Hej kalp.
Jeg benytter 1.99 af Hijacks. Jeg har IKKE slettet noget i log filen. Men disse hot-search.com som du kan se en masse af, har jeg slettet før, men de kommer igen.
men her er log filen:
Logfile of HijackThis v1.99.1
Scan saved at 23:33:20, on 04-04-2005
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\GEARSec.exe
C:\WINNT\system32\hidserv.exe
C:\Program Files\NOD\nod32krn.exe
C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.exe
C:\WINNT\System32\RUNDLL32.EXE
C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINNT\SOUNDMAN.EXE
C:\WINNT\System32\internat.exe
E:\BPFTP Server\G6FTPSrv.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\Hijacks\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.hot-search.biz/index.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.hot-search.biz/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.hot-search.biz/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.hot-search.biz/search.htmlR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.hot-search.biz/index.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.hot-search.biz/index.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.hot-search.biz/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.hot-search.biz/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.hot-search.biz/search.htmlR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.hot-search.biz/index.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.hot-search.biz/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://www.hot-search.biz/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://www.hot-search.biz/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://www.hot-search.biz/search.htmlR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
http://www.hot-search.biz/index.htmlR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
http://www.hot-search.biz/index.htmlR3 - URLSearchHook: SurfingShield Toolbar - {796AF358-6E53-4E90-AB45-503C3C8D2891} - C:\Program Files\SurfingShield Toolbar\surfingshield.dll (file missing)
O2 - BHO: BHO - {06CAD548-14DD-4fa3-9EA9-05F83C18CBD7} - C:\WINNT\System32\mspxs32.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Reactivator Class - {6C31790D-1EDF-4b05-83DC-925B3A8E2318} - C:\Program Files\SurfingShield Toolbar\surfingshield.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: SurfingShield Toolbar - {796AF358-6E53-4E90-AB45-503C3C8D2891} - C:\Program Files\SurfingShield Toolbar\surfingshield.dll (file missing)
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Norton Ghost 9.0] C:\Program Files\Symantec\Norton Ghost\Agent\GhostTray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Win32SystemMonitor] C:\WINNT\System32\Tqk.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Win32 Time Zone] C:\WINNT\System32\explorer32.exe
O4 - HKLM\..\Run: [Kqq] C:\WINNT\Cgc.exe
O4 - HKLM\..\Run: [Ulc] C:\WINNT\System32\Dua.exe
O4 - HKLM\..\Run: [Qbl] C:\WINNT\System32\Pup.exe
O4 - HKLM\..\Run: [Iug] C:\WINNT\Kfe.exe
O4 - HKLM\..\Run: [Ilb] C:\WINNT\System32\Lft.exe
O4 - HKLM\..\Run: [Tbd] C:\WINNT\System32\Jhs.exe
O4 - HKLM\..\Run: [Adu] C:\WINNT\System32\Hjh.exe
O4 - HKLM\..\Run: [Ptv] C:\WINNT\System32\Gej.exe
O4 - HKLM\..\Run: [Eic] C:\WINNT\System32\Qbv.exe
O4 - HKLM\..\Run: [Dln] C:\WINNT\Cjd.exe
O4 - HKLM\..\Run: [Jjr] C:\WINNT\Bop.exe
O4 - HKLM\..\Run: [Mtd] C:\WINNT\Aum.exe
O4 - HKLM\..\Run: [Lgd] C:\WINNT\System32\Cie.exe
O4 - HKLM\..\Run: [Cdr] C:\WINNT\Jnd.exe
O4 - HKLM\..\Run: [Hhj] C:\WINNT\System32\Ska.exe
O4 - HKLM\..\Run: [Bsi] C:\WINNT\System32\Joa.exe
O4 - HKLM\..\Run: [Ctt] C:\WINNT\System32\Dei.exe
O4 - HKLM\..\Run: [Cpq] C:\WINNT\Ail.exe
O4 - HKLM\..\Run: [Taj] C:\WINNT\Blu.exe
O4 - HKLM\..\Run: [Vke] C:\WINNT\System32\Rri.exe
O4 - HKLM\..\Run: [Daa] C:\WINNT\Mne.exe
O4 - HKLM\..\Run: [Ddm] C:\WINNT\Mkl.exe
O4 - HKLM\..\Run: [Nna] C:\WINNT\Nil.exe
