
Czynności które już zrobiłem : skan spyware , panda online , kaspersky , defragmentacja dysków, oczyszczanie dysku , sprawdzanie błędów,czyszczenie rejestru , cookies,usunięcie zbędnych programów oraz w zakładce URUCHAMIANIE zostawiłem 3-4 wpisy a także"odptaszyłem" kilka usług
Mam też kilka pytań mianowicie :
1 W dodaj/ usuń mam Microsoft.NET framework1.1 poźniej 2.0 i 3.0 czy można usunąć wszystkie zostawiając najwyższy?podobnie jest z Java
2 w manager zadań pojawia mi się czasem 6x svchost.exe , pojawia się też explorer.exe (nie używam w ogóle IE)przy próbie wyłączenia tego zadania znika pasek i ikony - zostaje sama tapeta ?!
3 w narzędziu konfiguracji systemu zakładka usługi i Uruchamianie mam stare programy "odptaszkowane" których nie mam na kompie np NOD32 czy kalendarz xp jak to usunąć?
- Kod: Zaznacz wszystko
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-19 12:15:16
Windows 5.1.2600 Dodatek Service Pack 3
Running: n6lj65wl.exe; Driver: C:\DOCUME~1\user\USTAWI~1\Temp\kgpoykoc.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwAdjustPrivilegesToken [0xBA2E11DA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwClose [0xBA2E17AE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwConnectPort [0xBA2E31EA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwCreateFile [0xBA2E2B9C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwCreateKey [0xBA2E0950]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwCreateSymbolicLinkObject [0xBA2E4B7C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwCreateThread [0xBA2E15AE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwDeleteKey [0xBA2E0D92]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwDeleteValueKey [0xBA2E0F92]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwDeviceIoControlFile [0xBA2E2EAC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwDuplicateObject [0xBA2E5084]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwEnumerateKey [0xBA2E10A8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwEnumerateValueKey [0xBA2E1110]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwFsControlFile [0xBA2E2D5E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwLoadDriver [0xBA2E4620]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwOpenFile [0xBA2E29F8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwOpenKey [0xBA2E0AB2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwOpenProcess [0xBA2E13B2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwOpenSection [0xBA2E4BA6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwOpenThread [0xBA2E12FE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwQueryKey [0xBA2E1178]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwQueryMultipleValueKey [0xBA2E0E7C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwQueryValueKey [0xBA2E0C5A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwQueueApcThread [0xBA2E4888]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwReplaceKey [0xBA2E05D2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwRequestWaitReplyPort [0xBA2E3A74]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwRestoreKey [0xBA2E0734]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwResumeThread [0xBA2E4F56]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSaveKey [0xBA2E03D0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSecureConnectPort [0xBA2E308C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSetContextThread [0xBA2E16AC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSetSecurityObject [0xBA2E471A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSetSystemInformation [0xBA2E4BD0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSetValueKey [0xBA2E0B08]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSuspendProcess [0xBA2E4CB4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSuspendThread [0xBA2E4DE0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwSystemDebugControl [0xBA2E454C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwTerminateProcess [0xBA2E147E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) ZwWriteVirtualMemory [0xBA2E14F0]
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) IoIsOperationSynchronous
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!FsRtlCheckLockForReadAccess 804E9FA0 5 Bytes JMP BA2F8626 \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab)
.text ntkrnlpa.exe!IoIsOperationSynchronous 804EE87E 5 Bytes JMP BA2F89E0 \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab)
.text ntkrnlpa.exe!ZwCallbackReturn + 2400 80501C38 4 Bytes JMP 48BA2E31
.text ntkrnlpa.exe!ZwCallbackReturn + 2778 80501FB0 12 Bytes [B4, 4C, 2E, BA, E0, 4D, 2E, ...]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] USER32.dll!GetWindowLongW 7E3688A6 5 Bytes JMP 63024E10 C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] USER32.dll!GetWindowLongA 7E36945D 5 Bytes JMP 63024D80 C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] USER32.dll!SetWindowPlacement 7E36DE46 5 Bytes JMP 63024ED0 C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] USER32.dll!GetWindowRect 7E3790B4 5 Bytes JMP 630259F0 C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] USER32.dll!SetWindowPos 7E3799F3 5 Bytes JMP 63025720 C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] USER32.dll!MoveWindow 7E37B29E 5 Bytes JMP 63025430 C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] USER32.dll!SetWindowLongA 7E37C29D 5 Bytes JMP 63024C00 C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] USER32.dll!SetWindowLongW 7E37C2BB 5 Bytes JMP 63024CC0 C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] USER32.dll!GetWindowPlacement 7E3803C7 5 Bytes JMP 63025150 C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
? C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe[216] C:\WINDOWS\system32\kernel32.dll time/date stamp mismatch;
.text C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe[216] USER32.dll!AlignRects + FFFA5598 7E362A78 4 Bytes [70, 11, 41, 6D] {JO 0x13; INC ECX; INSD }
? C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe[1960] C:\WINDOWS\system32\kernel32.dll time/date stamp mismatch;
.text C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe[1960] USER32.dll!AlignRects + FFFA5598 7E362A78 4 Bytes [70, 11, 41, 6D] {JO 0x13; INC ECX; INSD }
.text C:\Program Files\Mozilla Firefox\firefox.exe[2756] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 004013F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[TDI.SYS!TdiRegisterDeviceObject] [F7EADD50] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\DRIVERS\netbt.sys[TDI.SYS!TdiRegisterDeviceObject] [F7EADD50] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!CreateThread] [63032C40] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!ExitThread] [63032BC0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [63032B20] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [63032AC0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [63032CC0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [63032AC0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [63032B20] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [63032CC0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateThread] [63032C40] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [63032AC0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [63032B20] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [63032CC0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!DeleteObject] [63072AF0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [63032B50] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [63032B20] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] [63032C40] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!ExitThread] [63032BC0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [63032AC0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [63032CC0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [042C1850] C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [042C1890] C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetWindowLongA] [042C15B0] C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetWindowLongW] [042C15E0] C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [63072A90] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [63032C80] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [63032CA0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongA] [042C1530] C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!SetWindowLongW] [042C1570] C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CreateWindowExA] [63032E60] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CreateWindowExW] [63032E80] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DeferWindowPos] [042C14A0] C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CallWindowProcW] [6306D610] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!CallWindowProcA] [6306C3A0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [63032CC0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [63032AC0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!ExitThread] [63032BC0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateThread] [63032C40] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\shell32.dll [GDI32.dll!DeleteObject] [63072AF0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\shell32.dll [KERNEL32.dll!LoadLibraryA] [63032AC0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\shell32.dll [KERNEL32.dll!LoadLibraryW] [63032B20] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\shell32.dll [KERNEL32.dll!GetProcAddress] [63032CC0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\shell32.dll [KERNEL32.dll!CreateThread] [63032C40] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\shell32.dll [KERNEL32.dll!LoadLibraryExA] [63032B50] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TrackPopupMenuEx] [63032CA0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!CreateWindowExW] [63032E80] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!DefWindowProcA] [042C1850] C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!SetWindowLongW] [042C1570] C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetWindowLongW] [042C15E0] C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!DeferWindowPos] [042C14A0] C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetSysColor] [63072A90] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!DefWindowProcW] [042C1890] C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetSysColorBrush] [63072B30] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!FillRect] [630327C0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!DrawFrameControl] [63026150] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TrackPopupMenu] [63032C80] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!CallWindowProcW] [6306D610] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!SetScrollInfo] [042C1750] C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetWindowLongA] [042C15B0] C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\ole32.dll [GDI32.dll!DeleteObject] [63072AF0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [63032CC0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [63032AC0] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [63032B20] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateThread] [63032C40] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] [63032B50] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetSysColor] [63072A90] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!CallWindowProcW] [6306D610] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!CreateWindowExA] [63032E60] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!DefWindowProcW] [042C1890] C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!CreateWindowExW] [63032E80] C:\Program Files\ATI Technologies\ATI.ACE\skins\wbocx.ocx (WindowBlinds : DirectSkin /Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetWindowLongW] [042C15E0] C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
IAT C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe[108] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SetWindowLongW] [042C1570] C:\Program Files\ATI Technologies\ATI.ACE\Core-Implementation\32\wbhelp2.dll (WindowBlinds Helper DLL/Stardock.Net, Inc)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x4A 0xE6 0x7C 0x17 ...
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x36 0x6C 0xD2 0x7A ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x4A 0xE6 0x7C 0x17 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x93 0x5D 0x39 0xFD ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x4A 0xE6 0x7C 0x17 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x36 0x6C 0xD2 0x7A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x4A 0xE6 0x7C 0x17 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x93 0x5D 0x39 0xFD ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x4A 0xE6 0x7C 0x17 ...
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x93 0x5D 0x39 0xFD ...
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xC8 0x28 0x51 0xAF ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x6A 0x9C 0xD6 0x61 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0x25 0xDA 0xEC 0x7E ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x6B 0x65 0x49 0x6A ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xDF 0x20 0x58 0x62 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0xFB 0xA7 0x78 0xE6 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x01 0x3A 0x48 0xFC ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xF6 0x0F 0x4E 0x58 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0x3D 0xCE 0xEA 0x26 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0x2A 0xB7 0xCC 0xB5 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...
---- EOF - GMER 1.0.15 ----
Dodano 19.08.2010 11:42:22:
http://wklej.org/id/378882/#
http://wklej.org/id/378885/
Dodano 19.08.2010 11:44:02:
Proszę o wyrozumiałość gdyż jestem zielony w dziedzinie komputerów i prosiłbym w miarę dobre i proste instrukcję co dalej .
Ps mam skan z combofixa gdyby był potrzebny - zrobiłem go w desperacji .