tjek min hijack this - har store problemer med computer
min computer går lige pludselig i blåskærm og melder fejl. bagefter vil den ikke starte og kræver adskillige genstartsforsøg før det lykkes... vil en hjælpsom tjekke min log. mange takLogfile of
HijackThis v1.99.1
Scan saved at
22:31:42, on
27-04-2007
Platform: Windows
XP SP2 (WinNT
5.01.2600)
MSIE: Internet
Explorer v6.00 SP2
(6.00.2900.2180)
Running processes:
C:\WINDOWS\System3
2\smss.exe
C:\WINDOWS\system3
2\winlogon.exe
C:\WINDOWS\system3
2\services.exe
C:\WINDOWS\system3
2\lsass.exe
C:\WINDOWS\System3
2\ibmpmsvc.exe
C:\WINDOWS\System3
2\Ati2evxx.exe
C:\WINDOWS\system3
2\svchost.exe
C:\Programmer\Wind
ows
Defender\MsMpEng.e
xe
C:\WINDOWS\System3
2\svchost.exe
C:\WINDOWS\system3
2\Ati2evxx.exe
C:\WINDOWS\Explore
r.EXE
C:\WINDOWS\system3
2\spoolsv.exe
C:\PROGRA~1\Grisof
t\AVG7\avgamsvr.ex
e
C:\PROGRA~1\Grisof
t\AVG7\avgupsvc.ex
e
C:\WINDOWS\System3
2\QCONSVC.EXE
C:\Programmer\Syna
ptics\SynTP\SynTPL
pr.exe
C:\Programmer\Syna
ptics\SynTP\SynTPE
nh.exe
C:\PROGRA~1\ThinkP
ad\PkgMgr\HOTKEY\T
PHKMGR.exe
C:\Programmer\Thin
kPad\PkgMgr\HOTKEY
\TPONSCR.exe
C:\WINDOWS\system3
2\RunDll32.exe
C:\Programmer\Thin
kPad\PkgMgr\HOTKEY
_1\TpScrex.exe
C:\Program
Files\ThinkPad\Uti
lities\TpKmapMn.ex
e
C:\Programmer\Thin
kPad\ConnectUtilit
ies\QCWLICON.EXE
C:\PROGRA~1\ThinkP
ad\UTILIT~1\EzEjMn
Ap.Exe
C:\WINDOWS\AGRSMMS
G.exe
C:\WINDOWS\system3
2\dla\tfswctrl.exe
C:\PROGRA~1\Grisof
t\AVG7\avgcc.exe
C:\Programmer\Micr
osoft
IntelliPoint\point
32.exe
C:\Programmer\Wind
ows
Defender\MSASCui.e
xe
C:\WINDOWS\system3
2\ctfmon.exe
C:\Programmer\Goog
le\GoogleToolbarNo
tifier\1.2.1128.54
62\GoogleToolbarNo
tifier.exe
C:\Programmer\TEXT
ware\HotKey\TWALIN
K.EXE
C:\Programmer\Micr
osoft
Office\Office\1030
\OLFSNT40.EXE
C:\WINDOWS\system3
2\wuauclt.exe
C:\Program
Files\HijackThis\H
ijackThis.exe
C:\WINDOWS\system3
2\wuauclt.exe
R0 -
HKCU\Software\Micr
osoft\Internet
Explorer\Main,Star
t Page =
http://signon.stof
anet.dk/
R0 -
HKCU\Software\Micr
osoft\Internet
Explorer\Toolbar,L
inksFolderName =
Hyperlinks
O2 - BHO:
AcroIEHlprObj
Class -
{06849E9F-C8D7-4D5
9-B87D-784B7D6BE0B
3} -
C:\Programmer\Adob
e\Acrobat
5.0\Reader\ActiveX
\AcroIEHelper.ocx
O2 - BHO:
DriveLetterAccess
-
{5CA3D70E-1895-11C
F-8E15-00123456789
0} -
C:\WINDOWS\system3
2\dla\tfswshx.dll
O2 - BHO: Google
Toolbar Helper -
{AA58ED58-01DD-4d9
1-8333-CF10577473F
7} -
c:\windows\downloa
ded program
files\googletoolba
r3.dll
O3 - Toolbar:
&Google -
{2318C2B1-4965-11d
4-9B18-009027A5CD4
F} -
c:\windows\downloa
ded program
files\googletoolba
r3.dll
O4 - HKLM\..\Run:
[S3TRAY2]
S3Tray2.exe
O4 - HKLM\..\Run:
[SynTPLpr]
C:\Programmer\Syna
ptics\SynTP\SynTPL
pr.exe
O4 - HKLM\..\Run:
[SynTPEnh]
C:\Programmer\Syna
ptics\SynTP\SynTPE
nh.exe
O4 - HKLM\..\Run:
[ATIModeChange]
Ati2mdxx.exe
O4 - HKLM\..\Run:
[TPHOTKEY]
C:\PROGRA~1\ThinkP
ad\PkgMgr\HOTKEY\T
PHKMGR.exe
O4 - HKLM\..\Run:
[BMMGAG] RunDll32
C:\PROGRA~1\ThinkP
ad\UTILIT~1\pwrmon
it.dll,StartPwrMon
itor
O4 - HKLM\..\Run:
[TPKMAPMN]
C:\Program
Files\ThinkPad\Uti
lities\TpKmapMn.ex
e
O4 - HKLM\..\Run:
[QCWLICON]
C:\Programmer\Thin
kPad\ConnectUtilit
ies\QCWLICON.EXE
O4 - HKLM\..\Run:
[EZEJMNAP]
C:\PROGRA~1\ThinkP
ad\UTILIT~1\EzEjMn
Ap.Exe
O4 - HKLM\..\Run:
[AGRSMMSG]
AGRSMMSG.exe
O4 - HKLM\..\Run:
[ATIPTA]
C:\Programmer\ATI
Technologies\ATI
Control
Panel\atiptaxx.exe
O4 - HKLM\..\Run:
[ibmmessages]
C:\Programmer\IBM\
Messages By
IBM\ibmmessages.ex
e
O4 - HKLM\..\Run:
[StorageGuard]
"c:\Programmer\VER
ITAS
Software\Update
Manager\sgtray.exe
" /r
O4 - HKLM\..\Run:
[dla]
C:\WINDOWS\system3
2\dla\tfswctrl.exe
O4 - HKLM\..\Run:
[NeroCheck]
C:\WINDOWS\System3
2\NeroCheck.exe
O4 - HKLM\..\Run:
[HPDJ Taskbar
Utility]
C:\WINDOWS\system3
2\spool\drivers\w3
2x86\3\hpztsb05.ex
e
O4 - HKLM\..\Run:
[AVG7_CC]
C:\PROGRA~1\Grisof
t\AVG7\avgcc.exe
/STARTUP
O4 - HKLM\..\Run:
[QuickTime Task]
"C:\Programmer\Qui
ckTime\qttask.exe"
-atboottime
O4 - HKLM\..\Run:
[IntelliPoint]
"C:\Programmer\Mic
rosoft
IntelliPoint\point
32.exe"
O4 - HKLM\..\Run:
[Windows Defender]
"C:\Programmer\Win
dows
Defender\MSASCui.e
xe" -hide
O4 - HKCU\..\Run:
[CTFMON.EXE]
C:\WINDOWS\system3
2\ctfmon.exe
O4 - HKCU\..\Run:
[swg]
C:\Programmer\Goog
le\GoogleToolbarNo
tifier\1.2.1128.54
62\GoogleToolbarNo
tifier.exe
O4 - Global
Startup: Adobe
Gamma Loader.lnk =
?
O4 - Global
Startup:
HotKey.lnk =
C:\Programmer\TEXT
ware\HotKey\TWALIN
K.EXE
O4 - Global
Startup: Microsoft
Office.lnk =
C:\Programmer\Micr
osoft
Office\Office\OSA9
.EXE
O4 - Global
Startup: Symantec
WinFax Starter
Port.lnk =
C:\Programmer\Micr
osoft
Office\Office\1030
\OLFSNT40.EXE
O9 - Extra button:
Messenger -
{FB5F1910-F110-11d
2-BB9E-00C04F79568
3} -
C:\Programmer\Mess
enger\msmsgs.exe
O9 - Extra 'Tools'
menuitem: Windows
Messenger -
{FB5F1910-F110-11d
2-BB9E-00C04F79568
3} -
C:\Programmer\Mess
enger\msmsgs.exe
O16 - DPF:
{029FDBA6-3547-11D
7-AA4C-0050BF051A0
0} (Rawflow ICD
Client) -
http://downol.dr.d
k/download/netradi
o/Rawflow.cab
O16 - DPF:
{17492023-C23A-453
E-A040-C7C580BBF70
0} (Windows
Genuine Advantage
Validation Tool) -
http://go.microsof
t.com/fwlink/?link
id=39204
O16 - DPF:
{6414512B-B978-451
D-A0D8-FCFDF33E833
C} (WUWebControl
Class) -
http://v5.windowsu
pdate.microsoft.co
m/v5consumer/V5Con
trols/en/x86/clien
t/wuweb_site.cab?1
097332911593
O16 - DPF:
{6CB5E471-C305-11D
3-99A8-00008639549
5} -
http://toolbar.goo
gle.com/data/da/bi
g/1.1.62-big/Googl
eNav.cab
O18 - Protocol:
msnim -
{828030A1-22C1-400
9-854F-8E305202313
F} -
"C:\PROGRA~1\MSNME
S~1\msgrapp.dll"
(file missing)
O20 - Winlogon
Notify: WgaLogon -
C:\WINDOWS\SYSTEM3
2\WgaLogon.dll
O21 - SSODL:
WPDShServiceObj -
{AAA288BA-9A4C-45B
0-95D7-94D524869DB
5} -
C:\WINDOWS\system3
2\WPDShServiceObj.
dll
O23 - Service: Ati
HotKey Poller -
Unknown owner -
C:\WINDOWS\System3
2\Ati2evxx.exe
O23 - Service:
AVG7 Alert Manager
Server (Avg7Alrt)
- GRISOFT, s.r.o.
-
C:\PROGRA~1\Grisof
t\AVG7\avgamsvr.ex
e
O23 - Service:
AVG7 Update
Service
(Avg7UpdSvc) -
GRISOFT, s.r.o. -
C:\PROGRA~1\Grisof
t\AVG7\avgupsvc.ex
e
O23 - Service:
Google Updater
Service (gusvc) -
Google -
C:\Programmer\Goog
le\Common\Google
Updater\GoogleUpda
terService.exe
O23 - Service: IBM
PM Service
(IBMPMSVC) -
Unknown owner -
C:\WINDOWS\System3
2\ibmpmsvc.exe
O23 - Service:
PLSRemote Service
(PLSRemoteSvc) -
Unknown owner -
C:\WINDOWS\SYSTEM3
2\PLSRemote.exe
O23 - Service:
QCONSVC - Unknown
owner -
C:\WINDOWS\System3
2\QCONSVC.EXE