så blev jeg endelig færdig med at scanne, og her en ny log fra hijackthis
Logfile of HijackThis v1.98.2
Scan saved at 15:37:59, on 23-08-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
D:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Programmer\Norton AntiVirus\navapsvc.exe
D:\Programmer\Norton AntiVirus\AdvTools\NPROTECT.EXE
D:\WINDOWS\System32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe
D:\Programmer\Norton AntiVirus\SAVScan.exe
D:\Programmer\Symantec\LiveUpdate\ALUNOTIFY.EXE
D:\WINDOWS\System32\RunDll32.exe
D:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
D:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
D:\Programmer\QuickTime\qttask.exe
D:\Programmer\iTunes\iTunesHelper.exe
D:\WINDOWS\system32\ntph32.exe
D:\Program Files\Internet Optimizer\optimize.exe
D:\WINDOWS\System32\kzzspl.exe
D:\Programmer\iPod\bin\iPodService.exe
D:\Programmer\BullsEye Network\bin\bargains.exe
D:\WINDOWS\System32\RUNDLL32.EXE
D:\Programmer\MSN Messenger\MsnMsgr.Exe
D:\Documents and Settings\tommy\Application Data\dmwm.exe
D:\PROGRA~1\ICQ\ICQ.exe
D:\WINDOWS\Wininit.ini:cssuc
D:\Programmer\Caere\OmniPagePro90\EREG\REMIND32.EXE
D:\Programmer\TypeItIn\TypeItIn.exe
D:\Documents and Settings\tommy\Skrivebord\hijackthis\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
res://D:\WINDOWS\system32\fiaup.dll/sp.html#29126R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
res://D:\WINDOWS\system32\fiaup.dll/sp.html#29126R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
res://D:\WINDOWS\system32\fiaup.dll/sp.html#29126R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
res://D:\WINDOWS\system32\fiaup.dll/sp.html#29126R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
res://D:\WINDOWS\system32\fiaup.dll/sp.html#29126R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
res://D:\WINDOWS\system32\fiaup.dll/sp.html#29126R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
res://D:\WINDOWS\system32\fiaup.dll/sp.html#29126R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - Default URLSearchHook is missing
F3 - REG:win.ini: run=D:\WINDOWS\System32\services\msxmidi.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2536C943-1153-AD4C-300A-B4B7FF0DA8BA} - D:\WINDOWS\appqq32.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - D:\WINDOWS\Downloaded Program Files\googlenav.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Mirabilis ICQ] D:\PROGRA~1\ICQ\ICQNet.exe
O4 - HKLM\..\Run: [MaxtorOneTouch] D:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [ccApp] "D:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] D:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [PinnacleDriverCheck] D:\WINDOWS\System32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "D:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] D:\Programmer\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [ntph32.exe] D:\WINDOWS\system32\ntph32.exe
O4 - HKLM\..\Run: [Internet Optimizer] "D:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [anvfruedtn] D:\WINDOWS\System32\kzzspl.exe
O4 - HKLM\..\Run: [BullsEye Network] D:\Programmer\BullsEye Network\bin\bargains.exe
O4 - HKLM\..\RunOnce: [cssuc] D:\WINDOWS\Wininit.ini:cssuc
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MsnMsgr] "D:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Seot] D:\Documents and Settings\tommy\Application Data\dmwm.exe
O4 - Startup: reminder-ScanSoft Product Registration.lnk = D:\Programmer\Caere\OmniPagePro90\EREG\REMIND32.EXE
O4 - Startup: TypeItIn.lnk = D:\Programmer\TypeItIn\TypeItIn.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O8 - Extra context menu item: &Google Search -
res://D:\WINDOWS\Downloaded Program Files\googlenav.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links -
res://D:\WINDOWS\Downloaded Program Files\googlenav.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page -
res://D:\WINDOWS\Downloaded Program Files\googlenav.dll/cmcache.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel -
res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000O8 - Extra context menu item: Si&milar Pages -
res://D:\WINDOWS\Downloaded Program Files\googlenav.dll/cmsimilar.html
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - D:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O15 - Trusted Zone: *.05p.com
O15 - Trusted Zone: *.blazefind.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.scoobidoo.com
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.slotch.com
O16 - DPF: v2cab -
http://searchmiracle.com/cab/v2cab.cabO16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
http://public.windupdates.com/get_file.php?bt=ie&p=0c8af29cad1529a0c2f12262efe492244d317f6ab2c86bff7585b7e883263ddf35912dd813dee463c744961d2b31add589650eef4d876c0fc2a2f745d64562:c31e3730b38c174130e1e2729109a237O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) -
http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_regular.cabO16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} (Google Activate) -
http://toolbar.google.com/data/da/big/1.1.62-big/GoogleNav.cabO16 - DPF: {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} (brdg Class) -
http://static.flingstone.com/cab/2000XP/CDTInc/bridge.cabO16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) -
http://www.mt-download.com/MediaTicketsInstaller.cabO18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - D:\WINDOWS\msopt.dll (file missing)
min startside har nu ændret sig til noget andet, der står godt nok about:blank i adressebaren, men der kommer en side frem, og en enkelt popup.
Håber du/i kan se noget ud af denne log så vi kan få rodet bod på det.
Tak