You are on page 1of 21

21/12/15 11:03:39

D
call: DLL_PROCESS_ATTACH
21/12/15 11:03:39
D
call: DLL_PROCESS_ATTACH
21/12/15 11:03:39
D
call: DLL_PROCESS_ATTACH
21/12/15 11:03:39
D
call: DLL_PROCESS_ATTACH
21/12/15 11:03:39
D
call: DLL_PROCESS_ATTACH
21/12/15 11:03:39
D
call: DLL_PROCESS_ATTACH
21/12/15 11:03:39
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:00
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:00
A
21/12/15 10:59:00
A
21/12/15 10:59:00
A
21/12/15 10:59:00
A
21/12/15 10:59:00
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:00
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:00
A
21/12/15 10:59:00
D
call: DLL_PROCESS_DETACH
21/12/15 10:59:00
A
21/12/15 10:59:00
D
call: DLL_PROCESS_DETACH
21/12/15 10:59:17
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:17
A
21/12/15 10:59:17
D
call: DLL_PROCESS_DETACH
21/12/15 10:59:18
D
call: DLL_PROCESS_DETACH
21/12/15 10:59:18
D
call: DLL_PROCESS_DETACH
21/12/15 10:59:18
D
call: DLL_PROCESS_DETACH
21/12/15 10:59:18
D
call: DLL_PROCESS_DETACH
21/12/15 10:59:18
D
call: DLL_PROCESS_DETACH
21/12/15 10:59:18
D
call: DLL_PROCESS_DETACH
21/12/15 10:59:19
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:19
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:19
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:19
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:19
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:19
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:19
A

Enter DllMain -> Handle: 1835597824 - Reason for


Enter DllMain -> Handle: 1835597824 - Reason for
Enter DllMain -> Handle: 1835597824 - Reason for
Enter DllMain -> Handle: 1835597824 - Reason for
Enter DllMain -> Handle: 1835597824 - Reason for
Enter DllMain -> Handle: 1835597824 - Reason for
Enter DllMain -> Handle: 1835597824 - Reason for
Enter DllMain -> Handle: 1835597824 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1835597824 - Reason for
Enter DllMain -> Handle: 1835597824 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1835597824 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1835597824 - Reason for
Enter DllMain -> Handle: 1835597824 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1835597824 - Reason for
Enter DllMain -> Handle: 1835597824 - Reason for
Enter DllMain -> Handle: 1835597824 - Reason for
Enter DllMain -> Handle: 1835597824 - Reason for
Enter DllMain -> Handle: 1835597824 - Reason for
Enter DllMain -> Handle: 1835597824 - Reason for
Enter DllMain -> Handle: 1835597824 - Reason for
Enter DllMain -> Handle: 1927217152 - Reason for
Enter DllMain -> Handle: 1927217152 - Reason for
Enter DllMain -> Handle: 1927217152 - Reason for
Enter DllMain -> Handle: 1927217152 - Reason for
Enter DllMain -> Handle: 1927217152 - Reason for
Enter DllMain -> Handle: 1927217152 - Reason for
-> NtTerminateProcessCallback

21/12/15 10:59:19
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:19
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:19
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:19
A
21/12/15 10:59:19
A
21/12/15 10:59:19
A
21/12/15 10:59:19
A
21/12/15 10:59:19
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:19
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:19
A
21/12/15 10:59:19
D
call: DLL_PROCESS_DETACH
21/12/15 10:59:19
A
21/12/15 10:59:19
D
call: DLL_PROCESS_DETACH
21/12/15 10:59:26
D
call: DLL_PROCESS_DETACH
21/12/15 10:59:26
D
call: DLL_PROCESS_DETACH
21/12/15 10:59:26
D
call: DLL_PROCESS_DETACH
21/12/15 10:59:26
D
call: DLL_PROCESS_DETACH
21/12/15 10:59:26
D
call: DLL_PROCESS_DETACH
21/12/15 10:59:26
D
call: DLL_PROCESS_DETACH
21/12/15 10:59:26
D
call: DLL_PROCESS_DETACH
21/12/15 10:59:54
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:54
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:54
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:54
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:54
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:54
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:54
A
21/12/15 10:59:54
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:55
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:55
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:55
A
21/12/15 10:59:55
A
21/12/15 10:59:55
A
21/12/15 10:59:55
A
21/12/15 10:59:55
D
call: DLL_PROCESS_ATTACH
21/12/15 10:59:55
D

Enter DllMain -> Handle: 1927217152 - Reason for


Enter DllMain -> Handle: 1927217152 - Reason for
Enter DllMain -> Handle: 1927217152 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1927217152 - Reason for
Enter DllMain -> Handle: 1927217152 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1927217152 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1927217152 - Reason for
Enter DllMain -> Handle: 1927217152 - Reason for
Enter DllMain -> Handle: 1927217152 - Reason for
Enter DllMain -> Handle: 1927217152 - Reason for
Enter DllMain -> Handle: 1927217152 - Reason for
Enter DllMain -> Handle: 1927217152 - Reason for
Enter DllMain -> Handle: 1927217152 - Reason for
Enter DllMain -> Handle: 1927217152 - Reason for
Enter DllMain -> Handle: 1835139072 - Reason for
Enter DllMain -> Handle: 1835139072 - Reason for
Enter DllMain -> Handle: 1835139072 - Reason for
Enter DllMain -> Handle: 1835139072 - Reason for
Enter DllMain -> Handle: 1835139072 - Reason for
Enter DllMain -> Handle: 1835139072 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1835139072 - Reason for
Enter DllMain -> Handle: 1835139072 - Reason for
Enter DllMain -> Handle: 1835139072 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1835139072 - Reason for
Enter DllMain -> Handle: 1835139072 - Reason for

call: DLL_PROCESS_ATTACH
21/12/15 10:59:55
A
21/12/15 10:59:55
D
call: DLL_PROCESS_DETACH
21/12/15 10:59:55
A
21/12/15 10:59:55
D
call: DLL_PROCESS_DETACH
21/12/15 11:00:41
D
call: DLL_PROCESS_ATTACH
21/12/15 11:00:41
A
21/12/15 11:00:41
A
21/12/15 11:00:41
A
21/12/15 11:00:41
A
21/12/15 11:00:41
D
call: DLL_PROCESS_ATTACH
21/12/15 11:00:41
D
call: DLL_PROCESS_ATTACH
21/12/15 11:00:41
A
21/12/15 11:00:41
D
call: DLL_PROCESS_DETACH
21/12/15 11:00:41
A
21/12/15 11:00:41
D
call: DLL_PROCESS_DETACH
21/12/15 11:00:48
D
call: DLL_PROCESS_DETACH
21/12/15 11:00:48
D
call: DLL_PROCESS_DETACH
21/12/15 11:00:48
D
call: DLL_PROCESS_DETACH
21/12/15 11:00:48
D
call: DLL_PROCESS_DETACH
21/12/15 11:00:48
D
call: DLL_PROCESS_DETACH
21/12/15 11:00:48
D
call: DLL_PROCESS_DETACH
21/12/15 11:00:48
D
call: DLL_PROCESS_DETACH
21/12/15 11:01:54
D
call: DLL_PROCESS_ATTACH
21/12/15 11:01:54
D
call: DLL_PROCESS_ATTACH
21/12/15 11:01:54
D
call: DLL_PROCESS_ATTACH
21/12/15 11:01:54
D
call: DLL_PROCESS_ATTACH
21/12/15 11:01:55
D
call: DLL_PROCESS_ATTACH
21/12/15 11:01:55
D
call: DLL_PROCESS_ATTACH
21/12/15 11:01:55
A
21/12/15 11:01:55
A
21/12/15 11:01:55
D
call: DLL_PROCESS_ATTACH
21/12/15 11:01:55
A
21/12/15 11:01:56
A
21/12/15 11:01:56
D
call: DLL_PROCESS_ATTACH
21/12/15 11:01:56
D
call: DLL_PROCESS_ATTACH
21/12/15 11:01:56
D

-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1835139072 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1835139072 - Reason for
Enter DllMain -> Handle: 1835139072 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1835139072 - Reason for
Enter DllMain -> Handle: 1835139072 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1835139072 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1835139072 - Reason for
Enter DllMain -> Handle: 1835139072 - Reason for
Enter DllMain -> Handle: 1835139072 - Reason for
Enter DllMain -> Handle: 1835139072 - Reason for
Enter DllMain -> Handle: 1835139072 - Reason for
Enter DllMain -> Handle: 1835139072 - Reason for
Enter DllMain -> Handle: 1835139072 - Reason for
Enter DllMain -> Handle: 1835139072 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1925906432 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for

call: DLL_PROCESS_ATTACH
21/12/15 11:01:57
A
21/12/15 11:01:57
D
call: DLL_PROCESS_DETACH
21/12/15 11:01:57
A
21/12/15 11:01:57
D
call: DLL_PROCESS_DETACH
21/12/15 11:02:02
D
call: DLL_PROCESS_ATTACH
21/12/15 11:02:04
D
call: DLL_PROCESS_DETACH
21/12/15 11:02:04
D
call: DLL_PROCESS_DETACH
21/12/15 11:02:04
D
call: DLL_PROCESS_DETACH
21/12/15 11:02:04
D
call: DLL_PROCESS_DETACH
21/12/15 11:02:04
D
call: DLL_PROCESS_DETACH
21/12/15 11:02:05
D
call: DLL_PROCESS_DETACH
21/12/15 11:02:06
D
call: DLL_PROCESS_ATTACH
21/12/15 11:02:06
D
call: DLL_PROCESS_ATTACH
21/12/15 11:02:06
D
call: DLL_PROCESS_ATTACH
21/12/15 11:02:06
D
call: DLL_PROCESS_ATTACH
21/12/15 11:02:06
D
call: DLL_PROCESS_ATTACH
21/12/15 11:02:06
D
call: DLL_PROCESS_ATTACH
21/12/15 11:03:17
D
call: DLL_PROCESS_DETACH
21/12/15 11:03:59
D
call: DLL_PROCESS_DETACH
21/12/15 11:03:59
D
call: DLL_PROCESS_DETACH
21/12/15 11:04:00
D
call: DLL_PROCESS_DETACH
21/12/15 11:04:00
D
call: DLL_PROCESS_DETACH
21/12/15 11:04:00
D
call: DLL_PROCESS_DETACH
21/12/15 11:04:02
D
call: DLL_PROCESS_DETACH
21/12/15 11:04:06
D
call: DLL_PROCESS_ATTACH
21/12/15 11:04:06
D
call: DLL_PROCESS_ATTACH
21/12/15 11:04:06
D
call: DLL_PROCESS_ATTACH
21/12/15 11:04:06
D
call: DLL_PROCESS_ATTACH
21/12/15 11:04:06
D
call: DLL_PROCESS_ATTACH
21/12/15 11:04:07
D
call: DLL_PROCESS_ATTACH
21/12/15 11:06:12
A

-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1925906432 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1925906432 - Reason for
Enter DllMain -> Handle: 1926103040 - Reason for
Enter DllMain -> Handle: 1926103040 - Reason for
Enter DllMain -> Handle: 1926103040 - Reason for
Enter DllMain -> Handle: 1926103040 - Reason for
Enter DllMain -> Handle: 1926103040 - Reason for
Enter DllMain -> Handle: 1926103040 - Reason for
-> CreateDCWCallback

21/12/15 11:06:12
F
21/12/15 11:06:12
A
21/12/15 11:06:12
F
21/12/15 11:06:12
A
21/12/15 11:06:12
F
21/12/15 11:06:12
A
21/12/15 11:06:12
F
21/12/15 11:06:13
A
21/12/15 11:06:13
F
21/12/15 11:06:14
A
21/12/15 11:06:14
F
21/12/15 11:06:15
A
21/12/15 11:06:15
F
21/12/15 11:06:15
A
21/12/15 11:06:15
F
21/12/15 11:06:15
A
21/12/15 11:06:15
F
21/12/15 11:06:17
A
21/12/15 11:06:17
F
21/12/15 11:07:27
A
21/12/15 11:07:27
D
call: DLL_PROCESS_DETACH
21/12/15 11:10:12
D
call: DLL_PROCESS_ATTACH
21/12/15 11:10:13
D
call: DLL_PROCESS_ATTACH
21/12/15 11:10:13
D
call: DLL_PROCESS_ATTACH
21/12/15 11:10:13
D
call: DLL_PROCESS_ATTACH
21/12/15 11:10:13
A
21/12/15 11:10:13
A
21/12/15 11:10:13
A
21/12/15 11:10:13
A
21/12/15 11:10:13
A
21/12/15 11:10:13
A
21/12/15 11:10:13
A
21/12/15 11:10:13
A
21/12/15 11:10:13
D
call: DLL_PROCESS_ATTACH
21/12/15 11:10:13
D
call: DLL_PROCESS_ATTACH
21/12/15 11:10:13
D
call: DLL_PROCESS_ATTACH
21/12/15 11:10:13
A
21/12/15 11:10:13
D
call: DLL_PROCESS_DETACH
21/12/15 11:10:13
A
21/12/15 11:10:13
D
call: DLL_PROCESS_DETACH
21/12/15 11:10:13
A
21/12/15 11:10:13
D
call: DLL_PROCESS_DETACH
21/12/15 11:10:57
D
call: DLL_PROCESS_DETACH
21/12/15 11:10:57
D
call: DLL_PROCESS_DETACH
21/12/15 11:11:32
D
call: DLL_PROCESS_ATTACH
21/12/15 11:11:32
A

lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1926103040 - Reason for
Enter DllMain -> Handle: 1911881728 - Reason for
Enter DllMain -> Handle: 1911881728 - Reason for
Enter DllMain -> Handle: 1911881728 - Reason for
Enter DllMain -> Handle: 1911881728 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1911881728 - Reason for
Enter DllMain -> Handle: 1911881728 - Reason for
Enter DllMain -> Handle: 1911881728 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1911881728 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1911881728 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1911881728 - Reason for
Enter DllMain -> Handle: 1911881728 - Reason for
Enter DllMain -> Handle: 1911881728 - Reason for
Enter DllMain -> Handle: 1763115008 - Reason for
-> NtTerminateProcessCallback

21/12/15 11:11:32
D
call: DLL_PROCESS_ATTACH
21/12/15 11:11:32
D
call: DLL_PROCESS_ATTACH
21/12/15 11:11:33
D
call: DLL_PROCESS_ATTACH
21/12/15 11:11:33
A
21/12/15 11:11:33
A
21/12/15 11:11:33
A
21/12/15 11:11:33
A
21/12/15 11:11:33
D
call: DLL_PROCESS_ATTACH
21/12/15 11:11:33
D
call: DLL_PROCESS_ATTACH
21/12/15 11:11:33
A
21/12/15 11:11:33
D
call: DLL_PROCESS_DETACH
21/12/15 11:11:33
A
21/12/15 11:11:33
D
call: DLL_PROCESS_DETACH
21/12/15 11:11:53
D
call: DLL_PROCESS_ATTACH
21/12/15 11:11:53
A
21/12/15 11:11:53
A
21/12/15 11:11:53
A
21/12/15 11:11:53
A
21/12/15 11:11:53
D
call: DLL_PROCESS_ATTACH
21/12/15 11:11:53
D
call: DLL_PROCESS_ATTACH
21/12/15 11:11:53
A
21/12/15 11:11:53
D
call: DLL_PROCESS_DETACH
21/12/15 11:11:53
A
21/12/15 11:11:53
D
call: DLL_PROCESS_DETACH
21/12/15 11:12:00
D
call: DLL_PROCESS_DETACH
21/12/15 11:12:00
D
call: DLL_PROCESS_DETACH
21/12/15 11:13:07
D
call: DLL_PROCESS_ATTACH
21/12/15 11:13:07
D
call: DLL_PROCESS_ATTACH
21/12/15 11:13:07
D
call: DLL_PROCESS_ATTACH
21/12/15 11:13:07
A
21/12/15 11:13:07
A
21/12/15 11:13:07
A
21/12/15 11:13:07
A
21/12/15 11:13:07
D
call: DLL_PROCESS_ATTACH
21/12/15 11:13:07
A
21/12/15 11:13:07
D
call: DLL_PROCESS_DETACH
21/12/15 11:13:22
D
call: DLL_PROCESS_DETACH
21/12/15 11:13:22
D
call: DLL_PROCESS_DETACH
21/12/15 11:13:36
D

Enter DllMain -> Handle: 1763115008 - Reason for


Enter DllMain -> Handle: 1763115008 - Reason for
Enter DllMain -> Handle: 1763115008 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1763115008 - Reason for
Enter DllMain -> Handle: 1763115008 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1763115008 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1763115008 - Reason for
Enter DllMain -> Handle: 1763115008 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1763115008 - Reason for
Enter DllMain -> Handle: 1763115008 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1763115008 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1763115008 - Reason for
Enter DllMain -> Handle: 1763115008 - Reason for
Enter DllMain -> Handle: 1763115008 - Reason for
Enter DllMain -> Handle: 1908080640 - Reason for
Enter DllMain -> Handle: 1908080640 - Reason for
Enter DllMain -> Handle: 1908080640 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1908080640 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1908080640 - Reason for
Enter DllMain -> Handle: 1908080640 - Reason for
Enter DllMain -> Handle: 1908080640 - Reason for
Enter DllMain -> Handle: 1769799680 - Reason for

call: DLL_PROCESS_ATTACH
21/12/15 11:13:36
A
21/12/15 11:13:36
D
call: DLL_PROCESS_ATTACH
21/12/15 11:13:36
D
call: DLL_PROCESS_ATTACH
21/12/15 11:13:36
D
call: DLL_PROCESS_ATTACH
21/12/15 11:13:36
A
21/12/15 11:13:36
A
21/12/15 11:13:36
A
21/12/15 11:13:36
A
21/12/15 11:13:36
D
call: DLL_PROCESS_ATTACH
21/12/15 11:13:36
D
call: DLL_PROCESS_ATTACH
21/12/15 11:13:36
A
21/12/15 11:13:36
D
call: DLL_PROCESS_DETACH
21/12/15 11:13:36
A
21/12/15 11:13:36
D
call: DLL_PROCESS_DETACH
21/12/15 11:13:52
D
call: DLL_PROCESS_ATTACH
21/12/15 11:13:52
A
21/12/15 11:13:52
A
21/12/15 11:13:52
A
21/12/15 11:13:52
A
21/12/15 11:13:52
D
call: DLL_PROCESS_ATTACH
21/12/15 11:13:52
D
call: DLL_PROCESS_ATTACH
21/12/15 11:13:52
A
21/12/15 11:13:52
D
call: DLL_PROCESS_DETACH
21/12/15 11:13:52
A
21/12/15 11:13:52
D
call: DLL_PROCESS_DETACH
21/12/15 11:13:56
D
call: DLL_PROCESS_DETACH
21/12/15 11:13:56
D
call: DLL_PROCESS_DETACH
21/12/15 11:14:05
D
call: DLL_PROCESS_ATTACH
21/12/15 11:14:05
A
21/12/15 11:14:05
D
call: DLL_PROCESS_ATTACH
21/12/15 11:14:05
D
call: DLL_PROCESS_ATTACH
21/12/15 11:14:05
D
call: DLL_PROCESS_ATTACH
21/12/15 11:14:05
A
21/12/15 11:14:05
A
21/12/15 11:14:05
A
21/12/15 11:14:05
A
21/12/15 11:14:05
D
call: DLL_PROCESS_ATTACH
21/12/15 11:14:05
D
call: DLL_PROCESS_ATTACH
21/12/15 11:14:05
A

-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1769799680 - Reason for
Enter DllMain -> Handle: 1769799680 - Reason for
Enter DllMain -> Handle: 1769799680 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1769799680 - Reason for
Enter DllMain -> Handle: 1769799680 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1769799680 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1769799680 - Reason for
Enter DllMain -> Handle: 1769799680 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1769799680 - Reason for
Enter DllMain -> Handle: 1769799680 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1769799680 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1769799680 - Reason for
Enter DllMain -> Handle: 1769799680 - Reason for
Enter DllMain -> Handle: 1769799680 - Reason for
Enter DllMain -> Handle: 1769603072 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1769603072 - Reason for
Enter DllMain -> Handle: 1769603072 - Reason for
Enter DllMain -> Handle: 1769603072 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1769603072 - Reason for
Enter DllMain -> Handle: 1769603072 - Reason for
-> NtTerminateProcessCallback

21/12/15 11:14:05
D
call: DLL_PROCESS_DETACH
21/12/15 11:14:05
A
21/12/15 11:14:05
D
call: DLL_PROCESS_DETACH
21/12/15 11:14:46
D
call: DLL_PROCESS_ATTACH
21/12/15 11:14:46
A
21/12/15 11:14:46
A
21/12/15 11:14:46
A
21/12/15 11:14:46
A
21/12/15 11:14:46
D
call: DLL_PROCESS_ATTACH
21/12/15 11:14:46
D
call: DLL_PROCESS_ATTACH
21/12/15 11:14:46
A
21/12/15 11:14:46
D
call: DLL_PROCESS_DETACH
21/12/15 11:14:46
A
21/12/15 11:14:46
D
call: DLL_PROCESS_DETACH
21/12/15 11:14:55
D
call: DLL_PROCESS_DETACH
21/12/15 11:14:55
D
call: DLL_PROCESS_DETACH
21/12/15 15:26:33
D
call: DLL_PROCESS_ATTACH
21/12/15 15:26:33
D
call: DLL_PROCESS_ATTACH
21/12/15 15:26:33
A
21/12/15 15:26:33
A
21/12/15 15:26:33
A
21/12/15 15:26:33
A
22/12/15 09:18:00
D
call: DLL_PROCESS_ATTACH
22/12/15 09:18:00
D
call: DLL_PROCESS_ATTACH
22/12/15 09:18:00
A
22/12/15 09:18:00
A
22/12/15 09:18:00
A
22/12/15 09:18:00
A
22/12/15 09:18:00
D
call: DLL_PROCESS_ATTACH
22/12/15 09:18:00
D
call: DLL_PROCESS_ATTACH
22/12/15 09:18:00
D
call: DLL_PROCESS_ATTACH
22/12/15 09:18:00
A
22/12/15 09:18:00
D
call: DLL_PROCESS_DETACH
22/12/15 09:18:00
A
22/12/15 09:18:00
D
call: DLL_PROCESS_DETACH
22/12/15 09:18:00
A
22/12/15 09:18:00
D
call: DLL_PROCESS_DETACH
22/12/15 09:18:14
D
call: DLL_PROCESS_DETACH
22/12/15 09:18:14
D
call: DLL_PROCESS_DETACH

Enter DllMain -> Handle: 1769603072 - Reason for


-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1769603072 - Reason for
Enter DllMain -> Handle: 1769603072 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1769603072 - Reason for
Enter DllMain -> Handle: 1769603072 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1769603072 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1769603072 - Reason for
Enter DllMain -> Handle: 1769603072 - Reason for
Enter DllMain -> Handle: 1769603072 - Reason for
Enter DllMain -> Handle: 1910702080 - Reason for
Enter DllMain -> Handle: 1910702080 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1910702080 - Reason for
Enter DllMain -> Handle: 1910702080 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1910702080 - Reason for
Enter DllMain -> Handle: 1910702080 - Reason for
Enter DllMain -> Handle: 1910702080 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1910702080 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1910702080 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1910702080 - Reason for
Enter DllMain -> Handle: 1910702080 - Reason for
Enter DllMain -> Handle: 1910702080 - Reason for

22/12/15 09:19:54
D
call: DLL_PROCESS_ATTACH
22/12/15 09:19:54
D
call: DLL_PROCESS_ATTACH
22/12/15 09:19:55
D
call: DLL_PROCESS_ATTACH
22/12/15 09:19:55
A
22/12/15 09:19:55
A
22/12/15 09:19:55
A
22/12/15 09:19:55
A
22/12/15 09:19:55
D
call: DLL_PROCESS_ATTACH
22/12/15 09:19:55
D
call: DLL_PROCESS_ATTACH
22/12/15 09:19:55
A
22/12/15 09:19:55
D
call: DLL_PROCESS_DETACH
22/12/15 09:19:55
A
22/12/15 09:19:55
D
call: DLL_PROCESS_DETACH
22/12/15 09:19:59
A
22/12/15 09:19:59
D
call: DLL_PROCESS_ATTACH
22/12/15 09:20:09
D
call: DLL_PROCESS_ATTACH
22/12/15 09:20:14
A
22/12/15 09:20:26
D
call: DLL_PROCESS_ATTACH
22/12/15 09:20:26
A
22/12/15 09:20:26
A
22/12/15 09:20:26
A
22/12/15 09:20:26
A
22/12/15 09:20:26
D
call: DLL_PROCESS_ATTACH
22/12/15 09:20:26
D
call: DLL_PROCESS_ATTACH
22/12/15 09:20:26
A
22/12/15 09:20:26
D
call: DLL_PROCESS_DETACH
22/12/15 09:20:26
A
22/12/15 09:20:26
D
call: DLL_PROCESS_DETACH
22/12/15 09:20:40
D
call: DLL_PROCESS_DETACH
22/12/15 09:20:40
D
call: DLL_PROCESS_DETACH
15/01/16 11:36:00
D
call: DLL_PROCESS_ATTACH
15/01/16 11:36:00
D
call: DLL_PROCESS_ATTACH
15/01/16 11:36:00
D
call: DLL_PROCESS_ATTACH
15/01/16 11:36:00
A
15/01/16 11:36:00
D
call: DLL_PROCESS_DETACH
15/01/16 11:36:00
A
15/01/16 11:36:00
D
call: DLL_PROCESS_DETACH
15/01/16 11:36:00
D
call: DLL_PROCESS_ATTACH

Enter DllMain -> Handle: 1738932224 - Reason for


Enter DllMain -> Handle: 1738932224 - Reason for
Enter DllMain -> Handle: 1738932224 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1738932224 - Reason for
Enter DllMain -> Handle: 1738932224 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1738932224 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1738932224 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1738932224 - Reason for
Enter DllMain -> Handle: 1738932224 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1738932224 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1738932224 - Reason for
Enter DllMain -> Handle: 1738932224 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1738932224 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1738932224 - Reason for
Enter DllMain -> Handle: 1738932224 - Reason for
Enter DllMain -> Handle: 1738932224 - Reason for
Enter DllMain -> Handle: 1918631936 - Reason for
Enter DllMain -> Handle: 1918631936 - Reason for
Enter DllMain -> Handle: 1918631936 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1918631936 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1918631936 - Reason for
Enter DllMain -> Handle: 1918631936 - Reason for

15/01/16 11:36:00
D
call: DLL_PROCESS_ATTACH
15/01/16 11:36:00
D
call: DLL_PROCESS_ATTACH
15/01/16 11:36:00
D
call: DLL_PROCESS_ATTACH
15/01/16 11:36:00
A
15/01/16 11:36:00
A
15/01/16 11:36:00
A
15/01/16 11:36:00
A
15/01/16 11:36:00
A
15/01/16 11:36:00
A
15/01/16 11:36:00
A
15/01/16 11:36:00
A
15/01/16 11:36:00
A
15/01/16 11:36:00
A
15/01/16 11:36:00
A
15/01/16 11:36:00
A
15/01/16 11:36:00
D
call: DLL_PROCESS_ATTACH
15/01/16 11:36:00
D
call: DLL_PROCESS_ATTACH
15/01/16 11:36:00
D
call: DLL_PROCESS_ATTACH
15/01/16 11:36:00
A
15/01/16 11:36:00
A
15/01/16 11:36:00
D
call: DLL_PROCESS_DETACH
15/01/16 11:36:00
D
call: DLL_PROCESS_DETACH
15/01/16 11:36:00
A
15/01/16 11:36:00
D
call: DLL_PROCESS_DETACH
16/01/16 00:33:05
D
call: DLL_PROCESS_ATTACH
16/01/16 00:33:06
D
call: DLL_PROCESS_ATTACH
16/01/16 00:33:06
D
call: DLL_PROCESS_ATTACH
16/01/16 00:33:06
A
16/01/16 00:33:06
D
call: DLL_PROCESS_DETACH
16/01/16 00:33:06
A
16/01/16 00:33:06
F
16/01/16 00:33:06
A
16/01/16 00:33:06
F
16/01/16 00:33:06
A
16/01/16 00:33:06
F
16/01/16 00:33:06
A
16/01/16 00:33:06
F
16/01/16 00:33:06
D
call: DLL_PROCESS_ATTACH
16/01/16 00:33:06
A
16/01/16 00:33:06
F
16/01/16 00:33:06
D
call: DLL_PROCESS_ATTACH
16/01/16 00:33:06
A
16/01/16 00:33:06
D
call: DLL_PROCESS_DETACH
16/01/16 00:33:06
A

Enter DllMain -> Handle: 1918631936 - Reason for


Enter DllMain -> Handle: 1918631936 - Reason for
Enter DllMain -> Handle: 1918631936 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1918631936 - Reason for
Enter DllMain -> Handle: 1918631936 - Reason for
Enter DllMain -> Handle: 1918631936 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1918631936 - Reason for
Enter DllMain -> Handle: 1918631936 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1918631936 - Reason for
Enter DllMain -> Handle: 1918042112 - Reason for
Enter DllMain -> Handle: 1918042112 - Reason for
Enter DllMain -> Handle: 1918042112 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1918042112 - Reason for
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
Enter DllMain -> Handle: 1918042112 - Reason for
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
Enter DllMain -> Handle: 1918042112 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1918042112 - Reason for
-> CreateDCWCallback

16/01/16 00:33:06
F
16/01/16 00:33:06
D
call: DLL_PROCESS_ATTACH
16/01/16 00:33:06
D
call: DLL_PROCESS_ATTACH
16/01/16 00:33:06
D
call: DLL_PROCESS_ATTACH
16/01/16 00:33:06
A
16/01/16 00:33:06
D
call: DLL_PROCESS_ATTACH
16/01/16 00:33:06
D
call: DLL_PROCESS_DETACH
16/01/16 00:33:06
A
16/01/16 00:33:06
D
call: DLL_PROCESS_DETACH
16/01/16 00:33:07
D
call: DLL_PROCESS_ATTACH
16/01/16 00:33:07
D
call: DLL_PROCESS_ATTACH
16/01/16 00:33:07
A
16/01/16 00:33:07
D
call: DLL_PROCESS_DETACH
16/01/16 00:33:07
D
call: DLL_PROCESS_ATTACH
16/01/16 00:33:07
A
16/01/16 00:33:07
F
16/01/16 00:33:07
A
16/01/16 00:33:07
F
16/01/16 00:33:08
D
call: DLL_PROCESS_ATTACH
16/01/16 00:33:08
A
16/01/16 00:33:08
D
call: DLL_PROCESS_DETACH
16/01/16 00:33:10
D
call: DLL_PROCESS_DETACH
16/01/16 00:33:10
D
call: DLL_PROCESS_DETACH
16/01/16 00:33:10
D
call: DLL_PROCESS_DETACH
16/01/16 00:33:10
D
call: DLL_PROCESS_DETACH
16/01/16 00:33:10
D
call: DLL_PROCESS_DETACH
16/01/16 00:33:10
D
call: DLL_PROCESS_DETACH
16/01/16 00:33:10
D
call: DLL_PROCESS_DETACH
16/01/16 00:33:10
D
call: DLL_PROCESS_ATTACH
16/01/16 00:33:10
D
call: DLL_PROCESS_ATTACH
16/01/16 00:33:10
D
call: DLL_PROCESS_ATTACH
16/01/16 00:33:10
D
call: DLL_PROCESS_ATTACH
16/01/16 00:33:10
D
call: DLL_PROCESS_ATTACH
16/01/16 00:33:10
D
call: DLL_PROCESS_ATTACH
16/01/16 00:33:10
D

lpszDevice: \\.\DISPLAY1
Enter DllMain -> Handle: 1918042112 - Reason for
Enter DllMain -> Handle: 1918042112 - Reason for
Enter DllMain -> Handle: 1918042112 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1918042112 - Reason for
Enter DllMain -> Handle: 1918042112 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1918042112 - Reason for
Enter DllMain -> Handle: 1918042112 - Reason for
Enter DllMain -> Handle: 1918042112 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1918042112 - Reason for
Enter DllMain -> Handle: 1918042112 - Reason for
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
Enter DllMain -> Handle: 1918042112 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1918042112 - Reason for
Enter DllMain -> Handle: 1918042112 - Reason for
Enter DllMain -> Handle: 1918042112 - Reason for
Enter DllMain -> Handle: 1918042112 - Reason for
Enter DllMain -> Handle: 1918042112 - Reason for
Enter DllMain -> Handle: 1918042112 - Reason for
Enter DllMain -> Handle: 1918042112 - Reason for
Enter DllMain -> Handle: 1918042112 - Reason for
Enter DllMain -> Handle: 1883373568 - Reason for
Enter DllMain -> Handle: 1883373568 - Reason for
Enter DllMain -> Handle: 1883373568 - Reason for
Enter DllMain -> Handle: 1883373568 - Reason for
Enter DllMain -> Handle: 1883373568 - Reason for
Enter DllMain -> Handle: 1883373568 - Reason for
Enter DllMain -> Handle: 1883373568 - Reason for

call: DLL_PROCESS_ATTACH
16/01/16 00:33:16
D
call: DLL_PROCESS_ATTACH
16/01/16 00:33:17
D
call: DLL_PROCESS_DETACH
16/01/16 00:33:17
D
call: DLL_PROCESS_DETACH
16/01/16 00:33:17
D
call: DLL_PROCESS_DETACH
16/01/16 00:33:17
D
call: DLL_PROCESS_DETACH
16/01/16 00:33:17
D
call: DLL_PROCESS_DETACH
16/01/16 00:33:17
D
call: DLL_PROCESS_DETACH
16/01/16 00:33:17
D
call: DLL_PROCESS_DETACH
16/01/16 00:33:17
D
call: DLL_PROCESS_DETACH
16/01/16 00:54:35
D
call: DLL_PROCESS_ATTACH
16/01/16 00:55:09
D
call: DLL_PROCESS_ATTACH
16/01/16 00:55:09
D
call: DLL_PROCESS_ATTACH
16/01/16 00:55:09
A
16/01/16 00:55:09
D
call: DLL_PROCESS_DETACH
16/01/16 00:55:09
D
call: DLL_PROCESS_ATTACH
16/01/16 00:55:09
D
call: DLL_PROCESS_ATTACH
16/01/16 00:55:09
A
16/01/16 00:55:09
F
16/01/16 00:55:09
A
16/01/16 00:55:09
F
16/01/16 00:55:09
A
16/01/16 00:55:09
F
16/01/16 00:55:09
A
16/01/16 00:55:09
F
16/01/16 00:55:09
A
16/01/16 00:55:09
F
16/01/16 00:55:09
A
16/01/16 00:55:09
D
call: DLL_PROCESS_DETACH
16/01/16 00:55:09
D
call: DLL_PROCESS_ATTACH
16/01/16 00:55:09
A
16/01/16 00:55:09
F
16/01/16 00:55:09
D
call: DLL_PROCESS_ATTACH
16/01/16 00:55:10
D
call: DLL_PROCESS_ATTACH
16/01/16 00:55:10
D
call: DLL_PROCESS_ATTACH
16/01/16 00:55:10
D
call: DLL_PROCESS_ATTACH
16/01/16 00:55:10
A
16/01/16 00:55:10
D
call: DLL_PROCESS_DETACH

Enter DllMain -> Handle: 1883373568 - Reason for


Enter DllMain -> Handle: 1883373568 - Reason for
Enter DllMain -> Handle: 1883373568 - Reason for
Enter DllMain -> Handle: 1883373568 - Reason for
Enter DllMain -> Handle: 1883373568 - Reason for
Enter DllMain -> Handle: 1883373568 - Reason for
Enter DllMain -> Handle: 1883373568 - Reason for
Enter DllMain -> Handle: 1883373568 - Reason for
Enter DllMain -> Handle: 1883373568 - Reason for
Enter DllMain -> Handle: 1916338176 - Reason for
Enter DllMain -> Handle: 1916338176 - Reason for
Enter DllMain -> Handle: 1916338176 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1916338176 - Reason for
Enter DllMain -> Handle: 1916338176 - Reason for
Enter DllMain -> Handle: 1916338176 - Reason for
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1916338176 - Reason for
Enter DllMain -> Handle: 1916338176 - Reason for
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
Enter DllMain -> Handle: 1916338176 - Reason for
Enter DllMain -> Handle: 1916338176 - Reason for
Enter DllMain -> Handle: 1916338176 - Reason for
Enter DllMain -> Handle: 1916338176 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1916338176 - Reason for

16/01/16 00:55:10
A
16/01/16 00:55:10
F
16/01/16 00:55:11
A
16/01/16 00:55:11
F
16/01/16 00:55:11
A
16/01/16 00:55:11
F
16/01/16 00:55:13
D
call: DLL_PROCESS_DETACH
16/01/16 00:55:13
D
call: DLL_PROCESS_DETACH
16/01/16 00:55:13
D
call: DLL_PROCESS_DETACH
16/01/16 00:55:13
D
call: DLL_PROCESS_DETACH
16/01/16 00:55:13
D
call: DLL_PROCESS_DETACH
16/01/16 00:55:13
D
call: DLL_PROCESS_DETACH
16/01/16 00:55:13
D
call: DLL_PROCESS_DETACH
16/01/16 00:55:13
D
call: DLL_PROCESS_ATTACH
16/01/16 00:55:13
D
call: DLL_PROCESS_ATTACH
16/01/16 00:55:13
D
call: DLL_PROCESS_ATTACH
16/01/16 00:55:13
D
call: DLL_PROCESS_ATTACH
16/01/16 00:55:13
D
call: DLL_PROCESS_ATTACH
16/01/16 00:55:13
D
call: DLL_PROCESS_ATTACH
16/01/16 00:55:13
D
call: DLL_PROCESS_ATTACH
16/01/16 00:55:19
D
call: DLL_PROCESS_ATTACH
16/01/16 00:55:35
A
16/01/16 00:55:35
D
call: DLL_PROCESS_DETACH
16/01/16 00:55:50
D
call: DLL_PROCESS_ATTACH
16/01/16 00:55:59
A
16/01/16 00:55:59
R
16/01/16 00:56:05
A
16/01/16 00:56:05
R
16/01/16 00:56:56
A
16/01/16 00:56:56
R
16/01/16 00:57:08
A
16/01/16 00:57:08
R
16/01/16 00:57:08
A
16/01/16 00:57:08
R
16/01/16 00:57:09
A
16/01/16 00:57:09
A
16/01/16 00:57:28
D
call: DLL_PROCESS_ATTACH
16/01/16 00:57:32
D
call: DLL_PROCESS_ATTACH
16/01/16 00:57:34
D
call: DLL_PROCESS_ATTACH
16/01/16 00:57:38
A

-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
Enter DllMain -> Handle: 1916338176 - Reason for
Enter DllMain -> Handle: 1916338176 - Reason for
Enter DllMain -> Handle: 1916338176 - Reason for
Enter DllMain -> Handle: 1916338176 - Reason for
Enter DllMain -> Handle: 1916338176 - Reason for
Enter DllMain -> Handle: 1916338176 - Reason for
Enter DllMain -> Handle: 1916338176 - Reason for
Enter DllMain -> Handle: 1877082112 - Reason for
Enter DllMain -> Handle: 1877082112 - Reason for
Enter DllMain -> Handle: 1877082112 - Reason for
Enter DllMain -> Handle: 1877082112 - Reason for
Enter DllMain -> Handle: 1877082112 - Reason for
Enter DllMain -> Handle: 1877082112 - Reason for
Enter DllMain -> Handle: 1877082112 - Reason for
Enter DllMain -> Handle: 1877082112 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1877082112 - Reason for
Enter DllMain -> Handle: 1877082112 - Reason for
-> NtTerminateProcessCallback
La victima es chrome.exe Asesino chrome.exe
-> NtTerminateProcessCallback
La victima es chrome.exe Asesino chrome.exe
-> NtTerminateProcessCallback
La victima es chrome.exe Asesino chrome.exe
-> NtTerminateProcessCallback
La victima es chrome.exe Asesino chrome.exe
-> NtTerminateProcessCallback
La victima es chrome.exe Asesino chrome.exe
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1877082112 - Reason for
Enter DllMain -> Handle: 1877082112 - Reason for
Enter DllMain -> Handle: 1877082112 - Reason for
-> NtTerminateProcessCallback

16/01/16 00:57:40
A
16/01/16 00:57:40
D
call: DLL_PROCESS_DETACH
16/01/16 00:57:40
A
16/01/16 00:57:41
D
call: DLL_PROCESS_DETACH
16/01/16 00:57:55
D
call: DLL_PROCESS_ATTACH
16/01/16 00:58:06
D
call: DLL_PROCESS_ATTACH
16/01/16 00:58:10
A
16/01/16 00:58:10
D
call: DLL_PROCESS_DETACH
16/01/16 00:58:14
D
call: DLL_PROCESS_ATTACH
16/01/16 00:59:12
A
16/01/16 00:59:12
D
call: DLL_PROCESS_DETACH
16/01/16 00:59:27
A
16/01/16 00:59:27
R
16/01/16 01:00:45
D
call: DLL_PROCESS_ATTACH
16/01/16 01:00:52
A
16/01/16 01:00:52
R
16/01/16 01:00:53
A
16/01/16 01:00:53
R
16/01/16 01:01:05
A
16/01/16 01:01:05
R
16/01/16 01:01:42
A
16/01/16 01:01:42
R
16/01/16 01:01:56
A
16/01/16 01:01:56
R
16/01/16 01:03:24
A
16/01/16 01:03:24
R
16/01/16 01:03:25
A
16/01/16 01:03:25
R
16/01/16 01:03:28
A
16/01/16 01:03:28
R
16/01/16 01:03:28
A
16/01/16 01:03:28
R
16/01/16 01:03:29
A
16/01/16 01:03:30
A
16/01/16 01:03:55
D
call: DLL_PROCESS_ATTACH
16/01/16 01:04:06
A
16/01/16 01:04:06
D
call: DLL_PROCESS_DETACH
16/01/16 01:05:08
D
call: DLL_PROCESS_ATTACH
16/01/16 01:05:14
A
16/01/16 01:05:14
D
call: DLL_PROCESS_ATTACH
16/01/16 01:05:14
A
16/01/16 01:05:14
D
call: DLL_PROCESS_DETACH
16/01/16 01:08:10
D
call: DLL_PROCESS_ATTACH
16/01/16 01:08:10
A
16/01/16 01:08:10
D
call: DLL_PROCESS_DETACH

-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1877082112 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1877082112 - Reason for
Enter DllMain -> Handle: 1877082112 - Reason for
Enter DllMain -> Handle: 1877082112 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1877082112 - Reason for
Enter DllMain -> Handle: 1877082112 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1877082112 - Reason for
-> NtTerminateProcessCallback
La victima es chrome.exe Asesino chrome.exe
Enter DllMain -> Handle: 1877082112 - Reason for
-> NtTerminateProcessCallback
La victima es chrome.exe Asesino chrome.exe
-> NtTerminateProcessCallback
La victima es chrome.exe Asesino chrome.exe
-> NtTerminateProcessCallback
La victima es chrome.exe Asesino chrome.exe
-> NtTerminateProcessCallback
La victima es chrome.exe Asesino chrome.exe
-> NtTerminateProcessCallback
La victima es chrome.exe Asesino chrome.exe
-> NtTerminateProcessCallback
La victima es chrome.exe Asesino chrome.exe
-> NtTerminateProcessCallback
La victima es chrome.exe Asesino chrome.exe
-> NtTerminateProcessCallback
La victima es chrome.exe Asesino chrome.exe
-> NtTerminateProcessCallback
La victima es chrome.exe Asesino chrome.exe
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1877082112 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1877082112 - Reason for
Enter DllMain -> Handle: 1877082112 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1877082112 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1877082112 - Reason for
Enter DllMain -> Handle: 1877082112 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1877082112 - Reason for

16/01/16 02:19:15
D
call: DLL_PROCESS_ATTACH
16/01/16 02:32:53
D
call: DLL_PROCESS_ATTACH
16/01/16 02:32:53
A
16/01/16 02:32:53
A
16/01/16 02:32:54
A
16/01/16 02:32:54
D
call: DLL_PROCESS_ATTACH
16/01/16 02:33:08
A
16/01/16 02:33:08
F
16/01/16 02:33:08
A
16/01/16 02:33:08
F
16/01/16 02:33:08
A
16/01/16 02:33:08
F
16/01/16 02:33:08
A
16/01/16 02:33:08
F
16/01/16 02:33:08
A
16/01/16 02:33:08
F
16/01/16 02:33:08
A
16/01/16 02:33:08
F
16/01/16 02:33:09
A
16/01/16 02:33:09
F
16/01/16 02:33:09
A
16/01/16 02:33:09
F
16/01/16 02:37:55
A
16/01/16 02:37:55
D
call: DLL_PROCESS_DETACH
16/01/16 02:37:55
A
16/01/16 02:37:55
F
16/01/16 02:37:55
A
16/01/16 02:37:55
F
16/01/16 02:37:55
A
16/01/16 02:37:55
F
16/01/16 02:37:55
A
16/01/16 02:37:55
F
16/01/16 02:37:55
A
16/01/16 02:37:55
F
16/01/16 02:37:55
A
16/01/16 02:37:55
F
16/01/16 02:37:55
A
16/01/16 02:37:55
F
16/01/16 04:08:51
A
16/01/16 04:08:51
D
call: DLL_PROCESS_DETACH
19/01/15 13:25:53
D
call: DLL_PROCESS_ATTACH
19/01/16 13:25:00
D
call: DLL_PROCESS_ATTACH
19/01/16 13:25:00
A
19/01/16 13:25:00
A
19/01/16 13:25:00
A
19/01/16 13:25:00
A
19/01/16 13:25:00
D
call: DLL_PROCESS_ATTACH
19/01/16 13:25:00
D
call: DLL_PROCESS_ATTACH
19/01/16 13:25:00
A
19/01/16 13:25:00
D
call: DLL_PROCESS_DETACH

Enter DllMain -> Handle: 1877082112 - Reason for


Enter DllMain -> Handle: 1877082112 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1877082112 - Reason for
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1877082112 - Reason for
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1877082112 - Reason for
Enter DllMain -> Handle: 1910439936 - Reason for
Enter DllMain -> Handle: 1910439936 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1910439936 - Reason for
Enter DllMain -> Handle: 1910439936 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1910439936 - Reason for

19/01/16 13:25:00
A
19/01/16 13:25:00
D
call: DLL_PROCESS_DETACH
19/01/16 13:25:09
D
call: DLL_PROCESS_DETACH
19/01/16 13:25:36
D
call: DLL_PROCESS_ATTACH
19/01/16 13:25:36
D
call: DLL_PROCESS_ATTACH
19/01/16 13:25:36
D
call: DLL_PROCESS_ATTACH
19/01/16 13:25:36
D
call: DLL_PROCESS_ATTACH
19/01/16 13:25:36
D
call: DLL_PROCESS_ATTACH
19/01/16 13:25:36
D
call: DLL_PROCESS_ATTACH
19/01/16 13:25:37
D
call: DLL_PROCESS_ATTACH
19/01/16 13:25:37
A
19/01/16 13:25:37
A
19/01/16 13:25:37
A
19/01/16 13:25:37
A
19/01/16 13:25:37
D
call: DLL_PROCESS_ATTACH
19/01/16 13:25:37
D
call: DLL_PROCESS_ATTACH
19/01/16 13:25:37
A
19/01/16 13:25:37
D
call: DLL_PROCESS_DETACH
19/01/16 13:25:37
A
19/01/16 13:25:37
D
call: DLL_PROCESS_DETACH
19/01/16 13:25:38
D
call: DLL_PROCESS_ATTACH
19/01/16 13:25:38
D
call: DLL_PROCESS_ATTACH
19/01/16 13:25:39
A
19/01/16 13:25:39
A
19/01/16 13:25:39
D
call: DLL_PROCESS_DETACH
19/01/16 13:25:39
D
call: DLL_PROCESS_DETACH
19/01/16 13:25:41
D
call: DLL_PROCESS_DETACH
19/01/16 13:25:41
D
call: DLL_PROCESS_DETACH
19/01/16 13:25:41
D
call: DLL_PROCESS_DETACH
19/01/16 13:25:41
D
call: DLL_PROCESS_DETACH
19/01/16 13:25:41
D
call: DLL_PROCESS_DETACH
19/01/16 13:25:41
D
call: DLL_PROCESS_DETACH
19/01/16 13:31:38
D
call: DLL_PROCESS_ATTACH
19/01/16 13:31:38
D
call: DLL_PROCESS_ATTACH
19/01/16 13:31:38
A

-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1910439936 - Reason for
Enter DllMain -> Handle: 1910439936 - Reason for
Enter DllMain -> Handle: 1948712960 - Reason for
Enter DllMain -> Handle: 1948712960 - Reason for
Enter DllMain -> Handle: 1948712960 - Reason for
Enter DllMain -> Handle: 1948712960 - Reason for
Enter DllMain -> Handle: 1948712960 - Reason for
Enter DllMain -> Handle: 1948712960 - Reason for
Enter DllMain -> Handle: 1948712960 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1948712960 - Reason for
Enter DllMain -> Handle: 1948712960 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1948712960 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1948712960 - Reason for
Enter DllMain -> Handle: 1948712960 - Reason for
Enter DllMain -> Handle: 1948712960 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1948712960 - Reason for
Enter DllMain -> Handle: 1948712960 - Reason for
Enter DllMain -> Handle: 1948712960 - Reason for
Enter DllMain -> Handle: 1948712960 - Reason for
Enter DllMain -> Handle: 1948712960 - Reason for
Enter DllMain -> Handle: 1948712960 - Reason for
Enter DllMain -> Handle: 1948712960 - Reason for
Enter DllMain -> Handle: 1948712960 - Reason for
Enter DllMain -> Handle: 1862336512 - Reason for
Enter DllMain -> Handle: 1862336512 - Reason for
-> CreateDCWCallback

19/01/16 13:31:38
A
19/01/16 13:31:39
A
19/01/16 13:31:39
D
call: DLL_PROCESS_ATTACH
19/01/16 13:31:39
A
19/01/16 13:31:39
A
19/01/16 13:31:39
A
19/01/16 13:31:39
A
19/01/16 13:31:39
A
19/01/16 13:31:39
D
call: DLL_PROCESS_ATTACH
19/01/16 13:31:40
D
call: DLL_PROCESS_ATTACH
19/01/16 13:31:41
D
call: DLL_PROCESS_ATTACH
19/01/16 13:31:41
A
19/01/16 13:31:41
D
call: DLL_PROCESS_DETACH
19/01/16 13:31:41
A
19/01/16 13:31:41
D
call: DLL_PROCESS_DETACH
19/01/16 13:31:45
A
19/01/16 13:31:45
D
call: DLL_PROCESS_DETACH
19/01/16 13:31:57
D
call: DLL_PROCESS_DETACH
19/01/16 13:38:33
D
call: DLL_PROCESS_ATTACH
19/01/16 13:38:34
D
call: DLL_PROCESS_ATTACH
19/01/16 13:38:34
D
call: DLL_PROCESS_ATTACH
19/01/16 13:38:34
A
19/01/16 13:38:34
A
19/01/16 13:38:34
A
19/01/16 13:38:34
A
19/01/16 13:38:34
D
call: DLL_PROCESS_ATTACH
19/01/16 13:38:34
D
call: DLL_PROCESS_ATTACH
19/01/16 13:38:34
A
19/01/16 13:38:34
D
call: DLL_PROCESS_DETACH
19/01/16 13:38:34
A
19/01/16 13:38:34
D
call: DLL_PROCESS_DETACH
26/02/16 10:24:41
D
call: DLL_PROCESS_ATTACH
26/02/16 10:24:41
D
call: DLL_PROCESS_ATTACH
26/02/16 10:24:48
D
call: DLL_PROCESS_DETACH
26/02/16 10:24:48
D
call: DLL_PROCESS_DETACH
26/02/16 10:24:48
D
call: DLL_PROCESS_DETACH
26/02/16 10:24:48
D
call: DLL_PROCESS_DETACH
26/02/16 10:24:48
D
call: DLL_PROCESS_DETACH

-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1862336512 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1862336512 - Reason for
Enter DllMain -> Handle: 1862336512 - Reason for
Enter DllMain -> Handle: 1862336512 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1862336512 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1862336512 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1862336512 - Reason for
Enter DllMain -> Handle: 1862336512 - Reason for
Enter DllMain -> Handle: 1921449984 - Reason for
Enter DllMain -> Handle: 1921449984 - Reason for
Enter DllMain -> Handle: 1921449984 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1921449984 - Reason for
Enter DllMain -> Handle: 1921449984 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1921449984 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1921449984 - Reason for
Enter DllMain -> Handle: 1942618112 - Reason for
Enter DllMain -> Handle: 1942618112 - Reason for
Enter DllMain -> Handle: 1942618112 - Reason for
Enter DllMain -> Handle: 1942618112 - Reason for
Enter DllMain -> Handle: 1942618112 - Reason for
Enter DllMain -> Handle: 1942618112 - Reason for
Enter DllMain -> Handle: 1942618112 - Reason for

26/02/16 10:24:48
D
call: DLL_PROCESS_DETACH
07/03/16 16:42:44
D
call: DLL_PROCESS_ATTACH
07/03/16 16:42:44
D
call: DLL_PROCESS_ATTACH
07/03/16 16:42:44
A
07/03/16 16:42:44
F
07/03/16 16:42:44
A
07/03/16 16:42:44
F
07/03/16 16:42:44
A
07/03/16 16:42:44
F
07/03/16 16:42:44
A
07/03/16 16:42:44
F
07/03/16 16:42:44
A
07/03/16 16:42:44
F
07/03/16 16:42:44
D
call: DLL_PROCESS_ATTACH
07/03/16 16:42:44
A
07/03/16 16:42:44
F
07/03/16 16:42:44
D
call: DLL_PROCESS_ATTACH
07/03/16 16:42:45
A
07/03/16 16:42:45
D
call: DLL_PROCESS_DETACH
07/03/16 16:42:45
D
call: DLL_PROCESS_ATTACH
07/03/16 16:42:45
D
call: DLL_PROCESS_ATTACH
07/03/16 16:42:45
D
call: DLL_PROCESS_ATTACH
07/03/16 16:42:45
A
07/03/16 16:42:45
F
07/03/16 16:42:45
D
call: DLL_PROCESS_ATTACH
07/03/16 16:42:46
A
07/03/16 16:42:46
D
call: DLL_PROCESS_DETACH
07/03/16 16:42:46
A
07/03/16 16:42:46
F
07/03/16 16:42:46
A
07/03/16 16:42:46
F
07/03/16 16:42:46
D
call: DLL_PROCESS_ATTACH
07/03/16 16:42:46
A
07/03/16 16:42:46
D
call: DLL_PROCESS_DETACH
07/03/16 16:42:48
D
call: DLL_PROCESS_DETACH
07/03/16 16:42:48
D
call: DLL_PROCESS_DETACH
07/03/16 16:42:48
D
call: DLL_PROCESS_DETACH
07/03/16 16:42:48
D
call: DLL_PROCESS_DETACH
07/03/16 16:42:48
D
call: DLL_PROCESS_DETACH
07/03/16 16:42:48
D
call: DLL_PROCESS_DETACH
07/03/16 16:42:48
D

Enter DllMain -> Handle: 1942618112 - Reason for


Enter DllMain -> Handle: 1935671296 - Reason for
Enter DllMain -> Handle: 1935671296 - Reason for
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
Enter DllMain -> Handle: 1935671296 - Reason for
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
Enter DllMain -> Handle: 1935671296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1935671296 - Reason for
Enter DllMain -> Handle: 1935671296 - Reason for
Enter DllMain -> Handle: 1935671296 - Reason for
Enter DllMain -> Handle: 1935671296 - Reason for
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
Enter DllMain -> Handle: 1935671296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1935671296 - Reason for
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
-> CreateDCWCallback
lpszDevice: \\.\DISPLAY1
Enter DllMain -> Handle: 1935671296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1935671296 - Reason for
Enter DllMain -> Handle: 1935671296 - Reason for
Enter DllMain -> Handle: 1935671296 - Reason for
Enter DllMain -> Handle: 1935671296 - Reason for
Enter DllMain -> Handle: 1935671296 - Reason for
Enter DllMain -> Handle: 1935671296 - Reason for
Enter DllMain -> Handle: 1935671296 - Reason for
Enter DllMain -> Handle: 1944322048 - Reason for

call: DLL_PROCESS_ATTACH
07/03/16 16:42:48
D
call: DLL_PROCESS_ATTACH
07/03/16 16:42:48
D
call: DLL_PROCESS_ATTACH
07/03/16 16:42:48
D
call: DLL_PROCESS_ATTACH
07/03/16 16:42:48
D
call: DLL_PROCESS_ATTACH
07/03/16 16:42:48
D
call: DLL_PROCESS_ATTACH
07/03/16 16:42:52
D
call: DLL_PROCESS_DETACH
07/03/16 16:42:52
D
call: DLL_PROCESS_DETACH
07/03/16 16:42:52
D
call: DLL_PROCESS_DETACH
07/03/16 16:42:52
D
call: DLL_PROCESS_DETACH
07/03/16 16:42:52
D
call: DLL_PROCESS_DETACH
07/03/16 16:42:52
D
call: DLL_PROCESS_DETACH
08/03/16 07:49:01
D
call: DLL_PROCESS_ATTACH
08/03/16 07:50:48
A
08/03/16 07:50:48
D
call: DLL_PROCESS_ATTACH
08/03/16 07:50:48
D
call: DLL_PROCESS_ATTACH
08/03/16 07:50:48
A
08/03/16 07:50:48
A
08/03/16 07:50:48
A
08/03/16 07:50:48
A
08/03/16 07:50:48
D
call: DLL_PROCESS_ATTACH
08/03/16 07:50:48
D
call: DLL_PROCESS_ATTACH
08/03/16 07:50:48
A
08/03/16 07:50:48
D
call: DLL_PROCESS_DETACH
08/03/16 07:50:48
A
08/03/16 07:50:48
D
call: DLL_PROCESS_DETACH
08/03/16 07:50:49
D
call: DLL_PROCESS_ATTACH
08/03/16 10:48:05
D
call: DLL_PROCESS_DETACH
08/03/16 10:48:05
D
call: DLL_PROCESS_DETACH
08/03/16 11:15:53
D
call: DLL_PROCESS_ATTACH
08/03/16 11:15:53
D
call: DLL_PROCESS_ATTACH
08/03/16 11:15:57
D
call: DLL_PROCESS_ATTACH
08/03/16 11:15:57
D
call: DLL_PROCESS_ATTACH
08/03/16 11:15:57
D
call: DLL_PROCESS_DETACH

Enter DllMain -> Handle: 1944322048 - Reason for


Enter DllMain -> Handle: 1944322048 - Reason for
Enter DllMain -> Handle: 1944322048 - Reason for
Enter DllMain -> Handle: 1944322048 - Reason for
Enter DllMain -> Handle: 1944322048 - Reason for
Enter DllMain -> Handle: 1944322048 - Reason for
Enter DllMain -> Handle: 1944322048 - Reason for
Enter DllMain -> Handle: 1944322048 - Reason for
Enter DllMain -> Handle: 1944322048 - Reason for
Enter DllMain -> Handle: 1944322048 - Reason for
Enter DllMain -> Handle: 1944322048 - Reason for
Enter DllMain -> Handle: 1927217152 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1927217152 - Reason for
Enter DllMain -> Handle: 1927217152 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1927217152 - Reason for
Enter DllMain -> Handle: 1927217152 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1927217152 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1927217152 - Reason for
Enter DllMain -> Handle: 1927217152 - Reason for
Enter DllMain -> Handle: 1927217152 - Reason for
Enter DllMain -> Handle: 1927217152 - Reason for
Enter DllMain -> Handle: 1948319744 - Reason for
Enter DllMain -> Handle: 1948319744 - Reason for
Enter DllMain -> Handle: 1948319744 - Reason for
Enter DllMain -> Handle: 1948319744 - Reason for
Enter DllMain -> Handle: 1948319744 - Reason for

08/03/16 11:15:57
D
call: DLL_PROCESS_DETACH
08/03/16 11:15:57
D
call: DLL_PROCESS_DETACH
08/03/16 11:15:57
D
call: DLL_PROCESS_DETACH
08/03/16 11:15:57
D
call: DLL_PROCESS_DETACH
08/03/16 11:15:57
D
call: DLL_PROCESS_DETACH
08/03/16 11:15:57
D
call: DLL_PROCESS_DETACH
08/03/16 11:15:57
D
call: DLL_PROCESS_DETACH
08/03/16 15:33:02
D
call: DLL_PROCESS_ATTACH
08/03/16 15:33:02
D
call: DLL_PROCESS_ATTACH
08/03/16 15:33:02
D
call: DLL_PROCESS_ATTACH
08/03/16 15:33:02
D
call: DLL_PROCESS_ATTACH
08/03/16 15:33:02
A
08/03/16 15:33:02
A
08/03/16 15:33:02
A
08/03/16 15:33:02
A
08/03/16 15:33:02
A
08/03/16 15:33:02
A
08/03/16 15:33:02
A
08/03/16 15:33:02
A
08/03/16 15:33:03
D
call: DLL_PROCESS_ATTACH
08/03/16 15:33:03
D
call: DLL_PROCESS_ATTACH
08/03/16 15:33:03
D
call: DLL_PROCESS_ATTACH
08/03/16 15:33:03
A
08/03/16 15:33:03
D
call: DLL_PROCESS_DETACH
08/03/16 15:33:03
A
08/03/16 15:33:03
D
call: DLL_PROCESS_DETACH
08/03/16 15:33:04
A
08/03/16 15:33:04
D
call: DLL_PROCESS_DETACH
08/03/16 15:33:12
D
call: DLL_PROCESS_DETACH
08/03/16 15:33:12
D
call: DLL_PROCESS_DETACH
16/03/16 14:14:49
D
call: DLL_PROCESS_ATTACH
16/03/16 14:14:49
D
call: DLL_PROCESS_ATTACH
16/03/16 14:14:49
D
call: DLL_PROCESS_ATTACH
16/03/16 14:14:49
D
call: DLL_PROCESS_ATTACH
16/03/16 14:14:49
A
16/03/16 14:14:49
A
16/03/16 14:14:49
A

Enter DllMain -> Handle: 1948319744 - Reason for


Enter DllMain -> Handle: 1948319744 - Reason for
Enter DllMain -> Handle: 1948319744 - Reason for
Enter DllMain -> Handle: 1948319744 - Reason for
Enter DllMain -> Handle: 1948319744 - Reason for
Enter DllMain -> Handle: 1948319744 - Reason for
Enter DllMain -> Handle: 1948319744 - Reason for
Enter DllMain -> Handle: 1832058880 - Reason for
Enter DllMain -> Handle: 1832058880 - Reason for
Enter DllMain -> Handle: 1832058880 - Reason for
Enter DllMain -> Handle: 1832058880 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1832058880 - Reason for
Enter DllMain -> Handle: 1832058880 - Reason for
Enter DllMain -> Handle: 1832058880 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1832058880 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1832058880 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1832058880 - Reason for
Enter DllMain -> Handle: 1832058880 - Reason for
Enter DllMain -> Handle: 1832058880 - Reason for
Enter DllMain -> Handle: 1800601600 - Reason for
Enter DllMain -> Handle: 1800601600 - Reason for
Enter DllMain -> Handle: 1800601600 - Reason for
Enter DllMain -> Handle: 1800601600 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback

16/03/16 14:14:49
A
16/03/16 14:14:49
A
16/03/16 14:14:49
A
16/03/16 14:14:49
A
16/03/16 14:14:49
A
16/03/16 14:14:49
D
call: DLL_PROCESS_ATTACH
16/03/16 14:14:50
D
call: DLL_PROCESS_ATTACH
16/03/16 14:14:50
D
call: DLL_PROCESS_ATTACH
16/03/16 14:14:50
A
16/03/16 14:14:50
D
call: DLL_PROCESS_DETACH
16/03/16 14:14:50
A
16/03/16 14:14:50
D
call: DLL_PROCESS_DETACH
16/03/16 14:14:50
A
16/03/16 14:14:50
D
call: DLL_PROCESS_DETACH

-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1800601600 - Reason for
Enter DllMain -> Handle: 1800601600 - Reason for
Enter DllMain -> Handle: 1800601600 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1800601600 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1800601600 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1800601600 - Reason for

You might also like