Logfile of HijackThis v1.97.7
Scan saved at 18:24:08, on 13-11-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSSystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:ProgrammerTGTSoftStyleXPStyleXPService.exe
C:ProgrammerSygateSPFsmc.exe
C:WINDOWSsystem32spoolsv.exe
C:ProgrammerAlwil SoftwareAvast4aswUpdSv.exe
C:ProgrammerAlwil SoftwareAvast4ashServ.exe
C:WINDOWSSystem32
_server.exe
C:ProgrammerAnalog DevicesSoundMAXSMAgent.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSystem32wruaclt.exe
C:ProgrammerATI TechnologiesATI Control Panelatiptaxx.exe
C:WINDOWSSystem32G-VGA.exe
C:programmerpowerstrippstrip.exe
C:ProgrammerAnalog DevicesSoundMAXSMax4PNP.exe
C:ProgrammerAnalog DevicesSoundMAXSmax4.exe
C:PROGRA~1ALWILS~1Avast4ashDisp.exe
C:WINDOWSSystem32ctfmon.exe
C:ProgrammerSecwaySimpLite-MSN 2.1SimpLite-MSN.exe
C:ProgrammerMSN Messengermsnmsgr.exe
C:vzzmircvzzmircmirc.exe
C:Documents and SettingsOblivion^SkrivebordHijackThis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://www.google.dk[...]
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://www.microsoft.com[...]
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page =
http://www.microsoft.com[...]
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
http://www.microsoft.com[...]
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL =
http://www.microsoft.com[...]
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) =
http://home.microsoft.com[...]
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page =
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Hyperlinks
R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,Shellnext =
http://www.microsoft.com[...]
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:ProgrammerAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx
O3 - Toolbar: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O4 - HKLM..Run: [ATIPTA] C:ProgrammerATI TechnologiesATI Control Panelatiptaxx.exe
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [VGAUtil] C:WINDOWSSystem32G-VGA.exe
O4 - HKLM..Run: [Jet Detection] C:ProgrammerCreativeSBLivePROGRAMADGJDet.exe
O4 - HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k
O4 - HKLM..Run: [PowerStrip] c:programmerpowerstrippstrip.exe
O4 - HKLM..Run: [SoundMAXPnP] C:ProgrammerAnalog DevicesSoundMAXSMax4PNP.exe
O4 - HKLM..Run: [SoundMAX] "C:ProgrammerAnalog DevicesSoundMAXSmax4.exe" /tray
O4 - HKLM..Run: [avast!] C:PROGRA~1ALWILS~1Avast4ashDisp.exe
O4 - HKLM..Run: [SmcService] C:PROGRA~1SygateSPFsmc.exe -startgui
O4 - HKLM..Run: [*windows update] wruaclt.exe
O4 - HKLM..RunServices: [*windows update] wruaclt.exe
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 - HKCU..Run: [STYLEXP] C:ProgrammerTGTSoftStyleXPStyleXP.exe -Hide
O4 - HKCU..Run: [Simp] C:ProgrammerSecwaySimpLite-MSN 2.1SimpLite-MSN.exe
O4 - HKCU..Run: [*windows update] wruaclt.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O8 - Extra context menu item: Download all by Net Transport - C:ProgrammerXiNetTransport 2NTAddList.html
O8 - Extra context menu item: Download by Net Transport - C:ProgrammerXiNetTransport 2NTAddLink.html
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
http://download.macromedia.com[...]
O16 - DPF: {3334504D-9980-0010-8000-00AA00389B71} -
http://download.microsoft.com[...]
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplanet.com[...]
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net[...]
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com[...]
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) -
https://netbank.bgbank.dk[...]
--