GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2015-06-04 16:32:27
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1  rev. 465,76GB
Running: bvogi3km.exe; Driver: C:\Users\Anusia\AppData\Local\Temp\awrdypod.sys


---- User code sections - GMER 2.1 ----

.text  C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1132] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter                     0000000075458781 4 bytes [C2, 04, 00, 00]
.text  C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1132] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExW + 17                          00000000764b1401 2 bytes JMP 7547b21b C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1132] C:\Windows\syswow64\psapi.dll!EnumProcessModules + 17                            00000000764b1419 2 bytes JMP 7547b346 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1132] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 17                          00000000764b1431 2 bytes JMP 754f8f29 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1132] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 42                          00000000764b144a 2 bytes CALL 7545489d C:\Windows\syswow64\kernel32.dll
.text  ...                                                                                                                                            * 9
.text  C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1132] C:\Windows\syswow64\psapi.dll!EnumDeviceDrivers + 17                             00000000764b14dd 2 bytes JMP 754f8822 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1132] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameA + 17                      00000000764b14f5 2 bytes JMP 754f89f8 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1132] C:\Windows\syswow64\psapi.dll!QueryWorkingSetEx + 17                             00000000764b150d 2 bytes JMP 754f8718 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1132] C:\Windows\syswow64\psapi.dll!GetDeviceDriverBaseNameW + 17                      00000000764b1525 2 bytes JMP 754f8ae2 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1132] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameW + 17                            00000000764b153d 2 bytes JMP 7546fca8 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1132] C:\Windows\syswow64\psapi.dll!EnumProcesses + 17                                 00000000764b1555 2 bytes JMP 754768ef C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1132] C:\Windows\syswow64\psapi.dll!GetProcessMemoryInfo + 17                          00000000764b156d 2 bytes JMP 754f8fe3 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1132] C:\Windows\syswow64\psapi.dll!GetPerformanceInfo + 17                            00000000764b1585 2 bytes JMP 754f8b42 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1132] C:\Windows\syswow64\psapi.dll!QueryWorkingSet + 17                               00000000764b159d 2 bytes JMP 754f86dc C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1132] C:\Windows\syswow64\psapi.dll!GetModuleBaseNameA + 17                            00000000764b15b5 2 bytes JMP 7546fd41 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1132] C:\Windows\syswow64\psapi.dll!GetModuleFileNameExA + 17                          00000000764b15cd 2 bytes JMP 7547b2dc C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1132] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 20                      00000000764b16b2 2 bytes JMP 754f8ea4 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[1132] C:\Windows\syswow64\psapi.dll!GetProcessImageFileNameW + 31                      00000000764b16bd 2 bytes JMP 754f8671 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2320] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17               00000000764b1401 2 bytes JMP 7547b21b C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2320] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                 00000000764b1419 2 bytes JMP 7547b346 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2320] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17               00000000764b1431 2 bytes JMP 754f8f29 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2320] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42               00000000764b144a 2 bytes CALL 7545489d C:\Windows\syswow64\kernel32.dll
.text  ...                                                                                                                                            * 9
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2320] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                  00000000764b14dd 2 bytes JMP 754f8822 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2320] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17           00000000764b14f5 2 bytes JMP 754f89f8 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2320] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                  00000000764b150d 2 bytes JMP 754f8718 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2320] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17           00000000764b1525 2 bytes JMP 754f8ae2 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2320] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                 00000000764b153d 2 bytes JMP 7546fca8 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2320] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                      00000000764b1555 2 bytes JMP 754768ef C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2320] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17               00000000764b156d 2 bytes JMP 754f8fe3 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2320] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                 00000000764b1585 2 bytes JMP 754f8b42 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2320] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                    00000000764b159d 2 bytes JMP 754f86dc C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2320] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                 00000000764b15b5 2 bytes JMP 7546fd41 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2320] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17               00000000764b15cd 2 bytes JMP 7547b2dc C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2320] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20           00000000764b16b2 2 bytes JMP 754f8ea4 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2320] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31           00000000764b16bd 2 bytes JMP 754f8671 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2488] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                 00000000764b1401 2 bytes JMP 7547b21b C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2488] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                   00000000764b1419 2 bytes JMP 7547b346 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2488] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                 00000000764b1431 2 bytes JMP 754f8f29 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2488] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                 00000000764b144a 2 bytes CALL 7545489d C:\Windows\syswow64\kernel32.dll
