When I ran GMER I got the following message: LoadDriver(C:\Docume 1\Temp\uxtyrpog.sys") error 0xC000026C: Cannot create a stable subkey under a volatile parent key. I hit ok and it went to the GMER screen. Services, Registry, and Files are checked. Anything above them are lightened so they can't be checked. Here are my results:
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-09-20 17:29:37
Windows 5.1.2600 Service Pack 3
Running: gmer.exe
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-09-20 17:29:37
Windows 5.1.2600 Service Pack 3
Running: gmer.exe
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\tlntsvr.exe (*** hidden *** ) [DISABLED] TlntSvr <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys@start 1
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys@type 1
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys@imagepath \systemroot\system32\drivers\UACqlxmujew.sys
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys@group file system
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules@UACd \\?\globalroot\systemroot\system32\drivers\UACqlxmujew.sys
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules@UACc \\?\globalroot\systemroot\system32\UACwsowvvvr.dll
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules@UACsr \\?\globalroot\systemroot\system32\UACvmpkkbib.dat
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules@uaclog \\?\globalroot\systemroot\system32\UAChrmobwut.dll
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules@uacmask \\?\globalroot\systemroot\system32\UACfujdpkos.dll
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules@uacserf \\?\globalroot\systemroot\system32\UACsfodjkwb.dll
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules@uacbbr \\?\globalroot\systemroot\system32\UACivkdqxyx.dll
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules@UACproc \\?\globalroot\systemroot\system32\UACirptaxyx.log
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules@uacurls \\?\globalroot\systemroot\system32\UACgioylvmp.log
Reg HKLM\SYSTEM\ControlSet001\Services\UACd.sys\modules@uacerrors \\?\globalroot\systemroot\system32\UACmiitltmo.log
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Environment@Path %SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;C:\Program Files\Microsoft SQL Server\80\Tools\Binn;C:\Program Files\Common Files\Roxio Shared\DLLShared;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared;C:\Program Files\Common Files\Ulead Systems\MPEG;C:\Program Files\QuickTime\QTSystem;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Intel\WiFi\bin\
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application@Sources WSH?WMIAdapter?WMI.NET Provider Extension?WmdmPmSN?WinMgmt?Winlogon?Windows Product Activation?Windows 3.1 Migration?WebClient?VzFw?VzCdbSvc?VSS?VBRuntime?VAIO_VEDB?VAIO Media Integrated Server?VAIO Media Gateway Server?Userinit?Userenv?UPnPFramework?Tlntsvr?System.ServiceModel.Install 3.0.0.0?System.ServiceModel 3.0.0.0?System.Runtime.Serialization 3.0.0.0?System.IO.Log 3.0.0.0?System.IdentityModel 3.0.0.0?SysmonLog?Starter?SQLNCLI?SQLCTR$VAIO_VEDB?SQLAgent$VAIO_VEDB?Spybot - Search & Destroy 2?SPTISRV?SpoolerCtrs?Software Restriction Policies?Software Installation?SNL HiveManager?ServiceModel Audit 3.0.0.0?SecurityCenter?SclgNtfy?SceSrv?SceCli?safrslv?SAFrdms?RPC?RIMDeviceFileAccess?Remote Assistance?Pure Networks Network Magic Service?Picasa3?PerfProc?PerfOS?PerfNet?Perfmon?Perflib?PerfDisk?Perfctrs?Outlook?Offline Files?Oakley?ntbackup?NDP1.1sp1-KB979906-X86?NDP1.1sp1-KB953297-X86?MSSQLServerADHelper?MSSQLSERVER/MSDE?MSSOAP?MSSHA?MsiInstaller?MSDTC Client?MSDTC?MSDMine?mnmsrvc?Microsoft.Transactions.Brid
Reg HKLM\SYSTEM\CurrentControlSet\Services\HidServ\Parameters@ServiceDll %SystemRoot%\System32\hidserv.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch@Epoch 12680
Reg HKLM\SYSTEM\CurrentControlSet\Services\TlntSvr@Start 4
Reg HKLM\SYSTEM\ControlSet003\Control\Lsa@LsaPid 940
Reg HKLM\SYSTEM\ControlSet003\Control\Session Manager\Memory Management\PrefetchParameters@VideoInitTime 1203
Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0F652739-C0B4-4FEC-A050-5E79FA82D90C}@LeaseObtainedTime 1285000404
Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0F652739-C0B4-4FEC-A050-5E79FA82D90C}@T1 1285043604
Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0F652739-C0B4-4FEC-A050-5E79FA82D90C}@T2 1285076004
Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0F652739-C0B4-4FEC-A050-5E79FA82D90C}@LeaseTerminatesTime 1285086804
Reg HKLM\SYSTEM\ControlSet003\Services\{0F652739-C0B4-4FEC-A050-5E79FA82D90C}\Parameters\Tcpip@LeaseObtainedTime 1285000404
Reg HKLM\SYSTEM\ControlSet003\Services\{0F652739-C0B4-4FEC-A050-5E79FA82D90C}\Parameters\Tcpip@T1 1285043604
Reg HKLM\SYSTEM\ControlSet003\Services\{0F652739-C0B4-4FEC-A050-5E79FA82D90C}\Parameters\Tcpip@T2 1285076004
Reg HKLM\SYSTEM\ControlSet003\Services\{0F652739-C0B4-4FEC-A050-5E79FA82D90C}\Parameters\Tcpip@LeaseTerminatesTime 1285086804
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\Machine\Extension-List\{00000000-0000-0000-0000-000000000000}@StartTimeLo -1904950538
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\Machine\Extension-List\{00000000-0000-0000-0000-000000000000}@StartTimeHi 30103777
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\Machine\Extension-List\{00000000-0000-0000-0000-000000000000}@EndTimeLo -1904950538
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\Machine\Extension-List\{00000000-0000-0000-0000-000000000000}@EndTimeHi 30103777
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\S-1-5-21-3970022178-3845494283-2875992790-1005\Extension-List\{00000000-0000-0000-0000-000000000000}@StartTimeLo -1904950538
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\S-1-5-21-3970022178-3845494283-2875992790-1005\Extension-List\{00000000-0000-0000-0000-000000000000}@StartTimeHi 30103777
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\S-1-5-21-3970022178-3845494283-2875992790-1005\Extension-List\{00000000-0000-0000-0000-000000000000}@EndTimeLo -1904950538
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group Policy\State\S-1-5-21-3970022178-3845494283-2875992790-1005\Extension-List\{00000000-0000-0000-0000-000000000000}@EndTimeHi 30103777
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\82AB3363EC768CA46A774360AC483C8D\Usage@MSWM 1026818133
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8BCCDB238CD9d694D91B7F570177B5BD\Usage@IntentConfig 1026822297
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony@Perf1 1346720335
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update@NextDetectionTime 2010-09-20 14:10:36
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update@ScheduledInstallDate 2010-09-20 06:00:00
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update@NextSqmReportTime 2010-09-20 14:10:36
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update@UnableToDetectTime 2010-09-18 12:58:59
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Detect@LastError -2145107924
Reg HKLM\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{7185F29F-FB52-44FA-BCF0-87134EDD179F}
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher@StartTime 2010/09/20-12:33:19
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher@TracesProcessed 14
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher@TracesSuccessful 12
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher@ExitTime 2010/09/18-10:01:01
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19@ProfileLoadTimeLow -2002138038
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19@ProfileLoadTimeHigh 30103777
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19@RefCount 3
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20@ProfileLoadTimeLow -2012606788
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20@ProfileLoadTimeHigh 30103777
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3970022178-3845494283-2875992790-1005@ProfileLoadTimeLow -1997138038
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3970022178-3845494283-2875992790-1005@ProfileLoadTimeHigh 30103777
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Classes\.com@ ComFile
Reg HKLM\SOFTWARE\Classes\CLSID\{00000507-0000-0010-8000-00AA006D2EA4}\InprocServer32@ThreadingModel Both
Reg HKLM\SOFTWARE\Classes\CLSID\{0000050B-0000-0010-8000-00AA006D2EA4}\InprocServer32@ThreadingModel Both
Reg HKLM\SOFTWARE\Classes\CLSID\{00000535-0000-0010-8000-00AA006D2EA4}\InprocServer32@ThreadingModel Both
Reg HKLM\SOFTWARE\Classes\CLSID\{00000541-0000-0010-8000-00AA006D2EA4}\InprocServer32@ThreadingModel Both
Reg HKLM\SOFTWARE\Classes\telnet\shell\open\command@ "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\url.dll",TelnetProtocolHandler %l
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer@CleanShutdown 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}\iexplore@Count 278
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0B83C99C-1EFA-4259-858F-BCB33E007A5B}\iexplore@Count 92
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0B83C99C-1EFA-4259-858F-BCB33E007A5B}\iexplore@Blocked 92
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore@Count 39
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore@LoadTime 94
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3369AF0D-62E9-4BDA-8103-B4C75499B578}\iexplore@Count 92
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3369AF0D-62E9-4BDA-8103-B4C75499B578}\iexplore@Blocked 92
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29}\iexplore@Count 380
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29}\iexplore@Blocked 380
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22}\iexplore@Count 278
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{61539ECD-CC67-4437-A03C-9AACCBD14326}\iexplore@Count 102
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{61539ECD-CC67-4437-A03C-9AACCBD14326}\iexplore@Blocked 102
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{92780B25-18CC-41C8-B9BE-3C9C571A8263}\iexplore@Count 92
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{92780B25-18CC-41C8-B9BE-3C9C571A8263}\iexplore@Blocked 92
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore@Count 93
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore@Blocked 93
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DE9C389F-3316-41A7-809B-AA305ED9D922}\iexplore@Count 102
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DE9C389F-3316-41A7-809B-AA305ED9D922}\iexplore@Blocked 102
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}\iexplore@Count 93
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}\iexplore@Blocked 93
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\iexplore@Count 123
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FB5F1910-F110-11D2-BB9E-00C04F795683}\iexplore@Count 92
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FB5F1910-F110-11D2-BB9E-00C04F795683}\iexplore@Blocked 92
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010091820100919
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010091820100919@CachePath %USERPROFILE%\Local Settings\History\History.IE5\MSHist012010091820100919
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010091820100919@CachePrefix :2010091820100919:
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010091820100919@CacheLimit 8192
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010091820100919@CacheOptions 11
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010091820100919@CacheRepair 0
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010091920100920
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010091920100920@CachePath %USERPROFILE%\Local Settings\History\History.IE5\MSHist012010091920100920
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010091920100920@CachePrefix :2010091920100920:
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010091920100920@CacheLimit 8192
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010091920100920@CacheOptions 11
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012010091920100920@CacheRepair 0
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer@NoDriveTypeAutoRun 36
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce@SYMNRT C:\Program Files\Internet Explorer\iexplore.exe
http://www.symantec....000033.000001f9
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1\Shell@WinPos1280x800(1).top 219
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1\Shell@WinPos1280x800(1).bottom 819
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\144\Shell@WinPos1280x800(1).left 88
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\144\Shell@WinPos1280x800(1).top 116
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\144\Shell@WinPos1280x800(1).right 888
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\144\Shell@WinPos1280x800(1).bottom 716
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\144\Shell@Rev 0
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\144\Shell@FFlags 1
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\159\Shell@WinPos1280x800(1).left 177
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\159\Shell@WinPos1280x800(1).top 166
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\159\Shell@WinPos1280x800(1).right 977
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\159\Shell@WinPos1280x800(1).bottom 766
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\2\Shell@WinPos1280x800(1).left -2
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\2\Shell@WinPos1280x800(1).top 60
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\2\Shell@WinPos1280x800(1).right 798
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\2\Shell@WinPos1280x800(1).bottom 660
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\28\Shell@WinPos1280x800(1).left 5
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\28\Shell@WinPos1280x800(1).top -20
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\28\Shell@WinPos1280x800(1).right 805
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\28\Shell@WinPos1280x800(1).bottom 580
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\28\Shell@ScrollPos1280x800(1).y 962
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\334\Shell@WinPos1280x800(1).left 168
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\334\Shell@WinPos1280x800(1).right 968
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\34\Shell@WinPos1280x800(1).left -2
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\34\Shell@WinPos1280x800(1).top 60
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\34\Shell@WinPos1280x800(1).right 798
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\34\Shell@WinPos1280x800(1).bottom 660
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\344\Shell@WinPos1280x800(1).left 168
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\344\Shell@WinPos1280x800(1).right 968
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\358\Shell@WinPos1280x800(1).left 44
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\358\Shell@WinPos1280x800(1).top 58
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\358\Shell@WinPos1280x800(1).right 844
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\358\Shell@WinPos1280x800(1).bottom 658
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\358\Shell@Rev 0
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\358\Shell@FFlags 1
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\43\Shell@WinPos1280x800(1).left -2
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\43\Shell@WinPos1280x800(1).top 60
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\43\Shell@WinPos1280x800(1).right 798
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\43\Shell@WinPos1280x800(1).bottom 660
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\69\Shell@WinPos1280x800(1).left -2
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\69\Shell@WinPos1280x800(1).top 60
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\69\Shell@WinPos1280x800(1).right 798
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\69\Shell@WinPos1280x800(1).bottom 660
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell@WinPos1280x800(1).left 5
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell@WinPos1280x800(1).top -20
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell@WinPos1280x800(1).right 805
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell@WinPos1280x800(1).bottom 580
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell@ScrollPos1280x800(1).y 962
---- EOF - GMER 1.0.15 ----