Er der en der vil se denne Hijackhis log igennem
Da jeg ikke har en rygende f.. forstand på log og hvordan den skal se ud, har jeg brug for jeres hjælp.Min maskine er igennem de sidst par md. blevet meget langsom i opstarten, og der kommer "forkerte" opstartssider på min Browswe når jeg starter.
Hvis der er en behjertet sjæl der kan hjælpe mig, er min dag reddet.
Logfile of HijackThis v1.98.2
Scan saved at 11:57:41, on 14-10-2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\Norman\NVC\BIN\Zanda.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\ipvv32.exe
C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
C:\NORMAN\nvc\BIN\NJEEVES.EXE
C:\NORMAN\Nvc\BIN\nipsvc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\Dit.exe
C:\Programmer\Microsoft Works\WksSb.exe
C:\WINDOWS\system32\winya32.exe
C:\NORMAN\Nvc\BIN\ZLH.EXE
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Programmer\Classic PhoneTools\CapFax.EXE
C:\Programmer\Medion\PowerCinema\My_TV\Agent.exe
C:\Programmer\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\NORMAN\Nvc\BIN\NYMSE.EXE
C:\NORMAN\Nvc\BIN\NIP.EXE
C:\WINDOWS\DitExp.exe
C:\Programmer\Labtec Trådløse Skrivebord\MagicKey.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\HijackThis\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lryvc.dll/sp.html#37680
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lryvc.dll/sp.html#37680
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\lryvc.dll/sp.html#37680
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\lryvc.dll/sp.html#37680
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\lryvc.dll/sp.html#37680
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\lryvc.dll/sp.html#37680
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Tiscali A/S - Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmer\google\googletoolbar2.dll
O2 - BHO: (no name) - {D990B9E1-F168-13E8-1A21-97D04D3C2F96} - C:\WINDOWS\system32\adddp32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmer\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Folder Service ] C:\Program Files\Common Files\Services\wssdtu.exe
O4 - HKLM\..\Run: [Enumeration Service ] C:\Program Files\Common Files\Services\wsys.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [appwt32.exe] C:\WINDOWS\system32\appwt32.exe
O4 - HKLM\..\Run: [winya32.exe] C:\WINDOWS\system32\winya32.exe
O4 - HKLM\..\Run: [ipxw.exe] C:\WINDOWS\system32\ipxw.exe
O4 - HKLM\..\Run: [Norman ZANDA] C:\NORMAN\Nvc\BIN\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [CapFax] C:\Programmer\Classic PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [Agent] C:\Programmer\Medion\PowerCinema\My_TV\Agent.exe
O4 - HKLM\..\Run: [STOPzilla] "C:\Programmer\STOPzilla!\Stopzilla.exe" /autorun
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Programmer\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [DeskMateAutoUpdate] C:\PROGRA~1\DESKMA~1\DeskMateAutoUpdate.exe
O4 - HKLM\..\Run: [ipqf32.exe] C:\WINDOWS\system32\ipqf32.exe
O4 - HKLM\..\RunOnce: [iemb.exe] C:\WINDOWS\system32\iemb.exe
O4 - HKLM\..\RunOnce: [apihg.exe] C:\WINDOWS\system32\apihg.exe
