Logfile of HijackThis v1.98.0
Scan saved at 16:33:24, on 15-08-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\MMTray.exe
C:\WINDOWS\System32\MMTray2k.exe
C:\WINDOWS\System32\MMTrayLSI.exe
C:\Programmer\NuCam Corp\CamCheck\CamCheck.exe
C:\WINDOWS\TEMP\sidvff.exe
C:\Programmer\Fælles filer\Logitech\QCDriver\LVCOMS.EXE
c:\progra~1\intern~1\iexplore.exe
c:\progra~1\intern~1\iexplore.exe
C:\Documents and Settings\thomas\Application Data\uoea.exe
C:\WINDOWS\system32\winmm64.exe
C:\WINDOWS\system32\32mshh32.exe
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\twain_32\SiPix\SCBlink2\Srvany.exe
C:\WINDOWS\System32\LckFldService.exe
C:\WINDOWS\twain_32\SiPix\SCBlink2\USBPNP.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Programmer\MSN Messenger\msnmsgr.exe
C:\Programmer\eDonkey2000\edonkey2000.exe
C:\DOCUME~1\thomas\LOKALE~1\Temp\cxqx6p06wr.exe
C:\DOCUME~1\thomas\LOKALE~1\Temp\pr06tq7wkbfp.exe
C:\DOCUME~1\thomas\LOKALE~1\Temp\m9qp7l5.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\DOCUME~1\thomas\LOKALE~1\Temp\8jzwz1ne22s.exe
C:\Documents and Settings\thomas\Skrivebord\hijackthis.exe
C:\WINDOWS\System32\NET.exe
C:\WINDOWS\System32\NET.exe
C:\WINDOWS\System32\NET.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://countere.com/?a=2&b=cfhR1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL =
http://countere.com/?a=2&b=cfhR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://countere.com/?a=2&b=cfhR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://countere.com/?b=cfhR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://countere.com/?a=2&b=cfhR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.hfzohxrfcqswhfsipvqdrnrl.com/BEqNV_ZuJVqFUx_DUc9qYk_coS9Z0sRXwixyJdPyAVHlOPOtoaz_SUZY4HuFWqQX.phpR1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL =
http://countere.com/?a=2&b=cfhR1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,SearchURL =
http://countere.com/?a=2&b=cfhR3 - URLSearchHook: (no name) - _{00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {6AFD6122-9712-2694-8070-65550AA12A3E} - C:\WINDOWS\System32\csaofu.dll (file missing)
O2 - BHO: (no name) - {95FAD5A8-EA77-87D6-E847-8DD2454F4FF4} - C:\PROGRA~1\SETUPF~1\amok drive.exe
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [MMTray] MMTray.exe
O4 - HKLM\..\Run: [MMTray2K] MMTray2k.exe
O4 - HKLM\..\Run: [MMTrayLSI] MMTrayLSI.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CamCheck] C:\Programmer\NuCam Corp.\CamCheck\CamCheck.exe
O4 - HKLM\..\Run: [sidvff.exe] C:\WINDOWS\TEMP\sidvff.exe
O4 - HKLM\..\Run: [akcllhlrdf] C:\WINDOWS\System32\mrdixw.exe
O4 - HKLM\..\Run: [ihin] C:\WINDOWS\ihin.exe
O4 - HKLM\..\Run: [svqbwfmx] C:\WINDOWS\svqbwfmx.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Programmer\Fælles filer\Logitech\QCDriver\LVCOMS.EXE
O4 - HKLM\..\Run: [pir] C:\WINDOWS\pir.exe
O4 - HKLM\..\Run: [Barb Site] C:\PROGRA~1\FLAP TRANS\Ref Cool.exe
O4 - HKLM\..\Run: [ooze dog license that] C:\Documents and Settings\All Users\Application Data\way dumb ooze dog\Does camp.exe
O4 - HKCU\..\Run: [Steam] C:\Programmer\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [Uwci] C:\Documents and Settings\thomas\Application Data\uoea.exe
O4 - HKCU\..\Run: [SpywareGuard] C:\WINDOWS\system32\winmm64.exe
O4 - HKCU\..\Run: [32mshh32] C:\WINDOWS\system32\32mshh32.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Programmer\Webroot\Spy Sweeper\SpySweeper.exe" /0
O8 - Extra context menu item: E&ksporter til Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O16 - DPF: {53B3ABEA-4445-44D9-A01E-088144CAABD9} (FileSharingCtrl Class) -
http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/da/filesharingctrl.cabO16 - DPF: {AD688740-5246-40C3-AF27-090006046834} -
http://www.xpehbam.biz/5/load.exeO16 - DPF: {B94B4225-E02E-4D3F-BADB-026F1E2F3AD7} (HttpDownloader Control) -
http://www.instantplugin.com/SexDownloader.cabO16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) -
https://netbank.bgbank.dk/html/activex/e-Safekey/BG/e-Safekey.cab