Fjærn popup i IE der bliver ved med at komme
Hele tiden poper der et reklamevindue op ved at IE starter af sig selv. Er den en der kan hjælpe med dette?Jeg har læst lidt herinde og her er et par logge at se på, kan nogen hjælpe ?
---------------------------------------------------------
ewido anti-malware - Scanningsrapport
---------------------------------------------------------
+ Oprettet den: 22:30:53, 19-03-2006
+ Rapport-Checksum: DE551400
+ Scanningsresultat:
[432] C:\WINNT\system32\ezpsrv.dll -> Adware.Look2Me : Fejl under renselse
[452] C:\WINNT\system32\ezpsrv.dll -> Adware.Look2Me : Fejl under renselse
C:\Documents and Settings\Lars1\Cookies\lars1@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Renset med backup
C:\Documents and Settings\Lars1\Cookies\lars1@adtech[2].txt -> TrackingCookie.Adtech : Renset med backup
C:\Documents and Settings\Lars1\Cookies\lars1@as-eu.falkag[2].txt -> TrackingCookie.Falkag : Renset med backup
C:\Documents and Settings\Lars1\Cookies\lars1@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Renset med backup
C:\Documents and Settings\Lars1\Cookies\lars1@sel.as-eu.falkag[1].txt -> TrackingCookie.Falkag : Renset med backup
C:\Documents and Settings\Lars1\Cookies\lars1@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Renset med backup
C:\Documents and Settings\Lars1\Cookies\lars1@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Renset med backup
C:\Documents and Settings\Lars1\Lokale indstillinger\Temporary Internet Files\Content.IE5\OHEN0HIR\ErrorSafeFreeInstall_dk[1].cab/UERSK_0001_N68M2202NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Renset med backup
C:\Programmer\ISTsvc -> Adware.ISTBar : Renset med backup
C:\Programmer\SideFind -> Adware.SideFind : Renset med backup
C:\Programmer\SideFind\update -> Adware.SideFind : Renset med backup
C:\Programmer\SurfAccuracy -> Adware.SurfAccuracy : Renset med backup
C:\Programmer\SurfAccuracy\SAcc.cfg -> Adware.SurfAccuracy : Renset med backup
C:\Programmer\SurfAccuracy\SAccU.exe -> Adware.SurfAccuracy : Renset med backup
C:\Programmer\whInstall -> Adware.Webhancer : Renset med backup
C:\Programmer\whInstall\license.txt -> Adware.Webhancer : Renset med backup
C:\Programmer\whInstall\readme.txt -> Adware.Webhancer : Renset med backup
C:\Programmer\YourSiteBar -> Adware.YourSiteBar : Renset med backup
C:\Programmer\YourSiteBar\imagemap_over.bmp -> Adware.YourSiteBar : Renset med backup
C:\RECYCLER\NPROTECT\00027947.dll -> Adware.WebHancer : Renset med backup
C:\RECYCLER\NPROTECT\00027948.exe -> Adware.WebHancer : Renset med backup
C:\RECYCLER\NPROTECT\00027950.dll -> Adware.WebHancer : Renset med backup
C:\RECYCLER\NPROTECT\00027952.exe -> Adware.WebHancer : Renset med backup
C:\RECYCLER\NPROTECT\00028017.dll -> Adware.Look2Me : Renset med backup
C:\RECYCLER\NPROTECT\00028251.DLL -> Adware.Look2Me : Renset med backup
C:\RECYCLER\NPROTECT\00028252.DLL -> Adware.Look2Me : Renset med backup
C:\RECYCLER\NPROTECT\00028255.DLL -> Adware.Look2Me : Renset med backup
C:\RECYCLER\NPROTECT\00028265.DLL -> Adware.Look2Me : Renset med backup
C:\RECYCLER\NPROTECT\00028266.DLL -> Adware.Look2Me : Renset med backup
C:\RECYCLER\NPROTECT\00028290.dll -> Adware.Look2Me : Renset med backup
C:\RECYCLER\NPROTECT\00030079.EXE -> Adware.Look2Me : Renset med backup
C:\RECYCLER\NPROTECT\00030080.exe -> Adware.SurfAccuracy : Renset med backup
C:\RECYCLER\NPROTECT\00030082.dll -> Adware.Look2Me : Renset med backup
::Rapport slut
Logfile of HijackThis v1.99.1
Scan saved at 22:51:22, on 19-03-2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
H:\Programmer\ewido anti-malware\ewidoctrl.exe
H:\Programmer\ewido anti-malware\ewidoguard.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\Explorer.EXE
H:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
H:\Programmer\Lavasoft\Ad-aware 6\Ad-watch.exe
C:\Programmer\MSN Messenger\MsnMsgr.Exe
C:\Programmer\Adobe\Acrobat 6.0\Distillr\acrotray.exe
H:\A_lg\TurboNote\tbnote.exe
C:\Documents and Settings\Lars1\Skrivebord\hjt.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.igang.dk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - Default URLSearchHook is missing
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmer\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\winnt\downloaded program files\googletoolbar1.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [EM_EXEC] H:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Ad-watch] H:\Programmer\Lavasoft\Ad-aware 6\Ad-watch.exe
O4 - HKLM\..\Run: [Ad-aware] H:\Programmer\Lavasoft\Ad-aware 6\Ad-aware.exe +c
O4 - HKLM\..\Run: [Advanced Tools Check] H:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [ccRegVfy] "C:\Programmer\Fælles filer\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Genvej til tbnote.lnk = H:\A_lg\TurboNote\tbnote.exe
O4 - Startup: Microsoft Office.lnk = H:\Programmer\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Programmer\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Reader Hurtigstart.lnk = C:\Programmer\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Google-søgning - res://c:\winnt\downloaded program files\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Oversæt engelsk ord - res://c:\winnt\downloaded program files\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://H:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Lignende sider - res://c:\winnt\downloaded program files\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Tilbage via links - res://c:\winnt\downloaded program files\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Øjebliksbillede af side i cache - res://c:\winnt\downloaded program files\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmer\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - h:\programmer\ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - h:\programmer\ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - h:\programmer\ActiveSync\inetrepl.dll
O9 - Extra button: Opslag - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) - https://netbank.danskebank.dk/html/activex/DB/Menu.cab
O16 - DPF: {3D6DDD23-870A-4FC8-B3AF-5F67C935A9B7} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/PrimeInkCSP-1204.exe
O16 - DPF: {402EE96E-2CE8-482D-ADA5-CECEEA07E16D} (TurnTool Scene) - http://www.turntool.com/ViewerInstall.exe
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://129.142.30.54/viewer/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1125847809670
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/da/big/1.1.62-big/GoogleNav.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab32846.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey®) - https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O20 - Winlogon Notify: WindowsUpdate - C:\WINNT\system32\ir86l5ls1.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - H:\Programmer\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - H:\Programmer\ewido anti-malware\ewidoguard.exe
O23 - Service: kavsvc - Kaspersky Lab - H:\Programmer\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
O23 - Service: Network Monitor - Unknown owner - C:\Programmer\Network Monitor\netmon.exe (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe