GMER 1.0.14.14536 -
http://www.gmer.net
Rootkit scan 2008-12-13 19:55:23
Windows 5.1.2600 Service Pack 3
---- Devices - GMER 1.0.14 ----
AttachedDevice \FileSystem\Ntfs \Ntfs sisidex.sys (SISIDEX Driver/Windows (R) 2000 DDK provider)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- EOF - GMER 1.0.14 ----
GMER 1.0.14.14536 -
http://www.gmer.net
Rootkit scan 2008-12-13 20:16:09
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.14 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xBAD6F576]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xBAD6F432]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xBAD6F910]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xBAD6F00A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xBAD6F50C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xBAD6EF4A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xBAD6EFAE]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xBAD6F62C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xBAD6F5EC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xBAD6F76C]
---- Kernel code sections - GMER 1.0.14 ----
? C:\WINDOWS\system32\Drivers\PROCEXP90.SYS The system cannot find the file specified. !
? C:\ComboFix\catchme.sys The system cannot find the path specified. !
---- User code sections - GMER 1.0.14 ----
.text C:\Program Files\Mozilla Firefox\firefox.exe[240] USER32.dll!SetWindowPos 7E4299F3 5 Bytes JMP 01611040 C:\Program Files\Stardock\CursorFX\CurXP0.dll (CursorFX support DLL/ )
.text C:\Program Files\Mozilla Firefox\firefox.exe[240] USER32.dll!DrawIconEx 7E42CB84 5 Bytes JMP 016111E0 C:\Program Files\Stardock\CursorFX\CurXP0.dll (CursorFX support DLL/ )
.text C:\Program Files\Mozilla Firefox\firefox.exe[240] USER32.dll!GetIconInfo 7E42D427 5 Bytes JMP 01611120 C:\Program Files\Stardock\CursorFX\CurXP0.dll (CursorFX support DLL/ )
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[528] USER32.dll!SetWindowPos 7E4299F3 5 Bytes JMP 015F1040 C:\Program Files\Stardock\CursorFX\CurXP0.dll (CursorFX support DLL/ )
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[528] USER32.dll!DrawIconEx 7E42CB84 5 Bytes JMP 015F11E0 C:\Program Files\Stardock\CursorFX\CurXP0.dll (CursorFX support DLL/ )
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[528] USER32.dll!GetIconInfo 7E42D427 5 Bytes JMP 015F1120 C:\Program Files\Stardock\CursorFX\CurXP0.dll (CursorFX support DLL/ )
.text C:\Program Files\Steam\Steam.exe[988] USER32.dll!SetWindowPos 7E4299F3 5 Bytes JMP 01291040 C:\Program Files\Stardock\CursorFX\CurXP0.dll (CursorFX support DLL/ )
.text C:\Program Files\Steam\Steam.exe[988] USER32.dll!DrawIconEx 7E42CB84 5 Bytes JMP 012911E0 C:\Program Files\Stardock\CursorFX\CurXP0.dll (CursorFX support DLL/ )
.text C:\Program Files\Steam\Steam.exe[988] USER32.dll!GetIconInfo 7E42D427 5 Bytes JMP 01291120 C:\Program Files\Stardock\CursorFX\CurXP0.dll (CursorFX support DLL/ )
.text C:\WINDOWS\explorer.exe[1756] USER32.dll!SetWindowPos 7E4299F3 5 Bytes JMP 03FD1040 C:\Program Files\Stardock\CursorFX\CurXP0.dll (CursorFX support DLL/ )
.text C:\WINDOWS\explorer.exe[1756] USER32.dll!DrawIconEx 7E42CB84 5 Bytes JMP 03FD11E0 C:\Program Files\Stardock\CursorFX\CurXP0.dll (CursorFX support DLL/ )
.text C:\WINDOWS\explorer.exe[1756] USER32.dll!GetIconInfo 7E42D427 5 Bytes JMP 03FD1120 C:\Program Files\Stardock\CursorFX\CurXP0.dll (CursorFX support DLL/ )
.text C:\Documents and Settings\ERIKA VASEK\Desktop\gmer.exe[1984] USER32.DLL!SetWindowPos 7E4299F3 5 Bytes JMP 10001040 C:\Program Files\Stardock\CursorFX\CurXP0.dll (CursorFX support DLL/ )
.text C:\Documents and Settings\ERIKA VASEK\Desktop\gmer.exe[1984] USER32.DLL!DrawIconEx 7E42CB84 5 Bytes JMP 100011E0 C:\Program Files\Stardock\CursorFX\CurXP0.dll (CursorFX support DLL/ )
.text C:\Documents and Settings\ERIKA VASEK\Desktop\gmer.exe[1984] USER32.DLL!GetIconInfo 7E42D427 5 Bytes JMP 10001120 C:\Program Files\Stardock\CursorFX\CurXP0.dll (CursorFX support DLL/ )
---- Kernel IAT/EAT - GMER 1.0.14 ----
IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisCloseAdapter] [F7B473FC] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter] [F7B47458] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisDeregisterProtocol] [F7B476B2] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol] [F7B47684] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [F7B47684] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [F7B47458] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [F7B473FC] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [F7B476B2] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [F7B476B2] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [F7B47684] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [F7B47458] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [F7B473FC] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [F7B47684] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [F7B476B2] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [F7B473FC] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [F7B47458] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [F7B473FC] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [F7B47458] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [F7B47684] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [F7B476B2] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [F7B47684] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [F7B47458] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [F7B473FC] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisCloseAdapter] [F7B473FC] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisOpenAdapter] [F7B47458] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisDeregisterProtocol] [F7B476B2] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\system32\DRIVERS\arp1394.sys[NDIS.SYS!NdisRegisterProtocol] [F7B47684] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [F7B47684] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [F7B476B2] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [F7B473FC] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [F7B47458] NDISRD.sys (NDISRD helper driver/NT Kernel Resources)
---- User IAT/EAT - GMER 1.0.14 ----
IAT C:\WINDOWS\system32\services.exe[616] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003D0002
IAT C:\WINDOWS\system32\services.exe[616] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003D0000
---- Devices - GMER 1.0.14 ----
AttachedDevice \FileSystem\Ntfs \Ntfs sisidex.sys (SISIDEX Driver/Windows (R) 2000 DDK provider)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device ACPI.sys (ACPI Driver for NT/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- Registry - GMER 1.0.14 ----
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Encyklopedie Přírody 2.0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Encyklopedie Přírody 2.0@SlowInfoCache 0x28 0x02 0x00 0x00 ...
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Encyklopedie Přírody 2.0@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Encyklopedie Přírody 2.0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Encyklopedie Přírody 2.0@UninstallString C:\WINDOWS\IsUn0405.exe -f"C:\Program Files\BSP Multimedia\Encyklopedie Prirody 2.0\Uninst.isu"
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Encyklopedie Přírody 2.0@DisplayName Encyklopedie P??rody 2.0
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xC8 0x28 0x51 0xAF ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x6A 0x9C 0xD6 0x61 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0x25 0xDA 0xEC 0x7E ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x3E 0x1E 0x9E 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xCD 0x44 0xCD 0xB9 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xDF 0x20 0x58 0x62 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0xFB 0xA7 0x78 0xE6 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x83 0x6C 0x56 0x8B ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xF6 0x0F 0x4E 0x58 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0xB1 0xCD 0x45 0x5A ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0x2A 0xB7 0xCC 0xB5 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0x6C 0x43 0x2D 0x1E ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\BSP Multimedia\Encyklopedie Přírody 2.0
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\BSP Multimedia\Encyklopedie Přírody 2.0@Order 0x08 0x00 0x00 0x00 ...
---- Files - GMER 1.0.14 ----
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\housefloor2on.jpg 7260 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\sbbottom2.jpg 6857 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\bar.jpg 5152 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\bar2.jpg 5111 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\FamilyGFX 0 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\FamilyGFX\family1_face.jpg 2789 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\FamilyGFX\family1_full.jpg 9749 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\FamilyGFX\faminfo_1_-239311147 0 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\familyhome.html 20344 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\familymember1.html 11746 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\family_a.jpg 6982 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\family_b.jpg 6507 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\family_c.jpg 6969 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\house.html 12090 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\housefloor1off.jpg 6662 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\housefloor1on.jpg 6785 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\housefloor2dis.jpg 6672 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\housefloor2off.jpg 7290 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\houseroofoff.jpg 8302 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\houseroofon.jpg 8645 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\house_a.jpg 7189 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\house_b.jpg 6794 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\house_c.jpg 6940 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\logo.jpg 11265 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\logo2.jpg 10950 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\photo_a.jpg 7263 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\photo_b.jpg 6828 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\photo_c.jpg 6750 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\sbbottom.jpg 7146 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\scrapbook1.html 10921 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\scrapnav_icon.jpg 13249 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\scrapnav_next_a.jpg 5514 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\scrapnav_next_b.jpg 5527 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\scrapnav_prev_a.jpg 5538 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\scrapnav_prev_b.jpg 5520 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\scrappatt.jpg 6139 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\StockGFX 0 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\thesims.css 2902 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\vbar.jpg 5453 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\vbar2.jpg 5366 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\.......................\yellowback.jpg 5393 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\family_c.jpg 6969 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\houseroofon.jpg 8645 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\bar.jpg 5152 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\bar2.jpg 5111 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX 0 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX\family5_face.jpg 2577 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX\family1_face.jpg 2795 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX\family1_full.jpg 9680 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX\family2_face.jpg 2529 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX\family2_full.jpg 9664 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX\family3_face.jpg 2684 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX\family3_full.jpg 9893 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX\family4_face.jpg 2758 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX\family4_full.jpg 9934 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX\family5_full.jpg 9849 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX\family6_face.jpg 2635 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX\family6_full.jpg 9887 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX\family7_face.jpg 2486 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX\family7_full.jpg 7307 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX\faminfo_1_805811108 0 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX\faminfo_2_-811403648 0 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX\faminfo_3_1727120840 0 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX\faminfo_4_39051550 0 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX\faminfo_5_-595005520 0 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX\faminfo_6_-1048667347 0 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\FamilyGFX\faminfo_7_-1795165458 0 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\familyhome.html 20332 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\familymember1.html 11741 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\familymember2.html 11740 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\familymember3.html 11741 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\familymember4.html 11731 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\familymember5.html 11742 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\familymember6.html 11740 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\familymember7.html 11713 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\family_a.jpg 6982 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\family_b.jpg 6507 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\house.html 12072 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\housefloor1off.jpg 6662 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\housefloor1on.jpg 6785 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\housefloor2dis.jpg 6672 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\housefloor2off.jpg 7290 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\housefloor2on.jpg 7260 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\houseroofoff.jpg 8302 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\house_a.jpg 7189 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\house_b.jpg 6794 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\house_c.jpg 6940 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\logo.jpg 11265 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\logo2.jpg 10950 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\photo_a.jpg 7263 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\photo_b.jpg 6828 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\photo_c.jpg 6750 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\sbbottom.jpg 7146 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\sbbottom2.jpg 6857 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\scrapbook1.html 10885 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\scrapnav_icon.jpg 13249 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\scrapnav_next_a.jpg 5514 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\scrapnav_next_b.jpg 5527 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\scrapnav_prev_a.jpg 5538 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\scrapnav_prev_b.jpg 5520 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\scrappatt.jpg 6139 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\StockGFX 0 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\thesims.css 2902 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\vbar.jpg 5453 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\vbar2.jpg 5366 bytes
File C:\Program Files\Maxis\The Sims\UserData\Web Pages\ABC..\yellowback.jpg 5393 bytes
---- EOF - GMER 1.0.14 ----