile + 6 77925CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenFile + B 77925CE3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenProcess + 6 77925D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenProcess + B 77925D93 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenProcessToken + 6 77925D9E 4 Bytes CALL 769264A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenProcessToken + B 77925DA3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenProcessTokenEx + 6 77925DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenProcessTokenEx + B 77925DB3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenThread + 6 77925E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenThread + B 77925E13 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenThreadToken + 6 77925E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenThreadToken + B 77925E23 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenThreadTokenEx + 6 77925E2E 4 Bytes CALL 76926535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenThreadTokenEx + B 77925E33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtQueryAttributesFile + 6 77925F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtQueryAttributesFile + B 77925F43 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtQueryFullAttributesFile + 6 77925FEE 4 Bytes CALL 769266F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtQueryFullAttributesFile + B 77925FF3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtSetInformationFile + 6 7792663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtSetInformationFile + B 77926643 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtSetInformationThread + 6 7792669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtSetInformationThread + B 779266A3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 1 Byte [68]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtUnmapViewOfSection + B 779269C3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtCreateFile + 6 779255CE 4 Bytes [28, 00, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtCreateFile + B 779255D3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtMapViewOfSection + 6 77925C2E 1 Byte [28]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtMapViewOfSection + 6 77925C2E 4 Bytes [28, 03, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtMapViewOfSection + B 77925C33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenFile + 6 77925CDE 4 Bytes [68, 00, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenFile + B 77925CE3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcess + 6 77925D8E 4 Bytes [A8, 01, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcess + B 77925D93 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcessToken + 6 77925D9E 4 Bytes CALL 769274A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcessToken + B 77925DA3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcessTokenEx + 6 77925DAE 4 Bytes [A8, 02, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcessTokenEx + B 77925DB3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThread + 6 77925E0E 4 Bytes [68, 01, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThread + B 77925E13 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThreadToken + 6 77925E1E 4 Bytes [68, 02, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThreadToken + B 77925E23 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThreadTokenEx + 6 77925E2E 4 Bytes CALL 76927535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThreadTokenEx + B 77925E33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtQueryAttributesFile + 6 77925F3E 4 Bytes [A8, 00, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtQueryAttributesFile + B 77925F43 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtQueryFullAttributesFile + 6 77925FEE 4 Bytes CALL 769276F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtQueryFullAttributesFile + B 77925FF3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtSetInformationFile + 6 7792663E 4 Bytes [28, 01, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtSetInformationFile + B 77926643 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtSetInformationThread + 6 7792669E 4 Bytes [28, 02, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtSetInformationThread + B 779266A3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 1 Byte [68]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 4 Bytes [68, 03, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtUnmapViewOfSection + B 779269C3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtCreateFile + 6 779255CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtCreateFile + B 779255D3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtMapViewOfSection + 6 77925C2E 1 Byte [28]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtMapViewOfSection + 6 77925C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtMapViewOfSection + B 77925C33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenFile + 6 77925CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenFile + B 77925CE3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenProcess + 6 77925D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenProcess + B 77925D93 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenProcessToken + 6 77925D9E 4 Bytes CALL 769264A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenProcessToken + B 77925DA3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenProcessTokenEx + 6 77925DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenProcessTokenEx + B 77925DB3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenThread + 6 77925E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenThread + B 77925E13 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenThreadToken + 6 77925E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenThreadToken + B 77925E23 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenThreadTokenEx + 6 77925E2E 4 Bytes CALL 76926535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenThreadTokenEx + B 77925E33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtQueryAttributesFile + 6 77925F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtQueryAttributesFile + B 77925F43 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtQueryFullAttributesFile + 6 77925FEE 4 Bytes CALL 769266F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtQueryFullAttributesFile + B 77925FF3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtSetInformationFile + 6 7792663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtSetInformationFile + B 77926643 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtSetInformationThread + 6 7792669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtSetInformationThread + B 779266A3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 1 Byte [68]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtUnmapViewOfSection + B 779269C3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtCreateFile + 6 779255CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtCreateFile + B 779255D3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtMapViewOfSection + 6 77925C2E 1 Byte [28]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtMapViewOfSection + 6 77925C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtMapViewOfSection + B 77925C33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenFile + 6 77925CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenFile + B 77925CE3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenProcess + 6 77925D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenProcess + B 77925D93 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenProcessToken + 6 77925D9E 4 Bytes CALL 769264A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenProcessToken + B 77925DA3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenProcessTokenEx + 6 77925DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenProcessTokenEx + B 77925DB3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenThread + 6 77925E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenThread + B 77925E13 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenThreadToken + 6 77925E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenThreadToken + B 77925E23 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenThreadTokenEx + 6 77925E2E 4 Bytes CALL 76926535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenThreadTokenEx + B 77925E33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtQueryAttributesFile + 6 77925F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtQueryAttributesFile + B 77925F43 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtQueryFullAttributesFile + 6 77925FEE 4 Bytes CALL 769266F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtQueryFullAttributesFile + B 77925FF3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtSetInformationFile + 6 7792663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtSetInformationFile + B 77926643 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtSetInformationThread + 6 7792669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtSetInformationThread + B 779266A3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 1 Byte [68]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtUnmapViewOfSection + B 779269C3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtCreateFile + 6 779255CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtCreateFile + B 779255D3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtMapViewOfSection + 6 77925C2E 1 Byte [28]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtMapViewOfSection + 6 77925C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtMapViewOfSection + B 77925C33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenFile + 6 77925CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenFile + B 77925CE3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenProcess + 6 77925D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenProcess + B 77925D93 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenProcessToken + 6 77925D9E 4 Bytes CALL 769264A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenProcessToken + B 77925DA3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenProcessTokenEx + 6 77925DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenProcessTokenEx + B 77925DB3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenThread + 6 77925E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenThread + B 77925E13 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenThreadToken + 6 77925E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenThreadToken + B 77925E23 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenThreadTokenEx + 6 77925E2E 4 Bytes CALL 76926535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenThreadTokenEx + B 77925E33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtQueryAttributesFile + 6 77925F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtQueryAttributesFile + B 77925F43 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtQueryFullAttributesFile + 6 77925FEE 4 Bytes CALL 769266F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtQueryFullAttributesFile + B 77925FF3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtSetInformationFile + 6 7792663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtSetInformationFile + B 77926643 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtSetInformationThread + 6 7792669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtSetInformationThread + B 779266A3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 1 Byte [68]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtUnmapViewOfSection + B 779269C3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtCreateFile + 6 779255CE 4 Bytes [28, 00, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtCreateFile + B 779255D3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtMapViewOfSection + 6 77925C2E 1 Byte [28]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtMapViewOfSection + 6 77925C2E 4 Bytes [28, 03, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtMapViewOfSection + B 77925C33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenFile + 6 77925CDE 4 Bytes [68, 00, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenFile + B 77925CE3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenProcess + 6 77925D8E 4 Bytes [A8, 01, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenProcess + B 77925D93 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenProcessToken + 6 77925D9E 4 Bytes CALL 769274A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenProcessToken + B 77925DA3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenProcessTokenEx + 6 77925DAE 4 Bytes [A8, 02, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenProcessTokenEx + B 77925DB3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenThread + 6 77925E0E 4 Bytes [68, 01, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenThread + B 77925E13 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenThreadToken + 6 77925E1E 4 Bytes [68, 02, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenThreadToken + B 77925E23 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenThreadTokenEx + 6 77925E2E 4 Bytes CALL 76927535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenThreadTokenEx + B 77925E33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtQueryAttributesFile + 6 77925F3E 4 Bytes [A8, 00, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtQueryAttributesFile + B 77925F43 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtQueryFullAttributesFile + 6 77925FEE 4 Bytes CALL 769276F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtQueryFullAttributesFile + B 77925FF3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtSetInformationFile + 6 7792663E 4 Bytes [28, 01, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtSetInformationFile + B 77926643 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtSetInformationThread + 6 7792669E 4 Bytes [28, 02, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtSetInformationThread + B 779266A3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 1 Byte [68]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 4 Bytes [68, 03, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtUnmapViewOfSection + B 779269C3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtCreateFile + 6 779255CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtCreateFile + B 779255D3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtMapViewOfSection + 6 77925C2E 1 Byte [28]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtMapViewOfSection + 6 77925C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtMapViewOfSection + B 77925C33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenFile + 6 77925CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenFile + B 77925CE3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenProcess + 6 77925D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenProcess + B 77925D93 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenProcessToken + 6 77925D9E 4 Bytes CALL 769264A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenProcessToken + B 77925DA3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenProcessTokenEx + 6 77925DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenProcessTokenEx + B 77925DB3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenThread + 6 77925E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenThread + B 77925E13 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenThreadToken + 6 77925E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenThreadToken + B 77925E23 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenThreadTokenEx + 6 77925E2E 4 Bytes CALL 76926535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenThreadTokenEx + B 77925E33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtQueryAttributesFile + 6 77925F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtQueryAttributesFile + B 77925F43 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtQueryFullAttributesFile + 6 77925FEE 4 Bytes CALL 769266F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtQueryFullAttributesFile + B 77925FF3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtSetInformationFile + 6 7792663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtSetInformationFile + B 77926643 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtSetInformationThread + 6 7792669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtSetInformationThread + B 779266A3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 1 Byte [68]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtUnmapViewOfSection + B 779269C3 1 Byte [E2]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\system32\rundll32.exe[3124] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [759BFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[3124] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [759BFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[3124] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [759BFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[3124] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [759BFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[3124] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [759BFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[3124] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [759BFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000004c halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Threads - GMER 1.0.15 ----
Thread System [4:3504] A3854F2E
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Atheros AR5007EG \x2013 adaptér bezdrátové sítě 1?
Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Upgrade\BTHPORT (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Upgrade\HidBth (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Upgrade\HidBth\Devices (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Upgrade\HidBth\Devices\001d603cec22001b5953b1ca (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Upgrade\HidBth\Devices\001d603cec22001b5953b1ca@ConnectionAuthenticated 0
Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Upgrade\HidBth\Devices\001d603cec22001b5953b1ca@VirtuallyCabled 0
Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Upgrade\LocalRadioSettings (not active ControlSet)
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Atheros AR5007EG \x2013 adaptér bezdrátové sítě 1?
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\HidBth
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\HidBth\Devices
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\HidBth\Devices\001d603cec22001b5953b1ca
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\HidBth\Devices\001d603cec22001b5953b1ca@ConnectionAuthenticated 0
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\HidBth\Devices\001d603cec22001b5953b1ca@VirtuallyCabled 0
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings
Reg HKLM\SYSTEM\ControlSet003\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Atheros AR5007EG \x2013 adaptér bezdrátové sítě 1?
Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Upgrade\BTHPORT (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Upgrade\HidBth (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Upgrade\HidBth\Devices (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Upgrade\HidBth\Devices\001d603cec22001b5953b1ca (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Upgrade\HidBth\Devices\001d603cec22001b5953b1ca@ConnectionAuthenticated 0
Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Upgrade\HidBth\Devices\001d603cec22001b5953b1ca@VirtuallyCabled 0
Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Upgrade\LocalRadioSettings (not active ControlSet)
---- EOF - GMER 1.0.15 ----
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.1.7601 Disk: Hitachi_HTS542516K9SA00 rev.BBCOC31P -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
1 ntkrnlpa!IofCallDriver[0x8307652F] -> \Device\Harddisk0\DR0[0x8659B030]
3 CLASSPNP[0x89AF359E] -> ntkrnlpa!IofCallDriver[0x8307652F] -> [0x864CA7E0]
5 ACPI[0x895AE3D4] -> ntkrnlpa!IofCallDriver[0x8307652F] -> \Device\Ide\IdeDeviceP0T0L0-0[0x864AB908]
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; MOV CX, 0x4; MOV BP, 0x7be; CMP BYTE [BP+0x0], 0x0; }
user & kernel MBR OK
log s gmer první
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2011-07-25 21:53:50
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Hitachi_HTS542516K9SA00 rev.BBCOC31P
Running: gmer.exe; Driver: C:\Users\CHEVYO~1\AppData\Local\Temp\kwtyqkow.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
gmer druhý log
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-07-25 22:41:28
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Hitachi_HTS542516K9SA00 rev.BBCOC31P
Running: gmer.exe; Driver: C:\Users\CHEVYO~1\AppData\Local\Temp\kwtyqkow.sys
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13C1 8307D339 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 830B6D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
? system32\DRIVERS\71903405.sys Systém nemůže nalézt uvedenou cestu. !
? C:\Users\CHEVYO~1\AppData\Local\Temp\mbr.sys Systém nemůže nalézt uvedený soubor. !
---- User code sections - GMER 1.0.15 ----
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtCreateFile + 6 779255CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtCreateFile + B 779255D3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtMapViewOfSection + 6 77925C2E 1 Byte [28]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtMapViewOfSection + 6 77925C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtMapViewOfSection + B 77925C33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenFile + 6 77925CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenFile + B 77925CE3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenProcess + 6 77925D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenProcess + B 77925D93 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenProcessToken + 6 77925D9E 4 Bytes CALL 769264A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenProcessToken + B 77925DA3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenProcessTokenEx + 6 77925DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenProcessTokenEx + B 77925DB3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenThread + 6 77925E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenThread + B 77925E13 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenThreadToken + 6 77925E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenThreadToken + B 77925E23 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenThreadTokenEx + 6 77925E2E 4 Bytes CALL 76926535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtOpenThreadTokenEx + B 77925E33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtQueryAttributesFile + 6 77925F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtQueryAttributesFile + B 77925F43 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtQueryFullAttributesFile + 6 77925FEE 4 Bytes CALL 769266F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtQueryFullAttributesFile + B 77925FF3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtSetInformationFile + 6 7792663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtSetInformationFile + B 77926643 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtSetInformationThread + 6 7792669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtSetInformationThread + B 779266A3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 1 Byte [68]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[1124] ntdll.dll!NtUnmapViewOfSection + B 779269C3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtCreateFile + 6 779255CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtCreateFile + B 779255D3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtMapViewOfSection + 6 77925C2E 1 Byte [28]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtMapViewOfSection + 6 77925C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtMapViewOfSection + B 77925C33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenFile + 6 77925CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenFile + B 77925CE3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenProcess + 6 77925D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenProcess + B 77925D93 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenProcessToken + 6 77925D9E 4 Bytes CALL 769264A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenProcessToken + B 77925DA3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenProcessTokenEx + 6 77925DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenProcessTokenEx + B 77925DB3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenThread + 6 77925E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenThread + B 77925E13 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenThreadToken + 6 77925E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenThreadToken + B 77925E23 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenThreadTokenEx + 6 77925E2E 4 Bytes CALL 76926535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtOpenThreadTokenEx + B 77925E33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtQueryAttributesFile + 6 77925F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtQueryAttributesFile + B 77925F43 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtQueryFullAttributesFile + 6 77925FEE 4 Bytes CALL 769266F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtQueryFullAttributesFile + B 77925FF3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtSetInformationFile + 6 7792663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtSetInformationFile + B 77926643 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtSetInformationThread + 6 7792669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtSetInformationThread + B 779266A3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 1 Byte [68]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3112] ntdll.dll!NtUnmapViewOfSection + B 779269C3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtCreateFile + 6 779255CE 4 Bytes [28, 00, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtCreateFile + B 779255D3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtMapViewOfSection + 6 77925C2E 1 Byte [28]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtMapViewOfSection + 6 77925C2E 4 Bytes [28, 03, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtMapViewOfSection + B 77925C33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenFile + 6 77925CDE 4 Bytes [68, 00, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenFile + B 77925CE3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenProcess + 6 77925D8E 4 Bytes [A8, 01, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenProcess + B 77925D93 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenProcessToken + 6 77925D9E 4 Bytes CALL 769274A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenProcessToken + B 77925DA3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenProcessTokenEx + 6 77925DAE 4 Bytes [A8, 02, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenProcessTokenEx + B 77925DB3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenThread + 6 77925E0E 4 Bytes [68, 01, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenThread + B 77925E13 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenThreadToken + 6 77925E1E 4 Bytes [68, 02, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenThreadToken + B 77925E23 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenThreadTokenEx + 6 77925E2E 4 Bytes CALL 76927535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenThreadTokenEx + B 77925E33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtQueryAttributesFile + 6 77925F3E 4 Bytes [A8, 00, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtQueryAttributesFile + B 77925F43 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtQueryFullAttributesFile + 6 77925FEE 4 Bytes CALL 769276F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtQueryFullAttributesFile + B 77925FF3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtSetInformationFile + 6 7792663E 4 Bytes [28, 01, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtSetInformationFile + B 77926643 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtSetInformationThread + 6 7792669E 4 Bytes [28, 02, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtSetInformationThread + B 779266A3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 1 Byte [68]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 4 Bytes [68, 03, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtUnmapViewOfSection + B 779269C3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtCreateFile + 6 779255CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtCreateFile + B 779255D3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtMapViewOfSection + 6 77925C2E 1 Byte [28]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtMapViewOfSection + 6 77925C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtMapViewOfSection + B 77925C33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenFile + 6 77925CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenFile + B 77925CE3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenProcess + 6 77925D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenProcess + B 77925D93 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenProcessToken + 6 77925D9E 4 Bytes CALL 769264A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenProcessToken + B 77925DA3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenProcessTokenEx + 6 77925DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenProcessTokenEx + B 77925DB3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenThread + 6 77925E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenThread + B 77925E13 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenThreadToken + 6 77925E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenThreadToken + B 77925E23 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenThreadTokenEx + 6 77925E2E 4 Bytes CALL 76926535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtOpenThreadTokenEx + B 77925E33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtQueryAttributesFile + 6 77925F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtQueryAttributesFile + B 77925F43 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtQueryFullAttributesFile + 6 77925FEE 4 Bytes CALL 769266F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtQueryFullAttributesFile + B 77925FF3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtSetInformationFile + 6 7792663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtSetInformationFile + B 77926643 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtSetInformationThread + 6 7792669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtSetInformationThread + B 779266A3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 1 Byte [68]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3856] ntdll.dll!NtUnmapViewOfSection + B 779269C3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtCreateFile + 6 779255CE 4 Bytes [28, 00, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtCreateFile + B 779255D3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtMapViewOfSection + 6 77925C2E 1 Byte [28]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtMapViewOfSection + 6 77925C2E 4 Bytes [28, 03, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtMapViewOfSection + B 77925C33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenFile + 6 77925CDE 4 Bytes [68, 00, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenFile + B 77925CE3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcess + 6 77925D8E 4 Bytes [A8, 01, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcess + B 77925D93 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcessToken + 6 77925D9E 4 Bytes CALL 769274A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcessToken + B 77925DA3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcessTokenEx + 6 77925DAE 4 Bytes [A8, 02, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenProcessTokenEx + B 77925DB3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThread + 6 77925E0E 4 Bytes [68, 01, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThread + B 77925E13 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThreadToken + 6 77925E1E 4 Bytes [68, 02, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThreadToken + B 77925E23 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThreadTokenEx + 6 77925E2E 4 Bytes CALL 76927535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtOpenThreadTokenEx + B 77925E33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtQueryAttributesFile + 6 77925F3E 4 Bytes [A8, 00, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtQueryAttributesFile + B 77925F43 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtQueryFullAttributesFile + 6 77925FEE 4 Bytes CALL 769276F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtQueryFullAttributesFile + B 77925FF3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtSetInformationFile + 6 7792663E 4 Bytes [28, 01, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtSetInformationFile + B 77926643 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtSetInformationThread + 6 7792669E 4 Bytes [28, 02, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtSetInformationThread + B 779266A3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 1 Byte [68]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 4 Bytes [68, 03, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3864] ntdll.dll!NtUnmapViewOfSection + B 779269C3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtCreateFile + 6 779255CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtCreateFile + B 779255D3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtMapViewOfSection + 6 77925C2E 1 Byte [28]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtMapViewOfSection + 6 77925C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtMapViewOfSection + B 77925C33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenFile + 6 77925CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenFile + B 77925CE3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenProcess + 6 77925D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenProcess + B 77925D93 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenProcessToken + 6 77925D9E 4 Bytes CALL 769264A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenProcessToken + B 77925DA3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenProcessTokenEx + 6 77925DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenProcessTokenEx + B 77925DB3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenThread + 6 77925E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenThread + B 77925E13 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenThreadToken + 6 77925E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenThreadToken + B 77925E23 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenThreadTokenEx + 6 77925E2E 4 Bytes CALL 76926535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtOpenThreadTokenEx + B 77925E33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtQueryAttributesFile + 6 77925F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtQueryAttributesFile + B 77925F43 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtQueryFullAttributesFile + 6 77925FEE 4 Bytes CALL 769266F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtQueryFullAttributesFile + B 77925FF3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtSetInformationFile + 6 7792663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtSetInformationFile + B 77926643 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtSetInformationThread + 6 7792669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtSetInformationThread + B 779266A3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 1 Byte [68]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3912] ntdll.dll!NtUnmapViewOfSection + B 779269C3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtCreateFile + 6 779255CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtCreateFile + B 779255D3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtMapViewOfSection + 6 77925C2E 1 Byte [28]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtMapViewOfSection + 6 77925C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtMapViewOfSection + B 77925C33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenFile + 6 77925CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenFile + B 77925CE3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenProcess + 6 77925D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenProcess + B 77925D93 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenProcessToken + 6 77925D9E 4 Bytes CALL 769264A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenProcessToken + B 77925DA3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenProcessTokenEx + 6 77925DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenProcessTokenEx + B 77925DB3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenThread + 6 77925E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenThread + B 77925E13 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenThreadToken + 6 77925E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenThreadToken + B 77925E23 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenThreadTokenEx + 6 77925E2E 4 Bytes CALL 76926535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtOpenThreadTokenEx + B 77925E33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtQueryAttributesFile + 6 77925F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtQueryAttributesFile + B 77925F43 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtQueryFullAttributesFile + 6 77925FEE 4 Bytes CALL 769266F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtQueryFullAttributesFile + B 77925FF3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtSetInformationFile + 6 7792663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtSetInformationFile + B 77926643 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtSetInformationThread + 6 7792669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtSetInformationThread + B 779266A3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 1 Byte [68]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3924] ntdll.dll!NtUnmapViewOfSection + B 779269C3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtCreateFile + 6 779255CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtCreateFile + B 779255D3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtMapViewOfSection + 6 77925C2E 1 Byte [28]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtMapViewOfSection + 6 77925C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtMapViewOfSection + B 77925C33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenFile + 6 77925CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenFile + B 77925CE3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenProcess + 6 77925D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenProcess + B 77925D93 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenProcessToken + 6 77925D9E 4 Bytes CALL 769264A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenProcessToken + B 77925DA3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenProcessTokenEx + 6 77925DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenProcessTokenEx + B 77925DB3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenThread + 6 77925E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenThread + B 77925E13 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenThreadToken + 6 77925E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenThreadToken + B 77925E23 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenThreadTokenEx + 6 77925E2E 4 Bytes CALL 76926535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtOpenThreadTokenEx + B 77925E33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtQueryAttributesFile + 6 77925F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtQueryAttributesFile + B 77925F43 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtQueryFullAttributesFile + 6 77925FEE 4 Bytes CALL 769266F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtQueryFullAttributesFile + B 77925FF3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtSetInformationFile + 6 7792663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtSetInformationFile + B 77926643 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtSetInformationThread + 6 7792669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtSetInformationThread + B 779266A3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 1 Byte [68]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[3996] ntdll.dll!NtUnmapViewOfSection + B 779269C3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtCreateFile + 6 779255CE 4 Bytes [28, 00, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtCreateFile + B 779255D3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtMapViewOfSection + 6 77925C2E 1 Byte [28]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtMapViewOfSection + 6 77925C2E 4 Bytes [28, 03, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtMapViewOfSection + B 77925C33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenFile + 6 77925CDE 4 Bytes [68, 00, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenFile + B 77925CE3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenProcess + 6 77925D8E 4 Bytes [A8, 01, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenProcess + B 77925D93 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenProcessToken + 6 77925D9E 4 Bytes CALL 769274A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenProcessToken + B 77925DA3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenProcessTokenEx + 6 77925DAE 4 Bytes [A8, 02, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenProcessTokenEx + B 77925DB3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenThread + 6 77925E0E 4 Bytes [68, 01, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenThread + B 77925E13 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenThreadToken + 6 77925E1E 4 Bytes [68, 02, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenThreadToken + B 77925E23 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenThreadTokenEx + 6 77925E2E 4 Bytes CALL 76927535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtOpenThreadTokenEx + B 77925E33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtQueryAttributesFile + 6 77925F3E 4 Bytes [A8, 00, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtQueryAttributesFile + B 77925F43 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtQueryFullAttributesFile + 6 77925FEE 4 Bytes CALL 769276F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtQueryFullAttributesFile + B 77925FF3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtSetInformationFile + 6 7792663E 4 Bytes [28, 01, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtSetInformationFile + B 77926643 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtSetInformationThread + 6 7792669E 4 Bytes [28, 02, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtSetInformationThread + B 779266A3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 1 Byte [68]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 4 Bytes [68, 03, 17, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4012] ntdll.dll!NtUnmapViewOfSection + B 779269C3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtCreateFile + 6 779255CE 4 Bytes [28, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtCreateFile + B 779255D3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtMapViewOfSection + 6 77925C2E 1 Byte [28]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtMapViewOfSection + 6 77925C2E 4 Bytes [28, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtMapViewOfSection + B 77925C33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenFile + 6 77925CDE 4 Bytes [68, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenFile + B 77925CE3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenProcess + 6 77925D8E 4 Bytes [A8, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenProcess + B 77925D93 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenProcessToken + 6 77925D9E 4 Bytes CALL 769264A4 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenProcessToken + B 77925DA3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenProcessTokenEx + 6 77925DAE 4 Bytes [A8, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenProcessTokenEx + B 77925DB3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenThread + 6 77925E0E 4 Bytes [68, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenThread + B 77925E13 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenThreadToken + 6 77925E1E 4 Bytes [68, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenThreadToken + B 77925E23 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenThreadTokenEx + 6 77925E2E 4 Bytes CALL 76926535 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtOpenThreadTokenEx + B 77925E33 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtQueryAttributesFile + 6 77925F3E 4 Bytes [A8, 00, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtQueryAttributesFile + B 77925F43 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtQueryFullAttributesFile + 6 77925FEE 4 Bytes CALL 769266F3 C:\Windows\system32\SHELL32.dll (Windows Shell Common Dll/Microsoft Corporation)
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtQueryFullAttributesFile + B 77925FF3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtSetInformationFile + 6 7792663E 4 Bytes [28, 01, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtSetInformationFile + B 77926643 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtSetInformationThread + 6 7792669E 4 Bytes [28, 02, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtSetInformationThread + B 779266A3 1 Byte [E2]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 1 Byte [68]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtUnmapViewOfSection + 6 779269BE 4 Bytes [68, 03, 07, 00]
.text C:\Users\Chevy opava\AppData\Local\Google\Chrome\Application\chrome.exe[4056] ntdll.dll!NtUnmapViewOfSection + B 779269C3 1 Byte [E2]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Windows\system32\rundll32.exe[3124] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [759BFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[3124] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [759BFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[3124] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [759BFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[3124] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [759BFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[3124] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [759BFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
IAT C:\Windows\system32\rundll32.exe[3124] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [759BFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility client library/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000004c halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Threads - GMER 1.0.15 ----
Thread System [4:3504] A3854F2E
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Atheros AR5007EG \x2013 adaptér bezdrátové sítě 1?
Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Upgrade\BTHPORT (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Upgrade\HidBth (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Upgrade\HidBth\Devices (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Upgrade\HidBth\Devices\001d603cec22001b5953b1ca (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Upgrade\HidBth\Devices\001d603cec22001b5953b1ca@ConnectionAuthenticated 0
Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Upgrade\HidBth\Devices\001d603cec22001b5953b1ca@VirtuallyCabled 0
Reg HKLM\SYSTEM\ControlSet001\services\BTHPORT\Upgrade\LocalRadioSettings (not active ControlSet)
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Atheros AR5007EG \x2013 adaptér bezdrátové sítě 1?
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\BTHPORT
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\HidBth
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\HidBth\Devices
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\HidBth\Devices\001d603cec22001b5953b1ca
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\HidBth\Devices\001d603cec22001b5953b1ca@ConnectionAuthenticated 0
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\HidBth\Devices\001d603cec22001b5953b1ca@VirtuallyCabled 0
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Upgrade\LocalRadioSettings
Reg HKLM\SYSTEM\ControlSet003\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@Atheros AR5007EG \x2013 adaptér bezdrátové sítě 1?
Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Upgrade\BTHPORT (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Upgrade\HidBth (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Upgrade\HidBth\Devices (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Upgrade\HidBth\Devices\001d603cec22001b5953b1ca (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Upgrade\HidBth\Devices\001d603cec22001b5953b1ca@ConnectionAuthenticated 0
Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Upgrade\HidBth\Devices\001d603cec22001b5953b1ca@VirtuallyCabled 0
Reg HKLM\SYSTEM\ControlSet003\services\BTHPORT\Upgrade\LocalRadioSettings (not active ControlSet)
---- EOF - GMER 1.0.15 ----