HEE Skrevet 3. juni 2006 Del Skrevet 3. juni 2006 hallo folkens.. har i den siste tiden hatt en pop up som kaller seg ul window seek.. popper opp med noe spill reklame og dritt.. tenkte jaha jeg for laste ned noe spy bot ad-aware og litt diverse "værktøy" men etter og har kjørt alle desse så er den fremdeles der! begynner og bli kraftig iritert på denne.. i need some advices now har kjørt kompless scanning av både antivirus og ad.aware.. og spy bot både normal modus og advances.. sett i reg edit og i oppstart.. ms config og brukt andre oppstart programmer somone help me please ? Lenke til kommentar
berxter Skrevet 3. juni 2006 Del Skrevet 3. juni 2006 Vi behøver å få en titt på en HijackThislogg. Du finner HJT blant annet hos merijn.org. Bernt K Lenke til kommentar
HEE Skrevet 3. juni 2006 Forfatter Del Skrevet 3. juni 2006 Logfile of HijackThis v1.99.1 Scan saved at 03:42:08, on 24.05.2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\MessengerPlus! 3\MsgPlus.exe C:\Program Files\ICQLite\ICQLite.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\DAEMON Tools\daemon.exe C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE C:\Program Files\Macrogaming\SweetIM\SweetIM.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe C:\Program Files\DeskSite\binex\DeskSiteCMA.exe C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe C:\Program Files\Eset\nod32krn.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Outlook Express\msimn.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Håkon\Desktop\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.vg.no/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.vg.no/ R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll R3 - URLSearchHook: (no name) - {69EA67FA-FB60-FDCF-3527-FF6A66A98D91} - C:\WINDOWS\system32\kldxzr.dll (file missing) O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" O4 - HKLM\..\Run: [nod32kui] C:\Program Files\Eset\nod32kui.exe /WAITSERVICE O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [iCQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [inCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe O4 - HKLM\..\Run: [sweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [sweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe O4 - HKCU\..\RunOnce: [iCQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot O4 - Global Startup: Hurtigstart for Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing) O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing) O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Program Files\nordicbetMPP\MPPoker.exe O9 - Extra button: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk O9 - Extra 'Tools' menuitem: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: wineak32 - C:\WINDOWS\SYSTEM32\wineak32.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: DeskSiteCMA - - C:\Program Files\DeskSite\binex\DeskSiteCMA.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Program Files\Eset\nod32krn.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe here you go man Lenke til kommentar
berxter Skrevet 3. juni 2006 Del Skrevet 3. juni 2006 (endret) Tja, denne var da ikke så ille? Har du selv installert PartyPoker? Få HJT til å fikse R3 - URLSearchHook: (no name) - {69EA67FA-FB60-FDCF-3527-FF6A66A98D91} - C:\WINDOWS\system32\kldxzr.dll (file missing) O20 - Winlogon Notify: wineak32 - C:\WINDOWS\SYSTEM32\wineak32.dll Denne må vekk: C:\WINDOWS\SYSTEM32\wineak32.dll Det kan hende du må bruke Killbox i safe mode for å fjerne den. Da du installerte MSGPlus, valgte du advanced og ikke sponsored? Dersom du la inn den sponsored anbefaler jeg å avinstallere den og installere på ny, denne gang ikke "sponsored". Så, min anbefaling er: -Last ned Killbox og lim inn C:\WINDOWS\SYSTEM32\wineak32.dll, delete on reboot -Få HJT til å fikse linjene som nevnt -Skaff ccleaner, kjør den -Reboot -Kjør en Panda Activescan husk see report og save report (vær så snill og kjør ccleaner først...) -Legg ut Pandaloggen og en fersk HJTlogg. EDIT: Javainstallasjonen din er herpa. Avinstaller den, slett folderen(C:\Program Files\Java ) og hent deg en ny fra http://www.java.com/en/download/manual.jsp Husk at nettleseren din må være lukket mens du installerer Java! Bernt K Endret 3. juni 2006 av berxter Lenke til kommentar
HEE Skrevet 3. juni 2006 Forfatter Del Skrevet 3. juni 2006 Incident Status Location Adware:Adware/PurityScan Not disinfected C:\!KillBox\wineak32.dll Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.tribalfusion.com/] Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.advertising.com/] Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.tradedoubler.com/] Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.mediaplex.com/] Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.2o7.net/] Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.112.2o7.net/] Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.2o7.net/] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[ad.yieldmanager.com/] Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.fastclick.net/] Spyware:Cookie/Rn11 Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.rn11.com/] Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.trafficmp.com/] Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.qksrv.net/] Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.apmebf.com/] Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.doubleclick.net/] Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.casalemedia.com/] Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.adtech.de/] Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.atdmt.com/] Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.hotlog.ru/] Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.yadro.ru/] Spyware:Cookie/SpyLog Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.spylog.com/] Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.errorsafe.com/] Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[www.errorsafe.com/] Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[stats1.reliablestats.com/] Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.bluestreak.com/] Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.serving-sys.com/] Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.bs.serving-sys.com/] Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.serving-sys.com/] Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.microsofteup.112.2o7.net/] Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.247realmedia.com/] Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.adopt.hbmediapro.com/] Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.ads.pointroll.com/] Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.atwola.com/] Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.azjmp.com/] Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.belnk.com/] Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.bravenet.com/] Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.burstnet.com/] Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.com.com/] Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.go.com/] Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.maxserving.com/] Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.overture.com/] Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.questionmarket.com/] Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.realmedia.com/] Spyware:Cookie/Research-int Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.research-int.se/] Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.revenue.net/] Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.statcounter.com/] Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.toplist.cz/] Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.xiti.com/] Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.xmts.net/] Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.zedo.com/] Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[landing.domainsponsor.com/] Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[searchportal.information.com/] Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[server.iad.liveperson.net/] Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[server.iad.liveperson.net/hc/80570461] Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[server.iad.liveperson.net/hc/LPneimanmarcus] Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[stat.onestat.com/] Adware:adware/securityerror Not disinfected C:\Documents and Settings\Håkon\Favorites\Antivirus Test Online.url Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\Håkon\My Documents\M?crosoft\dexplore.exe Adware:Adware/SaveNow Not disinfected C:\Program Files\DAEMON Tools\SetupDTSB.exe Spyware:Spyware/New.net Not disinfected C:\WINDOWS\NDNuninstall7_22.exe Adware:Adware/SpyFalcon Not disinfected C:\WINDOWS\system32\1024\ld7A66.tmp Adware:Adware/EMediaCodec Not disinfected C:\WINDOWS\system32\atmclk.ex$ Adware:Adware/SecurityError Not disinfected C:\WINDOWS\system32\dcomcfg.exe Adware:Adware/SpyFalcon Not disinfected C:\WINDOWS\system32\fyhhxw.dl$ Adware:Adware/SecurityError Not disinfected C:\WINDOWS\system32\ld84C0.tmp Adware:Adware/MediaTickets Not disinfected C:\WINDOWS\system32\oins.exe Adware:Adware/SecurityError Not disinfected C:\WINDOWS\system32\regperf.ex$ here you go Lenke til kommentar
berxter Skrevet 3. juni 2006 Del Skrevet 3. juni 2006 (endret) Søtten, sa jeg ikke at du skulle kjøre ccleaner før Panda? Vel, jeg ser en SmitFraudvariant her. Last ned SmitFraudFix og kjør i safe mode. Du kan godt velge alternativ 2 med en gang. Så ccleaner Vi fikk opp i tillegg new.net, purityscan og SaveNow. Newdotnet og SaveNow skal du normalt kunne avinstallere i kontrollpanelet, men det virker ikke alltid. Prøv først. Purityscan gir seg ut for å kunne avinstalleres med http://www.purityscan.com/uninstall.html. Jeg antar at dette vil hjelpe noe, men at det vil være igjen rester. Vi prøver å ta dem med Ewido som du setter opp slik: "When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu". When you run Ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment. From the main Ewido screen, click on update in the left menu, then click the Start update button. After the update finishes, the status bar at the bottom will display "Update successful" Exit Ewido. DO NOT run a scan yet." Kjør Ewido i safe mode. restart normalt, kjør ccleaner. legg ut en ny HJTlogg og Ewidologgen. Bernt K Endret 3. juni 2006 av berxter Lenke til kommentar
HEE Skrevet 3. juni 2006 Forfatter Del Skrevet 3. juni 2006 (endret) Søtten, sa jeg ikke at du skulle kjøre ccleaner før Panda? Vel, jeg ser en SmitFraudvariant her. Last ned SmitFraudFix og kjør i safe mode. Du kan godt velge alternativ 2 med en gang. Så ccleaner Vi fikk opp i tillegg new.net, purityscan og SaveNow. Newdotnet og SaveNow skal du normalt kunne avinstallere i kontrollpanelet, men det virker ikke alltid. Prøv først. Purityscan gir seg ut for å kunne avinstalleres med http://www.purityscan.com/uninstall.html. Jeg antar at dette vil hjelpe noe, men at det vil være igjen rester. Vi prøver å ta dem med Ewido som du setter opp slik: "When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu". When you run Ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment. From the main Ewido screen, click on update in the left menu, then click the Start update button. After the update finishes, the status bar at the bottom will display "Update successful" Exit Ewido. DO NOT run a scan yet." Kjør Ewido i safe mode. restart normalt, kjør ccleaner. legg ut en ny HJTlogg og Ewidologgen. Bernt K 6236738[/snapback] jeg mener da jeg gjorde det ? hmm.. vel den ække mer i systemet uansett.. den ble borte.. så by by til den hehe.. takk for hjelpen bernt k.. natta Endret 3. juni 2006 av HEE Lenke til kommentar
berxter Skrevet 4. juni 2006 Del Skrevet 4. juni 2006 (endret) Njet, hadde du kjørt ccleaner først ville vi ikke fått opp hele remsa med cookies i Panda. Hva mener du med at den er borte? I Pandaloggen vises det 4 spywaretilfeller; Purityscan, SaveNow og newdotnet i tillegg til SmitFraudvarianten som er den verste av dem og MÅ fjernes. Wineak32.dll er bare den aktive delen av Purityscan, og med mindre du har slått til med SmitFraudFix og Ewido i tillegg til å prøve med en avinstallasjon avPS,SN og N.N skal jeg love deg at "den" slettes ikke er borte. Når du skal fjerne flere slike ting er det aldri nok med bare ett verktøy, og det kan ta timer å gjennomføre. Bernt K Endret 4. juni 2006 av berxter Lenke til kommentar
HEE Skrevet 4. juni 2006 Forfatter Del Skrevet 4. juni 2006 Njet, hadde du kjørt ccleaner først ville vi ikke fått opp hele remsa med cookies i Panda. Hva mener du med at den er borte? I Pandaloggen vises det 4 spywaretilfeller; Purityscan, SaveNow og newdotnet i tillegg til SmitFraudvarianten som er den verste av dem og MÅ fjernes.Wineak32.dll er bare den aktive delen av Purityscan, og med mindre du har slått til med SmitFraudFix og Ewido i tillegg til å prøve med en avinstallasjon avPS,SN og N.N skal jeg love deg at "den" slettes ikke er borte. Når du skal fjerne flere slike ting er det aldri nok med bare ett verktøy, og det kan ta timer å gjennomføre. Bernt K 6238757[/snapback] oki.. skal nok formatere snart alike vel hehe Lenke til kommentar
berxter Skrevet 4. juni 2006 Del Skrevet 4. juni 2006 Det er din maskin, så det er opp til deg. Følg rådene mine i nest siste post, så er det ikke malware som skulle nødvendiggjøre en formatering. Bernt K Lenke til kommentar
Anbefalte innlegg
Opprett en konto eller logg inn for å kommentere
Du må være et medlem for å kunne skrive en kommentar
Opprett konto
Det er enkelt å melde seg inn for å starte en ny konto!
Start en kontoLogg inn
Har du allerede en konto? Logg inn her.
Logg inn nå