Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 20:12:07, on 2008-03-11 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program\Glocalnet Bredband\Bredbandsklienten\GlocalnetBredbandService.exe C:\Program\Panda Software\Panda Platinum 2006 Internet Security\PsCtrls.exe C:\Program\Panda Software\Panda Platinum 2006 Internet Security\PavFnSvr.exe C:\Program\Delade filer\Panda Software\PavShld\pavprsrv.exe C:\Program\Panda Software\Panda Platinum 2006 Internet Security\pavsrv51.exe C:\WINDOWS\Explorer.EXE C:\Program\Panda Software\Panda Platinum 2006 Internet Security\AntiSpam\pskmssvc.exe C:\Program\Panda Software\Panda Platinum 2006 Internet Security\AVENGINE.EXE c:\program\panda software\panda platinum 2006 internet security\firewall\PSHOST.EXE C:\Program\Panda Software\Panda Platinum 2006 Internet Security\psimsvc.exe C:\WINDOWS\system32\svchost.exe C:\Program\Panda Software\Panda Platinum 2006 Internet Security\APVXDWIN.EXE C:\Program\Macrogaming\SweetIM\SweetIM.exe C:\Program\Delade filer\Real\Update_OB\realsched.exe C:\WINDOWS\system32\Rundll32.exe C:\Program\FreeMem Standard\freemem.exe C:\Program\Rainlendar\Rainlendar.exe C:\Program\MSN Messenger\msnmsgr.exe C:\Program\Panda Software\Panda Platinum 2006 Internet Security\SRVLOAD.EXE C:\Program\Panda Software\Panda Platinum 2006 Internet Security\WebProxy.exe C:\Program\Panda Software\Panda Platinum 2006 Internet Security\PavBckPT.exe C:\WINDOWS\system32\msiexec.exe C:\Program\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe C:\Program\ULTIMA~1.7\uzip.exe C:\DOCUME~1\YLVA\LOKALA~1\TEMP\HIJACKTHIS.EXE R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://op.se/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: {4a09bfdd-b89d-b578-8284-5dd973e1a570} - {075a1e37-9dd5-4828-875b-d98bddfb90a4} - C:\WINDOWS\system32\nreyrbmp.dll (file missing) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program\Java\jre1.6.0_01\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program\Delade filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [APVXDWIN] "C:\Program\Panda Software\Panda Platinum 2006 Internet Security\APVXDWIN.EXE" /s O4 - HKLM\..\Run: [SCANINICIO] "C:\Program\Panda Software\Panda Platinum 2006 Internet Security\Inicio.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [TkBellExe] "C:\Program\Delade filer\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [08284c73] rundll32.exe "C:\WINDOWS\system32\moprhbah.dll",b O4 - HKLM\..\Run: [BM0b1b7fef] Rundll32.exe "C:\WINDOWS\system32\bnwpneob.dll",s O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win O4 - HKCU\..\Run: [FreeMem Pro] "C:\Program\FreeMem Standard\freemem.exe" Startup O4 - HKCU\..\Run: [msnmsgr] "C:\Program\MSN Messenger\msnmsgr.exe" /background O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: Rainlendar.lnk = C:\Program\Rainlendar\Rainlendar.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java-konsol - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program\Java\jre1.6.0_01\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exe O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program\Yahoo!\Common\yinsthelper.dll O16 - DPF: {361E6B79-4A69-4376-B0F2-3D1EBEE9D7E2} (RtspVaPgCtrl Class) - http://83.227.230.63:8081/RtspVaPgDec.cab O16 - DPF: {745395C8-D0E1-4227-8586-624CA9A10A8D} (AxisMediaControl Class) - http://81.227.165.35//activex/AMC.cab O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - http://www.nanoscan.com/cabs/nanoinst.cab O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://webcam1.vilhelmina.se/activex/AxisCamControl.cab O16 - DPF: {A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C} (VaPgCtrl Class) - http://83.227.230.63/plugin/h263ctrl.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{126EDB8C-16D8-420A-B8F3-933D2E983E1D}: NameServer = 81.216.65.11,81.216.65.12 O17 - HKLM\System\CS1\Services\Tcpip\..\{126EDB8C-16D8-420A-B8F3-933D2E983E1D}: NameServer = 81.216.65.11,81.216.65.12 O17 - HKLM\System\CS2\Services\Tcpip\..\{126EDB8C-16D8-420A-B8F3-933D2E983E1D}: NameServer = 81.216.65.11,81.216.65.12 O20 - Winlogon Notify: !SASWinLogon - C:\Program\SUPERAntiSpyware\SASWINLO.dll O20 - Winlogon Notify: jkkjkhf - jkkjkhf.dll (file missing) O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\dxcktxup.exe (file missing) O23 - Service: Glocalnet Bredband (GlocalnetBredbandClientService) - Glocalnet AB - C:\Program\Glocalnet Bredband\Bredbandsklienten\GlocalnetBredbandService.exe O23 - Service: iPod Service - Apple Inc. - C:\Program\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: Panda Software Controller - Panda Software International - C:\Program\Panda Software\Panda Platinum 2006 Internet Security\PsCtrls.exe O23 - Service: Panda Function Service (PAVFNSVR) - Panda Software International - C:\Program\Panda Software\Panda Platinum 2006 Internet Security\PavFnSvr.exe O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software International - C:\Program\Delade filer\Panda Software\PavShld\pavprsrv.exe O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program\Panda Software\Panda Platinum 2006 Internet Security\pavsrv51.exe O23 - Service: Panda Antispam Engine (pmshellsrv) - Panda Software International - C:\Program\Panda Software\Panda Platinum 2006 Internet Security\AntiSpam\pskmssvc.exe O23 - Service: Panda Host Service (PSHost) - Panda Software International - c:\program\panda software\panda platinum 2006 internet security\firewall\PSHOST.EXE O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program\Panda Software\Panda Platinum 2006 Internet Security\psimsvc.exe -- End of file - 7777 bytes