Adware Cool Web search se.dll
HejsaHar en computer som er blevet ramt af en coolwebsearch trojan. Den installerer en fil temp filen som kaldes se.dll. Jeg har snart prøvet alt for at fjerne denne, næsten slettet hele reg databasen, men den kommer igen og igen.
Nogen der kender til en metode for at få fjernet denne ?
Ramt logfil postes her:
Logfile of HijackThis v1.99.1
Scan saved at 07:48:52, on 22-03-2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Programmer\Network Associates\VirusScan\Avsynmgr.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Programmer\Network Associates\VirusScan\VsStat.exe
C:\Programmer\Network Associates\VirusScan\Vshwin32.exe
C:\WINNT\Explorer.EXE
C:\Programmer\Fælles filer\Network Associates\McShield\Mcshield.exe
C:\Programmer\Network Associates\VirusScan\Avconsol.exe
C:\Programmer\Microsoft AntiSpyware\gcasServ.exe
C:\Programmer\WinZip\WZQKPICK.EXE
C:\Programmer\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\System32\svchost.exe
C:\Programmer\Internet Explorer\IEXPLORE.EXE
C:\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1.SE0\LOKALE~1\Temp\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1.SE0\LOKALE~1\Temp\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: (no name) - {2FFCB8D8-99F5-4D35-B4B7-B8813AB46123} - C:\WINNT\system32\bphj.dll
O4 - HKLM\..\Run: [gcasServ] "C:\Programmer\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\ADMINI~1.SE0\LOKALE~1\Temp\se.dll,DllInstall
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmer\WinZip\WZQKPICK.EXE
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = intranet.bk-bolig.dk
O17 - HKLM\System\CCS\Services\Tcpip\..\{5F145640-801B-420E-9FBB-6F9CE42B2BCF}: NameServer = 212.54.64.170
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = intranet.bk-bolig.dk
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = intranet.bk-bolig.dk
O18 - Filter: text/html - {CDC67296-3022-4C37-B5CB-089691A326FE} - C:\WINNT\system32\bphj.dll
O18 - Filter: text/plain - {CDC67296-3022-4C37-B5CB-089691A326FE} - C:\WINNT\system32\bphj.dll
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Programmer\Network Associates\VirusScan\Avsynmgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: McShield - Unknown owner - C:\Programmer\Fælles filer\Network Associates\McShield\Mcshield.exe
