offline
- Pridružio: 29 Nov 2012
- Poruke: 36
|
Napisano: 02 Jan 2014 20:37
I ove GMER logove cu morati rucno prvo ark:
GMER 2.1.19163 - gmer.net
Rootkit scan 2014-01-02 20:33:03
Windows 6.1.7601 Service Pack 1
Running: od1uut3p.exe; Driver: E:\Users\lazar\AppData\Local\Temp\awdyqkod.sys
---- System - GMER 2.1 ----
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwAddBootEntry [0x8F86BB10]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwAssignProcessToJobObject [0x8F86C5EE]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwCreateEvent [0x8F8785E0]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwCreateEventPair [0x8F87862C]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwCreateIoCompletion [0x8F8787C6]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwCreateMutant [0x8F87854E]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwCreateSection [0x8F878670]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwCreateSemaphore [0x8F878596]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwCreateThread [0x8F86CB24]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwCreateThreadEx [0x8F86CD40]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwCreateTimer [0x8F878780]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwDebugActiveProcess [0x8F86D3DC]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwDeleteBootEntry [0x8F86BB76]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwDuplicateObject [0x8F870B58]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwLoadDriver [0x8F86B75E]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwModifyBootEntry [0x8F86BBDC]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwNotifyChangeKey [0x8F870F4E]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwNotifyChangeMultipleKeys [0x8F86DE6C]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwOpenEvent [0x8F87860A]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwOpenEventPair [0x8F87864E]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwOpenIoCompletion [0x8F8787EA]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwOpenMutant [0x8F878574]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwOpenProcess [0x8F870452]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwOpenSection [0x8F8786FE]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwOpenSemaphore [0x8F8785BE]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwOpenThread [0x8F87083A]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwOpenTimer [0x8F8787A4]
SSDT \??\E:\Windows\system32\drivers\aswSP.sys ZwProtectVirtualMemory [0x904450CC]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwQueryObject [0x8F86DD38]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwQueueApcThreadEx [0x8F86DA46]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwSetBootEntryOrder [0x8F86BC42]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwSetBootOptions [0x8F86BCA8]
SSDT \??\E:\Windows\system32\drivers\aswSP.sys ZwSetContextThread [0x90445316]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwSetSystemInformation [0x8F86B7F8]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwSetSystemPowerState [0x8F86B9CE]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwShutdownSystem [0x8F86B95C]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwSuspendProcess [0x8F86D5A6]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwSuspendThread [0x8F86D708]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwSystemDebugControl [0x8F86BA56]
SSDT \??\E:\Windows\system32\drivers\aswSP.sys ZwTerminateProcess [0x90445194]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwTerminateThread [0x8F86D236]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwVdmControl [0x8F86BD0E]
SSDT \??\E:\Windows\system32\drivers\aswSnx.sys ZwWriteVirtualMemory [0x8F86C64A]
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 142D 82C80A15 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82CBA212 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10CB 82CC1460 4 Bytes [10, BB, 86, 8F]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1153 82CC14E8 4 Bytes [EE, C5, 86, 8F]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11A7 82CC153C 8 Bytes [E0, 85, 87, 8F, 2C, 86, 87, ...] {LOOPNZ 0xffffff87; XCHG [EDI-0x707879d4], ECX}
.text ntkrnlpa.exe!KeRemoveQueueEx + 11B3 82CC1548 4 Bytes [C6, 87, 87, 8F]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11CF 82CC1564 4 Bytes [4E, 85, 87, 8F]
.text ...
PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 108 82E7C4DF 4 Bytes CALL 8F86E52F \??\E:\Windows\system32\drivers\aswSnx.sys
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 122 82E96347 4 Bytes CALL 8F86E545 \??\E:\Windows\system32\drivers\aswSnx.sys
? E:\Windows\system32\drivers\aswTdi.sys The system cannot find the file specified. !
? E:\Windows\system32\drivers\aswFsBlk.sys The system cannot find the file specified. !
? E:\Users\lazar\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !
---- User code sections - GMER 2.1 ----
.text E:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[404] kernel32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
.text E:\Windows\system32\csrss.exe[424] kernel32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtCreateFile + 6 77A7560E 4 Bytes [28, 58, CE, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtCreateFile + B 77A75613 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtMapViewOfSection + 6 77A75C6E 4 Bytes [28, 5B, CE, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtMapViewOfSection + B 77A75C73 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtOpenFile + 6 77A75D1E 4 Bytes [68, 58, CE, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtOpenFile + B 77A75D23 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtOpenProcess + 6 77A75DCE 4 Bytes [A8, 59, CE, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtOpenProcess + B 77A75DD3 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtOpenProcessToken + 6 77A75DDE 4 Bytes CALL 76A82C3C E:\Windows\system32\SHELL32.dll
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtOpenProcessToken + B 77A75DE3 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtOpenProcessTokenEx + 6 77A75DEE 4 Bytes [A8, 5A, CE, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtOpenProcessTokenEx + B 77A75DF3 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtOpenThread + 6 77A75E4E 4 Bytes [68, 59, CE, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtOpenThread + B 77A75E53 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtOpenThreadToken + 6 77A75E5E 4 Bytes [68, 5A, CE, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtOpenThreadToken + B 77A75E63 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtOpenThreadTokenEx + 6 77A75E6E 4 Bytes CALL 76A82CCD E:\Windows\system32\SHELL32.dll
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtOpenThreadTokenEx + B 77A75E73 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtQueryAttributesFile + 6 77A75F7E 4 Bytes [A8, 58, CE, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtQueryAttributesFile + B 77A75F83 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtQueryFullAttributesFile + 6 77A7602E 4 Bytes CALL 76A82E8B E:\Windows\system32\SHELL32.dll
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtQueryFullAttributesFile + B 77A76033 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtSetInformationFile + 6 77A7667E 4 Bytes [28, 59, CE, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtSetInformationFile + B 77A76683 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtSetInformationThread + 6 77A766DE 4 Bytes [28, 5A, CE, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtSetInformationThread + B 77A766E3 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtUnmapViewOfSection + 6 77A769FE 4 Bytes [68, 5B, CE, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!NtUnmapViewOfSection + B 77A76A03 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!LdrUnloadDll 77A8C8DE 5 Bytes JMP 00DA03FC
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] ntdll.dll!LdrLoadDll 77A922AE 5 Bytes JMP 00DA01F8
.text E:\Program Files\Google\Chrome\Application\chrome.exe[440] KERNEL32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
.text E:\Windows\system32\wininit.exe[492] kernel32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
.text E:\Windows\system32\csrss.exe[504] kernel32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
.text E:\Windows\system32\services.exe[552] kernel32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
.text E:\Windows\system32\lsass.exe[568] kernel32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
.text ...
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtCreateFile + 6 77A7560E 4 Bytes [28, 10, B5, 00] {SUB [EAX], DL; MOV CH, 0x0}
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtCreateFile + B 77A75613 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtMapViewOfSection + 6 77A75C6E 4 Bytes [28, 13, B5, 00] {SUB [EBX], DL; MOV CH, 0x0}
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtMapViewOfSection + B 77A75C73 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtOpenFile + 6 77A75D1E 4 Bytes [68, 10, B5, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtOpenFile + B 77A75D23 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtOpenProcess + 6 77A75DCE 4 Bytes [A8, 11, B5, 00] {TEST AL, 0x11; MOV CH, 0x0}
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtOpenProcess + B 77A75DD3 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtOpenProcessToken + 6 77A75DDE 4 Bytes CALL 76A812F4 E:\Windows\system32\SHELL32.dll
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtOpenProcessToken + B 77A75DE3 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtOpenProcessTokenEx + 6 77A75DEE 4 Bytes [A8, 12, B5, 00] {TEST AL, 0x12; MOV CH, 0x0}
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtOpenProcessTokenEx + B 77A75DF3 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtOpenThread + 6 77A75E4E 4 Bytes [68, 11, B5, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtOpenThread + B 77A75E53 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtOpenThreadToken + 6 77A75E5E 4 Bytes [68, 12, B5, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtOpenThreadToken + B 77A75E63 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtOpenThreadTokenEx + 6 77A75E6E 4 Bytes CALL 76A81385 E:\Windows\system32\SHELL32.dll
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtOpenThreadTokenEx + B 77A75E73 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtQueryAttributesFile + 6 77A75F7E 4 Bytes [A8, 10, B5, 00] {TEST AL, 0x10; MOV CH, 0x0}
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtQueryAttributesFile + B 77A75F83 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtQueryFullAttributesFile + 6 77A7602E 4 Bytes CALL 76A81543 E:\Windows\system32\SHELL32.dll
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtQueryFullAttributesFile + B 77A76033 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtSetInformationFile + 6 77A7667E 4 Bytes [28, 11, B5, 00] {SUB [ECX], DL; MOV CH, 0x0}
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtSetInformationFile + B 77A76683 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtSetInformationThread + 6 77A766DE 4 Bytes [28, 12, B5, 00] {SUB [EDX], DL; MOV CH, 0x0}
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtSetInformationThread + B 77A766E3 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtUnmapViewOfSection + 6 77A769FE 4 Bytes [68, 13, B5, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!NtUnmapViewOfSection + B 77A76A03 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!LdrUnloadDll 77A8C8DE 5 Bytes JMP 00BB03FC
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] ntdll.dll!LdrLoadDll 77A922AE 5 Bytes JMP 00BB01F8
.text E:\Program Files\Google\Chrome\Application\chrome.exe[2612] KERNEL32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
.text E:\Users\lazar\Downloads\od1uut3p.exe[2648] kernel32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
.text E:\Windows\system32\svchost.exe[3264] kernel32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
.text E:\Windows\system32\svchost.exe[3304] kernel32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
.text E:\Windows\system32\SearchIndexer.exe[3340] kernel32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[3540] ntdll.dll!LdrUnloadDll 77A8C8DE 5 Bytes JMP 000E03FC
.text E:\Program Files\Google\Chrome\Application\chrome.exe[3540] ntdll.dll!LdrLoadDll 77A922AE 5 Bytes JMP 000E01F8
.text E:\Program Files\Google\Chrome\Application\chrome.exe[3540] KERNEL32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
.text E:\Program Files\Windows Media Player\wmpnetwk.exe[3552] kernel32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
.text E:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[3780] kernel32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtCreateFile + 6 77A7560E 4 Bytes [28, 28, FA, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtCreateFile + B 77A75613 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtMapViewOfSection + 6 77A75C6E 4 Bytes [28, 2B, FA, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtMapViewOfSection + B 77A75C73 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenFile + 6 77A75D1E 4 Bytes [68, 28, FA, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenFile + B 77A75D23 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenProcess + 6 77A75DCE 4 Bytes [A8, 29, FA, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenProcess + B 77A75DD3 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenProcessToken + 6 77A75DDE 4 Bytes CALL 76A8580C E:\Windows\system32\SHELL32.dll
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenProcessToken + B 77A75DE3 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenProcessTokenEx + 6 77A75DEE 4 Bytes [A8, 2A, FA, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenProcessTokenEx + B 77A75DF3 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenThread + 6 77A75E4E 4 Bytes [68, 29, FA, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenThread + B 77A75E53 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenThreadToken + 6 77A75E5E 4 Bytes [68, 2A, FA, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenThreadToken + B 77A75E63 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenThreadTokenEx + 6 77A75E6E 4 Bytes CALL 76A8589D E:\Windows\system32\SHELL32.dll
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtOpenThreadTokenEx + B 77A75E73 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtQueryAttributesFile + 6 77A75F7E 4 Bytes [A8, 28, FA, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtQueryAttributesFile + B 77A75F83 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtQueryFullAttributesFile + 6 77A7602E 4 Bytes CALL 76A85A5B E:\Windows\system32\SHELL32.dll
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtQueryFullAttributesFile + B 77A76033 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtSetInformationFile + 6 77A7667E 4 Bytes [28, 29, FA, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtSetInformationFile + B 77A76683 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtSetInformationThread + 6 77A766DE 4 Bytes [28, 2A, FA, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtSetInformationThread + B 77A766E3 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtUnmapViewOfSection + 6 77A769FE 4 Bytes [68, 2B, FA, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!NtUnmapViewOfSection + B 77A76A03 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!LdrUnloadDll 77A8C8DE 5 Bytes JMP 010703FC
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] ntdll.dll!LdrLoadDll 77A922AE 5 Bytes JMP 010701F8
.text E:\Program Files\Google\Chrome\Application\chrome.exe[4356] KERNEL32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
.text E:\Users\lazar\AppData\Roaming\uTorrent\uTorrent.exe[4452] kernel32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
.text E:\Windows\system32\svchost.exe[4728] kernel32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtCreateFile + 6 77A7560E 4 Bytes [28, 00, C5, 00] {SUB [EAX], AL; LDS EAX, [EAX]}
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtCreateFile + B 77A75613 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtMapViewOfSection + 6 77A75C6E 1 Byte [28]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtMapViewOfSection + 6 77A75C6E 4 Bytes [28, 03, C5, 00] {SUB [EBX], AL; LDS EAX, [EAX]}
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtMapViewOfSection + B 77A75C73 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtOpenFile + 6 77A75D1E 4 Bytes [68, 00, C5, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtOpenFile + B 77A75D23 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtOpenProcess + 6 77A75DCE 4 Bytes [A8, 01, C5, 00] {TEST AL, 0x1; LDS EAX, [EAX]}
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtOpenProcess + B 77A75DD3 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtOpenProcessToken + 6 77A75DDE 4 Bytes CALL 76A822E4 E:\Windows\system32\SHELL32.dll
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtOpenProcessToken + B 77A75DE3 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtOpenProcessTokenEx + 6 77A75DEE 4 Bytes [A8, 02, C5, 00] {TEST AL, 0x2; LDS EAX, [EAX]}
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtOpenProcessTokenEx + B 77A75DF3 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtOpenThread + 6 77A75E4E 4 Bytes [68, 01, C5, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtOpenThread + B 77A75E53 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtOpenThreadToken + 6 77A75E5E 4 Bytes [68, 02, C5, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtOpenThreadToken + B 77A75E63 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtOpenThreadTokenEx + 6 77A75E6E 4 Bytes CALL 76A82375 E:\Windows\system32\SHELL32.dll
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtOpenThreadTokenEx + B 77A75E73 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtQueryAttributesFile + 6 77A75F7E 4 Bytes [A8, 00, C5, 00] {TEST AL, 0x0; LDS EAX, [EAX]}
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtQueryAttributesFile + B 77A75F83 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtQueryFullAttributesFile + 6 77A7602E 4 Bytes CALL 76A82533 E:\Windows\system32\SHELL32.dll
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtQueryFullAttributesFile + B 77A76033 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtSetInformationFile + 6 77A7667E 4 Bytes [28, 01, C5, 00] {SUB [ECX], AL; LDS EAX, [EAX]}
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtSetInformationFile + B 77A76683 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtSetInformationThread + 6 77A766DE 4 Bytes [28, 02, C5, 00] {SUB [EDX], AL; LDS EAX, [EAX]}
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtSetInformationThread + B 77A766E3 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtUnmapViewOfSection + 6 77A769FE 1 Byte [68]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtUnmapViewOfSection + 6 77A769FE 4 Bytes [68, 03, C5, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!NtUnmapViewOfSection + B 77A76A03 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!LdrUnloadDll 77A8C8DE 5 Bytes JMP 00C903FC
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] ntdll.dll!LdrLoadDll 77A922AE 5 Bytes JMP 00C901F8
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5496] KERNEL32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
.text E:\Windows\system32\AUDIODG.EXE[5500] kernel32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtCreateFile + 6 77A7560E 4 Bytes [28, 4C, DD, 00] {SUB [EBP+EBX*8+0x0], CL}
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtCreateFile + B 77A75613 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtMapViewOfSection + 6 77A75C6E 4 Bytes [28, 4F, DD, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtMapViewOfSection + B 77A75C73 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtOpenFile + 6 77A75D1E 4 Bytes [68, 4C, DD, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtOpenFile + B 77A75D23 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtOpenProcess + 6 77A75DCE 4 Bytes [A8, 4D, DD, 00] {TEST AL, 0x4d; FLD QWORD [EAX]}
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtOpenProcess + B 77A75DD3 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtOpenProcessToken + 6 77A75DDE 4 Bytes CALL 76A83B30 E:\Windows\system32\SHELL32.dll
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtOpenProcessToken + B 77A75DE3 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtOpenProcessTokenEx + 6 77A75DEE 4 Bytes [A8, 4E, DD, 00] {TEST AL, 0x4e; FLD QWORD [EAX]}
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtOpenProcessTokenEx + B 77A75DF3 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtOpenThread + 6 77A75E4E 4 Bytes [68, 4D, DD, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtOpenThread + B 77A75E53 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtOpenThreadToken + 6 77A75E5E 4 Bytes [68, 4E, DD, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtOpenThreadToken + B 77A75E63 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtOpenThreadTokenEx + 6 77A75E6E 4 Bytes CALL 76A83BC1 E:\Windows\system32\SHELL32.dll
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtOpenThreadTokenEx + B 77A75E73 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtQueryAttributesFile + 6 77A75F7E 4 Bytes [A8, 4C, DD, 00] {TEST AL, 0x4c; FLD QWORD [EAX]}
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtQueryAttributesFile + B 77A75F83 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtQueryFullAttributesFile + 6 77A7602E 4 Bytes CALL 76A83D7F E:\Windows\system32\SHELL32.dll
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtQueryFullAttributesFile + B 77A76033 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtSetInformationFile + 6 77A7667E 4 Bytes [28, 4D, DD, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtSetInformationFile + B 77A76683 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtSetInformationThread + 6 77A766DE 4 Bytes [28, 4E, DD, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtSetInformationThread + B 77A766E3 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtUnmapViewOfSection + 6 77A769FE 4 Bytes [68, 4F, DD, 00]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!NtUnmapViewOfSection + B 77A76A03 1 Byte [E2]
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!LdrUnloadDll 77A8C8DE 5 Bytes JMP 00EA03FC
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] ntdll.dll!LdrLoadDll 77A922AE 5 Bytes JMP 00EA01F8
.text E:\Program Files\Google\Chrome\Application\chrome.exe[5604] KERNEL32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
.text E:\Windows\system32\taskhost.exe[6084] kernel32.dll!GetBinaryTypeW + 70 763769E4 1 Byte [62]
---- Devices - GMER 2.1 ----
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.sys
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@PendingFileRenameOperations ?????????????????????e???????????j?????????r?k??tunnel??????? ???????????????????,?? ?????????w????????????????????????????????????????????????????????????}??@input.inf,%hid_device%;HID-compliant device????? ??????????????????????????????????????? ??????? ??????yA???$??????????????????????????????????????? ?????????????}?????k??????????N?????????????s?????????????{00000000-0000-0000-0000-000000000000}??????????????????? ???????l?????752???????????????????$??????????????????????????@o??????????????????????????????????6.1.7601.18251??????????????????????????????????????????????? ??????????????????Unknown Device???????????????????????????&???&???&???&???&???&???&???&???&???&???&?7?&???&???&???&???&???&???&???&???&??????????????????????????? ???????F?????EE4??? ?????????????????????1????????????????????????? ??????????????????@input.inf,%stdmfg%;(Standard system devices)?????z?????????????{8ECC055D-047F-11D1-A537-0000F8753ED1}???????????????e????????????????????????????????0??????f???h??????????? ?????????????
---- EOF - GMER 2.1 ----
evo ga i autostart:
GMER 2.1.19163 - gmer.net
Autostart scan 2014-01-02 20:35:31
Windows 6.1.7601 Service Pack 1
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = autocheck autochk * /*file not found*/
HKLM\SYSTEM\CurrentControlSet\Services\ >>>
AdobeARMservice@ = "E:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe"
avast! Antivirus@ = "E:\Program Files\AVAST Software\Avast\AvastSvc.exe"
gupdate@ = "E:\Program Files\Google\Update\GoogleUpdate.exe" /svc
nvsvc@ = "E:\Windows\system32\nvvsvc.exe"
nvUpdatusService@ = "E:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
Stereo Service@ = "E:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@AvastUI.exe"E:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui = "E:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
@SunJavaUpdateSched"E:\Program Files\Common Files\Java\Java Update\jusched.exe" = "E:\Program Files\Common Files\Java\Java Update\jusched.exe"
@Adobe ARM"E:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" = "E:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
@AdobeAAMUpdater-1.0"E:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" = "E:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
@SwitchBoardE:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe = E:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
@AdobeCS6ServiceManager"E:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin = "E:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@AdobeBridge /*file not found*/ = /*file not found*/
@uTorrentE:\Users\Marijana\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED = E:\Users\Marijana\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad@WebCheck =
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{472083B0-C522-11CF-8763-00608CC02F24} /*avast*/E:\Program Files\AVAST Software\Avast\ashShell.dll = E:\Program Files\AVAST Software\Avast\ashShell.dll
@{E6FB5E20-DE35-11CF-9C87-00AA005127ED} /*WebCheck*/(null) =
@{A70C977A-BF00-412C-90B7-034C51DA2439} /*NvCpl DesktopContext Class*/E:\Program Files\NVIDIA Corporation\Display\nvui.dll = E:\Program Files\NVIDIA Corporation\Display\nvui.dll
@{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} /*NVIDIA Play On My TV Context Menu Extension*/%SystemRoot%\system32\nvshext.dll = %SystemRoot%\system32\nvshext.dll
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/E:\Program Files\WinRAR\rarext.dll = E:\Program Files\WinRAR\rarext.dll
@{A8065B9E-193F-4797-B62D-8F6321E7FCCB} /*Blueberry FlashBack Client*/(null) =
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
avast@{472083B0-C522-11CF-8763-00608CC02F24} = E:\Program Files\AVAST Software\Avast\ashShell.dll
BB FlashBack 2@{A8065B9E-193F-4797-B62D-8F6321E7FCCB} =
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = E:\Program Files\WinRAR\rarext.dll
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\NvCplDesktopContext@{3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} = %SystemRoot%\system32\nvshext.dll
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
avast@{472083B0-C522-11CF-8763-00608CC02F24} = E:\Program Files\AVAST Software\Avast\ashShell.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = E:\Program Files\WinRAR\rarext.dll
HKLM\Software\Classes\Folder\Shellex\ColumnHandlers@{F9DB5320-233E-11D1-9F84-707F02C10627} = E:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}E:\Program Files\Java\jre7\bin\ssv.dll = E:\Program Files\Java\jre7\bin\ssv.dll
@{DBC80044-A445-435b-BC74-9C25C1C588A9}E:\Program Files\Java\jre7\bin\jp2ssv.dll = E:\Program Files\Java\jre7\bin\jp2ssv.dll
HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://go.microsoft.com/fwlink/p/?LinkId=255141 = go.microsoft.com/fwlink/p/?LinkId=255141
@Start Pagehttp://go.microsoft.com/fwlink/p/?LinkId=255141 = go.microsoft.com/fwlink/p/?LinkId=255141
@Local PageE:\Windows\System32\blank.htm = E:\Windows\System32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://go.microsoft.com/fwlink/?LinkId=69157 = go.microsoft.com/fwlink/?LinkId=69157
@Local PageE:\Windows\system32\blank.htm = E:\Windows\system32\blank.htm
HKLM\Software\Classes\PROTOCOLS\Handler\skype4com@CLSID = E:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\ >>>
000000000001@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000002@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000003@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000004@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000005@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000006@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000007@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000008@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000009@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000010@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000011@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000012@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000013@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000014@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000015@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000016@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000017@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000018@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000019@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000020@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000021@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000022@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000023@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000024@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000025@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000026@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000027@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000028@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
000000000029@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000030@PackedCatalogItem = %SystemRoot%\system32\mswsock.dllp /*file not found*/
---- EOF - GMER 2.1 ----
Dopuna: 02 Jan 2014 20:40
magna86 ::Citat:ponovo ne mogu da koristim opciju "prikaci fajl" pa cu okaciti "rucno":
Sto ne mozes da koristis Prikaci fajl opciju?
Ceo kompjuter mi se odjednom sj%(@ skajp mi zakucava, ne moze da mi pokrene klip na youtube-u(nije do flesa 100%), itd, itd.. bukvalno odjednom! zato i sumnjam da imam virus
|