OK og tak. Her er den så:
Logfile of HijackThis v1.97.0
Scan saved at 16:59:18, on 10-09-2003
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\SA3DSRV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\MOUSE\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\SYSTEM\SXGDSENU.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\ATICWD32.EXE
C:\WINDOWS\SYSTEM\ATITASK.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\PROGRAMMER\COMPAQ\EASY ACCESS BUTTON SUPPORT\CPQEAUI.EXE
C:\COMPAQ\INTERNET\CISRVR.EXE
C:\PROGRAMMER\WINAMP\WINAMPA.EXE
C:\PROGRAMMER\PANICWARE\POP-UP STOPPER\DPPS2.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAMMER\COMPAQ\EASY ACCESS BUTTON SUPPORT\BTTNSERV.EXE
C:\PROGRAMMER\AVPERSONAL\AVGCTRL.EXE
C:\PROGRAMMER\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAMMER\ICONOID\ICONOID.EXE
C:\PROGRAMMER\ZONE LABS\ZONEALARM\ZONEALARM.EXE
C:\PROGRAMMER\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\DOKUMENTER\ESCAPE\ESCAPE.EXE
C:\PROGRAMMER\COMPAQ\ON-SCREEN DISPLAY\OSD.EXE
C:\PROGRAMMER\WINZIP\WINZIP32.EXE
C:\WINDOWS\NOTEPAD.EXE
C:\PROGRAMMER\INTERNET EXPLORER\IEXPLORE.EXE
C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://search.presario.net/scripts/redirectors/presario/srchredir.dll?c=1c99&s=search&i=danR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.dk/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://search.presario.net/scripts/redirectors/presario/srchredir.dll?c=1c99&s=search&i=danR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://search.presario.net/scripts/redirectors/presario/srchredir.dll?c=1c99&s=search&i=danR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Thomas & Mette's Internet!
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
F2 - REG:system.ini: Shell=
O1 - Hosts: 66.40.21.73 auto.search.msn.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMMER\ADOBE\ACROBAT 5.0\ACROBAT\ACTIVEX\ACROIEHELPER.OCX
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [Essdc] essdc.exe
O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
O4 - HKLM\..\Run: [SXGDSENU] SXGDSENU.exe
O4 - HKLM\..\Run: [Skan registreringsdatabase] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [Job-oversigt] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
O4 - HKLM\..\Run: [AtiKey] Atitask.exe
O4 - HKLM\..\Run: [EACLEAN] C:\Programmer\Compaq\Easy Access Button Support\eaclean.exe /NORESTART
O4 - HKLM\..\Run: [CPQEASYACC] "C:\PROGRAMMER\COMPAQ\EASY ACCESS BUTTON SUPPORT\Cpqeaui.exe"
O4 - HKLM\..\Run: [Aureal A3D Interactive Audio Init] A3dInit.exe
O4 - HKLM\..\Run: [Compaq Internet Setup] C:\Compaq\Internet\InetWizard.exe /RUN
O4 - HKLM\..\Run: [CISrvr Program] C:\COMPAQ\INTERNET\CISRVR.EXE
O4 - HKLM\..\Run: [WinampAgent] "C:\PROGRAMMER\WINAMP\WINAMPa.exe"
O4 - HKLM\..\Run: [System Service] C:\WINDOWS\SYSTEM\MSREXE.EXE
O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRAMMER\PANICWARE\POP-UP STOPPER\DPPS2.EXE"
O4 - HKLM\..\Run: [AVGCtrl] C:\PROGRAMMER\AVPERSONAL\AVGCTRL.EXE /min
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\RunServices: [HC Reminder] hc.exe
O4 - HKLM\..\RunServices: [Aureal A3D Interactive Audio] sa3dsrv.exe
O4 - HKLM\..\RunServices: [defwatch] c:\Programmer\Norton AntiVirus\defwatch.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [Planlægningsagent] c:\windows\SYSTEM\mstask.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAMMER\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - HKCU\..\Run: [Transparent Icon Labels] "C:\PROGRAMMER\TRANSPARENT ICON LABELS\TRANSPARENT ICON LABELS.EXE" 255
O4 - HKCU\..\Run: [Iconoid] "C:\PROGRAMMER\ICONOID\ICONOID.EXE" -wait 0
O4 - Startup: Microsoft Office-start.lnk = C:\Programmer\Microsoft Office\Office\OSA.EXE
O4 - Startup: Genvej til ESCape.lnk = C:\Dokumenter\escape\ESCape.exe
O4 - Global Startup: ZoneAlarm.lnk = C:\Programmer\Zone Labs\ZoneAlarm\zonealarm.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: SEARCH (HKLM)
O9 - Extra button: ANTIVIRUS (HKLM)
O9 - Extra button: ENTERTAINMENT (HKLM)
O9 - Extra button: SECURITY (HKLM)
O9 - Extra button: SEARCH (HKLM)
O9 - Extra button: SEARCH (HKLM)
O9 - Extra button: ANTIVIRUS (HKLM)
O9 - Extra button: ENTERTAINMENT (HKLM)
O9 - Extra button: SECURITY (HKLM)
O9 - Extra button: SEARCH (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: MSN Messenger Service (HKLM)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .mov: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin.dll
O12 - Plugin for .mid: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin2.dll
O12 - Plugin for .mpeg: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mp3: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin4.dll
O13 - DefaultPrefix:
http://www001.upp.so-net.ne:3128@DF809JOW4WJ2304LFD0SF9FSD0A2T4LDF809JOW4WJ2304LFD0SF9FSD0A2T4LD%2E%42%49%5A/c/c.pl?url=O16 - DPF: {25F5AA75-B6D8-11CF-B348-00002422759D} (DataPoolSV10.CDataPool) -
file://D:\win32\EBankWeb\Software\dpserver.CABO16 - DPF: {36C72320-EDFC-11D0-89DB-02AA3C04DD07} (EBLanguageSelector.LanguageSelector) -
file://D:\win32\EBankWeb\Software\EBLanguageSelector.CABO16 - DPF: {47FCD744-28E2-11D1-A13A-000024601F43} (EB_CommonUtilities.Common1) -
http://www.sparlolland.dk/ebankweb/Software/EB_CommonUtilities.CABO16 - DPF: {B7A2E681-3B00-11D1-81C5-000024222F7F} (EB_Secure.EBSecure) -
file://D:\win32\EBankWeb\Software\EB_Secure.CABO16 - DPF: {CF48D854-EC79-11D0-9EDC-00A0245DA6F6} (OfcCtl Class) -
http://www.sparlolland.dk/ebankweb/Software/Ofx.cabO16 - DPF: {0B4A9EB4-332F-11D1-BEA2-00A0245DA6F8} (FitCrypto Class) -
file://D:\win32\EBankWeb\Software\FitSecure.cabO16 - DPF: {E5CAA475-5F45-11D1-8064-A01A01C10000} (EBPrintSupport.HtmlTemplate) -
file://D:\win32\EBankWeb\Software\EBPrintSupport.CABO16 - DPF: {7C2A1E81-6A69-11D1-8064-A01A01C10000} (EB_Alerter.AlerterBO) -
file://D:\win32\EBankWeb\Software\AlerterBO.CABO16 - DPF: {131220DA-FF52-11D0-8445-000024202088} (EB_LogonUI.LogonUI) -
http://www.sparlolland.dk/ebankweb/Software/LogonUI.CABO16 - DPF: {61E5A398-FE97-11D0-81C5-000024222F7F} (EB_ExportImportUI.ExportImportUI) -
file://D:\win32\EBankWeb\Software\ExportImportUI.CABO16 - DPF: {FBF3B698-FC3A-11D0-8445-000024202088} (EB_RegistrationUI.RegistrationUI) -
file://D:\win32\EBankWeb\Software\RegistrationUI.CABO16 - DPF: {1847C1C1-7274-11D2-A47D-00104B5B4D54} (EB_AgreementUI.AgreementUI) -
file://D:\win32\EBankWeb\Software\AgreementUI.CABO16 - DPF: {EBC90C1A-FDDF-11D0-8445-000024202088} (EB_BalanceUI.BalanceUI) -
http://www.sparlolland.dk/ebankweb/Software/BalanceUI.CABO16 - DPF: {86D3FB35-2862-11D1-8445-000024202088} (EB_CalculatorBO.CalculatorBO) -
file://D:\win32\EBankWeb\Software\CalculatorBO.CABO16 - DPF: {1ED7CC80-F877-11D0-BD39-0000242179F2} (EB_ActivityUI.ActivityUI) -
file://D:\win32\EBankWeb\Software\ActivityUI.CABO16 - DPF: {71D082EF-E0E4-11D0-BD39-0000242179F2} (EB_LastStatementUI.LastStatementUI) -
file://D:\win32\EBankWeb\Software\LastStatementUI.CABO16 - DPF: {DAB01827-98C2-11D1-AC92-000024601F43} (EB_TransferUI.TransferUI) -
http://www.sparlolland.dk/ebankweb/Software/EB_TransferUI.CABO16 - DPF: {DD8B04E4-2B82-11D1-A13C-000024601F43} (EB_BillUI.BillUI) -
http://www.sparlolland.dk/ebankweb/Software/BillUI.CABO16 - DPF: {4DA8C674-6CCC-11D2-81C6-000024222F7F} (EB_BSRegisterUI.BSRegisterUI) -
http://www.sparlolland.dk/ebankweb/Software/BSRegisterUI.CABO16 - DPF: {DB92CCE8-7D33-11D2-81C6-000024222F7F} (EB_BSPaymentsUI.BSPaymentsUI) -
http://www.sparlolland.dk/ebankweb/Software/BSPaymentsUI.CABO16 - DPF: {AA0F7D96-17D8-11D1-A12C-000024601F43} (EB_CreditRegisterUI.CreditRegisterUI) -
http://www.sparlolland.dk/ebankweb/Software/CreditRegisterUI.CABO16 - DPF: {4C4C9342-7224-11D1-8D87-000024601F43} (EB_FuturePaymentsUI.FuturePaymentsUI) -
file://D:\win32\EBankWeb\Software\EB_FuturePaymentsUI.CABO16 - DPF: {DA90D5FC-F2E2-11D0-BD39-0000242179F2} (EB_OrderUI.OrderUI) -
file://D:\win32\EBankWeb\Software\OrderUI.CABO16 - DPF: {3C4C2F07-5F6F-11D2-A525-00A024651F92} (EB_System.CData) -
file://D:\win32\EBankWeb\Software\BDRTL.CABO16 - DPF: {BC94E7E2-545E-11D2-8279-E3236A1BE601} (FTOHomeBankObject) -
file://D:\win32\EBankWeb\Software\HBFTO.CABO16 - DPF: {41335962-52DD-11D2-8279-9CD28522D17E} (TFTRObject) -
file://D:\win32\EBankWeb\Software\FTR.CABO16 - DPF: {480F8542-52E9-11D2-8279-E12E0803FB4E} (boDepotObject) -
file://D:\win32\EBankWeb\Software\SBBO.CABO16 - DPF: {3EE838A3-5F59-11D2-A525-00A024651F92} (DepotovXControl) -
file://D:\win32\EBankWeb\Software\Custodies.cabO16 - DPF: {EF65E163-5EC7-11D2-A525-00A024651F92} (StraksXControl) -
file://D:\win32\EBankWeb\Software\prices.cabO16 - DPF: {3EE838BD-5F59-11D2-A525-00A024651F92} (HandelXControl) -
file://D:\win32\EBankWeb\Software\Trade.CABO16 - DPF: {DF2270CB-FDF3-11D0-81C5-000024222F7F} (EB_UserProfileUI.UserProfileUI) -
http://www.sparlolland.dk/ebankweb/Software/UserProfileUI.CABO16 - DPF: {CDAD63CB-DE65-11D0-BD39-0000242179F2} (EB_LogUI.LogUI) -
file://D:\win32\EBankWeb\Software\LogUI.CABO16 - DPF: {211E87BC-FD16-11D0-81C5-000024222F7F} (EB_BlockAccessUI.BlockAccessUI) -
http://www.sparlolland.dk/ebankweb/Software/BlockAccessUI.CABO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {CE00B72E-986F-11D3-BC3C-E29223000000} (ZLibCls Class) -
http://www.sparlolland.dk/ebankweb/Software/FitZip.cabO16 - DPF: {35A8AF38-5A10-11D3-AEEA-C5867FE56224} (EB_AccountEntriesUI.AccountEntriesUI) -
http://www.sparlolland.dk/ebankweb/Software/AccountEntries.cabO16 - DPF: {7A905C8E-85B4-11D1-9D0C-400000058483} (DNBSecure Control) -
https://www.danskenetbank.dk/netbank/activex/dnbsecure.cabO16 - DPF: {275E2FE0-7486-11D0-89D6-00A0C90C9B67} (MCSiMenuCtl Class) -
https://www.danskenetbank.dk/controls/mcsi/mcsimenu.cabO16 - DPF: {96654D92-BA6F-11D1-A202-400000035268} (Faneblad.FanebladsKontrol) -
https://www.danskenetbank.dk/netbank/activex/dnbtabs.cabO16 - DPF: {F6A56D95-A3A3-11D2-AC26-400000058481} (Danske e-Sec) -
https://netbank.danskebank.dk/netbank/activex/DanskeSikker.cabO16 - DPF: {59B18099-4C1D-4A08-A9F7-ED0554006749} (Select Class) -
http://foto.jubii.dk/components/photoupload.ocxO16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} -
http://dload.ipbill.com/del/loader.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2003080601/housecall.antivirus.com/housecall/xscan53.cabO16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37868.2711111111O16 - DPF: {4BEE3896-4820-48D1-85EA-5A9A9ECD3D95} (OPUCatalog Class) -
http://office.microsoft.com/productupdates/content/opuc.cabMvh Rasmus