Logfile of HijackThis v1.95.1
Scan saved at 16:29:42, on 21-07-2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Programmer\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe
C:\Programmer\Panda Software\Panda Antivirus Titanium\AVENGINE.EXE
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Panda Software\Panda Antivirus Titanium\apvxdwin.exe
C:\Programmer\Panda Software\Panda Antivirus Titanium\pavProxy.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Programmer\Logitech\iTouch\iTouch.exe
C:\Programmer\Desktop Messenger\8876480\Program\backWeb-8876480.exe
C:\Programmer\MusicMatch\MusicMatch Jukebox\mm_tray.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\Save\Save.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
C:\Programmer\Logitech\MouseWare\system\em_exec.exe
C:\Documents and Settings\Henning S\Skrivebord\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://vrape.hardloved.com/top/search.php?id=1&s=R1 - HKCU\Software\Microsoft\Internet Explorer,Search Page =
http://vrape.hardloved.com/top/search.php?id=1&s=R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://vrape.hardloved.com/top/search.php?id=1&s=R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://vrape.hardloved.com/top/search.php?id=1&s=R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.separations.dk/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://vrape.hardloved.com/top/search.php?id=1&s=R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://vrape.hardloved.com/top/search.php?id=1&s=R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://vrape.hardloved.com/top/search.php?id=1&s=R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://vrape.hardloved.com/top/search.php?id=1&s=R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://vrape.hardloved.com/top/search.php?id=1&s=R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://vrape.hardloved.com/top/search.php?id=1&s=R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://vrape.hardloved.com/top/search.php?id=1&s=R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://vrape.hardloved.com/top/search.php?id=1&s=R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
http://vrape.hardloved.com/top/search.php?id=1&s=R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
http://vrape.hardloved.com/top/search.php?id=1&s=R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O1 - Hosts: 65.77.83.222 thehun.com
O1 - Hosts: 65.77.83.222 thehun.net
O1 - Hosts: 65.77.83.222 madthumbs.com
O1 - Hosts: 65.77.83.222 worldsex.com
O1 - Hosts: 65.77.83.222 teeniefiles.com
O1 - Hosts: 65.77.83.222 al4a.com
O1 - Hosts: 65.77.83.222 sublimedirectory.com
O1 - Hosts: 65.77.83.222 thumbzilla.com
O1 - Hosts: 65.77.83.222 sexocean.com
O1 - Hosts: 65.77.83.222 easypic.com
O1 - Hosts: 65.77.83.222 absolut-series.com
O1 - Hosts: 65.77.83.222 jpeg4free.com
O1 - Hosts: 65.77.83.222 thumbnailpost.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMMER\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {1E1B2879-88FF-11D2-8D96-D7ACAC95951F} - C:\PROGRAMMER\COMMONNAME\TOOLBAR\CNBARIE.DLL
O2 - BHO: (no name) - {1F48AA48-C53A-4E21-85E7-AC7CC6B5FFA8} - C:\DOCUME~1\HENNIN~1\LOKALE~1\Temp\winlhfp.dll
O2 - BHO: (no name) - {A6475E6B-3C2E-4B1F-82FD-8F1C0B1D8AD0} - C:\PROGRAMMER\COMMONNAME\TOOLBAR\BABEIE.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: CommonName - {A3E3F04C-F98C-4295-95EF-41C57425B077} - C:\PROGRAMMER\COMMONNAME\TOOLBAR\CNBARIE.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\downloaded program files\GoogleToolbar_da_1.1.62-deleon.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.ExE
O4 - HKLM\..\Run: [APVXDWIN] "C:\Programmer\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Programmer\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [LDM] C:\Programmer\Desktop Messenger\8876480\Program\backWeb-8876480.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LDM] C:\Programmer\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [od-stnd36] c:\program files\Webdialer\od-stnd36.exe -m
O4 - Global Startup: Photo Express Calendar Checker SE.lnk = C:\Programmer\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programmer\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &Google Search -
res://c:\windows\downloaded program files\GoogleToolbar_da_1.1.62-deleon.dll/cmsearch.html
O8 - Extra context menu item: Add A Page Note - C:\Programmer\CommonName\Toolbar\createnote.htm
O8 - Extra context menu item: Backward &Links -
res://c:\windows\downloaded program files\GoogleToolbar_da_1.1.62-deleon.dll/cmbacklinks.html
O8 - Extra context menu item: Bookmark This Page - C:\Programmer\CommonName\Toolbar\createbookmark.htm
O8 - Extra context menu item: Cac&hed Snapshot of Page -
res://c:\windows\downloaded program files\GoogleToolbar_da_1.1.62-deleon.dll/cmcache.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel -
res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000O8 - Extra context menu item: Email This Link - C:\Programmer\CommonName\Toolbar\emaillink.htm
O8 - Extra context menu item: Search using CommonName - C:\Programmer\CommonName\Toolbar\navigate.htm
O8 - Extra context menu item: Si&milar Pages -
res://c:\windows\downloaded program files\GoogleToolbar_da_1.1.62-deleon.dll/cmsimilar.html
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .mp3: C:\Programmer\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .pic: C:\Programmer\Internet Explorer\PLUGINS\npqtplugin4.dll
O13 - DefaultPrefix:
http://vrape.hardloved.com/top/search.php?id=1&s=O13 - WWW Prefix:
http://vrape.hardloved.com/top/search.php?id=1&s=O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cabO16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akamai.net/7/1540/52/20020909/qtinstall.info.apple.com/qt505/dk/win/QuickTimeInstaller.exeO16 - DPF: {4E15D681-1D20-11D4-8B72-000021DA1956} -
http://home.wanadoo.nl/mirjam.klaassen/kira_eggers/xsnow.exeO16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} (Google Activate) -
http://toolbar.google.com/data/da/deleon/1.1.54-deleon/GoogleNav.cabO16 - DPF: {8522F9B3-38C5-4AA4-AE40-7401F1BBC851} -
http://2passwords.com/all_FREE_xxx.exeO16 - DPF: {A45F39DC-3608-4237-8F0E-139F1BC49464} -
http://64.157.10.150/diallerfiles/030813.exeO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {EB6AFDAB-E16D-430B-A5EE-0408A12289DC} -
http://download.mediacharger.com/movienetworks.cabO16 - DPF: {F6A56D95-A3A3-11D2-AC26-400000058481} (Danske e-Sec) -
https://netbank.danskebank.dk/netbank/activex/DanskeSikker.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{9EC7892C-B547-41C9-895C-0A8A21A6EE20}: Domain = stofanet.dk
O17 - HKLM\System\CCS\Services\Tcpip\..\{9EC7892C-B547-41C9-895C-0A8A21A6EE20}: NameServer = 212.10.30.252,212.10.10.4,212.10.10.5