O4 - HKLM\..\RunOnce: [winfg.exe] C:\WINDOWS\system32\winfg.exe
O4 - HKLM\..\RunOnce: [addvp32.exe] C:\WINDOWS\system32\addvp32.exe
O4 - HKLM\..\RunOnce: [ieqg.exe] C:\WINDOWS\ieqg.exe
O4 - HKLM\..\RunOnce: [crbc.exe] C:\WINDOWS\system32\crbc.exe
O4 - HKLM\..\RunOnce: [atlvi.exe] C:\WINDOWS\system32\atlvi.exe
O4 - HKLM\..\RunOnce: [d3dt.exe] C:\WINDOWS\system32\d3dt.exe
O4 - HKLM\..\RunOnce: [d3av32.exe] C:\WINDOWS\system32\d3av32.exe
O4 - HKLM\..\RunOnce: [winsm32.exe] C:\WINDOWS\winsm32.exe
O4 - HKLM\..\RunOnce: [appjl.exe] C:\WINDOWS\appjl.exe
O4 - HKLM\..\RunOnce: [syslm32.exe] C:\WINDOWS\system32\syslm32.exe
O4 - HKLM\..\RunOnce: [netel.exe] C:\WINDOWS\system32\netel.exe
O4 - HKLM\..\RunOnce: [sdkne.exe] C:\WINDOWS\system32\sdkne.exe
O4 - HKLM\..\RunOnce: [ntki.exe] C:\WINDOWS\ntki.exe
O4 - HKLM\..\RunOnce: [msro.exe] C:\WINDOWS\system32\msro.exe
O4 - HKLM\..\RunOnce: [ntqc32.exe] C:\WINDOWS\system32\ntqc32.exe
O4 - HKLM\..\RunOnce: [iemb32.exe] C:\WINDOWS\iemb32.exe
O4 - HKLM\..\RunOnce: [addsb.exe] C:\WINDOWS\system32\addsb.exe
O4 - HKLM\..\RunOnce: [msrb.exe] C:\WINDOWS\msrb.exe
O4 - HKLM\..\RunOnce: [ieaq32.exe] C:\WINDOWS\ieaq32.exe
O4 - HKLM\..\RunOnce: [sdkek.exe] C:\WINDOWS\system32\sdkek.exe
O4 - HKLM\..\RunOnce: [syszv.exe] C:\WINDOWS\syszv.exe
O4 - HKLM\..\RunOnce: [iehq32.exe] C:\WINDOWS\iehq32.exe
O4 - HKLM\..\RunOnce: [mfcsg32.exe] C:\WINDOWS\mfcsg32.exe
O4 - HKLM\..\RunOnce: [msfv32.exe] C:\WINDOWS\system32\msfv32.exe
O4 - HKLM\..\RunOnce: [ntsx32.exe] C:\WINDOWS\system32\ntsx32.exe
O4 - HKLM\..\RunOnce: [ipgs.exe] C:\WINDOWS\system32\ipgs.exe
O4 - HKLM\..\RunOnce: [apiqo.exe] C:\WINDOWS\apiqo.exe
O4 - HKLM\..\RunOnce: [netrw.exe] C:\WINDOWS\system32\netrw.exe
O4 - HKLM\..\RunOnce: [netpv.exe] C:\WINDOWS\netpv.exe
O4 - HKLM\..\RunOnce: [d3fg32.exe] C:\WINDOWS\system32\d3fg32.exe
O4 - HKLM\..\RunOnce: [winue32.exe] C:\WINDOWS\system32\winue32.exe
O4 - HKLM\..\RunOnce: [apiyg32.exe] C:\WINDOWS\apiyg32.exe
O4 - HKLM\..\RunOnce: [javarc.exe] C:\WINDOWS\javarc.exe
O4 - HKLM\..\RunOnce: [d3xz32.exe] C:\WINDOWS\d3xz32.exe
O4 - HKLM\..\RunOnce: [apiok.exe] C:\WINDOWS\apiok.exe
O4 - HKLM\..\RunOnce: [javawc.exe] C:\WINDOWS\javawc.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Programmer\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Aktiver Labtec Trådløse Skrivebord.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\programmer\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm777
O8 - Extra context menu item: Add to filterlist (WebWasher) - http://-Web.Washer-/ie_add
O8 - Extra context menu item: Backward &Links - res://c:\programmer\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\programmer\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://c:\programmer\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\programmer\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} (WebResponseAttachments Control) - https://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab
O18 - Protocol: icoo - {4A8DADD4-5A25-4D41-8599-CB7458766220} - C:\WINDOWS\msopt.dll
Sådan viser hijackthis min log...
Hilsen Villy