Min logfil ser således ud:
Logfile of HijackThis v1.97.7
Scan saved at 20:33:56, on 08-12-2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\Programmer\QuickTime\qttask.exe
D:\windows\system32\mscnt.exe
D:\Programmer\ICQ\ICQ.exe
D:\Programmer\KFH\cl\launcher.exe
D:\WINDOWS\svchost.exe
D:\Documents and Settings\Morten Stilling\Dokumenter\Modtagne filer\AnyDVD.exe
D:\Program Files\Internet Optimizer\optimize.exe
D:\WINDOWS\system32\spoolsv.exe
C:\Program Files\GMSoft\Dialers\Hot_nl\Hot_nl.exe
D:\WINDOWS\System32\P2P Networking\P2P Networking.exe
D:\Programmer\Common files\updater\wupdater.exe
C:\program files\altnet\points manager\points manager.exe
D:\WINDOWS\System32\LSAS.exe
C:\PROGRA~2\Altnet\DOWNLO~1\asm.exe
D:\WINDOWS\System32\SERVlCES.exe
D:\WINDOWS\System32\svchos1.exe
D:\WINDOWS\system32\gearsec.exe
D:\WINDOWS\System32\ctfmon.exe
D:\WINDOWS\System32\RUNDLL32.EXE
D:\Programmer\MSN Messenger\MsnMsgr.Exe
D:\program files\Webdialer\od-stnd520.exe
D:\program files\Webdialer\od-teen216.exe
D:\program files\Webdialer\od-matr60.exe
D:\program files\Webdialer\od-stnd174.exe
D:\WINDOWS\System32\filename.exe
D:\Documents and Settings\Morten Stilling\Skrivebord\DCOMbob.exe
D:\Programmer\Internet Explorer\iexplore.exe
D:\Programmer\Internet Explorer\IEXPLORE.EXE
D:\Documents and Settings\Morten Stilling\Lokale indstillinger\Temp\Midlertidig mappe 1 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL =
http://solongas.com/main/sp.phpR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://solongas.com/main/sp.phpR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://solongas.com/main/sp.phpR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://solongas.com/main/hp.phpR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ultralinks.info/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.searchv.com/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://solongas.com/main/sp.phpR1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.searchv.com/w/search.htmlR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ultralinks.info/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.search-1.net/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ultralinks.info/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.searchv.com/search.htmlR0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.searchv.com/w/search.htmlR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://www.searchv.com/w/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP =
http://approvedlinks.com/hp.htmR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant =
http://www.search-1.net/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer,CustomizeSearch =
http://www.search-1.net/search.htmlR3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{A045DC85-FC44-45be-8A50-E4F9C62C9A84} - (no file)
F2 - REG:system.ini: UserInit=D:\WINDOWS\System32\userinit.exe,D:\WINDOWS\System32\svcpack.exe
O2 - BHO: (no name) - {000006B1-19B5-414A-849F-2A3C64AE6939} - (no file)
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - D:\Programmer\MyWay\myBar\1.bin\MYBAR.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: HTML Source Editor - {086AE192-23A6-48D6-96EC-715F53797E85} - D:\WINDOWS\System32\DReplace.dll
O2 - BHO: DNSErr object - {1E1B2879-88FF-11D2-8D96-D7ACAC95951F} - D:\WINDOWS\DNSErr.dll
O2 - BHO: WinShow module - {6CC1C918-AE8B-4373-A5B4-28BA1851E39A} - D:\Documents and Settings\Morten Stilling\Application Data\winshow\winshow.dll
O2 - BHO: (no name) - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - D:\WINDOWS\wsem216.dll
O2 - BHO: NavErrRedir Class - {A045DC85-FC44-45be-8A50-E4F9C62C9A84} - D:\PROGRA~1\PERFEC~1\BHO\PERFEC~1.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Programmer\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {F7F808F0-6F7D-442C-93E3-4A4827C2E4C8} - D:\WINDOWS\nem214.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - D:\Programmer\MyWay\myBar\1.bin\MYBAR.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Programmer\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Mirabilis ICQ] D:\Programmer\ICQ\ICQNet.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "D:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Mscnt] d:\windows\system32\mscnt.exe /noconnect
O4 - HKLM\..\Run: [sys] regedit /s D:\WINDOWS\sys.reg
O4 - HKLM\..\Run: [SwimSuitNetwork] "D:\Programmer\SwimSuitNetwork\SwimSuitNetwork.exe" /H
O4 - HKLM\..\Run: [Launcher] "D:\Programmer\KFH\cl\launcher.exe" /P
O4 - HKLM\..\Run: [Online Service] D:\WINDOWS\svchost.exe
O4 - HKLM\..\Run: [ElbyCheckAnyDVD] "D:\Programmer\SlySoft\AnyDVD\ElbyCheck.exe" /L AnyDVD
O4 - HKLM\..\Run: [AnyDVD] D:\Documents and Settings\Morten Stilling\Dokumenter\Modtagne filer\AnyDVD.exe
O4 - HKLM\..\Run: [Internet Optimizer] "D:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [Hot_nl] C:\Program Files\GMSoft\Dialers\Hot_nl\Hot_nl.exe /dontdial
O4 - HKLM\..\Run: [Belt] D:\WINDOWS\Belt.exe
O4 - HKLM\..\Run: [P2P Networking] D:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [KAZAA] D:\Programmer\Kazaa\kazaa.exe /SYSTRAY
O4 - HKLM\..\Run: [updater] D:\Programmer\Common files\updater\wupdater.exe
O4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points manager\points manager.exe -s
O4 - HKLM\..\Run: [Windows Explorer] LSAS.exe
O4 - HKLM\..\Run: [Configuration Loader] SERVlCES.exe
O4 - HKLM\..\Run: [Win Init] filename.exe
O4 - HKLM\..\Run: [Configuration Loading] svchos1.exe
O4 - HKLM\..\Run: [NAV CfgWiz] D:\PROGRA~1\NORTON~1\Cfgwiz.exe /R
O4 - HKLM\..\Run: [ccApp] D:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] D:\Programmer\Fælles filer\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [Advanced Tools Check] D:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\RunServices: [Windows Explorer] LSAS.exe
O4 - HKLM\..\RunServices: [Configuration Loader] SERVlCES.exe
O4 - HKLM\..\RunServices: [Win Init] filename.exe
O4 - HKLM\..\RunServices: [Configuration Loading] svchos1.exe
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MsnMsgr] "D:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [iedll] C:\WINNT\iedll.exe
O4 - HKCU\..\Run: [loader] C:\WINNT\loader.exe
O4 - HKLM\..\RunOnce: [SpyBotSnD] "D:\Programmer\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\RunOnce: [ICQ] D:\Programmer\ICQ\ICQ.exe -trayboot
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://www.apple.com/qtactivex/qtplugin.cabO16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CABO16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} -
http://dload.ipbill.com/del/loader.cabO16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} (CSS Web Installer Class) -
http://scanner.virus112.com/cabs/cssweb.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabO16 - DPF: {EB6AFDAB-E16D-430B-A5EE-0408A12289DC} -
http://download.mediacharger.com/swimsuitnetwork.cabO16 - DPF: {FC87A650-207D-4392-A6A1-82ADBC56FA64} (MultiDist) -
http://xbs.climaxbucks.com/internet-optimizer/080703/MultiDist.CAB