ked som zapol gmer tak mi to uložilo prazdny log ale ked som scanoval tak toto
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-01-15 15:13:54
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 Hitachi_HTS541680J9SA00 rev.SB2OC70P
Running: gmer.exe; Driver: C:\DOCUME~1\Michal\LOCALS~1\Temp\pxtorpow.sys
---- User code sections - GMER 1.0.15 ----
.text C:\Documents and Settings\Michal\Application Data\1.exe[520] ntdll.dll!NtEnumerateValueKey 7C90D2D0 5 Bytes JMP 00986390
.text C:\Documents and Settings\Michal\Application Data\1.exe[520] ntdll.dll!NtQueryDirectoryFile 7C90D750 5 Bytes JMP 00986640
.text C:\Documents and Settings\Michal\Application Data\1.exe[520] ntdll.dll!NtResumeThread 7C90DB20 5 Bytes JMP 009853D0
.text C:\Documents and Settings\Michal\Application Data\1.exe[520] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00985300
.text C:\Documents and Settings\Michal\Application Data\1.exe[520] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 009811C0
.text C:\Documents and Settings\Michal\Application Data\1.exe[520] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00981290
.text C:\Documents and Settings\Michal\Application Data\1.exe[520] kernel32.dll!MoveFileW 7C821249 5 Bytes JMP 00982570
.text C:\Documents and Settings\Michal\Application Data\1.exe[520] kernel32.dll!CopyFileA 7C8286D6 5 Bytes JMP 00981000
.text C:\Documents and Settings\Michal\Application Data\1.exe[520] kernel32.dll!CopyFileW 7C82F863 5 Bytes JMP 009810A0
.text C:\Documents and Settings\Michal\Application Data\1.exe[520] kernel32.dll!MoveFileA 7C835EA7 5 Bytes JMP 00982510
.text C:\Documents and Settings\Michal\Application Data\1.exe[520] wininet.dll!HttpSendRequestA 771C60A1 5 Bytes JMP 009820A0
.text C:\Documents and Settings\Michal\Application Data\1.exe[520] wininet.dll!InternetWriteFile 771F8BB9 5 Bytes JMP 009823A0
.text C:\Documents and Settings\Michal\Application Data\1.exe[520] wininet.dll!HttpSendRequestW 77212EBC 5 Bytes JMP 00982160
.text C:\Documents and Settings\Michal\Application Data\1.exe[520] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 00981D10
.text C:\Documents and Settings\Michal\Application Data\1.exe[520] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00987250
.text C:\WINDOWS\System32\alg.exe[604] ntdll.dll!NtEnumerateValueKey 7C90D2D0 5 Bytes JMP 00AF6390
.text C:\WINDOWS\System32\alg.exe[604] ntdll.dll!NtQueryDirectoryFile 7C90D750 5 Bytes JMP 00AF6640
.text C:\WINDOWS\System32\alg.exe[604] ntdll.dll!NtResumeThread 7C90DB20 5 Bytes JMP 00AF53D0
.text C:\WINDOWS\System32\alg.exe[604] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00AF5300
.text C:\WINDOWS\System32\alg.exe[604] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00AF11C0
.text C:\WINDOWS\System32\alg.exe[604] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00AF1290
.text C:\WINDOWS\System32\alg.exe[604] kernel32.dll!MoveFileW 7C821249 5 Bytes JMP 00AF2570
.text C:\WINDOWS\System32\alg.exe[604] kernel32.dll!CopyFileA 7C8286D6 5 Bytes JMP 00AF1000
.text C:\WINDOWS\System32\alg.exe[604] kernel32.dll!CopyFileW 7C82F863 5 Bytes JMP 00AF10A0
.text C:\WINDOWS\System32\alg.exe[604] kernel32.dll!MoveFileA 7C835EA7 5 Bytes JMP 00AF2510
.text C:\WINDOWS\System32\alg.exe[604] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 00AF1D10
.text C:\WINDOWS\System32\alg.exe[604] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00AF7250
.text C:\WINDOWS\System32\alg.exe[604] WININET.dll!HttpSendRequestA 771C60A1 5 Bytes JMP 00AF20A0
.text C:\WINDOWS\System32\alg.exe[604] WININET.dll!InternetWriteFile 771F8BB9 5 Bytes JMP 00AF23A0
.text C:\WINDOWS\System32\alg.exe[604] WININET.dll!HttpSendRequestW 77212EBC 5 Bytes JMP 00AF2160
.text C:\WINDOWS\system32\csrss.exe[724] ntdll.dll!NtEnumerateValueKey 7C90D2D0 5 Bytes JMP 01336390
.text C:\WINDOWS\system32\csrss.exe[724] ntdll.dll!NtQueryDirectoryFile 7C90D750 5 Bytes JMP 01336640
.text C:\WINDOWS\system32\csrss.exe[724] ntdll.dll!NtResumeThread 7C90DB20 5 Bytes JMP 013353D0
.text C:\WINDOWS\system32\csrss.exe[724] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 01335300
.text C:\WINDOWS\system32\csrss.exe[724] KERNEL32.dll!CreateFileA 7C801A28 5 Bytes JMP 013311C0
.text C:\WINDOWS\system32\csrss.exe[724] KERNEL32.dll!CreateFileW 7C8107F0 5 Bytes JMP 01331290
.text C:\WINDOWS\system32\csrss.exe[724] KERNEL32.dll!MoveFileW 7C821249 5 Bytes JMP 01332570
.text C:\WINDOWS\system32\csrss.exe[724] KERNEL32.dll!CopyFileA 7C8286D6 5 Bytes JMP 01331000
.text C:\WINDOWS\system32\csrss.exe[724] KERNEL32.dll!CopyFileW 7C82F863 5 Bytes JMP 013310A0
.text C:\WINDOWS\system32\csrss.exe[724] KERNEL32.dll!MoveFileA 7C835EA7 5 Bytes JMP 01332510
.text C:\WINDOWS\system32\csrss.exe[724] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 01331D10
.text C:\WINDOWS\system32\csrss.exe[724] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01337250
.text C:\WINDOWS\system32\csrss.exe[724] WININET.dll!HttpSendRequestA 771C60A1 5 Bytes JMP 013320A0
.text C:\WINDOWS\system32\csrss.exe[724] WININET.dll!InternetWriteFile 771F8BB9 5 Bytes JMP 013323A0
.text C:\WINDOWS\system32\csrss.exe[724] WININET.dll!HttpSendRequestW 77212EBC 5 Bytes JMP 01332160
.text C:\WINDOWS\system32\winlogon.exe[752] ntdll.dll!NtEnumerateValueKey 7C90D2D0 5 Bytes JMP 01516390
.text C:\WINDOWS\system32\winlogon.exe[752] ntdll.dll!NtQueryDirectoryFile 7C90D750 5 Bytes JMP 01516640
.text C:\WINDOWS\system32\winlogon.exe[752] ntdll.dll!NtResumeThread 7C90DB20 5 Bytes JMP 015153D0
.text C:\WINDOWS\system32\winlogon.exe[752] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 01515300
.text C:\WINDOWS\system32\winlogon.exe[752] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 015111C0
.text C:\WINDOWS\system32\winlogon.exe[752] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 01511290
.text C:\WINDOWS\system32\winlogon.exe[752] kernel32.dll!MoveFileW 7C821249 5 Bytes JMP 01512570
.text C:\WINDOWS\system32\winlogon.exe[752] kernel32.dll!CopyFileA 7C8286D6 5 Bytes JMP 01511000
.text C:\WINDOWS\system32\winlogon.exe[752] kernel32.dll!CopyFileW 7C82F863 5 Bytes JMP 015110A0
.text C:\WINDOWS\system32\winlogon.exe[752] kernel32.dll!MoveFileA 7C835EA7 5 Bytes JMP 01512510
.text C:\WINDOWS\system32\winlogon.exe[752] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 01511D10
.text C:\WINDOWS\system32\winlogon.exe[752] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01517250
.text C:\WINDOWS\system32\winlogon.exe[752] WININET.dll!HttpSendRequestA 771C60A1 5 Bytes JMP 015120A0
.text C:\WINDOWS\system32\winlogon.exe[752] WININET.dll!InternetWriteFile 771F8BB9 5 Bytes JMP 015123A0
.text C:\WINDOWS\system32\winlogon.exe[752] WININET.dll!HttpSendRequestW 77212EBC 5 Bytes JMP 01512160
.text C:\WINDOWS\system32\services.exe[796] ntdll.dll!NtEnumerateValueKey 7C90D2D0 5 Bytes JMP 00D96390
.text C:\WINDOWS\system32\services.exe[796] ntdll.dll!NtQueryDirectoryFile 7C90D750 5 Bytes JMP 00D96640
.text C:\WINDOWS\system32\services.exe[796] ntdll.dll!NtResumeThread 7C90DB20 5 Bytes JMP 00D953D0
.text C:\WINDOWS\system32\services.exe[796] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00D95300
.text C:\WINDOWS\system32\services.exe[796] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00D911C0
.text C:\WINDOWS\system32\services.exe[796] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00D91290
.text C:\WINDOWS\system32\services.exe[796] kernel32.dll!MoveFileW 7C821249 5 Bytes JMP 00D92570
.text C:\WINDOWS\system32\services.exe[796] kernel32.dll!CopyFileA 7C8286D6 5 Bytes JMP 00D91000
.text C:\WINDOWS\system32\services.exe[796] kernel32.dll!CopyFileW 7C82F863 5 Bytes JMP 00D910A0
.text C:\WINDOWS\system32\services.exe[796] kernel32.dll!MoveFileA 7C835EA7 5 Bytes JMP 00D92510
.text C:\WINDOWS\system32\services.exe[796] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 00D91D10
.text C:\WINDOWS\system32\services.exe[796] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00D97250
.text C:\WINDOWS\system32\services.exe[796] WININET.dll!HttpSendRequestA 771C60A1 5 Bytes JMP 00D920A0
.text C:\WINDOWS\system32\services.exe[796] WININET.dll!InternetWriteFile 771F8BB9 5 Bytes JMP 00D923A0
.text C:\WINDOWS\system32\services.exe[796] WININET.dll!HttpSendRequestW 77212EBC 5 Bytes JMP 00D92160
.text C:\WINDOWS\system32\ctfmon.exe[852] ntdll.dll!NtEnumerateValueKey 7C90D2D0 5 Bytes JMP 00A66390
.text C:\WINDOWS\system32\ctfmon.exe[852] ntdll.dll!NtQueryDirectoryFile 7C90D750 5 Bytes JMP 00A66640
.text C:\WINDOWS\system32\ctfmon.exe[852] ntdll.dll!NtResumeThread 7C90DB20 5 Bytes JMP 00A653D0
.text C:\WINDOWS\system32\ctfmon.exe[852] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00A65300
.text C:\WINDOWS\system32\ctfmon.exe[852] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00A611C0
.text C:\WINDOWS\system32\ctfmon.exe[852] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00A61290
.text C:\WINDOWS\system32\ctfmon.exe[852] kernel32.dll!MoveFileW 7C821249 5 Bytes JMP 00A62570
.text C:\WINDOWS\system32\ctfmon.exe[852] kernel32.dll!CopyFileA 7C8286D6 5 Bytes JMP 00A61000
.text C:\WINDOWS\system32\ctfmon.exe[852] kernel32.dll!CopyFileW 7C82F863 5 Bytes JMP 00A610A0
.text C:\WINDOWS\system32\ctfmon.exe[852] kernel32.dll!MoveFileA 7C835EA7 5 Bytes JMP 00A62510
.text C:\WINDOWS\system32\ctfmon.exe[852] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 00A61D10
.text C:\WINDOWS\system32\ctfmon.exe[852] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00A67250
.text C:\WINDOWS\system32\ctfmon.exe[852] WININET.dll!HttpSendRequestA 771C60A1 5 Bytes JMP 00A620A0
.text C:\WINDOWS\system32\ctfmon.exe[852] WININET.dll!InternetWriteFile 771F8BB9 5 Bytes JMP 00A623A0
.text C:\WINDOWS\system32\ctfmon.exe[852] WININET.dll!HttpSendRequestW 77212EBC 5 Bytes JMP 00A62160
.text C:\WINDOWS\system32\Ati2evxx.exe[960] ntdll.dll!NtEnumerateValueKey 7C90D2D0 5 Bytes JMP 00EF6390
.text C:\WINDOWS\system32\Ati2evxx.exe[960] ntdll.dll!NtQueryDirectoryFile 7C90D750 5 Bytes JMP 00EF6640
.text C:\WINDOWS\system32\Ati2evxx.exe[960] ntdll.dll!NtResumeThread 7C90DB20 5 Bytes JMP 00EF53D0
.text C:\WINDOWS\system32\Ati2evxx.exe[960] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00EF5300
.text C:\WINDOWS\system32\Ati2evxx.exe[960] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00EF11C0
.text C:\WINDOWS\system32\Ati2evxx.exe[960] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00EF1290
.text C:\WINDOWS\system32\Ati2evxx.exe[960] kernel32.dll!MoveFileW 7C821249 5 Bytes JMP 00EF2570
.text C:\WINDOWS\system32\Ati2evxx.exe[960] kernel32.dll!CopyFileA 7C8286D6 5 Bytes JMP 00EF1000
.text C:\WINDOWS\system32\Ati2evxx.exe[960] kernel32.dll!CopyFileW 7C82F863 5 Bytes JMP 00EF10A0
.text C:\WINDOWS\system32\Ati2evxx.exe[960] kernel32.dll!MoveFileA 7C835EA7 5 Bytes JMP 00EF2510
.text C:\WINDOWS\system32\Ati2evxx.exe[960] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 00EF1D10
.text C:\WINDOWS\system32\Ati2evxx.exe[960] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00EF7250
.text C:\WINDOWS\system32\Ati2evxx.exe[960] WININET.dll!HttpSendRequestA 771C60A1 5 Bytes JMP 00EF20A0
.text C:\WINDOWS\system32\Ati2evxx.exe[960] WININET.dll!InternetWriteFile 771F8BB9 5 Bytes JMP 00EF23A0
.text C:\WINDOWS\system32\Ati2evxx.exe[960] WININET.dll!HttpSendRequestW 77212EBC 5 Bytes JMP 00EF2160
.text C:\WINDOWS\system32\svchost.exe[972] ntdll.dll!NtEnumerateValueKey 7C90D2D0 5 Bytes JMP 00F56390
.text C:\WINDOWS\system32\svchost.exe[972] ntdll.dll!NtQueryDirectoryFile 7C90D750 5 Bytes JMP 00F56640
.text C:\WINDOWS\system32\svchost.exe[972] ntdll.dll!NtResumeThread 7C90DB20 5 Bytes JMP 00F553D0
.text C:\WINDOWS\system32\svchost.exe[972] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00F55300
.text C:\WINDOWS\system32\svchost.exe[972] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00F511C0
.text C:\WINDOWS\system32\svchost.exe[972] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00F51290
.text C:\WINDOWS\system32\svchost.exe[972] kernel32.dll!MoveFileW 7C821249 5 Bytes JMP 00F52570
.text C:\WINDOWS\system32\svchost.exe[972] kernel32.dll!CopyFileA 7C8286D6 5 Bytes JMP 00F51000
.text C:\WINDOWS\system32\svchost.exe[972] kernel32.dll!CopyFileW 7C82F863 5 Bytes JMP 00F510A0
.text C:\WINDOWS\system32\svchost.exe[972] kernel32.dll!MoveFileA 7C835EA7 5 Bytes JMP 00F52510
.text C:\WINDOWS\system32\svchost.exe[972] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 00F51D10
.text C:\WINDOWS\system32\svchost.exe[972] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00F57250
.text C:\WINDOWS\system32\svchost.exe[972] WININET.dll!HttpSendRequestA 771C60A1 5 Bytes JMP 00F520A0
.text C:\WINDOWS\system32\svchost.exe[972] WININET.dll!InternetWriteFile 771F8BB9 5 Bytes JMP 00F523A0
.text C:\WINDOWS\system32\svchost.exe[972] WININET.dll!HttpSendRequestW 77212EBC 5 Bytes JMP 00F52160
.text C:\WINDOWS\system32\svchost.exe[1048] ntdll.dll!NtEnumerateValueKey 7C90D2D0 5 Bytes JMP 00C26390
.text C:\WINDOWS\system32\svchost.exe[1048] ntdll.dll!NtQueryDirectoryFile 7C90D750 5 Bytes JMP 00C26640
.text C:\WINDOWS\system32\svchost.exe[1048] ntdll.dll!NtResumeThread 7C90DB20 5 Bytes JMP 00C253D0
.text C:\WINDOWS\system32\svchost.exe[1048] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00C25300
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C211C0
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00C21290
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!MoveFileW 7C821249 5 Bytes JMP 00C22570
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!CopyFileA 7C8286D6 5 Bytes JMP 00C21000
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!CopyFileW 7C82F863 5 Bytes JMP 00C210A0
.text C:\WINDOWS\system32\svchost.exe[1048] kernel32.dll!MoveFileA 7C835EA7 5 Bytes JMP 00C22510
.text C:\WINDOWS\system32\svchost.exe[1048] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 00C21D10
.text C:\WINDOWS\system32\svchost.exe[1048] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00C27250
.text C:\WINDOWS\system32\svchost.exe[1048] WININET.dll!HttpSendRequestA 771C60A1 5 Bytes JMP 00C220A0
.text C:\WINDOWS\system32\svchost.exe[1048] WININET.dll!InternetWriteFile 771F8BB9 5 Bytes JMP 00C223A0
.text C:\WINDOWS\system32\svchost.exe[1048] WININET.dll!HttpSendRequestW 77212EBC 5 Bytes JMP 00C22160
.text C:\WINDOWS\System32\svchost.exe[1088] ntdll.dll!NtEnumerateValueKey 7C90D2D0 5 Bytes JMP 02C56390
.text C:\WINDOWS\System32\svchost.exe[1088] ntdll.dll!NtQueryDirectoryFile 7C90D750 5 Bytes JMP 02C56640
.text C:\WINDOWS\System32\svchost.exe[1088] ntdll.dll!NtResumeThread 7C90DB20 5 Bytes JMP 02C553D0
.text C:\WINDOWS\System32\svchost.exe[1088] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 02C55300
.text C:\WINDOWS\System32\svchost.exe[1088] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 02C511C0
.text C:\WINDOWS\System32\svchost.exe[1088] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 02C51290
