Logfile of HijackThis v1.98.0
Scan saved at 14:40:51, on 02.07.2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINNT\system32\DRIVERS\dcfssvc.exe
C:\WINNT\system32\svchost.exe
C:\Programme\KEN!\KENCLI.EXE
C:\WINNT\system32\regsvc.exe
C:\Programme\Analog Devices\SoundMAX\SMAgent.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\explorer.exe
C:\Programme\Analog Devices\SoundMAX\Smtray.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Programme\KEN!\kentbcli.exe
C:\Programme\QuickTime\qttask.exe
C:\WINNT\system32\internat.exe
\Server2000\data\palm\HOTSYNC.EXE
C:\lotus\organize\easyclip6.exe
C:\Programme\Microsoft Office\Office\OSA.EXE
C:\Programme\Internet Explorer\IEXPLORE.EXE
C:\WINNT\system32\taskmgr.exe
C:\DOKUME~1\user12\LOKALE~1\Temp\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://listdating.com/search/in.html?s
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL =
http://listdating.com/search/in.html?s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://213.159.117.132/redir.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://awebfind.biz/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://listdating.com/search/in.html?s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://listdating.com/search/in.html?s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://213.159.117.132/redir.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://listdating.com/search/in.html?s
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://listdating.com/search/in.html?s
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://listdating.com/search/in.html?m
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://listdating.com/search/in.html?s
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://listdating.com/search/in.html?s
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://listdating.com/search/in.html?s
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://listdating.com/search/in.html?s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
http://213.159.117.132/redir.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
http://213.159.117.132/redir.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer bereitgestellt von T-DSL Business
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.1.201:3128
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
F2 - REG:system.ini: Shell=explorer.exe C:\WINNT\System\user32.exe
O2 - BHO: IEHlprObj Class - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - c:\lotus\organize\iehelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1031,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Smapp] C:\Programme\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [KEN Taskbar Client] "C:\Programme\KEN!\kentbcli.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TaskMon] C:\WINNT\system32\taskmon.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ist service uninstall] C:\WINNT\mstasks2.exe /u
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Startup: HotSync Manager.lnk = palm\HOTSYNC.EXE
O4 - Startup: Lotus Organizer EasyClip.lnk = C:\lotus\organize\easyclip6.exe
O4 - Startup: Microsoft-Indexerstellung.lnk = C:\Programme\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Office-Start.lnk = C:\Programme\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Outlook\Office\OSA9.EXE
O8 - Extra context menu item: >> DATING >> -
http://listdating.com/dt.htm
O8 - Extra context menu item: >> SEARCH >> -
http://listdating.com/se.htm
O9 - Extra button: Web-Eintrag - {B4E30F61-16D9-11D3-85D1-005004229569} - c:\lotus\organize\bandobjs.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O13 - DefaultPrefix:
http://listdating.com/search/in.html?url=
O13 - WWW Prefix:
http://listdating.com/search/in.html?url=
O14 - IERESET.INF: START_PAGE_URL=http://192.168.1.201:3128/ken2000.html
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ALTENBURG.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ALTENBURG.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = ALTENBURG.local
O21 - SSODL: System - {6436CEEF-F5D6-4500-9900-5A77A180F8A5} - C:\WINNT\system32\system32.dll (file missing)