Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:48:29, on 23-09-2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16711)
Boot mode: Normal
Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\TDCpakke\Npm\Bin\Elogsvc.exe
C:\Program Files\TDCpakke\Ngs\bin\NPROSEC.EXE
C:\Windows\System32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\TDCpakke\Npm\Bin\Zanda.exe
C:\Program Files\TDCpakke\npm\bin\nvoy.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\TDCpakke\npf\bin\npfsvc32.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\TDCpakke\Npm\bin\NVCSCHED.EXE
C:\Program Files\TDCpakke\Npm\bin\NJEEVES.EXE
C:\Program Files\TDCpakke\npc\bin\npcsvc32.exe
C:\Program Files\TDCpakke\nse\bin\NSESVC.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\TDCpakke\npc\bin\nuaa.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamtrayctrl.exe
C:\Windows\RtHDVCpl.exe
c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\TDCpakke\Npm\Bin\Zlh.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Windows\System32\YURD04A.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\TDCpakke\Nvc\bin\nvcoas.exe
C:\Program Files\TDCpakke\Nvc\Bin\Nip.exe
C:\Program Files\TDCpakke\Nvc\Bin\Nvcoa.exe
C:\Program Files\TDCpakke\Nvc\Bin\cclaw.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.dk/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [StartCCC] "c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [recinfo327] c:\RecInfo\RecInfo.exe
O4 - HKLM\..\Run: [Norman ZANDA] "C:\Program Files\TDCpakke\Npm\Bin\ZLH.EXE" /LOAD /SPLASH
O4 - HKLM\..\Run: [recinfo] RecInfo.exe
O4 - HKLM\..\Run: [NPCTray] C:\Program Files\TDCpakke\npc\bin\npc_tray.exe /LOAD
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [\YURD04A.exe] C:\Windows\system32\YURD04A.exe
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\ssqNDSlJ.dll,#1
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Run] C:\Users\JT\AppData\Roaming\Adobe\Player.exe
O4 - HKCU\..\Run: [\YURD04A.exe] C:\Windows\system32\YURD04A.exe
O4 - HKCU\..\Run: [\YURF047.exe] C:\Windows\system32\YURF047.exe
O4 - HKCU\..\Run: [\YURE55E.exe] C:\Windows\system32\YURE55E.exe
O4 - HKCU\..\Run: [\YUREB09.exe] C:\Windows\system32\YUREB09.exe
O4 - HKCU\..\Run: [\YURF9A9.exe] C:\Windows\system32\YURF9A9.exe
O4 - HKCU\..\Run: [\YURF1AD.exe] C:\Windows\system32\YURF1AD.exe
O4 - HKCU\..\Run: [\YURD345.exe] C:\Windows\system32\YURD345.exe
O4 - HKCU\..\Run: [\YURE57D.exe] C:\Windows\system32\YURE57D.exe
O4 - HKCU\..\Run: [\YUREA1F.exe] C:\Windows\system32\YUREA1F.exe
O4 - HKCU\..\Run: [\YURF0B4.exe] C:\Windows\system32\YURF0B4.exe
O4 - HKCU\..\Run: [\YURE973.exe] C:\Windows\system32\YURE973.exe
O4 - HKCU\..\Run: [\YURD0E5.exe] C:\Windows\system32\YURD0E5.exe
O4 - HKCU\..\Run: [\YUR202.exe] C:\Windows\system32\YUR202.exe
O4 - HKCU\..\Run: [\YURD9AB.exe] C:\Windows\system32\YURD9AB.exe
O4 - HKCU\..\Run: [\YURDE6C.exe] C:\Windows\system32\YURDE6C.exe
O4 - HKCU\..\Run: [\YURE8F7.exe] C:\Windows\system32\YURE8F7.exe
O4 - HKCU\..\Run: [\YURE33C.exe] C:\Windows\system32\YURE33C.exe
O4 - HKCU\..\Run: [\YURE83B.exe] C:\Windows\system32\YURE83B.exe
O4 - HKCU\..\Run: [\YURDDA1.exe] C:\Windows\system32\YURDDA1.exe
O4 - HKCU\..\Run: [\YUR44FB.exe] C:\Windows\system32\YUR44FB.exe
O4 - HKCU\..\Run: [\YUR4D25.exe] C:\Windows\system32\YUR4D25.exe
O4 - HKCU\..\Run: [\YUR4671.exe] C:\Windows\system32\YUR4671.exe
O4 - HKCU\..\Run: [\YUR4910.exe] C:\Windows\system32\YUR4910.exe
O4 - HKCU\..\Run: [\YUR584C.exe] C:\Windows\system32\YUR584C.exe
O4 - HKCU\..\Run: [\YUR44CC.exe] C:\Windows\system32\YUR44CC.exe
O4 - HKCU\..\Run: [\YUR276D.exe] C:\Windows\system32\YUR276D.exe
O4 - HKCU\..\Run: [\YUR1D8E.exe] C:\Windows\system32\YUR1D8E.exe
O4 - HKCU\..\Run: [\YUR52E0.exe] C:\Windows\system32\YUR52E0.exe
O4 - HKCU\..\Run: [\YUR36C8.exe] C:\Windows\system32\YUR36C8.exe
O4 - HKCU\..\Run: [\YUR30CF.exe] C:\Windows\system32\YUR30CF.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETVÆRKSTJENESTE')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O10 - Unknown file in Winsock LSP: c:\program files\tdcpakke\npc\bin\nlf.dll
O10 - Unknown file in Winsock LSP: c:\program files\tdcpakke\npc\bin\nlf.dll
O10 - Unknown file in Winsock LSP: c:\program files\tdcpakke\npc\bin\nlf.dll
O10 - Unknown file in Winsock LSP: c:\program files\tdcpakke\npc\bin\nlf.dll
O10 - Unknown file in Winsock LSP: c:\program files\tdcpakke\npc\bin\nlf.dll
O10 - Unknown file in Winsock LSP: c:\program files\tdcpakke\npc\bin\nlf.dll
O10 - Unknown file in Winsock LSP: c:\program files\tdcpakke\npc\bin\nlf.dll
O10 - Unknown file in Winsock LSP: c:\program files\tdcpakke\npc\bin\nlf.dll
O10 - Unknown file in Winsock LSP: c:\program files\tdcpakke\npc\bin\nlf.dll
O10 - Unknown file in Winsock LSP: c:\program files\tdcpakke\npc\bin\nlf.dll
O10 - Unknown file in Winsock LSP: c:\program files\tdcpakke\npc\bin\nlf.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Norman eLogger service 6 (eLoggerSvc6) - Norman ASA - C:\Program Files\TDCpakke\Npm\Bin\Elogsvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Norman NJeeves - Norman ASA - C:\Program Files\TDCpakke\Npm\bin\NJEEVES.EXE
O23 - Service: Norman ZANDA - Norman ASA - C:\Program Files\TDCpakke\Npm\Bin\Zanda.exe
O23 - Service: Norman Parental Control (NPC) - Norman ASA - C:\Program Files\TDCpakke\npc\bin\npcsvc32.exe
O23 - Service: Norman Personal Firewall Service (NPFSvc32) - Norman ASA - C:\Program Files\TDCpakke\npf\bin\npfsvc32.exe
O23 - Service: Norman Security service (NPROSECSVC) - Norman ASA - C:\Program Files\TDCpakke\Ngs\bin\NPROSEC.EXE
O23 - Service: Norman Scanner Engine Service (nsesvc) - Norman ASA - C:\Program Files\TDCpakke\nse\bin\NSESVC.EXE
O23 - Service: Norman User Activity Agent (NUAA) - Norman ASA - C:\Program Files\TDCpakke\npc\bin\nuaa.exe
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\Program Files\TDCpakke\Nvc\bin\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman ASA - C:\Program Files\TDCpakke\Npm\bin\NVCSCHED.EXE
O23 - Service: Norman's Very Own supplY of resources (NVOY) - Norman ASA - C:\Program Files\TDCpakke\npm\bin\nvoy.exe
O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
--
End of file - 13121 bytes