Re: After the update, I got hacked by the ads company

From: Rob (Rob_at_discussions.microsoft.com)
Date: 10/17/04


Date: Sat, 16 Oct 2004 22:33:01 -0700

Program = 1st line
Command = 2nd line
User Name = 3rd line
Location = 4th line
>From what I know about the application = 5th

ATIModeChange
ati2mdxx.exe
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ATI graphic card stuff

ATIPTA
c:\program files\ati technologies\ati control panel\atiptaxx.exe
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ATI graphic card stuff

Adobe Gamma Loader
c:\progra~1\common~1\adobe\calibr~1\adobeg~1.exe
All Users
Common Startup
Adobe program

Apoint
c:\program files\apoint\apoint.exe
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Mouse pointer program for laptop

Billminder
c:\progra~1\quicken\billmind.exe -startup
All Users
Common Startup
Tax(investment) Program

CARPService
carpserv.exe
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
drivers for modem

HP Component Manager
"c:\program files\hp\hpcoretech\hpcmpmgr.exe"
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
For Printer

HP Software Update
"c:\program files\hewlett-packard\hp software update\hpwuschd2.exe"
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
For Printer

HPDJ Taskbar Utility
c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
For Printer

HPHUPD05
c:\program
files\hewlett-packard\{45b6180b-dcab-4093-8ee8-6164457517f0}\hphupd05.exe
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
For Printer

HPHmon05
c:\windows\system32\hphmon05.exe
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
For printer

IMJPMIG8.1
"c:\windows\ime\imjp8_1\imjpmig.exe" /spoil /remadvdef /migration32
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
File description said Microsoft IME

Kqrgl
c:\windows\system32\mѕiexec.exe
SONYPCG-FRV31\Chun Yip
HKU\S-1-5-21-3614739572-3038117068-3148897578-1005
\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
No idea

MSMSGS
"c:\program files\messenger\msmsgs.exe" /background
NT AUTHORITY\SYSTEM
HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Msn Messenger

MSMSGS
"c:\program files\messenger\msmsgs.exe" /background
.DEFAULT
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
MSN Messenger

MSNSysRestore
c:\windows\system32\pc32.exe bg
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
System Restore

MSPY2002
c:\windows\system32\ime\pintlgnt\imscinst.exe /sync
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
No idea

MessengerPlus3
"c:\program files\messenger plus! 3\msgplus.exe" /winstart
SONYPCG-FRV31\Chun Yip
HKU\S-1-5-21-3614739572-3038117068-3148897578-1005
\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Extra stuff for MSN messenger

MessengerPlus3
"c:\program files\messenger plus! 3\msgplus.exe"
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Extra stuff for MSN messneger

Microsoft Office
c:\progra~1\mi1933~1\office10\osa.exe -b -l
All Users
Common Startup
Microsoft Product

Microsoft Works Update Detection
c:\program files\common files\microsoft shared\works shared\wkufind.exe
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft Product

MoneyAgent
"c:\program files\microsoft money\system\mnyexpr.exe"
SONYPCG-FRV31\Chun Yip
HKU\S-1-5-21-3614739572-3038117068-3148897578-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft product

Mouse Suite 98 Daemon
ico.exe
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
No idea, maybe mouse stuff

NeroFilterCheck
c:\windows\system32\nerocheck.exe
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Burner program

PHIME2002A
c:\windows\system32\ime\tintlgnt\tintsetp.exe /imename
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
No idea

PHIME2002ASync
c:\windows\system32\ime\tintlgnt\tintsetp.exe /sync
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
No idea

QuickTime Task
"c:\program files\quicktime\qttask.exe" -atboottime
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
MediaPlayer Program

Quicken Scheduled Updates
c:\progra~1\quicken\bagent.exe
All Users
Common Startup
Tax(Investmnet) Program

Quicken Startup
c:\progra~1\quicken\qwdlls.exe
All Users
Common Startup
Tax(Investment) Program

SunJavaUpdateSched
c:\program files\java\j2re1.4.2_05\bin\jusched.exe
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Java Program

TkBellExe
"c:\program files\common files\real\update_ob\realsched.exe" -osboot
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
No idea, but look like Real Player Product

VAIO Recovery
c:\windows\sonysys\vaio recovery\partseal.exe
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Laptop itself, Recovery stuff

ZTgServerSwitch
"c:\program files\support.com\client\bin\tgcmd.exe" /server
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Sony VAIO laptop stuff

ccApp
"c:\program files\common files\symantec shared\ccapp.exe"
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
It looks like Norton Anti-Virus Product

ccRegVfy
"c:\program files\common files\symantec shared\ccregvfy.exe"
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
It looks like Norton Anti-Virus Product

ctfmon.exe
c:\windows\system32\ctfmon.exe
SONYPCG-FRV31\Chun Yip
HKU\S-1-5-21-3614739572-3038117068-3148897578-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
No Idea

desktop desktop.ini NT AUTHORITY\SYSTEM Startup

desktop desktop.ini SONYPCG-FRV31\Chun Yip Startup

desktop desktop.ini .DEFAULT Startup

desktop desktop.ini All Users Common Startup
No IDEA

ezShieldProtector for Px
c:\windows\system32\ezsp_px.exe
All Users
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
No Idea

msnmsgr
"c:\program files\msn messenger\msnmsgr.exe" /background
SONYPCG-FRV31\Chun Yip
HKU\S-1-5-21-3614739572-3038117068-3148897578-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
MSN Messenger

"Dave Patrick" wrote:
> * Try Start|Run|msinfo32.exe and paste in the body of a reply the contents
> of "Startup Programs"
>
>
> --
> Regards,
>
> Dave Patrick ....Please no email replies - reply in newsgroup.
> Microsoft Certified Professional
> Microsoft MVP [Windows]
> http://www.microsoft.com/protect
>
>
>



Relevant Pages