1
Removal of System Tool 2011 on Sat Dec 11, 2010 12:15 pm
jabunt

New Member
This is on a Vista machine
Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org
Database version: 5295
Windows 6.0.6002 Service Pack 2 (Safe Mode)
Internet Explorer 8.0.6001.18975
12/11/2010 10:59:51 AM
mbam-log-2010-12-11 (10-59-51).txt
Scan type: Quick scan
Objects scanned: 128890
Time elapsed: 2 minute(s), 16 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
this is the MSS FILE
MySystem-Search
MSS v1.7
Basic System Information
Username: Mom - Date: 12/11/2010 - Time: 11:04:25
Microsoft Windows [Version 6.0.6002]
Processor type: x86 Family 6 Model 22 Stepping 1, GenuineIntel
Total processors: 1
Computer Name: MOM-PC
Logon Server: \\MOM-PC
CD Emulation Drivers running?
Roxio found!
Peer-to-Peer applications?
Security Tools Check
Malwarebytes' Anti-Malware
ERUNT
File associations
.exe=exefile
.scr=scrfile
.pif=piffile
.com=comfile
.bat=batfile
.cmd=cmdfile
.log=txtfile
.txt=txtfile
.reg=regfile
.sys=sysfile
.dll=dllfile
.ini=inifile
.inf=inffile
Running processes
PROCESS PID PRIO PATH
smss.exe 348 Normal C:\Windows\System32\smss.exe
csrss.exe 408 Normal C:\Windows\system32\csrss.exe
csrss.exe 444 Normal C:\Windows\system32\csrss.exe
wininit.exe 452 High C:\Windows\system32\wininit.exe
winlogon.exe 480 High C:\Windows\system32\winlogon.exe
services.exe 524 Normal C:\Windows\system32\services.exe
lsass.exe 540 Normal C:\Windows\system32\lsass.exe
lsm.exe 548 Normal C:\Windows\system32\lsm.exe
svchost.exe 704 Normal C:\Windows\system32\svchost.exe
svchost.exe 764 Normal C:\Windows\system32\svchost.exe
svchost.exe 796 Normal C:\Windows\System32\svchost.exe
svchost.exe 880 Normal C:\Windows\System32\svchost.exe
svchost.exe 908 Normal C:\Windows\system32\svchost.exe
svchost.exe 944 Normal C:\Windows\System32\svchost.exe
svchost.exe 988 Normal C:\Windows\system32\svchost.exe
svchost.exe 1008 Normal C:\Windows\system32\svchost.exe
svchost.exe 1084 Normal C:\Windows\system32\svchost.exe
Explorer.EXE 1320 Normal C:\Windows\Explorer.EXE
svchost.exe 1404 Normal C:\Windows\system32\svchost.exe
wmpnscfg.exe 1764 Normal C:\Program Files\Windows Media Player\wmpnscfg.exe
wmiprvse.exe 1756 Normal C:\Windows\system32\wbem\wmiprvse.exe
mss.exe 1572 Normal C:\Users\Mom\Desktop\mss.exe
cmd.exe 1716 Normal C:\Windows\system32\cmd.exe
DllHost.exe 652 Normal C:\Windows\system32\DllHost.exe
pv.exe 368 Normal C:\Users\Mom\Desktop\pv.exe
User Profile check
Mom
Public
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
ProfilesDirectory REG_EXPAND_SZ %SystemDrive%\Users
Default REG_EXPAND_SZ %SystemDrive%\Users\Default
Public REG_EXPAND_SZ %SystemDrive%\Users\Public
ProgramData REG_EXPAND_SZ %SystemDrive%\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
Flags REG_DWORD 0xc
State REG_DWORD 0x0
RefCount REG_DWORD 0x1
Sid REG_BINARY 010100000000000512000000
ProfileImagePath REG_EXPAND_SZ %systemroot%\system32\config\systemprofile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19
ProfileImagePath REG_EXPAND_SZ %SystemRoot%\ServiceProfiles\LocalService
Flags REG_DWORD 0x0
State REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20
ProfileImagePath REG_EXPAND_SZ %SystemRoot%\ServiceProfiles\NetworkService
Flags REG_DWORD 0x0
State REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2944165837-3539766159-2639353112-1000
ProfileImagePath REG_EXPAND_SZ C:\Users\Mom
Flags REG_DWORD 0x0
State REG_DWORD 0x100
Sid REG_BINARY 010500000000000515000000CD677CAF8F8BFCD21855519DE8030000
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RefCount REG_DWORD 0x1
RunLogonScriptSync REG_DWORD 0x0
Current Scheduled Tasks
PATH: C:\Windows\Tasks
GoogleUpdateTaskMachineCore.job
GoogleUpdateTaskMachineUA.job
GoogleUpdateTaskUserS-1-5-21-2944165837-3539766159-2639353112-1000Core.job
GoogleUpdateTaskUserS-1-5-21-2944165837-3539766159-2639353112-1000UA.job
SCHEDLGU.TXT
Norton Security Scan for Mom.job
SA.DAT
Windows Drivers and NT-Services
Volume in drive C is OS
Volume Serial Number is EA2B-F62A
Directory of C:\Windows\System32\Drivers
10/15/2009 04:17 AM 0 Msft_User_WpdFs_01_00_00.Wdf
11/24/2009 03:17 AM 0 Msft_User_WpdFs_01_07_00.Wdf
06/26/2009 06:36 AM 0 Msft_User_WpdMtpDr_01_00_00.Wdf
11/24/2009 03:17 AM 0 Msft_User_WpdMtpDr_01_07_00.Wdf
09/09/2010 07:41 PM 0 Msft_User_WpdRapi_01_00_00.Wdf
5 File(s) 0 bytes
0 Dir(s) 175,848,452,096 bytes free
Volume in drive C is OS
Volume Serial Number is EA2B-F62A
Directory of C:\Windows\System32\Drivers
09/18/2006 03:26 PM 3,440,660 gm.dls
09/18/2006 03:26 PM 646 gmreadme.txt
10/01/2006 03:10 PM 328,162 ativcaxx.cpa
10/01/2006 03:10 PM 929 ativcaxx.vp
10/01/2006 03:10 PM 2,096 ativpkxx.vp
10/01/2006 03:10 PM 2,096 ativokxx.vp
10/15/2006 03:11 PM 34,656 ativvpxx.vp
11/02/2006 12:37 AM 20,480 secdrv.sys
11/02/2006 01:36 AM 2,028,032 atikmdag.sys
11/02/2006 01:36 AM 20,608 ntrigdigi.sys
11/02/2006 02:24 AM 62,336 BrSerWdm.sys
11/02/2006 02:24 AM 12,160 BrUsbMdm.sys
11/02/2006 02:24 AM 13,568 BrFiltLo.sys
11/02/2006 02:24 AM 5,248 BrFiltUp.sys
11/02/2006 02:24 AM 11,904 BrUsbSer.sys
11/02/2006 02:25 AM 71,808 BrSerId.sys
11/02/2006 02:51 AM 8,704 parvdm.sys
11/02/2006 02:51 AM 17,920 serenum.sys
11/02/2006 02:51 AM 83,456 serial.sys
11/02/2006 02:51 AM 79,360 parport.sys
11/02/2006 02:51 AM 13,312 sfloppy.sys
11/02/2006 02:52 AM 20,608 wacompen.sys
11/02/2006 02:55 AM 21,504 hidir.sys
11/02/2006 02:55 AM 19,456 usbohci.sys
11/02/2006 02:55 AM 68,608 usbcir.sys
11/02/2006 02:55 AM 53,376 1394bus.sys
11/02/2006 02:55 AM 62,080 ohci1394.sys
11/02/2006 02:55 AM 29,184 hidbth.sys
11/02/2006 02:55 AM 39,936 bthmodem.sys
11/02/2006 03:04 AM 878,080 PEAuth.sys
11/02/2006 03:49 AM 31,848 sym_hi.sys
11/02/2006 03:49 AM 33,384 Mraid35x.sys
11/02/2006 03:50 AM 34,920 sym_u3.sys
11/02/2006 03:50 AM 35,944 symc8xx.sys
11/02/2006 03:50 AM 35,944 iteatapi.sys
11/02/2006 03:50 AM 35,944 iteraid.sys
11/02/2006 03:50 AM 71,272 djsvs.sys
11/02/2006 03:50 AM 76,392 sbp2port.sys
11/02/2006 03:50 AM 41,576 iirsp.sys
11/02/2006 03:50 AM 45,160 nfrd960.sys
11/02/2006 03:50 AM 98,408 ulsata.sys
11/02/2006 03:50 AM 106,088 ql40xx.sys
11/02/2006 03:51 AM 167,528 pcmcia.sys
11/02/2006 05:18 AM etc
03/09/2007 05:04 PM 31,072 iqvw32.sys
04/26/2007 04:41 AM 304,920 iaStor.sys
04/29/2007 02:42 AM 228,224 e1e6032.sys
05/11/2007 07:26 AM 1,773,536 RTKVHDA.sys
10/17/2007 02:00 AM 9,072 cdr4_xp.sys
10/17/2007 02:00 AM 9,200 cdralw2k.sys
11/14/2007 03:00 AM 43,840 pxhelp20.sys
01/20/2008 08:32 PM 6,656 errdev.sys
01/20/2008 08:32 PM 11,264 wmiacpi.sys
01/20/2008 08:32 PM 28,216 battc.sys
01/20/2008 08:32 PM 20,792 compbatt.sys
01/20/2008 08:32 PM 41,472 intelppm.sys
01/20/2008 08:32 PM 41,472 viac7.sys
01/20/2008 08:32 PM 44,032 amdk8.sys
01/20/2008 08:32 PM 41,472 amdk7.sys
01/20/2008 08:32 PM 40,960 crusoe.sys
01/20/2008 08:32 PM 40,960 processr.sys
01/20/2008 08:32 PM 17,976 intelide.sys
01/20/2008 08:32 PM 19,000 cmdide.sys
01/20/2008 08:32 PM 17,464 aliide.sys
01/20/2008 08:32 PM 20,024 viaide.sys
01/20/2008 08:32 PM 17,976 amdide.sys
01/20/2008 08:32 PM 55,864 SISAGP.SYS
01/20/2008 08:32 PM 15,288 swenum.sys
01/20/2008 08:32 PM 60,984 ULIAGPKX.SYS
01/20/2008 08:32 PM 109,112 NV_AGP.SYS
01/20/2008 08:32 PM 31,288 mssmbios.sys
01/20/2008 08:32 PM 56,376 AGP440.sys
01/20/2008 08:32 PM 16,440 msisadrv.sys
01/20/2008 08:32 PM 49,720 isapnp.sys
01/20/2008 08:32 PM 52,792 volmgr.sys
01/20/2008 08:32 PM 56,888 VIAAGP.SYS
01/20/2008 08:32 PM 57,400 AMDAGP.SYS
01/20/2008 08:32 PM 248,832 rdpdr.sys
01/20/2008 08:32 PM 45,568 blbdrive.sys
01/20/2008 08:32 PM 26,112 vgapnp.sys
01/20/2008 08:32 PM 30,264 i2omp.sys
01/20/2008 08:32 PM 19,000 i2omgmt.sys
01/20/2008 08:32 PM 23,552 usbuhci.sys
01/20/2008 08:32 PM 5,888 usbd.sys
01/20/2008 08:32 PM 54,784 i8042prt.sys
01/20/2008 08:32 PM 15,872 mouhid.sys
01/20/2008 08:32 PM 34,360 mouclass.sys
01/20/2008 08:32 PM 19,968 sermouse.sys
01/20/2008 08:32 PM 25,088 fdc.sys
01/20/2008 08:32 PM 20,480 flpydisk.sys
01/20/2008 08:32 PM 73,216 usbccgp.sys
01/20/2008 08:32 PM 105,016 mpio.sys
01/20/2008 08:32 PM 238,648 uliahci.sys
01/20/2008 08:32 PM 130,048 drmk.sys
01/20/2008 08:32 PM 5,632 drmkaud.sys
01/20/2008 08:32 PM 422,968 adp94xx.sys
01/20/2008 08:32 PM 45,112 nvstor.sys
01/20/2008 08:32 PM 102,968 nvraid.sys
01/20/2008 08:32 PM 94,776 msdsm.sys
01/20/2008 08:32 PM 59,448 UAGP35.SYS
01/20/2008 08:32 PM 61,496 GAGP30KX.SYS
01/20/2008 08:32 PM 41,984 monitor.sys
01/20/2008 08:32 PM 24,632 crcdisk.sys
01/20/2008 08:32 PM 342,584 elxstor.sys
01/20/2008 08:32 PM 64,512 IPMIDrv.sys
01/20/2008 08:32 PM 18,944 usbprint.sys
01/20/2008 08:32 PM 34,816 umbus.sys
01/20/2008 08:32 PM 96,312 lsi_scsi.sys
01/20/2008 08:32 PM 235,064 iaStorV.sys
01/20/2008 08:32 PM 12,288 sffp_mmc.sys
01/20/2008 08:32 PM 13,312 sffdisk.sys
01/20/2008 08:32 PM 11,776 sffp_sd.sys
01/20/2008 08:32 PM 115,816 ulsata2.sys
01/20/2008 08:32 PM 35,384 kbdclass.sys
01/20/2008 08:32 PM 96,312 lsi_fc.sys
01/20/2008 08:32 PM 79,416 arc.sys
01/20/2008 08:32 PM 130,616 vsmraid.sys
01/20/2008 08:32 PM 79,928 arcsas.sys
01/20/2008 08:32 PM 22,072 wd.sys
01/20/2008 08:32 PM 118,784 E1G60I32.sys
01/20/2008 08:32 PM 1,122,360 ql2300.sys
01/20/2008 08:32 PM 89,656 lsi_sas.sys
01/20/2008 08:32 PM 300,600 adpahci.sys
01/20/2008 08:32 PM 41,016 sisraid2.sys
01/20/2008 08:32 PM 35,328 circlass.sys
01/20/2008 08:32 PM 101,432 adpu160m.sys
01/20/2008 08:32 PM 74,808 sisraid4.sys
01/20/2008 08:32 PM 40,504 HpCISSs.sys
01/20/2008 08:32 PM 25,472 hidparse.sys
01/20/2008 08:32 PM 386,616 MegaSR.sys
01/20/2008 08:32 PM 149,560 adpu320.sys
01/20/2008 08:32 PM 31,288 megasas.sys
01/20/2008 08:32 PM 35,328 usbscan.sys
01/20/2008 08:32 PM 31,232 qwavedrv.sys
01/20/2008 08:32 PM 12,288 bdasup.sys
01/20/2008 08:33 PM 17,976 wmilib.sys
01/20/2008 08:33 PM 110,080 videoprt.sys
01/20/2008 08:33 PM 57,400 mountmgr.sys
01/20/2008 08:33 PM 6,144 beep.sys
01/20/2008 08:33 PM 7,680 umpass.sys
01/20/2008 08:33 PM 4,608 null.sys
01/20/2008 08:33 PM 22,528 msfs.sys
01/20/2008 08:33 PM 70,144 cdfs.sys
01/20/2008 08:33 PM 503,864 Wdf01000.sys
01/20/2008 08:33 PM 35,896 WdfLdr.sys
01/20/2008 08:33 PM 3 MsftWdf_Kernel_01007_Inbox_Critical.Wdf
01/20/2008 08:33 PM 69,632 bowser.sys
01/20/2008 08:33 PM 13,312 irenum.sys
01/20/2008 08:33 PM 142,904 scsiport.sys
01/20/2008 08:33 PM 58,936 fileinfo.sys
01/20/2008 08:33 PM 17,408 asyncmac.sys
01/20/2008 08:33 PM 20,992 tdi.sys
01/20/2008 08:33 PM 6,144 RDPCDD.sys
01/20/2008 08:33 PM 12,800 fs_rec.sys
01/20/2008 08:33 PM 29,184 tdtcp.sys
01/20/2008 08:33 PM 17,920 tdpipe.sys
01/20/2008 08:33 PM 21,048 spldr.sys
01/20/2008 08:34 PM 11,776 rasacd.sys
01/20/2008 08:34 PM 35,840 netbios.sys
01/20/2008 08:34 PM 27,648 filetrace.sys
01/20/2008 08:34 PM 13,312 dxapi.sys
01/20/2008 08:34 PM 62,464 wanarp.sys
01/20/2008 08:34 PM 49,664 ndproxy.sys
01/20/2008 08:34 PM 20,992 ndistapi.sys
01/20/2008 08:34 PM 100,864 ipnat.sys
01/20/2008 08:34 PM 15,360 TUNMP.SYS
01/20/2008 08:34 PM 95,744 irda.sys
01/20/2008 08:34 PM 60,416 rspndr.sys
01/20/2008 08:34 PM 47,104 lltdio.sys
01/20/2008 08:34 PM 84,480 luafv.sys
01/20/2008 08:34 PM 24,576 tape.sys
01/20/2008 08:34 PM 47,616 ipfltdrv.sys
01/20/2008 08:34 PM 18,944 mcd.sys
01/20/2008 08:34 PM 16,384 nsiproxy.sys
01/20/2008 08:34 PM 15,872 ws2ifsl.sys
01/20/2008 08:34 PM 64,000 mpsdrv.sys
01/20/2008 08:34 PM 8,192 rootmdm.sys
01/20/2008 08:34 PM 6,144 RDPENCDD.sys
01/20/2008 08:34 PM 25,088 vga.sys
01/20/2008 08:34 PM 8,192 mskssrv.sys
01/20/2008 08:34 PM 5,504 mspqm.sys
01/20/2008 08:34 PM 6,016 mstee.sys
01/20/2008 08:34 PM 5,888 mspclock.sys
01/20/2008 08:34 PM 16,896 ndisuio.sys
01/20/2008 08:34 PM 17,408 smclib.sys
01/20/2008 08:34 PM 62,976 raspptp.sys
01/20/2008 08:34 PM 76,288 rasl2tp.sys
01/20/2008 08:34 PM 31,744 modem.sys
01/20/2008 08:34 PM 83,328 WUDFRd.sys
01/20/2008 08:34 PM 51,200 WUDFPf.sys
01/20/2008 08:34 PM 23,552 tssecsrv.sys
04/22/2008 12:17 AM 2,016,256 igdkmd32.sys
07/02/2008 12:43 AM 146,036 HSFProf.cty
07/02/2008 12:43 AM 980,992 HSX_DPV.sys
07/02/2008 12:43 AM 661,504 HSX_CNXT.sys
07/02/2008 12:43 AM 266,752 HSXHWBS2.sys
07/02/2008 12:43 AM 12,672 mdmxsdk.sys
07/02/2008 12:43 AM 386,560 XAudio.exe
07/02/2008 12:43 AM 8,704 XAudio.sys
02/28/2009 03:48 AM 4,085 1028_Dell_INS_530.mrk
02/28/2009 03:51 AM 28,728 msahci.sys
04/10/2009 08:52 PM 684,032 spsys.sys
04/10/2009 10:13 PM 142,848 fastfat.sys
04/10/2009 10:13 PM 136,704 exfat.sys
04/10/2009 10:13 PM 226,816 udfs.sys
04/10/2009 10:14 PM 35,328 npfs.sys
04/10/2009 10:14 PM 75,264 dfsc.sys
04/10/2009 10:14 PM 225,280 rdbss.sys
04/10/2009 10:14 PM 114,688 mrxdav.sys
04/10/2009 10:22 PM 33,280 watchdog.sys
04/10/2009 10:23 PM 76,288 dxg.sys
04/10/2009 10:38 PM 17,408 kbdhid.sys
04/10/2009 10:38 PM 149,504 ks.sys
04/10/2009 10:39 PM 19,456 Diskdump.sys
04/10/2009 10:39 PM 67,072 cdrom.sys
04/10/2009 10:42 PM 561,152 hdaudbus.sys
04/10/2009 10:42 PM 52,992 stream.sys
04/10/2009 10:42 PM 39,424 hidclass.sys
04/10/2009 10:42 PM 12,800 hidusb.sys
04/10/2009 10:42 PM 167,936 portcls.sys
04/10/2009 10:42 PM 39,936 usbehci.sys
04/10/2009 10:42 PM 65,536 USBSTOR.SYS
04/10/2009 10:42 PM 25,856 USBCAMD.sys
04/10/2009 10:42 PM 25,856 USBCAMD2.sys
04/10/2009 10:42 PM 226,304 usbport.sys
04/10/2009 10:43 PM 196,096 usbhub.sys
04/10/2009 10:43 PM 148,480 nwifi.sys
04/10/2009 10:45 PM 66,560 smb.sys
04/10/2009 10:45 PM 113,664 rmcast.sys
04/10/2009 10:45 PM 185,856 netbt.sys
04/10/2009 10:45 PM 72,192 pacer.sys
04/10/2009 10:45 PM 72,192 tdx.sys
04/10/2009 10:46 PM 33,280 rndismpx.sys
04/10/2009 10:46 PM 33,280 RNDISMP.sys
04/10/2009 10:46 PM 15,872 usb8023.sys
04/10/2009 10:46 PM 15,872 usb8023x.sys
04/10/2009 10:46 PM 41,472 raspppoe.sys
04/10/2009 10:46 PM 121,344 ndiswan.sys
04/10/2009 10:46 PM 69,120 rassstp.sys
04/10/2009 10:47 PM 273,920 afd.sys
04/10/2009 10:51 PM 180,736 rdpwd.sys
04/10/2009 11:42 PM 93,696 bridge.sys
04/11/2009 12:32 AM 19,944 atapi.sys
04/11/2009 12:32 AM 27,624 Dumpata.sys
04/11/2009 12:32 AM 35,304 crashdmp.sys
04/11/2009 12:32 AM 48,104 mup.sys
04/11/2009 12:32 AM 53,736 disk.sys
04/11/2009 12:32 AM 54,248 partmgr.sys
04/11/2009 12:32 AM 109,032 ataport.sys
04/11/2009 12:32 AM 99,816 FWPKCLNT.SYS
04/11/2009 12:32 AM 141,288 ecache.sys
04/11/2009 12:32 AM 125,928 Classpnp.sys
04/11/2009 12:32 AM 161,752 msrpc.sys
04/11/2009 12:32 AM 180,712 msiscsi.sys
04/11/2009 12:32 AM 223,208 netio.sys
04/11/2009 12:32 AM 265,688 acpi.sys
04/11/2009 12:32 AM 190,424 fltMgr.sys
04/11/2009 12:32 AM 527,848 ndis.sys
04/11/2009 12:32 AM 14,312 pciide.sys
04/11/2009 12:32 AM 1,083,880 ntfs.sys
04/11/2009 12:32 AM 43,496 pciidex.sys
04/11/2009 12:32 AM 53,224 termdd.sys
04/11/2009 12:32 AM 122,344 Storport.sys
04/11/2009 12:32 AM 149,480 pci.sys
04/11/2009 12:32 AM 226,280 volsnap.sys
04/11/2009 12:33 AM 292,840 volmgrx.sys
06/15/2009 05:15 PM 439,864 ksecdd.sys
09/24/2009 07:27 PM 634,880 dxgkrnl.sys
09/30/2009 07:01 PM 40,448 WpdUsb.sys
11/03/2009 01:41 PM 411,648 http.sys
12/08/2009 11:26 AM 30,720 tcpipreg.sys
12/09/2009 05:43 AM en-US
02/18/2010 05:28 AM 25,088 tunnel.sys
02/23/2010 05:10 AM 106,496 mrxsmb.sys
02/23/2010 05:10 AM 79,360 mrxsmb20.sys
02/23/2010 05:10 AM 212,992 mrxsmb10.sys
06/16/2010 10:04 AM 905,088 tcpip.sys
06/28/2010 02:10 PM 12,112 aswNdis.sys
09/06/2010 07:45 AM 102,400 srvnet.sys
09/06/2010 07:45 AM 145,408 srv2.sys
09/06/2010 07:45 AM 304,128 srv.sys
09/07/2010 08:47 AM 17,744 aswFsBlk.sys
09/07/2010 08:47 AM 50,768 aswMonFlt.sys
09/07/2010 08:47 AM 23,376 aswRdr.sys
09/07/2010 08:52 AM 165,584 aswSP.sys
09/07/2010 08:52 AM 46,672 aswTdi.sys
09/07/2010 08:53 AM 190,416 aswNdis2.sys
09/07/2010 08:53 AM 340,048 aswSnx.sys
09/07/2010 08:54 AM 99,792 aswFW.sys
09/09/2010 07:41 PM UMDF
11/27/2010 03:05 AM NSS
11/29/2010 05:42 PM 20,952 mbam.sys
11/29/2010 05:42 PM 38,224 mbamswissarmy.sys
12/11/2010 10:26 AM .
12/11/2010 10:26 AM ..
289 File(s) 38,248,745 bytes
6 Dir(s) 175,848,435,712 bytes free
Stealth malware?
Internet Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main
Start Page REG_SZ http://go.microsoft.com/fwlink/?LinkId=69157
AutoHide REG_SZ yes
Default_Page_URL REG_SZ http://go.microsoft.com/fwlink/?LinkId=69157
Default_Secondary_Page_URL REG_MULTI_SZ
Default_Search_URL REG_SZ http://go.microsoft.com/fwlink/?LinkId=54896
Search Page REG_SZ http://go.microsoft.com/fwlink/?LinkId=54896
Extensions Off Page REG_SZ about:NoAdd-ons
Security Risk Page REG_SZ about:SecurityRisk
Enable_Disk_Cache REG_SZ yes
Cache_Percent_of_Disk REG_BINARY 0A000000
Delete_Temp_Files_On_Exit REG_SZ yes
Local Page REG_SZ C:\Windows\System32\blank.htm
Anchor_Visitation_Horizon REG_BINARY 01000000
Use_Async_DNS REG_SZ yes
Placeholder_Width REG_BINARY 1A000000
Placeholder_Height REG_BINARY 1A000000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\ErrorThresholds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\UrlTemplate
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
IE5_UA_Backup_Flag REG_SZ 5.0
User Agent REG_SZ Mozilla/4.0 (compatible; MSIE 8.0; Win32)
EmailName REG_SZ IEUser@
AutoConfigProxy REG_SZ wininet.dll
MimeExclusionListForCache REG_SZ multipart/mixed multipart/x-mixed-replace multipart/x-byteranges
UseSchannelDirectly REG_BINARY 01000000
EnableHttp1_1 REG_DWORD 0x1
PrivDiscUiShown REG_DWORD 0x1
WarnOnIntranet REG_DWORD 0x1
WarnOnPost REG_BINARY 01000000
UrlEncoding REG_DWORD 0x0
SecureProtocols REG_DWORD 0x28
PrivacyAdvanced REG_DWORD 0x0
ZonesSecurityUpgradeDone REG_DWORD 0x1
DisableCachingOfSSLPages REG_DWORD 0x0
WarnonZoneCrossing REG_DWORD 0x0
CertificateRevocation REG_DWORD 0x1
EnableNegotiate REG_DWORD 0x1
MigrateProxy REG_DWORD 0x1
ProxyEnable REG_DWORD 0x0
EnableAutodial REG_DWORD 0x0
NoNetAutodial REG_DWORD 0x0
ZonesSecurityUpgrade REG_BINARY B05799A680FCC901
SyncMode5 REG_DWORD 0x4
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Http Filters
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Passport
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Protocols
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Disable Script Debugger REG_SZ yes
Anchor Underline REG_SZ yes
Cache_Update_Frequency REG_SZ Once_Per_Session
Display Inline Images REG_SZ yes
Do404Search REG_BINARY 01000000
Local Page REG_SZ C:\Windows\system32\blank.htm
Save_Session_History_On_Exit REG_SZ no
Show_FullURL REG_SZ no
Show_StatusBar REG_SZ yes
Show_ToolBar REG_SZ yes
Show_URLinStatusBar REG_SZ yes
Show_URLToolBar REG_SZ yes
Use_DlgBox_Colors REG_SZ yes
Search Page REG_SZ
XMLHTTP REG_DWORD 0x1
NoUpdateCheck REG_DWORD 0x1
UseClearType REG_SZ no
Enable Browser Extensions REG_SZ yes
Play_Background_Sounds REG_SZ yes
Play_Animations REG_SZ yes
Start Page REG_SZ http://www.msn.com
Default_Page_URL REG_SZ http://www.msn.com
CompatibilityFlags REG_DWORD 0x0
StartPageCache REG_DWORD 0x1
FullScreen REG_SZ no
SearchMigrated REG_DWORD 0x0
Window_Placement REG_BINARY 2C0000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0000000000000000200300003C020000
RunOnceHasShown REG_DWORD 0x1
RunOnceComplete REG_DWORD 0x1
FormSuggest PW Ask REG_SZ no
NotifyDownloadComplete REG_SZ yes
Friendly http errors REG_SZ yes
Error Dlg Displayed On Every Error REG_SZ no
Use FormSuggest REG_SZ yes
AutoSearch REG_DWORD 0x1
IE8RunOnceLastShown REG_DWORD 0x1
IE8RunOnceLastShown_TIMESTAMP REG_BINARY 2008C8917691CA01
IE8TourShown REG_DWORD 0x1
IE8TourShownTime REG_BINARY 002CEA4B9EFCC901
IE8RunOncePerInstallCompleted REG_DWORD 0x1
IE8RunOnceCompletionTime REG_BINARY 70B71EA07691CA01
SearchAssistant REG_SZ
ControlTooltipCount REG_DWORD 0x5
SearchDefaultBranded REG_DWORD 0x1
IE8TourNoShow REG_DWORD 0x1
AutoHide REG_SZ no
Default_Secondary_Page_URL REG_MULTI_SZ www.bing.com
FormSuggest Passwords REG_SZ yes
Search Bar REG_SZ
Start Page Restore REG_SZ http://www.msn.com/
Error Dlg Details Pane Open REG_SZ yes
AlwaysShowMenus REG_DWORD 0x1
Check_Associations REG_SZ no
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Default Feeds
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\WindowsSearch
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks
{CFBFAE00-17A6-11D0-99CB-00C04FD64497} REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{614BDA1F-9BEF-4CD1-BDE4-FA4804929B4A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D425283-D487-4337-BAB6-AB8354A81457}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
{21FA44EF-376D-4D53-9B0F-8A89D3229068} REG_BINARY 00
{5BED3930-2E9E-76D8-BACC-80DF2188D455} REG_BINARY 00
{89A2510A-B4B6-4683-BEC9-1B96700BC7F1} REG_BINARY 00
{9D425283-D487-4337-BAB6-AB8354A81457} REG_SZ Search Toolbar
{8dcb7100-df86-4384-8842-8fa844297b3f} REG_BINARY 00
{2318C2B1-4965-11d4-9B18-009027A5CD4F} REG_BINARY 00
Security Center
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
cval REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc
AntiVirusOverride REG_DWORD 0x0
AntiSpywareOverride REG_DWORD 0x0
FirewallOverride REG_DWORD 0x0
VistaSp1 REG_NONE 12B7DA3ED95BC801
VistaSp2 REG_NONE 93B08F43946CCA01
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\Logging
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Logging
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\AuthorizedApplications
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\GloballyOpenPorts
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\Logging
Uninstall List
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe AIR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player Plugin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Shockwave Player
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\avast5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Branding
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CNXT_MODEM_PCI_HSF
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Coupon Printer for Windows4.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dell Game Console
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DXM_Runtime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ERUNT_is1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoToAssist
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield Uninstall Information
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{BF6685DC-50F9-48EA-B2FF-99AF905D7660}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Malwarebytes' Anti-Malware_is1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\McAfee Security Scan
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft .NET Framework 3.5 SP1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft .NET Framework 4 Client Profile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MightyMagoo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox (3.6.12)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPlayer2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPoints Toolbar 2.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NSS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PC-Doctor for Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PROSetDX
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search Toolbar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TTB000001.TTB000001Toolbar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WIC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WildTangent dell Master Uninstall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinLiveSuite_Wave3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WT050941
Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org
Database version: 5295
Windows 6.0.6002 Service Pack 2 (Safe Mode)
Internet Explorer 8.0.6001.18975
12/11/2010 10:59:51 AM
mbam-log-2010-12-11 (10-59-51).txt
Scan type: Quick scan
Objects scanned: 128890
Time elapsed: 2 minute(s), 16 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
this is the MSS FILE
MySystem-Search
MSS v1.7
Basic System Information
Username: Mom - Date: 12/11/2010 - Time: 11:04:25
Microsoft Windows [Version 6.0.6002]
Processor type: x86 Family 6 Model 22 Stepping 1, GenuineIntel
Total processors: 1
Computer Name: MOM-PC
Logon Server: \\MOM-PC
CD Emulation Drivers running?
Roxio found!
Peer-to-Peer applications?
Security Tools Check
Malwarebytes' Anti-Malware
ERUNT
File associations
.exe=exefile
.scr=scrfile
.pif=piffile
.com=comfile
.bat=batfile
.cmd=cmdfile
.log=txtfile
.txt=txtfile
.reg=regfile
.sys=sysfile
.dll=dllfile
.ini=inifile
.inf=inffile
Running processes
PROCESS PID PRIO PATH
smss.exe 348 Normal C:\Windows\System32\smss.exe
csrss.exe 408 Normal C:\Windows\system32\csrss.exe
csrss.exe 444 Normal C:\Windows\system32\csrss.exe
wininit.exe 452 High C:\Windows\system32\wininit.exe
winlogon.exe 480 High C:\Windows\system32\winlogon.exe
services.exe 524 Normal C:\Windows\system32\services.exe
lsass.exe 540 Normal C:\Windows\system32\lsass.exe
lsm.exe 548 Normal C:\Windows\system32\lsm.exe
svchost.exe 704 Normal C:\Windows\system32\svchost.exe
svchost.exe 764 Normal C:\Windows\system32\svchost.exe
svchost.exe 796 Normal C:\Windows\System32\svchost.exe
svchost.exe 880 Normal C:\Windows\System32\svchost.exe
svchost.exe 908 Normal C:\Windows\system32\svchost.exe
svchost.exe 944 Normal C:\Windows\System32\svchost.exe
svchost.exe 988 Normal C:\Windows\system32\svchost.exe
svchost.exe 1008 Normal C:\Windows\system32\svchost.exe
svchost.exe 1084 Normal C:\Windows\system32\svchost.exe
Explorer.EXE 1320 Normal C:\Windows\Explorer.EXE
svchost.exe 1404 Normal C:\Windows\system32\svchost.exe
wmpnscfg.exe 1764 Normal C:\Program Files\Windows Media Player\wmpnscfg.exe
wmiprvse.exe 1756 Normal C:\Windows\system32\wbem\wmiprvse.exe
mss.exe 1572 Normal C:\Users\Mom\Desktop\mss.exe
cmd.exe 1716 Normal C:\Windows\system32\cmd.exe
DllHost.exe 652 Normal C:\Windows\system32\DllHost.exe
pv.exe 368 Normal C:\Users\Mom\Desktop\pv.exe
User Profile check
Mom
Public
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
ProfilesDirectory REG_EXPAND_SZ %SystemDrive%\Users
Default REG_EXPAND_SZ %SystemDrive%\Users\Default
Public REG_EXPAND_SZ %SystemDrive%\Users\Public
ProgramData REG_EXPAND_SZ %SystemDrive%\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
Flags REG_DWORD 0xc
State REG_DWORD 0x0
RefCount REG_DWORD 0x1
Sid REG_BINARY 010100000000000512000000
ProfileImagePath REG_EXPAND_SZ %systemroot%\system32\config\systemprofile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19
ProfileImagePath REG_EXPAND_SZ %SystemRoot%\ServiceProfiles\LocalService
Flags REG_DWORD 0x0
State REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20
ProfileImagePath REG_EXPAND_SZ %SystemRoot%\ServiceProfiles\NetworkService
Flags REG_DWORD 0x0
State REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-2944165837-3539766159-2639353112-1000
ProfileImagePath REG_EXPAND_SZ C:\Users\Mom
Flags REG_DWORD 0x0
State REG_DWORD 0x100
Sid REG_BINARY 010500000000000515000000CD677CAF8F8BFCD21855519DE8030000
ProfileLoadTimeLow REG_DWORD 0x0
ProfileLoadTimeHigh REG_DWORD 0x0
RefCount REG_DWORD 0x1
RunLogonScriptSync REG_DWORD 0x0
Current Scheduled Tasks
PATH: C:\Windows\Tasks
GoogleUpdateTaskMachineCore.job
GoogleUpdateTaskMachineUA.job
GoogleUpdateTaskUserS-1-5-21-2944165837-3539766159-2639353112-1000Core.job
GoogleUpdateTaskUserS-1-5-21-2944165837-3539766159-2639353112-1000UA.job
SCHEDLGU.TXT
Norton Security Scan for Mom.job
SA.DAT
Windows Drivers and NT-Services
Volume in drive C is OS
Volume Serial Number is EA2B-F62A
Directory of C:\Windows\System32\Drivers
10/15/2009 04:17 AM 0 Msft_User_WpdFs_01_00_00.Wdf
11/24/2009 03:17 AM 0 Msft_User_WpdFs_01_07_00.Wdf
06/26/2009 06:36 AM 0 Msft_User_WpdMtpDr_01_00_00.Wdf
11/24/2009 03:17 AM 0 Msft_User_WpdMtpDr_01_07_00.Wdf
09/09/2010 07:41 PM 0 Msft_User_WpdRapi_01_00_00.Wdf
5 File(s) 0 bytes
0 Dir(s) 175,848,452,096 bytes free
Volume in drive C is OS
Volume Serial Number is EA2B-F62A
Directory of C:\Windows\System32\Drivers
09/18/2006 03:26 PM 3,440,660 gm.dls
09/18/2006 03:26 PM 646 gmreadme.txt
10/01/2006 03:10 PM 328,162 ativcaxx.cpa
10/01/2006 03:10 PM 929 ativcaxx.vp
10/01/2006 03:10 PM 2,096 ativpkxx.vp
10/01/2006 03:10 PM 2,096 ativokxx.vp
10/15/2006 03:11 PM 34,656 ativvpxx.vp
11/02/2006 12:37 AM 20,480 secdrv.sys
11/02/2006 01:36 AM 2,028,032 atikmdag.sys
11/02/2006 01:36 AM 20,608 ntrigdigi.sys
11/02/2006 02:24 AM 62,336 BrSerWdm.sys
11/02/2006 02:24 AM 12,160 BrUsbMdm.sys
11/02/2006 02:24 AM 13,568 BrFiltLo.sys
11/02/2006 02:24 AM 5,248 BrFiltUp.sys
11/02/2006 02:24 AM 11,904 BrUsbSer.sys
11/02/2006 02:25 AM 71,808 BrSerId.sys
11/02/2006 02:51 AM 8,704 parvdm.sys
11/02/2006 02:51 AM 17,920 serenum.sys
11/02/2006 02:51 AM 83,456 serial.sys
11/02/2006 02:51 AM 79,360 parport.sys
11/02/2006 02:51 AM 13,312 sfloppy.sys
11/02/2006 02:52 AM 20,608 wacompen.sys
11/02/2006 02:55 AM 21,504 hidir.sys
11/02/2006 02:55 AM 19,456 usbohci.sys
11/02/2006 02:55 AM 68,608 usbcir.sys
11/02/2006 02:55 AM 53,376 1394bus.sys
11/02/2006 02:55 AM 62,080 ohci1394.sys
11/02/2006 02:55 AM 29,184 hidbth.sys
11/02/2006 02:55 AM 39,936 bthmodem.sys
11/02/2006 03:04 AM 878,080 PEAuth.sys
11/02/2006 03:49 AM 31,848 sym_hi.sys
11/02/2006 03:49 AM 33,384 Mraid35x.sys
11/02/2006 03:50 AM 34,920 sym_u3.sys
11/02/2006 03:50 AM 35,944 symc8xx.sys
11/02/2006 03:50 AM 35,944 iteatapi.sys
11/02/2006 03:50 AM 35,944 iteraid.sys
11/02/2006 03:50 AM 71,272 djsvs.sys
11/02/2006 03:50 AM 76,392 sbp2port.sys
11/02/2006 03:50 AM 41,576 iirsp.sys
11/02/2006 03:50 AM 45,160 nfrd960.sys
11/02/2006 03:50 AM 98,408 ulsata.sys
11/02/2006 03:50 AM 106,088 ql40xx.sys
11/02/2006 03:51 AM 167,528 pcmcia.sys
11/02/2006 05:18 AM
03/09/2007 05:04 PM 31,072 iqvw32.sys
04/26/2007 04:41 AM 304,920 iaStor.sys
04/29/2007 02:42 AM 228,224 e1e6032.sys
05/11/2007 07:26 AM 1,773,536 RTKVHDA.sys
10/17/2007 02:00 AM 9,072 cdr4_xp.sys
10/17/2007 02:00 AM 9,200 cdralw2k.sys
11/14/2007 03:00 AM 43,840 pxhelp20.sys
01/20/2008 08:32 PM 6,656 errdev.sys
01/20/2008 08:32 PM 11,264 wmiacpi.sys
01/20/2008 08:32 PM 28,216 battc.sys
01/20/2008 08:32 PM 20,792 compbatt.sys
01/20/2008 08:32 PM 41,472 intelppm.sys
01/20/2008 08:32 PM 41,472 viac7.sys
01/20/2008 08:32 PM 44,032 amdk8.sys
01/20/2008 08:32 PM 41,472 amdk7.sys
01/20/2008 08:32 PM 40,960 crusoe.sys
01/20/2008 08:32 PM 40,960 processr.sys
01/20/2008 08:32 PM 17,976 intelide.sys
01/20/2008 08:32 PM 19,000 cmdide.sys
01/20/2008 08:32 PM 17,464 aliide.sys
01/20/2008 08:32 PM 20,024 viaide.sys
01/20/2008 08:32 PM 17,976 amdide.sys
01/20/2008 08:32 PM 55,864 SISAGP.SYS
01/20/2008 08:32 PM 15,288 swenum.sys
01/20/2008 08:32 PM 60,984 ULIAGPKX.SYS
01/20/2008 08:32 PM 109,112 NV_AGP.SYS
01/20/2008 08:32 PM 31,288 mssmbios.sys
01/20/2008 08:32 PM 56,376 AGP440.sys
01/20/2008 08:32 PM 16,440 msisadrv.sys
01/20/2008 08:32 PM 49,720 isapnp.sys
01/20/2008 08:32 PM 52,792 volmgr.sys
01/20/2008 08:32 PM 56,888 VIAAGP.SYS
01/20/2008 08:32 PM 57,400 AMDAGP.SYS
01/20/2008 08:32 PM 248,832 rdpdr.sys
01/20/2008 08:32 PM 45,568 blbdrive.sys
01/20/2008 08:32 PM 26,112 vgapnp.sys
01/20/2008 08:32 PM 30,264 i2omp.sys
01/20/2008 08:32 PM 19,000 i2omgmt.sys
01/20/2008 08:32 PM 23,552 usbuhci.sys
01/20/2008 08:32 PM 5,888 usbd.sys
01/20/2008 08:32 PM 54,784 i8042prt.sys
01/20/2008 08:32 PM 15,872 mouhid.sys
01/20/2008 08:32 PM 34,360 mouclass.sys
01/20/2008 08:32 PM 19,968 sermouse.sys
01/20/2008 08:32 PM 25,088 fdc.sys
01/20/2008 08:32 PM 20,480 flpydisk.sys
01/20/2008 08:32 PM 73,216 usbccgp.sys
01/20/2008 08:32 PM 105,016 mpio.sys
01/20/2008 08:32 PM 238,648 uliahci.sys
01/20/2008 08:32 PM 130,048 drmk.sys
01/20/2008 08:32 PM 5,632 drmkaud.sys
01/20/2008 08:32 PM 422,968 adp94xx.sys
01/20/2008 08:32 PM 45,112 nvstor.sys
01/20/2008 08:32 PM 102,968 nvraid.sys
01/20/2008 08:32 PM 94,776 msdsm.sys
01/20/2008 08:32 PM 59,448 UAGP35.SYS
01/20/2008 08:32 PM 61,496 GAGP30KX.SYS
01/20/2008 08:32 PM 41,984 monitor.sys
01/20/2008 08:32 PM 24,632 crcdisk.sys
01/20/2008 08:32 PM 342,584 elxstor.sys
01/20/2008 08:32 PM 64,512 IPMIDrv.sys
01/20/2008 08:32 PM 18,944 usbprint.sys
01/20/2008 08:32 PM 34,816 umbus.sys
01/20/2008 08:32 PM 96,312 lsi_scsi.sys
01/20/2008 08:32 PM 235,064 iaStorV.sys
01/20/2008 08:32 PM 12,288 sffp_mmc.sys
01/20/2008 08:32 PM 13,312 sffdisk.sys
01/20/2008 08:32 PM 11,776 sffp_sd.sys
01/20/2008 08:32 PM 115,816 ulsata2.sys
01/20/2008 08:32 PM 35,384 kbdclass.sys
01/20/2008 08:32 PM 96,312 lsi_fc.sys
01/20/2008 08:32 PM 79,416 arc.sys
01/20/2008 08:32 PM 130,616 vsmraid.sys
01/20/2008 08:32 PM 79,928 arcsas.sys
01/20/2008 08:32 PM 22,072 wd.sys
01/20/2008 08:32 PM 118,784 E1G60I32.sys
01/20/2008 08:32 PM 1,122,360 ql2300.sys
01/20/2008 08:32 PM 89,656 lsi_sas.sys
01/20/2008 08:32 PM 300,600 adpahci.sys
01/20/2008 08:32 PM 41,016 sisraid2.sys
01/20/2008 08:32 PM 35,328 circlass.sys
01/20/2008 08:32 PM 101,432 adpu160m.sys
01/20/2008 08:32 PM 74,808 sisraid4.sys
01/20/2008 08:32 PM 40,504 HpCISSs.sys
01/20/2008 08:32 PM 25,472 hidparse.sys
01/20/2008 08:32 PM 386,616 MegaSR.sys
01/20/2008 08:32 PM 149,560 adpu320.sys
01/20/2008 08:32 PM 31,288 megasas.sys
01/20/2008 08:32 PM 35,328 usbscan.sys
01/20/2008 08:32 PM 31,232 qwavedrv.sys
01/20/2008 08:32 PM 12,288 bdasup.sys
01/20/2008 08:33 PM 17,976 wmilib.sys
01/20/2008 08:33 PM 110,080 videoprt.sys
01/20/2008 08:33 PM 57,400 mountmgr.sys
01/20/2008 08:33 PM 6,144 beep.sys
01/20/2008 08:33 PM 7,680 umpass.sys
01/20/2008 08:33 PM 4,608 null.sys
01/20/2008 08:33 PM 22,528 msfs.sys
01/20/2008 08:33 PM 70,144 cdfs.sys
01/20/2008 08:33 PM 503,864 Wdf01000.sys
01/20/2008 08:33 PM 35,896 WdfLdr.sys
01/20/2008 08:33 PM 3 MsftWdf_Kernel_01007_Inbox_Critical.Wdf
01/20/2008 08:33 PM 69,632 bowser.sys
01/20/2008 08:33 PM 13,312 irenum.sys
01/20/2008 08:33 PM 142,904 scsiport.sys
01/20/2008 08:33 PM 58,936 fileinfo.sys
01/20/2008 08:33 PM 17,408 asyncmac.sys
01/20/2008 08:33 PM 20,992 tdi.sys
01/20/2008 08:33 PM 6,144 RDPCDD.sys
01/20/2008 08:33 PM 12,800 fs_rec.sys
01/20/2008 08:33 PM 29,184 tdtcp.sys
01/20/2008 08:33 PM 17,920 tdpipe.sys
01/20/2008 08:33 PM 21,048 spldr.sys
01/20/2008 08:34 PM 11,776 rasacd.sys
01/20/2008 08:34 PM 35,840 netbios.sys
01/20/2008 08:34 PM 27,648 filetrace.sys
01/20/2008 08:34 PM 13,312 dxapi.sys
01/20/2008 08:34 PM 62,464 wanarp.sys
01/20/2008 08:34 PM 49,664 ndproxy.sys
01/20/2008 08:34 PM 20,992 ndistapi.sys
