and the StartUp Programs log:
"Silent Runners.vbs", revision R50,
http://www.silentrunners.org/
Operating System: Windows Me (Millennium Edition)
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"ScanRegistry" = "C:\WINDOWS\scanregw.exe /autorun" [MS]
"TaskMonitor" = "C:\WINDOWS\taskmon.exe" [MS]
"PCHealth" = "C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s" [MS]
"SystemTray" = "SysTray.Exe" [MS]
"LoadPowerProfile" = "Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" [MS]
"LoadQM" = "loadqm.exe" [MS]
"ICSMGR" = "ICSMGR.EXE" [MS]
"QuickTime Task" = ""C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime" ["Apple Computer, Inc."]
"NvCplDaemon" = "RUNDLL32.EXE C:\WINDOWS\SYSTEM\NvCpl.dll,NvStartup" [MS]
"nwiz" = "nwiz.exe /install" ["NVIDIA Corporation"]
"InCD" = "C:\Programas\Ahead\InCD\InCD.exe" ["Nero AG"]
"TkBellExe" = ""C:\Programas\Ficheiros comuns\Real\Update_OB\realsched.exe" -osboot" ["RealNetworks, Inc."]
"VSOCheckTask" = ""C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask" ["McAfee, Inc."]
"MCAgentExe" = "C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe" ["McAfee, Inc"]
"MCUpdateExe" = "C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE" ["McAfee, Inc"]
"MCTskShd" = "C:\PROGRA~1\MCAFEE.COM\AGENT\mctskshd.exe" ["McAfee, Inc"]
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\ {++}
"LoadPowerProfile" = "Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" [MS]
"SchedulingAgent" = "mstask.exe" [MS]
"*StateMgr" = "C:\WINDOWS\System\Restore\StateMgr.exe" [MS]
"StillImageMonitor" = "C:\WINDOWS\SYSTEM\STIMON.EXE" [MS]
"KB891711" = "C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE" [MS]
"KB918547" = "C:\WINDOWS\SYSTEM\KB918547\KB918547.EXE" [MS]
"McShld9x" = "C:\Programas\McAfee.com\VSO\mcshld9x.exe" ["McAfee, Inc."]
HKLM\Software\Microsoft\Active Setup\Installed Components\
PerUser_CVT_Inis\(Default) = "Programa de configuração do Windows - Conversor FAT32"
\StubPath = "rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_CVT_Inis 64 C:\WINDOWS\INF\applets1.inf" [MS]
PerUser_Enable_Inis\(Default) = "Programa de configuração do Windows - Acessibilidade"
\StubPath = "rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_Enable_Inis_remove 64 C:\WINDOWS\INF\enable.inf" [MS]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
-> {HKLM...CLSID} = "AcroIEHlprObj Class"
\InProcServer32\(Default) = "C:\PROGRAMAS\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL" ["Adobe Systems Incorporated"]
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{2E9D3540-211C-11d0-A5F2-00A0248C37BE}" = "Nero Shell Extension Property Sheet"
-> {HKLM...CLSID} = "Nero Shell Extension Property Sheet"
\InProcServer32\(Default) = "C:\Programas\Ahead\nero\neroshx.dll" ["Ahead Software AG"]
"{68f32140-2ca3-11d0-acc1-444553540000}" = "PicaView"
-> {HKLM...CLSID} = "PicaView Shell Extension"
\InProcServer32\(Default) = "C:\PROGRA~1\ACDSYS~1\PICAVIEW\PicaView.dll" ["ACD Systems, Ltd."]
"{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Explorador do ambiente de trabalho"
-> {HKLM...CLSID} = "Explorador do ambiente de trabalho"
\InProcServer32\(Default) = "C:\WINDOWS\SYSTEM\NVSHELL.DLL" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\SYSTEM\NVSHELL.DLL" ["NVIDIA Corporation"]
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {HKLM...CLSID} = "RealOne Player Context Menu Class"
\InProcServer32\(Default) = "C:\PROGRAMAS\REAL\REALONE PLAYER\RPSHELL.DLL" ["RealNetworks, Inc."]
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
yEnc32\(Default) = "{8CDA2F05-B2BA-4AC7-B731-51E9E6B006E1}"
-> {HKLM...CLSID} = "yEnc32 Context Menu Shell Extension"
\InProcServer32\(Default) = "C:\Programas\eSite Media\yEnc32\yEnc32Shell.dll" [null data]
PicaView\(Default) = "{68f32140-2ca3-11d0-acc1-444553540000}"
-> {HKLM...CLSID} = "PicaView Shell Extension"
\InProcServer32\(Default) = "C:\PROGRA~1\ACDSYS~1\PICAVIEW\PicaView.dll" ["ACD Systems, Ltd."]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM...CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM...CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {HKLM...CLSID} = "WinZip"
\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
System Policies {policy setting}:
---------------------------------
Note: detected settings may not have any effect.
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
"CDRAutoRun" = (REG_BINARY) hex:00 00 00 00
{unrecognized setting}
"NoToolbarCustomize" = (REG_DWORD) hex:0x00000000
{Disable customizing browser toolbar buttons}
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
"NoBandCustomize" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"NoToolbarCustomize" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\
"GeneralTab" = (REG_DWORD) hex:0x00000000
{Disable the General page}
"HomePage" = (REG_DWORD) hex:0x00000000
{Disable changing home page settings}
"Cache" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"History" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"Colors" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"links" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"Fonts" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"Languages" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"Accessibility" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"SecurityTab" = (REG_DWORD) hex:0x00000000
{Disable the Security page}
"ContentTab" = (REG_DWORD) hex:0x00000000
{Disable the Content page}
"Ratings" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"Certificates" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"FormSuggest" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"FormSuggest Passwords" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"Profiles" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"ConnectionsTab" = (REG_DWORD) hex:0x00000000
{Disable the Connections page}
"Connection Settings" = (REG_DWORD) hex:0x00000000
{Disable changing connection settings}
"Connwiz Admin Lock" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"Proxy" = (REG_DWORD) hex:0x00000000
{Disable changing proxy settings}
"ProgramsTab" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"Messaging" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"ResetWebSettings" = (REG_DWORD) hex:0x00000000
{Disable the Reset Web Settings feature}
"Check_If_Default" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"AdvancedTab" = (REG_DWORD) hex:0x00000000
{Disable the Advanced page}
"Advanced" = (REG_DWORD) hex:0x00000000
{Disable changing Advanced page settings}
HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel\
"GeneralTab" = (REG_DWORD) hex:0x00000000
{Disable the General page}
"HomePage" = (REG_DWORD) hex:0x00000000
{Disable changing home page settings}
"Cache" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"History" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"Colors" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"links" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"Fonts" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"Languages" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"Accessibility" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"SecurityTab" = (REG_DWORD) hex:0x00000000
{Disable the Security page}
"ContentTab" = (REG_DWORD) hex:0x00000000
{Disable the Content page}
"Ratings" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"Certificates" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"FormSuggest" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"FormSuggest Passwords" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"Profiles" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"ConnectionsTab" = (REG_DWORD) hex:0x00000000
{Disable the Connections page}
"Connection Settings" = (REG_DWORD) hex:0x00000000
{Disable changing connection settings}
"Connwiz Admin Lock" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"Proxy" = (REG_DWORD) hex:0x00000000
{Disable changing proxy settings}
"ProgramsTab" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"Messaging" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"ResetWebSettings" = (REG_DWORD) hex:0x00000000
{Disable the Reset Web Settings feature}
"Check_If_Default" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"AdvancedTab" = (REG_DWORD) hex:0x00000000
{Disable the Advanced page}
"Advanced" = (REG_DWORD) hex:0x00000000
{Disable changing Advanced page settings}
HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\
"NoSplash" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"NoJITSetup" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\
"NoSplash" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"NoJITSetup" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\
"NoBrowserSaveAs" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"NoFileNew" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"NoBrowserClose" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"NoFileOpen" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"NoTheaterMode" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"NoViewSource" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"NoFavorites" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"NoAddingChannels" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"NoBrowserOptions" = (REG_DWORD) hex:0x00000000
{Tools menu: Disable Internet Options... menu option}
"NoBrowserContextMenu" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"NoOpeninNewWnd" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions\
"NoBrowserSaveAs" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"NoFileNew" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"NoBrowserClose" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"NoFileOpen" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"NoTheaterMode" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"NoViewSource" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"NoFavorites" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"NoAddingChannels" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"NoBrowserOptions" = (REG_DWORD) hex:0x00000000
{Tools menu: Disable Internet Options... menu option}
"NoBrowserContextMenu" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
"NoOpeninNewWnd" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
Active Desktop and Wallpaper:
-----------------------------
Active Desktop may be enabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
Displayed if Active Desktop enabled and wallpaper not set by System Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\Os meus documentos\As minhas imagens\ariane_test.jpg"
Startup items in "Startup" & "All Users...Startup" folders:
-----------------------------------------------------------
C:\WINDOWS\Menu Iniciar\Programas\Arranque
"Microsoft Office" -> shortcut to: "C:\Programas\Microsoft Office\Office\OSA9.EXE -b -l" [MS]
"ImageFox" -> shortcut to: "C:\Programas\ACD Systems\ImageFox\ImageFox.exe" ["ACD Systems, Ltd."]
"Watch" -> shortcut to: "C:\Programas\3.0M SD DSC\Console\Watch.exe" [","]
"HIDEIT" -> shortcut to: "C:\HIDEIT.EXE" ["Ñacañaca ltd."]
"Watch_Scanner" -> shortcut to: "C:\Programas\Mustek 1200 UB Plus\Driver\WATCH.exe" ["Common Group"]
Enabled Scheduled Tasks:
------------------------
"Programador PCHealth para a recolha de dados" -> launches: "C:\WINDOWS\PCHEALTH\SUPPORT\PCHSCHD.EXE -c" [MS]
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "C:\WINDOWS\SYSTEM\rnr20.dll" [MS]
Transport Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
00000000000#\PackedCatalogItem (contains) DLL [Company Name], (at) # range:
C:\WINDOWS\SYSTEM\mswsosp.dll [MS], 1
C:\WINDOWS\SYSTEM\msafd.dll [MS], 2 - 4
C:\WINDOWS\SYSTEM\rsvpsp.dll [MS], 5 - 6
Toolbars, Explorer Bars, Extensions:
------------------------------------
Toolbars
HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{BA52B914-B692-46C4-B683-905236F6F655}" = "McAfee VirusScan"
-> {HKLM...CLSID} = "McAfee VirusScan"
\InProcServer32\(Default) = "C:\PROGRAMAS\MCAFEE.COM\VSO\MCVSSHL.DLL" ["McAfee, Inc."]
Extensions (Tools menu items, main toolbar menu buttons)
HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{08B0E5C0-4FCB-11CF-AAA5-00401C608501}"
-> {HKLM...CLSID} = "Web Browser Applet Control"
\InProcServer32\(Default) = "C:\WINDOWS\SYSTEM\MSJAVA.DLL" [MS]
Miscellaneous IE Hijack Points
------------------------------
C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")
Added lines (compared with English-language version):
[Strings]: START_PAGE_URL="
http://www.microsoft...5.5&ar=msnhome"
[Strings]: MS_START_PAGE_URL="
http://www.microsoft...5.5&ar=msnhome"
Missing lines (compared with English-language version):
[Strings]: 2 lines
HKLM\Software\Microsoft\Internet Explorer\AboutURLs\
<<H>> "NavigationFailure" = "res://shdoclc.dll/navcancl.htm" [MS]
<<H>> "DesktopItemNavigationFailure" = "res://shdoclc.dll/navcancl.htm" [MS]
<<H>> "NavigationCanceled" = "res://shdoclc.dll/navcancl.htm" [MS]
<<H>> "OfflineInformation" = "res://shdoclc.dll/offcancl.htm" [MS]
<<H>> "PostNotCached" = "res://mshtml.dll/repost.htm" [MS]
Print Monitors:
---------------
HKLM\System\CurrentControlSet\Control\Print\Monitors\
usbmon.dll\Driver = "usbmon.dll" [MS]
hpzs9x08\Driver = "hpzs9x08.dll" ["HP"]
----------
<<H>>: Suspicious data at a browser hijack point.
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
DLL launch points, use the -supp parameter or answer "No" at the
first message box and "Yes" at the second message box.
---------- (total run time: 56 seconds, including 18 seconds for message boxes)