XoN`-
Legacy Member
Code:
Logfile of HijackThis v1.99.0
Scan saved at 14:42:02, on 16/02/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Unable to get Internet Explorer version!
Running processes:
D:\WINNT\System32\smss.exe
D:\WINNT\system32\winlogon.exe
D:\WINNT\system32\services.exe
D:\WINNT\system32\lsass.exe
G:\Program Files\Sygate\SPF\smc.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\spoolsv.exe
G:\Program Files\AVPersonal\AVGUARD.EXE
G:\Program Files\AVPersonal\AVWUPSRV.EXE
D:\WINNT\system32\CTSvcCDA.EXE
C:\WinNT\system32\drivers\etc\system\su\FireDaemon.EXE
D:\WINNT\system32\svchost.exe
C:\WinNT\system32\drivers\etc\system\su\WinMgmt.exe
D:\WINNT\system32\gearsec.exe
D:\WINNT\system32\nvsvc32.exe
D:\WINNT\system32\oodag.exe
D:\WINNT\system32\regsvc.exe
D:\WINNT\System32\snmp.exe
D:\WINNT\system32\MsPMSPSv.exe
D:\WINNT\system32\svchost.exe
D:\WINNT\system32\inetsrv\inetinfo.exe
D:\WINNT\System32\svchost.exe
G:\PROGRA~1\Aston\aston.exe
G:\Program Files\Winamp\winampa.exe
D:\WINNT\system32\RUNDLL32.EXE
D:\WINNT\SOUNDMAN.EXE
G:\Program Files\Google\Gmail Notifier\gnotify.exe
G:\Program Files\Telemeter 3.0\telemeter3.exe
G:\Program Files\Rainmeter\Rainmeter.exe
G:\Program Files\Logitech keyboard\SetPoint\KEM.exe
G:\Program Files\Logitech keyboard\SetPoint\KHALMNPR.EXE
G:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
G:\Program Files\Trillian\trillian.exe
D:\WINNT\System32\mdm.exe
G:\Program Files\Soulseek\slsk.exe
D:\WINNT\system32\LVComsX.exe
D:\WINNT\system32\wisptis.exe
G:\Program Files\Winamp\winamp.exe
G:\Program Files\Opera 8 Beta\Opera.exe
D:\Program Files\WinRAR\WinRAR.exe
D:\DOCUME~1\omnicron\LOCALS~1\Temp\Rar$EX02.140\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [WinampAgent] G:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [gcasServ] "G:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [Gmail notifier] G:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKCU\..\Run: [Telemeter 3.0] "G:\Program Files\Telemeter 3.0\telemeter3.exe"
O4 - Startup: Rainmeter.lnk = G:\Program Files\Rainmeter\Rainmeter.exe
O4 - Global Startup: Logitech SetPoint.lnk = G:\Program Files\Logitech keyboard\SetPoint\KEM.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
O8 - Extra context menu item: &Google Search - res://d:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://d:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://d:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download &Flash Movies - G:\Program Files\Flash Hunter\save.htm
O8 - Extra context menu item: Similar Pages - res://d:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://d:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\WINNT\system32\msjava.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINNT\web\related.htm
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - G:\Program Files\Irfanview\Ebay\Ebay.htm
O9 - Extra button: Flash2X Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - G:\Program Files\Flash Hunter\save.htm (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: &Launch Flash Hunter - {77B563A5-2A35-4E6B-BFC8-F4B6BB65D5DF} - G:\Program Files\Flash Hunter\save.htm (file missing) (HKCU)
O13 - DefaultPrefix:
O13 - WWW Prefix:
O13 - Home Prefix:
O13 - Mosaic Prefix:
O13 - FTP Prefix:
O13 - Gopher Prefix:
O15 - Trusted Zone: [url]http://*.windowsupdate.com[/url]
O16 - DPF: ppctlcab - [url]http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab[/url]
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - [url]http://ppupdates.ca.com/downloads/scanner/axscanner.cab[/url]
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - [url]http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab[/url]
O23 - Service: AntiVir Service - H+BEDV Datentechnik GmbH - G:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update - H+BEDV Datentechnik GmbH, Germany - G:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINNT\system32\CTSvcCDA.EXE
O23 - Service: Diskeeper - Unknown - G:\Program Files\DiskeeperLite\DKService.exe (file missing)
O23 - Service: Logical Disk Manager Administrative-service - VERITAS Software Corp. - D:\WINNT\System32\dmadmin.exe
O23 - Service: FireDaemon Service: events - Unknown - C:\WinNT\system32\drivers\etc\system\su\FireDaemon.EXE
O23 - Service: gearsec - GEAR Software - D:\WINNT\system32\gearsec.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - D:\WINNT\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - D:\WINNT\system32\oodag.exe
O23 - Service: FireDaemon Service: rundll - Unknown - C:\WinNT\system32\drivers\etc\system\su\FireDaemon.EXE
O23 - Service: Sygate Personal Firewall Pro - Sygate Technologies, Inc. - G:\Program Files\Sygate\SPF\smc.exe

