mange tak armageddon.
Smider loggen her selvom jeg har været lidt langsom.
MANGE TAK
Logfile of HijackThis v1.97.7
Scan saved at 21:39:06, on 11-04-2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINNTSystem32smss.exe
C:WINNTsystem32winlogon.exe
C:WINNTsystem32services.exe
C:WINNTsystem32lsass.exe
C:WINNTsystem32svchost.exe
C:WINNTsystem32spoolsv.exe
C:WINNTSystem32svchost.exe
C:WINNTExplorer.EXE
C:WINNTsystem32sysflg32.exe
C:WINNTsystem32starter.exe
C:ProgrammerWinampwinampa.exe
C:winntsystem32sncntr.exe
C:WINNTsystem32msgfix.exe
C:WINNTsystem32WinHelp.exe
C:WINNTsystem32IEXPLORE.EXE
C:WINNTsystem32internat.exe
C:WINNTsystem32msgfix.exe
C:WINNTSystem32
vsvc32.exe
C:WINNTsystem32
egsvc.exe
C:WINNTsystem32MSTask.exe
C:WINNTSystem32WBEMWinMgmt.exe
C:WINNTsystem32svchost.exe
C:ProgrammerInternet ExplorerIEXPLORE.EXE
C:WINNTsystem32winrpc.exe
C:ProgrammerWebrootSpy SweeperSpySweeper.exe
C:Documents and SettingsMarkoTDokumenterHijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page =
http://searchcentral.cc[...]
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://www.signon.stofanet.dk[...]
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://www.signon.stofanet.dk[...]
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *hot-searches.com*;*lender-search.com*;<local>
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Hyperlinks
F1 - win.ini: run=c:winntsystem32sysflg32.exe
O1 - Hosts file is located at: C:WINNT
sdbhosts
O1 - Hosts: 81.211.105.69 lender-search.com
O1 - Hosts: 81.211.105.68 hot-searches.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:ProgrammerAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINNTSystem32msdxm.ocx
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM..Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM..Run: [EnsoniqMixer] C:WINNTsystem32starter.exe
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINNTSystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [LoadQM] loadqm.exe
O4 - HKLM..Run: [WinampAgent] C:ProgrammerWinampwinampa.exe
O4 - HKLM..Run: [QuickTime Task] "C:ProgrammerQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [sncntr] c:winntsystem32sncntr.exe /nocomm
O4 - HKLM..Run: [SexCams_dk] C:Program FilesSComDialersSexCams_dkSexCams_dk.exe /dontdial
O4 - HKLM..Run: [Configuration Loader] msgfix.exe
O4 - HKLM..Run: [WinHelp] C:WINNTsystem32WinHelp.exe
O4 - HKLM..Run: [WinGate initialize] C:WINNTsystem32WinGate.exe -remoteshell
O4 - HKLM..Run: [Remote Procedure Call Locator] RUNDLL32.EXE reg678.dll ondll_reg
O4 - HKLM..Run: [Program In Windows] C:WINNTsystem32IEXPLORE.EXE
O4 - HKLM..Run: [Sysflg32] c:winntsystem32sysflg32.exe
O4 - HKLM..RunServices: [Configuration Loader] msgfix.exe
O4 - HKCU..Run: [internat.exe] internat.exe
O4 - HKCU..Run: [MsnMsgr] "C:ProgrammerMSN MessengerMsnMsgr.Exe" /background
O4 - HKCU..Run: [Skype] "C:ProgrammerSkypePhoneSkype.exe" /nosplash /minimized
O4 - HKCU..Run: [RealUpdater] C:WINNTsystem32
ealupd.exe
O4 - HKCU..Run: [Configuration Loader] msgfix.exe
O4 - HKCU..Run: [Sysflg32] c:winntsystem32sysflg32.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Microsoft Office.lnk = C:ProgrammerMicrosoft OfficeOfficeOSA9.EXE
O16 - DPF: WebMaster ChatNow Client -
http://irc.cg.yu[...]
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://www.apple.com[...]
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net[...]
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
http://v4.windowsupdate.microsoft.com[...]
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) -
http://fdl.msn.com[...]
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://active.macromedia.com[...]
--
Nysgerrig af natur