Gå til innhold

Cashmere

Medlemmer
  • Innlegg

    945
  • Ble med

  • Besøkte siden sist

Innlegg skrevet av Cashmere

  1. HijackThis-logg:

     

     

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 21:38, on 2008-10-23

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16705)

    Boot mode: Normal

     

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\ibmpmsvc.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Programfiler\Windows Defender\MsMpEng.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Programfiler\Fellesfiler\Symantec Shared\ccSetMgr.exe

    C:\Programfiler\Fellesfiler\Symantec Shared\ccEvtMgr.exe

    C:\Programfiler\Fellesfiler\Symantec Shared\SPBBC\SPBBCSvc.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\acs.exe

    C:\Programfiler\Symantec AntiVirus\DefWatch.exe

    C:\Programfiler\Security Administrator\newlock.exe

    C:\Programfiler\Hotspot Shield\bin\openvpnas.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Programfiler\Fellesfiler\InterVideo\RegMgr\iviRegMgr.exe

    C:\Programfiler\Fellesfiler\Microsoft Shared\VS7DEBUG\MDM.EXE

    C:\WINDOWS\system32\svchost.exe

    C:\Programfiler\Symantec AntiVirus\Rtvscan.exe

    C:\WINDOWS\System32\TPHDEXLG.exe

    C:\Programfiler\TVersity\Media Server\MediaServer.exe

    C:\Programfiler\UPHClean\uphclean.exe

    C:\WINDOWS\system32\WgaTray.exe

    C:\Programfiler\Lenovo\HOTKEY\TPOSDSVC.exe

    C:\WINDOWS\system32\hkcmd.exe

    C:\WINDOWS\system32\igfxpers.exe

    C:\WINDOWS\system32\TpShocks.exe

    C:\WINDOWS\system32\igfxsrvc.exe

    C:\Programfiler\Lenovo\HOTKEY\TPONSCR.exe

    C:\Programfiler\Apoint2K\Apoint.exe

    C:\Programfiler\Lenovo\Zoom\TpScrex.exe

    C:\WINDOWS\System32\DLA\DLACTRLW.EXE

    C:\WINDOWS\system32\rundll32.exe

    C:\Programfiler\Lenovo\NPDIRECT\TPFNF7SP.exe

    C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe

    C:\Programfiler\Apoint2K\ApMsgFwd.exe

    C:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exe

    C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe

    C:\Programfiler\Apoint2K\Apntex.exe

    C:\PROGRA~1\SYMANT~1\VPTray.exe

    C:\Programfiler\Java\jre1.6.0_07\bin\jusched.exe

    C:\WINDOWS\FixCamera.exe

    C:\WINDOWS\vsnpstd.exe

    C:\Programfiler\Security Administrator\newlock.exe

    C:\Programfiler\Steam\Steam.exe

    C:\Documents and Settings\eriher4\Lokale innstillinger\Programdata\Google\Update\GoogleUpdate.exe

    C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe

    C:\Programfiler\Spybot - Search & Destroy\TeaTimer.exe

    C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe

    C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe

    C:\WINDOWS\system32\notepad.exe

    C:\WINDOWS\system32\imapi.exe

    C:\WINDOWS\explorer.exe

    C:\Programfiler\Mozilla Firefox\firefox.exe

    C:\Programfiler\Trend Micro\HijackThis\HijackThis.exe

     

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://ISAFarm:8080/array.dll?Get.Routing.Script

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koblinger

    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programfiler\Fellesfiler\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programfiler\Java\jre1.6.0_07\bin\ssv.dll

    O2 - BHO: Påloggingshjelp for Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programfiler\Fellesfiler\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O4 - HKLM\..\Run: [TPHOTKEY] C:\Programfiler\Lenovo\HOTKEY\TPOSDSVC.exe

    O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe

    O4 - HKLM\..\Run: [TpShocks] TpShocks.exe

    O4 - HKLM\..\Run: [Apoint] C:\Programfiler\Apoint2K\Apoint.exe

    O4 - HKLM\..\Run: [PSQLLauncher] "C:\Programfiler\ThinkVantage Fingerprint Software\launcher.exe" /startup

    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE

    O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor

    O4 - HKLM\..\Run: rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog

    O4 - HKLM\..\Run: [TPFNF7] C:\Programfiler\Lenovo\NPDIRECT\TPFNF7SP.exe /r

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Programfiler\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe

    O4 - HKLM\..\Run: [LPMailChecker] C:\PROGRA~1\THINKV~2\PrdCtr\LPMLCHK.exe

    O4 - HKLM\..\Run: [ccApp] "C:\Programfiler\Fellesfiler\Symantec Shared\ccApp.exe"

    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programfiler\Adobe\Reader 9.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Programfiler\Java\jre1.6.0_07\bin\jusched.exe"

    O4 - HKLM\..\Run: [synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon

    O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe

    O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe

    O4 - HKLM\..\Run: [00saskda] "C:\Programfiler\Security Administrator\newlock.exe" saskda

    O4 - HKCU\..\Run: [steam] "C:\Programfiler\Steam\Steam.exe" -silent

    O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\eriher4\Lokale innstillinger\Programdata\Google\Update\GoogleUpdate.exe" /c

    O4 - HKCU\..\Run: [uberIcon] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe"

    O4 - HKCU\..\Run: [WMPNSCFG] C:\Programfiler\Windows Media Player\WMPNSCFG.exe

    O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Programfiler\Spybot - Search & Destroy\TeaTimer.exe

    O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe

    O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe

    O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe

    O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present

    O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_07\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programfiler\Java\jre1.6.0_07\bin\ssv.dll

    O9 - Extra button: Oppslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programfiler\Messenger\msmsgs.exe

    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1207676639328

    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = hfk.vgs.no

    O17 - HKLM\Software\..\Telephony: DomainName = hfk.vgs.no

    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = hfk.vgs.no

    O23 - Service: Atheros Configuration Service (acs) - Atheros - C:\WINDOWS\system32\acs.exe

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\ccSetMgr.exe

    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Programfiler\Symantec AntiVirus\DefWatch.exe

    O23 - Service: DeskSaverService - Unknown owner - C:\Programfiler\Security Administrator\newlock.exe

    O23 - Service: Google Updater Service (gusvc) - Google - C:\Programfiler\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Programfiler\Hotspot Shield\bin\openvpnas.exe

    O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C:\WINDOWS\system32\ibmpmsvc.exe

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programfiler\Fellesfiler\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: IviRegMgr - InterVideo - C:\Programfiler\Fellesfiler\InterVideo\RegMgr\iviRegMgr.exe

    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Programfiler\Symantec AntiVirus\SavRoam.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\SNDSrvc.exe

    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programfiler\Fellesfiler\Symantec Shared\SPBBC\SPBBCSvc.exe

    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Programfiler\Symantec AntiVirus\Rtvscan.exe

    O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.exe

    O23 - Service: TVersityMediaServer - Unknown owner - C:\Programfiler\TVersity\Media Server\MediaServer.exe

     

    --

    End of file - 9912 bytes

     

×
×
  • Opprett ny...