GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-02-16 20:57:51 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST3500418AS rev.CC34 465,76GB Running: n5j6iwy0.exe; Driver: C:\DOCUME~1\SysOp\USTAWI~1\Temp\fglyqpob.sys ---- System - GMER 2.1 ---- SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAddBootEntry [0xB3A93AC4] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwAllocateVirtualMemory [0xB3D460BA] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAssignProcessToJobObject [0xB3A945A2] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwClose [0xB3ADA5A0] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEvent [0xB3AA063C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEventPair [0xB3AA0688] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateIoCompletion [0xB3AA0822] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateKey [0xB3AD9F54] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateMutant [0xB3AA05AA] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateSection [0xB3AA06CC] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateSemaphore [0xB3AA05F2] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateThread [0xB3A94AD8] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateTimer [0xB3AA07DC] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDebugActiveProcess [0xB3A95390] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteBootEntry [0xB3A93B2A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteKey [0xB3ADAC66] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteValueKey [0xB3ADAF1C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDuplicateObject [0xB3A98B86] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwEnumerateKey [0xB3ADAAD1] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwEnumerateValueKey [0xB3ADA93C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwLoadDriver [0xB3A93716] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwMapViewOfSection [0xB3D46574] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwModifyBootEntry [0xB3A93B90] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeKey [0xB3A98F7C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeMultipleKeys [0xB3A95E78] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEvent [0xB3AA0666] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEventPair [0xB3AA06AA] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenIoCompletion [0xB3AA0846] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenKey [0xB3ADA2B0] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenMutant [0xB3AA05D0] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenProcess [0xB3A9847E] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSection [0xB3AA075A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSemaphore [0xB3AA061A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenThread [0xB3A9886A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenTimer [0xB3AA0800] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwProtectVirtualMemory [0xB3D46312] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryKey [0xB3ADA7B7] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryObject [0xB3A95CEC] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryValueKey [0xB3ADA609] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueueApcThread [0xB3A95842] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwRenameKey [0xB3D54358] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwReplaceKey [0xB3D54CC4] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwRestoreKey [0xB3AD9597] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootEntryOrder [0xB3A93BF6] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootOptions [0xB3A93C5C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetContextThread [0xB3A9520A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemInformation [0xB3A937B0] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemPowerState [0xB3A93982] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetValueKey [0xB3ADAD6D] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwShutdownSystem [0xB3A93910] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendProcess [0xB3A9555A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendThread [0xB3A956BC] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSystemDebugControl [0xB3A93A0A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwTerminateProcess [0xB3A95048] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwTerminateThread [0xB3A951EA] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwVdmControl [0xB3A93CC2] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwWriteVirtualMemory [0xB3A945FE] INT 0x62 ? 8AD4CBF8 INT 0x63 ? 8AA50BF8 INT 0x82 ? 8AD4CBF8 INT 0x83 ? 8AA50BF8 INT 0xA4 ? 8AA50BF8 INT 0xB4 ? 8AA50BF8 ---- Kernel code sections - GMER 2.1 ---- .text TUKERNEL.EXE!ZwYieldExecution + 3C2 804E4BFC 12 Bytes [F6, 3B, A9, B3, 5C, 3C, A9, ...] .text TUKERNEL.EXE!ZwYieldExecution + 46A 804E4CA4 12 Bytes [5A, 55, A9, B3, BC, 56, A9, ...] PAGE TUKERNEL.EXE!PsCreateSystemThread + 455 80575B08 4 Bytes CALL B3A96549 \SystemRoot\system32\drivers\aswSnx.sys ? spfh.sys Nie można odnaleźć określonego pliku. ! .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB6C023C0, 0x83E20A, 0xE8000020] .text C:\WINDOWS\system32\DRIVERS\atksgt.sys section is writeable [0xB2418300, 0x3B6D8, 0xE8000020] .text C:\WINDOWS\system32\DRIVERS\lirsgt.sys section is writeable [0xB3DCB300, 0x1BEE, 0xE8000020] ? \PROGRAMY\DAEMON Tools Lite\Engine.dll System nie może odnaleźć określonej ścieżki. ! ---- User code sections - GMER 2.1 ---- .text D:\PROGRAMY\Avast\AvastSvc.exe[192] kernel32.dll!SetUnhandledExceptionFilter 7C844935 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP } .text D:\PROGRAMY\Avast\AvastUI.exe[956] kernel32.dll!SetUnhandledExceptionFilter 7C844935 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP } .text C:\Program Files\CCleaner\CCleaner.exe[988] USER32.dll!SetScrollInfo 7E369056 5 Bytes JMP 00505F4C C:\Program Files\CCleaner\CCleaner.exe .text C:\Program Files\CCleaner\CCleaner.exe[988] USER32.dll!GetScrollInfo 7E37DFE2 5 Bytes JMP 00505EA8 C:\Program Files\CCleaner\CCleaner.exe .text C:\Program Files\CCleaner\CCleaner.exe[988] USER32.dll!ShowScrollBar 7E37F2F2 5 Bytes JMP 00505EDB C:\Program Files\CCleaner\CCleaner.exe .text C:\Program Files\CCleaner\CCleaner.exe[988] USER32.dll!GetScrollPos 7E37F704 5 Bytes JMP 00505E83 C:\Program Files\CCleaner\CCleaner.exe .text C:\Program Files\CCleaner\CCleaner.exe[988] USER32.dll!SetScrollPos 7E37F750 5 Bytes JMP 00505E26 C:\Program Files\CCleaner\CCleaner.exe .text C:\Program Files\CCleaner\CCleaner.exe[988] USER32.dll!GetScrollRange 7E37F787 5 Bytes JMP 00505E4B C:\Program Files\CCleaner\CCleaner.exe .text C:\Program Files\CCleaner\CCleaner.exe[988] USER32.dll!SetScrollRange 7E37F99B 5 Bytes JMP 00505F15 C:\Program Files\CCleaner\CCleaner.exe .text C:\Program Files\CCleaner\CCleaner.exe[988] USER32.dll!EnableScrollBar 7E3B8005 5 Bytes JMP 00505F80 C:\Program Files\CCleaner\CCleaner.exe .text C:\Program Files\Mozilla Firefox\firefox.exe[2928] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 018E9AE0 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2928] ntdll.dll!NtFlushBuffersFile 7C90D32E 5 Bytes JMP 018CC434 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2928] ntdll.dll!NtQueryFullAttributesFile 7C90D7AE 5 Bytes JMP 018CC150 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2928] ntdll.dll!NtReadFile 7C90D9CE 5 Bytes JMP 018CC330 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2928] ntdll.dll!NtReadFileScatter 7C90D9DE 5 Bytes JMP 022EF60F C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2928] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 018EA9F0 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2928] ntdll.dll!NtWriteFileGather 7C90DF8E 5 Bytes JMP 022EF5BE C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2928] ntdll.dll!LdrLoadDll 7C915CD3 5 Bytes JMP 00881F42 C:\Program Files\Mozilla Firefox\mozglue.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2928] ntdll.dll!LdrUnloadDll 7C916C9B 5 Bytes JMP 003003FC .text C:\Program Files\Mozilla Firefox\firefox.exe[2928] KERNEL32.dll!lstrlenW + 43 7C809AEC 7 Bytes JMP 02214AC3 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2928] KERNEL32.dll!MapViewOfFileEx + 6A 7C80B9A0 2 Bytes JMP 02214AA0 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2928] KERNEL32.dll!MapViewOfFileEx + 6D 7C80B9A3 4 Bytes [A0, 85, EB, F9] .text C:\Program Files\Mozilla Firefox\firefox.exe[2928] KERNEL32.dll!ValidateLocale + B138 7C844930 7 Bytes JMP 018E63D0 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2928] user32.dll!GetWindowInfo 7E37C49C 5 Bytes JMP 0210B991 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[2928] GDI32.dll!SetDIBitsToDevice + 20A 77F19E14 7 Bytes JMP 02214A21 C:\Program Files\Mozilla Firefox\xul.dll .text D:\PROGRAMY\Avast\AvastUI.exe[4056] kernel32.dll!SetUnhandledExceptionFilter 7C844935 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP } ---- User IAT/EAT - GMER 2.1 ---- IAT C:\WINDOWS\system32\services.exe[1276] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003D0002 IAT C:\WINDOWS\system32\services.exe[1276] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003D0000 ---- Devices - GMER 2.1 ---- Device \FileSystem\Ntfs \Ntfs 8ACD91F8 Device \FileSystem\Fastfat \FatCdrom 89C3A500 AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.sys Device \Driver\usbuhci \Device\USBPDO-0 8AB041F8 Device \Driver\dmio \Device\DmControl\DmIoDaemon 8ACDB1F8 Device \Driver\dmio \Device\DmControl\DmConfig 8ACDB1F8 Device \Driver\dmio \Device\DmControl\DmPnP 8ACDB1F8 Device \Driver\dmio \Device\DmControl\DmInfo 8ACDB1F8 Device \Driver\usbuhci \Device\USBPDO-1 8AB041F8 Device \Driver\usbuhci \Device\USBPDO-2 8AB041F8 Device \Driver\usbuhci \Device\USBPDO-3 8AB041F8 Device \Driver\usbehci \Device\USBPDO-4 8AAED1F8 AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.sys Device \Driver\Ftdisk \Device\HarddiskVolume1 8AD4D1F8 Device \Driver\Ftdisk \Device\HarddiskVolume2 8AD4D1F8 Device \Driver\Cdrom \Device\CdRom0 8AA2C1F8 Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F7833B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort0 [F7833B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdePort1 [F7833B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-e [F7833B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX} Device \Driver\NetBT \Device\NetBt_Wins_Export 8A0431F8 Device \Driver\NetBT \Device\NetbiosSmb 8A0431F8 Device \Driver\NetBT \Device\NetBT_Tcpip_{4BAAD438-46D6-4EE6-9D8B-D2F4A51796DA} 8A0431F8 AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.sys AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.sys Device \Driver\usbuhci \Device\USBFDO-0 8AB041F8 Device \Driver\usbuhci \Device\USBFDO-1 8AB041F8 Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8A0401F8 Device \Driver\usbuhci \Device\USBFDO-2 8AB041F8 Device \FileSystem\MRxSmb \Device\LanmanRedirector 8A0401F8 Device \Driver\usbuhci \Device\USBFDO-3 8AB041F8 Device \Driver\usbehci \Device\USBFDO-4 8AAED1F8 Device \Driver\Ftdisk \Device\FtControl 8AD4D1F8 Device \FileSystem\Fastfat \Fat 89C3A500 AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys Device \FileSystem\Cdfs \Cdfs 8A00A1F8 ---- Trace I/O - GMER 2.1 ---- Trace TUKERNEL.EXE CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spfh.sys >>UNKNOWN [0x8acfb938]<< 8acfb938 Trace 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8ac58ab8] 8ac58ab8 Trace 3 CLASSPNP.SYS[f7647fd7] -> nt!IofCallDriver -> \Device\00000076[0x8ac9c3b8] 8ac9c3b8 Trace 5 ACPI.sys[f74a2620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8ac8d940] 8ac8d940 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\ControlSet001\Control\Video\{F185E27D-BE27-4844-9C29-5C49D9B54EC5}\0000@D3D_\x3332\x3331 2089309684 Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xC0 0xDB 0x89 0xE5 ... Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 D:\PROGRAMY\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x48 0xC4 0xAB 0xBA ... Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xD2 0x91 0x12 0xEB ... Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xFB 0x1F 0xED 0x16 ... Reg HKLM\SYSTEM\CurrentControlSet\Control\Video\{F185E27D-BE27-4844-9C29-5C49D9B54EC5}\0000@D3D_\x3332\x3331 2089309684 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x48 0xBD 0x2E 0xF6 ... Reg HKLM\SYSTEM\ControlSet003\Control\Video\{F185E27D-BE27-4844-9C29-5C49D9B54EC5}\0000@D3D_\x3332\x3331 2089309684 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x48 0xBD 0x2E 0xF6 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 D:\PROGRAMY\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x48 0xC4 0xAB 0xBA ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xA2 0xF3 0x37 0xD3 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xFB 0x1F 0xED 0x16 ... Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\151\Shell@ScrollPos1024x76đ'1).x 0 ---- Files - GMER 2.1 ---- File C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\nukl7zsu.default\cache2\entries\1B6B4D8F5DF507266BAA0A76D1178C4D10F59885 1370 bytes File C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\nukl7zsu.default\cache2\entries\9D2B4D8A6D1D099F9A81F3A061F6861D7431C9A6 2990 bytes File C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\nukl7zsu.default\cache2\entries\7219051D3254D0B8DD65D66D564A0BF73FD930B9 4299 bytes File C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\nukl7zsu.default\cache2\entries\061F237D9FA6C20A1F51D5F0DBD48A6462FE6AA9 1585 bytes File C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\nukl7zsu.default\cache2\entries\EDD97FD6A4DF0B4FAD24272C3D341AF081D208E7 54221 bytes File C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\nukl7zsu.default\cache2\entries\FBEB2192F0A5C3F360CAA12FFA46464873B50D99 3262 bytes File C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\nukl7zsu.default\cache2\entries\143539C48B2BF9F2F0884EB65738F367E3FA6A0C 17735 bytes File C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\nukl7zsu.default\cache2\entries\75F4DB2A46004108CB1C77AAA6E5BD50F3B75D10 4449 bytes File C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\nukl7zsu.default\cache2\entries\75FC14A030AFA9CED936569464A5BFBE98E9DB45 16567 bytes File C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\nukl7zsu.default\cache2\entries\996187F48428827B65709E4DDFF3A1692C8AF048 7012 bytes File C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\nukl7zsu.default\cache2\entries\C51EB1BFFF1E6C78504B8D0D55BD8F1609FA58D3 42501 bytes File C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\nukl7zsu.default\cache2\entries\FF82119A17261A52F7380BA205F53035618D6283 610 bytes File C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\nukl7zsu.default\cache2\entries\3C41A102814BA7F4379B595E82B7902311F70D91 1138 bytes File C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\nukl7zsu.default\cache2\entries\8E5482F4007717E4EAEB39EEBC26A823B81FD624 1219 bytes File C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\nukl7zsu.default\cache2\entries\E32BEC87D0B61F96C9E33D713119EDE76E7F6BF0 6949 bytes File C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\nukl7zsu.default\cache2\entries\4849CD2EADD4E77776F67D61CF647C45F0D977FE 20204 bytes File C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\nukl7zsu.default\cache2\entries\976084F5D4E93EBDC526C59B01522B2C4A4DD4E8 1627 bytes File C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\nukl7zsu.default\cache2\entries\806EC1A1952FC1C82CA396F3219E692954ECCAAD 1190 bytes File C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\nukl7zsu.default\cache2\entries\807545F6146D56758959E3BCCDBBBB49371D1AE0 5865 bytes File C:\Documents and Settings\SysOp\Ustawienia lokalne\Dane aplikacji\Mozilla\Firefox\Profiles\nukl7zsu.default\cache2\entries\AD08C6ACEE1A4F1063D7AD210D6AB610510EB89A 611 bytes ---- EOF - GMER 2.1 ----