MySystem-Search MSS v1.7
Basic System Information Username: Timothy Donovan - Date: 08/06/2010 - Time: 2:19:27
Microsoft Windows XP [Version 5.1.2600]
Processor type: x86 Family 15 Model 4 Stepping 4, GenuineIntel
Total processors: 2
Computer Name: HOMECOMPUTER
Logon Server: \\HOMECOMPUTER
CD Emulation Drivers running? Peer-to-Peer applications? Napster found!
Security Tools Check CCleaner
Malwarebytes' Anti-Malware
ComboFix
F-Secure BlackLight
GMER Stealth MBR Rootkit Detector
AVZ
Win32KDiag
Dr Web CureIt
System Repair Engineer (SRENG)
Bootkit Remover
File associations .exe=exefile
.scr=scrfile
.pif=piffile
.com=ComFile
.bat=batfile
.cmd=cmdfile
.log=txtfile
.txt=txtfile
.reg=regfile
.sys=sysfile
.dll=dllfile
.ini=inifile
.inf=inffile
Running processes PROCESS PID PRIO PATH
smss.exe 1000 Normal C:\WINDOWS\System32\smss.exe
csrss.exe 1076 Normal C:\WINDOWS\system32\csrss.exe
winlogon.exe 1100 High C:\WINDOWS\system32\winlogon.exe
services.exe 1148 Normal C:\WINDOWS\system32\services.exe
lsass.exe 1160 Normal C:\WINDOWS\system32\lsass.exe
AOLacsd.exe 1560 Normal C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
AppleMobileDeviceService.exe 1572 Normal C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
mDNSResponder.exe 1584 Normal C:\Program Files\Bonjour\mDNSResponder.exe
CTsvcCDA.EXE 1624 Normal C:\WINDOWS\system32\CTsvcCDA.EXE
IntuitUpdateService.exe 1672 Normal C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
ITMRTSVC.exe 1860 Normal C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
jqs.exe 1876 Idle C:\Program Files\Java\jre6\bin\jqs.exe
mfevtps.exe 1904 Normal C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
sqlservr.exe 1932 Normal C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
nvsvc32.exe 1968 Normal C:\WINDOWS\system32\nvsvc32.exe
sprtsvc.exe 1980 Normal C:\Program Files\Dell Support Center\bin\sprtsvc.exe
wanmpsvc.exe 2004 Normal C:\WINDOWS\wanmpsvc.exe
mcshield.exe 2040 Normal C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
mfefire.exe 260 Normal C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
Explorer.EXE 428 Normal C:\WINDOWS\Explorer.EXE
CTHELPER.EXE 952 Normal C:\WINDOWS\CTHELPER.EXE
IntelMEM.exe 972 Normal C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
DVDLauncher.exe 996 Normal C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
CTDVDDET.EXE 1024 Normal C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
VolPanel.exe 1028 Normal C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
DLLML.exe 1036 Normal C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
tfswctrl.exe 1068 Normal C:\WINDOWS\system32\dla\tfswctrl.exe
issch.exe 1056 Normal C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
DMXLauncher.exe 1228 Normal C:\Program Files\Dell\Media Experience\DMXLauncher.exe
mm_tray.exe 1692 Normal C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
MediaDetect.exe 984 Normal C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
AOLSP Scheduler.exe 1848 Normal C:\Program Files\Common Files\AOL\1144616972\ee\services\safetyCore\ver210_5_2_1\AOLSP Scheduler.exe
GoogleDesktop.exe 264 Normal C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
sprtcmd.exe 292 Normal C:\Program Files\Bellsouth\HelpCenter\bin\sprtcmd.exe
sprtcmd.exe 364 Normal C:\Program Files\Dell Support Center\bin\sprtcmd.exe
jusched.exe 480 Normal C:\Program Files\Java\jre6\bin\jusched.exe
mcagent.exe 524 Normal C:\Program Files\McAfee.com\Agent\mcagent.exe
DSAgnt.exe 460 Below Normal C:\Program Files\DellSupport\DSAgnt.exe
SSScheduler.exe 848 Normal C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
pnagent.exe 208 Normal C:\Program Files\Citrix\ICA Client\pnagent.exe
mss.exe 3052 Normal I:\mss.exe
