Avatar billede nop Nybegynder
06. maj 2006 - 12:10 Der er 3 kommentarer og
1 løsning

Hijack.log

Jeg er begynd at få processer der hænger ved luk, dwwin og en anden jeg ikke kan huske.
Her er en hijacj log, er der nogen der gider gi' den et kig?

Logfile of HijackThis v1.99.1
Scan saved at 12:07:50, on 06-05-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\adwiza\Sync\NSYNCSCH.exe
C:\WINDOWS\System32\cisvc.exe
C:\Programmer\Symantec AntiVirus\DefWatch.exe
C:\oracle\ora92\bin\omtsreco.exe
C:\oracle\ora92\BIN\TNSLSNR.exe
C:\Programmer\SAP Manage\SAP Business One ServerTools\SBOLicense\SBOLicense.exe
C:\Programmer\Symantec AntiVirus\SavRoam.exe
C:\Programmer\SAP Manage\SAP Business One ServerTools\SBODI_Server\SBODI_Server.exe
C:\Programmer\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Messenger\msmsgs.exe
C:\Programmer\Sybase\SQL Anywhere 9\win32\dbisqlg.exe
C:\Programmer\Sybase\Shared\Sybase Central 4.3\win32\scjview.exe
C:\Programmer\SAP Manage\SAP Business One ServerTools\Service Manager\ServerManager.exe
C:\Programmer\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Programmer\superoffice\SOEventServer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmer\Internet Explorer\iexplore.exe
C:\Documents and Settings\mka\Skrivebord\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [UC_Start] C:\IBMTools\Updater\ucstartup.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Client Access Service] "C:\Programmer\IBM\Client Access\cwbsvstr.exe"
O4 - HKLM\..\Run: [Client Access Help Update] "C:\Programmer\IBM\Client Access\cwbinhlp.exe"
O4 - HKLM\..\Run: [Client Access Check Version] "C:\Programmer\IBM\Client Access\cwbckver.exe" LOGIN
O4 - HKLM\..\Run: [Client Access Express Welcome] "C:\Programmer\IBM\Client Access\cwbwlwiz.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmer\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DBISQL9] "C:\Programmer\Sybase\SQL Anywhere 9\win32\dbisqlg.exe" -preload
O4 - HKCU\..\Run: [SybaseCentral43] "C:\Programmer\Sybase\Shared\Sybase Central 4.3\win32\scjview.exe" -preload
O4 - Startup: Adwiza Happy Birthday.lnk = C:\Programmer\superoffice\Modules\Adwiza\Happy Birthday\AdwizaBirthday.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Inquiero Client.lnk = C:\Programmer\Inquiero Client\_INQUIERO.EXE
O4 - Global Startup: SAP Business One Service manager.lnk = C:\Programmer\SAP Manage\SAP Business One ServerTools\Service Manager\ServerManager.exe
O4 - Global Startup: Service Manager.lnk = C:\Programmer\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Save page in SuperOffice - res://C:\PROGRA~1\SUPERO~1\SoIeExtensions.dll/SavePageInSuperOffice.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: SuperOffice - {CC88D81F-6166-4F46-AC89-B75CD9CEB292} - C:\Programmer\SuperOffice\SoIeExtensions.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O15 - Trusted Zone: https://*.webconference.com
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} - https://www.webconference.com/downloads/v5install/Install.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1115912782659
O16 - DPF: {7C896371-4B7F-4B34-95B1-24851F5DED24} (Microsoft Virtual Server VMRC Control) - http://hartig.dk:1024/VirtualServer/activex/VMRCActiveXClient.cab
O16 - DPF: {92DC836E-F1F7-4FCC-B550-99A0DDA47557} (SuperOffice DocumentHandler Class) - http://www.adwiza.com/crm5/cab/SoDwa.cab
O16 - DPF: {9DAD2E36-8A62-428C-9F1C-951050D5ABE4} (WDXMAPProject.WDXMAP) - http://www2c.web-direct.dk/neozone/WDXMAP.CAB
O16 - DPF: {C8C1066B-FE9E-4B1B-9951-1BBC5EE03E38} (WDX.WDX_Main) - https://www2.web-direct.dk/WDX.CAB
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey) - https://netbank.bgbank.dk/html/activex/e-Safekey/BG/e-Safekey.cab
O16 - DPF: {F11BFF96-CC7A-4482-819B-91EAE4C454EF} (NTR ActiveX 1.1.6) - https://www.inquiero.com/ssl/inquiero/mod/setup/ntractivex116_14.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = modules
O17 - HKLM\Software\..\Telephony: DomainName = modules
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = modules
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = modules
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = modules
O20 - AppInit_DLLs: HookDLL.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adwiza Sync Manager Scheduler (AdwizaSyncScheduler) - Unknown owner - C:\Programmer\adwiza\Sync\NSYNCSCH.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Programmer\Symantec AntiVirus\DefWatch.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oracle\ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: OracleOraHome92TNSListener - Unknown owner - C:\oracle\ora92\BIN\TNSLSNR.exe
O23 - Service: SonicWall VPN Client Service (RampartSvc) - SonicWALL, Inc. - C:\Programmer\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe
O23 - Service: SAP Business One License Manager - Unknown owner - C:\Programmer\SAP Manage\SAP Business One ServerTools\SBOLicense\SBOLicense.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Programmer\Symantec AntiVirus\SavRoam.exe
O23 - Service: SAP Business One BackUp Service (SBOBackUp) - Unknown owner - C:\Programmer\SAP Manage\SAP Business One ServerTools\SBOBackUp\SBObackUp.exe
O23 - Service: SAP Business One DI Server (SBODI_Server) - Unknown owner - C:\Programmer\SAP Manage\SAP Business One ServerTools\SBODI_Server\SBODI_Server.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: SOEventServer - SuperOffice ASA - C:\Programmer\superoffice\SOEventServer.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Programmer\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Programmer\TuneUp Utilities 2004\WinStylerThemeSvc.exe
Avatar billede fromsej Praktikant
06. maj 2006 - 13:23 #1
Din log er ren.

Prøv lige dette:
Klik på Start->Kør skriv SFC /scannowbemærk mellemrum), klik OK.
Din XP-CD skal sidde i drevet.
Genstart, se om det hjalp.
Avatar billede fromsej Praktikant
06. maj 2006 - 14:51 #2
*SUK*
SFC /scannow (bemærk mellemrum) skal der stå.
Avatar billede nop Nybegynder
10. maj 2006 - 23:41 #3
Tak for hjælpen.
Læg et svar.
--nop
Avatar billede fromsej Praktikant
11. maj 2006 - 08:50 #4
Så gerne.*S*
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester