Avatar billede max2012 Nybegynder
19. juni 2013 - 21:09 Der er 10 kommentarer og
1 løsning

Hjælp til at analyse af Log fra HiJackThis

Hej
Er der nogen erfaren personer som kan hjælpe med analayse af efterfølgende Log fra HiJackThis.

Jeg har nogle problemer med nogle popups og beskeder som fremommer om at script ikke kunne fuldføres.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:00:09, on 19-06-2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmer\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Programmer\Intel\WiFi\bin\S24EvMon.exe
C:\Programmer\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\notes\nslsvice.exe
C:\Programmer\LENOVO\HOTKEY\TPHKLOAD.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Programmer\LENOVO\HOTKEY\TPHKSVC.exe
C:\Programmer\BitKinex\bitkinexsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Programmer\IBM\SQLLIB\BIN\db2mgmtsvc.exe
C:\Programmer\ThinkPad\Utilities\DOZESVC.EXE
C:\Programmer\Intel\WiFi\bin\EvtEng.exe
C:\Programmer\Java\jre7\bin\jqs.exe
C:\Programmer\Intel\AMT\LMS.exe
C:\Programmer\IBM\Lotus8\nsd.exe
C:\Programmer\Fælles filer\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Programmer\ThinkPad\Utilities\PWMDBSVC.exe
C:\Programmer\Fælles filer\Microsoft Shared\Microsoft Online Services\MSOIDSvcm.exe
C:\Programmer\ThinkPad\Utilities\PWMEWSVC.exe
C:\Programmer\Fælles filer\Intel\WirelessCommon\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
c:\programmer\lenovo\system update\suservice.exe
C:\Programmer\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Programmer\Fælles filer\Lenovo\tvt_reg_monitor_svc.exe
C:\Programmer\Fælles filer\Lenovo\Scheduler\tvtsched.exe
C:\Programmer\Fælles filer\Intel\Privacy Icon\UNS\UNS.exe
C:\Programmer\VMware\VMware vCenter Converter Standalone\vmware-converter-a.exe
C:\Programmer\VMware\VMware vCenter Converter Standalone\vmware-converter.exe
C:\Programmer\VMware\VMware vCenter Converter Standalone\vmware-converter.exe
C:\Programmer\LENOVO\HOTKEY\tposdsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Programmer\Lenovo\HOTKEY\TPONSCR.exe
C:\Programmer\Lenovo\Zoom\TpScrex.exe
C:\Programmer\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\NILaunch.exe
C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe
C:\Programmer\IBM\SQLLIB\BIN\db2systray.exe
C:\Programmer\Fælles filer\Lenovo\Scheduler\scheduler_proxy.exe
C:\Programmer\Lenovo\VIRTSCRL\virtscrl.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmer\Analog Devices\Core\smax4pnp.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\IBM\SQLLIB\BIN\db2systray.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\SCHTASK.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmer\Fælles filer\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
C:\Programmer\Skype\Phone\Skype.exe
C:\Programmer\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Programmer\Malwarebytes' Anti-Malware\mbam.exe
C:\Programmer\Adobe\Reader 11.0\Reader\AcroRd32.exe
C:\Programmer\Adobe\Reader 11.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\msiexec.exe
C:\Programmer\Google\Chrome\Application\chrome.exe
C:\Programmer\Google\Chrome\Application\chrome.exe
C:\Programmer\Google\Chrome\Application\chrome.exe
C:\Programmer\Google\Chrome\Application\chrome.exe
C:\Programmer\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dk.msn.com/?pc=UP21&ocid=UP21DHP&dt=040313
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Programmer\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Net-It Launcher] C:\WINDOWS\system32\NILaunch.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Programmer\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [DB2 - db2systray.exe DB2] C:\Programmer\IBM\SQLLIB\BIN\db2systray.exe DB2
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Programmer\Fælles filer\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [LenovoAutoScrollUtility] C:\Programmer\Lenovo\VIRTSCRL\virtscrl.exe
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmer\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Programmer\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DB2COPY1 - db2systray.exe DB2] C:\Programmer\IBM\SQLLIB\BIN\db2systray.exe DB2
O4 - HKLM\..\Run: [Adobe ARM] "C:\Programmer\Fælles filer\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Fælles filer\Java\Java Update\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware] C:\Programmer\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmer\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Skype] "C:\Programmer\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-21-1652436197-1872974437-2255962115-1010\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'db2admin')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O4 - S-1-5-18 Startup: Dropbox.lnk = C:\Documents and Settings\max\Application Data\Dropbox\bin\Dropbox.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Dropbox.lnk = C:\Documents and Settings\max\Application Data\Dropbox\bin\Dropbox.exe (User 'Default user')
O4 - Startup: Dropbox.lnk = C:\Documents and Settings\max\Application Data\Dropbox\bin\Dropbox.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Programmer\Digital Line Detect\DLG.exe
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Programmer\Fiddler2\Fiddler.exe" (file missing)
O9 - Extra 'Tools' menuitem: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "C:\Programmer\Fiddler2\Fiddler.exe" (file missing)
O9 - Extra button: IE WebDeveloper V2 - {D851CEE8-86A0-440C-B8F4-DA7DA99B5765} - C:\Programmer\IEInspector\IEWebDeveloperV2\IEWebDeveloperV2.dll
O9 - Extra 'Tools' menuitem: IE WebDeveloper V2 - {D851CEE8-86A0-440C-B8F4-DA7DA99B5765} - C:\Programmer\IEInspector\IEWebDeveloperV2\IEWebDeveloperV2.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programmer\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O15 - ESC Trusted Zone: http://runonce.msn.com
O15 - ESC Trusted Zone: http://sea.search.msn.dk

O15 - ESC Trusted Zone: http://runonce.msn.com (HKLM)
O15 - ESC Trusted Zone: http://sea.search.msn.dk (HKLM)

O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install-ie/alttiff.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1259237159953

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Programmer\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FLLESF~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: BitKinex File Transfer Service (BitKinex) - Unknown owner - C:\Programmer\BitKinex\bitkinexsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSvcHst.exe
O23 - Service: DB2 - DB2COPY1 - DB2 (DB2) - International Business Machines Corporation - C:\Programmer\IBM\SQLLIB\bin\db2syscs.exe
O23 - Service: DB2DAS - DB2DAS00 (DB2DAS00) - International Business Machines Corporation - C:\Programmer\IBM\SQLLIB\\bin\db2dasrrm.exe
O23 - Service: DB2DAS - DB2DAS01 (DB2DAS01) - International Business Machines Corporation - C:\Programmer\IBM\SQLLIB\\bin\db2dasrrm.exe
O23 - Service: DB2-ressourcegrænsefunktion (Governor) (DB2COPY1) (DB2GOVERNOR_DB2COPY1) - International Business Machines Corporation - C:\Programmer\IBM\SQLLIB\BIN\db2govds.exe
O23 - Service: DB2-licensserver (DB2COPY1) (DB2LICD_DB2COPY1) - International Business Machines Corporation - C:\Programmer\IBM\SQLLIB\BIN\db2licd.exe
O23 - Service: DB2 Management Service (DB2COPY1) (DB2MGMTSVC_DB2COPY1) - International Business Machines Corporation - C:\Programmer\IBM\SQLLIB\BIN\db2mgmtsvc.exe
O23 - Service: Ekstern DB2-kommandoserver (DB2COPY1) (DB2REMOTECMD_DB2COPY1) - International Business Machines Corporation - C:\Programmer\IBM\SQLLIB\BIN\db2rcmd.exe
O23 - Service: Lenovo Doze Mode Service (DozeSvc) - Lenovo. - C:\Programmer\ThinkPad\Utilities\DOZESVC.EXE
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Programmer\Intel\WiFi\bin\EvtEng.exe
O23 - Service: Google Update Tjeneste (gupdate) (gupdate) - Google Inc. - C:\Programmer\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Tjeneste (gupdatem) (gupdatem) - Google Inc. - C:\Programmer\Google\Update\GoogleUpdate.exe
O23 - Service: IBM Notes Diagnostics - Unknown owner - C:\Programmer\IBM\Lotus\nsd.exe (file missing)
O23 - Service: Lenovo PM Service (IBMPMSVC) - Lenovo. - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Programmer\Java\jre7\bin\jqs.exe
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Programmer\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Intel(R) Active Management Technology Local Management Service (LMS) - Intel Corporation - C:\Programmer\Intel\AMT\LMS.exe
O23 - Service: IBM Notes Smart Upgrade Service (LNSUSvc) - Unknown owner - C:\Programmer\IBM\Lotus\SUService.exe (file missing)
O23 - Service: Lotus Notes Diagnostics - IBM - C:\Programmer\IBM\Lotus8\nsd.exe
O23 - Service: Lotus Notes Single Logon - IBM Corp - C:\notes\nslsvice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Programmer\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Multi-user Cleanup Service - Unknown owner - C:\Programmer\IBM\Lotus\ntmulti.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Power Manager DBC Service - Unknown owner - C:\Programmer\ThinkPad\Utilities\PWMDBSVC.exe
O23 - Service: Cisco EnergyWise Enabler (PwmEWSvc) - Lenovo Group Limited - C:\Programmer\ThinkPad\Utilities\PWMEWSVC.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Programmer\Fælles filer\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless WiFi Service (S24EventMonitor) - Intel(R) Corporation - C:\Programmer\Intel\WiFi\bin\S24EvMon.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Programmer\Skype\Updater\Updater.exe
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Programmer\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\programmer\lenovo\system update\suservice.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Programmer\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Programmer\Fælles filer\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Programmer\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: Vis på skærm (TPHKSVC) - Lenovo Group Limited - C:\Programmer\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Programmer\Fælles filer\Lenovo\Scheduler\tvtsched.exe
O23 - Service: Intel(R) Active Management Technology User Notification Service (UNS) - Intel Corporation - C:\Programmer\Fælles filer\Intel\Privacy Icon\UNS\UNS.exe
O23 - Service: VMware vCenter Converter Standalone Agent (vmware-converter-agent) - VMware, Inc. - C:\Programmer\VMware\VMware vCenter Converter Standalone\vmware-converter-a.exe
O23 - Service: VMware vCenter Converter Standalone Server (vmware-converter-server) - VMware, Inc. - C:\Programmer\VMware\VMware vCenter Converter Standalone\vmware-converter.exe
O23 - Service: VMware vCenter Converter Standalone Worker (vmware-converter-worker) - VMware, Inc. - C:\Programmer\VMware\VMware vCenter Converter Standalone\vmware-converter.exe
O23 - Service: Cisco AnyConnect VPN Agent (vpnagent) - Cisco Systems, Inc. - C:\Programmer\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Programmer\RealVNC\VNC4\WinVNC4.exe

--
End of file - 17952 bytes
Avatar billede 220661 Ekspert
19. juni 2013 - 21:34 #1
Disse her ser mærkeligt ud synes jeg:
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETVÆRKSTJENESTE')

Har du prøvet at lave en scanning med Malwarebytes?
Og evt disse 2 programmer også:

Hent og instalér CCleaner http://www.ccleaner.com/ + http://www.spywarefri.dk/manualer/manual-for-installation-og-brug-af-ccleaner/
http://www.spywarefri.dk/manualer/manual-for-installation-og-brug-af-ccleaner/
Lad programmet foretage en oprydning...

AdwCleaner: http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleaner
Når programmet startes, tryk på "slet". Pc scannes, og ved endt scanning, skal pc genstartes, for at fjerne det som programmet finder. Tilbage fra genstart fremkommer en log som du godt må poste ind i næste indlæg. Mht.: Vista/Win7 - HøjreMusseTast - "Kør som Administrator..."
Avatar billede 220661 Ekspert
19. juni 2013 - 21:35 #2
Avatar billede max2012 Nybegynder
19. juni 2013 - 21:40 #3
Er igang med Malware pt., vil den automatisk slette de inficeret filer.
Den har fundet 2 filer og har kørt 1 times tid.
Avatar billede 220661 Ekspert
19. juni 2013 - 21:48 #4
Nej den sletter ikke automatisk.

Når programmet har scannet færdigt tryk på "Vis resultater"  - og herefter tryk på "Fjern det valgte" - nu åbnes log'en og du skal gemme den et sted, hvor du kan finde den igen. Kopier loggen herind.
Kør også en tur med AdwCleaner og send loggen herind.

Hvordan kører det nu?
Avatar billede max2012 Nybegynder
19. juni 2013 - 22:14 #5
Den fandt noget i recycle som jeg slettet, men der er stadigvæk problemer.

Jeg vil prøve at fjerne de ting som du nævnte i loggen.
Avatar billede 220661 Ekspert
19. juni 2013 - 22:16 #6
AdwCleaner??
Avatar billede max2012 Nybegynder
19. juni 2013 - 22:32 #7
# AdwCleaner v2.303 - Logfil lavet d. 19/06/2013 kl. 22:25:46
# Opdateret d. 08/06/2013 af Xplode
# Operativ system : Microsoft Windows XP Service Pack 3 (32 bits)
# Bruger : MAX
# Boot Mode : Normal
# Kører fra : C:\Documents and Settings\MAX\Dokumenter\Downloads\adwcleaner.exe
# Indstilling [Slet]


***** [Servicer] *****


***** [Filer / Mapper] *****


***** [Registeret] *****


***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registeret er rent.

-\\ Mozilla Firefox v21.0 (da)

Filer : C:\Documents and Settings\MAXadmin\Application Data\Mozilla\Firefox\Profiles\v3kmdzyu.default\prefs.js

[OK] Filen er ren.

Filer : C:\Documents and Settings\MAX\Application Data\Mozilla\Firefox\Profiles\vcms2bug.default-1371497503125\prefs.js

[OK] Filen er ren.

-\\ Google Chrome v27.0.1453.116

Filer : C:\Documents and Settings\MAX\Lokale indstillinger\Application Data\Google\Chrome\User Data\Default\Preferences

[OK] Filen er ren.

*************************

AdwCleaner[S2].txt - [1057 octets] - [19/06/2013 22:25:46]

########## EOF - C:\AdwCleaner[S2].txt - [1117 octets] ##########
Avatar billede max2012 Nybegynder
19. juni 2013 - 22:36 #8
Har fjernet de 2 linie uden nogen form for hjælp.

Stadigvæk samme problem.

Skal man starte pc'eren i fejlsikret tilstand.
Avatar billede max2012 Nybegynder
20. juni 2013 - 08:09 #9
Er der andre som kan byde ind på hvad der kan være af yderligere som kan fjernes da det medføre forskellige gener som popup.
Avatar billede max2012 Nybegynder
02. august 2013 - 12:35 #10
Lukker ned da der ikke kom yderligere input.
Avatar billede 220661 Ekspert
02. august 2013 - 12:47 #11
Beklager min "ikke" tilstedeværelse i tråden. Eksperten har først reageret nu da du har lukket :-(
Har du fjernet de to punkter fra Hijackthis som du snakkede om?
Er problemet ikke løst, så opret et nyt spørgsmål, for at få hjælp.
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
IT-kurser om Microsoft 365, sikkerhed, personlig vækst, udvikling, digital markedsføring, grafisk design, SAP og forretningsanalyse.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester