GMER 1.0.15.15640 - http://www.gmer.net Rootkit scan 2011-06-20 23:52:08 Windows 5.1.2600 Dodatek Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD600VE-00HDT0 rev.09.07D09 Running: pd5v07f1.exe; Driver: C:\DOCUME~1\OEM\USTAWI~1\Temp\uwldyaog.sys ---- System - GMER 1.0.15 ---- SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0xEEBD6202] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0xEEC64CB2] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwClose [0xEEBFA6C1] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0xEEBD881C] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0xEEBD8874] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0xEEBD898A] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateKey [0xEEBFA075] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0xEEBD8772] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0xEEBD88C4] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0xEEBD87C6] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0xEEBD8938] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0xEEBD6226] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteKey [0xEEBFAD87] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteValueKey [0xEEBFB03D] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDuplicateObject [0xEEBD8C0E] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateKey [0xEEBFABF2] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateValueKey [0xEEBFAA5D] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0xEEC64D62] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0xEEBD5FF0] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0xEEBD624A] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0xEEBD8D82] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0xEEBD6CDA] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0xEEBD884C] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0xEEBD889C] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0xEEBD89B4] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenKey [0xEEBFA3D1] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0xEEBD879E] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenProcess [0xEEBD8A46] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0xEEBD8904] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0xEEBD87F4] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenThread [0xEEBD8B2A] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0xEEBD8962] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0xEEC64DFA] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryKey [0xEEBFA8D8] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0xEEBD6BA0] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryValueKey [0xEEBFA72A] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwRenameKey [0xEEC6DE48] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwRestoreKey [0xEEBF96E8] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0xEEBD626E] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0xEEBD6292] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0xEEBD604A] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0xEEBD6186] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetValueKey [0xEEBFAE8E] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0xEEBD6162] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0xEEBD61AA] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0xEEBD62B6] Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0xEEC7A902] Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject ---- Kernel code sections - GMER 1.0.15 ---- .text ntoskrnl.exe!_abnormal_termination + 37F 804E3050 4 Bytes [E8, 96, BF, EE] PAGE ntoskrnl.exe!ObInsertObject 805648A3 5 Bytes JMP EEC77D5C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) PAGE ntoskrnl.exe!ZwReplyWaitReceivePortEx + 3CC 8056A5DC 4 Bytes CALL EEBD7335 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) PAGE ntoskrnl.exe!ZwCreateProcessEx 805885D3 7 Bytes JMP EEC7A906 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) PAGE ntoskrnl.exe!ObMakeTemporaryObject 805A2BF9 5 Bytes JMP EEC762BE \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) init C:\WINDOWS\system32\drivers\o2mmb.sys entry point in "init" section [0xF722C320] .text win32k.sys!EngFreeUserMem + 674 BF80BA4F 5 Bytes JMP EEBD9CCE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngDeleteSurface + 45 BF810175 5 Bytes JMP EEBD9BDA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngBitBlt + 92C BF827A40 5 Bytes JMP EEBD8F60 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngUnmapFontFileFD + D80 BF83331E 5 Bytes JMP EEBD9E38 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngUnmapFontFileFD + 7717 BF839CB5 5 Bytes JMP EEBDA040 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngUnmapFontFileFD + 112EA BF843888 5 Bytes JMP EEBD8E9C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngMulDiv + 5509 BF849B03 5 Bytes JMP EEBD906A \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngTextOut + 1437 BF854BF4 5 Bytes JMP EEBD9B4A \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngFillPath + 1036 BF857AD0 5 Bytes JMP EEBD9D80 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngStrokePath + 62A3 BF87FFC9 5 Bytes JMP EEBD91AC \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngStrokePath + 632C BF880052 5 Bytes JMP EEBD9352 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngStrokePath + 70B0 BF880DD6 5 Bytes JMP EEBD8E84 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngCreatePalette + 245E BF884C65 5 Bytes JMP EEBD9F9E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!BRUSHOBJ_hGetColorTransform + AFDD BF89F83F 5 Bytes JMP EEBD932A \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngGradientFill + 4E4C BF8CEEE3 5 Bytes JMP EEBD8DB8 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!PATHOBJ_bCloseFigure + A434 BF8DAA77 5 Bytes JMP EEBD9C04 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!FONTOBJ_pxoGetXform + 77D BF8FAF04 5 Bytes JMP EEBD8FD0 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!PATHOBJ_vGetBounds + 58C BF908B12 5 Bytes JMP EEBD90DA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!PATHOBJ_vGetBounds + 80C BF908D92 5 Bytes JMP EEBD9114 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngCreateClip + 1993 BF911AD9 5 Bytes JMP EEBD8F1C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngCreateClip + 2567 BF9126AD 5 Bytes JMP EEBD9034 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngCreateClip + 4EC1 BF915007 5 Bytes JMP EEBD946C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) .text win32k.sys!EngPlgBlt + 191E BF94290C 5 Bytes JMP EEBD9EF6 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ---- User code sections - GMER 1.0.15 ---- .text C:\WINDOWS\system32\spoolsv.exe[384] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 000901F8 .text C:\WINDOWS\system32\spoolsv.exe[384] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916FCA 1 Byte [62] .text C:\WINDOWS\system32\spoolsv.exe[384] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 000903FC .text C:\WINDOWS\system32\spoolsv.exe[384] kernel32.dll!GetBinaryTypeW + 80 7C8678BC 1 Byte [62] .text C:\WINDOWS\system32\spoolsv.exe[384] ADVAPI32.dll!SetServiceObjectSecurity 77E26BE1 5 Bytes JMP 002F1014 .text C:\WINDOWS\system32\spoolsv.exe[384] ADVAPI32.dll!ChangeServiceConfigA 77E26CC9 5 Bytes JMP 002F0804 .text C:\WINDOWS\system32\spoolsv.exe[384] ADVAPI32.dll!ChangeServiceConfigW 77E26E61 5 Bytes JMP 002F0A08 .text C:\WINDOWS\system32\spoolsv.exe[384] ADVAPI32.dll!ChangeServiceConfig2A 77E26F61 5 Bytes JMP 002F0C0C .text C:\WINDOWS\system32\spoolsv.exe[384] ADVAPI32.dll!ChangeServiceConfig2W 77E26FE9 5 Bytes JMP 002F0E10 .text C:\WINDOWS\system32\spoolsv.exe[384] ADVAPI32.dll!CreateServiceA 77E27071 5 Bytes JMP 002F01F8 .text C:\WINDOWS\system32\spoolsv.exe[384] ADVAPI32.dll!CreateServiceW 77E27209 5 Bytes JMP 002F03FC .text C:\WINDOWS\system32\spoolsv.exe[384] ADVAPI32.dll!DeleteService 77E27311 5 Bytes JMP 002F0600 .text C:\WINDOWS\system32\spoolsv.exe[384] USER32.dll!SetWinEventHook 77D5E3D3 5 Bytes JMP 003001F8 .text C:\WINDOWS\system32\spoolsv.exe[384] USER32.dll!UnhookWinEvent 77D5E544 5 Bytes JMP 003003FC .text C:\WINDOWS\system32\spoolsv.exe[384] USER32.dll!SetWindowsHookExW 77D5E621 5 Bytes JMP 00300804 .text C:\WINDOWS\system32\spoolsv.exe[384] USER32.dll!UnhookWindowsHookEx 77D5F29F 5 Bytes JMP 00300A08 .text C:\WINDOWS\system32\spoolsv.exe[384] USER32.dll!SetWindowsHookExA 77D602B2 5 Bytes JMP 00300600 .text C:\Program Files\Google\Update\GoogleUpdate.exe[572] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 001501F8 .text C:\Program Files\Google\Update\GoogleUpdate.exe[572] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916FCA 1 Byte [62] .text C:\Program Files\Google\Update\GoogleUpdate.exe[572] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 001503FC .text C:\Program Files\Google\Update\GoogleUpdate.exe[572] kernel32.dll!GetBinaryTypeW + 80 7C8678BC 1 Byte [62] .text C:\Program Files\Google\Update\GoogleUpdate.exe[572] ADVAPI32.dll!SetServiceObjectSecurity 77E26BE1 5 Bytes JMP 003D1014 .text C:\Program Files\Google\Update\GoogleUpdate.exe[572] ADVAPI32.dll!ChangeServiceConfigA 77E26CC9 5 Bytes JMP 003D0804 .text C:\Program Files\Google\Update\GoogleUpdate.exe[572] ADVAPI32.dll!ChangeServiceConfigW 77E26E61 5 Bytes JMP 003D0A08 .text C:\Program Files\Google\Update\GoogleUpdate.exe[572] ADVAPI32.dll!ChangeServiceConfig2A 77E26F61 5 Bytes JMP 003D0C0C .text C:\Program Files\Google\Update\GoogleUpdate.exe[572] ADVAPI32.dll!ChangeServiceConfig2W 77E26FE9 5 Bytes JMP 003D0E10 .text C:\Program Files\Google\Update\GoogleUpdate.exe[572] ADVAPI32.dll!CreateServiceA 77E27071 5 Bytes JMP 003D01F8 .text C:\Program Files\Google\Update\GoogleUpdate.exe[572] ADVAPI32.dll!CreateServiceW 77E27209 5 Bytes JMP 003D03FC .text C:\Program Files\Google\Update\GoogleUpdate.exe[572] ADVAPI32.dll!DeleteService 77E27311 5 Bytes JMP 003D0600 .text C:\Program Files\Google\Update\GoogleUpdate.exe[572] USER32.dll!SetWinEventHook 77D5E3D3 5 Bytes JMP 003E01F8 .text C:\Program Files\Google\Update\GoogleUpdate.exe[572] USER32.dll!UnhookWinEvent 77D5E544 5 Bytes JMP 003E03FC .text C:\Program Files\Google\Update\GoogleUpdate.exe[572] USER32.dll!SetWindowsHookExW 77D5E621 5 Bytes JMP 003E0804 .text C:\Program Files\Google\Update\GoogleUpdate.exe[572] USER32.dll!UnhookWindowsHookEx 77D5F29F 5 Bytes JMP 003E0A08 .text C:\Program Files\Google\Update\GoogleUpdate.exe[572] USER32.dll!SetWindowsHookExA 77D602B2 5 Bytes JMP 003E0600 .text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[588] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 001401F8 .text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[588] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916FCA 1 Byte [62] .text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[588] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 001403FC .text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[588] kernel32.dll!GetBinaryTypeW + 80 7C8678BC 1 Byte [62] .text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[588] ADVAPI32.dll!SetServiceObjectSecurity 77E26BE1 5 Bytes JMP 003C1014 .text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[588] ADVAPI32.dll!ChangeServiceConfigA 77E26CC9 5 Bytes JMP 003C0804 .text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[588] ADVAPI32.dll!ChangeServiceConfigW 77E26E61 5 Bytes JMP 003C0A08 .text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[588] ADVAPI32.dll!ChangeServiceConfig2A 77E26F61 5 Bytes JMP 003C0C0C .text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[588] ADVAPI32.dll!ChangeServiceConfig2W 77E26FE9 5 Bytes JMP 003C0E10 .text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[588] ADVAPI32.dll!CreateServiceA 77E27071 5 Bytes JMP 003C01F8 .text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[588] ADVAPI32.dll!CreateServiceW 77E27209 5 Bytes JMP 003C03FC .text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[588] ADVAPI32.dll!DeleteService 77E27311 5 Bytes JMP 003C0600 .text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[588] USER32.dll!SetWinEventHook 77D5E3D3 5 Bytes JMP 003D01F8 .text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[588] USER32.dll!UnhookWinEvent 77D5E544 5 Bytes JMP 003D03FC .text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[588] USER32.dll!SetWindowsHookExW 77D5E621 5 Bytes JMP 003D0804 .text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[588] USER32.dll!UnhookWindowsHookEx 77D5F29F 5 Bytes JMP 003D0A08 .text C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[588] USER32.dll!SetWindowsHookExA 77D602B2 5 Bytes JMP 003D0600 .text C:\WINDOWS\System32\smss.exe[696] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916FCA 1 Byte [62] .text C:\WINDOWS\system32\slserv.exe[728] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 001401F8 .text C:\WINDOWS\system32\slserv.exe[728] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916FCA 1 Byte [62] .text C:\WINDOWS\system32\slserv.exe[728] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 001403FC .text C:\WINDOWS\system32\slserv.exe[728] kernel32.dll!GetBinaryTypeW + 80 7C8678BC 1 Byte [62] .text C:\WINDOWS\system32\slserv.exe[728] ADVAPI32.dll!SetServiceObjectSecurity 77E26BE1 5 Bytes JMP 003C1014 .text C:\WINDOWS\system32\slserv.exe[728] ADVAPI32.dll!ChangeServiceConfigA 77E26CC9 5 Bytes JMP 003C0804 .text C:\WINDOWS\system32\slserv.exe[728] ADVAPI32.dll!ChangeServiceConfigW 77E26E61 5 Bytes JMP 003C0A08 .text C:\WINDOWS\system32\slserv.exe[728] ADVAPI32.dll!ChangeServiceConfig2A 77E26F61 5 Bytes JMP 003C0C0C .text C:\WINDOWS\system32\slserv.exe[728] ADVAPI32.dll!ChangeServiceConfig2W 77E26FE9 5 Bytes JMP 003C0E10 .text C:\WINDOWS\system32\slserv.exe[728] ADVAPI32.dll!CreateServiceA 77E27071 5 Bytes JMP 003C01F8 .text C:\WINDOWS\system32\slserv.exe[728] ADVAPI32.dll!CreateServiceW 77E27209 5 Bytes JMP 003C03FC .text C:\WINDOWS\system32\slserv.exe[728] ADVAPI32.dll!DeleteService 77E27311 5 Bytes JMP 003C0600 .text C:\WINDOWS\system32\csrss.exe[748] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916FCA 1 Byte [62] .text C:\WINDOWS\system32\csrss.exe[748] KERNEL32.dll!GetBinaryTypeW + 80 7C8678BC 1 Byte [62] .text C:\WINDOWS\system32\winlogon.exe[776] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 000701F8 .text C:\WINDOWS\system32\winlogon.exe[776] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916FCA 1 Byte [62] .text C:\WINDOWS\system32\winlogon.exe[776] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 000703FC .text C:\WINDOWS\system32\winlogon.exe[776] kernel32.dll!GetBinaryTypeW + 80 7C8678BC 1 Byte [62] .text C:\WINDOWS\system32\winlogon.exe[776] ADVAPI32.dll!SetServiceObjectSecurity 77E26BE1 5 Bytes JMP 002F1014 .text C:\WINDOWS\system32\winlogon.exe[776] ADVAPI32.dll!ChangeServiceConfigA 77E26CC9 5 Bytes JMP 002F0804 .text C:\WINDOWS\system32\winlogon.exe[776] ADVAPI32.dll!ChangeServiceConfigW 77E26E61 5 Bytes JMP 002F0A08 .text C:\WINDOWS\system32\winlogon.exe[776] ADVAPI32.dll!ChangeServiceConfig2A 77E26F61 5 Bytes JMP 002F0C0C .text C:\WINDOWS\system32\winlogon.exe[776] ADVAPI32.dll!ChangeServiceConfig2W 77E26FE9 5 Bytes JMP 002F0E10 .text C:\WINDOWS\system32\winlogon.exe[776] ADVAPI32.dll!CreateServiceA 77E27071 5 Bytes JMP 002F01F8 .text C:\WINDOWS\system32\winlogon.exe[776] ADVAPI32.dll!CreateServiceW 77E27209 5 Bytes JMP 002F03FC .text C:\WINDOWS\system32\winlogon.exe[776] ADVAPI32.dll!DeleteService 77E27311 5 Bytes JMP 002F0600 .text C:\WINDOWS\system32\winlogon.exe[776] USER32.dll!SetWinEventHook 77D5E3D3 5 Bytes JMP 003001F8 .text C:\WINDOWS\system32\winlogon.exe[776] USER32.dll!UnhookWinEvent 77D5E544 5 Bytes JMP 003003FC .text C:\WINDOWS\system32\winlogon.exe[776] USER32.dll!SetWindowsHookExW 77D5E621 5 Bytes JMP 00300804 .text C:\WINDOWS\system32\winlogon.exe[776] USER32.dll!UnhookWindowsHookEx 77D5F29F 5 Bytes JMP 00300A08 .text C:\WINDOWS\system32\winlogon.exe[776] USER32.dll!SetWindowsHookExA 77D602B2 5 Bytes JMP 00300600 .text C:\WINDOWS\system32\services.exe[820] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 000901F8 .text C:\WINDOWS\system32\services.exe[820] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916FCA 1 Byte [62] .text C:\WINDOWS\system32\services.exe[820] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 000903FC .text C:\WINDOWS\system32\services.exe[820] kernel32.dll!GetBinaryTypeW + 80 7C8678BC 1 Byte [62] .text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!SetServiceObjectSecurity 77E26BE1 5 Bytes JMP 002F1014 .text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!ChangeServiceConfigA 77E26CC9 5 Bytes JMP 002F0804 .text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!ChangeServiceConfigW 77E26E61 5 Bytes JMP 002F0A08 .text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!ChangeServiceConfig2A 77E26F61 5 Bytes JMP 002F0C0C .text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!ChangeServiceConfig2W 77E26FE9 5 Bytes JMP 002F0E10 .text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!CreateServiceA 77E27071 5 Bytes JMP 002F01F8 .text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!CreateServiceW 77E27209 5 Bytes JMP 002F03FC .text C:\WINDOWS\system32\services.exe[820] ADVAPI32.dll!DeleteService 77E27311 5 Bytes JMP 002F0600 .text C:\WINDOWS\system32\services.exe[820] USER32.dll!SetWinEventHook 77D5E3D3 5 Bytes JMP 003001F8 .text C:\WINDOWS\system32\services.exe[820] USER32.dll!UnhookWinEvent 77D5E544 5 Bytes JMP 003003FC .text C:\WINDOWS\system32\services.exe[820] USER32.dll!SetWindowsHookExW 77D5E621 5 Bytes JMP 00300804 .text C:\WINDOWS\system32\services.exe[820] USER32.dll!UnhookWindowsHookEx 77D5F29F 5 Bytes JMP 00300A08 .text C:\WINDOWS\system32\services.exe[820] USER32.dll!SetWindowsHookExA 77D602B2 5 Bytes JMP 00300600 .text C:\WINDOWS\system32\lsass.exe[832] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 000901F8 .text C:\WINDOWS\system32\lsass.exe[832] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916FCA 1 Byte [62] .text C:\WINDOWS\system32\lsass.exe[832] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 000903FC .text C:\WINDOWS\system32\lsass.exe[832] kernel32.dll!GetBinaryTypeW + 80 7C8678BC 1 Byte [62] .text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!SetServiceObjectSecurity 77E26BE1 5 Bytes JMP 002F1014 .text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!ChangeServiceConfigA 77E26CC9 5 Bytes JMP 002F0804 .text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!ChangeServiceConfigW 77E26E61 5 Bytes JMP 002F0A08 .text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!ChangeServiceConfig2A 77E26F61 5 Bytes JMP 002F0C0C .text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!ChangeServiceConfig2W 77E26FE9 5 Bytes JMP 002F0E10 .text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!CreateServiceA 77E27071 5 Bytes JMP 002F01F8 .text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!CreateServiceW 77E27209 5 Bytes JMP 002F03FC .text C:\WINDOWS\system32\lsass.exe[832] ADVAPI32.dll!DeleteService 77E27311 5 Bytes JMP 002F0600 .text C:\WINDOWS\system32\lsass.exe[832] USER32.dll!SetWinEventHook 77D5E3D3 5 Bytes JMP 003001F8 .text C:\WINDOWS\system32\lsass.exe[832] USER32.dll!UnhookWinEvent 77D5E544 5 Bytes JMP 003003FC .text C:\WINDOWS\system32\lsass.exe[832] USER32.dll!SetWindowsHookExW 77D5E621 5 Bytes JMP 00300804 .text C:\WINDOWS\system32\lsass.exe[832] USER32.dll!UnhookWindowsHookEx 77D5F29F 5 Bytes JMP 00300A08 .text C:\WINDOWS\system32\lsass.exe[832] USER32.dll!SetWindowsHookExA 77D602B2 5 Bytes JMP 00300600 .text C:\WINDOWS\system32\svchost.exe[988] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 000901F8 .text C:\WINDOWS\system32\svchost.exe[988] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916FCA 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[988] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 000903FC .text C:\WINDOWS\system32\svchost.exe[988] kernel32.dll!GetBinaryTypeW + 80 7C8678BC 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!SetServiceObjectSecurity 77E26BE1 5 Bytes JMP 002F1014 .text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!ChangeServiceConfigA 