Her er den.
Logfile of HijackThis v1.98.2
Scan saved at 20:12:23, on 14-12-2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\NORMAN\NVC\BIN\ZANDA.EXE
C:\NORMAN\NVC\BIN\CCLAW.EXE
C:\NORMAN\NVC\BIN\NVCSCHED.EXE
C:\NORMAN\NVC\BIN\NJEEVES.EXE
C:\NORMAN\NVC\BIN\NIP.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\PCTVOICE.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\NORMAN\NVC\BIN\ZLH.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\SYSTEM\MSCDEX32.EXE
C:\WINDOWS\SYSTEM\TWINK64.EXE
C:\NORMAN\NVC\BIN\NYMSE.EXE
C:\PROGRAMMER\MESSENGER\MSMSGS.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\APPLICATION DATA\TNHM.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\E_SICN03.EXE
C:\WINDOWS\SYSTEM\WINDOS.EXE
C:\PROGRAMMER\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\WBEM\WINMGMT.EXE
C:\WINDOWS\SYSTEM\QUAAE.EXE
C:\SPION6\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
file://C:\WINDOWS\TEMP\sp.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
file://C:\WINDOWS\TEMP\sp.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.tdconline.dk/startR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
file://C:\WINDOWS\TEMP\sp.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
file://C:\WINDOWS\TEMP\sp.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
file://C:\WINDOWS\TEMP\sp.htmlR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
file://C:\WINDOWS\TEMP\sp.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O1 - Hosts: 66.180.173.39
www.google.aeO1 - Hosts: 66.180.173.39
www.google.amO1 - Hosts: 66.180.173.39
www.google.asO1 - Hosts: 66.180.173.39
www.google.atO1 - Hosts: 66.180.173.39
www.google.azO1 - Hosts: 66.180.173.39
www.google.beO1 - Hosts: 66.180.173.39
www.google.biO1 - Hosts: 66.180.173.39
www.google.caO1 - Hosts: 66.180.173.39
www.google.cdO1 - Hosts: 66.180.173.39
www.google.cgO1 - Hosts: 66.180.173.39
www.google.chO1 - Hosts: 66.180.173.39
www.google.ciO1 - Hosts: 66.180.173.39
www.google.clO1 - Hosts: 66.180.173.39
www.google.co.crO1 - Hosts: 66.180.173.39
www.google.co.huO1 - Hosts: 66.180.173.39
www.google.co.ilO1 - Hosts: 66.180.173.39
www.google.co.inO1 - Hosts: 66.180.173.39
www.google.co.jeO1 - Hosts: 66.180.173.39
www.google.co.jpO1 - Hosts: 66.180.173.39
www.google.co.keO1 - Hosts: 66.180.173.39
www.google.co.krO1 - Hosts: 66.180.173.39
www.google.co.lsO1 - Hosts: 66.180.173.39
www.google.co.nzO1 - Hosts: 66.180.173.39
www.google.co.thO1 - Hosts: 66.180.173.39
www.google.co.ugO1 - Hosts: 66.180.173.39
www.google.co.ukO1 - Hosts: 66.180.173.39
www.google.co.veO1 - Hosts: 66.180.173.39
www.google.deO1 - Hosts: 66.180.173.39
www.google.djO1 - Hosts: 66.180.173.39
www.google.dkO1 - Hosts: 66.180.173.39
www.google.esO1 - Hosts: 66.180.173.39
www.google.fiO1 - Hosts: 66.180.173.39
www.google.fmO1 - Hosts: 66.180.173.39
www.google.frO1 - Hosts: 66.180.173.39
www.google.ggO1 - Hosts: 66.180.173.39
www.google.glO1 - Hosts: 66.180.173.39
www.google.gmO1 - Hosts: 66.180.173.39
www.google.hnO1 - Hosts: 66.180.173.39
www.google.ieO1 - Hosts: 66.180.173.39
www.google.itO1 - Hosts: 66.180.173.39
www.google.kzO1 - Hosts: 66.180.173.39
www.google.liO1 - Hosts: 66.180.173.39
www.google.ltO1 - Hosts: 66.180.173.39
www.google.luO1 - Hosts: 66.180.173.39
www.google.lvO1 - Hosts: 66.180.173.39
www.google.mnO1 - Hosts: 66.180.173.39
www.google.msO1 - Hosts: 66.180.173.39
www.google.muO1 - Hosts: 66.180.173.39
www.google.mwO1 - Hosts: 66.180.173.39
www.google.nlO1 - Hosts: 66.180.173.39
www.google.noO1 - Hosts: 66.180.173.39
www.google.off.aiO1 - Hosts: 66.180.173.39
www.google.plO1 - Hosts: 66.180.173.39
www.google.pnO1 - Hosts: 66.180.173.39
www.google.ptO1 - Hosts: 66.180.173.39
www.google.roO1 - Hosts: 66.180.173.39
www.google.ruO1 - Hosts: 66.180.173.39
www.google.rwO1 - Hosts: 66.180.173.39
www.google.seO1 - Hosts: 66.180.173.39
www.google.shO1 - Hosts: 66.180.173.39
www.google.skO1 - Hosts: 66.180.173.39
www.google.smO1 - Hosts: 66.180.173.39
www.google.tdO1 - Hosts: 66.180.173.39
www.google.tmO1 - Hosts: 66.180.173.39
www.google.ttO1 - Hosts: 66.180.173.39
www.google.uzO1 - Hosts: 66.180.173.39
www.google.vgO1 - Hosts: 66.180.173.39 google.ae
O1 - Hosts: 66.180.173.39 google.am
O1 - Hosts: 66.180.173.39 google.as
O1 - Hosts: 66.180.173.39 google.at
O1 - Hosts: 66.180.173.39 google.az
O1 - Hosts: 66.180.173.39 google.be
O1 - Hosts: 66.180.173.39 google.bi
O1 - Hosts: 66.180.173.39 google.ca
O1 - Hosts: 66.180.173.39 google.cd
O1 - Hosts: 66.180.173.39 google.cg
O1 - Hosts: 66.180.173.39 google.ch
O1 - Hosts: 66.180.173.39 google.ci
O1 - Hosts: 66.180.173.39 google.cl
O1 - Hosts: 66.180.173.39 google.co.cr
O1 - Hosts: 66.180.173.39 google.co.hu
O1 - Hosts: 66.180.173.39 google.co.il
O1 - Hosts: 66.180.173.39 google.co.in
O1 - Hosts: 66.180.173.39 google.co.je
O1 - Hosts: 66.180.173.39 google.co.jp
O1 - Hosts: 66.180.173.39 google.co.ke
O1 - Hosts: 66.180.173.39 google.co.kr
O1 - Hosts: 66.180.173.39 google.co.ls
O1 - Hosts: 66.180.173.39 google.co.nz
O1 - Hosts: 66.180.173.39 google.co.th
O1 - Hosts: 66.180.173.39 google.co.ug
O1 - Hosts: 66.180.173.39 google.co.uk
O1 - Hosts: 66.180.173.39 google.co.ve
O1 - Hosts: 66.180.173.39 google.de
O1 - Hosts: 66.180.173.39 google.dj
O1 - Hosts: 66.180.173.39 google.dk
O1 - Hosts: 66.180.173.39 google.es
O1 - Hosts: 66.180.173.39 google.fi
O1 - Hosts: 66.180.173.39 google.fm
O1 - Hosts: 66.180.173.39 google.fr
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMMER\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {B03BABDC-4693-4312-8961-D3367A19E32E} - C:\WINDOWS\SYSTEM\KPJEIBA.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Spion4\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {B6290312-9FFB-ED09-89DE-E2ABA9710795} - C:\WINDOWS\SYSTEM\VBV.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [nVidiaTV-OUT] Regedit /S C:\Windows\tvout.reg
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PCTVOICE] pctvoice.exe
O4 - HKLM\..\Run: [Startup] C:\Amitech\Startup /START
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [Norton Antivirus AV] C:\WINDOWS\FVProtect.exe
O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\NVC\BIN\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [mscdex32] C:\WINDOWS\SYSTEM\mscdex32.exe
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\SYSTEM\twink64.exe internat.dll,LoadKeyboardProfile
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [Norman ZANDA] C:\NORMAN\NVC\BIN\ZANDA.EXE /LOAD
O4 - HKCU\..\Run: [MSMSGS] C:\PROGRA~1\MESSEN~1\msmsgs.exe /background
O4 - HKCU\..\Run: [Aurw] C:\WINDOWS\Application Data\tnhm.exe
O4 - HKCU\..\Run: [Dnk] C:\WINDOWS\SYSTEM\quaae.exe
O4 - Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\SYSTEM\E_SRCV03.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.tdconline.dk/start
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.blazefind.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.topconverting.com
O15 - Trusted Zone: *.crazywinnings.com
O15 - Trusted Zone: *.ysbweb.com
O15 - Trusted Zone: *.slotchbar.com
O16 - DPF: {11111111-1111-1111-1111-111111111157} - ms-its:mhtml:
file://c:\\nosuch.mht!http://lacroix.nm.ru/index.chm::/mscdex32.exeO16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
http://public.windupdates.com/get_file.php?bt=ie&p=8e3d0580d86447bf72f6c0621194141f1f77362faef9a2aea0f644ad8014481651320dc2dc54022539ddf37b4e7037625ed4d81d4470b7798bdf896f27cdc60a:1bd74c35a1c6f6116c9a2b8b9ea7b955O16 - DPF: {7E166582-590E-2BC0-E64B-6D9232C4D5AA} -
http://63.219.178.91/1/rdgDK990.exeO16 - DPF: {9E98E84C-79E1-49C3-82EB-798FCD552EFB} (VacPro.internazionale_ver4) -
http://www.globalphon.com/dialer/internazionale_ver4.CABO16 - DPF: {11311111-1111-1111-1111-111111111157} -
file://C:\Recycled\Q330995.exeO16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:
file://c:\nosuch.mht!http://2awm.com/pop/chm/markavsp.chm::/on-line.exeO16 - DPF: {52FFDAF5-BA97-0709-F809-01BD4C19D31A} -
http://63.219.178.91/1/rdgDK990.exeO16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) -
http://www.mt-download.com/MediaTicketsInstaller.cab?refid=3548O18 - Filter: text/html - {5BCAF3C0-E15B-489A-8C95-042F17BB1C23} - C:\WINDOWS\SYSTEM\KPJEIBA.DLL
O18 - Filter: text/plain - {5BCAF3C0-E15B-489A-8C95-042F17BB1C23} - C:\WINDOWS\SYSTEM\KPJEIBA.DLL