GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-02-22 17:57:55
Windows 5.1.2600 Dodatek Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST3250310AS rev.3.AAC
Running: 6057x3ki.exe; Driver: C:\DOCUME~1\Damiano\USTAWI~1\Temp\uxtdapow.sys


---- System - GMER 1.0.15 ----

SSDT            \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET)                                                                      ZwAssignProcessToJobObject [0xB71744B0]
SSDT            \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET)                                                                      ZwCreateThread [0xB71747F0]
SSDT            \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET)                                                                      ZwDebugActiveProcess [0xB7174AB0]
SSDT            \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET)                                                                      ZwDuplicateObject [0xB71745D0]
SSDT            \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET)                                                                      ZwLoadDriver [0xB71748B0]
SSDT            \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET)                                                                      ZwOpenProcess [0xB7174350]
SSDT            \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET)                                                                      ZwOpenThread [0xB7174410]
SSDT            \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET)                                                                      ZwProtectVirtualMemory [0xB7174570]
SSDT            \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET)                                                                      ZwQueueApcThread [0xB7174630]
SSDT            \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET)                                                                      ZwSetContextThread [0xB7174530]
SSDT            \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET)                                                                      ZwSetInformationThread [0xB71744F0]
SSDT            \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET)                                                                      ZwSetSecurityObject [0xB7174670]
SSDT            \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET)                                                                      ZwSetSystemInformation [0xB7174870]
SSDT            \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET)                                                                      ZwSuspendProcess [0xB71743B0]
SSDT            \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET)                                                                      ZwSuspendThread [0xB7174430]
SSDT            \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET)                                                                      ZwSystemDebugControl [0xB7174830]
SSDT            \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET)                                                                      ZwTerminateProcess [0xB7174370]
SSDT            \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET)                                                                      ZwTerminateThread [0xB7174470]
SSDT            \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET)                                                                      ZwWriteVirtualMemory [0xB71745F0]

---- Kernel code sections - GMER 1.0.15 ----

.text           ntkrnlpa.exe!ZwCallbackReturn + 2F28                                                                                                  80503B28 12 Bytes  [B0, 43, 17, B7, 30, 44, 17, ...]
.text           ntkrnlpa.exe!ZwCallbackReturn + 2F39                                                                                                  80503B39 7 Bytes  [43, 17, B7, 70, 44, 17, B7]
.text           C:\WINDOWS\system32\DRIVERS\nv4_mini.sys                                                                                              section is writeable [0xB9C04360, 0x3441C7, 0xE8000020]
.text           serial.sys                                                                                                                            B9A77301 181 Bytes  [08, 00, 00, 80, F8, 00, 00, ...]
.text           serial.sys                                                                                                                            B9A773C5 66 Bytes  [90, 90, 90, 90, 90, 90, 90, ...]
.text           serial.sys                                                                                                                            B9A77408 48 Bytes  [8D, 88, C8, 04, 00, 00, 83, ...]
.text           serial.sys                                                                                                                            B9A77439 145 Bytes  [D2, 8D, 88, C8, 04, 00, 00, ...]
.text           serial.sys                                                                                                                            B9A774CB 123 Bytes  [B9, FF, 75, 08, 8B, F0, E8, ...]
.text           ...                                                                                                                                   
.INIT           C:\WINDOWS\system32\DRIVERS\serial.sys                                                                                                entry point in ".INIT" section [0xB9A85722]
?               C:\WINDOWS\system32\DRIVERS\serial.sys                                                                                                suspicious PE modification
pnidata         C:\WINDOWS\system32\DRIVERS\secdrv.sys                                                                                                unknown last section [0xB6387F00, 0x24000, 0x48000000]

---- User code sections - GMER 1.0.15 ----

.text           C:\Program Files\SAGEM WiFi manager\WLANUTL.exe[360] ntdll.dll!NtEnumerateValueKey                                                    7C90D976 5 Bytes  JMP 00CE1890 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\SAGEM WiFi manager\WLANUTL.exe[360] ntdll.dll!NtQuerySystemInformation                                               7C90E1AA 5 Bytes  JMP 00CE1960 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\SAGEM WiFi manager\WLANUTL.exe[360] ntdll.dll!NtResumeThread                                                         7C90E45F 5 Bytes  JMP 00CE15F0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\SAGEM WiFi manager\WLANUTL.exe[360] ntdll.dll!LdrLoadDll                                                             7C9161CA 5 Bytes  JMP 00CE1690 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\SAGEM WiFi manager\WLANUTL.exe[360] kernel32.dll!FindFirstFileW                                                      7C80F0E1 5 Bytes  JMP 00CE1A90 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\SAGEM WiFi manager\WLANUTL.exe[360] kernel32.dll!FindNextFileW                                                       7C80F13A 7 Bytes  JMP 00CE1B70 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\SAGEM WiFi manager\WLANUTL.exe[360] kernel32.dll!FindFirstFileA                                                      7C813559 5 Bytes  JMP 00CE19D0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\SAGEM WiFi manager\WLANUTL.exe[360] kernel32.dll!FindNextFileA                                                       7C839019 5 Bytes  JMP 00CE1A40 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\SAGEM WiFi manager\WLANUTL.exe[360] WS2_32.dll!connect                                                               71A5406A 5 Bytes  JMP 00CE16C0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\ESET\ESET Smart Security\ekrn.exe[1700] kernel32.dll!SetUnhandledExceptionFilter                                     7C810386 4 Bytes  [C2, 04, 00, 00]
.text           C:\Program Files\Mozilla Firefox\plugin-container.exe[3296] ntdll.dll!NtEnumerateValueKey                                             7C90D976 5 Bytes  JMP 01061890 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Mozilla Firefox\plugin-container.exe[3296] ntdll.dll!NtQuerySystemInformation                                        7C90E1AA 5 Bytes  JMP 01061960 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Mozilla Firefox\plugin-container.exe[3296] ntdll.dll!NtResumeThread                                                  7C90E45F 5 Bytes  JMP 010615F0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Mozilla Firefox\plugin-container.exe[3296] ntdll.dll!LdrLoadDll                                                      7C9161CA 5 Bytes  JMP 01061690 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Mozilla Firefox\plugin-container.exe[3296] kernel32.dll!FindFirstFileW                                               7C80F0E1 5 Bytes  JMP 01061A90 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Mozilla Firefox\plugin-container.exe[3296] kernel32.dll!FindNextFileW                                                7C80F13A 7 Bytes  JMP 01061B70 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Mozilla Firefox\plugin-container.exe[3296] kernel32.dll!FindFirstFileA                                               7C813559 5 Bytes  JMP 010619D0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Mozilla Firefox\plugin-container.exe[3296] kernel32.dll!FindNextFileA                                                7C839019 5 Bytes  JMP 01061A40 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Mozilla Firefox\plugin-container.exe[3296] WS2_32.dll!connect                                                        71A5406A 5 Bytes  JMP 010616C0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Mozilla Firefox\plugin-container.exe[3296] USER32.dll!SetWindowLongA                                                 77D3DED3 5 Bytes  JMP 106C01A3 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text           C:\Program Files\Mozilla Firefox\plugin-container.exe[3296] USER32.dll!SetWindowLongW                                                 77D3DEF1 5 Bytes  JMP 106C0135 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text           C:\Program Files\Mozilla Firefox\plugin-container.exe[3296] USER32.dll!GetWindowInfo                                                  77D3F122 5 Bytes  JMP 10450924 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text           C:\Program Files\Mozilla Firefox\plugin-container.exe[3296] USER32.dll!TrackPopupMenu                                                 77D84F16 5 Bytes  JMP 10450ECF C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3388] ntdll.dll!NtEnumerateValueKey                                                      7C90D976 5 Bytes  JMP 00951890 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3388] ntdll.dll!NtQuerySystemInformation                                                 7C90E1AA 5 Bytes  JMP 00951960 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3388] ntdll.dll!NtResumeThread                                                           7C90E45F 5 Bytes  JMP 009515F0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3388] ntdll.dll!LdrLoadDll                                                               7C9161CA 5 Bytes  JMP 01445B60 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3388] kernel32.dll!FindFirstFileW                                                        7C80F0E1 5 Bytes  JMP 00951A90 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3388] kernel32.dll!FindNextFileW                                                         7C80F13A 7 Bytes  JMP 00951B70 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3388] kernel32.dll!FindFirstFileA                                                        7C813559 5 Bytes  JMP 009519D0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3388] kernel32.dll!FindNextFileA                                                         7C839019 5 Bytes  JMP 00951A40 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3388] ws2_32.dll!connect                                                                 71A5406A 5 Bytes  JMP 009516C0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Mozilla Firefox\firefox.exe[3388] CRYPT32.dll!CryptMsgCountersignEncoded + 27C                                       77A8123E 7 Bytes  JMP 356753FE C:\WINDOWS\system32\mswsock.dll (Microsoft Windows Sockets 2.0 Dostawca usługi/Microsoft Corporation)
.text           C:\WINDOWS\explorer.exe[3392] ntdll.dll!NtEnumerateValueKey                                                                           7C90D976 5 Bytes  JMP 02361890 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\explorer.exe[3392] ntdll.dll!NtQuerySystemInformation                                                                      7C90E1AA 5 Bytes  JMP 02361960 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\explorer.exe[3392] ntdll.dll!NtResumeThread                                                                                7C90E45F 5 Bytes  JMP 023615F0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\explorer.exe[3392] ntdll.dll!LdrLoadDll                                                                                    7C9161CA 5 Bytes  JMP 02361690 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\explorer.exe[3392] kernel32.dll!FindFirstFileW                                                                             7C80F0E1 5 Bytes  JMP 02361A90 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\explorer.exe[3392] kernel32.dll!FindNextFileW                                                                              7C80F13A 7 Bytes  JMP 02361B70 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\explorer.exe[3392] kernel32.dll!FindFirstFileA                                                                             7C813559 5 Bytes  JMP 023619D0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\explorer.exe[3392] kernel32.dll!FindNextFileA                                                                              7C839019 5 Bytes  JMP 02361A40 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\explorer.exe[3392] WS2_32.dll!connect                                                                                      71A5406A 5 Bytes  JMP 023616C0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\VDOTool\TBPanel.exe[3452] ntdll.dll!NtEnumerateValueKey                                                              7C90D976 5 Bytes  JMP 00E21890 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\VDOTool\TBPanel.exe[3452] ntdll.dll!NtQuerySystemInformation                                                         7C90E1AA 5 Bytes  JMP 00E21960 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\VDOTool\TBPanel.exe[3452] ntdll.dll!NtResumeThread                                                                   7C90E45F 5 Bytes  JMP 00E215F0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\VDOTool\TBPanel.exe[3452] ntdll.dll!LdrLoadDll                                                                       7C9161CA 5 Bytes  JMP 00E21690 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\VDOTool\TBPanel.exe[3452] kernel32.dll!FindFirstFileW                                                                7C80F0E1 5 Bytes  JMP 00E21A90 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\VDOTool\TBPanel.exe[3452] kernel32.dll!FindNextFileW                                                                 7C80F13A 7 Bytes  JMP 00E21B70 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\VDOTool\TBPanel.exe[3452] kernel32.dll!FindFirstFileA                                                                7C813559 5 Bytes  JMP 00E219D0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\VDOTool\TBPanel.exe[3452] kernel32.dll!FindNextFileA                                                                 7C839019 5 Bytes  JMP 00E21A40 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\VDOTool\TBPanel.exe[3452] ws2_32.dll!connect                                                                         71A5406A 5 Bytes  JMP 00E216C0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[3476] ntdll.dll!NtEnumerateValueKey                                              7C90D976 5 Bytes  JMP 00951890 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[3476] ntdll.dll!NtQuerySystemInformation                                         7C90E1AA 5 Bytes  JMP 00951960 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[3476] ntdll.dll!NtResumeThread                                                   7C90E45F 5 Bytes  JMP 009515F0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[3476] ntdll.dll!LdrLoadDll                                                       7C9161CA 5 Bytes  JMP 00951690 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[3476] kernel32.dll!FindFirstFileW                                                7C80F0E1 5 Bytes  JMP 00951A90 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[3476] kernel32.dll!FindNextFileW                                                 7C80F13A 7 Bytes  JMP 00951B70 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[3476] kernel32.dll!FindFirstFileA                                                7C813559 5 Bytes  JMP 009519D0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[3476] kernel32.dll!FindNextFileA                                                 7C839019 5 Bytes  JMP 00951A40 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\HP\HP Software Update\HPWuSchd2.exe[3476] ws2_32.dll!connect                                                         71A5406A 5 Bytes  JMP 009516C0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\RTHDCPL.EXE[3492] ntdll.dll!NtEnumerateValueKey                                                                            7C90D976 5 Bytes  JMP 04821890 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\RTHDCPL.EXE[3492] ntdll.dll!NtQuerySystemInformation                                                                       7C90E1AA 5 Bytes  JMP 04821960 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\RTHDCPL.EXE[3492] ntdll.dll!NtResumeThread                                                                                 7C90E45F 5 Bytes  JMP 048215F0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\RTHDCPL.EXE[3492] ntdll.dll!LdrLoadDll                                                                                     7C9161CA 5 Bytes  JMP 04821690 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\RTHDCPL.EXE[3492] kernel32.dll!FindFirstFileW                                                                              7C80F0E1 5 Bytes  JMP 04821A90 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\RTHDCPL.EXE[3492] kernel32.dll!FindNextFileW                                                                               7C80F13A 7 Bytes  JMP 04821B70 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\RTHDCPL.EXE[3492] kernel32.dll!FindFirstFileA                                                                              7C813559 5 Bytes  JMP 048219D0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\RTHDCPL.EXE[3492] kernel32.dll!FindNextFileA                                                                               7C839019 5 Bytes  JMP 04821A40 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\RTHDCPL.EXE[3492] ws2_32.dll!connect                                                                                       71A5406A 5 Bytes  JMP 