GMER 1.0.15.15281 -
http://www.gmer.netRootkit scan 2010-01-19 22:06:40
Windows 5.1.2600 Service Pack 2
Running: wvctdcmg.exe; Driver: C:\DOCUME~1\Shiva\LOCALS~1\Temp\fwloapob.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0xF491636E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwClose [0xF4916A86]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwConnectPort [0xF491760C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateEvent [0xF4917B40]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateFile [0xF4916D78]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateKey [0xF4915460]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateMutant [0xF4917A18]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0xF4914D0A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreatePort [0xF49178D4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSection [0xF4916102]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSemaphore [0xF4917C72]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSymbolicLinkObject [0xF491940E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateThread [0xF4916886]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateWaitablePort [0xF4917976]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteKey [0xF4915A20]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteValueKey [0xF4915CF8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeviceIoControlFile [0xF491721C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDuplicateObject [0xF4919980]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateKey [0xF4915E3A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateValueKey [0xF4915EE4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwFsControlFile [0xF4917016]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadDriver [0xF4918EA6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey [0xF491543C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey2 [0xF491544E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwNotifyChangeKey [0xF4916030]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenEvent [0xF4917BE2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenFile [0xF4916B08]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenKey [0xF4915604]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenMutant [0xF4917AB0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenProcess [0xF491656E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSection [0xF4919438]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSemaphore [0xF4917D14]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenThread [0xF4916492]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryKey [0xF4915F8E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryMultipleValueKey [0xF4915BB6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryValueKey [0xF49158BC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueueApcThread [0xF4919128]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRenameKey [0xF4915B34]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplaceKey [0xF49150C2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyPort [0xF491809E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0xF4917F64]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0xF4918C30]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRestoreKey [0xF4915224]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwResumeThread [0xF4919860]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSaveKey [0xF4914EC4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSecureConnectPort [0xF4917312]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetContextThread [0xF4916984]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetInformationToken [0xF49185F2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSecurityObject [0xF4918FA0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSystemInformation [0xF49194C2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetValueKey [0xF4915744]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendProcess [0xF49195A6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendThread [0xF49196D2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSystemDebugControl [0xF4918DD2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateProcess [0xF49166EA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateThread [0xF491663C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwWriteVirtualMemory [0xF49167C8]
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) IoIsOperationSynchronous
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!_abnormal_termination + 114 804E2770 16 Bytes [02, 61, 91, F4, 72, 7C, 91, ...] {ADD AH, [ECX-0x6f]; HLT ; JB 0x82; XCHG ECX, EAX; HLT ; PUSH CS; XCHG ESP, EAX; XCHG ECX, EAX; HLT ; XCHG [EAX-0x6f], CH; HLT }
.text ntoskrnl.exe!_abnormal_termination + 1D9 804E2835 3 Bytes [54, 91, F4] {PUSH ESP; XCHG ECX, EAX; HLT }
.text ntoskrnl.exe!_abnormal_termination + 34C 804E29A8 16 Bytes [34, 5B, 91, F4, C2, 50, 91, ...] {XOR AL, 0x5b; XCHG ECX, EAX; HLT ; RET 0x9150; HLT ; SAHF ; ADC BYTE [ECX-0x6e809b0c], 0xf4}
.text ntoskrnl.exe!_abnormal_termination + 440 804E2A9C 12 Bytes [A6, 95, 91, F4, D2, 96, 91, ...] {CMPSB ; XCHG EBP, EAX; XCHG ECX, EAX; HLT ; RCL BYTE [ESI-0x722d0b6f], CL; XCHG ECX, EAX; HLT }
.text ntoskrnl.exe!_abnormal_termination + 450 804E2AAC 8 Bytes JMP 3CF49166
.text ntoskrnl.exe!IoIsOperationSynchronous 804E8752 5 Bytes JMP F490B7DE \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)
.text ntoskrnl.exe!FsRtlCheckLockForReadAccess 80503C29 5 Bytes JMP F490B424 \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab)
? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
? C:\WINDOWS\System32\Drivers\SPTDDRV1.SYS The process cannot access the file because it is being used by another process.
.text C:\WINDOWS\System32\DRIVERS\nv4_mini.sys section is writeable [0xF6C66360, 0x24BB1D, 0xE8000020]
.text USBPORT.SYS!DllUnload F6C4762C 5 Bytes JMP 839B01B8
? C:\DOCUME~1\Shiva\LOCALS~1\Temp\fwloapog.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[200] USER32.dll!VRipOutput + FFFA4DE7 7E412A78 4 Bytes [70, 11, 32, 6D]
.text C:\Program Files\Palm\Hotsync.exe[1128] msvcrt.dll!??2@YAPAXI@Z 77C29CC5 5 Bytes JMP 0A93C080 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[1128] msvcrt.dll!??3@YAXPAX@Z 77C29CDD 5 Bytes JMP 0A93C0E0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[1128] msvcrt.dll!?set_new_handler@@YAP6AXXZP6AXXZ@Z 77C29D9F 5 Bytes JMP 0A93C110 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[1128] msvcrt.dll!_aligned_offset_malloc 77C29DAF 5 Bytes JMP 0A93BFE0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[1128] msvcrt.dll!_aligned_free 77C29E33 5 Bytes JMP 0A93C0E0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[1128] msvcrt.dll!_aligned_malloc 77C29E52 5 Bytes JMP 0A93BFC0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[1128] msvcrt.dll!_aligned_offset_realloc 77C29E6E 5 Bytes JMP 0A93C020 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[1128] msvcrt.dll!_aligned_realloc 77C29FC6 5 Bytes JMP 0A93C000 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[1128] msvcrt.dll!_expand 77C29FE5 5 Bytes JMP 0A93BFA0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[1128] msvcrt.dll!_heapadd 77C2BC9F 5 Bytes JMP 0A93C160 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[1128] msvcrt.dll!_heapchk 77C2BCB3 5 Bytes JMP 0A93C170 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[1128] msvcrt.dll!_heapset + 1 77C2BD83 4 Bytes JMP 0A93C191 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[1128] msvcrt.dll!_heapmin 77C2BD8C 5 Bytes JMP 0A93C260 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[1128] msvcrt.dll!_heapused 77C2BE3A 5 Bytes JMP 0A93C230 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[1128] msvcrt.dll!_heapwalk 77C2BE4D 5 Bytes JMP 0A93C1A0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[1128] msvcrt.dll!_msize 77C2BF6C 5 Bytes JMP 0A93BEB0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[1128] msvcrt.dll!calloc 77C2C0C3 5 Bytes JMP 0A93BE50 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[1128] msvcrt.dll!free 77C2C21B 5 Bytes JMP 0A93C0E0 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[1128] msvcrt.dll!malloc 77C2C407 5 Bytes JMP 0A93BE10 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
.text C:\Program Files\Palm\Hotsync.exe[1128] msvcrt.dll!realloc 77C2C437 5 Bytes JMP 0A93BE90 C:\Program Files\Palm\SHW32.DLL (Memory Management Library for Win32/MicroQuill Software Publishing, Inc.)
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2004] C:\WINDOWS\system32\ntdll.dll time/date stamp mismatch;
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2004] C:\WINDOWS\system32\kernel32.dll time/date stamp mismatch;
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe[2004] USER32.dll!VRipOutput + FFFA4DE7 7E412A78 4 Bytes [70, 11, 32, 6D]
.text C:\Program Files\Internet Explorer\iexplore.exe[2284] USER32.dll!UnhookWindowsHookEx 7E41F21E 5 Bytes JMP 3E254602 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2284] USER32.dll!CallNextHookEx 7E41F85B 5 Bytes JMP 3E2DCEE9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2284] USER32.dll!CreateWindowExW 7E41FC25 5 Bytes JMP 3E2ED6EC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2284] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 3E21541D C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2284] USER32.dll!SetWindowsHookExW 7E42DDB5 5 Bytes JMP 3E2E9865 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2284] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 3E3E441F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2284] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 3E3E4351 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2284] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 3E3E43BC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2284] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 3E3E4222 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2284] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 3E3E4284 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2284] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 3E3E4482 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2284] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 3E3E42E6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2284] ole32.dll!CoCreateInstance 774FFAC3 5 Bytes JMP 3E2ED748 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2284] ole32.dll!OleLoadFromStream 7752A257 5 Bytes JMP 3E3E47A0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3988] USER32.dll!CreateWindowExW 7E41FC25 5 Bytes JMP 3E2ED6EC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3988] USER32.dll!DialogBoxParamW 7E42555F 5 Bytes JMP 3E21541D C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3988] USER32.dll!DialogBoxIndirectParamW 7E432032 5 Bytes JMP 3E3E441F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3988] USER32.dll!MessageBoxIndirectA 7E43A04A 5 Bytes JMP 3E3E4351 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3988] USER32.dll!DialogBoxParamA 7E43B10C 5 Bytes JMP 3E3E43BC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3988] USER32.dll!MessageBoxExW 7E4505D8 5 Bytes JMP 3E3E4222 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3988] USER32.dll!MessageBoxExA 7E4505FC 5 Bytes JMP 3E3E4284 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3988] USER32.dll!DialogBoxIndirectParamA 7E456B50 5 Bytes JMP 3E3E4482 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3988] USER32.dll!MessageBoxIndirectW 7E4662AB 5 Bytes JMP 3E3E42E6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F869E6C4] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F86B4394] sptd.sys
IAT atapi.sys[ntoskrnl.exe!IoConnectInterrupt] [F869E718] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F868EAB6] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F868EBEE] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F868EB76] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F868F71C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F868F5F2] sptd.sys
IAT disk.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F86B44E8] sptd.sys
IAT \SystemRoot\System32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F86B37AE] sptd.sys
IAT \SystemRoot\System32\DRIVERS\cdrom.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F86B44E8] sptd.sys
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[TDI.SYS!TdiRegisterDeviceObject] [F7FFD820] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\DRIVERS\netbt.sys[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\DRIVERS\netbt.sys[TDI.SYS!TdiRegisterDeviceObject] [F7FFD820] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\drivers\afd.sys[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\DRIVERS\netbios.sys[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\DRIVERS\rdbss.sys[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\DRIVERS\mrxsmb.sys[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\Drivers\Fips.SYS[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\DRIVERS\ipnat.sys[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\DRIVERS\arp1394.sys[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\DRIVERS\HIDCLASS.SYS[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\DRIVERS\kbdhid.sys[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\DRIVERS\mouhid.sys[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\Drivers\Cdfs.SYS[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\DRIVERS\nwlnkipx.sys[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\DRIVERS\nwlnkipx.sys[TDI.SYS!TdiRegisterDeviceObject] [F7FFD820] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\DRIVERS\nwlnknb.sys[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\DRIVERS\nwlnknb.sys[TDI.SYS!TdiRegisterDeviceObject] [F7FFD820] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\DRIVERS\nwlnkspx.sys[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\DRIVERS\nwlnkspx.sys[TDI.SYS!TdiRegisterDeviceObject] [F7FFD820] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\DRIVERS\mrxdav.sys[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\drivers\wdmaud.sys[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\drivers\sysaudio.sys[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\Drivers\ParVdm.SYS[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\System32\Drivers\HTTP.sys[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
IAT \SystemRoot\system32\drivers\kmixer.sys[ntoskrnl.exe!IoCreateDevice] [F7FFD6D0] kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Internet Explorer\iexplore.exe[2284] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1ACB] C:\Program Files\Internet Explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 83B701D8
AttachedDevice \Driver\Tcpip \Device\Ip kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
Device \Driver\usbuhci \Device\USBPDO-0 839AF1D8
Device \Driver\usbuhci \Device\USBPDO-1 839AF1D8
Device \Driver\usbuhci \Device\USBPDO-2 839AF1D8
Device \Driver\usbuhci \Device\USBPDO-3 839AF1D8
Device \FileSystem\Cdfs \Cdfs 836E8248
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch@Epoch 12038
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 2049328659
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 94076017
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{703FDB1E-A014-4ED1-81A5-C81118BA4F06}@DhcpRetryTime 322
Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{703FDB1E-A014-4ED1-81A5-C81118BA4F06}@DhcpRetryStatus 1
Reg HKLM\SOFTWARE\Classes\.application\bootstrap@ bootstrap.application.1
Reg HKLM\SOFTWARE\Classes\.xaml\bootstrap@ bootstrap.xaml.1
Reg HKLM\SOFTWARE\Classes\.xbap\bootstrap@ bootstrap.xbap.1
Reg HKLM\SOFTWARE\Classes\.xps\bootstrap@ bootstrap.xps.1
Reg HKLM\SOFTWARE\Classes\htafile\CLSID@ {3050f4d8-98B5-11CF-BB82-00AA00BDCE0B}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00EF2092-6AC5-47C0-BD25-CF2D5D657FEB}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00EF2092-6AC5-47C0-BD25-CF2D5D657FEB}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00EF2092-6AC5-47C0-BD25-CF2D5D657FEB}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00EF2092-6AC5-47C0-BD25-CF2D5D657FEB}\iexplore@Count 160
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00EF2092-6AC5-47C0-BD25-CF2D5D657FEB}\iexplore@Time 0xD8 0x07 0x0B 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}\iexplore@Type 3
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}\iexplore@Count 43
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}\iexplore@Time 0xD7 0x07 0x04 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}\iexplore@Count 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}\iexplore@Time 0xD7 0x07 0x0B 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\iexplore@Count 4314
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\iexplore@Type 4
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\iexplore@Count 4104
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{166B1BCA-3F9C-11CF-8075-444553540000}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{166B1BCA-3F9C-11CF-8075-444553540000}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{166B1BCA-3F9C-11CF-8075-444553540000}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{166B1BCA-3F9C-11CF-8075-444553540000}\iexplore@Count 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{166B1BCA-3F9C-11CF-8075-444553540000}\iexplore@Time 0xD8 0x07 0x07 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{227B8AA8-DAF2-4892-BD1D-73F568BCB24E}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{227B8AA8-DAF2-4892-BD1D-73F568BCB24E}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{227B8AA8-DAF2-4892-BD1D-73F568BCB24E}\iexplore@Type 3
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{227B8AA8-DAF2-4892-BD1D-73F568BCB24E}\iexplore@Count 3775
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{227B8AA8-DAF2-4892-BD1D-73F568BCB24E}\iexplore@Time 0xD8 0x07 0x09 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{22D6F312-B0F6-11D0-94AB-0080C74C7E95}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{22D6F312-B0F6-11D0-94AB-0080C74C7E95}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{22D6F312-B0F6-11D0-94AB-0080C74C7E95}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{22D6F312-B0F6-11D0-94AB-0080C74C7E95}\iexplore@Count 14
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{22D6F312-B0F6-11D0-94AB-0080C74C7E95}\iexplore@Time 0xD8 0x07 0x08 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\iexplore@Count 6071
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{243B17DE-77C7-46BF-B94B-0B5F309A0E64}\iexplore@Count 4314
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25336920-03F9-11CF-8FD0-00AA00686F13}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25336920-03F9-11CF-8FD0-00AA00686F13}\iexplore@Count 17
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2D360201-FFF5-11D1-8D03-00A0C959BC0A}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2D360201-FFF5-11D1-8D03-00A0C959BC0A}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2D360201-FFF5-11D1-8D03-00A0C959BC0A}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2D360201-FFF5-11D1-8D03-00A0C959BC0A}\iexplore@Count 126
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2D360201-FFF5-11D1-8D03-00A0C959BC0A}\iexplore@Time 0xD8 0x07 0x0C 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2D8ED06D-3C30-438B-96AE-4D110FDC1FB8}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2D8ED06D-3C30-438B-96AE-4D110FDC1FB8}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2D8ED06D-3C30-438B-96AE-4D110FDC1FB8}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2D8ED06D-3C30-438B-96AE-4D110FDC1FB8}\iexplore@Count 4
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2D8ED06D-3C30-438B-96AE-4D110FDC1FB8}\iexplore@Time 0xD8 0x07 0x0A 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2D8ED06D-3C30-438B-96AE-4D110FDC1FB8}\iexplore@Blocked 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3050F819-98B5-11CF-BB82-00AA00BDCE0B}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3050F819-98B5-11CF-BB82-00AA00BDCE0B}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3050F819-98B5-11CF-BB82-00AA00BDCE0B}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3050F819-98B5-11CF-BB82-00AA00BDCE0B}\iexplore@Count 10
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3050F819-98B5-11CF-BB82-00AA00BDCE0B}\iexplore@Time 0xD8 0x07 0x06 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{36C417C6-13C6-448B-9784-DD73A93B0582}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{36C417C6-13C6-448B-9784-DD73A93B0582}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{36C417C6-13C6-448B-9784-DD73A93B0582}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{36C417C6-13C6-448B-9784-DD73A93B0582}\iexplore@Count 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{36C417C6-13C6-448B-9784-DD73A93B0582}\iexplore@Time 0xD8 0x07 0x06 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{38481807-CA0E-42D2-BF39-B33AF135CC4D}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{38481807-CA0E-42D2-BF39-B33AF135CC4D}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{38481807-CA0E-42D2-BF39-B33AF135CC4D}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{38481807-CA0E-42D2-BF39-B33AF135CC4D}\iexplore@Count 11
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{38481807-CA0E-42D2-BF39-B33AF135CC4D}\iexplore@Time 0xD8 0x07 0x09 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\iexplore@Count 443
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3EC8255F-E043-4CAE-8B3B-B191550C2A22}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3EC8255F-E043-4CAE-8B3B-B191550C2A22}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3EC8255F-E043-4CAE-8B3B-B191550C2A22}\iexplore@Type 3
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3EC8255F-E043-4CAE-8B3B-B191550C2A22}\iexplore@Count 3774
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3EC8255F-E043-4CAE-8B3B-B191550C2A22}\iexplore@Time 0xD8 0x07 0x09 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{406B5949-7190-4245-91A9-30A17DE16AD0}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{406B5949-7190-4245-91A9-30A17DE16AD0}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{406B5949-7190-4245-91A9-30A17DE16AD0}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{406B5949-7190-4245-91A9-30A17DE16AD0}\iexplore@Count 3
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{406B5949-7190-4245-91A9-30A17DE16AD0}\iexplore@Time 0xD7 0x07 0x0B 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{406B5949-7190-4245-91A9-30A17DE16AD0}\iexplore@Blocked 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{41524153-46FB-488C-8E53-7624AB83C46F}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{41524153-46FB-488C-8E53-7624AB83C46F}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{41524153-46FB-488C-8E53-7624AB83C46F}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{41524153-46FB-488C-8E53-7624AB83C46F}\iexplore@Count 6
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{41524153-46FB-488C-8E53-7624AB83C46F}\iexplore@Time 0xD8 0x07 0x0A 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4453D895-F2A1-4A38-A285-1EF9BD3F6D5D}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4453D895-F2A1-4A38-A285-1EF9BD3F6D5D}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4453D895-F2A1-4A38-A285-1EF9BD3F6D5D}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4453D895-F2A1-4A38-A285-1EF9BD3F6D5D}\iexplore@Count 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4453D895-F2A1-4A38-A285-1EF9BD3F6D5D}\iexplore@Time 0xD7 0x07 0x0A 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{48123BC4-99D9-11D1-A6B3-00C04FD91555}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{48123BC4-99D9-11D1-A6B3-00C04FD91555}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{48123BC4-99D9-11D1-A6B3-00C04FD91555}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{48123BC4-99D9-11D1-A6B3-00C04FD91555}\iexplore@Count 92
