Logfile of HijackThis v1.99.1
Scan saved at 15:28:54, on 29.11.2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\DRIVERS\CDANTSRV.EXE
C:\WINNT\System32\svchost.exe
C:\Programfiler\Fellesfiler\Microsoft Shared\VS7Debug\mdm.exe
C:\Programfiler\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Programfiler\Analog Devices\SoundMAX\SMAgent.exe
C:\WINNT\system32\stisvc.exe
C:\Programfiler\Trend Micro\OfficeScan Client\tmlisten.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\hkcmd.exe
C:\WINNT\System32\igfxpers.exe
C:\Programfiler\Trend Micro\OfficeScan Client\pccntmon.exe
C:\Programfiler\Picasa2\PicasaMediaDetector.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\ctfmon.exe
C:\Programfiler\WinZip\WZQKPICK.EXE
C:\Programfiler\Adobe\Acrobat 6.0\Distillr\acrotray.exe
T:\Sevserv1.exe
C:\WINNT\system32\ntvdm.exe
C:\Programfiler\Microsoft Office\Office10\msoffice.exe
C:\Programfiler\Trend Micro\OfficeScan Client\ofcdog.exe
C:\Programfiler\Trend Micro\OfficeScan Client\Pop3Trap.exe
C:\Programfiler\Internet Explorer\iexplore.exe
C:\Programfiler\Internet Explorer\IEXPLORE.EXE
C:\Programfiler\Spybot - Search & Destroy\SpybotSD.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Programfiler\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\edvard.SCANBRIDGE\Lokale innstillinger\Temp\wz67cb\HijackThis.exe
C:\Documents and Settings\edvard.SCANBRIDGE\Lokale innstillinger\Temp\wzb30d\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programfiler\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {35F7813A-AF74-4474-B1DC-7EE6FB6C43C6} - C:\WINNT\system32\wseyklnr.dll
O2 - BHO: (no name) - {4164B2DD-6B17-660D-7F30-07B7BBBBE975} - C:\WINNT\system32\secgcx.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programfiler\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {755bbd1a-aa59-456c-afeb-b4c42c4dcb6f} - C:\WINNT\system32\ixt0.dll (file missing)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programfiler\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programfiler\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [igfxtray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINNT\System32\igfxpers.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Programfiler\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Programfiler\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [jimixel.dll] C:\WINNT\system32\rundll32.exe C:\WINNT\system32\jimixel.dll,ildsdzb
O4 - HKLM\..\RunServicesOnce: [1] C:\WINNT\System32\RegSvr32.exe /s C:\WINNT\System32\BCHal.dll
O4 - HKLM\..\RunServicesOnce: [2] C:\WINNT\System32\RegSvr32.exe /s C:\WINNT\System32\BlstCtrl.dll
O4 - HKLM\..\RunServicesOnce: [3] C:\WINNT\System32\RegSvr32.exe /s C:\WINNT\System32\BCInfo.dll
O4 - HKLM\..\RunServicesOnce: [4] C:\WINNT\System32\RegSvr32.exe /s C:\WINNT\System32\BCMon.dll
O4 - HKLM\..\RunServicesOnce: [5] C:\WINNT\System32\RegSvr32.exe /s C:\WINNT\System32\BCColor.dll
O4 - HKLM\..\RunServicesOnce: [6] C:\WINNT\System32\RegSvr32.exe /s C:\WINNT\System32\BCDesk.dll
O4 - HKLM\..\RunServicesOnce: [20] C:\WINNT\System32\RegSvr32.exe /s C:\WINNT\System32\BCPref.dll
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: KINDIS ADF Utskrift.lnk = ?
O4 - Startup: Kopi av WinUDL V1.5.lnk = C:\WINUDL\WINUDL1.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Programfiler\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programfiler\WinZip\WZQKPICK.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Programfiler\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Hurtigstart for Adobe Reader.lnk = C:\Programfiler\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.t...ivex/hcImpl.cab
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Programfiler\AutoCAD 2000i\AcDcToday.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred Control) - file://C:\Programfiler\AutoCAD 2000i\InstFred.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Programfiler\AutoCAD 2000i\AcPreview.ocx
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = Scanbridge.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = Scanbridge.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = Scanbridge.local
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: winjup32 - C:\WINNT\SYSTEM32\winjup32.dll
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINNT\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Programfiler\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programfiler\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Programfiler\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: WMDM PMSP Service - Unknown owner - C:\WINNT\system32\mspmspsv.exe (file missing)