Thanks very much for offering your help to me.
Here is the Simple Report from the winpfind2.exe program:
Logfile created on: 09/17/2006 10:35
WinPFind2 by OldTimer - Version 1.0.9 Folder = C:\Documents and Settings\Administrator.NRS-MEKCSMQ3ZNE.007\Desktop\New Folder\WinPFind2\
Microsoft Windows 2000 Service Pack 4 (Version = 5.0.2195)
Internet Explorer (Version = 6.0.2800.1106)
< All Processes >
c:\program files\symantec\pcanywhere\awhost32.exe - (Symantec Corporation )
\??\c:\winnt\system32\csrss.exe - (Microsoft Corporation )
c:\winnt\explorer.exe - (Microsoft Corporation )
c:\program files\internet explorer\iexplore.exe - (Microsoft Corporation )
c:\winnt\system32\internat.exe - (Microsoft Corporation )
c:\program files\java\jre1.5.0_06\bin\jusched.exe - (Sun Microsystems, Inc. )
c:\winnt\system32\lsass.exe - (Microsoft Corporation )
c:\winnt\system32\dllcache\mscom.exe - ( )
c:\winnt\system32\dllcache\mslogon.exe - ( )
c:\winnt\system32\mspmspsv.exe - (Microsoft Corporation )
c:\winnt\system32\mstask.exe - (Microsoft Corporation )
d:\program files\symantec\ghost\ngctw32.exe - (Symantec New Zealand Limited )
c:\winnt\system32\progman.exe - (Microsoft Corporation )
c:\winnt\system32\regsvc.exe - (Microsoft Corporation )
c:\winnt\system32\rundll32.exe - (Microsoft Corporation )
c:\winnt\system32\services.exe - (Microsoft Corporation )
\systemroot\system32\smss.exe - (Microsoft Corporation )
c:\winnt\system32\snmp.exe - (Microsoft Corporation )
c:\winnt\system32\spoolsv.exe - (Microsoft Corporation )
c:\winnt\system32\stisvc.exe - (Microsoft Corporation )
c:\winnt\system32\svchost.exe - (Microsoft Corporation )
c:\winnt\system32\svchost.exe - (Microsoft Corporation )
\??\c:\winnt\system32\winlogon.exe - (Microsoft Corporation )
c:\winnt\system32\wbem\winmgmt.exe - (Microsoft Corporation )
c:\documents and settings\administrator.nrs-mekcsmq3zne.007\desktop\new folder\winpfind2\winpfind2.exe - (OldTimer Tools )
c:\winnt\system32\xpjavams.exe - ( )
< Registry Entries >
[>> Internet Explorer Settings <<]
HKLM->Main\\Start Page -
http://www.microsoft...p...ER}&ar=home HKLM->Main\\Search Page -
http://www.microsoft...amp;ar=iesearch HKLM->Main\\Default_Page_URL -
http://www.microsoft...p...&ar=msnhome HKLM->Main\\Default_Search_URL -
http://www.microsoft...amp;ar=iesearch HKLM->Main\\Local Page - %SystemRoot%\system32\blank.htm
HKCU->Main\\Start Page -
http://www.microsoft...p...&ar=msnhome HKCU->Main\\Search Page -
http://www.microsoft...amp;ar=iesearch HKCU->Main\\Local Page - C:\WINNT\system32\blank.htm
HKLM->Search\\CustomizeSearch -
http://ie.search.msn...st/srchcust.htm HKLM->Search\\SearchAssistant -
http://ie.search.msn...st/srchasst.htm HKCU->URLSearchHooks\\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Microsoft Url Search Hook = %SystemRoot%\system32\shdocvw.dll (Microsoft Corporation )
HKCU->Internet Settings\\ProxyEnable - 0
[>> BHO's <<]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - AcroIEHlprObj Class = d:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ( )
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - SSVHelper Class = C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (Sun Microsystems, Inc. )
[>> Internet Explorer Bars, Toolbars and Extensions <<]
[HKLM-> Internet Explorer Bars]
{4D5C8C25-D075-11d0-B416-00C04FB90376} - &Tip of the Day = %SystemRoot%\system32\shdocvw.dll (Microsoft Corporation )
[HKLM-> Internet Explorer ToolBars]
{8E718888-423F-11D2-876E-00A0C9082467} - &Radio = C:\WINNT\system32\msdxm.ocx ( )
[HKCU-> Internet Explorer ToolBars]
WebBrowser\\{01E04581-4EEE-11D0-BFE9-00AA005B4383} - &Address = %SystemRoot%\system32\browseui.dll (Microsoft Corporation )
WebBrowser\\{0E5CBF21-D15F-11D0-8301-00AA005B4383} - &Links = %SystemRoot%\system32\browseui.dll (Microsoft Corporation )
[HKCU-> Internet Explorer CmdMapping]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - 8192 - Sun Java Console
{669695BC-A811-4A9D-8CDF-BA8C795F261C} - 8193 - Reg Data missing or invalid
{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - 8194 - Reg Data missing or invalid
NextId - 8195
[HKLM-> Internet Explorer Extensions]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - MenuText: Sun Java Console = C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll (Sun Microsystems, Inc. )
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} (HKCU CLSID) - MenuText: Sun Java Console = C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (Sun Microsystems, Inc. )
{669695BC-A811-4A9D-8CDF-BA8C795F261C} - ButtonText: Run DAP = C:\PROGRA~1\DAP\DAP.EXE (Speedbit Ltd. )
{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - ButtonText: AIM = C:\Program Files\AIM\aim.exe (America Online, Inc. )
[HKCU-> Internet Explorer Menu Extensions]
&Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm ( )
Download &all with DAP - D:\PROGRA~1\DAP\dapextie2.htm (File not found))
[HKLM-> Internet Explorer Plugins]
.spop - Reg Data missing or invalid = C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (InterTrust Technologies Corporation, Inc. )
[>> Approved Shell Extensions (Non-Microsoft only) <<]
[HKLM-> Approved Shell Extensions]
{42071714-76d4-11d1-8b24-00a0c9068ff3} - Display Panning CPL Extension = deskpan.dll (File not found))
{764BF0E1-F219-11ce-972D-00AA00A14F56} - Shell extensions for file compression = Reg Data missing or invalid (File not found))
{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} - Encryption Context Menu = Reg Data missing or invalid (File not found))
{88895560-9AA2-1069-930E-00AA0030EBC8} - HyperTerminal Icon Ext = C:\WINNT\System32\hticons.dll (Hilgraeve, Inc. )
{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} - AVG7 Shell Extension = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o. )
{9F97547E-460A-42C5-AE0C-81C61FFAEBC3} - AVG7 Find Extension = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o. )
{E0D79304-84BE-11CE-9641-444553540000} - WinZip = D:\PROGRA~1\WinZip\WZSHLSTB.DLL (WinZip Computing, Inc. )
{E0D79305-84BE-11CE-9641-444553540000} - WinZip = D:\PROGRA~1\WinZip\WZSHLSTB.DLL (WinZip Computing, Inc. )
{E0D79306-84BE-11CE-9641-444553540000} - WinZip = D:\PROGRA~1\WinZip\WZSHLSTB.DLL (WinZip Computing, Inc. )
[>> ContextMenuHandlers (Non-Microsoft only) <<]
[HKLM-> ContextMenuHandlers]
* - AVG7 Shell Extension - {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o. )
* - WinZip - {E0D79304-84BE-11CE-9641-444553540000} = D:\PROGRA~1\WinZip\WZSHLSTB.DLL (WinZip Computing, Inc. )
Directory - WinZip - {E0D79304-84BE-11CE-9641-444553540000} = D:\PROGRA~1\WinZip\WZSHLSTB.DLL (WinZip Computing, Inc. )
Directory\Background - igfxcui - {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} = C:\WINNT\System32\igfxpph.dll (Intel Corporation )
Folder - AVG7 Shell Extension - {9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\Grisoft\AVG Free\avgse.dll (GRISOFT, s.r.o. )
Folder - WinZip - {E0D79304-84BE-11CE-9641-444553540000} = D:\PROGRA~1\WinZip\WZSHLSTB.DLL (WinZip Computing, Inc. )
[>> ColumnHandlers (Non-Microsoft only) <<]
[HKLM-> ColumnHandlers]
[>> File Associations Keys <<]
HKLM->SOFTWARE\Classes\.bat\\'' - batfile
HKLM->SOFTWARE\Classes\batfile\shell\open\command\\'' - "%1" %*
HKLM->SOFTWARE\Classes\.cmd\\'' - cmdfile
HKLM->SOFTWARE\Classes\cmdfile\shell\open\command\\'' - "%1" %*
HKLM->SOFTWARE\Classes\.com\\'' - comfile
HKLM->SOFTWARE\Classes\comfile\shell\open\command\\'' - "%1" %*
HKLM->SOFTWARE\Classes\.exe\\'' - exefile
HKLM->SOFTWARE\Classes\exefile\shell\open\command\\'' - "%1" %*
HKLM->SOFTWARE\Classes\.hta\\'' - htafile
HKLM->SOFTWARE\Classes\htafile\shell\open\command\\'' - C:\WINNT\system32\mshta.exe "%1" %*
HKLM->SOFTWARE\Classes\.js\\'' - JSFile
HKLM->SOFTWARE\Classes\jsfile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.jse\\'' - JSEFile
HKLM->SOFTWARE\Classes\jsefile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.scr\\'' - scrfile
HKLM->SOFTWARE\Classes\scrfile\shell\open\command\\'' - "%1" /S
HKLM->SOFTWARE\Classes\.vbe\\'' - VBEFile
HKLM->SOFTWARE\Classes\vbefile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.vbs\\'' - VBSFile
HKLM->SOFTWARE\Classes\vbsfile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.wsf\\'' - WSFFile
HKLM->SOFTWARE\Classes\wsffile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.wsh\\'' - WSHFile
HKLM->SOFTWARE\Classes\wshfile\shell\open\command\\'' - %SystemRoot%\System32\WScript.exe "%1" %*
HKLM->SOFTWARE\Classes\.txt\\'' - txtfile
HKLM->SOFTWARE\Classes\txtfile\shell\open\command\\'' - %SystemRoot%\system32\NOTEPAD.EXE %1
[>> Registry Run Keys <<]
HKLM->Run\\AVG7_CC - C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP (GRISOFT, s.r.o. )
HKLM->Run\\AVG7_EMC - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe (GRISOFT, s.r.o. )
HKLM->Run\\NGClient - D:\Program Files\Symantec\Ghost\ngctw32.exe (Symantec New Zealand Limited )
HKLM->Run\\PD0620 STISvc - RunDLL32.exe P0620Pin.dll,RunDLL32EP 513 (Microsoft Corporation )
HKLM->Run\\SunJavaUpdateSched - C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe (Sun Microsystems, Inc. )
HKLM->Run\\Synchronization Manager - mobsync.exe /logon (Microsoft Corporation )
HKLM->Run\\Tweak UI - RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp (Microsoft Corporation )
HKLM->RunServices\\MS Java for Windows NT, XP & ME - xpjavams.exe ( )
HKLM->RunServices\\MS Java Service Wrapper for Windows NT & XP - wrapper.exe ( )
HKLM->Run\OptionalComponents\IMAIL - Installed = 1
HKLM->Run\OptionalComponents\MAPI - Installed = 1
HKLM->Run\OptionalComponents\MSFS - Installed = 1
HKCU->Run\\AVG7_Run - C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (GRISOFT, s.r.o. )
HKCU->Run\\internat.exe - internat.exe (Microsoft Corporation )
HKCU->RunServices\\MS Java for Windows NT, XP & ME - xpjavams.exe ( )
HKCU->RunServices\\MS Java Service Wrapper for Windows NT & XP - wrapper.exe ( )
[>> Miscellaneous Startup Keys <<]
[AppInit DLLs]
AppInit_DLL - (File not found))
[Image File Execution Options]
Your Image File Name Here without a path - Debugger = ntsd -d
[Shell Service Object Delay Load]
Network.ConnectionTray - {7007ACCF-3202-11D1-AAD2-00805FC1270E} = C:\WINNT\system32\NETSHELL.dll (Microsoft Corporation )
SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} = stobject.dll (Microsoft Corporation )
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\system32\webcheck.dll (Microsoft Corporation )
[Shell Execute Hooks]
{AEB6717E-7E19-11d0-97EE-00C04FD91972} - URL Exec Hook = shell32.dll (Microsoft Corporation )
[Shared Task Scheduler]
{438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader = %SystemRoot%\system32\browseui.dll (Microsoft Corporation )
{8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon = %SystemRoot%\system32\browseui.dll (Microsoft Corporation )
[SafeBoot Option]
[HKLM Command Processor AutoRun]
HKLM->Command Processor\\AutoRun -
[HKCU Command Processor AutoRun]
[Security Providers]
SecurityProviders\\SecurityProviders - msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
[BootExecute]
Session Manager\\BootExecute - autocheck autochk *;
[PendingFileRenameOperations]
[FileRenameOperations]
[ExcludeFromKnownDlls]
Session Manager\\ExcludeFromKnownDlls -
[>> Disabled MSConfig Items <<]
[>> User Agent Post Platform <<]
[>> Winlogon <<]
HMLM->UserInit - C:\WINNT\system32\userinit.exe,xpjavams.exe (File not found))
HKLM->Shell - Explorer.exe xpjavams.exe (File not found))
HKLM->System - (File not found))
HKLM->VMApplet - rundll32 shell32,Control_RunDLL "sysdm.cpl"
Notify\crypt32chain - crypt32.dll (Microsoft Corporation )
Notify\cryptnet - cryptnet.dll (Microsoft Corporation )
Notify\cscdll - cscdll.dll (Microsoft Corporation )
Notify\PCANotify - PCANotify.dll (Symantec Corporation )
Notify\sclgntfy - sclgntfy.dll (Microsoft Corporation )
Notify\SensLogn - WlNotify.dll (Microsoft Corporation )
Notify\wzcnotif - wzcdlg.dll (Microsoft Corporation )
[>> DNS Name Servers <<]
{43C27F81-2F7A-49CA-8E23-676C7D944DA4} - (Intel® PRO/100 VE Network Connection)
{87F6BCED-71DA-48FE-AE65-AA211D84D10B} - (Intel® PRO/100 VE Network Connection)
[>> All Winsock2 Catalogs <<]
NameSpace_Catalog5\Catalog_Entries\000000000001 - %SystemRoot%\System32\rnr20.dll (Microsoft Corporation )
NameSpace_Catalog5\Catalog_Entries\000000000002 - %SystemRoot%\System32\winrnr.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\system32\msafd.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\system32\msafd.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\system32\msafd.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\system32\rsvpsp.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\system32\rsvpsp.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\system32\msafd.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\system32\msafd.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\system32\msafd.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\system32\msafd.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\system32\msafd.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\system32\msafd.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000012 - %SystemRoot%\system32\msafd.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000013 - %SystemRoot%\system32\msafd.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000014 - %SystemRoot%\system32\msafd.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000015 - %SystemRoot%\system32\msafd.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000016 - %SystemRoot%\system32\msafd.dll (Microsoft Corporation )
Protocol_Catalog9\Catalog_Entries\000000000017 - %SystemRoot%\system32\msafd.dll (Microsoft Corporation )
[>> Protocol Handlers (Non-Microsoft only) <<]
ipp - (File not found))
msdaipp - (File not found))
vnd.ms.radio - C:\WINNT\system32\msdxm.ocx ( )
[>> Protocol Filters (Non-Microsoft only) <<]
< All Services >
Abiosdsk (Abiosdsk) - (File not found)) [Disabled - Stopped - Kernel driver]
abp480n5 (abp480n5) - (File not found)) [Disabled - Stopped - Kernel driver]
Microsoft ACPI Driver (ACPI) - \SystemRoot\System32\DRIVERS\ACPI.sys (Microsoft Corporation ) [ - Running - Kernel driver]
ACPIEC (ACPIEC) - (File not found)) [Disabled - Stopped - Kernel driver]
adpu160m (adpu160m) - (File not found)) [Disabled - Stopped - Kernel driver]
AFD Networking Support Environment (AFD) - \SystemRoot\System32\drivers\afd.sys (Microsoft Corporation ) [Automatic - Running - Kernel driver]
Aha154x (Aha154x) - (File not found)) [Disabled - Stopped - Kernel driver]
aic116x (aic116x) - (File not found)) [Disabled - Stopped - Kernel driver]
aic78u2 (aic78u2) - (File not found)) [Disabled - Stopped - Kernel driver]
aic78xx (aic78xx) - (File not found)) [Disabled - Stopped - Kernel driver]
Alerter (Alerter) - C:\WINNT\System32\services.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in a shared process]
ami0nt (ami0nt) - (File not found)) [Disabled - Stopped - Kernel driver]
amsint (amsint) - (File not found)) [Disabled - Stopped - Kernel driver]
Application Management (AppMgmt) - C:\WINNT\system32\services.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in a shared process]
asc (asc) - (File not found)) [Disabled - Stopped - Kernel driver]
asc3350p (asc3350p) - (File not found)) [Disabled - Stopped - Kernel driver]
asc3550 (asc3550) - (File not found)) [Disabled - Stopped - Kernel driver]
RAS Asynchronous Media Driver (AsyncMac) - System32\DRIVERS\asyncmac.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
Standard IDE/ESDI Hard Disk Controller (atapi) - \SystemRoot\System32\DRIVERS\atapi.sys (Microsoft Corporation ) [ - Running - Kernel driver]
Atdisk (Atdisk) - (File not found)) [Disabled - Stopped - Kernel driver]
ATM ARP Client Protocol (Atmarpc) - System32\DRIVERS\atmarpc.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
Audio Stub Driver (audstub) - System32\DRIVERS\audstub.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver]
AVG7 Alert Manager Server (Avg7Alrt) - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (GRISOFT, s.r.o. ) [Automatic - Stopped - Win32, running in it's own process]
AVG7 Kernel (Avg7Core) - \SystemRoot\System32\Drivers\avg7core.sys (GRISOFT, s.r.o. ) [ - Running - Kernel driver]
AVG7 Rezident Driver (Avg7RsNT) - \SystemRoot\System32\Drivers\avg7rsnt.sys (GRISOFT, s.r.o. ) [ - Running - Kernel driver]
AVG7 Wrap Driver (Avg7RsW) - \SystemRoot\System32\Drivers\avg7rsw.sys (GRISOFT, s.r.o. ) [ - Running - Kernel driver]
AVG7 Update Service (Avg7UpdSvc) - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe (GRISOFT, s.r.o. ) [Automatic - Stopped - Win32, running in it's own process]
AVG Network Redirector (AvgTdi) - \??\C:\WINNT\System32\Drivers\avgtdi.sys (GRISOFT, s.r.o. ) [Automatic - Running - Kernel driver]
pcAnywhere Host Service (awhost32) - C:\Program Files\Symantec\pcAnywhere\awhost32.exe (Symantec Corporation ) [Automatic - Running - Win32, running in it's own process]
awlegacy (awlegacy) - \SystemRoot\System32\Drivers\awlegacy.sys (Symantec Corporation ) [ - Running - Kernel driver]
AW_HOST (AW_HOST) - system32\drivers\aw_host5.sys (Symantec Corporation ) [Disabled - Stopped - Kernel driver]
Beep (Beep) - (File not found)) [ - Running - Kernel driver]
Background Intelligent Transfer Service (BITS) - C:\WINNT\System32\svchost.exe -k BITSgroup (Microsoft Corporation ) [On Demand - Stopped - Win32, running in a shared process]
Computer Browser (Browser) - C:\WINNT\System32\services.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in a shared process]
BusLogic (BusLogic) - (File not found)) [Disabled - Stopped - Kernel driver]
Closed Caption Decoder (ccdecode) - system32\drivers\ccdecode.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
cd20xrnt (cd20xrnt) - (File not found)) [Disabled - Stopped - Kernel driver]
Cdaudio (Cdaudio) - (File not found)) [ - Stopped - Kernel driver]
Cdfs (Cdfs) - (File not found)) [Disabled - Running - Filesystem driver]
CD-ROM Driver (Cdrom) - System32\DRIVERS\cdrom.sys (Microsoft Corporation ) [ - Running - Kernel driver]
Changer (Changer) - (File not found)) [ - Stopped - Kernel driver]
Indexing Service (cisvc) - C:\WINNT\System32\cisvc.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in a shared process]
ClipBook (ClipSrv) - C:\WINNT\system32\clipsrv.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in it's own process]
Cpqarray (Cpqarray) - (File not found)) [Disabled - Stopped - Kernel driver]
cpqarry2 (cpqarry2) - (File not found)) [Disabled - Stopped - Kernel driver]
cpqfcalm (cpqfcalm) - (File not found)) [Disabled - Stopped - Kernel driver]
cpqfws2e (cpqfws2e) - (File not found)) [Disabled - Stopped - Kernel driver]
dac960nt (dac960nt) - (File not found)) [Disabled - Stopped - Kernel driver]
deckzpsx (deckzpsx) - (File not found)) [Disabled - Stopped - Kernel driver]
DHCP Client (Dhcp) - C:\WINNT\System32\services.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Disk Driver (Disk) - \SystemRoot\System32\DRIVERS\disk.sys (Microsoft Corporation ) [ - Running - Kernel driver]
Diskperf (Diskperf) - (File not found)) [ - Running - Kernel driver]
Logical Disk Manager Administrative Service (dmadmin) - C:\WINNT\System32\dmadmin.exe /com (VERITAS Software Corp. ) [On Demand - Stopped - Win32, running in a shared process]
dmboot (dmboot) - System32\drivers\dmboot.sys (VERITAS Software Corp. ) [Disabled - Stopped - Kernel driver]
Logical Disk Manager Driver (dmio) - \SystemRoot\System32\drivers\dmio.sys (VERITAS Software Corp. ) [ - Running - Kernel driver]
dmload (dmload) - \SystemRoot\System32\drivers\dmload.sys (VERITAS Software Corp. ) [ - Running - Kernel driver]
Logical Disk Manager (dmserver) - C:\WINNT\System32\services.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Microsoft DirectMusic SW Synth (WDM) (DMusic) - system32\drivers\DMusic.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
DNS Client (Dnscache) - C:\WINNT\System32\services.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Intel® PRO Adapter Driver (E100B) - System32\DRIVERS\e100bnt5.sys (Intel Corporation ) [On Demand - Running - Kernel driver]
e-DiagTools LAN Configuration Agent (edtlancfg) - C:\Program Files\HP\e-DiagTools\Service.exe ( ) [Automatic - Stopped - Win32, running in it's own process]
EFS (EFS) - (File not found)) [Disabled - Running - Filesystem driver]
Event Log (Eventlog) - C:\WINNT\system32\services.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
COM+ Event System (EventSystem) - C:\WINNT\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [On Demand - Running - Win32, running in a shared process]
Fastfat (Fastfat) - (File not found)) [Disabled - Stopped - Filesystem driver]
Fax Service (Fax) - C:\WINNT\system32\faxsvc.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in it's own process]
Fd16_700 (Fd16_700) - (File not found)) [Disabled - Stopped - Kernel driver]
Floppy Disk Controller Driver (Fdc) - System32\DRIVERS\fdc.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
Fips (Fips) - (File not found)) [Automatic - Running - Kernel driver]
fireport (fireport) - (File not found)) [Disabled - Stopped - Kernel driver]
flashpnt (flashpnt) - (File not found)) [Disabled - Stopped - Kernel driver]
Floppy Disk Driver (Flpydisk) - System32\DRIVERS\flpydisk.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
FltMgr (FltMgr) - \SystemRoot\system32\drivers\fltmgr.sys (Microsoft Corporation ) [ - Running - Filesystem driver]
Volume Manager Driver (Ftdisk) - \SystemRoot\System32\DRIVERS\ftdisk.sys (Microsoft Corporation ) [ - Running - Kernel driver]
Gernuwa (Gernuwa) - (File not found)) [ - Running - Kernel driver]
GhostPostConfig - Boot Phase Driver (GhPostConfig) - \SystemRoot\System32\Drivers\ghpcw2k.sys (Symantec Corporation ) [ - Stopped - Kernel driver]
GhostPostConfig - Auto Phase Driver (GhPostConfig_Auto) - System32\Drivers\ghpcw2k.sys (Symantec Corporation ) [Automatic - Stopped - Kernel driver]
Generic Packet Classifier (Gpc) - System32\DRIVERS\msgpc.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver]
i8042 Keyboard and PS/2 Mouse Port Driver (i8042prt) - System32\DRIVERS\i8042prt.sys (Microsoft Corporation ) [ - Running - Kernel driver]
i81x (i81x) - System32\DRIVERS\i81xnt5.sys (Intel Corporation ) [On Demand - Running - Kernel driver]
Service for AC'97 Driver (WDM) (ichaud) - system32\drivers\ichaud.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
idebd (idebd) - \SystemRoot\System32\DRIVERS\idebd.sys (Intel Corporation ) [ - Running - Kernel driver]
ini910u (ini910u) - (File not found)) [Disabled - Stopped - Kernel driver]
IntelATA (IntelATA) - \SystemRoot\System32\DRIVERS\intelata.sys (Intel Corporation ) [ - Running - Kernel driver]
IntelIde (IntelIde) - (File not found)) [Disabled - Stopped - Kernel driver]
IP Traffic Filter Driver (IpFilterDriver) - System32\DRIVERS\ipfltdrv.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
IP in IP Tunnel Driver (IpInIp) - System32\DRIVERS\ipinip.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
IP Network Address Translator (IpNat) - System32\DRIVERS\ipnat.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
IPSEC driver (IPSEC) - System32\DRIVERS\ipsec.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver]
ipsraidn (ipsraidn) - (File not found)) [Disabled - Stopped - Kernel driver]
IR Enumerator Service (IRENUM) - System32\DRIVERS\irenum.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
PnP ISA/EISA Bus Driver (isapnp) - \SystemRoot\System32\DRIVERS\isapnp.sys (Microsoft Corporation ) [ - Running - Kernel driver]
Keyboard Class Driver (Kbdclass) - System32\DRIVERS\kbdclass.sys (Microsoft Corporation ) [ - Running - Kernel driver]
Microsoft Kernel Wave Audio Mixer (kmixer) - system32\drivers\kmixer.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver]
KSecDD (KSecDD) - (File not found)) [ - Running - Kernel driver]
Server (lanmanserver) - C:\WINNT\System32\services.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Workstation (lanmanworkstation) - C:\WINNT\System32\services.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
lbrtfdc (lbrtfdc) - (File not found)) [ - Stopped - Kernel driver]
TCP/IP NetBIOS Helper Service (LmHosts) - C:\WINNT\System32\services.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
lp6nds35 (lp6nds35) - (File not found)) [Disabled - Stopped - Kernel driver]
Messenger (Messenger) - C:\WINNT\System32\services.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Microsoft Logon Service (Microsoft Logon Service) - "C:\WINNT\system32\dllcache\mslogon.exe" ( ) [Automatic - Running - Win32, running in it's own process]
mnmdd (mnmdd) - (File not found)) [ - Running - Kernel driver]
NetMeeting Remote Desktop Sharing (mnmsrvc) - C:\WINNT\System32\mnmsrvc.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in it's own process]
Modem (Modem) - (File not found)) [On Demand - Stopped - Kernel driver]
Mouse Class Driver (Mouclass) - System32\DRIVERS\mouclass.sys (Microsoft Corporation ) [ - Running - Kernel driver]
MountMgr (MountMgr) - (File not found)) [ - Running - Kernel driver]
BDA MPE Filter (MPE) - system32\DRIVERS\MPE.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
mraid35x (mraid35x) - (File not found)) [Disabled - Stopped - Kernel driver]
MRXSMB (MRxSmb) - System32\DRIVERS\mrxsmb.sys (Microsoft Corporation ) [ - Running - Filesystem driver]
MSCom (MSCom) - "C:\WINNT\system32\dllcache\mscom.exe" ( ) [Automatic - Running - Win32, running in it's own process]
Distributed Transaction Coordinator (MSDTC) - C:\WINNT\System32\msdtc.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in it's own process]
Msfs (Msfs) - (File not found)) [ - Running - Filesystem driver]
Windows Installer (MSIServer) - C:\WINNT\system32\msiexec.exe /V (Microsoft Corporation ) [On Demand - Stopped - Win32, running in a shared process]
Microsoft Streaming Service Proxy (MSKSSRV) - system32\drivers\MSKSSRV.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
Microsoft Streaming Clock Proxy (MSPCLOCK) - system32\drivers\MSPCLOCK.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
Microsoft Streaming Quality Manager Proxy (MSPQM) - system32\drivers\MSPQM.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
Microsoft Streaming Tee/Sink-to-Sink Converter (MSTEE) - system32\drivers\MSTEE.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
Mup (Mup) - (File not found)) [ - Running - Filesystem driver]
NABTS/FEC VBI Codec (NABTSFEC) - system32\DRIVERS\NABTSFEC.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
Ncrc710 (Ncrc710) - (File not found)) [Disabled - Stopped - Kernel driver]
NDIS System Driver (NDIS) - (File not found)) [ - Running - Kernel driver]
Remote Access NDIS TAPI Driver (NdisTapi) - System32\DRIVERS\ndistapi.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver]
NDIS Usermode I/O Protocol (Ndisuio) - System32\DRIVERS\ndisuio.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
Remote Access NDIS WAN Driver (NdisWan) - System32\DRIVERS\ndiswan.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver]
NDIS Proxy (NDProxy) - (File not found)) [On Demand - Running - Kernel driver]
NetBIOS Interface (NetBIOS) - System32\DRIVERS\netbios.sys (Microsoft Corporation ) [ - Running - Filesystem driver]
NetBios over Tcpip (NetBT) - System32\DRIVERS\netbt.sys (Microsoft Corporation ) [ - Running - Kernel driver]
Network DDE (NetDDE) - C:\WINNT\system32\netdde.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in a shared process]
Network DDE DSDM (NetDDEdsdm) - C:\WINNT\system32\netdde.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in a shared process]
NetDetect (NetDetect) - \SystemRoot\system32\drivers\netdtect.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
Net Logon (Netlogon) - C:\WINNT\System32\lsass.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in a shared process]
Network Connections (Netman) - C:\WINNT\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [On Demand - Running - Win32, running in a shared process]
Symantec Ghost Client Agent (NGClient) - D:\Program Files\Symantec\Ghost\ngctw32.exe (Symantec New Zealand Limited ) [Automatic - Running - Win32, running in it's own process]
Npfs (Npfs) - (File not found)) [ - Running - Filesystem driver]
Ntfs (Ntfs) - (File not found)) [Disabled - Running - Filesystem driver]
NT LM Security Support Provider (NtLmSsp) - C:\WINNT\System32\lsass.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in a shared process]
Removable Storage (NtmsSvc) - C:\WINNT\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Null (Null) - (File not found)) [ - Running - Kernel driver]
IPX Traffic Filter Driver (NwlnkFlt) - System32\DRIVERS\nwlnkflt.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
IPX Traffic Forwarder Driver (NwlnkFwd) - System32\DRIVERS\nwlnkfwd.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
Parallel class driver (Parallel) - System32\DRIVERS\parallel.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver]
Parallel port driver (Parport) - System32\DRIVERS\parport.sys (Microsoft Corporation ) [ - Running - Kernel driver]
PartMgr (PartMgr) - (File not found)) [ - Running - Kernel driver]
ParVdm (ParVdm) - (File not found)) [Automatic - Running - Kernel driver]
PCI Bus Driver (PCI) - \SystemRoot\System32\DRIVERS\pci.sys (Microsoft Corporation ) [ - Running - Kernel driver]
PCIDump (PCIDump) - (File not found)) [ - Stopped - Kernel driver]
PCIIde (PCIIde) - System32\DRIVERS\pciide.sys (Microsoft Corporation ) [Disabled - Stopped - Kernel driver]
Pcmcia (Pcmcia) - (File not found)) [Disabled - Stopped - Kernel driver]
Creative WebCam Instant (PD0620VID) - system32\DRIVERS\P0620Vid.sys (Creative Technology Ltd. ) [On Demand - Running - Kernel driver]
Plug and Play (PlugPlay) - C:\WINNT\system32\services.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
IPSEC Policy Agent (PolicyAgent) - C:\WINNT\System32\lsass.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
PPPoEWin Miniport (PPPoEWin) - system32\DRIVERS\PPPoEWin.SYS ( ) [On Demand - Running - Kernel driver]
WAN Miniport (PPTP) (PptpMiniport) - System32\DRIVERS\raspptp.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver]
Protected Storage (ProtectedStorage) - C:\WINNT\system32\services.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Direct Parallel Link Driver (Ptilink) - System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc. ) [On Demand - Running - Kernel driver]
ql1080 (ql1080) - (File not found)) [Disabled - Stopped - Kernel driver]
Ql10wnt (Ql10wnt) - (File not found)) [Disabled - Stopped - Kernel driver]
ql1240 (ql1240) - (File not found)) [Disabled - Stopped - Kernel driver]
ql2100 (ql2100) - (File not found)) [Disabled - Stopped - Kernel driver]
Remote Access Auto Connection Driver (RasAcd) - System32\DRIVERS\rasacd.sys (Microsoft Corporation ) [ - Running - Kernel driver]
Remote Access Auto Connection Manager (RasAuto) - C:\WINNT\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [On Demand - Stopped - Win32, running in a shared process]
WAN Miniport (L2TP) (Rasl2tp) - System32\DRIVERS\rasl2tp.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver]
Remote Access Connection Manager (RasMan) - C:\WINNT\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [On Demand - Running - Win32, running in a shared process]
Direct Parallel (Raspti) - System32\DRIVERS\raspti.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver]
Microsoft Streaming Network Raw Channel Access (RCA) - system32\drivers\RCA.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
Rdbss (Rdbss) - System32\DRIVERS\rdbss.sys (Microsoft Corporation ) [ - Running - Filesystem driver]
Digital CD Audio Playback Filter Driver (redbook) - System32\DRIVERS\redbook.sys (Microsoft Corporation ) [ - Stopped - Kernel driver]
Routing and Remote Access (RemoteAccess) - C:\WINNT\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [Disabled - Stopped - Win32, running in a shared process]
Remote Registry Service (RemoteRegistry) - C:\WINNT\system32\regsvc.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in it's own process]
Remote Procedure Call (RPC) Locator (RpcLocator) - C:\WINNT\System32\locator.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in it's own process]
Remote Procedure Call (RPC) (RpcSs) - C:\WINNT\system32\svchost -k rpcss (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
QoS RSVP (RSVP) - C:\WINNT\System32\rsvp.exe -s (Microsoft Corporation ) [On Demand - Stopped - Win32, running in it's own process]
Security Accounts Manager (SamSs) - C:\WINNT\system32\lsass.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Smart Card Helper (SCardDrv) - C:\WINNT\System32\SCardSvr.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in a shared process]
Smart Card (SCardSvr) - C:\WINNT\System32\SCardSvr.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in a shared process]
Task Scheduler (Schedule) - C:\WINNT\system32\MSTask.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
RunAs Service (seclogon) - C:\WINNT\system32\services.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
System Event Notification (SENS) - C:\WINNT\system32\svchost.exe -k netsvcs (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
Serenum Filter Driver (serenum) - System32\DRIVERS\serenum.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver]
Serial port driver (Serial) - System32\DRIVERS\serial.sys (Microsoft Corporation ) [ - Running - Kernel driver]
Sfloppy (Sfloppy) - (File not found)) [ - Stopped - Kernel driver]
sglfb (sglfb) - (File not found)) [ - Stopped - Kernel driver]
Internet Connection Sharing (SharedAccess) - C:\WINNT\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [Disabled - Stopped - Win32, running in a shared process]
Simbad (Simbad) - (File not found)) [Disabled - Stopped - Kernel driver]
BDA Slip De-Framer (SLIP) - system32\DRIVERS\SLIP.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
smwdm (smwdm) - system32\drivers\smwdm.sys (Analog Devices, Inc. ) [On Demand - Running - Kernel driver]
SNMP Service (SNMP) - C:\WINNT\System32\snmp.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in it's own process]
SNMP Trap Service (SNMPTRAP) - C:\WINNT\System32\snmptrap.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in it's own process]
Sparrow (Sparrow) - (File not found)) [Disabled - Stopped - Kernel driver]
Print Spooler (Spooler) - C:\WINNT\system32\spoolsv.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in it's own process]
Srv (Srv) - System32\DRIVERS\srv.sys (Microsoft Corporation ) [On Demand - Running - Filesystem driver]
Still Image Service (StiSvc) - C:\WINNT\system32\stisvc.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in it's own process]
BDA IPSink (streamip) - system32\DRIVERS\StreamIP.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
Software Bus Driver (swenum) - System32\DRIVERS\swenum.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver]
Microsoft Kernel GS Wavetable Synthesizer (swmidi) - system32\drivers\swmidi.sys (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
symc810 (symc810) - (File not found)) [Disabled - Stopped - Kernel driver]
symc8xx (symc8xx) - (File not found)) [Disabled - Stopped - Kernel driver]
SymEvent (SymEvent) - \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation ) [On Demand - Stopped - Kernel driver]
sym_hi (sym_hi) - (File not found)) [Disabled - Stopped - Kernel driver]
Microsoft System Audio Device (sysaudio) - system32\drivers\sysaudio.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver]
Performance Logs and Alerts (SysmonLog) - C:\WINNT\system32\smlogsvc.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in it's own process]
Telephony (TapiSrv) - C:\WINNT\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [On Demand - Running - Win32, running in a shared process]
TCP/IP Protocol Driver (Tcpip) - System32\DRIVERS\tcpip.sys (Microsoft Corporation ) [ - Running - Kernel driver]
tga (tga) - (File not found)) [ - Stopped - Kernel driver]
Telnet (TlntSvr) - C:\WINNT\system32\tlntsvr.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in it's own process]
Distributed Link Tracking Client (TrkWks) - C:\WINNT\system32\services.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in a shared process]
UdfReadr (UdfReadr) - (File not found)) [ - Running - Filesystem driver]
Udfs (Udfs) - (File not found)) [Disabled - Stopped - Filesystem driver]
Microsoft USB Universal Host Controller Driver (uhcd) - System32\DRIVERS\uhcd.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver]
ultra66 (ultra66) - (File not found)) [Disabled - Stopped - Kernel driver]
Microcode Update Driver (Update) - System32\DRIVERS\update.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver]
Uninterruptible Power Supply (UPS) - C:\WINNT\System32\ups.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in it's own process]
Microsoft USB Standard Hub Driver (usbhub) - System32\DRIVERS\usbhub.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver]
USB Mass Storage Driver (USBSTOR) - System32\DRIVERS\USBSTOR.SYS (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
Utility Manager (UtilMan) - C:\WINNT\System32\UtilMan.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in it's own process]
VgaSave (VgaSave) - \SystemRoot\System32\drivers\vga.sys (Microsoft Corporation ) [ - Running - Kernel driver]
Windows Time (W32Time) - C:\WINNT\System32\services.exe (Microsoft Corporation ) [On Demand - Stopped - Win32, running in a shared process]
Remote Access IP ARP Driver (Wanarp) - System32\DRIVERS\wanarp.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver]
Microsoft WINMM WDM Audio Compatibility Driver (wdmaud) - system32\drivers\wdmaud.sys (Microsoft Corporation ) [On Demand - Running - Kernel driver]
Windows Management Instrumentation (WinMgmt) - C:\WINNT\System32\WBEM\WinMgmt.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in it's own process]
WMDM PMSP Service (WMDM PMSP Service) - C:\WINNT\system32\mspmspsv.exe (Microsoft Corporation ) [Automatic - Running - Win32, running in it's own process]
Windows Management Instrumentation Driver Extensions (Wmi) - C:\WINNT\system32\Services.exe (Microsoft Corporation ) [On Demand - Running - Win32, running in a shared process]
World Standard Teletext Codec (WSTCODEC) - system32\DRIVERS\WSTCODEC.SYS (Microsoft Corporation ) [On Demand - Stopped - Kernel driver]
Automatic Updates (wuauserv) - C:\WINNT\system32\svchost.exe -k wugroup (Microsoft Corporation ) [Disabled - Stopped - Win32, running in a shared process]
Wireless Configuration (WZCSVC) - C:\WINNT\System32\svchost.exe -k netsvcs (Microsoft Corporation ) [On Demand - Stopped - Win32, running in a shared process]
< Files >
%SystemDrive%
%ProgramFilesDir%
%WinDir%
C:\WINNT\lpt$vpn.919 - PECompact2 ( [Ver = | Size = 16257389 bytes | Date = 10/30/2005 12:54 | Attr = ])
C:\WINNT\lpt$vpn.919 - qoologic ( [Ver = | Size = 16257389 bytes | Date = 10/30/2005 12:54 | Attr = ])
C:\WINNT\lpt$vpn.919 - SAHAgent ( [Ver = | Size = 16257389 bytes | Date = 10/30/2005 12:54 | Attr = ])
C:\WINNT\RMAgentOutput.dll - UPX! ( [Ver = | Size = 25157 bytes | Date = 05/03/2005 11:44 | Attr = ])
C:\WINNT\tsc.exe - UPX! (Trend Micro Inc. [Ver = 3.9.0.1020 | Size = 170053 bytes | Date = 01/10/2005 16:17 | Attr = ])
C:\WINNT\VPTNFILE.919 - PECompact2 ( [Ver = | Size = 16257389 bytes | Date = 10/30/2005 12:54 | Attr = ])
C:\WINNT\VPTNFILE.919 - qoologic ( [Ver = | Size = 16257389 bytes | Date = 10/30/2005 12:54 | Attr = ])
C:\WINNT\VPTNFILE.919 - SAHAgent ( [Ver = | Size = 16257389 bytes | Date = 10/30/2005 12:54 | Attr = ])
C:\WINNT\vsapi32.dll - UPX! (Trend Micro Inc. [Ver = 7.510-1002 | Size = 1044560 bytes | Date = 02/18/2005 18:40 | Attr = ])
C:\WINNT\vsapi32.dll - aspack (Trend Micro Inc. [Ver = 7.510-1002 | Size = 1044560 bytes | Date = 02/18/2005 18:40 | Attr = ])
%System%
C:\WINNT\SYSTEM32\DivX.dll - PEC2 (DivXNetworks [Ver = 6,0,0,1571 | Size = 692736 bytes | Date = 06/09/2005 22:32 | Attr = ])
C:\WINNT\SYSTEM32\DivX.dll - PECompact2 (DivXNetworks [Ver = 6,0,0,1571 | Size = 692736 bytes | Date = 06/09/2005 22:32 | Attr = ])
C:\WINNT\SYSTEM32\mfc42u.dll - WSUD (Microsoft Corporation [Ver = 6.00.9586.0 | Size = 1011764 bytes | Date = 06/19/2003 12:05 | Attr = ])
C:\WINNT\SYSTEM32\MRT.exe - PECompact2 (Microsoft Corporation [Ver = 1.17.1478.0 | Size = 5967776 bytes | Date = 06/08/2006 18:19 | Attr = ])
C:\WINNT\SYSTEM32\MRT.exe - aspack (Microsoft Corporation [Ver = 1.17.1478.0 | Size = 5967776 bytes | Date = 06/08/2006 18:19 | Attr = ])
C:\WINNT\SYSTEM32\RASDLG.DLL - Umonitor (Microsoft Corporation [Ver = 5.00.2195.6920 | Size = 531216 bytes | Date = 01/12/2005 21:39 | Attr = ])
C:\WINNT\SYSTEM32\wbdbase.deu - winsync ( [Ver = | Size = 1309184 bytes | Date = 12/07/1999 14:00 | Attr = ])
%System%\Drivers folder and sub-folders
C:\WINNT\SYSTEM32\drivers\avg7core.sys - UPX! (GRISOFT, s.r.o. [Ver = 7,1,0,402 | Size = 777472 bytes | Date = 08/24/2006 21:49 | Attr = ])
C:\WINNT\SYSTEM32\drivers\avg7core.sys - FSG! (GRISOFT, s.r.o. [Ver = 7,1,0,402 | Size = 777472 bytes | Date = 08/24/2006 21:49 | Attr = ])
C:\WINNT\SYSTEM32\drivers\avg7core.sys - PEC2 (GRISOFT, s.r.o. [Ver = 7,1,0,402 | Size = 777472 bytes | Date = 08/24/2006 21:49 | Attr = ])
C:\WINNT\SYSTEM32\drivers\avg7core.sys - aspack (GRISOFT, s.r.o. [Ver = 7,1,0,402 | Size = 777472 bytes | Date = 08/24/2006 21:49 | Attr = ])
%windir% + sub-dirs for System or Hidden files less than 60 days old
C:\WINNT\ShellIconCache - ( [Ver = | Size = 1286842 bytes | Date = 09/15/2006 17:14 | Attr = H ])
C:\WINNT\CSC\00000001 - ( [Ver = | Size = 64 bytes | Date = 09/17/2006 09:53 | Attr = S])
C:\WINNT\CSC\00000002 - ( [Ver = | Size = 64 bytes | Date = 09/17/2006 09:53 | Attr = S])
C:\WINNT\CSC\csc1.tmp - ( [Ver = | Size = 64 bytes | Date = 09/16/2006 22:20 | Attr = S])
C:\WINNT\system32\config\default.LOG - ( [Ver = | Size = 1024 bytes | Date = 09/17/2006 10:20 | Attr = H ])
C:\WINNT\system32\config\SAM.LOG - ( [Ver = | Size = 1024 bytes | Date = 09/17/2006 09:53 | Attr = H ])
C:\WINNT\system32\config\SECURITY.LOG - ( [Ver = | Size = 1024 bytes | Date = 09/17/2006 10:11 | Attr = H ])
C:\WINNT\system32\config\software.LOG - ( [Ver = | Size = 1024 bytes | Date = 09/17/2006 10:20 | Attr = H ])
C:\WINNT\system32\dllcache\mscom.exe - ( [Ver = | Size = 87040 bytes | Date = 08/28/2006 17:58 | Attr = RHS])
C:\WINNT\system32\dllcache\mslogon.exe - ( [Ver = | Size = 89088 bytes | Date = 09/05/2006 00:09 | Attr = RHS])
C:\WINNT\Tasks\SA.DAT - ( [Ver = | Size = 6 bytes | Date = 09/17/2006 09:53 | Attr = H ])
CPL files -
C:\WINNT\SYSTEM32\access.cpl - (Microsoft Corporation [Ver = 5.00.2134.1 | Size = 67344 bytes | Date = 12/07/1999 14:00 | Attr = ])
C:\WINNT\SYSTEM32\appwiz.cpl - (Microsoft Corporation [Ver = 5.00.2195.6624 | Size = 301328 bytes | Date = 06/19/2003 12:05 | Attr = ])
C:\WINNT\SYSTEM32\DESK.CPL - (Microsoft Corporation [Ver = 5.00.2195.6601 | Size = 237328 bytes | Date = 06/19/2003 12:05 | Attr = ])
C:\WINNT\SYSTEM32\hdwwiz.cpl - (Microsoft Corporation [Ver = 5.00.2134.1 | Size = 128272 bytes | Date = 12/07/1999 14:00 | Attr = ])
C:\WINNT\SYSTEM32\igfxcpl.cpl - (Intel Corporation [Ver = 2, 2, 0, 6 | Size = 69632 bytes | Date = 02/12/2001 14:14 | Attr = ])
C:\WINNT\SYSTEM32\inetcpl.cpl - (Microsoft Corporation [Ver = 6.00.2800.1106 | Size = 292352 bytes | Date = 08/29/2002 07:14 | Attr = ])
C:\WINNT\SYSTEM32\intl.cpl - (Microsoft Corporation [Ver = 5.00.2134.1 | Size = 118032 bytes | Date = 12/07/1999 14:00 | Attr = ])
C:\WINNT\SYSTEM32\irprops.cpl - (Microsoft Corporation [Ver = 5.00.2167.1 | Size = 36112 bytes | Date = 12/07/1999 14:00 | Attr = ])
C:\WINNT\SYSTEM32\joy.cpl - (Microsoft Corporation [Ver = 5.1.2600.881 built by: Lab06_N(mmbuild) | Size = 326144 bytes | Date = 10/30/2001 08:10 | Attr = ])
C:\WINNT\SYSTEM32\jpicpl32.cpl - (Sun Microsystems, Inc. [Ver = 5.0.60.5 | Size = 49265 bytes | Date = 11/10/2005 13:03 | Attr = ])
C:\WINNT\SYSTEM32\main.cpl - (Microsoft Corporation [Ver = 5.00.2134.1 | Size = 122128 bytes | Date = 12/07/1999 14:00 | Attr = ])
C:\WINNT\SYSTEM32\mmsys.cpl - (Microsoft Corporation [Ver = 5.00.2161.1 | Size = 303888 bytes | Date = 12/07/1999 14:00 | Attr = ])
C:\WINNT\SYSTEM32\ncpa.cpl - (Microsoft Corporation [Ver = 5.00.2176.1 | Size = 17168 bytes | Date = 12/07/1999 14:00 | Attr = ])
C:\WINNT\SYSTEM32\nwc.cpl - (Microsoft Corporation [Ver = 5.00.2134.1 | Size = 41232 bytes | Date = 12/07/1999 14:00 | Attr = ])
C:\WINNT\SYSTEM32\odbccp32.cpl - (Microsoft Corporation [Ver = 3.520.6200.0 | Size = 41232 bytes | Date = 06/19/2003 12:05 | Attr = ])
C:\WINNT\SYSTEM32\powercfg.cpl - (Microsoft Corporation [Ver = 5.00.3502.6601 | Size = 90896 bytes | Date = 06/19/2003 12:05 | Attr = ])
C:\WINNT\SYSTEM32\sticpl.cpl - (Microsoft Corporation [Ver = 5.00.2195.6656 | Size = 83216 bytes | Date = 06/19/2003 12:05 | Attr = ])
C:\WINNT\SYSTEM32\SYSDM.CPL - (Microsoft Corporation [Ver = 5.00.2195.6601 | Size = 125712 bytes | Date = 06/19/2003 12:05 | Attr = ])
C:\WINNT\SYSTEM32\telephon.cpl - (Microsoft Corporation [Ver = 5.00.2143.1 | Size = 5904 bytes | Date = 12/07/1999 14:00 | Attr = ])
C:\WINNT\SYSTEM32\timedate.cpl - (Microsoft Corporation [Ver = 5.00.2137.1 | Size = 61200 bytes | Date = 12/07/1999 14:00 | Attr = ])
C:\WINNT\SYSTEM32\TWEAKUI.CPL - (Microsoft Corporation [Ver = 1.33.0.0 | Size = 106544 bytes | Date = 06/18/2000 14:03 | Attr = R ])
C:\WINNT\SYSTEM32\wuaucpl.cpl - (Microsoft Corporation [Ver = 5.8.0.2469 built by: lab01_n(wmbla) | Size = 174360 bytes | Date = 05/26/2005 04:16 | Attr = ])
C:\WINNT\SYSTEM32\dllcache\inetcpl.cpl - (Microsoft Corporation [Ver = 6.00.2800.1106 | Size = 292352 bytes | Date = 08/29/2002 07:14 | Attr = ])
C:\WINNT\SYSTEM32\dllcache\msmq.cpl - (Microsoft Corporation [Ver = 5.00.0748 | Size = 64784 bytes | Date = 01/12/2005 21:40 | Attr = ])
C:\WINNT\SYSTEM32\dllcache\mwcpa32.cpl - (IBM Corporation [Ver = 2.60.35.0 | Size = 94208 bytes | Date = 09/23/1999 18:44 | Attr = ])
C:\WINNT\SYSTEM32\dllcache\nwc.cpl - (Microsoft Corporation [Ver = 5.00.2134.1 | Size = 41232 bytes | Date = 12/07/1999 14:00 | Attr = ])
C:\WINNT\SYSTEM32\dllcache\wuaucpl.cpl - (Microsoft Corporation [Ver = 5.8.0.2469 built by: lab01_n(wmbla) | Size = 174360 bytes | Date = 05/26/2005 04:16 | Attr = ])
Auto-Start Folders
HKLM->Explorer\Shell Folders\\Common Startup = C:\Documents and Settings\All Users\Start Menu\Programs\Startup
HKLM->Explorer\User Shell Folders\\Common Startup = %ALLUSERSPROFILE%\Start Menu\Programs\Startup
HKLM->Explorer\Shell Folders\\Startup = C:\Documents and Settings\Administrator.NRS-MEKCSMQ3ZNE.007\Start Menu\Programs\Startup
HKCU->Explorer\User Shell Folders\\Startup = %USERPROFILE%\Start Menu\Programs\Startup
Miscellaneous Auto-Start Files
System.ini->[Boot]\\Shell - Explorer.exe xpjavams.exe
Config.nt: Line 1 - REM Windows MS-DOS Startup File
Config.nt: Line 2 - REM
Config.nt: Line 3 - REM CONFIG.SYS vs CONFIG.NT
Config.nt: Line 4 - REM CONFIG.SYS is not used to initialize the MS-DOS environment.
Config.nt: Line 5 - REM CONFIG.NT is used to initialize the MS-DOS environment unless a
Config.nt: Line 6 - REM different startup file is specified in an application's PIF.
Config.nt: Line 7 - REM
Config.nt: Line 8 - REM ECHOCONFIG
Config.nt: Line 9 - REM By default, no information is displayed when the MS-DOS environment
Config.nt: Line 10 - REM is initialized. To display CONFIG.NT/AUTOEXEC.NT information, add
Config.nt: Line 11 - REM the command echoconfig to CONFIG.NT or other startup file.
Config.nt: Line 12 - REM
Config.nt: Line 13 - REM NTCMDPROMPT
Config.nt: Line 14 - REM When you return to the command prompt from a TSR or while running an
Config.nt: Line 15 - REM MS-DOS-based application, Windows runs COMMAND.COM. This allows the
Config.nt: Line 16 - REM TSR to remain active. To run CMD.EXE, the Windows command prompt,
Config.nt: Line 17 - REM rather than COMMAND.COM, add the command ntcmdprompt to CONFIG.NT or
Config.nt: Line 18 - REM other startup file.
Config.nt: Line 19 - REM
Config.nt: Line 20 - REM DOSONLY
Config.nt: Line 21 - REM By default, you can start any type of application when running
Config.nt: Line 22 - REM COMMAND.COM. If you start an application other than an MS-DOS-based
Config.nt: Line 23 - REM application, any running TSR may be disrupted. To ensure that only
Config.nt: Line 24 - REM MS-DOS-based applications can be started, add the command dosonly to
Config.nt: Line 25 - REM CONFIG.NT or other startup file.
Config.nt: Line 26 - REM
Config.nt: Line 27 - REM EMM
Config.nt: Line 28 - REM You can use EMM command line to configure EMM(Expanded Memory Manager).
Config.nt: Line 29 - REM The syntax is:
Config.nt: Line 30 - REM
Config.nt: Line 31 - REM EMM = [A=AltRegSets] [B=BaseSegment] [RAM]
Config.nt: Line 32 - REM
Config.nt: Line 33 - REM AltRegSets
Config.nt: Line 34 - REM specifies the total Alternative Mapping Register Sets you
Config.nt: Line 35 - REM want the system to support. 1 <= AltRegSets <= 255. The
Config.nt: Line 36 - REM default value is 8.
Config.nt: Line 37 - REM BaseSegment
Config.nt: Line 38 - REM specifies the starting segment address in the Dos conventional
Config.nt: Line 39 - REM memory you want the system to allocate for EMM page frames.
Config.nt: Line 40 - REM The value must be given in Hexdecimal.
Config.nt: Line 41 - REM 0x1000 <= BaseSegment <= 0x4000. The value is rounded down to
Config.nt: Line 42 - REM 16KB boundary. The default value is 0x4000
Config.nt: Line 43 - REM RAM
Config.nt: Line 44 - REM specifies that the system should only allocate 64Kb address
Config.nt: Line 45 - REM space from the Upper Memory Block(UMB) area for EMM page frames
Config.nt: Line 46 - REM and leave the rests(if available) to be used by DOS to support
Config.nt: Line 47 - REM loadhigh and devicehigh commands. The system, by default, would
Config.nt: Line 48 - REM allocate all possible and available UMB for page frames.
Config.nt: Line 49 - REM
Config.nt: Line 50 - REM The EMM size is determined by pif file(either the one associated
Config.nt: Line 51 - REM with your application or _default.pif). If the size from PIF file
Config.nt: Line 52 - REM is zero, EMM will be disabled and the EMM line will be ignored.
Config.nt: Line 53 - REM
Config.nt: Line 54 - dos=high, umb
Config.nt: Line 55 - device=%SystemRoot%\system32\himem.sys
Config.nt: Line 56 - files=40
AutoExec.nt: Line 1 - @echo off
AutoExec.nt: Line 3 - REM AUTOEXEC.BAT is not used to initialize the MS-DOS environment.
AutoExec.nt: Line 4 - REM AUTOEXEC.NT is used to initialize the MS-DOS environment unless a
AutoExec.nt: Line 5 - REM different startup file is specified in an application's PIF.
AutoExec.nt: Line 7 - REM Install CD ROM extensions
AutoExec.nt: Line 8 - lh %SystemRoot%\