Check hijackthis log
Er der en der kan hjælpe med at checke denne log.På forhånd tak.
Logfile of HijackThis v1.97.5
Scan saved at 12:25:05, on 01-03-2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\LEXBCES.EXE
E:\WINDOWS\system32\spoolsv.exe
E:\PROGRA~1\Grisoft\AVG6\avgserv.exe
E:\WINDOWS\system32\slserv.exe
E:\WINDOWS\System32\svchost.exe
E:\Programmer\RealVNC\WinVNC\WinVNC.exe
E:\WINDOWS\Explorer.EXE
E:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
E:\Programmer\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
E:\WINDOWS\System32\hkcmd.exe
E:\WINDOWS\System32\netsvc.exe
E:\Programmer\MSN Messenger\MsnMsgr.Exe
E:\Programmer\TimeCalendar\TC.exe
E:\Programmer\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
E:\Programmer\Microsoft Office\Office\1030\OLFSNT40.EXE
E:\Programmer\WinZip\WZQKPICK.EXE
E:\Programmer\Rainlendar\Rainlendar.exe
E:\Programmer\Outlook Express\msimn.exe
E:\Programmer\Messenger\msmsgs.exe
E:\Documents and Settings\Leif Agergaard\Dokumenter\Hijackdhis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O1 - Hosts: 172.16.128.39 ditas-online
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Programmer\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Configuration Loader] SERVlCES.exe
O4 - HKLM\..\Run: [AVG_CC] E:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [AdaptecDirectCD] "E:\Programmer\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [mode] D:\NBDriver.exe
O4 - HKLM\..\Run: [HotKeysCmds] E:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [WinVNC] "E:\Programmer\RealVNC\WinVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [Client Access Service] "E:\Programmer\IBM\Client Access\cwbsvstr.exe"
O4 - HKLM\..\Run: [Client Access Help Update] "E:\Programmer\IBM\Client Access\cwbinhlp.exe"
O4 - HKLM\..\Run: [Client Access Check Version] "E:\Programmer\IBM\Client Access\cwbckver.exe" LOGIN
O4 - HKLM\..\Run: [Client Access Express Welcome] "E:\Programmer\IBM\Client Access\cwbwlwiz.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [PNSetup] E:\Programmer\PopNot\PNSetup.exe
O4 - HKLM\..\Run: [PopNot] E:\Programmer\PopNot\PopNot.exe auto
O4 - HKLM\..\Run: [Network Services] netsvc.exe
O4 - HKLM\..\Run: [Zone Labs Client] E:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\RunServices: [Configuration Loader] SERVlCES.exe
O4 - HKLM\..\RunServices: [Network Services] netsvc.exe
O4 - HKCU\..\Run: [MsnMsgr] "E:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [TimeCalendar] "E:\Programmer\TimeCalendar\TC.exe" auto
O4 - Startup: MRU-Blaster Silent Clean.lnk = E:\Programmer\MRU-Blaster\mrublaster.exe
O4 - Startup: Rainlendar.lnk = E:\Programmer\Rainlendar\Rainlendar.exe
O4 - Global Startup: Acrobat Assistant.lnk = E:\Programmer\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = E:\Programmer\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec WinFax Starter Port.lnk = E:\Programmer\Microsoft Office\Office\1030\OLFSNT40.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = E:\Programmer\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Allow Site's Pop-&ups - file://E:\Programmer\PopNot\trustsite.script
O8 - Extra context menu item: Always &Kill this Pop-up - file://E:\Programmer\PopNot\blocksite.script
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: E:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02635476-2BB0-11D5-BBF2-A259802CEA3C} (RDAdCtl.RDAd) - http://netdv.dk/raadogdaad/RDAd.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{38D1F8BD-3346-4973-975D-D25A33FA179A}: NameServer = 194.239.134.83
