Avatar billede musti776 Nybegynder
14. november 2006 - 12:19 Der er 4 kommentarer og
1 løsning

Hijack this Log

Hej,
er der lige nogen der gider at tjekke denne log?
Explorer er begyndt at køre helt vildt langsomt...

Takker...

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Altiris\AClient\AClient.exe
C:\PROGRAM FILES\ALTIRIS\EXPRESS\NS CLIENT\AeXNSAgent.exe
c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Altiris\AClient\AClntUsr.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireTray.exe
G:\leverancen\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://intranet.ts.teliasonera.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://intranet.ts.teliasonera.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by TeliaSonera Denmark
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://dkkob2101alt/proxyconfig/TeliaDK_Proxy.js
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.intra.telia.dk;login.homerun.telia.com;tmweb3;10.10.0.50;10.10.249.114;*.dbts.dk;*.gsm.orange.dk;*.intra.orange.dk;*.mobilix.dk;*.teliasonera.net;<local>
N1 - Netscape 4: user_pref("browser.startup.homepage", "http://tea018.net.ejb.telia.dk:9974/wf25/wfa_html.home"); (C:\Program Files\Netscape\Users\ljksdf\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AClntUsr] C:\Program Files\Altiris\AClient\AClntUsr.EXE
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [AeXAgentLogon] "C:\PROGRAM FILES\ALTIRIS\EXPRESS\NS CLIENT\AeXAgentActivate.exe" /logon
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: McAfee Desktop Firewall Tray.lnk = ?
O4 - Global Startup: VPN Client.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: CAX - {065F986A-3360-48E7-8644-00730105CA53} - http://tcax.intra.telia.dk (file missing) (HKCU)
O9 - Extra button: Smallworld - {1A295B3B-1455-4EBF-AC22-78F7578BA31F} - http://10.5.16.141/pb (file missing) (HKCU)
O9 - Extra button: Oracle app - {62F7E390-FDCB-43A9-B253-3C7D5B4403B9} - http://tnd1002.net.ejb.telia.dk:8800/OA_HTML/US/APPSPRD.htm (file missing) (HKCU)
O9 - Extra button: Tidsadmin - {87DFF1F9-CC62-4345-8E0E-5AF8E8B472F7} - http://tnnt037.net.telia.dk/axprdess/ (file missing) (HKCU)
O9 - Extra button: Webdog - {96272B07-0A2D-4E9E-9C10-E1F718BB0719} - http://webdog.net.telia.dk/pls/dms/DM_IF.Logonscreen (file missing) (HKCU)
O9 - Extra button: Kisbi - {998432FA-97C0-4E92-9008-466BE084A74C} - http://tckiprod.ext.telia.dk/KiwiProd/KiwiProd.home (file missing) (HKCU)
O9 - Extra button: Intranet - {D86EA1EE-12D7-49DB-B221-AF08BAD86178} - http://www.teliasoneraworld.com/intranet/dk (file missing) (HKCU)
O9 - Extra button: Targitweb - {EAD9C3C6-AFA9-4FC0-8ABE-BABB970E1FE1} - http://tntargit.net.telia.dk/analysisnet (file missing) (HKCU)
O12 - Plugin for .rx: C:\Program Files\Internet Explorer\Plugins\npwrqxrx.dll
O12 - Plugin for .rxc: C:\Program Files\Internet Explorer\Plugins\npwrqxrx.dll
O14 - IERESET.INF: START_PAGE_URL=http://intranet.ts.teliasonera.net/
O15 - Trusted Zone: http://*.intra.mobilix.dk
O15 - Trusted Zone: http://*.intra.orange.dk
O15 - Trusted Zone: http://access-erhverv.teledanmark.dk
O15 - Trusted Zone: http://*.tsden.tcad.telia.se
O15 - Trusted Zone: http://*.intra.mobilix.dk (HKLM)
O15 - Trusted Zone: http://*.intra.orange.dk (HKLM)
O15 - Trusted Zone: http://access-erhverv.teledanmark.dk (HKLM)
O15 - Trusted Zone: http://*.tsden.tcad.telia.se (HKLM)
O15 - Trusted IP range: http://10.10.0.50
O15 - Trusted IP range: http://194.23.29.194
O15 - Trusted IP range: http://10.10.0.50 (HKLM)
O15 - Trusted IP range: http://194.23.29.194 (HKLM)
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {08F04139-8DFC-11D2-80E9-006008B066EE} (ConfigChkr Class) - https://onsite.trust.telia.com/services/TECABTeliaTrustServices/vscnfchk.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1128076282569
O16 - DPF: {9b935470-ad4a-11d5-b63e-00c04faedb18} (Oracle JInitiator 1.1.8.16) - http://tnd1002.net.ejb.telia.dk:8800/jinitiator/oajinit.exe
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = tsden.tcad.telia.se
O17 - HKLM\Software\..\Telephony: DomainName = tsden.tcad.telia.se
O17 - HKLM\System\CCS\Services\Tcpip\..\{66ED789C-A7C9-4EA9-910F-A14377F97A7B}: Domain = tsden.tcad.telia.se
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = tsden.tcad.telia.se
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = tsden.tcad.telia.se
O23 - Service: Altiris Client Service (AClient) - Altiris, Inc. - C:\Program Files\Altiris\AClient\AClient.exe
O23 - Service: ACU Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Altiris Agent (AeXNSClient) - Altiris, Inc. - C:\PROGRAM FILES\ALTIRIS\EXPRESS\NS CLIENT\AeXNSAgent.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: McAfee Desktop Firewall Service (FireSvc) - Networks Associates Technology, Inc. - C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
Avatar billede fromsej Praktikant
14. november 2006 - 12:26 #1
Der er ikke noget der skriger i øjnene.
Prøv at følge hele artiklen her:
http://www.eksperten.dk/artikler/954
Avatar billede musti776 Nybegynder
14. november 2006 - 16:29 #2
hej fromsej,
det vil vi prøve.. takker..

svarer du lige?
Avatar billede fromsej Praktikant
14. november 2006 - 16:46 #3
Det kan jeg da godt, men send lige logfilerne herind, så vi kan tjekke dem.
Avatar billede musti776 Nybegynder
16. januar 2007 - 22:22 #4
takker... beklager forsinkelsen..
Avatar billede fromsej Praktikant
17. januar 2007 - 18:21 #5
Velbekomme, tak for point. :-)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester