Hjælp til HJT log
Jeg har en bruger her på arbejde som jeg har følgende log fra.Nu har han fået samme virus i to dage i træk, men jeg kan ikke se noget direkte snavs. Kun ureglmæssigheder.
Logfile of HijackThis v1.97.7
Scan saved at 15:23:55, on 22-06-2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP1 (5.00.2920.0000)
Running processes:
M:\WINNT\system32\wfshell.exe
M:\Winnt\System32\wscript.exe
n:\NOTES\NLNOTES.EXE
N:\program files\pubexplorer\pubexplorer.exe
H:\XML\Værktøj\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://portalen
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://portalen
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://portalen
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = M:\WINNT\system32\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
F2 - REG:system.ini: UserInit=M:\WINNT\system32\userinit.exe,
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - M:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [UserJobs] m:\amows\userjobs.exe
O4 - HKLM\..\Run: [smbdpmi] M:\PROGRA~1\UMS\utils\smbdpmi.exe
O4 - HKLM\..\Run: [dllInit ibmasstw.dll] "M:\Program Files\UMS\utils\DLLINIT.EXE" ibmasstw.dll
O4 - Global Startup: Microsoft Office.lnk = N:\program files\Microsoft Office\Office\OSA9.EXE
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra 'Tools' menuitem: Launch Copernic 2001 (HKLM)
O9 - Extra button: Copernic (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O10 - Broken Internet access because of LSP provider 'm:\documents and settings\mol-cbm\windows\system32\rnr20.dll' missing
O16 - DPF: {86ecb6a0-400a-11d5-b638-00c04faedb18} -
O16 - DPF: {9b935470-ad4a-11d5-b63e-00c04faedb18} (Oracle JInitiator 1.1.8.16) -
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = berlingske.dk
O17 - HKLM\System\CCS\Services\Tcpip\..\{9BB17E87-4895-4C5A-92EC-CA795BAB014E}: Domain = berlingske.dk
O17 - HKLM\System\CCS\Services\Tcpip\..\{9BB17E87-4895-4C5A-92EC-CA795BAB014E}: NameServer = 10.19.1.60,10.19.2.60
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = berlingske.dk
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = berlingske.dk
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = berlingske.dk
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = berlingske.dk
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = berlingske.dk
