Så er jeg Hijack´t igen er der nogle der gider hjælpe ?
Så er jeg blevet hijac´t igen.der er et program der bruger alt min cpu "sgbhp.exe"
er der nogle der kan hjælpe mig med at fjerne den og hvad der ellers måtte være af snavs.
på forhånd tak.
Logfile of HijackThis v1.99.0
Scan saved at 21:34:38, on 31-08-2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
E:\INTERNETPRG\NORMAN INTERNET CONTROL V5.50\nvc\BIN\NPFSVICE.EXE
C:\WINDOWS\Explorer.EXE
E:\Internetprg\Norman internet control v5.50\bin\ZANDA.EXE
E:\musikprg\MusicMatch 7.1\mm_tray.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
E:\Internetprg\Norman internet control v5.50\bin\ZLH.EXE
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Programmer\QuickTime\qttask.exe
E:\Musikprg\Ipod\itunes\iTunesHelper.exe
C:\Programmer\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\System32\popcorn72.exe
C:\WINDOWS\System32\ctfmon.exe
E:\INTERNETPRG\NORMAN INTERNET CONTROL V5.50\Nvc\BIN\nipsvc.exe
E:\INTERNETPRG\NORMAN INTERNET CONTROL V5.50\nvc\BIN\NVCSCHED.EXE
C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE
E:\Internetprg\Norman internet control v5.50\bin\NJEEVES.EXE
E:\Musikprg\Ipod\bin\iPodService.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
E:\Internetprg\Norman internet control v5.50\Nvc\BIN\NIP.EXE
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
E:\INTERNETPRG\NORMAN INTERNET CONTROL V5.50\nvc\BIN\nvcoas.exe
E:\Internetprg\SpywareGuard\sgmain.exe
E:\Internetprg\Norman internet control v5.50\Nvc\BIN\npfmsg2.exe
E:\Internetprg\Norman internet control v5.50\Nvc\bin\cclaw.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Programmer\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
E:\Internetprg\SpywareGuard\sgbhp.exe
C:\Programmer\Internet Explorer\iexplore.exe
c:\Programmer\Hijackthis\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINDOWS\System32\msblank.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://default.home/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: (no name) - {AD8FEFF8-FBA0-1908-769E-ED942301E65F} - NukeSpan.dll (file missing)
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - E:\Internetprg\SpywareGuard\dlprotect.dll
O4 - HKLM\..\Run: [MMTray] e:\musikprg\MusicMatch 7.1\mm_tray.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Norman ZANDA] E:\Internetprg\Norman internet control v5.50\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [LaunchList] E:\Filmprg\Pinnacle PCTV deluxe 1.5\LaunchList.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "E:\Musikprg\Ipod\itunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\System32\popcorn72.exe rundll.dll,LoadMouseProfile
O4 - HKLM\..\Run: [init32] install2.exe
O4 - HKLM\..\Run: [ssweeper] InpriseMon.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programmer\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [WareOut] "C:\Programmer\WareOut\WareOut.exe"
O4 - HKCU\..\Run: [Testimonials] startman.exe
O4 - HKCU\..\Run: [WhatsNewBot] bhoserv.exe
O4 - HKCU\..\Run: [backd] SAPSTR.exe
O4 - Startup: SpywareGuard.lnk = E:\Internetprg\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Programmer\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = E:\Kontorprg\MS Office 2000 pro\Office10\OSA.EXE
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://E:\KONTOR~1\MSOFFI~1\Office10\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programmer\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20030523/qtinstall.info.apple.com/drakken/dk/win/QuickTimeInstaller.exe
O16 - DPF: {5A447319-0EA2-447B-A063-A5F849B097D0} (ScanZillaLE Class) - https://www.stopzilla.com/scanner/binaries/SZScanLE.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1094126590274
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/da/big/1.1.62-big/GoogleNav.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8EE2BF0A-5760-4BDC-82F5-0B2286211DC6}: NameServer = 195.95.218.35,85.255.112.11
O17 - HKLM\System\CCS\Services\Tcpip\..\{FC13E763-6094-4336-B2EB-1DF159A5EDD4}: NameServer = 195.95.218.35,85.255.112.11
O17 - HKLM\System\CS2\Services\Tcpip\..\{8EE2BF0A-5760-4BDC-82F5-0B2286211DC6}: NameServer = 195.95.218.35,85.255.112.11
O17 - HKLM\System\CS3\Services\Tcpip\..\{8EE2BF0A-5760-4BDC-82F5-0B2286211DC6}: NameServer = 195.95.218.35,85.255.112.11
O23 - Service: iPod Service - Apple Computer, Inc. - E:\Musikprg\Ipod\bin\iPodService.exe
O23 - Service: Norman API-hooking helper - Unknown - E:\INTERNETPRG\NORMAN INTERNET CONTROL V5.50\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown - E:\Internetprg\Norman internet control v5.50\bin\NJEEVES.EXE
O23 - Service: Norman Type-R - Unknown - E:\INTERNETPRG\NORMAN INTERNET CONTROL V5.50\nvc\BIN\NPFSVICE.EXE
O23 - Service: Norman ZANDA - Unknown - E:\Internetprg\Norman internet control v5.50\bin\ZANDA.EXE
O23 - Service: Norman Virus Control on-access component - Norman ASA - E:\INTERNETPRG\NORMAN INTERNET CONTROL V5.50\nvc\BIN\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler - Norman Data Defense Systems - E:\INTERNETPRG\NORMAN INTERNET CONTROL V5.50\nvc\BIN\NVCSCHED.EXE
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
