ellrolschell | 05.01.2013 19:07 | So nun die zwei Dateien; übrigens ist die Warnmeldung von Norman mit Ausnahme des einen Mals nach dem ESET Scan bis jetzt nicht wieder aufgetaucht.
Roland
SystemLook: Code:
SystemLook 30.07.11 by jpshortstuff
Log created at 13:40 on 05/01/2013 by Roland
Administrator - Elevation successful
========== filefind ==========
Searching for "ntqcfvte"
No files found.
Searching for "pngudv6q"
No files found.
Searching for "GMSIPCI"
No files found.
========== regfind ==========
Searching for "ntqcfvte"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NTQCFVTE]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NTQCFVTE\0000]
"Service"="ntqcfvte"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NTQCFVTE\0000]
"DeviceDesc"="ntqcfvte"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_NTQCFVTE\0000\Control]
"ActiveService"="ntqcfvte"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ntqcfvte]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ntqcfvte]
"ImagePath"="\??\C:\WINDOWS\system32\ntqcfvte.sys"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ntqcfvte\Enum]
"0"="Root\LEGACY_NTQCFVTE\0000"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_NTQCFVTE]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_NTQCFVTE\0000]
"Service"="ntqcfvte"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_NTQCFVTE\0000]
"DeviceDesc"="ntqcfvte"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ntqcfvte]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ntqcfvte]
"ImagePath"="\??\C:\WINDOWS\system32\ntqcfvte.sys"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NTQCFVTE]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NTQCFVTE\0000]
"Service"="ntqcfvte"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NTQCFVTE\0000]
"DeviceDesc"="ntqcfvte"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NTQCFVTE\0000\Control]
"ActiveService"="ntqcfvte"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ntqcfvte]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ntqcfvte]
"ImagePath"="\??\C:\WINDOWS\system32\ntqcfvte.sys"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ntqcfvte\Enum]
"0"="Root\LEGACY_NTQCFVTE\0000"
Searching for "pngudv6q"
No data found.
Searching for "GMSIPCI"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_GMSIPCI]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_GMSIPCI\0000]
"Service"="GMSIPCI"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_GMSIPCI\0000]
"DeviceDesc"="GMSIPCI"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\GMSIPCI]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\GMSIPCI]
"ImagePath"="\??\I:\INSTALL\GMSIPCI.SYS"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\GMSIPCI]
"DisplayName"="GMSIPCI"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\GMSIPCI\Enum]
"0"="Root\LEGACY_GMSIPCI\0000"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_GMSIPCI]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_GMSIPCI\0000]
"Service"="GMSIPCI"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_GMSIPCI\0000]
"DeviceDesc"="GMSIPCI"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\GMSIPCI]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\GMSIPCI]
"ImagePath"="\??\I:\INSTALL\GMSIPCI.SYS"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\GMSIPCI]
"DisplayName"="GMSIPCI"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_GMSIPCI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_GMSIPCI\0000]
"Service"="GMSIPCI"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_GMSIPCI\0000]
"DeviceDesc"="GMSIPCI"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GMSIPCI]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GMSIPCI]
"ImagePath"="\??\I:\INSTALL\GMSIPCI.SYS"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GMSIPCI]
"DisplayName"="GMSIPCI"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GMSIPCI\Enum]
"0"="Root\LEGACY_GMSIPCI\0000"
========== service ==========
ntqcfvte - Unable to open Service Handle.
GMSIPCI
GMSIPCI
(No Description)
Current Status: Stopped
Startup Type: Demand
Error Control: Critical
Binary: \??\I:\INSTALL\GMSIPCI.SYS
Group: (none)
SafeBoot:
Dependencies:
(none)
Dependant Services:
(none)
========== SafeBoot Info ==========
Alternate Shell: cmd.exe
--- Minimal ---
AppMgmt
Base
Boot Bus Extender
Boot file system
CryptSvc
DcomLaunch
dmadmin
dmboot.sys
dmio.sys
dmload.sys
dmserver
EventLog
File system
Filter
HelpSvc
Netlogon
PCI Configuration
PlugPlay
PNP Filter
Primary disk
RpcSs
SCSI Class
sermouse.sys
sr.sys
SRService
System Bus Extender
vds
vga.sys
vgasave.sys
Wdf01000.sys
WinMgmt
WudfSvc
(Universal Serial Bus controllers)
(CD-ROM Drive)
(DiskDrive)
(Standard floppy disk controller)
(Hdc)
(Keyboard)
(Mouse)
(PCMCIA Adapters)
(SCSIAdapter)
(System)
(Floppy disk drive)
(Volume shadow copy)
(Volume)
(Human Interface Devices)
--- Network ---
AFD
AppMgmt
Base
Boot Bus Extender
Boot file system
Browser
CryptSvc
DcomLaunch
Dhcp
dmadmin
dmboot.sys
dmio.sys
dmload.sys
dmserver
DnsCache
EventLog
File system
Filter
HelpSvc
ip6fw.sys
ipnat.sys
LanmanServer
LanmanWorkstation
LmHosts
Messenger
NDIS
NDIS Wrapper
Ndisuio
NetBIOS
NetBIOSGroup
NetBT
NetDDEGroup
Netlogon
NetMan
Network
NetworkProvider
NtLmSsp
PCI Configuration
PlugPlay
PNP Filter
PNP_TDI
Primary disk
rdpcdd.sys
rdpdd.sys
rdpwd.sys
rdsessmgr
RpcSs
SCSI Class
sermouse.sys
SharedAccess
sr.sys
SRService
Streams Drivers
System Bus Extender
Tcpip
TDI
tdpipe.sys
tdtcp.sys
termservice
vga.sys
vgasave.sys
Wdf01000.sys
WinMgmt
WudfSvc
WZCSVC
(Universal Serial Bus controllers)
(CD-ROM Drive)
(DiskDrive)
(Standard floppy disk controller)
(Hdc)
(Keyboard)
(Mouse)
(Net)
(NetClient)
(NetService)
(NetTrans)
(PCMCIA Adapters)
(SCSIAdapter)
(System)
(Floppy disk drive)
(Volume)
(Human Interface Devices)
-= EOF =- Gmer.txt: Code:
GMER 2.0.18327 - hxxp://www.gmer.net
Rootkit scan 2013-01-05 18:53:09
Windows 5.1.2600 Service Pack 3 \Device\Harddisk0\DR0 -> \Device\00000074 Hitachi_HDT725032VLA380 rev.V54OA52A 298,09GB
Running: 3p8re4xy.exe; Driver: C:\DOKUME~1\Roland\LOKALE~1\Temp\pxtdrpob.sys
---- System - GMER 2.0 ----
SSDT \??\C:\Programme\Norman\Ngs\Bin\nprosec.sys (Process Security Driver/Norman ASA) ZwCreateFile [0xAE6E53C4]
SSDT \??\C:\Programme\Norman\Ngs\Bin\nprosec.sys (Process Security Driver/Norman ASA) ZwCreateProcess [0xAE6E3F7C]
SSDT \??\C:\Programme\Norman\Ngs\Bin\nprosec.sys (Process Security Driver/Norman ASA) ZwCreateProcessEx [0xAE6E3FAC]
SSDT \??\C:\Programme\Norman\Ngs\Bin\nprosec.sys (Process Security Driver/Norman ASA) ZwCreateThread [0xAE6E3FDC]
SSDT \??\C:\Programme\Norman\Ngs\Bin\nprosec.sys (Process Security Driver/Norman ASA) ZwSetSystemInformation [0xAE6E551C]
SSDT \??\C:\Programme\Norman\Ngs\Bin\nprosec.sys (Process Security Driver/Norman ASA) ZwTerminateProcess [0xAE6E4D0A]
SSDT \??\C:\Programme\Norman\Ngs\Bin\nprosec.sys (Process Security Driver/Norman ASA) ZwWriteVirtualMemory [0xAE6E4F60]
Code \??\C:\WINDOWS\system32\ntqcfvte.sys (New Technology Quality Browser Support/New Technology Quality, Ltd.) ZwResumeThread [0xAE48376E]
---- Kernel code sections - GMER 2.0 ----
? Combo-Fix.sys Das System kann die angegebene Datei nicht finden. !
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF5F3D000, 0x2ACED8, 0xE8000020]
.text C:\WINDOWS\system32\drivers\ACEDRV07.sys section is writeable [0xAB5B1000, 0x328BA, 0xE8000020]
.pklstb C:\WINDOWS\system32\drivers\ACEDRV07.sys entry point in ".pklstb" section [0xAB5F5000]
.relo2 C:\WINDOWS\system32\drivers\ACEDRV07.sys unknown last section [0xAB611000, 0x8E, 0x42000040]
.vmp2 C:\WINDOWS\system32\drivers\acedrv11.sys entry point in ".vmp2" section [0xAAFF369D]
.text C:\WINDOWS\system32\DRIVERS\atksgt.sys section is writeable [0xAAE75300, 0x3B6D8, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\lirsgt.sys section is writeable [0xF77A7300, 0x1BEE, 0xE8000020]
? C:\ComboFix\catchme.sys Das System kann den angegebenen Pfad nicht finden. !
? C:\WINDOWS\system32\Drivers\PROCEXP113.SYS Das System kann die angegebene Datei nicht finden. !
---- User code sections - GMER 2.0 ----
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtCreateFile + 6 7C91D0B4 4 Bytes [28, 90, 57, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtCreateFile + B 7C91D0B9 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtMapViewOfSection + 6 7C91D524 4 Bytes [28, 93, 57, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtMapViewOfSection + B 7C91D529 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenFile + 6 7C91D5A4 4 Bytes [68, 90, 57, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenFile + B 7C91D5A9 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenProcess + 6 7C91D604 4 Bytes [A8, 91, 57, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenProcess + B 7C91D609 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenProcessToken + 6 7C91D614 4 Bytes CALL 7B922DAA
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenProcessToken + B 7C91D619 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenProcessTokenEx + 6 7C91D624 4 Bytes [A8, 92, 57, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenProcessTokenEx + B 7C91D629 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenThread + 6 7C91D664 4 Bytes [68, 91, 57, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenThread + B 7C91D669 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenThreadToken + 6 7C91D674 4 Bytes [68, 92, 57, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenThreadToken + B 7C91D679 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenThreadTokenEx + 6 7C91D684 4 Bytes CALL 7B922E1B
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtOpenThreadTokenEx + B 7C91D689 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtQueryAttributesFile + 6 7C91D714 4 Bytes [A8, 90, 57, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtQueryAttributesFile + B 7C91D719 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtQueryFullAttributesFile + 6 7C91D7B4 4 Bytes CALL 7B922F49
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtQueryFullAttributesFile + B 7C91D7B9 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtSetInformationFile + 6 7C91DC64 4 Bytes [28, 91, 57, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtSetInformationFile + B 7C91DC69 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtSetInformationThread + 6 7C91DCB4 4 Bytes [28, 92, 57, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtSetInformationThread + B 7C91DCB9 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 4 Bytes [68, 93, 57, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[1836] ntdll.dll!NtUnmapViewOfSection + B 7C91DF19 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtCreateFile + 6 7C91D0B4 4 Bytes [28, D0, EB, 00] {SUB AL, DL; JMP 0x4}
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtCreateFile + B 7C91D0B9 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtMapViewOfSection + 6 7C91D524 4 Bytes [28, D3, EB, 00] {SUB BL, DL; JMP 0x4}
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtMapViewOfSection + B 7C91D529 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtOpenFile + 6 7C91D5A4 4 Bytes [68, D0, EB, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtOpenFile + B 7C91D5A9 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtOpenProcess + 6 7C91D604 4 Bytes [A8, D1, EB, 00] {TEST AL, 0xd1; JMP 0x4}
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtOpenProcess + B 7C91D609 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtOpenProcessToken + 6 7C91D614 4 Bytes CALL 7B92C1EA
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtOpenProcessToken + B 7C91D619 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtOpenProcessTokenEx + 6 7C91D624 4 Bytes [A8, D2, EB, 00] {TEST AL, 0xd2; JMP 0x4}
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtOpenProcessTokenEx + B 7C91D629 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtOpenThread + 6 7C91D664 4 Bytes [68, D1, EB, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtOpenThread + B 7C91D669 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtOpenThreadToken + 6 7C91D674 4 Bytes [68, D2, EB, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtOpenThreadToken + B 7C91D679 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtOpenThreadTokenEx + 6 7C91D684 4 Bytes CALL 7B92C25B
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtOpenThreadTokenEx + B 7C91D689 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtQueryAttributesFile + 6 7C91D714 4 Bytes [A8, D0, EB, 00] {TEST AL, 0xd0; JMP 0x4}
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtQueryAttributesFile + B 7C91D719 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtQueryFullAttributesFile + 6 7C91D7B4 4 Bytes CALL 7B92C389
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtQueryFullAttributesFile + B 7C91D7B9 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtSetInformationFile + 6 7C91DC64 4 Bytes [28, D1, EB, 00] {SUB CL, DL; JMP 0x4}
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtSetInformationFile + B 7C91DC69 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtSetInformationThread + 6 7C91DCB4 4 Bytes [28, D2, EB, 00] {SUB DL, DL; JMP 0x4}
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtSetInformationThread + B 7C91DCB9 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 4 Bytes [68, D3, EB, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2288] ntdll.dll!NtUnmapViewOfSection + B 7C91DF19 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtCreateFile + 6 7C91D0B4 4 Bytes [28, 04, 80, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtCreateFile + B 7C91D0B9 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtMapViewOfSection + 6 7C91D524 4 Bytes [28, 07, 80, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtMapViewOfSection + B 7C91D529 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtOpenFile + 6 7C91D5A4 4 Bytes [68, 04, 80, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtOpenFile + B 7C91D5A9 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtOpenProcess + 6 7C91D604 4 Bytes [A8, 05, 80, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtOpenProcess + B 7C91D609 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtOpenProcessToken + 6 7C91D614 4 Bytes CALL 7B92561E
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtOpenProcessToken + B 7C91D619 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtOpenProcessTokenEx + 6 7C91D624 4 Bytes [A8, 06, 80, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtOpenProcessTokenEx + B 7C91D629 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtOpenThread + 6 7C91D664 4 Bytes [68, 05, 80, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtOpenThread + B 7C91D669 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtOpenThreadToken + 6 7C91D674 4 Bytes [68, 06, 80, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtOpenThreadToken + B 7C91D679 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtOpenThreadTokenEx + 6 7C91D684 4 Bytes CALL 7B92568F
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtOpenThreadTokenEx + B 7C91D689 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtQueryAttributesFile + 6 7C91D714 4 Bytes [A8, 04, 80, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtQueryAttributesFile + B 7C91D719 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtQueryFullAttributesFile + 6 7C91D7B4 4 Bytes CALL 7B9257BD
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtQueryFullAttributesFile + B 7C91D7B9 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtSetInformationFile + 6 7C91DC64 4 Bytes [28, 05, 80, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtSetInformationFile + B 7C91DC69 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtSetInformationThread + 6 7C91DCB4 4 Bytes [28, 06, 80, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtSetInformationThread + B 7C91DCB9 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 4 Bytes [68, 07, 80, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[2408] ntdll.dll!NtUnmapViewOfSection + B 7C91DF19 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtCreateFile + 6 7C91D0B4 4 Bytes [28, 74, 6D, 00] {SUB [EBP+EBP*2+0x0], DH}
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtCreateFile + B 7C91D0B9 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtMapViewOfSection + 6 7C91D524 4 Bytes [28, 77, 6D, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtMapViewOfSection + B 7C91D529 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtOpenFile + 6 7C91D5A4 4 Bytes [68, 74, 6D, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtOpenFile + B 7C91D5A9 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtOpenProcess + 6 7C91D604 4 Bytes [A8, 75, 6D, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtOpenProcess + B 7C91D609 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtOpenProcessToken + 6 7C91D614 4 Bytes CALL 7B92438E
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtOpenProcessToken + B 7C91D619 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtOpenProcessTokenEx + 6 7C91D624 4 Bytes [A8, 76, 6D, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtOpenProcessTokenEx + B 7C91D629 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtOpenThread + 6 7C91D664 4 Bytes [68, 75, 6D, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtOpenThread + B 7C91D669 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtOpenThreadToken + 6 7C91D674 4 Bytes [68, 76, 6D, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtOpenThreadToken + B 7C91D679 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtOpenThreadTokenEx + 6 7C91D684 4 Bytes CALL 7B9243FF
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtOpenThreadTokenEx + B 7C91D689 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtQueryAttributesFile + 6 7C91D714 4 Bytes [A8, 74, 6D, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtQueryAttributesFile + B 7C91D719 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtQueryFullAttributesFile + 6 7C91D7B4 4 Bytes CALL 7B92452D
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtQueryFullAttributesFile + B 7C91D7B9 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtSetInformationFile + 6 7C91DC64 4 Bytes [28, 75, 6D, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtSetInformationFile + B 7C91DC69 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtSetInformationThread + 6 7C91DCB4 4 Bytes [28, 76, 6D, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtSetInformationThread + B 7C91DCB9 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 4 Bytes [68, 77, 6D, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[3320] ntdll.dll!NtUnmapViewOfSection + B 7C91DF19 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtCreateFile + 6 7C91D0B4 4 Bytes [28, 20, 5B, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtCreateFile + B 7C91D0B9 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtMapViewOfSection + 6 7C91D524 4 Bytes [28, 23, 5B, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtMapViewOfSection + B 7C91D529 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenFile + 6 7C91D5A4 4 Bytes [68, 20, 5B, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenFile + B 7C91D5A9 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenProcess + 6 7C91D604 4 Bytes [A8, 21, 5B, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenProcess + B 7C91D609 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenProcessToken + 6 7C91D614 4 Bytes CALL 7B92313A
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenProcessToken + B 7C91D619 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenProcessTokenEx + 6 7C91D624 4 Bytes [A8, 22, 5B, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenProcessTokenEx + B 7C91D629 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenThread + 6 7C91D664 4 Bytes [68, 21, 5B, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenThread + B 7C91D669 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenThreadToken + 6 7C91D674 4 Bytes [68, 22, 5B, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenThreadToken + B 7C91D679 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenThreadTokenEx + 6 7C91D684 4 Bytes CALL 7B9231AB
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtOpenThreadTokenEx + B 7C91D689 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtQueryAttributesFile + 6 7C91D714 4 Bytes [A8, 20, 5B, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtQueryAttributesFile + B 7C91D719 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtQueryFullAttributesFile + 6 7C91D7B4 4 Bytes CALL 7B9232D9
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtQueryFullAttributesFile + B 7C91D7B9 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtSetInformationFile + 6 7C91DC64 4 Bytes [28, 21, 5B, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtSetInformationFile + B 7C91DC69 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtSetInformationThread + 6 7C91DCB4 4 Bytes [28, 22, 5B, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtSetInformationThread + B 7C91DCB9 1 Byte [E2]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtUnmapViewOfSection + 6 7C91DF14 4 Bytes [68, 23, 5B, 00]
.text C:\Programme\Google\Chrome\Application\chrome.exe[4876] ntdll.dll!NtUnmapViewOfSection + B 7C91DF19 1 Byte [E2]
---- Processes - GMER 2.0 ----
Library C:\WINDOWS\system32\jpgzfrcv.dll (*** hidden *** ) @ C:\Programme\Google\Chrome\Application\chrome.exe [3676] 0x10000000
---- EOF - GMER 2.0 ---- |