GMER 1.0.12.12244 - http://www.gmer.net Rootkit scan 2007-06-10 20:02:33 Windows 5.1.2600 ---- Kernel code sections - GMER 1.0.12 ---- .text ntoskrnl.exe!KeInitializeInterrupt + B79 804D4F8E 1 Byte [06] ? D:\WINDOWS\TEMP\mc21.tmp Nie można odnaleźć określonego pliku. ---- User code sections - GMER 1.0.12 ---- .text D:\WINDOWS\System32\wuauclt.exe[188] ntdll.dll!NtTerminateProcess 77F7F3C3 3 Bytes [FF, 25, 1E] .text D:\WINDOWS\System32\wuauclt.exe[188] ntdll.dll!NtTerminateProcess + 4 77F7F3C7 2 Bytes [0E, 5F] .text D:\WINDOWS\System32\wuauclt.exe[188] kernel32.dll!CreateProcessW 77E61B8A 6 Bytes JMP 5F0A0F5A .text D:\WINDOWS\System32\wuauclt.exe[188] kernel32.dll!CreateProcessA 77E61BB8 6 Bytes JMP 5F040F5A .text D:\WINDOWS\System32\wuauclt.exe[188] kernel32.dll!LoadLibraryExW 77E8049B 6 Bytes JMP 5F070F5A .text D:\WINDOWS\System32\wuauclt.exe[188] kernel32.dll!FreeLibrary + 11 77E80629 4 Bytes [0F, FA, 17, E7] .text D:\Program Files\Internet Explorer\iexplore.exe[320] ntdll.dll!NtTerminateProcess 77F7F3C3 3 Bytes [FF, 25, 1E] .text D:\Program Files\Internet Explorer\iexplore.exe[320] ntdll.dll!NtTerminateProcess + 4 77F7F3C7 2 Bytes [0E, 5F] .text D:\Program Files\Internet Explorer\iexplore.exe[320] kernel32.dll!CreateProcessW 77E61B8A 6 Bytes JMP 5F0A0F5A .text D:\Program Files\Internet Explorer\iexplore.exe[320] kernel32.dll!CreateProcessA 77E61BB8 6 Bytes JMP 5F040F5A .text D:\Program Files\Internet Explorer\iexplore.exe[320] kernel32.dll!LoadLibraryExW 77E8049B 6 Bytes JMP 5F070F5A .text D:\Program Files\Internet Explorer\iexplore.exe[320] kernel32.dll!FreeLibrary + 11 77E80629 4 Bytes [0F, FA, 17, E7] .text D:\WINDOWS\system32\csrss.exe[620] ntdll.dll!NtTerminateProcess 77F7F3C3 3 Bytes [FF, 25, 1E] .text D:\WINDOWS\system32\csrss.exe[620] ntdll.dll!NtTerminateProcess + 4 77F7F3C7 2 Bytes [0E, 5F] .text D:\WINDOWS\system32\csrss.exe[620] KERNEL32.dll!CreateProcessW 77E61B8A 6 Bytes JMP 5F0A0F5A .text D:\WINDOWS\system32\csrss.exe[620] KERNEL32.dll!CreateProcessA 77E61BB8 6 Bytes JMP 5F040F5A .text D:\WINDOWS\system32\csrss.exe[620] KERNEL32.dll!LoadLibraryExW 77E8049B 6 Bytes JMP 5F070F5A .text D:\WINDOWS\system32\winlogon.exe[644] ntdll.dll!NtTerminateProcess 77F7F3C3 3 Bytes [FF, 25, 1E] .text D:\WINDOWS\system32\winlogon.exe[644] ntdll.dll!NtTerminateProcess + 4 77F7F3C7 2 Bytes [0E, 5F] .text D:\WINDOWS\system32\winlogon.exe[644] kernel32.dll!CreateProcessW 77E61B8A 6 Bytes JMP 5F0A0F5A .text D:\WINDOWS\system32\winlogon.exe[644] kernel32.dll!CreateProcessA 77E61BB8 6 Bytes JMP 5F040F5A .text D:\WINDOWS\system32\winlogon.exe[644] kernel32.dll!LoadLibraryExW 77E8049B 6 Bytes JMP 5F070F5A .text D:\WINDOWS\system32\services.exe[688] ntdll.dll!NtTerminateProcess 77F7F3C3 3 Bytes [FF, 25, 1E] .text D:\WINDOWS\system32\services.exe[688] ntdll.dll!NtTerminateProcess + 4 77F7F3C7 2 Bytes [0E, 5F] .text D:\WINDOWS\system32\services.exe[688] kernel32.dll!CreateProcessW 77E61B8A 6 Bytes JMP 5F0A0F5A .text D:\WINDOWS\system32\services.exe[688] kernel32.dll!CreateProcessA 77E61BB8 6 Bytes JMP 5F040F5A .text D:\WINDOWS\system32\services.exe[688] kernel32.dll!LoadLibraryExW 77E8049B 6 Bytes JMP 5F070F5A .text D:\WINDOWS\system32\lsass.exe[700] ntdll.dll!NtTerminateProcess 77F7F3C3 3 Bytes [FF, 25, 1E] .text D:\WINDOWS\system32\lsass.exe[700] ntdll.dll!NtTerminateProcess + 4 77F7F3C7 2 Bytes [0E, 5F] .text D:\WINDOWS\system32\lsass.exe[700] kernel32.dll!CreateProcessW 77E61B8A 6 Bytes JMP 5F0A0F5A .text D:\WINDOWS\system32\lsass.exe[700] kernel32.dll!CreateProcessA 77E61BB8 6 Bytes JMP 5F040F5A .text D:\WINDOWS\system32\lsass.exe[700] kernel32.dll!LoadLibraryExW 77E8049B 6 Bytes JMP 5F070F5A .text D:\WINDOWS\system32\svchost.exe[868] ntdll.dll!NtTerminateProcess 77F7F3C3 3 Bytes [FF, 25, 1E] .text D:\WINDOWS\system32\svchost.exe[868] ntdll.dll!NtTerminateProcess + 4 77F7F3C7 2 Bytes [0E, 5F] .text D:\WINDOWS\system32\svchost.exe[868] kernel32.dll!CreateProcessW 77E61B8A 6 Bytes JMP 5F0A0F5A .text D:\WINDOWS\system32\svchost.exe[868] kernel32.dll!CreateProcessA 77E61BB8 6 Bytes JMP 5F040F5A .text D:\WINDOWS\system32\svchost.exe[868] kernel32.dll!LoadLibraryExW 77E8049B 6 Bytes JMP 5F070F5A .text D:\WINDOWS\system32\svchost.exe[884] ntdll.dll!NtTerminateProcess 77F7F3C3 3 Bytes [FF, 25, 1E] .text D:\WINDOWS\system32\svchost.exe[884] ntdll.dll!NtTerminateProcess + 4 77F7F3C7 2 Bytes [0E, 5F] .text D:\WINDOWS\system32\svchost.exe[884] kernel32.dll!CreateProcessW 77E61B8A 6 Bytes JMP 5F0A0F5A .text D:\WINDOWS\system32\svchost.exe[884] kernel32.dll!CreateProcessA 77E61BB8 6 Bytes JMP 5F040F5A .text D:\WINDOWS\system32\svchost.exe[884] kernel32.dll!LoadLibraryExW 77E8049B 6 Bytes JMP 5F070F5A .text D:\WINDOWS\system32\svchost.exe[976] ntdll.dll!NtTerminateProcess 77F7F3C3 3 Bytes [FF, 25, 1E] .text D:\WINDOWS\system32\svchost.exe[976] ntdll.dll!NtTerminateProcess + 4 77F7F3C7 2 Bytes [0E, 5F] .text D:\WINDOWS\system32\svchost.exe[976] kernel32.dll!CreateProcessW 77E61B8A 6 Bytes JMP 5F0A0F5A .text D:\WINDOWS\system32\svchost.exe[976] kernel32.dll!CreateProcessA 77E61BB8 6 Bytes JMP 5F040F5A .text D:\WINDOWS\system32\svchost.exe[976] kernel32.dll!LoadLibraryExW 77E8049B 6 Bytes JMP 5F070F5A .text D:\WINDOWS\system32\svchost.exe[1000] ntdll.dll!NtTerminateProcess 77F7F3C3 3 Bytes [FF, 25, 1E] .text D:\WINDOWS\system32\svchost.exe[1000] ntdll.dll!NtTerminateProcess + 4 77F7F3C7 2 Bytes [0E, 5F] .text D:\WINDOWS\system32\svchost.exe[1000] kernel32.dll!CreateProcessW 77E61B8A 6 Bytes JMP 5F0A0F5A .text D:\WINDOWS\system32\svchost.exe[1000] kernel32.dll!CreateProcessA 77E61BB8 6 Bytes JMP 5F040F5A .text D:\WINDOWS\system32\svchost.exe[1000] kernel32.dll!LoadLibraryExW 77E8049B 6 Bytes JMP 5F070F5A .text D:\WINDOWS\system32\spoolsv.exe[1092] ntdll.dll!NtTerminateProcess 77F7F3C3 3 Bytes [FF, 25, 1E] .text D:\WINDOWS\system32\spoolsv.exe[1092] ntdll.dll!NtTerminateProcess + 4 77F7F3C7 2 Bytes [0E, 5F] .text D:\WINDOWS\system32\spoolsv.exe[1092] kernel32.dll!CreateProcessW 77E61B8A 6 Bytes JMP 5F0A0F5A .text D:\WINDOWS\system32\spoolsv.exe[1092] kernel32.dll!CreateProcessA 77E61BB8 6 Bytes JMP 5F040F5A .text D:\WINDOWS\system32\spoolsv.exe[1092] kernel32.dll!LoadLibraryExW 77E8049B 6 Bytes JMP 5F070F5A .text D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1252] ntdll.dll!NtTerminateProcess 77F7F3C3 3 Bytes [FF, 25, 1E] .text D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1252] ntdll.dll!NtTerminateProcess + 4 77F7F3C7 2 Bytes [0E, 5F] .text D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1252] kernel32.dll!CreateProcessW 77E61B8A 6 Bytes JMP 5F0A0F5A .text D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1252] kernel32.dll!CreateProcessA 77E61BB8 6 Bytes JMP 5F040F5A .text D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE[1252] kernel32.dll!LoadLibraryExW 77E8049B 6 Bytes JMP 5F070F5A .text D:\Program Files\SiteAdvisor\6066\SAService.exe[1372] ntdll.dll!NtTerminateProcess 77F7F3C3 3 Bytes [FF, 25, 1E] .text D:\Program Files\SiteAdvisor\6066\SAService.exe[1372] ntdll.dll!NtTerminateProcess + 4 77F7F3C7 2 Bytes [0E, 5F] .text D:\Program Files\SiteAdvisor\6066\SAService.exe[1372] kernel32.dll!CreateProcessW 77E61B8A 6 Bytes JMP 5F0A0F5A .text D:\Program Files\SiteAdvisor\6066\SAService.exe[1372] kernel32.dll!CreateProcessA 77E61BB8 6 Bytes JMP 5F040F5A .text D:\Program Files\SiteAdvisor\6066\SAService.exe[1372] kernel32.dll!LoadLibraryExW 77E8049B 6 Bytes JMP 5F070F5A .text D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[1448] ntdll.dll!NtTerminateProcess 77F7F3C3 3 Bytes [FF, 25, 1E] .text D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[1448] ntdll.dll!NtTerminateProcess + 4 77F7F3C7 2 Bytes [0E, 5F] .text D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[1448] kernel32.dll!CreateProcessW 77E61B8A 6 Bytes JMP 5F0A0F5A .text D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[1448] kernel32.dll!CreateProcessA 77E61BB8 6 Bytes JMP 5F040F5A .text D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[1448] kernel32.dll!LoadLibraryExW 77E8049B 6 Bytes JMP 5F070F5A .text D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe[1448] kernel32.dll!FreeLibrary + 11 77E80629 4 Bytes [0F, FA, 17, E7] .text D:\Program Files\Internet Explorer\iexplore.exe[1656] ntdll.dll!NtTerminateProcess 77F7F3C3 3 Bytes [FF, 25, 1E] .text D:\Program Files\Internet Explorer\iexplore.exe[1656] ntdll.dll!NtTerminateProcess + 4 77F7F3C7 2 Bytes [0E, 5F] .text D:\Program Files\Internet Explorer\iexplore.exe[1656] kernel32.dll!CreateProcessW 77E61B8A 6 Bytes JMP 5F0A0F5A .text D:\Program Files\Internet Explorer\iexplore.exe[1656] kernel32.dll!CreateProcessA 77E61BB8 6 Bytes JMP 5F040F5A .text D:\Program Files\Internet Explorer\iexplore.exe[1656] kernel32.dll!LoadLibraryExW 77E8049B 6 Bytes JMP 5F070F5A .text D:\Program Files\Internet Explorer\iexplore.exe[1656] kernel32.dll!FreeLibrary + 11 77E80629 4 Bytes [0F, FA, 17, E7] .text D:\Documents and Settings\Kasia\Ustawienia lokalne\Temp\Katalog tymczasowy 4 dla gmer.zip\gmer.exe[1732] ntdll.dll!NtTerminateProcess 77F7F3C3 3 Bytes [FF, 25, 1E] .text D:\Documents and Settings\Kasia\Ustawienia lokalne\Temp\Katalog tymczasowy 4 dla gmer.zip\gmer.exe[1732] ntdll.dll!NtTerminateProcess + 4 77F7F3C7 2 Bytes [0E, 5F] .text D:\Documents and Settings\Kasia\Ustawienia lokalne\Temp\Katalog tymczasowy 4 dla gmer.zip\gmer.exe[1732] kernel32.dll!CreateProcessW 77E61B8A 6 Bytes JMP 5F0A0F5A .text D:\Documents and Settings\Kasia\Ustawienia lokalne\Temp\Katalog tymczasowy 4 dla gmer.zip\gmer.exe[1732] kernel32.dll!CreateProcessA 77E61BB8 6 Bytes JMP 5F040F5A .text D:\Documents and Settings\Kasia\Ustawienia lokalne\Temp\Katalog tymczasowy 4 dla gmer.zip\gmer.exe[1732] kernel32.dll!LoadLibraryExW 77E8049B 6 Bytes JMP 5F070F5A .text D:\Documents and Settings\Kasia\Ustawienia lokalne\Temp\Katalog tymczasowy 4 dla gmer.zip\gmer.exe[1732] kernel32.dll!FreeLibrary + 11 77E80629 4 Bytes [0F, FA, 17, E7] .text D:\WINDOWS\Explorer.EXE[1780] ntdll.dll!NtTerminateProcess 77F7F3C3 3 Bytes [FF, 25, 1E] .text D:\WINDOWS\Explorer.EXE[1780] ntdll.dll!NtTerminateProcess + 4 77F7F3C7 2 Bytes [0E, 5F] .text D:\WINDOWS\Explorer.EXE[1780] kernel32.dll!CreateProcessW 77E61B8A 6 Bytes JMP 5F0A0F5A .text D:\WINDOWS\Explorer.EXE[1780] kernel32.dll!CreateProcessA 77E61BB8 6 Bytes JMP 5F040F5A .text D:\WINDOWS\Explorer.EXE[1780] kernel32.dll!LoadLibraryExW 77E8049B 6 Bytes JMP 5F070F5A .text D:\WINDOWS\Explorer.EXE[1780] kernel32.dll!FreeLibrary + 11 77E80629 4 Bytes [0F, FA, 17, E7] .text D:\Program Files\SiteAdvisor\6066\SiteAdv.exe[1916] ntdll.dll!NtTerminateProcess 77F7F3C3 3 Bytes [FF, 25, 1E] .text D:\Program Files\SiteAdvisor\6066\SiteAdv.exe[1916] ntdll.dll!NtTerminateProcess + 4 77F7F3C7 2 Bytes [0E, 5F] .text D:\Program Files\SiteAdvisor\6066\SiteAdv.exe[1916] kernel32.dll!CreateProcessW 77E61B8A 6 Bytes JMP 5F0A0F5A .text D:\Program Files\SiteAdvisor\6066\SiteAdv.exe[1916] kernel32.dll!CreateProcessA 77E61BB8 6 Bytes JMP 5F040F5A .text D:\Program Files\SiteAdvisor\6066\SiteAdv.exe[1916] kernel32.dll!LoadLibraryExW 77E8049B 6 Bytes JMP 5F070F5A .text D:\Program Files\SiteAdvisor\6066\SiteAdv.exe[1916] kernel32.dll!FreeLibrary + 11 77E80629 4 Bytes [0F, FA, 17, E7] .text D:\Program Files\Spyware Doctor wer2.0\swdoctor.exe[1944] kernel32.dll!LoadLibraryExW 77E8049B 6 Bytes JMP 5F070F5A .text D:\Program Files\Spyware Doctor wer2.0\swdoctor.exe[1944] kernel32.dll!FreeLibrary + 11 77E80629 4 Bytes [0F, FA, 17, E7] .text D:\Program Files\Spyware Doctor wer2.0\swdoctor.exe[1944] USER32.dll!DispatchMessageA 77D341F2 6 Bytes JMP 5F040F5A .text D:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe[1952] ntdll.dll!NtTerminateProcess 77F7F3C3 3 Bytes [FF, 25, 1E] .text D:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe[1952] ntdll.dll!NtTerminateProcess + 4 77F7F3C7 2 Bytes [0E, 5F] .text D:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe[1952] kernel32.dll!CreateProcessW 77E61B8A 6 Bytes JMP 5F0A0F5A .text D:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe[1952] kernel32.dll!CreateProcessA 77E61BB8 6 Bytes JMP 5F040F5A .text D:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe[1952] kernel32.dll!LoadLibraryExW 77E8049B 6 Bytes JMP 5F070F5A .text D:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe[1952] kernel32.dll!FreeLibrary + 11 77E80629 4 Bytes [0F, FA, 17, E7] .text D:\Program Files\Corel\Graphics9\Register\Remind32.exe[1960] ntdll.dll!NtTerminateProcess 77F7F3C3 3 Bytes [FF, 25, 1E] .text D:\Program Files\Corel\Graphics9\Register\Remind32.exe[1960] ntdll.dll!NtTerminateProcess + 4 77F7F3C7 2 Bytes [0E, 5F] .text D:\Program Files\Corel\Graphics9\Register\Remind32.exe[1960] kernel32.dll!CreateProcessW 77E61B8A 6 Bytes JMP 5F0A0F5A .text D:\Program Files\Corel\Graphics9\Register\Remind32.exe[1960] kernel32.dll!CreateProcessA 77E61BB8 6 Bytes JMP 5F040F5A .text D:\Program Files\Corel\Graphics9\Register\Remind32.exe[1960] kernel32.dll!LoadLibraryExW 77E8049B 6 Bytes JMP 5F070F5A .text D:\Program Files\Corel\Graphics9\Register\Remind32.exe[1960] kernel32.dll!FreeLibrary + 11 77E80629 4 Bytes [0F, FA, 17, E7] ---- Registry - GMER 1.0.12 ---- Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{29B1E8E2-B1D0-4CDC-2C39-F170004CF4A4}@dbdijhljddbcfdhbndolcnclameahcaegchgenjj 0x6A 0x61 0x70 0x65 … Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{29B1E8E2-B1D0-4CDC-2C39-F170004CF4A4}@cbnhhlblojcpagbameglbdklmpiamnabfiagce 0x6A 0x61 0x70 0x65 … Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{29B1E8E2-B1D0-4CDC-2C39-F170004CF4A4}@abpcjlbjleblkofiapgndmnopcamggbpem 0x61 0x61 0x00 0x00 Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{29B1E8E2-B1D0-4CDC-2C39-F170004CF4A4}@mamcendncnlodhccdogmffefpb 0x61 0x61 0x00 0x00 Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{3560621D-8A84-8BC6-ECD2-E1DC9A56FCCA}@bbbkodamflpapiloojbngcilffjmlckkmhkg 0x6A 0x61 0x6E 0x61 … Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{3560621D-8A84-8BC6-ECD2-E1DC9A56FCCA}@abhnedbbjhklkkcjbjmdlcjnlnghppelhj 0x6A 0x61 0x6E 0x61 … Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{3560621D-8A84-8BC6-ECD2-E1DC9A56FCCA}@abnkkafmpihcgeibnlfadnidciphabbpje 0x61 0x61 0x00 0x00 Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{3560621D-8A84-8BC6-ECD2-E1DC9A56FCCA}@maoknanflkimlfckibgpbchokf 0x61 0x61 0x00 0x00 Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{3560621D-8A84-8BC6-ECD2-E1DC9A56FCCA}@iabkodamflpapilooj 0x61 0x61 0x00 0x01 Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{3560621D-8A84-8BC6-ECD2-E1DC9A56FCCA}@hahnedbbjhklkkcj 0x61 0x61 0x00 0x01 Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{3560621D-8A84-8BC6-ECD2-E1DC9A56FCCA}@iankkhgpmoonkbgccf 0x61 0x61 0x00 0x01 Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{3560621D-8A84-8BC6-ECD2-E1DC9A56FCCA}@bbbkodamflpapiloojbngcilffjmgbfofkbf 0x6A 0x61 0x6E 0x61 … Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{3560621D-8A84-8BC6-ECD2-E1DC9A56FCCA}@abhnedbbjhklkkcjbjmdlcjnlnpjedpima 0x6A 0x61 0x6E 0x61 … Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{8EC58BB7-F5A9-1797-E8F3-9114A9B45A40}@dbcgnijoampoldcfddfpmjibgaebaongmhkcopbb 0x6A 0x61 0x67 0x64 … Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{8EC58BB7-F5A9-1797-E8F3-9114A9B45A40}@cbifhflimenbflbcalcammhcampihoblfcjeon 0x6A 0x61 0x67 0x64 … Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{8EC58BB7-F5A9-1797-E8F3-9114A9B45A40}@iacgnijoampoldcfdd 0x61 0x61 0x00 0x00 Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{8EC58BB7-F5A9-1797-E8F3-9114A9B45A40}@haifhflimenbflbc 0x61 0x61 0x00 0x00 Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{8EC58BB7-F5A9-1797-E8F3-9114A9B45A40}@iagjffmcicjcpefhcg 0x61 0x61 0x00 0x00 Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{8EC58BB7-F5A9-1797-E8F3-9114A9B45A40}@abgjfgfggdbcgomnafomimjbcgddncffch 0x61 0x61 0x00 0x00 Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{8EC58BB7-F5A9-1797-E8F3-9114A9B45A40}@mahjacajjiocibpbhbnjbhbbhk 0x61 0x61 0x00 0x00 Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{EBB71504-5E49-CEFD-6213-ED87B1DCF6F6}@cbfidogciigjcdbignhnkboocjjljaflpchcam 0x6A 0x61 0x6A 0x64 … Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{EBB71504-5E49-CEFD-6213-ED87B1DCF6F6}@bbhhfofodhkanbgploepkaffhdbijibpalfd 0x6A 0x61 0x6A 0x64 … Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{EBB71504-5E49-CEFD-6213-ED87B1DCF6F6}@abjjdoklgkhioeehhjdmffmoadaeafnkfk 0x61 0x61 0x00 0x00 Reg \Registry\USER\S-1-5-21-507921405-1383384898-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved{EBB71504-5E49-CEFD-6213-ED87B1DCF6F6}@maijgoccbfpcbkfpofkbchphpi 0x61 0x61 0x00 0x00 ---- EOF - GMER 1.0.12 ----