048216C0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\RUNDLL32.EXE[3524] ntdll.dll!NtEnumerateValueKey                                                                  7C90D976 5 Bytes  JMP 00B41890 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\RUNDLL32.EXE[3524] ntdll.dll!NtQuerySystemInformation                                                             7C90E1AA 5 Bytes  JMP 00B41960 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\RUNDLL32.EXE[3524] ntdll.dll!NtResumeThread                                                                       7C90E45F 5 Bytes  JMP 00B415F0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\RUNDLL32.EXE[3524] ntdll.dll!LdrLoadDll                                                                           7C9161CA 5 Bytes  JMP 00B41690 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\RUNDLL32.EXE[3524] kernel32.dll!FindFirstFileW                                                                    7C80F0E1 5 Bytes  JMP 00B41A90 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\RUNDLL32.EXE[3524] kernel32.dll!FindNextFileW                                                                     7C80F13A 7 Bytes  JMP 00B41B70 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\RUNDLL32.EXE[3524] kernel32.dll!FindFirstFileA                                                                    7C813559 5 Bytes  JMP 00B419D0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\RUNDLL32.EXE[3524] kernel32.dll!FindNextFileA                                                                     7C839019 5 Bytes  JMP 00B41A40 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\RUNDLL32.EXE[3524] ws2_32.dll!connect                                                                             71A5406A 5 Bytes  JMP 00B416C0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\ESET\ESET Smart Security\egui.exe[3552] ntdll.dll!NtEnumerateValueKey                                                7C90D976 5 Bytes  JMP 012D1890 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\ESET\ESET Smart Security\egui.exe[3552] ntdll.dll!NtQuerySystemInformation                                           7C90E1AA 5 Bytes  JMP 012D1960 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\ESET\ESET Smart Security\egui.exe[3552] ntdll.dll!NtResumeThread                                                     7C90E45F 5 Bytes  JMP 012D15F0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\ESET\ESET Smart Security\egui.exe[3552] ntdll.dll!LdrLoadDll                                                         7C9161CA 5 Bytes  JMP 012D1690 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\ESET\ESET Smart Security\egui.exe[3552] kernel32.dll!FindFirstFileW                                                  7C80F0E1 5 Bytes  JMP 012D1A90 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\ESET\ESET Smart Security\egui.exe[3552] kernel32.dll!FindNextFileW                                                   7C80F13A 7 Bytes  JMP 012D1B70 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\ESET\ESET Smart Security\egui.exe[3552] kernel32.dll!FindFirstFileA                                                  7C813559 5 Bytes  JMP 012D19D0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\ESET\ESET Smart Security\egui.exe[3552] kernel32.dll!FindNextFileA                                                   7C839019 5 Bytes  JMP 012D1A40 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\ESET\ESET Smart Security\egui.exe[3552] ws2_32.dll!connect                                                           71A5406A 5 Bytes  JMP 012D16C0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Documents and Settings\Damiano\Dane aplikacji\dplaysvr.exe[3560] ntdll.dll!NtEnumerateValueKey                                     7C90D976 5 Bytes  JMP 00991890 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Documents and Settings\Damiano\Dane aplikacji\dplaysvr.exe[3560] ntdll.dll!NtQuerySystemInformation                                7C90E1AA 5 Bytes  JMP 00991960 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Documents and Settings\Damiano\Dane aplikacji\dplaysvr.exe[3560] ntdll.dll!NtResumeThread                                          7C90E45F 5 Bytes  JMP 009915F0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Documents and Settings\Damiano\Dane aplikacji\dplaysvr.exe[3560] ntdll.dll!LdrLoadDll                                              7C9161CA 5 Bytes  JMP 00991690 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Documents and Settings\Damiano\Dane aplikacji\dplaysvr.exe[3560] kernel32.dll!FindFirstFileW                                       7C80F0E1 5 Bytes  JMP 00991A90 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Documents and Settings\Damiano\Dane aplikacji\dplaysvr.exe[3560] kernel32.dll!FindNextFileW                                        7C80F13A 7 Bytes  JMP 00991B70 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Documents and Settings\Damiano\Dane aplikacji\dplaysvr.exe[3560] kernel32.dll!FindFirstFileA                                       7C813559 5 Bytes  JMP 009919D0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Documents and Settings\Damiano\Dane aplikacji\dplaysvr.exe[3560] kernel32.dll!FindNextFileA                                        7C839019 5 Bytes  JMP 00991A40 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Documents and Settings\Damiano\Dane aplikacji\dplaysvr.exe[3560] ws2_32.dll!connect                                                71A5406A 5 Bytes  JMP 009916C0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\ctfmon.exe[3572] ntdll.dll!NtEnumerateValueKey                                                                    7C90D976 5 Bytes  JMP 00A51890 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\ctfmon.exe[3572] ntdll.dll!NtQuerySystemInformation                                                               7C90E1AA 5 Bytes  JMP 00A51960 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\ctfmon.exe[3572] ntdll.dll!NtResumeThread                                                                         7C90E45F 5 Bytes  JMP 00A515F0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\ctfmon.exe[3572] ntdll.dll!LdrLoadDll                                                                             7C9161CA 5 Bytes  JMP 00A51690 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\ctfmon.exe[3572] kernel32.dll!FindFirstFileW                                                                      7C80F0E1 5 Bytes  JMP 00A51A90 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\ctfmon.exe[3572] kernel32.dll!FindNextFileW                                                                       7C80F13A 7 Bytes  JMP 00A51B70 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\ctfmon.exe[3572] kernel32.dll!FindFirstFileA                                                                      7C813559 5 Bytes  JMP 00A519D0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\ctfmon.exe[3572] kernel32.dll!FindNextFileA                                                                       7C839019 5 Bytes  JMP 00A51A40 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\ctfmon.exe[3572] ws2_32.dll!connect                                                                               71A5406A 5 Bytes  JMP 00A516C0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Messenger\msmsgs.exe[3580] ntdll.dll!NtEnumerateValueKey                                                             7C90D976 5 Bytes  JMP 00F41890 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Messenger\msmsgs.exe[3580] ntdll.dll!NtQuerySystemInformation                                                        7C90E1AA 5 Bytes  JMP 00F41960 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Messenger\msmsgs.exe[3580] ntdll.dll!NtResumeThread                                                                  7C90E45F 5 Bytes  JMP 00F415F0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Messenger\msmsgs.exe[3580] ntdll.dll!LdrLoadDll                                                                      7C9161CA 5 Bytes  JMP 00F41690 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Messenger\msmsgs.exe[3580] kernel32.dll!FindFirstFileW                                                               7C80F0E1 5 Bytes  JMP 00F41A90 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Messenger\msmsgs.exe[3580] kernel32.dll!FindNextFileW                                                                7C80F13A 7 Bytes  JMP 00F41B70 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Messenger\msmsgs.exe[3580] kernel32.dll!FindFirstFileA                                                               7C813559 5 Bytes  JMP 00F419D0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Messenger\msmsgs.exe[3580] kernel32.dll!FindNextFileA                                                                7C839019 5 Bytes  JMP 00F41A40 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Messenger\msmsgs.exe[3580] WS2_32.dll!connect                                                                        71A5406A 5 Bytes  JMP 00F416C0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3596] ntdll.dll!NtEnumerateValueKey                                           7C90D976 5 Bytes  JMP 00DA1890 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3596] ntdll.dll!NtQuerySystemInformation                                      7C90E1AA 5 Bytes  JMP 00DA1960 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3596] ntdll.dll!NtResumeThread                                                7C90E45F 5 Bytes  JMP 00DA15F0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3596] ntdll.dll!LdrLoadDll                                                    7C9161CA 5 Bytes  JMP 00DA1690 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3596] kernel32.dll!FindFirstFileW                                             7C80F0E1 5 Bytes  JMP 00DA1A90 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3596] kernel32.dll!FindNextFileW                                              7C80F13A 7 Bytes  JMP 00DA1B70 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3596] kernel32.dll!FindFirstFileA                                             7C813559 5 Bytes  JMP 00DA19D0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3596] kernel32.dll!FindNextFileA                                              7C839019 5 Bytes  JMP 00DA1A40 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[3596] ws2_32.dll!connect                                                      71A5406A 5 Bytes  JMP 00DA16C0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           D:\ActiveSync\Wcescomm.exe[3676] ntdll.dll!NtEnumerateValueKey                                                                        7C90D976 5 Bytes  JMP 00B71890 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           D:\ActiveSync\Wcescomm.exe[3676] ntdll.dll!NtQuerySystemInformation                                                                   7C90E1AA 5 Bytes  JMP 00B71960 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           D:\ActiveSync\Wcescomm.exe[3676] ntdll.dll!NtResumeThread                                                                             7C90E45F 5 Bytes  JMP 00B715F0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           D:\ActiveSync\Wcescomm.exe[3676] ntdll.dll!LdrLoadDll                                                                                 7C9161CA 5 Bytes  JMP 00B71690 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           D:\ActiveSync\Wcescomm.exe[3676] kernel32.dll!FindFirstFileW                                                                          7C80F0E1 5 Bytes  JMP 00B71A90 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           D:\ActiveSync\Wcescomm.exe[3676] kernel32.dll!FindNextFileW                                                                           7C80F13A 7 Bytes  JMP 00B71B70 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           D:\ActiveSync\Wcescomm.exe[3676] kernel32.dll!FindFirstFileA                                                                          7C813559 5 Bytes  JMP 00B719D0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           D:\ActiveSync\Wcescomm.exe[3676] kernel32.dll!FindNextFileA                                                                           7C839019 5 Bytes  JMP 00B71A40 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           D:\ActiveSync\Wcescomm.exe[3676] WS2_32.dll!connect                                                                                   71A5406A 5 Bytes  JMP 00B716C0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           D:\ACTIVE~1\rapimgr.exe[3760] ntdll.dll!NtEnumerateValueKey                                                                           7C90D976 5 Bytes  JMP 01A01890 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           D:\ACTIVE~1\rapimgr.exe[3760] ntdll.dll!NtQuerySystemInformation                                                                      7C90E1AA 5 Bytes  JMP 01A01960 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           D:\ACTIVE~1\rapimgr.exe[3760] ntdll.dll!NtResumeThread                                                                                7C90E45F 5 Bytes  JMP 01A015F0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           D:\ACTIVE~1\rapimgr.exe[3760] ntdll.dll!LdrLoadDll                                                                                    7C9161CA 5 Bytes  JMP 01A01690 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           D:\ACTIVE~1\rapimgr.exe[3760] kernel32.dll!FindFirstFileW                                                                             7C80F0E1 5 Bytes  JMP 01A01A90 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           D:\ACTIVE~1\rapimgr.exe[3760] kernel32.dll!FindNextFileW                                                                              7C80F13A 7 Bytes  JMP 01A01B70 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           D:\ACTIVE~1\rapimgr.exe[3760] kernel32.dll!FindFirstFileA                                                                             7C813559 5 Bytes  JMP 01A019D0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           D:\ACTIVE~1\rapimgr.exe[3760] kernel32.dll!FindNextFileA                                                                              7C839019 5 Bytes  JMP 01A01A40 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           D:\ACTIVE~1\rapimgr.exe[3760] WS2_32.dll!connect                                                                                      71A5406A 5 Bytes  JMP 01A016C0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Documents and Settings\Damiano\Pulpit\ratuj\6057x3ki.exe[3764] ntdll.dll!NtEnumerateValueKey                                       7C90D976 5 Bytes  JMP 009F1890 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Documents and Settings\Damiano\Pulpit\ratuj\6057x3ki.exe[3764] ntdll.dll!NtQuerySystemInformation                                  7C90E1AA 5 Bytes  JMP 009F1960 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Documents and Settings\Damiano\Pulpit\ratuj\6057x3ki.exe[3764] ntdll.dll!NtResumeThread                                            7C90E45F 5 Bytes  JMP 009F15F0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Documents and Settings\Damiano\Pulpit\ratuj\6057x3ki.exe[3764] ntdll.dll!LdrLoadDll                                                7C9161CA 5 Bytes  JMP 009F1690 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Documents and Settings\Damiano\Pulpit\ratuj\6057x3ki.exe[3764] kernel32.dll!FindFirstFileW                                         7C80F0E1 5 Bytes  JMP 009F1A90 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Documents and Settings\Damiano\Pulpit\ratuj\6057x3ki.exe[3764] kernel32.dll!FindNextFileW                                          7C80F13A 7 Bytes  JMP 009F1B70 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Documents and Settings\Damiano\Pulpit\ratuj\6057x3ki.exe[3764] kernel32.dll!FindFirstFileA                                         7C813559 5 Bytes  JMP 009F19D0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Documents and Settings\Damiano\Pulpit\ratuj\6057x3ki.exe[3764] kernel32.dll!FindNextFileA                                          7C839019 5 Bytes  JMP 009F1A40 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\Documents and Settings\Damiano\Pulpit\ratuj\6057x3ki.exe[3764] ws2_32.dll!connect                                                  71A5406A 5 Bytes  JMP 009F16C0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\wuauclt.exe[3936] ntdll.dll!NtEnumerateValueKey                                                                   7C90D976 5 Bytes  JMP 00BA1890 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\wuauclt.exe[3936] ntdll.dll!NtQuerySystemInformation                                                              7C90E1AA 5 Bytes  JMP 00BA1960 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\wuauclt.exe[3936] ntdll.dll!NtResumeThread                                                                        7C90E45F 5 Bytes  JMP 00BA15F0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\wuauclt.exe[3936] ntdll.dll!LdrLoadDll                                                                            7C9161CA 5 Bytes  JMP 00BA1690 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\wuauclt.exe[3936] kernel32.dll!FindFirstFileW                                                                     7C80F0E1 5 Bytes  JMP 00BA1A90 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\wuauclt.exe[3936] kernel32.dll!FindNextFileW                                                                      7C80F13A 7 Bytes  JMP 00BA1B70 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\wuauclt.exe[3936] kernel32.dll!FindFirstFileA                                                                     7C813559 5 Bytes  JMP 00BA19D0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\wuauclt.exe[3936] kernel32.dll!FindNextFileA                                                                      7C839019 5 Bytes  JMP 00BA1A40 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           C:\WINDOWS\system32\wuauclt.exe[3936] ws2_32.dll!connect                                                                              71A5406A 5 Bytes  JMP 00BA16C0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           E:\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe[3948] ntdll.dll!NtEnumerateValueKey                                     7C90D976 5 Bytes  JMP 00931890 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           E:\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe[3948] ntdll.dll!NtQuerySystemInformation                                7C90E1AA 5 Bytes  JMP 00931960 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           E:\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe[3948] ntdll.dll!NtResumeThread                                          7C90E45F 5 Bytes  JMP 009315F0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           E:\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe[3948] ntdll.dll!LdrLoadDll                                              7C9161CA 5 Bytes  JMP 00931690 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           E:\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe[3948] kernel32.dll!FindFirstFileW                                       7C80F0E1 5 Bytes  JMP 00931A90 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           E:\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe[3948] kernel32.dll!FindNextFileW                                        7C80F13A 7 Bytes  JMP 00931B70 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           E:\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe[3948] kernel32.dll!FindFirstFileA                                       7C813559 5 Bytes  JMP 009319D0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           E:\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe[3948] kernel32.dll!FindNextFileA                                        7C839019 5 Bytes  JMP 00931A40 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)
.text           E:\Apache Software Foundation\Apache2.2\bin\ApacheMonitor.exe[3948] ws2_32.dll!connect                                                71A5406A 5 Bytes  JMP 009316C0 C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll (volmgr for Windows/Microsoft Corporation)

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT             \SystemRoot\system32\DRIVERS\serial.sys[HAL.dll!KeAcquireQueuedSpinLock]                                                              90900004

---- Devices - GMER 1.0.15 ----

AttachedDevice  \FileSystem\Ntfs \Ntfs                                                                                                                eamon.sys (Amon monitor/ESET)
AttachedDevice  \Driver\Tcpip \Device\Ip                                                                                                              epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice  \Driver\Tcpip \Device\Tcp                                                                                                             epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)

Device          \Driver\prodrv06 \Device\ProDrv06                                                                                                     E20056E8
Device          \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3                                                                                           prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\atapi \Device\Ide\IdePort0                                                                                                    prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\atapi \Device\Ide\IdePort1                                                                                                    prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e                                                                                           prosync1.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device          \Driver\prohlp02 \Device\ProHlp02                                                                                                     E100C518

AttachedDevice  \Driver\Tcpip \Device\Udp                                                                                                             epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)
AttachedDevice  \Driver\Tcpip \Device\RawIp                                                                                                           epfwtdi.sys (ESET Personal Firewall TDI filter/ESET)

---- Modules - GMER 1.0.15 ----

Module          (noname) (*** hidden *** )                                                                                                            BAA28000-BAA37000 (61440 bytes)                                                                                                        

---- Threads - GMER 1.0.15 ----

Thread          System [4:128]                                                                                                                        8A84C540
Thread          System [4:132]                                                                                                                        8A84C540

---- Processes - GMER 1.0.15 ----

Process         C:\Documents and Settings\Damiano\Dane aplikacji\dplaysvr.exe (*** hidden *** )                                                       3560                                                                                                                                   

