You are on page 1of 28

22/05/12 06:42:11

D
call: DLL_PROCESS_ATTACH
22/05/12 06:42:11
D
call: DLL_PROCESS_ATTACH
22/05/12 06:42:11
D
call: DLL_PROCESS_ATTACH
22/05/12 06:42:11
D
call: DLL_PROCESS_ATTACH
22/05/12 06:42:11
D
call: DLL_PROCESS_ATTACH
22/05/12 06:42:11
D
call: DLL_PROCESS_ATTACH
22/05/12 06:42:11
D
call: DLL_PROCESS_ATTACH
22/05/12 06:42:11
D
call: DLL_PROCESS_ATTACH
22/05/12 06:42:11
D
call: DLL_PROCESS_ATTACH
22/05/12 06:42:12
D
call: DLL_PROCESS_ATTACH
22/05/12 06:42:12
D
call: DLL_PROCESS_ATTACH
22/05/12 06:42:12
D
call: DLL_PROCESS_ATTACH
22/05/12 06:42:12
A
22/05/12 06:42:12
D
call: DLL_PROCESS_DETACH
22/05/12 06:42:18
A
22/05/12 06:42:18
D
call: DLL_PROCESS_DETACH
22/05/12 06:42:43
D
call: DLL_PROCESS_ATTACH
22/05/12 06:43:00
A
22/05/12 06:43:00
D
call: DLL_PROCESS_DETACH
22/05/12 06:43:07
D
call: DLL_PROCESS_ATTACH
22/05/12 06:43:24
A
22/05/12 06:43:24
A
22/05/12 06:43:24
D
call: DLL_PROCESS_DETACH
22/05/12 06:43:27
D
call: DLL_PROCESS_ATTACH
22/05/12 06:43:46
D
call: DLL_PROCESS_ATTACH
22/05/12 06:43:51
D
call: DLL_PROCESS_ATTACH
22/05/12 06:43:51
A
22/05/12 06:43:51
D
call: DLL_PROCESS_DETACH
22/05/12 06:43:51
D
call: DLL_PROCESS_ATTACH
22/05/12 06:43:55
A
22/05/12 06:43:55
D
call: DLL_PROCESS_DETACH
22/05/12 06:43:56
A
22/05/12 06:43:56
A
22/05/12 06:43:56
D
call: DLL_PROCESS_DETACH
22/05/12 06:43:58
A

Enter DllMain -> Handle: 4207542272 - Reason for


Enter DllMain -> Handle: 4207542272 - Reason for
Enter DllMain -> Handle: 4207542272 - Reason for
Enter DllMain -> Handle: 4207542272 - Reason for
Enter DllMain -> Handle: 4207542272 - Reason for
Enter DllMain -> Handle: 4207542272 - Reason for
Enter DllMain -> Handle: 4207542272 - Reason for
Enter DllMain -> Handle: 4207542272 - Reason for
Enter DllMain -> Handle: 4207542272 - Reason for
Enter DllMain -> Handle: 1931870208 - Reason for
Enter DllMain -> Handle: 1931870208 - Reason for
Enter DllMain -> Handle: 1931870208 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4207542272 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4207542272 - Reason for
Enter DllMain -> Handle: 4207542272 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4207542272 - Reason for
Enter DllMain -> Handle: 4207542272 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4207542272 - Reason for
Enter DllMain -> Handle: 1931870208 - Reason for
Enter DllMain -> Handle: 1931870208 - Reason for
Enter DllMain -> Handle: 4207542272 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1931870208 - Reason for
Enter DllMain -> Handle: 1931870208 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1931870208 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4207542272 - Reason for
-> NtTerminateProcessCallback

22/05/12 06:43:58
D
call: DLL_PROCESS_DETACH
22/05/12 06:43:59
D
call: DLL_PROCESS_ATTACH
22/05/12 06:43:59
D
call: DLL_PROCESS_ATTACH
22/05/12 06:44:10
D
call: DLL_PROCESS_ATTACH
22/05/12 06:44:17
A
22/05/12 06:44:17
D
call: DLL_PROCESS_DETACH
22/05/12 06:44:31
A
22/05/12 06:45:36
D
call: DLL_PROCESS_ATTACH
22/05/12 06:45:36
D
call: DLL_PROCESS_ATTACH
22/05/12 06:45:36
D
call: DLL_PROCESS_ATTACH
22/05/12 06:45:37
D
call: DLL_PROCESS_ATTACH
22/05/12 06:45:37
D
call: DLL_PROCESS_ATTACH
22/05/12 06:45:37
D
call: DLL_PROCESS_ATTACH
22/05/12 06:45:37
D
call: DLL_PROCESS_ATTACH
22/05/12 06:45:37
D
call: DLL_PROCESS_ATTACH
22/05/12 06:46:38
D
call: DLL_PROCESS_ATTACH
22/05/12 06:46:50
D
call: DLL_PROCESS_ATTACH
22/05/12 06:46:50
D
call: DLL_PROCESS_ATTACH
22/05/12 06:46:51
A
22/05/12 06:46:51
D
call: DLL_PROCESS_DETACH
22/05/12 06:46:55
A
22/05/12 06:46:55
A
22/05/12 06:46:55
D
call: DLL_PROCESS_DETACH
22/05/12 06:46:55
A
22/05/12 06:46:55
D
call: DLL_PROCESS_DETACH
22/05/12 06:46:57
D
call: DLL_PROCESS_ATTACH
22/05/12 06:46:57
D
call: DLL_PROCESS_ATTACH
22/05/12 06:47:00
D
call: DLL_PROCESS_ATTACH
22/05/12 06:47:00
D
call: DLL_PROCESS_ATTACH
22/05/12 06:47:00
A
22/05/12 06:47:00
D
call: DLL_PROCESS_DETACH
22/05/12 06:47:00
D
call: DLL_PROCESS_ATTACH
22/05/12 06:47:00
D
call: DLL_PROCESS_ATTACH
22/05/12 06:47:00
A

Enter DllMain -> Handle: 1931870208 - Reason for


Enter DllMain -> Handle: 4207542272 - Reason for
Enter DllMain -> Handle: 1931870208 - Reason for
Enter DllMain -> Handle: 4207542272 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4207542272 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4133748736 - Reason for
Enter DllMain -> Handle: 4133748736 - Reason for
Enter DllMain -> Handle: 4133748736 - Reason for
Enter DllMain -> Handle: 4133748736 - Reason for
Enter DllMain -> Handle: 1931214848 - Reason for
Enter DllMain -> Handle: 1931214848 - Reason for
Enter DllMain -> Handle: 1931214848 - Reason for
Enter DllMain -> Handle: 1931214848 - Reason for
Enter DllMain -> Handle: 4133748736 - Reason for
Enter DllMain -> Handle: 4133748736 - Reason for
Enter DllMain -> Handle: 4133748736 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4133748736 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4133748736 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4133748736 - Reason for
Enter DllMain -> Handle: 4133748736 - Reason for
Enter DllMain -> Handle: 1931214848 - Reason for
Enter DllMain -> Handle: 1931214848 - Reason for
Enter DllMain -> Handle: 4133748736 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4133748736 - Reason for
Enter DllMain -> Handle: 1931214848 - Reason for
Enter DllMain -> Handle: 4133748736 - Reason for
-> NtTerminateProcessCallback

22/05/12 06:47:00
D
call: DLL_PROCESS_DETACH
22/05/12 06:47:01
D
call: DLL_PROCESS_ATTACH
22/05/12 06:47:01
A
22/05/12 06:47:01
D
call: DLL_PROCESS_ATTACH
22/05/12 06:47:01
A
22/05/12 06:47:01
D
call: DLL_PROCESS_DETACH
22/05/12 06:47:01
D
call: DLL_PROCESS_ATTACH
22/05/12 06:47:01
D
call: DLL_PROCESS_DETACH
22/05/12 06:47:01
D
call: DLL_PROCESS_ATTACH
22/05/12 06:47:02
A
22/05/12 06:47:02
A
22/05/12 06:47:02
D
call: DLL_PROCESS_DETACH
22/05/12 06:47:02
D
call: DLL_PROCESS_ATTACH
22/05/12 06:47:02
A
22/05/12 06:47:02
D
call: DLL_PROCESS_DETACH
22/05/12 06:47:02
D
call: DLL_PROCESS_ATTACH
22/05/12 06:47:06
A
22/05/12 06:47:06
R
22/05/12 06:47:08
D
call: DLL_PROCESS_ATTACH
22/05/12 06:47:08
A
22/05/12 06:47:08
D
call: DLL_PROCESS_DETACH
22/05/12 06:47:08
D
call: DLL_PROCESS_ATTACH
22/05/12 06:47:08
A
22/05/12 06:47:08
D
call: DLL_PROCESS_DETACH
22/05/12 06:47:17
A
22/05/12 06:47:17
R
22/05/12 06:47:17
A
22/05/12 06:47:17
R
22/05/12 06:47:17
A
22/05/12 06:47:17
R
22/05/12 06:47:18
A
22/05/12 06:47:18
D
call: DLL_PROCESS_DETACH
22/05/12 06:47:18
D
call: DLL_PROCESS_ATTACH
22/05/12 06:47:19
D
call: DLL_PROCESS_ATTACH
22/05/12 06:47:19
A
22/05/12 06:47:19
D
call: DLL_PROCESS_DETACH
22/05/12 06:47:19
D
call: DLL_PROCESS_ATTACH
22/05/12 06:47:19
D
call: DLL_PROCESS_ATTACH
22/05/12 06:47:19
A

Enter DllMain -> Handle: 4133748736 - Reason for


Enter DllMain -> Handle: 1931214848 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4133748736 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4133748736 - Reason for
Enter DllMain -> Handle: 1931214848 - Reason for
Enter DllMain -> Handle: 1931214848 - Reason for
Enter DllMain -> Handle: 1931214848 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4133748736 - Reason for
Enter DllMain -> Handle: 4133748736 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4133748736 - Reason for
Enter DllMain -> Handle: 1931214848 - Reason for
-> NtTerminateProcessCallback
La victima es CHROME.EXE
Enter DllMain -> Handle: 4133748736 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4133748736 - Reason for
Enter DllMain -> Handle: 1931214848 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1931214848 - Reason for
-> NtTerminateProcessCallback
La victima es CHROME.EXE
-> NtTerminateProcessCallback
La victima es CHROME.EXE
-> NtTerminateProcessCallback
La victima es CHROME.EXE
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1931214848 - Reason for
Enter DllMain -> Handle: 1931214848 - Reason for
Enter DllMain -> Handle: 4133748736 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4133748736 - Reason for
Enter DllMain -> Handle: 1931214848 - Reason for
Enter DllMain -> Handle: 4133748736 - Reason for
-> NtTerminateProcessCallback

22/05/12 06:47:19
D
call: DLL_PROCESS_DETACH
22/05/12 06:47:19
D
call: DLL_PROCESS_ATTACH
22/05/12 06:47:19
D
call: DLL_PROCESS_ATTACH
22/05/12 06:47:21
A
22/05/12 06:47:21
R
22/05/12 06:47:21
A
22/05/12 06:47:21
R
22/05/12 06:47:22
A
22/05/12 06:47:22
R
22/05/12 06:47:22
A
22/05/12 06:47:22
D
call: DLL_PROCESS_DETACH
22/05/12 06:47:31
D
call: DLL_PROCESS_ATTACH
22/05/12 06:47:32
A
22/05/12 06:47:32
D
call: DLL_PROCESS_DETACH
22/05/12 06:47:45
A
22/05/12 06:57:25
D
call: DLL_PROCESS_ATTACH
22/05/12 06:57:25
D
call: DLL_PROCESS_ATTACH
22/05/12 06:57:25
D
call: DLL_PROCESS_ATTACH
22/05/12 06:57:26
D
call: DLL_PROCESS_ATTACH
22/05/12 06:57:27
D
call: DLL_PROCESS_ATTACH
22/05/12 06:57:27
D
call: DLL_PROCESS_ATTACH
22/05/12 06:57:27
D
call: DLL_PROCESS_ATTACH
22/05/12 06:57:27
D
call: DLL_PROCESS_ATTACH
22/05/12 06:57:45
A
22/05/12 06:57:45
D
call: DLL_PROCESS_DETACH
22/05/12 07:00:08
D
call: DLL_PROCESS_ATTACH
22/05/12 07:00:16
D
call: DLL_PROCESS_ATTACH
22/05/12 07:00:16
D
call: DLL_PROCESS_ATTACH
22/05/12 07:00:18
A
22/05/12 07:00:18
A
22/05/12 07:00:18
D
call: DLL_PROCESS_DETACH
22/05/12 07:00:25
D
call: DLL_PROCESS_ATTACH
22/05/12 07:00:27
D
call: DLL_PROCESS_ATTACH
22/05/12 07:00:27
D
call: DLL_PROCESS_ATTACH
22/05/12 07:00:27
D
call: DLL_PROCESS_ATTACH
22/05/12 07:00:28
A
22/05/12 07:00:28
D

Enter DllMain -> Handle: 4133748736 - Reason for


Enter DllMain -> Handle: 1931214848 - Reason for
Enter DllMain -> Handle: 1931214848 - Reason for
-> NtTerminateProcessCallback
La victima es CHROME.EXE
-> NtTerminateProcessCallback
La victima es CHROME.EXE
-> NtTerminateProcessCallback
La victima es CHROME.EXE
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1931214848 - Reason for
Enter DllMain -> Handle: 1931214848 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1931214848 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4109631488 - Reason for
Enter DllMain -> Handle: 4109631488 - Reason for
Enter DllMain -> Handle: 4109631488 - Reason for
Enter DllMain -> Handle: 4109631488 - Reason for
Enter DllMain -> Handle: 1931935744 - Reason for
Enter DllMain -> Handle: 1931935744 - Reason for
Enter DllMain -> Handle: 1931935744 - Reason for
Enter DllMain -> Handle: 1931935744 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4109631488 - Reason for
Enter DllMain -> Handle: 4109631488 - Reason for
Enter DllMain -> Handle: 1931935744 - Reason for
Enter DllMain -> Handle: 1931935744 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4109631488 - Reason for
Enter DllMain -> Handle: 1931935744 - Reason for
Enter DllMain -> Handle: 1931935744 - Reason for
Enter DllMain -> Handle: 1931935744 - Reason for
Enter DllMain -> Handle: 4109631488 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4109631488 - Reason for

call: DLL_PROCESS_ATTACH
22/05/12 07:00:28
D
call: DLL_PROCESS_DETACH
22/05/12 07:00:28
D
call: DLL_PROCESS_ATTACH
22/05/12 07:00:28
D
call: DLL_PROCESS_ATTACH
22/05/12 07:00:28
D
call: DLL_PROCESS_ATTACH
22/05/12 07:00:28
D
call: DLL_PROCESS_ATTACH
22/05/12 07:00:28
A
22/05/12 07:00:28
A
22/05/12 07:00:28
A
22/05/12 07:00:28
A
22/05/12 07:00:28
D
call: DLL_PROCESS_ATTACH
22/05/12 07:00:28
A
22/05/12 07:00:28
A
22/05/12 07:00:28
A
22/05/12 07:00:28
A
22/05/12 07:00:28
A
22/05/12 07:00:28
A
22/05/12 07:00:28
A
22/05/12 07:00:28
A
22/05/12 07:00:28
A
22/05/12 07:00:28
A
22/05/12 07:00:28
A
22/05/12 07:00:28
A
22/05/12 07:00:28
A
22/05/12 07:00:28
A
22/05/12 07:00:28
A
22/05/12 07:00:28
D
call: DLL_PROCESS_DETACH
22/05/12 07:00:28
A
22/05/12 07:00:28
D
call: DLL_PROCESS_ATTACH
22/05/12 07:00:28
D
call: DLL_PROCESS_ATTACH
22/05/12 07:00:28
D
call: DLL_PROCESS_ATTACH
22/05/12 07:00:28
D
call: DLL_PROCESS_ATTACH
22/05/12 07:00:28
A
22/05/12 07:00:28
A
22/05/12 07:00:28
A
22/05/12 07:00:28
A
22/05/12 07:00:28
D
call: DLL_PROCESS_ATTACH
22/05/12 07:00:28
D
call: DLL_PROCESS_ATTACH
22/05/12 07:00:29
D
call: DLL_PROCESS_ATTACH
22/05/12 07:00:29
A
22/05/12 07:00:29
A
22/05/12 07:00:29
A
22/05/12 07:00:29
D
call: DLL_PROCESS_ATTACH
22/05/12 07:00:29
A
22/05/12 07:00:29
D

Enter DllMain -> Handle: 1931935744 - Reason for


Enter DllMain -> Handle: 4109631488 - Reason for
Enter DllMain -> Handle: 4109631488 - Reason for
Enter DllMain -> Handle: 4109631488 - Reason for
Enter DllMain -> Handle: 4109631488 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1931935744 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1931935744 - Reason for
-> CreateDCWCallback
Enter DllMain -> Handle: 4109631488 - Reason for
Enter DllMain -> Handle: 1931935744 - Reason for
Enter DllMain -> Handle: 1931935744 - Reason for
Enter DllMain -> Handle: 1931935744 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1931935744 - Reason for
Enter DllMain -> Handle: 4109631488 - Reason for
Enter DllMain -> Handle: 1931935744 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1931935744 - Reason for
-> CreateDCWCallback
Enter DllMain -> Handle: 1931935744 - Reason for

call: DLL_PROCESS_ATTACH
22/05/12 07:00:29
A
22/05/12 07:00:29
D
call: DLL_PROCESS_DETACH
22/05/12 07:00:32
A
22/05/12 07:02:24
D
call: DLL_PROCESS_ATTACH
22/05/12 07:02:24
D
call: DLL_PROCESS_ATTACH
22/05/12 07:02:24
D
call: DLL_PROCESS_ATTACH
22/05/12 07:02:24
D
call: DLL_PROCESS_ATTACH
22/05/12 07:02:24
D
call: DLL_PROCESS_ATTACH
22/05/12 07:02:24
D
call: DLL_PROCESS_ATTACH
22/05/12 07:02:24
D
call: DLL_PROCESS_ATTACH
22/05/12 07:02:32
D
call: DLL_PROCESS_ATTACH
22/05/12 07:02:40
A
22/05/12 07:02:40
A
22/05/12 07:02:40
D
call: DLL_PROCESS_DETACH
22/05/12 07:02:45
D
call: DLL_PROCESS_ATTACH
22/05/12 07:02:45
D
call: DLL_PROCESS_ATTACH
22/05/12 07:02:52
A
22/05/12 07:02:52
D
call: DLL_PROCESS_DETACH
22/05/12 07:02:52
A
22/05/12 07:02:52
D
call: DLL_PROCESS_DETACH
22/05/12 07:02:54
D
call: DLL_PROCESS_ATTACH
22/05/12 07:02:54
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:06
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:07
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:07
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:08
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:08
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:08
A
22/05/12 07:03:08
A
22/05/12 07:03:08
A
22/05/12 07:03:08
A
22/05/12 07:03:08
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:08
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:08
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:08
D

-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1931935744 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4082237440 - Reason for
Enter DllMain -> Handle: 4082237440 - Reason for
Enter DllMain -> Handle: 4082237440 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 4082237440 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4082237440 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1925840896 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 4082237440 - Reason for
Enter DllMain -> Handle: 4082237440 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 4082237440 - Reason for
Enter DllMain -> Handle: 4082237440 - Reason for
Enter DllMain -> Handle: 4082237440 - Reason for

call: DLL_PROCESS_ATTACH
22/05/12 07:03:08
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:08
A
22/05/12 07:03:08
A
22/05/12 07:03:08
A
22/05/12 07:03:08
A
22/05/12 07:03:08
A
22/05/12 07:03:08
A
22/05/12 07:03:08
A
22/05/12 07:03:08
A
22/05/12 07:03:08
A
22/05/12 07:03:08
A
22/05/12 07:03:08
A
22/05/12 07:03:08
A
22/05/12 07:03:08
A
22/05/12 07:03:08
A
22/05/12 07:03:08
A
22/05/12 07:03:08
A
22/05/12 07:03:08
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:08
A
22/05/12 07:03:08
D
call: DLL_PROCESS_DETACH
22/05/12 07:03:08
A
22/05/12 07:03:09
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:09
D
call: DLL_PROCESS_DETACH
22/05/12 07:03:09
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:09
A
22/05/12 07:03:09
A
22/05/12 07:03:09
A
22/05/12 07:03:09
A
22/05/12 07:03:09
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:09
A
22/05/12 07:03:09
A
22/05/12 07:03:09
A
22/05/12 07:03:09
A
22/05/12 07:03:09
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:09
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:09
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:09
A
22/05/12 07:03:09
A
22/05/12 07:03:09
A
22/05/12 07:03:09
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:09
A
22/05/12 07:03:09
A
22/05/12 07:03:09
A
22/05/12 07:03:09
A
22/05/12 07:03:09
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:09
D
call: DLL_PROCESS_ATTACH

Enter DllMain -> Handle: 4082237440 - Reason for


-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 4082237440 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4082237440 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 4082237440 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 4082237440 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 4082237440 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 4082237440 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for

22/05/12 07:03:09
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:09
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:09
A
22/05/12 07:03:09
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:09
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:09
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:09
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:09
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:09
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:09
A
22/05/12 07:03:09
A
22/05/12 07:03:09
D
call: DLL_PROCESS_DETACH
22/05/12 07:03:09
D
call: DLL_PROCESS_DETACH
22/05/12 07:03:09
A
22/05/12 07:03:09
D
call: DLL_PROCESS_DETACH
22/05/12 07:03:09
A
22/05/12 07:03:09
D
call: DLL_PROCESS_DETACH
22/05/12 07:03:10
A
22/05/12 07:03:10
A
22/05/12 07:03:10
D
call: DLL_PROCESS_DETACH
22/05/12 07:03:10
A
22/05/12 07:03:10
D
call: DLL_PROCESS_DETACH
22/05/12 07:03:10
A
22/05/12 07:03:10
D
call: DLL_PROCESS_DETACH
22/05/12 07:03:11
A
22/05/12 07:03:11
D
call: DLL_PROCESS_DETACH
22/05/12 07:03:12
A
22/05/12 07:03:12
D
call: DLL_PROCESS_DETACH
22/05/12 07:03:13
A
22/05/12 07:03:13
A
22/05/12 07:03:13
D
call: DLL_PROCESS_DETACH
22/05/12 07:03:14
A
22/05/12 07:03:14
A
22/05/12 07:03:14
D
call: DLL_PROCESS_DETACH
22/05/12 07:03:14
D
call: DLL_PROCESS_DETACH
22/05/12 07:03:14
A
22/05/12 07:03:14
A
22/05/12 07:03:14
D
call: DLL_PROCESS_DETACH
22/05/12 07:03:14
D

Enter DllMain -> Handle: 1925840896 - Reason for


Enter DllMain -> Handle: 1925840896 - Reason for
-> CreateDCWCallback
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1925840896 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1925840896 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1925840896 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1925840896 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1925840896 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1925840896 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1925840896 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4082237440 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 1925840896 - Reason for

call: DLL_PROCESS_DETACH
22/05/12 07:03:18
A
22/05/12 07:03:18
D
call: DLL_PROCESS_DETACH
22/05/12 07:03:18
A
22/05/12 07:03:19
D
call: DLL_PROCESS_DETACH
22/05/12 07:03:19
A
22/05/12 07:03:19
D
call: DLL_PROCESS_DETACH
22/05/12 07:03:19
A
22/05/12 07:03:19
D
call: DLL_PROCESS_DETACH
22/05/12 07:03:19
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:19
A
22/05/12 07:03:19
A
22/05/12 07:03:19
A
22/05/12 07:03:19
A
22/05/12 07:03:19
D
call: DLL_PROCESS_ATTACH
22/05/12 07:03:19
A
22/05/12 07:03:19
D
call: DLL_PROCESS_DETACH
22/05/12 07:03:20
A
22/05/12 01:05:09
D
call: DLL_PROCESS_ATTACH
22/05/12 01:05:09
D
call: DLL_PROCESS_ATTACH
22/05/12 01:05:09
D
call: DLL_PROCESS_ATTACH
22/05/12 01:05:09
D
call: DLL_PROCESS_ATTACH
22/05/12 01:05:09
D
call: DLL_PROCESS_ATTACH
22/05/12 01:05:09
D
call: DLL_PROCESS_ATTACH
22/05/12 01:05:09
D
call: DLL_PROCESS_ATTACH
22/05/12 01:05:09
D
call: DLL_PROCESS_ATTACH
22/05/12 01:05:09
D
call: DLL_PROCESS_ATTACH
22/05/12 01:05:09
D
call: DLL_PROCESS_ATTACH
22/05/12 01:05:09
A
22/05/12 01:05:09
A
22/05/12 01:05:09
R
22/05/12 01:05:09
A
22/05/12 01:05:09
R
22/05/12 01:05:09
A
22/05/12 01:05:09
R
22/05/12 01:05:09
D
call: DLL_PROCESS_ATTACH
22/05/12 01:05:15
D
call: DLL_PROCESS_ATTACH
22/05/12 01:05:15
D
call: DLL_PROCESS_ATTACH
22/05/12 01:05:17
D
call: DLL_PROCESS_ATTACH

-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1925840896 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1925840896 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1925840896 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1925840896 - Reason for
Enter DllMain -> Handle: 4082237440 - Reason for
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
-> CreateDCWCallback
Enter DllMain -> Handle: 1925840896 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1925840896 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4080467968 - Reason for
Enter DllMain -> Handle: 4080467968 - Reason for
Enter DllMain -> Handle: 4080467968 - Reason for
Enter DllMain -> Handle: 4080467968 - Reason for
Enter DllMain -> Handle: 4080467968 - Reason for
Enter DllMain -> Handle: 4080467968 - Reason for
Enter DllMain -> Handle: 1959854080 - Reason for
Enter DllMain -> Handle: 1959854080 - Reason for
Enter DllMain -> Handle: 1959854080 - Reason for
Enter DllMain -> Handle: 1959854080 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Dejamos matar a VIGIA.EXE
-> NtTerminateProcessCallback
Dejamos matar a
-> NtTerminateProcessCallback
Dejamos matar a
Enter DllMain -> Handle: 1959854080 - Reason for
Enter DllMain -> Handle: 1959854080 - Reason for
Enter DllMain -> Handle: 1959854080 - Reason for
Enter DllMain -> Handle: 1959854080 - Reason for

22/05/12 01:05:28
A
22/05/12 01:05:28
A
22/05/12 01:05:28
D
call: DLL_PROCESS_DETACH
22/05/12 01:05:28
D
call: DLL_PROCESS_DETACH
22/05/12 01:05:28
D
call: DLL_PROCESS_DETACH
22/05/12 01:05:28
A
22/05/12 01:05:28
A
22/05/12 01:05:28
D
call: DLL_PROCESS_DETACH
22/05/12 01:05:28
D
call: DLL_PROCESS_DETACH
22/05/12 01:05:28
D
call: DLL_PROCESS_DETACH
22/05/12 01:05:28
D
call: DLL_PROCESS_DETACH
22/05/12 01:05:28
D
call: DLL_PROCESS_DETACH
22/05/12 01:05:28
D
call: DLL_PROCESS_DETACH
22/05/12 01:05:28
D
call: DLL_PROCESS_DETACH
22/05/12 01:05:28
D
call: DLL_PROCESS_DETACH
24/05/12 10:17:37
D
call: DLL_PROCESS_ATTACH
24/05/12 10:17:37
D
call: DLL_PROCESS_ATTACH
24/05/12 10:17:37
D
call: DLL_PROCESS_ATTACH
24/05/12 10:17:37
D
call: DLL_PROCESS_ATTACH
24/05/12 10:17:37
D
call: DLL_PROCESS_ATTACH
24/05/12 10:17:37
A
24/05/12 10:17:37
A
24/05/12 10:17:37
R
24/05/12 10:17:37
D
call: DLL_PROCESS_ATTACH
24/05/12 10:17:43
A
24/05/12 10:17:43
D
call: DLL_PROCESS_DETACH
24/05/12 10:17:53
D
call: DLL_PROCESS_ATTACH
24/05/12 10:17:53
D
call: DLL_PROCESS_ATTACH
24/05/12 10:18:07
D
call: DLL_PROCESS_ATTACH
24/05/12 10:23:00
D
call: DLL_PROCESS_ATTACH
24/05/12 10:23:00
D
call: DLL_PROCESS_ATTACH
24/05/12 10:24:20
D
call: DLL_PROCESS_DETACH
24/05/12 10:24:20
D
call: DLL_PROCESS_DETACH
24/05/12 10:24:20
D
call: DLL_PROCESS_DETACH

-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4080467968 - Reason for
Enter DllMain -> Handle: 4080467968 - Reason for
Enter DllMain -> Handle: 4080467968 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4080467968 - Reason for
Enter DllMain -> Handle: 4080467968 - Reason for
Enter DllMain -> Handle: 4080467968 - Reason for
Enter DllMain -> Handle: 1959854080 - Reason for
Enter DllMain -> Handle: 1959854080 - Reason for
Enter DllMain -> Handle: 1959854080 - Reason for
Enter DllMain -> Handle: 1959854080 - Reason for
Enter DllMain -> Handle: 1959854080 - Reason for
Enter DllMain -> Handle: 4089905152 - Reason for
Enter DllMain -> Handle: 4089905152 - Reason for
Enter DllMain -> Handle: 1931870208 - Reason for
Enter DllMain -> Handle: 1931870208 - Reason for
Enter DllMain -> Handle: 1931870208 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Dejamos matar a VIGIA.EXE
Enter DllMain -> Handle: 1931870208 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4089905152 - Reason for
Enter DllMain -> Handle: 1931870208 - Reason for
Enter DllMain -> Handle: 1931870208 - Reason for
Enter DllMain -> Handle: 1931870208 - Reason for
Enter DllMain -> Handle: 4089905152 - Reason for
Enter DllMain -> Handle: 1931870208 - Reason for
Enter DllMain -> Handle: 4089905152 - Reason for
Enter DllMain -> Handle: 4089905152 - Reason for
Enter DllMain -> Handle: 4089905152 - Reason for

24/05/12 10:24:20
D
call: DLL_PROCESS_DETACH
24/05/12 10:24:20
D
call: DLL_PROCESS_DETACH
24/05/12 10:24:20
D
call: DLL_PROCESS_DETACH
24/05/12 10:24:20
D
call: DLL_PROCESS_DETACH
24/05/12 10:24:20
D
call: DLL_PROCESS_DETACH
24/05/12 10:24:20
D
call: DLL_PROCESS_DETACH
24/05/12 10:24:20
D
call: DLL_PROCESS_DETACH
24/05/12 10:24:20
D
call: DLL_PROCESS_DETACH
24/05/12 10:24:20
D
call: DLL_PROCESS_DETACH
24/05/12 10:24:20
D
call: DLL_PROCESS_DETACH
24/05/12 13:43:57
D
call: DLL_PROCESS_ATTACH
24/05/12 13:43:57
D
call: DLL_PROCESS_ATTACH
24/05/12 13:43:57
D
call: DLL_PROCESS_ATTACH
24/05/12 13:43:57
D
call: DLL_PROCESS_ATTACH
24/05/12 13:43:57
D
call: DLL_PROCESS_ATTACH
24/05/12 13:43:57
A
24/05/12 13:43:57
A
24/05/12 13:43:57
R
24/05/12 13:43:57
A
24/05/12 13:43:57
R
24/05/12 13:43:57
A
24/05/12 13:43:57
R
24/05/12 13:43:57
D
call: DLL_PROCESS_ATTACH
24/05/12 13:44:07
A
24/05/12 13:44:07
D
call: DLL_PROCESS_DETACH
24/05/12 13:44:13
D
call: DLL_PROCESS_ATTACH
24/05/12 13:44:13
D
call: DLL_PROCESS_ATTACH
24/05/12 13:44:27
D
call: DLL_PROCESS_ATTACH
24/05/12 13:51:13
D
call: DLL_PROCESS_ATTACH
24/05/12 13:51:13
A
24/05/12 13:51:13
D
call: DLL_PROCESS_DETACH
24/05/12 13:56:35
D
call: DLL_PROCESS_ATTACH
24/05/12 13:56:35
A
24/05/12 13:56:35
D
call: DLL_PROCESS_DETACH
24/05/12 13:58:34
D
call: DLL_PROCESS_ATTACH

Enter DllMain -> Handle: 4089905152 - Reason for


Enter DllMain -> Handle: 4089905152 - Reason for
Enter DllMain -> Handle: 4089905152 - Reason for
Enter DllMain -> Handle: 4089905152 - Reason for
Enter DllMain -> Handle: 1931870208 - Reason for
Enter DllMain -> Handle: 1931870208 - Reason for
Enter DllMain -> Handle: 1931870208 - Reason for
Enter DllMain -> Handle: 1931870208 - Reason for
Enter DllMain -> Handle: 1931870208 - Reason for
Enter DllMain -> Handle: 1931870208 - Reason for
Enter DllMain -> Handle: 4079943680 - Reason for
Enter DllMain -> Handle: 4079943680 - Reason for
Enter DllMain -> Handle: 1919352832 - Reason for
Enter DllMain -> Handle: 213450752 - Reason for
Enter DllMain -> Handle: 1919352832 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Dejamos matar a VIGIA.EXE
-> NtTerminateProcessCallback
Dejamos matar a
-> NtTerminateProcessCallback
Dejamos matar a
Enter DllMain -> Handle: 1919352832 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4079943680 - Reason for
Enter DllMain -> Handle: 1919352832 - Reason for
Enter DllMain -> Handle: 1919352832 - Reason for
Enter DllMain -> Handle: 1919352832 - Reason for
Enter DllMain -> Handle: 1919352832 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919352832 - Reason for
Enter DllMain -> Handle: 4079943680 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4079943680 - Reason for
Enter DllMain -> Handle: 4079943680 - Reason for

24/05/12 13:58:34
D
call: DLL_PROCESS_ATTACH
24/05/12 13:58:39
A
24/05/12 14:03:34
A
24/05/12 14:03:34
D
call: DLL_PROCESS_DETACH
24/05/12 14:23:00
D
call: DLL_PROCESS_ATTACH
24/05/12 14:23:00
D
call: DLL_PROCESS_ATTACH
24/05/12 14:23:00
A
24/05/12 14:23:00
D
call: DLL_PROCESS_DETACH
24/05/12 14:27:11
A
24/05/12 14:27:11
A
24/05/12 14:27:11
R
24/05/12 14:27:11
A
24/05/12 14:27:11
R
24/05/12 14:27:11
A
24/05/12 14:27:11
R
24/05/12 14:27:12
D
call: DLL_PROCESS_ATTACH
24/05/12 14:28:00
A
24/05/12 14:28:00
D
call: DLL_PROCESS_DETACH
24/05/12 14:31:39
D
call: DLL_PROCESS_DETACH
24/05/12 14:31:39
D
call: DLL_PROCESS_DETACH
24/05/12 14:31:39
D
call: DLL_PROCESS_DETACH
24/05/12 14:31:39
D
call: DLL_PROCESS_DETACH
24/05/12 14:31:39
D
call: DLL_PROCESS_DETACH
24/05/12 14:31:39
D
call: DLL_PROCESS_DETACH
24/05/12 14:31:39
D
call: DLL_PROCESS_DETACH
24/05/12 14:31:39
D
call: DLL_PROCESS_DETACH
24/05/12 14:31:39
D
call: DLL_PROCESS_DETACH
24/05/12 14:31:39
D
call: DLL_PROCESS_DETACH
24/05/12 14:31:39
D
call: DLL_PROCESS_DETACH
24/05/12 14:31:39
D
call: DLL_PROCESS_DETACH
24/05/12 14:31:39
D
call: DLL_PROCESS_DETACH
24/05/12 14:31:39
D
call: DLL_PROCESS_DETACH
24/05/12 14:40:21
D
call: DLL_PROCESS_ATTACH
24/05/12 14:40:21
D
call: DLL_PROCESS_ATTACH
24/05/12 14:40:21
D
call: DLL_PROCESS_ATTACH
24/05/12 14:40:21
D

Enter DllMain -> Handle: 1919352832 - Reason for


-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4079943680 - Reason for
Enter DllMain -> Handle: 4079943680 - Reason for
Enter DllMain -> Handle: 1919352832 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919352832 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Dejamos matar a VIGIA.EXE
-> NtTerminateProcessCallback
Dejamos matar a
-> NtTerminateProcessCallback
Dejamos matar a
Enter DllMain -> Handle: 1919352832 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4079943680 - Reason for
Enter DllMain -> Handle: 4079943680 - Reason for
Enter DllMain -> Handle: 4079943680 - Reason for
Enter DllMain -> Handle: 4079943680 - Reason for
Enter DllMain -> Handle: 4079943680 - Reason for
Enter DllMain -> Handle: 4079943680 - Reason for
Enter DllMain -> Handle: 4079943680 - Reason for
Enter DllMain -> Handle: 4079943680 - Reason for
Enter DllMain -> Handle: 1919352832 - Reason for
Enter DllMain -> Handle: 1919352832 - Reason for
Enter DllMain -> Handle: 1919352832 - Reason for
Enter DllMain -> Handle: 1919352832 - Reason for
Enter DllMain -> Handle: 213450752 - Reason for
Enter DllMain -> Handle: 1919352832 - Reason for
Enter DllMain -> Handle: 1919352832 - Reason for
Enter DllMain -> Handle: 4070440960 - Reason for
Enter DllMain -> Handle: 4070440960 - Reason for
Enter DllMain -> Handle: 1921843200 - Reason for
Enter DllMain -> Handle: 1921843200 - Reason for

call: DLL_PROCESS_ATTACH
24/05/12 14:40:21
D
call: DLL_PROCESS_ATTACH
24/05/12 14:40:21
A
24/05/12 14:40:21
A
24/05/12 14:40:21
R
24/05/12 14:40:21
A
24/05/12 14:40:21
R
24/05/12 14:40:21
A
24/05/12 14:40:21
R
24/05/12 14:40:21
D
call: DLL_PROCESS_ATTACH
24/05/12 14:40:37
D
call: DLL_PROCESS_ATTACH
24/05/12 14:40:38
D
call: DLL_PROCESS_ATTACH
24/05/12 14:40:51
D
call: DLL_PROCESS_ATTACH
24/05/12 14:40:59
D
call: DLL_PROCESS_ATTACH
24/05/12 14:40:59
A
24/05/12 14:40:59
D
call: DLL_PROCESS_DETACH
24/05/12 14:41:09
A
24/05/12 14:41:09
D
call: DLL_PROCESS_DETACH
24/05/12 14:52:38
D
call: DLL_PROCESS_ATTACH
24/05/12 14:52:38
A
24/05/12 14:52:38
D
call: DLL_PROCESS_DETACH
24/05/12 14:54:38
D
call: DLL_PROCESS_ATTACH
24/05/12 14:54:38
D
call: DLL_PROCESS_ATTACH
24/05/12 14:54:44
A
24/05/12 14:59:39
A
24/05/12 14:59:39
D
call: DLL_PROCESS_DETACH
24/05/12 15:04:58
D
call: DLL_PROCESS_DETACH
24/05/12 15:04:58
D
call: DLL_PROCESS_DETACH
24/05/12 15:04:58
D
call: DLL_PROCESS_DETACH
24/05/12 15:04:58
D
call: DLL_PROCESS_DETACH
24/05/12 15:04:58
D
call: DLL_PROCESS_DETACH
24/05/12 15:04:58
D
call: DLL_PROCESS_DETACH
24/05/12 15:04:58
D
call: DLL_PROCESS_DETACH
24/05/12 15:04:58
D
call: DLL_PROCESS_DETACH
24/05/12 15:04:58
D
call: DLL_PROCESS_DETACH
24/05/12 15:04:58
D
call: DLL_PROCESS_DETACH
24/05/12 15:04:58
D

Enter DllMain -> Handle: 1921843200 - Reason for


-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Dejamos matar a VIGIA.EXE
-> NtTerminateProcessCallback
Dejamos matar a VIGIA.EXE
-> NtTerminateProcessCallback
Dejamos matar a VIGIA.EXE
Enter DllMain -> Handle: 1921843200 - Reason for
Enter DllMain -> Handle: 1921843200 - Reason for
Enter DllMain -> Handle: 1921843200 - Reason for
Enter DllMain -> Handle: 1921843200 - Reason for
Enter DllMain -> Handle: 4070440960 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4070440960 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4070440960 - Reason for
Enter DllMain -> Handle: 4070440960 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4070440960 - Reason for
Enter DllMain -> Handle: 4070440960 - Reason for
Enter DllMain -> Handle: 1921843200 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4070440960 - Reason for
Enter DllMain -> Handle: 4070440960 - Reason for
Enter DllMain -> Handle: 4070440960 - Reason for
Enter DllMain -> Handle: 4070440960 - Reason for
Enter DllMain -> Handle: 4070440960 - Reason for
Enter DllMain -> Handle: 4070440960 - Reason for
Enter DllMain -> Handle: 4070440960 - Reason for
Enter DllMain -> Handle: 4070440960 - Reason for
Enter DllMain -> Handle: 4070440960 - Reason for
Enter DllMain -> Handle: 1921843200 - Reason for
Enter DllMain -> Handle: 1921843200 - Reason for
Enter DllMain -> Handle: 1921843200 - Reason for

call: DLL_PROCESS_DETACH
24/05/12 15:04:58
D
call: DLL_PROCESS_DETACH
24/05/12 15:04:58
D
call: DLL_PROCESS_DETACH
24/05/12 15:04:58
D
call: DLL_PROCESS_DETACH
24/05/12 18:39:07
D
call: DLL_PROCESS_ATTACH
24/05/12 18:39:07
D
call: DLL_PROCESS_ATTACH
24/05/12 18:39:07
D
call: DLL_PROCESS_ATTACH
24/05/12 18:39:08
D
call: DLL_PROCESS_ATTACH
24/05/12 18:39:08
D
call: DLL_PROCESS_ATTACH
24/05/12 18:39:08
D
call: DLL_PROCESS_ATTACH
24/05/12 18:39:08
D
call: DLL_PROCESS_ATTACH
24/05/12 18:39:08
D
call: DLL_PROCESS_ATTACH
24/05/12 18:39:08
D
call: DLL_PROCESS_ATTACH
24/05/12 18:39:08
D
call: DLL_PROCESS_ATTACH
24/05/12 18:39:08
A
24/05/12 18:39:08
A
24/05/12 18:39:08
R
24/05/12 18:39:08
A
24/05/12 18:39:08
R
24/05/12 18:39:08
A
24/05/12 18:39:08
R
24/05/12 18:39:08
D
call: DLL_PROCESS_ATTACH
24/05/12 18:39:16
D
call: DLL_PROCESS_ATTACH
24/05/12 18:39:26
A
24/05/12 18:39:26
D
call: DLL_PROCESS_DETACH
24/05/12 18:40:52
A
24/05/12 18:40:52
A
24/05/12 18:40:52
D
call: DLL_PROCESS_DETACH
24/05/12 18:40:52
D
call: DLL_PROCESS_DETACH
24/05/12 18:40:52
D
call: DLL_PROCESS_DETACH
24/05/12 18:40:52
D
call: DLL_PROCESS_DETACH
24/05/12 18:40:52
D
call: DLL_PROCESS_DETACH
24/05/12 18:40:52
D
call: DLL_PROCESS_DETACH
24/05/12 18:40:52
D
call: DLL_PROCESS_DETACH
24/05/12 18:40:52
A
24/05/12 18:40:52
D
call: DLL_PROCESS_DETACH

Enter DllMain -> Handle: 1921843200 - Reason for


Enter DllMain -> Handle: 1921843200 - Reason for
Enter DllMain -> Handle: 1921843200 - Reason for
Enter DllMain -> Handle: 4113694720 - Reason for
Enter DllMain -> Handle: 4113694720 - Reason for
Enter DllMain -> Handle: 4113694720 - Reason for
Enter DllMain -> Handle: 4113694720 - Reason for
Enter DllMain -> Handle: 1933443072 - Reason for
Enter DllMain -> Handle: 1933443072 - Reason for
Enter DllMain -> Handle: 1933443072 - Reason for
Enter DllMain -> Handle: 1933443072 - Reason for
Enter DllMain -> Handle: 1933443072 - Reason for
Enter DllMain -> Handle: 1933443072 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Dejamos matar a VIGIA.EXE
-> NtTerminateProcessCallback
Dejamos matar a
-> NtTerminateProcessCallback
Dejamos matar a
Enter DllMain -> Handle: 1933443072 - Reason for
Enter DllMain -> Handle: 1933443072 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4113694720 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4113694720 - Reason for
Enter DllMain -> Handle: 4113694720 - Reason for
Enter DllMain -> Handle: 4113694720 - Reason for
Enter DllMain -> Handle: 4113694720 - Reason for
Enter DllMain -> Handle: 4113694720 - Reason for
Enter DllMain -> Handle: 4113694720 - Reason for
Enter DllMain -> Handle: 4113694720 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1933443072 - Reason for

24/05/12 18:40:52
D
call: DLL_PROCESS_DETACH
24/05/12 18:40:52
D
call: DLL_PROCESS_DETACH
24/05/12 18:40:52
A
24/05/12 18:40:52
D
call: DLL_PROCESS_DETACH
24/05/12 18:40:52
D
call: DLL_PROCESS_DETACH
25/05/12 11:42:20
D
call: DLL_PROCESS_ATTACH
25/05/12 11:42:20
D
call: DLL_PROCESS_ATTACH
25/05/12 11:42:20
D
call: DLL_PROCESS_ATTACH
25/05/12 11:42:20
D
call: DLL_PROCESS_ATTACH
25/05/12 11:42:20
D
call: DLL_PROCESS_ATTACH
25/05/12 11:42:20
D
call: DLL_PROCESS_ATTACH
25/05/12 11:42:20
A
25/05/12 11:42:20
A
25/05/12 11:42:20
R
25/05/12 11:42:20
A
25/05/12 11:42:20
R
25/05/12 11:42:20
A
25/05/12 11:42:20
R
25/05/12 11:42:20
D
call: DLL_PROCESS_ATTACH
25/05/12 11:42:22
A
25/05/12 11:42:22
D
call: DLL_PROCESS_DETACH
25/05/12 11:42:25
D
call: DLL_PROCESS_ATTACH
25/05/12 11:42:25
D
call: DLL_PROCESS_ATTACH
25/05/12 11:42:28
D
call: DLL_PROCESS_ATTACH
25/05/12 11:42:38
D
call: DLL_PROCESS_DETACH
25/05/12 11:42:38
D
call: DLL_PROCESS_DETACH
25/05/12 11:42:38
D
call: DLL_PROCESS_DETACH
25/05/12 11:42:38
D
call: DLL_PROCESS_DETACH
25/05/12 11:42:38
D
call: DLL_PROCESS_DETACH
25/05/12 11:42:38
D
call: DLL_PROCESS_DETACH
25/05/12 11:42:38
D
call: DLL_PROCESS_DETACH
25/05/12 11:42:38
D
call: DLL_PROCESS_DETACH
25/05/12 11:42:38
D
call: DLL_PROCESS_DETACH
25/05/12 11:42:38
D
call: DLL_PROCESS_DETACH
25/05/12 11:42:38
D

Enter DllMain -> Handle: 1933443072 - Reason for


Enter DllMain -> Handle: 1933443072 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1933443072 - Reason for
Enter DllMain -> Handle: 1933443072 - Reason for
Enter DllMain -> Handle: 4090626048 - Reason for
Enter DllMain -> Handle: 4090626048 - Reason for
Enter DllMain -> Handle: 1930362880 - Reason for
Enter DllMain -> Handle: 1930362880 - Reason for
Enter DllMain -> Handle: 1930362880 - Reason for
Enter DllMain -> Handle: 1930362880 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Dejamos matar a VIGIA.EXE
-> NtTerminateProcessCallback
Dejamos matar a
-> NtTerminateProcessCallback
Dejamos matar a
Enter DllMain -> Handle: 1930362880 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4090626048 - Reason for
Enter DllMain -> Handle: 1930362880 - Reason for
Enter DllMain -> Handle: 1930362880 - Reason for
Enter DllMain -> Handle: 1930362880 - Reason for
Enter DllMain -> Handle: 4090626048 - Reason for
Enter DllMain -> Handle: 4090626048 - Reason for
Enter DllMain -> Handle: 4090626048 - Reason for
Enter DllMain -> Handle: 4090626048 - Reason for
Enter DllMain -> Handle: 4090626048 - Reason for
Enter DllMain -> Handle: 4090626048 - Reason for
Enter DllMain -> Handle: 4090626048 - Reason for
Enter DllMain -> Handle: 4090626048 - Reason for
Enter DllMain -> Handle: 1930362880 - Reason for
Enter DllMain -> Handle: 1930362880 - Reason for
Enter DllMain -> Handle: 1930362880 - Reason for

call: DLL_PROCESS_DETACH
25/05/12 11:42:38
D
call: DLL_PROCESS_DETACH
25/05/12 11:42:38
D
call: DLL_PROCESS_DETACH
25/05/12 11:42:38
D
call: DLL_PROCESS_DETACH
25/05/12 11:42:38
D
call: DLL_PROCESS_DETACH
25/05/12 11:48:54
D
call: DLL_PROCESS_ATTACH
25/05/12 11:48:54
D
call: DLL_PROCESS_ATTACH
25/05/12 11:48:55
D
call: DLL_PROCESS_ATTACH
25/05/12 11:48:55
D
call: DLL_PROCESS_ATTACH
25/05/12 11:48:55
D
call: DLL_PROCESS_ATTACH
25/05/12 11:48:55
D
call: DLL_PROCESS_ATTACH
25/05/12 11:48:55
D
call: DLL_PROCESS_ATTACH
25/05/12 11:48:55
A
25/05/12 11:48:55
A
25/05/12 11:48:55
R
25/05/12 11:48:55
A
25/05/12 11:48:55
R
25/05/12 11:48:55
A
25/05/12 11:48:55
R
25/05/12 11:48:55
D
call: DLL_PROCESS_ATTACH
25/05/12 11:48:56
A
25/05/12 11:48:56
D
call: DLL_PROCESS_DETACH
25/05/12 11:48:59
D
call: DLL_PROCESS_DETACH
25/05/12 11:48:59
D
call: DLL_PROCESS_DETACH
25/05/12 11:48:59
D
call: DLL_PROCESS_DETACH
25/05/12 11:48:59
D
call: DLL_PROCESS_DETACH
25/05/12 11:48:59
D
call: DLL_PROCESS_DETACH
25/05/12 11:48:59
D
call: DLL_PROCESS_DETACH
25/05/12 11:48:59
D
call: DLL_PROCESS_DETACH
25/05/12 11:48:59
D
call: DLL_PROCESS_DETACH
25/05/12 11:48:59
D
call: DLL_PROCESS_DETACH
25/05/12 11:48:59
D
call: DLL_PROCESS_DETACH
25/05/12 11:48:59
D
call: DLL_PROCESS_DETACH
25/05/12 12:34:27
D
call: DLL_PROCESS_ATTACH
25/05/12 12:34:27
D

Enter DllMain -> Handle: 1930362880 - Reason for


Enter DllMain -> Handle: 1930362880 - Reason for
Enter DllMain -> Handle: 1930362880 - Reason for
Enter DllMain -> Handle: 1930362880 - Reason for
Enter DllMain -> Handle: 4117430272 - Reason for
Enter DllMain -> Handle: 4117430272 - Reason for
Enter DllMain -> Handle: 4117430272 - Reason for
Enter DllMain -> Handle: 1934032896 - Reason for
Enter DllMain -> Handle: 1934032896 - Reason for
Enter DllMain -> Handle: 1934032896 - Reason for
Enter DllMain -> Handle: 1934032896 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Dejamos matar a VIGIA.EXE
-> NtTerminateProcessCallback
Dejamos matar a
-> NtTerminateProcessCallback
Dejamos matar a
Enter DllMain -> Handle: 1934032896 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4117430272 - Reason for
Enter DllMain -> Handle: 4117430272 - Reason for
Enter DllMain -> Handle: 4117430272 - Reason for
Enter DllMain -> Handle: 4117430272 - Reason for
Enter DllMain -> Handle: 4117430272 - Reason for
Enter DllMain -> Handle: 4117430272 - Reason for
Enter DllMain -> Handle: 4117430272 - Reason for
Enter DllMain -> Handle: 4117430272 - Reason for
Enter DllMain -> Handle: 1934032896 - Reason for
Enter DllMain -> Handle: 1934032896 - Reason for
Enter DllMain -> Handle: 1934032896 - Reason for
Enter DllMain -> Handle: 1934032896 - Reason for
Enter DllMain -> Handle: 4092919808 - Reason for
Enter DllMain -> Handle: 4092919808 - Reason for

call: DLL_PROCESS_ATTACH
25/05/12 12:34:27
D
call: DLL_PROCESS_ATTACH
25/05/12 12:34:27
D
call: DLL_PROCESS_ATTACH
25/05/12 12:34:27
D
call: DLL_PROCESS_ATTACH
25/05/12 12:34:27
D
call: DLL_PROCESS_ATTACH
25/05/12 12:34:27
A
25/05/12 12:34:27
D
call: DLL_PROCESS_DETACH
25/05/12 12:34:35
D
call: DLL_PROCESS_ATTACH
25/05/12 12:34:45
A
25/05/12 12:34:45
D
call: DLL_PROCESS_DETACH
25/05/12 12:41:00
D
call: DLL_PROCESS_ATTACH
25/05/12 12:41:00
D
call: DLL_PROCESS_ATTACH
25/05/12 12:41:00
D
call: DLL_PROCESS_ATTACH
25/05/12 12:41:01
A
25/05/12 12:41:01
A
25/05/12 12:41:01
D
call: DLL_PROCESS_DETACH
25/05/12 12:41:01
D
call: DLL_PROCESS_DETACH
25/05/12 12:46:01
A
25/05/12 12:46:01
D
call: DLL_PROCESS_DETACH
25/05/12 12:47:08
D
call: DLL_PROCESS_ATTACH
25/05/12 12:47:08
A
25/05/12 12:47:08
D
call: DLL_PROCESS_DETACH
25/05/12 12:49:09
D
call: DLL_PROCESS_ATTACH
25/05/12 12:49:10
D
call: DLL_PROCESS_ATTACH
25/05/12 12:49:15
A
25/05/12 12:54:10
A
25/05/12 12:54:10
D
call: DLL_PROCESS_DETACH
25/05/12 13:08:03
A
25/05/12 13:08:03
A
25/05/12 13:08:03
R
25/05/12 13:08:03
A
25/05/12 13:08:03
R
25/05/12 13:08:04
D
call: DLL_PROCESS_ATTACH
25/05/12 13:08:06
D
call: DLL_PROCESS_ATTACH
25/05/12 13:08:06
D
call: DLL_PROCESS_ATTACH
25/05/12 13:41:00
D
call: DLL_PROCESS_ATTACH
25/05/12 13:41:00
D
call: DLL_PROCESS_ATTACH

Enter DllMain -> Handle: 1935343616 - Reason for


Enter DllMain -> Handle: 1935343616 - Reason for
Enter DllMain -> Handle: 1935343616 - Reason for
Enter DllMain -> Handle: 1935343616 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4092919808 - Reason for
Enter DllMain -> Handle: 1935343616 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4092919808 - Reason for
Enter DllMain -> Handle: 4092919808 - Reason for
Enter DllMain -> Handle: 1935343616 - Reason for
Enter DllMain -> Handle: 1935343616 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1935343616 - Reason for
Enter DllMain -> Handle: 1935343616 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4092919808 - Reason for
Enter DllMain -> Handle: 4092919808 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4092919808 - Reason for
Enter DllMain -> Handle: 4092919808 - Reason for
Enter DllMain -> Handle: 1935343616 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4092919808 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Dejamos matar a VIGIA.EXE
-> NtTerminateProcessCallback
Dejamos matar a
Enter DllMain -> Handle: 1935343616 - Reason for
Enter DllMain -> Handle: 1935343616 - Reason for
Enter DllMain -> Handle: 1935343616 - Reason for
Enter DllMain -> Handle: 4092919808 - Reason for
Enter DllMain -> Handle: 1935343616 - Reason for

25/05/12 13:41:00
A
25/05/12 13:41:00
D
call: DLL_PROCESS_DETACH
25/05/12 13:46:00
A
25/05/12 13:46:00
D
call: DLL_PROCESS_DETACH
25/05/12 14:41:00
D
call: DLL_PROCESS_ATTACH
25/05/12 14:41:00
D
call: DLL_PROCESS_ATTACH
25/05/12 14:41:00
A
25/05/12 14:41:00
D
call: DLL_PROCESS_DETACH
25/05/12 14:46:00
A
25/05/12 14:46:00
D
call: DLL_PROCESS_DETACH
25/05/12 15:20:06
D
call: DLL_PROCESS_DETACH
25/05/12 15:20:06
D
call: DLL_PROCESS_DETACH
25/05/12 15:20:06
D
call: DLL_PROCESS_DETACH
25/05/12 15:20:06
D
call: DLL_PROCESS_DETACH
25/05/12 15:20:06
D
call: DLL_PROCESS_DETACH
25/05/12 15:20:06
D
call: DLL_PROCESS_DETACH
25/05/12 15:20:06
D
call: DLL_PROCESS_DETACH
25/05/12 15:20:06
D
call: DLL_PROCESS_DETACH
25/05/12 15:20:06
D
call: DLL_PROCESS_DETACH
25/05/12 15:20:06
D
call: DLL_PROCESS_DETACH
25/05/12 15:20:06
D
call: DLL_PROCESS_DETACH
25/05/12 15:20:06
D
call: DLL_PROCESS_DETACH
25/05/12 15:20:06
D
call: DLL_PROCESS_DETACH
25/05/12 15:20:06
D
call: DLL_PROCESS_DETACH
10/06/12 17:01:18
D
call: DLL_PROCESS_ATTACH
10/06/12 17:01:18
D
call: DLL_PROCESS_ATTACH
10/06/12 17:01:18
D
call: DLL_PROCESS_ATTACH
10/06/12 17:01:18
D
call: DLL_PROCESS_ATTACH
10/06/12 17:01:18
D
call: DLL_PROCESS_ATTACH
10/06/12 17:01:18
D
call: DLL_PROCESS_ATTACH
10/06/12 17:01:18
D
call: DLL_PROCESS_ATTACH
10/06/12 17:01:18
D
call: DLL_PROCESS_ATTACH

-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1935343616 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4092919808 - Reason for
Enter DllMain -> Handle: 4092919808 - Reason for
Enter DllMain -> Handle: 1935343616 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1935343616 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4092919808 - Reason for
Enter DllMain -> Handle: 4092919808 - Reason for
Enter DllMain -> Handle: 4092919808 - Reason for
Enter DllMain -> Handle: 4092919808 - Reason for
Enter DllMain -> Handle: 4092919808 - Reason for
Enter DllMain -> Handle: 4092919808 - Reason for
Enter DllMain -> Handle: 4092919808 - Reason for
Enter DllMain -> Handle: 4092919808 - Reason for
Enter DllMain -> Handle: 1935343616 - Reason for
Enter DllMain -> Handle: 1935343616 - Reason for
Enter DllMain -> Handle: 1935343616 - Reason for
Enter DllMain -> Handle: 1935343616 - Reason for
Enter DllMain -> Handle: 1935343616 - Reason for
Enter DllMain -> Handle: 1935343616 - Reason for
Enter DllMain -> Handle: 1935343616 - Reason for
Enter DllMain -> Handle: 4108320768 - Reason for
Enter DllMain -> Handle: 4108320768 - Reason for
Enter DllMain -> Handle: 4108320768 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for

10/06/12 17:01:18
D
call: DLL_PROCESS_ATTACH
10/06/12 17:01:18
D
call: DLL_PROCESS_ATTACH
10/06/12 17:01:39
A
10/06/12 17:01:39
D
call: DLL_PROCESS_DETACH
10/06/12 17:01:47
A
10/06/12 17:01:47
A
10/06/12 17:01:47
R
10/06/12 17:01:47
A
10/06/12 17:01:47
R
10/06/12 17:01:47
A
10/06/12 17:01:47
R
10/06/12 11:01:15
D
call: DLL_PROCESS_ATTACH
10/06/12 11:01:16
D
call: DLL_PROCESS_ATTACH
10/06/12 11:01:30
D
call: DLL_PROCESS_ATTACH
10/06/12 11:01:30
A
10/06/12 11:01:30
D
call: DLL_PROCESS_DETACH
10/06/12 11:01:45
D
call: DLL_PROCESS_ATTACH
10/06/12 11:02:02
D
call: DLL_PROCESS_ATTACH
10/06/12 11:02:02
A
10/06/12 11:02:02
D
call: DLL_PROCESS_DETACH
10/06/12 11:02:11
D
call: DLL_PROCESS_ATTACH
10/06/12 11:02:11
A
10/06/12 11:02:11
D
call: DLL_PROCESS_DETACH
10/06/12 11:02:16
A
10/06/12 11:02:16
D
call: DLL_PROCESS_DETACH
10/06/12 11:02:16
A
10/06/12 11:02:16
D
call: DLL_PROCESS_DETACH
10/06/12 11:02:19
D
call: DLL_PROCESS_ATTACH
10/06/12 11:02:19
A
10/06/12 11:02:19
D
call: DLL_PROCESS_DETACH
10/06/12 11:02:27
D
call: DLL_PROCESS_ATTACH
10/06/12 11:02:27
A
10/06/12 11:02:27
D
call: DLL_PROCESS_DETACH
10/06/12 11:02:35
D
call: DLL_PROCESS_ATTACH
10/06/12 11:02:35
A
10/06/12 11:02:35
D
call: DLL_PROCESS_DETACH
10/06/12 11:02:44
D
call: DLL_PROCESS_ATTACH
10/06/12 11:02:44
A
10/06/12 11:02:44
D

Enter DllMain -> Handle: 1919287296 - Reason for


Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4108320768 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Dejamos matar a VIGIA.EXE
-> NtTerminateProcessCallback
Dejamos matar a
-> NtTerminateProcessCallback
Dejamos matar a
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for

call: DLL_PROCESS_DETACH
10/06/12 11:02:52
D
call: DLL_PROCESS_ATTACH
10/06/12 11:02:52
A
10/06/12 11:02:52
D
call: DLL_PROCESS_DETACH
10/06/12 11:03:00
D
call: DLL_PROCESS_ATTACH
10/06/12 11:03:00
A
10/06/12 11:03:00
D
call: DLL_PROCESS_DETACH
10/06/12 11:03:08
D
call: DLL_PROCESS_ATTACH
10/06/12 11:03:08
A
10/06/12 11:03:08
D
call: DLL_PROCESS_DETACH
10/06/12 11:03:16
D
call: DLL_PROCESS_ATTACH
10/06/12 11:03:16
A
10/06/12 11:03:16
D
call: DLL_PROCESS_DETACH
10/06/12 11:03:25
D
call: DLL_PROCESS_ATTACH
10/06/12 11:03:25
A
10/06/12 11:03:25
D
call: DLL_PROCESS_DETACH
10/06/12 17:04:21
D
call: DLL_PROCESS_ATTACH
10/06/12 17:04:21
A
10/06/12 17:04:21
D
call: DLL_PROCESS_DETACH
10/06/12 11:04:07
D
call: DLL_PROCESS_ATTACH
10/06/12 11:04:07
A
10/06/12 11:04:07
D
call: DLL_PROCESS_DETACH
10/06/12 11:04:15
D
call: DLL_PROCESS_ATTACH
10/06/12 11:04:15
A
10/06/12 11:04:15
D
call: DLL_PROCESS_DETACH
10/06/12 11:04:24
D
call: DLL_PROCESS_ATTACH
10/06/12 11:04:24
A
10/06/12 11:04:24
D
call: DLL_PROCESS_DETACH
10/06/12 11:04:32
D
call: DLL_PROCESS_ATTACH
10/06/12 11:04:32
A
10/06/12 11:04:32
D
call: DLL_PROCESS_DETACH
10/06/12 11:04:40
D
call: DLL_PROCESS_ATTACH
10/06/12 11:04:40
A
10/06/12 11:04:40
D
call: DLL_PROCESS_DETACH
10/06/12 11:04:48
D
call: DLL_PROCESS_ATTACH
10/06/12 11:04:48
A
10/06/12 11:04:48
D

Enter DllMain -> Handle: 1919287296 - Reason for


-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for

call: DLL_PROCESS_DETACH
10/06/12 11:04:56
D
call: DLL_PROCESS_ATTACH
10/06/12 11:04:56
A
10/06/12 11:04:56
D
call: DLL_PROCESS_DETACH
10/06/12 11:05:05
D
call: DLL_PROCESS_ATTACH
10/06/12 11:05:05
A
10/06/12 11:05:05
D
call: DLL_PROCESS_DETACH
10/06/12 11:05:13
D
call: DLL_PROCESS_ATTACH
10/06/12 11:05:13
A
10/06/12 11:05:13
D
call: DLL_PROCESS_DETACH
10/06/12 11:05:21
D
call: DLL_PROCESS_ATTACH
10/06/12 11:05:21
A
10/06/12 11:05:21
D
call: DLL_PROCESS_DETACH
10/06/12 11:05:29
D
call: DLL_PROCESS_ATTACH
10/06/12 11:05:29
A
10/06/12 11:05:29
D
call: DLL_PROCESS_DETACH
10/06/12 11:05:38
D
call: DLL_PROCESS_ATTACH
10/06/12 11:05:38
A
10/06/12 11:05:38
D
call: DLL_PROCESS_DETACH
10/06/12 11:05:46
D
call: DLL_PROCESS_ATTACH
10/06/12 11:05:46
A
10/06/12 11:05:46
D
call: DLL_PROCESS_DETACH
10/06/12 11:05:54
D
call: DLL_PROCESS_ATTACH
10/06/12 11:05:54
A
10/06/12 11:05:54
D
call: DLL_PROCESS_DETACH
10/06/12 11:06:02
D
call: DLL_PROCESS_ATTACH
10/06/12 11:06:02
A
10/06/12 11:06:02
D
call: DLL_PROCESS_DETACH
10/06/12 11:06:10
D
call: DLL_PROCESS_ATTACH
10/06/12 11:06:10
A
10/06/12 11:06:10
D
call: DLL_PROCESS_DETACH
10/06/12 11:06:18
D
call: DLL_PROCESS_ATTACH
10/06/12 11:06:18
A
10/06/12 11:06:19
D
call: DLL_PROCESS_DETACH
10/06/12 11:06:27
D
call: DLL_PROCESS_ATTACH
10/06/12 11:06:27
A
10/06/12 11:06:27
D

Enter DllMain -> Handle: 1919287296 - Reason for


-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for

call: DLL_PROCESS_DETACH
10/06/12 11:06:35
D
call: DLL_PROCESS_ATTACH
10/06/12 11:06:35
A
10/06/12 11:06:35
D
call: DLL_PROCESS_DETACH
10/06/12 11:06:43
D
call: DLL_PROCESS_ATTACH
10/06/12 11:06:43
A
10/06/12 11:06:43
D
call: DLL_PROCESS_DETACH
10/06/12 11:06:51
D
call: DLL_PROCESS_ATTACH
10/06/12 11:06:51
A
10/06/12 11:06:51
D
call: DLL_PROCESS_DETACH
10/06/12 11:07:00
D
call: DLL_PROCESS_ATTACH
10/06/12 11:07:00
A
10/06/12 11:07:00
D
call: DLL_PROCESS_DETACH
10/06/12 11:07:08
D
call: DLL_PROCESS_ATTACH
10/06/12 11:07:08
A
10/06/12 11:07:08
D
call: DLL_PROCESS_DETACH
10/06/12 11:07:16
D
call: DLL_PROCESS_ATTACH
10/06/12 11:07:16
A
10/06/12 11:07:16
D
call: DLL_PROCESS_DETACH
10/06/12 11:07:24
D
call: DLL_PROCESS_ATTACH
10/06/12 11:07:24
A
10/06/12 11:07:24
D
call: DLL_PROCESS_DETACH
10/06/12 11:07:32
D
call: DLL_PROCESS_ATTACH
10/06/12 11:07:33
A
10/06/12 11:07:33
D
call: DLL_PROCESS_DETACH
10/06/12 11:07:41
D
call: DLL_PROCESS_ATTACH
10/06/12 11:07:41
A
10/06/12 11:07:41
D
call: DLL_PROCESS_DETACH
10/06/12 11:07:49
D
call: DLL_PROCESS_ATTACH
10/06/12 11:07:49
A
10/06/12 11:07:49
D
call: DLL_PROCESS_DETACH
10/06/12 11:07:57
D
call: DLL_PROCESS_ATTACH
10/06/12 11:07:57
A
10/06/12 11:07:57
D
call: DLL_PROCESS_DETACH
10/06/12 11:08:05
D
call: DLL_PROCESS_ATTACH
10/06/12 11:08:05
A
10/06/12 11:08:05
D

Enter DllMain -> Handle: 1919287296 - Reason for


-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for

call: DLL_PROCESS_DETACH
10/06/12 11:08:14
D
call: DLL_PROCESS_ATTACH
10/06/12 11:08:14
A
10/06/12 11:08:14
D
call: DLL_PROCESS_DETACH
10/06/12 11:08:22
D
call: DLL_PROCESS_ATTACH
10/06/12 11:08:22
A
10/06/12 11:08:22
D
call: DLL_PROCESS_DETACH
10/06/12 11:08:30
D
call: DLL_PROCESS_ATTACH
10/06/12 11:08:30
A
10/06/12 11:08:30
D
call: DLL_PROCESS_DETACH
10/06/12 11:08:38
D
call: DLL_PROCESS_ATTACH
10/06/12 11:08:38
A
10/06/12 11:08:38
D
call: DLL_PROCESS_DETACH
10/06/12 11:08:46
D
call: DLL_PROCESS_ATTACH
10/06/12 11:08:46
A
10/06/12 11:08:46
D
call: DLL_PROCESS_DETACH
10/06/12 11:08:55
D
call: DLL_PROCESS_ATTACH
10/06/12 11:08:55
A
10/06/12 11:08:55
D
call: DLL_PROCESS_DETACH
10/06/12 11:09:03
D
call: DLL_PROCESS_ATTACH
10/06/12 11:09:03
A
10/06/12 11:09:03
D
call: DLL_PROCESS_DETACH
10/06/12 11:09:11
D
call: DLL_PROCESS_ATTACH
10/06/12 11:09:11
A
10/06/12 11:09:11
D
call: DLL_PROCESS_DETACH
10/06/12 11:09:19
D
call: DLL_PROCESS_ATTACH
10/06/12 11:09:19
A
10/06/12 11:09:19
D
call: DLL_PROCESS_DETACH
10/06/12 11:09:27
D
call: DLL_PROCESS_ATTACH
10/06/12 11:09:28
A
10/06/12 11:09:28
D
call: DLL_PROCESS_DETACH
10/06/12 11:09:36
D
call: DLL_PROCESS_ATTACH
10/06/12 11:09:36
A
10/06/12 11:09:36
D
call: DLL_PROCESS_DETACH
10/06/12 11:09:44
D
call: DLL_PROCESS_ATTACH
10/06/12 11:09:44
A
10/06/12 11:09:44
D

Enter DllMain -> Handle: 1919287296 - Reason for


-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for

call: DLL_PROCESS_DETACH
10/06/12 11:09:52
D
call: DLL_PROCESS_ATTACH
10/06/12 11:09:52
A
10/06/12 11:09:52
D
call: DLL_PROCESS_DETACH
10/06/12 11:10:00
D
call: DLL_PROCESS_ATTACH
10/06/12 11:10:00
A
10/06/12 11:10:00
D
call: DLL_PROCESS_DETACH
10/06/12 11:10:09
D
call: DLL_PROCESS_ATTACH
10/06/12 11:10:09
A
10/06/12 11:10:09
D
call: DLL_PROCESS_DETACH
10/06/12 11:10:17
D
call: DLL_PROCESS_ATTACH
10/06/12 11:10:17
A
10/06/12 11:10:17
D
call: DLL_PROCESS_DETACH
10/06/12 11:10:25
D
call: DLL_PROCESS_ATTACH
10/06/12 11:10:25
A
10/06/12 11:10:25
D
call: DLL_PROCESS_DETACH
10/06/12 11:10:33
D
call: DLL_PROCESS_ATTACH
10/06/12 11:10:33
A
10/06/12 11:10:33
D
call: DLL_PROCESS_DETACH
10/06/12 11:10:41
D
call: DLL_PROCESS_ATTACH
10/06/12 11:10:41
A
10/06/12 11:10:41
D
call: DLL_PROCESS_DETACH
10/06/12 11:10:50
D
call: DLL_PROCESS_ATTACH
10/06/12 11:10:50
A
10/06/12 11:10:50
D
call: DLL_PROCESS_DETACH
10/06/12 11:10:58
D
call: DLL_PROCESS_ATTACH
10/06/12 11:10:58
A
10/06/12 11:10:58
D
call: DLL_PROCESS_DETACH
10/06/12 11:11:06
D
call: DLL_PROCESS_ATTACH
10/06/12 11:11:06
A
10/06/12 11:11:06
D
call: DLL_PROCESS_DETACH
10/06/12 11:11:14
D
call: DLL_PROCESS_ATTACH
10/06/12 11:11:14
A
10/06/12 11:11:14
D
call: DLL_PROCESS_DETACH
10/06/12 11:11:22
D
call: DLL_PROCESS_ATTACH
10/06/12 11:11:22
A
10/06/12 11:11:23
D

Enter DllMain -> Handle: 1919287296 - Reason for


-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for

call: DLL_PROCESS_DETACH
10/06/12 11:11:31
D
call: DLL_PROCESS_ATTACH
10/06/12 11:11:31
A
10/06/12 11:11:31
D
call: DLL_PROCESS_DETACH
10/06/12 11:11:39
D
call: DLL_PROCESS_ATTACH
10/06/12 11:11:39
A
10/06/12 11:11:39
D
call: DLL_PROCESS_DETACH
10/06/12 11:11:47
D
call: DLL_PROCESS_ATTACH
10/06/12 11:11:47
A
10/06/12 11:11:47
D
call: DLL_PROCESS_DETACH
10/06/12 11:11:55
D
call: DLL_PROCESS_ATTACH
10/06/12 11:11:55
A
10/06/12 11:11:55
D
call: DLL_PROCESS_DETACH
10/06/12 11:12:04
D
call: DLL_PROCESS_ATTACH
10/06/12 11:12:04
A
10/06/12 11:12:04
D
call: DLL_PROCESS_DETACH
10/06/12 11:12:12
D
call: DLL_PROCESS_ATTACH
10/06/12 11:12:12
A
10/06/12 11:12:12
D
call: DLL_PROCESS_DETACH
10/06/12 11:12:16
A
10/06/12 11:12:16
A
10/06/12 11:12:16
A
10/06/12 11:12:16
D
call: DLL_PROCESS_DETACH
10/06/12 11:12:16
D
call: DLL_PROCESS_DETACH
10/06/12 11:12:16
A
10/06/12 11:12:16
D
call: DLL_PROCESS_DETACH
10/06/12 11:12:16
D
call: DLL_PROCESS_DETACH
10/06/12 11:12:16
D
call: DLL_PROCESS_DETACH
10/06/12 11:12:16
D
call: DLL_PROCESS_DETACH
10/06/12 11:12:16
D
call: DLL_PROCESS_DETACH
10/06/12 11:12:16
D
call: DLL_PROCESS_DETACH
10/06/12 11:12:16
D
call: DLL_PROCESS_DETACH
10/06/12 11:12:16
D
call: DLL_PROCESS_DETACH
10/06/12 11:12:16
D
call: DLL_PROCESS_DETACH
10/06/12 11:12:16
D
call: DLL_PROCESS_DETACH
10/07/12 02:47:16
D

Enter DllMain -> Handle: 1919287296 - Reason for


-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1919287296 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4108320768 - Reason for
Enter DllMain -> Handle: 4108320768 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4108320768 - Reason for
Enter DllMain -> Handle: 4108320768 - Reason for
Enter DllMain -> Handle: 4108320768 - Reason for
Enter DllMain -> Handle: 4108320768 - Reason for
Enter DllMain -> Handle: 4108320768 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 1919287296 - Reason for
Enter DllMain -> Handle: 4088266752 - Reason for

call: DLL_PROCESS_ATTACH
10/07/12 02:47:16
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:16
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:16
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:16
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:16
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:16
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:16
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:16
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:16
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:16
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:16
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:16
A
10/07/12 02:47:16
D
call: DLL_PROCESS_DETACH
10/07/12 02:47:16
A
10/07/12 02:47:16
R
10/07/12 02:47:16
A
10/07/12 02:47:16
R
10/07/12 02:47:16
A
10/07/12 02:47:16
R
10/07/12 02:47:16
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:21
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:21
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:22
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:22
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:23
A
10/07/12 02:47:23
D
call: DLL_PROCESS_DETACH
10/07/12 02:47:23
A
10/07/12 02:47:23
D
call: DLL_PROCESS_DETACH
10/07/12 02:47:24
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:26
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:29
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:31
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:31
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:33
A
10/07/12 02:47:33
D

Enter DllMain -> Handle: 4088266752 - Reason for


Enter DllMain -> Handle: 4088266752 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1944190976 - Reason for
-> NtTerminateProcessCallback
Dejamos matar a VIGIA.EXE
-> NtTerminateProcessCallback
Dejamos matar a VIGIA.EXE
-> NtTerminateProcessCallback
Dejamos matar a VIGIA.EXE
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1944190976 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 4088266752 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 4088266752 - Reason for

call: DLL_PROCESS_DETACH
10/07/12 02:47:33
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:38
D
call: DLL_PROCESS_ATTACH
10/07/12 02:47:38
A
10/07/12 02:47:38
D
call: DLL_PROCESS_DETACH
10/07/12 02:47:59
D
call: DLL_PROCESS_ATTACH
10/07/12 02:48:07
D
call: DLL_PROCESS_ATTACH
10/07/12 02:48:29
A
10/07/12 02:48:29
R
10/07/12 02:49:52
D
call: DLL_PROCESS_ATTACH
10/07/12 02:49:53
A
10/07/12 02:49:59
A
10/07/12 02:49:59
A
10/07/12 02:49:59
O
ies Printer
10/07/12 02:49:59
V
eries
10/07/12 02:49:59
V
10/07/12 02:49:59
A
10/07/12 02:49:59
F
rinter
10/07/12 02:49:59
V
eries
10/07/12 02:49:59
V
10/07/12 02:49:59
A
10/07/12 02:49:59
F
rinter
10/07/12 02:49:59
V
eries
10/07/12 02:49:59
V
10/07/12 02:49:59
A
10/07/12 02:49:59
F
rinter
10/07/12 02:49:59
V
eries
10/07/12 02:49:59
V
10/07/12 02:50:24
D
call: DLL_PROCESS_ATTACH
10/07/12 02:50:24
D
call: DLL_PROCESS_ATTACH
10/07/12 02:50:24
A
10/07/12 02:50:24
D
call: DLL_PROCESS_DETACH
10/07/12 02:50:34
D
call: DLL_PROCESS_ATTACH
10/07/12 02:50:35
A
10/07/12 02:50:35
R
10/07/12 02:50:36
A
10/07/12 02:50:36
R
10/07/12 02:50:38
D
call: DLL_PROCESS_ATTACH
10/07/12 02:50:38
D
call: DLL_PROCESS_ATTACH
10/07/12 02:50:38
A

Enter DllMain -> Handle: 1944190976 - Reason for


Enter DllMain -> Handle: 1944190976 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
-> NtTerminateProcessCallback
La victima es CHROME.EXE
Enter DllMain -> Handle: 4088266752 - Reason for
-> CreateDCWCallback
-> DocumentPropertiesWCallBack
-> DocumentPropertiesWCallBack
Impresora Final: \\CS-SERVER\Canon MP250 ser
DevMode Impresora: \\CS-SERVER\Canon MP250 s
DevMode Copies: 1
-> CreateDCWCallback
lpszDevice: \\CS-SERVER\Canon MP250 series P
DevMode Impresora: \\CS-SERVER\Canon MP250 s
DevMode Copies: 1
-> CreateDCWCallback
lpszDevice: \\CS-SERVER\Canon MP250 series P
DevMode Impresora: \\CS-SERVER\Canon MP250 s
DevMode Copies: 1
-> CreateDCWCallback
lpszDevice: \\CS-SERVER\Canon MP250 series P
DevMode Impresora: \\CS-SERVER\Canon MP250 s
DevMode Copies: 1
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
-> NtTerminateProcessCallback
La victima es CHROME.EXE
-> NtTerminateProcessCallback
La victima es CHROME.EXE
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
-> NtTerminateProcessCallback

10/07/12 02:50:38
D
call: DLL_PROCESS_DETACH
10/07/12 02:50:46
D
call: DLL_PROCESS_ATTACH
10/07/12 02:50:47
A
10/07/12 02:50:47
A
10/07/12 02:50:47
R
10/07/12 02:50:51
D
call: DLL_PROCESS_ATTACH
10/07/12 02:50:53
A
10/07/12 02:50:53
R
10/07/12 02:53:11
D
call: DLL_PROCESS_ATTACH
10/07/12 02:53:14
D
call: DLL_PROCESS_ATTACH
10/07/12 02:53:14
A
10/07/12 02:53:14
D
call: DLL_PROCESS_DETACH
10/07/12 02:53:16
A
10/07/12 02:53:17
D
call: DLL_PROCESS_ATTACH
10/07/12 02:53:17
A
10/07/12 02:53:17
D
call: DLL_PROCESS_DETACH

Enter DllMain -> Handle: 1944190976 - Reason for


Enter DllMain -> Handle: 1944190976 - Reason for
-> NtTerminateProcessCallback
-> NtTerminateProcessCallback
La victima es CHROME.EXE
Enter DllMain -> Handle: 1944190976 - Reason for
-> NtTerminateProcessCallback
La victima es CHROME.EXE
Enter DllMain -> Handle: 1944190976 - Reason for
Enter DllMain -> Handle: 1944190976 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1944190976 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1944190976 - Reason for
-> NtTerminateProcessCallback
Enter DllMain -> Handle: 1944190976 - Reason for

You might also like