O4 - HKLM\..\Run: [Lar] C:\WINNT\Uao.exe
O4 - HKLM\..\Run: [Mim] C:\WINNT\System32\Seo.exe
O4 - HKLM\..\Run: [Nea] C:\WINNT\System32\Lmq.exe
O4 - HKLM\..\Run: [Acp] C:\WINNT\Ujs.exe
O4 - HKLM\..\Run: [Mff] C:\WINNT\Pih.exe
O4 - HKLM\..\Run: [Fud] C:\WINNT\System32\Bjc.exe
O4 - HKLM\..\Run: [Jne] C:\WINNT\System32\Nlu.exe
O4 - HKLM\..\Run: [Iqn] C:\WINNT\System32\Udr.exe
O4 - HKLM\..\Run: [Leh] C:\WINNT\Iuf.exe
O4 - HKLM\..\Run: [Len] C:\WINNT\Dga.exe
O4 - HKLM\..\Run: [Tpr] C:\WINNT\Its.exe
O4 - HKLM\..\Run: [Jqs] C:\WINNT\System32\Hcm.exe
O4 - HKLM\..\Run: [Kfj] C:\WINNT\Ftr.exe
O4 - HKLM\..\Run: [Vbk] C:\WINNT\Eml.exe
O4 - HKLM\..\Run: [Qkt] C:\WINNT\System32\Ohv.exe
O4 - HKLM\..\Run: [Jqv] C:\WINNT\System32\Fop.exe
O4 - HKLM\..\Run: [Edb] C:\WINNT\Tfg.exe
O4 - HKLM\..\Run: [Scb] C:\WINNT\Kpp.exe
O4 - HKLM\..\Run: [Ltf] C:\WINNT\Vpa.exe
O4 - HKCU\..\Run: [Kqq] C:\WINNT\Cgc.exe
O4 - HKCU\..\Run: [Win32SystemMonitor] C:\WINNT\System32\Tqk.exe
O4 - HKCU\..\Run: [iwfr] C:\PROGRA~1\COMMON~1\iwfr\iwfrm.exe
O4 - HKCU\..\Run: [Ulc] C:\WINNT\System32\Dua.exe
O4 - HKCU\..\Run: [Qbl] C:\WINNT\System32\Pup.exe
O4 - HKCU\..\Run: [Iug] C:\WINNT\Kfe.exe
O4 - HKCU\..\Run: [Ilb] C:\WINNT\System32\Lft.exe
O4 - HKCU\..\Run: [Tbd] C:\WINNT\System32\Jhs.exe
O4 - HKCU\..\Run: [Adu] C:\WINNT\System32\Hjh.exe
O4 - HKCU\..\Run: [Ptv] C:\WINNT\System32\Gej.exe
O4 - HKCU\..\Run: [Eic] C:\WINNT\System32\Qbv.exe
O4 - HKCU\..\Run: [Dln] C:\WINNT\Cjd.exe
O4 - HKCU\..\Run: [Jjr] C:\WINNT\Bop.exe
O4 - HKCU\..\Run: [Mtd] C:\WINNT\Aum.exe
O4 - HKCU\..\Run: [Lgd] C:\WINNT\System32\Cie.exe
O4 - HKCU\..\Run: [Cdr] C:\WINNT\Jnd.exe
O4 - HKCU\..\Run: [Hhj] C:\WINNT\System32\Ska.exe
O4 - HKCU\..\Run: [Bsi] C:\WINNT\System32\Joa.exe
O4 - HKCU\..\Run: [Ctt] C:\WINNT\System32\Dei.exe
O4 - HKCU\..\Run: [Cpq] C:\WINNT\Ail.exe
O4 - HKCU\..\Run: [Taj] C:\WINNT\Blu.exe
O4 - HKCU\..\Run: [Vke] C:\WINNT\System32\Rri.exe
O4 - HKCU\..\Run: [Daa] C:\WINNT\Mne.exe
O4 - HKCU\..\Run: [Ddm] C:\WINNT\Mkl.exe
O4 - HKCU\..\Run: [Nna] C:\WINNT\Nil.exe
O4 - HKCU\..\Run: [Lar] C:\WINNT\Uao.exe
O4 - HKCU\..\Run: [Mim] C:\WINNT\System32\Seo.exe
O4 - HKCU\..\Run: [Nea] C:\WINNT\System32\Lmq.exe
O4 - HKCU\..\Run: [Acp] C:\WINNT\Ujs.exe
O4 - HKCU\..\Run: [Mff] C:\WINNT\Pih.exe
O4 - HKCU\..\Run: [Fud] C:\WINNT\System32\Bjc.exe
O4 - HKCU\..\Run: [Jne] C:\WINNT\System32\Nlu.exe
O4 - HKCU\..\Run: [Iqn] C:\WINNT\System32\Udr.exe
O4 - HKCU\..\Run: [Leh] C:\WINNT\Iuf.exe
O4 - HKCU\..\Run: [Len] C:\WINNT\Dga.exe
O4 - HKCU\..\Run: [Tpr] C:\WINNT\Its.exe
O4 - HKCU\..\Run: [Jqs] C:\WINNT\System32\Hcm.exe
O4 - HKCU\..\Run: [Kfj] C:\WINNT\Ftr.exe
O4 - HKCU\..\Run: [Vbk] C:\WINNT\Eml.exe
O4 - HKCU\..\Run: [Qkt] C:\WINNT\System32\Ohv.exe
O4 - HKCU\..\Run: [Jqv] C:\WINNT\System32\Fop.exe
O4 - HKCU\..\Run: [Edb] C:\WINNT\Tfg.exe
O4 - HKCU\..\Run: [Scb] C:\WINNT\Kpp.exe
O4 - HKCU\..\Run: [HijackThis startup scan] C:\DOCUME~1\XXX\LOCALS~1\Temp\Rar$EX00.610\HijackThis.exe /startupscan
O4 - HKCU\..\Run: [Ltf] C:\WINNT\Vpa.exe
O4 - HKCU\..\Run: [Win32 Time Zone] C:\WINNT\System32\explorer32.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Startup: Shortcut to G6FTPSrv.exe.lnk = E:\BPFTP Server\G6FTPSrv.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O15 - Trusted IP range: 67.19.178.84
O15 - Trusted IP range: 67.19.178.84 (HKLM)
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} -
http://static.windupdates.com/cab/6247971CanadaInc/ie/bridge-c420.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) -
https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exeO17 - HKLM\System\CCS\Services\Tcpip\..\{B1FCA9BF-72B0-4004-90A7-AA71A39DCF51}: NameServer = 212.99.225.242,213.170.224.166
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINNT\System32\GEARSec.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Program Files\NOD\nod32krn.exe
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe