0 Members and 1 Guest are viewing this topic.
ntoskrnl.exe!KeWaitForMultipleObjects+0xc0antoskrnl.exe!KeAcquireSpinLockAtDpcLevel+0x732ntoskrnl.exe!KeWaitForMutexObject+0x19fntoskrnl.exe!PoStartNextPowerIrp+0xba4ntoskrnl.exe!PoStartNextPowerIrp+0x1821ntoskrnl.exe!KeAcquireSpinLockAtDpcLevel+0x93dntoskrnl.exe!KeWaitForMutexObject+0x19fwin32k.sys!memset+0x7a47win32k.sys!memset+0x7ae9win32k.sys!memset+0x612cwin32k.sys!memset+0x6235win32k.sys!memset+0x7c11ntoskrnl.exe!KeSynchronizeExecution+0x3a23wow64win.dll+0x3fe3awow64win.dll+0x1aea8wow64.dll!Wow64SystemServiceEx+0xd7wow64cpu.dll!TurboDispatchJumpAddressEnd+0x2dwow64.dll!Wow64SystemServiceEx+0x1cewow64.dll!Wow64LdrpInitialize+0x42bntdll.dll!RtlUniform+0x6e6ntdll.dll!RtlCreateTagHeap+0xa7ntdll.dll!LdrInitializeThunk+0xeUSER32.dll!DispatchMessageW+0x5cRogueKiller_DEBUG.exe+0xfac5RogueKiller_DEBUG.exe+0x1219RogueKiller_DEBUG.exe+0x1eaae2RogueKiller_DEBUG.exe+0x1ea98fkernel32.dll!BaseThreadInitThunk+0x12ntdll.dll!RtlInitializeExceptionChain+0x63ntdll.dll!RtlInitializeExceptionChain+0x36
I don't find the debug.log lines :/ Did you forget them?
[00:05:0460] [WK] select FileName,AllowedPaths,OwnerName from WELL_KNOWN_FILES where "SearchFilterHost.exe" LIKE FileName[00:05:0460] [WK] %WINDIR%\system32;%WINDIR%\syswow64[00:05:0460] [WK] 0 - %WINDIR%\system32[00:05:0460] [WK] 1 - %WINDIR%\syswow64[00:05:0460] [WK] 0 - C:\Windows\System32 - \Device\HarddiskVolume2\Windows\System32[00:05:0460] [WK] 1 - C:\Windows\SysWOW64 - \Device\HarddiskVolume2\Windows\System32[00:05:0460] [KILL] Trying to kill...[00:05:0460] [KILL] Try TerminateProcess...[00:05:0460] [KILL] Open Snap...[00:05:0460] [KILL] Snap -> 0x348[00:05:0460] [KILL] Terminate process...[00:05:0460] [KILL] OK![00:05:0460] [KILL] Handle closed![00:05:0460] [KILL] Returning TERMINATE_PROCESS...[00:05:0460] [KILL] Killed : 1[00:05:0460] [KILL] Kill finished : 1[00:05:0476] [WK] select FileName,AllowedPaths,OwnerName from WELL_KNOWN_FILES where "SearchProtocolHost.exe" LIKE FileName[00:05:0476] [WK] %WINDIR%\system32;%WINDIR%\syswow64[00:05:0476] [WK] 0 - %WINDIR%\system32[00:05:0476] [WK] 1 - %WINDIR%\syswow64[00:05:0476] [WK] 0 - C:\Windows\System32 - \Device\HarddiskVolume2\Windows\System32[00:05:0476] [WK] 1 - C:\Windows\SysWOW64 - \Device\HarddiskVolume2\Windows\System32[00:05:0476] [KILL] Trying to kill...[00:05:0476] [KILL] Try TerminateProcess...[00:05:0476] [KILL] Open Snap...[00:05:0476] [KILL] Snap -> 0x348[00:05:0476] [KILL] Terminate process...[00:05:0476] [KILL] OK![00:05:0476] [KILL] Handle closed![00:05:0476] [KILL] Returning TERMINATE_PROCESS...[00:05:0476] [KILL] Killed : 1[00:05:0476] [KILL] Kill finished : 1