! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
ProfilesDirectory REG_EXPAND_SZ %SystemDrive%\Documents and Settings
DefaultUserProfile REG_SZ Default User
AllUsersProfile REG_SZ All Users
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
Flags REG_DWORD 0xc
State REG_DWORD 0x0
RefCount REG_DWORD 0x1
Sid REG_BINARY 010100000000000512000000
ProfileImagePath REG_EXPAND_SZ %systemroot%\system32\config\systemprofile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\LocalService
Sid REG_BINARY 010100000000000513000000
Flags REG_DWORD 0x9
State REG_DWORD 0x0
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0xcd06692e
ProfileLoadTimeHigh REG_DWORD 0x1cb118e
RefCount REG_DWORD 0x3
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\NetworkService
Sid REG_BINARY 010100000000000514000000
Flags REG_DWORD 0x9
State REG_DWORD 0x0
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0xcc4a0f68
ProfileLoadTimeHigh REG_DWORD 0x1cb118e
RefCount REG_DWORD 0x2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1454471165-1606980848-839522115-1004
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\Computer1
Sid REG_BINARY 010500000000000515000000FD77B156F094C85F43170A32EC030000
Flags REG_DWORD 0x0
State REG_DWORD 0x100
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0xfcf5ee3e
ProfileLoadTimeHigh REG_DWORD 0x1c5c472
RefCount REG_DWORD 0x0
RunLogonscriptSync REG_DWORD 0x0
OptimizedLogonStatus REG_DWORD 0xb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1454471165-1606980848-839522115-1008
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\Mitchel
Sid REG_BINARY 010500000000000515000000FD77B156F094C85F43170A32F0030000
Flags REG_DWORD 0x0
State REG_DWORD 0x100
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0xcd6f50a6
ProfileLoadTimeHigh REG_DWORD 0x1cb118e
RefCount REG_DWORD 0x1
RunLogonscriptSync REG_DWORD 0x0
OptimizedLogonStatus REG_DWORD 0xb
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1454471165-1606980848-839522115-501
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\Guest
Sid REG_BINARY 010500000000000515000000FD77B156F094C85F43170A32F5010000
Flags REG_DWORD 0x0
State REG_DWORD 0x84
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0xcfb7b48c
ProfileLoadTimeHigh REG_DWORD 0x1c839f7
RefCount REG_DWORD 0x0
RunLogonscriptSync REG_DWORD 0x0
Current Scheduled Tasks
PATH: C:\Windows\Tasks
AppleSoftwareUpdate.job
desktop.ini
SA.DAT
Windows Drivers and NT-Services
Volume in drive C has no label.
Volume Serial Number is 086C-C998
Directory of C:\Windows\System32\Drivers
12/08/2009 09:38 PM 0 MsftWdf_Kernel_01001_Coinstaller_Critical.Wdf
12/08/2009 09:38 PM 0 Msft_Kernel_xusb21_01001.Wdf
2 File(s) 0 bytes
0 Dir(s) 21,783,130,112 bytes free
Volume in drive C has no label.
Volume Serial Number is 086C-C998
Directory of C:\Windows\System32\Drivers
01/21/1999 05:31 PM 2,259,070 eapci2m.ecw
08/17/2001 09:28 AM 871,388 BCMDM.sys
08/17/2001 09:57 AM 16,128 MODEMCSA.sys
08/17/2001 09:59 AM 3,072 audstub.sys
08/17/2001 01:48 PM 12,160 mouhid.sys
08/17/2001 02:00 PM 54,272 swmidi.sys
08/17/2001 02:02 PM 8,576 hidgame.sys
08/17/2001 03:02 PM 9,600 hidusb.sys
08/22/2001 08:42 AM 13,632 omci.sys
04/15/2002 09:11 PM 67,866 netwlan5.img
12/13/2002 04:06 AM 129,875 mr97310c.sys
03/04/2003 12:56 PM 145,408 e100b325.sys
07/16/2003 04:23 PM 11,648 acpiec.sys
07/16/2003 04:24 PM 31,360 atmepvc.sys
07/16/2003 04:24 PM 352,256 atmuni.sys
07/16/2003 04:24 PM 4,224 beep.sys
07/16/2003 04:25 PM 13,952 cbidf2k.sys
07/16/2003 04:27 PM 5,888 dmload.sys
07/16/2003 04:27 PM 12,032 rio8drv.sys
07/16/2003 04:27 PM 12,032 riodrv.sys
07/16/2003 04:27 PM 58,112 vdmindvd.sys
07/16/2003 04:27 PM 23,936 usbcamd2.sys
07/16/2003 04:27 PM 12,160 fsvga.sys
07/16/2003 04:27 PM 12,032 nikedrv.sys
07/16/2003 04:27 PM 51,712 tosdvd.sys
07/16/2003 04:27 PM 21,376 tsbvcap.sys
07/16/2003 04:27 PM 11,776 cpqdap01.sys
07/16/2003 04:27 PM 262,528 cinemst2.sys
07/16/2003 04:27 PM 18,688 cdaudio.sys
07/16/2003 04:27 PM 23,808 usbcamd.sys
07/16/2003 04:27 PM 10,496 dxapi.sys
07/16/2003 04:27 PM 3,328 dxgthk.sys
07/16/2003 04:28 PM 34,944 fips.sys
07/16/2003 04:28 PM 125,056 ftdisk.sys
07/16/2003 04:28 PM 7,936 fs_rec.sys
07/16/2003 04:28 PM 3,440,660 gm.dls
07/16/2003 04:30 PM 32,896 ipfltdrv.sys
07/16/2003 04:30 PM 35,840 isapnp.sys
07/16/2003 04:32 PM 7,680 mcd.sys
07/16/2003 04:33 PM 4,224 mnmdd.sys
07/16/2003 04:37 PM 9,600 ndistapi.sys
07/16/2003 04:37 PM 38,016 ndproxy.sys
07/16/2003 04:40 PM 2,944 null.sys
07/16/2003 04:40 PM 32,512 nwlnkfwd.sys
07/16/2003 04:40 PM 12,416 nwlnkflt.sys
07/16/2003 04:40 PM 63,232 nwlnknb.sys
07/16/2003 04:40 PM 55,936 nwlnkspx.sys
07/16/2003 04:40 PM 3,456 oprghdlr.sys
07/16/2003 04:41 PM 6,784 parvdm.sys
07/16/2003 04:41 PM 18,688 partmgr.sys
07/16/2003 04:41 PM 3,328 pciide.sys
07/16/2003 04:42 PM 17,792 ptilink.sys
07/16/2003 04:42 PM 8,832 rasacd.sys
07/16/2003 04:42 PM 16,512 raspti.sys
07/16/2003 04:42 PM 34,432 rawwan.sys
07/16/2003 04:42 PM 4,224 rdpcdd.sys
07/16/2003 04:43 PM 5,888 rootmdm.sys
07/16/2003 04:45 PM 14,592 smclib.sys
07/16/2003 04:49 PM 4,736 usbd.sys
07/16/2003 04:52 PM 4,352 wmilib.sys
07/16/2003 04:53 PM 12,032 ws2ifsl.sys
08/14/2003 11:58 AM 1,296,384 P16X.sys
10/17/2003 12:52 PM 1,330,172 nv4_mini.sys
03/19/2004 12:54 PM 38,912 P2k.sys
07/17/2004 02:36 PM 64,352 ativmc20.cod
07/18/2004 01:55 AM 129,045 cxthsfs2.cty
08/04/2004 01:29 AM 327,040 ati2mtaa.sys
08/04/2004 01:29 AM 57,856 atinbtxx.sys
08/04/2004 01:29 AM 13,824 atinmdxx.sys
08/04/2004 01:29 AM 14,336 atinpdxx.sys
08/04/2004 01:29 AM 52,224 atinraxx.sys
08/04/2004 01:29 AM 56,623 ati1btxx.sys
08/04/2004 01:29 AM 11,615 ati1mdxx.sys
08/04/2004 01:29 AM 12,047 ati1pdxx.sys
08/04/2004 01:29 AM 63,663 ati1rvxx.sys
08/04/2004 01:29 AM 28,672 atinsnxx.sys
08/04/2004 01:29 AM 104,960 atinrvxx.sys
08/04/2004 01:29 AM 30,671 ati1raxx.sys
08/04/2004 01:29 AM 13,824 atinttxx.sys
08/04/2004 01:29 AM 36,463 ati1tuxx.sys
08/04/2004 01:29 AM 34,735 ati1xsxx.sys
08/04/2004 01:29 AM 21,343 ati1ttxx.sys
08/04/2004 01:29 AM 29,455 ati1xbxx.sys
08/04/2004 01:29 AM 26,367 ati1snxx.sys
08/04/2004 01:29 AM 73,216 atintuxx.sys
08/04/2004 01:29 AM 31,744 atinxbxx.sys
08/04/2004 01:29 AM 63,488 atinxsxx.sys
08/04/2004 01:29 AM 452,736 mtxparhm.sys
08/04/2004 01:29 AM 11,807 wadv07nt.sys
08/04/2004 01:29 AM 11,295 wadv08nt.sys
08/04/2004 01:29 AM 11,935 wadv11nt.sys
08/04/2004 01:29 AM 11,871 wadv09nt.sys
08/04/2004 01:29 AM 22,271 watv06nt.sys
08/04/2004 01:29 AM 25,471 watv10nt.sys
08/04/2004 01:29 AM 166,912 s3gnbm.sys
08/04/2004 01:41 AM 1,309,184 mtlstrm.sys
08/04/2004 01:41 AM 126,686 mtlmnt5.sys
08/04/2004 01:41 AM 180,360 ntmtlfax.sys
08/04/2004 01:41 AM 13,776 recagent.sys
08/04/2004 01:41 AM 129,535 slnt7554.sys
08/04/2004 01:41 AM 404,990 slntamr.sys
08/04/2004 01:41 AM 95,424 slnthal.sys
08/04/2004 01:41 AM 13,240 slwdmsup.sys
08/04/2004 01:41 AM 220,032 hsfbs2s2.sys
08/04/2004 01:41 AM 685,056 hsfcxts2.sys
08/04/2004 01:41 AM 1,041,536 hsfdpsp2.sys
08/04/2004 01:41 AM 11,868 mdmxsdk.sys
08/04/2004 01:58 AM 61,824 nic1394.sys
08/04/2004 01:58 AM 60,800 arp1394.sys
08/04/2004 01:58 AM 42,240 mountmgr.sys
08/04/2004 01:58 AM 59,904 atmarpc.sys
08/04/2004 01:58 AM 23,040 mouclass.sys
08/04/2004 01:58 AM 24,576 kbdclass.sys
08/04/2004 01:58 AM 14,848 kbdhid.sys
08/04/2004 01:58 AM 55,936 atmlane.sys
08/04/2004 01:58 AM 5,376 mspclock.sys
08/04/2004 01:58 AM 100,992 bthpan.sys
08/04/2004 01:58 AM 4,992 mspqm.sys
08/04/2004 01:58 AM 4,352 swenum.sys
08/04/2004 01:58 AM 7,552 mskssrv.sys
08/04/2004 01:59 AM 80,128 parport.sys
08/04/2004 01:59 AM 15,488 serenum.sys
08/04/2004 01:59 AM 35,328 processr.sys
08/04/2004 01:59 AM 36,992 amdk6.sys
08/04/2004 01:59 AM 36,096 intelppm.sys
08/04/2004 01:59 AM 42,496 p3.sys
08/04/2004 01:59 AM 36,480 crusoe.sys
08/04/2004 01:59 AM 37,376 amdk7.sys
08/04/2004 01:59 AM 27,392 fdc.sys
08/04/2004 01:59 AM 20,480 flpydisk.sys
08/04/2004 01:59 AM 57,472 redbook.sys
08/04/2004 01:59 AM 96,256 scsiport.sys
08/04/2004 01:59 AM 25,088 pciidex.sys
08/04/2004 01:59 AM 95,360 atapi.sys
08/04/2004 01:59 AM 40,320 nmnt.sys
08/04/2004 01:59 AM 14,208 diskdump.sys
08/04/2004 01:59 AM 49,536 cdrom.sys
08/04/2004 01:59 AM 11,392 sfloppy.sys
08/04/2004 01:59 AM 36,352 disk.sys
08/04/2004 01:59 AM 10,240 sffp_sd.sys
08/04/2004 01:59 AM 11,136 sffdisk.sys
08/04/2004 01:59 AM 71,552 bridge.sys
08/04/2004 01:59 AM 14,976 tape.sys
08/04/2004 02:00 AM 29,056 ip6fw.sys
08/04/2004 02:00 AM 41,856 imapi.sys
08/04/2004 02:00 AM 52,352 volsnap.sys
08/04/2004 02:00 AM 66,176 udfs.sys
08/04/2004 02:00 AM 19,072 msfs.sys
08/04/2004 02:00 AM 30,848 npfs.sys
08/04/2004 02:00 AM 11,264 irenum.sys
08/04/2004 02:00 AM 71,040 _006330_.tmp.dll
08/04/2004 02:00 AM 71,040 _004424_.tmp.dll
08/04/2004 02:00 AM 71,040 _004465_.tmp.dll
08/04/2004 02:00 AM 71,040 _004418_.tmp.dll
08/04/2004 02:00 AM 71,040 dxg.sys
08/04/2004 02:00 AM 71,040 _004432_.tmp.dll
08/04/2004 02:01 AM 196,864 rdpdr.sys
08/04/2004 02:01 AM 25,856 usbprint.sys
08/04/2004 02:03 AM 12,928 ndisuio.sys
08/04/2004 02:03 AM 12,416 tunmp.sys
08/04/2004 02:03 AM 34,560 netbios.sys
08/04/2004 02:03 AM 88,448 nwlnkipx.sys
08/04/2004 02:04 AM 35,072 msgpc.sys
08/04/2004 02:04 AM 69,120 psched.sys
08/04/2004 02:04 AM 20,992 ipinip.sys
08/04/2004 02:04 AM 12,672 mutohpen.sys
08/04/2004 02:04 AM 13,568 wacompen.sys
08/04/2004 02:04 AM 34,560 wanarp.sys
08/04/2004 02:05 AM 14,336 asyncmac.sys
08/04/2004 02:05 AM 41,472 raspppoe.sys
08/04/2004 02:06 AM 73,472 sr.sys
08/04/2004 02:07 AM 79,744 videoprt.sys
08/04/2004 02:07 AM 20,992 vga.sys
08/04/2004 02:07 AM 153,344 dmio.sys
08/04/2004 02:07 AM 799,744 dmboot.sys
08/04/2004 02:07 AM 6,016 smbali.sys
08/04/2004 02:07 AM 52,864 dmusic.sys
08/04/2004 02:07 AM 187,776 acpi.sys
08/04/2004 02:07 AM 42,368 agp440.sys
08/04/2004 02:07 AM 42,752 alim1541.sys
08/04/2004 02:07 AM 41,088 sisagp.sys
08/04/2004 02:07 AM 43,008 amdagp.sys
08/04/2004 02:07 AM 42,240 viaagp.sys
08/04/2004 02:07 AM 44,928 agpcpq.sys
08/04/2004 02:07 AM 46,464 gagp30kx.sys
08/04/2004 02:07 AM 44,672 uagp35.sys
08/04/2004 02:07 AM 63,744 mf.sys
08/04/2004 02:07 AM 119,936 pcmcia.sys
08/04/2004 02:07 AM 68,224 pci.sys
08/04/2004 02:07 AM 15,488 mssmbios.sys
08/04/2004 02:07 AM 67,584 sdbus.sys
08/04/2004 02:07 AM 18,560 tdi.sys
08/04/2004 02:07 AM 60,288 drmk.sys
08/04/2004 02:07 AM 2,944 drmkaud.sys
08/04/2004 02:08 AM 48,640 stream.sys
08/04/2004 02:08 AM 30,080 modem.sys
08/04/2004 02:08 AM 15,104 hidir.sys
08/04/2004 02:08 AM 10,624 gameenum.sys
08/04/2004 02:08 AM 20,480 usbuhci.sys
08/04/2004 02:08 AM 26,624 usbehci.sys
08/04/2004 02:08 AM 57,600 usbhub.sys
08/04/2004 02:08 AM 25,600 usbser.sys
08/04/2004 02:08 AM 142,976 usbport.sys
08/04/2004 02:08 AM 26,496 usbstor.sys
08/04/2004 02:08 AM 31,616 usbccgp.sys
08/04/2004 02:08 AM 16,000 usbintel.sys
08/04/2004 02:09 AM 25,472 sonydcam.sys
08/04/2004 02:10 AM 78,464 usbvideo.sys
08/04/2004 02:10 AM 18,944 bthusb.sys
08/04/2004 02:10 AM 25,600 hidbth.sys
08/04/2004 02:10 AM 35,456 bthprint.sys
08/04/2004 02:10 AM 38,016 bthmodem.sys
08/04/2004 02:10 AM 17,024 bthenum.sys
08/04/2004 02:10 AM 59,648 rfcomm.sys
08/04/2004 02:14 AM 63,744 cdfs.sys
08/04/2004 02:14 AM 143,360 fastfat.sys
08/04/2004 02:14 AM 51,328 rasl2tp.sys
08/04/2004 02:14 AM 49,664 classpnp.sys
08/04/2004 02:14 AM 48,384 raspptp.sys
08/04/2004 02:14 AM 74,752 ipsec.sys
08/04/2004 02:14 AM 182,912 ndis.sys
08/04/2004 02:14 AM 91,776 ndiswan.sys
08/04/2004 02:14 AM 52,736 i8042prt.sys
08/04/2004 02:14 AM 162,816 netbt.sys
08/04/2004 02:15 AM 107,904 mup.sys
08/04/2004 02:15 AM 140,928 ks.sys
08/04/2004 02:15 AM 145,792 portcls.sys
08/04/2004 02:15 AM 64,896 serial.sys
08/04/2004 02:15 AM 60,800 sysaudio.sys
08/04/2004 02:58 AM 5,504 mstee.sys
08/04/2004 02:58 AM 15,104 usbscan.sys
08/04/2004 03:07 AM 59,264 usbaudio.sys
08/04/2004 03:08 AM 24,960 hidparse.sys
08/04/2004 03:08 AM 36,224 hidclass.sys
08/04/2004 03:10 AM 10,880 ndisip.sys
08/04/2004 03:10 AM 15,360 streamip.sys
08/04/2004 03:10 AM 11,136 slip.sys
08/04/2004 03:10 AM 17,024 ccdecode.sys
08/04/2004 03:10 AM 19,328 wstcodec.sys
08/04/2004 03:10 AM 85,376 nabtsfec.sys
08/04/2004 03:56 AM 3,967 adv02nt5.dll
08/04/2004 03:56 AM 25,471 atv04nt5.dll
08/04/2004 03:56 AM 15,423 ch7xxnt5.dll
08/04/2004 03:56 AM 11,359 atv02nt5.dll
08/04/2004 03:56 AM 3,775 adv11nt5.dll
08/04/2004 03:56 AM 4,255 adv01nt5.dll
08/04/2004 03:56 AM 3,647 adv07nt5.dll
08/04/2004 03:56 AM 17,279 atv10nt5.dll
08/04/2004 03:56 AM 3,615 adv05nt5.dll
08/04/2004 03:56 AM 21,183 atv01nt5.dll
08/04/2004 03:56 AM 3,711 adv09nt5.dll
08/04/2004 03:56 AM 14,143 atv06nt5.dll
08/04/2004 03:56 AM 3,135 adv08nt5.dll
08/04/2004 03:56 AM 3,901 siint5.dll
08/04/2004 03:56 AM 11,325 vchnt5.dll
08/04/2004 04:01 AM 12,040 tdpipe.sys
08/04/2004 04:01 AM 21,896 tdtcp.sys
08/04/2004 04:01 AM 40,840 termdd.sys
09/29/2004 06:28 PM 134,912 ipnat.sys
11/29/2004 06:51 PM 122,928 SPCA561.SYS
02/01/2005 07:18 PM 17,992 bcm42rly.sys
05/27/2005 10:23 AM 2,180,096 LVSVF2.sys
05/27/2005 10:31 AM 22,016 LVUSBSta.sys
05/27/2005 10:46 AM 913,280 LV302AV.SYS
06/07/2005 07:17 AM
disdn
06/10/2005 12:09 AM 139,528 rdpwd.sys
10/20/2005 09:47 PM 30,592 rndismpx.sys
10/20/2005 09:47 PM 30,592 rndismp.sys
10/20/2005 09:47 PM 12,800 usb8023x.sys
10/20/2005 09:47 PM 12,800 usb8023.sys
10/27/2005 04:06 PM 356,096 rt61.sys
02/14/2006 08:22 PM 142,464 aec.sys
04/08/2006 08:09 PM 12,032 tansgt.sys
04/08/2006 08:09 PM 137,344 litsgt.sys
04/20/2006 01:44 AM 479,200 wdf01000.sys
04/20/2006 01:44 AM 30,688 wdfldr.sys
05/05/2006 05:47 AM 174,592 rdbss.sys
06/01/2006 03:15 PM 509,440 xnacc.sys
06/14/2006 04:47 AM 172,416 kmixer.sys
06/14/2006 04:47 AM 6,400 splitter.sys
06/14/2006 05:00 AM 82,944 wdmaud.sys
08/21/2006 05:14 AM 128,896 fltmgr.sys
09/28/2006 07:55 PM 77,568 WudfPf.sys
09/28/2006 08:00 PM 82,944 WudfRd.sys
10/18/2006 09:00 PM 38,528 wpdusb.sys
11/06/2006 06:04 PM 28,672 wceusbsh.sys
02/02/2007 03:00 AM 9,336 cdr4_xp.sys
02/02/2007 03:00 AM 9,464 cdralw2k.sys
02/09/2007 07:10 AM 574,464 ntfs.sys
02/26/2007 06:15 PM 61,984 xusb21.sys
04/18/2007 12:19 PM 929 ativcaxx.vp
04/18/2007 12:19 PM 1,311,202 ativcaxx.cpa
04/18/2007 12:19 PM 2,096 ativdkxx.vp
04/23/2007 06:32 AM 364,160 update.sys
05/03/2007 10:27 AM 47,360 Surroundhp_kern_i386.sys
05/03/2007 10:27 AM 46,592 tshd4_kern_i386.sys
05/03/2007 10:27 AM 32,000 wowhd_kern_i386.sys
05/03/2007 10:27 AM 37,248 csiidecoder_kern_i386.sys
05/03/2007 10:28 AM 39,552 SRS_SSCFilter_i386.sys
05/10/2007 09:43 PM UMDF
05/30/2007 04:43 PM 2,096 ativckxx.vp
09/29/2007 05:46 AM 47,376 ativvpxx.vp
11/13/2007 06:25 AM 20,480 secdrv.sys
11/14/2007 07:16 AM 33,824 oreans32.sys
11/29/2007 02:17 AM 20,240 L8042Kbd.sys
11/29/2007 02:17 AM 63,120 L8042mou.Sys
11/29/2007 02:18 AM 78,992 LMouKE.Sys
12/18/2007 05:51 AM 179,584 mrxdav.sys
02/13/2008 03:00 AM 43,528 pxhelp20.sys
05/08/2008 08:28 AM 202,752 rmcast.sys
06/02/2008 10:27 PM 49,152 ati2erec.dll
06/03/2008 02:20 AM 3,100,160 ati2mtag.sys
06/13/2008 09:10 AM 272,128 bthport.sys
06/20/2008 06:45 AM 360,320 tcpip.sys
08/14/2008 05:51 AM 138,368 afd.sys
02/10/2009 04:15 PM 257,432 afwcore.sys
02/13/2009 12:17 PM 45,416 avgntdd.sys
02/13/2009 12:29 PM 22,360 avgntmgr.sys
02/18/2009 05:30 PM 31,128 afw.sys
03/30/2009 10:33 AM 96,104 avipbb.sys
04/06/2009 11:37 AM 704,384 SandBox.sys
04/23/2009 10:17 PM 138,920 PnkBstrK.sys
05/18/2009 02:17 PM 26,600 GEARAspiWDM.sys
06/10/2009 10:11 PM 28,520 ssmdrv.sys
06/22/2009 07:34 AM 92,544 ksecdd.sys
08/28/2009 07:42 PM 40,448 usbaapl.sys
09/10/2009 02:53 PM 19,160 mbam.sys
09/10/2009 02:54 PM 38,224 mbamswissarmy.sys
09/11/2009 01:47 PM 22,792 WmBEnum.sys
09/11/2009 01:47 PM 35,592 WmFilter.sys
09/11/2009 01:47 PM 31,752 WmHidLo.sys
09/11/2009 01:47 PM 14,984 WmVirHid.sys
09/11/2009 01:48 PM 66,056 WmXlCore.sys
10/20/2009 10:58 AM 263,552 http.sys
11/20/2009 08:21 PM 20,747 AegisP.sys
12/07/2009 11:41 PM 56,816 avgntflt.sys
12/31/2009 12:14 PM 352,640 srv.sys
02/11/2010 08:01 AM 226,880 tcpip6.sys
02/24/2010 08:31 AM 454,016 mrxsmb.sys
06/07/2010 11:50 PM etc
06/14/2010 11:42 AM .
06/14/2010 11:42 AM ..
337 File(s) 41,336,206 bytes
5 Dir(s) 21,783,093,248 bytes free
Virtual drives found?
Environment variables
ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Mitchel\Application Data
asl.log=Destination=file;OnFirstLog=command,environment,parent
CLASSPATH=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=PC1
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Mitchel
LOGONSERVER=\\PC1
MOZ_CRASHREPORTER_DATA_DIRECTORY=C:\Documents and Settings\Mitchel\Application Data\Mozilla\Firefox\Crash Reports
MOZ_CRASHREPORTER_RESTART_ARG_0=C:\Program Files\Mozilla Firefox\firefox.exe
MOZ_CRASHREPORTER_STRINGS_OVERRIDE=C:\Program Files\Mozilla Firefox\crashreporter-override.ini
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\Program Files\Mozilla Firefox;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\Program Files\Common Files\Adobe\AGL;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\QuickTime\QTSystem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 1, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0401
ProgramFiles=C:\Program Files
PROMPT=$P$G
QTJAVA=C:\Program Files\Java\jre6\lib\ext\QTJava.zip
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Mitchel\LOCALS~1\Temp
TMP=C:\DOCUME~1\Mitchel\LOCALS~1\Temp
USERDOMAIN=PC1
USERNAME=Mitchel
USERPROFILE=C:\Documents and Settings\Mitchel
windir=C:\WINDOWS
Stealth malware?
Internet Explorer
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main
Default_Page_URL REG_SZ http://go.microsoft.com/fwlink/?LinkId=69157
Default_Search_URL REG_SZ http://go.microsoft.com/fwlink/?LinkId=54896
Search Page REG_SZ http://go.microsoft.com/fwlink/?LinkId=54896
Enable_Disk_Cache REG_SZ yes
Cache_Percent_of_Disk REG_BINARY 0A000000
Delete_Temp_Files_On_Exit REG_SZ yes
Local Page REG_SZ C:\WINDOWS\system32\blank.htm
Anchor_Visitation_Horizon REG_BINARY 01000000
Use_Async_DNS REG_SZ yes
Placeholder_Width REG_BINARY 1A000000
Placeholder_Height REG_BINARY 1A000000
Start Page REG_SZ http://go.microsoft.com/fwlink/?LinkId=69157
CompanyName REG_SZ Microsoft Corporation
Custom_Key REG_SZ MICROSO
Wizard_Version REG_SZ 6.0.2600.0000
FullScreen REG_SZ no
Search Bar REG_SZ http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
Default_Secondary_Page_URL REG_MULTI_SZ \0
Extensions Off Page REG_SZ about:NoAdd-ons
Security Risk Page REG_SZ about:SecurityRisk
Check_Associations REG_SZ yes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\ErrorThresholds
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\UrlTemplate
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
User Agent REG_SZ Mozilla/4.0 (compatible; MSIE 8.0; Win32)
IE5_UA_Backup_Flag REG_SZ 5.0
NoNetAutodial REG_DWORD 0x1
MigrateProxy REG_DWORD 0x1
EnableNegotiate REG_DWORD 0x1
ProxyEnable REG_DWORD 0x0
EmailName REG_SZ IEUser@
AutoConfigProxy REG_SZ wininet.dll
MimeExclusionListForCache REG_SZ multipart/mixed multipart/x-mixed-replace multipart/x-byteranges
WarnOnPost REG_BINARY 01000000
UseSchannelDirectly REG_BINARY 01000000
EnableHttp1_1 REG_DWORD 0x1
PrivacyAdvanced REG_DWORD 0x1
PrivDiscUiShown REG_DWORD 0x1
WarnOnZoneCrossing REG_DWORD 0x1
GlobalUserOffline REG_DWORD 0x0
EnableAutodial REG_DWORD 0x0
WarnOnPostRedirect REG_DWORD 0x0
UrlEncoding REG_DWORD 0x0
ProxyHttp1.1 REG_DWORD 0x0
CertificateRevocation REG_DWORD 0x0
DisableCachingOfSSLPages REG_DWORD 0x0
SecureProtocols REG_DWORD 0xa0
WarnonBadCertRecving REG_DWORD 0x1
WarnOnHTTPSToHTTPRedirect REG_DWORD 0x1
ProxyOverride REG_SZ ;*.local
ZonesSecurityUpgrade REG_BINARY D0477CAFCDF9CA01
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Passport
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Protocols
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
NoUpdateCheck REG_DWORD 0x1
NoJITSetup REG_DWORD 0x1
Disable script Debugger REG_SZ no
Show_ChannelBand REG_SZ no
Anchor Underline REG_SZ yes
Cache_Update_Frequency REG_SZ Once_Per_Session
Display Inline Images REG_SZ yes
Do404Search REG_BINARY 01000000
Local Page REG_SZ C:\WINDOWS\system32\blank.htm
Save_Session_History_On_Exit REG_SZ no
Show_FullURL REG_SZ no
Show_StatusBar REG_SZ yes
Show_ToolBar REG_SZ yes
Show_URLinStatusBar REG_SZ yes
Show_URLToolBar REG_SZ yes
Start Page REG_SZ http://www.ask.com?o=101676&l=dis
Use_DlgBox_Colors REG_SZ yes
Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
FullScreen REG_SZ no
Window_Placement REG_BINARY 2C0000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0000000000000000EA030000A6020000
AddToFavoritesExpanded REG_DWORD 0x0
NotifyDownloadComplete REG_SZ yes
Use FormSuggest REG_SZ no
FormSuggest PW Ask REG_SZ no
HistoryViewType REG_BINARY 08006663010000000000
NoSaveAsPOSTWarning REG_DWORD 0x1
Enable Browser Extensions REG_SZ yes
Expand Alt Text REG_SZ no
Move System Caret REG_SZ no
NscSingleExpand REG_DWORD 0x1
DisablescriptDebuggerIE REG_SZ yes
Error Dlg Displayed On Every Error REG_SZ no
NoWebJITSetup REG_DWORD 0x0
Page_Transitions REG_DWORD 0x1
UseThemes REG_DWORD 0x1
Force Offscreen Composition REG_DWORD 0x0
AllowWindowReuse REG_DWORD 0x1
Friendly http errors REG_SZ yes
ShowGoButton REG_SZ yes
SmoothScroll REG_DWORD 0x1
Enable AutoImageResize REG_SZ yes
Enable_MyPics_Hoverbar REG_SZ yes
Play_Animations REG_SZ yes
Play_Background_Sounds REG_SZ yes
Display Inline Videos REG_SZ yes
Show image placeholders REG_DWORD 0x0
Print_Background REG_SZ no
AutoSearch REG_DWORD 0x4
XMLHTTP REG_DWORD 0x1
UseClearType REG_SZ yes
CompatibilityFlags REG_DWORD 0x0
SearchMigrated REG_DWORD 0x1
SearchMigratedDefaultName REG_SZ Google
SearchMigratedDefaultURL REG_SZ http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
SearchMigratedInstalled REG_DWORD 0x1
StatusBarWeb REG_DWORD 0x1
AlwaysShowMenus REG_DWORD 0x1
AutoHide REG_SZ yes
Check_Associations REG_SZ no
ShowedCheckBrowser REG_SZ Yes
RunOnceHasShown REG_DWORD 0x1
RunOnceComplete REG_DWORD 0x1
IE8RunOnceLastShown REG_DWORD 0x1
IE8RunOnceLastShown_TIMESTAMP REG_BINARY F44B9C025B12CB01
IE8TourShown REG_DWORD 0x1
IE8TourShownTime REG_BINARY 56A260BB9A06CB01
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Default Feeds
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\WindowsSearch
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search
SearchAssistant REG_SZ http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
CustomizeSearch REG_SZ http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
CustomSearch REG_SZ http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr8/*http://www.yahoo.com/ext/search/search.html
Default_Search_URL REG_SZ http://www.google.com/ie
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks
{CFBFAE00-17A6-11D0-99CB-00C04FD64497} REG_SZ
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
{3041d03e-fd4b-44e0-b742-2d9b88305f98} REG_BINARY 00
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&AIM Search
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&AOL Toolbar Search
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&Search
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\E&xport to Microsoft Excel
Security Center
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
AntiVirusDisableNotify REG_DWORD 0x0
FirewallDisableNotify REG_DWORD 0x0
UpdatesDisableNotify REG_DWORD 0x0
AntiVirusOverride REG_DWORD 0x0
FirewallOverride REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
EnableFirewall REG_DWORD 0x0
DoNotAllowExceptions REG_DWORD 0x0
DisableNotifications REG_DWORD 0x0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
C:\Program Files\Yahoo!\Messenger\YServer.exe REG_SZ C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server
C:\Program Files\LimeWire\LimeWire.exe REG_SZ C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
C:\Program Files\Messenger\msmsgs.exe REG_SZ C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
C:\Program Files\Common Files\AOL\Loader\aolload.exe REG_SZ C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader
C:\WINDOWS\system32\sessmgr.exe REG_SZ C:\WINDOWS\system32\sessmgr.exe:*:Enabled:@xpsp2res.dll,-22019
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
C:\Program Files\Mozilla Firefox\firefox.exe REG_SZ C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox
C:\Program Files\AIM6\aim6.exe REG_SZ C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe REG_SZ C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
C:\WINDOWS\system32\dxdiag.exe REG_SZ C:\WINDOWS\system32\dxdiag.exe:*:Enabled:Microsoft DirectX Diagnostic Tool
C:\WINDOWS\system32\dpnsvr.exe REG_SZ C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server
C:\WINDOWS\system32\dpvsetup.exe REG_SZ C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test
C:\WINDOWS\system32\PnkBstrA.exe REG_SZ C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA
C:\WINDOWS\system32\PnkBstrB.exe REG_SZ C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB
C:\Program Files\MSN Messenger\msnmsgr.exe REG_SZ C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1
C:\Program Files\MSN Messenger\livecall.exe REG_SZ C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
C:\Program Files\MySpace\IM\MySpaceIM.exe REG_SZ C:\Program Files\MySpace\IM\MySpaceIM.exe:*:Enabled:MySpaceIM
C:\Program Files\Microsoft ActiveSync\rapimgr.exe REG_SZ C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
C:\Program Files\Microsoft ActiveSync\wcescomm.exe REG_SZ C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
C:\Program Files\Microsoft ActiveSync\WCESMgr.exe REG_SZ C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
C:\Documents and Settings\Mitchel\Application Data\mjusbsp\magicJack.exe REG_SZ C:\Documents and Settings\Mitchel\Application Data\mjusbsp\magicJack.exe:*:Enabled:magicJack
C:\Program Files\Logitech\Logitech Vid\Vid.exe REG_SZ C:\Program Files\Logitech\Logitech Vid\Vid.exe:*:Enabled:Logitech Vid
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe REG_SZ C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server
C:\Program Files\Bonjour\mDNSResponder.exe REG_SZ C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service
C:\Program Files\iTunes\iTunes.exe REG_SZ C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
Uninstall List