![]() ![]() |
Nov 28 2006, 11:08 PM
Post
#1
|
|
|
Owner/Site Administrator Group: Administrator Posts: 3,093 Joined: 17-August 04 From: Newark, Nottingham, UK Member No.: 1 |
Logfile of HijackThis v1.99.1
Scan saved at 23:06:39, on 28/11/2006 Platform: Unknown Windows (WinNT 6.00.1648) MSIE: Internet Explorer v7.00 (7.00.5744.16384) Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\VMware\VMware Tools\VMwareUser.exe C:\Windows\system32\wuauclt.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Users\therock247uk\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [VMware Tools] C:\Program Files\VMware\VMware Tools\VMwareTray.exe O4 - HKLM\..\Run: [VMware User Process] C:\Program Files\VMware\VMware Tools\VMwareUser.exe O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll O11 - Options group: [INTERNATIONAL] International* O13 - Gopher Prefix: O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: VMware Tools Service (VMTools) - Unknown owner - C:\Program Files\VMware\VMware Tools\VMwareService.exe O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing) |
|
|
|
Nov 28 2006, 11:08 PM
Post
#2
|
|
|
Owner/Site Administrator Group: Administrator Posts: 3,093 Joined: 17-August 04 From: Newark, Nottingham, UK Member No.: 1 |
StartupList report, 28/11/2006, 23:08:44
StartupList version: 1.52.2 Started from : C:\Users\therock247uk\Desktop\HijackThis.EXE Detected: Unknown Windows (WinNT 6.00.1648) Detected: Internet Explorer v7.00 (7.00.5744.16384) * Using default options * Including empty and uninteresting sections * Showing rarely important sections ================================================== Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\VMware\VMware Tools\VMwareUser.exe C:\Windows\system32\wuauclt.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Users\therock247uk\Desktop\HijackThis.exe C:\Program Files\Internet Explorer\iexplore.exe -------------------------------------------------- Listing of startup folders: Shell folders Startup: [C:\Users\therock247uk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup] *No files* Shell folders AltStartup: *Folder not found* User shell folders Startup: *Folder not found* User shell folders AltStartup: *Folder not found* Shell folders Common Startup: [C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup] *No files* Shell folders Common AltStartup: *Folder not found* User shell folders Common Startup: *Folder not found* User shell folders Alternate Common Startup: *Folder not found* -------------------------------------------------- Checking Windows NT UserInit: [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] UserInit = C:\Windows\system32\userinit.exe, [HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon] *Registry key not found* [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] *Registry value not found* [HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon] *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run VMware Tools = C:\Program Files\VMware\VMware Tools\VMwareTray.exe VMware User Process = C:\Program Files\VMware\VMware Tools\VMwareUser.exe -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce *No values found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run WindowsWelcomeCenter = rundll32.exe oobefldr.dll,ShowWelcomeCenter -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\Run *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\Run *No subkeys found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run *Registry key not found* -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run *Registry key not found* -------------------------------------------------- File association entry for .EXE: HKEY_CLASSES_ROOT\exefile\shell\open\command (Default) = "%1" %* -------------------------------------------------- File association entry for .COM: HKEY_CLASSES_ROOT\comfile\shell\open\command (Default) = "%1" %* -------------------------------------------------- File association entry for .BAT: HKEY_CLASSES_ROOT\batfile\shell\open\command (Default) = "%1" %* -------------------------------------------------- File association entry for .PIF: HKEY_CLASSES_ROOT\piffile\shell\open\command (Default) = "%1" %* -------------------------------------------------- File association entry for .SCR: HKEY_CLASSES_ROOT\scrfile\shell\open\command (Default) = "%1" /S -------------------------------------------------- File association entry for .HTA: HKEY_CLASSES_ROOT\htafile\shell\open\command (Default) = C:\Windows\system32\mshta.exe "%1" %* -------------------------------------------------- File association entry for .TXT: HKEY_CLASSES_ROOT\txtfile\shell\open\command (Default) = %SystemRoot%\system32\NOTEPAD.EXE %1 -------------------------------------------------- Enumerating Active Setup stub paths: HKLM\Software\Microsoft\Active Setup\Installed Components (* = disabled by HKCU twin) [>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] StubPath = C:\Windows\system32\unregmp2.exe /ShowWMP [>{26923b43-4d38-484f-9b9e-de460746276c}] * StubPath = C:\Windows\system32\ie4uinit.exe -UserIconConfig [>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] * StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP [{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] * StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll [{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] * StubPath = "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE [{6BF52A52-394A-11d3-B153-00C04F79FAA6}] * StubPath = %SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI [{89820200-ECBD-11cf-8B85-00AA005B4340}] * StubPath = regsvr32.exe /s /n /i:U shell32.dll [{89820200-ECBD-11cf-8B85-00AA005B4383}] * StubPath = C:\Windows\system32\ie4uinit.exe -BaseSettings [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] * StubPath = C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install -------------------------------------------------- Enumerating ICQ Agent Autostart apps: HKCU\Software\Mirabilis\ICQ\Agent\Apps *Registry key not found* -------------------------------------------------- Load/Run keys from C:\Windows\WIN.INI: load=*INI section not found* run=*INI section not found* Load/Run keys from Registry: HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found* HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found* HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found* HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found* HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found* HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found* HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found* HKCU\..\Windows NT\CurrentVersion\Windows: load= HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found* HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs= -------------------------------------------------- Shell & screensaver key from C:\Windows\SYSTEM.INI: Shell=*INI section not found* SCRNSAVE.EXE=*INI section not found* drivers=*INI section not found* Shell & screensaver key from Registry: Shell=explorer.exe SCRNSAVE.EXE=C:\Windows\system32\logon.scr drivers=*Registry value not found* Policies Shell key: HKCU\..\Policies: Shell=*Registry key not found* HKLM\..\Policies: Shell=*Registry value not found* -------------------------------------------------- Checking for EXPLORER.EXE instances: C:\Windows\Explorer.exe: PRESENT! C:\Explorer.exe: not present C:\Windows\Explorer\Explorer.exe: not present C:\Windows\System\Explorer.exe: not present C:\Windows\System32\Explorer.exe: not present C:\Windows\Command\Explorer.exe: not present C:\Windows\Fonts\Explorer.exe: not present -------------------------------------------------- Checking for superhidden extensions: .lnk: HIDDEN! (arrow overlay: yes) .pif: HIDDEN! (arrow overlay: yes) .exe: not hidden .com: not hidden .bat: not hidden .hta: not hidden .scr: not hidden .shs: *Registry key not found* .shb: *Registry key not found* .vbs: not hidden .vbe: not hidden .wsh: not hidden .scf: HIDDEN! (arrow overlay: NO!) .url: HIDDEN! (arrow overlay: yes) .js: not hidden .jse: not hidden -------------------------------------------------- Verifying REGEDIT.EXE integrity: - Regedit.exe found in C:\Windows - .reg open command is normal (regedit.exe %1) - Company name OK: 'Microsoft Corporation' - Original filename NOT OK: 'REGEDIT.EXE.MUI' - File description: 'Registry Editor' Registry check failed! -------------------------------------------------- Enumerating Browser Helper Objects: *No BHO's found* -------------------------------------------------- Enumerating Task Scheduler jobs: *No jobs found* -------------------------------------------------- Enumerating Winsock LSP files: NameSpace #1: C:\Windows\system32\NLAapi.dll NameSpace #2: C:\Windows\System32\mswsock.dll NameSpace #3: C:\Windows\System32\winrnr.dll NameSpace #4: C:\Windows\system32\napinsp.dll NameSpace #5: C:\Windows\system32\pnrpnsp.dll NameSpace #6: C:\Windows\system32\pnrpnsp.dll Protocol #1: C:\Windows\system32\mswsock.dll Protocol #2: C:\Windows\system32\mswsock.dll Protocol #3: C:\Windows\system32\mswsock.dll Protocol #4: C:\Windows\system32\mswsock.dll Protocol #5: C:\Windows\system32\mswsock.dll Protocol #6: C:\Windows\system32\mswsock.dll Protocol #7: C:\Windows\system32\mswsock.dll Protocol #8: C:\Windows\system32\mswsock.dll Protocol #9: C:\Windows\system32\mswsock.dll Protocol #10: C:\Windows\system32\mswsock.dll Protocol #11: C:\Windows\system32\mswsock.dll Protocol #12: C:\Windows\system32\mswsock.dll Protocol #13: C:\Windows\system32\mswsock.dll Protocol #14: C:\Windows\system32\mswsock.dll -------------------------------------------------- Enumerating Windows NT/2000/XP services Microsoft ACPI Driver: system32\drivers\acpi.sys (system) adp94xx: \SystemRoot\system32\drivers\adp94xx.sys (disabled) adpahci: \SystemRoot\system32\drivers\adpahci.sys (disabled) adpu160m: \SystemRoot\system32\drivers\adpu160m.sys (disabled) adpu320: \SystemRoot\system32\drivers\adpu320.sys (disabled) @%SystemRoot%\system32\aelupsvc.dll,-1: %systemroot%\system32\svchost.exe -k netsvcs (autostart) Ancilliary Function Driver for Winsock: \SystemRoot\system32\drivers\afd.sys (system) Intel AGP Bus Filter: system32\DRIVERS\agp440.sys (system) aic78xx: \SystemRoot\system32\drivers\djsvs.sys (disabled) @%SystemRoot%\system32\Alg.exe,-112: %SystemRoot%\System32\alg.exe (manual start) aliide: \SystemRoot\system32\drivers\aliide.sys (disabled) AMD AGP Bus Filter Driver: \SystemRoot\system32\drivers\amdagp.sys (manual start) amdide: \SystemRoot\system32\drivers\amdide.sys (disabled) AMD K7 Processor Driver: \SystemRoot\system32\drivers\amdk7.sys (disabled) AMD K8 Processor Driver: \SystemRoot\system32\drivers\amdk8.sys (disabled) @%systemroot%\system32\appinfo.dll,-100: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start) @appmgmts.dll,-3250: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start) arc: \SystemRoot\system32\drivers\arc.sys (disabled) arcsas: \SystemRoot\system32\drivers\arcsas.sys (disabled) RAS Asynchronous Media Driver: system32\DRIVERS\asyncmac.sys (manual start) IDE Channel: system32\drivers\atapi.sys (system) @%SystemRoot%\system32\audiosrv.dll,-204: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted (autostart) @%SystemRoot%\system32\audiosrv.dll,-200: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted (autostart) @%SystemRoot%\system32\bfe.dll,-1001: %systemroot%\system32\svchost.exe -k LocalServiceNoNetwork (autostart) @%SystemRoot%\system32\qmgr.dll,-1000: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) blbdrive: \SystemRoot\system32\drivers\blbdrive.sys (disabled) Bowser: system32\DRIVERS\bowser.sys (manual start) Brother USB Mass-Storage Lower Filter Driver: \SystemRoot\system32\drivers\brfiltlo.sys (manual start) Brother USB Mass-Storage Upper Filter Driver: \SystemRoot\system32\drivers\brfiltup.sys (manual start) @%systemroot%\system32\browser.dll,-100: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Brother MFC Serial Port Interface Driver (WDM): \SystemRoot\system32\drivers\brserid.sys (disabled) Brother WDM Serial driver: \SystemRoot\system32\drivers\brserwdm.sys (disabled) Brother MFC USB Fax Only Modem: \SystemRoot\system32\drivers\brusbmdm.sys (disabled) Brother MFC USB Serial WDM Driver: \SystemRoot\system32\drivers\brusbser.sys (manual start) Bluetooth Serial Communications Driver: \SystemRoot\system32\drivers\bthmodem.sys (disabled) CD/DVD File System Reader: system32\DRIVERS\cdfs.sys (disabled) CD-ROM Driver: system32\DRIVERS\cdrom.sys (system) @%SystemRoot%\System32\certprop.dll,-11: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start) Consumer IR Devices: \SystemRoot\system32\drivers\circlass.sys (disabled) Common Log (CLFS): System32\CLFS.sys (system) Microsoft .NET Framework NGEN v2.0.50727_X86: %systemroot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (manual start) Microsoft AC Adapter Driver: system32\DRIVERS\CmBatt.sys (manual start) cmdide: \SystemRoot\system32\drivers\cmdide.sys (disabled) Microsoft Composite Battery Driver: system32\DRIVERS\compbatt.sys (system) @comres.dll,-947: %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start) Crcdisk Filter Driver: system32\drivers\crcdisk.sys (system) Transmeta Crusoe Processor Driver: \SystemRoot\system32\drivers\crusoe.sys (disabled) @%SystemRoot%\system32\cryptsvc.dll,-1001: %SystemRoot%\system32\svchost.exe -k NetworkService (autostart) Offline Files Driver: system32\drivers\csc.sys (system) @%systemroot%\system32\cscsvc.dll,-200: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted (autostart) @oleres.dll,-5012: %SystemRoot%\system32\svchost.exe -k DcomLaunch (autostart) Dfs Client Driver: System32\Drivers\dfsc.sys (system) @dfsrres.dll,-101: %SystemRoot%\system32\DFSR.exe (manual start) @%SystemRoot%\system32\dhcpcsvc.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted (autostart) Disk Driver: system32\drivers\disk.sys (system) @%SystemRoot%\System32\dnsapi.dll,-101: %SystemRoot%\system32\svchost.exe -k NetworkService (autostart) @%systemroot%\system32\dot3svc.dll,-1102: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted (manual start) @%systemroot%\system32\dps.dll,-500: %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork (autostart) LDDM Graphics Subsystem: \SystemRoot\System32\drivers\dxgkrnl.sys (manual start) Intel® PRO/1000 NDIS 6 Adapter Driver: system32\DRIVERS\E1G60I32.sys (manual start) @%systemroot%\system32\eapsvc.dll,-1: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) ReadyBoost Caching Driver: System32\drivers\ecache.sys (system) @%SystemRoot%\ehome\ehrecvr.exe,-101: %systemroot%\ehome\ehRecvr.exe (manual start) @%SystemRoot%\ehome\ehsched.exe,-101: %systemroot%\ehome\ehsched.exe (manual start) @%SystemRoot%\ehome\ehstart.dll,-101: %windir%\system32\svchost.exe -k LocalServiceNoNetwork (autostart) elxstor: \SystemRoot\system32\drivers\elxstor.sys (disabled) @%SystemRoot%\system32\emdmgmt.dll,-1000: %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted (autostart) @%SystemRoot%\system32\wevtsvc.dll,-200: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted (autostart) @comres.dll,-2450: %SystemRoot%\system32\svchost.exe -k LocalService (autostart) @%systemroot%\system32\fxsresm.dll,-118: %systemroot%\system32\fxssvc.exe (manual start) Floppy Disk Controller Driver: system32\DRIVERS\fdc.sys (manual start) @%systemroot%\system32\fdPHost.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalService (manual start) @%systemroot%\system32\fdrespub.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalService (manual start) File Information FS MiniFilter: system32\drivers\fileinfo.sys (system) FileTrace: system32\drivers\filetrace.sys (manual start) Floppy Disk Driver: system32\DRIVERS\flpydisk.sys (manual start) FltMgr: system32\drivers\fltmgr.sys (system) @%SystemRoot%\system32\PresentationHost.exe,-3309: %systemroot%\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (manual start) BitLocker Drive Encryption Filter Driver: System32\DRIVERS\fvevol.sys (system) Microsoft Generic AGPv3.0 Filter for K8 Processor Platforms: \SystemRoot\system32\drivers\gagp30kx.sys (manual start) @gpapi.dll,-112: %systemroot%\system32\svchost.exe -k netsvcs (autostart) Microsoft UAA Bus Driver for High Definition Audio: \SystemRoot\system32\drivers\hdaudbus.sys (disabled) hgfs: System32\DRIVERS\hgfs.sys (autostart) Microsoft Bluetooth HID Miniport: \SystemRoot\system32\drivers\hidbth.sys (disabled) Microsoft Infrared HID Driver: \SystemRoot\system32\drivers\hidir.sys (disabled) @%SystemRoot%\System32\hidserv.dll,-101: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted (manual start) Microsoft HID Class Driver: \SystemRoot\system32\drivers\hidusb.sys (disabled) @%SystemRoot%\system32\kmsvc.dll,-6: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) HpCISSs: \SystemRoot\system32\drivers\hpcisss.sys (disabled) HTTP: system32\drivers\HTTP.sys (manual start) i2omp: \SystemRoot\system32\drivers\i2omp.sys (disabled) i8042 Keyboard and PS/2 Mouse Port Driver: system32\DRIVERS\i8042prt.sys (system) Intel RAID Controller Vista: \SystemRoot\system32\drivers\iastorv.sys (disabled) @%systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8193: "%systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe" (manual start) iirsp: \SystemRoot\system32\drivers\iirsp.sys (disabled) @%SystemRoot%\system32\ikeext.dll,-501: %systemroot%\system32\svchost.exe -k netsvcs (autostart) intelide: system32\drivers\intelide.sys (system) Intel Processor Driver: system32\DRIVERS\intelppm.sys (manual start) @%systemroot%\system32\IPBusEnum.dll,-102: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted (manual start) IP Traffic Filter Driver: system32\DRIVERS\ipfltdrv.sys (manual start) @%SystemRoot%\system32\iphlpsvc.dll,-200: %SystemRoot%\System32\svchost.exe -k NetSvcs (autostart) IP in IP Tunnel Driver: system32\DRIVERS\ipinip.sys (manual start) IPMIDRV: \SystemRoot\system32\drivers\ipmidrv.sys (disabled) IP Network Address Translator: system32\DRIVERS\ipnat.sys (manual start) IR Bus Enumerator: system32\drivers\irenum.sys (manual start) PnP ISA/EISA Bus Driver: \SystemRoot\system32\drivers\isapnp.sys (disabled) iScsiPort Driver: system32\DRIVERS\msiscsi.sys (manual start) ITEATAPI_Service_Install: \SystemRoot\system32\drivers\iteatapi.sys (disabled) ITERAID_Service_Install: \SystemRoot\system32\drivers\iteraid.sys (disabled) Keyboard Class Driver: system32\DRIVERS\kbdclass.sys (system) Keyboard HID Driver: \SystemRoot\system32\drivers\kbdhid.sys (disabled) @keyiso.dll,-100: %SystemRoot%\system32\lsass.exe (manual start) KSecDD: System32\Drivers\ksecdd.sys (system) @comres.dll,-2946: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart) @%systemroot%\system32\srvsvc.dll,-100: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) @%systemroot%\system32\wkssvc.dll,-100: %SystemRoot%\System32\svchost.exe -k LocalService (autostart) Link-Layer Topology Discovery Mapper I/O Driver: system32\DRIVERS\lltdio.sys (autostart) @%SystemRoot%\system32\lltdres.dll,-1: %SystemRoot%\System32\svchost.exe -k LocalService (manual start) @%SystemRoot%\system32\lmhsvc.dll,-101: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted (autostart) LSI_FC: \SystemRoot\system32\drivers\lsi_fc.sys (disabled) LSI_SAS: \SystemRoot\system32\drivers\lsi_sas.sys (disabled) LSI_SCSI: system32\drivers\lsi_scsi.sys (system) UAC File Virtualization: \SystemRoot\system32\drivers\luafv.sys (autostart) @%SystemRoot%\ehome\ehres.dll,-15501: %SystemRoot%\system32\svchost.exe -k LocalService (disabled) megasas: \SystemRoot\system32\drivers\megasas.sys (disabled) @%systemroot%\system32\mmcss.dll,-100: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Modem: system32\drivers\modem.sys (manual start) Microsoft Monitor Class Function Driver Service: system32\DRIVERS\monitor.sys (manual start) Mouse Class Driver: system32\DRIVERS\mouclass.sys (system) Mouse HID Driver: \SystemRoot\system32\drivers\mouhid.sys (disabled) Mount Point Manager: System32\drivers\mountmgr.sys (system) Microsoft Multi-Path Bus Driver: \SystemRoot\system32\drivers\mpio.sys (disabled) @%SystemRoot%\system32\FirewallAPI.dll,-23092: System32\drivers\mpsdrv.sys (manual start) @%SystemRoot%\system32\FirewallAPI.dll,-23090: %SystemRoot%\system32\svchost.exe -k LocalServiceNoNetwork (autostart) Mraid35x: \SystemRoot\system32\drivers\mraid35x.sys (disabled) WebDav Client Redirector Driver: \SystemRoot\system32\drivers\mrxdav.sys (manual start) SMB MiniRedirector Wrapper and Engine: system32\DRIVERS\mrxsmb.sys (manual start) SMB 1.x MiniRedirector: system32\DRIVERS\mrxsmb10.sys (manual start) SMB 2.0 MiniRedirector: system32\DRIVERS\mrxsmb20.sys (manual start) msahci: \SystemRoot\system32\drivers\msahci.sys (disabled) Microsoft Multi-Path Device Specific Module: \SystemRoot\system32\drivers\msdsm.sys (disabled) @comres.dll,-2797: %SystemRoot%\System32\msdtc.exe (manual start) ISA/EISA Class Driver: system32\drivers\msisadrv.sys (system) @%SystemRoot%\system32\iscsidsc.dll,-5000: %systemroot%\system32\svchost.exe -k netsvcs (manual start) @%SystemRoot%\system32\msimsg.dll,-27: %systemroot%\system32\msiexec /V (manual start) Microsoft System Management BIOS Driver: system32\DRIVERS\mssmbios.sys (manual start) Mup: System32\Drivers\mup.sys (system) @%SystemRoot%\system32\qagentrt.dll,-6: %SystemRoot%\System32\svchost.exe -k NetworkService (manual start) NativeWiFi Filter: system32\DRIVERS\nwifi.sys (manual start) NDIS System Driver: system32\drivers\ndis.sys (system) Remote Access NDIS TAPI Driver: system32\DRIVERS\ndistapi.sys (manual start) NDIS Usermode I/O Protocol: system32\DRIVERS\ndisuio.sys (manual start) Remote Access NDIS WAN Driver: system32\DRIVERS\ndiswan.sys (manual start) NetBIOS Interface: system32\DRIVERS\netbios.sys (system) NETBT: System32\DRIVERS\netbt.sys (system) @%SystemRoot%\System32\netlogon.dll,-102: %systemroot%\system32\lsass.exe (manual start) @%SystemRoot%\system32\netman.dll,-109: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted (manual start) @%SystemRoot%\system32\netprof.dll,-246: %SystemRoot%\System32\svchost.exe -k LocalService (autostart) @%systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll,-8201: "%systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe" (disabled) nfrd960: \SystemRoot\system32\drivers\nfrd960.sys (disabled) @%SystemRoot%\System32\nlasvc.dll,-1: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart) @%SystemRoot%\system32\nsisvc.dll,-200: %systemroot%\system32\svchost.exe -k LocalService (autostart) NSI proxy service: system32\drivers\nsiproxy.sys (system) N-trig HID Tablet Driver: \SystemRoot\system32\drivers\ntrigdigi.sys (disabled) nvraid: \SystemRoot\system32\drivers\nvraid.sys (disabled) nvstor: \SystemRoot\system32\drivers\nvstor.sys (disabled) NVIDIA nForce AGP Bus Filter: \SystemRoot\system32\drivers\nv_agp.sys (manual start) IPX Traffic Filter Driver: system32\DRIVERS\nwlnkflt.sys (manual start) IPX Traffic Forwarder Driver: system32\DRIVERS\nwlnkfwd.sys (manual start) NEC FireWarden OHCI Compliant IEEE 1394 Host Controller: \SystemRoot\system32\drivers\ohci1394.sys (disabled) @%SystemRoot%\system32\p2psvc.dll,-8004: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted (manual start) @%SystemRoot%\system32\p2psvc.dll,-8006: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted (manual start) Parallel port driver: system32\DRIVERS\parport.sys (manual start) Partition Manager: System32\drivers\partmgr.sys (system) Parvdm: system32\DRIVERS\parvdm.sys (autostart) @%SystemRoot%\system32\pcasvc.dll,-1: %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted (autostart) PCI Bus Driver: system32\drivers\pci.sys (system) pciide: \SystemRoot\system32\drivers\pciide.sys (disabled) pcmcia: \SystemRoot\system32\drivers\pcmcia.sys (disabled) PEAUTH: system32\drivers\peauth.sys (autostart) @%systemroot%\system32\pla.dll,-500: %SystemRoot%\System32\svchost.exe -k LocalServiceNoNetwork (manual start) @%SystemRoot%\system32\umpnpmgr.dll,-100: %SystemRoot%\system32\svchost.exe -k DcomLaunch (autostart) @%SystemRoot%\system32\p2psvc.dll,-8002: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted (manual start) @%SystemRoot%\system32\p2psvc.dll,-8000: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted (manual start) @%SystemRoot%\System32\polstore.dll,-5010: %SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestricted (autostart) WAN Miniport (PPTP): system32\DRIVERS\raspptp.sys (manual start) Processor Driver: \SystemRoot\system32\drivers\processr.sys (disabled) @%systemroot%\system32\profsvc.dll,-300: %systemroot%\system32\svchost.exe -k netsvcs (autostart) @%systemroot%\system32\psbase.dll,-300: %SystemRoot%\system32\lsass.exe (manual start) @%SystemRoot%\System32\drivers\pacer.sys,-101: system32\DRIVERS\pacer.sys (system) QLogic Fibre Channel Miniport Driver: \SystemRoot\system32\drivers\ql2300.sys (disabled) QLogic iSCSI Miniport Driver: \SystemRoot\system32\drivers\ql40xx.sys (disabled) @%SystemRoot%\system32\qwave.dll,-1: %windir%\system32\svchost.exe -k LocalService (manual start) @%SystemRoot%\system32\drivers\qwavedrv.sys,-1: \SystemRoot\system32\drivers\qwavedrv.sys (manual start) Remote Access Auto Connection Driver: System32\DRIVERS\rasacd.sys (system) @%Systemroot%\system32\rasauto.dll,-200: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start) WAN Miniport (L2TP): system32\DRIVERS\rasl2tp.sys (manual start) @%Systemroot%\system32\rasmans.dll,-200: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start) Remote Access PPPOE Driver: system32\DRIVERS\raspppoe.sys (manual start) Redirected Buffering Sub Sysytem: system32\DRIVERS\rdbss.sys (system) RDPCDD: System32\DRIVERS\RDPCDD.sys (system) Terminal Server Device Redirector Driver: system32\DRIVERS\rdpdr.sys (manual start) RDP Encoder Mirror Driver: system32\drivers\rdpencdd.sys (system) @%Systemroot%\system32\mprdim.dll,-200: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled) @regsvc.dll,-1: %SystemRoot%\system32\svchost.exe -k regsvc (manual start) @%systemroot%\system32\Locator.exe,-2: %SystemRoot%\system32\locator.exe (manual start) @oleres.dll,-5010: %SystemRoot%\system32\svchost.exe -k rpcss (autostart) Link-Layer Topology Discovery Responder: system32\DRIVERS\rspndr.sys (autostart) @%SystemRoot%\system32\samsrv.dll,-1: %SystemRoot%\system32\lsass.exe (autostart) SBP-2 Transport/Protocol Bus Driver: \SystemRoot\system32\drivers\sbp2port.sys (disabled) @%SystemRoot%\System32\SCardSvr.dll,-1: %SystemRoot%\system32\svchost.exe -k LocalService (manual start) @%SystemRoot%\system32\schedsvc.dll,-100: %systemroot%\system32\svchost.exe -k netsvcs (autostart) @%SystemRoot%\System32\certprop.dll,-13: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start) @%SystemRoot%\system32\sdrsvc.dll,-107: %SystemRoot%\system32\svchost.exe -k SDRSVC (manual start) @%SystemRoot%\system32\seclogon.dll,-7001: %windir%\system32\svchost.exe -k netsvcs (autostart) @%SystemRoot%\system32\Sens.dll,-200: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Serenum Filter Driver: system32\DRIVERS\serenum.sys (manual start) Serial port driver: system32\DRIVERS\serial.sys (system) Serial Mouse Driver: \SystemRoot\system32\drivers\sermouse.sys (disabled) @%SystemRoot%\System32\SessEnv.dll,-1026: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) SFF Storage Class Driver: \SystemRoot\system32\drivers\sffdisk.sys (disabled) SFF Storage Protocol Driver for MMC: \SystemRoot\system32\drivers\sffp_mmc.sys (manual start) SFF Storage Protocol Driver for SDBus: \SystemRoot\system32\drivers\sffp_sd.sys (manual start) High-Capacity Floppy Disk Drive: \SystemRoot\system32\drivers\sfloppy.sys (disabled) @%SystemRoot%\system32\ipnathlp.dll,-106: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled) @%SystemRoot%\System32\shsvcs.dll,-12288: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) SIS AGP Bus Filter: \SystemRoot\system32\drivers\sisagp.sys (manual start) SiSRaid2: \SystemRoot\system32\drivers\sisraid2.sys (disabled) SiSRaid4: \SystemRoot\system32\drivers\sisraid4.sys (disabled) @%SystemRoot%\system32\SLsvc.exe,-101: %SystemRoot%\system32\SLsvc.exe (autostart) @%SystemRoot%\system32\SLUINotify.dll,-103: %SystemRoot%\system32\svchost.exe -k LocalService (manual start) @%SystemRoot%\system32\tcpipcfg.dll,-50005: system32\DRIVERS\smb.sys (system) @%SystemRoot%\system32\snmptrap.exe,-3: %SystemRoot%\System32\snmptrap.exe (manual start) @%systemroot%\system32\spoolsv.exe,-1: %SystemRoot%\System32\spoolsv.exe (autostart) srv: System32\DRIVERS\srv.sys (manual start) srv2: System32\DRIVERS\srv2.sys (manual start) srvnet: System32\DRIVERS\srvnet.sys (manual start) @%systemroot%\system32\ssdpsrv.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalService (manual start) @%SystemRoot%\system32\wiaservc.dll,-9: %SystemRoot%\system32\svchost.exe -k imgsvc (manual start) Software Bus Driver: system32\DRIVERS\swenum.sys (manual start) @%SystemRoot%\System32\swprv.dll,-103: %SystemRoot%\System32\svchost.exe -k swprv (manual start) Symc8xx: \SystemRoot\system32\drivers\symc8xx.sys (disabled) Sym_hi: \SystemRoot\system32\drivers\sym_hi.sys (disabled) Sym_u3: \SystemRoot\system32\drivers\sym_u3.sys (disabled) @%SystemRoot%\system32\sysmain.dll,-1000: %systemroot%\system32\svchost.exe -k LocalSystemNetworkRestricted (autostart) @%SystemRoot%\system32\TabSvc.dll,-100: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted (autostart) @%SystemRoot%\system32\tapisrv.dll,-10100: %SystemRoot%\System32\svchost.exe -k NetworkService (manual start) @%SystemRoot%\system32\tbssvc.dll,-100: %SystemRoot%\System32\svchost.exe -k LocalService (manual start) @%SystemRoot%\system32\tcpipcfg.dll,-50003: System32\drivers\tcpip.sys (system) Microsoft IPv6 Protocol Driver: system32\DRIVERS\tcpip.sys (manual start) TCP/IP Registry Compatibility: System32\drivers\tcpipreg.sys (autostart) TDPIPE: system32\drivers\tdpipe.sys (manual start) TDTCP: system32\drivers\tdtcp.sys (manual start) @%SystemRoot%\system32\tcpipcfg.dll,-50004: system32\DRIVERS\tdx.sys (system) Terminal Device Driver: system32\DRIVERS\termdd.sys (system) @%SystemRoot%\System32\termsrv.dll,-268: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart) @%SystemRoot%\System32\shsvcs.dll,-8192: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) @%systemroot%\system32\mmcss.dll,-102: %SystemRoot%\system32\svchost.exe -k LocalService (manual start) @%SystemRoot%\system32\trkwks.dll,-1: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted (autostart) @%SystemRoot%\servicing\TrustedInstaller.exe,-100: %SystemRoot%\servicing\TrustedInstaller.exe (manual start) Terminal Services Security Filter Driver: System32\DRIVERS\tssecsrv.sys (manual start) Microsoft Tun Miniport Adapter Driver: system32\DRIVERS\tunmp.sys (manual start) Microsoft IPv6 Tunnel Miniport Adapter Driver: system32\DRIVERS\tunnel.sys (manual start) Microsoft AGPv3.5 Filter: \SystemRoot\system32\drivers\uagp35.sys (manual start) udfs: system32\DRIVERS\udfs.sys (disabled) @%SystemRoot%\system32\ui0detect.exe,-101: %SystemRoot%\system32\UI0Detect.exe (manual start) Uli AGP Bus Filter: \SystemRoot\system32\drivers\uliagpkx.sys (manual start) uliahci: \SystemRoot\system32\drivers\uliahci.sys (disabled) UlSata: \SystemRoot\system32\drivers\ulsata.sys (disabled) ulsata2: \SystemRoot\system32\drivers\ulsata2.sys (disabled) UMBus Enumerator Driver: system32\DRIVERS\umbus.sys (manual start) @%SystemRoot%\system32\umrdp.dll,-1000: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted (manual start) @%systemroot%\system32\upnphost.dll,-213: %SystemRoot%\system32\svchost.exe -k LocalService (manual start) Microsoft USB Generic Parent Driver: \SystemRoot\system32\drivers\usbccgp.sys (disabled) eHome Infrared Receiver (USBCIR): \SystemRoot\system32\drivers\usbcir.sys (disabled) Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: system32\DRIVERS\usbehci.sys (disabled) USB2 Enabled Hub: system32\DRIVERS\usbhub.sys (manual start) Microsoft USB Open Host Controller Miniport Driver: \SystemRoot\system32\drivers\usbohci.sys (disabled) Microsoft USB PRINTER Class: \SystemRoot\system32\drivers\usbprint.sys (disabled) USB Mass Storage Driver: \SystemRoot\system32\drivers\usbstor.sys (disabled) Microsoft USB Universal Host Controller Miniport Driver: system32\DRIVERS\usbuhci.sys (manual start) @%SystemRoot%\system32\dwm.exe,-2000: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted (autostart) @%SystemRoot%\system32\vds.exe,-100: %SystemRoot%\System32\vds.exe (manual start) vga: system32\DRIVERS\vgapnp.sys (manual start) VgaSave: \SystemRoot\System32\drivers\vga.sys (system) VIA AGP Bus Filter: \SystemRoot\system32\drivers\viaagp.sys (manual start) VIA C7 Processor Driver: \SystemRoot\system32\drivers\viac7.sys (disabled) viaide: \SystemRoot\system32\drivers\viaide.sys (disabled) VMware Pointing Device: system32\DRIVERS\vmmouse.sys (manual start) VMware Tools Service: "C:\Program Files\VMware\VMware Tools\VMwareService.exe" (autostart) VMware Ethernet Adapter Driver: system32\DRIVERS\vmxnet.sys (manual start) vmx_svga: system32\DRIVERS\vmx_svga.sys (manual start) Volume Manager Driver: system32\drivers\volmgr.sys (system) Dynamic Volume Manager: System32\drivers\volmgrx.sys (system) Storage volumes: system32\drivers\volsnap.sys (system) vsmraid: \SystemRoot\system32\drivers\vsmraid.sys (disabled) @%systemroot%\system32\vssvc.exe,-102: %systemroot%\system32\vssvc.exe (manual start) @%SystemRoot%\system32\w32time.dll,-200: %SystemRoot%\system32\svchost.exe -k LocalService (autostart) Wacom Serial Pen HID Driver: \SystemRoot\system32\drivers\wacompen.sys (disabled) Remote Access IP ARP Driver: system32\DRIVERS\wanarp.sys (manual start) Remote Access IPv6 ARP Driver: system32\DRIVERS\wanarp.sys (system) @%systemroot%\system32\wbengine.exe,-104: "%systemroot%\system32\wbengine.exe" (manual start) @%SystemRoot%\system32\wcncsvc.dll,-3: %SystemRoot%\System32\svchost.exe -k LocalService (manual start) @%SystemRoot%\system32\WcsPlugInService.dll,-200: %SystemRoot%\system32\svchost.exe -k wcssvc (manual start) Microsoft Watchdog Timer Driver: \SystemRoot\system32\drivers\wd.sys (disabled) Kernel Mode Driver Frameworks service: system32\drivers\Wdf01000.sys (system) @%systemroot%\system32\wdi.dll,-502: %SystemRoot%\System32\svchost.exe -k wdisvc (manual start) @%systemroot%\system32\wdi.dll,-500: %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted (manual start) @%systemroot%\system32\webclnt.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalService (autostart) @%SystemRoot%\system32\wecsvc.dll,-200: %SystemRoot%\system32\svchost.exe -k NetworkService (manual start) @%SystemRoot%\System32\wercplsupport.dll,-101: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start) @%SystemRoot%\System32\wersvc.dll,-100: %SystemRoot%\System32\svchost.exe -k WerSvcGroup (autostart) @%ProgramFiles%\Windows Defender\MsMpRes.dll,-103: %SystemRoot%\System32\svchost.exe -k secsvcs (autostart) @%SystemRoot%\system32\winhttp.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalService (manual start) @%Systemroot%\system32\wbem\wmisvc.dll,-205: %systemroot%\system32\svchost.exe -k netsvcs (autostart) @%Systemroot%\system32\wsmsvc.dll,-101: %SystemRoot%\System32\svchost.exe -k NetworkService (manual start) @%SystemRoot%\System32\wlansvc.dll,-257: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted (manual start) Microsoft Windows Management Interface for ACPI: \SystemRoot\system32\drivers\wmiacpi.sys (disabled) @%Systemroot%\system32\wbem\wmiapsrv.exe,-110: %systemroot%\system32\wbem\WmiApSrv.exe (manual start) @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101: "%ProgramFiles%\Windows Media Player\wmpnetwk.exe" (manual start) @%SystemRoot%\system32\wpcsvc.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted (manual start) @%SystemRoot%\system32\wpdbusenum.dll,-100: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted (autostart) Winsock IFS driver: \SystemRoot\system32\drivers\ws2ifsl.sys (disabled) @%SystemRoot%\System32\wscsvc.dll,-200: %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted (autostart) @%systemroot%\system32\SearchIndexer.exe,-103: %systemroot%\system32\SearchIndexer.exe /Embedding (autostart) @%systemroot%\system32\wuaueng.dll,-105: %systemroot%\system32\svchost.exe -k netsvcs (autostart) @%SystemRoot%\system32\wudfsvc.dll,-1000: %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted (manual start) -------------------------------------------------- Enumerating Windows NT logon/logoff scripts: *No scripts set to run* Windows NT checkdisk command: BootExecute = autocheck autochk * Windows NT 'Wininit.ini': PendingFileRenameOperations: *Registry value not found* -------------------------------------------------- Enumerating ShellServiceObjectDelayLoad items: WebCheck: C:\Windows\system32\webcheck.dll -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run *Registry key not found* -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run *Registry key not found* -------------------------------------------------- End of report, 42,851 bytes Report generated in 0.469 seconds Command line options: /verbose - to add additional info on each section /complete - to include empty sections and unsuspicious data /full - to include several rarely-important sections /force9x - to include Win9x-only startups even if running on WinNT /forcent - to include WinNT-only startups even if running on Win9x /forceall - to include all Win9x and WinNT startups, regardless of platform /history - to list version history only |
|
|
|
Nov 29 2006, 06:30 PM
Post
#3
|
|
|
Owner/Site Administrator Group: Administrator Posts: 3,093 Joined: 17-August 04 From: Newark, Nottingham, UK Member No.: 1 |
"Silent Runners.vbs", revision 49, http://www.silentrunners.org/ Operating System: Windows Vista RC1 Output of all locations checked and all values found. Startup items buried in registry: --------------------------------- HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ "WindowsWelcomeCenter" = "rundll32.exe oobefldr.dll,ShowWelcomeCenter" [MS] "swg" = "C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.6962\GoogleToolbarNotifier.exe" ["Google Inc."] "MsnMsgr" = ""C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background" [MS] HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\ HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\ HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ "Windows Defender" = "C:\Program Files\Windows Defender\MSASCui.exe -hide" "VMware Tools" = "C:\Program Files\VMware\VMware Tools\VMwareTray.exe" ["VMware, Inc."] "VMware User Process" = "C:\Program Files\VMware\VMware Tools\VMwareUser.exe" ["VMware, Inc."] "WPCUMI" = "C:\Windows\system32\WpcUmi.exe" [MS] HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\ HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\ HKLM\Software\Microsoft\Active Setup\Installed Components\ >{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\(Default) = "Microsoft Windows Media Player" \StubPath = "C:\Windows\system32\unregmp2.exe /ShowWMP" [MS] HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ {AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided) -> {HKLM...CLSID} = "Google Toolbar Helper" \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."] HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\ "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}" = "Microsoft Data Link" -> {HKLM...CLSID} = "Microsoft OLE DB Service Component Data Links" \InProcServer32\(Default) = "C:\Program Files\Common Files\System\Ole DB\oledb32.dll" [MS] "{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}" = "Computers and Devices" -> {HKLM...CLSID} = "Computers and Devices" \InProcServer32\(Default) = "C:\Windows\system32\NetworkExplorer.dll" [MS] "{E7DE9B1A-7533-4556-9484-B26FB486475E}" = (no title provided) -> {HKLM...CLSID} = "Network Map" \InProcServer32\(Default) = "C:\Windows\system32\shdocvw.dll" [MS] "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}" = "MMC Icon Handler" -> {HKLM...CLSID} = "ExtractIcon Class" \InProcServer32\(Default) = "C:\Windows\system32\mmcshext.dll" [MS] "{08165EA0-E946-11CF-9C87-00AA005127ED}" = "WebCheckWebCrawler" -> {HKLM...CLSID} = "WebCheckWebCrawler" \InProcServer32\(Default) = "C:\Windows\system32\webcheck.dll" [MS] "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}" = "Code Download Agent" -> {HKLM...CLSID} = "Code Download Agent" \InProcServer32\(Default) = "C:\Windows\system32\webcheck.dll" [MS] "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}" = "WebCheck SyncMgr Handler" -> {HKLM...CLSID} = "WebCheck SyncMgr Handler" \InProcServer32\(Default) = "C:\Windows\system32\webcheck.dll" [MS] "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}" = "Subscription Mgr" -> {HKLM...CLSID} = "Subscription Mgr" \InProcServer32\(Default) = "C:\Windows\system32\webcheck.dll" [MS] "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" = "WebCheck" -> {HKLM...CLSID} = "WebCheck" \InProcServer32\(Default) = "C:\Windows\system32\webcheck.dll" [MS] "{F5175861-2688-11d0-9C5E-00AA00A45957}" = "Subscription Folder" -> {HKLM...CLSID} = "Subscription Folder" \InProcServer32\(Default) = "C:\Windows\system32\webcheck.dll" [MS] "{7007ACC7-3202-11D1-AAD2-00805FC1270E}" = "Network Connections" -> {HKLM...CLSID} = "Network Connections" \InProcServer32\(Default) = "C:\Windows\System32\netshell.dll" [MS] "{992CFFA0-F557-101A-88EC-00DD010CCC48}" = "Network Connections" -> {HKLM...CLSID} = "Network Connections" \InProcServer32\(Default) = "C:\Windows\System32\netshell.dll" [MS] "{4A1E5ACD-A108-4100-9E26-D2FAFA1BA486}" = "IGD Property Sheet Handler" -> {HKLM...CLSID} = "IGD Property Page" \InProcServer32\(Default) = "C:\Windows\System32\icsigd.dll" [MS] "{92dbad9f-5025-49b0-9078-2d78f935e341}" = "Microsoft Windows Mail Html Preview Handler" -> {HKLM...CLSID} = "CLSID_PreviewMime" \InProcServer32\(Default) = "C:\Windows\system32\inetcomm.dll" [MS] "{b9815375-5d7f-4ce2-9245-c9d4da436930}" = "Microsoft Windows Mail Html Preview Handler" -> {HKLM...CLSID} = "CLSID_PreviewEmail" \InProcServer32\(Default) = "C:\Windows\system32\inetcomm.dll" [MS] "{f8b8412b-dea3-4130-b36c-5e8be73106ac}" = "Microsoft Windows Mail Html Preview Handler" -> {HKLM...CLSID} = "CLSID_PreviewHtml" \InProcServer32\(Default) = "C:\Windows\system32\inetcomm.dll" [MS] "{5FA29220-36A1-40f9-89C6-F4B384B7642E}" = "Shell Message Handler" -> {HKLM...CLSID} = "Shell Message Handler" \InProcServer32\(Default) = "C:\Windows\system32\inetcomm.dll" [MS] "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}" = "Shell DocObject Viewer" -> {HKLM...CLSID} = "Shell DocObject Viewer" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{BC476F4C-D9D7-4100-8D4E-E043F6DEC409}" = "Microsoft Browser Architecture" -> {HKLM...CLSID} = "Microsoft Browser Architecture" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{FBF23B40-E3F0-101B-8488-00AA003E56F8}" = "InternetShortcut" -> {HKLM...CLSID} = "Internet Shortcut" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}" = "Microsoft Url History Service" -> {HKLM...CLSID} = "Microsoft Url History Service" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{FF393560-C2A7-11CF-BFF4-444553540000}" = "History" -> {HKLM...CLSID} = "History" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}" = "Temporary Internet Files" -> {HKLM...CLSID} = "Temporary Internet Files" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}" = "Temporary Internet Files" -> {HKLM...CLSID} = "Temporary Internet Files" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" = "Microsoft Url Search Hook" -> {HKLM...CLSID} = "Microsoft Url Search Hook" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}" = "The Internet" -> {HKLM...CLSID} = "The Internet" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{73CFD649-CD48-4fd8-A272-2070EA56526B}" = "IE BandProxy" -> {HKLM...CLSID} = "IE BandProxy" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{07C45BB1-4A8C-4642-A1F5-237E7215FF66}" = "IE Microsoft BrowserBand" -> {HKLM...CLSID} = "IE Microsoft BrowserBand" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{43886CD5-6529-41c4-A707-7B3C92C05E68}" = "IE Navigation Bar" -> {HKLM...CLSID} = "IE Navigation Bar" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{30D02401-6A81-11d0-8274-00C04FD5AE38}" = "IE Search Band" -> {HKLM...CLSID} = "IE Search Band" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E}" = "IE Registry Tree Options Utility" -> {HKLM...CLSID} = "IE Registry Tree Options Utility" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{3028902F-6374-48b2-8DC6-9725E775B926}" = "IE AutoComplete" -> {HKLM...CLSID} = "IE AutoComplete" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8}" = "IE MRU AutoComplete List" -> {HKLM...CLSID} = "IE MRU AutoComplete List" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{FDE7673D-2E19-4145-8376-BBD58C4BC7BA}" = "IE Custom MRU AutoCompleted List" -> {HKLM...CLSID} = "IE Custom MRU AutoCompleted List" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{6038EF75-ABFC-4e59-AB6F-12D397F6568D}" = "IE Microsoft History AutoComplete List" -> {HKLM...CLSID} = "IE Microsoft History AutoComplete List" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{9D958C62-3954-4b44-8FAB-C4670C1DB4C2}" = "IE Microsoft Shell Folder AutoComplete List" -> {HKLM...CLSID} = "IE Microsoft Shell Folder AutoComplete List" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{B31C5FAE-961F-415b-BAF0-E697A5178B94}" = "IE Microsoft Multiple AutoComplete List Container" -> {HKLM...CLSID} = "IE Microsoft Multiple AutoComplete List Container" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{E6EE9AAC-F76B-4947-8260-A9F136138E11}" = "IE Shell Band Site Menu" -> {HKLM...CLSID} = "IE Shell Band Site Menu" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A}" = "IE Shell Rebar BandSite" -> {HKLM...CLSID} = "IE Shell Rebar BandSite" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}" = "IE User Assist" -> {HKLM...CLSID} = "IE User Assist" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{4B78D326-D922-44f9-AF2A-07805C2A3560}" = "IE Menu Band" -> {HKLM...CLSID} = "IE Menu Band" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{6CF48EF8-44CD-45d2-8832-A16EA016311B}" = "IE IShellFolderBand" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{F2CF5485-4E02-4f68-819C-B92DE9277049}" = "&Links" -> {HKLM...CLSID} = "&Links" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{1C1EDB47-CE22-4bbb-B608-77B48F83C823}" = "IE Fade Task" -> {HKLM...CLSID} = "IE Fade Task" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE}" = "IE Tracking Shell Menu" -> {HKLM...CLSID} = "IE Tracking Shell Menu" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{44C76ECD-F7FA-411c-9929-1B77BA77F524}" = "IE Menu Site" -> {HKLM...CLSID} = "IE Menu Site" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{205D7A97-F16D-4691-86EF-F3075DCCA57D}" = "IE Menu Desk Bar" -> {HKLM...CLSID} = "IE Menu Desk Bar" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{871C5380-42A0-1069-A2EA-08002B30309D}" = "Internet Name Space" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E}" = "IE RSS Feeder Folder" -> {HKLM...CLSID} = "IE RSS Feeds Folder" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{8856f961-340a-11d0-a96b-00c04fd705a2}" = "Microsoft Web Browser" -> {HKLM...CLSID} = "Microsoft Web Browser" \InProcServer32\(Default) = "C:\Windows\system32\ieframe.dll" [MS] "{3050f3d9-98b5-11cf-bb82-00aa00bdce0b}" = "MSHTML Document" -> {HKLM...CLSID} = "MHTML Document" \InProcServer32\(Default) = "C:\Windows\system32\mshtml.dll" [MS] "{25336920-03f9-11cf-8fd0-00aa00686f13}" = "HTML Document" -> {HKLM...CLSID} = "HTML Document" \InProcServer32\(Default) = "C:\Windows\system32\mshtml.dll" [MS] "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}" = "Mail Service" -> {HKLM...CLSID} = "Mail Service" \InProcServer32\(Default) = "C:\Windows\System32\sendmail.dll" [MS] "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}" = "Desktop Shortcut" -> {HKLM...CLSID} = "Desktop Shortcut" \InProcServer32\(Default) = "C:\Windows\System32\sendmail.dll" [MS] "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}" = "Web Publishing Wizard" -> {HKLM...CLSID} = "Web Publishing Wizard" \InProcServer32\(Default) = "C:\Windows\System32\shwebsvc.dll" [MS] "{add36aa8-751a-4579-a266-d66f5202ccbb}" = "Print Ordering via the Web" -> {HKLM...CLSID} = "Print Ordering via the Web" \InProcServer32\(Default) = "C:\Windows\System32\shwebsvc.dll" [MS] "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}" = "Shell Publishing Wizard Object" -> {HKLM...CLSID} = "Shell Publishing Wizard Object" \InProcServer32\(Default) = "C:\Windows\System32\shwebsvc.dll" [MS] "{176d6597-26d3-11d1-b350-080036a75b03}" = "ICM Scanner Management" -> {HKLM...CLSID} = "ICM Scanner Management" \InProcServer32\(Default) = "C:\Windows\System32\colorui.dll" [MS] "{5DB2625A-54DF-11D0-B6C4-0800091AA605}" = "ICM Monitor Management" -> {HKLM...CLSID} = "ICM Monitor Management" \InProcServer32\(Default) = "C:\Windows\System32\colorui.dll" [MS] "{675F097E-4C4D-11D0-B6C1-0800091AA605}" = "ICM Printer Management" -> {HKLM...CLSID} = "ICM Printer Management" \InProcServer32\(Default) = "C:\Windows\system32\colorui.dll" [MS] "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}" = "ICC Profile" -> {HKLM...CLSID} = "Color Profile" \InProcServer32\(Default) = "C:\Windows\system32\colorui.dll" [MS] "{0D45D530-764B-11d0-A1CA-00AA00C16E65}" = "Directory Property UI" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Windows\system32\dsuiext.dll" [MS] "{62AE1F9A-126A-11D0-A14B-0800361B1103}" = "Directory Context Menu Verbs" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Windows\system32\dsuiext.dll" [MS] "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}" = "Directory Query UI" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Windows\system32\dsquery.dll" [MS] "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}" = "Shell properties for a DS object" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Windows\system32\dsquery.dll" [MS] "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}" = "Directory Object Find" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Windows\system32\dsquery.dll" [MS] "{F020E586-5264-11d1-A532-0000F8757D7E}" = "Directory Start/Search Find" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Windows\system32\dsquery.dll" [MS] "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}" = "Printers Security Page" -> {HKLM...CLSID} = "Security Shell Extension" \InProcServer32\(Default) = "rshx32.dll" [MS] "{1F2E5C40-9550-11CE-99D2-00AA006E086C}" = "NTFS Security Page" -> {HKLM...CLSID} = "Security Shell Extension" \InProcServer32\(Default) = "rshx32.dll" [MS] "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}" = "Shell extensions for sharing" -> {HKLM...CLSID} = "Shell extensions for sharing" \InProcServer32\(Default) = "ntshrui.dll" [MS] "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}" = "Shell extensions for sharing" -> {HKLM...CLSID} = "Shell extensions for sharing" \InProcServer32\(Default) = "ntshrui.dll" [MS] "{77597368-7b15-11d0-a0c2-080036af3f03}" = "Web Printer Shell Extension" -> {HKLM...CLSID} = "PrintUIShellExtension Class" \InProcServer32\(Default) = "C:\Windows\system32\printui.dll" [MS] "{4E40F770-369C-11d0-8922-00A024AB2DBB}" = "DS Security Page" -> {HKLM...CLSID} = "Security Shell Extension" \InProcServer32\(Default) = "dssec.dll" [MS] "{41E300E0-78B6-11ce-849B-444553540000}" = "PlusPack CPL Extension" -> {HKLM...CLSID} = "Display Effects CPL Extension" \InProcServer32\(Default) = "C:\Windows\system32\themeui.dll" [MS] "{36eef7db-88ad-4e81-ad49-0e313f0c35f8}" = "Windows Update" -> {HKLM...CLSID} = "Windows Update" \InProcServer32\(Default) = "C:\Windows\system32\shdocvw.dll" [MS] "{74246bfc-4c96-11d0-abef-0020af6b0b7a}" = "Device Manager" -> {HKLM...CLSID} = "Device Manager" \InProcServer32\(Default) = "C:\Windows\System32\devmgr.dll" [MS] "{7b81be6a-ce2b-4676-a29e-eb907a5126c5}" = "Programs and Features" -> {HKLM...CLSID} = "Programs and Features" \InProcServer32\(Default) = "C:\Windows\System32\appwiz.cpl" [MS] "{15eae92e-f17a-4431-9f28-805e482dafd4}" = "Install New Programs" -> {HKLM...CLSID} = "Install New Programs" \InProcServer32\(Default) = "C:\Windows\System32\appwiz.cpl" [MS] "{d450a8a1-9568-45c7-9c0e-b4f9fb4537bd}" = "Installed Updates" -> {HKLM...CLSID} = "Installed Updates" \InProcServer32\(Default) = "C:\Windows\System32\appwiz.cpl" [MS] "{ceefea1b-3e29-4ef1-b34c-fec79c4f70af}" = "New Shortcut Wizard" -> {HKLM...CLSID} = "New Shortcut Wizard" \InProcServer32\(Default) = "C:\Windows\System32\appwiz.cpl" [MS] "{0BFCF7B7-E7B6-433a-B205-2904FCF040DD}" = "New Shortcut Wizard Modal" -> {HKLM...CLSID} = "New Shortcut Wizard Modal" \InProcServer32\(Default) = "C:\Windows\System32\appwiz.cpl" [MS] "{CFCCC7A0-A282-11D1-9082-006008059382}" = "Darwin App Publisher" -> {HKLM...CLSID} = "Darwin App Publisher" \InProcServer32\(Default) = "C:\Windows\System32\appwiz.cpl" [MS] "{59099400-57FF-11CE-BD94-0020AF85B590}" = "Disk Copy Extension" -> {HKLM...CLSID} = "Disk Copy Extension" \InProcServer32\(Default) = "diskcopy.dll" [MS] "{ECF03A32-103D-11d2-854D-006008059367}" = "MyDocs Drop Target" -> {HKLM...CLSID} = "MyDocs Drop Target" \InProcServer32\(Default) = "C:\Windows\system32\mydocs.dll" [MS] "{4a7ded0a-ad25-11d0-98a8-0800361b1103}" = "MyFolder Properties" -> {HKLM...CLSID} = "MyFolder menu and properties" \InProcServer32\(Default) = "C:\Windows\system32\mydocs.dll" [MS] "{44f3dab6-4392-4186-bb7b-6282ccb7a9f6}" = "MyDocuments menu and properties" -> {HKLM...CLSID} = "MyDocuments menu and properties" \InProcServer32\(Default) = "C:\Windows\system32\mydocs.dll" [MS] "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}" = "Search" -> {HKLM...CLSID} = "Search" \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}" = "Help and Support" -> {HKLM...CLSID} = "Help and Support" \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}" = "Help and Support" -> {HKLM...CLSID} = "Windows Security" \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}" = "Run..." -> {HKLM...CLSID} = "Run..." \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}" = "Internet" -> {HKLM...CLSID} = "Internet" \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}" = "E-mail" -> {HKLM...CLSID} = "E-mail" \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{2559a1f6-21d7-11d4-bdaf-00c04f60b9f0}" = "Start Menu OEM Command" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}" = "Set Program Access and Defaults" -> {HKLM...CLSID} = "Set Program Access and Defaults" \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{3080F90D-D7AD-11D9-BD98-0000947B0257}" = "Show Desktop" -> {HKLM...CLSID} = "Show Desktop" \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{3080F90E-D7AD-11D9-BD98-0000947B0257}" = "Window Switcher" -> {HKLM...CLSID} = "Window Switcher" \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{eb124705-128b-40d4-8dd8-d93ed12589a4}" = "WPL property store" -> {HKLM...CLSID} = "WPL property store" \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{3c2654c6-7372-4f6b-b310-55d6128f49d2}" = "Alphabetical Categorizer" -> {HKLM...CLSID} = "Alphabetical Categorizer" \InProcServer32\(Default) = "C:\Windows\system32\shell32.dll" [MS] "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}" = "Summary Info Thumbnail handler (DOCFILES)" -> {HKLM...CLSID} = "Property Thumbnail Handler" \InProcServer32\(Default) = "C:\Windows\system32\shell32.dll" [MS] "{708e1662-b832-42a8-bbe1-0a77121e3908}" = "Tree property value folder" -> {HKLM...CLSID} = "Tree property value folder" \InProcServer32\(Default) = "C:\Windows\system32\shell32.dll" [MS] "{71f96385-ddd6-48d3-a0c1-ae06e8b055fb}" = "Explorer Browser" -> {HKLM...CLSID} = "Explorer Browser" \InProcServer32\(Default) = "C:\Windows\system32\shell32.dll" [MS] "{b2952b16-0e07-4e5a-b993-58c52cb94cae}" = "Search Folders" -> {HKLM...CLSID} = "DB Folder" \InProcServer32\(Default) = "C:\Windows\system32\shell32.dll" [MS] "{437ff9c0-a07f-4fa0-af80-84b6c6440a16}" = "Command Folder" -> {HKLM...CLSID} = "Command Folder" \InProcServer32\(Default) = "C:\Windows\system32\shell32.dll" [MS] "{90f8c90b-04e0-4e92-a186-e6e9c125d664}" = "Property Labels" -> {HKLM...CLSID} = "Property Labels" \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{D20EA4E1-3957-11d2-A40B-0C5020524152}" = "Fonts" -> {HKLM...CLSID} = "Fonts" \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{D20EA4E1-3957-11d2-A40B-0C5020524153}" = "Administrative Tools" -> {HKLM...CLSID} = "Administrative Tools" \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{b155bdf8-02f0-451e-9a26-ae317cfd7779}" = "nethood delegate folder" -> {HKLM...CLSID} = "delegate folder that appears in Computer" \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{DFFACDC5-679F-4156-8947-C5C76BC0B67F}" = "users files delegate folder" -> {HKLM...CLSID} = "delegate folder that appears in Users Files Folder" \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{ed50fc29-b964-48a9-afb3-15ebb9b97f36}" = "printhood delegate folder" -> {HKLM...CLSID} = "printhood delegate folder" \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{328B0346-7EAF-4BBE-A479-7CB88A095F5B}" = "Layout Folder" -> {HKLM...CLSID} = "LayoutFolder" \InProcServer32\(Default) = "C:\Windows\system32\shell32.dll" [MS] "{4336a54d-038b-4685-ab02-99bb52d3fb8b}" = "Public Folder" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{00021401-0000-0000-C000-000000000046}" = "Shortcut" -> {HKLM...CLSID} = "Shortcut" \InProcServer32\(Default) = "shell32.dll" [MS] "{C73F6F30-97A0-4AD1-A08F-540D4E9BC7B9}" = "Search Folder" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{0AFCCBA6-BF90-4A4E-8482-0AC960981F5B}" = ".fon, .otf, .ttc or .ttf files" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Windows\system32\shell32.dll" [MS] "{66742402-F9B9-11D1-A202-0000F81FEDEE}" = ".cpl, .dll, .exe, .ocx, .rll or .sys files" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Windows\system32\shell32.dll" [MS] "{D34A6CA6-62C2-4C34-8A7C-14709C1AD938}" = "Common Places Folder" -> {HKLM...CLSID} = "Common Places FS Folder" \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{865e5e76-ad83-4dca-a109-50dc2113ce9a}" = "Programs Folder and Fast Items" -> {HKLM...CLSID} = "Programs Folder and Fast Items" \InProcServer32\(Default) = "C:\Windows\system32\shell32.dll" [MS] "{21ec2020-3aea-1069-a2dd-08002b30309d}" = "Control Panel" -> {HKLM...CLSID} = "Control Panel" \InProcServer32\(Default) = "shell32.dll" [MS] "{25585dc7-4da0-438d-ad04-e42c8d2d64b9}" = "Client application shell extension" -> {HKLM...CLSID} = "Client application shell extension" \InProcServer32\(Default) = "C:\Windows\system32\shell32.dll" [MS] "{a42c2ccb-67d3-46fa-abe6-7d2f3488c7a3}" = "Microsoft Windows RTF Preview Handler" -> {HKLM...CLSID} = "Microsoft Windows RTF Preview Handler" \InProcServer32\(Default) = "C:\Windows\system32\shell32.dll" [MS] "{1531d583-8375-4d3f-b5fb-d23bbd169f22}" = "Window TXT Preview Handler" -> {HKLM...CLSID} = "Microsoft Windows TXT Preview Handler" \InProcServer32\(Default) = "C:\Windows\system32\shell32.dll" [MS] "{97e467b4-98c6-4f19-9588-161b7773d6f6}" = "Office Document Property Handler" -> {HKLM...CLSID} = "Office Document Property Handler" \InProcServer32\(Default) = "C:\Windows\system32\propsys.dll" [MS] "{88C6C381-2E85-11D0-94DE-444553540000}" = "ActiveX Cache Folder" -> {HKLM...CLSID} = "ActiveX Cache Folder" \InProcServer32\(Default) = "C:\Windows\system32\occache.dll" [MS] "{5E6AB780-7743-11CF-A12B-00AA004AE837}" = "Microsoft Internet Toolbar" -> {HKLM...CLSID} = "Microsoft Internet Toolbar" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{7BA4C742-9E81-11CF-99D3-00AA004AE837}" = "Microsoft BrowserBand" -> {HKLM...CLSID} = "Microsoft BrowserBand" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{056440FD-8568-48e7-A632-72157243B55B}" = "Explorer Navigation Bar" -> {HKLM...CLSID} = "Explorer Navigation Bar" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{C4EC38BD-4E9E-4b5e-935A-D1BFF237D980}" = "Explorer Travel Band" -> {HKLM...CLSID} = "Explorer Travel Band" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{6D8BB3D3-9D87-4a91-AB56-4F30CFFEFE9F}" = "Explorer Search Band" -> {HKLM...CLSID} = "Explorer Search Band" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{21569614-B795-46b1-85F4-E737A8DC09AD}" = "Search Band" -> {HKLM...CLSID} = "Search Band" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}" = "In-pane search" -> {HKLM...CLSID} = "In-pane search" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{AF4F6510-F982-11d0-8595-00AA004CD6D8}" = "Registry Tree Options Utility" -> {HKLM...CLSID} = "Registry Tree Options Utility" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{01E04581-4EEE-11d0-BFE9-00AA005B4383}" = "&Address" -> {HKLM...CLSID} = "&Address" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{a542e116-8088-4146-a352-b0d06e7f6af6}" = "Address EditBox" -> {HKLM...CLSID} = "Address EditBox" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{F61FFEC1-754F-11d0-80CA-00AA005B4383}" = "BandProxy" -> {HKLM...CLSID} = "BandProxy" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{00BB2763-6A77-11D0-A535-00C04FD7D062}" = "Microsoft AutoComplete" -> {HKLM...CLSID} = "Microsoft AutoComplete" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{596742A5-1393-4e13-8765-AE1DF71ACAFB}" = "Microsoft Breadcrumb Bar" -> {HKLM...CLSID} = "Microsoft Breadcrumb Bar" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{6756A641-DE71-11d0-831B-00AA005B4383}" = "MRU AutoComplete List" -> {HKLM...CLSID} = "MRU AutoComplete List" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}" = "Custom MRU AutoCompleted List" -> {HKLM...CLSID} = "Custom MRU AutoCompleted List" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{00BB2764-6A77-11D0-A535-00C04FD7D062}" = "Microsoft History AutoComplete List" -> {HKLM...CLSID} = "Microsoft History AutoComplete List" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{03C036F1-A186-11D0-824A-00AA005B4383}" = "Microsoft Shell Folder AutoComplete List" -> {HKLM...CLSID} = "Microsoft Shell Folder AutoComplete List" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{00BB2765-6A77-11D0-A535-00C04FD7D062}" = "Microsoft Multiple AutoComplete List Container" -> {HKLM...CLSID} = "Microsoft Multiple AutoComplete List Container" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}" = "Shell Band Site Menu" -> {HKLM...CLSID} = "Shell Band Site Menu" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}" = "Shell DeskBarApp" -> {HKLM...CLSID} = "Shell DeskBarApp" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}" = "Shell Rebar BandSite" -> {HKLM...CLSID} = "Shell Rebar BandSite" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}" = "User Assist" -> {HKLM...CLSID} = "User Assist" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}" = "Global Folder Settings" -> {HKLM...CLSID} = "Global Folder Settings" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{fccf70c8-f4d7-4d8b-8c17-cd6715e37fff}" = "Search Control" -> {HKLM...CLSID} = "Search Control" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{4d5c8c2a-d075-11d0-b416-00c04fb90376}" = "Microsoft CommBand" -> {HKLM...CLSID} = "Microsoft CommBand" \InProcServer32\(Default) = "C:\Windows\system32\browseui.dll" [MS] "{DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7}" = "File Open Dialog" -> {HKLM...CLSID} = "File Open Dialog" \InProcServer32\(Default) = "C:\Windows\System32\comdlg32.dll" [MS] "{C0B4E2F3-BA21-4773-8DBA-335EC946EB8B}" = "File Save Dialog" -> {HKLM...CLSID} = "File Save Dialog" \InProcServer32\(Default) = "C:\Windows\System32\comdlg32.dll" [MS] "{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}" = "Shell Icon Handler for Application References" -> {HKLM...CLSID} = "Shell Icon Handler for Application References" \InProcServer32\(Default) = "C:\Windows\system32\dfshim.dll" [MS] "{e82a2d71-5b2f-43a0-97b8-81be15854de8}" = "ShellLink for Application References" -> {HKLM...CLSID} = "ShellLink for Application References" \InProcServer32\(Default) = "C:\Windows\system32\dfshim.dll" [MS] "{92337A8C-E11D-11D0-BE48-00C04FC30DF6}" = "OlePrn.PrinterURL" -> {HKLM...CLSID} = "prturl Class" \InProcServer32\(Default) = "C:\Windows\system32\oleprn.dll" [MS] "{45670FA8-ED97-4F44-BC93-305082590BFB}" = "Microsoft XPS Properties" -> {HKLM...CLSID} = "Microsoft XPS Shell Metadata Handler" \InProcServer32\(Default) = "C:\Windows\system32\XPSSHHDR.DLL" [MS] "{44121072-A222-48f2-A58A-6D9AD51EBBE9}" = "Microsoft XPS Thumbnail" -> {HKLM...CLSID} = (no title provided) \InProcServer32\(Default) = "C:\Windows\system32\XPSSHHDR.DLL" [MS] "{13D3C4B8-B179-4ebb-BF62-F704173E7448}" = "Windows Contact Preview Handler" -> {HKLM...CLSID} = "CLSID_ContactReadingPane" \InProcServer32\(Default) = "C:\Program Files\Common Files\System\wab32.dll" [MS] "{32714800-2E5F-11d0-8B85-00AA0044F941}" = "For &People..." -> {HKLM...CLSID} = "For &People..." \InProcServer32\(Default) = "C:\Program Files\Windows Mail\wabfind.dll" [MS] "{4F58F63F-244B-4c07-B29F-210BE59BE9B4}" = ".group shell extension handler" -> {HKLM...CLSID} = ".group shell extension handler" \InProcServer32\(Default) = "C:\Program Files\Common Files\System\wab32.dll" [MS] "{8082C5E6-4C27-48ec-A809-B8E1122E8F97}" = ".contact shell extension handler" -> {HKLM...CLSID} = ".contact shell extension handler" \InProcServer32\(Default) = "C:\Program Files\Common Files\System\wab32.dll" [MS] "{16C2C29D-0E5F-45f3-A445-03E03F587B7D}" = "group_wab_auto_file" -> {HKLM...CLSID} = ".group shell context menu" \InProcServer32\(Default) = "C:\Program Files\Common Files\System\wab32.dll" [MS] "{CF67796C-F57F-45F8-92FB-AD698826C602}" = "contact_wab_auto_file" -> {HKLM...CLSID} = ".contact shell context menu" \InProcServer32\(Default) = "C:\Program Files\Common Files\System\wab32.dll" [MS] "{7444C717-39BF-11D1-8CD9-00C04FC29D45}" = "Crypto PKO Extension" -> {HKLM...CLSID} = "CryptPKO Class" \InProcServer32\(Default) = "C:\Windows\system32\cryptext.dll" [MS] "{7444C719-39BF-11D1-8CD9-00C04FC29D45}" = "Crypto Sign Extension" -> {HKLM...CLSID} = "CryptSig Class" \InProcServer32\(Default) = "C:\Windows\system32\cryptext.dll" [MS] "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}" = "Compatibility Property Page" -> {HKLM...CLSID} = "LayerUIPropPage" \InProcServer32\(Default) = "C:\Windows\system32\acppage.dll" [MS] "{F0152790-D56E-4445-850E-4F3117DB740C}" = "Remote Sessions CPL Extension" -> {HKLM...CLSID} = "Remote Sessions CPL Extension" \InProcServer32\(Default) = "C:\Windows\system32\remotepg.dll" [MS] "{D555645E-D4F8-4c29-A827-D93C859C4F2A}" = (no title provided) -> {HKLM...CLSID} = "Ease of Access" \InProcServer32\(Default) = "C:\Windows\System32\shdocvw.dll" [MS] "{692F0339-CBAA-47e6-B5B5-3B84DB604E87}" = "Extensions Manager Folder" -> {HKLM...CLSID} = "Extensions Manager Folder" \InProcServer32\(Default) = "C:\Windows\system32\extmgr.dll" [MS] "{60254CA5-953B-11CF-8C96-00AA00B8708C}" = "Shell extensions for Windows Script Host" |