davidascott
asked on
Unable to view source file - "right click">"view source"
I previously had problems with being able to view source files. See question below:
https://www.experts-exchange.com/questions/22671676/Unable-to-View-Source-File-Windows-XP-IE7-Problem.html
I have now had a reoccurence of the problem but have not been able to fix it using the suggestions in the above solution.
Can anyone help here please?
Thanks, David
https://www.experts-exchange.com/questions/22671676/Unable-to-View-Source-File-Windows-XP-IE7-Problem.html
I have now had a reoccurence of the problem but have not been able to fix it using the suggestions in the above solution.
Can anyone help here please?
Thanks, David
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
Thanks JSoup....a couple of questions first:
1. The Photodex application is a bonefide application that is very useful....do you think that it is corrupted or are there compatibility issues?....would you mind sharing your thoughts please...thank-you
2. Do you know what te Yahoo things are?
3. What do you mean by 'fake protection' ....and.....how do I address this?
Thanks again,
David
1. The Photodex application is a bonefide application that is very useful....do you think that it is corrupted or are there compatibility issues?....would you mind sharing your thoughts please...thank-you
2. Do you know what te Yahoo things are?
3. What do you mean by 'fake protection' ....and.....how do I address this?
Thanks again,
David
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Whot do you mean?? "how do I address this"
ASKER
Hi.....See your initial comments re security. I'm very interested/concerned on how I can deal with/overcome "fake protection"...you got me thinking/worrying. If I can do anything about the security protection I would be grateful of any advice. Thanks, David
ASKER
I am not very experienced in this area - please bear with me.
To 'disable' the 2 yahoo files (which I have located) what do I need to do? i.e. I could not see how I could disable them (aside from deleting them)
To edit the registry do I go to 'run' and type 'regedit'?...then find the file and delete it?...would this on its own (aside from removing the whole program) still allow the photdex application to operate? If I unistalled could I remove from 'control panel'?
I have run superantispyware and nothing to report.
Thanks, David
To 'disable' the 2 yahoo files (which I have located) what do I need to do? i.e. I could not see how I could disable them (aside from deleting them)
To edit the registry do I go to 'run' and type 'regedit'?...then find the file and delete it?...would this on its own (aside from removing the whole program) still allow the photdex application to operate? If I unistalled could I remove from 'control panel'?
I have run superantispyware and nothing to report.
Thanks, David
can you access the internet from safemode with networking?
if yes then go there, and check if you can view IE source from there or not?
if yes then go there, and check if you can view IE source from there or not?
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
then click the fix checked in HijackThis
ASKER
Hi JSoup,
Thank you for your help. Your solution worked a treat. Just to finish off, would you recommend that I reinstall zonelabs and superanitspyware?
I am assuming that there was a corruption on the installation that caused the issues?
Thanks again,
David
Thank you for your help. Your solution worked a treat. Just to finish off, would you recommend that I reinstall zonelabs and superanitspyware?
I am assuming that there was a corruption on the installation that caused the issues?
Thanks again,
David
I belive the your pruduct to be dated. zonelabs is now ZONEALARM. ZONEALARM is a very good product. The answer is no from my standpoint. But its your system. Spyware / adware / malware changes daily or more. the best defense For me is to reduce the privalage I have when I surff the internet. They can't install and can't do damage to the system. Please note that A JPG picture can carry a payload .
a hardware firewall would be best look ZoneAlarm Secure router Price is high but it work.
superanitspyware is not of value.
Haker hide using other peaple network and system they are anonymously. You can not be anonymously.
a hardware firewall would be best look ZoneAlarm Secure router Price is high but it work.
superanitspyware is not of value.
Haker hide using other peaple network and system they are anonymously. You can not be anonymously.
I believe the your product to be dated. zonelabs is now ZONEALARM. ZONEALARM is a very good product. The answer is no from my standpoint. But its your system. Spyware / adware / malware changes daily or more. the best defense For me is to reduce the privilege I have when I surf the internet. They can't install and can't do damage to the system. Please note that A JPG picture can carry a payload.
a hardware firewall would be best look ZoneAlarm Secure router Price is high but it work.
superanitspyware is not of value.
Hacker hide using other people network and system they are anonymously. You cannot be anonymously.
a hardware firewall would be best look ZoneAlarm Secure router Price is high but it work.
superanitspyware is not of value.
Hacker hide using other people network and system they are anonymously. You cannot be anonymously.
ASKER
One thing that may help is that I've noticed that in the information below that the following page has 'taken over my home page'
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi
*Registry key not found*
This started about two weeks ago......................
Logfile of HijackThis v1.99.1
Scan saved at 21:01:50, on 28/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtr
C:\WINDOWS\system32\hkcmd.
C:\WINDOWS\system32\igfxpe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\SMINST\Schedule
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\PROGRA~1\BTHOME~1\Help\
C:\Program Files\btbb_wcm\McciTrayApp
C:\PROGRA~1\Yahoo!\browser
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
C:\WINDOWS\system32\WDBtnM
C:\PROGRA~1\Yahoo!\browser
C:\Program Files\Norton Save and Restore\Agent\VProTray.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Hewlett-Packard\Orde
C:\Program Files\iTunes\iTunesHelper.
C:\Program Files\Plaxo\2.13.0.12\Plax
C:\WINDOWS\system32\ctfmon
C:\Program Files\SUPERAntiSpyware\SUP
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
C:\Program Files\Symantec\LiveUpdate\
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe
C:\Program Files\Photodex\ProShowGold
C:\Program Files\Steganos Internet Anonym VPN\SVPNStarter.exe
C:\WINDOWS\system32\ZoneLa
C:\PROGRA~1\ZONELA~1\ZONEA
C:\WINDOWS\system32\wscntf
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\iPod\bin\iPodService
C:\Program Files\Litera\ChangePro3\lc
C:\Program Files\My Book\WD Backup\uBBMonitor.exe
C:\Program Files\BT Home Hub\Help\bin\mpbtn.exe
C:\WINDOWS\System32\svchos
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Des
R1 - HKCU\Software\Microsoft\In
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\Wi
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-1
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtr
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SDMSSplash] "C:\Program Files\HP_SDMS\SDMSSplash\l
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\Se
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard
O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_
O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Schedule
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\BTHOME~1\Help\
O4 - HKLM\..\Run: [btbb_wcm_McciTrayApp] C:\Program Files\btbb_wcm\McciTrayApp
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [Norton Save and Restore 2.0] "C:\Program Files\Norton Save and Restore\Agent\VProTray.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe
O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\Orde
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.
O4 - HKCU\..\Run: [eyeBeam SIP Client] "C:\Program Files\BT Broadband Talk Softphone\BTSoftphone.exe"
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.13.0.12\Plax
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateMana
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUP
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BT Broadband Desktop Help.lnk = C:\Program Files\BT Home Hub\Help\bin\matcli.exe
O4 - Global Startup: Launcher.lnk = C:\Program Files\Litera\ChangePro3\lc
O4 - Global Startup: WD Backup Monitor.lnk = C:\Program Files\My Book\WD Backup\uBBMonitor.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2359626E-7524-4F87-B04E-2
O16 - DPF: {4C39376E-FA9D-4349-BACC-D
O16 - DPF: {CB50428B-657F-47DF-9B32-6
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-0
O17 - HKLM\System\CCS\Services\T
O17 - HKLM\System\CS1\Services\T
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SAS
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxde
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEU
O23 - Service: Norton Save and Restore - Symantec Corporation - C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe
O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Steganos VPN Starter Service (SVPNStarter) - Unknown owner - C:\Program Files\Steganos Internet Anonym VPN\SVPNStarter.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLa
..........................
StartupList report, 28/09/2007, 21:05:16
StartupList version: 1.52.2
Started from : C:\Documents and Settings\Administrator\Des
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16512)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==========================
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtr
C:\WINDOWS\system32\hkcmd.
C:\WINDOWS\system32\igfxpe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\SMINST\Schedule
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\PROGRA~1\BTHOME~1\Help\
C:\Program Files\btbb_wcm\McciTrayApp
C:\PROGRA~1\Yahoo!\browser
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
C:\WINDOWS\system32\WDBtnM
C:\PROGRA~1\Yahoo!\browser
C:\Program Files\Norton Save and Restore\Agent\VProTray.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Hewlett-Packard\Orde
C:\Program Files\iTunes\iTunesHelper.
C:\Program Files\Plaxo\2.13.0.12\Plax
C:\WINDOWS\system32\ctfmon
C:\Program Files\SUPERAntiSpyware\SUP
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
C:\Program Files\Symantec\LiveUpdate\
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe
C:\Program Files\Photodex\ProShowGold
C:\Program Files\Steganos Internet Anonym VPN\SVPNStarter.exe
C:\WINDOWS\system32\ZoneLa
C:\PROGRA~1\ZONELA~1\ZONEA
C:\WINDOWS\system32\wscntf
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\iPod\bin\iPodService
C:\Program Files\Litera\ChangePro3\lc
C:\Program Files\My Book\WD Backup\uBBMonitor.exe
C:\Program Files\BT Home Hub\Help\bin\mpbtn.exe
C:\WINDOWS\System32\svchos
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\NoteTab Pro 5\NotePro.exe
C:\Documents and Settings\Administrator\Des
--------------------------
Listing of startup folders:
Shell folders Startup:
[C:\Documents and Settings\Administrator\Sta
*No files*
Shell folders AltStartup:
*Folder not found*
User shell folders Startup:
*Folder not found*
User shell folders AltStartup:
*Folder not found*
Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
BT Broadband Desktop Help.lnk = C:\Program Files\BT Home Hub\Help\bin\matcli.exe
Launcher.lnk = C:\Program Files\Litera\ChangePro3\lc
WD Backup Monitor.lnk = C:\Program Files\My Book\WD Backup\uBBMonitor.exe
Shell folders Common AltStartup:
*Folder not found*
User shell folders Common Startup:
*Folder not found*
User shell folders Alternate Common Startup:
*Folder not found*
--------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\W
UserInit = C:\WINDOWS\system32\userin
[HKLM\Software\Microsoft\W
*Registry key not found*
[HKCU\Software\Microsoft\W
*Registry value not found*
[HKCU\Software\Microsoft\W
*Registry key not found*
--------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
IgfxTray = C:\WINDOWS\system32\igfxtr
HotKeysCmds = C:\WINDOWS\system32\hkcmd.
Persistence = C:\WINDOWS\system32\igfxpe
High Definition Audio Property Page Shortcut = HDAShCut.exe
RTHDCPL = RTHDCPL.EXE
SDMSSplash = "C:\Program Files\HP_SDMS\SDMSSplash\l
SetRefresh = C:\Program Files\Compaq\SetRefresh\Se
Recguard = C:\WINDOWS\Sminst\Recguard
Reminder = C:\WINDOWS\Creator\Remind_
Scheduler = C:\WINDOWS\SMINST\Schedule
type32 = "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
IntelliPoint = "C:\Program Files\Microsoft IntelliPoint\point32.exe"
Motive SmartBridge = C:\PROGRA~1\BTHOME~1\Help\
btbb_wcm_McciTrayApp = C:\Program Files\btbb_wcm\McciTrayApp
YBrowser = C:\PROGRA~1\Yahoo!\browser
ZoneAlarm Client = "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
RegistryMechanic =
WD Button Manager = WDBtnMgr.exe
Norton Save and Restore 2.0 = "C:\Program Files\Norton Save and Restore\Agent\VProTray.exe
PCSuiteTrayApplication = C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
QuickTime Task = "C:\Program Files\QuickTime\QTTask.exe
OrderReminder = C:\Program Files\Hewlett-Packard\Orde
iTunesHelper = "C:\Program Files\iTunes\iTunesHelper.
--------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
*No values found*
--------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
*No values found*
--------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
eyeBeam SIP Client = "C:\Program Files\BT Broadband Talk Softphone\BTSoftphone.exe"
PlaxoUpdate = C:\Program Files\Plaxo\2.13.0.12\Plax
ctfmon.exe = C:\WINDOWS\system32\ctfmon
updateMgr = C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateMana
SUPERAntiSpyware = C:\Program Files\SUPERAntiSpyware\SUP
--------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
*No values found*
--------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi
[OptionalComponents]
*No values found*
--------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi
*No subkeys found*
--------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi
*No subkeys found*
--------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi
*No subkeys found*
--------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi
*No subkeys found*
--------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Wi
*Registry key not found*
--------------------------
File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\
(Default) = "%1" %*
--------------------------
File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\
(Default) = "%1" %*
--------------------------
File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\
(Default) = "%1" %*
--------------------------
File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\
(Default) = "%1" %*
--------------------------
File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\
(Default) = "%1" /S
--------------------------
File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\
(Default) = C:\WINDOWS\system32\mshta.
--------------------------
File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\
(Default) = %SystemRoot%\system32\NOTE
--------------------------
Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Ac
(* = disabled by HKCU twin)
[<{12d0ed0d-0ee0-4f90-8827
StubPath = C:\WINDOWS\system32\ieudin
[>{22d6f312-b0f6-11d0-94ab
StubPath = C:\WINDOWS\inf\unregmp2.ex
[>{26923b43-4d38-484f-9b9e
StubPath = C:\WINDOWS\system32\ie4uin
[>{60B49E34-C7CC-11D0-8953
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
[>{60B49E34-C7CC-11D0-8953
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
[>{881dd1c5-3dcf-431b-b061
StubPath = %systemroot%\system32\shmg
[{2C7339CF-2B09-4501-B3F3-
StubPath = %SystemRoot%\system32\regs
[{44BBA840-CC51-11CF-AAFA-
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
[{44BBA842-CC51-11CF-AAFA-
StubPath = rundll32.exe advpack.dll,LaunchINFSecti
[{5945c046-1e7d-11d1-bc44-
StubPath = rundll32.exe advpack.dll,LaunchINFSecti
[{6BF52A52-394A-11d3-B153-
StubPath = rundll32.exe advpack.dll,LaunchINFSecti
[{7790769C-0471-11d2-AF11-
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
[{89820200-ECBD-11cf-8B85-
StubPath = regsvr32.exe /s /n /i:U shell32.dll
[{89820200-ECBD-11cf-8B85-
StubPath = C:\WINDOWS\system32\ie4uin
[{89B4C1CD-B018-4511-B0A1-
StubPath = C:\WINDOWS\system32\Rundll
--------------------------
Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\IC
*Registry key not found*
--------------------------
Load/Run keys from C:\WINDOWS\WIN.INI:
load=*INI section not found*
run=*INI section not found*
Load/Run keys from Registry:
HKLM\..\Windows NT\CurrentVersion\WinLogon
HKLM\..\Windows NT\CurrentVersion\WinLogon
HKLM\..\Windows\CurrentVer
HKLM\..\Windows\CurrentVer
HKCU\..\Windows NT\CurrentVersion\WinLogon
HKCU\..\Windows NT\CurrentVersion\WinLogon
HKCU\..\Windows\CurrentVer
HKCU\..\Windows\CurrentVer
HKCU\..\Windows NT\CurrentVersion\Windows:
HKCU\..\Windows NT\CurrentVersion\Windows:
HKLM\..\Windows NT\CurrentVersion\Windows:
HKLM\..\Windows NT\CurrentVersion\Windows:
HKLM\..\Windows NT\CurrentVersion\Windows:
--------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\sy
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------
Checking for EXPLORER.EXE instances:
C:\WINDOWS\Explorer.exe: PRESENT!
C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explor
C:\WINDOWS\System\Explorer
C:\WINDOWS\System32\Explor
C:\WINDOWS\Command\Explore
C:\WINDOWS\Fonts\Explorer.
--------------------------
Checking for superhidden extensions:
.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden
--------------------------
Verifying REGEDIT.EXE integrity:
- Regedit.exe found in C:\WINDOWS
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'
Registry check passed
--------------------------
Enumerating Browser Helper Objects:
(no name) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.d
(no name) - C:\Program Files\Yahoo!\Common\yiesrv
(no name) - C:\Program Files\Yahoo!\Common\YIeTag
(no name) - C:\Program Files\Java\jre1.5.0_06\bin
(no name) - C:\Program Files\Yahoo!\browser\YSide
--------------------------
Enumerating Task Scheduler jobs:
AppleSoftwareUpdate.job
--------------------------
Enumerating Download Program Files:
[Microsoft XML Parser for Java]
CODEBASE = file://C:\WINDOWS\Java\cla
OSD = C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:\WINDOWS\system32\LegitC
CODEBASE = http://download.microsoft.com/download/9/b/d/9bdc68ef-6a9f-4505-8fb8-d0d2d160e512/LegitCheckControl.cab
[ICSScannerLight Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\ICSScannerLight.dll
CODEBASE = http://download.zonelabs.com/bin/free/cm/ICSCM.cab
[EPUImageControl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\EPUWALcontrol.dll
CODEBASE = http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-48.cab
[Java Plug-in]
InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin
CODEBASE = http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
[Java Plug-in]
InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin
CODEBASE = http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
[Java Plug-in 1.5.0_06]
InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin
CODEBASE = http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
[Photodex Presenter AX control]
InProcServer32 = C:\PROGRA~1\PHOTOD~1\pxpla
CODEBASE = http://www.photodex.com/pxplay.cab
[get_atlcom Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\gp.ocx
CODEBASE = http://www.adobe.com/products/acrobat/nos/gp.cab
--------------------------
Enumerating Winsock LSP files:
NameSpace #1: C:\WINDOWS\System32\mswsoc
NameSpace #2: C:\WINDOWS\System32\winrnr
NameSpace #3: C:\WINDOWS\System32\mswsoc
Protocol #1: C:\WINDOWS\system32\mswsoc
Protocol #2: C:\WINDOWS\system32\mswsoc
Protocol #3: C:\WINDOWS\system32\mswsoc
Protocol #4: C:\WINDOWS\system32\rsvpsp
Protocol #5: C:\WINDOWS\system32\rsvpsp
Protocol #6: C:\WINDOWS\system32\mswsoc
Protocol #7: C:\WINDOWS\system32\mswsoc
Protocol #8: C:\WINDOWS\system32\mswsoc
Protocol #9: C:\WINDOWS\system32\mswsoc
Protocol #10: C:\WINDOWS\system32\mswsoc
Protocol #11: C:\WINDOWS\system32\mswsoc
Protocol #12: C:\WINDOWS\system32\mswsoc
Protocol #13: C:\WINDOWS\system32\mswsoc
--------------------------
Enumerating Windows NT/2000/XP services
Intel(r) 82801 Audio Driver Install Service (WDM): system32\drivers\ac97intc.
Microsoft ACPI Driver: system32\DRIVERS\ACPI.sys (system)
adpu160m: \SystemRoot\system32\DRIVE
adpu320: \SystemRoot\system32\DRIVE
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
PPdus ASPI Shell: system32\drivers\Afc.sys (manual start)
AFD: \SystemRoot\System32\drive
aic78u2: \SystemRoot\system32\DRIVE
aic78xx: \SystemRoot\system32\DRIVE
Alerter: %SystemRoot%\system32\svch
Application Layer Gateway Service: %SystemRoot%\System32\alg.
Apple Mobile Device: "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
Application Management: %SystemRoot%\system32\svch
ASP.NET State Service: %SystemRoot%\Microsoft.NET
RAS Asynchronous Media Driver: system32\DRIVERS\asyncmac.
Standard IDE/ESDI Hard Disk Controller: system32\DRIVERS\atapi.sys
ATM ARP Client Protocol: system32\DRIVERS\atmarpc.s
Windows Audio: %SystemRoot%\System32\svch
Audio Stub Driver: system32\DRIVERS\audstub.s
Automatic LiveUpdate Scheduler: "C:\Program Files\Symantec\LiveUpdate\
Broadcom NetXtreme Gigabit Ethernet: system32\DRIVERS\b57xp32.s
Background Intelligent Transfer Service: %SystemRoot%\system32\svch
Broadcom Advanced Server Program Driver: system32\DRIVERS\baspxp32.
Computer Browser: %SystemRoot%\system32\svch
CD-ROM Driver: system32\DRIVERS\cdrom.sys
Indexing Service: %SystemRoot%\system32\cisv
ClipBook: %SystemRoot%\system32\clip
.NET Runtime Optimization Service v2.0.50727_X86: C:\WINDOWS\Microsoft.NET\F
COM+ System Application: C:\WINDOWS\system32\dllhos
Cryptographic Services: %SystemRoot%\system32\svch
DCOM Server Process Launcher: %SystemRoot%\system32\svch
DHCP Client: %SystemRoot%\system32\svch
Disk Driver: system32\DRIVERS\disk.sys (system)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmad
dmboot: System32\drivers\dmboot.sy
Logical Disk Manager Driver: System32\drivers\dmio.sys (system)
dmload: System32\drivers\dmload.sy
Logical Disk Manager: %SystemRoot%\System32\svch
Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sy
DNS Client: %SystemRoot%\system32\svch
dpti2o: \SystemRoot\system32\DRIVE
Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.s
Intel(R) PRO Adapter Driver: system32\DRIVERS\e100b325.
Error Reporting Service: %SystemRoot%\System32\svch
Event Log: %SystemRoot%\system32\serv
COM+ Event System: C:\WINDOWS\system32\svchos
Fast User Switching Compatibility: %SystemRoot%\System32\svch
Floppy Disk Controller Driver: system32\DRIVERS\fdc.sys (manual start)
Floppy Disk Driver: system32\DRIVERS\flpydisk.
FltMgr: system32\DRIVERS\fltMgr.sy
Volume Manager Driver: system32\DRIVERS\ftdisk.sy
GearAspiWDM: system32\DRIVERS\GEARAspiW
Generic Packet Classifier: system32\DRIVERS\msgpc.sys
Microsoft UAA Function Driver for High Definition Audio Service: system32\drivers\HdAudio.s
Microsoft UAA Bus Driver for High Definition Audio: system32\DRIVERS\HDAudBus.
Help and Support: %SystemRoot%\System32\svch
HID Input Service: %SystemRoot%\System32\svch
Microsoft HID Class Driver: system32\DRIVERS\hidusb.sy
HTTP: System32\Drivers\HTTP.sys (manual start)
HTTP SSL: %SystemRoot%\System32\svch
i8042 Keyboard and PS/2 Mouse Port Driver: system32\DRIVERS\i8042prt.
i81x: system32\DRIVERS\i81xnt5.s
iAimFP0: system32\DRIVERS\wADV01nt.
iAimFP1: system32\DRIVERS\wADV02NT.
iAimFP2: system32\DRIVERS\wADV05NT.
iAimFP3: system32\DRIVERS\wSiINTxx.
iAimFP4: system32\DRIVERS\wVchNTxx.
iAimFP5: system32\DRIVERS\wADV07nt.
iAimFP6: system32\DRIVERS\wADV08nt.
iAimFP7: system32\DRIVERS\wADV09nt.
iAimTV0: system32\DRIVERS\wATV01nt.
iAimTV1: system32\DRIVERS\wATV02NT.
iAimTV3: system32\DRIVERS\wATV04nt.
iAimTV4: system32\DRIVERS\wCh7xxNT.
iAimTV5: system32\DRIVERS\wATV10nt.
iAimTV6: system32\DRIVERS\wATV06nt.
ialm: system32\DRIVERS\igxpmp32.
InstallDriver Table Manager: "C:\Program Files\Common Files\InstallShield\Driver
CD-Burning Filter Driver: system32\DRIVERS\imapi.sys
IMAPI CD-Burning COM Service: C:\WINDOWS\system32\imapi.
Service for Realtek HD Audio (WDM): system32\drivers\RtkHDAud.
IntelIde: \SystemRoot\system32\DRIVE
Intel Processor Driver: system32\DRIVERS\intelppm.
IPv6 Windows Firewall Driver: system32\DRIVERS\Ip6Fw.sys
IP Traffic Filter Driver: system32\DRIVERS\ipfltdrv.
IP in IP Tunnel Driver: system32\DRIVERS\ipinip.sy
IP Network Address Translator: system32\DRIVERS\ipnat.sys
iPod Service: "C:\Program Files\iPod\bin\iPodService
IPSEC driver: system32\DRIVERS\ipsec.sys
IR Enumerator Service: system32\DRIVERS\irenum.sy
PnP ISA/EISA Bus Driver: system32\DRIVERS\isapnp.sy
Keyboard Class Driver: system32\DRIVERS\kbdclass.
Keyboard HID Driver: system32\DRIVERS\kbdhid.sy
KLIF: \??\C:\WINDOWS\system32\Zo
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sy
Server: %SystemRoot%\system32\svch
Workstation: %SystemRoot%\system32\svch
LiveUpdate: "C:\PROGRA~1\Symantec\LIVE
TCP/IP NetBIOS Helper: %SystemRoot%\system32\svch
Machine Debug Manager: "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" (autostart)
Messenger: %SystemRoot%\system32\svch
NetMeeting Remote Desktop Sharing: C:\WINDOWS\system32\mnmsrv
Mouse Class Driver: system32\DRIVERS\mouclass.
Mouse HID Driver: system32\DRIVERS\mouhid.sy
MRENDIS5 NDIS Protocol Driver: \??\C:\PROGRA~1\COMMON~1\M
WebDav Client Redirector: system32\DRIVERS\mrxdav.sy
MRXSMB: system32\DRIVERS\mrxsmb.sy
Distributed Transaction Coordinator: C:\WINDOWS\system32\msdtc.
Windows Installer: C:\WINDOWS\system32\msiexe
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.s
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys
Microsoft System Management BIOS Driver: system32\DRIVERS\mssmbios.
Remote Access NDIS TAPI Driver: system32\DRIVERS\ndistapi.
NDIS Usermode I/O Protocol: system32\DRIVERS\ndisuio.s
Remote Access NDIS WAN Driver: system32\DRIVERS\ndiswan.s
NetBIOS Interface: system32\DRIVERS\netbios.s
NetBios over Tcpip: system32\DRIVERS\netbt.sys
Network DDE: %SystemRoot%\system32\netd
Network DDE DSDM: %SystemRoot%\system32\netd
Net Logon: %SystemRoot%\system32\lsas
Network Connections: %SystemRoot%\System32\svch
Network Location Awareness (NLA): %SystemRoot%\system32\svch
Nokia USB Phone Parent: system32\drivers\nmwcd.sys
Nokia USB Generic: system32\drivers\nmwcdc.sy
Nokia USB Port: system32\drivers\nmwcdcj.s
Nokia USB Modem: system32\drivers\nmwcdcm.s
Norton Save and Restore: C:\Program Files\Norton Save and Restore\Agent\VProSvc.exe (autostart)
NT LM Security Support Provider: %SystemRoot%\system32\lsas
Removable Storage: %SystemRoot%\system32\svch
IPX Traffic Filter Driver: system32\DRIVERS\nwlnkflt.
IPX Traffic Forwarder Driver: system32\DRIVERS\nwlnkfwd.
Office Source Engine: "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" (manual start)
Intel PentiumIII Processor Driver: system32\DRIVERS\p3.sys (system)
Parallel port driver: system32\DRIVERS\parport.s
PC Angel: C:\WINDOWS\SMINST\PCAngel.
PCI Bus Driver: system32\DRIVERS\pci.sys (system)
PCIIde: system32\DRIVERS\pciide.sy
Plug and Play: %SystemRoot%\system32\serv
Microsoft IntelliPoint Filter Driver: system32\DRIVERS\point32.s
IPSEC Services: %SystemRoot%\system32\lsas
WAN Miniport (PPTP): system32\DRIVERS\raspptp.s
Protected Storage: %SystemRoot%\system32\lsas
QoS Packet Scheduler: system32\DRIVERS\psched.sy
Direct Parallel Link Driver: system32\DRIVERS\ptilink.s
Remote Access Auto Connection Driver: system32\DRIVERS\rasacd.sy
Remote Access Auto Connection Manager: %SystemRoot%\system32\svch
WAN Miniport (L2TP): system32\DRIVERS\rasl2tp.s
Remote Access Connection Manager: %SystemRoot%\system32\svch
Remote Access PPPOE Driver: system32\DRIVERS\raspppoe.
Direct Parallel: system32\DRIVERS\raspti.sy
Rdbss: system32\DRIVERS\rdbss.sys
RDPCDD: System32\DRIVERS\RDPCDD.sy
Terminal Server Device Redirector Driver: system32\DRIVERS\rdpdr.sys
Remote Desktop Help Session Manager: C:\WINDOWS\system32\sessmg
Digital CD Audio Playback Filter Driver: system32\DRIVERS\redbook.s
Routing and Remote Access: %SystemRoot%\system32\svch
Remote Registry: %SystemRoot%\system32\svch
Remote Procedure Call (RPC) Locator: %SystemRoot%\system32\loca
Remote Procedure Call (RPC): %SystemRoot%\system32\svch
QoS RSVP: %SystemRoot%\system32\rsvp
Security Accounts Manager: %SystemRoot%\system32\lsas
SASDIFSV: \??\C:\Program Files\SUPERAntiSpyware\SAS
SASENUM: \??\C:\Program Files\SUPERAntiSpyware\SAS
SASKUTIL: \??\C:\Program Files\SUPERAntiSpyware\SAS
Smart Card: %SystemRoot%\System32\SCar
Task Scheduler: %SystemRoot%\System32\svch
ScsiAccess: C:\Program Files\Photodex\ProShowGold
Secdrv: system32\DRIVERS\secdrv.sy
Secondary Logon: %SystemRoot%\System32\svch
System Event Notification: %SystemRoot%\system32\svch
Serenum Filter Driver: system32\DRIVERS\serenum.s
Serial port driver: system32\DRIVERS\serial.sy
ServiceLayer: "C:\Program Files\PC Connectivity Solution\ServiceLayer.exe"
Windows Firewall/Internet Connection Sharing (ICS): %SystemRoot%\system32\svch
Shell Hardware Detection: %SystemRoot%\System32\svch
Microsoft Kernel Audio Splitter: system32\drivers\splitter.
Print Spooler: %SystemRoot%\system32\spoo
System Restore Filter Driver: system32\DRIVERS\sr.sys (system)
srescan: system32\ZoneLabs\srescan.
System Restore Service: %SystemRoot%\system32\svch
Srv: system32\DRIVERS\srv.sys (manual start)
SSDP Discovery Service: %SystemRoot%\system32\svch
Windows Image Acquisition (WIA): %SystemRoot%\system32\svch
Steganos VPN Starter Service: "C:\Program Files\Steganos Internet Anonym VPN\SVPNStarter.exe" (autostart)
Software Bus Driver: system32\DRIVERS\swenum.sy
Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sy
MS Software Shadow Copy Provider: C:\WINDOWS\system32\dllhos
symc810: \SystemRoot\system32\DRIVE
symc8xx: \SystemRoot\system32\DRIVE
Symmpi: \SystemRoot\system32\DRIVE
Symantec Volume Snap Shot Driver: system32\DRIVERS\symsnap.s
sym_hi: \SystemRoot\system32\DRIVE
sym_u3: \SystemRoot\system32\DRIVE
Microsoft Kernel System Audio Device: system32\drivers\sysaudio.
Performance Logs and Alerts: %SystemRoot%\system32\smlo
TAP-Win32 Adapter V8: system32\DRIVERS\tap0801.s
Telephony: %SystemRoot%\System32\svch
TCP/IP Protocol Driver: system32\DRIVERS\tcpip.sys
Terminal Device Driver: system32\DRIVERS\termdd.sy
Terminal Services: %SystemRoot%\System32\svch
Themes: %SystemRoot%\System32\svch
Telnet: C:\WINDOWS\system32\tlntsv
Distributed Link Tracking Client: %SystemRoot%\system32\svch
Universal Plug and Play Device Host: %SystemRoot%\system32\svch
Uninterruptible Power Supply: %SystemRoot%\System32\ups.
Microsoft USB Generic Parent Driver: system32\DRIVERS\usbccgp.s
Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: system32\DRIVERS\usbehci.s
Microsoft USB Standard Hub Driver: system32\DRIVERS\usbhub.sy
Microsoft USB PRINTER Class: system32\DRIVERS\usbprint.
USB Mass Storage Driver: system32\DRIVERS\USBSTOR.S
Microsoft USB Universal Host Controller Miniport Driver: system32\DRIVERS\usbuhci.s
Symantec V2i Mount Driver: system32\DRIVERS\v2imount.
VgaSave: \SystemRoot\System32\drive
ViaIde: \SystemRoot\system32\DRIVE
Virtual Machine Network Services Driver: system32\DRIVERS\VMNetSrv.
Symantec Event Monitor Driver: system32\DRIVERS\vproevent
vsdatant: System32\vsdatant.sys (system)
TrueVector Internet Monitor: C:\WINDOWS\system32\ZoneLa
Volume Shadow Copy: %SystemRoot%\System32\vssv
Windows Time: %SystemRoot%\System32\svch
Remote Access IP ARP Driver: system32\DRIVERS\wanarp.sy
Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sy
WebClient: %SystemRoot%\system32\svch
WimFltr: system32\DRIVERS\wimfltr.s
Windows Management Instrumentation: %systemroot%\system32\svch
Portable Media Serial Number Service: %SystemRoot%\System32\svch
Windows Management Instrumentation Driver Extensions: %SystemRoot%\System32\svch
Microsoft Windows Management Interface for ACPI: system32\DRIVERS\wmiacpi.s
WMI Performance Adapter: C:\WINDOWS\system32\wbem\w
Security Center: %SystemRoot%\System32\svch
Automatic Updates: %systemroot%\system32\svch
Wireless Zero Configuration: %SystemRoot%\System32\svch
Network Provisioning Service: %SystemRoot%\System32\svch
--------------------------
Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*
Windows NT checkdisk command:
BootExecute = autocheck autochk *
Windows NT 'Wininit.ini':
PendingFileRenameOperation
--------------------------
Enumerating ShellServiceObjectDelayLoa
PostBootReminder: C:\WINDOWS\system32\SHELL3
CDBurn: C:\WINDOWS\system32\SHELL3
WebCheck: C:\WINDOWS\system32\webche
SysTray: C:\WINDOWS\system32\stobje
--------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Wi
*Registry key not found*
--------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Wi
*Registry key not found*
--------------------------
End of report, 38,718 bytes
Report generated in 0.094 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only