startup list (i let have a look while i try buzz's solution
):
StartupList report, 20/05/2005, 20:20:38
StartupList version: 1.52
Started from : I:\# PROGRAMS\# PROGRAMS\Setups\StartupList.EXE
Detected: Windows 2000 SP4 (WinNT 5.00.2195)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
E:\WINNT\System32\smss.exe
E:\WINNT\system32\csrss.exe
E:\WINNT\system32\winlogon.exe
E:\WINNT\system32\services.exe
E:\WINNT\system32\lsass.exe
E:\WINNT\system32\svchost.exe
E:\WINNT\system32\spoolsv.exe
E:\WINNT\System32\Ati2evxx.exe
E:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
E:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
E:\WINNT\System32\svchost.exe
E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kavmm.exe
E:\WINNT\system32\regsvc.exe
E:\WINNT\system32\MSTask.exe
E:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
E:\WINNT\System32\WBEM\WinMgmt.exe
E:\WINNT\system32\svchost.exe
E:\WINNT\Explorer.EXE
E:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
E:\WINNT\system32\rundll32.exe
E:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
E:\Program Files\Analog Devices\SoundMAX\Smax4.exe
E:\WINNT\System32\hphmon05.exe
E:\WINNT\System32\spool\drivers\w32x86\3\hpztsb09.exe
E:\Program Files\Olitec\USB ADSL\CnxDslTb.exe
E:\Program Files\Common Files\Real\Update_OB\realsched.exe
E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kav.exe
E:\PROGRA~1\Grisoft\AVG7\avgcc.exe
E:\PROGRA~1\Grisoft\AVG7\avgemc.exe
I:\# PROGRAMS\# PROGRAMS\Setups\# UTILS\hijackthis\hijackthis_199\HijackThis.exe
E:\WINNT\System32\HPZipm12.exe
E:\Program Files\Internet Explorer\IEXPLORE.EXE
I:\# PROGRAMS\# PROGRAMS\Setups\StartupList.exe
--------------------------------------------------
Listing of startup folders:
Shell folders Common Startup:
[E:\Documents and Settings\All Users.WINNT\Start Menu\Programs\Startup]
Adobe Gamma Loader.lnk = E:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office\OSA9.EXE
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = E:\WINNT\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Synchronization Manager = mobsync.exe /logon
ATIPTA = E:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
AdslTaskBar = rundll32.exe stmctrl.dll,TaskBar
SoundMAXPnP = E:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
SoundMAX = "E:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
NeroFilterCheck = E:\WINNT\system32\NeroCheck.exe
HPHUPD05 = E:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
HP Software Update = "E:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
HPHmon05 = E:\WINNT\System32\hphmon05.exe
HPDJ Taskbar Utility = E:\WINNT\System32\spool\drivers\w32x86\3\hpztsb09.exe
CnxDslTaskBar = E:\Program Files\Olitec\USB ADSL\CnxDslTb.exe
TkBellExe = "E:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
KAV50 = "E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro 5\kav.exe" -run -n PersonalPro -v 5.0.0.0
AVG7_CC = E:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
AVG7_EMC = E:\PROGRA~1\Grisoft\AVG7\avgemc.exe
THGuard = "E:\Program Files\TrojanHunter 4.2\THGuard.exe"
WindowsUpdate = E:\WINNT\System\svchost.exe /s
--------------------------------------------------
Shell & screensaver key from E:\WINNT\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - E:\PROGRA~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - e:\program files\google\googletoolbar1.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
--------------------------------------------------
Enumerating Task Scheduler jobs:
HP Usg Daily.job
--------------------------------------------------
Enumerating Download Program Files:
[HouseCall Control]
InProcServer32 = E:\WINNT\DOWNLO~1\xscan53.ocx
CODEBASE =
http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
[Update Class]
InProcServer32 = E:\WINNT\System32\iuctl.dll
CODEBASE =
http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38491.9471064815
[Shockwave Flash Object]
InProcServer32 = E:\WINNT\System32\macromed\flash\Flash.ocx
CODEBASE =
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
Network.ConnectionTray: E:\WINNT\system32\NETSHELL.dll
WebCheck: E:\WINNT\System32\webcheck.dll
SysTray: stobject.dll
--------------------------------------------------
End of report, 5*983 bytes
Report generated in 0,047 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only