Gå til innhold

ul window seek ? iriterende pop up!


Anbefalte innlegg

hallo folkens..

har i den siste tiden hatt en pop up som kaller seg ul window seek.. popper opp med noe spill reklame og dritt.. tenkte jaha jeg for laste ned noe spy bot ad-aware og litt diverse "værktøy" men etter og har kjørt alle desse så er den fremdeles der! begynner og bli kraftig iritert på denne.. i need some advices now :hmm:

 

har kjørt kompless scanning av både antivirus og ad.aware.. og spy bot både normal modus og advances.. sett i reg edit og i oppstart.. ms config og brukt andre oppstart programmer :) somone help me please ?

Lenke til kommentar
Videoannonse
Annonse

Logfile of HijackThis v1.99.1

Scan saved at 03:42:08, on 24.05.2006

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe

C:\Program Files\Eset\nod32kui.exe

C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\MessengerPlus! 3\MsgPlus.exe

C:\Program Files\ICQLite\ICQLite.exe

C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

C:\Program Files\DAEMON Tools\daemon.exe

C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE

C:\Program Files\Macrogaming\SweetIM\SweetIM.exe

C:\Program Files\MSN Messenger\MsnMsgr.Exe

C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE

C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe

C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe

C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe

C:\Program Files\DeskSite\binex\DeskSiteCMA.exe

C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe

C:\Program Files\Eset\nod32krn.exe

C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

C:\Program Files\Outlook Express\msimn.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Documents and Settings\Håkon\Desktop\hijackthis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.vg.no/

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.vg.no/

R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll

R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll

R3 - URLSearchHook: (no name) - {69EA67FA-FB60-FDCF-3527-FF6A66A98D91} - C:\WINDOWS\system32\kldxzr.dll (file missing)

O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll

O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll

O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"

O4 - HKLM\..\Run: [nod32kui] C:\Program Files\Eset\nod32kui.exe /WAITSERVICE

O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay

O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe

O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"

O4 - HKLM\..\Run: [iCQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033

O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [inCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe

O4 - HKLM\..\Run: [sweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe

O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe

O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart

O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog

O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [sweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe

O4 - HKCU\..\RunOnce: [iCQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot

O4 - Global Startup: Hurtigstart for Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)

O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe

O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe

O9 - Extra button: NordicBet Poker - {E6073F93-9541-4be4-9800-109D378EB99B} - C:\Program Files\nordicbetMPP\MPPoker.exe

O9 - Extra button: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk

O9 - Extra 'Tools' menuitem: Absolute Poker - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)

O20 - Winlogon Notify: wineak32 - C:\WINDOWS\SYSTEM32\wineak32.dll

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: DeskSiteCMA - - C:\Program Files\DeskSite\binex\DeskSiteCMA.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe

O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Program Files\Eset\nod32krn.exe

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

 

here you go man :)

Lenke til kommentar

Tja, denne var da ikke ille?

Har du selv installert PartyPoker?

 

Få HJT til å fikse

R3 - URLSearchHook: (no name) - {69EA67FA-FB60-FDCF-3527-FF6A66A98D91} - C:\WINDOWS\system32\kldxzr.dll (file missing)

O20 - Winlogon Notify: wineak32 - C:\WINDOWS\SYSTEM32\wineak32.dll

Denne må vekk:

C:\WINDOWS\SYSTEM32\wineak32.dll

Det kan hende du må bruke Killbox i safe mode for å fjerne den.

 

Da du installerte MSGPlus, valgte du advanced og ikke sponsored? Dersom du la inn den sponsored anbefaler jeg å avinstallere den og installere på ny, denne gang ikke "sponsored".

Så, min anbefaling er:

-Last ned Killbox og lim inn

C:\WINDOWS\SYSTEM32\wineak32.dll, delete on reboot

-Få HJT til å fikse linjene som nevnt

-Skaff ccleaner, kjør den

-Reboot

-Kjør en Panda Activescan husk see report og save report (vær så snill og kjør ccleaner først...)

-Legg ut Pandaloggen og en fersk HJTlogg.

 

EDIT: Javainstallasjonen din er herpa. Avinstaller den, slett folderen(C:\Program Files\Java ) og hent deg en ny fra

http://www.java.com/en/download/manual.jsp

Husk at nettleseren din må være lukket mens du installerer Java!

 

 

Bernt K

Endret av berxter
Lenke til kommentar

Incident Status Location

 

Adware:Adware/PurityScan Not disinfected C:\!KillBox\wineak32.dll

Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.tribalfusion.com/]

Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.advertising.com/]

Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.tradedoubler.com/]

Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.mediaplex.com/]

Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.2o7.net/]

Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.112.2o7.net/]

Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.2o7.net/]

Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[ad.yieldmanager.com/]

Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.fastclick.net/]

Spyware:Cookie/Rn11 Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.rn11.com/]

Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.trafficmp.com/]

Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.qksrv.net/]

Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.apmebf.com/]

Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.doubleclick.net/]

Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.casalemedia.com/]

Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.adtech.de/]

Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.atdmt.com/]

Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.hotlog.ru/]

Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.yadro.ru/]

Spyware:Cookie/SpyLog Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.spylog.com/]

Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.errorsafe.com/]

Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[www.errorsafe.com/]

Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[stats1.reliablestats.com/]

Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.bluestreak.com/]

Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.serving-sys.com/]

Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.bs.serving-sys.com/]

Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.serving-sys.com/]

Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.microsofteup.112.2o7.net/]

Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.247realmedia.com/]

Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.adopt.hbmediapro.com/]

Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.ads.pointroll.com/]

Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.atwola.com/]

Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.azjmp.com/]

Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.belnk.com/]

Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.bravenet.com/]

Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.burstnet.com/]

Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.com.com/]

Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.go.com/]

Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.maxserving.com/]

Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.overture.com/]

Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.questionmarket.com/]

Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.realmedia.com/]

Spyware:Cookie/Research-int Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.research-int.se/]

Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.revenue.net/]

Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.statcounter.com/]

Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.toplist.cz/]

Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.xiti.com/]

Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.xmts.net/]

Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[.zedo.com/]

Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[landing.domainsponsor.com/]

Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[searchportal.information.com/]

Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[server.iad.liveperson.net/]

Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[server.iad.liveperson.net/hc/80570461]

Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[server.iad.liveperson.net/hc/LPneimanmarcus]

Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\Håkon\Application Data\Mozilla\Firefox\Profiles\thkvirto.default\cookies.txt[stat.onestat.com/]

Adware:adware/securityerror Not disinfected C:\Documents and Settings\Håkon\Favorites\Antivirus Test Online.url

Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\Håkon\My Documents\M?crosoft\dexplore.exe

Adware:Adware/SaveNow Not disinfected C:\Program Files\DAEMON Tools\SetupDTSB.exe

Spyware:Spyware/New.net Not disinfected C:\WINDOWS\NDNuninstall7_22.exe

Adware:Adware/SpyFalcon Not disinfected C:\WINDOWS\system32\1024\ld7A66.tmp

Adware:Adware/EMediaCodec Not disinfected C:\WINDOWS\system32\atmclk.ex$

Adware:Adware/SecurityError Not disinfected C:\WINDOWS\system32\dcomcfg.exe

Adware:Adware/SpyFalcon Not disinfected C:\WINDOWS\system32\fyhhxw.dl$

Adware:Adware/SecurityError Not disinfected C:\WINDOWS\system32\ld84C0.tmp

Adware:Adware/MediaTickets Not disinfected C:\WINDOWS\system32\oins.exe

Adware:Adware/SecurityError Not disinfected C:\WINDOWS\system32\regperf.ex$

 

 

here you go :)

Lenke til kommentar

Søtten, sa jeg ikke at du skulle kjøre ccleaner før Panda? :cool:

 

Vel, jeg ser en SmitFraudvariant her.

 

Last ned SmitFraudFix og kjør i safe mode. Du kan godt velge alternativ 2 med en gang.

 

Så ccleaner

 

Vi fikk opp i tillegg new.net, purityscan og SaveNow.

Newdotnet og SaveNow skal du normalt kunne avinstallere i kontrollpanelet, men det virker ikke alltid. Prøv først.

Purityscan gir seg ut for å kunne avinstalleres med

http://www.purityscan.com/uninstall.html.

 

Jeg antar at dette vil hjelpe noe, men at det vil være igjen rester. Vi prøver å ta dem med Ewido som du setter opp slik:

"When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".

When you run Ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.

From the main Ewido screen, click on update in the left menu, then click the Start update button.

After the update finishes, the status bar at the bottom will display "Update successful"

Exit Ewido. DO NOT run a scan yet."

 

Kjør Ewido i safe mode.

restart normalt, kjør ccleaner.

legg ut en ny HJTlogg og Ewidologgen.

 

Bernt K

Endret av berxter
Lenke til kommentar
Søtten, sa jeg ikke at du skulle kjøre ccleaner før Panda? :cool:

 

Vel, jeg ser en SmitFraudvariant her.

 

Last ned SmitFraudFix og kjør i safe mode. Du kan godt velge alternativ 2 med en gang.

 

Så ccleaner

 

Vi fikk opp i tillegg new.net, purityscan og SaveNow.

Newdotnet og SaveNow skal du normalt kunne avinstallere i kontrollpanelet, men det virker ikke alltid. Prøv først.

Purityscan gir seg ut for å kunne avinstalleres med

http://www.purityscan.com/uninstall.html.

 

Jeg antar at dette vil hjelpe noe, men at det vil være igjen rester. Vi prøver å ta dem med Ewido som du setter opp slik:

"When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".

When you run Ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.

From the main Ewido screen, click on update in the left menu, then click the Start update button.

After the update finishes, the status bar at the bottom will display "Update successful"

Exit Ewido. DO NOT run a scan yet."

 

Kjør Ewido i safe mode.

restart normalt, kjør ccleaner.

legg ut en ny HJTlogg og Ewidologgen.

 

Bernt K

6236738[/snapback]

 

 

jeg mener da jeg gjorde det ? hmm.. vel den ække mer i systemet uansett.. den ble borte.. så by by til den hehe.. takk for hjelpen bernt k.. natta

Endret av HEE
Lenke til kommentar

Njet, hadde du kjørt ccleaner først ville vi ikke fått opp hele remsa med cookies i Panda. Hva mener du med at den er borte? I Pandaloggen vises det 4 spywaretilfeller; Purityscan, SaveNow og newdotnet i tillegg til SmitFraudvarianten som er den verste av dem og MÅ fjernes.

Wineak32.dll er bare den aktive delen av Purityscan, og med mindre du har slått til med SmitFraudFix og Ewido i tillegg til å prøve med en avinstallasjon avPS,SN og N.N skal jeg love deg at "den" slettes ikke er borte.

 

Når du skal fjerne flere slike ting er det aldri nok med bare ett verktøy, og det kan ta timer å gjennomføre.

 

Bernt K

Endret av berxter
Lenke til kommentar
Njet, hadde du kjørt ccleaner først ville vi ikke fått opp hele remsa med cookies i Panda. Hva mener du med at den er borte? I Pandaloggen vises det 4 spywaretilfeller; Purityscan, SaveNow og newdotnet i tillegg til SmitFraudvarianten som er den verste av dem og MÅ fjernes.

Wineak32.dll er bare den aktive delen av Purityscan, og med mindre du har slått til med SmitFraudFix og Ewido i tillegg til å prøve med en avinstallasjon avPS,SN og N.N skal  jeg love deg at "den" slettes ikke er borte.

 

Når du skal fjerne flere slike ting er det aldri nok med bare ett verktøy, og det kan ta timer å gjennomføre.

 

Bernt K

6238757[/snapback]

 

 

oki.. skal nok formatere snart alike vel :) hehe

Lenke til kommentar

Opprett en konto eller logg inn for å kommentere

Du må være et medlem for å kunne skrive en kommentar

Opprett konto

Det er enkelt å melde seg inn for å starte en ny konto!

Start en konto

Logg inn

Har du allerede en konto? Logg inn her.

Logg inn nå
  • Hvem er aktive   0 medlemmer

    • Ingen innloggede medlemmer aktive
×
×
  • Opprett ny...