Logfile of HijackThis v1.97.7
Scan saved at 18:45:00, on 03-01-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\NORMAN\nvc\BIN\NPFSVICE.EXE
C:\Norman\NVC\BIN\Zanda.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\NORMAN\nvc\BIN\ZLH.EXE
C:\Programmer\QuickTime\qttask.exe
C:\WINDOWS\MSMGT.exe
C:\DOCUME~1\KATHEA~1\APPLIC~1\clybshou.exe
C:\Programmer\Messenger\msmsgs.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\NCLAUNCH.EXe
C:\Program Files\Exif Launcher\QuickDCF.exe
C:\Programmer\Ulead Systems\Ulead Photo Express 4.0 My Custom
Edition\CalCheck.exe
C:\Programmer\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\ntvdm.exe
C:\OPLIMIT\ocrawr32.exe
C:\DOCUME~1\KATHEA~1\LOKALE~1\Temp\Uos2.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Outlook Express\msimn.exe
C:\Documents and Settings\Kathe Andersen\Skrivebord\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://tdmy.com/searchbar.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://tdmy.com/searchbar.htmlR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://tdmy.com/passthrough/index.html?http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=homeR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://tdmy.com/searchbar.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://tdmy.com/searchbar.htmlR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://tdmy.com/searchbar.htmlR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
Hyperlinks
R3 - URLSearchHook: CleverHook Class -
{707E6F76-9FFB-4920-A976-EA101271BC25} - C:\WINDOWS\jeired.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {6325cbab-e7bc-4b77-b3c9-2799e5f72da2} -
C:\DOCUME~1\KATHEA~1\APPLIC~1\drfickfrqm.dll
O2 - BHO: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} -
C:\WINDOWS\jeired.dll
O3 - Toolbar: Toolbar - {BC97B254-B2B9-4D40-971D-78E0978F5F26}} - (no file)
O3 - Toolbar: IEToolbar.clsIEToolbar -
{BC97B254-B2B9-4D40-971D-78E0978F5F26} - C:\WINDOWS\System32\ietoolbar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: ashououtvcr - {7c1da7b0-0afd-41b9-9b05-6fe3856d64fc} -
C:\DOCUME~1\KATHEA~1\APPLIC~1\drfickfrqm.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\nvc\BIN\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [QuickTime Task]
"C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [stcloader] C:\WINDOWS\System32\stcloader.exe
O4 - HKLM\..\Run: [MSMGT] C:\WINDOWS\MSMGT.exe
O4 - HKLM\..\Run: [dfrqf] C:\DOCUME~1\KATHEA~1\APPLIC~1\clybshou.exe -QuieT
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE
C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
O4 - Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\Exif
Launcher\QuickDCF.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft
Office\Office10\OSA.EXE
O4 - Global Startup: Ulead Photo Express Calendar Checker For My Custom
Edition.lnk = C:\Programmer\Ulead Systems\Ulead Photo Express 4.0 My Custom
Edition\CalCheck.exe
O4 - Global Startup: WinZip Quick Pick.lnk =
C:\Programmer\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&ksporter til Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .pdf: C:\Programmer\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://www.apple.com/qtactivex/qtplugin.cabO16 - DPF: {03C543A1-C090-418F-A1D0-FB96380D601D} (preload control) -
http://www.thepaymentcentre.com/build/preload.cabO16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX
Control) -
http://active.macromedia.com/director/cabs/sw.cabO16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CABO16 - DPF: {421A63BA-4632-43E0-A942-3B4AB645BE51} -
http://download-ak.systemsoap.com/ssoap/pptproactauthakamai/systemsoappro.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/d052c1d7d32ead/housecall.antivirus.com/housecall/xscan53.cabO16 - DPF: {763C10EE-E4C6-49AA-9325-F15ABF1C52B0} (X1 DownloadControl
Class) -
http://www.x1.com/download/X1WebInstall.cabO16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield
International Setup Player) -
http://www.napster.com/client/isetup.cabO16 - DPF: {9B4AA442-9EBF-11D5-8C11-0050DA4957F5} -
http://www.cavello.com/dialxs/plugins/d/11/272/nl.exeO16 - DPF: {C7B05B62-C8D7-438C-840B-4994DAAA8EEE} -
http://webpdp.gator.com/v3/download/pdpplugin5094_hd3ptdmgainads.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {DBAE7000-01EC-4162-8FEB-8A27AC937CA0} (HDPluginCtrl Class) -
http://webpdp.gator.com/v3/download/hdplugin1014_hd3ptdmgainads.cabO16 - DPF: {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF} -
http://www.searchwww.com/toolbar/toolbar.cabO17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = mydomain.com
O17 -
HKLM\System\CCS\Services\Tcpip\..\{3FD2737E-B037-4473-9F97-C80232989463}:
NameServer = 69.57.146.14
O17 -
HKLM\System\CCS\Services\Tcpip\..\{E911A6F6-4206-46BB-97A5-44D46A438056}:
NameServer = 69.57.146.14
O17 - HKLM\System\CS1\Services\VxD\MSTCP: Domain = mydomain.com
O17 - HKLM\System\CS1\Services\VxD\MSTCP: NameServer = 69.57.146.14
O17 -
HKLM\System\CS1\Services\Tcpip\..\{3FD2737E-B037-4473-9F97-C80232989463}:
NameServer = 69.57.146.14
O17 - HKLM\System\CS2\Services\VxD\MSTCP: Domain = mydomain.com
O17 - HKLM\System\CS2\Services\VxD\MSTCP: NameServer = 69.57.146.14
O17 -
HKLM\System\CS2\Services\Tcpip\..\{3FD2737E-B037-4473-9F97-C80232989463}:
NameServer = 69.57.146.14
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.57.146.14