StartupList report, 24.05.2006, 13:27:27
StartupList version: 1.52.2
Started from : C:\Dokumente und Einstellungen\Christina Bouchard\Eigene Dateien\download-programme\HijackThis.EXE
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\AntiVir PersonalEdition Classic\sched.exe
C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Programme\Java\jre1.5.0_06\bin\jusched.exe
C:\Programme\iTunes\iTunesHelper.exe
C:\Programme\QuickTime\qttask.exe
C:\WINDOWS\System32\gearsec.exe
C:\Programme\Synaptics\SynTP\SynTPLpr.exe
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
C:\Programme\HP\Digital Imaging\Unload\hpqcmon.exe
C:\Programme\HP\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Programme\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Programme\Browser USB MOUSE\mouse32a.exe
C:\Programme\Analog Devices\SoundMAX\SMAgent.exe
C:\Programme\ICQLite\ICQLite.exe
C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\Messenger\msmsgs.exe
C:\Programme\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\NCLAUNCH.EXe
C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programme\HP\HP Share-to-Web\hpgs2wnf.exe
C:\Programme\OpenOffice.org1.1.0\program\soffice.e xe
C:\WINDOWS\system32\ssoftsrv.exe
C:\DOKUME~1\CHRIST~1\LOKALE~1\TEMP\_VWUPSRV.EXE
C:\WINDOWS\System32\UAService7.exe
C:\Programme\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Programme\iTunes\iTunes.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\Dokumente und Einstellungen\Christina Bouchard\Eigene Dateien\download-programme\HijackThis.exe
--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\Dokumente und Einstellungen\Christina Bouchard\Startmenü\Programme\Autostart]
OpenOffice.org 1.1.0.lnk = C:\Programme\OpenOffice.org1.1.0\program\quickstar t.exe
Shell folders Common Startup:
[C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart]
Adobe Reader - Schnellstart.lnk = C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe
HP Digital Imaging Monitor.lnk = C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe
Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
ATIModeChange = Ati2mdxx.exe
AGRSMMSG = AGRSMMSG.exe
Cpqset = C:\Programme\HPQ\Default Settings\cpqset.exe
SunJavaUpdateSched = C:\Programme\Java\jre1.5.0_06\bin\jusched.exe
iTunesHelper = C:\Programme\iTunes\iTunesHelper.exe
QuickTime Task = "C:\Programme\QuickTime\qttask.exe" -atboottime
ATIPTA = C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
UpdateManager = "C:\Programme\Gemeinsame Dateien\Sonic\Update Manager\sgtray.exe" /r
SynTPLpr = C:\Programme\Synaptics\SynTP\SynTPLpr.exe
SynTPEnh = C:\Programme\Synaptics\SynTP\SynTPEnh.exe
CamMonitor = C:\Programme\HP\Digital Imaging\Unload\hpqcmon.exe
Share-to-Web Namespace Daemon = C:\Programme\HP\HP Share-to-Web\hpgs2wnd.exe
HPHmon05 = C:\WINDOWS\System32\hphmon05.exe
HP Software Update = "C:\Programme\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
FLMOFFICE4DMOUSE = C:\Programme\Browser USB MOUSE\mouse32a.exe
ICQ Lite = C:\Programme\ICQLite\ICQLite.exe -minimize
avgnt = "C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min
New.net Startup = rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
CTFMON.EXE = C:\WINDOWS\System32\ctfmon.exe
MSMSGS = "C:\Programme\Messenger\msmsgs.exe" /background
MsnMsgr = "C:\Programme\MSN Messenger\MsnMsgr.Exe" /background
NCLaunch = C:\WINDOWS\NCLAUNCH.EXe
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run Once
ICQ Lite = C:\Programme\ICQLite\ICQLite.exe -trayboot
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\UNDERW~1.SCR
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\Programme\Java\jre1.5.0_06\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
--------------------------------------------------
Enumerating Task Scheduler jobs:
1-Klick-Wartung.job
{0E282F9B-3411-4270-BEFB-7B2301579EB3}_LILITH_Christina Bouchard.job
--------------------------------------------------
Enumerating Winsock LSP files:
Protocol #1: C:\Programme\NewDotNet\newdotnet7_22.dll
Protocol #2: C:\Programme\NewDotNet\newdotnet7_22.dll
Protocol #19: C:\Programme\NewDotNet\newdotnet7_22.dll
Protocol #20: C:\Programme\NewDotNet\newdotnet7_22.dll
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll
--------------------------------------------------
End of report, 7.033 bytes
Report generated in 0,060 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only