HiJackThis log hjælp
Hej min computer er fyldt med spyware som ikke lige er til at fjerne med diverse programmer..Logfile of HijackThis v1.97.7
Scan saved at 21:39:58, on 07-07-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\appta32.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\ntla32.exe
C:\Program Files\Winamp\winampa.exe
C:\program files\steam\steam.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Eyeball\Eyeball Chat\EyeballChat.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\download\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\dkbhc.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://dkbhc.dll/index.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://dkbhc.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\dkbhc.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://dkbhc.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\dkbhc.dll/sp.html#37049
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {C207C0FE-A804-D46C-81D2-A2A37FC7ED6B} - C:\WINDOWS\system32\ntjq32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1601.0\da\msntb.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [ntla32.exe] C:\WINDOWS\ntla32.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Eyeball Chat] "C:\Program Files\Eyeball\Eyeball Chat\EyeballChat.exe" -min
O4 - HKLM\..\RunOnce: [crav32.exe] C:\WINDOWS\system32\crav32.exe
O4 - HKLM\..\RunOnce: [appta32.exe] C:\WINDOWS\system32\appta32.exe
O4 - HKLM\..\RunOnce: [syswa32.exe] C:\WINDOWS\syswa32.exe
O4 - HKLM\..\RunOnce: [atlqb32.exe] C:\WINDOWS\atlqb32.exe
O4 - HKLM\..\RunOnce: [ntje.exe] C:\WINDOWS\ntje.exe
O4 - HKLM\..\RunOnce: [d3jv32.exe] C:\WINDOWS\system32\d3jv32.exe
O4 - HKLM\..\RunOnce: [apibv.exe] C:\WINDOWS\system32\apibv.exe
O4 - HKLM\..\RunOnce: [sdkqf.exe] C:\WINDOWS\system32\sdkqf.exe
O4 - HKLM\..\RunOnce: [d3cd32.exe] C:\WINDOWS\d3cd32.exe
O4 - HKLM\..\RunOnce: [sdkky32.exe] C:\WINDOWS\system32\sdkky32.exe
O4 - HKLM\..\RunOnce: [ipqj.exe] C:\WINDOWS\ipqj.exe
O4 - HKLM\..\RunOnce: [syshh.exe] C:\WINDOWS\system32\syshh.exe
O4 - HKLM\..\RunOnce: [mscj32.exe] C:\WINDOWS\mscj32.exe
O4 - HKLM\..\RunOnce: [sdkku.exe] C:\WINDOWS\system32\sdkku.exe
O4 - HKLM\..\RunOnce: [d3ya32.exe] C:\WINDOWS\d3ya32.exe
O4 - HKLM\..\RunOnce: [addiz.exe] C:\WINDOWS\system32\addiz.exe
O4 - HKLM\..\RunOnce: [sysws.exe] C:\WINDOWS\system32\sysws.exe
O4 - HKLM\..\RunOnce: [winga.exe] C:\WINDOWS\system32\winga.exe
O4 - HKLM\..\RunOnce: [javasq.exe] C:\WINDOWS\javasq.exe
O4 - HKLM\..\RunOnce: [sdkad32.exe] C:\WINDOWS\sdkad32.exe
O4 - HKLM\..\RunOnce: [apppb32.exe] C:\WINDOWS\system32\apppb32.exe
O4 - HKLM\..\RunOnce: [crez.exe] C:\WINDOWS\crez.exe
O4 - HKLM\..\RunOnce: [wintl.exe] C:\WINDOWS\wintl.exe
O4 - HKLM\..\RunOnce: [ipip.exe] C:\WINDOWS\ipip.exe
O4 - HKLM\..\RunOnce: [netwz.exe] C:\WINDOWS\netwz.exe
O4 - HKLM\..\RunOnce: [apisp32.exe] C:\WINDOWS\system32\apisp32.exe
O4 - HKLM\..\RunOnce: [apicb32.exe] C:\WINDOWS\system32\apicb32.exe
O4 - HKLM\..\RunOnce: [crhu32.exe] C:\WINDOWS\crhu32.exe
O4 - HKLM\..\RunOnce: [apiod32.exe] C:\WINDOWS\apiod32.exe
O4 - HKLM\..\RunOnce: [winel32.exe] C:\WINDOWS\system32\winel32.exe
O4 - HKLM\..\RunOnce: [javagq.exe] C:\WINDOWS\javagq.exe
O4 - HKLM\..\RunOnce: [syssb.exe] C:\WINDOWS\syssb.exe
O4 - HKLM\..\RunOnce: [msuv.exe] C:\WINDOWS\system32\msuv.exe
O4 - HKLM\..\RunOnce: [appqj32.exe] C:\WINDOWS\system32\appqj32.exe
O4 - HKLM\..\RunOnce: [addyg.exe] C:\WINDOWS\system32\addyg.exe
O4 - HKLM\..\RunOnce: [netbw32.exe] C:\WINDOWS\netbw32.exe
O4 - HKLM\..\RunOnce: [syscf.exe] C:\WINDOWS\system32\syscf.exe
O4 - HKLM\..\RunOnce: [appcs.exe] C:\WINDOWS\appcs.exe
O4 - HKLM\..\RunOnce: [atlxu32.exe] C:\WINDOWS\atlxu32.exe
O4 - HKLM\..\RunOnce: [javarl.exe] C:\WINDOWS\javarl.exe
O4 - HKLM\..\RunOnce: [netlu32.exe] C:\WINDOWS\system32\netlu32.exe
O4 - HKLM\..\RunOnce: [addkr32.exe] C:\WINDOWS\addkr32.exe
O4 - HKLM\..\RunOnce: [ntap32.exe] C:\WINDOWS\system32\ntap32.exe
O4 - HKLM\..\RunOnce: [mfcdi.exe] C:\WINDOWS\mfcdi.exe
O4 - HKLM\..\RunOnce: [ipzi.exe] C:\WINDOWS\system32\ipzi.exe
O4 - HKLM\..\RunOnce: [sysas.exe] C:\WINDOWS\sysas.exe
O4 - HKLM\..\RunOnce: [msfe.exe] C:\WINDOWS\msfe.exe
O9 - Extra button: Research (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {53B3ABEA-4445-44D9-A01E-088144CAABD9} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/FileSharing/da/filesharingctrl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab27571.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38030.1388541667
hvad skal jeg fixe .. ?
MvH Anders Rohde
