Avatar billede terib Nybegynder
20. august 2006 - 20:09 Der er 2 kommentarer og
1 løsning

Problemer med inst måske snavs

Hej
Jeg har de sidste par aftner prøvet at få installeret office 2007 beta2, men den laver en fejl så jeg ikke får den installeret.
Har afinstalleret snart sagt alle mine programmer for at finde ud af hvor den fejler, og scannet med DR.web, SAS, Spybot adware m.m. og lige lidt har det hjulpet.
Er der en der er venlig at kigge min log igennem for at se om der skulle være noget snavs, og hvilke ting der ikke er nødvendige at have liggende?
På forhånd tak

Log fra dr web
[Scan path] C:\
C:\Documents and Settings\navn\NTUSER.DAT - read error
C:\Documents and Settings\navn\NTUSER~1.LOG - read error
C:\Documents and Settings\navn\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat - read error
C:\Documents and Settings\navn\Lokale indstillinger\Application Data\Microsoft\Windows\USRCLA~1.LOG - read error
C:\Documents and Settings\navn\Skrivebord\CMS-SYSTEMER\CMS\CMS\jscripts\tiny_mce_src.js probably infected with SCRIPT.Virus - user denied renaming
C:\Documents and Settings\navn\Skrivebord\CMS-SYSTEMER\DE_NYE_DANSKERE_PÅ_FYN_CMS\CMS\jscripts\tiny_mce_src.js probably infected with SCRIPT.Virus - user denied renaming
C:\Documents and Settings\navn\Skrivebord\CMS-SYSTEMER\LAMMEHAVE_CMS\CMS\jscripts\tiny_mce_src.js probably infected with SCRIPT.Virus - user denied renaming
C:\Documents and Settings\navn\Skrivebord\CMS-SYSTEMER\MM_CMS\CMS\jscripts\tiny_mce_src.js probably infected with SCRIPT.Virus - user denied renaming
C:\Documents and Settings\navn\Skrivebord\CMS-SYSTEMER\QAANAAQ_CMS\CMS\jscripts\tiny_mce_src.js probably infected with SCRIPT.Virus - user denied renaming
C:\Documents and Settings\navn\Skrivebord\CMS-SYSTEMER\VISIOWEB_CMS_MAJ_2006\VisioWeb\jscripts\tiny_mce_src.js probably infected with SCRIPT.Virus - user denied renaming
C:\Documents and Settings\navn\Skrivebord\CMS-SYSTEMER\WISIOWEB_CMS_JUNI_2006\VisioWeb\jscripts\tiny_mce_src.js probably infected with SCRIPT.Virus - user denied renaming
C:\Documents and Settings\NetworkService\NTUSER.DAT - read error
C:\Documents and Settings\NetworkService\NTUSER~1.LOG - read error
C:\Documents and Settings\NetworkService\Lokale indstillinger\Application Data\Microsoft\Windows\UsrClass.dat - read error
C:\Documents and Settings\NetworkService\Lokale indstillinger\Application Data\Microsoft\Windows\USRCLA~1.LOG - read error
C:\Programmer\Radmin\AdmDll.dll is riskware program Program.RemoteAdmin.21 - user denied renaming
C:\Programmer\Radmin\raddrv.dll is riskware program Program.RemoteAdmin - user denied renaming
C:\Programmer\Radmin\radmin.exe is riskware program Program.RemoteAdmin - user denied renaming
C:\Programmer\Radmin\r_server.exe is riskware program Program.RemoteAdmin - user denied renaming
C:\Programmer\themexp\Themexp.org File\NNWDAB638.EXE is adware program Adware.NewDotNet - renamed
>C:\Programmer\WinRAR\Dos.SFXC:\System Volume Information\_restore{BB5B4A12-C83D-47C4-811A-C52210A3E349}\RP274\A0068117.exe is adware program Adware.SaveNow - renamed
C:\System Volume Information\_restore{BB5B4A12-C83D-47C4-811A-C52210A3E349}\RP292\A0070119.exe is riskware program Program.RemoteAdmin - user denied renaming
C:\System Volume Information\_restore{BB5B4A12-C83D-47C4-811A-C52210A3E349}\RP292\A0070121.dll is riskware program Program.RemoteAdmin - user denied renaming
C:\System Volume Information\_restore{BB5B4A12-C83D-47C4-811A-C52210A3E349}\RP292\A0072012.exe is riskware program Program.RemoteAdmin.30 - user denied renaming
C:\System Volume Information\_restore{BB5B4A12-C83D-47C4-811A-C52210A3E349}\RP303\A0075190.EXE is adware program Adware.NewDotNet - renamed
C:\WINNT\system32\admdll.dll is riskware program Program.RemoteAdmin.21 - user denied renaming
C:\WINNT\system32\raddrv.dll is riskware program Program.RemoteAdmin - user denied renaming
C:\WINNT\system32\r_server.exe is riskware program Program.RemoteAdmin - user denied renaming
C:\WINNT\system32\config\default - read error
C:\WINNT\system32\config\default.LOG - read error
C:\WINNT\system32\config\SAM - read error
C:\WINNT\system32\config\SAM.LOG - read error
C:\WINNT\system32\config\SECURITY - read error
C:\WINNT\system32\config\SECURITY.LOG - read error
C:\WINNT\system32\config\software - read error
C:\WINNT\system32\config\software.LOG - read error
C:\WINNT\system32\config\system - read error
C:\WINNT\system32\config\system.LOG - read error

-----------------------------------------------------------------------------
Scan statistics
-----------------------------------------------------------------------------
Objects scanned: 250621
Infected objects found: 0
Objects with modifications found: 0
Suspicious objects found: 7
Adware programs found: 3
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 10
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 0
Objects renamed: 3
Objects moved: 0
Objects ignored: 0
Scan speed: 142 Kb/s
Scan time: 03:29:54
-----------------------------------------------------------------------------

=============================================================================
Total session statistics
=============================================================================
Objects scanned: 250897
Infected objects found: 0
Objects with modifications found: 0
Suspicious objects found: 7
Adware programs found: 3
Dialer programs found: 0
Joke programs found: 0
Riskware programs found: 10
Hacktool programs found: 0
Objects cured: 0
Objects deleted: 0
Objects renamed: 3
Objects moved: 0
Objects ignored: 0
Scan speed: 147 Kb/s
Scan time: 03:30:21
=============================================================================

Logfile of HijackThis v1.99.1
Scan saved at 19:54:07, on 20-08-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\Programmer\QuickTime\qttask.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Programmer\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINNT\system32\ctfmon.exe
C:\Programmer\Cisco Systems\VPN Client\cvpnd.exe
C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\fxssvc.exe
C:\WINNT\system32\wscntfy.exe
C:\Programmer\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Programmer\SpywareGuard\sgmain.exe
C:\Programmer\SpywareGuard\sgbhp.exe
C:\WINNT\system32\wuauclt.exe
C:\Documents and Settings\navn\Skrivebord\hijack\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Programmer\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programmer\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmer\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Programmer\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Programmer\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [NBJ] "C:\Programmer\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = ?
O4 - Startup: SpywareGuard.lnk = C:\Programmer\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Programmer\Cisco Systems\VPN Client\vpngui.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Programmer\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Programmer\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Programmer\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Programmer\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Programmer\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Programmer\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Programmer\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Programmer\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Programmer\VisualRoute\vrie.dll
O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Programmer\VisualRoute\vrie.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlmanager.akamaitools.com.edgesuite.net/dlmanager/versions/activex/dlm-activex-2.0.5.1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A446D7DF-D7EA-44C1-8A92-BD31209B0726}: NameServer = 194.239.134.83
O17 - HKLM\System\CCS\Services\Tcpip\..\{AA586AED-A51C-4BA5-B6C5-96BE97B9498F}: NameServer = 194.239.134.83
O18 - Protocol: CDS300 - {AD43AA67-6860-4531-AC8A-0E68F9CF023E} - E:\Player\__CDS2.dll (file missing)
O20 - Winlogon Notify: SASWinLogon - C:\Programmer\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programmer\Fælles filer\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINNT\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Programmer\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Programmer\Fælles filer\LightScribe\LSSrvc.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Programmer\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
Avatar billede johnstigers Seniormester
20. august 2006 - 20:11 #1
Avatar billede terib Nybegynder
20. august 2006 - 20:53 #2
mener du jeg skal lukke det - er gjort. Det løste ikke mit problem, derfor dette forsøg:-)
mvh
Avatar billede terib Nybegynder
21. august 2006 - 16:15 #3
Ikke nødvendigt alligevel - ny HD startet forfra - alt virker igen.
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester