Logfile of HijackThis v1.97.7
Scan saved at 21:17, on 18-04-2004
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAMMER\CANON\MULTIPASS4\MPTBOX.EXE
C:\PROGRAMMER\TDC INTERNET\WINPPPOVERETHERNET.EXE
C:\PROGRAMMER\PANDA SOFTWARE\PANDA ANTIVIRUS TITANIUM\APVXDWIN.EXE
C:\WINDOWS\SYSTEM32\WINPROC32.EXE
C:\HPOJTPRO\DTOLE.EXE
C:\HPOJTPRO\PROCDB.EXE
C:\PROGRAMMER\PANDA SOFTWARE\PANDA ANTIVIRUS TITANIUM\PAVPROXY.EXE
C:\PROGRAMMER\CANON\MULTIPASS4\MPDBMGR.EXE
C:\PROGRAMMER\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAMMER\FæLLES FILER\MICROSOFT SHARED\MSINFO\MSINFO32.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\HJT.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://4-counter.com/?a=2&b=diaR1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL =
http://brutal-video.net/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://4-counter.com/?a=2&b=diaR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://4-counter.com/?a=2&b=diaR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://4-counter.com/?b=diaR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ultralinks.info/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://drusearch.com/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://4-counter.com/?a=2&b=diaR1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.nkvd.us/s.htmR1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL =
http://4-counter.com/?a=2&b=diaR1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL =
http://brutal-video.net/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://4-counter.com/?a=2&b=diaR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://4-counter.com/?a=2&b=diaR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://drusearch.com/search.htmlR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://4-counter.com/?a=2&b=diaR1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://teenhqpics.com/r/scr.phpR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=HS01:80;ftp=HS01:80;gopher=HS01:80;https=HS01:80
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP =
http://search123.biz/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R1 - HKCU\Software\Microsoft\Internet Explorer,Search =
http://www.nkvd.us/s.htmR1 - HKLM\Software\Microsoft\Internet Explorer,Search =
http://www.nkvd.us/s.htmF1 - win.ini: load=c:\hpojtpro\onlreg\remind.exe
O1 - Hosts: 5377608764 spywareinfo.com
O1 - Hosts: 5377608764
www.spywareinfo.comO1 - Hosts: 5377608764 lavasoftsupport.com
O1 - Hosts: 5377608764
www.lavasoftsupport.comO1 - Hosts: 5377608764 searchv.com
O1 - Hosts: 5377608764
www.searchv.comO1 - Hosts: 5377608764 approvedlinks.com
O1 - Hosts: 5377608764
www.approvedlinks.comO1 - Hosts: 5377608764 searching-the-net.com
O1 - Hosts: 5377608764
www.searching-the-net.comO1 - Hosts: 5377608764 ywebsearch.info
O1 - Hosts: 5377608764
www.ywebsearch.infoO1 - Hosts: 5377608764 ok-search.com
O1 - Hosts: 5377608764
www.ok-search.comO1 - Hosts: 5377608764 ewebsearch.net
O1 - Hosts: 5377608764
www.ewebsearch.netO1 - Hosts: 5377608764
www.008k.comO1 - Hosts: 5377608764 autosearcher.com
O1 - Hosts: 5377608764
www.autosearcher.comO1 - Hosts: 5377608764
www.smutserver.comO1 - Hosts: 5377608764
www.smuthosts.comO1 - Hosts: 5377608764
www.kinghost.comO1 - Hosts: 5377608764 exit.xitcash.com
O1 - Hosts: 5377608764
www.exitforcash.comO1 - Hosts: 5377608764 exit.sellyourexit.com
O1 - Hosts: 5377608764 sex-explorer.com
O1 - Hosts: 5377608764
www.sex-explorer.comO1 - Hosts: 5377608764
www.online-dialer.comO1 - Hosts: 5377608764 network.nocreditcard.com
O1 - Hosts: 5377608764
www.mtreexxx.netO1 - Hosts: 5377608764
www.0190-dialer.comO1 - Hosts: 5377608764 install.xxxtoolbar.com
O1 - Hosts: 5377608764
www.xxxtoolbar.comO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Skan registreringsdatabase] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [MPTBox] C:\Programmer\Canon\MultiPASS4\MPTBox.exe
O4 - HKLM\..\Run: [WinPoET] C:\Programmer\TDC Internet\WinPPPoverEthernet.exe
O4 - HKLM\..\Run: [APVXDWIN] "C:\Programmer\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [keymgrldr] rundll32 setupapi,InstallHinfSection Oemkeymgr9x 128 keymgr3.inf
O4 - HKLM\..\Run: [Windows Security Assistant] C:\WINDOWS\system32\rundll32.vbe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [Windows Security Assistant] C:\WINDOWS\system32\rundll32.vbe
O4 - HKCU\..\Run: [Windows Security Assistant] C:\WINDOWS\system32\rundll32.vbe
O4 - HKCU\..\Run: [Windows Internet Protocol] C:\WINDOWS\SYSTEM32\WINPROC32.EXE
O4 - Startup: HP PictureLink.lnk = C:\HPOJTPRO\DTOle.exe
O4 - Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O13 - WWW. Prefix: http://
O16 - DPF: {DC840BE3-16D9-11D0-BA39-00C04FDDB4CD} (Conveyer-kontrolenhed) -
http://cdm.microsoft.com/update/Jan8/OSB/6/conveyer1.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as/asinst.cabO16 - DPF: {486E48B5-ABF2-42BB-A327-2679DF3FB822} -
http://akamai.downloadv3.com/binaries/IA/ia.cabO16 - DPF: {CEFB7B49-9652-464F-8AFD-A577C0500F39} (EGP2ECOM Class) -
http://akamai.downloadv3.com/binaries/P2EClient/EGAUTH_pack.cabO16 - DPF: {03C543A1-C090-418F-A1D0-FB96380D601D} (preload control) -
http://www.thepaymentcentre.com/build/preload.cabO16 - DPF: {7589EEE6-E336-11D4-8A7E-EE1D971D9B47} (AcontiX Control) -
http://secure.aconti.net/acontix/goodthinxx.cabO16 - DPF: {2048B51E-8D74-4762-82CE-B48CF545EEEA} (CAX Object) -
http://download4.payoutpal.com/download/dialer/cax.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38092.3136342593O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} -
http://www.netvenda.com/sites/games-intl/dk/games1.cab