HiJackThis log
Hej eksperter,Jeg sidder ved en pc, som jeg tror er hijacked.
Selvom min startside i IE står til "blank", så bliver jeg smidt ind på en slags portalside, hver gang jeg starter IE.
Desuden får jeg ofte popups med fake beskeder om at min computer er inficeret med spyware.
Jeg har scannet min computer med HiJackThis og her kommer min log. Jeg håber I kan hjælpe mig!!
---------------------------------
Logfile of HijackThis v1.98.2
Scan saved at 09:05:00, on 14-02-2005
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\SCardSvr.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\Programmer\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
C:\WINNT\System32\rundll32.exe
C:\WINNT\System32\internat.exe
C:\Programmer\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
C:\Documents and Settings\sbp\Skrivebord\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\sbp\LOKALE~1\Temp\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\sbp\LOKALE~1\Temp\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E35B6A2-CFAE-451E-83AE-4553317F7FFC} - C:\WINNT\System32\omle.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [vptray] C:\Programmer\Symantec_Client_Security\Symantec AntiVirus\vptray.exe
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\spa\LOKALE~1\Temp\se.dll,DllInstall
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Programmer\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://housecall.trendmicro-europe.com/housecall/Xscan53.cab
O16 - DPF: {C07E5288-22FB-11D7-962E-0004AC77C761} (Dataloen.ctlVirtuelDesktop) - http://activex.dataloen.dk/controls/Dataloen3311.CAB
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = hh.lan
O17 - HKLM\System\CCS\Services\Tcpip\..\{4564554E-E000-473D-9ECA-2429D7D77959}: NameServer = 192.168.20.10,193.88.44.22
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = hh.lan
O17 - HKLM\System\CS1\Services\Tcpip\..\{4564554E-E000-473D-9ECA-2429D7D77959}: NameServer = 192.168.20.10,193.88.44.22
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = hh.lan
O17 - HKLM\System\CS2\Services\Tcpip\..\{4564554E-E000-473D-9ECA-2429D7D77959}: NameServer = 192.168.20.10,193.88.44.22
O18 - Filter: text/html - {5EF4AE84-AA69-4B64-B14E-3678CE4DC0ED} - C:\WINNT\System32\omle.dll
O18 - Filter: text/plain - {5EF4AE84-AA69-4B64-B14E-3678CE4DC0ED} - C:\WINNT\System32\omle.dll