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{48123BC4-99D9-11D1-A6B3-00C04FD91555}\iexplore@Time 0xD8 0x07 0x08 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4C29D864-C55A-46DD-865C-17A1B7CC1A1A}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4C29D864-C55A-46DD-865C-17A1B7CC1A1A}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4C29D864-C55A-46DD-865C-17A1B7CC1A1A}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4C29D864-C55A-46DD-865C-17A1B7CC1A1A}\iexplore@Count 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4C29D864-C55A-46DD-865C-17A1B7CC1A1A}\iexplore@Time 0xD8 0x07 0x06 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}\iexplore@Count 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}\iexplore@Time 0xD8 0x07 0x06 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}\iexplore@Count 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}\iexplore@Time 0xD8 0x07 0x03 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4F1E5B1A-2A80-42CA-8532-2D05CB959537}\iexplore@Blocked 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5220CB21-C88D-11CF-B347-00AA00A28331}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5220CB21-C88D-11CF-B347-00AA00A28331}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5220CB21-C88D-11CF-B347-00AA00A28331}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5220CB21-C88D-11CF-B347-00AA00A28331}\iexplore@Count 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5220CB21-C88D-11CF-B347-00AA00A28331}\iexplore@Time 0xD8 0x07 0x06 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5940894F-4BA9-4FAC-ACFD-2F56F7CE0E3B}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5940894F-4BA9-4FAC-ACFD-2F56F7CE0E3B}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5940894F-4BA9-4FAC-ACFD-2F56F7CE0E3B}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5940894F-4BA9-4FAC-ACFD-2F56F7CE0E3B}\iexplore@Count 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5940894F-4BA9-4FAC-ACFD-2F56F7CE0E3B}\iexplore@Time 0xD8 0x07 0x06 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5D637FAD-E202-48D1-8F18-5B9C459BD1E3}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5D637FAD-E202-48D1-8F18-5B9C459BD1E3}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5D637FAD-E202-48D1-8F18-5B9C459BD1E3}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5D637FAD-E202-48D1-8F18-5B9C459BD1E3}\iexplore@Count 7
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5D637FAD-E202-48D1-8F18-5B9C459BD1E3}\iexplore@Time 0xD8 0x07 0x08 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5D637FAD-E202-48D1-8F18-5B9C459BD1E3}\iexplore@Blocked 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{63B78BC1-A711-4D46-AD2F-C581AC420D41}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{63B78BC1-A711-4D46-AD2F-C581AC420D41}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{63B78BC1-A711-4D46-AD2F-C581AC420D41}\iexplore@Type 3
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{63B78BC1-A711-4D46-AD2F-C581AC420D41}\iexplore@Count 49
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{63B78BC1-A711-4D46-AD2F-C581AC420D41}\iexplore@Time 0xD7 0x07 0x04 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64AB4BB7-111E-11D1-8F79-00C04FC2FBE1}\iexplore@Count 15
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{669B269B-0D4E-41FB-A3D8-FD67CA94F646}\iexplore@Count 4047
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\iexplore@Count 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\iexplore@Time 0xD7 0x07 0x0C 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67DABFBF-D0AB-41FA-9C46-CC0F21721616}\iexplore@Blocked 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6BF52A52-394A-11D3-B153-00C04F79FAA6}\iexplore@Count 18
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{72267F6A-A6F9-11D0-BC94-00C04FB67863}\iexplore@Count 1363
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore@Type 3
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore@Count 200
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore@Time 0xD7 0x07 0x0B 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}\iexplore@Type 3
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}\iexplore@Count 75
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}\iexplore@Time 0xD8 0x07 0x0A 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{87766247-311C-43B4-8499-3D5FEC94A183}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{87766247-311C-43B4-8499-3D5FEC94A183}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{87766247-311C-43B4-8499-3D5FEC94A183}\iexplore@Type 3
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{87766247-311C-43B4-8499-3D5FEC94A183}\iexplore@Count 49
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{87766247-311C-43B4-8499-3D5FEC94A183}\iexplore@Time 0xD7 0x07 0x04 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8828075D-D097-4055-AA02-2DBFA9D85E8A}\iexplore@Count 4047
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8856F961-340A-11D0-A96B-00C04FD705A2}\iexplore@Count 87
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\iexplore@Count 2
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\iexplore@Time 0xD7 0x07 0x0A 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\iexplore@Blocked 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{92780B25-18CC-41C8-B9BE-3C9C571A8263}\iexplore@Count 4047
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9600F64D-755F-11D4-A47F-0001023E6D5A}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9600F64D-755F-11D4-A47F-0001023E6D5A}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9600F64D-755F-11D4-A47F-0001023E6D5A}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9600F64D-755F-11D4-A47F-0001023E6D5A}\iexplore@Count 6
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9600F64D-755F-11D4-A47F-0001023E6D5A}\iexplore@Time 0xD8 0x07 0x08 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9600F64D-755F-11D4-A47F-0001023E6D5A}\iexplore@Blocked 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{97809617-3937-4F84-B335-9BB05EF1A8D4}\iexplore@Count 4047
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9BE8D7B2-329C-442A-A4AC-ABA9D7572602}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9BE8D7B2-329C-442A-A4AC-ABA9D7572602}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9BE8D7B2-329C-442A-A4AC-ABA9D7572602}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9BE8D7B2-329C-442A-A4AC-ABA9D7572602}\iexplore@Count 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9BE8D7B2-329C-442A-A4AC-ABA9D7572602}\iexplore@Time 0xD8 0x07 0x06 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7EA8AD2-287F-11D3-B120-006008C39542}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7EA8AD2-287F-11D3-B120-006008C39542}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7EA8AD2-287F-11D3-B120-006008C39542}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7EA8AD2-287F-11D3-B120-006008C39542}\iexplore@Count 2
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7EA8AD2-287F-11D3-B120-006008C39542}\iexplore@Time 0xD7 0x07 0x0A 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7EA8AD2-287F-11D3-B120-006008C39542}\iexplore@Blocked 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AA58ED58-01DD-4D91-8333-CF10577473F7}\iexplore@Count 4145
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B45FF030-4447-11D2-85DE-00C04FA35C89}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B45FF030-4447-11D2-85DE-00C04FA35C89}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B45FF030-4447-11D2-85DE-00C04FA35C89}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B45FF030-4447-11D2-85DE-00C04FA35C89}\iexplore@Count 14
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B45FF030-4447-11D2-85DE-00C04FA35C89}\iexplore@Time 0xD8 0x07 0x08 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA52B914-B692-46C4-B683-905236F6F655}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA52B914-B692-46C4-B683-905236F6F655}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA52B914-B692-46C4-B683-905236F6F655}\iexplore@Type 2
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA52B914-B692-46C4-B683-905236F6F655}\iexplore@Count 5496
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA52B914-B692-46C4-B683-905236F6F655}\iexplore@Time 0xD8 0x07 0x09 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BCC0FF27-31D9-4614-A68E-C18E1ADA4389}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BCC0FF27-31D9-4614-A68E-C18E1ADA4389}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BCC0FF27-31D9-4614-A68E-C18E1ADA4389}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BCC0FF27-31D9-4614-A68E-C18E1ADA4389}\iexplore@Count 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BCC0FF27-31D9-4614-A68E-C18E1ADA4389}\iexplore@Time 0xD8 0x07 0x06 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD96C556-65A3-11D0-983A-00C04FC29E36}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD96C556-65A3-11D0-983A-00C04FC29E36}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD96C556-65A3-11D0-983A-00C04FC29E36}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD96C556-65A3-11D0-983A-00C04FC29E36}\iexplore@Count 8
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD96C556-65A3-11D0-983A-00C04FC29E36}\iexplore@Time 0xD8 0x07 0x0B 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA145D71-4BCB-461D-BCBE-C01C42867380}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA145D71-4BCB-461D-BCBE-C01C42867380}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA145D71-4BCB-461D-BCBE-C01C42867380}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA145D71-4BCB-461D-BCBE-C01C42867380}\iexplore@Count 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA145D71-4BCB-461D-BCBE-C01C42867380}\iexplore@Time 0xD8 0x07 0x06 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA8A9780-280D-11CF-A24D-444553540000}\iexplore@Count 18
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD3AFA74-B84F-48F0-9393-7EDC34128127}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD3AFA74-B84F-48F0-9393-7EDC34128127}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD3AFA74-B84F-48F0-9393-7EDC34128127}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD3AFA74-B84F-48F0-9393-7EDC34128127}\iexplore@Count 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD3AFA74-B84F-48F0-9393-7EDC34128127}\iexplore@Time 0xD7 0x07 0x0C 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD3AFA7B-B84F-48F0-9393-7EDC34128127}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD3AFA7B-B84F-48F0-9393-7EDC34128127}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD3AFA7B-B84F-48F0-9393-7EDC34128127}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD3AFA7B-B84F-48F0-9393-7EDC34128127}\iexplore@Count 2
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD3AFA7B-B84F-48F0-9393-7EDC34128127}\iexplore@Time 0xD8 0x07 0x07 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD3AFA8F-B84F-48F0-9393-7EDC34128127}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD3AFA8F-B84F-48F0-9393-7EDC34128127}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD3AFA8F-B84F-48F0-9393-7EDC34128127}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD3AFA8F-B84F-48F0-9393-7EDC34128127}\iexplore@Count 2
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD3AFA8F-B84F-48F0-9393-7EDC34128127}\iexplore@Time 0xD8 0x07 0x05 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD3AFA94-B84F-48F0-9393-7EDC34128127}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD3AFA94-B84F-48F0-9393-7EDC34128127}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD3AFA94-B84F-48F0-9393-7EDC34128127}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD3AFA94-B84F-48F0-9393-7EDC34128127}\iexplore@Count 2
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD3AFA94-B84F-48F0-9393-7EDC34128127}\iexplore@Time 0xD7 0x07 0x08 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CD67F990-D8E9-11D2-98FE-00C0F0318AFE}\iexplore@Count 4047
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA}\iexplore@Count 23
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA}\iexplore@Time 0xD8 0x07 0x08 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore@Count 25473
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D2D8D3C0-C750-4703-A6AD-75D6B578FFE6}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D2D8D3C0-C750-4703-A6AD-75D6B578FFE6}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D2D8D3C0-C750-4703-A6AD-75D6B578FFE6}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D2D8D3C0-C750-4703-A6AD-75D6B578FFE6}\iexplore@Count 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D2D8D3C0-C750-4703-A6AD-75D6B578FFE6}\iexplore@Time 0xD8 0x07 0x06 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D6DFF6D8-B94B-4720-B730-1C38C7065C3B}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D6DFF6D8-B94B-4720-B730-1C38C7065C3B}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D6DFF6D8-B94B-4720-B730-1C38C7065C3B}\iexplore@Type 3
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D6DFF6D8-B94B-4720-B730-1C38C7065C3B}\iexplore@Count 4313
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D6DFF6D8-B94B-4720-B730-1C38C7065C3B}\iexplore@Time 0xD9 0x07 0x02 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DFEAF541-F3E1-4C24-ACAC-99C30715084A}\iexplore@Count 158
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E023F504-0C5A-4750-A1E7-A9046DEA8A21}\iexplore@Count 4047
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\iexplore@Type 2
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\iexplore@Count 85
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\iexplore@Time 0xD7 0x07 0x04 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F04A8AE2-A59D-11D2-8792-00C04F8EF29D}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F04A8AE2-A59D-11D2-8792-00C04F8EF29D}\iexplore
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F04A8AE2-A59D-11D2-8792-00C04F8EF29D}\iexplore@Type 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F04A8AE2-A59D-11D2-8792-00C04F8EF29D}\iexplore@Count 5
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F04A8AE2-A59D-11D2-8792-00C04F8EF29D}\iexplore@Time 0xD7 0x07 0x04 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F04A8AE2-A59D-11D2-8792-00C04F8EF29D}\iexplore@Blocked 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F0D4B231-DA4B-4DAF-81E4-DFEE4931A4AA}\iexplore@Count 459
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}\iexplore@Count 643
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FB5F1910-F110-11D2-BB9E-00C04F795683}\iexplore@Count 4047
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FDD3B846-8D59-4FFB-8758-209B6AD74ACC}\iexplore@Count 4313
---- EOF - GMER 1.0.15 ----