.text C:\WINDOWS\System32\svchost.exe[1088] kernel32.dll!MoveFileW 7C821249 5 Bytes JMP 02C52570
.text C:\WINDOWS\System32\svchost.exe[1088] kernel32.dll!CopyFileA 7C8286D6 5 Bytes JMP 02C51000
.text C:\WINDOWS\System32\svchost.exe[1088] kernel32.dll!CopyFileW 7C82F863 5 Bytes JMP 02C510A0
.text C:\WINDOWS\System32\svchost.exe[1088] kernel32.dll!MoveFileA 7C835EA7 5 Bytes JMP 02C52510
.text C:\WINDOWS\System32\svchost.exe[1088] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 02C51D10
.text C:\WINDOWS\System32\svchost.exe[1088] WS2_32.dll!send 71AB4C27 5 Bytes JMP 02C57250
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!HttpSendRequestA 771C60A1 5 Bytes JMP 02C520A0
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!InternetWriteFile 771F8BB9 5 Bytes JMP 02C523A0
.text C:\WINDOWS\System32\svchost.exe[1088] WININET.dll!HttpSendRequestW 77212EBC 5 Bytes JMP 02C52160
.text C:\Documents and Settings\Michal\Application Data\1.exe[1120] ntdll.dll!NtEnumerateValueKey 7C90D2D0 5 Bytes JMP 00B46390
.text C:\Documents and Settings\Michal\Application Data\1.exe[1120] ntdll.dll!NtQueryDirectoryFile 7C90D750 5 Bytes JMP 00B46640
.text C:\Documents and Settings\Michal\Application Data\1.exe[1120] ntdll.dll!NtResumeThread 7C90DB20 5 Bytes JMP 00B453D0
.text C:\Documents and Settings\Michal\Application Data\1.exe[1120] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00B45300
.text C:\Documents and Settings\Michal\Application Data\1.exe[1120] ntdll.dll!DbgUiRemoteBreakin 7C94FFE3 5 Bytes JMP 7C81CAFA C:\WINDOWS\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation)
.text C:\Documents and Settings\Michal\Application Data\1.exe[1120] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B411C0
.text C:\Documents and Settings\Michal\Application Data\1.exe[1120] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00B41290
.text C:\Documents and Settings\Michal\Application Data\1.exe[1120] kernel32.dll!MoveFileW 7C821249 5 Bytes JMP 00B42570
.text C:\Documents and Settings\Michal\Application Data\1.exe[1120] kernel32.dll!CopyFileA 7C8286D6 5 Bytes JMP 00B41000
.text C:\Documents and Settings\Michal\Application Data\1.exe[1120] kernel32.dll!CopyFileW 7C82F863 5 Bytes JMP 00B410A0
.text C:\Documents and Settings\Michal\Application Data\1.exe[1120] kernel32.dll!MoveFileA 7C835EA7 5 Bytes JMP 00B42510
.text C:\Documents and Settings\Michal\Application Data\1.exe[1120] WININET.dll!HttpSendRequestA 771C60A1 5 Bytes JMP 00B420A0
.text C:\Documents and Settings\Michal\Application Data\1.exe[1120] WININET.dll!InternetWriteFile 771F8BB9 5 Bytes JMP 00B423A0
.text C:\Documents and Settings\Michal\Application Data\1.exe[1120] WININET.dll!HttpSendRequestW 77212EBC 5 Bytes JMP 00B42160
.text C:\Documents and Settings\Michal\Application Data\1.exe[1120] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 00B41D10
.text C:\Documents and Settings\Michal\Application Data\1.exe[1120] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00B47250
.text C:\WINDOWS\system32\svchost.exe[1132] ntdll.dll!NtEnumerateValueKey 7C90D2D0 5 Bytes JMP 007A6390
.text C:\WINDOWS\system32\svchost.exe[1132] ntdll.dll!NtQueryDirectoryFile 7C90D750 5 Bytes JMP 007A6640
.text C:\WINDOWS\system32\svchost.exe[1132] ntdll.dll!NtResumeThread 7C90DB20 5 Bytes JMP 007A53D0
.text C:\WINDOWS\system32\svchost.exe[1132] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 007A5300
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 007A11C0
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 007A1290
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!MoveFileW 7C821249 5 Bytes JMP 007A2570
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!CopyFileA 7C8286D6 5 Bytes JMP 007A1000
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!CopyFileW 7C82F863 5 Bytes JMP 007A10A0
.text C:\WINDOWS\system32\svchost.exe[1132] kernel32.dll!MoveFileA 7C835EA7 5 Bytes JMP 007A2510
.text C:\WINDOWS\system32\svchost.exe[1132] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 007A1D10
.text C:\WINDOWS\system32\svchost.exe[1132] WS2_32.dll!send 71AB4C27 5 Bytes JMP 007A7250
.text C:\WINDOWS\system32\svchost.exe[1132] WININET.dll!HttpSendRequestA 771C60A1 5 Bytes JMP 007A20A0
.text C:\WINDOWS\system32\svchost.exe[1132] WININET.dll!InternetWriteFile 771F8BB9 5 Bytes JMP 007A23A0
.text C:\WINDOWS\system32\svchost.exe[1132] WININET.dll!HttpSendRequestW 77212EBC 5 Bytes JMP 007A2160
.text C:\Program Files\Wireless Console 2\wcourier.exe[1172] ntdll.dll!NtEnumerateValueKey 7C90D2D0 5 Bytes JMP 00C16390
.text C:\Program Files\Wireless Console 2\wcourier.exe[1172] ntdll.dll!NtQueryDirectoryFile 7C90D750 5 Bytes JMP 00C16640
.text C:\Program Files\Wireless Console 2\wcourier.exe[1172] ntdll.dll!NtResumeThread 7C90DB20 5 Bytes JMP 00C153D0
.text C:\Program Files\Wireless Console 2\wcourier.exe[1172] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00C15300
.text C:\Program Files\Wireless Console 2\wcourier.exe[1172] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C111C0
.text C:\Program Files\Wireless Console 2\wcourier.exe[1172] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00C11290
.text C:\Program Files\Wireless Console 2\wcourier.exe[1172] kernel32.dll!MoveFileW 7C821249 5 Bytes JMP 00C12570
.text C:\Program Files\Wireless Console 2\wcourier.exe[1172] kernel32.dll!CopyFileA 7C8286D6 5 Bytes JMP 00C11000
.text C:\Program Files\Wireless Console 2\wcourier.exe[1172] kernel32.dll!CopyFileW 7C82F863 5 Bytes JMP 00C110A0
.text C:\Program Files\Wireless Console 2\wcourier.exe[1172] kernel32.dll!MoveFileA 7C835EA7 5 Bytes JMP 00C12510
.text C:\Program Files\Wireless Console 2\wcourier.exe[1172] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 00C11D10
.text C:\Program Files\Wireless Console 2\wcourier.exe[1172] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00C17250
.text C:\Program Files\Wireless Console 2\wcourier.exe[1172] WININET.dll!HttpSendRequestA 771C60A1 5 Bytes JMP 00C120A0
.text C:\Program Files\Wireless Console 2\wcourier.exe[1172] WININET.dll!InternetWriteFile 771F8BB9 5 Bytes JMP 00C123A0
.text C:\Program Files\Wireless Console 2\wcourier.exe[1172] WININET.dll!HttpSendRequestW 77212EBC 5 Bytes JMP 00C12160
.text C:\Program Files\Atheros\ACU.exe[1196] ntdll.dll!NtEnumerateValueKey 7C90D2D0 5 Bytes JMP 00BF6390
.text C:\Program Files\Atheros\ACU.exe[1196] ntdll.dll!NtQueryDirectoryFile 7C90D750 5 Bytes JMP 00BF6640
.text C:\Program Files\Atheros\ACU.exe[1196] ntdll.dll!NtResumeThread 7C90DB20 5 Bytes JMP 00BF53D0
.text C:\Program Files\Atheros\ACU.exe[1196] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00BF5300
.text C:\Program Files\Atheros\ACU.exe[1196] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BF11C0
.text C:\Program Files\Atheros\ACU.exe[1196] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00BF1290
.text C:\Program Files\Atheros\ACU.exe[1196] kernel32.dll!MoveFileW 7C821249 5 Bytes JMP 00BF2570
.text C:\Program Files\Atheros\ACU.exe[1196] kernel32.dll!CopyFileA 7C8286D6 5 Bytes JMP 00BF1000
.text C:\Program Files\Atheros\ACU.exe[1196] kernel32.dll!CopyFileW 7C82F863 5 Bytes JMP 00BF10A0
.text C:\Program Files\Atheros\ACU.exe[1196] kernel32.dll!MoveFileA 7C835EA7 5 Bytes JMP 00BF2510
.text C:\Program Files\Atheros\ACU.exe[1196] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 00BF1D10
.text C:\Program Files\Atheros\ACU.exe[1196] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00BF7250
.text C:\Program Files\Atheros\ACU.exe[1196] WININET.dll!HttpSendRequestA 771C60A1 5 Bytes JMP 00BF20A0
.text C:\Program Files\Atheros\ACU.exe[1196] WININET.dll!InternetWriteFile 771F8BB9 5 Bytes JMP 00BF23A0
.text C:\Program Files\Atheros\ACU.exe[1196] WININET.dll!HttpSendRequestW 77212EBC 5 Bytes JMP 00BF2160
.text C:\WINDOWS\system32\svchost.exe[1248] ntdll.dll!NtEnumerateValueKey 7C90D2D0 5 Bytes JMP 00C86390
.text C:\WINDOWS\system32\svchost.exe[1248] ntdll.dll!NtQueryDirectoryFile 7C90D750 5 Bytes JMP 00C86640
.text C:\WINDOWS\system32\svchost.exe[1248] ntdll.dll!NtResumeThread 7C90DB20 5 Bytes JMP 00C853D0
.text C:\WINDOWS\system32\svchost.exe[1248] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00C85300
.text C:\WINDOWS\system32\svchost.exe[1248] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00C811C0
.text C:\WINDOWS\system32\svchost.exe[1248] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00C81290
.text C:\WINDOWS\system32\svchost.exe[1248] kernel32.dll!MoveFileW 7C821249 5 Bytes JMP 00C82570
.text C:\WINDOWS\system32\svchost.exe[1248] kernel32.dll!CopyFileA 7C8286D6 5 Bytes JMP 00C81000
.text C:\WINDOWS\system32\svchost.exe[1248] kernel32.dll!CopyFileW 7C82F863 5 Bytes JMP 00C810A0
.text C:\WINDOWS\system32\svchost.exe[1248] kernel32.dll!MoveFileA 7C835EA7 5 Bytes JMP 00C82510
.text C:\WINDOWS\system32\svchost.exe[1248] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 00C81D10
.text C:\WINDOWS\system32\svchost.exe[1248] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00C87250
.text C:\WINDOWS\system32\svchost.exe[1248] WININET.dll!HttpSendRequestA 771C60A1 5 Bytes JMP 00C820A0
.text C:\WINDOWS\system32\svchost.exe[1248] WININET.dll!InternetWriteFile 771F8BB9 5 Bytes JMP 00C823A0
.text C:\WINDOWS\system32\svchost.exe[1248] WININET.dll!HttpSendRequestW 77212EBC 5 Bytes JMP 00C82160
.text C:\WINDOWS\system32\Ati2evxx.exe[1272] ntdll.dll!NtEnumerateValueKey 7C90D2D0 5 Bytes JMP 015F6390
.text C:\WINDOWS\system32\Ati2evxx.exe[1272] ntdll.dll!NtQueryDirectoryFile 7C90D750 5 Bytes JMP 015F6640
.text C:\WINDOWS\system32\Ati2evxx.exe[1272] ntdll.dll!NtResumeThread 7C90DB20 5 Bytes JMP 015F53D0
.text C:\WINDOWS\system32\Ati2evxx.exe[1272] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 015F5300
.text C:\WINDOWS\system32\Ati2evxx.exe[1272] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 015F11C0
.text C:\WINDOWS\system32\Ati2evxx.exe[1272] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 015F1290
.text C:\WINDOWS\system32\Ati2evxx.exe[1272] kernel32.dll!MoveFileW 7C821249 5 Bytes JMP 015F2570
.text C:\WINDOWS\system32\Ati2evxx.exe[1272] kernel32.dll!CopyFileA 7C8286D6 5 Bytes JMP 015F1000
.text C:\WINDOWS\system32\Ati2evxx.exe[1272] kernel32.dll!CopyFileW 7C82F863 5 Bytes JMP 015F10A0
.text C:\WINDOWS\system32\Ati2evxx.exe[1272] kernel32.dll!MoveFileA 7C835EA7 5 Bytes JMP 015F2510
.text C:\WINDOWS\system32\Ati2evxx.exe[1272] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 015F1D10
.text C:\WINDOWS\system32\Ati2evxx.exe[1272] WS2_32.dll!send 71AB4C27 5 Bytes JMP 015F7250
.text C:\WINDOWS\system32\Ati2evxx.exe[1272] WININET.dll!HttpSendRequestA 771C60A1 5 Bytes JMP 015F20A0
.text C:\WINDOWS\system32\Ati2evxx.exe[1272] WININET.dll!InternetWriteFile 771F8BB9 5 Bytes JMP 015F23A0
.text C:\WINDOWS\system32\Ati2evxx.exe[1272] WININET.dll!HttpSendRequestW 77212EBC 5 Bytes JMP 015F2160
.text C:\Documents and Settings\Michal\Application Data\regsrv33.exe[1300] ntdll.dll!NtEnumerateValueKey 7C90D2D0 5 Bytes JMP 00B36390
.text C:\Documents and Settings\Michal\Application Data\regsrv33.exe[1300] ntdll.dll!NtQueryDirectoryFile 7C90D750 5 Bytes JMP 00B36640
.text C:\Documents and Settings\Michal\Application Data\regsrv33.exe[1300] ntdll.dll!NtResumeThread 7C90DB20 5 Bytes JMP 00B353D0
.text C:\Documents and Settings\Michal\Application Data\regsrv33.exe[1300] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00B35300
.text C:\Documents and Settings\Michal\Application Data\regsrv33.exe[1300] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00B311C0
.text C:\Documents and Settings\Michal\Application Data\regsrv33.exe[1300] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00B31290
.text C:\Documents and Settings\Michal\Application Data\regsrv33.exe[1300] kernel32.dll!MoveFileW 7C821249 5 Bytes JMP 00B32570
.text C:\Documents and Settings\Michal\Application Data\regsrv33.exe[1300] kernel32.dll!CopyFileA 7C8286D6 5 Bytes JMP 00B31000
.text C:\Documents and Settings\Michal\Application Data\regsrv33.exe[1300] kernel32.dll!CopyFileW 7C82F863 5 Bytes JMP 00B310A0
.text C:\Documents and Settings\Michal\Application Data\regsrv33.exe[1300] kernel32.dll!MoveFileA 7C835EA7 5 Bytes JMP 00B32510
.text C:\Documents and Settings\Michal\Application Data\regsrv33.exe[1300] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 00B31D10
.text C:\Documents and Settings\Michal\Application Data\regsrv33.exe[1300] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00B37250
.text C:\Documents and Settings\Michal\Application Data\regsrv33.exe[1300] WININET.dll!HttpSendRequestA 771C60A1 5 Bytes JMP 00B320A0
.text C:\Documents and Settings\Michal\Application Data\regsrv33.exe[1300] WININET.dll!InternetWriteFile 771F8BB9 5 Bytes JMP 00B323A0
.text C:\Documents and Settings\Michal\Application Data\regsrv33.exe[1300] WININET.dll!HttpSendRequestW 77212EBC 5 Bytes JMP 00B32160
.text C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1328] ntdll.dll!NtEnumerateValueKey 7C90D2D0 5 Bytes JMP 00166390
.text C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1328] ntdll.dll!NtQueryDirectoryFile 7C90D750 5 Bytes JMP 00166640
.text C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1328] ntdll.dll!NtResumeThread 7C90DB20 5 Bytes JMP 001653D0
.text C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1328] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00165300
.text C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1328] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 00161D10
.text C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1328] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00167250
.text C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1328] WININET.dll!HttpSendRequestA 771C60A1 5 Bytes JMP 001620A0
.text C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1328] WININET.dll!InternetWriteFile 771F8BB9 5 Bytes JMP 001623A0
.text C:\Documents and Settings\Michal\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1328] WININET.dll!HttpSendRequestW 77212EBC 5 Bytes JMP 00162160
.text C:\WINDOWS\system32\wscntfy.exe[1352] ntdll.dll!NtEnumerateValueKey 7C90D2D0 5 Bytes JMP 00BB6390
.text C:\WINDOWS\system32\wscntfy.exe[1352] ntdll.dll!NtQueryDirectoryFile 7C90D750 5 Bytes JMP 00BB6640
.text C:\WINDOWS\system32\wscntfy.exe[1352] ntdll.dll!NtResumeThread 7C90DB20 5 Bytes JMP 00BB53D0
.text C:\WINDOWS\system32\wscntfy.exe[1352] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00BB5300
.text C:\WINDOWS\system32\wscntfy.exe[1352] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00BB11C0
.text C:\WINDOWS\system32\wscntfy.exe[1352] kernel32.dll!CreateFileW 7C8107F0 5 Bytes JMP 00BB1290
.text C:\WINDOWS\system32\wscntfy.exe[1352] kernel32.dll!MoveFileW 7C821249 5 Bytes JMP 00BB2570
.text C:\WINDOWS\system32\wscntfy.exe[1352] kernel32.dll!CopyFileA