hijack this
Hjælp der foregår et eller andet med nogle pop up vinduer.Hijack vedlagt
ogfile of HijackThis v1.99.1
Scan saved at 14:43:10, on 05-04-2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINNT\system32\spoolsv.exe
C:\Programmer\Symantec AntiVirus\DefWatch.exe
C:\Programmer\Symantec AntiVirus\SavRoam.exe
C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe
C:\Programmer\Symantec AntiVirus\Rtvscan.exe
c:\winnt\system32\CISTUB.EXE
C:\WINNT\Explorer.EXE
C:\WINNT\System32\igfxtray.exe
C:\WINNT\System32\hkcmd.exe
C:\Programmer\Analog Devices\SoundMAX\SMTray.exe
C:\WINNT\System32\igfxpers.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINNT\System32\ctfmon.exe
C:\WINNT\System32\igfxsrvc.exe
C:\WINNT\System32\nvctrl.exe
C:\WINNT\System32\mssearchnet.exe
C:\Programmer\Ad-Protect\ad-protect.exe
C:\Programmer\Ad-Protect\ad-protect.exe
C:\Documents and Settings\sutru\Lokale indstillinger\Temp\Midlertidig mappe 2 for hijackthis.zip\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://intranet.stam.dk
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Nothing - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINNT\System32\hpFDAE.tmp
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Ad-Protect Toolbar - {EA038DDD-0FE0-41f5-BA60-FC3660529E71} - C:\Programmer\Ad-Protect\ToolBand.dll
O4 - HKLM\..\Run: [SchedulingAgent] mstinit.exe /firstlogon
O4 - HKLM\..\Run: [IgfxTray] C:\WINNT\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Programmer\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [AlternaTIFF] C:\WINNT\regedit.exe /s C:\Programmer\AlternaTIFF\AlternaTIFF.reg
O4 - HKLM\..\Run: [GWAdrBook] Regedit.exe /s C:\WINNT\System32\GWMailbox.reg
O4 - HKLM\..\Run: [SyncMode] C:\WINNT\regedit.exe /s C:\WINNT\System32\SyncMode5.reg
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [Persistence] C:\WINNT\System32\igfxpers.exe
O4 - HKLM\..\Run: [STAMPowerSettings] C:\WINNT\System32\wscript.exe //B C:\WINNT\System32\SetPowerSettings.cis
O4 - HKLM\..\Run: [DeaktivateBHOIE] C:\WINNT\Regedit.exe /S C:\WINNT\System32\DeativateAcrobatIE.reg
O4 - HKLM\..\Run: [AlternaTIFF1] C:\WINNT\System32\Regsvr32.exe /s C:\Programmer\AlternaTIFF\alttiff.ocx
O4 - HKLM\..\Run: [OPUSIEzone] C:\WINNT\regedit.exe /s C:\WINNT\System32\OPUSIEzone.reg
O4 - HKLM\..\Run: [NoGWupdate] "Regedit.exe /s C:\novell\noGWupdate.reg"
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NOAdobeUpdate] "Regedit.exe /s C:\Programmer\Adobe\Acrobat 7.0\NoAdobeUpdate.reg"
O4 - HKLM\..\Run: [Ad-Protect] C:\Programmer\Ad-Protect\ad-protect.exe /s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O14 - IERESET.INF: START_PAGE_URL= "http://intranet.stam.dk
O14 - IERESET.INF: MS_START_PAGE_URL= "http://intranet.stam.dk
O15 - Trusted Zone: http://*.ggst.dk
O15 - Trusted Zone: http://*.scandihealth.net
O15 - Trusted Zone: http://*.stam.dk
O15 - Trusted Zone: http://*.ggst.dk (HKLM)
O15 - Trusted Zone: http://*.scandihealth.net (HKLM)
O15 - Trusted Zone: http://*.srvarh120 (HKLM)
O15 - Trusted Zone: http://*.srvarh121 (HKLM)
O15 - Trusted Zone: http://*.stam.dk (HKLM)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = stam.dk
O17 - HKLM\Software\..\Telephony: DomainName = stam.dk
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = stam.dk
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = stam.dk
O20 - Winlogon Notify: igfxcui - C:\WINNT\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: CapaInstaller Agent Service (CISTUB) - CapaSystems A/S - c:\winnt\system32\CISTUB.EXE
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Programmer\Symantec AntiVirus\DefWatch.exe
O23 - Service: NetOp Helper ver. 7.60 (2003146) (NetOp Host for NT Service) - Danware Data A/S - C:\NetOp\HOST\NHOSTSVC.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Programmer\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmer\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Programmer\Symantec AntiVirus\Rtvscan.exe