Ciao Luke,
innanzitutto grazie per la risposta e l'interesse.....
In secondo luogo una precisazione: ho fatto ciò che mi hai detto salvando i report e mi sono accorto (dall'alto della mia ignoranza in materia) che mi dà qcosa anche riguardo al disco C che è una partizione dove avevo il SO prima che un bel giorno nn mi partisse più il pc e fossi costretto a reinstallare Xp sulla partizione D! Non ho formattato iol disco C qdi c'è ancora il residuo SO che tuttavia nn mi parte più.
Tutto ciò solo per maggior chiarezza!
Incollo l'enorme quantità di roba che mi ha tirato fuori Gmer...
Grazie ancora,gufo..
GMER 1.0.12.12011 -
http://www.gmer.net
Rootkit scan 2007-01-09 16:56:57
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.12 ----
SSDT \??\D:\Documents and Settings\orli\Dati applicazioni\hidires\m_hook.sys ZwCreateFile
SSDT \??\D:\Documents and Settings\orli\Dati applicazioni\hidires\m_hook.sys ZwEnumerateKey
SSDT \??\D:\Documents and Settings\orli\Dati applicazioni\hidires\m_hook.sys ZwEnumerateValueKey
SSDT kl1.sys ZwOpenFile
SSDT \??\D:\Documents and Settings\orli\Dati applicazioni\hidires\m_hook.sys ZwQueryDirectoryFile
SSDT \??\D:\Documents and Settings\orli\Dati applicazioni\hidires\m_hook.sys ZwQueryKey
SSDT \??\D:\Documents and Settings\orli\Dati applicazioni\hidires\m_hook.sys ZwQuerySystemInformation
SYSENTER \??\D:\WINDOWS\system32:lzx32.sys F6D3CB83
Code \??\D:\WINDOWS\system32:lzx32.sys pIofCallDriver
---- Kernel code sections - GMER 1.0.12 ----
.text ntoskrnl.exe!Kei386EoiHelper + 4F5 804DFDF0 3 Bytes [ 51, 8D, 6D ]
.text tcpip.sys!IPTransmit + 10B7 F6C90CFA 6 Bytes CALL F6D3E94C \??\D:\WINDOWS\system32:lzx32.sys
.text tcpip.sys!IPTransmit + 24D9 F6C9211C 6 Bytes CALL F6D3E94C \??\D:\WINDOWS\system32:lzx32.sys
.text tcpip.sys!IPTransmit + 4662 F6C942A5 6 Bytes CALL F6D3E94C \??\D:\WINDOWS\system32:lzx32.sys
.text wanarp.sys F863A3FD 7 Bytes CALL F6D3E956 \??\D:\WINDOWS\system32:lzx32.sys
---- Processes - GMER 1.0.12 ----
Process D:\WINDOWS\system32\wintems.exe (*** hidden *** ) 196
Process D:\WINDOWS\system32\hldrrr.exe (*** hidden *** ) 1824
---- Services - GMER 1.0.12 ----
Service D:\WINDOWS\system32:lzx32.sys (*** hidden *** ) [SYSTEM] pe386 <-- ROOTKIT !!!
---- Registry - GMER 1.0.12 ----
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Documents and Settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\ 1
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdate.Resources\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdate.Resources\da.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdate.Resources\de.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdate.Resources\en.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdate.Resources\es.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdate.Resources\fi.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdate.Resources\fr.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdate.Resources\it.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdate.Resources\ja.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdate.Resources\ko.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdate.Resources\nb.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdate.Resources\nl.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdate.Resources\ru.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdate.Resources\sv.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdate.Resources\zh_CN.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdate.Resources\zh_TW.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdateFiles.Resources\da.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdateFiles.Resources\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdateFiles.Resources\de.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdateFiles.Resources\en.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdateFiles.Resources\es.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdateFiles.Resources\fi.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdateFiles.Resources\fr.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdateFiles.Resources\it.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdateFiles.Resources\ja.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdateFiles.Resources\ko.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdateFiles.Resources\nb.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdateFiles.Resources\nl.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdateFiles.Resources\ru.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdateFiles.Resources\sv.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdateFiles.Resources\zh_CN.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\SoftwareUpdateFiles.Resources\zh_TW.lproj\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Programmi\Apple Software Update\plugins\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\WINDOWS\Installer\{A50C25D7-62E9-4511-AD70-8E2DA5E79B7D}\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Documents and Settings\All Users\Dati applicazioni\Apple Computer\iTunes\SC Info\ 1
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Documents and Settings\All Users\Dati applicazioni\Apple Computer\iTunes\ 1
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@D:\Config.Msi\
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run@hldrrr D:\WINDOWS\system32\hldrrr.exe
Reg \Registry\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run@hldrrr D:\WINDOWS\system32\hldrrr.exe
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@Type 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@Start 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@ErrorControl 0
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@ImagePath \??\D:\WINDOWS\system32:lzx32.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@DisplayName Win23 lzx files loader
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@Group Base
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@ExtParam 0x7F 0xCB 0x3D 0xAD ...
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@Checked 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@Type 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@Start 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@ErrorControl 0
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@ImagePath \??\D:\WINDOWS\system32:lzx32.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@DisplayName Win23 lzx files loader
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@Group Base
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@ExtParam 0x7F 0xCB 0x3D 0xAD ...
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@Checked 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386\Security
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@Type 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@Start 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@ErrorControl 0
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@ImagePath \??\D:\WINDOWS\system32:lzx32.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@DisplayName Win23 lzx files loader
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@Group Base
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@ExtParam 0x7F 0xCB 0x3D 0xAD ...
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@Checked 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386\Enum
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@Type 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@Start 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@ErrorControl 0
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@ImagePath \??\D:\WINDOWS\system32:lzx32.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@DisplayName Win23 lzx files loader
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@Group Base
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@ExtParam 0x7F 0xCB 0x3D 0xAD ...
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\pe386@Checked 1
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@Type 1
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@Start 1
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@ErrorControl 0
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@ImagePath \??\D:\WINDOWS\system32:lzx32.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@DisplayName Win23 lzx files loader
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@Group Base
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@ExtParam 0x7F 0xCB 0x3D 0xAD ...
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@Checked 1
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@Type 1
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@Start 1
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@ErrorControl 0
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@ImagePath \??\D:\WINDOWS\system32:lzx32.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@DisplayName Win23 lzx files loader
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@Group Base
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@ExtParam 0x7F 0xCB 0x3D 0xAD ...
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@Checked 1
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386\Security
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@Type 1
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@Start 1
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@ErrorControl 0
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@ImagePath \??\D:\WINDOWS\system32:lzx32.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@DisplayName Win23 lzx files loader
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@Group Base
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@ExtParam 0x7F 0xCB 0x3D 0xAD ...
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\pe386@Checked 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@Type 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@Start 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@ErrorControl 0
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@ImagePath \??\D:\WINDOWS\system32:lzx32.sys
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@DisplayName Win23 lzx files loader
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@Group Base
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@ExtParam 0x7F 0xCB 0x3D 0xAD ...
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@Checked 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@Type 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@Start 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@ErrorControl 0
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@ImagePath \??\D:\WINDOWS\system32:lzx32.sys
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@DisplayName Win23 lzx files loader
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@Group Base
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@ExtParam 0x7F 0xCB 0x3D 0xAD ...
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@Checked 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386\Security
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@Type 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@Start 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@ErrorControl 0
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@ImagePath \??\D:\WINDOWS\system32:lzx32.sys
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@DisplayName Win23 lzx files loader
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@Group Base
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@ExtParam 0x7F 0xCB 0x3D 0xAD ...
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@Checked 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386\Enum
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@Type 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@Start 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@ErrorControl 0
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@ImagePath \??\D:\WINDOWS\system32:lzx32.sys
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@DisplayName Win23 lzx files loader
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@Group Base
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@ExtParam 0x7F 0xCB 0x3D 0xAD ...
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\pe386@Checked 1
Reg \Registry\USER\S-1-5-21-1085031214-651377827-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count@HRZR_EHACVQY:%pfvqy6%\Uine Fhaaluine freivmv ?abyrttvb nhgb.hey 0x13 0x00 0x00 0x00 ...
Reg \Registry\USER\S-1-5-21-1085031214-651377827-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count@HRZR_EHACVQY:%pfvqy6%\RhebZRGRB - Cerivfvbav zrgrb Uine, Pebnmvn.hey 0x13 0x00 0x00 0x00 ...
Reg \Registry\USER\S-1-5-21-1085031214-651377827-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count@HRZR_HVGBBYONE:0k1,2000 0x98 0x00 0x00 0x00 ...
Reg \Registry\USER\S-1-5-21-1085031214-651377827-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count@HRZR_HVGBBYONE:0k4,2000 0x98 0x00 0x00 0x00 ...
Reg \Registry\USER\S-1-5-21-1085031214-651377827-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count@HRZR_EHACVQY:%pfvqy6%\qvtvgnyr greerfger obk - Qrpbqre - Xryxbb - cermmv, bssregr, bppnfvbav r fpbagv.hey 0x3E 0x00 0x00 0x00 ...
Reg \Registry\USER\S-1-5-21-1085031214-651377827-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count@HRZR_EHACVQY:%pfvqy6%\FXL Yvsr.hey 0x48 0x00 0x00 0x00 ...
Reg \Registry\USER\S-1-5-21-1085031214-651377827-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count@HRZR_EHACVQY:%pfvqy6%\Ivehfyvfg.pbz - Gebwna-Pyvpxre.Jva32.Fznyy.xw.hey 0x45 0x00 0x00 0x00 ...
Reg \Registry\USER\S-1-5-21-1085031214-651377827-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count@HRZR_EHACVQY:%pfvqy6%\Jvaqbjf Yvir Zrffratre.hey 0xB9 0x00 0x00 0x00 ...
Reg \Registry\USER\S-1-5-21-1085031214-651377827-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count@HRZR_EHACVQY:%pfvqy6%\Fcrrqgrfg - Nyxra.ay Grfg lbhe vagrearg pbaarpgvba fcrrq, cnegvphyneyl hfrshy sbe grfgvat Yrnfrq Yvar, NQFY naq Pnoyr yvar fcrr.hey 0x58 0x00 0x00 0x00 ...
Reg \Registry\USER\S-1-5-21-1085031214-651377827-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count@HRZR_EHACVQY:%pfvqy6%\Xngnjro Ynibeb.hey 0x95 0x00 0x00 0x00 ...
Reg \Registry\USER\S-1-5-21-1085031214-651377827-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count@HRZR_EHACVQY:%pfvqy6%\Qverggn - Pbccn Qnivf - Eboerqb G.-Ibynaqev S. - Graavf - Fcbegvgnyvn.hey 0x51 0x00 0x00 0x00 ...
Reg \Registry\USER\S-1-5-21-1085031214-651377827-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count@HRZR_EHACVQY:%pfvqy6%\Ubzr Cntr qryyn INETNENTR.hey 0x56 0x00 0x00 0x00 ...
Reg \Registry\USER\S-1-5-21-1085031214-651377827-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count@HRZR_EHACVQY:%pfvqy6%\Vzcbffvovyr gebiner vy freire.hey