StartupList report, 8/17/2008, 3:03:11 AM StartupList version: 1.52.2 Started from : C:\Documents and Settings\Carlos\Desktop\util1\HijackThis.EXE Detected: Windows XP SP2 (WinNT 5.01.2600) Detected: Internet Explorer v7.00 (7.00.6000.16674) * Using default options ================================================== Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Utilities\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Utilities\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\UTILIT~2\AVG75\avgamsvr.exe C:\UTILIT~2\AVG75\avgupsvc.exe C:\UTILIT~2\AVG75\avgemc.exe C:\UTILIT~1\NU\NORTON~2\NPROTECT.EXE C:\WINDOWS\system32\HPZipm12.exe C:\UTILIT~1\NU\NORTON~2\SPEEDD~1\NOPDB.EXE C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\fxssvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\WINDOWS\sm56hlpr.exe C:\WINDOWS\system32\VTTimer.exe C:\WINDOWS\system32\VTtrayp.exe C:\Acer\Empowering Technology\eRecovery\Monitor.exe C:\Utilities\RAMpage\RAMpage.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Utilities\Windows Defender\MSASCui.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe C:\Utilitiest\AVG75\avgcc.exe C:\Documents and Settings\Carlos\Desktop\util1\HijackThis.exe -------------------------------------------------- Listing of startup folders: Shell folders Common Startup: [C:\Documents and Settings\All Users\Start Menu\Programs\Startup] Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe -------------------------------------------------- Checking Windows NT UserInit: [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] UserInit = C:\WINDOWS\system32\userinit.exe, -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run SoundMan = SOUNDMAN.EXE ntiMUI = c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe SunJavaUpdateSched = "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" IMJPMIG8.1 = "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 MSPY2002 = C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC PHIME2002ASync = C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC PHIME2002A = C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName SMSERIAL = sm56hlpr.exe VTTimer = VTTimer.exe VTTrayp = VTtrayp.exe eRecoveryService = C:\Acer\Empowering Technology\eRecovery\Monitor.exe NeroCheck = C:\WINDOWS\system32\NeroCheck.exe RAMpage = "C:\Utilities\RAMpage\RAMpage.exe" M=28 T=4 S P="C:\Utilities\RAMpage\RAMpageConfig.exe" ZoneAlarm Client = "C:\Utilities\ZoneAlarm\zlclient.exe" AVG7_CC = C:\UTILIT~2\AVG75\avgcc.exe /STARTUP AcctMgr = C:\Utilities\NU\Password Manager\AcctMgr.exe /startup ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" Windows Defender = "C:\Utilities\Windows Defender\MSASCui.exe" -hide -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe CyberDefender Early Detection Center = "C:\Utilities\CyberDefender\AntiSpyware\cdas2a6.exe" /minimize -------------------------------------------------- Shell & screensaver key from C:\WINDOWS\SYSTEM.INI: Shell=*INI section not found* SCRNSAVE.EXE=*INI section not found* drivers=*INI section not found* Shell & screensaver key from Registry: Shell=Explorer.exe SCRNSAVE.EXE=C:\WINDOWS\system32\logon.scr drivers=*Registry value not found* Policies Shell key: HKCU\..\Policies: Shell=*Registry key not found* HKLM\..\Policies: Shell=*Registry value not found* -------------------------------------------------- Enumerating Browser Helper Objects: WormRadar.com IESiteBlocker.NavFilter - C:\Documents and Settings\All Users\Application Data\avg8\update\backup\avgssie.dll - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} (no name) - C:\UTILIT~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F} (no name) - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (no name) - C:\WINDOWS\system32\msvxi30.dll - {89044184-F260-4FDD-8FAB-2662814846E5} (no name) - C:\Documents and Settings\Carlos\Local Settings\Application Data\CyberDefender\cdmyidd.dll - {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} ZoneAlarm Spy Blocker BHO - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} -------------------------------------------------- Enumerating Task Scheduler jobs: AppleSoftwareUpdate.job MP Scheduled Scan.job Norton SystemWorks One Button Checkup.job Symantec Drmc.job Symantec NetDetect.job -------------------------------------------------- Enumerating Download Program Files: [Windows Genuine Advantage Validation Tool] InProcServer32 = C:\WINDOWS\system32\legitcheckcontrol.dll CODEBASE = http://download.microsoft.com/download/9/b/d/9bdc68ef-6a9f-4505-8fb8-d0d2d160e512/LegitCheckControl.cab [{DE22A7AB-A739-4C58-AD52-21F9CD6306B7}] CODEBASE = http://download.microsoft.com/download/7/E/6/7E6A8567-DFE4-4624-87C3-163549BE2704/clearadj.cab -------------------------------------------------- Enumerating ShellServiceObjectDelayLoad items: PostBootReminder: C:\WINDOWS\system32\SHELL32.dll CDBurn: C:\WINDOWS\system32\SHELL32.dll WebCheck: C:\WINDOWS\system32\webcheck.dll SysTray: C:\WINDOWS\system32\stobject.dll WebExtLocation: C:\WINDOWS\system32\wmhshell.dll WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll -------------------------------------------------- End of report, 6,909 bytes Report generated in 0.063 seconds Command line options: /verbose - to add additional info on each section /complete - to include empty sections and unsuspicious data /full - to include several rarely-important sections /force9x - to include Win9x-only startups even if running on WinNT /forcent - to include WinNT-only startups even if running on Win9x /forceall - to include all Win9x and WinNT startups, regardless of platform /history - to list version history only