Started about fiveish days ago. I search Google (only Google, I've never been redirected from any other site), and upon clicking one of the results - I am sent through a long series of redirects, eventually landing on some BS site. This happens for 3 or 4 search results in a row (regardless of link), then the next roughly 10 clicked results go through a-okay. The ending site is usually different (surprisingly Bing and Google once each).
Yes I am absolutely 100% sure that I'm not just clicking on garbage links.
I believe Google-bombing is involved. Upon entering a legitimate Google query, I was asked to enter a captcha, due to unusual activity.
My primary browser is Chrome, however I also have FireFox and Internet Explorer installed - I get the redirects in all three browsers.
What I've done so far:
MalWareBytes - turned up some results, all of which were removed. Log included
Ad-Aware - turned up a few more results, I removed them all. No log =(
HijackThis - log file included
GMER - log generated and included, no action taken.
TDSSKiller - turned up one false positive. sptd.sys - A driver used by Daemon Tools, no log. http://www.bleepingcomputer.com/startups/sptd.sys-13477.html
ESET Online Scanner - turned up one result, which I believe to be a false positive. The log was just simply the 1 result found, so I'll post it right here: C:\§Programs\Name Gen Pixartist\NameGen_eng.exe Win32/Packed.Autoit.A.Gen application deleted - quarantined
SUPERAntiSpyware - Detected quite a bit. SUPERAntiSpyware recommended I remove all accept 2, and I know the 2 to be legitimate and wouldn't have removed them anyways. (Sysinternal's BSOD Screen Saver and a password digger) Log included.
Logs: (Wall of text mode, ACTIVATE!)
DDS
DDS (Ver_11-03-05.01) - NTFSx86
Run by Jimmy at 13:36:30.31 on Mon 05/09/2011
Internet Explorer: 7.0.6000.16982 BrowserJavaVersion: 1.6.0_21
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1918.1044 [GMT -5:00]
.
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\rundll32.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\RtHDVCpl.exe
C:\Program Files\Razer\Tarantula\razerhid.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Windows\system32\taskeng.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\lxdncoms.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Razer\Tarantula\razertra.exe
C:\Program Files\foobar2000\foobar2000.exe
C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jimmy\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Presario&pf=desktop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Presario&pf=desktop
mURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {ECDEE021-0D17-467F-A1FF-C7A115230949} - No File
uRun: [AdobeBridge]
uRun: [DAEMON Tools] "c:\program files\daemon tools\daemon.exe" -lang 1033
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [<NO NAME>]
mRun: [Tarantula] c:\program files\razer\tarantula\razerhid.exe
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
dRun: [NtWqIVLZEWZU] c:\windows\temp\Qil.exe
dRun: [Q7NZMT7RLB] c:\windows\temp\Qh1.exe
StartupFolder: c:\users\jimmy\appdata\roaming\micros~1\windows\startm~1\programs\startup\52book~1.lnk - c:\users\jimmy\desktop\52 Books.xlsx
StartupFolder: c:\users\jimmy\appdata\roaming\micros~1\windows\startm~1\programs\startup\now!tx~1.lnk - c:\users\jimmy\desktop\NOW!.txt
mPolicies-system: EnableLUA = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - c:\program files\common files\sourcetec\swf catcher\InternetExplorer.htm
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
mASetup: {D969EF8E-D30E-C039-B90F-C3E08A300701} - c:\windows\system32\EXPLORER64.EXE
IFEO: taskmgr.exe - "c:\program files\process explorer\PROCEXP.EXE"
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\jimmy\appdata\roaming\mozilla\firefox\profiles\2mwvlijq.default\
FF - prefs.js: browser.startup.homepage - hxxp://Google.com
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\vistacodecpack\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\vistacodecpack\rm\browser\plugins\nprpjplug.dll
FF - plugin: c:\users\jimmy\appdata\local\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Ant Video Downloader: anttoolbar@ant.com - %profile%\extensions\anttoolbar@ant.com
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
.
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-5-7 64512]
R2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe -service --> c:\windows\system32\lxdncoms.exe -service [?]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2010-8-24 92008]
R3 TarFltr;Razer Tarantula USB Keyboard;c:\windows\system32\drivers\UsbFltr.sys [2007-4-11 45440]
S2 Apache2.2;Apache2.2;"c:\program files\xampp\apache\bin\apache.exe" -k runservice --> c:\program files\xampp\apache\bin\apache.exe [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-4-29 2146496]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\aspi32.sys [2009-8-6 84832]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2011-1-3 14216]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2011-1-3 8456]
S3 OPHE DCS Loader;OPHE DCS Loader;c:\windows\system32\spool\drivers\w32x86\3\OPHELDCS.EXE [2009-12-7 24576]
S3 PsSdk31;PsSdk31;c:\windows\system32\drivers\pssdk31.drv [2008-10-17 30272]
S3 PsSdkLBF;PsSdkLBF;c:\windows\system32\drivers\pssdklbf.drv [2008-10-17 37440]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 VST_DPV;VST_DPV;c:\windows\system32\drivers\VSTDPV3.SYS [2006-11-2 987648]
S3 VSTHWBS2;VSTHWBS2;c:\windows\system32\drivers\VSTBS23.SYS [2006-11-2 251904]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2009-2-13 11520]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 WDDMService;WD SmartWare Drive Manager;c:\program files\western digital\wd smartware\wd drive manager\WDDMService.exe [2009-11-5 110592]
S4 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\western digital\wd smartware\front parlor\WDSmartWareBackgroundService.exe [2009-6-16 20480]
.
=============== File Associations ===============
.
.txt=Notepad++_file
.
=============== Created Last 30 ================
.
2011-05-09 00:36:13 -------- d-----w- c:\users\jimmy\appdata\local\Broad Intelligence
2011-05-08 01:13:04 16432 ----a-w- c:\windows\system32\lsdelete.exe
2011-05-07 20:04:57 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-05-07 20:03:08 64512 ----a-w- c:\windows\system32\drivers\Lbd.sys
2011-05-07 20:03:05 -------- d-----w- c:\program files\Lavasoft
2011-05-02 15:27:12 -------- d-----w- c:\windows\solcache
2011-05-02 15:22:54 2829 ----a-w- c:\windows\DiabUnin.pif
2011-05-02 15:22:54 118784 ----a-w- c:\windows\DiabUnin.exe
2011-05-01 21:04:22 297753112 ----a-w- C:\Registry Backup 2011-05-01.reg
2011-04-30 22:23:19 -------- d-----w- c:\program files\TeamViewer
2011-04-26 03:05:55 -------- d-----w- c:\program files\VideoLAN
2011-04-25 04:39:53 -------- d-----w- c:\program files\SpeedFan
2011-04-20 02:13:03 -------- d-----w- c:\users\jimmy\appdata\roaming\Broad Intelligence
2011-04-20 02:13:00 -------- d-----w- c:\program files\MediaCoder
2011-04-20 01:35:40 73728 ----a-w- c:\windows\system\vdremote.dll
2011-04-20 01:35:40 65536 ----a-w- c:\windows\system\vdsvrlnk.dll
2011-04-13 01:57:07 -------- d-----w- c:\program files\WoW Stuff
.
==================== Find3M ====================
.
2011-03-15 05:01:16 86016 ----a-w- c:\windows\system32\frapsvid.dll
.
============= FINISH: 13:37:10.53 ===============
GMER
GMER 1.0.15.15627 - http://www.gmer.net
Rootkit scan 2011-05-09 19:36:27
Windows 6.0.6000 Harddisk0\DR0 -> \Device\0000005a ST312021 rev.3.CH
Running: gprlzx5b.exe; Driver: C:\Users\Jimmy\AppData\Local\Temp\kfrdypow.sys
---- System - GMER 1.0.15 ----
INT 0x72 ? 8551DBF8
INT 0x82 ? 8551DBF8
INT 0x92 ? 8450DBF8
INT 0xA2 ? 8450EBF8
INT 0xB1 ? 8450CF00
INT 0xB1 ? 8450CF00
INT 0xB2 ? 8450EBF8
---- Kernel code sections - GMER 1.0.15 ----
? System32\Drivers\spfb.sys The system cannot find the path specified. !
.text USBPORT.SYS!DllUnload 88C98FEB 5 Bytes JMP 8551D1D8
.text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x8BCE1340, 0x3DA8C7, 0xE8000020]
.text aqmoemsr.SYS 8B9FF000 22 Bytes [1A, B2, 39, 82, 04, B1, 39, ...]
.text aqmoemsr.SYS 8B9FF017 159 Bytes [00, 99, C7, 7D, 87, A4, C5, ...]
.text aqmoemsr.SYS 8B9FF0B7 22 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text aqmoemsr.SYS 8B9FF0CE 80 Bytes [00, 00, 27, 00, 00, 00, E0, ...]
.text aqmoemsr.SYS 8B9FF11F 194 Bytes [7E, 38, 40, 39, 82, 3B, C4, ...]
.text ...
.text axpilu59.SYS 8B998000 22 Bytes [1A, B2, 39, 82, 04, B1, 39, ...]
.text axpilu59.SYS 8B998017 27 Bytes [00, 99, C7, 7D, 87, A4, C5, ...]
.text axpilu59.SYS 8B998033 39 Bytes [82, A8, 55, 03, 82, 40, 59, ...]
.text axpilu59.SYS 8B99805B 113 Bytes [82, 1A, E2, 08, 82, BA, 02, ...]
.text axpilu59.SYS 8B9980CE 73 Bytes [00, 00, 00, 00, 01, C2, 03, ...]
.text ...
.text C:\Windows\system32\DRIVERS\atksgt.sys section is writeable [0x9C068300, 0x3B6D8, 0xE8000020]
.text C:\Windows\system32\DRIVERS\lirsgt.sys section is writeable [0x8B46A300, 0x1BEE, 0xE8000020]
? C:\Users\Jimmy\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !
? C:\Windows\system32\Drivers\PROCEXP110.SYS The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtCreateFile + 6 771CF41A 4 Bytes [28, 00, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtCreateFile + B 771CF41F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtMapViewOfSection + 6 771CFB6A 1 Byte [28]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtMapViewOfSection + 6 771CFB6A 4 Bytes [28, 03, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtMapViewOfSection + B 771CFB6F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenFile + 6 771CFBFA 4 Bytes [68, 00, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenFile + B 771CFBFF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenProcess + 6 771CFC7A 4 Bytes [A8, 01, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenProcess + B 771CFC7F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenProcessToken + B 771CFC8F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenProcessTokenEx + 6 771CFC9A 4 Bytes [A8, 02, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenProcessTokenEx + B 771CFC9F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenThread + 6 771CFCEA 4 Bytes [68, 01, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenThread + B 771CFCEF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenThreadToken + 6 771CFCFA 4 Bytes [68, 02, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenThreadToken + B 771CFCFF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenThreadTokenEx + B 771CFD0F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtQueryAttributesFile + 6 771CFD9A 4 Bytes [A8, 00, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtQueryAttributesFile + B 771CFD9F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtQueryFullAttributesFile + B 771CFE4F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtSetInformationFile + 6 771D036A 4 Bytes [28, 01, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtSetInformationFile + B 771D036F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtSetInformationThread + 6 771D03BA 4 Bytes [28, 02, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtSetInformationThread + B 771D03BF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtUnmapViewOfSection + 6 771D065A 1 Byte [68]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtUnmapViewOfSection + 6 771D065A 4 Bytes [68, 03, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtUnmapViewOfSection + B 771D065F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtCreateFile + 6 771CF41A 4 Bytes [28, 00, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtCreateFile + B 771CF41F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtMapViewOfSection + 6 771CFB6A 1 Byte [28]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtMapViewOfSection + 6 771CFB6A 4 Bytes [28, 03, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtMapViewOfSection + B 771CFB6F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtOpenFile + 6 771CFBFA 4 Bytes [68, 00, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtOpenFile + B 771CFBFF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtOpenProcess + 6 771CFC7A 4 Bytes [A8, 01, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtOpenProcess + B 771CFC7F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtOpenProcessToken + B 771CFC8F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtOpenProcessTokenEx + 6 771CFC9A 4 Bytes [A8, 02, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtOpenProcessTokenEx + B 771CFC9F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtOpenThread + 6 771CFCEA 4 Bytes [68, 01, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtOpenThread + B 771CFCEF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtOpenThreadToken + 6 771CFCFA 4 Bytes [68, 02, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtOpenThreadToken + B 771CFCFF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtOpenThreadTokenEx + B 771CFD0F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtQueryAttributesFile + 6 771CFD9A 4 Bytes [A8, 00, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtQueryAttributesFile + B 771CFD9F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtQueryFullAttributesFile + B 771CFE4F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtSetInformationFile + 6 771D036A 4 Bytes [28, 01, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtSetInformationFile + B 771D036F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtSetInformationThread + 6 771D03BA 4 Bytes [28, 02, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtSetInformationThread + B 771D03BF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtUnmapViewOfSection + 6 771D065A 1 Byte [68]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtUnmapViewOfSection + 6 771D065A 4 Bytes [68, 03, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] ntdll.dll!NtUnmapViewOfSection + B 771D065F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] USER32.dll!DrawTextExW 75AEBEBE 5 Bytes JMP 00DED349
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] USER32.dll!DrawTextW 75AEC128 5 Bytes JMP 00DED187
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] USER32.dll!DialogBoxParamW 75B0129F 5 Bytes JMP 00DEC23C
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] USER32.dll!DrawTextA 75B056FD 5 Bytes JMP 00DED0AC
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] USER32.dll!DrawTextExA 75B05734 5 Bytes JMP 00DED262
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] USER32.dll!SetClipboardData 75B2116B 5 Bytes JMP 00DECDFD
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] GDI32.dll!ExtTextOutW 75E189EC 5 Bytes JMP 00DED514
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] GDI32.dll!GetGlyphIndicesW 75E1C821 5 Bytes JMP 00DED9A1
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] GDI32.dll!ExtTextOutA 75E210E8 5 Bytes JMP 00DED430
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] GDI32.dll!TextOutW 75E21550 5 Bytes JMP 00DECFE0
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] GDI32.dll!TextOutA 75E216E5 5 Bytes JMP 00DECF14
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] GDI32.dll!GetGlyphIndicesA 75E3AF3A 5 Bytes JMP 00DED8D4
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] WS2_32.dll!closesocket 75C23847 5 Bytes JMP 00DECD56
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] WS2_32.dll!send 75C23A8A 5 Bytes JMP 00DEC8CB
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] WS2_32.dll!GetAddrInfoW 75C24672 5 Bytes JMP 00DEBE67
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] WS2_32.dll!recv 75C24ABD 5 Bytes JMP 00DEC970
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] WS2_32.dll!getaddrinfo 75C24C58 5 Bytes JMP 00DEBD87
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] WS2_32.dll!WSASend 75C24EE9 5 Bytes JMP 00DECA1E
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] WS2_32.dll!WSARecv 75C272B5 5 Bytes JMP 00DECAF2
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] WS2_32.dll!WSAGetOverlappedResult 75C2A4F5 5 Bytes JMP 00DECC36
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] WS2_32.dll!gethostbyname 75C2DB26 5 Bytes JMP 00DEBCC6
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] WS2_32.dll!WSAAsyncGetHostByName 75C36131 5 Bytes JMP 00DEC15D
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] WININET.dll!InternetCrackUrlW 75C53F0F 5 Bytes JMP 00DEDDB0
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2236] WININET.dll!InternetCrackUrlA 75C80114 5 Bytes JMP 00DEDC67
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtCreateFile + 6 771CF41A 4 Bytes [28, 00, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtCreateFile + B 771CF41F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtMapViewOfSection + 6 771CFB6A 1 Byte [28]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtMapViewOfSection + 6 771CFB6A 4 Bytes [28, 03, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtMapViewOfSection + B 771CFB6F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtOpenFile + 6 771CFBFA 4 Bytes [68, 00, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtOpenFile + B 771CFBFF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtOpenProcess + 6 771CFC7A 4 Bytes [A8, 01, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtOpenProcess + B 771CFC7F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtOpenProcessToken + B 771CFC8F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtOpenProcessTokenEx + 6 771CFC9A 4 Bytes [A8, 02, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtOpenProcessTokenEx + B 771CFC9F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtOpenThread + 6 771CFCEA 4 Bytes [68, 01, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtOpenThread + B 771CFCEF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtOpenThreadToken + 6 771CFCFA 4 Bytes [68, 02, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtOpenThreadToken + B 771CFCFF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtOpenThreadTokenEx + B 771CFD0F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtQueryAttributesFile + 6 771CFD9A 4 Bytes [A8, 00, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtQueryAttributesFile + B 771CFD9F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtQueryFullAttributesFile + B 771CFE4F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtSetInformationFile + 6 771D036A 4 Bytes [28, 01, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtSetInformationFile + B 771D036F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtSetInformationThread + 6 771D03BA 4 Bytes [28, 02, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtSetInformationThread + B 771D03BF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtUnmapViewOfSection + 6 771D065A 1 Byte [68]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtUnmapViewOfSection + 6 771D065A 4 Bytes [68, 03, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2260] ntdll.dll!NtUnmapViewOfSection + B 771D065F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] USER32.dll!DrawTextExW 75AEBEBE 5 Bytes JMP 019AD349
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] USER32.dll!DrawTextW 75AEC128 5 Bytes JMP 019AD187
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] USER32.dll!DialogBoxParamW 75B0129F 5 Bytes JMP 019AC23C
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] USER32.dll!DrawTextA 75B056FD 5 Bytes JMP 019AD0AC
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] USER32.dll!DrawTextExA 75B05734 5 Bytes JMP 019AD262
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] USER32.dll!SetClipboardData 75B2116B 5 Bytes JMP 019ACDFD
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] GDI32.dll!ExtTextOutW 75E189EC 5 Bytes JMP 019AD514
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] GDI32.dll!GetGlyphIndicesW 75E1C821 5 Bytes JMP 019AD9A1
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] GDI32.dll!ExtTextOutA 75E210E8 5 Bytes JMP 019AD430
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] GDI32.dll!TextOutW 75E21550 5 Bytes JMP 019ACFE0
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] GDI32.dll!TextOutA 75E216E5 5 Bytes JMP 019ACF14
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] GDI32.dll!GetGlyphIndicesA 75E3AF3A 5 Bytes JMP 019AD8D4
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] WS2_32.dll!closesocket 75C23847 5 Bytes JMP 019ACD56
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] WS2_32.dll!send 75C23A8A 5 Bytes JMP 019AC8CB
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] WS2_32.dll!GetAddrInfoW 75C24672 5 Bytes JMP 019ABE67
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] WS2_32.dll!recv 75C24ABD 5 Bytes JMP 019AC970
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] WS2_32.dll!getaddrinfo 75C24C58 5 Bytes JMP 019ABD87
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] WS2_32.dll!WSASend 75C24EE9 5 Bytes JMP 019ACA1E
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] WS2_32.dll!WSARecv 75C272B5 5 Bytes JMP 019ACAF2
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] WS2_32.dll!WSAGetOverlappedResult 75C2A4F5 5 Bytes JMP 019ACC36
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] WS2_32.dll!gethostbyname 75C2DB26 5 Bytes JMP 019ABCC6
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] WS2_32.dll!WSAAsyncGetHostByName 75C36131 5 Bytes JMP 019AC15D
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] WININET.dll!InternetCrackUrlW 75C53F0F 5 Bytes JMP 019ADDB0
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2524] WININET.dll!InternetCrackUrlA 75C80114 5 Bytes JMP 019ADC67
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtCreateFile + 6 771CF41A 4 Bytes [28, 00, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtCreateFile + B 771CF41F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtMapViewOfSection + 6 771CFB6A 1 Byte [28]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtMapViewOfSection + 6 771CFB6A 4 Bytes [28, 03, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtMapViewOfSection + B 771CFB6F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtOpenFile + 6 771CFBFA 4 Bytes [68, 00, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtOpenFile + B 771CFBFF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtOpenProcess + 6 771CFC7A 4 Bytes [A8, 01, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtOpenProcess + B 771CFC7F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtOpenProcessToken + B 771CFC8F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtOpenProcessTokenEx + 6 771CFC9A 4 Bytes [A8, 02, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtOpenProcessTokenEx + B 771CFC9F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtOpenThread + 6 771CFCEA 4 Bytes [68, 01, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtOpenThread + B 771CFCEF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtOpenThreadToken + 6 771CFCFA 4 Bytes [68, 02, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtOpenThreadToken + B 771CFCFF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtOpenThreadTokenEx + B 771CFD0F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtQueryAttributesFile + 6 771CFD9A 4 Bytes [A8, 00, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtQueryAttributesFile + B 771CFD9F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtQueryFullAttributesFile + B 771CFE4F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtSetInformationFile + 6 771D036A 4 Bytes [28, 01, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtSetInformationFile + B 771D036F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtSetInformationThread + 6 771D03BA 4 Bytes [28, 02, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtSetInformationThread + B 771D03BF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtUnmapViewOfSection + 6 771D065A 1 Byte [68]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtUnmapViewOfSection + 6 771D065A 4 Bytes [68, 03, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[2852] ntdll.dll!NtUnmapViewOfSection + B 771D065F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtCreateFile + 6 771CF41A 4 Bytes [28, 00, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtCreateFile + B 771CF41F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtMapViewOfSection + 6 771CFB6A 1 Byte [28]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtMapViewOfSection + 6 771CFB6A 4 Bytes [28, 03, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtMapViewOfSection + B 771CFB6F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtOpenFile + 6 771CFBFA 4 Bytes [68, 00, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtOpenFile + B 771CFBFF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtOpenProcess + 6 771CFC7A 4 Bytes [A8, 01, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtOpenProcess + B 771CFC7F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtOpenProcessToken + B 771CFC8F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtOpenProcessTokenEx + 6 771CFC9A 4 Bytes [A8, 02, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtOpenProcessTokenEx + B 771CFC9F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtOpenThread + 6 771CFCEA 4 Bytes [68, 01, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtOpenThread + B 771CFCEF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtOpenThreadToken + 6 771CFCFA 4 Bytes [68, 02, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtOpenThreadToken + B 771CFCFF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtOpenThreadTokenEx + B 771CFD0F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtQueryAttributesFile + 6 771CFD9A 4 Bytes [A8, 00, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtQueryAttributesFile + B 771CFD9F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtQueryFullAttributesFile + B 771CFE4F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtSetInformationFile + 6 771D036A 4 Bytes [28, 01, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtSetInformationFile + B 771D036F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtSetInformationThread + 6 771D03BA 4 Bytes [28, 02, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtSetInformationThread + B 771D03BF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtUnmapViewOfSection + 6 771D065A 1 Byte [68]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtUnmapViewOfSection + 6 771D065A 4 Bytes [68, 03, 16, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3036] ntdll.dll!NtUnmapViewOfSection + B 771D065F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtCreateFile + 6 771CF41A 4 Bytes [28, 00, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtCreateFile + B 771CF41F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtMapViewOfSection + 6 771CFB6A 1 Byte [28]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtMapViewOfSection + 6 771CFB6A 4 Bytes [28, 03, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtMapViewOfSection + B 771CFB6F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtOpenFile + 6 771CFBFA 4 Bytes [68, 00, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtOpenFile + B 771CFBFF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtOpenProcess + 6 771CFC7A 4 Bytes [A8, 01, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtOpenProcess + B 771CFC7F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtOpenProcessToken + B 771CFC8F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtOpenProcessTokenEx + 6 771CFC9A 4 Bytes [A8, 02, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtOpenProcessTokenEx + B 771CFC9F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtOpenThread + 6 771CFCEA 4 Bytes [68, 01, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtOpenThread + B 771CFCEF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtOpenThreadToken + 6 771CFCFA 4 Bytes [68, 02, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtOpenThreadToken + B 771CFCFF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtOpenThreadTokenEx + B 771CFD0F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtQueryAttributesFile + 6 771CFD9A 4 Bytes [A8, 00, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtQueryAttributesFile + B 771CFD9F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtQueryFullAttributesFile + B 771CFE4F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtSetInformationFile + 6 771D036A 4 Bytes [28, 01, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtSetInformationFile + B 771D036F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtSetInformationThread + 6 771D03BA 4 Bytes [28, 02, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtSetInformationThread + B 771D03BF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtUnmapViewOfSection + 6 771D065A 1 Byte [68]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtUnmapViewOfSection + 6 771D065A 4 Bytes [68, 03, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3288] ntdll.dll!NtUnmapViewOfSection + B 771D065F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtCreateFile + 6 771CF41A 4 Bytes [28, 00, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtCreateFile + B 771CF41F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtMapViewOfSection + 6 771CFB6A 1 Byte [28]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtMapViewOfSection + 6 771CFB6A 4 Bytes [28, 03, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtMapViewOfSection + B 771CFB6F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenFile + 6 771CFBFA 4 Bytes [68, 00, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenFile + B 771CFBFF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenProcess + 6 771CFC7A 4 Bytes [A8, 01, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenProcess + B 771CFC7F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenProcessToken + B 771CFC8F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenProcessTokenEx + 6 771CFC9A 4 Bytes [A8, 02, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenProcessTokenEx + B 771CFC9F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenThread + 6 771CFCEA 4 Bytes [68, 01, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenThread + B 771CFCEF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenThreadToken + 6 771CFCFA 4 Bytes [68, 02, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenThreadToken + B 771CFCFF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtOpenThreadTokenEx + B 771CFD0F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtQueryAttributesFile + 6 771CFD9A 4 Bytes [A8, 00, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtQueryAttributesFile + B 771CFD9F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtQueryFullAttributesFile + B 771CFE4F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtSetInformationFile + 6 771D036A 4 Bytes [28, 01, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtSetInformationFile + B 771D036F 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtSetInformationThread + 6 771D03BA 4 Bytes [28, 02, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtSetInformationThread + B 771D03BF 1 Byte [E2]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtUnmapViewOfSection + 6 771D065A 1 Byte [68]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtUnmapViewOfSection + 6 771D065A 4 Bytes [68, 03, 06, 00]
.text C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe[3348] ntdll.dll!NtUnmapViewOfSection + B 771D065F 1 Byte [E2]
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 845141F8
Device \Driver\volmgr \Device\VolMgrControl 845101F8
Device \Driver\usbohci \Device\USBPDO-0 855231F8
Device \Driver\usbehci \Device\USBPDO-1 855371F8
Device \Driver\USBSTOR \Device\00000063 866C01F8
Device \Driver\volmgr \Device\HarddiskVolume1 845101F8
Device \Driver\USBSTOR \Device\00000064 866C01F8
Device \Driver\USBSTOR \Device\00000065 866C01F8
Device \Driver\cdrom \Device\CdRom0 855271F8
Device \Driver\volmgr \Device\HarddiskVolume2 845101F8
Device \Driver\atapi \Device\Ide\IdePort0 845121F8
Device \Driver\atapi \Device\Ide\IdePort1 845121F8
Device \Driver\USBSTOR \Device\00000066 866C01F8
Device \Driver\volmgr \Device\HarddiskVolume3 845101F8
Device \Driver\cdrom \Device\CdRom1 855271F8
Device \Driver\USBSTOR \Device\00000067 866C01F8
Device \Driver\volmgr \Device\HarddiskVolume4 845101F8
Device \Driver\volmgr \Device\HarddiskVolume5 845101F8
Device \Driver\volmgr \Device\HarddiskVolume6 845101F8
Device \Driver\netbt \Device\NetBt_Wins_Export 8669E1F8
Device \Driver\Smb \Device\NetbiosSmb 8660C1F8
Device \Driver\sptd \Device\885684625 spfb.sys
Device \Driver\nvstor32 \Device\0000005a 845131F8
Device \Driver\nvstor32 \Device\0000005b 845131F8
Device \Driver\PCI_PNP8619 \Device\0000004e spfb.sys
Device \Driver\nvstor32 \Device\RaidPort0 845131F8
Device \Driver\PCI_PNP8619 \Device\0000004f spfb.sys
Device \Driver\iScsiPrt \Device\RaidPort1 855EB1F8
Device \Driver\usbohci \Device\USBFDO-0 855231F8
Device \Driver\usbehci \Device\USBFDO-1 855371F8
Device \Driver\sptd \Device\885840626 spfb.sys
Device \Driver\netbt \Device\NetBT_Tcpip_{79470AA1-A7E0-47DD-A805-B910433C643B} 8669E1F8
Device \Driver\aqmoemsr \Device\Scsi\aqmoemsr1 855E11F8
Device \Driver\axpilu59 \Device\Scsi\axpilu591 855EA1F8
Device \Driver\axpilu59 \Device\Scsi\axpilu591Port5Path0Target0Lun0 855EA1F8
Device \FileSystem\cdfs \Cdfs 86EE4498
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x1C 0x9C 0x7D 0x4F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x55 0x59 0x55 0xA0 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xF1 0xAC 0xC4 0x78 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x3B 0x46 0x51 0x83 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xC1 0x29 0xFA 0xE6 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0xDB 0xBB 0x19 0xF4 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0x0C 0xF4 0x96 0x47 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x1C 0x9C 0x7D 0x4F ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x55 0x59 0x55 0xA0 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xF1 0xAC 0xC4 0x78 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x3B 0x46 0x51 0x83 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xC1 0x29 0xFA 0xE6 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42@khjeh 0xDB 0xBB 0x19 0xF4 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43@khjeh 0x0C 0xF4 0x96 0x47 ...
---- EOF - GMER 1.0.15 ----
MalWareBytes
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5542
Windows 6.0.6000
Internet Explorer 7.0.6000.16982
1/17/2011 9:54:48 PM
mbam-log-2011-01-17 (21-54-48).txt
Scan type: Full scan (C:\|)
Objects scanned: 282387
Time elapsed: 2 hour(s), 28 minute(s), 49 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\JP595IR86O (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MFJJEC0A1L (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\NtWqIVLZEWZU (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\JP595IR86O (Trojan.CodecPack) -> Value: JP595IR86O -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Users\Jimmy\AppData\Local\Temp\Qg1.exe (Trojan.CodecPack) -> Quarantined and deleted successfully.
c:\Users\Jimmy\AppData\Local\Google\Chrome\user data\Default\Cache\f_0010cc (Trojan.CodecPack) -> Quarantined and deleted successfully.
c:\Users\Jimmy\AppData\Local\Google\Chrome\user data\Default\Cache\f_0010cd (Trojan.CodecPack) -> Quarantined and deleted successfully.
HijackThis
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:02:25 PM, on 5/8/2011
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16982)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Razer\Tarantula\razerhid.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Razer\Tarantula\razertra.exe
C:\Program Files\foobar2000\foobar2000.exe
C:\Program Files\Adobe\Adobe Photoshop CS5\Photoshop.exe
C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
C:\PROGRAM FILES\PROCESS EXPLORER\PROCEXP.EXE
C:\Program Files\Notepad++\notepad++.exe
C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jimmy\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jimmy\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Presario&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Presario&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Tarantula] C:\Program Files\Razer\Tarantula\razerhid.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\RunOnce: [DeleteFile0] "C:\Program Files\FileMenu Tools\FileMenuTools.exe" /d "C:\Windows\System32\psapi.dll"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [K8CE6CA1JO] C:\Windows\TEMP\Qhl.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [K8CE6CA1JO] C:\Windows\TEMP\Qhl.exe (User 'Default user')
O4 - Startup: 52 Books.xlsx - Shortcut.lnk = ?
