Logfile of HijackThis v1.99.1
Scan saved at 02:19:18, on 23.05.2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\rbtray.exe
C:\Programme\Ashampoo\Ashampoo FireWall\FireWall.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\Apache Group\Apache2\bin\ApacheMonitor.exe
C:\Programme\AntiVir PersonalEdition Classic\sched.exe
C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
C:\Programme\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe
C:\WINDOWS\System32\oodag.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Programme\WinTV\WinTV2K.EXE
C:\Programme\SenseConnect! PRO\sc_pro.exe
C:\Programme\Internet Explorer\IEXPLORE.EXE
D:\Programme\WinHex\WinHex.exe
C:\Programme\GetRight\getright.exe
D:\Programme\hijackthis199\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:loser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Syphos
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 4.78.211.221:8080
O1 - Hosts: 198.176.8.70 patch01.us.segaonline.jp # usa server psobb
O1 - Hosts: 207.210.93.28 game01.us.segaonline.jp # usa server psobb
O1 - Hosts: 127.0.0.255
http://www.microsoft.de
O1 - Hosts: 127.0.0.255
http://www.microsoft.com
O1 - Hosts: 127.0.0.255
http://www.microsoft.net
O1 - Hosts: 127.0.0.255
http://www.tuifly.com
O1 - Hosts: 127.0.0.255
http://www.sponsorads.de
O1 - Hosts: 127.0.0.255
http://www.sponsorads.com
O1 - Hosts: 127.0.0.255
http://www.hitbox.com
O1 - Hosts: 127.0.0.255
http://www.tribalfusion.com
O1 - Hosts: 127.0.0.255
http://www.bravenet.com
O1 - Hosts: 127.0.0.255 stat.onestat.com
O1 - Hosts: 127.0.0.255 www1.paypopup.com
O1 - Hosts: 127.0.0.255
http://www.bluestreak.com
O1 - Hosts: 127.0.0.255 as-us.falkag.net
O1 - Hosts: 127.0.0.255
http://www.bfast.com
O1 - Hosts: 127.0.0.255 server.iad.liveperson.net
O1 - Hosts: 127.0.0.255
http://www.2o7.net
O1 - Hosts: 127.0.0.255
http://www.doubleclick.net
O1 - Hosts: 127.0.0.255 ads.multimania.lycos.fr
O1 - Hosts: 127.0.0.255
http://www.imrworldwide.com
O1 - Hosts: 127.0.0.255
http://www.seeq.com
O1 - Hosts: 127.0.0.255 servedby.netshelter.net
O1 - Hosts: 127.0.0.255
http://www.advertising.com
O1 - Hosts: 127.0.0.255
http://www.z1.adserver.com
O1 - Hosts: 127.0.0.255 serving-sys.com
O1 - Hosts: 127.0.0.255
http://www.spylog.com
O1 - Hosts: 127.0.0.255 as1.falkag.de
O1 - Hosts: 127.0.0.255
http://www.fastclick.net
O1 - Hosts: 127.0.0.255
http://www.adserver.71i.de
O1 - Hosts: 127.0.0.255
http://www.atdmt.com
O1 - Hosts: 127.0.0.255
http://www.realmedia.com
O1 - Hosts: 127.0.0.255
http://www.tradedoubler.com
O1 - Hosts: 127.0.0.255
http://www.casalemedia.com
O1 - Hosts: 127.0.0.255
http://www.mediaplex.com
O1 - Hosts: 127.0.0.255 ehg-idg.hitbox.com
O1 - Hosts: 127.0.0.255 ads.pointroll.com
O1 - Hosts: 127.0.0.255 partners.webmasterplan.com
O1 - Hosts: 127.0.0.255
http://www.counter.hitslink.com
O1 - Hosts: 127.0.0.255
http://www.valueclick.com
O1 - Hosts: 127.0.0.255 servedby.advertising.com
O1 - Hosts: 127.0.0.255 www10.paypopup.com
O1 - Hosts: 127.0.0.255 bs.serving-sys.com
O1 - Hosts: 127.0.0.255
http://www.spylog.com
O1 - Hosts: 127.0.0.255
http://www.targetnet.com
O1 - Hosts: 127.0.0.255
http://www.hotlog.ru
O1 - Hosts: 127.0.0.255
http://www.statcounter.com
O1 - Hosts: 127.0.0.255
http://www.trafficmp.com
O1 - Hosts: 127.0.0.255 imrworldwide.com
O1 - Hosts: 127.0.0.255
http://www.ilove.de
O1 - Hosts: 127.0.0.255
http://www.layer-ads.de
O1 - Hosts: 127.0.0.255 offsearch.cc
O1 - Hosts: 127.0.0.255
http://www.x-google.net
O1 - Hosts: 127.0.0.255 x-google.net
O1 - Hosts: 127.0.0.255 new-search.net
O1 - Hosts: 127.0.0.255 install.xxxtoolbar.com
O1 - Hosts: 127.0.0.255 uk.adserver.yahoo.com
O1 - Hosts: 127.0.0.255 us.ard.yahoo.com
O1 - Hosts: 127.0.0.255 searchCo.com
O1 - Hosts: 127.0.0.255 pop.searchCo.com
O1 - Hosts: 127.0.0.255 servedby.advertising.com
O1 - Hosts: 127.0.0.255 friendfinder.com
O1 - Hosts: 127.0.0.255 banners.dot.tk
O1 - Hosts: 127.0.0.255 www8.paypopup.com
O1 - Hosts: 127.0.0.255
http://www.skycolors.com
O1 - Hosts: 127.0.0.255
http://www.websponsor.net
O1 - Hosts: 127.0.0.255
http://www.gothic-underground.com
O1 - Hosts: 127.0.0.255 partners.webmasterplan.com
O1 - Hosts: 127.0.0.255
http://www.sponsorpro.de
O1 - Hosts: 127.0.0.255 207.net
O1 - Hosts: 127.0.0.255 ads.tripod.lycos.de
O1 - Hosts: 127.0.0.255 adserver.planet-multiplayer.de
O1 - Hosts: 127.0.0.255 advertising.com
O1 - Hosts: 127.0.0.255 as-us.falkag.net
O1 - Hosts: 127.0.0.255 as-eu.falkag.net
O1 - Hosts: 127.0.0.255 as1.falkag.de
O1 - Hosts: 127.0.0.255 atdmt.com
O1 - Hosts: 127.0.0.255 bfast.com
O1 - Hosts: 127.0.0.255 bluestreak.com
O1 - Hosts: 127.0.0.255 doubleclick.net
O1 - Hosts: 127.0.0.255 *.fastclick.net
O1 - Hosts: 127.0.0.255 imrworldwide.com
O1 - Hosts: 127.0.0.255 maxserving.com
O1 - Hosts: 127.0.0.255 partners.webmasterplan.com
O1 - Hosts: 127.0.0.255 realmedia.com
O1 - Hosts: 127.0.0.255 servedby.advertising.com
O1 - Hosts: 127.0.0.255 tribalfusion.com
O1 - Hosts: 127.0.0.255 z1.adserver.com
O1 - Hosts: 127.0.0.255 rcm-de.amazon.de
O1 - Hosts: 127.0.0.255
http://www.raus.de
O1 - Hosts: 127.0.0.255 raus.de
O1 - Hosts: 127.0.0.255 raus.net
O1 - Hosts: 127.0.0.255 protcpa.coolfreepages.com
O1 - Hosts: 127.0.0.255 windows.microsoft.com
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar2.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [avgnt] "C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [RBTray] rbtray.exe
O4 - HKLM\..\Run: [Ashampoo FireWall] "C:\Programme\Ashampoo\Ashampoo FireWall\FireWall.exe" -TRAY
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Monitor Apache Servers.lnk = C:\Programme\Apache Group\Apache2\bin\ApacheMonitor.exe
O8 - Extra context menu item: Download with GetRight - C:\Programme\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Programme\GetRight\GRbrowse.htm
O8 - Extra context menu item: Sothink SWF Catcher - C:\Programme\Gemeinsame Dateien\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Programme\Gemeinsame Dateien\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Programme\Gemeinsame Dateien\SourceTec\SWF Catcher\InternetExplorer.htm
O10 - Unknown file in Winsock LSP: c:\programme\ashampoo\ashampoo firewall\spi.dll
O10 - Unknown file in Winsock LSP: c:\programme\ashampoo\ashampoo firewall\spi.dll
O10 - Unknown file in Winsock LSP: c:\programme\ashampoo\ashampoo firewall\spi.dll
O10 - Unknown file in Winsock LSP: c:\programme\ashampoo\ashampoo firewall\spi.dll
O10 - Unknown file in Winsock LSP: c:\programme\ashampoo\ashampoo firewall\spi.dll
O10 - Unknown file in Winsock LSP: c:\programme\ashampoo\ashampoo firewall\spi.dll
O12 - Plugin for .PDF: C:\Programme\Internet Explorer\PLUGINS\nppdf32.dll
O15 - Trusted Zone: tota.ath.cx
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = syphos.sub
O17 - HKLM\Software\..\Telephony: DomainName = syphos.sub
O17 - HKLM\System\CCS\Services\Tcpip\..\{83D515C7-0C76-48F2-9659-FA53CCC571CF}: NameServer = 217.237.151.142 217.237.150.188
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = syphos.sub
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = syphos.sub
O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apache2 - Unknown owner - C:\Programme\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MySQL - Unknown owner - C:\Programme\MySQL\MySQL.exe (file missing)
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\System32\oodag.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: WindowsROOTLogin (winrtlognSY) - Unknown owner - cmd.exe (file missing)