StartupList report, 5/26/2008, 10:33:48 PM StartupList version: 1.52 Started from : C:\Documents and Settings\Owner\Desktop\startuplist\StartupList.EXE Detected: Windows XP SP2 (WinNT 5.01.2600) Detected: Internet Explorer v7.00 (7.00.6000.16640) * Using default options ================================================== Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\McAfee.com\Agent\mcagent.exe C:\Program Files\SiteAdvisor\6261\SiteAdv.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\imapi.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\SiteAdvisor\6261\SAService.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\Documents and Settings\Owner\Desktop\startuplist\StartupList.exe -------------------------------------------------- Checking Windows NT UserInit: [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] UserInit = C:\WINDOWS\system32\userinit.exe, -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run LTMSG = LTMSG.exe 7 KBD = C:\HP\KBD\KBD.EXE GrooveMonitor = "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" KernelFaultCheck = %systemroot%\system32\dumprep 0 -k mcagent_exe = C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey SiteAdvisor = "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe" -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe -------------------------------------------------- Autorun entries in Registry subkeys of: HKCU\Software\Microsoft\Windows\CurrentVersion\Run [AdobeUpdater] = -------------------------------------------------- File association entry for .SCR: HKEY_CLASSES_ROOT\AutoCADScriptFile\shell\open\command (Default) = "C:\WINDOWS\system32\NOTEPAD.EXE" "%1" -------------------------------------------------- Shell & screensaver key from C:\WINDOWS\SYSTEM.INI: Shell=*INI section not found* SCRNSAVE.EXE=*INI section not found* drivers=*INI section not found* Shell & screensaver key from Registry: Shell=Explorer.exe SCRNSAVE.EXE=C:\WINDOWS\system32\J_J}Z_~1.SCR drivers=*Registry value not found* Policies Shell key: HKCU\..\Policies: Shell=*Registry value not found* HKLM\..\Policies: Shell=*Registry value not found* -------------------------------------------------- Enumerating Browser Helper Objects: (no name) - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll - {089FD14D-132B-48FC-8861-0048AE113215} (no name) - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} (no name) - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} scriptproxy - C:\Program Files\McAfee\VirusScan\scriptsn.dll - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} -------------------------------------------------- Enumerating Task Scheduler jobs: AppleSoftwareUpdate.job McDefragTask.job McQcTask.job MP Scheduled Scan.job -------------------------------------------------- Enumerating Download Program Files: [{0000000A-0000-0010-8000-00AA00389B71}] CODEBASE = http://download.microsoft.com/download/d/4/4/d446e8a9-3a86-4b59-bb19-f5bd11b40367/wmavax.CAB [MUCatalogWebControl Class] InProcServer32 = C:\WINDOWS\system32\MicrosoftUpdateCatalogWebControl.dll CODEBASE = http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1193626600328 [Pearson Installation Assistant 2] InProcServer32 = C:\WINDOWS\DOWNLO~1\PEARSO~1.OCX CODEBASE = http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab [Crucial cpcScan] InProcServer32 = C:\WINDOWS\Downloaded Program Files\cpcScan.dll CODEBASE = http://www.crucial.com/controls/cpcScanner.cab [Toontown Installer ActiveX Control] InProcServer32 = C:\WINDOWS\Downloaded Program Files\ttinst.dll CODEBASE = http://a.download.toontown.com/sv1.0.33.7/ttinst.cab [Pearson MathXL Player] InProcServer32 = C:\WINDOWS\DOWNLO~1\MATHPL~1.OCX CODEBASE = http://asp.mathxl.com/books/_Players/MathPlayer.cab -------------------------------------------------- Enumerating Winsock LSP files: NameSpace #1: C:\Program Files\Bonjour\mdnsNSP.dll -------------------------------------------------- Enumerating ShellServiceObjectDelayLoad items: PostBootReminder: C:\WINDOWS\system32\SHELL32.dll CDBurn: C:\WINDOWS\system32\SHELL32.dll WebCheck: C:\WINDOWS\system32\webcheck.dll SysTray: C:\WINDOWS\system32\stobject.dll WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll -------------------------------------------------- End of report, 6,081 bytes Report generated in 0.187 seconds Command line options: /verbose - to add additional info on each section /complete - to include empty sections and unsuspicious data /full - to include several rarely-important sections /force9x - to include Win9x-only startups even if running on WinNT /forcent - to include WinNT-only startups even if running on Win9x /forceall - to include all Win9x and WinNT startups, regardless of platform /history - to list version history only