In looking at startup entries on my computer I noticed entries that I have not noticed before and I am suspicious of them. Here is a copy of my startup log generated by Hijack this.
StartupList report, 3/29/2005, 9:12:55 AM
StartupList version: 1.52.2
Started from : F:\Program Files\hijack this\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==========================
==========
==========
====
Running processes:
E:\WINDOWS\System32\smss.e
xe
E:\WINDOWS\system32\winlog
on.exe
E:\WINDOWS\system32\servic
es.exe
E:\WINDOWS\system32\lsass.
exe
E:\WINDOWS\System32\Ati2ev
xx.exe
E:\WINDOWS\system32\svchos
t.exe
E:\WINDOWS\System32\svchos
t.exe
E:\WINDOWS\system32\spools
v.exe
F:\PROGRA~1\Grisoft\avgams
vr.exe
F:\PROGRA~1\Grisoft\avgups
vc.exe
E:\Program Files\Common Files\Stardock\SDMCP.exe
F:\Program Files\Process Guard\ProcessGuard\dcsuser
prot.exe
E:\WINDOWS\System32\GEARSe
c.exe
F:\Nero\InCD\InCDsrv.exe
E:\WINDOWS\Explorer.EXE
F:\Program Files\Agent\PQV2iSvc.exe
E:\WINDOWS\System32\Tablet
.exe
E:\WINDOWS\system32\ZoneLa
bs\vsmon.e
xe
F:\PROGRA~1\Grisoft\avgemc
.exe
F:\Program Files\Agent\GhostTray.exe
E:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
F:\Program Files\Process Guard\ProcessGuard\pgaccou
nt.exe
E:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
e
F:\Program Files\Process Guard\ProcessGuard\procgua
rd.exe
E:\Program Files\1-Click Answers\answers.exe
E:\PROGRA~1\COMMON~1\GURUN
E~1\agtser
v.exe
E:\WINDOWS\system32\Wtable
t\TabUserW
.exe
F:\Program Files\Grisoft\avgcc.exe
E:\WINDOWS\system32\notepa
d.exe
F:\Program Files\hijack this\HijackThis.exe
F:\Program Files\mozilla firefox opr 1.0\firefox.exe
--------------------------
----------
----------
----
Listing of startup folders:
Shell folders Startup:
[E:\Documents and Settings\Mike\Start Menu\Programs\Startup]
PowerReg Scheduler V3.exe
Shell folders AltStartup:
*Folder not found*
User shell folders Startup:
*Folder not found*
User shell folders AltStartup:
*Folder not found*
Shell folders Common Startup:
[E:\Documents and Settings\All Users\Start Menu\Programs\Startup]
1-Click Answers.lnk = E:\Program Files\1-Click Answers\answers.exe
Adobe Gamma Loader.exe.lnk = E:\Program Files\Common Files\Adobe\Calibration\Ad
obe Gamma Loader.exe
Adobe Reader Speed Launch.lnk = F:\Program Files\Reader\reader_sl.exe
Microsoft Office.lnk = F:\Program Files\Office\OSA9.EXE
Start GetRight.lnk = ?
Symantec Fax Starter Edition Port.lnk = F:\Program Files\Office\1033\OLFSNT40
.EXE
TabUserW.exe.lnk = E:\WINDOWS\system32\Wtable
t\TabUserW
.exe
Shell folders Common AltStartup:
*Folder not found*
User shell folders Common Startup:
*Folder not found*
User shell folders Alternate Common Startup:
*Folder not found*
--------------------------
----------
----------
----
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\W
indows NT\CurrentVersion\Winlogon
]
UserInit = E:\WINDOWS\system32\userin
it.exe,
[HKLM\Software\Microsoft\W
indows\Cur
rentVersio
n\Winlogon
]
*Registry key not found*
[HKCU\Software\Microsoft\W
indows NT\CurrentVersion\Winlogon
]
*Registry value not found*
[HKCU\Software\Microsoft\W
indows\Cur
rentVersio
n\Winlogon
]
*Registry key not found*
--------------------------
----------
----------
----
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\Run
AVG7_EMC = F:\PROGRA~1\Grisoft\avgemc
.exe
(Default) =
Norton Ghost 9.0 = F:\Program Files\Agent\GhostTray.exe
ViewMgr = E:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
!1_pgaccount = "F:\Program Files\Process Guard\ProcessGuard\pgaccou
nt.exe"
Zone Labs Client = "E:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
e"
--------------------------
----------
----------
----
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\RunOnce
*No values found*
--------------------------
----------
----------
----
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\RunOnceEx
*No values found*
--------------------------
----------
----------
----
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\RunServic
es
*No values found*
--------------------------
----------
----------
----
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\RunServic
esOnce
*Registry key not found*
--------------------------
----------
----------
----
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Run
!1_ProcessGuard_Startup = "F:\Program Files\Process Guard\ProcessGuard\procgua
rd.exe" -minimize
--------------------------
----------
----------
----
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\RunOnce
*No values found*
--------------------------
----------
----------
----
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\RunOnceEx
*Registry key not found*
--------------------------
----------
----------
----
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\RunServic
es
*Registry key not found*
--------------------------
----------
----------
----
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\RunServic
esOnce
*Registry key not found*
--------------------------
----------
----------
----
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
ndows NT\CurrentVersion\Run
*Registry key not found*
--------------------------
----------
----------
----
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
ndows NT\CurrentVersion\Run
*Registry key not found*
--------------------------
----------
----------
----
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\Run
[OptionalComponents]
*No values found*
--------------------------
----------
----------
----
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\RunOnce
*No subkeys found*
--------------------------
----------
----------
----
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\RunOnceEx
*No subkeys found*
--------------------------
----------
----------
----
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\RunServic
es
*No subkeys found*
--------------------------
----------
----------
----
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\RunServic
esOnce
*Registry key not found*
--------------------------
----------
----------
----
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Run
*No subkeys found*
--------------------------
----------
----------
----
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\RunOnce
*No subkeys found*
--------------------------
----------
----------
----
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\RunOnceEx
*Registry key not found*
--------------------------
----------
----------
----
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\RunServic
es
*Registry key not found*
--------------------------
----------
----------
----
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\RunServic
esOnce
*Registry key not found*
--------------------------
----------
----------
----
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi
ndows NT\CurrentVersion\Run
*Registry key not found*
--------------------------
----------
----------
----
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi
ndows NT\CurrentVersion\Run
*Registry key not found*
--------------------------
----------
----------
----
File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\
shell\open
\command
(Default) = "%1" %*
--------------------------
----------
----------
----
File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\
shell\open
\command
(Default) = "%1" %*
--------------------------
----------
----------
----
File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\
shell\open
\command
(Default) = "%1" %*
--------------------------
----------
----------
----
File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\
shell\open
\command
(Default) = "%1" %*
--------------------------
----------
----------
----
File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\
shell\open
\command
(Default) = "%1" /S
--------------------------
----------
----------
----
File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\
shell\open
\command
(Default) = E:\WINDOWS\System32\mshta.
exe "%1" %*
--------------------------
----------
----------
----
File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\
shell\open
\command
(Default) = %SystemRoot%\system32\NOTE
PAD.EXE %1
--------------------------
----------
----------
----
Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Ac
tive Setup\Installed Components
(* = disabled by HKCU twin)
[>{22d6f312-b0f6-11d0-94ab
-0080c74c7
e95}]
StubPath = E:\WINDOWS\inf\unregmp2.ex
e /ShowWMP
[>{26923b43-4d38-484f-9b9e
-de4607462
76c}] *
StubPath = %systemroot%\system32\shmg
rate.exe OCInstallUserConfigIE
[>{60B49E34-C7CC-11D0-8953
-00A0C9034
7FF}MICROS
] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
[>{881dd1c5-3dcf-431b-b061
-f3f88e8be
88a}] *
StubPath = %systemroot%\system32\shmg
rate.exe OCInstallUserConfigOE
[{2C7339CF-2B09-4501-B3F3-
F3508C9228
ED}] *
StubPath = %SystemRoot%\system32\regs
vr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\them
eui.dll
[{44BBA840-CC51-11CF-AAFA-
00AA00B601
5C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
[{44BBA842-CC51-11CF-AAFA-
00AA00B601
5B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSecti
on E:\WINDOWS\INF\msnetmtg.in
f,NetMtg.I
nstall.Per
User.NT
[{4b218e3e-bc98-4770-93d3-
2731b93292
78}] *
StubPath = %SystemRoot%\System32\rund
ll32.exe setupapi,InstallHinfSectio
n MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf
[{5945c046-1e7d-11d1-bc44-
00c04fd912
be}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSecti
on E:\WINDOWS\INF\msmsgs.inf,
BLC.QuietI
nstall.Per
User
[{6BF52A52-394A-11d3-B153-
00C04F79FA
A6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSecti
on E:\WINDOWS\INF\wmp.inf,Per
UserStub
[{7790769C-0471-11d2-AF11-
00C04FA35D
02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
[{89820200-ECBD-11cf-8B85-
00AA005B43
40}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll
[{89820200-ECBD-11cf-8B85-
00AA005B43
83}] *
StubPath = %SystemRoot%\system32\ie4u
init.exe
[{89B4C1CD-B018-4511-B0A1-
5476DBF708
20}] *
StubPath = E:\WINDOWS\System32\Rundll
32.exe E:\WINDOWS\System32\mscori
es.dll,Ins
tall
--------------------------
----------
----------
----
Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\IC
Q\Agent\Ap
ps
*Registry key not found*
--------------------------
----------
----------
----
Load/Run keys from E:\WINDOWS\WIN.INI:
load=*INI section not found*
run=*INI section not found*
Load/Run keys from Registry:
HKLM\..\Windows NT\CurrentVersion\WinLogon
: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon
: run=*Registry value not found*
HKLM\..\Windows\CurrentVer
sion\WinLo
gon: load=*Registry key not found*
HKLM\..\Windows\CurrentVer
sion\WinLo
gon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon
: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon
: run=*Registry value not found*
HKCU\..\Windows\CurrentVer
sion\WinLo
gon: load=*Registry key not found*
HKCU\..\Windows\CurrentVer
sion\WinLo
gon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows:
load=
HKCU\..\Windows NT\CurrentVersion\Windows:
run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows:
load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows:
run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows:
AppInit_DLLs=
--------------------------
----------
----------
----
Shell & screensaver key from E:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=E:\WINDOWS\Sy
stem32\ss3
dfo.scr
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------
----------
----------
----
Checking for EXPLORER.EXE instances:
E:\WINDOWS\Explorer.exe: PRESENT!
C:\Explorer.exe: not present
E:\WINDOWS\Explorer\Explor
er.exe: not present
E:\WINDOWS\System\Explorer
.exe: not present
E:\WINDOWS\System32\Explor
er.exe: not present
E:\WINDOWS\Command\Explore
r.exe: not present
E:\WINDOWS\Fonts\Explorer.
exe: not present
--------------------------
----------
----------
----
Checking for superhidden extensions:
.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden
--------------------------
----------
----------
----
Verifying REGEDIT.EXE integrity:
- Regedit.exe found in E:\WINDOWS
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'
Registry check passed
--------------------------
----------
----------
----
Enumerating Browser Helper Objects:
(no name) - F:\Program Files\ActiveX\AcroIEHelper
.dll - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3}
--------------------------
----------
----------
----
Enumerating Task Scheduler jobs:
*No jobs found*
--------------------------
----------
----------
----
Enumerating Download Program Files:
[Shockwave Flash Object]
InProcServer32 = E:\WINDOWS\system32\macrom
ed\flash\F
lash.ocx
CODEBASE =
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash5r42.cab--------------------------
----------
----------
----
Enumerating Winsock LSP files:
NameSpace #1: E:\WINDOWS\System32\mswsoc
k.dll
NameSpace #2: E:\WINDOWS\System32\winrnr
.dll
NameSpace #3: E:\WINDOWS\System32\mswsoc
k.dll
Protocol #1: E:\WINDOWS\system32\mswsoc
k.dll
Protocol #2: E:\WINDOWS\system32\mswsoc
k.dll
Protocol #3: E:\WINDOWS\system32\mswsoc
k.dll
Protocol #4: E:\WINDOWS\system32\rsvpsp
.dll
Protocol #5: E:\WINDOWS\system32\rsvpsp
.dll
Protocol #6: E:\WINDOWS\system32\mswsoc
k.dll
Protocol #7: E:\WINDOWS\system32\mswsoc
k.dll
Protocol #8: E:\WINDOWS\system32\mswsoc
k.dll
Protocol #9: E:\WINDOWS\system32\mswsoc
k.dll
Protocol #10: E:\WINDOWS\system32\mswsoc
k.dll
Protocol #11: E:\WINDOWS\system32\mswsoc
k.dll
Protocol #12: E:\WINDOWS\system32\mswsoc
k.dll
Protocol #13: E:\WINDOWS\system32\mswsoc
k.dll
Protocol #14: E:\WINDOWS\system32\mswsoc
k.dll
Protocol #15: E:\WINDOWS\system32\mswsoc
k.dll
--------------------------
----------
----------
----
Enumerating Windows NT/2000/XP services
Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system)
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
AFD Networking Support Environment: \SystemRoot\System32\drive
rs\afd.sys
(system)
Service for Realtek AC97 Audio (WDM): system32\drivers\ALCXWDM.S
YS (manual start)
Alerter: %SystemRoot%\System32\svch
ost.exe -k LocalService (autostart)
Application Layer Gateway Service: %SystemRoot%\System32\alg.
exe (manual start)
Application Management: %SystemRoot%\system32\svch
ost.exe -k netsvcs (manual start)
ASP.NET State Service: %SystemRoot%\Microsoft.NET
\Framework
\v1.1.4322
\aspnet_st
ate.exe (manual start)
RAS Asynchronous Media Driver: System32\DRIVERS\asyncmac.
sys (manual start)
Standard IDE/ESDI Hard Disk Controller: System32\DRIVERS\atapi.sys
(system)
Ati HotKey Poller: %SystemRoot%\System32\Ati2
evxx.exe (autostart)
ATI Smart: E:\WINDOWS\system32\ati2sg
ag.exe (autostart)
ati2mtag: System32\DRIVERS\ati2mtag.
sys (manual start)
ATM ARP Client Protocol: System32\DRIVERS\atmarpc.s
ys (manual start)
Windows Audio: %SystemRoot%\System32\svch
ost.exe -k netsvcs (autostart)
Audio Stub Driver: System32\DRIVERS\audstub.s
ys (manual start)
AVG7 Alert Manager Server: F:\PROGRA~1\Grisoft\avgams
vr.exe (autostart)
AVG7 Kernel: \SystemRoot\System32\Drive
rs\avg7cor
e.sys (system)
AVG7 Wrap Driver: \SystemRoot\System32\Drive
rs\avg7rsw
.sys (system)
AVG7 Rezident Driver: \SystemRoot\System32\Drive
rs\avg7rsx
p.sys (system)
AVG7 Update Service: F:\PROGRA~1\Grisoft\avgups
vc.exe (autostart)
AVG Network Redirector: \??\E:\WINDOWS\System32\Dr
ivers\avgt
di.sys (autostart)
Background Intelligent Transfer Service: %SystemRoot%\System32\svch
ost.exe -k netsvcs (manual start)
Computer Browser: %SystemRoot%\System32\svch
ost.exe -k netsvcs (autostart)
CD-ROM Driver: System32\DRIVERS\cdrom.sys
(system)
Indexing Service: E:\WINDOWS\System32\cisvc.
exe (manual start)
ClipBook: %SystemRoot%\system32\clip
srv.exe (disabled)
COM+ System Application: E:\WINDOWS\System32\dllhos
t.exe /Processid:{02D4B3F1-FD88-
11D1-960D-
00805FC792
35} (manual start)
Cryptographic Services: %SystemRoot%\system32\svch
ost.exe -k netsvcs (autostart)
DCOM Server Process Launcher: %SystemRoot%\system32\svch
ost -k DcomLaunch (autostart)
DiamondCS Process Guard Service v3.000: "F:\Program Files\Process Guard\ProcessGuard\dcsuser
prot.exe" (autostart)
DHCP Client: %SystemRoot%\System32\svch
ost.exe -k netsvcs (autostart)
Disk Driver: System32\DRIVERS\disk.sys (system)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmad
min.exe /com (manual start)
dmboot: System32\drivers\dmboot.sy
s (disabled)
dmio: System32\drivers\dmio.sys (disabled)
dmload: System32\drivers\dmload.sy
s (disabled)
Logical Disk Manager: %SystemRoot%\System32\svch
ost.exe -k netsvcs (manual start)
Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sy
s (manual start)
DNS Client: %SystemRoot%\System32\svch
ost.exe -k NetworkService (autostart)
Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.s
ys (manual start)
Error Reporting Service: %SystemRoot%\System32\svch
ost.exe -k netsvcs (autostart)
Event Log: %SystemRoot%\system32\serv
ices.exe (autostart)
COM+ Event System: E:\WINDOWS\System32\svchos
t.exe -k netsvcs (manual start)
Fast User Switching Compatibility: %SystemRoot%\System32\svch
ost.exe -k netsvcs (manual start)
Floppy Disk Controller Driver: System32\DRIVERS\fdc.sys (manual start)
VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver: System32\DRIVERS\fetnd5.sy
s (manual start)
VIA Rhine Family Fast Ethernet Adapter Driver Service: System32\DRIVERS\fetnd5b.s
ys (manual start)
Floppy Disk Driver: System32\DRIVERS\flpydisk.
sys (manual start)
FltMgr: system32\drivers\fltmgr.sy
s (system)
Volume Manager Driver: System32\DRIVERS\ftdisk.sy
s (system)
GEARSecurity: %SystemRoot%\System32\GEAR
Sec.exe (autostart)
GMSIPCI: \??\D:\INSTALL\GMSIPCI.SYS
(manual start)
Generic Packet Classifier: System32\DRIVERS\msgpc.sys
(manual start)
HCF_MSFT: System32\DRIVERS\HCF_MSFT.
sys (manual start)
Help and Support: %SystemRoot%\System32\svch
ost.exe -k netsvcs (autostart)
Human Interface Device Access: %SystemRoot%\System32\svch
ost.exe -k netsvcs (disabled)
Microsoft HID Class Driver: System32\DRIVERS\hidusb.sy
s (manual start)
HTTP: System32\Drivers\HTTP.sys (manual start)
HTTP SSL: %SystemRoot%\System32\svch
ost.exe -k HTTPFilter (manual start)
i8042 Keyboard and PS/2 Mouse Port Driver: System32\DRIVERS\i8042prt.
sys (system)
IMAPI CD-Burning COM Service: E:\WINDOWS\System32\imapi.
exe (manual start)
InCdPass: System32\DRIVERS\InCDPass.
sys (system)
InCD File System Service: F:\Nero\InCD\InCDsrv.exe (autostart)
IPv6 Windows Firewall Driver: system32\drivers\ip6fw.sys
(manual start)
IP Traffic Filter Driver: System32\DRIVERS\ipfltdrv.
sys (manual start)
IP in IP Tunnel Driver: System32\DRIVERS\ipinip.sy
s (manual start)
IP Network Address Translator: System32\DRIVERS\ipnat.sys
(manual start)
IPSEC driver: System32\DRIVERS\ipsec.sys
(system)
IR Enumerator Service: System32\DRIVERS\irenum.sy
s (manual start)
PnP ISA/EISA Bus Driver: System32\DRIVERS\isapnp.sy
s (system)
Keyboard Class Driver: System32\DRIVERS\kbdclass.
sys (system)
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sy
s (manual start)
Server: %SystemRoot%\System32\svch
ost.exe -k netsvcs (autostart)
Workstation: %SystemRoot%\System32\svch
ost.exe -k netsvcs (autostart)
TCP/IP NetBIOS Helper: %SystemRoot%\System32\svch
ost.exe -k LocalService (autostart)
mbmiodrvr: \??\E:\WINDOWS\system32\mb
miodrvr.sy
s (system)
Messenger: %SystemRoot%\System32\svch
ost.exe -k netsvcs (disabled)
NetMeeting Remote Desktop Sharing: E:\WINDOWS\System32\mnmsrv
c.exe (manual start)
Mouse Class Driver: System32\DRIVERS\mouclass.
sys (system)
Mouse HID Driver: System32\DRIVERS\mouhid.sy
s (manual start)
WebDav Client Redirector: System32\DRIVERS\mrxdav.sy
s (manual start)
MRXSMB: System32\DRIVERS\mrxsmb.sy
s (system)
Distributed Transaction Coordinator: E:\WINDOWS\System32\msdtc.
exe (manual start)
Windows Installer: E:\WINDOWS\System32\msiexe
c.exe /V (manual start)
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.s
ys (manual start)
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.
sys (manual start)
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys
(manual start)
Microsoft System Management BIOS Driver: System32\DRIVERS\mssmbios.
sys (manual start)
Remote Access NDIS TAPI Driver: System32\DRIVERS\ndistapi.
sys (manual start)
NDIS Usermode I/O Protocol: System32\DRIVERS\ndisuio.s
ys (manual start)
Remote Access NDIS WAN Driver: System32\DRIVERS\ndiswan.s
ys (manual start)
NetBIOS Interface: System32\DRIVERS\netbios.s
ys (system)
NetBios over Tcpip: System32\DRIVERS\netbt.sys
(system)
Network DDE: %SystemRoot%\system32\netd
de.exe (disabled)
Network DDE DSDM: %SystemRoot%\system32\netd
de.exe (disabled)
Net Logon: %SystemRoot%\System32\lsas
s.exe (manual start)
Network Connections: %SystemRoot%\System32\svch
ost.exe -k netsvcs (manual start)
Network Location Awareness (NLA): %SystemRoot%\System32\svch
ost.exe -k netsvcs (manual start)
Network Monitor Driver: System32\DRIVERS\NMnt.sys (manual start)
Norton Ghost: F:\Program Files\Agent\PQV2iSvc.exe (autostart)
NetGroup Packet Filter Driver: system32\drivers\npf.sys (manual start)
NTACCESS: \??\D:\NTACCESS.sys (manual start)
NT LM Security Support Provider: %SystemRoot%\System32\lsas
s.exe (manual start)
Removable Storage: %SystemRoot%\system32\svch
ost.exe -k netsvcs (manual start)
IPX Traffic Filter Driver: System32\DRIVERS\nwlnkflt.
sys (manual start)
IPX Traffic Forwarder Driver: System32\DRIVERS\nwlnkfwd.
sys (manual start)
Parallel port driver: System32\DRIVERS\parport.s
ys (manual start)
PCI Bus Driver: System32\DRIVERS\pci.sys (system)
Pen Class: System32\Drivers\penclass.
sys (system)
Plug and Play: %SystemRoot%\system32\serv
ices.exe (autostart)
IPSEC Services: %SystemRoot%\System32\lsas
s.exe (autostart)
WAN Miniport (PPTP): System32\DRIVERS\raspptp.s
ys (manual start)
Processor Driver: System32\DRIVERS\processr.
sys (system)
procguard: \??\E:\WINDOWS\system32\dr
ivers\proc
guard.sys (autostart)
Protected Storage: %SystemRoot%\system32\lsas
s.exe (autostart)
QoS Packet Scheduler: System32\DRIVERS\psched.sy
s (manual start)
Direct Parallel Link Driver: System32\DRIVERS\ptilink.s
ys (manual start)
Remote Access Auto Connection Driver: System32\DRIVERS\rasacd.sy
s (system)
Remote Access Auto Connection Manager: %SystemRoot%\System32\svch
ost.exe -k netsvcs (manual start)
WAN Miniport (L2TP): System32\DRIVERS\rasl2tp.s
ys (manual start)
Remote Access Connection Manager: %SystemRoot%\System32\svch
ost.exe -k netsvcs (manual start)
Remote Access PPPOE Driver: System32\DRIVERS\raspppoe.
sys (manual start)
Direct Parallel: System32\DRIVERS\raspti.sy
s (manual start)
Rdbss: System32\DRIVERS\rdbss.sys
(system)
RDPCDD: System32\DRIVERS\RDPCDD.sy
s (system)
Remote Desktop Help Session Manager: E:\WINDOWS\system32\sessmg
r.exe (manual start)
Digital CD Audio Playback Filter Driver: System32\DRIVERS\redbook.s
ys (system)
Routing and Remote Access: %SystemRoot%\System32\svch
ost.exe -k netsvcs (disabled)
Remote Packet Capture Protocol v.0 (experimental): "%ProgramFiles%\WinPcap\rp
capd.exe" -d -f "%ProgramFiles%\WinPcap\rp
capd.ini" (manual start)
Remote Procedure Call (RPC) Locator: %SystemRoot%\System32\loca
tor.exe (manual start)
Remote Procedure Call (RPC): %SystemRoot%\system32\svch
ost -k rpcss (autostart)
QoS RSVP: %SystemRoot%\System32\rsvp
.exe (manual start)
Security Accounts Manager: %SystemRoot%\system32\lsas
s.exe (autostart)
Smart Card: %SystemRoot%\System32\SCar
dSvr.exe (manual start)
Task Scheduler: %SystemRoot%\System32\svch
ost.exe -k netsvcs (autostart)
Secdrv: System32\DRIVERS\secdrv.sy
s (manual start)
Secondary Logon: %SystemRoot%\System32\svch
ost.exe -k netsvcs (autostart)
System Event Notification: %SystemRoot%\system32\svch
ost.exe -k netsvcs (autostart)
Serenum Filter Driver: System32\DRIVERS\serenum.s
ys (manual start)
Serial port driver: System32\DRIVERS\serial.sy
s (system)
SetupNTGLM7X: \??\D:\NTGLM7X.sys (manual start)
Windows Firewall/Internet Connection Sharing (ICS): %SystemRoot%\System32\svch
ost.exe -k netsvcs (autostart)
Shell Hardware Detection: %SystemRoot%\System32\svch
ost.exe -k netsvcs (autostart)
Microsoft Kernel Audio Splitter: system32\drivers\splitter.
sys (manual start)
Print Spooler: %SystemRoot%\system32\spoo
lsv.exe (autostart)
System Restore Filter Driver: System32\DRIVERS\sr.sys (system)
System Restore Service: %SystemRoot%\System32\svch
ost.exe -k netsvcs (autostart)
Srv: System32\DRIVERS\srv.sys (manual start)
SSDP Discovery Service: %SystemRoot%\System32\svch
ost.exe -k LocalService (manual start)
Windows Image Acquisition (WIA): %SystemRoot%\System32\svch
ost.exe -k imgsvc (manual start)
Software Bus Driver: System32\DRIVERS\swenum.sy
s (manual start)
Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sy
s (manual start)
MS Software Shadow Copy Provider: E:\WINDOWS\System32\dllhos
t.exe /Processid:{F5662483-DD26-
4770-A50A-
0842F7001C
7F} (manual start)
Microsoft Kernel System Audio Device: system32\drivers\sysaudio.
sys (manual start)
Performance Logs and Alerts: %SystemRoot%\system32\smlo
gsvc.exe (manual start)
TabletService: E:\WINDOWS\System32\Tablet
.exe (autostart)
Telephony: %SystemRoot%\System32\svch
ost.exe -k netsvcs (manual start)
TCP/IP Protocol Driver: System32\DRIVERS\tcpip.sys
(system)
Terminal Device Driver: System32\DRIVERS\termdd.sy
s (system)
Terminal Services: %SystemRoot%\System32\svch
ost -k DComLaunch (manual start)
Themes: %SystemRoot%\System32\svch
ost.exe -k netsvcs (autostart)
Distributed Link Tracking Client: %SystemRoot%\system32\svch
ost.exe -k netsvcs (autostart)
Microcode Update Driver: System32\DRIVERS\update.sy
s (manual start)
Universal Plug and Play Device Host: %SystemRoot%\System32\svch
ost.exe -k LocalService (manual start)
Uninterruptible Power Supply: %SystemRoot%\System32\ups.
exe (manual start)
USB2 Enabled Hub: System32\DRIVERS\usbhub.sy
s (manual start)
USB Mass Storage Driver: System32\DRIVERS\USBSTOR.S
YS (manual start)
Microsoft USB Universal Host Controller Miniport Driver: System32\DRIVERS\usbuhci.s
ys (manual start)
VGA Display Controller.: \SystemRoot\System32\drive
rs\vga.sys
(system)
VIA AGP Filter: System32\DRIVERS\viaagp1.s
ys (system)
ViaIde: System32\DRIVERS\viaidexp.
sys (system)
vsdatant: System32\vsdatant.sys (system)
TrueVector Internet Monitor: E:\WINDOWS\system32\ZoneLa
bs\vsmon.e
xe -service (autostart)
Volume Shadow Copy: %SystemRoot%\System32\vssv
c.exe (manual start)
Windows Time: %SystemRoot%\System32\svch
ost.exe -k netsvcs (autostart)
Remote Access IP ARP Driver: System32\DRIVERS\wanarp.sy
s (manual start)
Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sy
s (manual start)
WebClient: %SystemRoot%\System32\svch
ost.exe -k LocalService (autostart)
Windows Management Instrumentation: %systemroot%\system32\svch
ost.exe -k netsvcs (autostart)
VNC Server Version 4: "F:\Program Files\VNC4\WinVNC4.exe" -service (autostart)
Portable Media Serial Number Service: %SystemRoot%\System32\svch
ost.exe -k netsvcs (manual start)
WMI Performance Adapter: E:\WINDOWS\System32\wbem\w
miapsrv.ex
e (manual start)
Security Center: %SystemRoot%\System32\svch
ost.exe -k netsvcs (autostart)
Automatic Updates: %systemroot%\system32\svch
ost.exe -k netsvcs (autostart)
Wireless Zero Configuration: %SystemRoot%\System32\svch
ost.exe -k netsvcs (autostart)
Network Provisioning Service: %SystemRoot%\System32\svch
ost.exe -k netsvcs (manual start)
--------------------------
----------
----------
----
Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*
Windows NT checkdisk command:
BootExecute = autocheck autochk *
Windows NT 'Wininit.ini':
PendingFileRenameOperation
s: *Registry value not found*
--------------------------
----------
----------
----
Enumerating ShellServiceObjectDelayLoa
d items:
0aMCPClient: E:\Program Files\Common Files\Stardock\mcpcore.dll
PostBootReminder: E:\WINDOWS\system32\SHELL3
2.dll
CDBurn: E:\WINDOWS\system32\SHELL3
2.dll
WebCheck: E:\WINDOWS\System32\webche
ck.dll
SysTray: E:\WINDOWS\System32\stobje
ct.dll
--------------------------
----------
----------
----
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\policies\
Explorer\R
un
*Registry key not found*
--------------------------
----------
----------
----
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\policies\
Explorer\R
un
*Registry key not found*
--------------------------
----------
----------
----
End of report, 31,455 bytes
Report generated in 0.125 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only