.text  ...                                                                                                                                            * 9
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2488] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                    00000000764b14dd 2 bytes JMP 754f8822 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2488] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17             00000000764b14f5 2 bytes JMP 754f89f8 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2488] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                    00000000764b150d 2 bytes JMP 754f8718 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2488] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17             00000000764b1525 2 bytes JMP 754f8ae2 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2488] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                   00000000764b153d 2 bytes JMP 7546fca8 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2488] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                        00000000764b1555 2 bytes JMP 754768ef C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2488] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                 00000000764b156d 2 bytes JMP 754f8fe3 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2488] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                   00000000764b1585 2 bytes JMP 754f8b42 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2488] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                      00000000764b159d 2 bytes JMP 754f86dc C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2488] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                   00000000764b15b5 2 bytes JMP 7546fd41 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2488] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                 00000000764b15cd 2 bytes JMP 7547b2dc C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2488] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20             00000000764b16b2 2 bytes JMP 754f8ea4 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2488] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31             00000000764b16bd 2 bytes JMP 754f8671 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2768] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17                        00000000764b1401 2 bytes JMP 7547b21b C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2768] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17                          00000000764b1419 2 bytes JMP 7547b346 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2768] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17                        00000000764b1431 2 bytes JMP 754f8f29 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2768] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42                        00000000764b144a 2 bytes CALL 7545489d C:\Windows\syswow64\kernel32.dll
.text  ...                                                                                                                                            * 9
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2768] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17                           00000000764b14dd 2 bytes JMP 754f8822 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2768] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17                    00000000764b14f5 2 bytes JMP 754f89f8 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2768] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17                           00000000764b150d 2 bytes JMP 754f8718 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2768] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17                    00000000764b1525 2 bytes JMP 754f8ae2 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2768] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17                          00000000764b153d 2 bytes JMP 7546fca8 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2768] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17                               00000000764b1555 2 bytes JMP 754768ef C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2768] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17                        00000000764b156d 2 bytes JMP 754f8fe3 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2768] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17                          00000000764b1585 2 bytes JMP 754f8b42 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2768] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17                             00000000764b159d 2 bytes JMP 754f86dc C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2768] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17                          00000000764b15b5 2 bytes JMP 7546fd41 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2768] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17                        00000000764b15cd 2 bytes JMP 7547b2dc C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2768] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20                    00000000764b16b2 2 bytes JMP 754f8ea4 C:\Windows\syswow64\kernel32.dll
.text  C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2768] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31                    00000000764b16bd 2 bytes JMP 754f8671 C:\Windows\syswow64\kernel32.dll

---- User IAT/EAT - GMER 2.1 ----

IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!_onexit]                                                           [7fef1b8d7a8] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!_lock]                                                             [7fef1b42ea0] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!__dllonexit]                                                       [7fef1b23f78] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!_unlock]                                                           [7fef1b23f60] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!?terminate@@YAXXZ]                                                 [7fef1b852d0] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!??1type_info@@UEAA@XZ]                                             [7fef1b237a0] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!_amsg_exit]                                                        [7fef1b8541c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!_initterm]                                                         [7fef1b85354] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!_XcptFilter]                                                       [7fef1b85288] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!memset]                                                            [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!malloc]                                                            [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!wcsstr]                                                            [7fef1b30bbc] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!_ui64tow]                                                          [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!vswprintf_s]                                                       [7fef1b30bbc] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!_vscwprintf]                                                       [7fef1b30bbc] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!_wcsicmp]                                                          [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!wcstok_s]                                                          [7fef1b30bbc] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!iswspace]                                                          [7fef1b8548c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!memcmp]                                                            [7fef1b237a0] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!memcpy]                                                            [7fef1b8541c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!wcstol]                                                            [7fef1b85510] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!wcscspn]                                                           [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!calloc]                                                            [7fef1b85288] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!free]                                                              [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!memmove_s]                                                         [0] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!memcpy_s]                                                          [7fef1b85398] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!_wsplitpath_s]                                                     [7fef1b237a0] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!_vsnwprintf]                                                       [7fef1b8541c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!sqrtf]                                                             [7fef1b85448] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!logf]                                                              [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!__CxxFrameHandler3]                                                [7fef1b85288] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!_CxxThrowException]                                                [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[msvcrt.dll!ceilf]                                                             [7fef1b30bbc] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetModuleHandleW]                                                [7fef1b30bbc] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!CreateToolhelp32Snapshot]                                        [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetCurrentThreadId]                                              [7fef1b30bbc] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!Sleep]                                                           [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!CompareStringOrdinal]                                            [7fef1b30bbc] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetVersion]                                                      [7fef1b85288] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!LocalFree]                                                       [7fef1b30bbc] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!SetLastError]                                                    [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!DeactivateActCtx]                                                [7fef1b30bbc] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetLastError]                                                    [7fef1b85288] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!LoadLibraryW]                                                    [7fef1b30bbc] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetProcAddress]                                                  [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!ActivateActCtx]                                                  [7fef1b30bbc] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!FindActCtxSectionStringW]                                        [7fef1b8ad98] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!CreateActCtxW]                                                   [7fef1b8ad98] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetModuleFileNameW]                                              [7fef1b30bbc] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetModuleHandleExW]                                              [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!QueryActCtxW]                                                    [7fef1b42ea0] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!OutputDebugStringA]                                              [7fef1b8ad98] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!CloseHandle]                                                     [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!WaitForSingleObject]                                             [7fef1b85288] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!CreateEventW]                                                    [7fef1b8ad98] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!SetEvent]                                                        [0] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!DeleteFileW]                                                     [7fef1b30bbc] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!CompareFileTime]                                                 [7fef1b24298] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!lstrlenW]                                                        [7fef1b82ef0] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!SetFileAttributesW]                                              [7fef1b8ce7c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!CreateFileW]                                                     [7fef1b8cfe4] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GlobalFree]                                                      [7fef1b242a8] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!CreateThread]                                                    [7fef1b26f18] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!LocalAlloc]                                                      [7fef1b26570] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!lstrcmpW]                                                        [7fef1b34d9c] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!lstrcmpiW]                                                       [7fef1b8ce4c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!FreeLibrary]                                                     [7fef1b8cdfc] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!SizeofResource]                                                  [7fef1b8ce20] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!LockResource]                                                    [7fef1b252e0] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!LoadResource]                                                    [7fef1b8d084] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!FindResourceW]                                                   [7fef1b30bbc] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!FindResourceExW]                                                 [7fef1b24298] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetFileAttributesW]                                              [7fef1b82ef0] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetSystemTime]                                                   [7fef1b242bc] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!SystemTimeToTzSpecificLocalTime]                                 [7fef1b8cfe4] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!WaitForMultipleObjects]                                          [7fef1b242a8] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!FileTimeToSystemTime]                                            [7fef1b26f18] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GlobalAlloc]                                                     [7fef1b26570] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GlobalReAlloc]                                                   [7fef1b34d9c] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!SystemTimeToFileTime]                                            [7fef1b8ce4c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetTickCount]                                                    [7fef1b8cdfc] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!Process32FirstW]                                                 [7fef1b8ce20] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!ReadFile]                                                        [7fef1b252e0] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!WriteFile]                                                       [7fef1b8d084] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!SetFilePointerEx]                                                [7fef1b30bbc] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!FlushFileBuffers]                                                [7fef1b367d4] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetFileInformationByHandle]                                      [7fef1b8d090] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GlobalSize]                                                      [7fef1b387bc] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GlobalLock]                                                      [7fef1b8d09c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GlobalUnlock]                                                    [7fef1b36bc8] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetCurrentProcessId]                                             [7fef1b26f18] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!FileTimeToLocalFileTime]                                         [7fef1b24460] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetDateFormatW]                                                  [7fef1b39ddc] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetTimeFormatW]                                                  [7fef1b40cd8] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!FormatMessageW]                                                  [7fef1b41070] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!ReleaseActCtx]                                                   [7fef1b41084] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!ExpandEnvironmentStringsW]                                       [7fef1b367e4] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!DosDateTimeToFileTime]                                           [7fef1b8d270] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!EnumUILanguagesW]                                                [7fef1b8dea8] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetUserDefaultUILanguage]                                        [7fef1b30a10] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetLocaleInfoW]                                                  [7fef1b24460] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetDriveTypeW]                                                   [7fef1b30a1c] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetProcessHeap]                                                  [7fef1b24460] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!HeapFree]                                                        [7fef1b83154] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!DisableThreadLibraryCalls]                                       [7fef1b8df18] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetSystemDirectoryW]                                             [7fef1b30a28] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetNumberFormatW]                                                [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!MulDiv]                                                          [7fef1b8dec0] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetTempPathW]                                                    [7fef1b8decc] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!CreateDirectoryW]                                                [7fef1b8df0c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!TzSpecificLocalTimeToSystemTime]                                 [7fef1b24460] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!QueryPerformanceCounter]                                         [7fef1b8df38] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!QueryPerformanceFrequency]                                       [7fef1b8df18] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!ResetEvent]                                                      [7fef1b30a28] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!LoadLibraryExA]                                                  [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!DelayLoadFailureHook]                                            [7fef1b8df50] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!HeapDestroy]                                                     [7fef1b8dee0] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!RaiseException]                                                  [7fef1b30a50] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetVersionExA]                                                   [7fef1b30bbc] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetSystemTimeAsFileTime]                                         [7fef1bbbfec] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!TerminateProcess]                                                [7fef1bbc21c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetCurrentProcess]                                               [7fef1bbc09c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!UnhandledExceptionFilter]                                        [7fef1b82d60] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!SetUnhandledExceptionFilter]                                     [7fef1bbc0dc] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!RtlVirtualUnwind]                                                [7fef1bbc5c4] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!RtlLookupFunctionEntry]                                          [7fef1b73748] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!RtlCaptureContext]                                               [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!Process32NextW]                                                  [7fef1b73748] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!OpenProcess]                                                     [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[KERNEL32.dll!GetProcessTimes]                                                 [7fef1b82e90] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[ADVAPI32.dll!CryptAcquireContextW]                                            [7fef1b73748] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[ADVAPI32.dll!CryptImportKey]                                                  [7fef1bbc1c0] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[ADVAPI32.dll!CryptCreateHash]                                                 [7fef1b73748] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[ADVAPI32.dll!CryptHashData]                                                   [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[ADVAPI32.dll!CryptSignHashW]                                                  [7fef1bbc110] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[ADVAPI32.dll!CryptDestroyHash]                                                [7fef1bbc5dc] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[ADVAPI32.dll!CryptDestroyKey]                                                 [7fef1b24460] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[ADVAPI32.dll!CryptReleaseContext]                                             [7fef1bbc68c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[ADVAPI32.dll!RegCloseKey]                                                     [7fef1bbd178] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[ADVAPI32.dll!RegOpenKeyExW]                                                   [7fef1bbc21c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[ADVAPI32.dll!RegQueryValueExW]                                                [7fef1bbc230] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[ADVAPI32.dll!RegEnumKeyW]                                                     [7fef1b24460] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[GDI32.dll!GetDeviceCaps]                                                      [7fef1b28f5c] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[GDI32.dll!DeleteDC]                                                           [7fef1b28f48] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[GDI32.dll!GetTextExtentPoint32W]                                              [7fef1b81de0] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[GDI32.dll!GetStockObject]                                                     [7fef1b7f23c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[GDI32.dll!GetTextExtentPointW]                                                [7fef1b28758] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[GDI32.dll!CreateDIBSection]                                                   [7fef1b2bdb0] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[GDI32.dll!DeleteObject]                                                       [7fef1b81c3c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[GDI32.dll!CreateCompatibleDC]                                                 [7fef1b81c2c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!StrRetToBufW]                                                     [7fef1b95130] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!SHGetThreadRef]                                                   [7fef1b95354] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!SHRegGetValueW]                                                   [7fef1b81c00] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!StrStrIW]                                                         [7fef1b953d0] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!PathCombineW]                                                     [7fef1b30714] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!StrCmpIW]                                                         [7fef1b2ec44] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!StrStrW]                                                          [7fef1b83018] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!StrCSpnW]                                                         [7fef1b830c8] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!PathFindFileNameW]                                                [7fef1b46730] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!StrFormatByteSizeW]                                               [7fef1b82d60] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!StrCmpW]                                                          [7fef1b830dc] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!SHGetValueW]                                                      [7fef1bbc5c4] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!StrCmpLogicalW]                                                   [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!PathRemoveBlanksW]                                                [7fef1b73748] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!AssocQueryKeyW]                                                   [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!PathRemoveExtensionW]                                             [7fef1b82e90] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!SHStrDupW]                                                        [7fef1b82ea8] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!PathStripPathW]                                                   [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!PathAddBackslashW]                                                [7fef1b82ed0] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!PathAppendW]                                                      [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!AssocCreate]                                                      [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!PathFindExtensionW]                                               [7fef1b83110] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[SHLWAPI.dll!PathRemoveFileSpecW]                                              [7fef1b30bbc] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!UnregisterClassA]                                                  [7fef1b46764] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!DialogBoxParamW]                                                   [0] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!InsertMenuW]                                                       [7fef1b7c0d0] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!CharNextW]                                                         [7fef1b7c288] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!RemoveMenu]                                                        [7fef1b7c2b8] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetSubMenu]                                                        [7fef1b82e40] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!TrackPopupMenu]                                                    [7fef1b7c2e8] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!SetFocus]                                                          [7fef1b7c31c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!SetForegroundWindow]                                               [7fef1b7c31c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetForegroundWindow]                                               [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetShellWindow]                                                    [7fef1b7c31c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!LoadMenuW]                                                         [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!DestroyMenu]                                                       [7fef1b7c334] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!LoadStringW]                                                       [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!SendMessageW]                                                      [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetClassNameW]                                                     [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!SetMenuDefaultItem]                                                [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!LoadIconW]                                                         [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!SetWindowTextW]                                                    [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!SetDlgItemTextW]                                                   [7fef1b7c350] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!EndDialog]                                                         [7fef1b7c36c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetDlgItem]                                                        [7fef1b7c3e0] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetWindowLongPtrW]                                                 [7fef1b73748] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!SetWindowLongPtrW]                                                 [7fef1b7c6d8] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!IsDlgButtonChecked]                                                [7fef1b7c80c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!UnhookWindowsHookEx]                                               [7fef1b7c824] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!SendDlgItemMessageW]                                               [7fef1b7c830] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!CheckDlgButton]                                                    [7fef1b73748] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!EnableWindow]                                                      [7fef1b7c830] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!ShowWindow]                                                        [0] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetWindowLongW]                                                    [7fef1b7f230] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!SetWindowLongW]                                                    [7fef1b7f250] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetClientRect]                                                     [7fef1b7f260] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetSystemMetrics]                                                  [7fef1b7f270] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!LoadImageW]                                                        [7fef1b81de0] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetParent]                                                         [7fef1b7f23c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!IsChild]                                                           [7fef1b95054] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!CallNextHookEx]                                                    [7fef1bd1bf0] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!CreateWindowExW]                                                   [7fef1bd1bf0] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!SetWindowPos]                                                      [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!SetWindowsHookExW]                                                 [7fef1b83610] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetDC]                                                             [7fef1b9508c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!ReleaseDC]                                                         [7fef1b95130] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetWindowRect]                                                     [7fef1b95354] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!ScreenToClient]                                                    [7fef1b81c10] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!SetTimer]                                                          [7fef1b81c00] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!KillTimer]                                                         [7fef1b81a24] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!PostMessageW]                                                      [7fef1b953d0] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetDlgCtrlID]                                                      [7fef1b6754c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!DestroyIcon]                                                       [7fef1b6752c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetWindowTextW]                                                    [7fef1b674dc] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!CopyImage]                                                         [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetSysColor]                                                       [7fef1b6748c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetCursorPos]                                                      [7fef1b6756c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetClassInfoW]                                                     [7fef1b674fc] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!LoadCursorW]                                                       [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!RegisterClassW]                                                    [0] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!FindWindowW]                                                       [7fef1b674cc] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetWindow]                                                         [7fef1b674ac] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetWindowThreadProcessId]                                          [7fef1b6755c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!SendMessageTimeoutW]                                               [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!SwitchToThisWindow]                                                [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetLastActivePopup]                                                [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!DestroyWindow]                                                     [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!RegisterClipboardFormatW]                                          [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetMenuItemInfoW]                                                  [7fef1b6750c] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[USER32.dll!GetMenuItemCount]                                                  [7fef1b674ec] C:\Windows\system32\wpdshext.dll
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[WINMM.dll!timeSetEvent]                                                       [7fef1b28f70] 
IAT    C:\Windows\Explorer.EXE[2104] @ C:\Windows\system32\wpdshext.dll[WINMM.dll!timeKillEvent]                                                      [7fef1b28f70] 

---- Registry - GMER 2.1 ----

Reg    HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{09E1E186-2FC6-4608-8891-53D1B9FD8180}\Connection@Name    isatap.{D36EF36C-51EF-4B02-AF13-B9094789EDDD}
Reg    HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Bind       \Device\{09E1E186-2FC6-4608-8891-53D1B9FD8180}?\Device\{03A16472-BDB0-424A-8094-30F11FB11A3C}?\Device\{CFD1783C-B4D6-4E32-83FF-15A2E3E64B25}?
Reg    HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Route      "{09E1E186-2FC6-4608-8891-53D1B9FD8180}"?"{03A16472-BDB0-424A-8094-30F11FB11A3C}"?"{CFD1783C-B4D6-4E32-83FF-15A2E3E64B25}"?
Reg    HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Export     \Device\TCPIP6TUNNEL_{09E1E186-2FC6-4608-8891-53D1B9FD8180}?\Device\TCPIP6TUNNEL_{03A16472-BDB0-424A-8094-30F11FB11A3C}?\Device\TCPIP6TUNNEL_{CFD1783C-B4D6-4E32-83FF-15A2E3E64B25}?
Reg    HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{09E1E186-2FC6-4608-8891-53D1B9FD8180}@InterfaceName                         isatap.{D36EF36C-51EF-4B02-AF13-B9094789EDDD}
Reg    HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{09E1E186-2FC6-4608-8891-53D1B9FD8180}@ReusableType                          0

---- Disk sectors - GMER 2.1 ----

Disk   \Device\Harddisk0\DR0                                                                                                                          unknown MBR code

---- Files - GMER 2.1 ----

File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\38B797D5C1AA12A61A054371EF32487214ACD14F  0 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\14C0AF6A928B5DB212A96DAB1C0FC11ABC24AE7F  29774 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\B33AEBDD1F299C6F0DE5A43ADE72F3A5F4829DB6  3221 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\F6B655A419FA7F2044C71896959A67740E9AEF69  891 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\DFF3A8DCE339226794D5318362A992178EEC7D20  1835 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\1AFAF7882411BD2B1D11CD86B335B850EE2CA031  3285 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\3D8E14F6E1D7B88C4384DA48CFABAC15D187F09B  416 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\454471C78373A928B64BABDD2B8189F91DA9C16F  891 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\08550ACFDA8F3310D7C3321E6C629AF2A72A0E2F  4739 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\3081706FC358ABDDAEB947DD16C55BA1DA59DFA0  1845 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\5661B85F1F19ADC3C64541049B95546EF677F121  2359 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\2348B3183B98611F77F392EAFDE1766588DA6055  897 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\F2C45BDB2AA491D84283059CA176FAE7A348D49C  3179 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\7B332F690829D186F81764474E7D4CF6EB67F44B  626 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\CA871C5908BC5A17467A2CC170D238C5730699C3  2188 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\561E51E4345F02599CED0A2C76FF42D0BFCDD2B1  3108 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\CEA7DF0759EF7ECE307523F37B675E43AE66AAAC  3206 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\B0B76F3A5E432B9C89EEEBFA73D0B2582BD1176A  1738 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\D8F3ADCCEB25E6C5F0D4B6DAB23AC52B28A26EC0  10297 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\700EEA8837E79BAE5D0B7C117884A406499FCB4E  7254 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\F41F9D135C2E94DBBC67E0860E966B359F535C32  2214 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\343F7E595AFDB6C5525351AC0567DEBCCE6849B3  3239 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\76941F06A7719E664C2F01CDF513F75B6CD5BC0D  7769 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\759B680269D1AD642DA809FC430389297FDDB263  4117 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\C497667C4E278732B981312642949480699D1B97  3894 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\B0584D8C235BCB007EDEE376299259F8A27F8299  3436 bytes
File   C:\Users\Anusia\AppData\Local\Mozilla\Firefox\Profiles\k7x97cbn.default-1424855432198\cache2\entries\5BCF404F2C3C5D762B21202D387BFC8E2101CB2D  4247 bytes

---- EOF - GMER 2.1 ----