O4 - Startup: NOW!.txt - Shortcut.lnk = C:\Users\Jimmy\Desktop\NOW!.txt
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm (file missing)
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm (file missing)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Apache2.2 - Unknown owner - C:\Program Files\XAMPP\apache\bin\apache.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Unknown owner - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft Limited - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: lxdn_device - - C:\Windows\system32\lxdncoms.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: OPHE DCS Loader - Oki Data Corporation - C:\Windows\system32\spool\DRIVERS\W32X86\3\OPHELDCS.EXE
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 6410 bytes
SUPERAntiSpyware
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 05/09/2011 at 11:59 PM
Application Version : 4.52.1000
Core Rules Database Version : 7022
Trace Rules Database Version: 4834
Scan type : Complete Scan
Total Scan Time : 00:53:18
Memory items scanned : 540
Memory threats detected : 0
Registry items scanned : 9717
Registry threats detected : 9
File items scanned : 37116
File threats detected : 109
Adware.Tracking Cookie
C:\Users\Jimmy\AppData\Roaming\Microsoft\Windows\Cookies\jimmy@doubleclick[1].txt
C:\Users\Jimmy\AppData\Roaming\Microsoft\Windows\Cookies\jimmy@statcounter[2].txt
C:\Users\Jimmy\AppData\Roaming\Microsoft\Windows\Cookies\jimmy@fastclick[1].txt
C:\Users\Jimmy\AppData\Roaming\Microsoft\Windows\Cookies\jimmy@apmebf[2].txt
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\administrator@media6degrees[1].txt
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\administrator@at.atwola[1].txt
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\administrator@burstnet[2].txt
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\administrator@collective-media[2].txt
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\administrator@clicktorrent[1].txt
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\administrator@chitika[1].txt
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\administrator@www.burstnet[1].txt
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\administrator@ad1.clickhype[1].txt
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\administrator@content.yieldmanager[1].txt
C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\administrator@ads.gmodules[2].txt
.tracking.parktastic.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.icityfind.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.specificclick.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.liveperson.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.atdmt.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.find-quick-results.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.imrworldwide.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.imrworldwide.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.interclick.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.interclick.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.liveperson.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.apmebf.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediaplex.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.www.burstnet.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.interclick.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.fastclick.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
server.iad.liveperson.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.liveperson.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
adserv.brandaffinity.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
adserv.brandaffinity.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
adserv.brandaffinity.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediacoderhq.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediacoderhq.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediacoderhq.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
search.clicksthe.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
search.amazeclick.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
bridge2.admarketplace.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.admarketplace.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.mediaplex.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.tribalfusion.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adbrite.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.invitemedia.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.kontera.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.2o7.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.doubleclick.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collective-media.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.findstuffforme.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.collegepro.112.2o7.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.trafficmp.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.trafficmp.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.trafficmp.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.media6degrees.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertising.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.solvemedia.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.solvemedia.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.insightexpressai.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.adxpose.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.content.yieldmanager.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
ad.yieldmanager.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.eset.122.2o7.net [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.statcounter.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.statcounter.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
.advertise.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.plomedia.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
www.findstuff.com [ C:\Users\Jimmy\AppData\Local\Google\Chrome\User Data\Default\Cookies ]
msnbcmedia.msn.com [ C:\Users\Jimmy\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\BKYTXCB4 ]
www.naiadsystems.com [ C:\Users\Jimmy\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\BKYTXCB4 ]
www.organogoldmedia.com [ C:\Users\Jimmy\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\BKYTXCB4 ]
Browser Hijacker.Deskbar
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid32
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib#Version
Malware.Trace
HKU\.DEFAULT\Software\NtWqIVLZEWZU
HKU\S-1-5-18\Software\NtWqIVLZEWZU
Security.HiJack[ImageFileExecutionOptions]
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TASKMGR.EXE
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TASKMGR.EXE#Debugger
NotHarmful.Sysinternals Bluescreen Screen Saver
C:\§PROGRAMS\BLUE SCREEN SYSINTERNALSBLUESCREEN.SCR
Trojan.Agent/Gen-MailPassView
C:\§PROGRAMS\PASSWORD PROGRAMS\MAILPV.EXE
If you're still reading this, you deserve a hug
Attached File(s)
-
Attach.txt (7.4K)
Number of downloads: 0

Help
This topic is locked

Back to top













