Logfile of HijackThis v1.99.1
Scan saved at 17:59:18, on 27-05-2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\SYSTEM32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\FoxServ\apache\Apache.exe
C:\CODA\SERVER\BIN\oaslsv.exe
C:\CODA\SERVER\BIN\oasnsv.exe
C:\WINNT\System32\svchost.exe
C:\FoxServ\apache\Apache.exe
C:\Program Files\lotus\notes\ntmulti.exe
C:\FoxServ\mysql\bin\mysqld-nt.exe
C:\ORANT\bin\agntsrvc.exe
C:\ORANT\Apache\Apache\apache.exe
C:\WINNT\SYSTEM32\cmd.exe
C:\ORANT\bin\dbsnmp.exe
C:\ORANT\BIN\TNSLSNR.exe
C:\ORANT\bin\omtsreco.exe
C:\WINNT\Explorer.EXE
c:\orant\bin\ORACLE.EXE
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\tcpsvcs.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\MSSQL7\binn\sqlagent.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\ORANT\Apache\Apache\apache.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\ORANT\jdk\bin\java.exe
C:\ORANT\jdk\bin\java.exe
c:\orant\bin\isqlplus
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Winamp3\winampa.exe
C:\WINNT\AGRSMMSG.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Free Download Manager\fdm.exe
C:\MSSQL7\Binn\sqlmangr.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
C:\DISCOD\Instaladores\Spyware\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: WgBHO Class - {67E9834D-B226-49E6-B6F6-85AA64E14BA3} - C:\Program Files\Free Download Manager\iefdm.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NetPurity.SiteAccess - {DC3EB972-8628-4C46-B7CE-25EBD05EA362} - C:\WINNT\system32\NetPurity.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\RunServices: [WebSiteServer] C:\WebSite\httpd32.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\nbj.exe"
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
O4 - Startup: Monitor Apache Servers.lnk = C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe
O4 - Global Startup: Service Manager.lnk = C:\MSSQL7\Binn\sqlmangr.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site with Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
O23 - Service: Apache.exe - Unknown owner - C:\FoxServ\apache\Apache.exe
O23 - Service: CODA-Financials Logical Server daniela - Unknown owner - C:\CODA\SERVER\BIN\oaslsv.exe
O23 - Service: CODA-Financials Logical Server DANIELA1 - Unknown owner - C:\CODA\SERVER\BIN\oaslsv.exe
O23 - Service: CODA-Financials Name Server 08.101.0207 - Unknown owner - C:\CODA\SERVER\BIN\oasnsv.exe
O23 - Service: CODA-Financials Name Server DANIELA1 - Unknown owner - C:\CODA\SERVER\BIN\oasnsv.exe
O23 - Service: Cognos Communication Service (cer2) - Cognos Incorporated - C:\Program Files\Cognos\cer2\bin\cogcomsvc7_0.exe
O23 - Service: Cognos PowerPlay Enterprise Server (cer2) - Cognos Incorporated - C:\Program Files\Cognos\cer2\bin\ppserver.exe
O23 - Service: Cognos Upfront Administration Service (cer2) (Cognos UpfrontAdministration (cer2)) - Cognos Incorporated - C:\Program Files\Cognos\cer2\bin\UpfrontAdministration.exe
O23 - Service: Cognos Upfront Data Store (cer2) (Cognos UpfrontDataStore (cer2)) - Cognos Incorporated - C:\Program Files\Cognos\cer2\bin\upfdbsrv.exe
O23 - Service: Cognos Upfront Dispatcher (cer2) (Cognos UpfrontDispatcher (cer2)) - Cognos Incorporated - C:\Program Files\Cognos\cer2\bin\UpfDispatcherService.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Cognos Ticket Server (DSTicketSrv) - Cognos Inc - C:\Program Files\Cognos\cer2\..\TicketServer\bin\ticketserver.exe
O23 - Service: Cognos IWR Service Manager (cer2) (IWSvcMancer2) - Cognos Incorporated - C:\Program Files\Cognos\cer2\bin\iwsvcman.exe
O23 - Service: MSSQLServerADHelper - Unknown owner - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe (file missing)
O23 - Service: Multi-user Cleanup Service - Unknown owner - C:\Program Files\lotus\notes\ntmulti.exe
O23 - Service: mysqld-nt.exe - Unknown owner - C:\FoxServ\mysql\bin\mysqld-nt.exe
O23 - Service: ObjectStore Cache Manager R6.0 - eXcelon Corp. - C:\ODI\OStore\BIN\OSCMGR6.EXE
O23 - Service: ObjectStore Server R6.0 - eXcelon Corp. - C:\ODI\OStore\BIN\OSSERVER.EXE
O23 - Service: OracleDEFAULT_HOME2Agent - Oracle Corporation - c:\ORANT2\bin\agntsrvc.exe
O23 - Service: OracleDEFAULT_HOME2ClientCache - Unknown owner - c:\ORANT2\BIN\ONRSD.EXE
O23 - Service: OracleDEFAULT_HOMEAgent - Oracle Corporation - C:\ORANT\bin\agntsrvc.exe
O23 - Service: OracleDEFAULT_HOMEClientCache - Unknown owner - C:\ORANT\BIN\ONRSD.EXE
O23 - Service: OracleDEFAULT_HOMEHTTPServer - Unknown owner - C:\ORANT\Apache\Apache\apache.exe" --ntservice (file missing)
O23 - Service: OracleDEFAULT_HOMEPagingServer - Unknown owner - C:\ORANT/bin/pagntsrv.exe
O23 - Service: OracleDEFAULT_HOMESNMPPeerEncapsulator - Unknown owner - C:\ORANT\BIN\ENCSVC.EXE
O23 - Service: OracleDEFAULT_HOMESNMPPeerMasterAgent - Unknown owner - C:\ORANT\BIN\AGNTSVC.EXE
O23 - Service: OracleDEFAULT_HOMETNSListener - Unknown owner - C:\ORANT\BIN\TNSLSNR.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\ORANT\bin\omtsreco.exe
O23 - Service: OracleServiceDANIELA1 - Oracle Corporation - c:\orant\bin\ORACLE.EXE
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Web Server (WebServer) - O'Reilly & Associates, Inc. - C:\WebSite\httpd32.exe

