StartupList report, 3/12/2010, 12:45:56 PM StartupList version: 1.52.2 Started from : C:\Program Files\TrendMicro\HiJackThis\HiJackThis.EXE Detected: Windows XP SP3 (WinNT 5.01.2600) Detected: Internet Explorer v8.00 (8.00.6001.18702) * Using default options * Showing rarely important sections ================================================== Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe c:\Program Files\Microsoft Security Essentials\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\AOL\1139276051\ee\AOLSoftware.exe C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe C:\Program Files\Nero\Nero8\InCD\NBHGui.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\Microsoft Security Essentials\msseces.exe C:\Program Files\Nero\Nero8\InCD\InCD.exe C:\Program Files\HP\HP Software Update\HPWuSchd.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\AOL\Active Security Monitor\ASMonitor.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe C:\Documents and Settings\Linda Gail\Application Data\CA462682FB2EB0AA253B0AA161DDE992\dbf70700.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\wanmpsvc.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\AOL 9.5\waol.exe C:\Program Files\AOL 9.5\shellmon.exe C:\WINDOWS\explorer.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe -------------------------------------------------- Listing of startup folders: Shell folders Common Startup: [C:\Documents and Settings\All Users\Start Menu\Programs\Startup] HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe -------------------------------------------------- Checking Windows NT UserInit: [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] UserInit = C:\WINDOWS\system32\userinit.exe, -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run HostManager = C:\Program Files\Common Files\AOL\1139276051\ee\AOLSoftware.exe IgfxTray = C:\WINDOWS\system32\igfxtray.exe HotKeysCmds = C:\WINDOWS\system32\hkcmd.exe QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime UpdateManager = "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r SunJavaUpdateSched = C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe SecurDisc = C:\Program Files\Nero\Nero8\InCD\NBHGui.exe RealTray = C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER Pure Networks Port Magic = "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run NeroFilterCheck = C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe MSSE = "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey InCD = C:\Program Files\Nero\Nero8\InCD\InCD.exe HP Software Update = "C:\Program Files\HP\HP Software Update\HPWuSchd.exe" HP Component Manager = "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" dla = C:\WINDOWS\system32\dla\tfswctrl.exe ATIPTA = C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe ASM = "C:\Program Files\AOL\Active Security Monitor\ASMonitor.exe" HIDEMAIN -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe DW6 = "C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" Messenger (Yahoo!) = "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet Search Protection = C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe MSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /background IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} = "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 dbf70700.exe = C:\Documents and Settings\Linda Gail\Application Data\CA462682FB2EB0AA253B0AA161DDE992\dbf70700.exe AOL Fast Start = "C:\Program Files\AOL 9.5\AOL.EXE" -b -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce Shockwave Updater = C:\WINDOWS\SYSTEM32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1103472 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://www8.agame.com/games/shockwave/p/power_driving/power_driving_agame_com.htm" -------------------------------------------------- Enumerating Active Setup stub paths: HKLM\Software\Microsoft\Active Setup\Installed Components (* = disabled by HKCU twin) [<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}] * StubPath = C:\WINDOWS\system32\ieudinit.exe [>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP [>{26923b43-4d38-484f-9b9e-de460746276c}] * StubPath = C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig [>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] * StubPath = "C:\WINDOWS\system32\rundll32.exe" "C:\WINDOWS\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP [>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] * StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE [{10880D85-AAD9-4558-ABDC-2AB1552D831F}] * StubPath = "C:\Program Files\Common Files\LightScribe\LSRunOnce.exe" [{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] * StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll [{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] * StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install [{7790769C-0471-11d2-AF11-00C04FA35D02}] * StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install [{89820200-ECBD-11cf-8B85-00AA005B4340}] * StubPath = regsvr32.exe /s /n /i:U shell32.dll [{89820200-ECBD-11cf-8B85-00AA005B4383}] * StubPath = C:\WINDOWS\system32\ie4uinit.exe -BaseSettings [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] * StubPath = c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install -------------------------------------------------- Shell & screensaver key from C:\WINDOWS\SYSTEM.INI: Shell=*INI section not found* SCRNSAVE.EXE=*INI section not found* drivers=*INI section not found* Shell & screensaver key from Registry: Shell=Explorer.exe SCRNSAVE.EXE=C:\WINDOWS\system32\logon.scr drivers=*Registry value not found* Policies Shell key: HKCU\..\Policies: Shell=*Registry value not found* HKLM\..\Policies: Shell=*Registry value not found* -------------------------------------------------- Checking for EXPLORER.EXE instances: C:\WINDOWS\Explorer.exe: PRESENT! C:\Explorer.exe: not present C:\WINDOWS\Explorer\Explorer.exe: not present C:\WINDOWS\System\Explorer.exe: not present C:\WINDOWS\System32\Explorer.exe: not present C:\WINDOWS\Command\Explorer.exe: not present C:\WINDOWS\Fonts\Explorer.exe: not present -------------------------------------------------- Checking for superhidden extensions: .lnk: HIDDEN! (arrow overlay: yes) .pif: HIDDEN! (arrow overlay: yes) .exe: not hidden .com: not hidden .bat: not hidden .hta: not hidden .scr: not hidden .shs: HIDDEN! .shb: HIDDEN! .vbs: not hidden .vbe: not hidden .wsh: not hidden .scf: HIDDEN! (arrow overlay: NO!) .url: HIDDEN! (arrow overlay: yes) .js: not hidden .jse: not hidden -------------------------------------------------- Enumerating Browser Helper Objects: (no name) - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll - {02478D38-C3F9-4EFB-9B51-7695ECA05670} AOL Toolbar Loader - C:\Program Files\AOL Toolbar\aoltb.dll - {3ef64538-8b54-4573-b48f-4d34b0238ab2} (no name) - C:\Program Files\Yahoo!\Common\yiesrvc.dll - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} (no name) - C:\WINDOWS\system32\dla\tfswshx.dll - {5CA3D70E-1895-11CF-8E15-001234567890} (no name) - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll - {9030D464-4C02-4ABF-8ECC-5164760863C6} (no name) - C:\Program Files\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} -------------------------------------------------- Enumerating Task Scheduler jobs: MP Scheduled Scan.job TraditionalTaskUserS-1-5-21-1213626551-43752332-793207223-1008.job User_Feed_Synchronization-{AC0E6C7C-CC4B-4263-BC92-379440EC5790}.job -------------------------------------------------- Enumerating Download Program Files: [QuickTime Object] InProcServer32 = C:\Program Files\QuickTime\QTPlugin.ocx CODEBASE = http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab [Office Genuine Advantage Validation Tool] InProcServer32 = C:\WINDOWS\system32\OGACheckControl.DLL CODEBASE = http://download.microsoft.com/download/e/7/3/e7345c16-80aa-4488-ae10-9ac6be844f99/OGAControl.cab [Microsoft Data Collection Control] InProcServer32 = C:\WINDOWS\Downloaded Program Files\MSDcode.dll CODEBASE = https://support.microsoft.com/OAS/ActiveX/MSDcode.cab [Shockwave ActiveX Control] InProcServer32 = C:\WINDOWS\system32\Adobe\Director\SwDir.dll CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab [Windows Genuine Advantage Validation Tool] InProcServer32 = C:\WINDOWS\system32\LegitCheckControl.DLL CODEBASE = http://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab [Shockwave ActiveX Control] InProcServer32 = C:\WINDOWS\SYSTEM32\Adobe\Director\swdir.dll CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab [Installation Support] InProcServer32 = C:\Program Files\Yahoo!\Common\Yinsthelper.dll CODEBASE = C:\Program Files\Yahoo!\Common\Yinsthelper.dll [SysData Class] InProcServer32 = C:\WINDOWS\DOWNLO~1\SysInfo.dll CODEBASE = http://ipgweb.cce.hp.com/rdqaio/downloads/sysinfo.cab [FixController Control] InProcServer32 = C:\Program Files\Hp\Common\FixEngine.dll CODEBASE = http://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01_5.cab [{7530BFB8-7293-4D34-9923-61A11451AFC5}] CODEBASE = http://download.eset.com/special/eos/OnlineScanner.cab [ActivatorControl1 Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\Activator.dll CODEBASE = https://objects.aol.com/activator/en-us/Activator.cab [{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}] CODEBASE = http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab [InstallShield International Setup Player] InProcServer32 = c:\windows\DOWNLO~1\isetup.dll CODEBASE = http://www.eaglegps.com/Downloads/Emulators/FishElite_320/isetup.cab [Get_ActiveX Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\HPGETD~1.OCX CODEBASE = https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx [Office Update Installation Engine] InProcServer32 = C:\WINDOWS\opuc.dll CODEBASE = http://office.microsoft.com/officeupdate/content/opuc4.cab [Photodex Presenter AX control] CODEBASE = http://www.photodex.com/pxplay.cab [Shockwave Flash Object] InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash10e.ocx CODEBASE = http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab [{E2883E8F-472F-4FB0-9522-AC9BF37916A7}] CODEBASE = http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab [WildTangent Control] CODEBASE = file://D:\games\WebDriverFullInstall.exe -------------------------------------------------- Enumerating Winsock LSP files: NameSpace #4: C:\Program Files\Bonjour\mdnsNSP.dll -------------------------------------------------- Enumerating Windows NT/2000/XP services AOL Connectivity Service: "C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" (autostart) Ati HotKey Poller: %SystemRoot%\system32\Ati2evxx.exe (autostart) Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Computer Browser: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Cryptographic Services: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) DCOM Server Process Launcher: %SystemRoot%\system32\svchost -k DcomLaunch (autostart) DHCP Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Logical Disk Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) DNS Client: %SystemRoot%\system32\svchost.exe -k NetworkService (autostart) drvnddm: system32\drivers\drvnddm.sys (autostart) DellSupport UniDriver: system32\DRIVERS\dsunidrv.sys (autostart) Error Reporting Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Event Log: %SystemRoot%\system32\services.exe (autostart) Fast User Switching Compatibility: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Fax: %systemroot%\system32\fxssvc.exe (autostart) Help and Support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) HID Input Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Windows Visual Services: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) InCD Helper: C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe (autostart) Server: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Workstation: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) LightScribeService Direct Disc Labeling Service: "C:\Program Files\Common Files\LightScribe\LSSrvc.exe" (autostart) TCP/IP NetBIOS Helper: %SystemRoot%\system32\svchost.exe -k LocalService (autostart) Machine Debug Manager: "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" (autostart) mdmxsdk: system32\DRIVERS\mdmxsdk.sys (autostart) Microsoft Antimalware Service: "c:\Program Files\Microsoft Security Essentials\MsMpEng.exe" (autostart) MSSQL$MICROSOFTBCM: C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe -sMICROSOFTBCM (autostart) Nero Registry InCD Service: C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe (autostart) Removable Storage: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Plug and Play: %SystemRoot%\system32\services.exe (autostart) IPSEC Services: %SystemRoot%\system32\lsass.exe (autostart) Protected Storage: %SystemRoot%\system32\lsass.exe (autostart) Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart) Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart) Task Scheduler: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) SeaPort: "C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe" (autostart) Secondary Logon: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Windows Firewall/Internet Connection Sharing (ICS): %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Shell Hardware Detection: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Print Spooler: %SystemRoot%\system32\spoolsv.exe (autostart) System Restore Service: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Windows Image Acquisition (WIA): %SystemRoot%\system32\svchost.exe -k imgsvc (autostart) tfsnboio: system32\dla\tfsnboio.sys (autostart) tfsncofs: system32\dla\tfsncofs.sys (autostart) tfsndrct: system32\dla\tfsndrct.sys (autostart) tfsndres: system32\dla\tfsndres.sys (autostart) tfsnifs: system32\dla\tfsnifs.sys (autostart) tfsnopio: system32\dla\tfsnopio.sys (autostart) tfsnpool: system32\dla\tfsnpool.sys (autostart) tfsnudf: system32\dla\tfsnudf.sys (autostart) tfsnudfa: system32\dla\tfsnudfa.sys (autostart) Themes: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Distributed Link Tracking Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) WAN Miniport (ATW) Service: "C:\WINDOWS\wanmpsvc.exe" (autostart) Windows Management Instrumentation: %systemroot%\system32\svchost.exe -k netsvcs (autostart) Windows Live ID Sign-in Assistant: "C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE" (autostart) Security Center: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Automatic Updates: %systemroot%\system32\svchost.exe -k netsvcs (autostart) Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Yahoo! Updater: "C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe" (autostart) -------------------------------------------------- Enumerating ShellServiceObjectDelayLoad items: PostBootReminder: C:\WINDOWS\system32\SHELL32.dll CDBurn: C:\WINDOWS\system32\SHELL32.dll WebCheck: C:\WINDOWS\system32\webcheck.dll SysTray: C:\WINDOWS\system32\stobject.dll WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll -------------------------------------------------- End of report, 18,709 bytes Report generated in 0.172 seconds Command line options: /verbose - to add additional info on each section /complete - to include empty sections and unsuspicious data /full - to include several rarely-important sections /force9x - to include Win9x-only startups even if running on WinNT /forcent - to include WinNT-only startups even if running on Win9x /forceall - to include all Win9x and WinNT startups, regardless of platform /history - to list version history only