GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2012-06-04 13:58:13 Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Scsi\nvgts1Port0Path0Target0Lun0 WDC_WD32 rev.01.0 Running: 4mh0co3n.exe; Driver: C:\DOCUME~1\R447D~1.BED\USTAWI~1\Temp\kfldrpob.sys ---- System - GMER 1.0.15 ---- SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwAssignProcessToJobObject [0xB45F9610] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwDebugActiveProcess [0xB45F9C10] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwDuplicateObject [0xB45F9730] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwOpenProcess [0xB45F94B0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwOpenThread [0xB45F9570] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwProtectVirtualMemory [0xB45F96D0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwQueueApcThread [0xB45F9790] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetContextThread [0xB45F9690] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetInformationThread [0xB45F9650] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetSecurityObject [0xB45F97D0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSuspendProcess [0xB45F9510] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSuspendThread [0xB45F9590] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwTerminateProcess [0xB45F94D0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwTerminateThread [0xB45F95D0] SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwWriteVirtualMemory [0xB45F9750] ---- Kernel code sections - GMER 1.0.15 ---- .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB7419380, 0x3D0F75, 0xE8000020] ---- User code sections - GMER 1.0.15 ---- .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 1E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 1E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 1E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 1E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90F41A .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 1E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 1E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 1E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90F48B .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 1E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90F5B9 .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 1E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 1E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 1E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B912B1A .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B912B8B .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B912CB9 .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2] .text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1760] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 2D, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 2D, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 2D, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 2D, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B91031A .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 2D, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 2D, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 2D, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B91038B .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 2D, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B9104B9 .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 2D, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 2D, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 2D, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 3E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 3E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 3E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 3E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B91141A .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 3E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 3E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 3E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B91148B .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 3E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B9115B9 .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 3E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 3E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 3E, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 20, 00] {SUB [EAX], AL; AND [EAX], AL} .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 20, 00] {SUB [EBX], AL; AND [EAX], AL} .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 20, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 20, 00] {TEST AL, 0x1; AND [EAX], AL} .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90F61A .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 20, 00] {TEST AL, 0x2; AND [EAX], AL} .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 20, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 20, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90F68B .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 20, 00] {TEST AL, 0x0; AND [EAX], AL} .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90F7B9 .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 20, 00] {SUB [ECX], AL; AND [EAX], AL} .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 20, 00] {SUB [EDX], AL; AND [EAX], AL} .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 20, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2] .text C:\Program Files\Internet Explorer\iexplore.exe[3636] USER32.dll!DialogBoxParamW 7E3747AB 5 Bytes JMP 405D5505 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3636] USER32.dll!CreateWindowExW 7E37D0A3 5 Bytes JMP 406ADB14 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3636] USER32.dll!DialogBoxIndirectParamW 7E382072 5 Bytes JMP 407A53AF C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3636] USER32.dll!MessageBoxIndirectA 7E38A082 5 Bytes JMP 407A52E1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3636] USER32.dll!DialogBoxParamA 7E38B144 5 Bytes JMP 407A534C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3636] USER32.dll!MessageBoxExW 7E3A0838 5 Bytes JMP 407A51B2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3636] USER32.dll!MessageBoxExA 7E3A085C 5 Bytes JMP 407A5214 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3636] USER32.dll!DialogBoxIndirectParamA 7E3A6D7D 5 Bytes JMP 407A5412 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3636] USER32.dll!MessageBoxIndirectW 7E3B64D5 5 Bytes JMP 407A5276 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3708] USER32.dll!DialogBoxParamW 7E3747AB 5 Bytes JMP 405D5505 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3708] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 406A9AA5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3708] USER32.dll!CallNextHookEx 7E37B3C6 5 Bytes JMP 4069D119 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3708] USER32.dll!CreateWindowExW 7E37D0A3 5 Bytes JMP 406ADB14 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3708] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 40614686 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3708] USER32.dll!DialogBoxIndirectParamW 7E382072 5 Bytes JMP 407A53AF C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3708] USER32.dll!MessageBoxIndirectA 7E38A082 5 Bytes JMP 407A52E1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3708] USER32.dll!DialogBoxParamA 7E38B144 5 Bytes JMP 407A534C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3708] USER32.dll!MessageBoxExW 7E3A0838 5 Bytes JMP 407A51B2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3708] USER32.dll!MessageBoxExA 7E3A085C 5 Bytes JMP 407A5214 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3708] USER32.dll!DialogBoxIndirectParamA 7E3A6D7D 5 Bytes JMP 407A5412 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3708] USER32.dll!MessageBoxIndirectW 7E3B64D5 5 Bytes JMP 407A5276 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3708] ole32.dll!CoCreateInstance 774EF1BC 5 Bytes JMP 406ADB70 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Program Files\Internet Explorer\iexplore.exe[3708] ole32.dll!OleLoadFromStream 7751983B 5 Bytes JMP 407A5717 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation) .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B912B1A .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B912B8B .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B912CB9 .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 55, 00] .text C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2] ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[620] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 00340010 IAT C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[900] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 006C0010 IAT C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2092] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 00580010 IAT C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3152] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 00690010 IAT C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3444] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 00370010 IAT C:\Program Files\Internet Explorer\iexplore.exe[3708] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1ACB] C:\Program Files\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation) IAT C:\Documents and Settings\r.bednarz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[4004] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 006C0010 ---- Devices - GMER 1.0.15 ---- AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET) AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET) ---- EOF - GMER 1.0.15 ----