Logfile of HijackThis v1.99.1
Scan saved at 00:23:07, on 23-03-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
D:\XP\System32\smss.exe
D:\XP\system32\winlogon.exe
D:\XP\system32\services.exe
D:\XP\system32\lsass.exe
D:\XP\system32\svchost.exe
D:\XP\System32\svchost.exe
F:\Sygate\SPF\smc.exe
D:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
D:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
D:\XP\system32\spoolsv.exe
J:\Apache2\Apache2\bin\Apache.exe
D:\XP\system32\drivers\CDAC11BA.EXE
D:\XP\system32\CTsvcCDA.exe
D:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
J:\mysql\bin\mysqld-nt.exe
F:\Norton SystemWorks\Norton Antivirus\navapsvc.exe
F:\NORTON~1\NORTON~2\NPROTECT.EXE
J:\Apache2\Apache2\bin\Apache.exe
D:\XP\system32\nvsvc32.exe
F:\Norton SystemWorks\Norton Antivirus\SAVScan.exe
C:\SFMGR\sfmgr.exe
D:\XP\System32\svchost.exe
D:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
D:\XP\Explorer.EXE
D:\XP\system32\UAService7.exe
D:\XP\system32\MsPMSPSv.exe
D:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
D:\XP\htpatch.exe
F:\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
F:\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
D:\XP\system32\CTHELPER.EXE
F:\D-Tools\daemon.exe
D:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
F:\AD-AWA~1\Ad-Watch.exe
D:\Programmer\PestPatrol\PPControl.exe
D:\Programmer\PestPatrol\PPMemCheck.exe
D:\Programmer\PestPatrol\CookiePatrol.exe
F:\HP\HP Software Update\HPWuSchd2.exe
F:\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
F:\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
D:\Programmer\MSN Messenger\MsnMsgr.Exe
D:\Programmer\Logitech\MouseWare\system\em_exec.exe
D:\XP\system32\ctfmon.exe
D:\XP\system32\rundll32.exe
J:\Apache2\Apache2\bin\ApacheMonitor.exe
F:\Microsoft Office\OFFICE11\OUTLOOK.EXE
D:\Programmer\Messenger\msmsgs.exe
D:\Programmer\Internet Explorer\iexplore.exe
G:\Project Entropia\ClientLoader.exe
D:\Programmer\Internet Explorer\iexplore.exe
D:\XP\system32\notepad.exe
F:\Norton SystemWorks\Norton Antivirus\OPScan.exe
D:\Documents and Settings\nikolaj\Skrivebord\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.liverpoolfans.dk/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: CFilter Object - {2A7B720A-7A28-4e99-80A0-2DF985EC93D0} - D:\XP\system32\font.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - F:\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - F:\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - F:\Norton SystemWorks\Norton Antivirus\NavShExt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - F:\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [HTpatch] D:\XP\htpatch.exe
O4 - HKLM\..\Run: [SiSUSBRG] D:\XP\SiSUSBrg.exe
O4 - HKLM\..\Run: [CTSysVol] f:\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] f:\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [DAEMON Tools-1033] "F:\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [ccApp] "D:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\XP\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AWMON] "F:\AD-AWA~1\Ad-Watch.exe"
O4 - HKLM\..\Run: [SmcService] F:\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [PestPatrol Control Center] D:\Programmer\PestPatrol\PPControl.exe
O4 - HKLM\..\Run: [PPMemCheck] D:\Programmer\PestPatrol\PPMemCheck.exe
O4 - HKLM\..\Run: [CookiePatrol] D:\Programmer\PestPatrol\CookiePatrol.exe
O4 - HKLM\..\Run: [HP Software Update] "F:\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] D:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [NeroFilterCheck] D:\XP\system32\NeroCheck.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] F:\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AdobeVersionCue] f:\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] D:\XP\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Programmer\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Monitor Apache Servers.lnk = J:\Apache2\Apache2\bin\ApacheMonitor.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) -
http://www.creative.com/su/ocx/15009/CTSUEng.cabO16 - DPF: {89A312AE-8D21-42B1-848B-FD8E27F9A2A9} (PrimeInk for Web Applications Signing Component) -
https://webreg.dk/web.dllO16 - DPF: {A590956F-AE99-4419-BB39-3C721276C625} (Util Class) -
https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-0504.exeO16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) -
https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cabO16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://www.creative.com/su/ocx/15009/CTPID.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{5AFDB601-D6EA-4345-93B1-1172A8E2A51A}: NameServer = 212.242.40.3,212.242.40.51
O23 - Service: Apache2 - Unknown owner - J:\Apache2\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - D:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - D:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - D:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\XP\system32\CTsvcCDA.exe
O23 - Service: Flash Communication Server (FlashCom) - Macromedia, Inc. - j:\Flash Communication Server MX\FlashCom.exe
O23 - Service: Flash Communication Admin Service (FlashComAdmin) - Macromedia, Inc. - j:\Flash Communication Server MX\FlashComAdmin.exe
O23 - Service: Macromedia Licensing Service - Macromedia - D:\Programmer\Fælles filer\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MySql - Unknown owner - J:/mysql/bin/mysqld-nt.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - F:\Norton SystemWorks\Norton Antivirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - F:\NORTON~1\NORTON~2\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\XP\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - D:\XP\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - F:\Norton SystemWorks\Norton Antivirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - D:\PROGRA~1\FLLESF~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: CaReTaKeR-CT NetMgr 1.2.1 (sfmgr) - Unknown owner - C:\SFMGR\sfmgr.exe
O23 - Service: Sygate Personal Firewall Pro (SmcService) - Sygate Technologies, Inc. - F:\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - D:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - D:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - D:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - D:\XP\system32\UAService7.exe