cmd.exe 3076 Normal C:\WINDOWS\system32\cmd.exe
pv.exe 3112 Normal I:\pv.exe
User Profile check ! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
ProfilesDirectory REG_EXPAND_SZ %SystemDrive%\Documents and Settings
DefaultUserProfile REG_SZ Default User
AllUsersProfile REG_SZ All Users
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
Flags REG_DWORD 0xc
State REG_DWORD 0x0
RefCount REG_DWORD 0x1
Sid REG_BINARY 010100000000000512000000
ProfileImagePath REG_EXPAND_SZ %systemroot%\system32\config\systemprofile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\LocalService
Sid REG_BINARY 010100000000000513000000
Flags REG_DWORD 0x9
State REG_DWORD 0x0
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0x944018ec
ProfileLoadTimeHigh REG_DWORD 0x1cb352e
RefCount REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\NetworkService
Sid REG_BINARY 010100000000000514000000
Flags REG_DWORD 0x9
State REG_DWORD 0x0
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0x4f5a63d0
ProfileLoadTimeHigh REG_DWORD 0x1cb352f
RefCount REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2213691641-1270660180-3033463972-1007
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\Paul Donovan
Sid REG_BINARY 010500000000000515000000F940F28354BCBC4
BA4FCCEB4EF030000
Flags REG_DWORD 0x0
State REG_DWORD 0x100
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0x7bc0e980
ProfileLoadTimeHigh REG_DWORD 0x1cb1941
RefCount REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
OptimizedLogonStatus REG_DWORD 0xb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2213691641-1270660180-3033463972-1008
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\Susan Donovan
Sid REG_BINARY 010500000000000515000000F940F28354BCBC4
BA4FCCEB4F0030000
Flags REG_DWORD 0x0
State REG_DWORD 0x100
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0x3665f8ea
ProfileLoadTimeHigh REG_DWORD 0x1cb0fb3
RefCount REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
OptimizedLogonStatus REG_DWORD 0xb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2213691641-1270660180-3033463972-1009
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\Kendra Donovan
Sid REG_BINARY 010500000000000515000000F940F28354BCBC4
BA4FCCEB4F1030000
Flags REG_DWORD 0x0
State REG_DWORD 0x100
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0x34423b66
ProfileLoadTimeHigh REG_DWORD 0x1cac2bd
RefCount REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
OptimizedLogonStatus REG_DWORD 0xb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2213691641-1270660180-3033463972-1010
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\Timothy Donovan
Sid REG_BINARY 010500000000000515000000F940F28354BCBC4
BA4FCCEB4F2030000
Flags REG_DWORD 0x0
State REG_DWORD 0x100
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0x9f790a8e
ProfileLoadTimeHigh REG_DWORD 0x1cb352e
RefCount REG_DWORD 0x1
RunLogonScriptSync REG_DWORD 0x0
OptimizedLogonStatus REG_DWORD 0xb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2213691641-1270660180-3033463972-1011
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\Stefani Donovan
Sid REG_BINARY 010500000000000515000000F940F28354BCBC4
BA4FCCEB4F3030000
Flags REG_DWORD 0x0
State REG_DWORD 0x100
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0xf2e5c196
ProfileLoadTimeHigh REG_DWORD 0x1cae720
RefCount REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
OptimizedLogonStatus REG_DWORD 0xb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2213691641-1270660180-3033463972-500
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\Administrator
Sid REG_BINARY 010500000000000515000000F940F28354BCBC4
BA4FCCEB4F4010000
Flags REG_DWORD 0x0
State REG_DWORD 0x100
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0x2869acb8
ProfileLoadTimeHigh REG_DWORD 0x1cb1e05
RefCount REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
OptimizedLogonStatus REG_DWORD 0xb
Current Scheduled Tasks PATH: C:\Windows\Tasks
AppleSoftwareUpdate.job
Disk Cleanup.job
Google Software Updater.job
GoogleUpdateTaskMachineCore.job
GoogleUpdateTaskMachineUA.job
Norton Security Scan for Timothy Donovan.job
desktop.ini
MP Scheduled Scan.job
SA.DAT
Windows Drivers and NT-Services Volume in drive C has no label.
Volume Serial Number is 1049-3C69
Directory of C:\Windows\System32\Drivers
Volume in drive C has no label.
Volume Serial Number is 1049-3C69
Directory of C:\Windows\System32\Drivers
11/02/2000 01:10 AM 164,180 windrvr.sys
08/17/2001 02:12 PM 117,760 e100b325.sys
08/17/2001 02:47 PM 23,808 Dot4usb.sys
08/17/2001 02:47 PM 8,704 Dot4scan.sys
08/17/2001 02:47 PM 12,928 Dot4Prt.sys
08/17/2001 02:48 PM 12,160 mouhid.sys
08/17/2001 03:46 PM 6,400 enum1394.sys
08/17/2001 03:51 PM 3,328 pciide.sys
08/17/2001 03:51 PM 6,656 cmdide.sys
08/17/2001 03:51 PM 4,992 toside.sys
08/17/2001 03:51 PM 5,248 aliide.sys
08/17/2001 03:51 PM 14,848 asc3550.sys
08/17/2001 03:52 PM 23,552 ABP480N5.SYS
08/17/2001 03:52 PM 26,496 asc.sys
08/17/2001 03:52 PM 12,800 aha154x.sys
08/17/2001 03:52 PM 22,400 asc3350p.sys
08/17/2001 03:52 PM 12,032 amsint.sys
08/17/2001 03:52 PM 7,680 cd20xrnt.sys
08/17/2001 03:52 PM 14,976 cpqarray.sys
08/17/2001 03:52 PM 16,000 ini910u.sys
08/17/2001 03:52 PM 13,952 cbidf2k.sys
08/17/2001 03:52 PM 17,280 mraid35x.sys
08/17/2001 03:52 PM 14,720 dac960nt.sys
08/17/2001 03:52 PM 179,584 dac2w2k.sys
08/17/2001 03:52 PM 33,152 ql10wnt.sys
08/17/2001 03:52 PM 40,448 ql1240.sys
08/17/2001 03:52 PM 49,024 ql1280.sys
08/17/2001 03:52 PM 40,320 ql1080.sys
08/17/2001 03:52 PM 45,312 ql12160.sys
08/17/2001 03:52 PM 36,736 ultra.sys
08/17/2001 03:52 PM 125,056 ftdisk.sys
08/17/2001 03:57 PM 16,128 MODEMCSA.sys
08/17/2001 03:59 PM 3,072 audstub.sys
08/17/2001 04:07 PM 101,888 adpu160m.sys
08/17/2001 04:07 PM 16,256 symc810.sys
08/17/2001 04:07 PM 55,168 aic78u2.sys
08/17/2001 04:07 PM 32,640 symc8xx.sys
08/17/2001 04:07 PM 56,960 aic78xx.sys
08/17/2001 04:07 PM 27,296 perc2.sys
08/17/2001 04:07 PM 28,384 sym_hi.sys
08/17/2001 04:07 PM 5,504 perc2hib.sys
08/17/2001 04:07 PM 30,688 sym_u3.sys
08/17/2001 04:07 PM 25,952 hpn.sys
08/17/2001 04:07 PM 20,192 dpti2o.sys
08/17/2001 04:07 PM 19,072 sparrow.sys
05/24/2002 02:33 AM 16,016 hpoipr07.sys
12/30/2002 06:53 PM 12,160 CTGAME.SYS
01/10/2003 05:13 PM 33,588 wanatw4.sys
03/06/2004 06:13 AM 37,048 mohfilt.sys
03/06/2004 06:14 AM 1,233,525 IntelC51.sys
03/06/2004 06:15 AM 647,929 IntelC52.sys
06/16/2004 05:52 AM 61,157 IntelC53.sys
07/14/2004 01:28 PM 23,545 ssrtln.sys
07/14/2004 01:29 PM 5,627 sscdbhk5.sys
07/17/2004 11:35 AM 67,866 netwlan5.img
07/17/2004 11:36 AM 64,352 ativmc20.cod
07/17/2004 10:55 PM 129,045 cxthsfs2.cty
08/03/2004 10:29 PM 701,440 ati2mtag.sys
08/03/2004 10:29 PM 57,856 atinbtxx.sys
08/03/2004 10:29 PM 327,040 ati2mtaa.sys
08/03/2004 10:29 PM 52,224 atinraxx.sys
08/03/2004 10:29 PM 14,336 atinpdxx.sys
08/03/2004 10:29 PM 13,824 atinmdxx.sys
08/03/2004 10:29 PM 56,623 ati1btxx.sys
08/03/2004 10:29 PM 12,047 ati1pdxx.sys
08/03/2004 10:29 PM 11,615 ati1mdxx.sys
08/03/2004 10:29 PM 13,824 atinttxx.sys
08/03/2004 10:29 PM 30,671 ati1raxx.sys
08/03/2004 10:29 PM 104,960 atinrvxx.sys
08/03/2004 10:29 PM 63,663 ati1rvxx.sys
08/03/2004 10:29 PM 36,463 ati1tuxx.sys
08/03/2004 10:29 PM 29,455 ati1xbxx.sys
08/03/2004 10:29 PM 63,488 atinxsxx.sys
08/03/2004 10:29 PM 31,744 atinxbxx.sys
08/03/2004 10:29 PM 26,367 ati1snxx.sys
08/03/2004 10:29 PM 28,672 atinsnxx.sys
08/03/2004 10:29 PM 21,343 ati1ttxx.sys
08/03/2004 10:29 PM 34,735 ati1xsxx.sys
08/03/2004 10:29 PM 73,216 atintuxx.sys
08/03/2004 10:29 PM 452,736 mtxparhm.sys
08/03/2004 10:29 PM 11,807 wadv07nt.sys
08/03/2004 10:29 PM 11,295 wadv08nt.sys
08/03/2004 10:29 PM 11,935 wadv11nt.sys
08/03/2004 10:29 PM 11,871 wadv09nt.sys
08/03/2004 10:29 PM 22,271 watv06nt.sys
08/03/2004 10:29 PM 25,471 watv10nt.sys
08/03/2004 10:29 PM 166,912 s3gnbm.sys
08/03/2004 10:41 PM 1,309,184 mtlstrm.sys
08/03/2004 10:41 PM 126,686 mtlmnt5.sys
08/03/2004 10:41 PM 13,776 recagent.sys
08/03/2004 10:41 PM 180,360 ntmtlfax.sys
08/03/2004 10:41 PM 129,535 slnt7554.sys
08/03/2004 10:41 PM 404,990 slntamr.sys
08/03/2004 10:41 PM 95,424 slnthal.sys
08/03/2004 10:41 PM 13,240 slwdmsup.sys
08/03/2004 10:41 PM 220,032 hsfbs2s2.sys
08/03/2004 10:41 PM 685,056 hsfcxts2.sys
08/03/2004 10:41 PM 11,868 mdmxsdk.sys
08/03/2004 10:41 PM 1,041,536 hsfdpsp2.sys
08/04/2004 07:00 AM 14,592 smclib.sys
08/04/2004 07:00 AM 4,224 mnmdd.sys
08/04/2004 07:00 AM 352,256 atmuni.sys
08/04/2004 07:00 AM 31,360 atmepvc.sys
08/04/2004 07:00 AM 11,776 cpqdap01.sys
08/04/2004 07:00 AM 4,736 usbd.sys
08/04/2004 07:00 AM 262,528 cinemst2.sys
08/04/2004 07:00 AM 17,792 ptilink.sys
08/04/2004 07:00 AM 6,784 parvdm.sys
08/04/2004 07:00 AM 3,456 oprghdlr.sys
08/04/2004 07:00 AM 55,936 nwlnkspx.sys
08/04/2004 07:00 AM 5,888 dmload.sys
08/04/2004 07:00 AM 63,232 nwlnknb.sys
08/04/2004 07:00 AM 32,512 nwlnkfwd.sys
08/04/2004 07:00 AM 21,376 tsbvcap.sys
08/04/2004 07:00 AM 18,688 cdaudio.sys
08/04/2004 07:00 AM 51,712 tosdvd.sys
08/04/2004 07:00 AM 4,352 wmilib.sys
08/04/2004 07:00 AM 12,416 nwlnkflt.sys
08/04/2004 07:00 AM 7,680 mcd.sys
08/04/2004 07:00 AM 8,832 rasacd.sys
08/04/2004 07:00 AM 16,512 raspti.sys
08/04/2004 07:00 AM 10,496 dxapi.sys
08/04/2004 07:00 AM 34,432 rawwan.sys
08/04/2004 07:00 AM 3,328 dxgthk.sys
08/04/2004 07:00 AM 11,648 acpiec.sys
08/04/2004 07:00 AM 4,224 rdpcdd.sys
08/04/2004 07:00 AM 12,032 rio8drv.sys
08/04/2004 07:00 AM 12,032 ws2ifsl.sys
08/04/2004 07:00 AM 4,224 beep.sys
08/04/2004 07:00 AM 12,032 riodrv.sys
08/04/2004 07:00 AM 12,032 nikedrv.sys
08/04/2004 07:00 AM 5,888 rootmdm.sys
08/04/2004 07:00 AM 646 gmreadme.txt
08/04/2004 07:00 AM 12,160 fsvga.sys
08/04/2004 07:00 AM 7,936 fs_rec.sys
08/04/2004 07:00 AM 58,112 vdmindvd.sys
08/04/2004 07:00 AM 3,440,660 gm.dls
08/04/2004 07:00 AM 2,944 null.sys
08/04/2004 07:00 AM 32,896 ipfltdrv.sys
08/11/2004 07:02 PM <DIR> disdn
09/29/2004 02:02 AM 16,752 ctpdusb2.sys
11/23/2004 04:56 AM 40,480 drvnddm.sys
12/01/2004 05:22 AM 87,488 drvmcdb.sys
12/18/2004 08:32 PM 38,229 StMp3Rec.sys
07/09/2005 01:57 AM 3,198,304 nv4_mini.sys
07/14/2005 12:18 AM 340,704 ctdvda2k.sys
07/20/2005 04:59 AM 93,440 nvatabus.sys
07/20/2005 04:59 AM 76,544 nvraid.sys
07/27/2005 12:48 AM 209,920 nvsnpu.sys
07/27/2005 12:48 AM 283,136 nvnrm.sys
07/27/2005 12:48 AM 101,120 nvtcp.sys
07/27/2005 12:48 AM 33,664 NVENETFD.sys
07/27/2005 12:48 AM 12,928 nvnetbus.sys
08/08/2005 08:54 PM 501,760 ctac32k.sys
08/08/2005 08:54 PM 77,824 emupia2k.sys
08/08/2005 08:54 PM 142,848 ctsfm2k.sys
08/08/2005 08:54 PM 114,688 ctoss2k.sys
08/08/2005 08:54 PM 751,104 ha10kx2k.sys
08/08/2005 08:54 PM 178,688 haP17v2k.sys
08/08/2005 08:54 PM 153,088 haP16v2k.sys
08/08/2005 08:54 PM 1,093,632 ha20x2k.sys
08/08/2005 08:54 PM 439,424 ctaud2k.sys
08/08/2005 08:54 PM 7,168 ctprxy2k.sys
08/08/2005 09:15 PM 9,216 pfmodnt.sys
10/07/2005 07:58 PM 44,224 BVRPMPR5.SYS
12/13/2005 08:09 AM 6,552 1028_Dell_XPS_600.mrk
09/28/2006 06:55 PM 77,568 WudfPf.sys
09/28/2006 07:00 PM 82,944 WudfRd.sys
10/18/2006 03:00 AM 2,432 cdr4_xp.sys
10/18/2006 03:00 AM 2,560 cdralw2k.sys
10/18/2006 08:00 PM 38,528 wpdusb.sys
05/19/2007 11:04 PM <DIR> UMDF
10/11/2007 07:20 AM 24,960 atwpkt2.sys
10/11/2007 07:20 AM 33,384 atwpkt264.sys
11/13/2007 06:25 AM 20,480 secdrv.sys
04/13/2008 12:36 PM 144,384 hdaudbus.sys
04/13/2008 12:39 PM 142,592 aec.sys
04/13/2008 01:40 PM 36,352 disk.sys
04/13/2008 01:45 PM 26,368 USBSTOR.SYS
04/13/2008 02:31 PM 35,840 processr.sys
04/13/2008 02:31 PM 42,752 p3.sys
04/13/2008 02:31 PM 37,376 amdk6.sys
04/13/2008 02:31 PM 36,352 intelppm.sys
04/13/2008 02:31 PM 36,736 crusoe.sys
04/13/2008 02:31 PM 37,760 amdk7.sys
04/13/2008 02:32 PM 66,048 udfs.sys
04/13/2008 02:32 PM 19,072 msfs.sys
04/13/2008 02:32 PM 30,848 npfs.sys
04/13/2008 02:32 PM 180,608 mrxdav.sys
04/13/2008 02:32 PM 196,224 rdpdr.sys
04/13/2008 02:32 PM 129,792 fltmgr.sys
04/13/2008 02:33 PM 44,544 fips.sys
04/13/2008 02:34 PM 163,584 nwrdr.sys
04/13/2008 02:36 PM 5,888 smbali.sys
04/13/2008 02:36 PM 187,776 acpi.sys
04/13/2008 02:36 PM 42,368 agp440.sys
04/13/2008 02:36 PM 42,752 alim1541.sys
04/13/2008 02:36 PM 40,960 sisagp.sys
04/13/2008 02:36 PM 43,008 amdagp.sys
04/13/2008 02:36 PM 44,928 agpcpq.sys
04/13/2008 02:36 PM 44,672 uagp35.sys
04/13/2008 02:36 PM 42,240 viaagp.sys
04/13/2008 02:36 PM 46,464 gagp30kx.sys
04/13/2008 02:36 PM 37,248 isapnp.sys
04/13/2008 02:36 PM 63,744 mf.sys
04/13/2008 02:36 PM 120,192 pcmcia.sys
04/13/2008 02:36 PM 68,224 pci.sys
04/13/2008 02:36 PM 79,232 sdbus.sys
04/13/2008 02:36 PM 15,488 mssmbios.sys
04/13/2008 02:36 PM 73,472 sr.sys
04/13/2008 02:38 PM 71,168 dxg.sys
04/13/2008 02:39 PM 42,368 mountmgr.sys
04/13/2008 02:39 PM 206,976 dot4.sys
04/13/2008 02:39 PM 384,768 update.sys
04/13/2008 02:39 PM 24,576 kbdclass.sys
04/13/2008 02:39 PM 23,040 mouclass.sys
04/13/2008 02:39 PM 14,592 kbdhid.sys
04/13/2008 02:39 PM 5,376 mspclock.sys
04/13/2008 02:39 PM 4,992 mspqm.sys
04/13/2008 02:39 PM 7,552 mskssrv.sys
04/13/2008 02:39 PM 4,352 swenum.sys
04/13/2008 02:40 PM 80,128 parport.sys
04/13/2008 02:40 PM 15,744 serenum.sys
04/13/2008 02:40 PM 27,392 fdc.sys
04/13/2008 02:40 PM 20,480 flpydisk.sys
04/13/2008 02:40 PM 57,600 redbook.sys
04/13/2008 02:40 PM 5,504 intelide.sys
04/13/2008 02:40 PM 24,960 pciidex.sys
04/13/2008 02:40 PM 96,384 scsiport.sys
04/13/2008 02:40 PM 96,512 atapi.sys
04/13/2008 02:40 PM 5,376 viaide.sys
04/13/2008 02:40 PM 14,208 diskdump.sys
04/13/2008 02:40 PM 62,976 cdrom.sys
04/13/2008 02:40 PM 11,008 sffp_sd.sys
04/13/2008 02:40 PM 11,904 sffdisk.sys
04/13/2008 02:40 PM 10,240 sffp_mmc.sys
04/13/2008 02:40 PM 11,392 sfloppy.sys
04/13/2008 02:40 PM 19,712 partmgr.sys
04/13/2008 02:40 PM 14,976 tape.sys
04/13/2008 02:40 PM 42,112 imapi.sys
04/13/2008 02:41 PM 52,352 volsnap.sys
04/13/2008 02:41 PM 8,576 i2omgmt.sys
04/13/2008 02:41 PM 18,560 i2omp.sys
04/13/2008 02:43 PM 14,208 wacompen.sys
04/13/2008 02:43 PM 12,672 mutohpen.sys
04/13/2008 02:44 PM 81,664 videoprt.sys
04/13/2008 02:44 PM 20,992 vga.sys
04/13/2008 02:44 PM 153,344 dmio.sys
04/13/2008 02:44 PM 799,744 dmboot.sys
04/13/2008 02:45 PM 52,864 dmusic.sys
04/13/2008 02:45 PM 6,272 splitter.sys
04/13/2008 02:45 PM 172,416 kmixer.sys
04/13/2008 02:45 PM 56,576 swmidi.sys
04/13/2008 02:45 PM 2,944 drmkaud.sys
04/13/2008 02:45 PM 60,160 drmk.sys
04/13/2008 02:45 PM 49,408 stream.sys
04/13/2008 02:45 PM 24,960 hidparse.sys
04/13/2008 02:45 PM 19,200 hidir.sys
04/13/2008 02:45 PM 36,864 hidclass.sys
04/13/2008 02:45 PM 10,368 hidusb.sys
04/13/2008 02:45 PM 15,104 usbscan.sys
04/13/2008 02:45 PM 46,592 irbus.sys
04/13/2008 02:45 PM 17,152 usbohci.sys
04/13/2008 02:45 PM 20,608 usbuhci.sys
04/13/2008 02:45 PM 30,208 usbehci.sys
04/13/2008 02:45 PM 143,872 usbport.sys
04/13/2008 02:45 PM 59,520 usbhub.sys
04/13/2008 02:45 PM 32,128 usbccgp.sys
04/13/2008 02:45 PM 25,600 usbcamd.sys
04/13/2008 02:45 PM 25,728 usbcamd2.sys
04/13/2008 02:45 PM 15,872 usbintel.sys
04/13/2008 02:46 PM 25,344 sonydcam.sys
04/13/2008 02:46 PM 53,376 1394bus.sys
04/13/2008 02:46 PM 61,696 ohci1394.sys
04/13/2008 02:46 PM 121,984 usbvideo.sys
04/13/2008 02:46 PM 18,944 bthusb.sys
04/13/2008 02:46 PM 25,600 hidbth.sys
04/13/2008 02:46 PM 36,480 bthprint.sys
04/13/2008 02:46 PM 59,136 rfcomm.sys
04/13/2008 02:46 PM 17,024 bthenum.sys
04/13/2008 02:46 PM 37,888 bthmodem.sys
04/13/2008 02:51 PM 59,904 atmarpc.sys
04/13/2008 02:51 PM 60,800 arp1394.sys
04/13/2008 02:51 PM 61,824 nic1394.sys
04/13/2008 02:51 PM 55,808 atmlane.sys
04/13/2008 02:51 PM 101,120 bthpan.sys
04/13/2008 02:53 PM 40,320 nmnt.sys
04/13/2008 02:53 PM 71,552 bridge.sys
04/13/2008 02:53 PM 36,608 ip6fw.sys
04/13/2008 02:54 PM 11,264 irenum.sys
04/13/2008 02:55 PM 14,592 ndisuio.sys
04/13/2008 02:56 PM 12,288 tunmp.sys
04/13/2008 02:56 PM 34,688 netbios.sys
04/13/2008 02:56 PM 88,320 nwlnkipx.sys
04/13/2008 02:56 PM 35,072 msgpc.sys
04/13/2008 02:56 PM 69,120 psched.sys
04/13/2008 02:56 PM 30,592 rndismpx.sys
04/13/2008 02:56 PM 30,592 rndismp.sys
04/13/2008 02:56 PM 12,800 usb8023x.sys
04/13/2008 02:56 PM 12,800 usb8023.sys
04/13/2008 02:57 PM 20,864 ipinip.sys
04/13/2008 02:57 PM 152,832 ipnat.sys
04/13/2008 02:57 PM 34,560 wanarp.sys
04/13/2008 02:57 PM 14,336 asyncmac.sys
04/13/2008 02:57 PM 10,112 ndistapi.sys
04/13/2008 02:57 PM 40,576 ndproxy.sys
04/13/2008 02:57 PM 41,472 raspppoe.sys
04/13/2008 03:00 PM 19,072 tdi.sys
04/13/2008 03:00 PM 30,080 modem.sys
04/13/2008 03:14 PM 63,744 cdfs.sys
04/13/2008 03:14 PM 143,744 fastfat.sys
04/13/2008 03:15 PM 64,512 serial.sys
04/13/2008 03:15 PM 574,976 ntfs.sys
04/13/2008 03:15 PM 60,800 sysaudio.sys
04/13/2008 03:16 PM 49,536 classpnp.sys
04/13/2008 03:16 PM 141,056 ks.sys
04/13/2008 03:17 PM 105,344 mup.sys
04/13/2008 03:17 PM 83,072 wdmaud.sys
04/13/2008 03:18 PM 52,480 i8042prt.sys
04/13/2008 03:19 PM 146,048 portcls.sys
04/13/2008 03:19 PM 75,264 ipsec.sys
04/13/2008 03:19 PM 51,328 rasl2tp.sys
04/13/2008 03:19 PM 48,384 raspptp.sys
04/13/2008 03:20 PM 182,656 ndis.sys
04/13/2008 03:20 PM 91,520 ndiswan.sys
04/13/2008 03:21 PM 162,816 netbt.sys
04/13/2008 03:28 PM 175,744 rdbss.sys
04/13/2008 08:11 PM 3,135 adv08nt5.dll
04/13/2008 08:11 PM 3,775 adv11nt5.dll
04/13/2008 08:11 PM 3,711 adv09nt5.dll
04/13/2008 08:11 PM 3,967 adv02nt5.dll
04/13/2008 08:11 PM 3,647 adv07nt5.dll
04/13/2008 08:11 PM 4,255 adv01nt5.dll
04/13/2008 08:11 PM 3,615 adv05nt5.dll
04/13/2008 08:11 PM 11,359 atv02nt5.dll
04/13/2008 08:11 PM 15,423 ch7xxnt5.dll
04/13/2008 08:11 PM 14,143 atv06nt5.dll
04/13/2008 08:11 PM 25,471 atv04nt5.dll
04/13/2008 08:11 PM 17,279 atv10nt5.dll
04/13/2008 08:11 PM 21,183 atv01nt5.dll
04/13/2008 08:12 PM 3,901 siint5.dll
04/13/2008 08:12 PM 11,325 vchnt5.dll
04/13/2008 08:13 PM 40,840 termdd.sys
04/13/2008 08:13 PM 12,040 tdpipe.sys
04/13/2008 08:13 PM 21,896 tdtcp.sys
04/13/2008 08:13 PM 139,656 rdpwd.sys
05/08/2008 10:02 AM 203,136 rmcast.sys
06/13/2008 07:05 AM 272,128 bthport.sys
06/20/2008 07:51 AM 361,600 tcpip.sys
08/14/2008 06:04 AM 138,496 afd.sys
08/14/2008 08:57 AM 74,720 adfs.sys
11/20/2008 03:19 PM 43,872 pxhelp20.sys
05/18/2009 03:17 PM 26,600 GEARAspiWDM.sys
06/22/2009 07:48 AM 91,776 mqac.sys
06/24/2009 07:18 AM 92,928 ksecdd.sys
07/24/2009 03:02 PM <DIR> NSS
10/16/2009 02:33 AM 41,472 usbaapl.sys
10/20/2009 12:20 PM 265,728 http.sys
11/04/2009 05:53 PM 34,248 mferkdk.sys
11/04/2009 05:54 PM 40,552 mfesmfk.sys
12/03/2009 05:13 PM 19,160 mbam.sys
12/03/2009 05:14 PM 38,224 mbamswissarmy.sys
12/31/2009 12:50 PM 353,792 srv.sys
01/05/2010 06:04 PM 55,456 cfwids.sys
01/05/2010 06:04 PM 83,496 mferkdet.sys
01/05/2010 06:04 PM 312,584 mfefirek.sys
01/05/2010 06:04 PM 152,320 mfeavfk.sys
01/05/2010 06:04 PM 385,536 mfehidk.sys
01/05/2010 06:04 PM 95,568 mfeapfk.sys
01/05/2010 06:04 PM 82,952 mfetdi2k.sys
01/05/2010 06:04 PM 88,480 mfendisk.sys
01/05/2010 06:04 PM 9,344 mfeclnk.sys
01/05/2010 06:04 PM 51,688 mfebopk.sys
02/11/2010 08:02 AM 226,880 tcpip6.sys
02/24/2010 09:11 AM 455,680 mrxsmb.sys
07/12/2010 12:27 PM <DIR> etc
07/28/2010 10:22 PM <DIR> .
07/28/2010 10:22 PM <DIR> ..
372 File(s) 37,961,609 bytes
6 Dir(s) 100,070,232,064 bytes free
Stealth malware? Internet Explorer ! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main
Default_Page_URL REG_SZ
http://go.microsoft.com/fwlink/?LinkId=69157 Default_Search_URL REG_SZ
http://go.microsoft.com/fwlink/?LinkId=54896 Search Page REG_SZ
http://go.microsoft.com/fwlink/?LinkId=54896 Enable_Disk_Cache REG_SZ yes
Cache_Percent_of_Disk REG_BINARY 0A000000
Delete_Temp_Files_On_Exit REG_SZ yes
Local Page REG_EXPAND_SZ %SystemRoot%\system32\blank.htm
Anchor_Visitation_Horizon REG_BINARY 01000000
Use_Async_DNS REG_SZ yes
Placeholder_Width REG_BINARY 1A000000
Placeholder_Height REG_BINARY 1A000000
Start Page REG_SZ
http://www.yahoo.com CompanyName REG_SZ Microsoft Corporation
Custom_Key REG_SZ MICROSO
Wizard_Version REG_SZ 6.0.2600.0000
FullScreen REG_SZ no
Default_Secondary_Page_URL REG_MULTI_SZ \0
Extensions Off Page REG_SZ about:NoAdd-ons
Security Risk Page REG_SZ about:SecurityRisk
Check_Associations REG_SZ yes
Search Bar REG_SZ
http://us.rd.yahoo.com/customize/ie/defaults/sb/ymj/*http://www.yahoo.com/ext/search/search.html
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\ErrorThresholds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\UrlTemplate
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
User Agent REG_SZ Mozilla/4.0 (compatible; MSIE 6.0; Win32)
IE5_UA_Backup_Flag REG_SZ 5.0
NoNetAutodial REG_DWORD 0x0
MigrateProxy REG_DWORD 0x1
EmailName REG_SZ IEUser@
AutoConfigProxy REG_SZ wininet.dll
MimeExclusionListForCache REG_SZ multipart/mixed multipart/x-mixed-replace multipart/x-byteranges
WarnOnPost REG_BINARY 01000000
UseSchannelDirectly REG_BINARY 01000000
EnableHttp1_1 REG_DWORD 0x1
PrivacyAdvanced REG_DWORD 0x0
EnableNegotiate REG_DWORD 0x1
ProxyEnable REG_DWORD 0x0
ProxyHttp1.1 REG_DWORD 0x0
SyncMode5 REG_DWORD 0x4
GlobalUserOffline REG_DWORD 0x0
PrivDiscUiShown REG_DWORD 0x1
WarnOnZoneCrossing REG_DWORD 0x1
ProxyOverride REG_SZ *.local
EnableAutodial REG_DWORD 0x0
WarnonBadCertRecving REG_DWORD 0x1
WarnOnPostRedirect REG_DWORD 0x0
WarnOnHTTPSToHTTPRedirect REG_DWORD 0x1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Passport
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Protocols
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
NoUpdateCheck REG_DWORD 0x1
NoJITSetup REG_DWORD 0x1
Disable Script Debugger REG_SZ yes
Show_ChannelBand REG_SZ No
Anchor Underline REG_SZ yes
Cache_Update_Frequency REG_SZ Once_Per_Session
Display Inline Images REG_SZ yes
Do404Search REG_BINARY 01000000
Local Page REG_SZ C:\WINDOWS\system32\blank.htm
Save_Session_History_On_Exit REG_SZ no
Show_FullURL REG_SZ no
Show_StatusBar REG_SZ yes
Show_ToolBar REG_SZ yes
Show_URLinStatusBar REG_SZ yes
Show_URLToolBar REG_SZ yes
Start Page REG_SZ
http://www.google.com/ Use_DlgBox_Colors REG_SZ yes
Search Page REG_SZ
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch Use Search Asst REG_SZ no
Use Custom Search URL REG_BINARY 01000000
FullScreen REG_SZ no
Window_Placement REG_BINARY 2C0000000200000003000000FFFFFFFFFFFFFFF
FFFFFFFFFFFFFFFFF580000003A0000006A0300
00C1020000
Error Dlg Displayed On Every Error REG_SZ no
Use FormSuggest REG_SZ no
AddToFavoritesExpanded REG_DWORD 0x0
ShowedCheckBrowser REG_SZ Yes
Check_Associations REG_SZ No
NotifyDownloadComplete REG_SZ no
CompatibilityFlags REG_DWORD 0x9
SearchMigrated REG_DWORD 0x1
RunOnceHasShown REG_DWORD 0x1
StatusBarWeb REG_DWORD 0x0
