Avatar billede george Nybegynder
13. september 2004 - 16:55 Der er 10 kommentarer og
1 løsning

Min computer opfører sig underligt igen

Har kørt Spybot, Ad-aware, HijackThis og har denne logfil.

Logfile of HijackThis v1.98.0
Scan saved at 10:49:50 PM, on 9/13/2004
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\AccessManager\Client\AMBroker.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\AccessManager\Client\sygman.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\GPQ\Pad32.exe
C:\GPQ\Fahid.exe
C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE
C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
C:\Program Files\AccessManager\Client\AccessMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\Adaptec\EASYCD~1\CreateCD\createcd.exe
C:\WINNT\system32\MSsrvs32.exe
C:\WINNT\system32\internat.exe
C:\WINNT\system32\conime.exe
C:\Program Files\EPSON\EPSON SMART PANEL for Scanner\EspMain.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINNT\System32\SCardSvr.exe
C:\WINNT\explorer.exe
C:\download\HijackThis\hijackthis.exe

O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {65FB335A-9E13-5093-8602-605509AA2817} - C:\WINNT\system32\rcp.dll
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINNT\2_0_1browserhelper2.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Pad32] C:\GPQ\Pad32.exe
O4 - HKLM\..\Run: [FAhid] C:\GPQ\Fahid.exe
O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h
O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
O4 - HKLM\..\Run: [AccessManager] C:\Program Files\AccessManager\Client\AccessMgr.exe
O4 - HKLM\..\Run: [Microsoft Visual Studio VSA] varpc32.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Microsoft Video Capture Controls] MSsrvs32.exe
O4 - HKLM\..\Run: [CreateCD] C:\PROGRA~1\Adaptec\EASYCD~1\CreateCD\createcd.exe -r
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKLM\..\RunServices: [Microsoft Visual Studio VSA] varpc32.exe
O4 - HKLM\..\RunServices: [Microsoft Video Capture Controls] MSsrvs32.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [Microsoft Video Capture Controls] MSsrvs32.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON SMART PANEL for Scanner.lnk = C:\Program Files\EPSON\EPSON SMART PANEL for Scanner\EspMain.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: Comshare DecisionWeb Applets - http://212.130.45.167/deciweb/cdweb/classes/DecisionWeb.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=b67e34f990e464e775745674cbeabb816653af1ae4b34dfc3830479d4b7482ede88853985ee0d776ee7c8b5fdc6800913b434d12389000c33ef8d83585ef67ca:d36e1cf1c98c452b76dffc4cecfcdd55
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
Avatar billede resist Nybegynder
13. september 2004 - 17:26 #1
Download denne engangsscanner: http://www.mwti.net/download/tools/mwav.exe

Genstart i fejlsikret tilstand (F8 i opstart). Tag en scanning med mwav.exe – aktiver så den scanner mest muligt (alle filer og mapper m.m.).

Når scanneren er færdig, genstarter du normalt og kopierer en ny log fra HijackThis herind. Brug venligst denne nyere version af HijackThis: http://danborg.org/spy/HJT/hijackthis.exe - tak.
Avatar billede george Nybegynder
14. september 2004 - 10:44 #2
Jeg har prøvet at få min pc til at kører i "safe mode", det kan den ikke. Det er vist bedst at jeg laver en reinstalling. Tak for hjælpen. Lav et svar så du kan få dine point.
Avatar billede resist Nybegynder
14. september 2004 - 13:18 #3
Du kan eventuelt prøve at køre mwav.exe fra normaltilstand.
Avatar billede resist Nybegynder
14. september 2004 - 13:31 #4
Eller vi kan prøve at snuppe ”snavset” manuelt? Bare sig til, hvis vi skal prøve.
Avatar billede george Nybegynder
15. september 2004 - 22:35 #5
Vi kan godt prøve at fjerne snavset manuelt.
Avatar billede resist Nybegynder
16. september 2004 - 06:40 #6
Tryk på Ctrl+Alt+ Delete

Afslut disse processer:
varpc32.exe
MSsrvs32.exe

Herunder er der nogle filer, som du skal fixe. Sæt en vinge ud for disse filer. Når du har gjort det, så lukker du alle andre vinduer ned.

Fix disse med HijackThis:

O2 - BHO: (no name) - {65FB335A-9E13-5093-8602-605509AA2817} - C:\WINNT\system32\rcp.dll
O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINNT\2_0_1browserhelper2.dll (file missing)

---
Kender du selv disse programmer. Hvis ikke så fix dem.
O4 - HKLM\..\Run: [Pad32] C:\GPQ\Pad32.exe
O4 - HKLM\..\Run: [FAhid] C:\GPQ\Fahid.exe
---

O4 - HKLM\..\Run: [Microsoft Visual Studio VSA] varpc32.exe
O4 - HKLM\..\Run: [Microsoft Video Capture Controls] MSsrvs32.exe
O4 - HKLM\..\RunServices: [Microsoft Visual Studio VSA] varpc32.exe
O4 - HKLM\..\RunServices: [Microsoft Video Capture Controls] MSsrvs32.exe
O4 - HKCU\..\Run: [Microsoft Video Capture Controls] MSsrvs32.exe

O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=b67e34f990e464e775745674cbeabb816653af1ae4b34dfc3830479d4b7482ede88853985ee0d776ee7c8b5fdc6800913b434d12389000c33ef8d83585ef67ca:d36e1cf1c98c452b76dffc4cecfcdd55

----
Åbn en mappe, klik på Funktioner=>Mappeindstillinger=>Vis.
Fjern flueben ved "Skjul beskyttede operativsystemfiler".
Fjern flueben ved "Skjul filtypenavne for kendte filtyper".
Sæt prik i "Vis skjulte filer og mapper".
----

Find og slet:

C:\WINNT\system32\MSsrvs32.exe >>>> filen

Brug Start > Søg. Find og slet: varpc32.exe


Genstart.

Tag en scanning med http://www.mwti.net/download/tools/mwav.exe - aktiver så den scanner mest muligt

Send herefter en ny HijackThis-log herind – tak.
Avatar billede resist Nybegynder
16. september 2004 - 06:42 #7
Brug venligst denne nyere version af HijackThis: http://danborg.org/spy/HJT/hijackthis.exe - tak.
Avatar billede george Nybegynder
17. september 2004 - 16:22 #8
Done!

Her er logfilen fra eScan : Skal nogle af disse filer slettes ? Tænker herpå "No Action Taken".

File C:\WINNT\mmdcd.exe tagged as not-a-virus:RiskWare.ftp.Serv-U.3017. No Action Taken.
File C:\WINNT\system32\\NtlogonWrk.EXE tagged as not-a-virus:RiskWare.RemoteAdmin.RA.3826. No Action Taken.
File C:\WINNT\mmdcd.exe tagged as not-a-virus:RiskWare.ftp.Serv-U.3017. No Action Taken.
File C:\WINNT\mmdcd.exe tagged as not-a-virus:RiskWare.ftp.Serv-U.3017. No Action Taken.
File C:\WINNT\system32\ntlogonwrk.exe tagged as not-a-virus:RiskWare.RemoteAdmin.RA.3826. No Action Taken.
File C:\Documents and Settings\CC\Local Settings\Temporary Internet Files\Content.IE5\3T0NZJIG\leveringstider forar 2001.xls infected by "BkCln.Unknown" Virus. Action Taken: File Renamed.
File C:\WINNT\mmdcd.exe tagged as not-a-virus:RiskWare.ftp.Serv-U.3017. No Action Taken.
File C:\WINNT\msdownld.tmp\_dll\ftp\service.exe tagged as not-a-virus:RiskWare.ftp.SlimFTPd.314. No Action Taken.
File C:\WINNT\msdownld.tmp\_dll\mmdcd.exe tagged as not-a-virus:RiskWare.ftp.Serv-U.3017. No Action Taken.
File C:\WINNT\msdownld.tmp\_dll\ntlogonwrk.exe tagged as not-a-virus:RiskWare.RemoteAdmin.RA.3826. No Action Taken.
File C:\WINNT\msdownld.tmp\_dll\services2.exe tagged as not-a-virus:RiskWare.Tool.Hideout. No Action Taken.
File C:\WINNT\msdownld.tmp\_dll\services3.exe tagged as not-a-virus:RiskWare.Tool.Hideout. No Action Taken.
File C:\WINNT\system32\ntlogonwrk.exe tagged as not-a-virus:RiskWare.RemoteAdmin.RA.3826. No Action Taken.
File C:\WINNT\mmdcd.exe tagged as not-a-virus:RiskWare.ftp.Serv-U.3017. No Action Taken.
File C:\WINNT\msdownld.tmp\_dll\ftp\service.exe tagged as not-a-virus:RiskWare.ftp.SlimFTPd.314. No Action Taken.
File C:\WINNT\msdownld.tmp\_dll\mmdcd.exe tagged as not-a-virus:RiskWare.ftp.Serv-U.3017. No Action Taken.
File C:\WINNT\msdownld.tmp\_dll\ntlogonwrk.exe tagged as not-a-virus:RiskWare.RemoteAdmin.RA.3826. No Action Taken.
File C:\WINNT\msdownld.tmp\_dll\services2.exe tagged as not-a-virus:RiskWare.Tool.Hideout. No Action Taken.
File C:\WINNT\msdownld.tmp\_dll\services3.exe tagged as not-a-virus:RiskWare.Tool.Hideout. No Action Taken.
File C:\WINNT\system32\ntlogonwrk.exe tagged as not-a-virus:RiskWare.RemoteAdmin.RA.3826. No Action Taken.

HijackThis logfil :
Logfile of HijackThis v1.98.2
Scan saved at 10:15:44 PM, on 9/17/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\AccessManager\Client\AMBroker.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINNT\SYSTEM32\DNTUS26.EXE
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\hidserv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\AccessManager\Client\sygman.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\mmdcd.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\GPQ\Pad32.exe
C:\GPQ\Fahid.exe
C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE
C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
C:\Program Files\AccessManager\Client\AccessMgr.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\PROGRA~1\Adaptec\EASYCD~1\CreateCD\createcd.exe
C:\WINNT\system32\internat.exe
C:\WINNT\system32\conime.exe
C:\Program Files\EPSON\EPSON SMART PANEL for Scanner\EspMain.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Softmate\IPSwitcher Basic\IPSwitcherBasic.exe
C:\download\HijackThis\hijackthis.exe

O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [InstantAccess] C:\PROGRA~1\TEXTBR~1.0\Bin\INSTAN~1.EXE /h
O4 - HKLM\..\Run: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
O4 - HKLM\..\Run: [AccessManager] C:\Program Files\AccessManager\Client\AccessMgr.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [CreateCD] C:\PROGRA~1\Adaptec\EASYCD~1\CreateCD\createcd.exe -r
O4 - HKLM\..\RunServices: [RegisterDropHandler] C:\PROGRA~1\TEXTBR~1.0\Bin\REGIST~1.EXE
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON SMART PANEL for Scanner.lnk = C:\Program Files\EPSON\EPSON SMART PANEL for Scanner\EspMain.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: Comshare DecisionWeb Applets - http://212.130.45.167/deciweb/cdweb/classes/DecisionWeb.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
Avatar billede resist Nybegynder
18. september 2004 - 10:19 #9
Jeg kan se, at du har fixet disse to:
O4 - HKLM\..\Run: [Pad32] C:\GPQ\Pad32.exe
O4 - HKLM\..\Run: [FAhid] C:\GPQ\Fahid.exe

Kender du dem ikke? De findes i denne mappe: C:\GPQ\
Hvad er der ellers i denne mappe.

Dette program har jeg lidt svært ved at finde noget på: C:\WINNT\mmdcd.exe >>> højreklik eventuelt og se egenskaber for filen.

Angående: msdownld.tmp:
http://www.jsiinc.com/SUBI/tip4000/rh4052.htm
og http://support.microsoft.com/default.aspx?scid=http://support.microsoft.com:80/support/kb/articles/316/5/40.asp&NoWebContent=1


Du skal have tømt din midlertidige Internetfiler.

Hvordan kører computeren?

Du kan eventuelt prøve at tage en scanning med en eller flere af disse onlinescannere:

Housecall: http://housecall.trendmicro.com/
Panda: http://www.pandasoftware.com/activescan/com/activescan_principal.htm
BitDefender: http://www.bitdefender.com/scan/license.php
Avatar billede george Nybegynder
18. september 2004 - 13:34 #10
Jeg mener at GPQ er skriveplade ( Pad ) jeg har prøvet på et tidspunkt. Det sletter jeg, den skal ikke bruges mere.

Jeg har heller ikke kunnet finde noget om mmdcd.exe så den glemmer vi bare. Måske finder jeg noget senere om den fil.

Hvad mener du med :
Angående: msdownld.tmp:
http://www.jsiinc.com/SUBI/tip4000/rh4052.htm
og http://support.microsoft.com/default.aspx?scid=http://support.microsoft.com:80/support/kb/articles/316/5/40.asp&NoWebContent=1

Skal det slettes eller hva ?

Midlertidige filer slettet.

Ja den kører meget bedre nu.

Tak får hjælpen, jeg prøver lige onlinescannerne.
Avatar billede resist Nybegynder
18. september 2004 - 17:25 #11
Velbekomme ;-)

Du kan eventuelt prøve at slette msdownld.tmp og lade være med at tømme skraldespanden. Prøv det af i en uges tid, og hvis det ikke giver problemer, kan du tømme skraldespanden.

Her er et link til sikker surfing: http://www.spywarefri.dk/pakken.htm
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester