GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-03-07 22:41:35 Windows 6.1.7600 x64 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-3 Corsair_Force_3_SSD rev.5.03 111,79GB Running: jhnmqgsg.exe; Driver: C:\Users\Kamil\AppData\Local\Temp\awddykob.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\Windows\system32\DRIVERS\USBPORT.SYS!DllUnload fffff88006275c34 12 bytes {MOV RAX, 0xfffffa800c04f2a0; JMP RAX} ---- User code sections - GMER 2.1 ---- .text C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1980] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000074afd03c 4 bytes [C2, 04, 00, 00] .text C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1980] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 00000000760e1465 2 bytes [0E, 76] .text C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1980] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 00000000760e14bb 2 bytes [0E, 76] .text ... * 2 .text C:\Program Files (x86)\OkayFreedom\OkayFreedomService.exe[2272] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000760e1465 2 bytes [0E, 76] .text C:\Program Files (x86)\OkayFreedom\OkayFreedomService.exe[2272] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760e14bb 2 bytes [0E, 76] .text ... * 2 .text C:\Windows\system32\PnkBstrA.exe[2348] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000760e1465 2 bytes [0E, 76] .text C:\Windows\system32\PnkBstrA.exe[2348] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760e14bb 2 bytes [0E, 76] .text ... * 2 .text C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe[3284] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000760e1465 2 bytes [0E, 76] .text C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe[3284] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760e14bb 2 bytes [0E, 76] .text ... * 2 .text C:\Program Files (x86)\Steam\Steam.exe[3944] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 00000000760e1465 2 bytes [0E, 76] .text C:\Program Files (x86)\Steam\Steam.exe[3944] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 00000000760e14bb 2 bytes [0E, 76] .text ... * 2 .text C:\Program Files (x86)\Origin\Origin.exe[3980] C:\Windows\syswow64\kernel32.dll!CreateFileW 0000000074af22fb 5 bytes JMP 0000000156708c00 .text C:\Program Files (x86)\Origin\Origin.exe[3980] C:\Windows\syswow64\USER32.dll!SetWindowPos 00000000762ecdb4 5 bytes JMP 00000001567080f0 .text C:\Program Files (x86)\Origin\Origin.exe[3980] C:\Windows\syswow64\USER32.dll!ShowWindow 00000000762f0dbe 5 bytes JMP 0000000156707ed0 .text C:\Program Files (x86)\Origin\Origin.exe[3980] C:\Windows\syswow64\USER32.dll!SetFocus 00000000762f1b99 5 bytes JMP 0000000156707fe0 .text C:\Program Files (x86)\Origin\Origin.exe[3980] C:\Windows\syswow64\USER32.dll!SetForegroundWindow 00000000762f1d34 5 bytes JMP 0000000156707af0 .text C:\Program Files (x86)\Origin\Origin.exe[3980] C:\Windows\syswow64\USER32.dll!SetActiveWindow 00000000762f2890 5 bytes JMP 0000000156708200 .text C:\Program Files (x86)\Origin\Origin.exe[3980] C:\Windows\syswow64\USER32.dll!BringWindowToTop 00000000762f7ba7 5 bytes JMP 0000000156707c00 .text C:\Program Files (x86)\Origin\Origin.exe[3980] C:\Windows\syswow64\USER32.dll!SwitchToThisWindow 000000007632908c 5 bytes JMP 0000000156707d10 .text C:\Program Files (x86)\Origin\Origin.exe[3980] C:\Windows\syswow64\USER32.dll!ShowWindowAsync 0000000076347f27 5 bytes JMP 0000000156707dc0 .text C:\Program Files (x86)\Origin\Origin.exe[3980] C:\Windows\syswow64\ole32.dll!DoDragDrop 00000000768fa4cf 5 bytes JMP 0000000156707a00 .text C:\Program Files (x86)\Origin\Origin.exe[3980] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000760e1465 2 bytes [0E, 76] .text C:\Program Files (x86)\Origin\Origin.exe[3980] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760e14bb 2 bytes [0E, 76] .text ... * 2 .text C:\Users\Kamil\AppData\Roaming\Spotify\spotify.exe[4048] C:\Windows\SysWOW64\ntdll.dll!DbgBreakPoint 0000000076f0000c 1 byte [C3] .text C:\Users\Kamil\AppData\Roaming\Spotify\spotify.exe[4048] C:\Windows\SysWOW64\ntdll.dll!DbgUiRemoteBreakin 0000000076f8f962 5 bytes JMP 0000000176f3d579 .text C:\Users\Kamil\AppData\Roaming\Spotify\spotify.exe[4048] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000760e1465 2 bytes [0E, 76] .text C:\Users\Kamil\AppData\Roaming\Spotify\spotify.exe[4048] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760e14bb 2 bytes [0E, 76] .text ... * 2 .text C:\Program Files (x86)\OkayFreedom\OkayFreedomClient.exe[4088] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000760e1465 2 bytes [0E, 76] .text C:\Program Files (x86)\OkayFreedom\OkayFreedomClient.exe[4088] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760e14bb 2 bytes [0E, 76] .text ... * 2 .text C:\Program Files (x86)\Overwolf\Overwolf.exe[1764] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000762e7e92 5 bytes JMP 0000000114363220 .text C:\Program Files (x86)\Overwolf\Overwolf.exe[1764] C:\Windows\syswow64\USER32.dll!ShowWindow 00000000762f0dbe 5 bytes JMP 00000001143637a0 .text C:\Program Files (x86)\Overwolf\Overwolf.exe[1764] C:\Windows\syswow64\USER32.dll!GetCursorPos 00000000762f0e0d 5 bytes JMP 00000001143626f0 .text C:\Program Files (x86)\Overwolf\Overwolf.exe[1764] C:\Windows\syswow64\USER32.dll!AttachThreadInput 00000000762f1d4c 5 bytes JMP 0000000114365680 .text C:\Program Files (x86)\Overwolf\Overwolf.exe[1764] C:\Windows\syswow64\USER32.dll!UpdateLayeredWindowIndirect 00000000762f260a 5 bytes JMP 0000000114361b70 .text C:\Program Files (x86)\Overwolf\Overwolf.exe[1764] C:\Windows\syswow64\USER32.dll!WindowFromPoint 00000000762f2ddb 5 bytes JMP 0000000114362170 .text C:\Program Files (x86)\Overwolf\Overwolf.exe[1764] C:\Windows\syswow64\USER32.dll!SetCursor 00000000762f4076 5 bytes JMP 0000000114362cb0 .text C:\Program Files (x86)\Overwolf\Overwolf.exe[1764] C:\Windows\syswow64\shell32.dll!ShellExecuteW 0000000074c04228 5 bytes JMP 00000001143654b0 .text C:\Program Files (x86)\Overwolf\Overwolf.exe[1764] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000760e1465 2 bytes [0E, 76] .text C:\Program Files (x86)\Overwolf\Overwolf.exe[1764] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760e14bb 2 bytes [0E, 76] .text ... * 2 .text C:\Program Files (x86)\Overwolf\Overwolf.exe[1764] C:\Windows\syswow64\COMDLG32.dll!GetSaveFileNameW 0000000075c2619f 5 bytes JMP 0000000114365390 .text C:\Program Files (x86)\Overwolf\Overwolf.exe[1764] C:\Windows\syswow64\COMDLG32.dll!GetOpenFileNameW 0000000075c4b425 5 bytes JMP 0000000114365270 .text C:\Program Files (x86)\Steam\bin\steamwebhelper.exe[6588] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000760e1465 2 bytes [0E, 76] .text C:\Program Files (x86)\Steam\bin\steamwebhelper.exe[6588] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760e14bb 2 bytes [0E, 76] .text ... * 2 .text C:\Users\Kamil\AppData\Roaming\Spotify\Data\SpotifyHelper.exe[6912] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000760e1465 2 bytes [0E, 76] .text C:\Users\Kamil\AppData\Roaming\Spotify\Data\SpotifyHelper.exe[6912] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760e14bb 2 bytes [0E, 76] .text ... * 2 .text C:\Users\Kamil\AppData\Roaming\Spotify\Data\SpotifyHelper.exe[6924] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000760e1465 2 bytes [0E, 76] .text C:\Users\Kamil\AppData\Roaming\Spotify\Data\SpotifyHelper.exe[6924] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760e14bb 2 bytes [0E, 76] .text ... * 2 .text C:\Users\Kamil\AppData\Roaming\Spotify\Data\SpotifyHelper.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000760e1465 2 bytes [0E, 76] .text C:\Users\Kamil\AppData\Roaming\Spotify\Data\SpotifyHelper.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760e14bb 2 bytes [0E, 76] .text ... * 2 .text C:\Users\Kamil\AppData\Roaming\Spotify\Data\SpotifyHelper.exe[6320] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000760e1465 2 bytes [0E, 76] .text C:\Users\Kamil\AppData\Roaming\Spotify\Data\SpotifyHelper.exe[6320] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760e14bb 2 bytes [0E, 76] .text ... * 2 .text C:\Program Files (x86)\Overwolf\0.83.62.0\OverwolfBrowser.exe[7156] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000760e1465 2 bytes [0E, 76] .text C:\Program Files (x86)\Overwolf\0.83.62.0\OverwolfBrowser.exe[7156] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760e14bb 2 bytes [0E, 76] .text ... * 2 .text C:\Program Files (x86)\Common Files\Overwolf\0.83.62.0\OverwolfHelper.exe[7356] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 00000000760e1465 2 bytes [0E, 76] .text C:\Program Files (x86)\Common Files\Overwolf\0.83.62.0\OverwolfHelper.exe[7356] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 00000000760e14bb 2 bytes [0E, 76] .text ... * 2 .text C:\Program Files (x86)\Overwolf\0.83.62.0\Purplizer\Purplizer.exe[7616] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000760e1465 2 bytes [0E, 76] .text C:\Program Files (x86)\Overwolf\0.83.62.0\Purplizer\Purplizer.exe[7616] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760e14bb 2 bytes [0E, 76] .text ... * 2 .text C:\Program Files (x86)\Overwolf\0.83.62.0\OverwolfBrowser.exe[7900] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000760e1465 2 bytes [0E, 76] .text C:\Program Files (x86)\Overwolf\0.83.62.0\OverwolfBrowser.exe[7900] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760e14bb 2 bytes [0E, 76] .text ... * 2 ---- Kernel IAT/EAT - GMER 2.1 ---- IAT C:\Windows\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortReadPortBufferUshort] [fffff8800108df1c] \SystemRoot\System32\Drivers\sptd.sys [.text] IAT C:\Windows\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortReadPortUchar] [fffff8800108dcc0] \SystemRoot\System32\Drivers\sptd.sys [.text] IAT C:\Windows\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortUchar] [fffff8800108e69c] \SystemRoot\System32\Drivers\sptd.sys [.text] IAT C:\Windows\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortUlong] [fffff8800108ea98] \SystemRoot\System32\Drivers\sptd.sys [.text] IAT C:\Windows\system32\DRIVERS\atapi.sys[ataport.SYS!AtaPortWritePortBufferUshort] [fffff8800108e8f4] \SystemRoot\System32\Drivers\sptd.sys [.text] ---- Devices - GMER 2.1 ---- Device \Driver\atapi \Device\Ide\IdePort0 fffffa8009d162c0 Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-6 fffffa8009d162c0 Device \Driver\atapi \Device\Ide\IdePort1 fffffa8009d162c0 Device \Driver\atapi \Device\Ide\IdeDeviceP3T0L0-3 fffffa8009d162c0 Device \Driver\atapi \Device\Ide\IdePort2 fffffa8009d162c0 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-2 fffffa8009d162c0 Device \Driver\atapi \Device\Ide\IdePort3 fffffa8009d162c0 Device \Driver\aajgonw4 \Device\Scsi\aajgonw41Port5Path0Target0Lun0 fffffa800c0d72c0 Device \Driver\aajgonw4 \Device\Scsi\aajgonw41 fffffa800c0d72c0 Device \FileSystem\Ntfs \Ntfs fffffa8009d1c2c0 Device \Driver\usbehci \Device\USBPDO-1 fffffa800c0512c0 Device \Driver\mvs91xx \Device\RaidPort0 fffffa8009d182c0 Device \Driver\cdrom \Device\CdRom0 fffffa800b8322c0 Device \Driver\cdrom \Device\CdRom1 fffffa800b8322c0 Device \Driver\usbehci \Device\USBFDO-0 fffffa800c0512c0 Device \Driver\usbehci \Device\USBFDO-1 fffffa800c0512c0 Device \Driver\NetBT \Device\NetBT_Tcpip_{2FE70322-8EFB-4759-AA22-F2EF59DAD736} fffffa800b9e52c0 Device \Driver\NetBT \Device\NetBT_Tcpip_{63A03310-1490-4AA4-BACB-1BAA52B18274} fffffa800b9e52c0 Device \Driver\NetBT \Device\NetBt_Wins_Export fffffa800b9e52c0 Device \Driver\atapi \Device\ScsiPort0 fffffa8009d162c0 Device \Driver\usbehci \Device\USBPDO-0 fffffa800c0512c0 Device \Driver\atapi \Device\ScsiPort1 fffffa8009d162c0 Device \Driver\atapi \Device\ScsiPort2 fffffa8009d162c0 Device \Driver\atapi \Device\ScsiPort3 fffffa8009d162c0 Device \Driver\mvs91xx \Device\ScsiPort4 fffffa8009d182c0 Device \Driver\aajgonw4 \Device\ScsiPort5 fffffa800c0d72c0 ---- Trace I/O - GMER 2.1 ---- Trace ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys >>UNKNOWN [0xfffffa8009d162c0]<< sptd.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys fffffa8009d162c0 Trace 1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0xfffffa800b6e8060] fffffa800b6e8060 Trace 3 CLASSPNP.SYS[fffff88001aee43f] -> nt!IofCallDriver -> [0xfffffa8009dab900] fffffa8009dab900 Trace 5 ACPI.sys[fffff8800100b781] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP3T0L0-3[0xfffffa800a398060] fffffa800a398060 Trace \Driver\atapi[0xfffffa800a36d060] -> IRP_MJ_CREATE -> 0xfffffa8009d162c0 fffffa8009d162c0 ---- Modules - GMER 2.1 ---- Module \SystemRoot\System32\Drivers\aajgonw4.SYS fffff88006348000-fffff88006394000 (311296 bytes) ---- Threads - GMER 2.1 ---- Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [5936:7120] 000007fefb212a88 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [5936:7140] 000007feebedc0b0 ---- Processes - GMER 2.1 ---- Process C:\Users\Kamil\AppData\Local\Temp\Rar$EXa0.921\jhnmqgsg.exe (*** suspicious ***) @ C:\Users\Kamil\AppData\Local\Temp\Rar$EXa0.921\jhnmqgsg.exe [5168](2015-02-04 12:59:56) 0000000000400000 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files (x86)\Alcohol Soft\Alcohol 120\ Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x9B 0x4B 0x99 0x30 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0xA0 0x02 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x0E 0x0A 0xF3 0xEE ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xF6 0x65 0xA2 0x68 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files (x86)\Alcohol Soft\Alcohol 120\ Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0 Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x9B 0x4B 0x99 0x30 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0xA0 0x02 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x0E 0x0A 0xF3 0xEE ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xF6 0x65 0xA2 0x68 ... ---- Files - GMER 2.1 ---- File C:\Users\Kamil\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\7A60.tmp 28134 bytes File C:\Users\Kamil\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\7A71.tmp 28134 bytes File C:\Users\Kamil\AppData\Local\Google\Chrome\User Data\Default\JumpListIcons\7A73.tmp 28134 bytes File C:\Users\Kamil\Desktop\RESZTA\Foldery\Web\Template\Joomla_new\RT_Ionosphere15_25\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\plugins\editors\rokpad\rokpad\lib\htmlpurifier-2.1.5\HTMLPurifier\DefinitionCache\Decorator\Cleanup.php 1104 bytes File C:\Users\Kamil\Desktop\RESZTA\Foldery\Web\Template\Joomla_new\RT_Ionosphere15_25\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\plugins\editors\rokpad\rokpad\lib\htmlpurifier-2.1.5\HTMLPurifier\DefinitionCache\Decorator\index.html 47 bytes File C:\Users\Kamil\Desktop\RESZTA\Foldery\Web\Template\Joomla_new\RT_Ionosphere15_25\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\plugins\editors\rokpad\rokpad\lib\htmlpurifier-2.1.5\HTMLPurifier\DefinitionCache\Decorator\Memory.php 1426 bytes File C:\Users\Kamil\Desktop\RESZTA\Foldery\Web\Template\Joomla_new\RT_Ionosphere15_25\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\plugins\editors\rokpad\rokpad\lib\htmlpurifier-2.1.5\HTMLPurifier\DefinitionCache\Serializer\index.html 47 bytes File C:\Users\Kamil\Desktop\RESZTA\Foldery\Web\Template\Joomla_new\RT_Ionosphere15_25\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\plugins\editors\rokpad\rokpad\lib\htmlpurifier-4.0.0\HTMLPurifier\ConfigSchema\Interchange\Directive.php 1831 bytes File C:\Users\Kamil\Desktop\RESZTA\Foldery\Web\Template\Joomla_new\RT_Ionosphere15_25\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\plugins\editors\rokpad\rokpad\lib\htmlpurifier-4.0.0\HTMLPurifier\ConfigSchema\Interchange\Id.php 818 bytes File C:\Users\Kamil\Desktop\RESZTA\Foldery\Web\Template\Joomla_new\RT_Ionosphere15_25\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\plugins\editors\rokpad\rokpad\lib\htmlpurifier-4.0.0\HTMLPurifier\ConfigSchema\Interchange\index.html 47 bytes File C:\Users\Kamil\Desktop\RESZTA\Foldery\Web\Template\Joomla_new\RT_Ionosphere15_25\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\plugins\editors\rokpad\rokpad\lib\htmlpurifier-4.0.0\HTMLPurifier\DefinitionCache\Decorator\Cleanup.php 1075 bytes File C:\Users\Kamil\Desktop\RESZTA\Foldery\Web\Template\Joomla_new\RT_Ionosphere15_25\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\plugins\editors\rokpad\rokpad\lib\htmlpurifier-4.0.0\HTMLPurifier\DefinitionCache\Decorator\index.html 47 bytes File C:\Users\Kamil\Desktop\RESZTA\Foldery\Web\Template\Joomla_new\RT_Ionosphere15_25\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\plugins\editors\rokpad\rokpad\lib\htmlpurifier-4.0.0\HTMLPurifier\DefinitionCache\Decorator\Memory.php 1402 bytes File C:\Users\Kamil\Desktop\RESZTA\Foldery\Web\Template\Joomla_new\RT_Ionosphere15_25\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\plugins\editors\rokpad\rokpad\lib\htmlpurifier-4.0.0\HTMLPurifier\DefinitionCache\Serializer\index.html 47 bytes File C:\Users\Kamil\Desktop\RESZTA\Foldery\Web\Template\Joomla_new\RT_Ionosphere15_25\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\rt_ionosphere-rocketlauncher\plugins\editors\rokpad\rokpad\lib\htmlpurifier-4.0.0\HTMLPurifier\DefinitionCache\Serializer\README 99 bytes ---- EOF - GMER 2.1 ----