Logfile of HijackThis v1.97.7
Scan saved at 16:52:17, on 19-05-2004
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINNTSystem32smss.exe
C:WINNTsystem32csrss.exe
C:WINNTsystem32winlogon.exe
C:WINNTsystem32services.exe
C:WINNTsystem32lsass.exe
C:WINNTsystem32svchost.exe
C:WINNTsystem32spoolsv.exe
C:WINNTSystem32Ati2evxx.exe
C:PROGRA~1GrisoftAVG6avgserv.exe
C:WINNTSystem32svchost.exe
C:NORMANNvcBINNPFSVICE.EXE
C:NormanNVCBINanda.exe
C:WINNTsystem32
egsvc.exe
C:WINNTsystem32MSTask.exe
C:WINNTsystem32stisvc.exe
C:WINNTSystem32WBEMWinMgmt.exe
C:WINNTsystem32svchost.exe
C:WINNTExplorer.exe
C:ProgrammerAnalog DevicesSoundMAXSMax4PNP.exe
C:ProgrammerWinampWinampa.exe
C:ProgrammerPCI Audio ApplicationsBinEchoCtrl.exe
C:WINNTMixer.exe
C:ProgrammerAnalog DevicesSoundMAXsmax4.exe
C:NormanNVCBINLH.EXE
C:PROGRA~1GrisoftAVG6avgcc32.exe
C:ProgrammerQuickTimeqttask.exe
C:ProgrammerLogitechMouseWaresystemem_exec.exe
C:WINNTSystem32internat.exe
C:ProgrammerMSN Messengermsnmsgr.exe
C:NORMANNvcBINNYMSE.EXE
C:NORMANNvcBINNIP.EXE
C:NORMANNvcBIN
pfmsg2.exe
C:ProgrammerWinZipWZQKPICK.EXE
C:ProgrammerMicrosoft OfficeOffice1030msoffice.exe
C:WINNTSystem32svchost.exe
C:NORMANNvcBIN
vcoas.exe
C:NORMANNvcBINNVCSCHED.EXE
C:NORMANNvcBIN
ipsvc.exe
C:NORMANNvcBINNJEEVES.EXE
C:NORMANNvcBINcclaw.exe
C:ProgrammerInternet Exploreriexplore.exe
C:Documents and SettingsPreben Færch NielsenSkrivebordhjt.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://www.tdconline.dk[...]
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = localhost
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:ProgrammerMyWaySearchAt3.binMWSSRCAS.DLL (file missing)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:ProgrammerAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:ProgrammerMyWebSearchar3.binMWSBAR.DLL (file missing)
O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:ProgrammerMyWebSearchar3.binMWSBAR.DLL (file missing)
O3 - Toolbar: @msdxmLC.dll,-1@1030,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINNTSystem32msdxm.ocx
O4 - HKLM..Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM..Run: [SoundMAXPnP] C:ProgrammerAnalog DevicesSoundMAXSMax4PNP.exe
O4 - HKLM..Run: [NeroCheck] C:WINNTSystem32\NeroCheck.exe
O4 - HKLM..Run: [WinampAgent] "C:ProgrammerWinampWinampa.exe"
O4 - HKLM..Run: [LoadQM] loadqm.exe
O4 - HKLM..Run: [MyWebSearch Email Plugin] C:PROGRA~1MYWEBS~1ar3.binmwsoemon.exe
O4 - HKLM..Run: [C-Media Echo Control] C:ProgrammerPCI Audio ApplicationsBinEchoCtrl.exe
O4 - HKLM..Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM..Run: [SoundMax] "C:ProgrammerAnalog DevicesSoundMAXsmax4.exe" /tray
O4 - HKLM..Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM..Run: [Norman ZANDA] C:NormanNVCBINLH.EXE /LOAD /SPLASH
O4 - HKLM..Run: [Ass and titties] cmd32.exe
O4 - HKLM..Run: [AVG_CC] C:PROGRA~1GrisoftAVG6avgcc32.exe /STARTUP
O4 - HKLM..Run: [QuickTime Task] "C:ProgrammerQuickTimeqttask.exe" -atboottime
O4 - HKLM..RunServices: [Ass and titties] cmd32.exe
O4 - HKCU..Run: [internat.exe] internat.exe
O4 - HKCU..Run: [MyWebSearch Email Plugin] C:PROGRA~1MYWEBS~1ar3.binmwsoemon.exe
O4 - HKCU..Run: [Skype] "C:ProgrammerSkypePhoneSkype.exe" /nosplash /minimized
O4 - HKCU..Run: [H/PC Connection Agent] "C:ProgrammerMicrosoft ActiveSyncWCESCOMM.EXE"
O4 - HKCU..Run: [msnmsgr] "C:ProgrammerMSN Messengermsnmsgr.exe" /background
O4 - Startup: MyWebSearch Email Plugin.lnk = C:ProgrammerMyWebSearchar3.binMWSOEMON.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:ProgrammerLogitechDesktop Messenger8876480ProgramLDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:ProgrammerMicrosoft OfficeOfficeOSA9.EXE
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:ProgrammerMyWebSearchar3.binMWSOEMON.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:ProgrammerWinZipWZQKPICK.EXE
O8 - Extra context menu item: &Search -
http://bar.mywebsearch.com[...]
O8 - Extra context menu item: Tilføj Link Til Online Bookmark - Res://C:ProgrammerTDC Online MenubarTDCOBar.dll/ADDBOOKMARKLINK_HTM
O9 - Extra button: Create Mobile Favorite (HKLM)
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .spop: C:ProgrammerInternet ExplorerPluginsNPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://www.apple.com[...]
O16 - DPF: {0D06CDB2-163D-46FD-94B7-BD3B1D69F846} (WDX.WDX_Main) -
https://www.web-direct.dk[...]
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
http://download.macromedia.com[...]
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.com[...]
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) -
http://www.cult3d.com[...]
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) -
http://office.microsoft.com[...]
O16 - DPF: {41A22D90-5502-4C52-9FB7-67901FBBD515} (Util Class) -
https://udstedelse.certifikat.tdc.dk[...]
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net[...]
O16 - DPF: {7AEBACC1-D7E4-4360-B520-6DA4C565B42C} (UploaderCtrl Class) -
http://foto.tdconline.dk[...]
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
http://v4.windowsupdate.microsoft.com[...]
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} (IEAnimBehaviorFactory Class) -
http://download.microsoft.com[...]
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com[...]
O16 - DPF: {D3426292-3750-4D80-9D0F-2816F61A6D15} (SpeedTest Control) -
http://81.19.245.211[...]
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) -
http://www2.incredimail.com[...]
^^
her er den?
--
vildere klovn, vildere..!
Jada.. :D nyt vildt site.. : http://www.mmoforum.tk[...]
Så kigger vi lige ind i mit eget lille pæne drivhus: http://www.growyourownshit.com[...]