---- Registry - GMER 1.0.15 ----

Reg             HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)                                  
Reg             HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0                                                       C:\Program Files\DAEMON Tools Lite\
Reg             HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                                       0
Reg             HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                                                    0x77 0x66 0x36 0xE8 ...
Reg             HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)                         
Reg             HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0                                              0x20 0x01 0x00 0x00 ...
Reg             HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh                                           0x80 0x0E 0x6F 0xB7 ...
Reg             HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)                   
Reg             HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh                                     0x0C 0xAD 0x74 0xDF ...
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)                                  
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0                                                       C:\Program Files\DAEMON Tools Lite\
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                                       0
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                                                    0x77 0x66 0x36 0xE8 ...
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)                         
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0                                              0x20 0x01 0x00 0x00 ...
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh                                           0x80 0x0E 0x6F 0xB7 ...
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)                   
Reg             HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh                                     0x24 0xEF 0xFF 0xE4 ...
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4                                                      
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                                   0
Reg             HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                                                0xB4 0x2E 0xC4 0x4E ...
Reg             HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)                                  
Reg             HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0                                                       0
Reg             HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh                                                    0xB4 0x2E 0xC4 0x4E ...
Reg             HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run@dplaysvr                                                                           C:\Documents and Settings\Damiano\Dane aplikacji\dplaysvr.exe
Reg             HKCU\Software\Microsoft\Windows\CurrentVersion\Run@dplaysvr                                                                           C:\Documents and Settings\Damiano\Dane aplikacji\dplaysvr.exe
Reg             HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{65F2FA5F-74C4-2F7C-5C9E-E3D78FD60CE0}                       
Reg             HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{65F2FA5F-74C4-2F7C-5C9E-E3D78FD60CE0}@hafnaihmmemepckf      0x6D 0x61 0x68 0x6D ...
Reg             HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{65F2FA5F-74C4-2F7C-5C9E-E3D78FD60CE0}@jagnnifcjnnnogmfjmdn  0x6F 0x61 0x6B 0x6E ...
Reg             HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache@C:\Documents and Settings\Damiano\Dane aplikacji\dplaysvr.exe                    dplaysvr

---- Files - GMER 1.0.15 ----

File            C:\Documents and Settings\Damiano\Ustawienia lokalne\Dane aplikacji\367a4043\U\800000cf.$                                             16384 bytes executable
File            C:\Documents and Settings\Damiano\Dane aplikacji\dplaysvr.exe                                                                         77824 bytes executable
File            C:\Documents and Settings\Damiano\Dane aplikacji\dplayx.dll                                                                           58368 bytes executable
File            C:\WINDOWS\$NtUninstallKB35270$\2274491323                                                                                            0 bytes
File            C:\WINDOWS\$NtUninstallKB35270$\913981507                                                                                             0 bytes
File            C:\WINDOWS\$NtUninstallKB35270$\913981507\@                                                                                           2048 bytes
File            C:\WINDOWS\$NtUninstallKB35270$\913981507\L                                                                                           0 bytes
File            C:\WINDOWS\$NtUninstallKB35270$\913981507\L\kyaesvbd                                                                                  65664 bytes
File            C:\WINDOWS\$NtUninstallKB35270$\913981507\loader.tlb                                                                                  2632 bytes
File            C:\WINDOWS\$NtUninstallKB35270$\913981507\U                                                                                           0 bytes
File            C:\WINDOWS\$NtUninstallKB35270$\913981507\U\@00000001                                                                                 45968 bytes
File            C:\WINDOWS\$NtUninstallKB35270$\913981507\U\@000000c0                                                                                 3072 bytes
File            C:\WINDOWS\$NtUninstallKB35270$\913981507\U\@000000cb                                                                                 3072 bytes
File            C:\WINDOWS\$NtUninstallKB35270$\913981507\U\@000000cf                                                                                 1536 bytes
File            C:\WINDOWS\$NtUninstallKB35270$\913981507\U\@80000000                                                                                 73216 bytes
File            C:\WINDOWS\$NtUninstallKB35270$\913981507\U\@800000c0                                                                                 41984 bytes
File            C:\WINDOWS\$NtUninstallKB35270$\913981507\U\@800000cb                                                                                 25600 bytes
File            C:\WINDOWS\$NtUninstallKB35270$\913981507\U\@800000cf                                                                                 31232 bytes
File            C:\WINDOWS\system32\dllcache\dplaysvr.exe                                                                                             30208 bytes executable
File            C:\WINDOWS\system32\dllcache\dplayx.dll                                                                                               229888 bytes executable
File            C:\WINDOWS\system32\dplaysvr.exe                                                                                                      30208 bytes executable
File            C:\WINDOWS\system32\dplayx.dll                                                                                                        229888 bytes executable

---- EOF - GMER 1.0.15 ----
