HijackThis log
Hej allesammenNu er den gal igen. Er der en der gider kigge på min log?
M.V.H. Mokof
Logfile of HijackThis v1.99.0
Scan saved at 15:50:00, on 16-05-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Programmer\Sygate\SPF\smc.exe
C:\windows\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Programmer\ewido\security suite\ewidoctrl.exe
C:\Programmer\Messenger\msmsgs.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Downloads\Winamp\winampa.exe
C:\Programmer\Java\jre1.5.0\bin\jusched.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\programmer\180solutions\sais.exe
C:\windows\isrvs\desktop.exe
C:\windows\System32\exssic.exe
C:\windows\System32\dwwin.exe
C:\Programmer\CxtPls\CxtPls.exe
C:\Programmer\FF Browser 1.0 Beta\FFbrowser.exe
C:\Programmer\Internet Explorer\iexplore.exe
c:\windows\system32\nvpurq.exe
C:\Programmer\ISTsvc\istsvc.exe
C:\windows\Explorer.exe
C:\windows\System32\dwwin.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\BullsEye Network\bin\bargains.exe
C:\windows\System32\exdl1.exe
C:\Downloads\Sikkerhed\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
F2 - REG:system.ini: Shell=Explorer.exe C:\windows\Nail.exe
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Programmer\CxtPls\cxtpls.dll
O2 - BHO: Loader Class - {2E246FAE-8420-11D9-870D-000C2917DE7F} - C:\WINDOWS\SYSTEM\Loader.dll
O2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - C:\windows\System32\nse64.dll
O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\Programmer\SideFind\sfbho.dll
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\windows\System32\msbe.dll
O3 - Toolbar: UCmore XP - The Search Accelerator - {44BE0690-5429-47f0-85BB-3FFD8020233E} - C:\Programmer\TheSearchAccelerator\UCMTSAIE.dll
O3 - Toolbar: YourSiteBar - {86227D9C-0EFE-4f8a-AA55-30386A3F5686} - C:\PROGRA~1\YOURSI~1\ys2.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Downloads\Winamp\winampa.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [USSShReg] c:\PROGRA~1\SSaver\Ussshreg.exe /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WebRun] C:\windows\System32\msxmidi.exe
O4 - HKLM\..\Run: [sais] c:\programmer\180solutions\sais.exe
O4 - HKLM\..\Run: [Desktop Search] C:\windows\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\windows\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [IST Service] C:\Programmer\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [BullsEye Network] C:\Programmer\BullsEye Network\bin\bargains.exe
O4 - HKLM\..\Run: [Tsl2] C:\PROGRA~1\COMMON~1\tsa\tsl2.exe
O4 - HKLM\..\Run: [5F4O3FX] exssic.exe
O4 - HKLM\..\Run: [abasa5jrp] C:\windows\System32\abasa5jrp.exe
O4 - HKLM\..\Run: [Power Scan] C:\Programmer\Power Scan\powerscan.exe
O4 - HKLM\..\Run: [sjalcoe] c:\windows\system32\nvpurq.exe
O4 - HKCU\..\Run: [ATnotes.exe] C:\Downloads\ATnotes\ATnotes.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [System backup] C:\windows\System32\web.exe
O4 - HKCU\..\Run: [Scbl] C:\Documents and Settings\Mogens\Application Data\dauw.exe
O4 - HKCU\..\Run: [Lpbccon] C:\windows\System32\??crosoft.NET\ati2evxx.exe
O4 - HKCU\..\Run: [KovERPb4g] dmsarta.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Programmer\SideFind\sidefind.dll
O16 - DPF: {01343DD6-B63E-2E34-51DE-6A3F400091F5} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {021D54C8-12C2-02A2-BC8F-5D34256623AD} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {0337C0B9-E6F7-13D0-6D64-032D49FD2B9D} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {034128FE-AEFF-735F-98D1-579D50D647EC} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {061DE425-0A2D-3008-C491-00A66C59FB99} -
O16 - DPF: {06C38DDD-31F7-0551-3DE7-39973AA5FF60} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {08699216-7E45-31F3-3BA8-4D024E8AD062} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {0CD2DA69-62CE-367E-088D-2C601AB58A6E} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {11919C49-1AC3-6C7D-645F-6AD308B62FDB} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {11A48F24-0EB7-09FA-B831-472C4D502CD3} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {1CB7C316-204A-1619-755E-0560236B5827} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {214FD528-00C1-2594-6196-6D0C5BC22BA6} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {22FB9B92-0DF8-4942-BB12-0A457A1A6B07} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {2B52C178-8EE5-4702-E3FC-235A7EDEF09C} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {2D09BB6E-A322-5A92-0FE8-6C2B19FE6B4C} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {3340FAFC-99F6-5D4F-3AAC-630616235ECD} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {336CBC85-555C-3A0F-C40D-6FA8260F70FF} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {37E23EBC-B10F-6FC8-A3F7-519E7206D0F9} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://www.miniclip.com/ricochet/ReflexiveWebGameLoader.cab
O16 - DPF: {493D27F7-FC37-6B85-92B6-58BB5D47A274} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {49533EEF-DBB4-1698-BAC9-7CE505B29AD7} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {4B5F85A0-151C-17A2-B1D3-77BF580F5A40} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {5CD363E5-A0F6-319C-D303-5B46421536D0} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {5EE6A688-8F27-020E-6AE3-7D6033C606E4} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {66D810A8-AC01-1065-93E0-1DA051E8CCB2} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {6C0957E5-9FED-5F69-28B0-5EBC7F40060C} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {7605C8D7-62D5-4C19-D6D3-669B1F98FE68} - http://67.19.178.86/1/rdgDK1742.exe
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) - http://static.topconverting.com/activex/mp3.ocx
O16 - DPF: {7CE3F46F-0CEE-1667-D515-28214FDC05CD} - http://67.19.178.86/1/rdgDK1742.exe
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINDOWS\isrvs\mfiltis.dll
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programmer\ewido\security suite\ewidoctrl.exe
O23 - Service: Sygate Personal Firewall - Sygate Technologies, Inc. - C:\Programmer\Sygate\SPF\smc.exe
O23 - Service: ZESOFT - Unknown - C:\windows\zeta.exe
