ogfile of HijackThis v1.99.1
Scan saved at 21:00:48, on 20-02-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\InfoKing\InfoPenMSN\Pro\InfoPenIM.exe
C:\Programmer\BearShare\BearShare.exe
C:\PROGRA~1\Save\Save.exe
C:\WINDOWS\System32\WScript.exe
C:\Programmer\Logitech\Video\LogiTray.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\Messenger\MSMSGS.EXE
C:\Programmer\Valve\Steam\Steam.exe
C:\WINDOWS\System32\2668.exe
C:\Programmer\BearShare\BearShare.exe
C:\WINDOWS\system32\regsrv.exe
C:\WINDOWS\system32\cmd.exe
C:\Programmer\WinAce\WinAce.exe
C:\DOCUME~1\Mikkel\LOKALE~1\Temp\~AceTemp\hijackthis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://thesearchmall.com/index.phpR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://thesearchmall.com/index.phpR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://thesearchmall.com/index.phpR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.kill-bill2.dk/R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://thesearchmall.com/index.phpR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://thesearchmall.com/index.phpR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\system32\winmgd.win
F1 - win.ini: run=C:\WINDOWS\system32\mouse_configurator.win
O2 - BHO: ohb - {0AEE4D0C-4B38-4196-AE32-70ACE5656647} - C:\WINDOWS\System32\winsrm32.dll
O3 - Toolbar: TheSearchMall.com Bar - {4B8F38C7-62FC-4762-B9A0-27E63F768167} - C:\WINDOWS\System32\winsrm32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [InfoPenMSN] C:\Programmer\InfoKing\InfoPenMSN\Pro\InfoPenIM.exe
O4 - HKLM\..\Run: [BearShare] "C:\Programmer\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [WhenUSave] C:\PROGRA~1\Save\Save.exe
O4 - HKLM\..\Run: [Kernel32] C:\WINDOWS\system32\Kernel32.win
O4 - HKLM\..\Run: [Israfel] C:\WINDOWS\system32\Israfel.vbs
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programmer\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programmer\Logitech\Video\LogiTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [Steam] C:\Programmer\Valve\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [Apwheel] C:\WINDOWS\System32\2668.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O15 - Trusted Zone:
www.gangstawar.comO15 - Trusted Zone:
http://www.komogvind.dkO16 - DPF: {0CB2BD5A-7A80-4BA9-B49A-02DC51144BDF} (vciewer control) -
http://www.thepaymentcentre.com/build/vciewer.cabO16 - DPF: {41D13E9A-BB94-402A-8502-AFA78526B63D} (iiittt Class) -
http://www.thesearchmall.com/toolbar/winsrm32.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab