Logfile of HijackThis v1.97.7
Scan saved at 16:03:56, on 21-05-2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:/WINDOWS/System32/smss.exe
C:/WINDOWS/system32/winlogon.exe
C:/WINDOWS/system32/services.exe
C:/WINDOWS/system32/lsass.exe
C:/WINDOWS/System32/Ati2evxx.exe
C:/WINDOWS/system32/svchost.exe
C:/WINDOWS/System32/svchost.exe
C:/WINDOWS/system32/spoolsv.exe
C:/WINDOWS/system32/Ati2evxx.exe
C:/WINDOWS/Explorer.EXE
C:/WINDOWS/SOUNDMAN.EXE
C:/Programmer/Winamp/Winampa.exe
C:/Programmer/D-Tools/daemon.exe
C:/Programmer/ATI Technologies/ATI Control Panel/atiptaxx.exe
C:/PROGRA~1/ALWILS~1/Avast4/ashmaisv.exe
C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe
C:/Programmer/WIDCOMM/Bluetooth Software/BTTray.exe
C:/Programmer/Nokia/PC Suite for Nokia 6600/connmngmntbox.exe
C:/Programmer/Nokia/PC Suite for Nokia 6600/ectaskscheduler.exe
C:/Programmer/Intuwave/Shared/mRouterRunTime/mRouterRuntime.exe
C:/PROGRA~1/Nokia/PCSUIT~1/Elogerr.exe
C:/PROGRA~1/WIDCOMM/BLUETO~1/BTSTAC~1.EXE
C:/PROGRA~1/Nokia/PCSUIT~1/BROADC~1.EXE
C:/PROGRA~1/Nokia/PCSUIT~1/SCRFS.exe
C:/Programmer/Alwil Software/Avast4/aswUpdSv.exe
C:/Programmer/WIDCOMM/Bluetooth Software/bin/btwdins.exe
C:/WINDOWS/System32/svchost.exe
C:/Programmer/Internet Explorer/IEXPLORE.EXE
C:/Programmer/Internet Explorer/IEXPLORE.EXE
C:/Documents and Settings/Lars.G/Skrivebord/hijackthis.exe
R1 - HKCU/Software/Microsoft/Internet Explorer,SearchURL = http://www.windowws.cc/sp.htm?id=632
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Bar = res://C:/WINDOWS/System32/mcd.dll/sp.html (obfuscated)
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Page = res://C:/WINDOWS/System32/mcd.dll/sp.html (obfuscated)
R1 - HKCU/Software/Microsoft/Internet Explorer/Search,SearchAssistant = res://C:/WINDOWS/System32/mcd.dll/sp.html (obfuscated)
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Search Bar = res://C:/WINDOWS/System32/mcd.dll/sp.html (obfuscated)
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Search Page = res://C:/WINDOWS/System32/mcd.dll/sp.html (obfuscated)
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = about:blank
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Search_URL = res://mshp.dll/sp.html#37049
R0 - HKLM/Software/Microsoft/Internet Explorer/Search,SearchAssistant = res://C:/WINDOWS/System32/mcd.dll/sp.html (obfuscated)
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,HomeOldSP = about:blank
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {A9A674BF-771F-42E5-A440-D20DDA85A862} - C:/WINDOWS/System32/hg8bz0609k0rna.dll
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINDOWS/System32/msdxm.ocx
O3 - Toolbar: Pop-Up Stopper &Companion; - {8F05B1A8-9D77-4B8F-AF54-6B2202066F95} - C:/Programmer/Panicware/Pop-Up Stopper Companion/popupus.dll
O4 - HKLM/../Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM/../Run: [WinampAgent] “C:/Programmer/Winamp/Winampa.exe”
O4 - HKLM/../Run: [NeroCheck] C:/WINDOWS/system32/NeroCheck.exe
O4 - HKLM/../Run: [DAEMON Tools-1033] “C:/Programmer/D-Tools/daemon.exe” -lang 1033
O4 - HKLM/../Run: [ATIPTA] C:/Programmer/ATI Technologies/ATI Control Panel/atiptaxx.exe
O4 - HKLM/../Run: [avast!] C:/PROGRA~1/ALWILS~1/Avast4/ashDisp.exe
O4 - HKLM/../Run: [ashMaiSv] C:/PROGRA~1/ALWILS~1/Avast4/ashmaisv.exe
O4 - HKLM/../Run: [TkBellExe] “C:/Programmer/Fælles filer/Real/Update_OB/realsched.exe” -osboot
O4 - HKLM/../Run: [jopa] C:/WINDOWS/System32/sysstartup.exe
O4 - HKLM/../Run: [Image] rundll32 C:/WINDOWS/image.new,Install
O4 - HKCU/../Run: [jopa] C:/WINDOWS/System32/sysstartup.exe
O4 - HKCU/../Run: [uninstal] regsvr32 /u /s image.dll
O4 - HKCU/../RunServices: [Image] rundll32 C:/WINDOWS/image.new,Install
O4 - HKLM/../RunOnce: [SpyBotSnD] “C:/Programmer/Spybot - Search & Destroy/SpybotSD.exe” /autocheck
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: PCSuiteForNokia6600 Detect.lnk = ?
O4 - Global Startup: PCSuiteForNokia6600 TS.lnk = ?
O8 - Extra context menu item: E&ksporter; til Microsoft Excel - res://C:/PROGRA~1/MICROS~2/OFFICE11/EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth; - C:/Programmer/WIDCOMM/Bluetooth Software/btsendto_ie_ctx.htm
O9 - Extra button: ICQ (HKLM)
O9 - Extra ‘Tools’ menuitem: ICQ (HKLM)
O9 - Extra button: Opslag (HKLM)
O9 - Extra button: PartyPoker.com (HKLM)
O9 - Extra ‘Tools’ menuitem: PartyPoker.com (HKLM)
O9 - Extra button: @btrez.dll,-4015 (HKLM)
O9 - Extra ‘Tools’ menuitem: @btrez.dll,-4017 (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra ‘Tools’ menuitem: Messenger (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {5445BE81-B796-11D2-B931-002018654E2E} (MeadCo Security Manager) - http://egainlive.idatanet.com/wcsapp/weblib/Javascript/messaging/ie/SecMgr.cab
O16 - DPF: {91BE8DAC-957E-416C-B735-E2B63CDB915B} (MyEMessengerSetup Control) - http://www.myemessenger.com/activex/MyEMessengerSetupProject.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D3426292-3750-4D80-9D0F-2816F61A6D15} (SpeedTest Control) - http://81.19.245.211/speedtest/SpeedTest_2.cab
O16 - DPF: {FE5D6722-826F-11D5-A24E-0060B0F1A5AE} (Tukati Launcher) - http://3dgamers.tukati.com/tukati/1.7.20.20/tukati.cab
