Logfile of HijackThis v1.97.2
Scan saved at 18:17:51, on 20-09-03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\REGSERV.EXE
C:\WINDOWS\SNMP.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\DMI98\WIN32\BIN\WIN32SL.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\TMP\ICSUPP95.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAMMER\SOPHOS SWEEP\ICMON.EXE
C:\PROGRAMMER\SAVAGENT\SAVAGENT.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAMMER\REAL\REALPLAYER\REALPLAY.EXE
C:\WINDOWS\STARTUPMONITOR.EXE
C:\WINDOWS\RunDLL.exe
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAMMER\BITZIPPER\BITZIPPER.EXE
C:\TMP\BZ_TEMP_0\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://redteen2.da.ru/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://redteen2.da.ru/R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://opslagstavlen/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.clickyestoenter.net/search.htmR1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = +s
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = +s
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www001.upp.so-net.ne:3128@DF809JOW4WJ2304LFD0SF9FSD0A2T4LDF809JOW4WJ2304LFD0SF9FSD0A2T4LD.BIZ/search.htm (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://OpslagstavlenR0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://mommykiss.com/search.htmlR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://mommykiss.com/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer leveret af Folketinget - IT & Tele
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ProXyB.ft.dk:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
N1 - Netscape 4: user_pref("browser.startup.homepage", "
http://opslagstavlen/"); (C:\Programmer\Netscape\Users\default\prefs.js)
O1 - Hosts: 66.159.18.187 auto.search.msn.com
O1 - Hosts: 66.159.18.187 search.msn.com
O1 - Hosts: 66.159.18.186
www.thecashzone.comO1 - Hosts: 66.159.18.186 db.smutcash.com
O1 - Hosts: 66.159.18.186
www.eroticcash.comO1 - Hosts: 66.159.18.186 home.vividvip.com
O1 - Hosts: 66.159.18.186
www.stiffycash.comO1 - Hosts: 66.159.18.186 gotd.stiffycash.com
O1 - Hosts: 66.159.18.186 cash.helmy.com
O1 - Hosts: 66.159.18.186 adultmegacash.com
O1 - Hosts: 66.159.18.186 amc2.adultmegacash.com
O1 - Hosts: 66.159.18.186
www.candidclicks.comO1 - Hosts: 66.159.18.186 clicks.filthyclicks.com
O1 - Hosts: 66.159.18.186
www.eazybucks.comO1 - Hosts: 66.159.18.186
www.bigpay.comO1 - Hosts: 66.159.18.186
www.fatclicks.comO1 - Hosts: 66.159.18.186 stats1.pussypayments.com
O1 - Hosts: 66.159.18.186
www.adultbucks.comO1 - Hosts: 66.159.18.186
www.babylon-x.comO1 - Hosts: 66.159.18.186
www.dollartraffic.comO1 - Hosts: 66.159.18.186 ctc.japanesegirls.com
O1 - Hosts: 66.159.18.186
www.entertainmentcash.comO1 - Hosts: 66.159.18.186
www.mtreexxx.netO1 - Hosts: 66.159.18.186 join.pibcash.com
O1 - Hosts: 66.159.18.186
www.intergal.comO1 - Hosts: 66.159.18.186 www2.seductiveamateurs.com
O1 - Hosts: 66.159.18.186 porndollar.com
O1 - Hosts: 66.159.18.186
www.porndollar.comO1 - Hosts: 66.159.18.186
www.pink4free.comO1 - Hosts: 66.159.18.186 click.sizepro.com
O1 - Hosts: 66.159.18.186 mt1.mtree.com
O1 - Hosts: 66.159.18.186 mt2.mtree.com
O1 - Hosts: 66.159.18.186 mt3.mtree.com
O1 - Hosts: 66.159.18.186 mt4.mtree.com
O1 - Hosts: 66.159.18.186 mt5.mtree.com
O1 - Hosts: 66.159.18.186 mt6.mtree.com
O1 - Hosts: 66.159.18.186 mt7.mtree.com
O1 - Hosts: 66.159.18.186 mt8.mtree.com
O1 - Hosts: 66.159.18.186 mt9.mtree.com
O1 - Hosts: 66.159.18.186 mt10.mtree.com
O1 - Hosts: 66.159.18.186 mt11.mtree.com
O1 - Hosts: 66.159.18.186 mt12.mtree.com
O1 - Hosts: 66.159.18.186 mt13.mtree.com
O1 - Hosts: 66.159.18.186 mt14.mtree.com
O1 - Hosts: 66.159.18.186 mt15.mtree.com
O1 - Hosts: 66.159.18.186 mt16.mtree.com
O1 - Hosts: 66.159.18.186 mt17.mtree.com
O1 - Hosts: 66.159.18.186 mt18.mtree.com
O1 - Hosts: 66.159.18.186 mt19.mtree.com
O1 - Hosts: 66.159.18.186 mt20.mtree.com
O1 - Hosts: 66.159.18.186 mt21.mtree.com
O1 - Hosts: 66.159.18.186 mt22.mtree.com
O1 - Hosts: 66.159.18.186 mt23.mtree.com
O1 - Hosts: 66.159.18.186 mt24.mtree.com
O1 - Hosts: 66.159.18.186 mt25.mtree.com
O1 - Hosts: 66.159.18.186 mt26.mtree.com
O1 - Hosts: 66.159.18.186 mt27.mtree.com
O1 - Hosts: 66.159.18.186 mt28.mtree.com
O1 - Hosts: 66.159.18.186 mt29.mtree.com
O1 - Hosts: 66.159.18.186 mt30.mtree.com
O1 - Hosts: 66.159.18.186 mt31.mtree.com
O1 - Hosts: 66.159.18.186 mt32.mtree.com
O1 - Hosts: 66.159.18.186 mt33.mtree.com
O1 - Hosts: 66.159.18.186 mt34.mtree.com
O1 - Hosts: 66.159.18.186 mt35.mtree.com
O1 - Hosts: 66.159.18.186 mt36.mtree.com
O1 - Hosts: 66.159.18.186 mt37.mtree.com
O1 - Hosts: 66.159.18.186 mt38.mtree.com
O1 - Hosts: 66.159.18.186 mt39.mtree.com
O1 - Hosts: 66.159.18.186 mt40.mtree.com
O1 - Hosts: 66.159.18.186 mt41.mtree.com
O1 - Hosts: 66.159.18.186 mt42.mtree.com
O1 - Hosts: 66.159.18.186 mt43.mtree.com
O1 - Hosts: 66.159.18.186 mt44.mtree.com
O1 - Hosts: 66.159.18.186 mt45.mtree.com
O1 - Hosts: 66.159.18.186 mt46.mtree.com
O1 - Hosts: 66.159.18.186 mt47.mtree.com
O1 - Hosts: 66.159.18.186 mt48.mtree.com
O1 - Hosts: 66.159.18.186 mt49.mtree.com
O1 - Hosts: 66.159.18.186 mt50.mtree.com
O1 - Hosts: 66.159.18.186 mt51.mtree.com
O1 - Hosts: 66.159.18.186 mt52.mtree.com
O1 - Hosts: 66.159.18.186 mt53.mtree.com
O1 - Hosts: 66.159.18.186 mt54.mtree.com
O1 - Hosts: 66.159.18.186 mt55.mtree.com
O1 - Hosts: 66.159.18.186 mt56.mtree.com
O1 - Hosts: 66.159.18.186 mt57.mtree.com
O1 - Hosts: 66.159.18.186 mt58.mtree.com
O1 - Hosts: 66.159.18.186 mt59.mtree.com
O1 - Hosts: 66.159.18.186 mt60.mtree.com
O1 - Hosts: 66.159.18.186 mt61.mtree.com
O1 - Hosts: 66.159.18.186 mt62.mtree.com
O1 - Hosts: 66.159.18.186 mt63.mtree.com
O1 - Hosts: 66.159.18.186 mt64.mtree.com
O1 - Hosts: 66.159.18.186 mt65.mtree.com
O1 - Hosts: 66.159.18.186 mt66.mtree.com
O1 - Hosts: 66.159.18.186 mt67.mtree.com
O1 - Hosts: 66.159.18.186 mt68.mtree.com
O1 - Hosts: 66.159.18.186 mt69.mtree.com
O1 - Hosts: 66.159.18.186 mt70.mtree.com
O1 - Hosts: 66.159.18.186 mt71.mtree.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMMER\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {1678F7E1-C422-11D0-AD7D-00400515CAAA} - (no file)
O2 - BHO: CSBrBHO - {96DA5BEE-4ACC-476C-B3EC-54C6730C4293} - C:\PROGRAMMER\COMET\INSTALL\TEMP\BRBHO.DLL (file missing)
O4 - HKLM\..\Run: [Skan registreringsdatabase] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [Job-oversigt] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [InterCheckMonitor] "C:\PROGRAMMER\SOPHOS SWEEP\ICMON.EXE" -minimised
O4 - HKLM\..\Run: [Ftstart] C:\Programmer\Ftaddon\Ftstart.exe
O4 - HKLM\..\Run: [SAVAgent] C:\Programmer\SAVAgent\SAVAgent.exe -POLL=7200
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [RealTray] C:\Programmer\Real\RealPlayer\realplay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Sweep95] "C:\Programmer\Sophos SWEEP\SETUP.EXE"
O4 - HKLM\..\Run: [sys] regedit /s sys.reg
O4 - HKLM\..\Run: [Ad-aware] "C:\PROGRAMMER\LAVASOFT\AD-AWARE 6\AD-AWARE.EXE" +c
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\RunServices: [regserv] regserv.exe
O4 - HKLM\..\RunServices: [SNMP agent] SNMP.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [Planlægningsagent] C:\WINDOWS\SYSTEM\mstask.exe
O4 - HKLM\..\RunServices: [Win32SL] C:\Dmi98\WIN32\bin\Win32sl.exe -i -p -r
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [Sweep95] C:\Programmer\Sophos SWEEP\ICLOAD95.EXE
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [li-speed00314] c:\program files\Webdialer\li-speed00314.exe -m
O4 - HKCU\..\RunServices: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\RunServices: [li-speed00314] c:\program files\Webdialer\li-speed00314.exe -m
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: RealGuide (HKLM)
O9 - Extra button: SEARCH (HKLM)
O9 - Extra button: ANTIVIRUS (HKLM)
O9 - Extra button: ENTERTAINMENT (HKLM)
O9 - Extra button: SECURITY (HKLM)
O9 - Extra button: SEARCH (HKLM)
O13 - DefaultPrefix:
http://www001.upp.so-net.ne:3128@DF809JOW4WJ2304LFD0SF9FSD0A2T4LDF809JOW4WJ2304LFD0SF9FSD0A2T4LD%2E%42%49%5A/c/c.pl?url=O14 - IERESET.INF: START_PAGE_URL=http://Opslagstavlen
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = ft.dk
O17 - HKLM\System\CCS\Services\VxD\MSTCP: SearchList = ft.dk
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 147.29.233.30,147.29.233.65