
Wyjechałem na tydzień z domu - urlop.
Od razu piszę, że nikt nie korzystał z komputera i wracam a tutaj problemy typu:
- windows nie chciał się załadować i zawieszał się w momencie "Witamy w systemie Windows" - restart i dopiero może sie załaduje
- przy każdym włączaniu komputera bluescreen i restart komnputera - dopiero po kilku próbach komputer startuje
- znów wyświetla się okienko "system windows nie jest oryginalny" - miałem to zablokowane i było okej
- ustawione mam wszystko na ' wydajnosc ' w opcjach komputera bo strasznie ciężko pracuje przy kilku operacjach na ' normalnych ' parametrach i nie wiem co sie dzieje..
Może czas na ' format ' komputera?
Wkleje poniżej wszystkie możliwe logi + zdjecie z bluescreena itp.
Proszę o cierpliwośc bo komputer już ma swoje lata.
--> Zapraszam też do tego tematu w celu pomocy wyboru nowego laptopa -> -kupno-pomoc-kupno-laptopa-do-3tys-vt140645.html
Z Góry dziekuje za pomoc!
Dodano 29.06.2014 10:27:15:
OTL :
Dodano 29.06.2014 10:43:59:
COMBOFIX:
Dodano 29.06.2014 11:17:50:
GMER:
GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-06-29 12:17:24
Windows 6.1.7600 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T1L0-5 ST3500320AS rev.SD15 465,76GB
Running: 014jbg7z.exe; Driver: C:\Users\dom\AppData\Local\Temp\pxtiqpow.sys
---- System - GMER 2.1 ----
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAddBootEntry [0x91C50AA0]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAssignProcessToJobObject [0x91C5157E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEvent [0x91C5D5C8]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEventPair [0x91C5D614]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateIoCompletion [0x91C5D7AE]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateMutant [0x91C5D536]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwCreateSection [0x91D076D2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateSemaphore [0x91C5D57E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateThread [0x91C51AB4]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateThreadEx [0x91C51CD0]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateTimer [0x91C5D768]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDebugActiveProcess [0x91C5236C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteBootEntry [0x91C50B06]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDuplicateObject [0x91C55B40]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwLoadDriver [0x91C506F2]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwMapViewOfSection [0x91D077B2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwModifyBootEntry [0x91C50B6C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeKey [0x91C55F36]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeMultipleKeys [0x91C52E54]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEvent [0x91C5D5F2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEventPair [0x91C5D636]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenIoCompletion [0x91C5D7D2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenMutant [0x91C5D55C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenProcess [0x91C5543A]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSection [0x91C5D6E6]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSemaphore [0x91C5D5A6]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenThread [0x91C55822]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenTimer [0x91C5D78C]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwProtectVirtualMemory [0x91D07556]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryObject [0x91C52CC8]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueueApcThreadEx [0x91C529D6]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootEntryOrder [0x91C50BD2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootOptions [0x91C50C38]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwSetContextThread [0x91D078AE]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemInformation [0x91C5078C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemPowerState [0x91C5095E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwShutdownSystem [0x91C508EC]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendProcess [0x91C52536]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendThread [0x91C52698]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSystemDebugControl [0x91C509E6]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwTerminateProcess [0x91D07624]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwTerminateThread [0x91C521C6]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwVdmControl [0x91C50C9E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwWriteVirtualMemory [0x91C515DA]
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwRollbackTransaction + 13F9 83456829 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 8347B132 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!RtlSidHashLookup + 224 83482904 4 Bytes [A0, 0A, C5, 91]
.text ntkrnlpa.exe!RtlSidHashLookup + 2AC 8348298C 4 Bytes [7E, 15, C5, 91]
.text ntkrnlpa.exe!RtlSidHashLookup + 300 834829E0 8 Bytes [C8, D5, C5, 91, 14, D6, C5, ...]
.text ntkrnlpa.exe!RtlSidHashLookup + 30C 834829EC 4 Bytes [AE, D7, C5, 91]
.text ntkrnlpa.exe!RtlSidHashLookup + 328 83482A08 4 Bytes [36, D5, C5, 91] {AAD 0xc5; XCHG ECX, EAX}
.text ...
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 108 836818C0 4 Bytes CALL 91C53517 \SystemRoot\system32\drivers\aswSnx.sys
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 122 836899AD 4 Bytes CALL 91C5352D \SystemRoot\system32\drivers\aswSnx.sys
.sptd1 C:\Windows\System32\Drivers\sptd.sys entry point in ".sptd1" section [0x840B5774]
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x96611000, 0x388539, 0xE8000020]
? C:\Windows\system32\Drivers\PROCEXP113.SYS Nie można odnaleźć określonego pliku. !
---- User code sections - GMER 2.1 ----
.text C:\Program Files\EslWire\service\WireHelperSvc.exe[360] kernel32.dll!GetBinaryTypeW + 70 75627934 1 Byte [62]
.text C:\Windows\system32\csrss.exe[444] kernel32.dll!GetBinaryTypeW + 70 75627934 1 Byte [62]
.text C:\Windows\system32\wininit.exe[524] kernel32.dll!GetBinaryTypeW + 70 75627934 1 Byte [62]
.text C:\Windows\system32\csrss.exe[532] kernel32.dll!GetBinaryTypeW + 70 75627934 1 Byte [62]
.text C:\Windows\system32\services.exe[572] kernel32.dll!GetBinaryTypeW + 70 75627934 1 Byte [62]
.text ...
.text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1392] kernel32.dll!SetUnhandledExceptionFilter 75613122 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP }
.text C:\Program Files\Alwil Software\Avast5\AvastSvc.exe[1392] kernel32.dll!GetBinaryTypeW + 70 75627934 1 Byte [62]
.text C:\Program Files\Alwil Software\Avast5\avastui.exe[1548] kernel32.dll!SetUnhandledExceptionFilter 75613122 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP }
.text C:\Program Files\Alwil Software\Avast5\avastui.exe[1548] kernel32.dll!GetBinaryTypeW + 70 75627934 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1592] kernel32.dll!GetBinaryTypeW + 70 75627934 1 Byte [62]
.text C:\Windows\System32\spoolsv.exe[1700] kernel32.dll!GetBinaryTypeW + 70 75627934 1 Byte [62]
.text C:\Windows\system32\svchost.exe[1752] kernel32.dll!GetBinaryTypeW + 70 75627934 1 Byte [62]
.text C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe[1780] kernel32.dll!GetBinaryTypeW + 70 75627934 1 Byte [62]
.text ...
.text C:\Program Files\Mozilla Firefox\firefox.exe[4728] ntdll.dll!NtCreateFile 76E146B0 5 Bytes JMP 6044B8D0 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[4728] ntdll.dll!NtFlushBuffersFile 76E14A40 5 Bytes JMP 60447B07 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[4728] ntdll.dll!NtQueryFullAttributesFile 76E150D0 5 Bytes JMP 60447820 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[4728] ntdll.dll!NtReadFile 76E153A0 5 Bytes JMP 60447A00 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[4728] ntdll.dll!NtReadFileScatter 76E153B0 5 Bytes JMP 60C9CCC0 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[4728] ntdll.dll!NtWriteFile 76E15B50 5 Bytes JMP 6044BFE0 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[4728] ntdll.dll!NtWriteFileGather 76E15B60 5 Bytes JMP 60C9CC6F C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[4728] ntdll.dll!LdrUnloadDll 76E2BD1F 5 Bytes JMP 001E03FC
.text C:\Program Files\Mozilla Firefox\firefox.exe[4728] ntdll.dll!LdrLoadDll 76E2F425 5 Bytes JMP 6BBA1EAE C:\Program Files\Mozilla Firefox\mozglue.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[4728] KERNEL32.dll!K32GetDeviceDriverBaseNameW + 16F 7560C0A7 7 Bytes JMP 60C69E65 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[4728] KERNEL32.dll!CloseHandle + 38 756105CF 7 Bytes JMP 60C69E88 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[4728] KERNEL32.dll!GetExitCodeProcess + 2C 7561311D 7 Bytes JMP 60448236 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[4728] KERNEL32.dll!GetBinaryTypeW + 70 75627934 1 Byte [62]
.text C:\Program Files\Mozilla Firefox\firefox.exe[4728] user32.dll!GetWindowInfo 76366A82 5 Bytes JMP 60B77585 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[4728] GDI32.dll!GetViewportOrgEx + 21C 76A985EB 7 Bytes JMP 60C69DE6 C:\Program Files\Mozilla Firefox\xul.dll
---- Devices - GMER 2.1 ----
Device \FileSystem\Ntfs \Ntfs 863311F8
Device \Driver\usbohci \Device\USBPDO-0 87810440
Device \Driver\usbohci \Device\USBPDO-1 87810440
Device \Driver\usbehci \Device\USBPDO-2 8780C440
Device \Driver\usbohci \Device\USBPDO-3 87810440
Device \Driver\usbohci \Device\USBPDO-4 87810440
Device \Driver\usbehci \Device\USBPDO-5 8780C440
Device \Driver\usbohci \Device\USBPDO-6 87810440
Device \Driver\cdrom \Device\CdRom0 8742D1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-2 8632F1F8
Device \Driver\atapi \Device\Ide\IdePort0 8632F1F8
Device \Driver\atapi \Device\Ide\IdePort1 8632F1F8
Device \Driver\atapi \Device\Ide\IdePort2 8632F1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-5 8632F1F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{FD197CFF-FAC8-47F6-A7D0-507A9DE51F46} 876701F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 876701F8
Device \Driver\usbohci \Device\USBFDO-0 87810440
Device \Driver\usbohci \Device\USBFDO-1 87810440
Device \Driver\usbehci \Device\USBFDO-2 8780C440
Device \Driver\usbohci \Device\USBFDO-3 87810440
Device \Driver\usbohci \Device\USBFDO-4 87810440
Device \Driver\usbehci \Device\USBFDO-5 8780C440
Device \Driver\usbohci \Device\USBFDO-6 87810440
---- Trace I/O - GMER 2.1 ----
Trace ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll >>UNKNOWN [0x8632f1f8]<< 8632f1f8
Trace 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8703f098] 8703f098
Trace 3 CLASSPNP.SYS[8cb3159e] -> nt!IofCallDriver -> [0x871307a8] 871307a8
Trace 5 ACPI.sys[840da3b2] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T1L0-5[0x862fb908] 862fb908
Trace \Driver\atapi[0x87021b98] -> IRP_MJ_CREATE -> 0x8632f1f8 8632f1f8
---- Registry - GMER 2.1 ----
Reg HKLM\SOFTWARE\Microsoft\Windows Search\UsnNotifier\Windows\Catalogs\SystemIndex@{62E53CA3-BB5C-11DF-A1C8-806E6F6E6963} 23514613136
---- Files - GMER 2.1 ----
File C:\avast! sandbox 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Program Files 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Program Files\Alwil Software 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Program Files\Alwil Software\Avast5 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Program Files\Alwil Software\Avast5\sfzone 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\chrome_shutdown_ms.txt 4 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Network Action Predictor-journal 3608 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Archived History 57344 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Archived History-journal 512 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Cache 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Cache\data_0 8192 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Cache\data_1 270336 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Cache\data_2 8192 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Cache\data_3 8192 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Cache\index 524656 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Cookies 6144 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Cookies-journal 1544 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Current Session 771 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Current Tabs 8 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Favicons 20480 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Favicons-journal 512 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\History 94208 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\History Provider Cache 13 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\History-journal 512 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Last Session 621 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Network Action Predictor 16384 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Preferences 9868 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Shortcuts 12288 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Shortcuts-journal 512 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Top Sites 20480 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Top Sites-journal 12824 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\User StyleSheets 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\User StyleSheets\Custom.css 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Visited Links 131072 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Web Data 73728 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Default\Web Data-journal 4624 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\First Run 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\sfzone_profile\Local State 2032 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Local 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Local\Microsoft 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Local\Microsoft\Windows 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Local\Microsoft\Windows\History 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Local\Microsoft\Windows\History\History.IE5 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat 16384 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Local\Microsoft\Windows\Temporary Internet Files 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9VSYNSRS 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9VSYNSRS\desktop.ini 67 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A7S95HCK 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A7S95HCK\desktop.ini 67 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CZB6VF1V 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CZB6VF1V\desktop.ini 67 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat 32768 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OUX0CR0E 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OUX0CR0E\desktop.ini 67 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Local\Temp 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\LocalLow 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\LocalLow\Microsoft 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\LocalLow\Microsoft\CryptnetUrlCache 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 328 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Roaming 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Roaming\Microsoft 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Roaming\Microsoft\Windows 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Roaming\Microsoft\Windows\Cookies 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Users\dom\AppData\Roaming\Microsoft\Windows\Cookies\index.dat 16384 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Windows 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Windows\Prefetch 0 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Windows\Prefetch\CALC.EXE-AC08706A.pf 24990 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\C\Windows\Prefetch\NOTEPAD.EXE-EB1B961A.pf 26738 bytes
File C:\avast! sandbox\S-1-5-21-3295308795-277811586-1615858928-1000\sfzone\snx_fs.dat 11490 bytes
File C:\avast! sandbox\snx_rhive 262144 bytes
File C:\avast! sandbox\snx_rhive.LOG1 37888 bytes
File C:\avast! sandbox\snx_rhive.LOG2 0 bytes
File C:\avast! sandbox\snx_rhive{a5212343-c395-11e1-bf65-dcc8d6f965fe}.TM.blf 65536 bytes
File C:\avast! sandbox\snx_rhive{a5212343-c395-11e1-bf65-dcc8d6f965fe}.TMContainer00000000000000000001.regtrans-ms 524288 bytes
File C:\avast! sandbox\snx_rhive{a5212343-c395-11e1-bf65-dcc8d6f965fe}.TMContainer00000000000000000002.regtrans-ms 524288 bytes
---- EOF - GMER 2.1 ----