log:
Logfile of HijackThis v1.94.0
Scan saved at 21:33:21, on 24-06-2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch=http://www.searchv.com/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.searchv.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL=http://www.searchv.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL=http://www.searchv.com/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch=http://www.searchv.com/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default)=http://www.searchv.com/search.php?qq=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\System32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\SYSTEM\blank.htm
O1 - Hosts: 209.66.123.175 admin.promaxhost.com
O1 - Hosts: 209.66.123.175 tds.alekshost.com
O1 - Hosts: 209.66.123.175 tds.bgporn.com
O1 - Hosts: 209.66.123.175 redfuck.com
O1 - Hosts: 209.66.123.175
www.geo-traffic.comO1 - Hosts: 209.66.123.175
www.bloodyroot.comO2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {5ef70b4f-bec4-4b35-ac9a-198f54b469b5} - C:\DOCUME~1\DENNIS~1\APPLIC~1\ollifrbrxck.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: stqwfroassc - {6c2365c3-31dc-4baa-954e-5921e6993852} - C:\DOCUME~1\DENNIS~1\APPLIC~1\ollifrbrxck.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MessengerPlus2] "C:\Programmer\Messenger Plus! 2\MsgPlus.exe"
O4 - HKCU\..\Run: [Project2] C:\Documents and Settings\Dennis Hellner\Project2.exe
O4 - HKCU\..\Run: [MessengerPlus2] "C:\Programmer\Messenger Plus! 2\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmer\MSN Messenger\msnmsgr.exe" /background
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = a9029.find-quick.com
O17 - HKLM\Software\..\Telephony: DomainName = a9029.find-quick.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{0A614754-836D-4C17-B001-4DB426A4E7AD}: Domain = a9029.find-quick.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{13A40E38-5FB7-4835-BBD8-C9AE2CEE037A}: Domain = a9029.find-quick.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = a9029.find-quick.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{0A614754-836D-4C17-B001-4DB426A4E7AD}: Domain = a9029.find-quick.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = a9029.find-quick.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{0A614754-836D-4C17-B001-4DB426A4E7AD}: Domain = a9029.find-quick.com