HJT
Logfile of HijackThis v1.97.7
Scan saved at 20:36:22, on 17-04-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSystem32RunDll32.exe
C:WINDOWSSystem32atiptaxx.exe
C:WINDOWSSystem32G-VGA.exe
C:PROGRA~1GrisoftAVG6avgcc32.exe
C:ProgrammerCyberLinkPowerVCRIIAgent.exe
C:WINDOWSSystem32ctfmon.exe
C:ProgrammerMSN MessengerMsnMsgr.Exe
C:PROGRA~1GrisoftAVG6avgserv.exe
C:WINDOWSSystem32svchost.exe
C:ProgrammerInternet Exploreriexplore.exe
C:Documents and SettingskemoSkrivebordHijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar =
http://homepage.com[...] href="mailto:00@
[email protected]/search/" target="_BLANK" title="www.e-finder.cc">
[email protected]/search/">www.e-finder.cc[...] (obfuscated)
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page =
http://homepage.com[...] href="mailto:00@
[email protected]/search/" target="_BLANK" title="www.e-finder.cc">
[email protected]/search/">www.e-finder.cc[...] (obfuscated)
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://www.qxl.dk[...]
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL =
http://homepage.com[...] href="mailto:00@
[email protected]/search/" target="_BLANK" title="www.e-finder.cc">
[email protected]/search/">www.e-finder.cc[...] (obfuscated)
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
http://homepage.com[...] href="mailto:00@
[email protected]/search/" target="_BLANK" title="www.e-finder.cc">
[email protected]/search/">www.e-finder.cc[...] (obfuscated)
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
http://homepage.com[...] href="mailto:00@
[email protected]/search/" target="_BLANK" title="www.e-finder.cc">
[email protected]/search/">www.e-finder.cc[...] (obfuscated)
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://homepage.com[...] href="mailto:00@
[email protected]/hp/" target="_BLANK" title="www.e-finder.cc">
[email protected]/hp/">www.e-finder.cc[...] (obfuscated)
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar =
http://homepage.com[...] href="mailto:00@
[email protected]/search/" target="_BLANK" title="www.e-finder.cc">
[email protected]/search/">www.e-finder.cc[...] (obfuscated)
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page =
http://homepage.com[...] href="mailto:00@
[email protected]/search/" target="_BLANK" title="www.e-finder.cc">
[email protected]/search/">www.e-finder.cc[...] (obfuscated)
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
http://www.microsoft.com[...]
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL =
http://homepage.com[...] href="mailto:00@
[email protected]/search/" target="_BLANK" title="www.e-finder.cc">
[email protected]/search/">www.e-finder.cc[...] (obfuscated)
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
http://homepage.com[...] href="mailto:00@
[email protected]/search/" target="_BLANK" title="www.e-finder.cc">
[email protected]/search/">www.e-finder.cc[...] (obfuscated)
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
http://homepage.com[...] href="mailto:00@
[email protected]/search/" target="_BLANK" title="www.e-finder.cc">
[email protected]/search/">www.e-finder.cc[...] (obfuscated)
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) =
http://homepage.com[...] href="mailto:00@
[email protected]/search/" target="_BLANK" title="www.e-finder.cc">
[email protected]/search/">www.e-finder.cc[...] (obfuscated)
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Hyperlinks
R1 - HKLMSoftwareMicrosoftInternet ExplorerSearch,(Default) =
http://homepage.com[...] href="mailto:00@
[email protected]/search/" target="_BLANK" title="www.e-finder.cc">
[email protected]/search/">www.e-finder.cc[...] (obfuscated)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx
O4 - HKLM..Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM..Run: [AtiPTA] atiptaxx.exe
O4 - HKLM..Run: [VGAUtil] C:WINDOWSSystem32G-VGA.exe
O4 - HKLM..Run: [AVG_CC] C:PROGRA~1GrisoftAVG6avgcc32.exe /STARTUP
O4 - HKLM..Run: [Agent] C:ProgrammerCyberLinkPowerVCRIIAgent.exe
O4 - HKLM..Run: [Remote_Agent] C:ProgrammerCyberLinkPowerVCRIIRemoteAgent.exe
O4 - HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k
O4 - HKLM..Run: [ICONFIG.EXE] C:PROGRA~1FLLESF~1SHUTTL~1ICONFIG.EXE "SoftwareShuttle Technology80000010"
O4 - HKLM..Run: [NeroCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 - HKCU..Run: [MsnMsgr] "C:ProgrammerMSN MessengerMsnMsgr.Exe" /background
O4 - HKCU..Run: [Steam] "f:steamsteam.exe" -silent
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O9 - Extra button: Opslag (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
fjernede 2 linier fra HJT hvor " %65%68%74%74%70%2e%63%63 " stod i men er der andet der skal fjernes ????
--
Gæstebruger, opret dit eget login og få din egen signatur.