77E26CC9 5 Bytes JMP 002F0804 .text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!ChangeServiceConfigW 77E26E61 5 Bytes JMP 002F0A08 .text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!ChangeServiceConfig2A 77E26F61 5 Bytes JMP 002F0C0C .text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!ChangeServiceConfig2W 77E26FE9 5 Bytes JMP 002F0E10 .text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!CreateServiceA 77E27071 5 Bytes JMP 002F01F8 .text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!CreateServiceW 77E27209 5 Bytes JMP 002F03FC .text C:\WINDOWS\system32\svchost.exe[988] ADVAPI32.dll!DeleteService 77E27311 5 Bytes JMP 002F0600 .text C:\WINDOWS\system32\svchost.exe[988] USER32.dll!SetWinEventHook 77D5E3D3 5 Bytes JMP 003001F8 .text C:\WINDOWS\system32\svchost.exe[988] USER32.dll!UnhookWinEvent 77D5E544 5 Bytes JMP 003003FC .text C:\WINDOWS\system32\svchost.exe[988] USER32.dll!SetWindowsHookExW 77D5E621 5 Bytes JMP 00300804 .text C:\WINDOWS\system32\svchost.exe[988] USER32.dll!UnhookWindowsHookEx 77D5F29F 5 Bytes JMP 00300A08 .text C:\WINDOWS\system32\svchost.exe[988] USER32.dll!SetWindowsHookExA 77D602B2 5 Bytes JMP 00300600 .text C:\WINDOWS\system32\svchost.exe[1088] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 000901F8 .text C:\WINDOWS\system32\svchost.exe[1088] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916FCA 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1088] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 000903FC .text C:\WINDOWS\system32\svchost.exe[1088] kernel32.dll!GetBinaryTypeW + 80 7C8678BC 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1088] ADVAPI32.dll!SetServiceObjectSecurity 77E26BE1 5 Bytes JMP 002F1014 .text C:\WINDOWS\system32\svchost.exe[1088] ADVAPI32.dll!ChangeServiceConfigA 77E26CC9 5 Bytes JMP 002F0804 .text C:\WINDOWS\system32\svchost.exe[1088] ADVAPI32.dll!ChangeServiceConfigW 77E26E61 5 Bytes JMP 002F0A08 .text C:\WINDOWS\system32\svchost.exe[1088] ADVAPI32.dll!ChangeServiceConfig2A 77E26F61 5 Bytes JMP 002F0C0C .text C:\WINDOWS\system32\svchost.exe[1088] ADVAPI32.dll!ChangeServiceConfig2W 77E26FE9 5 Bytes JMP 002F0E10 .text C:\WINDOWS\system32\svchost.exe[1088] ADVAPI32.dll!CreateServiceA 77E27071 5 Bytes JMP 002F01F8 .text C:\WINDOWS\system32\svchost.exe[1088] ADVAPI32.dll!CreateServiceW 77E27209 5 Bytes JMP 002F03FC .text C:\WINDOWS\system32\svchost.exe[1088] ADVAPI32.dll!DeleteService 77E27311 5 Bytes JMP 002F0600 .text C:\WINDOWS\system32\svchost.exe[1088] USER32.dll!SetWinEventHook 77D5E3D3 5 Bytes JMP 003001F8 .text C:\WINDOWS\system32\svchost.exe[1088] USER32.dll!UnhookWinEvent 77D5E544 5 Bytes JMP 003003FC .text C:\WINDOWS\system32\svchost.exe[1088] USER32.dll!SetWindowsHookExW 77D5E621 5 Bytes JMP 00300804 .text C:\WINDOWS\system32\svchost.exe[1088] USER32.dll!UnhookWindowsHookEx 77D5F29F 5 Bytes JMP 00300A08 .text C:\WINDOWS\system32\svchost.exe[1088] USER32.dll!SetWindowsHookExA 77D602B2 5 Bytes JMP 00300600 .text C:\WINDOWS\System32\svchost.exe[1132] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 000901F8 .text C:\WINDOWS\System32\svchost.exe[1132] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916FCA 1 Byte [62] .text C:\WINDOWS\System32\svchost.exe[1132] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 000903FC .text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!GetBinaryTypeW + 80 7C8678BC 1 Byte [62] .text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!SetServiceObjectSecurity 77E26BE1 5 Bytes JMP 002F1014 .text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!ChangeServiceConfigA 77E26CC9 5 Bytes JMP 002F0804 .text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!ChangeServiceConfigW 77E26E61 5 Bytes JMP 002F0A08 .text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!ChangeServiceConfig2A 77E26F61 5 Bytes JMP 002F0C0C .text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!ChangeServiceConfig2W 77E26FE9 5 Bytes JMP 002F0E10 .text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!CreateServiceA 77E27071 5 Bytes JMP 002F01F8 .text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!CreateServiceW 77E27209 5 Bytes JMP 002F03FC .text C:\WINDOWS\System32\svchost.exe[1132] ADVAPI32.dll!DeleteService 77E27311 5 Bytes JMP 002F0600 .text C:\WINDOWS\System32\svchost.exe[1132] USER32.dll!SetWinEventHook 77D5E3D3 5 Bytes JMP 003001F8 .text C:\WINDOWS\System32\svchost.exe[1132] USER32.dll!UnhookWinEvent 77D5E544 5 Bytes JMP 003003FC .text C:\WINDOWS\System32\svchost.exe[1132] USER32.dll!SetWindowsHookExW 77D5E621 5 Bytes JMP 00300804 .text C:\WINDOWS\System32\svchost.exe[1132] USER32.dll!UnhookWindowsHookEx 77D5F29F 5 Bytes JMP 00300A08 .text C:\WINDOWS\System32\svchost.exe[1132] USER32.dll!SetWindowsHookExA 77D602B2 5 Bytes JMP 00300600 .text C:\WINDOWS\system32\svchost.exe[1168] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 000901F8 .text C:\WINDOWS\system32\svchost.exe[1168] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916FCA 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1168] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 000903FC .text C:\WINDOWS\system32\svchost.exe[1168] kernel32.dll!GetBinaryTypeW + 80 7C8678BC 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1168] ADVAPI32.dll!SetServiceObjectSecurity 77E26BE1 5 Bytes JMP 002F1014 .text C:\WINDOWS\system32\svchost.exe[1168] ADVAPI32.dll!ChangeServiceConfigA 77E26CC9 5 Bytes JMP 002F0804 .text C:\WINDOWS\system32\svchost.exe[1168] ADVAPI32.dll!ChangeServiceConfigW 77E26E61 5 Bytes JMP 002F0A08 .text C:\WINDOWS\system32\svchost.exe[1168] ADVAPI32.dll!ChangeServiceConfig2A 77E26F61 5 Bytes JMP 002F0C0C .text C:\WINDOWS\system32\svchost.exe[1168] ADVAPI32.dll!ChangeServiceConfig2W 77E26FE9 5 Bytes JMP 002F0E10 .text C:\WINDOWS\system32\svchost.exe[1168] ADVAPI32.dll!CreateServiceA 77E27071 5 Bytes JMP 002F01F8 .text C:\WINDOWS\system32\svchost.exe[1168] ADVAPI32.dll!CreateServiceW 77E27209 5 Bytes JMP 002F03FC .text C:\WINDOWS\system32\svchost.exe[1168] ADVAPI32.dll!DeleteService 77E27311 5 Bytes JMP 002F0600 .text C:\WINDOWS\system32\svchost.exe[1168] USER32.dll!SetWinEventHook 77D5E3D3 5 Bytes JMP 003001F8 .text C:\WINDOWS\system32\svchost.exe[1168] USER32.dll!UnhookWinEvent 77D5E544 5 Bytes JMP 003003FC .text C:\WINDOWS\system32\svchost.exe[1168] USER32.dll!SetWindowsHookExW 77D5E621 5 Bytes JMP 00300804 .text C:\WINDOWS\system32\svchost.exe[1168] USER32.dll!UnhookWindowsHookEx 77D5F29F 5 Bytes JMP 00300A08 .text C:\WINDOWS\system32\svchost.exe[1168] USER32.dll!SetWindowsHookExA 77D602B2 5 Bytes JMP 00300600 .text C:\WINDOWS\system32\svchost.exe[1264] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 000901F8 .text C:\WINDOWS\system32\svchost.exe[1264] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916FCA 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1264] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 000903FC .text C:\WINDOWS\system32\svchost.exe[1264] kernel32.dll!GetBinaryTypeW + 80 7C8678BC 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!SetServiceObjectSecurity 77E26BE1 5 Bytes JMP 002F1014 .text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!ChangeServiceConfigA 77E26CC9 5 Bytes JMP 002F0804 .text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!ChangeServiceConfigW 77E26E61 5 Bytes JMP 002F0A08 .text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!ChangeServiceConfig2A 77E26F61 5 Bytes JMP 002F0C0C .text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!ChangeServiceConfig2W 77E26FE9 5 Bytes JMP 002F0E10 .text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!CreateServiceA 77E27071 5 Bytes JMP 002F01F8 .text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!CreateServiceW 77E27209 5 Bytes JMP 002F03FC .text C:\WINDOWS\system32\svchost.exe[1264] ADVAPI32.dll!DeleteService 77E27311 5 Bytes JMP 002F0600 .text C:\WINDOWS\system32\svchost.exe[1264] USER32.dll!SetWinEventHook 77D5E3D3 5 Bytes JMP 003001F8 .text C:\WINDOWS\system32\svchost.exe[1264] USER32.dll!UnhookWinEvent 77D5E544 5 Bytes JMP 003003FC .text C:\WINDOWS\system32\svchost.exe[1264] USER32.dll!SetWindowsHookExW 77D5E621 5 Bytes JMP 00300804 .text C:\WINDOWS\system32\svchost.exe[1264] USER32.dll!UnhookWindowsHookEx 77D5F29F 5 Bytes JMP 00300A08 .text C:\WINDOWS\system32\svchost.exe[1264] USER32.dll!SetWindowsHookExA 77D602B2 5 Bytes JMP 00300600 .text C:\WINDOWS\system32\svchost.exe[1312] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 000901F8 .text C:\WINDOWS\system32\svchost.exe[1312] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916FCA 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1312] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 000903FC .text C:\WINDOWS\system32\svchost.exe[1312] kernel32.dll!GetBinaryTypeW + 80 7C8678BC 1 Byte [62] .text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!SetServiceObjectSecurity 77E26BE1 5 Bytes JMP 002F1014 .text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!ChangeServiceConfigA 77E26CC9 5 Bytes JMP 002F0804 .text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!ChangeServiceConfigW 77E26E61 5 Bytes JMP 002F0A08 .text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!ChangeServiceConfig2A 77E26F61 5 Bytes JMP 002F0C0C .text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!ChangeServiceConfig2W 77E26FE9 5 Bytes JMP 002F0E10 .text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!CreateServiceA 77E27071 5 Bytes JMP 002F01F8 .text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!CreateServiceW 77E27209 5 Bytes JMP 002F03FC .text C:\WINDOWS\system32\svchost.exe[1312] ADVAPI32.dll!DeleteService 77E27311 5 Bytes JMP 002F0600 .text C:\WINDOWS\system32\svchost.exe[1312] USER32.dll!SetWinEventHook 77D5E3D3 5 Bytes JMP 003001F8 .text C:\WINDOWS\system32\svchost.exe[1312] USER32.dll!UnhookWinEvent 77D5E544 5 Bytes JMP 003003FC .text C:\WINDOWS\system32\svchost.exe[1312] USER32.dll!SetWindowsHookExW 77D5E621 5 Bytes JMP 00300804 .text C:\WINDOWS\system32\svchost.exe[1312] USER32.dll!UnhookWindowsHookEx 77D5F29F 5 Bytes JMP 00300A08 .text C:\WINDOWS\system32\svchost.exe[1312] USER32.dll!SetWindowsHookExA 77D602B2 5 Bytes JMP 00300600 .text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1632] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916FCA 1 Byte [62] .text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1632] kernel32.dll!SetUnhandledExceptionFilter 7C810386 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP } .text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1632] kernel32.dll!GetBinaryTypeW + 80 7C8678BC 1 Byte [62] .text C:\WINDOWS\System32\alg.exe[1716] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 000901F8 .text C:\WINDOWS\System32\alg.exe[1716] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916FCA 1 Byte [62] .text C:\WINDOWS\System32\alg.exe[1716] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 000903FC .text C:\WINDOWS\System32\alg.exe[1716] kernel32.dll!GetBinaryTypeW + 80 7C8678BC 1 Byte [62] .text C:\WINDOWS\System32\alg.exe[1716] USER32.dll!SetWinEventHook 77D5E3D3 5 Bytes JMP 002F01F8 .text C:\WINDOWS\System32\alg.exe[1716] USER32.dll!UnhookWinEvent 77D5E544 5 Bytes JMP 002F03FC .text C:\WINDOWS\System32\alg.exe[1716] USER32.dll!SetWindowsHookExW 77D5E621 5 Bytes JMP 002F0804 .text C:\WINDOWS\System32\alg.exe[1716] USER32.dll!UnhookWindowsHookEx 77D5F29F 5 Bytes JMP 002F0A08 .text C:\WINDOWS\System32\alg.exe[1716] USER32.dll!SetWindowsHookExA 77D602B2 5 Bytes JMP 002F0600 .text C:\WINDOWS\System32\alg.exe[1716] ADVAPI32.dll!SetServiceObjectSecurity 77E26BE1 5 Bytes JMP 00301014 .text C:\WINDOWS\System32\alg.exe[1716] ADVAPI32.dll!ChangeServiceConfigA 77E26CC9 5 Bytes JMP 00300804 .text C:\WINDOWS\System32\alg.exe[1716] ADVAPI32.dll!ChangeServiceConfigW 77E26E61 5 Bytes JMP 00300A08 .text C:\WINDOWS\System32\alg.exe[1716] ADVAPI32.dll!ChangeServiceConfig2A 77E26F61 5 Bytes JMP 00300C0C .text C:\WINDOWS\System32\alg.exe[1716] ADVAPI32.dll!ChangeServiceConfig2W 77E26FE9 5 Bytes JMP 00300E10 .text C:\WINDOWS\System32\alg.exe[1716] ADVAPI32.dll!CreateServiceA 77E27071 5 Bytes JMP 003001F8 .text C:\WINDOWS\System32\alg.exe[1716] ADVAPI32.dll!CreateServiceW 77E27209 5 Bytes JMP 003003FC .text C:\WINDOWS\System32\alg.exe[1716] ADVAPI32.dll!DeleteService 77E27311 5 Bytes JMP 00300600 .text C:\WINDOWS\Explorer.EXE[1760] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 000901F8 .text C:\WINDOWS\Explorer.EXE[1760] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916FCA 1 Byte [62] .text C:\WINDOWS\Explorer.EXE[1760] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 000903FC .text C:\WINDOWS\Explorer.EXE[1760] kernel32.dll!GetBinaryTypeW + 80 7C8678BC 1 Byte [62] .text C:\WINDOWS\Explorer.EXE[1760] ADVAPI32.dll!SetServiceObjectSecurity 77E26BE1 5 Bytes JMP 00301014 .text C:\WINDOWS\Explorer.EXE[1760] ADVAPI32.dll!ChangeServiceConfigA 77E26CC9 5 Bytes JMP 00300804 .text C:\WINDOWS\Explorer.EXE[1760] ADVAPI32.dll!ChangeServiceConfigW 77E26E61 5 Bytes JMP 00300A08 .text C:\WINDOWS\Explorer.EXE[1760] ADVAPI32.dll!ChangeServiceConfig2A 77E26F61 5 Bytes JMP 00300C0C .text C:\WINDOWS\Explorer.EXE[1760] ADVAPI32.dll!ChangeServiceConfig2W 77E26FE9 5 Bytes JMP 00300E10 .text C:\WINDOWS\Explorer.EXE[1760] ADVAPI32.dll!CreateServiceA 77E27071 5 Bytes JMP 003001F8 .text C:\WINDOWS\Explorer.EXE[1760] ADVAPI32.dll!CreateServiceW 77E27209 5 Bytes JMP 003003FC .text C:\WINDOWS\Explorer.EXE[1760] ADVAPI32.dll!DeleteService 77E27311 5 Bytes JMP 00300600 .text C:\WINDOWS\Explorer.EXE[1760] USER32.dll!SetWinEventHook 77D5E3D3 5 Bytes JMP 003101F8 .text C:\WINDOWS\Explorer.EXE[1760] USER32.dll!UnhookWinEvent 77D5E544 5 Bytes JMP 003103FC .text C:\WINDOWS\Explorer.EXE[1760] USER32.dll!SetWindowsHookExW 77D5E621 5 Bytes JMP 00310804 .text C:\WINDOWS\Explorer.EXE[1760] USER32.dll!UnhookWindowsHookEx 77D5F29F 5 Bytes JMP 00310A08 .text C:\WINDOWS\Explorer.EXE[1760] USER32.dll!SetWindowsHookExA 77D602B2 5 Bytes JMP 00310600 .text C:\WINDOWS\system32\ctfmon.exe[2132] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 000A01F8 .text C:\WINDOWS\system32\ctfmon.exe[2132] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916FCA 1 Byte [62] .text C:\WINDOWS\system32\ctfmon.exe[2132] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 000A03FC .text C:\WINDOWS\system32\ctfmon.exe[2132] kernel32.dll!GetBinaryTypeW + 80 7C8678BC 1 Byte [62] .text C:\WINDOWS\system32\ctfmon.exe[2132] ADVAPI32.dll!SetServiceObjectSecurity 77E26BE1 5 Bytes JMP 00371014 .text C:\WINDOWS\system32\ctfmon.exe[2132] ADVAPI32.dll!ChangeServiceConfigA 77E26CC9 5 Bytes JMP 00370804 .text C:\WINDOWS\system32\ctfmon.exe[2132] ADVAPI32.dll!ChangeServiceConfigW 77E26E61 5 Bytes JMP 00370A08 .text C:\WINDOWS\system32\ctfmon.exe[2132] ADVAPI32.dll!ChangeServiceConfig2A 77E26F61 5 Bytes JMP 00370C0C .text C:\WINDOWS\system32\ctfmon.exe[2132] ADVAPI32.dll!ChangeServiceConfig2W 77E26FE9 5 Bytes JMP 00370E10 .text C:\WINDOWS\system32\ctfmon.exe[2132] ADVAPI32.dll!CreateServiceA 77E27071 5 Bytes JMP 003701F8 .text C:\WINDOWS\system32\ctfmon.exe[2132] ADVAPI32.dll!CreateServiceW 77E27209 5 Bytes JMP 003703FC .text C:\WINDOWS\system32\ctfmon.exe[2132] ADVAPI32.dll!DeleteService 77E27311 5 Bytes JMP 00370600 .text C:\WINDOWS\system32\ctfmon.exe[2132] USER32.dll!SetWinEventHook 77D5E3D3 5 Bytes JMP 003801F8 .text C:\WINDOWS\system32\ctfmon.exe[2132] USER32.dll!UnhookWinEvent 77D5E544 5 Bytes JMP 003803FC .text C:\WINDOWS\system32\ctfmon.exe[2132] USER32.dll!SetWindowsHookExW 77D5E621 5 Bytes JMP 00380804 .text C:\WINDOWS\system32\ctfmon.exe[2132] USER32.dll!UnhookWindowsHookEx 77D5F29F 5 Bytes JMP 00380A08 .text C:\WINDOWS\system32\ctfmon.exe[2132] USER32.dll!SetWindowsHookExA 77D602B2 5 Bytes JMP 00380600 .text D:\Antywiry\pd5v07f1.exe[2392] ntdll.dll!LdrLoadDll 7C9161CA 5 Bytes JMP 001501F8 .text D:\Antywiry\pd5v07f1.exe[2392] ntdll.dll!RtlDosSearchPath_U + 1D1 7C916FCA 1 Byte [62] .text D:\Antywiry\pd5v07f1.exe[2392] ntdll.dll!LdrUnloadDll 7C91718B 5 Bytes JMP 001503FC .text D:\Antywiry\pd5v07f1.exe[2392] kernel32.dll!GetBinaryTypeW + 80 7C8678BC 1 Byte [62] .text D:\Antywiry\pd5v07f1.exe[2392] ADVAPI32.dll!SetServiceObjectSecurity 77E26BE1 3 Bytes JMP 009B1014 .text D:\Antywiry\pd5v07f1.exe[2392] ADVAPI32.dll!SetServiceObjectSecurity + 4 77E26BE5 1 Byte [88] .text D:\Antywiry\pd5v07f1.exe[2392] ADVAPI32.dll!ChangeServiceConfigA 77E26CC9 5 Bytes JMP 009B0804 .text D:\Antywiry\pd5v07f1.exe[2392] ADVAPI32.dll!ChangeServiceConfigW 77E26E61 5 Bytes JMP 009B0A08 .text D:\Antywiry\pd5v07f1.exe[2392] ADVAPI32.dll!ChangeServiceConfig2A 77E26F61 5 Bytes JMP 009B0C0C .text D:\Antywiry\pd5v07f1.exe[2392] ADVAPI32.dll!ChangeServiceConfig2W 77E26FE9 5 Bytes JMP 009B0E10 .text D:\Antywiry\pd5v07f1.exe[2392] ADVAPI32.dll!CreateServiceA 77E27071 5 Bytes JMP 009B01F8 .text D:\Antywiry\pd5v07f1.exe[2392] ADVAPI32.dll!CreateServiceW 77E27209 5 Bytes JMP 009B03FC .text D:\Antywiry\pd5v07f1.exe[2392] ADVAPI32.dll!DeleteService 77E27311 5 Bytes JMP 009B0600 .text D:\Antywiry\pd5v07f1.exe[2392] USER32.dll!SetWinEventHook 77D5E3D3 5 Bytes JMP 00AC01F8 .text D:\Antywiry\pd5v07f1.exe[2392] USER32.dll!UnhookWinEvent 77D5E544 5 Bytes JMP 00AC03FC .text D:\Antywiry\pd5v07f1.exe[2392] USER32.dll!SetWindowsHookExW 77D5E621 5 Bytes JMP 00AC0804 .text D:\Antywiry\pd5v07f1.exe[2392] USER32.dll!UnhookWindowsHookEx 77D5F29F 5 Bytes JMP 00AC0A08 .text D:\Antywiry\pd5v07f1.exe[2392] USER32.dll!SetWindowsHookExA 77D602B2 5 Bytes JMP 00AC0600 ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\WINDOWS\system32\services.exe[820] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00620002 IAT C:\WINDOWS\system32\services.exe[820] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00620000 ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/AVAST Software) AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software) AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/AVAST Software) AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software) AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software) AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software) ---- Files - GMER 1.0.15 ---- File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\style-cbr[1].gif 149 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\style-ie[1].css 220 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\style[1].css 3190 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\style[2].css 31402 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\style[3].css 3190 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\supers[1].gif 508 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\swfobject_fa08[1] 6299 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\t4fbTk96lLS[1].css 1724 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\t986k0OO1IV[1].js 136173 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\tabs[1].png 229 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\tab_left[1].gif 334 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_image[3].jpg 3783 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_image[4].jpg 2412 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_image[5].jpg 2555 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_image[5].png 17204 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_image[6].jpg 3318 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_image[7].jpg 2640 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_image[8].jpg 2653 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_image[9].jpg 2126 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\search[5].php 2989 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\search[6].php 3225 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\www-core-vflvTi9ps[1].js 217466 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\WYDsZtpFC2N[2].png 112 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\wylogowano[1].gif 1196 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\xPz_in8Tq1O[1].css 1748 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\XXVvDYAks_i[1].png 667 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\x[1].png 259 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\y-2LR9eyI1L[1].gif 