![]() |
|
#1
| |||
| |||
| min pc er syk den tar lang tid å åpne programmer og sider og når det starter opp nå jeg har en blå skjerm vises fora noen sekunder så går inn i windows siden jeg har gjort en HJT logg for å se om alle kan finne noe til menigheter ? ![]() Logfile of HijackThis v1.99.1 Scan lagret på 10:56:15, on 22.08.2008 Plattform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16705) Kjører prosesser: C: \ WINDOWS \ System32 \ smss.exe C: \ WINDOWS \ system32 \ Winlogon.exe C: \ WINDOWS \ system32 \ Services.exe C: \ WINDOWS \ system32 \ Lsass.exe C: \ WINDOWS \ system32 \ Svchost.exe C: \ WINDOWS \ system32 \ Svchost.exe C: \ WINDOWS \ system32 \ ZoneLabs \ vsmon.exe C: \ WINDOWS \ Explorer.exe C: \ Programfiler \ Lavasoft \ Ad-Aware \ aawservice.exe C: \ WINDOWS \ system32 \ Spoolsv.exe C: \ Acer \ Styrke Technology \ ePerformance \ MemCheck.exe C: \ progra ~ 1 \ AVG \ AVG8 \ avgwdsvc.exe C: \ WINDOWS \ system32 \ hasplms.exe c: \ Programfiler \ Fellesfiler \ LightScribe \ LSSrvc.exe C: \ Acer \ Styrke Technology \ eLock \ LockServ.exe C: \ WINDOWS \ system32 \ nvsvc32.exe C: \ WINDOWS \ system32 \ Svchost.exe C: \ progra ~ 1 \ AVG \ AVG8 \ avgrsx.exe C: \ progra ~ 1 \ AVG \ AVG8 \ avgemc.exe C: \ WINDOWS \ system32 \ Ctfmon.exe C: \ Acer \ Styrke Technology \ eRecovery \ eRAgent.exe C: \ WINDOWS \ system32 \ Svchost.exe C: \ WINDOWS \ RTHDCPL.EXE C: \ Program Files \ Cyberlink \ PowerDVD \ PDVDServ.exe C: \ WINDOWS \ system32 \ rundll32.exe C: \ WINDOWS \ system32 \ SysMonitor.exe C: \ WINDOWS \ CameraFixer.exe C: \ WINDOWS \ tsnp2std.exe C: \ WINDOWS \ vsnp2std.exe C: \ Programfiler \ Real \ RealPlayer \ RealPlay.exe C: \ Programfiler \ QuickTime \ qttask.exe C: \ progra ~ 1 \ Yahoo! \ Browser \ ybrwicon.exe C: \ Programfiler \ Java \ jre1.6.0_05 \ bin \ jusched.exe C: \ Programfiler \ btbb_wcm \ McciTrayApp.exe C: \ Acer \ Styrke Technology \ eLock \ Monitor \ LockMon.exe C: \ progra ~ 1 \ Yahoo! \ Browser \ ycommon.exe C: \ Programfiler \ BT bredbånd Desktop \ bin \ BTHelpNotifier.exe C: \ Programfiler \ Zone Labs \ ZoneAlarm \ zlclient.exe C: \ progra ~ 1 \ AVG \ AVG8 \ avgtray.exe C: \ Programfiler \ Messenger \ msmsgs.exe C: \ Programfiler \ Hewlett-Packard \ Digital Imaging \ bin \ hpohmr08.exe C: \ Programfiler \ Hewlett-Packard \ Digital Imaging \ bin \ hpotdd01.exe C: \ Program Files \ BT bredbånd Desktop \ bin \ BTHelp.exe C: \ WINDOWS \ system32 \ wuauclt.exe C: \ WINDOWS \ system32 \ wbem \ wmiapsrv.exe C: \ Programfiler \ BT bredbånd Desktop \ bin \ mpbtn.exe C: \ Programfiler \ Hewlett-Packard \ Digital Imaging \ bin \ hpoevm08.exe C: \ PROGRA ~ 1 \ Hewlet ~ 1 \ hpis \ Felles \ motiv ~ 1.EXE C: \ Programfiler \ Hewlett-Packard \ Digital Imaging \ Bin \ hpoSTS08.exe C: \ progra ~ 1 \ Yahoo! \ Messen ~ 1 \ ymsgr_tray.exe C: \ Programfiler \ King Kong Software \ Capture \ KingKongCapture.exe C: \ Programfiler \ Yahoo! \ Browser \ ybrowser.exe C: \ Documents and Settings \ Christine \ Mine dokumenter \ PRORAM DOWNOADS \ HijackThis.exe R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://kingkongsearch.com/ R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://home.bt.yahoo.com/ R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ SearchURL, (Default) = http://search.aol.co.uk/web?isinit=true&query =% s R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Int ernet Settings, ProxyOverride = 127.0.0.1 R3 - URLSearchHook: Yahoo! Toolbar - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ Programfiler \ Yahoo! \ Companion \ Installerer \ cpn0 \ yt.dll O2 - BHO: Yahoo! Toolbar Helper - (02478D38-C3F9-4EFB-9B51-7695ECA05670) - C: \ Programfiler \ Yahoo! \ Companion \ Installerer \ cpn0 \ yt.dll O2 - BHO: Adobe PDF Reader Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Programfiler \ Fellesfiler \ Adobe \ Acrobat \ ActiveX \ AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - (3CA2F312-6F6E-4B53-A66E-4E65E497C8C0) - C: \ Programfiler \ AVG \ AVG8 \ avgssie.dll O2 - BHO: Spybot-S & D IE Protection - (53707962-6F74-2D53-2644-206D7942484F) - C: \ progra ~ 1 \ Spybot ~ 1 \ SDHelper.dll O2 - BHO: Yahoo! IE Services Button - (5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897) - c: \ progra ~ 1 \ Yahoo! \ Felles \ yiesrvc.dll O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Programfiler \ Java \ jre1.6.0_05 \ bin \ ssv.dll O2 - BHO: Windows Live Sign-in Helper - (9030D464-4C02-4ABF-8ECC-5164760863C6) - C: \ Programfiler \ Fellesfiler \ Microsoft Shared \ Windows Live \ WindowsLiveLogin.dll O2 - BHO: AVG Security Toolbar - (A057A204-BACC-4D26-9990-79A187E2698E) - c: \ progra ~ 1 \ AVG \ AVG8 \ AVGTOO ~ 1.DLL O2 - BHO: ZoneAlarm Spy Blocker BHO - (F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA) - C: \ Programfiler \ ZoneAlarmSB \ bar \ 1.bin \ SPYBLOCK.DLL O2 - BHO: SidebarAutoLaunch Class - (F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D) - C: \ Programfiler \ Yahoo! \ Browser \ YSidebarIEBHO.dll O3 - Toolbar: Yahoo! Toolbar - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ Programfiler \ Yahoo! \ Companion \ Installerer \ cpn0 \ yt.dll O3 - Toolbar: ZoneAlarm Spy Blocker - (F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA) - C: \ Programfiler \ ZoneAlarmSB \ bar \ 1.bin \ SPYBLOCK.DLL O3 - Toolbar: AVG Security Toolbar - (A057A204-BACC-4D26-9990-79A187E2698E) - c: \ progra ~ 1 \ AVG \ AVG8 \ AVGTOO ~ 1.DLL O4 - HKLM \ .. \ Run: [LaunchApp] Alaunch O4 - HKLM \ .. \ Run: [NvCplDaemon] rundll32.exe C: \ WINDOWS \ system32 \ NvCpl.dll, NvStartup O4 - HKLM \ .. \ Run: [nwiz] nwiz.exe / install O4 - HKLM \ .. \ Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM \ .. \ Run: [SkyTel] SkyTel.EXE O4 - HKLM \ .. \ Run: [ntiMUI] c: \ Program Files \ NewTech Infosystems \ NTI CD & DVD-Maker 7 \ ntiMUI.exe O4 - HKLM \ .. \ Run: [RemoteControl] "C: \ Program Files \ Cyberlink \ PowerDVD \ PDVDServ.exe" O4 - HKLM \ .. \ Run: [IMJPMIG8.1] "C: \ WINDOWS \ IME \ imjp8_1 \ IMJPMIG.EXE" / Skjem bort / RemAdvDef / Migration32 O4 - HKLM \ .. \ Run: [IMEKRMIG6.1] C: \ WINDOWS \ IME \ imkr6_1 \ IMEKRMIG.EXE O4 - HKLM \ .. \ Run: [MSPY2002] C: \ WINDOWS \ system32 \ IME \ PINTLGNT \ ImScInst.exe / SYNC O4 - HKLM \ .. \ Run: [PHIME2002ASync] C: \ WINDOWS \ system32 \ IME \ TINTLGNT \ TINTSETP.EXE / SYNC O4 - HKLM \ .. \ Run: [PHIME2002A] C: \ WINDOWS \ system32 \ IME \ TINTLGNT \ TINTSETP.EXE / IMEName O4 - HKLM \ .. \ Run: [NvMediaCenter] rundll32.exe C: \ WINDOWS \ system32 \ NvMcTray.dll, NvTaskbarInit O4 - HKLM \ .. \ Run: [Acer Styrke Technology Monitor] C: \ WINDOWS \ system32 \ SysMonitor.exe O4 - HKLM \ .. \ Run: [eLockMonitor] C: \ Acer \ Styrke Technology \ eLock \ Monitor \ LaunchMonitor.exe O4 - HKLM \ .. \ Run: [eRecoveryService] C: \ Acer \ Styrke Technology \ eRecovery \ eRAgent.exe O4 - HKLM \ .. \ Run: [CameraFixer] C: \ WINDOWS \ CameraFixer.exe O4 - HKLM \ .. \ Run: [tsnp2std] C: \ WINDOWS \ tsnp2std.exe O4 - HKLM \ .. \ Run: [snp2std] C: \ WINDOWS \ vsnp2std.exe O4 - HKLM \ .. \ Run: [RealTray] C: \ Programfiler \ Real \ RealPlayer \ RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Programfiler \ QuickTime \ qttask.exe"-atboottime O4 - HKLM \ .. \ Run: [AOLDialer] C: \ Programfiler \ Fellesfiler \ AOL \ ACS \ AOLDial.exe O4 - HKLM \ .. \ Run: [Adobe Reader Speed Launcher] "C: \ Programfiler \ Adobe \ Reader 8.0 \ Reader \ Reader_sl.exe" O4 - HKLM \ .. \ Run: [YBrowser] C: \ progra ~ 1 \ Yahoo! \ Browser \ ybrwicon.exe O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Programfiler \ Java \ jre1.6.0_05 \ bin \ jusched.exe" O4 - HKLM \ .. \ Run: [btbb_wcm_McciTrayApp] C: \ Programfiler \ btbb_wcm \ McciTrayApp.exe O4 - HKLM \ .. \ Run: [btbb_McciTrayApp] C: \ Programfiler \ BT bredbånd Desktop \ bin \ BTHelpNotifier.exe O4 - HKLM \ .. \ Run: [ZoneAlarm Client] "C: \ Programfiler \ Zone Labs \ ZoneAlarm \ zlclient.exe" O4 - HKLM \ .. \ Run: [AVG8_TRAY] C: \ progra ~ 1 \ AVG \ AVG8 \ avgtray.exe O4 - HKCU \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe O4 - HKCU \ .. \ Run: [MsnMsgr] "C: \ Programfiler \ Windows Live \ Messenger \ MsnMsgr.Exe" / background O4 - HKCU \ .. \ Run: [MSMSGS] "C: \ Programfiler \ Messenger \ msmsgs.exe" / background O4 - HKCU \ .. \ Run: [Yahoo! Personsøker] "c: \ progra ~ 1 \ Yahoo! \ Messen ~ 1 \ YAHOOM ~ 1.EXE"-quiet O4 - Global Startup: BT bredbånd Desktop Help.lnk = C: \ Programfiler \ BT bredbånd Desktop \ bin \ matcli.exe O4 - Global Startup: HP PSC 1000 series.lnk =? O4 - Global Startup: hpoddt01.exe.lnk =? O4 - Global Startup: Microsoft Office.lnk = C: \ Programfiler \ Microsoft Office \ Office10 \ Osa.exe O8 - Extra sammenheng menyelement: & AOL Toolbar søk - res: / / C: \ Program Files \ AOL Toolbar \ toolbar.dll / SEARCH.HTML O9 - Extra knappen: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Programfiler \ Java \ jre1.6.0_05 \ bin \ ssv.dll O9 - Extra "Verktøy" MENUITEM: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Programfiler \ Java \ jre1.6.0_05 \ bin \ ssv.dll O9 - Extra knappen: BT Yahoo! Services - (5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897) - c: \ progra ~ 1 \ Yahoo! \ Felles \ yiesrvc.dll O9 - Extra knappen: Real.com - (CD67F990-D8E9-11d2-98FE-00C0F0318AFE) - C: \ WINDOWS \ system32 \ Shdocvw.dll O9 - Extra knappen: (no name) - (DFB852A3-47F8-48C4-a200-58CAB36FD2A2) - C: \ progra ~ 1 \ Spybot ~ 1 \ SDHelper.dll O9 - Extra "Verktøy" MENUITEM: Spybot - Search & Destroy Configuration - (DFB852A3-47F8-48C4-a200-58CAB36FD2A2) - C: \ progra ~ 1 \ Spybot ~ 1 \ SDHelper.dll O9 - Extra knappen: (no name) - (e2e2dd38-d088-4134-82b7-f2ba38496583) -% windir% \ Network Diagnostic \ xpnetdiag.exe (file missing) O9 - Extra "Verktøy" MENUITEM: @ xpsp3res.dll, -20001 - (e2e2dd38-d088-4134-82b7-f2ba38496583) -% windir% \ Network Diagnostic \ xpnetdiag.exe (file missing) O9 - Extra knappen: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Programfiler \ Messenger \ msmsgs.exe O9 - Extra "Verktøy" MENUITEM: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Programfiler \ Messenger \ msmsgs.exe O11 - Options group: [INTERNATIONAL] International * O15 - Trusted Zone: http://www.photobucket.com O16 - DPF: (149E45D8-163E-4189-86FC-45022AB2B6C9) (SpinTop DRM Control) -- file: / / / C: / Program% 20Files/Chessmast...es/stg_drm.ocx O16 - DPF: (30528230-99f7-4bb4-88d8-fa1d4f56a2ab) (Installation Support) - C: \ Programfiler \ Yahoo! \ Common \ Yinsthelper.dll O16 - DPF: (6B75345B-AA36-438A-BBE6-4078B4C6984D) (HpProductDetection klasse) -- http://h20270.www2.hp.com/ediags/gmn...tDetection.cab O16 - DPF: (CC450D71-CC90-424C-8638-1F2DBAC87A54) (ArmHelper Control) -- file: / / / C: / Program% 20Files/Chessmast.../armhelper.ocx O16 - DPF: (D27CDB6E-AE6D-11CF-96B8-444553540000) (Shockwave Flash Object) -- http://fpdownload2.macromedia.com/ge...sh/swflash.cab O18 - Protocol: linkscanner - (F274614C-63F8-47D5-A4D1-FBDDE494F8D1) - C: \ Programfiler \ AVG \ AVG8 \ avgpp.dll O20 - AppInit_DLLs: avgrsstx.dll O21 - SSODL: WPDShServiceObj - (AAA288BA-9A4C-45B0-95D7-94D524869DB5) - C: \ WINDOWS \ system32 \ WPDShServiceObj.dll O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C: \ Programfiler \ Lavasoft \ Ad-Aware \ aawservice.exe O23 - Service: Acer ODDSpeedControl - TODO: <????> - C: \ Acer \ Styrke Technology \ eAcoustics \ ODDSpeedCtl \ speedcontrol.exe O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C: \ Acer \ Styrke Technology \ ePerformance \ MemCheck.exe O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, sro - C: \ progra ~ 1 \ AVG \ AVG8 \ avgemc.exe O23 - Service: AVG Free8 Watchdog (avg8wd) - AVG Technologies CZ, sro - C: \ progra ~ 1 \ AVG \ AVG8 \ avgwdsvc.exe O23 - Service: HASP License Manager (hasplms) - Aladdin Knowledge Systems Ltd - C: \ WINDOWS \ system32 \ hasplms.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Programfiler \ Fellesfiler \ InstallShield \ Driver \ 1150 \ Intel 32 \ IDriverT.exe O23 - Service: LightScribeService Direct Disc Merking Service (LightScribeService) - Hewlett-Packard Company - c: \ Programfiler \ Fellesfiler \ LightScribe \ LSSrvc.exe O23 - Service: LockServ - Unknown owner - C: \ Acer \ Styrke Technology \ eLock \ LockServ.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C: \ WINDOWS \ system32 \ nvsvc32.exe O23 - Service: Pml Driver HPZ12 - HP - C: \ WINDOWS \ system32 \ HPZipm12.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C: \ WINDOWS \ system32 \ ZoneLabs \ vsmon.exe |
|
#2
| |||
| |||
| Jeg tror ikke dette er malware. Java må oppdateres.
Prøv oppslaget i Windows operativsystemer forum for råd om den blå skjermene. |
![]() |
|
| Hugseliste |
Lignende Tråder | ||||
| Tråd | Tråd startet | Forum | Svar | Siste innlegg |
| Datamaskin som kjører veldig sakte | curlysmith | General Hardware Chat | 5 | 12 september 2009 02:48 |
| Problemet med datamaskin som kjører sakte kapre logge pls hjelpe | antbann | Virus, spionprogrammer og sikkerhet | 6 | 5 nov 2008 07:28 |
| Har jeg god sikkerhet? Og min datamaskin kjører sakte. | paudashlake | Virus, spionprogrammer og sikkerhet | 13 | 18 oktober 2008 12:02 |
| Please help-datamaskinen kjører veldig treg, virus? | neno85 | Virus, spionprogrammer og sikkerhet | 12 | 2 april 2008 18:25 |
| Datamaskin som kjører sakte | antbann | Virus, spionprogrammer og sikkerhet | 10 | 23 mars 2008 12:21 |
| Thread Tools | |
| |