Er der én der er rigtig sød at kigge på denn Hijackthis logfile?
Jeg vil være evigt taknemmelig, hvis en eller anden der har mere forstand på det her end jeg har vil kigge på den her hijackthis logfil? Jeg tør ikke selv rode med den.Jeg kan se, at det er det I beder folk om at gøre, når de har uvelkomne ting, der pupper op. Jeg får irriterende shortcuts på skrivebordet til diverse internetsider. Jeg har nu installeret både: Spywareblaster, Spybot Search & Destroy, SpywareGuard og Ad-aware. Men nogle af dem er først installeret efter problemerne sneg sig ind og de kan ikke fange det her åbenbart. Vil en eller anden være rigtig sød at hjælpe mig?
Her kommer den: Den er godt nok lang. Håber en har tid. :-)
Logfile of HijackThis v1.99.0
Scan saved at 22:21:07, on 06-01-05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\LVCOMS.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\INTERNAT.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\MSWHEEL.EXE
C:\PROGRAMMER\NORTON ANTIVIRUS\NAVAPW32.EXE
C:\PROGRAMMER\NORTON ANTIVIRUS\POPROXY.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\PROGRAMMER\COMMON FILES\SEARCHUPGRADER\SEARCHUPGRADER.EXE
C:\PROGRAMMER\ADAPTEC\EASY CD CREATOR 4\CREATECD\CREATECD.EXE
C:\WINDOWS\RunDLL.exe
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAMMER\SPYWAREGUARD\SGMAIN.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAMMER\SPYWAREGUARD\SGBHP.EXE
C:\PROGRAMMER\OUTLOOK EXPRESS\MSIMN.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\LMU.EXE
C:\PROGRAMMER\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.alltheweb.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = Cache-aalb.stofanet.dk:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)
O2 - BHO: YBIOCtrl Class - {004A5840-FF59-11d2-B50D-0090271D3FD4} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMMER\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {021BB032-80A8-4FB6-B3D5-CF27B1553B95} - C:\WINDOWS\MSLAGENT\4B_1,0,1,0_MSLAGENT.DLL (file missing)
O2 - BHO: Fizzlebar.clsFwBar - {9056A11F-5EA6-4A67-BDE9-8D3C7C453DAC} - C:\SYSFWB\6261539511\IEFWBAR.DLL
O2 - BHO: NavErrRedir Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
O2 - BHO: InstaFinder - {4E7BD74F-2B8D-469E-DCF7-F96DA086B434} - C:\WINDOWS\DOWNLO~1\INSTAFIN.DLL
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\PROGRAMMER\SPYWAREGUARD\DLPROTECT.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O2 - BHO: ohb - {4D568F0F-8AC9-40AB-88B7-415134C78777} - C:\WINDOWS\SYSTEM\WINB2S32.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Begin2Search.com Bar - {52FE5233-367C-4EFB-BDD7-0BE4D212C107} - C:\WINDOWS\SYSTEM\WINB2S32.DLL
O4 - HKLM\..\Run: [Skan registreringsdatabase] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [Job-oversigt] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [POINTER] C:\PROGRA~1\MICROS~1\point32.exe
O4 - HKLM\..\Run: [LVComs] C:\WINDOWS\SYSTEM\LVComS.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [Sexy_dk] C:\Program Files\GMSoft\Dialers\Sexy_dk\Sexy_dk.exe /dontdial
O4 - HKLM\..\Run: [Microsoft Tray] C:\PROGRAMMER\KAZAA\MY SHARED FOLDER\SIMS NO CD(ALL VERSIONS).EXE
O4 - HKLM\..\Run: [BullGuard Virus Shield] C:\Programmer\BullGuard\\vsserv.exe
O4 - HKLM\..\Run: [BDMCon] C:\Programmer\BullGuard\\bdmcon.exe
O4 - HKLM\..\Run: [BGNewsAgent] C:\PROGRAMMER\BULLGUARD\bgnewsag.exe
O4 - HKLM\..\Run: [NAV DefAlert] C:\PROGRA~1\NORTON~1\DEFALERT.EXE
O4 - HKLM\..\Run: [Norton Auto-Protect] C:\PROGRA~1\NORTON~1\NAVAPW32.EXE /LOADQUIET
O4 - HKLM\..\Run: [Norton eMail Protect] C:\Programmer\Norton AntiVirus\POPROXY.EXE
O4 - HKLM\..\Run: [ICQ Lite] C:\Programmer\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [SearchUpgrader] C:\Programmer\Common files\SearchUpgrader\SearchUpgrader.exe
O4 - HKLM\..\Run: [Hot_Tarts_mc] C:\Program Files\Video1\Dialers\Hot_Tarts_mc\Hot_Tarts_mc.exe /dontdial
O4 - HKLM\..\Run: [CreateCD] C:\PROGRA~1\ADAPTEC\EASYCD~1\CREATECD\CREATECD.EXE -r
O4 - HKLM\..\Run: [lmu] C:\WINDOWS\LMU.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [BullGuard Scan Server] C:\Programmer\Fælles filer\BullGuard\BullGuard Scan Server\\bdss.exe
O4 - HKLM\..\RunServices: [BullGuard Communicator] C:\Programmer\Fælles filer\BullGuard\BullGuard Communicator\\xcommsvr.exe
O4 - HKLM\..\RunServices: [BullGuard Live! Init] C:\Programmer\BullGuard\\bdinit.exe
O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Programmer\Fælles filer\Symantec Shared\Script Blocking\SBServ.exe" -reg
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\YAHOO!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [Instant Access] rundll32.exe p2esocks_1015.dll,InstantAccess
O4 - Startup: Corel Family and Friends Reminders.LNK = C:\Programmer\Corel\Print House Magic\cffrem.exe
O4 - Startup: SpywareGuard.lnk = C:\Programmer\SpywareGuard\sgmain.exe
O8 - Extra context menu item: Download with GetRight - C:\Programmer\GetRight\GRdownload.htm
O8 - Extra context menu item: Open with GetRight Browser - C:\Programmer\GetRight\GRbrowse.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAMMER\YAHOO!\MESSENGER\YPAGER.EXE (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRAMMER\YAHOO!\MESSENGER\YPAGER.EXE (file missing)
O9 - Extra button: Descargas - {AF0828BC-CB46-4C8D-95B6-8A7C4988F9FF} - c:\eurokazaa\local.htm (file missing)
O9 - Extra button: ICQ 4.0 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programmer\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programmer\ICQLite\ICQLite.exe (file missing)
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O16 - DPF: {25F5AA75-B6D8-11CF-B348-00002422759D} (DataPoolSV10.CDataPool) - file://D:\win32\EBankWeb\Software\dpserver.CAB
O16 - DPF: {36C72320-EDFC-11D0-89DB-02AA3C04DD07} (EBLanguageSelector.LanguageSelector) - file://D:\win32\EBankWeb\Software\EBLanguageSelector.CAB
O16 - DPF: {CF48D854-EC79-11D0-9EDC-00A0245DA6F6} (OfcCtl Class) - http://195.184.35.73/hb/ebankweb/Software/Ofx.cab
O16 - DPF: {47FCD744-28E2-11D1-A13A-000024601F43} (EB_CommonUtilities.Common1) - http://195.184.35.73/hb/ebankweb/Software/EB_CommonUtilities.CAB
O16 - DPF: {B7A2E681-3B00-11D1-81C5-000024222F7F} (EB_Secure.EBSecure) - file://D:\win32\EBankWeb\Software\EB_Secure.CAB
O16 - DPF: {0B4A9EB4-332F-11D1-BEA2-00A0245DA6F8} (FitCrypto Class) - file://D:\win32\EBankWeb\Software\FitSecure.cab
O16 - DPF: {E5CAA475-5F45-11D1-8064-A01A01C10000} (EBPrintSupport.HtmlTemplate) - file://D:\win32\EBankWeb\Software\EBPrintSupport.CAB
O16 - DPF: {7C2A1E81-6A69-11D1-8064-A01A01C10000} (EB_Alerter.AlerterBO) - file://D:\win32\EBankWeb\Software\AlerterBO.CAB
O16 - DPF: {131220DA-FF52-11D0-8445-000024202088} (EB_LogonUI.LogonUI) - http://195.184.35.73/hb/ebankweb/Software/LogonUI.CAB
O16 - DPF: {61E5A398-FE97-11D0-81C5-000024222F7F} (EB_ExportImportUI.ExportImportUI) - file://D:\win32\EBankWeb\Software\ExportImportUI.CAB
O16 - DPF: {FBF3B698-FC3A-11D0-8445-000024202088} (EB_RegistrationUI.RegistrationUI) - http://195.184.35.73/hb/ebankweb/Software/RegistrationUI.CAB
O16 - DPF: {1847C1C1-7274-11D2-A47D-00104B5B4D54} (EB_AgreementUI.AgreementUI) - file://D:\win32\EBankWeb\Software\AgreementUI.CAB
O16 - DPF: {EBC90C1A-FDDF-11D0-8445-000024202088} (EB_BalanceUI.BalanceUI) - http://195.184.35.73/hb/ebankweb/Software/BalanceUI.CAB
O16 - DPF: {86D3FB35-2862-11D1-8445-000024202088} (EB_CalculatorBO.CalculatorBO) - file://D:\win32\EBankWeb\Software\CalculatorBO.CAB
O16 - DPF: {1ED7CC80-F877-11D0-BD39-0000242179F2} (EB_ActivityUI.ActivityUI) - file://D:\win32\EBankWeb\Software\ActivityUI.CAB
O16 - DPF: {71D082EF-E0E4-11D0-BD39-0000242179F2} (EB_LastStatementUI.LastStatementUI) - file://D:\win32\EBankWeb\Software\LastStatementUI.CAB
O16 - DPF: {DAB01827-98C2-11D1-AC92-000024601F43} (EB_TransferUI.TransferUI) - http://195.184.35.73/hb/ebankweb/Software/EB_TransferUI.CAB
O16 - DPF: {DD8B04E4-2B82-11D1-A13C-000024601F43} (EB_BillUI.BillUI) - http://195.184.35.73/hb/ebankweb/Software/BillUI.CAB
O16 - DPF: {4DA8C674-6CCC-11D2-81C6-000024222F7F} (EB_BSRegisterUI.BSRegisterUI) - http://195.184.35.73/hb/ebankweb/software/BSRegisterUI.CAB
O16 - DPF: {DB92CCE8-7D33-11D2-81C6-000024222F7F} (EB_BSPaymentsUI.BSPaymentsUI) - file://D:\win32\EBankWeb\Software\BSPaymentsUI.CAB
O16 - DPF: {AA0F7D96-17D8-11D1-A12C-000024601F43} (EB_CreditRegisterUI.CreditRegisterUI) - file://D:\win32\EBankWeb\Software\CreditRegisterUI.CAB
O16 - DPF: {4C4C9342-7224-11D1-8D87-000024601F43} (EB_FuturePaymentsUI.FuturePaymentsUI) - file://D:\win32\EBankWeb\Software\EB_FuturePaymentsUI.CAB
O16 - DPF: {DA90D5FC-F2E2-11D0-BD39-0000242179F2} (EB_OrderUI.OrderUI) - file://D:\win32\EBankWeb\Software\OrderUI.CAB
O16 - DPF: {3C4C2F07-5F6F-11D2-A525-00A024651F92} (EB_System.CData) - file://D:\win32\EBankWeb\Software\BDRTL.CAB
O16 - DPF: {BC94E7E2-545E-11D2-8279-E3236A1BE601} (FTOHomeBankObject) - file://D:\win32\EBankWeb\Software\HBFTO.CAB
O16 - DPF: {41335962-52DD-11D2-8279-9CD28522D17E} (TFTRObject) - file://D:\win32\EBankWeb\Software\FTR.CAB
O16 - DPF: {480F8542-52E9-11D2-8279-E12E0803FB4E} (boDepotObject) - file://D:\win32\EBankWeb\Software\SBBO.CAB
O16 - DPF: {3EE838A3-5F59-11D2-A525-00A024651F92} (DepotovXControl) - file://D:\win32\EBankWeb\Software\Custodies.cab
O16 - DPF: {EF65E163-5EC7-11D2-A525-00A024651F92} (StraksXControl) - file://D:\win32\EBankWeb\Software\prices.cab
O16 - DPF: {3EE838BD-5F59-11D2-A525-00A024651F92} (HandelXControl) - file://D:\win32\EBankWeb\Software\Trade.CAB
O16 - DPF: {DF2270CB-FDF3-11D0-81C5-000024222F7F} (EB_UserProfileUI.UserProfileUI) - file://D:\win32\EBankWeb\Software\UserProfileUI.CAB
O16 - DPF: {CDAD63CB-DE65-11D0-BD39-0000242179F2} (EB_LogUI.LogUI) - file://D:\win32\EBankWeb\Software\LogUI.CAB
O16 - DPF: {211E87BC-FD16-11D0-81C5-000024222F7F} (EB_BlockAccessUI.BlockAccessUI) - file://D:\win32\EBankWeb\Software\BlockAccessUI.CAB
O16 - DPF: {35A8AF38-5A10-11D3-AEEA-C5867FE56224} (EB_AccountEntriesUI.AccountEntriesUI) - http://195.184.35.73/hb/ebankweb/Software/AccountEntries.cab
O16 - DPF: {CE00B72E-986F-11D3-BC3C-E29223000000} (ZLibCls Class) - http://195.184.35.73/hb/ebankweb/software/FitZip.cab
O16 - DPF: {C1BAC744-8F0B-11D0-89E7-00C0A8295197} (Cameractl Class) - www.voyeurchallenge.com/vidtest/push.cab" target="_blank">http://tryme:tryme@www.voyeurchallenge.com/vidtest/push.cab
O16 - DPF: {7A96FF35-4937-11D1-8F2C-00609779BDA3} (Scol Class) - http://www.cryo-networks.com/files/ATLScol.dll
O16 - DPF: {D22AC3EF-B7D8-11D5-A281-005056BF0101} (plug Class) - http://dist02.chargitdial.com/chargitplug.dll
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://fr.encyclopedia.yahoo.com/rsc/tdserver.cab
O16 - DPF: {6BF52A52-394A-11D3-B153-00C04F79FAA6} (Windows Media Player 7) - http://activex.microsoft.com/activex/controls/mplayer/en/nsmp2inf.cab
O16 - DPF: {2ABE804B-4D3A-41BF-A172-304627874B45} - http://akamai.downloadv3.com/binaries/DialHTML/EGDHTML.cab
O16 - DPF: {0006F063-0000-0000-C000-000000000046} (Microsoft Outlook View Control) - http://activex.microsoft.com/activex/controls/office/outlctlx.CAB
O16 - DPF: {5F426A93-0821-47D2-A126-5A48A874B289} - http://212.145.159.194/251065/dialercab/WebRecomendada.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4336/mcfscan.cab
O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downloadv3.com/binaries/IA/nethv32_EN.cab
O16 - DPF: {0594AF7E-573B-40DF-8165-E47AB2EAEFE8} - http://akamai.downloadv3.com/binaries/P2EClient/EGAUTH_1015_EN.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab28578.cab
O16 - DPF: {706F3805-27D7-478D-80E5-E25D2BB030B3} (VacPro.internazionale_ver3) - http://www.advnt01.com/dialer/internazionale_ver3.CAB
O16 - DPF: {9076A11F-5EA6-4A67-BDE9-8D3C7C453DAC} - http://www.thecoolbar.com/installfiles/coolbar.cab
O16 - DPF: {A590956F-AE99-4419-BB39-3C721276C625} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-0504.exe
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab
O16 - DPF: {042EEA26-2402-4E5A-B5BB-0FB445A5526E} (VacPro.win98_P) - http://www9.advnt01.com/dialer/win98_P.CAB
O16 - DPF: {10000000-1000-0000-1000-000000000000} - mhtml:file://C:\ARCHIVE.MHT!http://download.moonri.com/l.exe
O18 - Filter: text/html - {DFAA31C8-A356-4313-9D95-5EDAB46C5070} - C:\WINDOWS\SYSTEM\LMF32V.DLL
