Hijackthis log
Er der nogen der kan se noget i denne log?Logfile of HijackThis v1.98.2
Scan saved at 16:35:22, on 17.08.2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\NavNT\DefWatch.exe
C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\LCFD.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\NavNT\rtvscan.exe
C:\WINDOWS\system32\ieij32.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\NavNT\vptray.exe
C:\WINDOWS\atljt32.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Attachmate\E!E2K\EXTRA.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\IFR\Desktop\Ny mappe\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\nmgmv.dll/sp.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\elrcm.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://elrcm.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://elrcm.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\elrcm.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\nmgmv.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\elrcm.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://elrcm.dll/index.html#37049
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {60010401-2B35-4071-50C0-6C8A5F1A267A} - C:\WINDOWS\system32\apisb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SwdisUsrPCN.CR101376] "C:\PROGRA~1\Tivoli\lcf\dat\1\cache\lib\w32-ix86\wdusrpcn.exe" "C:\Program Files\Tivoli\swdis\1\wdusrpcn.env"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\NavNT\vptray.exe
O4 - HKLM\..\Run: [atljt32.exe] C:\WINDOWS\atljt32.exe
O4 - HKLM\..\RunOnce: [crrt.exe] C:\WINDOWS\crrt.exe
O4 - HKLM\..\RunOnce: [sdkbk32.exe] C:\WINDOWS\sdkbk32.exe
O4 - HKLM\..\RunOnce: [d3kg32.exe] C:\WINDOWS\d3kg32.exe
O4 - HKLM\..\RunOnce: [d3fu32.exe] C:\WINDOWS\system32\d3fu32.exe
O4 - HKLM\..\RunOnce: [crpu32.exe] C:\WINDOWS\system32\crpu32.exe
O4 - HKLM\..\RunOnce: [sysrc32.exe] C:\WINDOWS\sysrc32.exe
O4 - HKLM\..\RunOnce: [atlwn.exe] C:\WINDOWS\atlwn.exe
O4 - HKLM\..\RunOnce: [appsm.exe] C:\WINDOWS\appsm.exe
O4 - HKLM\..\RunOnce: [apitg32.exe] C:\WINDOWS\apitg32.exe
O4 - HKLM\..\RunOnce: [apihi.exe] C:\WINDOWS\apihi.exe
O4 - HKLM\..\RunOnce: [winwj.exe] C:\WINDOWS\winwj.exe
O4 - HKLM\..\RunOnce: [nettr.exe] C:\WINDOWS\nettr.exe
O4 - HKLM\..\RunOnce: [d3ee32.exe] C:\WINDOWS\d3ee32.exe
O4 - HKLM\..\RunOnce: [d3av.exe] C:\WINDOWS\system32\d3av.exe
O4 - HKLM\..\RunOnce: [ipyv.exe] C:\WINDOWS\ipyv.exe
O4 - HKLM\..\RunOnce: [msnm.exe] C:\WINDOWS\system32\msnm.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://intra.ifint.biz/nav.nsf/L?OpenPage&noCorporate
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://anu.popcap.com/games/popcaploader_v5.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = europe.ifint.biz
O17 - HKLM\Software\..\Telephony: DomainName = europe.ifint.biz
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = europe.ifint.biz