01/20/2008 08:34 PM 100,864 ipnat.sys
01/20/2008 08:34 PM 15,360 TUNMP.SYS
01/20/2008 08:34 PM 95,744 irda.sys
01/20/2008 08:34 PM 60,416 rspndr.sys
01/20/2008 08:34 PM 47,104 lltdio.sys
01/20/2008 08:34 PM 84,480 luafv.sys
01/20/2008 08:34 PM 24,576 tape.sys
01/20/2008 08:34 PM 47,616 ipfltdrv.sys
01/20/2008 08:34 PM 18,944 mcd.sys
01/20/2008 08:34 PM 16,384 nsiproxy.sys
01/20/2008 08:34 PM 15,872 ws2ifsl.sys
01/20/2008 08:34 PM 64,000 mpsdrv.sys
01/20/2008 08:34 PM 8,192 rootmdm.sys
01/20/2008 08:34 PM 6,144 RDPENCDD.sys
01/20/2008 08:34 PM 25,088 vga.sys
01/20/2008 08:34 PM 8,192 mskssrv.sys
01/20/2008 08:34 PM 5,504 mspqm.sys
01/20/2008 08:34 PM 6,016 mstee.sys
01/20/2008 08:34 PM 5,888 mspclock.sys
01/20/2008 08:34 PM 16,896 ndisuio.sys
01/20/2008 08:34 PM 17,408 smclib.sys
01/20/2008 08:34 PM 62,976 raspptp.sys
01/20/2008 08:34 PM 76,288 rasl2tp.sys
01/20/2008 08:34 PM 31,744 modem.sys
01/20/2008 08:34 PM 83,328 WUDFRd.sys
01/20/2008 08:34 PM 51,200 WUDFPf.sys
01/20/2008 08:34 PM 23,552 tssecsrv.sys
04/22/2008 12:17 AM 2,016,256 igdkmd32.sys
07/02/2008 12:43 AM 146,036 HSFProf.cty
07/02/2008 12:43 AM 980,992 HSX_DPV.sys
07/02/2008 12:43 AM 661,504 HSX_CNXT.sys
07/02/2008 12:43 AM 266,752 HSXHWBS2.sys
07/02/2008 12:43 AM 12,672 mdmxsdk.sys
07/02/2008 12:43 AM 386,560 XAudio.exe
07/02/2008 12:43 AM 8,704 XAudio.sys
02/28/2009 03:48 AM 4,085 1028_Dell_INS_530.mrk
02/28/2009 03:51 AM 28,728 msahci.sys
04/10/2009 08:52 PM 684,032 spsys.sys
04/10/2009 10:13 PM 142,848 fastfat.sys
04/10/2009 10:13 PM 136,704 exfat.sys
04/10/2009 10:13 PM 226,816 udfs.sys
04/10/2009 10:14 PM 35,328 npfs.sys
04/10/2009 10:14 PM 75,264 dfsc.sys
04/10/2009 10:14 PM 225,280 rdbss.sys
04/10/2009 10:14 PM 114,688 mrxdav.sys
04/10/2009 10:22 PM 33,280 watchdog.sys
04/10/2009 10:23 PM 76,288 dxg.sys
04/10/2009 10:38 PM 17,408 kbdhid.sys
04/10/2009 10:38 PM 149,504 ks.sys
04/10/2009 10:39 PM 19,456 Diskdump.sys
04/10/2009 10:39 PM 67,072 cdrom.sys
04/10/2009 10:42 PM 561,152 hdaudbus.sys
04/10/2009 10:42 PM 52,992 stream.sys
04/10/2009 10:42 PM 39,424 hidclass.sys
04/10/2009 10:42 PM 12,800 hidusb.sys
04/10/2009 10:42 PM 167,936 portcls.sys
04/10/2009 10:42 PM 39,936 usbehci.sys
04/10/2009 10:42 PM 65,536 USBSTOR.SYS
04/10/2009 10:42 PM 25,856 USBCAMD.sys
04/10/2009 10:42 PM 25,856 USBCAMD2.sys
04/10/2009 10:42 PM 226,304 usbport.sys
04/10/2009 10:43 PM 196,096 usbhub.sys
04/10/2009 10:43 PM 148,480 nwifi.sys
04/10/2009 10:45 PM 66,560 smb.sys
04/10/2009 10:45 PM 113,664 rmcast.sys
04/10/2009 10:45 PM 185,856 netbt.sys
04/10/2009 10:45 PM 72,192 pacer.sys
04/10/2009 10:45 PM 72,192 tdx.sys
04/10/2009 10:46 PM 33,280 rndismpx.sys
04/10/2009 10:46 PM 33,280 RNDISMP.sys
04/10/2009 10:46 PM 15,872 usb8023.sys
04/10/2009 10:46 PM 15,872 usb8023x.sys
04/10/2009 10:46 PM 41,472 raspppoe.sys
04/10/2009 10:46 PM 121,344 ndiswan.sys
04/10/2009 10:46 PM 69,120 rassstp.sys
04/10/2009 10:47 PM 273,920 afd.sys
04/10/2009 10:51 PM 180,736 rdpwd.sys
04/10/2009 11:42 PM 93,696 bridge.sys
04/11/2009 12:32 AM 19,944 atapi.sys
04/11/2009 12:32 AM 27,624 Dumpata.sys
04/11/2009 12:32 AM 35,304 crashdmp.sys
04/11/2009 12:32 AM 48,104 mup.sys
04/11/2009 12:32 AM 53,736 disk.sys
04/11/2009 12:32 AM 54,248 partmgr.sys
04/11/2009 12:32 AM 109,032 ataport.sys
04/11/2009 12:32 AM 99,816 FWPKCLNT.SYS
04/11/2009 12:32 AM 141,288 ecache.sys
04/11/2009 12:32 AM 125,928 Classpnp.sys
04/11/2009 12:32 AM 161,752 msrpc.sys
04/11/2009 12:32 AM 180,712 msiscsi.sys
04/11/2009 12:32 AM 223,208 netio.sys
04/11/2009 12:32 AM 265,688 acpi.sys
04/11/2009 12:32 AM 190,424 fltMgr.sys
04/11/2009 12:32 AM 527,848 ndis.sys
04/11/2009 12:32 AM 14,312 pciide.sys
04/11/2009 12:32 AM 1,083,880 ntfs.sys
04/11/2009 12:32 AM 43,496 pciidex.sys
04/11/2009 12:32 AM 53,224 termdd.sys
04/11/2009 12:32 AM 122,344 Storport.sys
04/11/2009 12:32 AM 149,480 pci.sys
04/11/2009 12:32 AM 226,280 volsnap.sys
04/11/2009 12:33 AM 292,840 volmgrx.sys
06/15/2009 05:15 PM 439,864 ksecdd.sys
09/24/2009 07:27 PM 634,880 dxgkrnl.sys
09/30/2009 07:01 PM 40,448 WpdUsb.sys
11/03/2009 01:41 PM 411,648 http.sys
12/08/2009 11:26 AM 30,720 tcpipreg.sys
12/09/2009 05:43 AM
02/18/2010 05:28 AM 25,088 tunnel.sys
02/23/2010 05:10 AM 106,496 mrxsmb.sys
02/23/2010 05:10 AM 79,360 mrxsmb20.sys
02/23/2010 05:10 AM 212,992 mrxsmb10.sys
06/16/2010 10:04 AM 905,088 tcpip.sys
06/28/2010 02:10 PM 12,112 aswNdis.sys
09/06/2010 07:45 AM 102,400 srvnet.sys
09/06/2010 07:45 AM 145,408 srv2.sys
09/06/2010 07:45 AM 304,128 srv.sys
09/07/2010 08:47 AM 17,744 aswFsBlk.sys
09/07/2010 08:47 AM 50,768 aswMonFlt.sys
09/07/2010 08:47 AM 23,376 aswRdr.sys
09/07/2010 08:52 AM 165,584 aswSP.sys
09/07/2010 08:52 AM 46,672 aswTdi.sys
09/07/2010 08:53 AM 190,416 aswNdis2.sys
09/07/2010 08:53 AM 340,048 aswSnx.sys
09/07/2010 08:54 AM 99,792 aswFW.sys
09/09/2010 07:41 PM
11/27/2010 03:05 AM
11/29/2010 05:42 PM 20,952 mbam.sys
11/29/2010 05:42 PM 38,224 mbamswissarmy.sys
12/11/2010 10:26 AM
12/11/2010 10:26 AM
289 File(s) 38,248,745 bytes
6 Dir(s) 175,848,435,712 bytes free
Stealth malware?
Internet Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main
Start Page REG_SZ http://go.microsoft.com/fwlink/?LinkId=69157
AutoHide REG_SZ yes
Default_Page_URL REG_SZ http://go.microsoft.com/fwlink/?LinkId=69157
Default_Secondary_Page_URL REG_MULTI_SZ
Default_Search_URL REG_SZ http://go.microsoft.com/fwlink/?LinkId=54896
Search Page REG_SZ http://go.microsoft.com/fwlink/?LinkId=54896
Extensions Off Page REG_SZ about:NoAdd-ons
Security Risk Page REG_SZ about:SecurityRisk
Enable_Disk_Cache REG_SZ yes
Cache_Percent_of_Disk REG_BINARY 0A000000
Delete_Temp_Files_On_Exit REG_SZ yes
Local Page REG_SZ C:\Windows\System32\blank.htm
Anchor_Visitation_Horizon REG_BINARY 01000000
Use_Async_DNS REG_SZ yes
Placeholder_Width REG_BINARY 1A000000
Placeholder_Height REG_BINARY 1A000000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\ErrorThresholds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\UrlTemplate
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
IE5_UA_Backup_Flag REG_SZ 5.0
User Agent REG_SZ Mozilla/4.0 (compatible; MSIE 8.0; Win32)
EmailName REG_SZ IEUser@
AutoConfigProxy REG_SZ wininet.dll
MimeExclusionListForCache REG_SZ multipart/mixed multipart/x-mixed-replace multipart/x-byteranges
UseSchannelDirectly REG_BINARY 01000000
EnableHttp1_1 REG_DWORD 0x1
PrivDiscUiShown REG_DWORD 0x1
WarnOnIntranet REG_DWORD 0x1
WarnOnPost REG_BINARY 01000000
UrlEncoding REG_DWORD 0x0
SecureProtocols REG_DWORD 0x28
PrivacyAdvanced REG_DWORD 0x0
ZonesSecurityUpgradeDone REG_DWORD 0x1
DisableCachingOfSSLPages REG_DWORD 0x0
WarnonZoneCrossing REG_DWORD 0x0
CertificateRevocation REG_DWORD 0x1
EnableNegotiate REG_DWORD 0x1
MigrateProxy REG_DWORD 0x1
ProxyEnable REG_DWORD 0x0
EnableAutodial REG_DWORD 0x0
NoNetAutodial REG_DWORD 0x0
ZonesSecurityUpgrade REG_BINARY B05799A680FCC901
SyncMode5 REG_DWORD 0x4
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Http Filters
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Passport
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Protocols
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Disable Script Debugger REG_SZ yes
Anchor Underline REG_SZ yes
Cache_Update_Frequency REG_SZ Once_Per_Session
Display Inline Images REG_SZ yes
Do404Search REG_BINARY 01000000
Local Page REG_SZ C:\Windows\system32\blank.htm
Save_Session_History_On_Exit REG_SZ no
Show_FullURL REG_SZ no
Show_StatusBar REG_SZ yes
Show_ToolBar REG_SZ yes
Show_URLinStatusBar REG_SZ yes
Show_URLToolBar REG_SZ yes
Use_DlgBox_Colors REG_SZ yes
Search Page REG_SZ
XMLHTTP REG_DWORD 0x1
NoUpdateCheck REG_DWORD 0x1
UseClearType REG_SZ no
Enable Browser Extensions REG_SZ yes
Play_Background_Sounds REG_SZ yes
Play_Animations REG_SZ yes
Start Page REG_SZ http://www.msn.com
Default_Page_URL REG_SZ http://www.msn.com
CompatibilityFlags REG_DWORD 0x0
StartPageCache REG_DWORD 0x1
FullScreen REG_SZ no
SearchMigrated REG_DWORD 0x0
Window_Placement REG_BINARY 2C0000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0000000000000000200300003C020000
RunOnceHasShown REG_DWORD 0x1
RunOnceComplete REG_DWORD 0x1
FormSuggest PW Ask REG_SZ no
NotifyDownloadComplete REG_SZ yes
Friendly http errors REG_SZ yes
Error Dlg Displayed On Every Error REG_SZ no
Use FormSuggest REG_SZ yes
AutoSearch REG_DWORD 0x1
IE8RunOnceLastShown REG_DWORD 0x1
IE8RunOnceLastShown_TIMESTAMP REG_BINARY 2008C8917691CA01
IE8TourShown REG_DWORD 0x1
IE8TourShownTime REG_BINARY 002CEA4B9EFCC901
IE8RunOncePerInstallCompleted REG_DWORD 0x1
IE8RunOnceCompletionTime REG_BINARY 70B71EA07691CA01
SearchAssistant REG_SZ
ControlTooltipCount REG_DWORD 0x5
SearchDefaultBranded REG_DWORD 0x1
IE8TourNoShow REG_DWORD 0x1
AutoHide REG_SZ no
Default_Secondary_Page_URL REG_MULTI_SZ www.bing.com
FormSuggest Passwords REG_SZ yes
Search Bar REG_SZ
Start Page Restore REG_SZ http://www.msn.com/
Error Dlg Details Pane Open REG_SZ yes
AlwaysShowMenus REG_DWORD 0x1
Check_Associations REG_SZ no
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Default Feeds
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\WindowsSearch
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks
{CFBFAE00-17A6-11D0-99CB-00C04FD64497} REG_SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{614BDA1F-9BEF-4CD1-BDE4-FA4804929B4A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9D425283-D487-4337-BAB6-AB8354A81457}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
{21FA44EF-376D-4D53-9B0F-8A89D3229068} REG_BINARY 00
{5BED3930-2E9E-76D8-BACC-80DF2188D455} REG_BINARY 00
{89A2510A-B4B6-4683-BEC9-1B96700BC7F1} REG_BINARY 00
{9D425283-D487-4337-BAB6-AB8354A81457} REG_SZ Search Toolbar
{8dcb7100-df86-4384-8842-8fa844297b3f} REG_BINARY 00
{2318C2B1-4965-11d4-9B18-009027A5CD4F} REG_BINARY 00
Security Center
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
cval REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc
AntiVirusOverride REG_DWORD 0x0
AntiSpywareOverride REG_DWORD 0x0
FirewallOverride REG_DWORD 0x0
VistaSp1 REG_NONE 12B7DA3ED95BC801
VistaSp2 REG_NONE 93B08F43946CCA01
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\Logging
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\Logging
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile
EnableFirewall REG_DWORD 0x1
DisableNotifications REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\AuthorizedApplications
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\GloballyOpenPorts
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\Logging
Uninstall List
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe AIR
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player Plugin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Shockwave Player
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\avast5
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Branding
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CNXT_MODEM_PCI_HSF
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Coupon Printer for Windows4.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dell Game Console
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DXM_Runtime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ERUNT_is1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\GoToAssist
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield Uninstall Information
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{BF6685DC-50F9-48EA-B2FF-99AF905D7660}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Malwarebytes' Anti-Malware_is1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\McAfee Security Scan
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft .NET Framework 3.5 SP1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft .NET Framework 4 Client Profile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MightyMagoo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox (3.6.12)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPlayer2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPoints Toolbar 2.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NSS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PC-Doctor for Windows
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PROSetDX
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search Toolbar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TTB000001.TTB000001Toolbar
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WIC
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WildTangent dell Master Uninstall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinLiveSuite_Wave3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WT050941
Last edited by jabunt on Sat Dec 11, 2010 1:05 pm; edited 1 time in total (Reason for editing : forgot to put on what system is running since not on my normal machine)
