204 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\yDnr5YfbJCH[1].gif 1291 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\YM_skAm5nTs[1].js 130930 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\show_pics_21947[1].jpg 13490 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\show_pics_22086[1].jpg 23790 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\show_pics_22204[1].jpg 50336 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\sidebar-ads[1].htm 448 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\sidebar-links[1].png 575 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\skin-happy[1].css 7663 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\skin-modern[1].css 21207 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\QAMsMilVydZ[1].js 451 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\QH3ct8_252w[2].png 994 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\quick_menu_eba4[1].css 31918 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\ramka600[1].png 1829 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\ready_all_aff9[1] 443052 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\read[1].gif 46 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\redirectiframe[1].html 428 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\remake[1].png 1672 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\right[1].gif 171 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\robots[1].txt 401 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\roster-border-left[1].png 198 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\vanity[1].gif 42 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\viewing_options_gallery_ico[1].gif 306 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\viewing_options_header[1].png 245 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\viewing_options_small_font_ico[1].gif 82 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\viewMainPage[1].htm 40432 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\view[2].htm 37564 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_imageCA1RIVKA.jpg 1590 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_imageCAA5RU1Z.jpg 3198 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\searchCA093RTP.php 2797 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\searchCAEF1HSP.php 2821 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\searchCAGHOA2G.php 4851 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=15[1].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=16[2].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2CAG2PBTU.txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2[9].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=6[10].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=8[1].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=14[1].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\RS0YepQ_wes[1].css 9059 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\s780715916_1474271_9134[1].jpg 4464 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_imageCAG132NZ.jpg 2799 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_imageCAOI81V6.jpg 1797 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_imageCASPRH38.jpg 1763 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_imageCASTG59U.jpg 5169 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_imageCAVLUFWL.jpg 2976 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_imageCAY2Z4NA.jpg 3078 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_image[10].jpg 2979 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_image[10].png 9125 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_image[11].jpg 3682 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_image[11].png 5959 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_image[1].jpg 3660 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_image[1].png 23479 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_image[2].jpg 4064 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\voting[1].js 2173 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\VrW2oCBAAqR[1].png 577 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\wait[1].gif 1553 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\wait[2].gif 1553 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\welcome-header-back[1].png 1018 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\welcome-icon[1].png 1856 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\welcome-tip-right[1].png 265 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\welcome-tip-right[2].png 265 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\welcome-widgets-preview[1].png 42059 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\wHDx_vnawh3[1].js 8282 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\widget-header-icons[1].png 564 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\widgets[1].css 16687 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\wiejskiezycie.1202d614ab26b5099ca20881faf28f3290d5fc11[1].jpg 26524 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\wrapperCorners2[1].gif 199 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\WRlpiEVxHGI[1].png 886 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\smallcoolbluebutton_left[1].gif 106 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\sort-icons[1].png 352 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\ssl_ico[1].png 173 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\star25[1].gif 952 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\stats_load[1].js 684 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\stats_load[2].js 684 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\status-dropdown-back[1].png 509 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\status-dropdown-back[2].png 509 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\statusbar_right[1].png 2729 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\STeWPW2kh0m[1].png 129 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\SakaC0tDjfm[1].png 610 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\screen-type-default-selected[1].png 1802 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\screen-type-default[1].png 1774 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\screen-type-split-selected[1].png 2394 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\screen-type-split[1].png 2361 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\searchSuggest[1].js 11450 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\search[1].txt 157414 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\search[3].php 2958 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_imageCAB0OKR3.jpg 4439 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\safe_image[2].png 3523 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\searchCAUAGHOT.php 2445 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\search[4].php 2174 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\skin-prokonto[1].css 7344 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\teebBtOrBpC[1].css 1249 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\vJRBjt5XzbL[1].gif 67 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\YsCvSejwukd[1].js 14387 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=3[3].