StartupList report, 20/03/2005, 13:38:15 StartupList version: 1.52 Started from : C:\DOCUME~1\Sylvanor\LOCALS~1\Temp\Rar$EX00.543\StartupList.EXE Detected: Windows XP SP1 (WinNT 5.01.2600) Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106) * Using default options ================================================== Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\System32\ctfmon.exe C:\Program Files\WinRAR\WinRAR.exe C:\DOCUME~1\Sylvanor\LOCALS~1\Temp\Rar$EX00.543\StartupList.exe -------------------------------------------------- Listing of startup folders: Shell folders Common Startup: [C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage] GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE -------------------------------------------------- Checking Windows NT UserInit: [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] UserInit = C:\WINDOWS\system32\userinit.exe, -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run ATIPTA = C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe CTSysVol = C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe CTDVDDet = C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE CTHelper = CTHELPER.EXE Dit = Dit.exe Cmaudio = RunDll32 cmicnfg.cpl,CMICtrlWnd ccApp = "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" Symantec NetDriver Monitor = C:\PROGRA~1\SYMNET~1\SNDMon.exe QuickTime Task = "C:\WINDOWS\system32\qttask.exe" -atboottime SSC_UserPrompt = C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe atwtusb = atwtusb.exe beta AVGCtrl = "C:\Program Files\AVPersonal\AVGNT.EXE" /min -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run STYLEXP = C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide CursorXP = C:\Program Files\CursorXP\CursorXP.exe msnmsgr = "C:\Program Files\MSN Messenger\msnmsgr.exe" /background SpybotSD TeaTimer = C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe -------------------------------------------------- Shell & screensaver key from C:\WINDOWS\SYSTEM.INI: Shell=*INI section not found* SCRNSAVE.EXE=*INI section not found* drivers=*INI section not found* Shell & screensaver key from Registry: Shell=Explorer.exe SCRNSAVE.EXE=C:\WINDOWS\System32\ssstars.scr drivers=*Registry value not found* Policies Shell key: HKCU\..\Policies: Shell=*Registry key not found* HKLM\..\Policies: Shell=*Registry value not found* -------------------------------------------------- Enumerating Browser Helper Objects: (no name) - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (no name) - C:\Program Files\GetRight\xx2gr.dll - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} (no name) - C:\PROGRA~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F} Web assistant - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} -------------------------------------------------- Enumerating Task Scheduler jobs: Symantec NetDetect.job -------------------------------------------------- Enumerating Download Program Files: [EGamesPlugin Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\EGamesPlugin.dll CODEBASE = https://www.e-games.com.my/com/EGamesPlugin.cab [egames.AxRTPC] InProcServer32 = C:\WINDOWS\Downloaded Program Files\AxRTPC.ocx CODEBASE = http://dreamville.e-games.com.my/AxClient/AxRTPC.CAB [MCSendMessageHandler Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\MISBH.dll CODEBASE = http://xtraz.icq.com/xtraz/activex/MISBH.cab -------------------------------------------------- Enumerating ShellServiceObjectDelayLoad items: PostBootReminder: C:\WINDOWS\system32\SHELL32.dll CDBurn: C:\WINDOWS\system32\SHELL32.dll WebCheck: C:\WINDOWS\System32\webcheck.dll SysTray: C:\WINDOWS\System32\stobject.dll -------------------------------------------------- End of report, 5 246 bytes Report generated in 0,060 seconds Command line options: /verbose - to add additional info on each section /complete - to include empty sections and unsuspicious data /full - to include several rarely-important sections /force9x - to include Win9x-only startups even if running on WinNT /forcent - to include WinNT-only startups even if running on Win9x /forceall - to include all Win9x and WinNT startups, regardless of platform /history - to list version history only