Logfile of HijackThis v1.99.1
Scan saved at 16:32:37, on 13-11-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32csrss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:AcerEmpowering TechnologyePerformanceMemCheck.exe
C:AcerEmpowering TechnologyePowerePower_DMC.exe
C:ProgrammerLaunch ManagerWbutton.exe
C:ProgrammerSynapticsSynTPSynTPEnh.exe
C:ProgrammerJavajre1.5.0_06injusched.exe
C:WINDOWSRTHDCPL.EXE
C:Program FilesAcerAcer ArcadePCMService.exe
C:ProgrammerLaunch ManagerOSDCtrl.exe
C:ProgrammerLaunch ManagerHotkeyApp.exe
C:ProgrammerLaunch ManagerLaunchAp.exe
C:WINDOWSsystem32igfxtray.exe
C:WINDOWSsystem32igfxpers.exe
C:WINDOWSsystem32hkcmd.exe
C:AcerEmpowering TechnologyeRecoveryeRAgent.exe
C:WINDOWSAGRSMMSG.exe
C:AcerEmpowering TechnologyePresentationePresentation.exe
C:VIRUSfighterinLH.EXE
C:ProgrammerWebrootSpy SweeperSpySweeperUI.exe
C:ProgrammerMessengermsmsgs.exe
C:WINDOWSsystem32ctfmon.exe
C:AcerEmpowering TechnologyAcer.Empowering.Framework.Launcher.exe
C:ProgrammerHewlett-PackardDigital Imaginginhpotdd01.exe
C:ProgrammerHewlett-PackardDigital Imaginginhpohmr08.exe
C:Program FilesAcerAcer ArcadeKernelTVCLCapSvc.exe
C:Program FilesAcerAcer ArcadeKernelCLML_NTServiceCLMLServer.exe
C:Program FilesAcerAcer ArcadeKernelCLML_NTServiceCLMLService.exe
C:VIRUSfighterBinanda.exe
C:ProgrammerCyberLinkShared FilesRichVideo.exe
C:WINDOWSsystem32svchost.exe
C:ProgrammerWebrootSpy SweeperSpySweeper.exe
C:ProgrammerHewlett-PackardDigital Imaginginhpoevm08.exe
C:VIRUSfighterNvcBINNIP.EXE
C:Program FilesAcerAcer ArcadeKernelTVCLSched.exe
C:VIRUSfighterNvcin
vcoas.exe
C:WINDOWSsystem32wbemwmiprvse.exe
C:VIRUSfighterinNJEEVES.EXE
C:VIRUSfighterNvcBIN
ipsvc.exe
C:VIRUSfighterNvcBINNVCSCHED.EXE
C:WINDOWSsystem32wbemwmiprvse.exe
C:WINDOWSsystem32wbemwmiapsrv.exe
C:WINDOWSSystem32alg.exe
C:WINDOWSsystem32wbemunsecapp.exe
C:ProgrammerHewlett-PackardDigital ImagingBinhpoSTS08.exe
C:VIRUSfighterNvcincclaw.exe
C:ProgrammerWebrootSpy SweeperSSU.EXE
C:WINDOWSSystem32svchost.exe
C:ProgrammerWindows Media Playerwmplayer.exe
C:ProgrammerInternet Exploreriexplore.exe
C:Documents and SettingsDaniel madsenSkrivebordhijackthis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://www.google.dk[...]
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
http://global.acer.com[...]
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:ProgrammerAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:ProgrammerJavajre1.5.0_06inssv.dll
O4 - HKLM..Run: [ePower_DMC] "C:AcerEmpowering TechnologyePowerePower_DMC.exe"
O4 - HKLM..Run: [zango] "c:programmerzangozango.exe"
O4 - HKLM..Run: [Wbutton] "C:ProgrammerLaunch ManagerWbutton.exe"
O4 - HKLM..Run: [SynTPEnh] C:ProgrammerSynapticsSynTPSynTPEnh.exe
O4 - HKLM..Run: [SunJavaUpdateSched] C:ProgrammerJavajre1.5.0_06injusched.exe
O4 - HKLM..Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM..Run: [preload] C:WindowsRUNXMLPL.exe
O4 - HKLM..Run: [PHIME2002ASync] "C:WINDOWSsystem32IMETINTLGNTTINTSETP.EXE" /SYNC
O4 - HKLM..Run: [PHIME2002A] "C:WINDOWSsystem32IMETINTLGNTTINTSETP.EXE" /IMEName
O4 - HKLM..Run: [PCMService] "C:Program FilesAcerAcer ArcadePCMService.exe"
O4 - HKLM..Run: [ntiMUI] "C:ProgrammerNewTech InfosystemsNTI CD & DVD-Maker 7
tiMUI.exe"
O4 - HKLM..Run: [MSPY2002] "C:WINDOWSsystem32IMEPINTLGNTImScInst.exe" /SYNC
O4 - HKLM..Run: [LMgrOSD] "C:ProgrammerLaunch ManagerOSDCtrl.exe"
O4 - HKLM..Run: [LManager] "C:ProgrammerLaunch ManagerHotkeyApp.exe"
O4 - HKLM..Run: [LaunchAp] "C:ProgrammerLaunch ManagerLaunchAp.exe"
O4 - HKLM..Run: [IMJPMIG8.1] "C:WINDOWSIMEimjp8_1IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM..Run: [ImageItEncrypt] C:WINDOWSsystem32ImageItEncrypt.exe
O4 - HKLM..Run: [igfxtray] C:WINDOWSsystem32igfxtray.exe
O4 - HKLM..Run: [igfxpers] C:WINDOWSsystem32igfxpers.exe
O4 - HKLM..Run: [igfxhkcmd] C:WINDOWSsystem32hkcmd.exe
O4 - HKLM..Run: [eRecoveryService] "C:AcerEmpowering TechnologyeRecoveryeRAgent.exe"
O4 - HKLM..Run: [CtrlVol] "C:ProgrammerLaunch ManagerCtrlVol.exe"
O4 - HKLM..Run: [Boot] "C:AcerEmpowering TechnologyePowerBoot.exe"
O4 - HKLM..Run: [BearShare] "C:ProgrammerBearShareBearShare.exe" /pause
O4 - HKLM..Run: [BearFlix] "C:ProgrammerBearFlixearflix.exe" /pause
O4 - HKLM..Run: [AzMixerSel] C:ProgrammerRealtekInstallShieldAzMixerSel.exe
O4 - HKLM..Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM..Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM..Run: [Acer ePresentation HPD] "C:AcerEmpowering TechnologyePresentationePresentation.exe"
O4 - HKLM..Run: [Norman ZANDA] "C:VIRUSfighterinLH.EXE" /LOAD /SPLASH
O4 - HKLM..Run: [SpySweeper] "C:ProgrammerWebrootSpy SweeperSpySweeperUI.exe" /startintray
O4 - HKCU..Run: [MSMSGS] "C:ProgrammerMessengermsmsgs.exe" /background
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:ProgrammerAdobeAcrobat 7.0Reader
eader_sl.exe
O4 - Global Startup: Acer Empowering Technology.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgrammerJavajre1.5.0_06inssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgrammerJavajre1.5.0_06inssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:ProgrammerMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:ProgrammerMessengermsmsgs.exe
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) -
https://h17000.www1.hp.com[...]
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
https://download.macromedia.com[...]
O20 - Winlogon Notify: igfxcui - C:WINDOWSSYSTEM32igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:WINDOWSSYSTEM32WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:WINDOWSSYSTEM32WRLogonNTF.dll
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:AcerEmpowering TechnologyePerformanceMemCheck.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:Program FilesAcerAcer ArcadeKernelTVCLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:Program FilesAcerAcer ArcadeKernelTVCLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:Program FilesAcerAcer ArcadeKernelCLML_NTServiceCLMLServer.exe
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:VIRUSfighterNvcBIN
ipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - C:VIRUSfighterinNJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:VIRUSfighterBinanda.exe
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:VIRUSfighterNvcin
vcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:VIRUSfighterNvcBINNVCSCHED.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:WINDOWSsystem32HPZipm12.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:ProgrammerCyberLinkShared FilesRichVideo.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:ProgrammerWebrootSpy SweeperSpySweeper.exe
--