Hijack this
Vil I være søde at tjekke min log?Logfile of HijackThis v1.98.2
Scan saved at 15:31:45, on 19-09-2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\SYSTEM32\DNTUS26.EXE
C:\WINNT\System32\svchost.exe
C:\RECYCLER\S-1-5-21-0606982848-1057904186-854245398-1003\itnalispyf.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\spolsv.exe
C:\WINNT\system32\stisvc.exe
c:\winnt\system32\FireDaemon.EXE
C:\WINNT\system32\mspmspsv.exe
c:\winnt\system32\winlogin.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\MSDEV.EXE
C:\programmer\umsd tools2.33\umsd.exe
C:\WINNT\system32\winlog0n.exe
C:\WINNT\system32\internat.exe
C:\sp.exe
C:\WINNT\System32\svchost.exe
C:\Programmer\Opera7\Opera.exe
C:\Documents and Settings\Susan Pape\Skrivebord\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.wowsearch.org/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.wowsearch.org/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://http://dk.search.yahoo.com/search/dk/options?p=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.wowsearch.org/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.wowsearch.org/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?p=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O3 - Toolbar: (no name) - {69550BE2-9A78-11d2-BA91-00600827878D} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WinampAgent] "C:\Programmer\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [ExplorerTask] C:\WINNT\Fonts\explorer.exe
O4 - HKLM\..\Run: [TaskMan] C:\WINNT\Fonts\rundll32.exe
O4 - HKLM\..\Run: [Explorer] c:\winnt\system\expl32.exe
O4 - HKLM\..\Run: [messnger] C:\WINNT\system32\Dvldr32.exe
O4 - HKLM\..\Run: [winapildr] C:\Programmer\explore.EXE
O4 - HKLM\..\Run: [explore] C:\Programmer\explore.exe
O4 - HKLM\..\Run: [Configuration Loader] MSDEV.EXE
O4 - HKLM\..\Run: [SpoolService] spolsv.exe
O4 - HKLM\..\Run: [PLoader] c:\programmer\umsd tools2.33\umsd.exe sys_auto_run C:\Programmer\UMSD Tools2.33
O4 - HKLM\..\Run: [Windows Firewall] winlog0n.exe
O4 - HKLM\..\Run: [dllhost.exe] C:\WINNT\system32\dllhost.exe
O4 - HKLM\..\RunServices: [Configuration Loader] MSDEV.EXE
O4 - HKLM\..\RunServices: [SpoolService] spolsv.exe
O4 - HKLM\..\RunServices: [Windows Firewall] winlog0n.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [CFDStart] C:\WINNT\WinMuschi.exe -m
O4 - HKCU\..\Run: [sp] C:\sp.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {10000000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!http://www.free32.com/POP.CHM::/sp.exe