Hej her er en log jeg håber nogen kan hjælpe mig med. Den er fra en ven, som ikke længere har fuld kontrol over sin browser.
Logfile of HijackThis v1.99.1
Scan saved at 11:41:08, on 05-03-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:ProgrammerLogMeInRaMaint.exe
C:ProgrammerLogMeInLogMeIn.exe
C:ProgrammerFælles filerMicrosoft SharedVS7DEBUGMDM.EXE
C:WINDOWSSystem32
vsvc32.exe
C:ProgrammerAnalog DevicesSoundMAXSMAgent.exe
C:WINDOWSsystem32wscntfy.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spooldriversw32x863hpztsb04.exe
C:ProgrammerQuickTimeqttask.exe
C:ProgrammerMaxtorOneTouchutilsOnetouch.exe
C:PROGRA~1DantzRETROS~1RetroExpress.exe
C:ProgrammerLogMeInLogMeInSystray.exe
C:VIRUSfighterBinLH.EXE
C:WINDOWSsystem32ctfmon.exe
C:ProgrammerMessengerMSMSGS.EXE
C:ProgrammerAdobeAcrobat 6.0Distillracrotray.exe
C:ProgrammerTEXTwareHotKeyTwalink.exe
C:PROGRA~1DantzRETROS~1
etrorun.exe
C:ProgrammerLavasoftAd-Aware SE PersonalAd-Aware.exe
C:ProgrammerSkypePhoneSkype.exe
C:Documents and SettingsJacobSkrivebordDownloadhijackthis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://www.google.dk[...]
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:ProgrammerAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:ProgrammerAdobeAcrobat 6.0AcrobatAcroIEFavClient.dll (file missing)
O3 - Toolbar: Cole2k Media Toolbar - {015407A9-D183-4379-8452-DFD7C2297902} - C:ProgrammerCole2k Media Toolbarv2.0.0.2Cole2k_Media_Toolbar.dll (file missing)
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit
O4 - HKLM..Run: [HPDJ Taskbar Utility] C:WINDOWSsystem32spooldriversw32x863hpztsb04.exe
O4 - HKLM..Run: [QuickTime Task] "C:ProgrammerQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [MaxtorOneTouch] C:ProgrammerMaxtorOneTouchutilsOnetouch.exe
O4 - HKLM..Run: [MXOBG] C:Documents and SettingsJacobLokale indstillingerTemp{231F68F4-70E4-41A6-BEDA-7E7934169B54}MXOALDR.EXE
O4 - HKLM..Run: [RetroExpress] C:PROGRA~1DantzRETROS~1RetroExpress.exe /h
O4 - HKLM..Run: [NeroCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [LogMeIn GUI] "C:ProgrammerLogMeInLogMeInSystray.exe"
O4 - HKLM..Run: [Norman ZANDA] C:VIRUSfighterBinLH.EXE /LOAD /SPLASH
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [MSMSGS] "C:ProgrammerMessengerMSMSGS.EXE" /background
O4 - HKCU..Run: [Skype] "C:ProgrammerSkypePhoneSkype.exe" /nosplash /minimized
O4 - Global Startup: Acrobat Assistant.lnk = C:ProgrammerAdobeAcrobat 6.0Distillracrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:ProgrammerAdobeAcrobat 7.0Reader
eader_sl.exe
O4 - Global Startup: HotKey.lnk = C:ProgrammerTEXTwareHotKeyTwalink.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:PROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:ProgrammerMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:ProgrammerMessengermsmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com[...]
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com[...]
O16 - DPF: {8B3512EF-4FF5-4AA4-9CDE-56BB03E04B9F} (SAXFileEE ActiveX Control) -
http://www.billedbutikken.dk[...]
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com[...]
O16 - DPF: {CA79DF4A-E7DD-4175-A88A-7B72533A4130} (Sky Software FolderView ActiveX Control 6.0) -
http://www.billedbutikken.dk[...]
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) -
https://secure.logmein.com[...]
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:PROGRA~1MSNMES~1msgrapp.dll" (file missing)
O20 - Winlogon Notify: ldr64 - C:WINDOWSSYSTEM32ldr64.dll
O20 - Winlogon Notify: LMIinit - C:WINDOWSSYSTEM32LMIinit.dll
O20 - Winlogon Notify: mloader32 - C:WINDOWSSYSTEM32mloader32.dll
O23 - Service: Adobe LM Service - Unknown owner - C:ProgrammerFælles filerAdobe Systems SharedServiceAdobelmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:ProgrammerFælles filerInstallShieldDriver11Intel 32IDriverT.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - 3am Labs, Inc. - C:ProgrammerLogMeInRaMaint.exe
O23 - Service: LogMeIn - 3am Labs, Inc. - C:ProgrammerLogMeInLogMeIn.exe
O23 - Service: DTC (Distributed Transaction Coordinator) (MSDTC) - Unknown owner - C:WINDOWSSystem32msdtc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSSystem32
vsvc32.exe
O23 - Service: Retrospect Express HD Restore Helper (RetroExp Helper) - Dantz Development Corporation - C:PROGRA~1DantzRETROS~1
thlpsvc.exe
O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - Dantz Development Corporation - C:PROGRA~1DantzRETROS~1
etrorun.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:ProgrammerAnalog DevicesSoundMAXSMAgent.exe
--