Ursprungligen inskrivet av Robilibob
här är loggfilen:
Logfile of HijackThis v1.97.7
Scan saved at 20:43:15, on 2005-01-24
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\system32\hb184h3b7mjymthd.exe
C:\Program\Messenger\Msmsgs.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://win-eto.com/sp.htm?id=33464
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://win-eto.com/sp.htm?id=33464
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://win-eto.com/hp.htm?id=33464
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://win-eto.com/hp.htm?id=33464
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://win-eto.com/sp.htm?id=33464
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lookfor.cc?pin=44768
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://win-eto.com/hp.htm?id=33464
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lookfor.cc?pin=44768
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://lookfor.cc/sp.php?pin=44768
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar
O2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINDOWS\system32\UD6HJ5~1.DLL
O4 - HKLM\..\Run: [AQ3HelperStartUp] C:\Program\AQUATI~1\AQ3HEL~1.EXE /partner AQ3
O4 - HKLM\..\Run: [CloseLicenseInfoCorn] C:\Documents and Settings\All Users\Application Data\ROADBINDCLOSELICENSE\city beep.exe
O4 - HKLM\..\Run: [HopeShowEggsByte] C:\Documents and Settings\All Users\Application Data\PLAYGREATHOPESHOW\ownsinside.exe
O4 - HKLM\..\Run: [Control handler] C:\WINDOWS\system32\hb184h3b7mjymthd.exe
O4 - HKLM\..\Run: [KqP4lEE] C:\WINDOWS\qxotyw.exe
O4 - HKLM\..\Run: [sais] c:\program\180solutions\sais.exe
O4 - HKLM\..\Run: [fhIRjBZ] C:\WINDOWS\qxotyw.exe
O4 - HKLM\..\Run: [<°b@¡•§TlY«f°EÀ‡ÀÌC:\Program\ISTsvc\istsvc.exe] C:\WINDOWS\qxotyw.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program\Messenger\Msmsgs.exe" /background
O4 - HKCU\..\Run: [Spyware Begone] c:\freescan\freescan.exe -FastScan
O4 - HKCU\..\Run: [Spyware Vanisher] c:\spywarevanisher-free\FreeScanner.exe -FastScan
O4 - Global Startup: GStartup.lnk = C:\Program\Delade filer\GMT\GMT.exe
O16 - DPF: {22A88341-AFCB-45F0-A856-C2BAE74F878E} (InstallX Class) - http://www.20x2p.com/5c5878e7/enter.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/085980f18b2535ffb218/netzip/RdxIE...
O16 - DPF: {706F3805-27D7-478D-80E5-E25D2BB030B3} (VacPro.internazionale_ver3) - http://www.advnt01.com/dialer/internazionale_ver3.CAB
O16 - DPF: {9E98E84C-79E1-49C3-82EB-798FCD552EFB} (VacPro.internazionale_ver4) - http://www.advnt01.com/dialer/internazionale_ver4.CAB
är det nåt skumt?
EDIT:
snälla hjälp mig nu!
kommer upp sådana här fönster en gång i minuten: http://trenton.kicks-ass.net/store/ggg.jpg
varje gång är det olika exe-filer fast de ligger ungefär på samma ställe.
vad ska jag göra?