Grazie Chill-Out,
questo è il log che mi avevi chiesto,
penso che ci sia tanta carne a cuocere
...come procedere?
Ho bisogno di avenger
o posso riprovare con A-square ?
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-05-13 09:28:58
Windows 5.1.2600 Service Pack 3
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\System32\svchost.exe[876] ntdll.dll!NtQueryInformationProcess 7C91D7E0 3 Bytes JMP 00929DC2
.text C:\WINDOWS\System32\svchost.exe[876] ntdll.dll!NtQueryInformationProcess + 4 7C91D7E4 1 Byte [84]
.text C:\WINDOWS\System32\svchost.exe[944] ntdll.dll!NtQueryInformationProcess 7C91D7E0 5 Bytes JMP 01C19DC2
.text C:\WINDOWS\System32\svchost.exe[944] NETAPI32.dll!NetpwPathCanonicalize 5BC7A3A9 5 Bytes JMP 01C19D62
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [019573CC] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [01957376] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [01957376] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [019573CC] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [019573CC] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [01957376] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [01957376] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [019573CC] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [019573CC] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [01957376] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [019573CC] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [01957376] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [019573CC] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [01957376] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [01957376] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [019573CC] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [019573CC] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [01957376] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [019573CC] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [01957376] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [01957376] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [019573CC] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] [01957376] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!SetUnhandledExceptionFilter] [019573CC] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [019573CC] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] [01957376] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [019573CC] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [01957376] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [019573CC] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] [01957376] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\SAMLIB.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [019573CC] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] [01957376] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
IAT C:\Programmi\Mozilla Thunderbird\thunderbird.exe[3844] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [019573CC] C:\Programmi\Mozilla Thunderbird\extensions\
[email protected]\components\FULLSOFT.DLL (Talkback Library/Full Circle Software, Inc.)
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 hotcore3.sys (Hotbackup helper driver/Paragon Software Group)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 hotcore3.sys (Hotbackup helper driver/Paragon Software Group)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume3 hotcore3.sys (Hotbackup helper driver/Paragon Software Group)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume4 hotcore3.sys (Hotbackup helper driver/Paragon Software Group)
---- Services - GMER 1.0.15 ----
Service C:\Programmi\File comuni\Services\Obo.exe (*** hidden *** ) [AUTO] SecLwd <-- ROOTKIT !!!
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [AUTO] zdebv <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\SecLwd@Type 16
Reg HKLM\SYSTEM\CurrentControlSet\Services\SecLwd@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\SecLwd@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\SecLwd@ImagePath "C:\Programmi\File comuni\Services\Obo.exe"
Reg HKLM\SYSTEM\CurrentControlSet\Services\SecLwd@DisplayName SecLwd
Reg HKLM\SYSTEM\CurrentControlSet\Services\SecLwd@ObjectName .\BCMwuscaUfcganXx
Reg HKLM\SYSTEM\CurrentControlSet\Services\SecLwd@Description Assicura la sincronizzazione data e ora su tutti i client e i server della rete. Se il servizio viene interrotto, la sincronizzazione data e ora non sar? disponibile. Se questo servizio ? disattivato, non potr? essere avviato alcun servizio che dipende direttamente da esso.
Reg HKLM\SYSTEM\CurrentControlSet\Services\SecLwd\Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\SecLwd\Security@Security 0x01 0x00 0x14 0x80 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\zdebv@DisplayName Config Server
Reg HKLM\SYSTEM\CurrentControlSet\Services\zdebv@Type 32
Reg HKLM\SYSTEM\CurrentControlSet\Services\zdebv@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\zdebv@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\zdebv@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\CurrentControlSet\Services\zdebv@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\Services\zdebv@Description Archivia le informazioni di protezione per gli account utenti locali.
Reg HKLM\SYSTEM\CurrentControlSet\Services\zdebv\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\zdebv\Parameters@ServiceDll C:\WINDOWS\system32\axwskll.dll
Reg HKLM\SYSTEM\ControlSet002\Services\SecLwd@Type 16
Reg HKLM\SYSTEM\ControlSet002\Services\SecLwd@Start 2
Reg HKLM\SYSTEM\ControlSet002\Services\SecLwd@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet002\Services\SecLwd@ImagePath "C:\Programmi\File comuni\Services\prF.exe"
Reg HKLM\SYSTEM\ControlSet002\Services\SecLwd@DisplayName SecLwd
Reg HKLM\SYSTEM\ControlSet002\Services\SecLwd@ObjectName .\BCMwuscaUfcganXx
Reg HKLM\SYSTEM\ControlSet002\Services\SecLwd@Description Assicura la sincronizzazione data e ora su tutti i client e i server della rete. Se il servizio viene interrotto, la sincronizzazione data e ora non sar? disponibile. Se questo servizio ? disattivato, non potr? essere avviato alcun servizio che dipende direttamente da esso.
Reg HKLM\SYSTEM\ControlSet002\Services\SecLwd\Security
Reg HKLM\SYSTEM\ControlSet002\Services\SecLwd\Security@Security 0x01 0x00 0x14 0x80 ...
Reg HKLM\SYSTEM\ControlSet002\Services\SysmonLog\Log Queries\{220582b5-a05e-423b-a0bd-3af2f27aa2cf}@Current State 0
Reg HKLM\SYSTEM\ControlSet002\Services\SysmonLog\Log Queries\{220582b5-a05e-423b-a0bd-3af2f27aa2cf}@Log Type 0
Reg HKLM\SYSTEM\ControlSet002\Services\SysmonLog\Log Queries\{220582b5-a05e-423b-a0bd-3af2f27aa2cf}@Collection Name Anteprima di sistema
Reg HKLM\SYSTEM\ControlSet002\Services\SysmonLog\Log Queries\{220582b5-a05e-423b-a0bd-3af2f27aa2cf}@Collection Name Indirect @C:\WINDOWS\System32\smlogcfg.dll,-731
Reg HKLM\SYSTEM\ControlSet002\Services\SysmonLog\Log Queries\{220582b5-a05e-423b-a0bd-3af2f27aa2cf}@Counter List \Processor(_Total)\% Processor Time?\Memory\Pages/sec?\PhysicalDisk(_Total)\Avg. Disk Queue Length?
Reg HKLM\SYSTEM\ControlSet002\Services\SysmonLog\Log Queries\{220582b5-a05e-423b-a0bd-3af2f27aa2cf}@Comment Il registro campione presenta un'anteprima delle prestazioni del sistema.
Reg HKLM\SYSTEM\ControlSet002\Services\SysmonLog\Log Queries\{220582b5-a05e-423b-a0bd-3af2f27aa2cf}@Commento indiretto @C:\WINDOWS\System32\smlogcfg.dll,-735
Reg HKLM\SYSTEM\ControlSet002\Services\SysmonLog\Log Queries\{220582b5-a05e-423b-a0bd-3af2f27aa2cf}@RealTime DataSource 1
Reg HKLM\SYSTEM\ControlSet002\Services\SysmonLog\Log Queries\{220582b5-a05e-423b-a0bd-3af2f27aa2cf}@Log File Max Size -1
Reg HKLM\SYSTEM\ControlSet002\Services\SysmonLog\Log Queries\{220582b5-a05e-423b-a0bd-3af2f27aa2cf}@Attributi archivio dati 33
Reg HKLM\SYSTEM\ControlSet002\Services\SysmonLog\Log Queries\{220582b5-a05e-423b-a0bd-3af2f27aa2cf}@Log File Base Name System_Overview
Reg HKLM\SYSTEM\ControlSet002\Services\SysmonLog\Log Queries\{220582b5-a05e-423b-a0bd-3af2f27aa2cf}@Nome di base del file di registro indiretto @C:\WINDOWS\System32\smlogcfg.dll,-744
Reg HKLM\SYSTEM\ControlSet002\Services\SysmonLog\Log Queries\{220582b5-a05e-423b-a0bd-3af2f27aa2cf}@Sql Log Base Name SQL:!Anteprima di sistema
Reg HKLM\SYSTEM\ControlSet002\Services\SysmonLog\Log Queries\{220582b5-a05e-423b-a0bd-3af2f27aa2cf}@Log File Serial Number 1
Reg HKLM\SYSTEM\ControlSet002\Services\SysmonLog\Log Queries\{220582b5-a05e-423b-a0bd-3af2f27aa2cf}@Log File Folder C:\PerfLogs
Reg HKLM\SYSTEM\ControlSet002\Services\SysmonLog\Log Queries\{220582b5-a05e-423b-a0bd-3af2f27aa2cf}@Log File Auto Format -1
Reg HKLM\SYSTEM\ControlSet002\Services\SysmonLog\Log Queries\{220582b5-a05e-423b-a0bd-3af2f27aa2cf}@Log File Type 2
Reg HKLM\SYSTEM\ControlSet002\Services\SysmonLog\Log Queries\{220582b5-a05e-423b-a0bd-3af2f27aa2cf}@ExecuteOnly 1
Reg HKLM\SYSTEM\ControlSet003\Services\SecLwd@Type 16
Reg HKLM\SYSTEM\ControlSet003\Services\SecLwd@Start 2
Reg HKLM\SYSTEM\ControlSet003\Services\SecLwd@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet003\Services\SecLwd@ImagePath "C:\Programmi\File comuni\Services\Obo.exe"
Reg HKLM\SYSTEM\ControlSet003\Services\SecLwd@DisplayName SecLwd
Reg HKLM\SYSTEM\ControlSet003\Services\SecLwd@ObjectName .\BCMwuscaUfcganXx
Reg HKLM\SYSTEM\ControlSet003\Services\SecLwd@Description Assicura la sincronizzazione data e ora su tutti i client e i server della rete. Se il servizio viene interrotto, la sincronizzazione data e ora non sar? disponibile. Se questo servizio ? disattivato, non potr? essere avviato alcun servizio che dipende direttamente da esso.
Reg HKLM\SYSTEM\ControlSet003\Services\SecLwd\Security
Reg HKLM\SYSTEM\ControlSet003\Services\SecLwd\Security@Security 0x01 0x00 0x14 0x80 ...
Reg HKLM\SYSTEM\ControlSet004\Services\SecLwd@Type 16
Reg HKLM\SYSTEM\ControlSet004\Services\SecLwd@Start 2
Reg HKLM\SYSTEM\ControlSet004\Services\SecLwd@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet004\Services\SecLwd@ImagePath "C:\Programmi\File comuni\Services\Obo.exe"
Reg HKLM\SYSTEM\ControlSet004\Services\SecLwd@DisplayName SecLwd
Reg HKLM\SYSTEM\ControlSet004\Services\SecLwd@ObjectName .\BCMwuscaUfcganXx
Reg HKLM\SYSTEM\ControlSet004\Services\SecLwd@Description Assicura la sincronizzazione data e ora su tutti i client e i server della rete. Se il servizio viene interrotto, la sincronizzazione data e ora non sar? disponibile. Se questo servizio ? disattivato, non potr? essere avviato alcun servizio che dipende direttamente da esso.
Reg HKLM\SYSTEM\ControlSet004\Services\SecLwd\Security
Reg HKLM\SYSTEM\ControlSet004\Services\SecLwd\Security@Security 0x01 0x00 0x14 0x80 ...
Reg HKLM\SYSTEM\ControlSet004\Services\zdebv@DisplayName Config Server
Reg HKLM\SYSTEM\ControlSet004\Services\zdebv@Type 32
Reg HKLM\SYSTEM\ControlSet004\Services\zdebv@Start 2
Reg HKLM\SYSTEM\ControlSet004\Services\zdebv@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet004\Services\zdebv@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet004\Services\zdebv@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet004\Services\zdebv@Description Archivia le informazioni di protezione per gli account utenti locali.
Reg HKLM\SYSTEM\ControlSet004\Services\zdebv\Parameters
Reg HKLM\SYSTEM\ControlSet004\Services\zdebv\Parameters@ServiceDll C:\WINDOWS\system32\axwskll.dll
Reg HKLM\SOFTWARE\Classes\Applications\AcroRd32.exe\shell\open
Reg HKLM\SOFTWARE\Classes\Applications\AcroRd32.exe\shell\open\command
Reg HKLM\SOFTWARE\Classes\Applications\AcroRd32.exe\shell\open\command@ "C:\Programmi\Adobe\Acrobat 5.0\Reader\AcroRd32.exe" "%1"
Reg HKLM\SOFTWARE\Classes\Applications\AcroRd32.exe\shell\print
Reg HKLM\SOFTWARE\Classes\Applications\AcroRd32.exe\shell\printto
Reg HKLM\SOFTWARE\Classes\Applications\openfile.bat\shell\open
Reg HKLM\SOFTWARE\Classes\Applications\openfile.bat\shell\open\command
Reg HKLM\SOFTWARE\Classes\Applications\openfile.bat\shell\open\command@ e:\Program Files\s1studio\me\bin\openfile.bat "%1"
Reg HKLM\SOFTWARE\Classes\Applications\PBE.exe\shell\open
Reg HKLM\SOFTWARE\Classes\Applications\PBE.exe\shell\open\command
Reg HKLM\SOFTWARE\Classes\Applications\PBE.exe\shell\open\command@ "C:\Programmi\PhotoDeluxe VA 1.0\PBE.exe" "%1"
Reg HKLM\SOFTWARE\Classes\Applications\Poseidon for UML.exe\shell\open
Reg HKLM\SOFTWARE\Classes\Applications\Poseidon for UML.exe\shell\open\command
Reg HKLM\SOFTWARE\Classes\Applications\Poseidon for UML.exe\shell\open\command@ "C:\Programmi\PoseidonCE2\Poseidon for UML.exe" "%1"
Reg HKLM\SOFTWARE\Classes\CLSID\{119F01C5-E62B-11d2-AB3E-00C04FA3014E}\PersistentHandler@ {098f2470-bae0-11cd-b579-08002b30bfeb}
Reg HKLM\SOFTWARE\Classes\MSWC.PageCounter\CLSID@ {EF88CA72-B840-11D0-8B40-00C0F00AE35A}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\Desktop@Upgrade 1
Reg HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop
Reg HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop@Mode 1
Reg HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop@ScrollPos1024x768(1).x 0
Reg HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop@ScrollPos1024x768(1).y 0
Reg HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop@Sort 0
Reg HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop@SortDir 1
Reg HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop@Col 0
Reg HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop@ColInfo 0x00 0x00 0x00 0x00 ...
Reg HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop@FFlags 548
Reg HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop@ScrollPos800x600(1).x 0
Reg HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop@ScrollPos800x600(1).y 0
Reg HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop@ItemPos1024x768(1) 0x00 0x00 0x00 0x00 ...
Reg HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop@ItemPos800x600(1) 0x00 0x00 0x00 0x00 ...
Reg HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop@ScrollPos1152x864(1).x 0
Reg HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop@ScrollPos1152x864(1).y 0
Reg HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop@ItemPos1152x864(1) 0x00 0x00 0x00 0x00 ...
Reg HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop@ScrollPos640x480(1).x 0
Reg HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop@ScrollPos640x480(1).y 0
Reg HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop@ItemPos640x480(1) 0x00 0x00 0x00 0x00 ...
---- EOF - GMER 1.0.15 ----