Logfile of HijackThis v1.98.0
Scan saved at 21:50:56, on 12-07-2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Atievxx.exe
C:\WINNT\System32\CTsvcCDA.EXE
C:\Programmer\Trend Micro\PC-cillin 2000\Tmntsrv.exe
C:\WINNT\System32\Atiptaxx.exe
C:\Programmer\Trend Micro\PC-cillin 2000\Pop3trap.exe
C:\Programmer\Trend Micro\PC-cillin 2000\WebTrapNT.exe
C:\Programmer\Creative\ShareDLL\CtNotify.exe
C:\Programmer\Actiontec\80211a\config\CONFIGUTILITY.EXE
C:\WINNT\System32\AEIWLSTA.EXE
C:\WINNT\system32\pcs\pcsvc.exe
C:\Programmer\Common Files\Dpi\dpi.exe
C:\Programmer\Fælles filer\PCSuite\DataLayer\DataLayer.exe
C:\Programmer\Creative\ShareDLL\MediaDet.Exe
C:\Programmer\Fælles filer\Nokia\Tools\NclTray.exe
C:\Programmer\WhenUSearch\Search.exe
C:\WINNT\System32\nssys32.exe
C:\Documents and Settings\Casper D. Carstens\Application Data\weuo.exe
C:\WINNT\System32\cqw.exe
C:\Programmer\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Programmer\Fælles filer\PCSuite\Services\ServiceLayer.exe
C:\Programmer\Trend Micro\PC-cillin 2000\PNTIOMON.exe
C:\Programmer\Trend Micro\PC-cillin 2000\pccntupd.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Programmer\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://216.65.101.250/sbms/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
file://C:\WINNT\System32/left.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://216.65.101.250/sbms/R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://216.65.101.250/sbms/R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: IncrediFindBHO Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL
R3 - URLSearchHook: IncrediFindBHO Class - {4FC95EDD-4796-4966-9049-29649C80111D} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~2.DLL
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: CSIECore Class - {00000000-0000-0000-0000-000000000221} - C:\Programmer\ClearSearch\CSIE.DLL
O2 - BHO: (no name) - {3AD73603-EC15-05CA-D156-64550DD32D4B} - C:\WINNT\System32\qvlt.dll
O2 - BHO: NavErrRedir Class - {4FC95EDD-4796-4966-9049-29649C80111D} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~2.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Programmer\Trend Micro\PC-cillin 2000\Pop3trap.exe"
O4 - HKLM\..\Run: [WebTrapNT.exe] "C:\Programmer\Trend Micro\PC-cillin 2000\WebTrapNT.exe"
O4 - HKLM\..\Run: [Disc Detector] C:\Programmer\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Actiontec 802.11a Wireless Configuration Utility] C:\Programmer\Actiontec\80211a\config\CONFIGUTILITY.EXE
O4 - HKLM\..\Run: [AEIWLSTA.EXE] AEIWLSTA.EXE
O4 - HKLM\..\Run: [Pcsv] C:\WINNT\system32\pcs\pcsvc.exe
O4 - HKLM\..\Run: [Dpi] C:\Programmer\Common Files\Dpi\dpi.exe
O4 - HKLM\..\Run: [DataLayer] C:\Programmer\Fælles filer\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Programmer\Fælles filer\Nokia\Tools\NclTray.exe
O4 - HKLM\..\Run: [WhenUSearch] "C:\Programmer\WhenUSearch\Search.exe"
O4 - HKCU\..\Run: [nsdriver] C:\WINNT\System32\nssys32.exe
O4 - HKCU\..\Run: [Hhtc] C:\Documents and Settings\Casper D. Carstens\Application Data\weuo.exe
O4 - HKCU\..\Run: [Tqwjtg] C:\WINNT\System32\cqw.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Real-time Monitor.lnk = C:\Programmer\Trend Micro\PC-cillin 2000\PNTIOMON.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: (no name) - {1A00C40B-DA85-4aa3-A67F-582D9347EECD} - C:\WINNT\System32\IEDriver\TD.exe (file missing)
O9 - Extra 'Tools' menuitem: MaxSpeed - {1A00C40B-DA85-4aa3-A67F-582D9347EECD} - C:\WINNT\System32\IEDriver\TD.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE