Hi, my computer is infected by a search engine redirection virus and my ISP also called me to say that large amount of spam have been sent from my computer. That happened while my anti-virus (Kaspersky) was not up-to-date and Malwarebytes report that: "195.88.209.15 (Type: outgoing, Port: 63838, Process: rundll32.exe)"
I've followed the guide and here's the DDS log:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_31
Run by Julie at 13:19:48 on 2012-05-05
Microsoft Windows 7 Édition Familiale Premium 6.1.7601.1.1252.2.1036.18.2942.1617 [GMT -4:00]
.
AV: Kaspersky Internet Security *Enabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Kaspersky Internet Security *Enabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB}
FW: Kaspersky Internet Security *Enabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D}
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\system32\atiesrxx.exe
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalService
C:\windows\system32\atieclxx.exe
C:\windows\system32\svchost.exe -k NetworkService
C:\windows\System32\spoolsv.exe
C:\windows\system32\taskeng.exe
C:\windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\system32\rundll32.exe
C:\windows\Explorer.EXE
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\windows\system32\svchost.exe -k imgsvc
C:\windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\TOSHIBA\TECO\TecoService.exe
C:\windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\windows\System32\rundll32.exe
C:\windows\system32\SearchIndexer.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
C:\Program Files\TOSHIBA\TECO\TEco.exe
C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe
C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\real\realplayer\Update\realsched.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
C:\Program Files\LSI SoftModem\agrsmsvc.exe
C:\windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\TOSHIBA\RSelect\RSelSvc.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\klwtblfs.exe
C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe
C:\windows\system32\rundll32.exe
C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\DllHost.exe
C:\windows\system32\conhost.exe
C:\windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.ca/
uWindow Title = Présenté par TOSHIBA Leading Innovation >>>
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.toshiba.ca/fr/bienvenue
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
mDefault_Page_URL = hxxp://www.toshiba.ca/fr/bienvenue
mStart Page = hxxp://www.toshiba.ca/fr/bienvenue
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2012\ievkbd.dll
BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2012\klwtbbho.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Gestionnaire Antidote.exe] c:\program files\druide\antidote\Gestionnaire Antidote.exe
uRun: [Google Update] "c:\users\julie\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [WeatherEye] c:\users\julie\appdata\local\météomédia\météoéclair\WeatherEye.exe
mRun: [<NO NAME>]
mRun: [SVPWUTIL] c:\program files\toshiba\utilities\SVPWUTIL.exe SVPwUTIL
mRun: [HWSetup] "c:\program files\toshiba\utilities\HWSetup.exe" hwSetUP
mRun: [KeNotify] c:\program files\toshiba\utilities\KeNotify.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
mRun: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
mRun: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
mRun: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [TWebCamera] "%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
mRun: [SmartFaceVWatcher] %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
mRun: [TosSENotify] c:\program files\toshiba\toshiba hdd ssd alert\TosWaitSrv.exe
mRun: [ToshibaServiceStation] "c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe" /hide:60
mRun: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
mRun: [TosWaitSrv] %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
mRun: [TosNC] %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
mRun: [TosReelTimeMonitor] %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
mRun: [Nikon Transfer Monitor] c:\program files\common files\nikon\monitor\NkMonitor.exe
mRun: [ContentTransferWMDetector.exe] c:\program files\sony\content transfer\ContentTransferWMDetector.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe"
mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" updatewithcreateonce "software\cyberlink\youcam\1.0"
mRun: [UpdatePSTShortCut] "c:\program files\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\programdata\scansoft\paperport\11\config\ereg\Ereg.ini"
mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2012\avp.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
StartupFolder: c:\users\julie\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xporter vers Microsoft Excel - c:\progra~1\micros~3\office10\EXCEL.EXE/3000
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky internet security 2012\ievkbd.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2012\klwtbbho.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{82C303E5-15EF-4636-9EA5-4824333D6973} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{82C303E5-15EF-4636-9EA5-4824333D6973}\46166796464767 : DhcpNameServer = 192.168.10.1
TCP: Interfaces\{82C303E5-15EF-4636-9EA5-4824333D6973}\A455354594E4540534 : DhcpNameServer = 216.144.115.251 216.144.115.252
TCP: Interfaces\{82C303E5-15EF-4636-9EA5-4824333D6973}\C45675962756C6563737 : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{9825FD63-315D-447B-8026-8CA822814995} : DhcpNameServer = 192.168.0.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: klogon - c:\windows\system32\klogon.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\julie\appdata\roaming\mozilla\firefox\profiles\8hzjdy88.default\
FF - prefs.js: browser.startup.homepage - www.google.ca
FF - component: c:\program files\kaspersky lab\kaspersky internet security 2011\ffext\kavantibanner@kaspersky.ru\components\abhelperxpcom.dll
FF - component: c:\program files\kaspersky lab\kaspersky internet security 2011\ffext\linkfilter@kaspersky.ru\components\kavlinkfilter.dll
FF - component: c:\program files\kaspersky lab\kaspersky internet security 2011\ffext\virtualkeyboard@kaspersky.ru\components\ffvkplugin.dll
FF - component: c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\users\julie\appdata\local\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\users\julie\appdata\roaming\facebook\npfbplugin_1_0_3.dll
.
============= SERVICES / DRIVERS ===============
.
