ekspert søges til gennemgang af Hijackthis log
min log ser sådan her ud...Logfile of HijackThis v1.98.2
Scan saved at 17:16:37, on 01-12-2004
Platform: <a href="http://www.ntsearch.com/search.php?q=Windows&v=56">Windows</a> XP (WinNT 5.01.2600)
MSIE: <a href="http://www.ntsearch.com/search.php?q=Internet&v=56">Internet</a> Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmer\Norton <a href="http://www.ntsearch.com/search.php?q=Personal&v=56">Personal</a> Firewall\NISUM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Norton <a href="http://www.ntsearch.com/search.php?q=Personal&v=56">Personal</a> Firewall\SymProxySvc.exe
C:\Programmer\Norton <a href="http://www.ntsearch.com/search.php?q=Personal&v=56">Personal</a> Firewall\NISSERV.EXE
C:\WINDOWS\System32\mslaugh.exe
C:\WINDOWS\essspk.exe
C:\Programmer\Norton <a href="http://www.ntsearch.com/search.php?q=Personal&v=56">Personal</a> Firewall\IAMAPP.EXE
C:\documents and settings\birgit pedersen\lokale indstillinger\temp\fsg_tmp\ginst_001_1234_4201.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\sp.exe
C:\Programmer\Messenger\msmsgs.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\WPSC3PSW.EXE
C:\Programmer\Internet Explorer\iexplore.exe
E:\Genstart\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ni.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O1 - Hosts: 69.20.16.183 <a href="http://www.ntsearch.com/search.php?q=auto&v=56">auto</a>.search.msn.com
O1 - Hosts: 69.20.16.183 <a href="http://www.ntsearch.com/search.php?q=search&v=56">search</a>.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WpsRePsw] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\WpsRePsw.EXE
O4 - HKLM\..\Run: [Windows Automation] mslaugh.exe
O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe
O4 - HKLM\..\Run: [Belt] C:\WINDOWS\Belt.exe
O4 - HKLM\..\Run: [iamapp] C:\Programmer\Norton <a href="http://www.ntsearch.com/search.php?q=Personal&v=56">Personal</a> Firewall\IAMAPP.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Trickler] "c:\documents and settings\birgit pedersen\lokale indstillinger\temp\fsg_tmp\ginst_001_1234_4201.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [sp] C:\sp.exe
O4 - Global Startup: Microsoft <a href="http://www.ntsearch.com/search.php?q=Office&v=56">Office</a>.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&ksporter til Microsoft <a href="http://www.ntsearch.com/search.php?q=Excel&v=56">Excel</a> - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: <a href="http://www.ntsearch.com/search.php?q=Windows&v=56">Windows</a> Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O16 - DPF: {10000000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!http://www.free32.com/POP.CHM::/sp.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.6.cab
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) - http://static.topconverting.com/activex/loader2.ocx
O16 - DPF: {E2F2B9D0-96B9-4B25-B90C-636ECB207D18} - http://www.whenusearch.com/WUInstSEWC.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C5AF445A-2E9F-41C4-B2A3-A4068D6CB133}: NameServer = 195.82.195.101 129.142.7.101
er der noget at komme efter ? IE siger tit at siden ikke kan besøges og går væk, men klikker man tilbage til den et par gange i træk kan den god indlæse det...
udover det er min IE begyndt at lave ord til links i tekster på internettet, linket henleder så til www.ntserach.com
håber i kan hjælpe mig...
