Avatar billede djurhuus20 Nybegynder
12. december 2006 - 18:03 Der er 1 kommentar og
1 løsning

Hjælp! Filer der skal kigges på!

Kære Eksperten.dk

Opretttede et spørgsmål for omkring 3 dage siden som omhandlede Trojansk virus. Her er de logs jeg blev bedt om at sætte ind. Forstår ikke meget af dem selv.

Ewido log:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on:            17:37:04, 12-12-2006
+ Report-Checksum:        3D862DA1

+ Scan result:

    HKLM\SOFTWARE\Classes\CLSID\{70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} -> Spyware.GameSpyArcade : Cleaned with backup
    HKLM\SOFTWARE\Classes\GSDA.GSDACtl\CLSID\\ -> Spyware.GameSpyArcade : Cleaned with backup
    HKLM\SOFTWARE\Classes\GSDA.GSDACtl.1\CLSID\\ -> Spyware.GameSpyArcade : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} -> Spyware.GameSpyArcade : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/gsda.dll\\.Owner -> Spyware.GameSpyArcade : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/gsda.dll\\{70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} -> Spyware.GameSpyArcade : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/HDPlugin1018.dll\\.Owner -> Spyware.Gator : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/HDPlugin1018.dll\\{DBAE7000-01EC-4162-8FEB-8A27AC937CA0} -> Spyware.Gator : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/HDPlugin1101.dll\\.Owner -> Spyware.Gator : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/HDPlugin1101.dll\\{DBAE7000-01EC-4162-8FEB-8A27AC937CA0} -> Spyware.Gator : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/StarInstall.ocx\\.Owner -> Dialer.Generic : Cleaned with backup
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/StarInstall.ocx\\{E0B795B4-FD95-4ABD-A375-27962EFCE8CF} -> Dialer.Generic : Cleaned with backup
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{669695BC-A811-4A9D-8CDF-BA8C795F261C} -> Spyware.PowerStrip : Cleaned with backup
    HKU\S-1-5-21-2306665932-2055962413-3641420591-1006\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{669695BC-A811-4A9D-8CDF-BA8C795F261C} -> Spyware.PowerStrip : Cleaned with backup
    HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{669695BC-A811-4A9D-8CDF-BA8C795F261C} -> Spyware.PowerStrip : Error during cleaning
    C:\Documents and Settings\Ask\Dokumenter\Billeder\SjovOgSpas\Stuff\Programmer\Nero.Burning.ROM.v6.3.0.3.Ultra.Edition-ORiON.ShareReactor.rar/Ahead.Nero.Burning.ROM.v6.3.0.3.Ultra.Edition.Incl.Keygen-ORiON\Keygen.exe -> TrojanDropper.Delf.gi : Cleaned with backup
    C:\Documents and Settings\Ask\Dokumenter\Billeder\SjovOgSpas\Stuff\Programmer\Real RealPlayer V9.0 (RealOne) Full Ver.rar/RealPlayer V9.0 (RealOne) Full Ver\RealOnePlayer.exe -> Backdoor.Optix.Pro.o : Cleaned with backup
    C:\Documents and Settings\Ask\Lokale indstillinger\Temp\Cookies\ask@com[1].txt -> Spyware.Cookie.Com : Cleaned with backup
    C:\Documents and Settings\Ask\Lokale indstillinger\Temp\Cookies\ask@download.com[1].txt -> Spyware.Cookie.Com : Cleaned with backup
    C:\Documents and Settings\Ask\Lokale indstillinger\Temp\__unin__.#xe -> Spyware.Altnet : Cleaned with backup
    C:\Programmer\WebSecureAlert\WebSecureAlert.#xe -> Adware.Gator : Cleaned with backup
    C:\Programmer\WebSecureAlert\WSAHelper.#ll -> Adware.Gator : Cleaned with backup
    C:\WINDOWS\Downloaded Program Files\gsda.#ll -> Dialer.Generic : Cleaned with backup
    C:\WINDOWS\installer[veo-10049,de].#xe -> Dialer.Generic : Cleaned with backup


::Report End

Superantispyware log:

SUPERAntiSpyware Scan Log
Generated 12/12/2006 at 03:33 PM

Application Version : 3.3.1020

Core Rules Database Version : 3146
Trace Rules Database Version: 1162

Scan type      : Complete Scan
Total Scan Time : 00:08:44

Memory items scanned      : 194
Memory threats detected  : 0
Registry items scanned    : 5910
Registry threats detected : 33
File items scanned        : 710
File threats detected    : 21

Trojan.Downloader-AVPMon
    [Recoveru systems] C:\DOCUME~1\ASK\LOKALE~1\TEMP\SVCHOST.EXE
    C:\DOCUME~1\ASK\LOKALE~1\TEMP\SVCHOST.EXE

