Problem med en PC - Popups etc.
Heysan Eksperter...Jeg har en pc'er som kommer med pop ups, og er det hele taget underlig. Jeg har følgende HIJACKTHIS log. Kan nogen hjælpe mig?
Logfile of HijackThis v1.99.0
Scan saved at 09:07:04, on 10-02-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Norman\NVC\BIN\Zanda.exe
C:\WINDOWS\System32\winpnp32.exe
C:\NORMAN\nvc\BIN\nvcoas.exe
C:\NORMAN\nvc\BIN\NJEEVES.EXE
C:\NORMAN\nvc\BIN\NVCSCHED.EXE
C:\WINDOWS\System32\SDK0mCORE.exe
C:\WINDOWS\System32\hostsvc32.exe
C:\WINDOWS\System32\wxmst.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\NORMAN\nvc\BIN\ZLH.EXE
C:\WINDOWS\System32\configsys.exe
C:\WINDOWS\System32\configsys.exe
C:\WINDOWS\System32\wuaumgr.exe
C:\WINDOWS\System32\soundblaster.exe
C:\NORMAN\nvc\BIN\NYMSE.EXE
C:\NORMAN\nvc\BIN\NIP.EXE
C:\WINDOWS\System32\soundblaster.exe
C:\WINDOWS\System32\crsss.exe
C:\NORMAN\nvc\BIN\cclaw.exe
C:\WINDOWS\System32\koko.exe
C:\Program Files\Internet Optimizer\optimize.exe
C:\programmer\180solutions\sais.exe
C:\WINDOWS\System32\winms.exe
C:\WINDOWS\System32\winms.exe
C:\Program Files\Internet Optimizer\actalert.exe
C:\WINDOWS\System32\real.updat.exe
C:\WINDOWS\System32\SahAgent.exe
C:\WINDOWS\System32\wuamgrdn32.exe
C:\Program Files\Oybl\Vfads.exe
C:\windows\system32\exploer.exe
C:\Program Files\Windows AdStatus\WinStat.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Windows AdStatus\WinStatKeep.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\System32\wpabaln.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Programmer\Internet Explorer\iexplore.exe
G:\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.html?&account_id=152316
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.couldnotfind.com/search_page.html?&account_id=152316
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=152316
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll
O2 - BHO: (no name) - {1D7E3B41-23CE-469B-BE1B-A64B877923E1} - C:\PROGRA~1\SEARCH~1\SEARCH~1.DLL
O2 - BHO: BHObj Class - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem303.dll
O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\Programmer\SideFind\sfbho.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: ISTbar - {5F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\PROGRA~1\ISTbar\istbar.dll
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [System Update] C:\WINDOWS\System32\zdcfb.exe
O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\nvc\BIN\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [RPC Time Check AN Date] configsys.exe
O4 - HKLM\..\Run: [Windows Update Auto Update] wuaumgr.exe
O4 - HKLM\..\Run: [Micr Update] soundblaster.exe
O4 - HKLM\..\Run: [Windows media service] crsss.exe
O4 - HKLM\..\Run: [koko.exe] koko.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [sais] c:\programmer\180solutions\sais.exe
O4 - HKLM\..\Run: [Power Scan] C:\Programmer\Power Scan\powerscan.exe
O4 - HKLM\..\Run: [Microsoft Windows Storage Machine Service] winms.exe
O4 - HKLM\..\Run: [sdkupdate22] SDK0mCORE.exe
O4 - HKLM\..\Run: [*wuauclt.exe] wxmst.exe
O4 - HKLM\..\Run: [zsdsx] C:\WINDOWS\zsdsx.exe
O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\ocxqde.exe
O4 - HKLM\..\Run: [Microsoft Windows Graphic Spooler] hostsvc32.exe
O4 - HKLM\..\Run: [zonalarm Personal Firewall] real.updat.exe
O4 - HKLM\..\Run: [SAHAgent] C:\WINDOWS\System32\SahAgent.exe
O4 - HKLM\..\Run: [wuamgrdn32] wuamgrdn32.exe
O4 - HKLM\..\Run: [Uanojqyx] C:\Program Files\Jwxv\Ijwphym.exe
O4 - HKLM\..\Run: [Uhpnv] C:\Program Files\Oybl\Vfads.exe
O4 - HKLM\..\Run: [ImInstaller_IncrediMail] C:\DOCUME~1\JOHNNY~1.JOH\LOKALE~1\Temp\ImInstaller\IncrediMail\imloader.exe -startup -product IncrediMail
O4 - HKLM\..\Run: [Updat] c:\windows\system32\exploer.exe
O4 - HKLM\..\Run: [Windows AdStatus] C:\Program Files\Windows AdStatus\WinStat.exe
O4 - HKLM\..\RunServices: [RPC Time Check AN Date] configsys.exe
O4 - HKLM\..\RunServices: [Windows Update Auto Update] wuaumgr.exe
O4 - HKLM\..\RunServices: [Micr Update] soundblaster.exe
O4 - HKLM\..\RunServices: [Windows media service] crsss.exe
O4 - HKLM\..\RunServices: [koko.exe] koko.exe
O4 - HKLM\..\RunServices: [Microsoft Windows Storage Machine Service] winms.exe
O4 - HKLM\..\RunServices: [sdkupdate22] SDK0mCORE.exe
O4 - HKLM\..\RunServices: [*wuauclt.exe] wxmst.exe
O4 - HKLM\..\RunServices: [Microsoft Windows Graphic Spooler] hostsvc32.exe
O4 - HKLM\..\RunServices: [zonalarm Personal Firewall] real.updat.exe
O4 - HKLM\..\RunServices: [wuamgrdn32] wuamgrdn32.exe
O4 - HKLM\..\RunOnce: [sdkupdate22] SDK0mCORE.exe
O4 - HKLM\..\RunOnce: [Microsoft Windows Graphic Spooler] hostsvc32.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Windows Update Auto Update] wuaumgr.exe
O4 - HKCU\..\Run: [RPC Time Check AN Date] configsys.exe
O4 - HKCU\..\Run: [Micr Update] soundblaster.exe
O4 - HKCU\..\Run: [sdkupdate22] SDK0mCORE.exe
O4 - HKCU\..\Run: [*wuauclt.exe] wxmst.exe
O4 - HKCU\..\Run: [Microsoft Windows Graphic Spooler] hostsvc32.exe
O4 - HKCU\..\Run: [zonalarm Personal Firewall] real.updat.exe
O4 - HKCU\..\Run: [wuamgrdn32] wuamgrdn32.exe
O4 - HKCU\..\RunServices: [wuamgrdn32] wuamgrdn32.exe
O4 - HKCU\..\RunOnce: [sdkupdate22] SDK0mCORE.exe
O4 - HKCU\..\RunOnce: [Microsoft Windows Graphic Spooler] hostsvc32.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Programmer\InterVideo\Common\Bin\WinCinemaMgr.exe
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Programmer\SideFind\sidefind.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/CDT/ie/bridge-c46.cab
O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_regular.cab
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) - http://static.topconverting.com/activex/loader2.ocx
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www5.incredimail.com/contents/setup/downloader_sp1/imloader.cab
O21 - SSODL: Web Event Logger - {79FEACFF-FFCE-815E-A900-316290B5B738} - C:\WINDOWS\System32\Fbndphla.dll
O21 - SSODL: mtklef - {D17BE188-F9CF-4619-53A9-BF48EAB5C62E} - C:\WINDOWS\System32\llev32.dll
O23 - Service: *wuauclt.exe - Unknown - C:\WINDOWS\System32\wxmst.exe
O23 - Service: LexBce Server - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norman NJeeves - Unknown - C:\NORMAN\nvc\BIN\NJEEVES.EXE
O23 - Service: Norman ZANDA - Unknown - C:\Norman\NVC\BIN\Zanda.exe
O23 - Service: Norman Virus Control on-access component - Norman ASA - C:\NORMAN\nvc\BIN\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler - Norman Data Defense Systems - C:\NORMAN\nvc\BIN\NVCSCHED.EXE
O23 - Service: Windows 32-bit PnP Driver - Unknown - C:\WINDOWS\System32\winpnp32.exe
VH
Moltov
