StartupList report, 13-08-2008, 19:53:09 StartupList version: 1.52.2 Started from : C:\Programas\Trend Micro\HijackThis\HijackThis.EXE Detected: Windows XP SP2 (WinNT 5.01.2600) Detected: Internet Explorer v7.00 (7.00.6000.16674) * Using default options * Showing rarely important sections ================================================== Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programas\Ficheiros comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\mdm.exe C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe C:\Programas\Eset\nod32krn.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\IoctlSvc.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programas\Ficheiros comuns\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexingService.exe C:\Programas\Windows Live\Messenger\usnsvc.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\Explorer.EXE C:\Programas\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe C:\Programas\Creative\Shared Files\Module Loader\DLLML.exe C:\WINDOWS\CTHELPER.EXE C:\WINDOWS\system32\CTXFIHLP.EXE C:\Programas\Eset\nod32kui.exe C:\Programas\Java\jre1.6.0_07\bin\jusched.exe C:\Programas\DAEMON Tools\daemon.exe C:\Programas\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe C:\Programas\Microsoft IntelliPoint\point32.exe C:\WINDOWS\SYSTEM32\CTXFISPI.EXE C:\Programas\AGEIA Technologies\TrayIcon.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Programas\Microsoft Office\Office12\GrooveMonitor.exe C:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe C:\WINDOWS\system32\ctfmon.exe C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexStoreSvr.exe C:\Programas\ASUS WiFi-AP Solo\RtWLan.exe C:\Programas\HP\Digital Imaging\bin\hpqtra08.exe C:\Programas\RemoteScan Server\RemoteScanServer.exe C:\PROGRA~1\Webshots\webshots.scr C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\rdpclip.exe C:\WINDOWS\system32\logonui.exe C:\WINDOWS\system32\logon.scr C:\Programas\Trend Micro\HijackThis\HijackThis.exe C:\Programas\Internet Explorer\iexplore.exe C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WLLoginProxy.exe -------------------------------------------------- Listing of startup folders: Shell folders Startup: [C:\Documents and Settings\Manuel\Menu Iniciar\Programas\Arranque] RemoteScan Server.lnk = C:\Programas\RemoteScan Server\RemoteScanServer.exe Webshots.lnk = C:\Programas\Webshots\Launcher.exe Shell folders Common Startup: [C:\Documents and Settings\All Users\Menu Iniciar\Programas\Arranque] Adobe Gamma.lnk = C:\Programas\Ficheiros comuns\Adobe\Calibration\Adobe Gamma Loader.exe ASUS WiFi-AP Solo.lnk = ? HP Digital Imaging Monitor.lnk = C:\Programas\HP\Digital Imaging\bin\hpqtra08.exe -------------------------------------------------- Checking Windows NT UserInit: [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] UserInit = C:\WINDOWS\system32\userinit.exe, -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup nwiz = nwiz.exe /install JMB36X Configure = C:\WINDOWS\system32\JMRaidTool.exe boot VolPanel = "C:\Programas\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r AudioDrvEmulator = "C:\Programas\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Programas\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll" CTHelper = CTHELPER.EXE CTxfiHlp = CTXFIHLP.EXE UpdReg = C:\WINDOWS\UpdReg.EXE nod32kui = "C:\Programas\Eset\nod32kui.exe" /WAITSERVICE SunJavaUpdateSched = "C:\Programas\Java\jre1.6.0_07\bin\jusched.exe" DAEMON Tools = "C:\Programas\DAEMON Tools\daemon.exe" -lang 1033 Acrobat Assistant 8.0 = "C:\Programas\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" (Default) = IntelliPoint = "C:\Programas\Microsoft IntelliPoint\point32.exe" AGEIA PhysX SysTray = C:\Programas\AGEIA Technologies\TrayIcon.exe NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit GrooveMonitor = "C:\Programas\Microsoft Office\Office12\GrooveMonitor.exe" NeroFilterCheck = C:\Programas\Ficheiros comuns\Nero\Lib\NeroCheck.exe NBKeyScan = "C:\Programas\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" QuickTime Task = "C:\Programas\QuickTime\qttask.exe" -atboottime TkBellExe = "C:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe" -osboot -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe WeatherWatcher = C:\Programas\Weather Watcher\ww.exe MsnMsgr = "C:\Programas\MSN Messenger\MsnMsgr.Exe" /background swg = C:\Programas\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} = "C:\Programas\Ficheiros comuns\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 -------------------------------------------------- Enumerating Active Setup stub paths: HKLM\Software\Microsoft\Active Setup\Installed Components (* = disabled by HKCU twin) [<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}] * StubPath = C:\WINDOWS\system32\ieudinit.exe [>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}] StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP [>{26923b43-4d38-484f-9b9e-de460746276c}] * StubPath = C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig [>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] * StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE [{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] * StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll [{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] * StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install [{7790769C-0471-11d2-AF11-00C04FA35D02}] * StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install [{89820200-ECBD-11cf-8B85-00AA005B4340}] * StubPath = regsvr32.exe /s /n /i:U shell32.dll [{89820200-ECBD-11cf-8B85-00AA005B4383}] * StubPath = C:\WINDOWS\system32\ie4uinit.exe -BaseSettings [{89B4C1CD-B018-4511-B0A1-5476DBF70820}] * StubPath = C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install -------------------------------------------------- Shell & screensaver key from C:\WINDOWS\SYSTEM.INI: Shell=*INI section not found* SCRNSAVE.EXE=*INI section not found* drivers=*INI section not found* Shell & screensaver key from Registry: Shell=Explorer.exe SCRNSAVE.EXE=C:\PROGRA~1\Webshots\webshots.scr drivers=*Registry value not found* Policies Shell key: HKCU\..\Policies: Shell=*Registry key not found* HKLM\..\Policies: Shell=*Registry value not found* -------------------------------------------------- Checking for EXPLORER.EXE instances: C:\WINDOWS\Explorer.exe: PRESENT! C:\Explorer.exe: not present C:\WINDOWS\Explorer\Explorer.exe: not present C:\WINDOWS\System\Explorer.exe: not present C:\WINDOWS\System32\Explorer.exe: not present C:\WINDOWS\Command\Explorer.exe: not present C:\WINDOWS\Fonts\Explorer.exe: not present -------------------------------------------------- Checking for superhidden extensions: .lnk: HIDDEN! (arrow overlay: yes) .pif: HIDDEN! (arrow overlay: yes) .exe: not hidden .com: not hidden .bat: not hidden .hta: not hidden .scr: not hidden .shs: HIDDEN! .shb: HIDDEN! .vbs: not hidden .vbe: not hidden .wsh: not hidden .scf: HIDDEN! (arrow overlay: NO!) .url: HIDDEN! (arrow overlay: yes) .js: not hidden .jse: not hidden -------------------------------------------------- Enumerating Browser Helper Objects: (no name) - C:\Programas\TechSmith\SnagIt 9\SnagItBHO.dll - {00C6482D-C502-44C8-8409-FCE54AD9C208} (no name) - C:\Programas\Ficheiros comuns\Adobe\Acrobat\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (no name) - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll - {3049C3E9-B461-4BC5-8870-4C09146192CA} (no name) - C:\PROGRA~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F} (no name) - C:\Programas\Microsoft Office\Office12\GrooveShellExtensions.dll - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} (no name) - C:\Programas\Java\jre1.6.0_07\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (no name) - (no file) - {7E853D72-626A-48EC-A868-BA8D5E23E045} (no name) - C:\Programas\Ficheiros comuns\Microsoft Shared\Windows Live\WindowsLiveLogin.dll - {9030D464-4C02-4ABF-8ECC-5164760863C6} ACA Capture - C:\Programas\ACASystems\ACACapturePro422\scap0003p.dll - {93C69D87-A11D-4FFC-BC56-BE7EE0D235BA} (no name) - C:\Programas\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll - {AE7CD045-E861-484f-8273-0445EE161910} -------------------------------------------------- Enumerating Task Scheduler jobs: AppleSoftwareUpdate.job -------------------------------------------------- Enumerating Download Program Files: [SentinelVE3D Class] InProcServer32 = C:\Programas\Virtual Earth 3D\SentinelVirtualEarth3D.dll CODEBASE = http://download.microsoft.com/download/7/0/7/707a44ad-52ad-49af-b7ef-e21b6b0656e4/VirtualEarth3D.cab [Shockwave ActiveX Control] InProcServer32 = C:\WINDOWS\system32\Adobe\Director\SwDir.dll CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab [Windows Genuine Advantage Validation Tool] InProcServer32 = C:\WINDOWS\system32\LegitCheckControl.DLL CODEBASE = http://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab [Checkers Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\CONFLICT.1\msgrchkr.dll CODEBASE = http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab [Autodesk MapGuide ActiveX Control] InProcServer32 = C:\WINDOWS\Downloaded Program Files\MgAxCtrl.dll CODEBASE = http://download.autodesk.com/esd/mapguide/SP1/ENG/mgaxctrl.cab [System Requirements Lab Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\sysreqlab2.dll CODEBASE = http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab OSD = C:\WINDOWS\Downloaded Program Files\SysReqLab2.osd [DivXBrowserPlugin Object] InProcServer32 = C:\Programas\DivX\DivX Web Player\npdivx32.dll CODEBASE = http://download.divx.com/player/DivXBrowserPlugin.cab [MUWebControl Class] InProcServer32 = C:\WINDOWS\system32\muweb.dll CODEBASE = http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1178655243490 [{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}] CODEBASE = http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab [MessengerStatsClient Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\MessengerStatsPAClient.dll CODEBASE = http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab [Shockwave Flash Object] InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx CODEBASE = http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab [Minesweeper Flags Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\MineSweeper.dll CODEBASE = http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab -------------------------------------------------- Enumerating Windows NT/2000/XP services AEGIS Protocol (IEEE 802.1x) v3.4.5.0: system32\DRIVERS\AegisP.sys (autostart) AMON: \SystemRoot\system32\drivers\amon.sys (autostart) Apple Mobile Device: "C:\Programas\Ficheiros comuns\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe" (autostart) Áudio do Windows: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Serviço de transferência inteligente em fundo: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Browser de computador: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Creative Service for CDROM Access: C:\WINDOWS\system32\CTsvcCDA.exe (autostart) Serviços criptográficos: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) DCOM - Lançador de processo de servidor: %SystemRoot%\system32\svchost -k DcomLaunch (autostart) Cliente DHCP: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Gestor de discos lógicos: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Cliente DNS: %SystemRoot%\system32\svchost.exe -k NetworkService (autostart) Realtek EAPPkt Protocol: system32\DRIVERS\EAPPkt.sys (autostart) Serviço de relato de erros: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Registo de eventos: %SystemRoot%\system32\services.exe (autostart) Ajuda e suporte: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) HID Input Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Servidor: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Estação de trabalho: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Programa auxiliar TCP/IP NetBIOS: %SystemRoot%\system32\svchost.exe -k LocalService (autostart) Machine Debug Manager: "C:\Programas\Ficheiros comuns\Microsoft Shared\VS7DEBUG\mdm.exe" (autostart) Nero BackItUp Scheduler 3: C:\Programas\Nero\Nero8\Nero BackItUp\NBService.exe (autostart) NOD32 Kernel Service: "C:\Programas\Eset\nod32krn.exe" (autostart) NVIDIA Display Driver Service: %SystemRoot%\system32\nvsvc32.exe (autostart) PLFlash DeviceIoControl Service: C:\WINDOWS\system32\IoctlSvc.exe (autostart) Plug and Play: %SystemRoot%\system32\services.exe (autostart) Pml Driver HPZ12: C:\WINDOWS\system32\HPZipm12.exe (autostart) PnkBstrA: C:\WINDOWS\system32\PnkBstrA.exe (autostart) Serviços IPSEC: %SystemRoot%\system32\lsass.exe (autostart) Armazenamento protegido: %SystemRoot%\system32\lsass.exe (autostart) Gestor de ligação de acesso remoto: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Registo remoto: %SystemRoot%\system32\svchost.exe -k LocalService (autostart) Chamada de procedimento remoto (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart) Gestor de contas de segurança: %SystemRoot%\system32\lsass.exe (autostart) Programador de tarefas: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Início de sessão secundário: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Notificação de evento de sistema: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Firewall do Windows/Partilha de ligação à Internet (ICS): %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Detecção de hadrware da shell: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Spooler de impressão: %SystemRoot%\system32\spoolsv.exe (autostart) Serviço de 'Restauro do sistema': %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Windows Image Acquisition (WIA): %SystemRoot%\system32\svchost.exe -k imgsvc (autostart) Temas: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Cliente de Distributed Link Tracking: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart) Hora do Windows: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) WebClient: %SystemRoot%\system32\svchost.exe -k LocalService (autostart) WMI (Instrumento de gestão do Windows): %systemroot%\system32\svchost.exe -k netsvcs (autostart) Centro de segurança: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) Actualizações automáticas: %systemroot%\system32\svchost.exe -k netsvcs (autostart) Configuração zero sem fios: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart) -------------------------------------------------- Enumerating ShellServiceObjectDelayLoad items: PostBootReminder: C:\WINDOWS\system32\SHELL32.dll CDBurn: C:\WINDOWS\system32\SHELL32.dll WebCheck: C:\WINDOWS\system32\webcheck.dll SysTray: C:\WINDOWS\system32\stobject.dll WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll -------------------------------------------------- End of report, 17.031 bytes Report generated in 0,062 seconds Command line options: /verbose - to add additional info on each section /complete - to include empty sections and unsuspicious data /full - to include several rarely-important sections /force9x - to include Win9x-only startups even if running on WinNT /forcent - to include WinNT-only startups even if running on Win9x /forceall - to include all Win9x and WinNT startups, regardless of platform /history - to list version history only