Trojan.Downloader-RPCC
    Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\rpcc
    C:\WINDOWS\SYSTEM32\RPCC.DLL
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\rpcc
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\rpcc#DllName
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\rpcc#Asynchronous
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\rpcc#Impersonate
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\rpcc#Startup

Adware.Tracking Cookie
    C:\Documents and Settings\Ask\Cookies\ask@adserver.banneradministration[1].txt
    C:\Documents and Settings\Ask\Cookies\ask@tradedoubler[2].txt
    C:\Documents and Settings\Ask\Cookies\ask@atdmt[2].txt
    C:\Documents and Settings\Ask\Cookies\ask@advertising[1].txt
    C:\Documents and Settings\Ask\Cookies\ask@mediaplex[1].txt
    C:\Documents and Settings\Ask\Cookies\ask@track.adform[1].txt
    C:\Documents and Settings\Ask\Cookies\ask@ad.yieldmanager[1].txt
    C:\Documents and Settings\Ask\Cookies\ask@adtech[1].txt

Trojan.WinAntiSpyware/WinAntiVirus 2006
    HKCR\AppId\WinPGI.DLL
    HKCR\AppId\WinPGI.DLL#AppID
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#Type
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#Start
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#ErrorControl
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#Tag
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#ImagePath
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#DisplayName
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN#Group
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\Security
    HKLM\SYSTEM\CurrentControlSet\Services\FOPN\Security#Security
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run#WinAntiVirusPro2006 [ "C:\Programmer\WinAntiVirus Pro 2006\WinAV.exe" /min ]
    C:\WINDOWS\system32\av.cpl
    C:\WINDOWS\system32\stera.exe

Adware.Avenue Media/Internet Optimizer
    HKU\S-1-5-21-2306665932-2055962413-3641420591-1006\Software\Microsoft\Internet Explorer\URLSearchHooks#_{CFBFAE00-17A6-11D0-99CB-00C04FD64497}

Adware.Toolbar888
    HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}
    HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid
    HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\ProxyStubClsid32
    HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib
    HKCR\Interface\{C6F2214E-0B54-45A9-B90D-7DD4BA45ED0B}\TypeLib#Version

Adware.ClickSpring/Yazzle
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yazzle1122Oin
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yazzle1122Oin#DisplayName
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yazzle1122Oin#UninstallString

Adware.MyWay
    C:\Programmer\MyWay

Adware.IPWins
    HKU\S-1-5-21-2306665932-2055962413-3641420591-1006\Software\IpWins
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IpWins
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IpWins#DisplayName
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IpWins#UninstallString
    C:\Programmer\ipwins\ipwins.#xe
    C:\Programmer\ipwins\pop13.tmp
    C:\Programmer\ipwins\pop4B.tmp
    C:\Programmer\ipwins\pop5F.tmp
    C:\Programmer\ipwins\popF7.tmp
    C:\Programmer\ipwins\Services.dll
    C:\Programmer\ipwins\Uninst.exe
    C:\Programmer\ipwins

Hijack this log:

Logfile of HijackThis v1.99.1
Scan saved at 17:54:04, on 12-12-2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\AntiVir PersonalEdition Classic\sched.exe
C:\Programmer\AntiVir PersonalEdition Classic\avguard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Virus Dr\security suite\ewidoctrl.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\atiptaxx.exe
C:\PROGRA~1\HPQ\ONE-TO~1\OneTouch.EXE
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\Java\j2re1.4.2_06\bin\jusched.exe
C:\Programmer\AntiVir PersonalEdition Classic\avgnt.exe
C:\Programmer\Winamp\winampa.exe
C:\Programmer\Java\j2re1.4.2_06\bin\jucheck.exe
C:\Programmer\??crosoft\?xplorer.exe
C:\Programmer\Fælles filer\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
c:\Programmer\Microsoft Office\Office10\WINWORD.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\Virus Dr\halløj\belle.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://desktop.presario.net/scripts/redirectors/presario/deskredir2.dll?s=consumer&ap=b201&c=1c02&lc=0406&ac
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.presario.net/scripts/redirectors/presario/srchredir2.dll?c=1c02&lc=0406&s=search&ap=b204
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.presario.net/scripts/redirectors/presario/srchredir2.dll?c=1c02&lc=0406&s=search&ap=b204
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.presario.net/scripts/redirectors/presario/srchredir2.dll?c=1c02&lc=0406&s=search&ap=b204
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://desktop.presario.net/scripts/redirectors/presario/deskredir2.dll?s=consumer&ap=b201&c=1c02&lc=0406&ac
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.compaq.com/2Q00CPT/0406/bF7.asp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - URLSearchHook: (no name) - {BFC7F172-67ED-7E23-EC59-3976123456E6} - C:\WINDOWS\System32\kqv.dll
O2 - BHO: C:\WINDOWS\System32\zkPeCrypt.dll - {8A5849C4-93F3-429D-FF34-660A2068897C} - C:\WINDOWS\System32\zkPeCrypt.dll (file missing)
O2 - BHO: (no name) - {BFC7F172-67ED-7E23-EC59-3976123456E6} - C:\WINDOWS\System32\kqv.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmer\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\da\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [QT4HPOT] C:\PROGRA~1\HPQ\ONE-TO~1\OneTouch.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Cpqset] C:\Programmer\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [buKAZK7] C:\WINDOWS\chhafwj.exe
O4 - HKLM\..\Run: [Kdotunle] C:\Program Files\Imtdt\Fecn.exe
O4 - HKLM\..\Run: [Etlmhyze] C:\Program Files\Wgaonv\Abpewby.exe
O4 - HKLM\..\Run: [avgnt] "C:\Programmer\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [WinampAgent] C:\Programmer\Winamp\winampa.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Nord] C:\WINDOWS\System32\nordsys.exe
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [staveplade] "C:\Documents and Settings\Ask\Skrivebord\TVGuide\staveplade.exe"
O4 - HKCU\..\Run: [Ria] C:\Programmer\??crosoft\?xplorer.exe
O4 - HKCU\..\Run: [Nord] C:\WINDOWS\System32\nordsys.exe
O4 - HKCU\..\Run: [WinMedia] "C:\WINDOWS\System32\z23041138246.exe "
O4 - HKCU\..\Run: [WinUpdate] "C:\WINDOWS\System32\z23041159317.exe "
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Virus Dr\SUPERAntiSpyware.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Download all by Net Transport - C:\Programmer\Xi\NetTransport 2\NTAddList.html
O8 - Extra context menu item: Download by Net Transport - C:\Programmer\Xi\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: GetRight Mini-Browser - C:\Programmer\GetRightIETools\GRMiniBrowser.htm
O8 - Extra context menu item: Search FileMirrors - C:\Programmer\GetRightIETools\FileMirrors.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O16 - DPF: symsupportutil - https://www-secure.symantec.com/region/reg_eu/techsupp/activedata/symsupportutil.CAB
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://www.virtuel-hfc.kk.dk/qp2.cab
O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://cdn.drivecleaner.com/installdrivecleanerstart_dk.cab
O16 - DPF: {1C763326-813B-466F-AF7A-8618C10955D6} (SysCheck.SystemCheck) - http://services.yummy.net/download/WebInstall.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by18fd.bay18.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/3106551f1cbde37cd719/netzip/RdxIE601.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {E055C02E-6258-40FF-80A7-3BDA52FACAD7} - http://activex.matcash.com/speedtest2.dll
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/region/reg_eu/techsupp/activedata/ActiveData.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = mydomain.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{DEED689B-76D0-4129-8C60-BDEAFF303467}: NameServer = 69.57.146.14
O17 - HKLM\System\CS1\Services\VxD\MSTCP: Domain = mydomain.com
O17 - HKLM\System\CS1\Services\VxD\MSTCP: NameServer = 69.57.146.14
O17 - HKLM\System\CS2\Services\VxD\MSTCP: Domain = mydomain.com
O17 - HKLM\System\CS2\Services\VxD\MSTCP: NameServer = 69.57.146.14
O17 - HKLM\System\CS3\Services\VxD\MSTCP: Domain = mydomain.com
O17 - HKLM\System\CS3\Services\VxD\MSTCP: NameServer = 69.57.146.14
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 69.57.146.14
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Programmer\Fælles filer\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Virus Dr\SASWINLO.dll
O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programmer\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - AVIRA GmbH - C:\Programmer\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Virus Dr\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Virus Dr\security suite\ewidoguard.exe
O23 - Service: Microsoft authenticate service (MsaSvc) - Unknown owner - C:\WINDOWS\System32\msasvc.exe (file missing)
O23 - Service: RadClock - Unknown owner - C:\Programmer\RadLinker\RadClock.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

Håber at jeg kan få noget hjælp. Har virkelig brug for det.
Avatar billede ejvindh Ekspert
13. december 2006 - 09:13 #1
Hej Djuurhus. Du skal lægge disse logs ind i den oprindelige tråd:
http://www.eksperten.dk/spm/750012

...så skal dr1 nok hjælpe dig videre med dit problem :-)

(det er altid bedst at holde sig til én tråd, idet man så bedre kan bevare overblikket over, hvad der ER gjort)

Luk derfor dette spørgsmål ved selv at lægge et svar, som du accepterer, og så herefter lægge indholdet af dit indlæg over i den gamle tråd.
Avatar billede djurhuus20 Nybegynder
13. december 2006 - 21:04 #2
okay tak for hjælpen:)
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester