1
philipwk log on Sat Apr 23, 2011 2:32 am
philipwk
Member

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6422
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
4/22/2011 5:38:14 PM
mbam-log-2011-04-22 (17-38-14).txt
Scan type: Quick scan
Objects scanned: 183627
Time elapsed: 8 minute(s), 47 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 11
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\itlnfw32 (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\GoWNKtoBbTfMqRQ (Trojan.FakeAlert) -> Value: GoWNKtoBbTfMqRQ -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\documents and settings\all users\application data\gownktobbtfmqrq.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\itlnfw32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\16899892.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\null0.019796283825301852.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\null0.09884048293238279.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\null0.21870310611980437.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\null0.5718803396663437.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\null0.8356442089299158.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\temp\jar_cache1442940674180269922.tmp (Trojan.FakeAlert) -> Delete on reboot.
c:\WINDOWS\temp\jar_cache2772797397516559471.tmp (Trojan.FakeAlert) -> Delete on reboot.
c:\WINDOWS\temp\jar_cache6944927343098075797.tmp (Trojan.FakeAlert) -> Delete on reboot.
___________________________________________________________________________________________________________________
mss log:
MySystem-Search
MSS v1.7
Basic System Information
Username: Philip - Date: 04/22/2011 - Time: 23:00:39
Microsoft Windows XP [Version 5.1.2600]
Processor type: x86 Family 6 Model 10 Stepping 0, AuthenticAMD
Total processors: 1
Computer Name: DARREN
Logon Server: \\DARREN
CD Emulation Drivers running?
DAEMON Tools/Duplex Secure found!
Peer-to-Peer applications?
Security Tools Check
CCleaner
Trend Micro HijackThis
Malwarebytes' Anti-Malware
File associations
.exe=exefile
.scr=scrfile
.pif=piffile
.com=comfile
.bat=batfile
.cmd=cmdfile
.log=txtfile
.txt=txtfile
.reg=regfile
.sys=sysfile
.dll=dllfile
.ini=inifile
.inf=inffile
Running processes
PROCESS PID PRIO PATH
smss.exe 716 Normal C:\WINDOWS\System32\smss.exe
csrss.exe 780 Normal C:\WINDOWS\system32\csrss.exe
winlogon.exe 812 High C:\WINDOWS\system32\winlogon.exe
avgchsvx.exe 824 Normal C:\Program Files\AVG\AVG9\avgchsvx.exe
avgrsx.exe 832 Normal C:\Program Files\AVG\AVG9\avgrsx.exe
avgcsrvx.exe 904 Normal C:\Program Files\AVG\AVG9\avgcsrvx.exe
services.exe 936 Normal C:\WINDOWS\system32\services.exe
lsass.exe 948 Normal C:\WINDOWS\system32\lsass.exe
Ati2evxx.exe 1340 Normal C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe 1364 Normal C:\WINDOWS\system32\svchost.exe
svchost.exe 1452 Normal C:\WINDOWS\system32\svchost.exe
svchost.exe 1628 Normal C:\WINDOWS\System32\svchost.exe
Ati2evxx.exe 1752 Normal C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe 1908 Normal C:\WINDOWS\system32\svchost.exe
spoolsv.exe 268 Normal C:\WINDOWS\system32\spoolsv.exe
AppleMobileDeviceService.exe 1380 Normal C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
avgwdsvc.exe 1528 Normal C:\Program Files\AVG\AVG9\avgwdsvc.exe
mDNSResponder.exe 1548 Normal C:\Program Files\Bonjour\mDNSResponder.exe
jqs.exe 1896 Idle C:\Program Files\Java\jre6\bin\jqs.exe
MDM.EXE 1980 Normal C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
MSCamS32.exe 308 Normal C:\Program Files\Microsoft LifeCam\MSCamS32.exe
RosettaStoneDaemon.exe 404 Normal C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe
SeaPort.EXE 484 Normal C:\Program Files\Microsoft\BingBar\SeaPort.EXE
svchost.exe 536 Normal C:\WINDOWS\System32\svchost.exe
WLIDSVC.EXE 624 Normal C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
avgnsx.exe 1716 Normal C:\Program Files\AVG\AVG9\avgnsx.exe
wuauclt.exe 2268 Normal C:\WINDOWS\system32\wuauclt.exe
Explorer.EXE 2380 Normal C:\WINDOWS\Explorer.EXE
WLIDSvcM.exe 2572 Normal C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
alg.exe 2724 Normal C:\WINDOWS\System32\alg.exe
SOUNDMAN.EXE 3156 Normal C:\WINDOWS\SOUNDMAN.EXE
shwicon.exe 3172 Normal C:\Program Files\USB Product Driver v2.16r002\shwicon.exe
hpcmpmgr.exe 3228 Normal C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
avgtray.exe 3264 Normal C:\PROGRA~1\AVG\AVG9\avgtray.exe
atiptaxx.exe 3288 Normal C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
Acrobat_sl.exe 3324 Normal C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe
Acrotray.exe 3384 Normal C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
iTunesHelper.exe 3752 Normal C:\Program Files\iTunes\iTunesHelper.exe
brctrcen.exe 3852 Normal C:\Program Files\Brother\ControlCenter2\brctrcen.exe
ctfmon.exe 3864 Normal C:\WINDOWS\system32\ctfmon.exe
GoogleToolbarNotifier.exe 3876 Normal C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
CLI.EXE 3888 Normal C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
hptskmgr.exe 3696 Normal C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
iPodService.exe 140 Normal C:\Program Files\iPod\bin\iPodService.exe
cli.exe 3432 Normal C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
cli.exe 3460 Normal C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
IEXPLORE.EXE 3544 Normal C:\Program Files\Internet Explorer\IEXPLORE.EXE
IEXPLORE.EXE 2192 Normal C:\Program Files\Internet Explorer\IEXPLORE.EXE
IEXPLORE.EXE 3496 Normal C:\Program Files\Internet Explorer\IEXPLORE.EXE
mss.exe 3952 Normal C:\Documents and Settings\Philip\Desktop\mss.exe
cmd.exe 3688 Normal C:\WINDOWS\system32\cmd.exe
pv.exe 2652 Normal C:\Documents and Settings\Philip\Desktop\pv.exe
User Profile check
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
ProfilesDirectory REG_EXPAND_SZ %SystemDrive%\Documents and Settings
DefaultUserProfile REG_SZ Default User
AllUsersProfile REG_SZ All Users
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
Flags REG_DWORD 0xc
State REG_DWORD 0x0
RefCount REG_DWORD 0x1
Sid REG_BINARY 010100000000000512000000
ProfileImagePath REG_EXPAND_SZ %systemroot%\system32\config\systemprofile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\LocalService
Sid REG_BINARY 010100000000000513000000
Flags REG_DWORD 0x9
State REG_DWORD 0x0
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0x25b12bb8
ProfileLoadTimeHigh REG_DWORD 0x1cc017b
RefCount REG_DWORD 0x2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\NetworkService
Sid REG_BINARY 010100000000000514000000
Flags REG_DWORD 0x9
State REG_DWORD 0x0
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0x2503200e
ProfileLoadTimeHigh REG_DWORD 0x1cc017b
RefCount REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1202660629-583907252-725345543-1003
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\Philip
Sid REG_BINARY 0105000000000005150000001525AF47B4B7CD2207E53B2BEB030000
Flags REG_DWORD 0x0
State REG_DWORD 0x100
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0x2bfce160
ProfileLoadTimeHigh REG_DWORD 0x1cc017b
RefCount REG_DWORD 0x1
RunLogonScriptSync REG_DWORD 0x0
OptimizedLogonStatus REG_DWORD 0xb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1202660629-583907252-725345543-1006
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\Wayne
Sid REG_BINARY 0105000000000005150000001525AF47B4B7CD2207E53B2BEE030000
Flags REG_DWORD 0x0
State REG_DWORD 0x100
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0xa7b887fc
ProfileLoadTimeHigh REG_DWORD 0x1cbd5e1
RefCount REG_DWORD 0x1
OptimizedLogonStatus REG_DWORD 0xb
RunLogonScriptSync REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1202660629-583907252-725345543-500
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\Administrator
Sid REG_BINARY 0105000000000005150000001525AF47B4B7CD2207E53B2BF4010000
Flags REG_DWORD 0x0
State REG_DWORD 0x100
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0xa6877f0e
ProfileLoadTimeHigh REG_DWORD 0x1cc00a3
RefCount REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
OptimizedLogonStatus REG_DWORD 0xb
Current Scheduled Tasks
PATH: C:\Windows\Tasks
AppleSoftwareUpdate.job
AWC AutoSweep.job
AWC Update.job
Driver Robot.job
Google Software Updater.job
GoogleUpdateTaskUserS-1-5-21-1202660629-583907252-725345543-1003Core.job
GoogleUpdateTaskUserS-1-5-21-1202660629-583907252-725345543-1003UA.job
ParetoLogic Registration3.job
ParetoLogic Update Version3.job
PC Health Advisor Defrag.job
PC Health Advisor.job
Scheduled Update for Ask Toolbar.job
WebReg 20090507203209.job
desktop.ini
SA.DAT
Windows Drivers and NT-Services
Volume in drive C has no label.
Volume Serial Number is 90EC-904F
Directory of C:\Windows\System32\Drivers
05/23/2009 20:55 0 MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
01/11/2011 21:50 0 MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
05/23/2009 20:55 0 Msft_Kernel_motmodem_01005.Wdf
01/11/2011 21:50 0 Msft_Kernel_motmodem_01007.Wdf
4 File(s) 0 bytes
0 Dir(s) 39,629,312,000 bytes free
Volume in drive C has no label.
Volume Serial Number is 90EC-904F
Directory of C:\Windows\System32\Drivers
09/10/1999 12:06 25,244 ASPI32.SYS
03/29/2000 07:17 5,824 ASUSHWIO.SYS
08/17/2001 06:28 794,399 USR1806V.SYS
08/17/2001 06:46 6,400 enum1394.sys
08/17/2001 06:57 16,128 MODEMCSA.sys
08/17/2001 06:59 3,072 audstub.sys
08/17/2001 07:00 2,944 msmpu401.sys
08/17/2001 13:48 12,160 mouhid.sys
08/17/2001 14:51 18,688 irsir.sys
08/17/2001 14:51 19,584 rasirda.sys
08/17/2001 14:51 3,328 pciide.sys
04/15/2002 22:11 67,866 netwlan5.img
08/13/2002 06:27 74,338 el90Xbc5.SYS
09/05/2002 20:24 13,568 nv_agp.SYS
09/22/2002 19:37 42 jedireg.pat
09/22/2002 19:37 80,896 NVENET.sys
09/22/2002 19:37 122 ramsed.bin
09/22/2002 19:37 1,024 jedih2rx.bin
03/31/2003 05:00 16,512 raspti.sys
03/31/2003 05:00 32,896 ipfltdrv.sys
03/31/2003 05:00 8,832 rasacd.sys
03/31/2003 05:00 34,432 rawwan.sys
03/31/2003 05:00 17,792 ptilink.sys
03/31/2003 05:00 4,736 usbd.sys
03/31/2003 05:00 12,160 fsvga.sys
03/31/2003 05:00 7,936 fs_rec.sys
03/31/2003 05:00 4,224 rdpcdd.sys
03/31/2003 05:00 125,056 ftdisk.sys
03/31/2003 05:00 3,328 dxgthk.sys
03/31/2003 05:00 4,352 wmilib.sys
03/31/2003 05:00 10,496 dxapi.sys
03/31/2003 05:00 21,376 tsbvcap.sys
03/31/2003 05:00 51,712 tosdvd.sys
03/31/2003 05:00 7,680 mcd.sys
03/31/2003 05:00 5,888 dmload.sys
03/31/2003 05:00 4,224 mnmdd.sys
03/31/2003 05:00 3,440,660 gm.dls
03/31/2003 05:00 11,648 acpiec.sys
03/31/2003 05:00 3,456 oprghdlr.sys
03/31/2003 05:00 12,032 rio8drv.sys
03/31/2003 05:00 55,936 nwlnkspx.sys
03/31/2003 05:00 11,776 cpqdap01.sys
03/31/2003 05:00 262,528 cinemst2.sys
03/31/2003 05:00 14,592 smclib.sys
03/31/2003 05:00 18,688 cdaudio.sys
03/31/2003 05:00 13,952 cbidf2k.sys
03/31/2003 05:00 12,032 ws2ifsl.sys
03/31/2003 05:00 12,032 nikedrv.sys
03/31/2003 05:00 2,944 null.sys
03/31/2003 05:00 4,224 beep.sys
03/31/2003 05:00 12,032 riodrv.sys
03/31/2003 05:00 58,112 vdmindvd.sys
03/31/2003 05:00 646 gmreadme.txt
03/31/2003 05:00 6,784 parvdm.sys
03/31/2003 05:00 5,888 rootmdm.sys
03/31/2003 05:00 352,256 atmuni.sys
03/31/2003 05:00 63,232 nwlnknb.sys
03/31/2003 05:00 32,512 nwlnkfwd.sys
03/31/2003 05:00 31,360 atmepvc.sys
03/31/2003 05:00 12,416 nwlnkflt.sys
08/22/2003 13:03 105,633 ET251.sys
09/29/2003 22:25 22,880 Gvcpldrv.sys
01/05/2004 00:27 51,056 hpzid412.sys
01/05/2004 00:27 21,488 HPZius12.sys
01/05/2004 00:27 16,496 HPZipr12.sys
05/25/2004 15:58 48,640 nvax.sys
05/25/2004 15:58 66,688 nvarm.sys
05/25/2004 15:58 396,032 nvapu.sys
05/25/2004 15:58 962,560 nvmcp.sys
07/17/2004 11:36 64,352 ativmc20.cod
07/17/2004 22:55 129,045 cxthsfs2.cty
08/03/2004 22:29 327,040 ati2mtaa.sys
08/03/2004 22:29 57,856 atinbtxx.sys
08/03/2004 22:29 13,824 atinmdxx.sys
08/03/2004 22:29 12,047 ati1pdxx.sys
08/03/2004 22:29 52,224 atinraxx.sys
08/03/2004 22:29 11,615 ati1mdxx.sys
08/03/2004 22:29 56,623 ati1btxx.sys
08/03/2004 22:29 14,336 atinpdxx.sys
08/03/2004 22:29 28,672 atinsnxx.sys
08/03/2004 22:29 104,960 atinrvxx.sys
08/03/2004 22:29 13,824 atinttxx.sys
08/03/2004 22:29 30,671 ati1raxx.sys
08/03/2004 22:29 63,663 ati1rvxx.sys
08/03/2004 22:29 36,463 ati1tuxx.sys
08/03/2004 22:29 31,744 atinxbxx.sys
08/03/2004 22:29 29,455 ati1xbxx.sys
08/03/2004 22:29 73,216 atintuxx.sys
08/03/2004 22:29 34,735 ati1xsxx.sys
08/03/2004 22:29 26,367 ati1snxx.sys
08/03/2004 22:29 21,343 ati1ttxx.sys
08/03/2004 22:29 63,488 atinxsxx.sys
08/03/2004 22:29 452,736 mtxparhm.sys
08/03/2004 22:29 11,807 wadv07nt.sys
08/03/2004 22:29 11,295 wadv08nt.sys
08/03/2004 22:29 11,871 wadv09nt.sys
08/03/2004 22:29 11,935 wadv11nt.sys
08/03/2004 22:29 22,271 watv06nt.sys
08/03/2004 22:29 25,471 watv10nt.sys
08/03/2004 22:29 166,912 s3gnbm.sys
08/03/2004 22:29 1,897,408 nv4_mini.sys
08/03/2004 22:41 1,309,184 mtlstrm.sys
08/03/2004 22:41 126,686 mtlmnt5.sys
08/03/2004 22:41 13,776 recagent.sys
08/03/2004 22:41 180,360 ntmtlfax.sys
08/03/2004 22:41 129,535 slnt7554.sys
08/03/2004 22:41 404,990 slntamr.sys
08/03/2004 22:41 95,424 slnthal.sys
08/03/2004 22:41 13,240 slwdmsup.sys
08/03/2004 22:41 220,032 hsfbs2s2.sys
08/03/2004 22:41 685,056 hsfcxts2.sys
08/03/2004 22:41 1,041,536 hsfdpsp2.sys
08/03/2004 22:41 11,868 mdmxsdk.sys
10/15/2004 12:50 15,295 BrScnUsb.sys
02/23/2005 14:58 11,776 afc.sys
07/25/2005 11:04 48,640 ser2pl.sys
04/26/2006 14:21 25,214 VOLHelp.ico
08/23/2006 14:26 2,096 ativdkxx.vp
08/23/2006 14:26 2,096 ativckxx.vp
08/23/2006 14:26 655,842 ativcaxx.cpa
08/23/2006 14:26 929 ativcaxx.vp
09/28/2006 18:55 77,568 WudfPf.sys
09/28/2006 19:00 82,944 WudfRd.sys
10/11/2006 18:21 49,152 ati2erec.dll
10/11/2006 18:43 1,777,152 ati2mtag.sys
10/11/2006 19:11 36,272 ativvpxx.vp
10/18/2006 20:00 38,528 wpdusb.sys
03/27/2008 17:27 503,008 wdf01000.sys
03/27/2008 17:27 35,040 wdfldr.sys
04/13/2008 09:36 144,384 hdaudbus.sys
04/13/2008 09:39 20,480 secdrv.sys
04/13/2008 09:39 142,592 aec.sys
04/13/2008 11:31 35,840 processr.sys
04/13/2008 11:31 42,752 p3.sys
04/13/2008 11:31 37,376 amdk6.sys
04/13/2008 11:31 36,352 intelppm.sys
04/13/2008 11:31 36,736 crusoe.sys
04/13/2008 11:31 37,760 amdk7.sys
04/13/2008 11:32 66,048 udfs.sys
04/13/2008 11:32 30,848 npfs.sys
04/13/2008 11:32 19,072 msfs.sys
04/13/2008 11:32 180,608 mrxdav.sys
04/13/2008 11:32 196,224 rdpdr.sys
04/13/2008 11:32 129,792 fltmgr.sys
04/13/2008 11:33 44,544 fips.sys
04/13/2008 11:34 163,584 nwrdr.sys
04/13/2008 11:36 5,888 smbali.sys
04/13/2008 11:36 187,776 acpi.sys
04/13/2008 11:36 42,752 alim1541.sys
04/13/2008 11:36 42,368 agp440.sys
04/13/2008 11:36 44,928 agpcpq.sys
04/13/2008 11:36 43,008 amdagp.sys
04/13/2008 11:36 40,960 sisagp.sys
04/13/2008 11:36 42,240 viaagp.sys
04/13/2008 11:36 46,464 gagp30kx.sys
04/13/2008 11:36 44,672 uagp35.sys
04/13/2008 11:36 63,744 mf.sys
04/13/2008 11:36 37,248 isapnp.sys
04/13/2008 11:36 120,192 pcmcia.sys
04/13/2008 11:36 79,232 sdbus.sys
04/13/2008 11:36 68,224 pci.sys
04/13/2008 11:36 15,488 mssmbios.sys
04/13/2008 11:36 73,472 sr.sys
04/13/2008 11:38 71,168 dxg.sys
04/13/2008 11:39 92,544 mqac.sys
04/13/2008 11:39 384,768 update.sys
04/13/2008 11:39 42,368 mountmgr.sys
04/13/2008 11:39 24,576 kbdclass.sys
04/13/2008 11:39 23,040 mouclass.sys
04/13/2008 11:39 5,376 mspclock.sys
04/13/2008 11:39 4,992 mspqm.sys
04/13/2008 11:39 7,552 mskssrv.sys
04/13/2008 11:39 4,352 swenum.sys
04/13/2008 11:40 80,128 parport.sys
04/13/2008 11:40 15,744 serenum.sys
04/13/2008 11:40 20,480 flpydisk.sys
04/13/2008 11:40 27,392 fdc.sys
04/13/2008 11:40 57,600 redbook.sys
04/13/2008 11:40 24,960 pciidex.sys
04/13/2008 11:40 96,384 scsiport.sys
04/13/2008 11:40 96,512 atapi.sys
04/13/2008 11:40 14,208 diskdump.sys
04/13/2008 11:40 62,976 cdrom.sys
04/13/2008 11:40 36,352 disk.sys
04/13/2008 11:40 11,904 sffdisk.sys
04/13/2008 11:40 11,008 sffp_sd.sys
04/13/2008 11:40 11,392 sfloppy.sys
04/13/2008 11:40 10,240 sffp_mmc.sys
04/13/2008 11:40 19,712 partmgr.sys
04/13/2008 11:40 14,976 tape.sys
04/13/2008 11:40 42,112 imapi.sys
04/13/2008 11:41 52,352 volsnap.sys
04/13/2008 11:43 12,672 mutohpen.sys
04/13/2008 11:43 14,208 wacompen.sys
04/13/2008 11:44 20,992 vga.sys
04/13/2008 11:44 81,664 videoprt.sys
04/13/2008 11:44 153,344 dmio.sys
04/13/2008 11:44 799,744 dmboot.sys
04/13/2008 11:45 52,864 dmusic.sys
04/13/2008 11:45 6,272 splitter.sys
04/13/2008 11:45 172,416 kmixer.sys
04/13/2008 11:45 56,576 swmidi.sys
04/13/2008 11:45 2,944 drmkaud.sys
04/13/2008 11:45 60,160 drmk.sys
04/13/2008 11:45 49,408 stream.sys
04/13/2008 11:45 24,960 hidparse.sys
04/13/2008 11:45 19,200 hidir.sys
04/13/2008 11:45 36,864 hidclass.sys
04/13/2008 11:45 10,368 hidusb.sys
04/13/2008 11:45 10,624 gameenum.sys
04/13/2008 11:45 46,592 irbus.sys
04/13/2008 11:45 15,104 usbscan.sys
04/13/2008 11:45 17,152 usbohci.sys
04/13/2008 11:45 30,208 usbehci.sys
04/13/2008 11:45 143,872 usbport.sys
04/13/2008 11:45 26,112 usbser.sys
04/13/2008 11:45 59,520 usbhub.sys
04/13/2008 11:45 26,368 usbstor.sys
04/13/2008 11:45 32,128 usbccgp.sys
04/13/2008 11:45 25,600 usbcamd.sys
04/13/2008 11:45 25,728 usbcamd2.sys
04/13/2008 11:45 15,872 usbintel.sys
04/13/2008 11:46 25,344 sonydcam.sys
04/13/2008 11:46 53,376 1394bus.sys
04/13/2008 11:46 61,696 ohci1394.sys
04/13/2008 11:46 121,984 usbvideo.sys
04/13/2008 11:46 18,944 bthusb.sys
04/13/2008 11:46 25,600 hidbth.sys
04/13/2008 11:46 36,480 bthprint.sys
04/13/2008 11:46 59,136 rfcomm.sys
04/13/2008 11:46 17,024 bthenum.sys
04/13/2008 11:46 37,888 bthmodem.sys
04/13/2008 11:47 25,856 usbprint.sys
04/13/2008 11:51 60,800 arp1394.sys
04/13/2008 11:51 59,904 atmarpc.sys
04/13/2008 11:51 61,824 nic1394.sys
04/13/2008 11:51 55,808 atmlane.sys
04/13/2008 11:51 101,120 bthpan.sys
04/13/2008 11:53 40,320 nmnt.sys
04/13/2008 11:53 71,552 bridge.sys
04/13/2008 11:53 36,608 ip6fw.sys
04/13/2008 11:54 11,264 irenum.sys
04/13/2008 11:55 14,592 ndisuio.sys
04/13/2008 11:56 12,288 tunmp.sys
04/13/2008 11:56 34,688 netbios.sys
04/13/2008 11:56 88,320 nwlnkipx.sys
04/13/2008 11:56 35,072 msgpc.sys
04/13/2008 11:56 69,120 psched.sys
04/13/2008 11:56 12,800 usb8023.sys
04/13/2008 11:56 30,592 rndismpx.sys
04/13/2008 11:56 12,800 usb8023x.sys
04/13/2008 11:56 30,592 rndismp.sys
04/13/2008 11:57 20,864 ipinip.sys
04/13/2008 11:57 152,832 ipnat.sys
04/13/2008 11:57 34,560 wanarp.sys
04/13/2008 11:57 14,336 asyncmac.sys
04/13/2008 11:57 10,112 ndistapi.sys
04/13/2008 11:57 41,472 raspppoe.sys
04/13/2008 12:00 19,072 tdi.sys
04/13/2008 12:00 30,080 modem.sys
04/13/2008 12:14 63,744 cdfs.sys
04/13/2008 12:14 143,744 fastfat.sys
04/13/2008 12:15 64,512 serial.sys
04/13/2008 12:15 574,976 ntfs.sys
04/13/2008 12:15 60,800 sysaudio.sys
04/13/2008 12:16 49,536 classpnp.sys
04/13/2008 12:17 105,344 mup.sys
04/13/2008 12:17 83,072 wdmaud.sys
04/13/2008 12:18 52,480 i8042prt.sys
04/13/2008 12:19 146,048 portcls.sys
04/13/2008 12:19 75,264 ipsec.sys
04/13/2008 12:19 51,328 rasl2tp.sys
04/13/2008 12:19 48,384 raspptp.sys
04/13/2008 12:20 182,656 ndis.sys
04/13/2008 12:20 91,520 ndiswan.sys
04/13/2008 12:21 162,816 netbt.sys
04/13/2008 12:28 175,744 rdbss.sys
04/13/2008 12:39 5,504 MSTEE.sys
04/13/2008 12:45 60,032 USBAUDIO.sys
04/13/2008 12:46 15,232 StreamIP.sys
04/13/2008 12:46 10,880 NdisIP.sys
04/13/2008 12:46 11,136 SLIP.sys
04/13/2008 12:46 19,200 WSTCODEC.SYS
04/13/2008 12:46 17,024 CCDECODE.sys
04/13/2008 12:46 85,248 NABTSFEC.sys
04/13/2008 12:54 88,192 irda.sys
04/13/2008 13:16 141,056 ks.sys
04/13/2008 17:11 3,135 adv08nt5.dll
04/13/2008 17:11 3,615 adv05nt5.dll
04/13/2008 17:11 4,255 adv01nt5.dll
04/13/2008 17:11 3,775 adv11nt5.dll
04/13/2008 17:11 3,711 adv09nt5.dll
04/13/2008 17:11 3,967 adv02nt5.dll
04/13/2008 17:11 3,647 adv07nt5.dll
04/13/2008 17:11 14,143 atv06nt5.dll
04/13/2008 17:11 11,359 atv02nt5.dll
04/13/2008 17:11 21,183 atv01nt5.dll
04/13/2008 17:11 15,423 ch7xxnt5.dll
04/13/2008 17:11 25,471 atv04nt5.dll
04/13/2008 17:11 17,279 atv10nt5.dll
04/13/2008 17:12 3,901 siint5.dll
04/13/2008 17:12 11,325 vchnt5.dll
04/13/2008 17:13 12,040 tdpipe.sys
04/13/2008 17:13 40,840 termdd.sys
04/13/2008 17:13 21,896 tdtcp.sys
04/13/2008 17:13 139,656 rdpwd.sys
05/08/2008 07:02 203,136 rmcast.sys
06/13/2008 04:05 272,128 bthport.sys
06/20/2008 04:51 361,600 tcpip.sys
10/16/2008 07:43 138,496 afd.sys
11/11/2008 15:58 23,096 MusCAudio.sys
11/11/2008 15:58 3,768 MusCVideo.sys
11/25/2008 10:26 disdn
11/27/2008 12:52 22,768 usbsermpt.sys
12/18/2008 13:16 73,840 PCTAppEvent.sys
05/18/2009 14:17 26,600 GEARAspiWDM.sys
06/24/2009 04:18 92,928 ksecdd.sys
09/09/2009 09:16 UMDF
10/20/2009 09:20 265,728 http.sys
10/27/2009 13:02 23,936 motmodem.sys
02/11/2010 05:02 226,880 tcpip6.sys
06/07/2010 19:51 29,584 avgmfx86.sys
07/15/2010 16:41 216,400 avgldx86.sys
07/15/2010 16:41 243,024 avgtdix.sys
08/14/2010 14:48 691,696 sptd.sys
09/28/2010 16:44 41,984 usbaapl.sys
11/02/2010 08:17 40,960 ndproxy.sys
11/10/2010 20:30 4,122,368 ALCXWDM.SYS
11/10/2010 20:32 7,180 a2ptbtn.sys
12/13/2010 15:37 30,576 nx6000.sys
12/20/2010 18:08 20,952 mbam.sys
12/20/2010 18:09 38,224 mbamswissarmy.sys
02/17/2011 06:18 357,888 srv.sys
02/17/2011 06:18 455,936 mrxsmb.sys
04/21/2011 22:16 etc
04/22/2011 16:36 Avg
04/22/2011 22:33 .
04/22/2011 22:33 ..
332 File(s) 37,569,819 bytes
6 Dir(s) 39,629,275,136 bytes free
Stealth malware?
Internet Explorer
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main
Default_Page_URL REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Enable_Disk_Cache REG_SZ yes
Cache_Percent_of_Disk REG_BINARY 0A000000
Delete_Temp_Files_On_Exit REG_SZ yes
Anchor_Visitation_Horizon REG_BINARY 01000000
Use_Async_DNS REG_SZ yes
Placeholder_Width REG_BINARY 1A000000
Placeholder_Height REG_BINARY 1A000000
Start Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
CompanyName REG_SZ Microsoft Corporation
Custom_Key REG_SZ MICROSO
Wizard_Version REG_SZ 6.0.2600.0000
FullScreen REG_SZ no
Check_Associations REG_SZ yes
Default_Secondary_Page_URL REG_MULTI_SZ \0
Extensions Off Page REG_SZ about:NoAdd-ons
Security Risk Page REG_SZ about:SecurityRisk
DEPOff REG_DWORD 0x0
StatusBarWeb REG_DWORD 0x1
SearchControlWidth REG_DWORD 0x12c
ForceGDIPlus REG_DWORD 0x0
MaxRenderLine REG_DWORD 0xfa0
UseClearType REG_SZ yes
Page_Transitions REG_DWORD 0x1
Use_DlgBox_Colors REG_SZ yes
Anchor Underline REG_SZ yes
Display Inline Images REG_SZ yes
Display Inline Videos REG_DWORD 0x1
Play_Background_Sounds REG_SZ yes
Play_Animations REG_SZ yes
Print_Background REG_SZ no
SmoothScroll REG_DWORD 0x1
XMLHTTP REG_DWORD 0x1
Show image placeholders REG_DWORD 0x0
Disable Script Debugger REG_SZ yes
Enable AutoImageResize REG_SZ yes
XDomainRequest REG_DWORD 0x1
DOMStorage REG_DWORD 0x1
IE8RunOnceLastShown REG_DWORD 0x0
IE8RunOncePerInstallCompleted REG_DWORD 0x0
IE8TourNoShow REG_DWORD 0x0
IE8TourShown REG_DWORD 0x0
FrameTabWindow REG_DWORD 0x1
AdminTabProcs REG_DWORD 0x1
SessionMerging REG_DWORD 0x1
FrameMerging REG_DWORD 0x1
HangResistantFrame REG_DWORD 0x0
TabShutdownDelay REG_DWORD 0xea60
FrameShutdownDelay REG_DWORD 0x0
IEWatsonDisable REG_DWORD 0x1
Local Page REG_SZ C:\windows\system32\blank.htm
SearchMigrated REG_DWORD 0x0
Use Custom Search URL REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\ErrorThresholds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\UrlTemplate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\WindowsSearch
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
User Agent REG_SZ Mozilla/4.0 (compatible; MSIE 8.0; Win32)
IE5_UA_Backup_Flag REG_SZ 5.0
NoNetAutodial REG_DWORD 0x1
MigrateProxy REG_DWORD 0x1
EnableNegotiate REG_DWORD 0x1
ProxyEnable REG_DWORD 0x0
EmailName REG_SZ IEUser@
AutoConfigProxy REG_SZ wininet.dll
MimeExclusionListForCache REG_SZ multipart/mixed multipart/x-mixed-replace multipart/x-byteranges
WarnOnPost REG_BINARY 01000000
UseSchannelDirectly REG_BINARY 01000000
EnableHttp1_1 REG_DWORD 0x1
PrivacyAdvanced REG_DWORD 0x0
EnableAutodial REG_DWORD 0x1
GlobalUserOffline REG_DWORD 0x0
PrivDiscUiShown REG_DWORD 0x1
WarnOnZoneCrossing REG_DWORD 0x0
SyncMode5 REG_DWORD 0x4
WarnonBadCertRecving REG_DWORD 0x1
WarnOnPostRedirect REG_DWORD 0x0
WarnOnHTTPSToHTTPRedirect REG_DWORD 0x1
UrlEncoding REG_DWORD 0x0
SecureProtocols REG_DWORD 0x28
ZonesSecurityUpgrade REG_BINARY DE8B3646EAE0C901
DisableCachingOfSSLPages REG_DWORD 0x0
ProxyOverride REG_SZ;*.local
ProxyHttp1.1 REG_DWORD 0x1
ShowPunycode REG_DWORD 0x0
EnablePunycode REG_DWORD 0x1
DisableIDNPrompt REG_DWORD 0x0
CertificateRevocation REG_DWORD 0x0
MaxConnectionsPerServer REG_DWORD 0xa
MaxConnectionsPer1_0Server REG_DWORD 0xa
CreateUriCacheSize REG_DWORD 0x50
CoInternetCombineIUriCacheSize REG_DWORD 0x50
SecurityIdIUriCacheSize REG_DWORD 0x1e
SpecialFoldersCacheSize REG_DWORD 0x8
WarnOnIntranet REG_DWORD 0x1
www.malwarebytes.org
Database version: 6422
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
4/22/2011 5:38:14 PM
mbam-log-2011-04-22 (17-38-14).txt
Scan type: Quick scan
Objects scanned: 183627
Time elapsed: 8 minute(s), 47 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 11
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\itlnfw32 (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\GoWNKtoBbTfMqRQ (Trojan.FakeAlert) -> Value: GoWNKtoBbTfMqRQ -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\documents and settings\all users\application data\gownktobbtfmqrq.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\itlnfw32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\16899892.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\null0.019796283825301852.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\null0.09884048293238279.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\null0.21870310611980437.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\null0.5718803396663437.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\null0.8356442089299158.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\WINDOWS\temp\jar_cache1442940674180269922.tmp (Trojan.FakeAlert) -> Delete on reboot.
c:\WINDOWS\temp\jar_cache2772797397516559471.tmp (Trojan.FakeAlert) -> Delete on reboot.
c:\WINDOWS\temp\jar_cache6944927343098075797.tmp (Trojan.FakeAlert) -> Delete on reboot.
___________________________________________________________________________________________________________________
mss log:
MySystem-Search
MSS v1.7
Basic System Information
Username: Philip - Date: 04/22/2011 - Time: 23:00:39
Microsoft Windows XP [Version 5.1.2600]
Processor type: x86 Family 6 Model 10 Stepping 0, AuthenticAMD
Total processors: 1
Computer Name: DARREN
Logon Server: \\DARREN
CD Emulation Drivers running?
DAEMON Tools/Duplex Secure found!
Peer-to-Peer applications?
Security Tools Check
CCleaner
Trend Micro HijackThis
Malwarebytes' Anti-Malware
File associations
.exe=exefile
.scr=scrfile
.pif=piffile
.com=comfile
.bat=batfile
.cmd=cmdfile
.log=txtfile
.txt=txtfile
.reg=regfile
.sys=sysfile
.dll=dllfile
.ini=inifile
.inf=inffile
Running processes
PROCESS PID PRIO PATH
smss.exe 716 Normal C:\WINDOWS\System32\smss.exe
csrss.exe 780 Normal C:\WINDOWS\system32\csrss.exe
winlogon.exe 812 High C:\WINDOWS\system32\winlogon.exe
avgchsvx.exe 824 Normal C:\Program Files\AVG\AVG9\avgchsvx.exe
avgrsx.exe 832 Normal C:\Program Files\AVG\AVG9\avgrsx.exe
avgcsrvx.exe 904 Normal C:\Program Files\AVG\AVG9\avgcsrvx.exe
services.exe 936 Normal C:\WINDOWS\system32\services.exe
lsass.exe 948 Normal C:\WINDOWS\system32\lsass.exe
Ati2evxx.exe 1340 Normal C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe 1364 Normal C:\WINDOWS\system32\svchost.exe
svchost.exe 1452 Normal C:\WINDOWS\system32\svchost.exe
svchost.exe 1628 Normal C:\WINDOWS\System32\svchost.exe
Ati2evxx.exe 1752 Normal C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe 1908 Normal C:\WINDOWS\system32\svchost.exe
spoolsv.exe 268 Normal C:\WINDOWS\system32\spoolsv.exe
AppleMobileDeviceService.exe 1380 Normal C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
avgwdsvc.exe 1528 Normal C:\Program Files\AVG\AVG9\avgwdsvc.exe
mDNSResponder.exe 1548 Normal C:\Program Files\Bonjour\mDNSResponder.exe
jqs.exe 1896 Idle C:\Program Files\Java\jre6\bin\jqs.exe
MDM.EXE 1980 Normal C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
MSCamS32.exe 308 Normal C:\Program Files\Microsoft LifeCam\MSCamS32.exe
RosettaStoneDaemon.exe 404 Normal C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe
SeaPort.EXE 484 Normal C:\Program Files\Microsoft\BingBar\SeaPort.EXE
svchost.exe 536 Normal C:\WINDOWS\System32\svchost.exe
WLIDSVC.EXE 624 Normal C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
avgnsx.exe 1716 Normal C:\Program Files\AVG\AVG9\avgnsx.exe
wuauclt.exe 2268 Normal C:\WINDOWS\system32\wuauclt.exe
Explorer.EXE 2380 Normal C:\WINDOWS\Explorer.EXE
WLIDSvcM.exe 2572 Normal C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
alg.exe 2724 Normal C:\WINDOWS\System32\alg.exe
SOUNDMAN.EXE 3156 Normal C:\WINDOWS\SOUNDMAN.EXE
shwicon.exe 3172 Normal C:\Program Files\USB Product Driver v2.16r002\shwicon.exe
hpcmpmgr.exe 3228 Normal C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
avgtray.exe 3264 Normal C:\PROGRA~1\AVG\AVG9\avgtray.exe
atiptaxx.exe 3288 Normal C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
Acrobat_sl.exe 3324 Normal C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe
Acrotray.exe 3384 Normal C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
iTunesHelper.exe 3752 Normal C:\Program Files\iTunes\iTunesHelper.exe
brctrcen.exe 3852 Normal C:\Program Files\Brother\ControlCenter2\brctrcen.exe
ctfmon.exe 3864 Normal C:\WINDOWS\system32\ctfmon.exe
GoogleToolbarNotifier.exe 3876 Normal C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
CLI.EXE 3888 Normal C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
hptskmgr.exe 3696 Normal C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
iPodService.exe 140 Normal C:\Program Files\iPod\bin\iPodService.exe
cli.exe 3432 Normal C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
cli.exe 3460 Normal C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
IEXPLORE.EXE 3544 Normal C:\Program Files\Internet Explorer\IEXPLORE.EXE
IEXPLORE.EXE 2192 Normal C:\Program Files\Internet Explorer\IEXPLORE.EXE
IEXPLORE.EXE 3496 Normal C:\Program Files\Internet Explorer\IEXPLORE.EXE
mss.exe 3952 Normal C:\Documents and Settings\Philip\Desktop\mss.exe
cmd.exe 3688 Normal C:\WINDOWS\system32\cmd.exe
pv.exe 2652 Normal C:\Documents and Settings\Philip\Desktop\pv.exe
User Profile check
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
ProfilesDirectory REG_EXPAND_SZ %SystemDrive%\Documents and Settings
DefaultUserProfile REG_SZ Default User
AllUsersProfile REG_SZ All Users
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
Flags REG_DWORD 0xc
State REG_DWORD 0x0
RefCount REG_DWORD 0x1
Sid REG_BINARY 010100000000000512000000
ProfileImagePath REG_EXPAND_SZ %systemroot%\system32\config\systemprofile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\LocalService
Sid REG_BINARY 010100000000000513000000
Flags REG_DWORD 0x9
State REG_DWORD 0x0
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0x25b12bb8
ProfileLoadTimeHigh REG_DWORD 0x1cc017b
RefCount REG_DWORD 0x2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\NetworkService
Sid REG_BINARY 010100000000000514000000
Flags REG_DWORD 0x9
State REG_DWORD 0x0
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0x2503200e
ProfileLoadTimeHigh REG_DWORD 0x1cc017b
RefCount REG_DWORD 0x1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1202660629-583907252-725345543-1003
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\Philip
Sid REG_BINARY 0105000000000005150000001525AF47B4B7CD2207E53B2BEB030000
Flags REG_DWORD 0x0
State REG_DWORD 0x100
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0x2bfce160
ProfileLoadTimeHigh REG_DWORD 0x1cc017b
RefCount REG_DWORD 0x1
RunLogonScriptSync REG_DWORD 0x0
OptimizedLogonStatus REG_DWORD 0xb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1202660629-583907252-725345543-1006
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\Wayne
Sid REG_BINARY 0105000000000005150000001525AF47B4B7CD2207E53B2BEE030000
Flags REG_DWORD 0x0
State REG_DWORD 0x100
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0xa7b887fc
ProfileLoadTimeHigh REG_DWORD 0x1cbd5e1
RefCount REG_DWORD 0x1
OptimizedLogonStatus REG_DWORD 0xb
RunLogonScriptSync REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1202660629-583907252-725345543-500
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\Administrator
Sid REG_BINARY 0105000000000005150000001525AF47B4B7CD2207E53B2BF4010000
Flags REG_DWORD 0x0
State REG_DWORD 0x100
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0xa6877f0e
ProfileLoadTimeHigh REG_DWORD 0x1cc00a3
RefCount REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
OptimizedLogonStatus REG_DWORD 0xb
Current Scheduled Tasks
PATH: C:\Windows\Tasks
AppleSoftwareUpdate.job
AWC AutoSweep.job
AWC Update.job
Driver Robot.job
Google Software Updater.job
GoogleUpdateTaskUserS-1-5-21-1202660629-583907252-725345543-1003Core.job
GoogleUpdateTaskUserS-1-5-21-1202660629-583907252-725345543-1003UA.job
ParetoLogic Registration3.job
ParetoLogic Update Version3.job
PC Health Advisor Defrag.job
PC Health Advisor.job
Scheduled Update for Ask Toolbar.job
WebReg 20090507203209.job
desktop.ini
SA.DAT
Windows Drivers and NT-Services
Volume in drive C has no label.
Volume Serial Number is 90EC-904F
Directory of C:\Windows\System32\Drivers
05/23/2009 20:55 0 MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
01/11/2011 21:50 0 MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
05/23/2009 20:55 0 Msft_Kernel_motmodem_01005.Wdf
01/11/2011 21:50 0 Msft_Kernel_motmodem_01007.Wdf
4 File(s) 0 bytes
0 Dir(s) 39,629,312,000 bytes free
Volume in drive C has no label.
Volume Serial Number is 90EC-904F
Directory of C:\Windows\System32\Drivers
09/10/1999 12:06 25,244 ASPI32.SYS
03/29/2000 07:17 5,824 ASUSHWIO.SYS
08/17/2001 06:28 794,399 USR1806V.SYS
08/17/2001 06:46 6,400 enum1394.sys
08/17/2001 06:57 16,128 MODEMCSA.sys
08/17/2001 06:59 3,072 audstub.sys
08/17/2001 07:00 2,944 msmpu401.sys
08/17/2001 13:48 12,160 mouhid.sys
08/17/2001 14:51 18,688 irsir.sys
08/17/2001 14:51 19,584 rasirda.sys
08/17/2001 14:51 3,328 pciide.sys
04/15/2002 22:11 67,866 netwlan5.img
08/13/2002 06:27 74,338 el90Xbc5.SYS
09/05/2002 20:24 13,568 nv_agp.SYS
09/22/2002 19:37 42 jedireg.pat
09/22/2002 19:37 80,896 NVENET.sys
09/22/2002 19:37 122 ramsed.bin
09/22/2002 19:37 1,024 jedih2rx.bin
03/31/2003 05:00 16,512 raspti.sys
03/31/2003 05:00 32,896 ipfltdrv.sys
03/31/2003 05:00 8,832 rasacd.sys
03/31/2003 05:00 34,432 rawwan.sys
03/31/2003 05:00 17,792 ptilink.sys
03/31/2003 05:00 4,736 usbd.sys
03/31/2003 05:00 12,160 fsvga.sys
03/31/2003 05:00 7,936 fs_rec.sys
03/31/2003 05:00 4,224 rdpcdd.sys
03/31/2003 05:00 125,056 ftdisk.sys
03/31/2003 05:00 3,328 dxgthk.sys
03/31/2003 05:00 4,352 wmilib.sys
03/31/2003 05:00 10,496 dxapi.sys
03/31/2003 05:00 21,376 tsbvcap.sys
03/31/2003 05:00 51,712 tosdvd.sys
03/31/2003 05:00 7,680 mcd.sys
03/31/2003 05:00 5,888 dmload.sys
03/31/2003 05:00 4,224 mnmdd.sys
03/31/2003 05:00 3,440,660 gm.dls
03/31/2003 05:00 11,648 acpiec.sys
03/31/2003 05:00 3,456 oprghdlr.sys
03/31/2003 05:00 12,032 rio8drv.sys
03/31/2003 05:00 55,936 nwlnkspx.sys
03/31/2003 05:00 11,776 cpqdap01.sys
03/31/2003 05:00 262,528 cinemst2.sys
03/31/2003 05:00 14,592 smclib.sys
03/31/2003 05:00 18,688 cdaudio.sys
03/31/2003 05:00 13,952 cbidf2k.sys
03/31/2003 05:00 12,032 ws2ifsl.sys
03/31/2003 05:00 12,032 nikedrv.sys
03/31/2003 05:00 2,944 null.sys
03/31/2003 05:00 4,224 beep.sys
03/31/2003 05:00 12,032 riodrv.sys
03/31/2003 05:00 58,112 vdmindvd.sys
03/31/2003 05:00 646 gmreadme.txt
03/31/2003 05:00 6,784 parvdm.sys
03/31/2003 05:00 5,888 rootmdm.sys
03/31/2003 05:00 352,256 atmuni.sys
03/31/2003 05:00 63,232 nwlnknb.sys
03/31/2003 05:00 32,512 nwlnkfwd.sys
03/31/2003 05:00 31,360 atmepvc.sys
03/31/2003 05:00 12,416 nwlnkflt.sys
08/22/2003 13:03 105,633 ET251.sys
09/29/2003 22:25 22,880 Gvcpldrv.sys
01/05/2004 00:27 51,056 hpzid412.sys
01/05/2004 00:27 21,488 HPZius12.sys
01/05/2004 00:27 16,496 HPZipr12.sys
05/25/2004 15:58 48,640 nvax.sys
05/25/2004 15:58 66,688 nvarm.sys
05/25/2004 15:58 396,032 nvapu.sys
05/25/2004 15:58 962,560 nvmcp.sys
07/17/2004 11:36 64,352 ativmc20.cod
07/17/2004 22:55 129,045 cxthsfs2.cty
08/03/2004 22:29 327,040 ati2mtaa.sys
08/03/2004 22:29 57,856 atinbtxx.sys
08/03/2004 22:29 13,824 atinmdxx.sys
08/03/2004 22:29 12,047 ati1pdxx.sys
08/03/2004 22:29 52,224 atinraxx.sys
08/03/2004 22:29 11,615 ati1mdxx.sys
08/03/2004 22:29 56,623 ati1btxx.sys
08/03/2004 22:29 14,336 atinpdxx.sys
08/03/2004 22:29 28,672 atinsnxx.sys
08/03/2004 22:29 104,960 atinrvxx.sys
08/03/2004 22:29 13,824 atinttxx.sys
08/03/2004 22:29 30,671 ati1raxx.sys
08/03/2004 22:29 63,663 ati1rvxx.sys
08/03/2004 22:29 36,463 ati1tuxx.sys
08/03/2004 22:29 31,744 atinxbxx.sys
08/03/2004 22:29 29,455 ati1xbxx.sys
08/03/2004 22:29 73,216 atintuxx.sys
08/03/2004 22:29 34,735 ati1xsxx.sys
08/03/2004 22:29 26,367 ati1snxx.sys
08/03/2004 22:29 21,343 ati1ttxx.sys
08/03/2004 22:29 63,488 atinxsxx.sys
08/03/2004 22:29 452,736 mtxparhm.sys
08/03/2004 22:29 11,807 wadv07nt.sys
08/03/2004 22:29 11,295 wadv08nt.sys
08/03/2004 22:29 11,871 wadv09nt.sys
08/03/2004 22:29 11,935 wadv11nt.sys
08/03/2004 22:29 22,271 watv06nt.sys
08/03/2004 22:29 25,471 watv10nt.sys
08/03/2004 22:29 166,912 s3gnbm.sys
08/03/2004 22:29 1,897,408 nv4_mini.sys
08/03/2004 22:41 1,309,184 mtlstrm.sys
08/03/2004 22:41 126,686 mtlmnt5.sys
08/03/2004 22:41 13,776 recagent.sys
08/03/2004 22:41 180,360 ntmtlfax.sys
08/03/2004 22:41 129,535 slnt7554.sys
08/03/2004 22:41 404,990 slntamr.sys
08/03/2004 22:41 95,424 slnthal.sys
08/03/2004 22:41 13,240 slwdmsup.sys
08/03/2004 22:41 220,032 hsfbs2s2.sys
08/03/2004 22:41 685,056 hsfcxts2.sys
08/03/2004 22:41 1,041,536 hsfdpsp2.sys
08/03/2004 22:41 11,868 mdmxsdk.sys
10/15/2004 12:50 15,295 BrScnUsb.sys
02/23/2005 14:58 11,776 afc.sys
07/25/2005 11:04 48,640 ser2pl.sys
04/26/2006 14:21 25,214 VOLHelp.ico
08/23/2006 14:26 2,096 ativdkxx.vp
08/23/2006 14:26 2,096 ativckxx.vp
08/23/2006 14:26 655,842 ativcaxx.cpa
08/23/2006 14:26 929 ativcaxx.vp
09/28/2006 18:55 77,568 WudfPf.sys
09/28/2006 19:00 82,944 WudfRd.sys
10/11/2006 18:21 49,152 ati2erec.dll
10/11/2006 18:43 1,777,152 ati2mtag.sys
10/11/2006 19:11 36,272 ativvpxx.vp
10/18/2006 20:00 38,528 wpdusb.sys
03/27/2008 17:27 503,008 wdf01000.sys
03/27/2008 17:27 35,040 wdfldr.sys
04/13/2008 09:36 144,384 hdaudbus.sys
04/13/2008 09:39 20,480 secdrv.sys
04/13/2008 09:39 142,592 aec.sys
04/13/2008 11:31 35,840 processr.sys
04/13/2008 11:31 42,752 p3.sys
04/13/2008 11:31 37,376 amdk6.sys
04/13/2008 11:31 36,352 intelppm.sys
04/13/2008 11:31 36,736 crusoe.sys
04/13/2008 11:31 37,760 amdk7.sys
04/13/2008 11:32 66,048 udfs.sys
04/13/2008 11:32 30,848 npfs.sys
04/13/2008 11:32 19,072 msfs.sys
04/13/2008 11:32 180,608 mrxdav.sys
04/13/2008 11:32 196,224 rdpdr.sys
04/13/2008 11:32 129,792 fltmgr.sys
04/13/2008 11:33 44,544 fips.sys
04/13/2008 11:34 163,584 nwrdr.sys
04/13/2008 11:36 5,888 smbali.sys
04/13/2008 11:36 187,776 acpi.sys
04/13/2008 11:36 42,752 alim1541.sys
04/13/2008 11:36 42,368 agp440.sys
04/13/2008 11:36 44,928 agpcpq.sys
04/13/2008 11:36 43,008 amdagp.sys
04/13/2008 11:36 40,960 sisagp.sys
04/13/2008 11:36 42,240 viaagp.sys
04/13/2008 11:36 46,464 gagp30kx.sys
04/13/2008 11:36 44,672 uagp35.sys
04/13/2008 11:36 63,744 mf.sys
04/13/2008 11:36 37,248 isapnp.sys
04/13/2008 11:36 120,192 pcmcia.sys
04/13/2008 11:36 79,232 sdbus.sys
04/13/2008 11:36 68,224 pci.sys
04/13/2008 11:36 15,488 mssmbios.sys
04/13/2008 11:36 73,472 sr.sys
04/13/2008 11:38 71,168 dxg.sys
04/13/2008 11:39 92,544 mqac.sys
04/13/2008 11:39 384,768 update.sys
04/13/2008 11:39 42,368 mountmgr.sys
04/13/2008 11:39 24,576 kbdclass.sys
04/13/2008 11:39 23,040 mouclass.sys
04/13/2008 11:39 5,376 mspclock.sys
04/13/2008 11:39 4,992 mspqm.sys
04/13/2008 11:39 7,552 mskssrv.sys
04/13/2008 11:39 4,352 swenum.sys
04/13/2008 11:40 80,128 parport.sys
04/13/2008 11:40 15,744 serenum.sys
04/13/2008 11:40 20,480 flpydisk.sys
04/13/2008 11:40 27,392 fdc.sys
04/13/2008 11:40 57,600 redbook.sys
04/13/2008 11:40 24,960 pciidex.sys
04/13/2008 11:40 96,384 scsiport.sys
04/13/2008 11:40 96,512 atapi.sys
04/13/2008 11:40 14,208 diskdump.sys
04/13/2008 11:40 62,976 cdrom.sys
04/13/2008 11:40 36,352 disk.sys
04/13/2008 11:40 11,904 sffdisk.sys
04/13/2008 11:40 11,008 sffp_sd.sys
04/13/2008 11:40 11,392 sfloppy.sys
04/13/2008 11:40 10,240 sffp_mmc.sys
04/13/2008 11:40 19,712 partmgr.sys
04/13/2008 11:40 14,976 tape.sys
04/13/2008 11:40 42,112 imapi.sys
04/13/2008 11:41 52,352 volsnap.sys
04/13/2008 11:43 12,672 mutohpen.sys
04/13/2008 11:43 14,208 wacompen.sys
04/13/2008 11:44 20,992 vga.sys
04/13/2008 11:44 81,664 videoprt.sys
04/13/2008 11:44 153,344 dmio.sys
04/13/2008 11:44 799,744 dmboot.sys
04/13/2008 11:45 52,864 dmusic.sys
04/13/2008 11:45 6,272 splitter.sys
04/13/2008 11:45 172,416 kmixer.sys
04/13/2008 11:45 56,576 swmidi.sys
04/13/2008 11:45 2,944 drmkaud.sys
04/13/2008 11:45 60,160 drmk.sys
04/13/2008 11:45 49,408 stream.sys
04/13/2008 11:45 24,960 hidparse.sys
04/13/2008 11:45 19,200 hidir.sys
04/13/2008 11:45 36,864 hidclass.sys
04/13/2008 11:45 10,368 hidusb.sys
04/13/2008 11:45 10,624 gameenum.sys
04/13/2008 11:45 46,592 irbus.sys
04/13/2008 11:45 15,104 usbscan.sys
04/13/2008 11:45 17,152 usbohci.sys
04/13/2008 11:45 30,208 usbehci.sys
04/13/2008 11:45 143,872 usbport.sys
04/13/2008 11:45 26,112 usbser.sys
04/13/2008 11:45 59,520 usbhub.sys
04/13/2008 11:45 26,368 usbstor.sys
04/13/2008 11:45 32,128 usbccgp.sys
04/13/2008 11:45 25,600 usbcamd.sys
04/13/2008 11:45 25,728 usbcamd2.sys
04/13/2008 11:45 15,872 usbintel.sys
04/13/2008 11:46 25,344 sonydcam.sys
04/13/2008 11:46 53,376 1394bus.sys
04/13/2008 11:46 61,696 ohci1394.sys
04/13/2008 11:46 121,984 usbvideo.sys
04/13/2008 11:46 18,944 bthusb.sys
04/13/2008 11:46 25,600 hidbth.sys
04/13/2008 11:46 36,480 bthprint.sys
04/13/2008 11:46 59,136 rfcomm.sys
04/13/2008 11:46 17,024 bthenum.sys
04/13/2008 11:46 37,888 bthmodem.sys
04/13/2008 11:47 25,856 usbprint.sys
04/13/2008 11:51 60,800 arp1394.sys
04/13/2008 11:51 59,904 atmarpc.sys
04/13/2008 11:51 61,824 nic1394.sys
04/13/2008 11:51 55,808 atmlane.sys
04/13/2008 11:51 101,120 bthpan.sys
04/13/2008 11:53 40,320 nmnt.sys
04/13/2008 11:53 71,552 bridge.sys
04/13/2008 11:53 36,608 ip6fw.sys
04/13/2008 11:54 11,264 irenum.sys
04/13/2008 11:55 14,592 ndisuio.sys
04/13/2008 11:56 12,288 tunmp.sys
04/13/2008 11:56 34,688 netbios.sys
04/13/2008 11:56 88,320 nwlnkipx.sys
04/13/2008 11:56 35,072 msgpc.sys
04/13/2008 11:56 69,120 psched.sys
04/13/2008 11:56 12,800 usb8023.sys
04/13/2008 11:56 30,592 rndismpx.sys
04/13/2008 11:56 12,800 usb8023x.sys
04/13/2008 11:56 30,592 rndismp.sys
04/13/2008 11:57 20,864 ipinip.sys
04/13/2008 11:57 152,832 ipnat.sys
04/13/2008 11:57 34,560 wanarp.sys
04/13/2008 11:57 14,336 asyncmac.sys
04/13/2008 11:57 10,112 ndistapi.sys
04/13/2008 11:57 41,472 raspppoe.sys
04/13/2008 12:00 19,072 tdi.sys
04/13/2008 12:00 30,080 modem.sys
04/13/2008 12:14 63,744 cdfs.sys
04/13/2008 12:14 143,744 fastfat.sys
04/13/2008 12:15 64,512 serial.sys
04/13/2008 12:15 574,976 ntfs.sys
04/13/2008 12:15 60,800 sysaudio.sys
04/13/2008 12:16 49,536 classpnp.sys
04/13/2008 12:17 105,344 mup.sys
04/13/2008 12:17 83,072 wdmaud.sys
04/13/2008 12:18 52,480 i8042prt.sys
04/13/2008 12:19 146,048 portcls.sys
04/13/2008 12:19 75,264 ipsec.sys
04/13/2008 12:19 51,328 rasl2tp.sys
04/13/2008 12:19 48,384 raspptp.sys
04/13/2008 12:20 182,656 ndis.sys
04/13/2008 12:20 91,520 ndiswan.sys
04/13/2008 12:21 162,816 netbt.sys
04/13/2008 12:28 175,744 rdbss.sys
04/13/2008 12:39 5,504 MSTEE.sys
04/13/2008 12:45 60,032 USBAUDIO.sys
04/13/2008 12:46 15,232 StreamIP.sys
04/13/2008 12:46 10,880 NdisIP.sys
04/13/2008 12:46 11,136 SLIP.sys
04/13/2008 12:46 19,200 WSTCODEC.SYS
04/13/2008 12:46 17,024 CCDECODE.sys
04/13/2008 12:46 85,248 NABTSFEC.sys
04/13/2008 12:54 88,192 irda.sys
04/13/2008 13:16 141,056 ks.sys
04/13/2008 17:11 3,135 adv08nt5.dll
04/13/2008 17:11 3,615 adv05nt5.dll
04/13/2008 17:11 4,255 adv01nt5.dll
04/13/2008 17:11 3,775 adv11nt5.dll
04/13/2008 17:11 3,711 adv09nt5.dll
04/13/2008 17:11 3,967 adv02nt5.dll
04/13/2008 17:11 3,647 adv07nt5.dll
04/13/2008 17:11 14,143 atv06nt5.dll
04/13/2008 17:11 11,359 atv02nt5.dll
04/13/2008 17:11 21,183 atv01nt5.dll
04/13/2008 17:11 15,423 ch7xxnt5.dll
04/13/2008 17:11 25,471 atv04nt5.dll
04/13/2008 17:11 17,279 atv10nt5.dll
04/13/2008 17:12 3,901 siint5.dll
04/13/2008 17:12 11,325 vchnt5.dll
04/13/2008 17:13 12,040 tdpipe.sys
04/13/2008 17:13 40,840 termdd.sys
04/13/2008 17:13 21,896 tdtcp.sys
04/13/2008 17:13 139,656 rdpwd.sys
05/08/2008 07:02 203,136 rmcast.sys
06/13/2008 04:05 272,128 bthport.sys
06/20/2008 04:51 361,600 tcpip.sys
10/16/2008 07:43 138,496 afd.sys
11/11/2008 15:58 23,096 MusCAudio.sys
11/11/2008 15:58 3,768 MusCVideo.sys
11/25/2008 10:26
11/27/2008 12:52 22,768 usbsermpt.sys
12/18/2008 13:16 73,840 PCTAppEvent.sys
05/18/2009 14:17 26,600 GEARAspiWDM.sys
06/24/2009 04:18 92,928 ksecdd.sys
09/09/2009 09:16
10/20/2009 09:20 265,728 http.sys
10/27/2009 13:02 23,936 motmodem.sys
02/11/2010 05:02 226,880 tcpip6.sys
06/07/2010 19:51 29,584 avgmfx86.sys
07/15/2010 16:41 216,400 avgldx86.sys
07/15/2010 16:41 243,024 avgtdix.sys
08/14/2010 14:48 691,696 sptd.sys
09/28/2010 16:44 41,984 usbaapl.sys
11/02/2010 08:17 40,960 ndproxy.sys
11/10/2010 20:30 4,122,368 ALCXWDM.SYS
11/10/2010 20:32 7,180 a2ptbtn.sys
12/13/2010 15:37 30,576 nx6000.sys
12/20/2010 18:08 20,952 mbam.sys
12/20/2010 18:09 38,224 mbamswissarmy.sys
02/17/2011 06:18 357,888 srv.sys
02/17/2011 06:18 455,936 mrxsmb.sys
04/21/2011 22:16
04/22/2011 16:36
04/22/2011 22:33
04/22/2011 22:33
332 File(s) 37,569,819 bytes
6 Dir(s) 39,629,275,136 bytes free
Stealth malware?
Internet Explorer
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main
Default_Page_URL REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Enable_Disk_Cache REG_SZ yes
Cache_Percent_of_Disk REG_BINARY 0A000000
Delete_Temp_Files_On_Exit REG_SZ yes
Anchor_Visitation_Horizon REG_BINARY 01000000
Use_Async_DNS REG_SZ yes
Placeholder_Width REG_BINARY 1A000000
Placeholder_Height REG_BINARY 1A000000
Start Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
CompanyName REG_SZ Microsoft Corporation
Custom_Key REG_SZ MICROSO
Wizard_Version REG_SZ 6.0.2600.0000
FullScreen REG_SZ no
Check_Associations REG_SZ yes
Default_Secondary_Page_URL REG_MULTI_SZ \0
Extensions Off Page REG_SZ about:NoAdd-ons
Security Risk Page REG_SZ about:SecurityRisk
DEPOff REG_DWORD 0x0
StatusBarWeb REG_DWORD 0x1
SearchControlWidth REG_DWORD 0x12c
ForceGDIPlus REG_DWORD 0x0
MaxRenderLine REG_DWORD 0xfa0
UseClearType REG_SZ yes
Page_Transitions REG_DWORD 0x1
Use_DlgBox_Colors REG_SZ yes
Anchor Underline REG_SZ yes
Display Inline Images REG_SZ yes
Display Inline Videos REG_DWORD 0x1
Play_Background_Sounds REG_SZ yes
Play_Animations REG_SZ yes
Print_Background REG_SZ no
SmoothScroll REG_DWORD 0x1
XMLHTTP REG_DWORD 0x1
Show image placeholders REG_DWORD 0x0
Disable Script Debugger REG_SZ yes
Enable AutoImageResize REG_SZ yes
XDomainRequest REG_DWORD 0x1
DOMStorage REG_DWORD 0x1
IE8RunOnceLastShown REG_DWORD 0x0
IE8RunOncePerInstallCompleted REG_DWORD 0x0
IE8TourNoShow REG_DWORD 0x0
IE8TourShown REG_DWORD 0x0
FrameTabWindow REG_DWORD 0x1
AdminTabProcs REG_DWORD 0x1
SessionMerging REG_DWORD 0x1
FrameMerging REG_DWORD 0x1
HangResistantFrame REG_DWORD 0x0
TabShutdownDelay REG_DWORD 0xea60
FrameShutdownDelay REG_DWORD 0x0
IEWatsonDisable REG_DWORD 0x1
Local Page REG_SZ C:\windows\system32\blank.htm
SearchMigrated REG_DWORD 0x0
Use Custom Search URL REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\ErrorThresholds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\UrlTemplate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\WindowsSearch
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
User Agent REG_SZ Mozilla/4.0 (compatible; MSIE 8.0; Win32)
IE5_UA_Backup_Flag REG_SZ 5.0
NoNetAutodial REG_DWORD 0x1
MigrateProxy REG_DWORD 0x1
EnableNegotiate REG_DWORD 0x1
ProxyEnable REG_DWORD 0x0
EmailName REG_SZ IEUser@
AutoConfigProxy REG_SZ wininet.dll
MimeExclusionListForCache REG_SZ multipart/mixed multipart/x-mixed-replace multipart/x-byteranges
WarnOnPost REG_BINARY 01000000
UseSchannelDirectly REG_BINARY 01000000
EnableHttp1_1 REG_DWORD 0x1
PrivacyAdvanced REG_DWORD 0x0
EnableAutodial REG_DWORD 0x1
GlobalUserOffline REG_DWORD 0x0
PrivDiscUiShown REG_DWORD 0x1
WarnOnZoneCrossing REG_DWORD 0x0
SyncMode5 REG_DWORD 0x4
WarnonBadCertRecving REG_DWORD 0x1
WarnOnPostRedirect REG_DWORD 0x0
WarnOnHTTPSToHTTPRedirect REG_DWORD 0x1
UrlEncoding REG_DWORD 0x0
SecureProtocols REG_DWORD 0x28
ZonesSecurityUpgrade REG_BINARY DE8B3646EAE0C901
DisableCachingOfSSLPages REG_DWORD 0x0
ProxyOverride REG_SZ
ProxyHttp1.1 REG_DWORD 0x1
ShowPunycode REG_DWORD 0x0
EnablePunycode REG_DWORD 0x1
DisableIDNPrompt REG_DWORD 0x0
CertificateRevocation REG_DWORD 0x0
MaxConnectionsPerServer REG_DWORD 0xa
MaxConnectionsPer1_0Server REG_DWORD 0xa
CreateUriCacheSize REG_DWORD 0x50
CoInternetCombineIUriCacheSize REG_DWORD 0x50
SecurityIdIUriCacheSize REG_DWORD 0x1e
SpecialFoldersCacheSize REG_DWORD 0x8
WarnOnIntranet REG_DWORD 0x1

















