En rigtig snavset hijackthis fil
HejEr der en der kan hjælpe ?
Logfile of HijackThis v1.98.2
Scan saved at 19:47:02, on 12-10-2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\Programmer\Norton Internet Security\NISUM.EXE
C:\Programmer\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Programmer\Norton Internet Security\SymProxySvc.exe
C:\Programmer\Norton Internet Security\NISSERV.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\inetdata\services.exe
C:\Programmer\Norton Internet Security\IAMAPP.EXE
C:\WINDOWS\System32\LzioMediaUpdater.exe
C:\WINDOWS\System32\bdsmsbg.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\lejvwncs.exe
C:\WINDOWS\System32\windllsys32.exe
C:\WINDOWS\System32\dllcache\IExplore.exe
C:\WINDOWS\System32\dllcache\IExplore.exe
C:\WINDOWS\System32\dllcache\IExplore.exe
C:\WINDOWS\System32\dllcache\IExplore.exe
C:\WINDOWS\System32\dllcache\IExplore.exe
C:\WINDOWS\System32\dllcache\IExplore.exe
C:\WINDOWS\System32\dllcache\IExplore.exe
C:\WINDOWS\System32\dllcache\IExplore.exe
C:\Documents and Settings\Ib W Hansen\Skrivebord\Sikkerhed\hijack\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.richfind.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.richfind.com/ie/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.searchportal.info/10039/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.richfind.com/ie/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.richfind.com/ie/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.richfind.com/home/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.richfind.com/ie/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.richfind.com/ie/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: Richfind - {E99C5605-1DFD-41BA-90BB-B8B786C18BD5} - C:\WINDOWS\System32\Q29531250.dll
F3 - REG:win.ini: run=C:\WINDOWS\inetdata\services.exe
O2 - BHO: Richfind - {26713CE3-9E87-405E-A9C0-F1BC18ADC721} - C:\WINDOWS\System32\Q29531250.dll
O2 - BHO: IEHelper - {33e68829-36d5-4e64-a67a-77f0283d3ea6} - C:\WINDOWS\System32\Q12691046.dll
O2 - BHO: Richfind - {45D375DE-A961-4C18-B322-A44B34BA4344} - C:\WINDOWS\System32\Q29531250.dll
O2 - BHO: HBO Class - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - C:\WINDOWS\inetdata\1.02.04.dll
O2 - BHO: Richfind - {6B3E71F0-2C84-4614-B3E5-2CE398B47D11} - C:\WINDOWS\System32\Q1281062.dll
O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B136188F5DEB} - C:\WINDOWS\questmod.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\FÆLLES~1\WinTools\WToolsB.dll (file missing)
O2 - BHO: Richfind - {CC7BD169-74B1-4345-BF22-A53D45B6655B} - C:\WINDOWS\System32\Q29531250.dll
O2 - BHO: (no name) - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {E5A2678F-DA83-4D2E-BA85-6236E90098FA} - (no file)
O3 - Toolbar: Richfind - {3478254F-64D1-4C42-9758-D08DAD34D646} - C:\WINDOWS\System32\Q29531250.dll
O3 - Toolbar: Richfind - {4219F871-48E3-4042-994F-9F75A5C56869} - C:\WINDOWS\System32\Q1281062.dll
O3 - Toolbar: Richfind - {7648A093-3884-4649-995D-2F62D1FF4CD0} - C:\WINDOWS\System32\Q29531250.dll
O3 - Toolbar: Richfind - {A75B7A4B-C760-425C-AEB0-DB8B5D4296F7} - C:\WINDOWS\System32\Q29531250.dll
O3 - Toolbar: (no name) - {339BB23F-A864-48C0-A59F-29EA915965EC} - (no file)
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Programmer\Fælles filer\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [iamapp] C:\Programmer\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [LzioMediaUpdater] C:\WINDOWS\System32\LzioMediaUpdater.exe
O4 - HKLM\..\Run: [hpsysconf1] C:\WINDOWS\System32\bdsmsbg.exe
O4 - HKLM\..\Run: [WebRebates0] "C:\Programmer\Web_Rebates\WebRebates0.exe"
O4 - HKLM\..\Run: [TBPS] C:\Programmer\Toolbar\TBPS.exe
O4 - HKLM\..\Run: [towfezv] C:\WINDOWS\Lbczxs.exe
O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inetdata\services.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Dawzxzy] C:\WINDOWS\System32\lejvwncs.exe
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [windllsys32.exe] C:\WINDOWS\System32\windllsys32.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inetdata\services.exe
O9 - Extra button: Richfind - {3478254F-64D1-4C42-9758-D08DAD34D646} - C:\WINDOWS\System32\Q29531250.dll
O9 - Extra button: Richfind - {4219F871-48E3-4042-994F-9F75A5C56869} - C:\WINDOWS\System32\Q1281062.dll
O9 - Extra button: Richfind - {7648A093-3884-4649-995D-2F62D1FF4CD0} - C:\WINDOWS\System32\Q29531250.dll
O9 - Extra button: Richfind - {A75B7A4B-C760-425C-AEB0-DB8B5D4296F7} - C:\WINDOWS\System32\Q29531250.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downloadv3.com/binaries/IA/nethv32_EN_XP.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.bgbank.dk/html/activex/e-Safekey/BG/e-Safekey.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{AF89EB2D-2F16-4AFF-AF4E-BF7AB23626C8}: NameServer = 194.239.134.83
O18 - Filter: text/html - {091A8F1B-2721-4B21-A28E-6E40AF7C0CF0} - C:\WINDOWS\System32\Q29531250.dll
O18 - Filter: text/plain - {091A8F1B-2721-4B21-A28E-6E40AF7C0CF0} - C:\WINDOWS\System32\Q29531250.dll