R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [2011-3-4 11352]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2011-3-10 23856]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-12-16 176128]
R2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\toshiba\configfree\CFIWmxSvcs.exe [2009-8-10 185712]
R2 ConfigFree Service;ConfigFree Service;c:\program files\toshiba\configfree\CFSvcs.exe [2009-3-10 46448]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-5-4 654408]
R2 RSELSVC;TOSHIBA Modem region select service;c:\program files\toshiba\rselect\RSelSvc.exe [2009-7-7 62832]
R2 SSPORT;SSPORT;c:\windows\system32\drivers\SSPORT.SYS [2009-12-23 5120]
R2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\toshiba\teco\TecoService.exe [2009-8-11 185712]
R2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\drivers\TVALZFL.sys [2009-6-19 12920]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-11-2 19984]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-5-4 22344]
R3 PGEffect;Pangu effect driver;c:\windows\system32\drivers\PGEffect.sys [2009-12-16 24064]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-12-16 167936]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\drivers\rtl8192se.sys [2010-4-26 1011232]
R3 TMachInfo;TMachInfo;c:\program files\toshiba\toshiba service station\TMachInfo.exe [2009-12-16 51512]
R3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\toshiba\toshiba hdd ssd alert\TosSmartSrv.exe [2009-8-3 111960]
R3 TPCHSrv;TPCH Service;c:\program files\toshiba\tphm\TPCHSrv.exe [2009-8-6 685424]
R3 WSDPrintDevice;Prise en charge de l’impression WSD via UMB;c:\windows\system32\drivers\WSDPrint.sys [2009-7-13 17920]
S2 AVP;Kaspersky Anti-Virus Service;c:\program files\kaspersky lab\kaspersky internet security 2012\avp.exe [2011-4-24 202296]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Service Google Update (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-12-1 136176]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-2-29 158856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-29 257696]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 gupdatem;Service Google Update (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-12-1 136176]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [2009-12-16 171520]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-7-3 52224]
S3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\wat\WatAdminSvc.exe [2010-4-20 1343400]
.
=============== Created Last 30 ================
.
2012-05-04 21:17:28 -------- d-----w- c:\users\julie\appdata\roaming\Malwarebytes
2012-05-04 21:16:52 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-05-04 21:16:52 -------- d-----w- c:\programdata\Malwarebytes
2012-05-04 21:16:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-04-29 19:46:22 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-29 19:46:22 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-29 18:55:43 4777280 ----a-w- C:\procexp.exe
2012-04-29 18:54:05 2473592 ----a-w- C:\Procmon.exe
2012-04-29 12:36:02 -------- d-----w- c:\users\julie\appdata\local\{B23B3B6C-C838-4B20-A3E1-7BDCA6D026F2}
2012-04-29 12:35:45 -------- d-----w- c:\users\julie\appdata\local\{3F412DA4-8D59-4CF6-BFAE-C0C3757E3398}
2012-04-26 11:14:16 -------- d-----w- c:\users\julie\appdata\local\{0A88F25C-67AC-4182-8504-1A12E836E171}
2012-04-26 11:14:02 -------- d-----w- c:\users\julie\appdata\local\{9DE53F2F-8147-4975-8647-50BE5F48260C}
2012-04-25 21:32:43 -------- d-----w- c:\users\julie\appdata\local\{A28DDD1C-B874-4EF9-B80E-62FD57A6C8E8}
2012-04-25 21:32:25 -------- d-----w- c:\users\julie\appdata\local\{6F040F82-9516-4ACF-B65D-D2172B06F111}
2012-04-23 11:58:11 -------- d-----w- c:\users\julie\appdata\local\{91273DE9-E9D8-4336-9703-11BB1DB47D28}
2012-04-23 11:57:34 -------- d-----w- c:\users\julie\appdata\local\{9B205AE0-CAC8-451D-92DA-F3824C5C9184}
2012-04-22 22:16:46 -------- d-----w- c:\users\julie\appdata\local\{4EB5778F-60CD-4AD2-9442-5645A4D27477}
2012-04-22 22:16:23 -------- d-----w- c:\users\julie\appdata\local\{77156185-E72D-4533-9246-9B52C3732547}
2012-04-21 22:47:02 -------- d-----w- c:\users\julie\appdata\local\{343A5D85-390C-470F-85AA-E21AD9E2986C}
2012-04-21 22:46:43 -------- d-----w- c:\users\julie\appdata\local\{047CB805-53A4-4719-A22C-416A8F724B4E}
2012-04-20 12:10:35 -------- d-----w- c:\users\julie\appdata\local\{C8322060-0090-4F09-94C4-7920F0FB25FF}
2012-04-20 12:10:16 -------- d-----w- c:\users\julie\appdata\local\{FA989777-56C7-4A79-A4F9-878D34A0EFE8}
2012-04-19 22:48:27 -------- d-----w- c:\users\julie\appdata\local\{7CFA799F-B083-4E2F-AA0C-18D2634535B2}
2012-04-19 22:48:11 -------- d-----w- c:\users\julie\appdata\local\{F14A617F-2785-44B4-95CF-D0407A1E811B}
2012-04-18 00:07:42 -------- d-----w- c:\users\julie\appdata\local\{9422EE31-8B82-49F7-9BDF-63E4D5E9B5C0}
2012-04-18 00:07:19 -------- d-----w- c:\users\julie\appdata\local\{5680990A-353F-4272-A422-D8C1DE9E6905}
2012-04-15 22:49:22 -------- d-----w- c:\users\julie\appdata\local\{8C93976E-B8EC-4B9D-A398-29A14EAF8696}
2012-04-15 22:49:09 -------- d-----w- c:\users\julie\appdata\local\{BA35A5A0-F482-4CA0-AA57-91ACFDD9A1B8}
2012-04-15 22:25:33 -------- d-----w- c:\users\julie\appdata\local\{74650EE1-9CA6-418A-A156-002C214D6512}
2012-04-15 22:25:09 -------- d-----w- c:\users\julie\appdata\local\{A67B89D8-6B80-4BEB-8566-47F35DAD0908}
2012-04-14 19:39:24 -------- d-----w- c:\program files\common files\Canon
2012-04-14 18:50:10 -------- d-----w- c:\users\julie\appdata\local\{90C02063-E965-4A27-92C5-47C011786E51}
2012-04-14 15:31:50 -------- d-----w- c:\users\julie\appdata\local\{8C19D541-F508-474D-8DDA-308D5F7B0A8A}
2012-04-14 15:31:28 -------- d-----w- c:\users\julie\appdata\local\{3A25F304-5126-45C3-AA38-24BD2345C40C}
2012-04-12 21:35:29 -------- d-----w- c:\users\julie\appdata\local\{436257CE-0682-4934-B79A-6087BFD743A6}
2012-04-12 21:35:05 -------- d-----w- c:\users\julie\appdata\local\{CBB2D3BA-E71D-4A00-ADD6-8DAECA0FFE88}
2012-04-12 01:16:03 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-12 01:16:03 19824 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-12 01:16:03 172544 ----a-w- c:\windows\system32\wintrust.dll
2012-04-12 01:16:03 159232 ----a-w- c:\windows\system32\imagehlp.dll
2012-04-12 01:15:45 3968368 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-12 01:15:44 3913072 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-04-11 22:04:08 -------- d-----w- c:\users\julie\appdata\local\{89A11C68-25BD-4EC3-AA4A-72A37254CA47}
2012-04-11 22:03:40 -------- d-----w- c:\users\julie\appdata\local\{42642482-62CB-4C1C-AE54-E1D8261828DD}
2012-04-10 12:24:42 -------- d-----w- c:\users\julie\appdata\local\{EB6A1B8A-D098-4BE1-8180-F7A3414BEFC7}
2012-04-10 12:24:30 -------- d-----w- c:\users\julie\appdata\local\{E21E2174-5B1C-49EA-B98D-221BB82EF9C4}
2012-04-09 13:53:10 -------- d-----w- c:\users\julie\appdata\local\{0E10F5CE-3178-4FF2-90BE-911CFA09D1C7}
2012-04-09 13:52:57 -------- d-----w- c:\users\julie\appdata\local\{DA195952-C21C-481F-B9B0-9A8BE037F822}
2012-04-08 17:51:09 -------- d-----w- c:\users\julie\appdata\local\{CEA34F0B-BCCE-4D9E-9417-02257F887FDA}
2012-04-06 13:39:44 -------- d-----w- c:\users\julie\appdata\local\{C2B92FD7-01E0-4EE2-BF65-1CCCCB2CE5F4}
2012-04-06 13:39:21 -------- d-----w- c:\users\julie\appdata\local\{C4B045FE-9F3B-4682-8F9A-B742F210B269}
2012-04-05 20:25:11 -------- d-----w- c:\users\julie\appdata\local\{AE9F2296-3986-47BC-A383-79EAB55E7435}
2012-04-05 20:24:58 -------- d-----w- c:\users\julie\appdata\local\{5398D990-5AC3-4800-88F3-F3B555E2A387}
2012-04-05 20:03:52 -------- d-----w- c:\users\julie\appdata\local\ECRSC
.
==================== Find3M ====================
.
2012-04-23 19:14:30 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-02-28 05:38:52 981504 ----a-w- c:\windows\system32\wininet.dll
2012-02-28 03:52:27 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2012-02-17 05:34:22 826880 ----a-w- c:\windows\system32\rdpcore.dll
2012-02-17 04:14:08 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-02-17 04:13:22 24576 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2012-02-10 05:38:43 1077248 ----a-w- c:\windows\system32\DWrite.dll
.
============= FINISH: 13:20:20,08 ===============
and GMER:
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-05-05 13:56:21
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 FUJITSU_MJA2500BH_G2 rev.00400018
Running: 22xl74v5.exe; Driver: C:\Users\Julie\AppData\Local\Temp\kwloypod.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0x8BF1628A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcConnectPort [0x8BF30342]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcCreatePort [0x8BF30678]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwAlpcSendWaitReceivePort [0x8BF309EE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwClose [0x8BF16D04]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwConnectPort [0x8BF3002A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateEvent [0x8BF17276]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateMutant [0x8BF17164]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreatePort [0x8BF304E8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateSection [0x8BF16046]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateSemaphore [0x8BF1738E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateThread [0x8BF168BA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateThreadEx [0x8BF16A2A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateUserProcess [0x8BF174A6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwCreateWaitablePort [0x8BF305B0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwDebugActiveProcess [0x8BF1774E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwDeviceIoControlFile [0x8BF16D46]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwDuplicateObject [0x8BF18750]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwLoadDriver [0x8BF17840]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwMapViewOfSection [0x8BF17DAC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwNotifyChangeKey [0x8BF2E840]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenEvent [0x8BF17308]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenMutant [0x8BF171F0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenProcess [0x8BF164C4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenSection [0x8BF17B90]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenSemaphore [0x8BF17420]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwOpenThread [0x8BF163B8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQueryDirectoryObject [0x8BF1755C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQueryObject [0x8BF2EA38]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQuerySection [0x8BF180D2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwQueueApcThread [0x8BF179E0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwReplyPort [0x8BF307DC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0x8BF3072A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0x8BF30848]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwResumeThread [0x8BF185F2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSecureConnectPort [0x8BF301B2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetContextThread [0x8BF16BA4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetInformationToken [0x8BF175FA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSetSystemInformation [0x8BF18222]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSuspendProcess [0x8BF18316]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSuspendThread [0x8BF18450]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwSystemDebugControl [0x8BF17670]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwTerminateProcess [0x8BF16664]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwTerminateThread [0x8BF165BA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwUnmapViewOfSection [0x8BF17F8A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wlh_x86]/Kaspersky Lab) ZwWriteVirtualMemory [0x8BF16750]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13C1 82E59359 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82E92D52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10D7 82E99DAC 4 Bytes [8A, 62, F1, 8B]
.text ntkrnlpa.exe!KeRemoveQueueEx + 10FF 82E99DD4 8 Bytes [42, 03, F3, 8B, 78, 06, F3, ...]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1143 82E99E18 4 Bytes [EE, 09, F3, 8B]
.text ntkrnlpa.exe!KeRemoveQueueEx + 116F 82E99E44 4 Bytes [04, 6D, F1, 8B]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1193 82E99E68 4 Bytes [2A, 00, F3, 8B]
.text ...
.text C:\windows\system32\DRIVERS\tos_sps32.sys section is writeable [0x843A3000, 0x3C849, 0xE8000020]
.dsrt C:\windows\system32\DRIVERS\tos_sps32.sys unknown last section [0x843E8000, 0x3DC, 0x48000040]
.text C:\windows\system32\DRIVERS\atikmdag.sys section is writeable [0x91E0B000, 0x2D5526, 0xE8000020]
? C:\Users\Julie\AppData\Local\Temp\mbr.sys Le fichier spécifié est introuvable. !
---- User code sections - GMER 1.0.15 ----
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] ntdll.dll!NtQueryInformationProcess 77B06048 5 Bytes JMP 00445A3A
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] GDI32.dll!ExtTextOutW 763E8192 5 Bytes JMP 0042F09E
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] GDI32.dll!GetGlyphIndicesW 763EB78F 5 Bytes JMP 0042F52B
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] GDI32.dll!TextOutW 763EFDE4 5 Bytes JMP 0042EB6A
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] GDI32.dll!ExtTextOutA 763F03F9 5 Bytes JMP 0042EFBA
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] GDI32.dll!TextOutA 763F077D 5 Bytes JMP 0042EA9E
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] GDI32.dll!GetGlyphIndicesA 7640BB6A 5 Bytes JMP 0042F45E
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] USER32.dll!DrawTextExW 771E5894 5 Bytes JMP 0042EED3
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] USER32.dll!DrawTextW 771E5B6A 5 Bytes JMP 0042ED11
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] USER32.dll!SetClipboardData 771F2962 5 Bytes JMP 0042E987
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] USER32.dll!DialogBoxParamW 771F3B9B 5 Bytes JMP 0042DC86
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] USER32.dll!DrawTextA 771FAE29 5 Bytes JMP 0042EC36
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] USER32.dll!DrawTextExA 771FAE60 5 Bytes JMP 0042EDEC
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] WININET.dll!InternetCrackUrlA 777DD07D 5 Bytes JMP 0042F7F1
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] WININET.dll!InternetCrackUrlW 7781893C 5 Bytes JMP 0042F93A
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] WS2_32.dll!closesocket 77C13918 5 Bytes JMP 0042E8E0
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] WS2_32.dll!getaddrinfo 77C14296 5 Bytes JMP 0042D7D7
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] WS2_32.dll!WSASend 77C14406 5 Bytes JMP 0042E5A8
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] WS2_32.dll!GetAddrInfoW 77C14889 5 Bytes JMP 0042D8B7
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] WS2_32.dll!recv 77C16B0E 5 Bytes JMP 0042E4FA
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] WS2_32.dll!send 77C16F01 5 Bytes JMP 0042E455
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] WS2_32.dll!WSARecv 77C17089 5 Bytes JMP 0042E67C
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] WS2_32.dll!WSAGetOverlappedResult 77C17489 5 Bytes JMP 0042E7C0
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] WS2_32.dll!WSAAsyncGetHostByName 77C2726A 5 Bytes JMP 0042DBA7
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[1652] WS2_32.dll!gethostbyname 77C27673 5 Bytes JMP 0042D716
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtCreateFile + 6 77B055CE 4 Bytes [28, 00, 25, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtCreateFile + B 77B055D3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtMapViewOfSection + 6 77B05C2E 1 Byte [28]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtMapViewOfSection + 6 77B05C2E 4 Bytes [28, 03, 25, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtMapViewOfSection + B 77B05C33 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtOpenFile + 6 77B05CDE 4 Bytes [68, 00, 25, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtOpenFile + B 77B05CE3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtOpenProcess + 6 77B05D8E 4 Bytes [A8, 01, 25, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtOpenProcess + B 77B05D93 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtOpenProcessToken + 6 77B05D9E 4 Bytes CALL 76B082A4 C:\windows\system32\SHELL32.dll (DLL commune du shell Windows/Microsoft Corporation)
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtOpenProcessToken + B 77B05DA3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtOpenProcessTokenEx + 6 77B05DAE 4 Bytes [A8, 02, 25, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtOpenProcessTokenEx + B 77B05DB3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtOpenThread + 6 77B05E0E 4 Bytes [68, 01, 25, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtOpenThread + B 77B05E13 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtOpenThreadToken + 6 77B05E1E 4 Bytes [68, 02, 25, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtOpenThreadToken + B 77B05E23 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtOpenThreadTokenEx + 6 77B05E2E 4 Bytes CALL 76B08335 C:\windows\system32\SHELL32.dll (DLL commune du shell Windows/Microsoft Corporation)
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtOpenThreadTokenEx + B 77B05E33 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtQueryAttributesFile + 6 77B05F3E 4 Bytes [A8, 00, 25, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtQueryAttributesFile + B 77B05F43 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtQueryFullAttributesFile + 6 77B05FEE 4 Bytes CALL 76B084F3 C:\windows\system32\SHELL32.dll (DLL commune du shell Windows/Microsoft Corporation)
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtQueryFullAttributesFile + B 77B05FF3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtSetInformationFile + 6 77B0663E 4 Bytes [28, 01, 25, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtSetInformationFile + B 77B06643 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtSetInformationThread + 6 77B0669E 4 Bytes [28, 02, 25, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtSetInformationThread + B 77B066A3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtUnmapViewOfSection + 6 77B069BE 1 Byte [68]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtUnmapViewOfSection + 6 77B069BE 4 Bytes [68, 03, 25, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2032] ntdll.dll!NtUnmapViewOfSection + B 77B069C3 1 Byte [E2]
.text C:\Program Files\real\realplayer\Update\realsched.exe[2552] kernel32.dll!SetUnhandledExceptionFilter 762DF4FB 5 Bytes [33, C0, C2, 04, 00] {XOR EAX, EAX; RET 0x4}
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] ntdll.dll!NtQueryInformationProcess 77B06048 5 Bytes JMP 014D5A3A
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] GDI32.dll!ExtTextOutW 763E8192 5 Bytes JMP 014BF09E
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] GDI32.dll!GetGlyphIndicesW 763EB78F 5 Bytes JMP 014BF52B
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] GDI32.dll!TextOutW 763EFDE4 5 Bytes JMP 014BEB6A
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] GDI32.dll!ExtTextOutA 763F03F9 5 Bytes JMP 014BEFBA
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] GDI32.dll!TextOutA 763F077D 5 Bytes JMP 014BEA9E
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] GDI32.dll!GetGlyphIndicesA 7640BB6A 5 Bytes JMP 014BF45E
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] USER32.dll!DrawTextExW 771E5894 5 Bytes JMP 014BEED3
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] USER32.dll!DrawTextW 771E5B6A 5 Bytes JMP 014BED11
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] USER32.dll!SetClipboardData 771F2962 5 Bytes JMP 014BE987
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] USER32.dll!DialogBoxParamW 771F3B9B 5 Bytes JMP 014BDC86
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] USER32.dll!DrawTextA 771FAE29 5 Bytes JMP 014BEC36
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] USER32.dll!DrawTextExA 771FAE60 5 Bytes JMP 014BEDEC
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] WININET.dll!InternetCrackUrlA 777DD07D 5 Bytes JMP 014BF7F1
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] WININET.dll!InternetCrackUrlW 7781893C 5 Bytes JMP 014BF93A
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] WS2_32.dll!closesocket 77C13918 5 Bytes JMP 014BE8E0
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] WS2_32.dll!getaddrinfo 77C14296 5 Bytes JMP 014BD7D7
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] WS2_32.dll!WSASend 77C14406 5 Bytes JMP 014BE5A8
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] WS2_32.dll!GetAddrInfoW 77C14889 5 Bytes JMP 014BD8B7
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] WS2_32.dll!recv 77C16B0E 5 Bytes JMP 014BE4FA
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] WS2_32.dll!send 77C16F01 5 Bytes JMP 014BE455
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] WS2_32.dll!WSARecv 77C17089 5 Bytes JMP 014BE67C
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] WS2_32.dll!WSAGetOverlappedResult 77C17489 5 Bytes JMP 014BE7C0
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] WS2_32.dll!WSAAsyncGetHostByName 77C2726A 5 Bytes JMP 014BDBA7
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2580] WS2_32.dll!gethostbyname 77C27673 5 Bytes JMP 014BD716
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtCreateFile + 6 77B055CE 4 Bytes [28, 00, 11, 00] {SUB [EAX], AL; ADC [EAX], EAX}
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtCreateFile + B 77B055D3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtMapViewOfSection + 6 77B05C2E 1 Byte [28]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtMapViewOfSection + 6 77B05C2E 4 Bytes [28, 03, 11, 00] {SUB [EBX], AL; ADC [EAX], EAX}
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtMapViewOfSection + B 77B05C33 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtOpenFile + 6 77B05CDE 4 Bytes [68, 00, 11, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtOpenFile + B 77B05CE3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtOpenProcess + 6 77B05D8E 4 Bytes [A8, 01, 11, 00] {TEST AL, 0x1; ADC [EAX], EAX}
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtOpenProcess + B 77B05D93 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtOpenProcessToken + 6 77B05D9E 4 Bytes CALL 76B06EA4 C:\windows\system32\SHELL32.dll (DLL commune du shell Windows/Microsoft Corporation)
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtOpenProcessToken + B 77B05DA3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtOpenProcessTokenEx + 6 77B05DAE 4 Bytes [A8, 02, 11, 00] {TEST AL, 0x2; ADC [EAX], EAX}
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtOpenProcessTokenEx + B 77B05DB3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtOpenThread + 6 77B05E0E 4 Bytes [68, 01, 11, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtOpenThread + B 77B05E13 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtOpenThreadToken + 6 77B05E1E 4 Bytes [68, 02, 11, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtOpenThreadToken + B 77B05E23 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtOpenThreadTokenEx + 6 77B05E2E 4 Bytes CALL 76B06F35 C:\windows\system32\SHELL32.dll (DLL commune du shell Windows/Microsoft Corporation)
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtOpenThreadTokenEx + B 77B05E33 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtQueryAttributesFile + 6 77B05F3E 4 Bytes [A8, 00, 11, 00] {TEST AL, 0x0; ADC [EAX], EAX}
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtQueryAttributesFile + B 77B05F43 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtQueryFullAttributesFile + 6 77B05FEE 4 Bytes CALL 76B070F3 C:\windows\system32\SHELL32.dll (DLL commune du shell Windows/Microsoft Corporation)
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtQueryFullAttributesFile + B 77B05FF3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtSetInformationFile + 6 77B0663E 4 Bytes [28, 01, 11, 00] {SUB [ECX], AL; ADC [EAX], EAX}
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtSetInformationFile + B 77B06643 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtSetInformationThread + 6 77B0669E 4 Bytes [28, 02, 11, 00] {SUB [EDX], AL; ADC [EAX], EAX}
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtSetInformationThread + B 77B066A3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtUnmapViewOfSection + 6 77B069BE 1 Byte [68]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtUnmapViewOfSection + 6 77B069BE 4 Bytes [68, 03, 11, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[2796] ntdll.dll!NtUnmapViewOfSection + B 77B069C3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtCreateFile + 6 77B055CE 4 Bytes [28, 00, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtCreateFile + B 77B055D3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtMapViewOfSection + 6 77B05C2E 1 Byte [28]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtMapViewOfSection + 6 77B05C2E 4 Bytes [28, 03, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtMapViewOfSection + B 77B05C33 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenFile + 6 77B05CDE 4 Bytes [68, 00, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenFile + B 77B05CE3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenProcess + 6 77B05D8E 4 Bytes [A8, 01, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenProcess + B 77B05D93 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenProcessToken + 6 77B05D9E 4 Bytes CALL 76B0A3A4 C:\windows\system32\SHELL32.dll (DLL commune du shell Windows/Microsoft Corporation)
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenProcessToken + B 77B05DA3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenProcessTokenEx + 6 77B05DAE 4 Bytes [A8, 02, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenProcessTokenEx + B 77B05DB3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenThread + 6 77B05E0E 4 Bytes [68, 01, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenThread + B 77B05E13 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenThreadToken + 6 77B05E1E 4 Bytes [68, 02, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenThreadToken + B 77B05E23 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenThreadTokenEx + 6 77B05E2E 4 Bytes CALL 76B0A435 C:\windows\system32\SHELL32.dll (DLL commune du shell Windows/Microsoft Corporation)
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtOpenThreadTokenEx + B 77B05E33 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtQueryAttributesFile + 6 77B05F3E 4 Bytes [A8, 00, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtQueryAttributesFile + B 77B05F43 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtQueryFullAttributesFile + 6 77B05FEE 4 Bytes CALL 76B0A5F3 C:\windows\system32\SHELL32.dll (DLL commune du shell Windows/Microsoft Corporation)
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtQueryFullAttributesFile + B 77B05FF3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtSetInformationFile + 6 77B0663E 4 Bytes [28, 01, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtSetInformationFile + B 77B06643 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtSetInformationThread + 6 77B0669E 4 Bytes [28, 02, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtSetInformationThread + B 77B066A3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtUnmapViewOfSection + 6 77B069BE 1 Byte [68]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtUnmapViewOfSection + 6 77B069BE 4 Bytes [68, 03, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3152] ntdll.dll!NtUnmapViewOfSection + B 77B069C3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtCreateFile + 6 77B055CE 4 Bytes [28, 00, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtCreateFile + B 77B055D3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtMapViewOfSection + 6 77B05C2E 1 Byte [28]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtMapViewOfSection + 6 77B05C2E 4 Bytes [28, 03, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtMapViewOfSection + B 77B05C33 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtOpenFile + 6 77B05CDE 4 Bytes [68, 00, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtOpenFile + B 77B05CE3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtOpenProcess + 6 77B05D8E 4 Bytes [A8, 01, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtOpenProcess + B 77B05D93 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtOpenProcessToken + 6 77B05D9E 4 Bytes CALL 76B0A3A4 C:\windows\system32\SHELL32.dll (DLL commune du shell Windows/Microsoft Corporation)
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtOpenProcessToken + B 77B05DA3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtOpenProcessTokenEx + 6 77B05DAE 4 Bytes [A8, 02, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtOpenProcessTokenEx + B 77B05DB3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtOpenThread + 6 77B05E0E 4 Bytes [68, 01, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtOpenThread + B 77B05E13 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtOpenThreadToken + 6 77B05E1E 4 Bytes [68, 02, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtOpenThreadToken + B 77B05E23 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtOpenThreadTokenEx + 6 77B05E2E 4 Bytes CALL 76B0A435 C:\windows\system32\SHELL32.dll (DLL commune du shell Windows/Microsoft Corporation)
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtOpenThreadTokenEx + B 77B05E33 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtQueryAttributesFile + 6 77B05F3E 4 Bytes [A8, 00, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtQueryAttributesFile + B 77B05F43 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtQueryFullAttributesFile + 6 77B05FEE 4 Bytes CALL 76B0A5F3 C:\windows\system32\SHELL32.dll (DLL commune du shell Windows/Microsoft Corporation)
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtQueryFullAttributesFile + B 77B05FF3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtSetInformationFile + 6 77B0663E 4 Bytes [28, 01, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtSetInformationFile + B 77B06643 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtSetInformationThread + 6 77B0669E 4 Bytes [28, 02, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtSetInformationThread + B 77B066A3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtUnmapViewOfSection + 6 77B069BE 1 Byte [68]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtUnmapViewOfSection + 6 77B069BE 4 Bytes [68, 03, 46, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[3696] ntdll.dll!NtUnmapViewOfSection + B 77B069C3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] ntdll.dll!NtQueryInformationProcess 77B06048 5 Bytes JMP 01235A3A
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] GDI32.dll!ExtTextOutW 763E8192 5 Bytes JMP 0121F09E
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] GDI32.dll!GetGlyphIndicesW 763EB78F 5 Bytes JMP 0121F52B
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] GDI32.dll!TextOutW 763EFDE4 5 Bytes JMP 0121EB6A
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] GDI32.dll!ExtTextOutA 763F03F9 5 Bytes JMP 0121EFBA
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] GDI32.dll!TextOutA 763F077D 5 Bytes JMP 0121EA9E
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] GDI32.dll!GetGlyphIndicesA 7640BB6A 5 Bytes JMP 0121F45E
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] USER32.dll!DrawTextExW 771E5894 5 Bytes JMP 0121EED3
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] USER32.dll!DrawTextW 771E5B6A 5 Bytes JMP 0121ED11
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] USER32.dll!SetClipboardData 771F2962 5 Bytes JMP 0121E987
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] USER32.dll!DialogBoxParamW 771F3B9B 5 Bytes JMP 0121DC86
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] USER32.dll!DrawTextA 771FAE29 5 Bytes JMP 0121EC36
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] USER32.dll!DrawTextExA 771FAE60 5 Bytes JMP 0121EDEC
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] WININET.dll!InternetCrackUrlA 777DD07D 5 Bytes JMP 0121F7F1
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] WININET.dll!InternetCrackUrlW 7781893C 5 Bytes JMP 0121F93A
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] WS2_32.dll!closesocket 77C13918 5 Bytes JMP 0121E8E0
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] WS2_32.dll!getaddrinfo 77C14296 5 Bytes JMP 0121D7D7
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] WS2_32.dll!WSASend 77C14406 5 Bytes JMP 0121E5A8
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] WS2_32.dll!GetAddrInfoW 77C14889 5 Bytes JMP 0121D8B7
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] WS2_32.dll!recv 77C16B0E 5 Bytes JMP 0121E4FA
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] WS2_32.dll!send 77C16F01 5 Bytes JMP 0121E455
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] WS2_32.dll!WSARecv 77C17089 5 Bytes JMP 0121E67C
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] WS2_32.dll!WSAGetOverlappedResult 77C17489 5 Bytes JMP 0121E7C0
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] WS2_32.dll!WSAAsyncGetHostByName 77C2726A 5 Bytes JMP 0121DBA7
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[4604] WS2_32.dll!gethostbyname 77C27673 5 Bytes JMP 0121D716
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] ntdll.dll!NtQueryInformationProcess 77B06048 5 Bytes JMP 011F5A3A
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] GDI32.dll!ExtTextOutW 763E8192 5 Bytes JMP 011DF09E
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] GDI32.dll!GetGlyphIndicesW 763EB78F 5 Bytes JMP 011DF52B
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] GDI32.dll!TextOutW 763EFDE4 5 Bytes JMP 011DEB6A
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] GDI32.dll!ExtTextOutA 763F03F9 5 Bytes JMP 011DEFBA
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] GDI32.dll!TextOutA 763F077D 5 Bytes JMP 011DEA9E
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] GDI32.dll!GetGlyphIndicesA 7640BB6A 5 Bytes JMP 011DF45E
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] USER32.dll!DrawTextExW 771E5894 5 Bytes JMP 011DEED3
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] USER32.dll!DrawTextW 771E5B6A 5 Bytes JMP 011DED11
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] USER32.dll!SetClipboardData 771F2962 5 Bytes JMP 011DE987
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] USER32.dll!DialogBoxParamW 771F3B9B 5 Bytes JMP 011DDC86
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] USER32.dll!DrawTextA 771FAE29 5 Bytes JMP 011DEC36
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] USER32.dll!DrawTextExA 771FAE60 5 Bytes JMP 011DEDEC
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] WININET.dll!InternetCrackUrlA 777DD07D 5 Bytes JMP 011DF7F1
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] WININET.dll!InternetCrackUrlW 7781893C 5 Bytes JMP 011DF93A
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] WS2_32.dll!closesocket 77C13918 5 Bytes JMP 011DE8E0
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] WS2_32.dll!getaddrinfo 77C14296 5 Bytes JMP 011DD7D7
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] WS2_32.dll!WSASend 77C14406 5 Bytes JMP 011DE5A8
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] WS2_32.dll!GetAddrInfoW 77C14889 5 Bytes JMP 011DD8B7
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] WS2_32.dll!recv 77C16B0E 5 Bytes JMP 011DE4FA
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] WS2_32.dll!send 77C16F01 5 Bytes JMP 011DE455
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] WS2_32.dll!WSARecv 77C17089 5 Bytes JMP 011DE67C
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] WS2_32.dll!WSAGetOverlappedResult 77C17489 5 Bytes JMP 011DE7C0
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] WS2_32.dll!WSAAsyncGetHostByName 77C2726A 5 Bytes JMP 011DDBA7
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5400] WS2_32.dll!gethostbyname 77C27673 5 Bytes JMP 011DD716
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtCreateFile + 6 77B055CE 4 Bytes [28, 00, 0F, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtCreateFile + B 77B055D3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtMapViewOfSection + 6 77B05C2E 1 Byte [28]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtMapViewOfSection + 6 77B05C2E 4 Bytes [28, 03, 0F, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtMapViewOfSection + B 77B05C33 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtOpenFile + 6 77B05CDE 4 Bytes [68, 00, 0F, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtOpenFile + B 77B05CE3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtOpenProcess + 6 77B05D8E 4 Bytes [A8, 01, 0F, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtOpenProcess + B 77B05D93 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtOpenProcessToken + 6 77B05D9E 4 Bytes CALL 76B06CA4 C:\windows\system32\SHELL32.dll (DLL commune du shell Windows/Microsoft Corporation)
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtOpenProcessToken + B 77B05DA3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtOpenProcessTokenEx + 6 77B05DAE 4 Bytes [A8, 02, 0F, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtOpenProcessTokenEx + B 77B05DB3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtOpenThread + 6 77B05E0E 4 Bytes [68, 01, 0F, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtOpenThread + B 77B05E13 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtOpenThreadToken + 6 77B05E1E 4 Bytes [68, 02, 0F, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtOpenThreadToken + B 77B05E23 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtOpenThreadTokenEx + 6 77B05E2E 4 Bytes CALL 76B06D35 C:\windows\system32\SHELL32.dll (DLL commune du shell Windows/Microsoft Corporation)
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtOpenThreadTokenEx + B 77B05E33 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtQueryAttributesFile + 6 77B05F3E 4 Bytes [A8, 00, 0F, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtQueryAttributesFile + B 77B05F43 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtQueryFullAttributesFile + 6 77B05FEE 4 Bytes CALL 76B06EF3 C:\windows\system32\SHELL32.dll (DLL commune du shell Windows/Microsoft Corporation)
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtQueryFullAttributesFile + B 77B05FF3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtQueryInformationProcess 77B06048 5 Bytes JMP 020B5A3A
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtSetInformationFile + 6 77B0663E 4 Bytes [28, 01, 0F, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtSetInformationFile + B 77B06643 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtSetInformationThread + 6 77B0669E 4 Bytes [28, 02, 0F, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtSetInformationThread + B 77B066A3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtUnmapViewOfSection + 6 77B069BE 1 Byte [68]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtUnmapViewOfSection + 6 77B069BE 4 Bytes [68, 03, 0F, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] ntdll.dll!NtUnmapViewOfSection + B 77B069C3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] GDI32.dll!ExtTextOutW 763E8192 5 Bytes JMP 0209F09E
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] GDI32.dll!GetGlyphIndicesW 763EB78F 5 Bytes JMP 0209F52B
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] GDI32.dll!TextOutW 763EFDE4 5 Bytes JMP 0209EB6A
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] GDI32.dll!ExtTextOutA 763F03F9 5 Bytes JMP 0209EFBA
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] GDI32.dll!TextOutA 763F077D 5 Bytes JMP 0209EA9E
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] GDI32.dll!GetGlyphIndicesA 7640BB6A 5 Bytes JMP 0209F45E
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] USER32.dll!DrawTextExW 771E5894 5 Bytes JMP 0209EED3
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] USER32.dll!DrawTextW 771E5B6A 5 Bytes JMP 0209ED11
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] USER32.dll!SetClipboardData 771F2962 5 Bytes JMP 0209E987
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] USER32.dll!DialogBoxParamW 771F3B9B 5 Bytes JMP 0209DC86
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] USER32.dll!DrawTextA 771FAE29 5 Bytes JMP 0209EC36
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] USER32.dll!DrawTextExA 771FAE60 5 Bytes JMP 0209EDEC
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] WININET.dll!InternetCrackUrlA 777DD07D 5 Bytes JMP 0209F7F1
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] WININET.dll!InternetCrackUrlW 7781893C 5 Bytes JMP 0209F93A
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] WS2_32.dll!closesocket 77C13918 5 Bytes JMP 0209E8E0
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] WS2_32.dll!getaddrinfo 77C14296 5 Bytes JMP 0209D7D7
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] WS2_32.dll!WSASend 77C14406 5 Bytes JMP 0209E5A8
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] WS2_32.dll!GetAddrInfoW 77C14889 5 Bytes JMP 0209D8B7
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] WS2_32.dll!recv 77C16B0E 5 Bytes JMP 0209E4FA
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] WS2_32.dll!send 77C16F01 5 Bytes JMP 0209E455
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] WS2_32.dll!WSARecv 77C17089 5 Bytes JMP 0209E67C
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] WS2_32.dll!WSAGetOverlappedResult 77C17489 5 Bytes JMP 0209E7C0
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] WS2_32.dll!WSAAsyncGetHostByName 77C2726A 5 Bytes JMP 0209DBA7
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5556] WS2_32.dll!gethostbyname 77C27673 5 Bytes JMP 0209D716
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtCreateFile + 6 77B055CE 4 Bytes [28, 00, 3B, 00] {SUB [EAX], AL; CMP EAX, [EAX]}
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtCreateFile + B 77B055D3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtMapViewOfSection + 6 77B05C2E 1 Byte [28]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtMapViewOfSection + 6 77B05C2E 4 Bytes [28, 03, 3B, 00] {SUB [EBX], AL; CMP EAX, [EAX]}
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtMapViewOfSection + B 77B05C33 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtOpenFile + 6 77B05CDE 4 Bytes [68, 00, 3B, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtOpenFile + B 77B05CE3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtOpenProcess + 6 77B05D8E 4 Bytes [A8, 01, 3B, 00] {TEST AL, 0x1; CMP EAX, [EAX]}
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtOpenProcess + B 77B05D93 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtOpenProcessToken + 6 77B05D9E 4 Bytes CALL 76B098A4 C:\windows\system32\SHELL32.dll (DLL commune du shell Windows/Microsoft Corporation)
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtOpenProcessToken + B 77B05DA3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtOpenProcessTokenEx + 6 77B05DAE 4 Bytes [A8, 02, 3B, 00] {TEST AL, 0x2; CMP EAX, [EAX]}
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtOpenProcessTokenEx + B 77B05DB3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtOpenThread + 6 77B05E0E 4 Bytes [68, 01, 3B, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtOpenThread + B 77B05E13 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtOpenThreadToken + 6 77B05E1E 4 Bytes [68, 02, 3B, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtOpenThreadToken + B 77B05E23 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtOpenThreadTokenEx + 6 77B05E2E 4 Bytes CALL 76B09935 C:\windows\system32\SHELL32.dll (DLL commune du shell Windows/Microsoft Corporation)
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtOpenThreadTokenEx + B 77B05E33 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtQueryAttributesFile + 6 77B05F3E 4 Bytes [A8, 00, 3B, 00] {TEST AL, 0x0; CMP EAX, [EAX]}
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtQueryAttributesFile + B 77B05F43 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtQueryFullAttributesFile + 6 77B05FEE 4 Bytes CALL 76B09AF3 C:\windows\system32\SHELL32.dll (DLL commune du shell Windows/Microsoft Corporation)
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtQueryFullAttributesFile + B 77B05FF3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtSetInformationFile + 6 77B0663E 4 Bytes [28, 01, 3B, 00] {SUB [ECX], AL; CMP EAX, [EAX]}
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtSetInformationFile + B 77B06643 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtSetInformationThread + 6 77B0669E 4 Bytes [28, 02, 3B, 00] {SUB [EDX], AL; CMP EAX, [EAX]}
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtSetInformationThread + B 77B066A3 1 Byte [E2]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtUnmapViewOfSection + 6 77B069BE 1 Byte [68]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtUnmapViewOfSection + 6 77B069BE 4 Bytes [68, 03, 3B, 00]
.text C:\Users\Julie\AppData\Local\Google\Chrome\Application\chrome.exe[5800] ntdll.dll!NtUnmapViewOfSection + B 77B069C3 1 Byte [E2]
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Runtime de l’infrastructure de pilotes en mode noyau/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Runtime de l’infrastructure de pilotes en mode noyau/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000004c halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
AttachedDevice \Driver\tdx \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab ZAO)
---- EOF - GMER 1.0.15 ----