Hej!
Jag har fått lop i min dator och kan inte bli av med eländet hur jag än gör. Jag skulle bli jätteblad om någon kan hjälpa mig.
Här är min hijack this logg och därefter adaware:
Logfile of HijackThis v1.99.1
Scan saved at 10:10:13, on 2005-09-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program\Delade filer\Symantec Shared\ccProxy.exe
C:\Program\Delade filer\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program\VPN\VPN Client\icsrv.exe
C:\Program\Delade filer\Microsoft Shared\VS7Debug\mdm.exe
C:\Program\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\Program\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE
C:\Program\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program\Lexmark X74-X75\lxbbbmgr.exe
C:\Program\QuickLib\QuickLibSysTray.exe
C:\Program\Lexmark X74-X75\lxbbbmon.exe
C:\Program\ekort\ekort.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program\Microsoft Hardware\Mouse\point32.exe
C:\Program\Delade filer\Symantec Shared\ccApp.exe
C:\Program\Microsoft Hardware\Keyboard\type32.exe
C:\Program\Winamp\winampa.exe
C:\Program\QuickTime\qttask.exe
C:\Program\Delade filer\Symantec Shared\SNDSrvc.exe
C:\Program\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Creative\MediaSource\Detector\CTDetect.exe
C:\WINDOWS\System32\svchost.exe
C:\Program\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program\Delade filer\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program\Delade filer\Symantec Shared\ccEvtMgr.exe
C:\Program\Delade filer\Symantec Shared\Security Center\SymWSC.exe
C:\Program\iPod\bin\iPodService.exe
C:\Program\Messenger\msmsgs.exe
C:\Documents and Settings\Gitte\Skrivbord\HijackThis-2.exe <=HiJack This felaktigt placerad:
Adaware:
Ad-Aware SE Build 1.06r1
Loggfil skapad den:den 25 september 2005 08:45:28
Created with Ad-Aware SE Personal, free for private use.
Använder definitionsfil:SE1R67 20.09.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Referenser som upptäcktes under genomsökningen:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
123Search(TAC-index:2):8 antal referenser
Lop(TAC-index:7):3 antal referenser
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Ange : Search for low-risk threats
Ange : Safe mode (begär alltid bekräftelse)
Ange : Genomsök aktiva processer
Ange : Genomsök register
Ange : Djupsök i registret
Ange : Sök IE-Favoriter efter spärrade URL:er
Ange : Genomsök min värdfil
Extended Ad-Aware SE Settings
===========================
Ange : Inaktivera igenkända processer och moduler under genomsökning
Ange : Genomsök registret efter alla användare i stället för endast aktuell användare
Ange : Försök alltid att inaktivera modulerna före borttagning
Ange : Inaktivera om nödvändigt Explorer och IE under borttagningen
Ange : Låt Windows ta bort filer som används vid nästa omstart
Ange : Ta bort objekt i karantän efter återställning
Ange : Inkludera grundläggande inställningar för Ad-Aware i loggfil
Ange : Inkludera ytterligare inställningar för Ad-Aware i loggfil
Ange : Inkludera referenssammanfattning i loggfil
Ange : Inkludera information för alternerande dataström (ADS) i loggfil
Ange : Spela upp ljud vid slutförd genomsökning om riskobjekt hittas
2005-09-25 08:45:28 - Genomsökningen har startats. (Fullständig genomsökning av systemet)
Visar processer som körs
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 636
ThreadCreationTime : 2005-09-24 11:41:16
BasePriority : Normal
#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 748
ThreadCreationTime : 2005-09-24 11:41:22
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 776
ThreadCreationTime : 2005-09-24 11:41:27
BasePriority : High
#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 820
ThreadCreationTime : 2005-09-24 11:41:27
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Operativsystemet Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Tjänst- och styrenhetsprogram
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. Med ensamrätt.
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 832
ThreadCreationTime : 2005-09-24 11:41:28
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1012
ThreadCreationTime : 2005-09-24 11:41:29
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1068
ThreadCreationTime : 2005-09-24 11:41:30
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1168
ThreadCreationTime : 2005-09-24 11:41:30
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:9 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1232
ThreadCreationTime : 2005-09-24 11:41:30
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:10 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1360
ThreadCreationTime : 2005-09-24 11:41:31
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:11 [devldr32.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1420
ThreadCreationTime : 2005-09-24 11:41:31
BasePriority : Normal
FileVersion : 1, 0, 0, 22
ProductVersion : 1, 0, 0, 22
ProductName : Creative Ring3 NT Inteface
CompanyName : Creative Technology Ltd.
FileDescription : DevLdr32
InternalName : DevLdr
LegalCopyright : Copyright © 1997-2001 Creative Technology Ltd.
OriginalFilename : DevLdr32.exe
#:12 [lexbces.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1604
ThreadCreationTime : 2005-09-24 11:41:33
BasePriority : Normal
FileVersion : 7.4
ProductVersion : 7.4
ProductName : MarkVision for Windows (32 bit)
CompanyName : Lexmark International, Inc.
FileDescription : LexBce Service
InternalName : LexBce Service
LegalCopyright : (C) 1993 - 2002 Lexmark International, Inc.
OriginalFilename : LexBceS.exe
#:13 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1632
ThreadCreationTime : 2005-09-24 11:41:33
BasePriority : Normal
FileVersion : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)
ProductVersion : 5.1.2600.2696
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe
#:14 [lexpps.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1680
ThreadCreationTime : 2005-09-24 11:41:33
BasePriority : Normal
FileVersion : 7.4
ProductVersion : 7.4
ProductName : MarkVision for Windows (32 bit)
CompanyName : Lexmark International, Inc.
FileDescription : LEXPPS.EXE
InternalName : LEXPPS
LegalCopyright : (C) 1993 - 2002 Lexmark International, Inc.
OriginalFilename : LEXPPS.EXE
Comments : MarkVision for Windows '95 New P2P Server (32-bit)
#:15 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 460
ThreadCreationTime : 2005-09-24 11:41:40
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Operativsystemet Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Utforskaren
InternalName : explorer
LegalCopyright : © Microsoft Corporation. Med ensamrätt.
OriginalFilename : EXPLORER.EXE
#:16 [photoshopelementsfileagent.exe]
FilePath : C:\Program\Adobe\Photoshop Elements 3.0\
ProcessID : 584
ThreadCreationTime : 2005-09-24 11:41:41
BasePriority : Normal
#:17 [ccproxy.exe]
FilePath : C:\Program\Delade filer\Symantec Shared\
ProcessID : 392
ThreadCreationTime : 2005-09-24 11:41:41
BasePriority : Normal
FileVersion : 2.1.6.3
ProductVersion : 2.1.6.3
ProductName : Common Client
CompanyName : Symantec Corporation
FileDescription : Common Client Network Proxy Service
InternalName : ccProxy
LegalCopyright : Copyright (c) 2000-2003 Symantec Corporation. All rights reserved.
OriginalFilename : ccProxy.exe
#:18 [ccsetmgr.exe]
FilePath : C:\Program\Delade filer\Symantec Shared\
ProcessID : 624
ThreadCreationTime : 2005-09-24 11:41:41
BasePriority : Normal
FileVersion : 2.1.6.3
ProductVersion : 2.1.6.3
ProductName : Common Client
CompanyName : Symantec Corporation
FileDescription : Common Client Settings Manager Service
InternalName : ccSetMgr
LegalCopyright : Copyright (c) 2000-2003 Symantec Corporation. All rights reserved.
OriginalFilename : ccSetMgr.exe
#:19 [ctsvccda.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 656
ThreadCreationTime : 2005-09-24 11:41:42
BasePriority : Normal
FileVersion : 1.0.1.0
ProductVersion : 1.0.0.0
ProductName : Creative Service for CDROM Access
CompanyName : Creative Technology Ltd
FileDescription : Creative Service for CDROM Access
InternalName : CTsvcCDAEXE
LegalCopyright : Copyright (c) Creative Technology Ltd., 1999. All rights reserved.
OriginalFilename : CTsvcCDA.EXE
#:20 [icsrv.exe]
FilePath : C:\Program\VPN\VPN Client\
ProcessID : 688
ThreadCreationTime : 2005-09-24 11:41:42
BasePriority : Normal
#:21 [mdm.exe]
FilePath : C:\Program\Delade filer\Microsoft Shared\VS7Debug\
ProcessID : 344
ThreadCreationTime : 2005-09-24 11:41:42
BasePriority : Normal
FileVersion : 7.00.9466
ProductVersion : 7.00.9466
ProductName : Microsoft® Visual Studio .NET
CompanyName : Microsoft Corporation
FileDescription : Machine Debug Manager
InternalName : mdm.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : mdm.exe
#:22 [navapsvc.exe]
FilePath : C:\Program\Norton Internet Security\Norton AntiVirus\
ProcessID : 728
ThreadCreationTime : 2005-09-24 11:41:42
BasePriority : Normal
FileVersion : 10.00.2
ProductVersion : 10.00.2
ProductName : Norton AntiVirus
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Auto-Protect Service
InternalName : NAVAPSVC
LegalCopyright : Norton AntiVirus 2004 for Windows 98/ME/2000/XP Copyright (c) 2003 Symantec Corporation. All rights reserved.
OriginalFilename : NAVAPSVC.EXE
#:23 [diagent.exe]
FilePath : C:\Program\Creative\SBLive\Creative Diagnostics 2.0\
ProcessID : 1156
ThreadCreationTime : 2005-09-24 11:41:44
BasePriority : Normal
FileVersion : 1.0.10.0
ProductVersion : 1.00.10
ProductName : Creative Diagnostics Agent
CompanyName : Creative Technology Ltd
FileDescription : Creative Diagnostics Agent
InternalName : Creative Diagnostics Agent
LegalCopyright : Copyright (C) 2001 Creative Technology Ltd
OriginalFilename : diagent.exe
#:24 [directcd.exe]
FilePath : C:\Program\Roxio\Easy CD Creator 5\DirectCD\
ProcessID : 1208
ThreadCreationTime : 2005-09-24 11:41:44
BasePriority : Normal
FileVersion : 5.3.2.34
ProductVersion : 5.3.2.34
ProductName : DirectCD
CompanyName : Roxio
FileDescription : DirectCD Application
InternalName : DirectCD
LegalCopyright : Copyright (c) 2001,2002, Roxio, Inc.
OriginalFilename : Directcd.exe
#:25 [lxbbbmgr.exe]
FilePath : C:\Program\Lexmark X74-X75\
ProcessID : 1280
ThreadCreationTime : 2005-09-24 11:41:44
BasePriority : Normal
FileVersion : 1.0.5.3
ProductVersion : 1.0.5.3
ProductName : Button Manager Executable
CompanyName : Lexmark International, Inc.
FileDescription : Lexmark X74-X75 Button Manager
InternalName : lxbbbmgr.exe
LegalCopyright : (C) 2002 Lexmark International, Inc.
OriginalFilename : lxbbbmgr.exe
#:26 [quicklibsystray.exe]
FilePath : C:\Program\QuickLib\
ProcessID : 1264
ThreadCreationTime : 2005-09-24 11:41:44
BasePriority : Normal
#:27 [ekort.exe]
FilePath : C:\Program\ekort\
ProcessID : 1300
ThreadCreationTime : 2005-09-24 11:41:44
BasePriority : Normal
FileVersion : 2, 4, 0, 1, 81
ProductVersion : 2, 4, 0, 1, 81
ProductName : Swedbank e-kort
CompanyName : Orbiscom Ltd. All rights reserved.
FileDescription : Swedbank e-kort
InternalName : WEBOCARD
LegalCopyright : Copyright © 1999-2002, Orbiscom Ltd.
All rights reserved.
OriginalFilename : WebOCard.EXE
#:28 [rundll32.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1296
ThreadCreationTime : 2005-09-24 11:41:44
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Operativsystemet Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Kör en DLL-fil som ett program
InternalName : rundll
LegalCopyright : © Microsoft Corporation. Med ensamrätt.
OriginalFilename : RUNDLL.EXE
#:29 [lxbbbmon.exe]
FilePath : C:\Program\Lexmark X74-X75\
ProcessID : 1308
ThreadCreationTime : 2005-09-24 11:41:44
BasePriority : Normal
FileVersion : 1.0.5.3
ProductVersion : 1.0.5.3
ProductName : Button Monitor Executable
CompanyName : Lexmark International, Inc.
FileDescription : Lexmark X74-X75 Button Monitor
InternalName : lxbbbmon.exe
LegalCopyright : (C) 2002 Lexmark International, Inc.
OriginalFilename : lxbbbmon.exe
#:30 [point32.exe]
FilePath : C:\Program\Microsoft Hardware\Mouse\
ProcessID : 1384
ThreadCreationTime : 2005-09-24 11:41:44
BasePriority : Normal
#:31 [ccapp.exe]
FilePath : C:\Program\Delade filer\Symantec Shared\
ProcessID : 1388
ThreadCreationTime : 2005-09-24 11:41:45
BasePriority : Normal
FileVersion : 2.1.6.3
ProductVersion : 2.1.6.3
ProductName : Common Client
CompanyName : Symantec Corporation
FileDescription : Common Client User Session
InternalName : ccApp
LegalCopyright : Copyright (c) 2000-2003 Symantec Corporation. All rights reserved.
OriginalFilename : ccApp.exe
#:32 [type32.exe]
FilePath : C:\Program\Microsoft Hardware\Keyboard\
ProcessID : 1448
ThreadCreationTime : 2005-09-24 11:41:45
BasePriority : Normal
#:33 [winampa.exe]
FilePath : C:\Program\Winamp\
ProcessID : 1536
ThreadCreationTime : 2005-09-24 11:41:45
BasePriority : Normal
#:34 [nvsvc32.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1568
ThreadCreationTime : 2005-09-24 11:41:46
BasePriority : Normal
FileVersion : 6.14.10.5216
ProductVersion : 6.14.10.5216
ProductName : NVIDIA Driver Helper Service, Version 52.16
CompanyName : NVIDIA Corporation
FileDescription : NVIDIA Driver Helper Service, Version 52.16
InternalName : NVSVC
LegalCopyright : (C) NVIDIA Corporation. All rights reserved.
OriginalFilename : nvsvc32.exe
#:35 [qttask.exe]
FilePath : C:\Program\QuickTime\
ProcessID : 1724
ThreadCreationTime : 2005-09-24 11:41:46
BasePriority : Normal
FileVersion : 6.5.1
ProductVersion : QuickTime 6.5.1
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
InternalName : QuickTime Task
LegalCopyright : © Apple Computer, Inc. 2001-2004
OriginalFilename : QTTask.exe
#:36 [photoshopelementsdeviceconnect.exe]
FilePath : C:\Program\Adobe\Photoshop Elements 3.0\
ProcessID : 1812
ThreadCreationTime : 2005-09-24 11:41:47
BasePriority : Normal
#:37 [ituneshelper.exe]
FilePath : C:\Program\iTunes\
ProcessID : 964
ThreadCreationTime : 2005-09-24 11:41:47
BasePriority : Normal
FileVersion : 4.9.0.17
ProductVersion : 4.9.0.17
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iTunesHelper Module
InternalName : iTunesHelper
LegalCopyright : © 2003-2005 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iTunesHelper.exe
#:38 [ctfmon.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1676
ThreadCreationTime : 2005-09-24 11:41:48
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CTFMON.EXE
#:39 [savscan.exe]
FilePath : C:\Program\Norton Internet Security\Norton AntiVirus\
ProcessID : 1928
ThreadCreationTime : 2005-09-24 11:41:48
BasePriority : Normal
ProductVersion : 9.2
ProductName : Symantec AntiVirus AutoProtect
CompanyName : Symantec Corporation
FileDescription : Symantec AntiVirus Scanner
InternalName : SAVSCAN
LegalCopyright : Copyright (c) 2004 Symantec Corporation
OriginalFilename : SAVSCAN.EXE
#:40 [ctdetect.exe]
FilePath : C:\Program\Creative\MediaSource\Detector\
ProcessID : 352
ThreadCreationTime : 2005-09-24 11:41:49
BasePriority : Normal
FileVersion : 2.3.1.0
ProductVersion : 2.3.0.0
ProductName : Creative MediaSource Detector
CompanyName : Creative Technology Ltd
FileDescription : Creative MediaSource Detector
InternalName : CTDetect
LegalCopyright : Copyright (c) Creative Technology Ltd., 2003-2004. All rights reserved.
OriginalFilename : CTDetect.EXE
#:41 [sndsrvc.exe]
FilePath : C:\Program\Delade filer\Symantec Shared\
ProcessID : 220
ThreadCreationTime : 2005-09-24 11:41:50
BasePriority : Normal
FileVersion : 5.5.1.6
ProductVersion : 5.5
ProductName : Symantec Security Drivers
CompanyName : Symantec Corporation
FileDescription : Network Driver Service
InternalName : SndSrvc
LegalCopyright : Copyright 2002, 2003, 2004 Symantec Corporation
OriginalFilename : SndSrvc.exe
#:42 [acrotray.exe]
FilePath : C:\Program\Adobe\Acrobat 6.0\Distillr\
ProcessID : 1204
ThreadCreationTime : 2005-09-24 11:41:51
BasePriority : Normal
FileVersion : 6.0.1.2003102300
ProductVersion : 6.0.1.2003102300
ProductName : AcroTray - Adobe Acrobat Distiller helper application.
CompanyName : Adobe Systems Inc.
FileDescription : AcroTray
InternalName : AcroTray
LegalCopyright : Copyright 1984-2003 Adobe Systems Incorporated and its licensors. All rights reserved.
OriginalFilename : AcroTray.exe
#:43 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1492
ThreadCreationTime : 2005-09-24 11:41:51
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:44 [ulcdrsvr.exe]
FilePath : C:\Program\Delade filer\Ulead Systems\DVD\
ProcessID : 2092
ThreadCreationTime : 2005-09-24 11:41:53
BasePriority : Normal
FileVersion : 1, 0, 0, 3
ProductVersion : 1, 0, 0, 3
ProductName : Ulead Systems ULCDRSvr
CompanyName : Ulead Systems, Inc.
FileDescription : ULCDRSvr
InternalName : ULCDRSvr
LegalCopyright : Copyright © 2002 Ulead Systems, Inc.
OriginalFilename : ULCDRSvr.exe
#:45 [wdfmgr.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 2136
ThreadCreationTime : 2005-09-24 11:41:53
BasePriority : Normal
FileVersion : 5.2.3790.1230 built by: dnsrv(bld4act)
ProductVersion : 5.2.3790.1230
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows User Mode Driver Manager
InternalName : WdfMgr
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WdfMgr.exe
#:46 [mspmspsv.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2208
ThreadCreationTime : 2005-09-24 11:41:53
BasePriority : Normal
FileVersion : 7.00.00.1954
ProductVersion : 7.00.00.1954
ProductName : Microsoft (R) DRM
CompanyName : Microsoft Corporation
FileDescription : WMDM PMSP Service
InternalName : MSPMSPSV.EXE
LegalCopyright : Copyright (C) Microsoft Corp. 1981-2000
OriginalFilename : MSPMSPSV.EXE
#:47 [ccevtmgr.exe]
FilePath : C:\Program\Delade filer\Symantec Shared\
ProcessID : 2244
ThreadCreationTime : 2005-09-24 11:41:53
BasePriority : Normal
FileVersion : 2.1.6.3
ProductVersion : 2.1.6.3
ProductName : Common Client
CompanyName : Symantec Corporation
FileDescription : Common Client Event Manager Service
InternalName : ccEvtMgr
LegalCopyright : Copyright (c) 2000-2003 Symantec Corporation. All rights reserved.
OriginalFilename : ccEvtMgr.exe
#:48 [symwsc.exe]
FilePath : C:\Program\Delade filer\Symantec Shared\Security Center\
ProcessID : 2276
ThreadCreationTime : 2005-09-24 11:41:54
BasePriority : Normal
FileVersion : 2005.1.2.20
ProductVersion : 2005.1
ProductName : Norton Security Center
CompanyName : Symantec Corporation
FileDescription : Norton Security Center Service
InternalName : SymWSC.exe
LegalCopyright : Copyright (c) 1997-2004 Symantec Corporation
OriginalFilename : SymWSC.exe
#:49 [iexplore.exe]
FilePath : C:\Program\Internet Explorer\
ProcessID : 2344
ThreadCreationTime : 2005-09-24 11:41:54
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Operativsystemet Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : © Microsoft Corporation. Med ensamrätt.
OriginalFilename : IEXPLORE.EXE
#:50 [ipodservice.exe]
FilePath : C:\Program\iPod\bin\
ProcessID : 2952
ThreadCreationTime : 2005-09-24 11:42:01
BasePriority : Normal
FileVersion : 4.9.0.17
ProductVersion : 4.9.0.17
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iPodService Module
InternalName : iPodService
LegalCopyright : © 2003-2005 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iPodService.exe
#:51 [alg.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 3368
ThreadCreationTime : 2005-09-24 11:42:08
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe
#:52 [iexplore.exe]
FilePath : c:\program\intern~1\
ProcessID : 5992
ThreadCreationTime : 2005-09-24 16:28:12
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Operativsystemet Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : © Microsoft Corporation. Med ensamrätt.
OriginalFilename : IEXPLORE.EXE
Lop Igenkända objekt!
Typ : Process
Data : dafpwgfy.exe
TAC-värde : 7
Kategori : Malware
Kommentar : (CSI MATCH)
Objekt : c:\docume~1\gitte\lokala~1\temp\
Varning! Lop Objekt har hittats i minnet(c:\docume~1\gitte\lokala~1\temp\dafpwgfy.exe)
"c:\docume~1\gitte\lokala~1\temp\dafpwgfy.exe"Processen är slutförd
"c:\program\intern~1\iexplore.exe"Processen är slutförd
#:53 [msnmsgr.exe]
FilePath : C:\Program\MSN Messenger\
ProcessID : 8712
ThreadCreationTime : 2005-09-25 01:42:19
BasePriority : Normal
FileVersion : 7.0.0816
ProductVersion : 7.0.0816
ProductName : MSN Messenger
CompanyName : Microsoft Corporation
FileDescription : MSN Messenger
InternalName : msnmsgr
LegalCopyright : Copyright (c) Microsoft Corporation 1997-2005
LegalTrademarks : Microsoft(R) is a registered trademark of Microsoft Corporation in the U.S. and/or other countries.
OriginalFilename : msnmsgr.exe
#:54 [dcplusplus.exe]
FilePath : C:\Program\DC++\
ProcessID : 8336
ThreadCreationTime : 2005-09-25 01:50:04
BasePriority : Normal
FileVersion : 0, 6, 6, 7
ProductVersion : 0, 6, 6, 7
ProductName : DC++
FileDescription : DC++
InternalName : DC++
LegalCopyright : Copyright 2001-2004 Jacek Sieka
OriginalFilename : DCPlusPlus.exe
Comments : http://dcplusplus.sourceforge.net
#:55 [ad-aware.exe]
FilePath : C:\Program\Lavasoft\Ad-Aware SE Personal\
ProcessID : 11108
ThreadCreationTime : 2005-09-25 06:44:27
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Resultat från minnesgenomsökning:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Nya riskobjekt: 1
Hittills funna objekt: 1
Startade genomsökning av register
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Resultat från genomsökning av register:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Nya riskobjekt: 0
Hittills funna objekt: 1
Startade djupsökning i register
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
123Search Igenkända objekt!
Typ : RegValue
Data :
TAC-värde : 0
Kategori : Data Miner
Kommentar : "16 Live"
Rootkey : HKEY_CURRENT_USER
Objekt : Software\Microsoft\Windows\CurrentVersion\Run
Värde : 16 Live
123Search Igenkända objekt!
Typ : Fil
Data : bows tick.exe
TAC-värde : 0
Kategori : Data Miner
Kommentar :
Objekt : c:\docume~1\gitte\applic~1\closeu~1\
Resultat från djupsökning av register:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Nya riskobjekt: 1
Hittills funna objekt: 3
Startade genomsökning efter cookies
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Resultat av genomsökning efter cookies:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Nya riskobjekt: 0
Hittills funna objekt: 3
Djupsöker och undersöker filer (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
123Search Igenkända objekt!
Typ : Fil
Data : bows tick.exe
TAC-värde : 0
Kategori : Data Miner
Kommentar :
Objekt : C:\Documents and Settings\Gitte\Application Data\Close User Software\
123Search Igenkända objekt!
Typ : Fil
Data : dafpwgfy.exe
TAC-värde : 0
Kategori : Data Miner
Kommentar :
Objekt : C:\Documents and Settings\Gitte\Lokala inställningar\Temp\
123Search Igenkända objekt!
Typ : Fil
Data : A0104864.exe
TAC-värde : 0
Kategori : Data Miner
Kommentar :
Objekt : C:\System Volume Information\_restore{D91440D9-A0AE-4A8D-93E5-1721A6531EA0}\RP162\
123Search Igenkända objekt!
Typ : Fil
Data : A0104940.exe
TAC-värde : 0
Kategori : Data Miner
Kommentar :
Objekt : C:\System Volume Information\_restore{D91440D9-A0AE-4A8D-93E5-1721A6531EA0}\RP164\
123Search Igenkända objekt!
Typ : Fil
Data : A0105069.exe
TAC-värde : 0
Kategori : Data Miner
Kommentar :
Objekt : C:\System Volume Information\_restore{D91440D9-A0AE-4A8D-93E5-1721A6531EA0}\RP166\
123Search Igenkända objekt!
Typ : Fil
Data : A0110270.exe
TAC-värde : 0
Kategori : Data Miner
Kommentar :
Objekt : C:\System Volume Information\_restore{D91440D9-A0AE-4A8D-93E5-1721A6531EA0}\RP172\
Resultat från genomsökning av disk C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Nya riskobjekt: 0
Hittills funna objekt: 9
Genomsöker värdfil......
Värdfilens plats:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Resultat från genomsökning av värdfil:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
1 poster har genomsökts.
Nya riskobjekt:0
Hittills funna objekt: 9
Utför anpassade genomsökningar...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Lop Igenkända objekt!
Typ : RegValue
Data :
TAC-värde : 7
Kategori : Malware
Kommentar :
Rootkey : HKEY_CURRENT_USER
Objekt : software\microsoft\internet explorer\main
Värde : Search Bar
Lop Igenkända objekt!
Typ : RegValue
Data :
TAC-värde : 7
Kategori : Malware
Kommentar :
Rootkey : HKEY_CURRENT_USER
Objekt : software\microsoft\internet explorer\main
Värde : Use Custom Search URL
Resultat från anpassad genomsökning:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Nya riskobjekt: 2
Hittills funna objekt: 11
09:03:43 Genomsökning klar
Sammanf. av genomsökn.
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total genomsökn.tid:00:18:14.937
Objekt som genomsökts:184230
Objekt som identifierats:11
Objekt som ignorerats:0
Nya riskobjekt:11
Hälsningar Esmeralda
[Redigerad: Ofullständig HJT-log (Felplacerad)]
Malou


, frågan var om den tjänsten använder en proxy, det är det som är det kluriga eller om det är VPN klienten som byggt denna proxy, något annat "otyg" eller något "klåfinger" 