HTJ log
Syntes ikke rigtig jeg er "herre" over hvad der foregår på maskinen.Logfile of HijackThis v1.99.1
Scan saved at 13:04:51, on 10-03-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\SKDAEMON.EXE
C:\WINDOWS\system32\ICO.EXE
C:\Programmer\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Programmer\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\PROGRA~1\xpoint\pe\PCRECSA.EXE
C:\Programmer\MSN Apps\Updater\01.02.3000.1001\da\msnappau.exe
C:\WINDOWS\system32\qhsjaip.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\Programmer\Norton Internet Security\NISUM.EXE
C:\WINDOWS\System32\NMSSvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\PROGRA~1\xpoint\xpadmin\xpadmin.exe
C:\PROGRA~1\xpoint\agent\Xpagent.exe
C:\Programmer\Norton Internet Security\ccPxySvc.exe
C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
C:\PROGRA~1\xpoint\EEClient\xpclient.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Temp\hjt.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = www.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://tv2.dk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchmiracle.com/sp.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: DLMaxObj Class - {00000000-59D4-4008-9058-080011001200} - C:\WINDOWS\dlmax.dll
O2 - BHO: (no name) - {29D06CD9-7436-4196-83D6-0C92BEC98E4B} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {2B743985-3FB1-43AC-8752-F56944D1BA92} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {2D838783-0A22-48C1-96E8-9769D1D0335D} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {331F36DC-E150-4438-9801-4D5D1B0D4195} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {3CE70C4F-4B13-4074-9F37-6982400A6086} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {44213C0E-B87C-4AD9-861E-958C63BC775E} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C7973EE-C52B-425C-81A7-32879733A359} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {608D98E4-B0F0-4FBE-8802-1EA66CFA4DC0} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {73A2B976-BD5D-4485-A5FE-245510C1BC02} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {751118F3-3A10-4FD8-86EF-FED3319487ED} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {7900341C-8E3E-40FA-98A7-44AE39E2EC73} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {7909D58C-2021-405C-B483-1C096EF99DAE} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {7994BB03-8CB2-4AC1-9A77-1ADF7769F809} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {79D770C9-9AAF-4941-82C5-2188AC66523D} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {866490C0-8793-4F66-B76B-1F51EFE86048} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {895DCD2D-6210-4FFE-AE8D-13E3051C2C8A} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {9527F10F-0BA1-4332-AA2B-67515708A45C} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {AD92E5E0-027E-488A-9735-0054645E4685} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {AFD77883-A5B6-4E07-A5AD-8BCA1ECEC59F} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {B110234B-C73A-4B21-A2D9-2772D2510384} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {B15EB5A1-0E7F-4A84-803D-4ABC47CC0F55} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {B946DD64-2D18-45A8-9F01-54E6613C7BDB} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {EA8ACA47-F4C0-4CF9-BCA3-AF4090400884} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {EBE6A75D-B11B-48A0-8974-5B1B5AF111B5} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O2 - BHO: (no name) - {F16ACDF9-0178-4B97-90C7-AC3BD9D035DE} - C:\Programmer\zh6f6v33\zh6f6v33.dll
O4 - HKLM\..\Run: [StorageGuard] "C:\Programmer\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Hot Key Kbd Daemon] SKDAEMON.EXE
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CTSysVol] C:\Programmer\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Programmer\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTStartup] "C:\Programmer\Creative\Splash Screen\CTEaxSpl.EXE" /run
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Programmer\Fælles filer\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [PCRecSA] C:\PROGRA~1\xpoint\pe\PCRECSA.EXE -noshow
O4 - HKLM\..\Run: [msnappau] "C:\Programmer\MSN Apps\Updater\01.02.3000.1001\da\msnappau.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [oloyvhaqbzx] C:\WINDOWS\system32\qhsjaip.exe
O4 - HKLM\..\Run: [antiware] C:\windows\system32\elitezjx32.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Programmer\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O12 - Plugin for .spop: C:\Programmer\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .tif: C:\Programmer\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: Nordea Online investering - https://www.onlineinvestering.nordea.dk/oiclient.nsf/files/client/$FILE/oiclient.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://host.cycore.net/plugins/windows/ie/Cult3D_IE_5.3.0.228.cab
O16 - DPF: {402EE96E-2CE8-482D-ADA5-CECEEA07E16D} (TurnTool Scene) - http://www.turntool.com/ViewerInstall.exe
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {8EC18CE2-D7B4-11D2-88C8-006008A717FD} (NCSView Class) - http://130.228.229.70/ecwplugins/ncs.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Programmer\Norton Internet Security\ccPxySvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Programmer\Norton Internet Security\NISUM.EXE
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Xpoint PCRadmin Server (PCRadminServer) - Unknown owner - C:\PROGRA~1\xpoint\pe\pcradmin.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FÆLLES~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Xpoint Admin Server (XPadminServer) - Unknown owner - C:\PROGRA~1\xpoint\xpadmin\xpadmin.exe
O23 - Service: Xpoint Agent Server (xpAgentServer) - Unknown owner - C:\PROGRA~1\xpoint\agent\Xpagent.exe