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=3[4].txt 2126 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=3[5].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=3[6].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=4[1].txt 2082 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=4[2].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=4[3].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=4[4].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=4[5].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=5[1].txt 1404 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=5[2].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=5[9].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=6CA8MI568.txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=6CAGIDV07.txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=6CAI7XN1K.txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=6CAMLHYCP.txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=6CAQ51A4F.txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\YWlEoKyYLWW[1].css 6120 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\Yz_2RL5XOEG[1].png 293 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\zippy_plus_sm[1].gif 200 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\text_group[1].php 1916 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\time-tracker[1].js 3267 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\top-ads[1].htm 428 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\top2_blue_narrow[1].gif 840 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\top[1].htm 477 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\top_boxes[1].png 12782 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\toshiba_gzp2_175x70_I_v02[1].swf 15910 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\translate_logo[1].gif 3701 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\translucent-background[1].png 180 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\tray-icon-background[1].png 494 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\TzVuOAtGXif[1].css 1105 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\update_app_path[1].aspx 12 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\user-search-bottom[1].gif 1095 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\usmiech[1].gif 615 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\usmiech[2].gif 615 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=1[2].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=1[3].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=1[4].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=1[5].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=1[6].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2CA0BB58Q.txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2CA0EC40Q.txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2CA2SZ5N0.txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2CA3XJSB4.txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2CA4HVSKR.txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2CA6P0ATZ.txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2CA7KYLNL.txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2CAAPCYN9.txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2CABIA6RQ.txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2CAD8K6WA.txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\service_avatar_brandings[1].png 688 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\shade_right[1].png 755 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\shop_default_logo_mini[1].gif 1614 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\short-boxes-content[1].png 192 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\showcase[1].php 542 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\showcatBorderBottom[1].png 249 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\showitem-gallery.min[1].js 14426 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=6[11].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=6[3].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=6[4].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=6[5].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=6[6].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=6[7].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=6[8].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=6[9].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=7CA088ZHJ.txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=7CAE5Y53Y.txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=7CAEYMO9J.txt 113 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=7[10].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=7[11].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=7[1].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=7[2].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=7[3].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=7[4].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=7[5].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=7[6].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=7[7].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=7[8].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=7[9].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2CAM1A6DY.txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2CAS3WXAG.txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2[10].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2[11].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2[1].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2[2].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2[3].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2[4].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2[6].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2[7].txt 25 bytes File C:\Documents and Settings\OEM\Ustawienia lokalne\Temporary Internet Files\Content.IE5\Z7VFIKSA\p_562794279=2[8].txt 25 bytes ---- EOF - GMER 1.0.15 ----