Report:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\:
Name:Windows Defender , Path:%ProgramFiles%\Windows Defender\MSASCui.exe -hide
Name:RtHDVCpl , Path:RtHDVCpl.exe
Name:TPwrMain , Path:%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
Name:HSON , Path:%ProgramFiles%\TOSHIBA\TBS\HSON.exe
Name:SmoothView , Path:%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
Name:00TCrdMain , Path:%ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
Name:KeNotify , Path:C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
Name:HWSetup , Path:C:\Program Files\TOSHIBA\Utilities\HWSetup.exe hwSetUP
Name:SVPWUTIL , Path:C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
Name:NDSTray.exe , Path:NDSTray.exe
Name:ccApp , Path:"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
Name:osCheck , Path:"C:\Program Files\Norton Internet Security\osCheck.exe"
Name:NvSvc , Path:RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
Name:NvCplDaemon , Path:RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
Name:NvMediaCenter , Path:RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
Name:SynTPEnh , Path:C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
Name:SynTPStart , Path:C:\Program Files\Synaptics\SynTP\SynTPStart.exe
Name:Wah , Path:C:\Program Files\Common Files\Mdn2.exe
Name:Acrobat Assistant 8.0 , Path:"C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
Name:Symantec PIF AlertEng , Path:"C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
Name:IgfxTray , Path:C:\Windows\system32\igfxtray.exe
Name:HotKeysCmds , Path:C:\Windows\system32\hkcmd.exe
Name:Persistence , Path:C:\Windows\system32\igfxpers.exe
Name:QuickTime Task , Path:"C:\Program Files\QuickTime\QTTask.exe" -atboottime
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\:
Name:TOSCDSPD , Path:TOSCDSPD.EXE
Name:ehTray.exe , Path:C:\Windows\ehome\ehTray.exe
Name:msnmsgr , Path:"C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
Name:WMPNSCFG , Path:C:\Program Files\Windows Media Player\WMPNSCFG.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx\:
HKCC\Software\Microsoft\Windows NT\CurrentVersion\Windows\[Load]:
Value: None
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\[Userinit]:
Value: C:\Windows\system32\userinit.exe,
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\[Shell]:
Value: Explorer.exe
HKLM\SYSTEM\ControlSet001\Control\Session Manager\[BootExecute]:
Value: autocheck autochk *
BHO Items List:
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
InprocServer32:None
ThreadingModel:None
ProgID:None
Programmable:None
TypeLib:None
VersionIndependentProgID:None
{1E8A6170-7264-4D0F-BEAE-D42A53123C75}
InprocServer32:C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
ThreadingModel:Apartment
ProgID:NppBHO.NppBHOObj.1
Programmable:
TypeLib:{954138ED-7951-433C-BAF9-AF1DAD0F4261}
VersionIndependentProgID:NppBHO.NppBHOObj
{22BF413B-C6D2-4d91-82A9-A0F997BA588C}
InprocServer32:C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
ThreadingModel:Apartment
ProgID:ToolBand.SkypeIEHelper.1
Programmable:
TypeLib:{937936AF-28CA-4973-B8AE-F250406149A2}
VersionIndependentProgID:ToolBand.SkypeIEHelper
{3049C3E9-B461-4BC5-8870-4C09146192CA}
InprocServer32:C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
ThreadingModel:apartment
ProgID:rpbrowserrecordplugin.CRPRecordBrowse.1
Programmable:None
TypeLib:{333A04DC-E916-463C-9658-00CAF7A01728}
VersionIndependentProgID:rpbrowserrecordplugin.CRPRecordBrowserH
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
InprocServer32:C:\Program Files\AVG\AVG8\avgssie.dll
ThreadingModel:apartment
ProgID:LinkScannerIE.NavFilter.1
Programmable:None
TypeLib:{5DAB1D4C-D020-41CD-936F-D63FF662E9F7}
VersionIndependentProgID:LinkScannerIE.NavFilter
{53707962-6F74-2D53-2644-206D7942484F}
InprocServer32:E:\2\SDHelper.dll
ThreadingModel:Apartment
ProgID:None
Programmable:None
TypeLib:None
VersionIndependentProgID:None
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
InprocServer32:C:\Program Files\Java\jre1.6.0\bin\ssv.dll
ThreadingModel:Apartment
ProgID:None
Programmable:None
TypeLib:None
VersionIndependentProgID:None
{9030D464-4C02-4ABF-8ECC-5164760863C6}
InprocServer32:C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
ThreadingModel:Apartment
ProgID:IDBHO.IDBrowserExtension.1
Programmable:None
TypeLib:{FD609BF1-0E01-403F-8F20-EA238F5CDCC3}
VersionIndependentProgID:IDBHO.IDBrowserExtension
{AE7CD045-E861-484f-8273-0445EE161910}
InprocServer32:None
ThreadingModel:None
ProgID:None
Programmable:None
TypeLib:None
VersionIndependentProgID:None
File Links List:
.txt: no this file type
.exe: "%1" %*
.com: "%1" %*
.pif: "%1" %*
.bat: "%1" %*
.reg: regedit.exe "%1"
.chm: None
.hlp: %SystemRoot%\winhlp32.exe %1
.ini: %SystemRoot%\system32\NOTEPAD.EXE %1
.inf: %SystemRoot%\system32\NOTEPAD.EXE %1
.vbs: "%SystemRoot%\System32\WScript.exe" "%1" %*
.js: no this file type
.lnk: CLSID: {00021401-0000-0000-C000-000000000046} shell32.dll
Image File Execution Options:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\[AppInit_DLLs]:
Value:
ShellExecuteHooks:
{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} : SABShellExecuteHook Class
InProcServer32:E:\1\SASSEH.DLL
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AeDebug\[Debugger]:
Value: "C:\Windows\system32\vsjitdebugger.exe" -p %ld -e %ld
Kernel Drivers:
blbdrive
DisplayName:None
Description:None
ImagePath:\SystemRoot\system32\drivers\blbdrive.sys [File not found]
ObjectName:None
Start:SERVICE_DISABLED(4)
Type:SERVICE_KERNEL_DRIVER(1)
BlueletAudio
DisplayName:Bluetooth Audio Service
Description:None
ImagePath:system32\DRIVERS\blueletaudio.sys [File not found]
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
BlueletSCOAudio
DisplayName:Bluetooth SCO Audio Service
Description:None
ImagePath:system32\DRIVERS\BlueletSCOAudio.sys [File not found]
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
BT
DisplayName:Bluetooth PAN Network Adapter
Description:None
ImagePath:system32\DRIVERS\btnetdrv.sys [File not found]
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
BTHidEnum
DisplayName:Bluetooth HID Enumerator
Description:None
ImagePath:System32\Drivers\vbtenum.sys [File not found]
ObjectName:None
Start:SERVICE_BOOT_START(0)
Type:SERVICE_KERNEL_DRIVER(1)
BTHidMgr
DisplayName:Bluetooth HID Manager Service
Description:None
ImagePath:System32\Drivers\BTHidMgr.sys [File not found]
ObjectName:None
Start:SERVICE_BOOT_START(0)
Type:SERVICE_KERNEL_DRIVER(1)
catchme
DisplayName:None
Description:None
ImagePath:\??\C:\Combo-Fix\catchme.sys [File not found]
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
gmer
DisplayName:None
Description:None
ImagePath:System32\DRIVERS\gmer.sys
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
IpInIp
DisplayName:IP in IP Tunnel Driver
Description:IP in IP Tunnel Driver
ImagePath:system32\DRIVERS\ipinip.sys [File not found]
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
NetworkX
DisplayName:NetworkX
Description:None
ImagePath:\SystemRoot\system32\ckldrv.sys
ObjectName:None
Start:SERVICE_SYSTEM_START(1)
Type:SERVICE_KERNEL_DRIVER(1)
NIAPSafe
DisplayName:NIAPSafe
Description:None
ImagePath:\??\C:\Users\R\Desktop\NIAP 0.5\NIAPMirrorSystem.sys
ObjectName:None
Start:SERVICE_DISABLED(4)
Type:SERVICE_KERNEL_DRIVER(1)
NwlnkFlt
DisplayName:IPX Traffic Filter Driver
Description:IPX Traffic Filter Driver
ImagePath:system32\DRIVERS\nwlnkflt.sys [File not found]
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
NwlnkFwd
DisplayName:IPX Traffic Forwarder Driver
Description:IPX Traffic Forwarder Driver
ImagePath:system32\DRIVERS\nwlnkfwd.sys [File not found]
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
SASENUM
DisplayName:SASENUM
Description:None
ImagePath:\??\E:\1\SASENUM.SYS
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
SASKUTIL
DisplayName:SASKUTIL
Description:None
ImagePath:\??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys [File not found]
ObjectName:None
Start:SERVICE_SYSTEM_START(1)
Type:SERVICE_KERNEL_DRIVER(1)
sptd
DisplayName:None
Description:None
ImagePath:System32\Drivers\sptd.sys
ObjectName:None
Start:SERVICE_BOOT_START(0)
Type:SERVICE_KERNEL_DRIVER(1)
tap0801
DisplayName:TAP-Win32 Adapter V8
Description:None
ImagePath:system32\DRIVERS\tap0801.sys
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
Tcpip
DisplayName:@%SystemRoot%\system32\tcpipcfg.dll,-50003
Description:@%SystemRoot%\system32\tcpipcfg.dll,-50003
ImagePath:System32\drivers\tcpip.sys
ObjectName:None
Start:SERVICE_SYSTEM_START(1)
Type:SERVICE_KERNEL_DRIVER(1)
Tcpip6
DisplayName:Microsoft IPv6 Protocol Driver
Description:Microsoft IPv6 Protocol Driver
ImagePath:system32\DRIVERS\tcpip.sys
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
TpChoice
DisplayName:Touch Pad Detection Filter driver
Description:None
ImagePath:system32\DRIVERS\TpChoice.sys [File not found]
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
VComm
DisplayName:Virtual Serial port driver
Description:None
ImagePath:system32\DRIVERS\VComm.sys [File not found]
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
VcommMgr
DisplayName:Bluetooth VComm Manager Service
Description:None
ImagePath:System32\Drivers\VcommMgr.sys [File not found]
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
VPCAppSv
DisplayName:Virtual PC Application Services
Description:Provides application services for Virtual PC.
ImagePath:system32\DRIVERS\VPCAppSv.sys
ObjectName:None
Start:SERVICE_AUTO_START(2)
Type:SERVICE_KERNEL_DRIVER(1)
VPCNetS2
DisplayName:Virtual PC Emulated Ethernet Switch Driver
Description:None
ImagePath:system32\DRIVERS\VPCNetS2.sys
ObjectName:None
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_KERNEL_DRIVER(1)
Services:
Adobe LM Service
DisplayName:Adobe LM Service
Description:Adobe LM Service
ImagePath:"C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe"
ObjectName:LocalSystem
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_WIN32_OWN_PROCESS(16)
AppMgmt
DisplayName:None
Description:None
ImagePath:%SystemRoot%\system32\svchost.exe -k netsvcs
ServiceDll:%SystemRoot%\System32\appmgmts.dll [File not found]
ObjectName:None
Start:None
Type:None
AresChatServer
DisplayName:Ares Chatroom server
Description:Hosts your chatroom on the Ares network.
ImagePath:C:\Program Files\Ares\chatServer.exe
ObjectName:LocalSystem
Start:SERVICE_DEMAND_START(3)
Type:None
CardBusService
DisplayName:CardBusService
Description:Latency Timer Service
ImagePath:C:\Program Files\Common Files\AVerMedia\Service\CardBusService.exe
ObjectName:LocalSystem
Start:SERVICE_AUTO_START(2)
Type:SERVICE_WIN32_OWN_PROCESS(16)
CFSvcs
DisplayName:ConfigFree Service
Description:None
ImagePath:C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
ObjectName:LocalSystem
Start:SERVICE_AUTO_START(2)
Type:SERVICE_WIN32_OWN_PROCESS(16)
Crypkey License
DisplayName:Crypkey License
Description:None
ImagePath:crypserv.exe [File not found]
ObjectName:LocalSystem
Start:SERVICE_AUTO_START(2)
Type:SERVICE_WIN32_OWN_PROCESS(16)
FLEXnet Licensing Service
DisplayName:FLEXnet Licensing Service
Description:This service performs licensing functions on behalf of FLEXnet enabled products.
ImagePath:"C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe"
ObjectName:LocalSystem
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_WIN32_OWN_PROCESS(16)
ISPwdSvc
DisplayName:Symantec IS Password Validation
Description:User account management service
ImagePath:"C:\Program Files\Norton Internet Security\isPwdSvc.exe"
ObjectName:LocalSystem
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_WIN32_OWN_PROCESS(16)
LiveUpdate
DisplayName:LiveUpdate
Description:LiveUpdate Core Engine
ImagePath:"C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE"
ObjectName:LocalSystem
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_WIN32_OWN_PROCESS(16)
Symantec Core LC
DisplayName:Symantec Core LC
Description:Symantec Core LC
ImagePath:"C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe"
ObjectName:LocalSystem
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_WIN32_OWN_PROCESS(16)
TODDSrv
DisplayName:TOSHIBA Optical Disc Drive Service
Description:None
ImagePath:C:\Windows\system32\TODDSrv.exe
ObjectName:LocalSystem
Start:SERVICE_AUTO_START(2)
Type:SERVICE_WIN32_OWN_PROCESS(16)
TOSHIBA Bluetooth Service
DisplayName:TOSHIBA Bluetooth Service
Description:None
ImagePath:c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
ObjectName:LocalSystem
Start:SERVICE_AUTO_START(2)
Type:SERVICE_WIN32_OWN_PROCESS(16)
UleadBurningHelper
DisplayName:Ulead Burning Helper
Description:None
ImagePath:C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
ObjectName:LocalSystem
Start:SERVICE_AUTO_START(2)
Type:SERVICE_WIN32_OWN_PROCESS(16)
WinHttpAutoProxySvc
DisplayName:@%SystemRoot%\system32\winhttp.dll,-100
Description:@%SystemRoot%\system32\winhttp.dll,-101
ImagePath:%SystemRoot%\system32\svchost.exe -k LocalService
ServiceDll:winhttp.dll [File not found]
ObjectName:NT AUTHORITY\LocalService
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_WIN32_SHARE_PROCESS(32)
WLSetupSvc
DisplayName:Windows Live Setup Service
Description:Windows Live Setup Service
ImagePath:"C:\Program Files\Windows Live\installer\WLSetupSvc.exe"
ObjectName:LocalSystem
Start:SERVICE_DEMAND_START(3)
Type:SERVICE_WIN32_OWN_PROCESS(16)