Logfile of HijackThis v1.97.7
Scan saved at 13:05:26, on 05-05-2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSSystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:PROGRA~1GrisoftAVG6avgserv.exe
C:WINDOWSsystem32ONELABSvsmon.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSystem32CTHELPER.EXE
C:ProgrammerGrisoftAVG6avgcc32.exe
C:ProgrammerLogitechiTouchiTouch.exe
C:WINDOWSSystem32umonit.exe
C:WINDOWSSystem32G-VGA.exe
C:ProgrammerATI TechnologiesATI HydraVisionHydraDM.exe
C:ProgrammerWinampwinampa.exe
C:ProgrammerMSN MessengerMsnMsgr.Exe
C:Programmerone LabsoneAlarmzapro.exe
C:ProgrammerSpywareGuardsgmain.exe
C:ProgrammerSpywareGuardsgbhp.exe
c:programmerinternet exploreriexplore.exe
C:ProgrammerMessengermsmsgs.exe
C:Documents and SettingsClaus DrejerSkrivebordHijackThis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://tdckabeltv.dk[...]
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {09F0F280-FB9A-481B-B69A-CB00DC44D027} - C:PROGRA~1ADVANC~1POPUPJ~1.DLL
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:ProgrammerSpywareGuarddlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll
O2 - BHO: (no name) - {77712A64-F30B-47C8-A363-CDA1CEC7DC1B} - C:PROGRA~1ADVANC~1ADVANC~1.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx
O4 - HKLM..Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM..Run: [UpdReg] C:WINDOWSUpdReg.EXE
O4 - HKLM..Run: [AVG_CC] C:ProgrammerGrisoftAVG6avgcc32.exe /startup
O4 - HKLM..Run: [NeroCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [zBrowser Launcher] C:ProgrammerLogitechiTouchiTouch.exe
O4 - HKLM..Run: [UMonit] C:WINDOWSSystem32umonit.exe
O4 - HKLM..Run: [Ad-aware] "C:ProgrammerLavasoftAd-aware 6Ad-aware.exe" +c
O4 - HKLM..Run: [CTHelper] CTHELPER.EXE
O4 - HKLM..Run: [VGAUtil] C:WINDOWSSystem32G-VGA.exe
O4 - HKLM..Run: [HydraVisionDesktopManager] C:ProgrammerATI TechnologiesATI HydraVisionHydraDM.exe
O4 - HKLM..Run: [WinampAgent] C:ProgrammerWinampwinampa.exe
O4 - HKLM..Run: [AceGain LiveUpdate] C:ProgrammerAceGainLiveUpdateLiveUpdate.exe
O4 - HKLM..Run: [SpybotSnD] "C:ProgrammerSpybot - Search & DestroySpybotSD.exe"
O4 - HKCU..Run: [STYLEXP] C:ProgrammerTGTSoftStyleXPStyleXP.exe -Hide
O4 - HKCU..Run: [MsnMsgr] "C:ProgrammerMSN MessengerMsnMsgr.Exe" /background
O4 - Startup: SpywareGuard.lnk = C:ProgrammerSpywareGuardsgmain.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:Programmerone LabsoneAlarmzapro.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
http://download.macromedia.com[...]
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com[...]
O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} (InstallFromTheWeb ActiveX Control) -
http://tw.msi.com.tw[...]
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
http://v4.windowsupdate.microsoft.com[...]
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) -
http://security.symantec.com[...]
O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} (CSS Web Installer Class) -
http://scanner.virus112.com[...]
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com[...]
O16 - DPF: {D3426292-3750-4D80-9D0F-2816F61A6D15} (SpeedTest Control) -
http://81.19.245.211[...]
O16 - DPF: {F9408298-9658-482C-8B02-93F09A80225F} (Util Class) -
https://udstedelse.certifikat.tdc.dk[...]
--