Her er min log er nok lidt amatør her men har mistanke om en mailer er på min maskine.
Jeg har en entry i HLM/software/microsoft/windows/currentversion/run/optionalcomponents/IMAIL/ installed 1 .
Her er min log hjælp mig plz!!!!
Logfile of HijackThis v1.97.7
Scan saved at 01:55:36, on 25-04-2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSSystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:ProgrammerFælles filerSymantec SharedccSetMgr.exe
C:ProgrammerFælles filerSymantec SharedccEvtMgr.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:ProgrammerNorton AntiVirus
avapsvc.exe
C:ProgrammerAnalog DevicesSoundMAXSMAgent.exe
C:ProgrammerFælles filerSymantec SharedccApp.exe
C:ProgrammerLabtecLabtec Keyboard-Desktop SoftwareDsiMmKbd.EXE
C:ProgrammerQuickTimeqttask.exe
C:ProgrammerAnalog DevicesSoundMAXSMax4PNP.exe
C:ProgrammerAnalog DevicesSoundMAXSmax4.exe
C:ProgrammerATI TechnologiesATI Control Panelatiptaxx.exe
C:WINDOWSSystem32ctfmon.exe
C:ProgrammerMessengermsmsgs.exe
C:ProgrammerSkypePhoneSkype.exe
C:ProgrammerNorton AntiVirusSAVScan.exe
C:ProgrammerKiSS TechnologyKiSS PC-LinkKiSS PC-Link.exe
C:ProgrammerInternet Exploreriexplore.exe
C:WINDOWS
egedit.exe
D:BACKUPwormkillHijackThis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Hyperlinks
R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,Shellnext =
http://www.dvddecrypter.com[...]
O2 - BHO: (no name) - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:ProgrammerDAPDAPBHO.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:ProgrammerAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:ProgrammerNorton AntiVirusNavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:ProgrammerNorton AntiVirusNavShExt.dll
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:ProgrammerDAPDAPIEBar.dll
O4 - HKLM..Run: [ccApp] "C:ProgrammerFælles filerSymantec SharedccApp.exe"
O4 - HKLM..Run: [LabtecKB] C:ProgrammerLabtecLabtec Keyboard-Desktop SoftwareDsiMmKbd.EXE
O4 - HKLM..Run: [QuickTime Task] "C:ProgrammerQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [PtiuPbmd] Rundll32.exe ptipbm.dll,SetWriteBack
O4 - HKLM..Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM..Run: [SoundMAXPnP] C:ProgrammerAnalog DevicesSoundMAXSMax4PNP.exe
O4 - HKLM..Run: [SoundMAX] "C:ProgrammerAnalog DevicesSoundMAXSmax4.exe" /tray
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [ATIPTA] C:ProgrammerATI TechnologiesATI Control Panelatiptaxx.exe
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 - HKCU..Run: [MSMSGS] "C:ProgrammerMessengermsmsgs.exe" /background
O4 - HKCU..Run: [Skype] "C:ProgrammerSkypePhoneSkype.exe" /nosplash /minimized
O4 - Global Startup: Microsoft Office.lnk = C:ProgrammerMicrosoft OfficeOffice10OSA.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:PROGRA~1INCRED~1in
esourcesWebMenuImg.htm
O8 - Extra context menu item: &Download with &DAP - C:PROGRA~1DAPdapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:PROGRA~1DAPdapextie2.htm
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 - Extra button: Run DAP (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) -
https://www-secure.symantec.com[...]
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com[...]
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) -
https://www-secure.symantec.com[...]
Tak på forhånd Armagedon :)
--
For dem der har viljen i hjertet er intet umuligt. CLICK,N,LOAD