Jeg er ramt en trojansk hest,der bliver ved med at ændre min startside, selv om jeg prøver at holde rent i PC’eren.
Log fra HijackThis:
Logfile of HijackThis v1.97.7
Scan saved at 10:38:28, on 16-05-2004
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:/WINNT/MS/SMS/CORE/BIN/CLISVCL.EXE
C:/WINNT/MS/SMS/clicomp/apa/Bin/smsapm32.exe
C:/WINNT/system32/control.exe
C:/WINNT/Explorer.EXE
C:/WINNT/System32/hkcmd.exe
C:/Programmer/NavNT/vptray.exe
C:/WINNT/MS/SMS/CORE/BIN/LAUNCH32.EXE
C:/WINNT/vpnloginapplet.exe
C:/PROGRA~1/BILLPS~1/WINPAT~1/WinPatrol.exe
C:/Programmer/COMPAQ/Easy Access Button Support/STARTEAK.exe
C:/PROGRA~1/Grisoft/AVG6/avgcc32.exe
C:/WINNT/System32/ctfmon.exe
C:/WINNT/MS/SMS/CLICOMP/SWDist32/bin/smsmon32.exe
C:/Programmer/Compaq/Easy Access Button Support/CPQEAKSYSTEMTRAY.EXE
C:/Programmer/Compaq/Easy Access Button Support/CPQEADM.EXE
C:/Compaq/EAKDRV/EAUSBKBD.EXE
C:/PROGRA~1/Compaq/EASYAC~1/BttnServ.exe
C:/WINNT/system32/proquota.exe
C:/Programmer/Internet Explorer/IEXPLORE.EXE
C:/WINNT/system32/control.exe
C:/Programmer/Outlook Express/msimn.exe
C:/Temp/Download/HijackThis.exe
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,SearchURL = http://www.searchmaniacs.net/search.html
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Bar = http://inline/applikationer/findemaskine
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Search Page = res://C:/WINNT/System32/opfjfp.dll/sp.html (obfuscated)
R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Start Page = http://www.google.dk/
R1 - HKCU/Software/Microsoft/Internet Explorer/Search,SearchAssistant = res://C:/WINNT/System32/opfjfp.dll/sp.html (obfuscated)
R1 - HKLM/Software/Microsoft/Internet Explorer,SearchURL = http://4-counter.com/?a=2&b=enc
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,SearchURL = http://www.searchmaniacs.net/search.html
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Search Bar = res://C:/WINNT/System32/opfjfp.dll/sp.html (obfuscated)
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Search Page = res://C:/WINNT/System32/opfjfp.dll/sp.html (obfuscated)
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Page_URL = res://mshp.dll/index.html#37049
R1 - HKLM/Software/Microsoft/Internet Explorer/Main,Default_Search_URL = http://homepage.com@www.e-finder.cc/search/ (obfuscated)
R0 - HKLM/Software/Microsoft/Internet Explorer/Search,CustomizeSearch = http://homepage.com@www.e-finder.cc/search/ (obfuscated)
R0 - HKLM/Software/Microsoft/Internet Explorer/Search,SearchAssistant = res://C:/WINNT/System32/opfjfp.dll/sp.html (obfuscated)
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,Window Title = Microsoft Internet Explorer leveret af DR
R1 - HKCU/Software/Microsoft/Internet Explorer/SearchURL,(Default) = http://1-se.com/home.html (obfuscated)
R1 - HKCU/Software/Microsoft/Internet Explorer/Main,HomeOldSP = about:blank
R0 - HKCU/Software/Microsoft/Internet Explorer/Toolbar,LinksFolderName = Hyperlinks
R1 - HKLM/Software/Microsoft/Internet Explorer,Search = http://in.webcounter.cc/—/?bzbjr (obfuscated)
R1 - HKLM/Software/Microsoft/Internet Explorer/Search,(Default) = http://homepage.com@www.e-finder.cc/search/ (obfuscated)
O1 - Hosts: 1089288654 #uto.search.msn.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:/PROGRA~1/SPYBOT~1/SDHelper.dll
O2 - BHO: (no name) - {9009A3EE-97E0-4755-A82A-AFF935C163A6} - C:/WINNT/System32/opfjfp.dll (file missing)
O2 - BHO: (no name) - {9F5B4E53-8984-4C9B-81B5-2F89321F5ABD} - C:/WINNT/System32/hfgacbc.dll (file missing)
O2 - BHO: (no name) - {B106C7D5-BB8D-4DB4-A27C-03ABB73C5413} - C:/WINNT/System32/mhdnf.dll (file missing)
O2 - BHO: (no name) - {C72E3182-DCCD-44FB-B153-E6D510136994} - C:/WINNT/System32/cbddjla.dll (file missing)
O2 - BHO: (no name) - {CE7C3CF0-4B15-11D1-ABED-709549C10000} - C:/WINNT/system32/StopzillaBH0.dll
O2 - BHO: (no name) - {D540364A-28B5-48A7-8F87-0943078C24AD} - (no file)
O2 - BHO: (no name) - {FC84F334-5168-4D22-91D4-D62897E92E8F} - C:/WINNT/System32/kgpcf.dll (file missing)
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:/WINNT/System32/msdxm.ocx
O4 - HKLM/../Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM/../Run: [HotKeysCmds] C:/WINNT/System32/hkcmd.exe
O4 - HKLM/../Run: [QuickTime Task] “C:/Programmer/QuickTime/qttask.exe” -atboottime
O4 - HKLM/../Run: [vptray] C:/Programmer/NavNT/vptray.exe
O4 - HKLM/../Run: [SMS Application Launcher] C:/WINNT/MS/SMS/CORE/BIN/LAUNCH32.EXE
O4 - HKLM/../Run: [VpnLoginApplet] C:/WINNT/vpnloginapplet
O4 - HKLM/../Run: [NeroCheck] C:/WINNT/system32/NeroCheck.exe
O4 - HKLM/../Run: [WinPatrol] C:/PROGRA~1/BILLPS~1/WINPAT~1/WinPatrol.exe
O4 - HKLM/../Run: [ElbyCheckElbyCDFL] “C:/Programmer/Elaborate Bytes/CloneCD/ElbyCheck.exe” /L ElbyCDFL
O4 - HKLM/../Run: [CPQEASYACC] C:/Programmer/COMPAQ/Easy Access Button Support/STARTEAK.exe
O4 - HKLM/../Run: [AVG_CC] C:/PROGRA~1/Grisoft/AVG6/avgcc32.exe /STARTUP
O4 - HKCU/../Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: emptemp2.lnk = C:/Programmer/Empty Temp Folders 2.8.3/emptemp2.exe
O6 - HKCU/Software/Policies/Microsoft/Internet Explorer/Control Panel present
O7 - HKCU/Software/Microsoft/Windows/CurrentVersion/Policies/System, DisableRegedit=1
O8 - Extra context menu item: E&ksporter; til Microsoft Excel - res://C:/PROGRA~1/MICROS~2/Office10/EXCEL.EXE/3000
O8 - Extra context menu item: Translate Page - res://c:/winnt/GoogleToolbar_en_2.0.95-big.dll/cmtrans.html
O8 - Extra context menu item: Web Search - C:/WINNT/ex.htm
O9 - Extra button: Microsoft® JavaScript® Console (HKLM)
O9 - Extra ‘Tools’ menuitem: JavaScript Console (HKLM)
O9 - Extra button: Microsoft® JavaScript® Console (HKCU)
O9 - Extra ‘Tools’ menuitem: JavaScript Console (HKCU)
O13 - DefaultPrefix: http://ehttp.cc/?
O13 - WWW Prefix: http://ehttp.cc/?
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/da/big/1.1.62-big/GoogleNav.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9b935470-ad4a-11d5-b63e-00c04faedb18} (Oracle JInitiator 1.1.8.16) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM/System/CCS/Services/Tcpip/Parameters: Domain = net.dr.dk
O17 - HKLM/System/CS1/Services/Tcpip/Parameters: Domain = net.dr.dk
O17 - HKLM/System/CS2/Services/Tcpip/Parameters: Domain = net.dr.dk
O19 - User stylesheet: C:/WINNT/hh.htt (HKLM)