HistoryViewType REG_BINARY 08006663030000000000
HistoryTopNSitesView REG_DWORD 0x14
FormSuggest PW Ask REG_SZ no
RunOnceComplete REG_DWORD 0x1
UseClearType REG_SZ yes
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search
SearchAssistant REG_SZ
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm CustomizeSearch REG_SZ
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm CustomSearch REG_SZ
http://us.rd.yahoo.com/customize/ie/defaults/cs/ymj/*http://www.yahoo.com/ext/search/search.html
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks
{CFBFAE00-17A6-11D0-99CB-00C04FD64497} REG_SZ
{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} REG_SZ
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b0cda128-b425-4eef-a174-61a11ac5dbf8}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
{EF99BD32-C1FB-11D2-892F-0090271D4F88} REG_BINARY 00
{DE9C389F-3316-41A7-809B-AA305ED9D922} REG_SZ AOL Toolbar
{61539ecd-cc67-4437-a03c-9aaccbd14326} REG_SZ AIM Toolbar
{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} REG_SZ McAfee SiteAdvisor
{2318C2B1-4965-11d4-9B18-009027A5CD4F} REG_BINARY 00
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&AOL Toolbar Search
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Add to Google Photos Screensa&ver
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\E&xport to Microsoft Excel
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Google Sidewiki...
Security Center ! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
FirstRunDisabled REG_DWORD 0x1
UpdatesDisableNotify REG_DWORD 0x0
AntiVirusOverride REG_DWORD 0x0
FirewallOverride REG_DWORD 0x0
AntiVirusDisableNotify REG_DWORD 0x0
FirewallDisableNotify REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
EnableFirewall REG_DWORD 0x0
DoNotAllowExceptions REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe REG_SZ C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe REG_SZ C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
C:\Program Files\America Online 9.0\waol.exe REG_SZ C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0
C:\Program Files\Common Files\AOL\Loader\aolload.exe REG_SZ C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader
C:\Program Files\Common Files\AOL\1144616972\ee\aolsoftware.exe REG_SZ C:\Program Files\Common Files\AOL\1144616972\ee\aolsoftware.exe:*:Enabled:AOL Services
C:\Program Files\Common Files\AOL\1144616972\ee\aim6.exe REG_SZ C:\Program Files\Common Files\AOL\1144616972\ee\aim6.exe:*:Enabled:AIM
C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe REG_SZ C:\Program Files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:*:Enabled:AOL TopSpeed
C:\Program Files\Common Files\AOL\1144616972\ee\AOLOpenRide.exe REG_SZ C:\Program Files\Common Files\AOL\1144616972\ee\AOLOpenRide.exe:*:Enabled:AOL OpenRide
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
C:\Program Files\AOL 9.1\waol.exe REG_SZ C:\Program Files\AOL 9.1\waol.exe:*:Enabled:AOL
C:\Program Files\Common Files\AOL\System Information\sinf.exe REG_SZ C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL System Information
C:\Program Files\Sony\Media Manager for PSP\MediaManager.exe REG_SZ C:\Program Files\Sony\Media Manager for PSP\MediaManager.exe:*:Enabled:Media Manager for PSP 3.0
C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe REG_SZ C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe REG_SZ C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server
C:\Program Files\Bonjour\mDNSResponder.exe REG_SZ C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service
C:\Program Files\iTunes\iTunes.exe REG_SZ C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe REG_SZ C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe:*:Enabled:McAfee Shared Service Host