Logfile of HijackThis v1.99.1
Scan saved at 20:32:39, on 29-5-2005
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C
:\WINDOWS\
SYSTEM\KERNEL32
.DLL
C
:\WINDOWS\
SYSTEM\MSGSRV32
.EXE
C
:\WINDOWS\
SYSTEM\ATI2EVXX
.EXE
C:\PROGRAM FILES\MESSENGERPLUS! 3\MSGPLUS.EXE
C:\WINDOWS\EXPLORER.EXE
C
:\PROGRAM FILES\MOUSEWARE\
SYSTEM\EM_EXEC
.EXE
C
:\WINDOWS\
SYSTEM\RESTORE\STMGR
.EXE
C:\PROGRAM FILES\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE
C:\PROGRAM FILES\ALCATEL\SPEEDTOUCH USB\DRAGDIAG.EXE
C:\WINDOWS\LOADQM.EXE
C
:\WINDOWS\
SYSTEM\ELITETPG32
.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP PSC 700 SERIES\BIN\HPODEV07.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP PSC 700 SERIES\FRU\REMIND32.EXE
C:\WINDOWS\CALC.EXE
C:\PROGRAM FILES\WINAMP\WINAMP.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\WINDOWS\PROFILES\MARTIJN\MIJN DOCUMENTEN\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer speciaal voor u van Planetis
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - Default URLSearchHook is missing
O2
- BHO
: &EliteSideBar
- {ED103D9F
-3070-4580-AB1E
-E5C179C1AE41
} - C
:\WINDOWS\EliteSideBar\EliteSideBar 08
.dll
(file missing
)O2
- BHO
: &EliteBar
- {28CAEFF3
-0F18
-4036-B504
-51D73BD81ABC
} - C
:\WINDOWS\EliteToolBar\EliteToolBar version 60
.dll
(file missing
)O2 - BHO: CeresObj Class - {00000049-8F91-4D9C-9573-F016E7626484} - C:\WINDOWS\CERES.DLL
O3
- Toolbar
: &Radio
- {8E718888-423F
-11D2
-876E
-00A0C9082467
} - C
:\WINDOWS\
SYSTEM\MSDXM
.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [EW Message Server] msg32.exe
O4
- HKLM\
..\Run
: [EM_EXEC
] C
:\PROGRA~
1\MOUSEW~
1\
SYSTEM\EM_EXEC
.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [WebSpecials] rundll32 "C:\Program Files\WebSpecials\webspec.dll",run
O4
- HKLM\
..\Run
: [checkrun
] C
:\WINDOWS\
SYSTEM\ELITETPG32
.EXE
O4
- HKLM\
..\Run
: [ruihke
] c
:\windows\
system\ruihke
.exe
O4
- HKLM\
..\Run
: [ASDPLUGIN
] C
:\WINDOWS\
SYSTEM\Netherlands
.exe
-N
O4
- HKLM\
..\Run
: [HPAIO_PrintFolderMgr
] C
:\WINDOWS\
SYSTEM\hpoopm07
.exe
O4
- HKLM\
..\RunServices
: [*StateMgr
] C
:\WINDOWS\
System\Restore\StateMgr
.exe
O4
- HKLM\
..\RunServices
: [SSDPSRV
] C
:\WINDOWS\
SYSTEM\ssdpsrv
.exe
O4 - HKLM\..\RunServices: [ATIPOLL] ati2evxx.exe
O4
- HKLM\
..\RunServices
: [ATISmart
] C
:\WINDOWS\
SYSTEM\ati2s9ag
.exe
O4 - HKLM\..\RunServices: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4
- HKLM\
..\RunServices
: [StillImageMonitor
] C
:\WINDOWS\
SYSTEM\STIMON
.EXE
O4 - HKCU\..\Run: [Windows Registry Repair Pro] C:\PROGRAM FILES\3B SOFTWARE\WINDOWS REGISTRY REPAIR PRO\REGISTRYREPAIRPRO.EXE 4
O4 - HKCU\..\Run: [Update Service] "C:\Program Files\Common Files\Teknum Systems\update.exe" /startup
O4 - Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: HPAiODevice.lnk = C:\Program Files\Hewlett-Packard\hp psc 700 series\bin\hpodev07.exe
O4 - Startup: Hewlett-Packard Recorder.lnk = C:\Program Files\Hewlett-Packard\hp psc 700 series\FRU\Remind32.exe
O9
- Extra button
: Real
.com
- {CD67F990
-D8E9
-11d2
-98FE
-00C0F0318AFE
} - C
:\WINDOWS\
SYSTEM\Shdocvw
.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll