Hijackthis log
Logfile of HijackThis v1.99.1Scan saved at 18:44:16, on 22-04-2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSYSTEMKERNEL32.DLL
C:WINDOWSSYSTEMMSGSRV32.EXE
C:WINDOWSSYSTEMSPOOL32.EXE
C:WINDOWSSYSTEMMPREXE.EXE
C:WINDOWSSYSTEMMSTASK.EXE
C:WINDOWSSYSTEMSSDPSRV.EXE
C:WINDOWSSYSTEMMDM.EXE
C:WINDOWSSYSTEMmmtask.tsk
C:WINDOWSSYSTEMRESTORESTMGR.EXE
C:WINDOWSTASKMON.EXE
C:WINDOWSSYSTEMSYSTRAY.EXE
C:WINDOWSPCTVOICE.EXE
C:PROGRAMMERNETROPATOUCH MANAGERTOUCHMGR.EXE
C:PROGRAMMERNETRATINGSPREMETERPRMT.EXE
C:WINDOWSSYSTEMWMIEXE.EXE
C:PROGRAMMERAHEADINCDINCD.EXE
C:PROGRAM FILESWEBHANCERPROGRAMSWHSURVEY.EXE
C:WINDOWSRUNDLL32.EXE
C:WINDOWSSYSTEMHPOOPM07.EXE
C:PROGRAM FILESWEBHANCERPROGRAMSWHAGENT.EXE
C:PROGRAMMERHEWLETT-PACKARDHP PSC 700 SERIESBINHPODEV07.EXE
C:PROGRAMMERHEWLETT-PACKARDHP PSC 700 SERIESFRUREMIND32.EXE
C:PROGRAMMERFæLLES FILERREALUPDATE_OBRNDAL.EXE
C:PROGRAMMERNETROPATOUCH MANAGERMEDIACTR.EXE
C:PROGRAMMERNETROPAONSCREEN DISPLAYOSD.EXE
C:AMITECHONNOW.EXE
C:PROGRAMMERNETROPATOUCH MANAGERMMUSBKB2.EXE
C:AMITECHFORTRYD.EXE
C:PROGRAMMERHEWLETT-PACKARDHP PSC 700 SERIESBINHPOEVM07.EXE
C:PROGRAMMERHEWLETT-PACKARDHP PSC 700 SERIESBINHPOSTS07.EXE
C:WINDOWSSYSTEMDDHELP.EXE
C:WINDOWSSYSTEMPSTORES.EXE
C:PROGRAMMERSPYBOT - SEARCH & DESTROYUPDATESIMMUFIX.EXE
C:PROGRAMMERFæLLES FILERREALUPDATE_OBEVNTSVC.EXE
C:WINDOWSEXPLORER.EXE
C:PROGRAMMERREALREALDOWNLOADREALDOWNLOAD.EXE
C:WINDOWSSYSTEMTAPISRV.EXE
C:WINDOWSRUNDLL32.EXE
C:MY DOWNLOAD FILESHJT.EXE
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = about:blank
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = about:blank
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.olivant.fo/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = about:blank
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = about:blank
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Hyperlinks
O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - C:WINDOWSSYSTEMNZDD.DLL
O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:ProgrammerNewDotNet ewdotnet6_38.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSYSTEMMSDXM.OCX
O4 - HKLM..Run: [ScanRegistry] C:WINDOWSscanregw.exe /autorun
O4 - HKLM..Run: [TaskMonitor] C:WINDOWS askmon.exe
O4 - HKLM..Run: [PCHealth] C:WINDOWSPCHealthSupportPCHSchd.exe -s
O4 - HKLM..Run: [SystemTray] SysTray.Exe
O4 - HKLM..Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..Run: [CountrySelection] pctptt.exe
O4 - HKLM..Run: [PCTVOICE] pctvoice.exe
O4 - HKLM..Run: [nVidiaTV-OUT] Regedit /S C:Windows vout.reg
O4 - HKLM..Run: [Touch Manager] C:ProgrammerNetropaTouch ManagerTouchMgr.exe
O4 - HKLM..Run: [Startup] C:AmitechStartup /START
O4 - HKLM..Run: [InCD] C:ProgrammerAheadInCDInCD.exe
O4 - HKLM..Run: [TkBellExe] C:ProgrammerFælles filerRealUpdate_OBevntsvc.exe -osboot
O4 - HKLM..Run: [New.net Startup] rundll32 C:PROGRA~1NEWDOT~1NEWDOT~1.DLL,NewDotNetStartup -s
O4 - HKLM..Run: [HPAIO_PrintFolderMgr] C:WINDOWSSYSTEMhpoopm07.exe
O4 - HKLM..RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM..RunServices: [SSDPSRV] C:WINDOWSSYSTEMssdpsrv.exe
O4 - HKLM..RunServices: [*StateMgr] C:WINDOWSSystemRestoreStateMgr.exe
O4 - HKLM..RunServices: [Machine Debug Manager] C:WINDOWSSYSTEMMDM.EXE
O4 - HKLM..RunOnce: [SpybotSnD] "C:PROGRAMMERSPYBOT - SEARCH & DESTROYSPYBOTSD.EXE" /autocheck
O4 - Startup: HPAiODevice.lnk = C:ProgrammerHewlett-Packardhp psc 700 seriesinhpodev07.exe
O4 - Startup: Microsoft Office.lnk = C:ProgrammerMicrosoft OfficeOfficeOSA9.EXE
O4 - Startup: Hewlett-Packard Recorder.lnk = C:ProgrammerHewlett-Packardhp psc 700 seriesFRURemind32.exe
O4 - Startup: CAMEDIA Master.lnk = C:ProgrammerOLYMPUSCAMEDIA Master 4.1CM_camera.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSweb elated.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINDOWSweb elated.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:PROGRA~1MESSEN~1MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:PROGRA~1MESSEN~1MSMSGS.EXE
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:WINDOWSSYSTEMMSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:WINDOWSSYSTEMMSJAVA.DLL
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O14 - IERESET.INF: START_PAGE_URL= http://www.amitech.dk
O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} (CSS Web Installer Class) - http://www.eb.dk/codekstra/cabs/cssweb.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
