Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)
[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = C:\WINNT\System32\setup\wmpocm.exe /ShowWMP
[>{26923b43-4d38-484f-9b9e-de460746276c}] *
StubPath = “C:\WINNT\system32\shmgrate.exe” OCInstallUserConfigIE
[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
StubPath = “C:\WINNT\system32\shmgrate.exe” OCInstallUserConfigOE
[>{A9E8FC4B-FDB2-4F07-8FA5-973302667A77}] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
[{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\mplayer2.inf,PerUserStub.NT
[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = “%ProgramFiles%\Outlook Express\setup50.exe” /APP:OE /CALLER:WINNT /user /install
[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINNT\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
[{6A5110B5-E14B-4268-A065-EF89FF33C325}] *
StubPath = regsvr32.exe /s /n /i:“S 2 true 3 true 4 true 5 true 6 true 7 true” initpki.dll
[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = “%ProgramFiles%\Outlook Express\setup50.exe” /APP:WAB /CALLER:WINNT /user /install
[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll
[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\system32\ie4uinit.exe
[{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}] *
StubPath = %SystemRoot%\system32\updcrl.exe -e -u %SystemRoot%\system32\verisignpub1.crl
Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps
Registry key not found
Load/Run keys from C:\WINNT\WIN.INI:
load=INI section not found
run=INI section not found
Load/Run keys from Registry:
HKLM..\Windows NT\CurrentVersion\WinLogon: load=Registry value not found
HKLM..\Windows NT\CurrentVersion\WinLogon: run=Registry value not found
HKLM..\Windows\CurrentVersion\WinLogon: load=Registry key not found
HKLM..\Windows\CurrentVersion\WinLogon: run=Registry key not found
HKCU..\Windows NT\CurrentVersion\WinLogon: load=Registry value not found
HKCU..\Windows NT\CurrentVersion\WinLogon: run=Registry value not found
HKCU..\Windows\CurrentVersion\WinLogon: load=Registry key not found
HKCU..\Windows\CurrentVersion\WinLogon: run=Registry key not found
HKCU..\Windows NT\CurrentVersion\Windows: load=
HKCU..\Windows NT\CurrentVersion\Windows: run=Registry value not found
HKLM..\Windows NT\CurrentVersion\Windows: load=Registry value not found
HKLM..\Windows NT\CurrentVersion\Windows: run=Registry value not found
HKLM..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=
Shell & screensaver key from C:\WINNT\SYSTEM.INI:
Shell=INI section not found
SCRNSAVE.EXE=INI section not found
drivers=INI section not found
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINNT\system32\sspipes.scr
drivers=Registry value not found
Policies Shell key:
HKCU..\Policies: Shell=Registry key not found
HKLM..\Policies: Shell=Registry value not found
Checking for EXPLORER.EXE instances:
C:\WINNT\Explorer.exe: PRESENT!
C:\Explorer.exe: not present
C:\WINNT\Explorer\Explorer.exe: not present
C:\WINNT\System\Explorer.exe: not present
C:\WINNT\System32\Explorer.exe: not present
C:\WINNT\Command\Explorer.exe: not present
C:\WINNT\Fonts\Explorer.exe: not present
Checking for superhidden extensions:
.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden
Verifying REGEDIT.EXE integrity:
- Regedit.exe found in C:\WINNT
- .reg open command is normal (regedit.exe %1)
- Company name OK: ‘Microsoft Corporation’
- Original filename OK: ‘REGEDIT.EXE’
- File description: ‘Registry Editor’
Registry check passed
Enumerating Browser Helper Objects:
(no name) - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\Program Files\Sun Java\jre1.6.0_01\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
Enumerating Task Scheduler jobs:
No jobs found