jlathrop01
Topic Starter
StartupList report, 11/15/2004, 8:43:38 PM
StartupList version: 1.52
Started from : C:\Documents and
Settings\Lathrop\Desktop\Hijackthis\HijackThis.EXE
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\sj655\hpupdate.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\WINDOWS\System32\l?gonui.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software
Updater\7288971\Program\backWeb-7288971.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
c:\windows\softwaredistribution\download\bfb74eecad88f639a6147d02cb5d70f7\spu
ninst.exe
C:\WINDOWS\System32\wuauclt.exe
C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe
C:\Documents and Settings\Lathrop\Desktop\Hijackthis\HijackThis.exe
————————————————–
Listing of startup folders:
Shell folders Startup:
[C:\Documents and Settings\Lathrop\Start Menu\Programs\Startup]
PowerReg Scheduler.exe
Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMREMIND.EXE
Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare
software\bin\EasyShare.exe
KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software
Updater\7288971\Program\backWeb-7288971.exe
Microsoft Works Calendar Reminders.lnk = ?
————————————————–
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
nwiz = nwiz.exe /install
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
NeroCheck = C:\WINDOWS\System32\NeroCheck.exe
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
ccRegVfy = "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
hplampc = C:\WINDOWS\system32\hplampc.exe
HP Update 4200C = C:\sj655\hpupdate.exe 4200C+
SSC_UserPrompt = C:\Program Files\Common Files\Symantec Shared\Security
Center\UsrPrmpt.exe
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
sys145499 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
sys248545419 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
sys331350667 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
sys414155964 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
sys496961202 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
sys579766830 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
(Default) =
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
MSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /background
PowerProf = PowerProf.exe
Yahoo! Pager = C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
Mntic = C:\WINDOWS\System32\l?gonui.exe
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
sys145499 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
sys248545419 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
sys331350667 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
sys414155964 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
sys496961202 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
sys579766830 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
————————————————–
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\System32\f3pssavr.scr
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
————————————————–
Enumerating Browser Helper Objects:
(no name) - (no file) - {00000010-6F7D-442C-93E3-4A4827C2E4C8}
(no name) - C:\Program Files\Adobe\Acrobat
6.0\Reader\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
ie - c:\windows\iehr.dll (file missing) -
{2FF5573C-0EB5-43db-A1B2-C4326813468E}
(no name) - c:\program files\google\googletoolbar2.dll -
{AA58ED58-01DD-4d91-8333-CF10577473F7}
(no name) - C:\Program Files\Norton AntiVirus\NavShExt.dll -
{BDF3E430-B101-42AD-A544-FADC6B084872}
————————————————–
Enumerating Task Scheduler jobs:
Norton AntiVirus - Scan my computer.job
Symantec NetDetect.job
————————————————–
Enumerating Download Program Files:
[Pool Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\pool.ocx
CODEBASE = http://mirror.worldwinner.com/games/v45/pool/pool.cab
[{886DDE35-E955-11D0-A707-000000521958}]
CODEBASE = http://69.56.176.78/webplugin.cab
[Wwlaunch Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\wwlaunch.ocx
CODEBASE = https://www.worldwinner.com/games/shared/wwlaunch.cab
[ZoneIntro Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\ZIntro.ocx
CODEBASE = http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
[PopCapLoader Object]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\popcaploader.dll
CODEBASE = http://zone.msn.com/bingame/isan/default/popcaploader_v6.cab
[HeartbeatCtl Class]
InProcServer32 = C:\WINDOWS\DOWNLO~1\hrtbeat.ocx
CODEBASE = http://fdl.msn.com/zone/datafiles/heartbeat.cab
————————————————–
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll
kevGTbaYcJ: C:\WINDOWS\System32\ecyh.dll
————————————————–
End of report, 7,985 bytes
Report generated in 0.040 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of
platform
/history - to list version history only
StartupList version: 1.52
Started from : C:\Documents and
Settings\Lathrop\Desktop\Hijackthis\HijackThis.EXE
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\sj655\hpupdate.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\ypager.exe
C:\WINDOWS\System32\l?gonui.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software
Updater\7288971\Program\backWeb-7288971.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
c:\windows\softwaredistribution\download\bfb74eecad88f639a6147d02cb5d70f7\spu
ninst.exe
C:\WINDOWS\System32\wuauclt.exe
C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe
C:\Documents and Settings\Lathrop\Desktop\Hijackthis\HijackThis.exe
————————————————–
Listing of startup folders:
Shell folders Startup:
[C:\Documents and Settings\Lathrop\Start Menu\Programs\Startup]
PowerReg Scheduler.exe
Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMREMIND.EXE
Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare
software\bin\EasyShare.exe
KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software
Updater\7288971\Program\backWeb-7288971.exe
Microsoft Works Calendar Reminders.lnk = ?
————————————————–
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
nwiz = nwiz.exe /install
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
NeroCheck = C:\WINDOWS\System32\NeroCheck.exe
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
ccRegVfy = "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
hplampc = C:\WINDOWS\system32\hplampc.exe
HP Update 4200C = C:\sj655\hpupdate.exe 4200C+
SSC_UserPrompt = C:\Program Files\Common Files\Symantec Shared\Security
Center\UsrPrmpt.exe
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
sys145499 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
sys248545419 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
sys331350667 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
sys414155964 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
sys496961202 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
sys579766830 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
(Default) =
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
MSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /background
PowerProf = PowerProf.exe
Yahoo! Pager = C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
Mntic = C:\WINDOWS\System32\l?gonui.exe
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
sys145499 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
sys248545419 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
sys331350667 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
sys414155964 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
sys496961202 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
sys579766830 = C:\DOCUME~1\Lathrop\LOCALS~1\Temp\94b4ff24.exe delete
————————————————–
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\System32\f3pssavr.scr
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
————————————————–
Enumerating Browser Helper Objects:
(no name) - (no file) - {00000010-6F7D-442C-93E3-4A4827C2E4C8}
(no name) - C:\Program Files\Adobe\Acrobat
6.0\Reader\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
ie - c:\windows\iehr.dll (file missing) -
{2FF5573C-0EB5-43db-A1B2-C4326813468E}
(no name) - c:\program files\google\googletoolbar2.dll -
{AA58ED58-01DD-4d91-8333-CF10577473F7}
(no name) - C:\Program Files\Norton AntiVirus\NavShExt.dll -
{BDF3E430-B101-42AD-A544-FADC6B084872}
————————————————–
Enumerating Task Scheduler jobs:
Norton AntiVirus - Scan my computer.job
Symantec NetDetect.job
————————————————–
Enumerating Download Program Files:
[Pool Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\pool.ocx
CODEBASE = http://mirror.worldwinner.com/games/v45/pool/pool.cab
[{886DDE35-E955-11D0-A707-000000521958}]
CODEBASE = http://69.56.176.78/webplugin.cab
[Wwlaunch Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\wwlaunch.ocx
CODEBASE = https://www.worldwinner.com/games/shared/wwlaunch.cab
[ZoneIntro Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\ZIntro.ocx
CODEBASE = http://zone.msn.com/binFramework/v10/ZIntro.cab27513.cab
[PopCapLoader Object]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\popcaploader.dll
CODEBASE = http://zone.msn.com/bingame/isan/default/popcaploader_v6.cab
[HeartbeatCtl Class]
InProcServer32 = C:\WINDOWS\DOWNLO~1\hrtbeat.ocx
CODEBASE = http://fdl.msn.com/zone/datafiles/heartbeat.cab
————————————————–
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll
kevGTbaYcJ: C:\WINDOWS\System32\ecyh.dll
————————————————–
End of report, 7,985 bytes
Report generated in 0.040 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of
platform
/history - to list version history only