Her er det fra det der hijackthis program
Logfile of HijackThis v1.99.1
Scan saved at 19:23:31, on 05-12-2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:ProgrammerAntiVir PersonalEdition Classicsched.exe
C:ProgrammerAntiVir PersonalEdition Classicavguard.exe
C:WINDOWSSystem32atievxx.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:ProgrammerJavajre1.5.0_05injusched.exe
C:Documents and SettingsAdministratorSkrivebordwinstall.exe
C:ProgrammerJavajre1.5.0_05injucheck.exe
C:WINDOWSSystem32jgzejq.exe
C:ProgrammerAntiVir PersonalEdition Classicavgnt.exe
C:WINDOWSSystem32ctfmon.exe
C:ProgrammerMessengermsmsgs.exe
C:ProgrammerSteamSteam.exe
C:ProgrammerSaveSave.exe
C:WINDOWSSystem32svchost.exe
C:ProgrammerInternet Exploreriexplore.exe
C:WINDOWSSystem32svchost.exe
C:ProgrammerInternet Exploreriexplore.exe
C:Documents and SettingsAdministratorLokale indstillingerTempMidlertidig mappe 1 for hijackthis.zipHijackThis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://www.google.dk[...]
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:ProgrammerAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 - BHO: 888Bar - {C004DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx
O3 - Toolbar: 888Bar - {C004DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
O4 - HKLM..Run: [SunJavaUpdateSched] C:ProgrammerJavajre1.5.0_05injusched.exe
O4 - HKLM..Run: [explorer] C:Documents and SettingsAdministratorSkrivebordwinstall.exe
O4 - HKLM..Run: [IpWins] C:Programmeripwinsipwins.exe
O4 - HKLM..Run: [Client Server Runtime Process] C:WINDOWSSystem32csrs.exe
O4 - HKLM..Run: [Services] C:WINDOWSSystem32jgzejq.exe
O4 - HKLM..Run: [WINDOWS] C:egnt.exe
O4 - HKLM..Run: [avgnt] "C:ProgrammerAntiVir PersonalEdition Classicavgnt.exe" /min
O4 - HKLM..Run: [UserFaultCheck] %systemroot%system32dumprep 0 -u
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 - HKCU..Run: [MSMSGS] "C:ProgrammerMessengermsmsgs.exe" /background
O4 - HKCU..Run: [MsnMsgr] "C:ProgrammerMSN MessengerMsnMsgr.Exe" /background
O4 - HKCU..Run: [Steam] C:ProgrammerSteamSteam.exe -silent
O4 - HKCU..Run: [WhenUSave] "C:ProgrammerSaveSave.exe"
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:ProgrammerAdobeAcrobat 7.0Reader
eader_sl.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com[...]
O16 - DPF: {E055C02E-6258-40FF-80A7-3BDA52FACAD7} (Installer Class) -
http://activex.matcash.com[...]
O17 - HKLMSystemCCSServicesTcpipParameters: Domain = skov.com
O17 - HKLMSoftware..Telephony: DomainName = skov.com
O17 - HKLMSystemCS1ServicesTcpipParameters: Domain = skov.com
O17 - HKLMSystemCS2ServicesTcpipParameters: Domain = skov.com
O20 - AppInit_DLLs: C:WINDOWSSystem32systbdf.dll
O20 - Winlogon Notify: rpcc - C:WINDOWSSystem32
pcc.dll
O21 - SSODL: CDRecorder026 - {A3BC5E20-0235-1ABF-9CE1-00AA00512026} - C:WINDOWSSystem32kwail32.dll (file missing)
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:ProgrammerAntiVir PersonalEdition Classicsched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:ProgrammerAntiVir PersonalEdition Classicavguard.exe
O23 - Service: Microsoft authenticate service (MsaSvc) - Unknown owner - C:WINDOWSSystem32msasvc.exe (file missing)
--