Avatar billede andersd241 Nybegynder
27. april 2007 - 22:35 Der er 6 kommentarer og
1 løsning

tjek min hijack this - har store problemer med computer

min computer går lige pludselig i blåskærm og melder fejl. bagefter vil den ikke starte og kræver adskillige genstartsforsøg før det lykkes... vil en hjælpsom tjekke min log. mange tak

Logfile of

HijackThis v1.99.1
Scan saved at

22:31:42, on

27-04-2007
Platform: Windows

XP SP2 (WinNT

5.01.2600)
MSIE: Internet

Explorer v6.00 SP2

(6.00.2900.2180)

Running processes:
C:\WINDOWS\System3

2\smss.exe
C:\WINDOWS\system3

2\winlogon.exe
C:\WINDOWS\system3

2\services.exe
C:\WINDOWS\system3

2\lsass.exe
C:\WINDOWS\System3

2\ibmpmsvc.exe
C:\WINDOWS\System3

2\Ati2evxx.exe
C:\WINDOWS\system3

2\svchost.exe
C:\Programmer\Wind

ows

Defender\MsMpEng.e

xe
C:\WINDOWS\System3

2\svchost.exe
C:\WINDOWS\system3

2\Ati2evxx.exe
C:\WINDOWS\Explore

r.EXE
C:\WINDOWS\system3

2\spoolsv.exe
C:\PROGRA~1\Grisof

t\AVG7\avgamsvr.ex

e
C:\PROGRA~1\Grisof

t\AVG7\avgupsvc.ex

e
C:\WINDOWS\System3

2\QCONSVC.EXE
C:\Programmer\Syna

ptics\SynTP\SynTPL

pr.exe
C:\Programmer\Syna

ptics\SynTP\SynTPE

nh.exe
C:\PROGRA~1\ThinkP

ad\PkgMgr\HOTKEY\T

PHKMGR.exe
C:\Programmer\Thin

kPad\PkgMgr\HOTKEY

\TPONSCR.exe
C:\WINDOWS\system3

2\RunDll32.exe
C:\Programmer\Thin

kPad\PkgMgr\HOTKEY

_1\TpScrex.exe
C:\Program

Files\ThinkPad\Uti

lities\TpKmapMn.ex

e
C:\Programmer\Thin

kPad\ConnectUtilit

ies\QCWLICON.EXE
C:\PROGRA~1\ThinkP

ad\UTILIT~1\EzEjMn

Ap.Exe
C:\WINDOWS\AGRSMMS

G.exe
C:\WINDOWS\system3

2\dla\tfswctrl.exe
C:\PROGRA~1\Grisof

t\AVG7\avgcc.exe
C:\Programmer\Micr

osoft

IntelliPoint\point

32.exe
C:\Programmer\Wind

ows

Defender\MSASCui.e

xe
C:\WINDOWS\system3

2\ctfmon.exe
C:\Programmer\Goog

le\GoogleToolbarNo

tifier\1.2.1128.54

62\GoogleToolbarNo

tifier.exe
C:\Programmer\TEXT

ware\HotKey\TWALIN

K.EXE
C:\Programmer\Micr

osoft

Office\Office\1030

\OLFSNT40.EXE
C:\WINDOWS\system3

2\wuauclt.exe
C:\Program

Files\HijackThis\H

ijackThis.exe
C:\WINDOWS\system3

2\wuauclt.exe

R0 -

HKCU\Software\Micr

osoft\Internet

Explorer\Main,Star

t Page =

http://signon.stof

anet.dk/
R0 -

HKCU\Software\Micr

osoft\Internet

Explorer\Toolbar,L

inksFolderName =

Hyperlinks
O2 - BHO:

AcroIEHlprObj

Class -

{06849E9F-C8D7-4D5

9-B87D-784B7D6BE0B

3} -

C:\Programmer\Adob

e\Acrobat

5.0\Reader\ActiveX

\AcroIEHelper.ocx
O2 - BHO:

DriveLetterAccess

-

{5CA3D70E-1895-11C

F-8E15-00123456789

0} -

C:\WINDOWS\system3

2\dla\tfswshx.dll
O2 - BHO: Google

Toolbar Helper -

{AA58ED58-01DD-4d9

1-8333-CF10577473F

7} -

c:\windows\downloa

ded program

files\googletoolba

r3.dll
O3 - Toolbar:

&Google -

{2318C2B1-4965-11d

4-9B18-009027A5CD4

F} -

c:\windows\downloa

ded program

files\googletoolba

r3.dll
O4 - HKLM\..\Run:

[S3TRAY2]

S3Tray2.exe
O4 - HKLM\..\Run:

[SynTPLpr]

C:\Programmer\Syna

ptics\SynTP\SynTPL

pr.exe
O4 - HKLM\..\Run:

[SynTPEnh]

C:\Programmer\Syna

ptics\SynTP\SynTPE

nh.exe
O4 - HKLM\..\Run:

[ATIModeChange]

Ati2mdxx.exe
O4 - HKLM\..\Run:

[TPHOTKEY]

C:\PROGRA~1\ThinkP

ad\PkgMgr\HOTKEY\T

PHKMGR.exe
O4 - HKLM\..\Run:

[BMMGAG] RunDll32

C:\PROGRA~1\ThinkP

ad\UTILIT~1\pwrmon

it.dll,StartPwrMon

itor
O4 - HKLM\..\Run:

[TPKMAPMN]

C:\Program

Files\ThinkPad\Uti

lities\TpKmapMn.ex

e
O4 - HKLM\..\Run:

[QCWLICON]

C:\Programmer\Thin

kPad\ConnectUtilit

ies\QCWLICON.EXE
O4 - HKLM\..\Run:

[EZEJMNAP]

C:\PROGRA~1\ThinkP

ad\UTILIT~1\EzEjMn

Ap.Exe
O4 - HKLM\..\Run:

[AGRSMMSG]

AGRSMMSG.exe
O4 - HKLM\..\Run:

[ATIPTA]

C:\Programmer\ATI

Technologies\ATI

Control

Panel\atiptaxx.exe
O4 - HKLM\..\Run:

[ibmmessages]

C:\Programmer\IBM\

Messages By

IBM\ibmmessages.ex

e
O4 - HKLM\..\Run:

[StorageGuard]

"c:\Programmer\VER

ITAS

Software\Update

Manager\sgtray.exe

" /r
O4 - HKLM\..\Run:

[dla]

C:\WINDOWS\system3

2\dla\tfswctrl.exe
O4 - HKLM\..\Run:

[NeroCheck]

C:\WINDOWS\System3

2\NeroCheck.exe
O4 - HKLM\..\Run:

[HPDJ Taskbar

Utility]

C:\WINDOWS\system3

2\spool\drivers\w3

2x86\3\hpztsb05.ex

e
O4 - HKLM\..\Run:

[AVG7_CC]

C:\PROGRA~1\Grisof

t\AVG7\avgcc.exe

/STARTUP
O4 - HKLM\..\Run:

[QuickTime Task]

"C:\Programmer\Qui

ckTime\qttask.exe"

-atboottime
O4 - HKLM\..\Run:

[IntelliPoint]

"C:\Programmer\Mic

rosoft

IntelliPoint\point

32.exe"
O4 - HKLM\..\Run:

[Windows Defender]

"C:\Programmer\Win

dows

Defender\MSASCui.e

xe" -hide
O4 - HKCU\..\Run:

[CTFMON.EXE]

C:\WINDOWS\system3

2\ctfmon.exe
O4 - HKCU\..\Run:

[swg]

C:\Programmer\Goog

le\GoogleToolbarNo

tifier\1.2.1128.54

62\GoogleToolbarNo

tifier.exe
O4 - Global

Startup: Adobe

Gamma Loader.lnk =

?
O4 - Global

Startup:

HotKey.lnk =

C:\Programmer\TEXT

ware\HotKey\TWALIN

K.EXE
O4 - Global

Startup: Microsoft

Office.lnk =

C:\Programmer\Micr

osoft

Office\Office\OSA9

.EXE
O4 - Global

Startup: Symantec

WinFax Starter

Port.lnk =

C:\Programmer\Micr

osoft

Office\Office\1030

\OLFSNT40.EXE
O9 - Extra button:

Messenger -

{FB5F1910-F110-11d

2-BB9E-00C04F79568

3} -

C:\Programmer\Mess

enger\msmsgs.exe
O9 - Extra 'Tools'

menuitem: Windows

Messenger -

{FB5F1910-F110-11d

2-BB9E-00C04F79568

3} -

C:\Programmer\Mess

enger\msmsgs.exe
O16 - DPF:

{029FDBA6-3547-11D

7-AA4C-0050BF051A0

0} (Rawflow ICD

Client) -

http://downol.dr.d

k/download/netradi

o/Rawflow.cab
O16 - DPF:

{17492023-C23A-453

E-A040-C7C580BBF70

0} (Windows

Genuine Advantage

Validation Tool) -

http://go.microsof

t.com/fwlink/?link

id=39204
O16 - DPF:

{6414512B-B978-451

D-A0D8-FCFDF33E833

C} (WUWebControl

Class) -

http://v5.windowsu

pdate.microsoft.co

m/v5consumer/V5Con

trols/en/x86/clien

t/wuweb_site.cab?1

097332911593
O16 - DPF:

{6CB5E471-C305-11D

3-99A8-00008639549

5} -

http://toolbar.goo

gle.com/data/da/bi

g/1.1.62-big/Googl

eNav.cab
O18 - Protocol:

msnim -

{828030A1-22C1-400

9-854F-8E305202313

F} -

"C:\PROGRA~1\MSNME

S~1\msgrapp.dll"

(file missing)
O20 - Winlogon

Notify: WgaLogon -

C:\WINDOWS\SYSTEM3

2\WgaLogon.dll
O21 - SSODL:

WPDShServiceObj -

{AAA288BA-9A4C-45B

0-95D7-94D524869DB

5} -

C:\WINDOWS\system3

2\WPDShServiceObj.

dll
O23 - Service: Ati

HotKey Poller -

Unknown owner -

C:\WINDOWS\System3

2\Ati2evxx.exe
O23 - Service:

AVG7 Alert Manager

Server (Avg7Alrt)

- GRISOFT, s.r.o.

-

C:\PROGRA~1\Grisof

t\AVG7\avgamsvr.ex

e
O23 - Service:

AVG7 Update

Service

(Avg7UpdSvc) -

GRISOFT, s.r.o. -

C:\PROGRA~1\Grisof

t\AVG7\avgupsvc.ex

e
O23 - Service:

Google Updater

Service (gusvc) -

Google -

C:\Programmer\Goog

le\Common\Google

Updater\GoogleUpda

terService.exe
O23 - Service: IBM

PM Service

(IBMPMSVC) -

Unknown owner -

C:\WINDOWS\System3

2\ibmpmsvc.exe
O23 - Service:

PLSRemote Service

(PLSRemoteSvc) -

Unknown owner -

C:\WINDOWS\SYSTEM3

2\PLSRemote.exe
O23 - Service:

QCONSVC - Unknown

owner -

C:\WINDOWS\System3

2\QCONSVC.EXE
Avatar billede andersd241 Nybegynder
27. april 2007 - 22:35 #1
prøver lige igen med loggen

Logfile of HijackThis v1.99.1
Scan saved at 22:31:42, on 27-04-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmer\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Programmer\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Programmer\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe
C:\Programmer\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Programmer\Microsoft IntelliPoint\point32.exe
C:\Programmer\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Programmer\TEXTware\HotKey\TWALINK.EXE
C:\Programmer\Microsoft Office\Office\1030\OLFSNT40.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://signon.stofanet.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\downloaded program files\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\downloaded program files\googletoolbar3.dll
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [TPKMAPMN] C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe
O4 - HKLM\..\Run: [QCWLICON] C:\Programmer\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programmer\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ibmmessages] C:\Programmer\IBM\Messages By IBM\ibmmessages.exe
O4 - HKLM\..\Run: [StorageGuard] "c:\Programmer\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IntelliPoint] "C:\Programmer\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Programmer\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Programmer\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: HotKey.lnk = C:\Programmer\TEXTware\HotKey\TWALINK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Symantec WinFax Starter Port.lnk = C:\Programmer\Microsoft Office\Office\1030\OLFSNT40.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1097332911593
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/da/big/1.1.62-big/GoogleNav.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmer\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: PLSRemote Service (PLSRemoteSvc) - Unknown owner - C:\WINDOWS\SYSTEM32\PLSRemote.exe
O23 - Service: QCONSVC - Unknown owner - C:\WINDOWS\System32\QCONSVC.EXE
27. april 2007 - 22:48 #2
(Jeg ser på den...)
27. april 2007 - 23:00 #3
Klik på Start->Kør skriv Services.msc og klik OK.
Find Tjenesten
* PLSRemote Service (PLSRemoteSvc)
stop den hvis den kører, højreklik på den og vælg Starttype Deaktiveret.

---------------------------------------------------------------

Kør en scanning med Hijackthis,
Du får herunder nogle filer, som du skal fixe. Det, du skal gøre, er at sætte et flueben ud for disse filer. Når du har gjort det, så lukker du alle andre vinduer ned. Det er meget vigtigt at det eneste vindue, som er åbent er HijackThis vinduet. Husk også at lukke dette vindue, når du har markeret filerne. Nu må du fixe. Klik på Fix checked.

Det er disse, som skal fixes:

O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: PLSRemote Service (PLSRemoteSvc) - Unknown owner - C:\WINDOWS\SYSTEM32\PLSRemote.exe

For at kunne se alle filer og mapper, så følg denne vejledning:
http://www.spywareinfo.dk/tip-og-tricks/mappeindstillinger.htm

Genstart i fejlsikret tilstand http://www.spywareinfo.dk/#/htm/fejlsikret_tilstand.htm

Søg og slet de markerede filer/mapper hvis de stadig findes. Ellers fortsætter du bare vejledningen. De kan være røget i fixet.

C:\WINDOWS\SYSTEM32\PLSRemote.exe

Genstart normalt, kør en ny scanning med hijackthis, og kopier en frisk log herind til tjek.

NB: Inden næste kørsel med HiJackThis.exe skal du OMDØBE programfilen HiJackThis.exe til ALTERNATIV.exe , da visse uønskede elementer har en tendens til at skjule sig når der kører en process ved navn HiJackThis.exe !!!

------------------------------------------------------------------------

RegBase oprydning kan anbefales ->
RegCleaner http://www.ccleaner.com/ + http://www.spywarefri.dk/manualer/ccleaner-manual.htm (Specielt punktet [Problemer]...)

Fraklik Yahoo Toolbar under instalationen !!!
Fraklik Yahoo Toolbar under instalationen !!!
Fraklik Yahoo Toolbar under instalationen !!!
Avatar billede andersd241 Nybegynder
02. maj 2007 - 18:08 #4
hele computeren var desværre brændt af... det er motherboardet den var gal med... men tak for ulejligheden med min log.
Avatar billede andersd241 Nybegynder
02. maj 2007 - 18:09 #5
hvis du vil have pointene så skriv et "svar".
03. maj 2007 - 01:12 #6
Ping...

Læg selv et [svar] og la' os dele...
09. december 2008 - 19:12 #7
Takker for Point...
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester