Hejsa.
Ja, så er der endnu en HJT-log, som jeg håber der er en venlig sjæld der vil kigge igennem for mig. På forhånd tak.
Logfile of HijackThis v1.98.2
Scan saved at 14:46:01, on 15-03-2005
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINNTSystem32smss.exe
C:WINNTsystem32winlogon.exe
C:WINNTsystem32services.exe
C:WINNTsystem32lsass.exe
C:WINNTsystem32svchost.exe
C:WINNTsystem32spoolsv.exe
C:PROGRA~1GrisoftAVG6avgserv.exe
C:WINNTSystem32svchost.exe
C:ProgrammerNorton Personal FirewallNISUM.EXE
C:WINNTSystem32
vsvc32.exe
C:WINNTsystem32
egsvc.exe
C:WINNTsystem32MSTask.exe
C:ProgrammerNorton Personal FirewallSymProxySvc.exe
C:WINNTSystem32WBEMWinMgmt.exe
C:ProgrammerNorton Personal FirewallNISSERV.EXE
C:WINNTExplorer.exe
C:ProgrammerMicrosoft HardwareMousepoint32.exe
C:PROGRA~1GrisoftAVG6avgcc32.exe
C:ProgrammerNorton Personal FirewallIAMAPP.EXE
C:WINNTloadqm.exe
C:WINNTSystem32internat.exe
C:ProgrammerMSN MessengerMsnMsgr.Exe
C:ProgrammerInternet Exploreriexplore.exe
C:WUTempcom_microsoft.WMPlayer_9_non_XP_5909MPSetup.exe
C:DOCUME~1ADMINI~1LOKALE~1TempIXP000.TMPsetup_wm.exe
C:ProgrammerInternet ExplorerIEXPLORE.EXE
C:Documents and SettingsAdministratorSkrivebordHijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar =
http://g.msn.dk[...]
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://www.msn.dk[...]
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar =
http://wtbzlm.t.muxa.cc[...] (obfuscated)
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
http://wtbzlm.t.muxa.cc[...] (obfuscated)
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,HomeOldSP =
http://wtbzlm.t.muxa.cc[...] (obfuscated)
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,HomeOldSP =
http://wtbzlm.t.muxa.cc[...] (obfuscated)
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Hyperlinks
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINNTSystem32msdxm.ocx
O4 - HKLM..Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM..Run: [POINTER] point32.exe
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINNTSystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [AVG_CC] C:PROGRA~1GrisoftAVG6avgcc32.exe /STARTUP
O4 - HKLM..Run: [iamapp] C:ProgrammerNorton Personal FirewallIAMAPP.EXE
O4 - HKLM..Run: [sys] regedit -s sys.reg
O4 - HKLM..Run: [LoadQM] loadqm.exe
O4 - HKLM..Run: [supervideospornodk-htm] RunDll32 UDConn.dll,RunAsIcon supervideospornodk
O4 - HKLM..Run: [NeroCheck] C:WINNTSystem32NeroCheck.exe
O4 - HKLM..RunOnce: [wextract_cleanup0] rundll32.exe C:WINNTSystem32advpack.dll,DelNodeRunDLL32 "C:DOCUME~1ADMINI~1LOKALE~1TempIXP000.TMP"
O4 - HKCU..Run: [internat.exe] internat.exe
O4 - HKCU..Run: [MsnMsgr] "C:ProgrammerMSN MessengerMsnMsgr.Exe" /background
O4 - HKCU..Run: [NvMediaCenter] RUNDLL32.EXE C:WINNTSystem32NVMCTRAY.DLL,NvTaskbarInit
O4 - Global Startup: Microsoft Office.lnk = C:ProgrammerMicrosoft OfficeOffice10OSA.EXE
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:PROGRA~1MICROS~3Office10EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINNTweb
elated.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:WINNTweb
elated.htm
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com[...]
O16 - DPF: {018B7EC3-EECA-11D3-8E71-0000E82C6C0D} (Installer Class) -
http://www.xxxtoolbar.com[...]
O16 - DPF: {037B3D58-D14A-4C41-BDFD-BD779B0B97BA} (vxiewer control) -
http://www.thepaymentcentre.com[...]
O16 - DPF: {093F9CF8-0DE1-491C-95D5-5EC257BD4CA3} -
http://akamai.downloadv3.com[...]
O16 - DPF: {1EB17D1C-141D-4D9D-91CB-24D99215851D} -
http://akamai.downloadv3.com[...]
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com[...]
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com[...]
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} -
http://dload.ipbill.com[...]
O16 - DPF: {CEFB7B49-9652-464F-8AFD-A577C0500F39} (EGP2ECOM Class) -
http://akamai.downloadv3.com[...]
O16 - DPF: {D62B5127-8D03-4175-BA71-E0041595DA4B} (UDConnect Class) -
http://03.sharedsource.org[...]
O16 - DPF: {E6A3C1E2-F792-483E-9133-596215172BE9} (AcceptLang Class) -
http://runonce.msn.com[...]
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) -
http://messenger.zone.msn.com[...]
O17 - HKLMSystemCCSServicesTcpip..{9547E9D7-BEB4-4AD2-A076-FF2FD48B763C}: NameServer = 194.239.134.83,193.162.153.164
--