There you go
sebastian
StartupList report, 2/9/03, 07:56:39 PM
StartupList version: 1.51
Started from : C:\WINDOWS\DESKTOP\PROGRAMS\STARTUPLIST.EXE
Detected: Windows 98 SE (Win9x 4.10.2222A)
Detected: Internet Explorer v5.51 SP2 (5.51.4807.2300)
* Using default options
==================================================
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGSERV9.EXE
C:\PROGRAM FILES\KERIO\PERSONAL FIREWALL\PERSFW.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAM FILES\GRISOFT\AVG6\AVGCC32.EXE
C:\REGPROT\REGPROT.EXE
C:\PROGRAM FILES\ICONOID\ICONOID.EXE
C:\RAIN\RAIN.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\DESKTOP\PROGRAMS\STARTUPLIST.EXE
--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\WINDOWS\Start Menu\Programs\StartUp]
Rain.lnk = C:\Rain\Rain.exe
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
internat.exe = internat.exe
SystemTray = SysTray.Exe
ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
TaskMonitor = C:\WINDOWS\taskmon.exe
AVG_CC = C:\PROGRAM FILES\GRISOFT\AVG6\avgcc32.exe /startup
Lwinst Run Profiler = C:\Program Files\Logitech\WingMan Profiler\Lwtest.exe /detect /quiet /launch "C:\Program Files\Logitech\WingMan Profiler\Lwpevntm.exe"
RegProt = c:\regprot\regprot.exe /start
ScriptSentry = C:\PROGRAM FILES\SCRIPT SENTRY\SCRIPTSENTRY.exe /check
RivaTunerStartupDaemon = "C:\RIVA TUNER\RIVATUNER.EXE" /S
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
Avgserv9.exe = C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
PersFw = "C:\PROGRAM FILES\KERIO\PERSONAL FIREWALL\PERSFW.EXE"
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Iconoid = "C:\PROGRAM FILES\ICONOID\ICONOID.EXE"
--------------------------------------------------
File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command
(Default) = C:\PROGRAM FILES\SCRIPT SENTRY\SCRIPTSENTRY.exe "%1" %*
--------------------------------------------------
C:\WINDOWS\WININIT.BAK listing:
(Created 2/2/2003, 10:21:2)
[rename]
NUL=C:\WINDOWS\w98setup.bin
NUL=C:\WINDOWS\suback.bin
[NUL]
C:\WINDOWS\SYSTEM\DCOMREG.EXE=1
--------------------------------------------------
C:\AUTOEXEC.BAT listing:
****** PCI AUDIO DOS UTILS *******
C:\WINDOWS\SYSTEM\WaveInit /A220 /I5 /D1 /L388 /U330 /S
C:\WINDOWS\SYSTEM\WAVETSR.COM
LH MSCDEX.EXE /D:MSCD001
mode con codepage prepare=((862) C:\WINDOWS\COMMAND\hebega.cpi)
mode con codepage select=862
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - C:\PROGRA~1\STARDO~1\SDIEINT.DLL - {FFFFFEF0-5B30-21D4-945D-000000000000}
(no name) - (no file) - {206E52E0-D52E-11D4-AD54-0000E86C26F6}
(no name) - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
--------------------------------------------------
Enumerating Task Scheduler jobs:
Tune-up Application Start.job
--------------------------------------------------
Enumerating Download Program Files:
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
CODEBASE =
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
[HouseCall Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\XSCAN53.OCX
CODEBASE =
http://a840.g.akamai.net/7/840/537/20011223/housecall.antivirus.com/housecall/xscan53.cab
[MSN Chat Control 4.2]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\MSNCHAT42.OCX
CODEBASE =
http://fdl.msn.com/public/chat/msnchat42.cab
[YInstStarter Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\YINSTHELPER.DLL
CODEBASE =
http://download.yahoo.com/dl/installs/yinst.cab
[{41F17733-B041-4099-A042-B518BB6A408C}]
CODEBASE =
http://apple.speedera.net/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
--------------------------------------------------
End of report, 5,173 bytes
Report generated in 0.671 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only