Logfile of HijackThis v1.97.7
Scan saved at 19:44:36, on 16-06-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\apikn.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\HighCriteria\TotalRecorder\TotRecSched.exe
C:\WINDOWS\System32\ewpxjkag.exe
C:\Programmer\Messenger\msmsgs.exe
C:\WINDOWS\system32\appmy32.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
C:\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
res://C:\WINDOWS\system32\xrclt.dll/sp.html#96676R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
res://xrclt.dll/index.html#96676R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
res://xrclt.dll/index.html#96676R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
res://C:\WINDOWS\system32\xrclt.dll/sp.html#96676R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
res://xrclt.dll/index.html#96676R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
res://C:\WINDOWS\system32\xrclt.dll/sp.html#96676O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\twaintec.dll
O2 - BHO: (no name) - {63F55AAB-207A-4070-C941-3AF6DF73213B} - C:\WINDOWS\sdkxn32.dll
O2 - BHO: (no name) - {F7F808F0-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem217.dll
O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Programmer\HighCriteria\TotalRecorder\TotRecSched.exe"
O4 - HKLM\..\Run: [fwfguupwb] C:\WINDOWS\System32\ewpxjkag.exe
O4 - HKLM\..\Run: [appmy32.exe] C:\WINDOWS\system32\appmy32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\Programmer\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O4 - HKCU\..\Run: [SpyKiller] C:\Programmer\SpyKiller\spykiller.exe /startup
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O12 - Plugin for .mov: C:\Programmer\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cabO16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} -
http://www.mt-download.com/MediaTicketsInstaller.cab