these are the results
Microsoft Windows [Version 6.0.6000]
Copyright (c) 2006 Microsoft Corporation. All rights reserved.
C:\Windows\system32>tasklist
Image Name PID Session Name Session# Mem Usage
========================= ======== ================ =========== ============
System Idle Process 0 Services 0 28 K
System 4 Services 0 416 K
smss.exe 388 Services 0 536 K
csrss.exe 452 Services 0 4,300 K
wininit.exe 500 Services 0 2,860 K
csrss.exe 512 Console 1 8,904 K
services.exe 544 Services 0 4,180 K
lsass.exe 560 Services 0 6,448 K
lsm.exe 568 Services 0 2,968 K
winlogon.exe 720 Console 1 4,060 K
svchost.exe 740 Services 0 5,428 K
svchost.exe 800 Services 0 6,640 K
svchost.exe 844 Services 0 12,452 K
svchost.exe 896 Services 0 9,184 K
svchost.exe 924 Services 0 56,320 K
svchost.exe 964 Services 0 17,636 K
audiodg.exe 1028 Services 0 9,728 K
SLsvc.exe 1060 Services 0 3,504 K
svchost.exe 1104 Services 0 8,040 K
svchost.exe 1232 Services 0 9,684 K
spoolsv.exe 1404 Services 0 6,424 K
svchost.exe 1428 Services 0 7,576 K
taskeng.exe 1800 Console 1 8,896 K
dwm.exe 1832 Console 1 57,080 K
explorer.exe 1308 Console 1 42,800 K
AppleMobileDeviceService. 1852 Services 0 2,536 K
avgamsvr.exe 1984 Services 0 544 K
avgupsvc.exe 1712 Services 0 884 K
avgrssvc.exe 1760 Services 0 2,884 K
avgemc.exe 1332 Services 0 1,824 K
avgrssvc.exe 1568 Services 0 16,428 K
svchost.exe 700 Services 0 3,216 K
CLCapSvc.exe 1628 Services 0 5,752 K
svchost.exe 2036 Services 0 5,576 K
LSSrvc.exe 1080 Services 0 2,488 K
svchost.exe 916 Services 0 2,280 K
svchost.exe 1112 Services 0 3,160 K
svchost.exe 1068 Services 0 3,036 K
svchost.exe 1040 Services 0 4,200 K
svchost.exe 1580 Services 0 1,756 K
SearchIndexer.exe 1608 Services 0 20,768 K
XAudio.exe 1012 Services 0 1,868 K
hpqwmiex.exe 1016 Services 0 3,788 K
CLSched.exe 2364 Services 0 3,992 K
taskeng.exe 2748 Services 0 4,100 K
MSASCui.exe 2940 Console 1 9,932 K
SynTPEnh.exe 2948 Console 1 4,136 K
QPService.exe 3048 Console 1 8,196 K
QLBCTRL.exe 3072 Console 1 4,568 K
WiFiMsg.exe 3148 Console 1 3,548 K
HPWAMain.exe 3184 Console 1 4,108 K
rundll32.exe 3192 Console 1 3,220 K
jusched.exe 3200 Console 1 2,656 K
avgcc.exe 3236 Console 1 1,116 K
WmiPrvSE.exe 3256 Services 0 3,840 K
hpwuSchd2.exe 3296 Console 1 2,604 K
winampa.exe 3336 Console 1 3,612 K
iTunesHelper.exe 3352 Console 1 5,808 K
realsched.exe 3380 Console 1 192 K
sidebar.exe 3388 Console 1 27,828 K
ehtray.exe 3400 Console 1 956 K
mRouterConfig.exe 3408 Console 1 4,632 K
YahooMessenger.exe 3556 Console 1 33,696 K
ehmsas.exe 3600 Console 1 3,144 K
btdna.exe 3612 Console 1 5,968 K
VeohClient.exe 3636 Console 1 14,500 K
BTTray.exe 3668 Console 1 7,016 K
hpqtra08.exe 3812 Console 1 8,284 K
HPQTOA~1.EXE 2744 Console 1 4,068 K
mRouterRuntime.exe 3172 Console 1 5,360 K
hpqste08.exe 3440 Console 1 5,056 K
BTStackServer.exe 2100 Console 1 7,448 K
iPodService.exe 3960 Services 0 3,724 K
HPHC_Service.exe 4460 Services 0 9,180 K
svchost.exe 1792 Services 0 3,556 K
ieuser.exe 5764 Console 1 9,988 K
iexplore.exe 6036 Console 1 103,240 K
winampTbServer.exe 3308 Console 1 7,036 K
hpswp_clipbook.exe 5780 Console 1 4,168 K
avgwb.dat 2392 Console 1 68,288 K
SearchProtocolHost.exe 2428 Services 0 8,224 K
SearchFilterHost.exe 4900 Services 0 4,464 K
taskmgr.exe 4772 Console 1 10,228 K
cmd.exe 5832 Console 1 1,952 K
tasklist.exe 5632 Console 1 4,504 K
WmiPrvSE.exe 3088 Services 0 5,412 K
C:\Windows\system32>reg query "hklm\software\microsoft\windows nt\currentver
\winlogon"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon
ReportBootOk REG_SZ 1
Shell REG_SZ Explorer.exe C:\WINDOWS\Config\csrss.exe
Userinit REG_SZ C:\Windows\system32\userinit.exe,
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
AutoRestartShell REG_DWORD 0x1
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ShutdownWithoutLogon REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0x0
passwordexpirywarning REG_DWORD 0xe
Background REG_SZ 0 0 0
DebugServerCommand REG_SZ no
WinStationsDisabled REG_SZ 0
DisableCAD REG_DWORD 0x1
scremoveoption REG_SZ 0
ShutdownFlags REG_DWORD 0x80000027
AutoLogonCount REG_DWORD 0x1
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\GPE
sions
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\Not
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\Aut
onChecked
C:\Windows\system32>