Helpmij tegen spyware offensief

Status
Niet open voor verdere reacties.
log

Hier is mijn log, en mijn computer is ook een stuk langzamer geworden en dat met een pentium 4, 2.8mhz en 1gb intern geheugen


Logfile of HijackThis v1.97.7
Scan saved at 18:47:58, on 5-12-2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\svchost.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\control.exe
C:\WINDOWS\System32\svchosts.exe
C:\WINDOWS\System32\svchostc.exe
C:\Program Files\Microsoft Office\Office\1043\msoffice.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Robbert Akkermans\Local Settings\Temp\Tijdelijke map 1 voor hijackthis.zip\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.windowws.cc/sp.htm?id=9
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.windowws.cc/sp.htm?id=9
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sweeties.teensfestival.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.windowws.cc/sp.htm?id=9
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wanadoo.nl
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer aangeboden door Wanadoo Cable v2.0c NL
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.wanadoo.nl/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [Fortis Secure Layer Config] cseinst.exe -o-h
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [Online Service] C:\WINDOWS\svchost.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Windows Control] C:\WINDOWS\control.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O9 - Extra button: Website (HKCU)
O9 - Extra button: Help (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.nl
O15 - Trusted Zone: *.waitsex.com
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/downl...-a3de-373c3e5552fc/msSecAdv.cab?1070624637890
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.6.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/1662a922ea6943b9fa05/netzip/RdxIE601.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37960.1791319444
O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DE591B16-A452-11D6-AED1-0001030A4E46} (PBGNX Control) - https://gto.postbank.nl/GTO/PBGNX.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DE9AD72E-8041-4D64-BC22-B5E603654971}: NameServer = 195.96.96.97 195.96.96.33
 
hijackthis log

hallo pieter .

heb eerst een scan gedaan met spybot .

hier is mijn log alvast bedankt .

Logfile of HijackThis v1.97.2
Scan saved at 18:22:43, on 6-12-2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\PROGRA~1\PANICW~1\POP-UP~3\PSFree.exe
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\Program Files\Optical Mousemate\4DMAIN.EXE
D:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Startpagina = http://www.startpagina.nl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.startpagina.nl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O1 - Hosts: 217.116.231.7 aimtoday.aol.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
O4 - HKLM\..\Run: [Lexmark X73 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [NsUpdate] C:\WINDOWS\NsUpdate.exe UPDATE
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [SFD] C:\Program Files\SFD\SFD.exe -AutoStart
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~3\PSFree.exe"
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {214868A8-F71B-473E-8ECF-6EE1DE6B91D8} - http://pms.localscripts.nl/plugins/4/ms7531_nl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/SSC/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {4B6015E7-3ABB-45DC-96B7-55A843751F28} (IntRuboskizo2 Class) - http://www.chicasmodelos.com/ruboskizo2.cab
O16 - DPF: {4E15D681-1D20-11D4-8B72-000021DA1956} - http://www.net69.nl/plugin/net69nl126.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/2742c8dcaeadd3bcfd22/netzip/RdxIE601.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupdates/content/opuc.cab
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
O16 - DPF: {86698251-D2C0-4D0F-A3E4-95CEF12F9F18} - http://64.156.188.99/iwasher/proactauthwb/internetwasherpro.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37565.537025463
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedContent/common/bin/cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DE591B16-A452-11D6-AED1-0001030A4E46} (PBGNX Control) - https://www.p3.postbank.nl/GTO/PBGNX.cab
O16 - DPF: {F4653484-F38C-455F-BB15-1175E527754E} (VideoProducer Class) - http://www.normal.video-party.com/class/webcam2.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O16 - DPF: {FE8287E9-5F43-11D3-ABCA-00105A5C1F46} (HouseCall Control) - http://www.housecall.nl/housecall/xscan4.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{37AAB253-C099-4FC4-8932-B173B3A9677B}: NameServer = 195.121.1.34 195.121.1.66
 
Re: log

Geplaatst door RA10
Hier is mijn log, en mijn computer is ook een stuk langzamer geworden en dat met een pentium 4, 2.8mhz en 1gb intern geheugen

O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O15 - Trusted Zone: *.waitsex.com
vink deze 2 uit en klik op "fix checked" (die 1e ben ik niet zeker van...is het iets wat je zelf hebt geinstalleerd?)
voor de rest is het netjes :thumb: :)
 
problemen met explorer

hallo pieter,

heb je advies opgevolgd adware en hijack gedraaid. Nog niets aangepast.

Wil graag wat tips voor opschonen

i-loopu site verschijnt automatisch in mijn browser.

hijack fil en adware file bijgesloten

Logfile of HijackThis v1.97.7
Scan saved at 12:12:46, on 07-12-2003
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\ati2evxx.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINNT\SYSTEM32\DWRCS.EXE
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Sophos SWEEP for NT\SWEEPSRV.SYS
C:\Program Files\Sophos SWEEP for NT\SWUPDATE.EXE
C:\WINNT\system32\usrbridg.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Compaq\Hotkey Software\hkss.exe
C:\WINNT\system32\Atiptaxx.exe
C:\WINNT\system32\PRPCUI.exe
C:\Program Files\Common Files\Nokia\NCLTools\NCLConf.exe
C:\Program Files\ClockSync\Sync.exe
C:\Program Files\Sophos SWEEP for NT\ICMON.EXE
C:\Program Files\Linksys\Wireless-G Notebook Adapter\WPC54CFG.EXE
C:\Program Files\ClockSync\Sync.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\explorer.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\WINNT\msagent\AgentSvr.exe
C:\WINNT\system32\mobsync.exe
C:\hijack\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://i-lookup.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://i-lookup.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://i-lookup.com/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://i-lookup.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://i-lookup.com/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://i-lookup.com/search.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sphb02:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = au.cdri.intranet;<local>
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.publishnet.nl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: ohb - {18B79968-1A76-4953-9EBB-B651407F8998} - C:\WINNT\system32\windec32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: I-Lookup.com Bar - {6EF3AE25-5A7D-40C2-9B44-9ED0068621C0} - C:\WINNT\system32\windec32.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\WINNT\Downloaded Program Files\CONFLICT.2\googlenav.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EabServr.exe /Start
O4 - HKLM\..\Run: [hkss] C:\Program Files\Compaq\Hotkey Software\hkss.exe
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [Nokia Connection Monitor] "C:\Program Files\Common Files\Nokia\NCLTools\NCLConf.exe"
O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe
O4 - HKLM\..\Run: [Syscpy] C:\WINNT\system32\syscpy.exe
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [SpyBlocker] C:\Program Files\SpyBlocker Software\spyblocker.exe
O4 - HKCU\..\Run: [ClockSync] C:\Program Files\ClockSync\Sync.exe
O4 - Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: InterCheck Monitor.LNK = C:\Program Files\Sophos SWEEP for NT\ICMON.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Wireless-G Notebook Adapter Utility.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\WPC54CFG.EXE
O8 - Extra context menu item: &Email It - C:\Program Files\QuickSend\quicksend.html
O8 - Extra context menu item: &Google Search - res://C:\WINNT\Downloaded Program Files\CONFLICT.2\googlenav.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\WINNT\Downloaded Program Files\CONFLICT.2\googlenav.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\WINNT\Downloaded Program Files\CONFLICT.2\googlenav.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\WINNT\Downloaded Program Files\CONFLICT.2\googlenav.dll/cmsimilar.html
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {018B7EC3-EECA-11D3-8E71-0000E82C6C0D} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {2ABE804B-4D3A-41BF-A172-304627874B45} - http://akamai.downloadv3.com/binaries/DialHTML/EGDHTML.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/ProductUpdates/content/opuc.cab
O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} (Google Activate) - http://toolbar.google.com/data/nl/big/1.1.62-big/GoogleNav.cab
O16 - DPF: {6EB5B540-1E74-4D91-A7F0-5B758D333702} (nCaseInstaller Class) - http://bis.180solutions.com/activexinstallers/Installer/nCaseInstaller.cab
O16 - DPF: {841A9192-5690-11D4-A258-0040954A01BE} (DialXSCtl Object) - http://dialxs.nl/install/dialxs.ocx
O16 - DPF: {94742E3F-D9A1-4780-9A87-2FFA43655DA2} - http://akamai.downloadv3.com/binaries/DialHTML/EGDHTML_pack.cab
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} (loader Class) - http://dload.ipbill.com/del/loader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab


adaware

Lavasoft Ad-aware Personal Build 6.181
Logfile created on :zondag 7 december 2003 12:02:55
Created with Ad-aware Personal, free for private use.
Using reference-file :01R236 06.12.2003
______________________________________________________

Ad-aware Settings
=========================
Set : Activate in-depth scan (Recommended)
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep scan registry


07-12-2003 12:02:55 - Scan started. (Smart mode)

Listing running processes
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯

#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ThreadCreationTime : 07-12-2003 8:32:22
BasePriority : Normal


#:2 [winlogon.exe]
FilePath : \??\C:\WINNT\system32\
ThreadCreationTime : 07-12-2003 8:32:51
BasePriority : High


#:3 [services.exe]
FilePath : C:\WINNT\system32\
ThreadCreationTime : 07-12-2003 8:32:54
BasePriority : Normal
FileSize : 87 KB
FileVersion : 5.00.2195.6700
ProductVersion : 5.00.2195.6700
Copyright : Copyright (C) Microsoft Corp. 1981-1999
CompanyName : Microsoft Corporation
FileDescription : Services en controllertoepassingen
InternalName : services.exe
OriginalFilename : services.exe
ProductName : Besturingssysteem Microsoft(R) Windows (R) 2000
Created on : 11-01-2000
Last accessed : 07-12-2003 11:02:55
Last modified : 19-06-2003 10:05:04

#:4 [lsass.exe]
FilePath : C:\WINNT\system32\
ThreadCreationTime : 07-12-2003 8:32:54
BasePriority : Normal
FileSize : 36 KB
FileVersion : 5.00.2195.6695
ProductVersion : 5.00.2195.6695
Copyright : Copyright (C) Microsoft Corp. 1981-1999
CompanyName : Microsoft Corporation
FileDescription : DLL-bestand voorLSA Executable en Server (exportversie)
InternalName : lsasrv.dll en lsass.exe
OriginalFilename : lsasrv.dll en lsass.exe
ProductName : Besturingssysteem Microsoft(R) Windows (R) 2000
Created on : 11-11-2002 14:42:56
Last accessed : 07-12-2003 11:02:55
Last modified : 19-06-2003 10:05:04

#:5 [svchost.exe]
FilePath : C:\WINNT\system32\
ThreadCreationTime : 07-12-2003 8:33:02
BasePriority : Normal
FileSize : 7 KB
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
Copyright : Copyright (C) Microsoft Corp. 1981-1999
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft(R) Windows (R) 2000 Operating System
Created on : 11-01-2000
Last accessed : 07-12-2003 11:02:55
Last modified : 11-01-2000

#:6 [svchost.exe]
FilePath : C:\WINNT\System32\
ThreadCreationTime : 07-12-2003 8:33:02
BasePriority : Normal
FileSize : 7 KB
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
Copyright : Copyright (C) Microsoft Corp. 1981-1999
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft(R) Windows (R) 2000 Operating System
Created on : 11-01-2000
Last accessed : 07-12-2003 11:02:55
Last modified : 11-01-2000

#:7 [spoolsv.exe]
FilePath : C:\WINNT\system32\
ThreadCreationTime : 07-12-2003 8:33:03
BasePriority : Normal
FileSize : 44 KB
FileVersion : 5.00.2195.6659
ProductVersion : 5.00.2195.6659
Copyright : Copyright (C) Microsoft Corp. 1981-1999
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolss.exe
OriginalFilename : spoolss.exe
ProductName : Microsoft(R) Windows (R) 2000 Operating System
Created on : 06-09-2002 15:29:29
Last accessed : 07-12-2003 11:02:55
Last modified : 19-06-2003 10:05:04

#:8 [ati2evxx.exe]
FilePath : C:\WINNT\System32\
ThreadCreationTime : 07-12-2003 8:33:03
BasePriority : Normal
FileSize : 80 KB
Created on : 12-06-2001 2:00:02
Last accessed : 07-12-2003 11:02:55
Last modified : 12-06-2001 2:00:02

#:9 [cvpnd.exe]
FilePath : C:\Program Files\Cisco Systems\VPN Client\
ThreadCreationTime : 07-12-2003 8:33:09
BasePriority : Normal
FileSize : 1391 KB
FileVersion : 4.0.3 (A)
ProductVersion : 4.0.3 (A)
Copyright : Copyright
CompanyName : Cisco Systems, Inc.
FileDescription : Cisco Systems VPN Client
InternalName : cvpnd
OriginalFilename : CVPND.EXE
ProductName : Cisco Systems VPN Client
Created on : 21-10-2003 8:53:45
Last accessed : 07-12-2003 10:09:21
Last modified : 17-10-2003 14:43:48

#:10 [dwrcs.exe]
FilePath : C:\WINNT\SYSTEM32\
ThreadCreationTime : 07-12-2003 8:33:14
BasePriority : Normal
FileSize : 244 KB
FileVersion : 3, 72, 0, 0
ProductVersion : 3, 72, 0, 0
Copyright : Copyright
CompanyName : DameWare Development
FileDescription : DWRCS
InternalName : DWRCS
OriginalFilename : DWRCS.exe
ProductName : DameWare Development DWRCS
Created on : 18-09-2003 7:11:40
Last accessed : 07-12-2003 10:27:28
Last modified : 27-08-2003 12:45:00

#:11 [regsvc.exe]
FilePath : C:\WINNT\system32\
ThreadCreationTime : 07-12-2003 8:33:18
BasePriority : Normal
FileSize : 66 KB
FileVersion : 5.00.2195.6701
ProductVersion : 5.00.2195.6701
Copyright : Copyright (C) Microsoft Corp. 1981-1999
CompanyName : Microsoft Corporation
FileDescription : Remote Registry Service
InternalName : regsvc
OriginalFilename : REGSVC.EXE
ProductName : Microsoft(R) Windows (R) 2000 Operating System
Created on : 21-10-2003 9:32:50
Last accessed : 07-12-2003 11:02:56
Last modified : 19-06-2003 10:05:04

#:12 [mstask.exe]
FilePath : C:\WINNT\system32\
ThreadCreationTime : 07-12-2003 8:33:19
BasePriority : Normal
FileSize : 117 KB
FileVersion : 4.71.2195.6704
ProductVersion : 4.71.2195.6704
Copyright : Copyright (C) Microsoft Corp. 1997
CompanyName : Microsoft Corporation
FileDescription : Taakplanner Engine
InternalName : TaskScheduler
OriginalFilename : mstask.exe
ProductName : Microsoft
Created on : 21-10-2003 9:32:31
Last accessed : 07-12-2003 11:02:56
Last modified : 19-06-2003 10:05:04

#:13 [stisvc.exe]
FilePath : C:\WINNT\system32\
ThreadCreationTime : 07-12-2003 8:33:21
BasePriority : Normal
FileSize : 60 KB
FileVersion : 5.00.2195.6656
ProductVersion : 5.00.2195.6656
Copyright : Copyright (C) Microsoft Corp. 1996-1997
CompanyName : Microsoft Corporation
FileDescription : Monitor voor Still Image-apparaten
InternalName : STIMON
OriginalFilename : STIMON.EXE
ProductName : Besturingssysteem Microsoft(R) Windows (R) 2000
Created on : 21-10-2003 9:33:01
Last accessed : 07-12-2003 11:02:56
Last modified : 19-06-2003 10:05:04

#:14 [sweepsrv.sys]
FilePath : C:\Program Files\Sophos SWEEP for NT\
ThreadCreationTime : 07-12-2003 8:33:23
BasePriority : Normal
FileSize : 284 KB
FileVersion : 2.01.0227
ProductVersion : 3 (Build 0227)
CompanyName : Sophos Plc
FileDescription : Sophos Anti-Virus detection system service
InternalName : SWEEPSRV
OriginalFilename : SWEEPSRV.SYS
ProductName : Sophos Anti-Virus
Created on : 15-09-2003 10:38:31
Last accessed : 07-12-2003 11:02:56
Last modified : 21-10-2003 6:55:36

#:15 [swupdate.exe]
FilePath : C:\Program Files\Sophos SWEEP for NT\
ThreadCreationTime : 07-12-2003 8:33:38
BasePriority : Normal
FileSize : 244 KB
FileVersion : 1.00.0227
ProductVersion : 3 (Build 0227)
CompanyName : Sophos Plc
FileDescription : Sophos Anti-Virus update service
InternalName : SWUPDATE
OriginalFilename : SWUPDATE.EXE
ProductName : Sophos Anti-Virus
Created on : 15-09-2003 10:37:59
Last accessed : 07-12-2003 11:02:56
Last modified : 21-10-2003 6:55:36

#:16 [usrbridg.exe]
FilePath : C:\WINNT\system32\
ThreadCreationTime : 07-12-2003 8:33:40
BasePriority : Normal
FileSize : 60 KB
FileVersion : 1, 0, 2, 0
ProductVersion : 1, 0, 0, 0
Copyright : Copyright
CompanyName : Extended Systems, Inc.
FileDescription : usrbridg.exe
InternalName : USRBRIDG
OriginalFilename : usrbridg.sys
Created on : 24-10-2002 8:18:39
Last accessed : 07-12-2003 11:02:57
Last modified : 06-07-2000 7:57:06

#:17 [winmgmt.exe]
FilePath : C:\WINNT\System32\WBEM\
ThreadCreationTime : 07-12-2003 8:33:46
BasePriority : Normal
FileSize : 192 KB
FileVersion : 1.50.1085.0100
ProductVersion : 1.50.1085.0100
Copyright : Copyright (C) Microsoft Corp. 1995-1999
CompanyName : Microsoft Corporation
FileDescription : Windows Management Instrumentation
InternalName : WINMGMT
ProductName : Windows Management Instrumentation
Created on : 21-10-2003 9:33:25
Last accessed : 07-12-2003 11:02:57
Last modified : 19-06-2003 10:05:04

#:18 [mspmspsv.exe]
FilePath : C:\WINNT\System32\
ThreadCreationTime : 07-12-2003 8:33:48
BasePriority : Normal
FileSize : 56 KB
FileVersion : 7.10.00.3068
ProductVersion : 7.10.00.3068
Copyright : Copyright (C) Microsoft Corp. 1981-2000
CompanyName : Microsoft Corporation
FileDescription : WMDM PMSP Service
InternalName : MSPMSPSV.EXE
OriginalFilename : MSPMSPSV.EXE
ProductName : Microsoft (R) DRM
Created on : 06-09-2002 15:12:19
Last accessed : 07-12-2003 11:02:57
Last modified : 17-05-2002 0:24:48

#:19 [svchost.exe]
FilePath : C:\WINNT\system32\
ThreadCreationTime : 07-12-2003 8:33:48
BasePriority : Normal
FileSize : 7 KB
FileVersion : 5.00.2134.1
ProductVersion : 5.00.2134.1
Copyright : Copyright (C) Microsoft Corp. 1981-1999
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft(R) Windows (R) 2000 Operating System
Created on : 11-01-2000
Last accessed : 07-12-2003 11:02:55
Last modified : 11-01-2000

#:20 [hkss.exe]
FilePath : C:\Program Files\Compaq\Hotkey Software\
ThreadCreationTime : 07-12-2003 8:34:43
BasePriority : Normal
FileSize : 188 KB
FileVersion : 1.1.D3
ProductVersion : 1.1.D3
CompanyName : Compaq Computer Corporation
FileDescription : Hot Key Support Software Loader
InternalName : HKSS
OriginalFilename : hkss.exe
ProductName : Hot Key Support Software
Created on : 06-09-2002 14:58:43
Last accessed : 07-12-2003 10:09:08
Last modified : 19-03-2002 9:12:40

#:21 [atiptaxx.exe]
FilePath : C:\WINNT\system32\
ThreadCreationTime : 07-12-2003 8:34:45
BasePriority : Normal
FileSize : 200 KB
FileVersion : 5.13.2506
ProductVersion : 5.13.2506
Copyright : Copyright (C) 1998-2001 ATI Technologies Inc.
CompanyName : ATI Technologies, Inc.
FileDescription : ATI Desktop Control Panel
InternalName : Atiptaxx.exe
OriginalFilename : Atiptaxx.exe
ProductName : ATI Desktop Component
Created on : 28-05-2001 8:19:48
Last accessed : 07-12-2003 11:02:57
Last modified : 28-05-2001 8:19:48

#:22 [prpcui.exe]
FilePath : C:\WINNT\system32\
ThreadCreationTime : 07-12-2003 8:34:47
BasePriority : Normal
FileSize : 41 KB
FileVersion : 2.1.0.0
ProductVersion : 2.1.0.0
Copyright : Copyright
CompanyName : Intel Corporation
FileDescription : Intel(R) SpeedStep(TM) technology User Interface
InternalName : prpcui.exe
OriginalFilename : prpcui.exe
ProductName : Intel(R) SpeedStep(TM) technology applet
Created on : 09-09-2002 12:50:18
Last accessed : 07-12-2003 11:02:57
Last modified : 24-04-2001 8:00:00

#:23 [nclconf.exe]
FilePath : C:\Program Files\Common Files\Nokia\NCLTools\
ThreadCreationTime : 07-12-2003 8:34:49
BasePriority : Normal
FileSize : 120 KB
FileVersion : 4.00.014
ProductVersion : 4.0
Copyright : Copyright
CompanyName : Nokia Mobile Phones Ltd.
FileDescription : NclConf taskbar application
InternalName : NclConf
OriginalFilename : NclConf.exe
ProductName : Nokia Connectivity Library
Created on : 24-10-2002 8:25:44
Last accessed : 07-12-2003 11:02:57
Last modified : 23-03-2001 9:08:42

#:24 [sync.exe]
FilePath : C:\Program Files\ClockSync\
ThreadCreationTime : 07-12-2003 8:34:54
BasePriority : Normal
FileSize : 65 KB
FileVersion : 0, 1, 5, 1
ProductVersion : 0, 1, 5, 1
Copyright : Copyright 2003
CompanyName : WhenU.com
FileDescription : DnldStub
InternalName : DnldStub
OriginalFilename : dnldstub.exe
ProductName : DnldStub Module
Created on : 06-12-2003 15:38:08
Last accessed : 07-12-2003 11:02:57
Last modified : 19-11-2003 14:53:34

#:25 [icmon.exe]
FilePath : C:\Program Files\Sophos SWEEP for NT\
ThreadCreationTime : 07-12-2003 8:35:02
BasePriority : Normal
FileSize : 204 KB
FileVersion : 1.00.0227
ProductVersion : 3 (Build 0227)
CompanyName : Sophos Plc
FileDescription : Sophos Anti-Virus InterCheck activity monitor (ENG)
InternalName : ICMON
OriginalFilename : ICMON.EXE
ProductName : Sophos Anti-Virus
Created on : 15-09-2003 10:38:35
Last accessed : 07-12-2003 11:02:57
Last modified : 21-10-2003 6:55:30

#:26 [wpc54cfg.exe]
FilePath : C:\Program Files\Linksys\Wireless-G Notebook Adapter\
ThreadCreationTime : 07-12-2003 8:35:07
BasePriority : Normal
FileSize : 4506 KB
FileVersion : 1.0.5.98
ProductVersion : 1.0.5.0
Copyright : Copyright (C) 2003, Linksys
CompanyName : The Linksys Group, Inc.
FileDescription : Linksys Instant WLAN Monitor
InternalName : WLANMonitor.EXE
OriginalFilename : WLANMonitor.EXE
ProductName : Linksys Instant WLAN Monitor
Created on : 18-05-2003 19:05:14
Last accessed : 07-12-2003 10:09:07
Last modified : 24-12-2002 7:53:18

#:27 [sync.exe]
FilePath : C:\Program Files\ClockSync\
ThreadCreationTime : 07-12-2003 8:59:20
BasePriority : Normal
FileSize : 65 KB
FileVersion : 0, 1, 5, 1
ProductVersion : 0, 1, 5, 1
Copyright : Copyright 2003
CompanyName : WhenU.com
FileDescription : DnldStub
InternalName : DnldStub
OriginalFilename : dnldstub.exe
ProductName : DnldStub Module
Created on : 06-12-2003 15:38:08
Last accessed : 07-12-2003 11:02:57
Last modified : 19-11-2003 14:53:34

#:28 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ThreadCreationTime : 07-12-2003 9:22:43
BasePriority : Normal
FileSize : 89 KB
FileVersion : 6.00.2800.1106
ProductVersion : 6.00.2800.1106
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
OriginalFilename : IEXPLORE.EXE
ProductName : Besturingssysteem Microsoft
Created on : 04-09-2002 8:23:58
Last accessed : 07-12-2003 10:22:17
Last modified : 04-09-2002 8:23:58

#:29 [explorer.exe]
FilePath : C:\WINNT\
ThreadCreationTime : 07-12-2003 9:26:02
BasePriority : Normal
FileSize : 238 KB
FileVersion : 5.00.3700.6690
ProductVersion : 5.00.3700.6690
Copyright : Copyright (C) Microsoft Corp. 1981-1999
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
OriginalFilename : EXPLORER.EXE
ProductName : Microsoft(R) Windows (R) 2000 Operating System
Created on : 21-10-2003 9:33:14
Last accessed : 07-12-2003 10:49:50
Last modified : 19-06-2003 10:05:04

#:30 [msimn.exe]
FilePath : C:\Program Files\Outlook Express\
ThreadCreationTime : 07-12-2003 10:21:29
BasePriority : Normal
FileSize : 56 KB
FileVersion : 6.00.2800.1106
ProductVersion : 6.00.2800.1106
CompanyName : Microsoft Corporation
FileDescription : Outlook Express
InternalName : MSIMN
OriginalFilename : MSIMN.EXE
ProductName : Besturingssysteem Microsoft
Created on : 04-09-2002 8:07:58
Last accessed : 07-12-2003 10:21:29
Last modified : 04-09-2002 8:07:58

#:31 [winword.exe]
FilePath : C:\Program Files\Microsoft Office\Office\
ThreadCreationTime : 07-12-2003 10:22:02
BasePriority : Normal
FileSize : 8608 KB
FileVersion : 9.0.6328
ProductVersion : 9.0.6328
Copyright : Copyright
CompanyName : Microsoft Corporation
FileDescription : Microsoft Word for Windows
InternalName : WinWord
OriginalFilename : WinWord.exe
ProductName : Microsoft Office 2000
Created on : 03-04-2002 0:58:50
Last accessed : 07-12-2003 10:22:02
Last modified : 03-04-2002 0:58:50

#:32 [agentsvr.exe]
FilePath : C:\WINNT\msagent\
ThreadCreationTime : 07-12-2003 10:22:27
BasePriority : Normal
FileSize : 236 KB
FileVersion : 2.00.0.3422
ProductVersion : 2.00.0.3422
Copyright : Copyright (C) Microsoft Corp. 1997-98
CompanyName : Microsoft Corporation
FileDescription : Microsoft Agent Server
InternalName : AgentServer
OriginalFilename : AgentSvr.exe
ProductName : Microsoft Agent Server
Created on : 11-01-2000
Last accessed : 07-12-2003 11:02:58
Last modified : 11-01-2000

#:33 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-aware 6\
ThreadCreationTime : 07-12-2003 11:02:12
BasePriority : Normal
FileSize : 668 KB
FileVersion : 6.0.1.181
ProductVersion : 6.0.0.0
Copyright : Copyright
CompanyName : Lavasoft Sweden
FileDescription : Ad-aware 6 core application
InternalName : Ad-aware.exe
OriginalFilename : Ad-aware.exe
ProductName : Lavasoft Ad-aware Plus
Created on : 07-12-2003 10:13:46
Last accessed : 07-12-2003 11:02:12
Last modified : 12-07-2003 21:00:20

Memory scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 0
Objects found so far: 0


Started registry scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯

Alexa Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}


BonziBuddy Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18B79968-1A76-4953-9EBB-B651407F8998}


Coulomb Dialer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : TYPELIB\{266f948a-3dee-4270-8f55-e79accd569fa}


Coulomb Dialer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\Coulomb


Coulomb Dialer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : comload.loader2.1


Coulomb Dialer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : comload.loader2


Coulomb Dialer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : comload.loader.1


Coulomb Dialer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : comload.loader


Coulomb Dialer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{ad7fafb0-16d6-40c3-af27-585d6e6453fd}


Coulomb Dialer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{9e1089bc-1ae8-4685-8d77-6721e5c318a8}


Dial XS Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\DialXS


e-Group Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : TypeLib\{83F0D6AA-CD15-46B5-AA4E-BDB506B4AE53}


e-Group Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Code Store Database\Distribution Units\{94742E3F-D9A1-4780-9A87-2FFA43655DA2}


e-Group Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\EGDHTML


e-Group Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{2F668A6D-2EC7-4E3A-A485-819E210738D6}


e-Group Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : EGDialObject.EGDial.1


e-Group Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : EGDialObject.EGDial


e-Group Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : EGDHTML.EGDialHTML.1


e-Group Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : EGDHTML.EGDialHTML


e-Group Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{94742E3F-D9A1-4780-9A87-2FFA43655DA2}


e-Group Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{486E48B5-ABF2-42BB-A327-2679DF3FB822}


e-Group Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{2ABE804B-4D3A-41BF-A172-304627874B45}


Holystic-Dialer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CURRENT_USER
Object : software\holistyc


Holystic-Dialer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : HOL_PRELOAD.FULL.1


Holystic-Dialer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{03C543A1-C090-418F-A1D0-FB96380D601D}


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : windec.ohb.1


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : windec.ohb


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : windec.momo.1


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : windec.momo


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : windec.iiittt.1


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : windec.iiittt


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : windec.dbi.1


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : windec.dbi


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : windec.amo.1


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : windec.amo


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : TYPELIB\{660b38cb-6349-4c67-a418-aadabae09c38}


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{F3A898B0-6D64-4155-BDF9-C26C99E15071}


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{E432B411-6E00-4A49-B715-A88E1CC90CC5}


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{D28B0B4C-C2A8-4F2D-8A9C-E98844D293D2}


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{C8418B66-7898-4131-A131-F2B839308C15}


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{B7383D80-81AA-4FD7-8AC2-D852677CDEAE}


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{3FD0EE3A-96AF-434B-8B05-6970699905AE}


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{fe1a240f-b247-4e06-a600-30e28f5af3a0}


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{895fdaae-9464-458d-a2f8-0dbe95788620}


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{89580613-09bb-4df6-8c2f-41896f7ea5cd}


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{6ef3ae25-5a7d-40c2-9b44-9ed0068621c0}


I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{18b79968-1a76-4953-9ebb-b651407f8998}


istbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ISTbarISTbar


istbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Code Store Database\Distribution Units\{018B7EC3-EECA-11D3-8E71-0000E82C6C0D}


istbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\ISTsvc


istbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\ISTbar


istbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\IST


istbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : ISTactivex.Installer.1


istbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : ISTactivex.Installer


istbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{5f1abcdb-a875-46c1-8345-b72a4567e486}


istbar Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{018b7ec3-eeca-11d3-8e71-0000e82c6c0d}


MainPean Dialer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\MainPean Highspeed


NCase Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : TYPELIB\{18dd1792-64fb-42db-acbe-435c598045f4}


NCase Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : ncaseinstaller.ncaseinstaller.1


NCase Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : ncaseinstaller.ncaseinstaller


NCase Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : CLSID\{6eb5b540-1e74-4d91-a7f0-5b758d333702}


SaveNow Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\WhenUSave


TIB Browser Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\WebSiteViewer


WeatherCast Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\WhenU


Atztecmarketing.syscpy Object recognized!
Type : RegValue
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value : Syscpy


istbar Object recognized!
Type : RegValue
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value : IST Service


Powerscan Object recognized!
Type : RegValue
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\Powerscan
Value : account_id


Windows Object recognized!
Type : RegData
Data :
Rootkey : HKEY_USERS
Object : .DEFAULT\Software\Microsoft\MediaPlayer\Player\Settings
Value : Client ID
Data :


Registry scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 68
Objects found so far: 68


Started deep registry scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Pagei-lookup.com

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "http://i-lookup.com/search.html"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Page
Data : "http://i-lookup.com/search.html"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainStart Pagei-lookup.com

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "http://i-lookup.com/"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "http://i-lookup.com/"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainSearch Bari-lookup.com

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "http://i-lookup.com/search.html"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Search Bar
Data : "http://i-lookup.com/search.html"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\SearchSearchAssistanti-lookup.com

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "http://i-lookup.com/search.html"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Search
Value : SearchAssistant
Data : "http://i-lookup.com/search.html"

Possible browser hijack attempt : Software\Microsoft\Internet ExplorerSearchURLi-lookup.com

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "http://i-lookup.com/search.html"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer
Value : SearchURL
Data : "http://i-lookup.com/search.html"

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\SearchSearchAssistanti-lookup.com

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "http://i-lookup.com/search.html"
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\Microsoft\Internet Explorer\Search
Value : SearchAssistant
Data : "http://i-lookup.com/search.html"

Possible browser hijack attempt : {018B7EC3-EECA-11D3-8E71-0000E82C6C0D} (http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab)
Possible browser hijack attempt : {6EB5B540-1E74-4D91-A7F0-5B758D333702} (http://bis.180solutions.com/activexinstallers/installer/ncaseinstaller.cab)

Possible Browser Hijack attempt Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Code Store Database\Distribution Units\{6EB5B540-1E74-4D91-A7F0-5B758D333702}


Deep registry scan result :
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 7
Objects found so far: 75


¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯

Tracking Cookie Object recognized!
Type : File
Data : ardonr@metriweb[1].txt
Object : C:\Documents and Settings\ArdonR\Cookies\

Created on : 07-12-2003 9:37:52
Last accessed : 07-12-2003 11:05:40
Last modified : 07-12-2003 9:37:52



Tracking Cookie Object recognized!
Type : File
Data : ardonr@tmpad[2].txt
Object : C:\Documents and Settings\ArdonR\Cookies\

Created on : 07-12-2003 10:12:22
Last accessed : 07-12-2003 10:12:22
Last modified : 07-12-2003 10:12:22



Tracking Cookie Object recognized!
Type : File
Data : ardonr@tradedoubler[1].txt
Object : C:\Documents and Settings\ArdonR\Cookies\

Created on : 07-12-2003 11:00:29
Last accessed : 07-12-2003 11:00:29
Last modified : 07-12-2003 11:00:29



Tracking Cookie Object recognized!
Type : File
Data : ardonr@trafficmp[1].txt
Object : C:\Documents and Settings\ArdonR\Cookies\

Created on : 07-12-2003 10:12:22
Last accessed : 07-12-2003 10:12:22
Last modified : 07-12-2003 10:12:22


¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯


Deep scanning and examining files (C:)
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯

NCase Object recognized!
Type : File
Data : msbb.exe
Object : C:\WINNT\system32\
FileSize : 160 KB
Created on : 05-12-2003 8:33:05
Last accessed : 07-12-2003 11:05:55
Last modified : 05-12-2003 8:33:05




Performing conditional scans..
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯

Coulomb Dialer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{F5F779A9-24E5-4BCD-9AE5-6313D4B5AC24}


Coulomb Dialer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{19E91D82-7AD7-419F-866A-58C122DB1459}


Coulomb Dialer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : dctl


Coulomb Dialer Object recognized!
Type : File
Data : comload.dll
Object : c:\winnt\system32\
FileSize : 27 KB
FileVersion : 1, 0, 0, 7
ProductVersion : 1, 0, 0, 7
CompanyName : Coulomb Ltd
InternalName : comload
OriginalFilename : comload.dll
Created on : 28-10-2003 20:07:45
Last accessed : 07-12-2003 11:04:13
Last modified : 28-10-2003 20:07:48



e-Group Object recognized!
Type : File
Data : egdhtml.inf
Object : c:\winnt\downloaded program files\

Created on : 13-11-2003 11:13:28
Last accessed : 07-12-2003 11:06:15
Last modified : 13-11-2003 11:13:28



e-Group Object recognized!
Type : File
Data : egdhtml_pack.inf
Object : c:\winnt\downloaded program files\

Created on : 29-10-2003 16:23:26
Last accessed : 07-12-2003 11:06:15
Last modified : 29-10-2003 16:23:26



e-Group Object recognized!
Type : File
Data : mseggrpid.dll
Object : c:\winnt\system32\

Created on : 14-11-2003 13:14:12
Last accessed : 07-12-2003 11:06:15
Last modified : 06-12-2003 8:23:57



e-Group Object recognized!
Type : File
Data : ia.dll
Object : c:\winnt\system32\
FileSize : 6 KB
Created on : 13-10-2003 15:05:50
Last accessed : 07-12-2003 11:05:50
Last modified : 13-10-2003 15:05:50



e-Group Object recognized!
Type : File
Data : egdial.dll
Object : c:\winnt\system32\
FileSize : 10 KB
FileVersion : 1, 0, 0, 7
ProductVersion : 1, 0, 0, 7
Copyright : Copyright
CompanyName : E-Group
FileDescription : EGDial
InternalName : EGDial
OriginalFilename : EGDial.dll
ProductName : E-Group EGDial
Created on : 14-10-2003 15:16:12
Last accessed : 07-12-2003 11:04:12
Last modified : 14-10-2003 15:16:12



e-Group Object recognized!
Type : File
Data : egdhtml_1024.dll
Object : c:\winnt\system32\
FileSize : 59 KB
FileVersion : 1, 0, 2, 4
ProductVersion : 1, 0, 2, 4
Copyright : Copyright
CompanyName : E-Group
FileDescription : EGDHTML
InternalName : EGDHTML
OriginalFilename : EGDHTML_1024.dll
ProductName : E-Group EGDHTML
Created on : 13-11-2003 10:53:22
Last accessed : 07-12-2003 11:03:42
Last modified : 13-11-2003 10:53:22



Holystic-Dialer Object recognized!
Type : Folder
Object : c:\winnt\Icons


Holystic-Dialer Object recognized!
Type : File
Data : preload.ocx
Object : c:\winnt\system32\
FileSize : 13 KB
FileVersion : 1.0.391102
ProductVersion : 1.0
CompanyName : Holistyc Limited
FileDescription : preload plugin
InternalName : preload
OriginalFilename : preload.ocx
ProductName : preload
Created on : 04-08-2003 14:39:50
Last accessed : 07-12-2003 11:03:29
Last modified : 04-08-2003 14:39:50



I-LookUp Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\share_docs


I-LookUp Object recognized!
Type : Folder
Object : c:\documents and settings\ardonr\favorieten\Messenger Links


I-LookUp Object recognized!
Type : Folder
Object : c:\documents and settings\ardonr\favorieten\I-lookup Favorites


I-LookUp Object recognized!
Type : Folder
Object : c:\documents and settings\ardonr\favorieten\Hot Links


I-LookUp Object recognized!
Type : Folder
Object : c:\documents and settings\ardonr\favorieten\Gambling


I-LookUp Object recognized!
Type : File
Data : dice.ico
Object : c:\winnt\system32\
FileSize : 3 KB
Created on : 06-12-2003 15:37:49
Last accessed : 07-12-2003 10:56:47
Last modified : 07-12-2003 10:56:47



I-LookUp Object recognized!
Type : File
Data : aim.url
Object : c:\documents and settings\ardonr\favorieten\messenger links\

Created on : 06-12-2003 19:58:49
Last accessed : 07-12-2003 11:00:34
Last modified : 07-12-2003 11:00:34



I-LookUp Object recognized!
Type : File
Data : icq.url
Object : c:\documents and settings\ardonr\favorieten\messenger links\

Created on : 06-12-2003 19:58:49
Last accessed : 07-12-2003 11:00:34
Last modified : 07-12-2003 11:00:34



I-LookUp Object recognized!
Type : File
Data : black planet love.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:32
Last modified : 07-12-2003 11:00:32



I-LookUp Object recognized!
Type : File
Data : college recruiter.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:32
Last modified : 07-12-2003 11:00:32



I-LookUp Object recognized!
Type : File
Data : dating direct.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:32
Last modified : 07-12-2003 11:00:32



I-LookUp Object recognized!
Type : File
Data : email psychic.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:32
Last modified : 07-12-2003 11:00:32



I-LookUp Object recognized!
Type : File
Data : for sale by owner.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:32
Last modified : 07-12-2003 11:00:32



I-LookUp Object recognized!
Type : File
Data : foreclosure free search.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:32
Last modified : 07-12-2003 11:00:32



I-LookUp Object recognized!
Type : File
Data : gay.com.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:32
Last modified : 07-12-2003 11:00:32



I-LookUp Object recognized!
Type : File
Data : hot jobs.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:32
Last modified : 07-12-2003 11:00:32



I-LookUp Object recognized!
Type : File
Data : i connect here.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:32
Last modified : 07-12-2003 11:00:32



I-LookUp Object recognized!
Type : File
Data : i-lookup.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:32
Last modified : 07-12-2003 11:00:32



I-LookUp Object recognized!
Type : File
Data : life-answers.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:32
Last modified : 07-12-2003 11:00:32



I-LookUp Object recognized!
Type : File
Data : move out.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:32
Last modified : 07-12-2003 11:00:32



I-LookUp Object recognized!
Type : File
Data : music 123.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:29
Last modified : 07-12-2003 11:00:29



I-LookUp Object recognized!
Type : File
Data : norton antivirus.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:31
Last modified : 07-12-2003 11:00:31



I-LookUp Object recognized!
Type : File
Data : online drugstore.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:32
Last modified : 07-12-2003 11:00:32



I-LookUp Object recognized!
Type : File
Data : phone shark.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:32
Last modified : 07-12-2003 11:00:32



I-LookUp Object recognized!
Type : File
Data : planet out.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:32
Last modified : 07-12-2003 11:00:32



I-LookUp Object recognized!
Type : File
Data : private for sale.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:32
Last modified : 07-12-2003 11:00:32



I-LookUp Object recognized!
Type : File
Data : room mate menu.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:32
Last modified : 07-12-2003 11:00:32



I-LookUp Object recognized!
Type : File
Data : roommate.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:31
Last modified : 07-12-2003 11:00:31



I-LookUp Object recognized!
Type : File
Data : tel 3.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:32
Last modified : 07-12-2003 11:00:32



I-LookUp Object recognized!
Type : File
Data : the online psychic.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:31
Last modified : 07-12-2003 11:00:31



I-LookUp Object recognized!
Type : File
Data : zaptel.url
Object : c:\documents and settings\ardonr\favorieten\i-lookup favorites\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:32
Last modified : 07-12-2003 11:00:32



I-LookUp Object recognized!
Type : File
Data : date a hottie.url
Object : c:\documents and settings\ardonr\favorieten\hot links\

Created on : 06-12-2003 19:58:49
Last accessed : 07-12-2003 11:00:34
Last modified : 07-12-2003 11:00:34



I-LookUp Object recognized!
Type : File
Data : espn.url
Object : c:\documents and settings\ardonr\favorieten\hot links\

Created on : 06-12-2003 19:58:49
Last accessed : 07-12-2003 11:00:34
Last modified : 07-12-2003 11:00:34



I-LookUp Object recognized!
Type : File
Data : free software.url
Object : c:\documents and settings\ardonr\favorieten\hot links\

Created on : 06-12-2003 19:58:49
Last accessed : 07-12-2003 11:00:34
Last modified : 07-12-2003 11:00:34



I-LookUp Object recognized!
Type : File
Data : pc cillin.url
Object : c:\documents and settings\ardonr\favorieten\hot links\

Created on : 06-12-2003 19:58:49
Last accessed : 07-12-2003 11:00:34
Last modified : 07-12-2003 11:00:34



I-LookUp Object recognized!
Type : File
Data : penis patch.url
Object : c:\documents and settings\ardonr\favorieten\hot links\

Created on : 06-12-2003 19:58:49
Last accessed : 07-12-2003 11:00:34
Last modified : 07-12-2003 11:00:34



I-LookUp Object recognized!
Type : File
Data : weather.url
Object : c:\documents and settings\ardonr\favorieten\hot links\

Created on : 06-12-2003 19:58:48
Last accessed : 07-12-2003 11:00:33
Last modified : 07-12-2003 11:00:33



I-LookUp Object recognized!
Type : File
Data : golden palace casino.url
Object : c:\documents and settings\ardonr\favorieten\gambling\

Created on : 06-12-2003 19:58:49
Last accessed : 07-12-2003 11:00:35
Last modified : 07-12-2003 11:00:35



I-LookUp Object recognized!
Type : File
Data : poker club.url
Object : c:\documents and settings\ardonr\favorieten\gambling\

Created on : 06-12-2003 19:58:49
Last accessed : 07-12-2003 11:00:35
Last modified : 07-12-2003 11:00:35



istbar Object recognized!
Type : Folder
Object : c:\program files\ISTsvc


istbar Object recognized!
Type : File
Data : istactivex.dll
Object : c:\winnt\downloaded program files\
FileSize : 64 KB
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
Copyright : Copyright 2003
FileDescription : ISTactivex Module
InternalName : ISTactivex
OriginalFilename : ISTactivex.DLL
ProductName : ISTactivex Module
Created on : 18-09-2003 14:19:26
Last accessed : 07-12-2003 11:05:16
Last modified : 18-09-2003 14:19:26



istbar Object recognized!
Type : File
Data : ruud
Object : c:\program files\istsvc\
FileSize : 7 KB
Created on : 06-12-2003 15:37:55
Last accessed : 07-12-2003 11:06:16
Last modified : 06-12-2003 15:37:55



MainPean Dialer Object recognized!
Type : Folder
Object : c:\winnt\Coder


MainPean Dialer Object recognized!
Type : File
Data : coder.log
Object : c:\winnt\

Created on : 24-05-2003 14:57:58
Last accessed : 07-12-2003 11:06:16
Last modified : 24-05-2003 15:02:13



MainPean Dialer Object recognized!
Type : File
Data : coder.ini
Object : c:\winnt\

Created on : 24-05-2003 14:57:58
Last accessed : 07-12-2003 11:06:16
Last modified : 24-05-2003 15:02:13



NCase Object recognized!
Type : File
Data : ncaseinstaller.dll
Object : c:\winnt\downloaded program files\
FileSize : 325 KB
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
Copyright : Copyright(C) 180 Solutions. 2002
CompanyName : 180 Solutions
FileDescription : nCaseInstaller Module
InternalName : nCaseInstaller
OriginalFilename : nCaseInstaller.DLL
ProductName : nCaseInstaller Module
Created on : 12-09-2003 15:24:50
Last accessed : 07-12-2003 11:06:16
Last modified : 12-09-2003 15:24:50



NCase Object recognized!
Type : File
Data : ncaseinstaller.inf
Object : c:\winnt\downloaded program files\

Created on : 12-09-2003 15:24:50
Last accessed : 07-12-2003 11:06:16
Last modified : 12-09-2003 15:24:50



NCase Object recognized!
Type : File
Data : ncaselib.dll
Object : c:\winnt\downloaded program files\
FileSize : 116 KB
Created on : 04-09-2003 11:04:02
Last accessed : 07-12-2003 11:05:16
Last modified : 04-09-2003 11:04:02



Atztecmarketing.syscpy Object recognized!
Type : File
Data : syscpy.exe
Object : c:\winnt\system32\
FileSize : 52 KB
Created on : 06-12-2003 15:37:42
Last accessed : 07-12-2003 11:05:17
Last modified : 02-12-2003 15:54:28



Atztecmarketing.syscpy Object recognized!
Type : File
Data : syscpy1.exe
Object : c:\winnt\system32\
FileSize : 52 KB
Created on : 02-12-2003 15:54:28
Last accessed : 07-12-2003 11:06:11
Last modified : 02-12-2003 15:54:28



Powerscan Object recognized!
Type : RegValue
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value : Power Scan


Conditional scan result:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
New objects : 63
Objects found so far: 143


12:06:20 Scan complete

Summary of this scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Total scanning time :00:03:21:780
Objects scanned :35842
Objects identified :143
Objects ignored :0
New objects :143


gaarne je reactie

mvg Ruud
 
Re: hijackthis log

Geplaatst door free_roelie
hallo pieter .

heb eerst een scan gedaan met spybot .

hier is mijn log alvast bedankt .

O16 - DPF: {214868A8-F71B-473E-8ECF-6EE1DE6B91D8} - http://pms.localscripts.nl/plugins/4/ms7531_nl.cab
NAV gaf waarschuwing bij dit bestand!
O16 - DPF: {4B6015E7-3ABB-45DC-96B7-55A843751F28} (IntRuboskizo2 Class) - http://www.chicasmodelos.com/ruboskizo2.cab
O16 - DPF: {4E15D681-1D20-11D4-8B72-000021DA1956} - http://www.net69.nl/plugin/net69nl126.exe
vink bovenstaanden aan en klik op "fix checked"
:thumb:
 
Re: problemen met explorer

Geplaatst door system1
grote lap text :confused:
zou je ff dat van ad-aware kunnen verwijderen? alleen de hijacklog-this log aub :thumb:

hier ff antwoord op je log (na véél scrollen :rolleyes: ):
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://i-lookup.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://i-lookup.com/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://i-lookup.com/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://i-lookup.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://i-lookup.com/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://i-lookup.com/search.html

O16 - DPF: {018B7EC3-EECA-11D3-8E71-0000E82C6C0D} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab O16 - DPF: {2ABE804B-4D3A-41BF-A172-304627874B45} - http://akamai.downloadv3.com/binari...TML/EGDHTML.cab
O16 - DPF: {841A9192-5690-11D4-A258-0040954A01BE} (DialXSCtl Object) - http://dialxs.nl/install/dialxs.ocx
O16 - DPF: {94742E3F-D9A1-4780-9A87-2FFA43655DA2} - http://akamai.downloadv3.com/binari...GDHTML_pack.cab

vink bovenstaanden aan en klik op "fix checked" :thumb:
 
Laatst bewerkt:
startpagina

heb hetzelfde probleem met de startpagina.
vervolgens heb ik adaware en hijack.this gedwld en de instructie gevolgd.

hierbij de txt bestand van hijack:

Logfile of HijackThis v1.97.7
Scan saved at 13:43:35, on 7-12-2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\program files\altnet\points manager\points manager.exe
C:\Program Files\Common Files\CMEII\CMESys.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\DownloadWare\dw.exe
C:\WINDOWS\System32\cat.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Wanadoo\NL\Mnu\IGOMNU.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\GMT\GMT.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\PROGRA~1\Altnet\DOWNLO~1\asm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\PopupKillerTracksEraser\PopupKillerTray.exe
C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe
C:\PROGRA~1\WINZIP\wzqkpick.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Willem\Local Settings\Temp\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.defaultsearch.com/search/B90D4C2B8B3F4AB2BDDB776C16EAB8D8/1043/ie/searchmn.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Program%20Files/Startportal/Portal/portal.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.defaultsearch.com/search/B90D4C2B8B3F4AB2BDDB776C16EAB8D8/1043/ie/searchba.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.defaultsearch.com/search/B90D4C2B8B3F4AB2BDDB776C16EAB8D8/1043/ie/searchmn.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.defaultsearch.com/search/B90D4C2B8B3F4AB2BDDB776C16EAB8D8/1043/ie/searchmn.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.defaultsearch.com/search/B90D4C2B8B3F4AB2BDDB776C16EAB8D8/1043/ie/searchcs.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.defaultsearch.com/search/B90D4C2B8B3F4AB2BDDB776C16EAB8D8/1043/ie/searchsa.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Startpagina = file:///C:/Program%20Files/Startportal/Portal/portal.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: MediaLoads Enhanced - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C:\Program Files\MediaLoads Enhanced\ME2.DLL
O2 - BHO: (no name) - {A09790E7-DD00-4A83-B632-5B563423CFBB} - C:\Program Files\PopupKillerTracksEraser\PopupKillerIEDLL.dll
O2 - BHO: Httper - {A5483501-070C-41DD-AF44-9BD8864B3015} - C:\Program Files\Httper\httper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Zipclix - {319A68DB-06D0-46DA-9F93-A810D5A70836} - C:\Program Files\Zipclix\zipclix.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points manager\points manager.exe -s
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DownloadWare] "C:\Program Files\DownloadWare\dw.exe" /H
O4 - HKLM\..\Run: [Diskstart] C:\WINDOWS\System32\cat.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Wanadoo Menu] C:\Program Files\Wanadoo\NL\Mnu\IGOMNU.EXE /S:T
O4 - HKCU\..\Run: [System Soap Pro] C:\PROGRA~1\SYSTEM~1\soap.exe min
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {03C543A1-C090-418F-A1D0-FB96380D601D} (preload control) - http://216.82.66.200/build/preload.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {421A63BA-4632-43E0-A942-3B4AB645BE51} - http://download-ak.systemsoap.com/ssoap/pptproactauthakamai/systemsoappro.cab
O16 - DPF: {486E48B5-ABF2-42BB-A327-2679DF3FB822} - http://akamai.downloadv3.com/binaries/IA/ia_XP.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {94742E3F-D9A1-4780-9A87-2FFA43655DA2} - http://akamai.downloadv3.com/binaries/DialHTML/EGDHTML_pack_XP.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37907.1239930556
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} (loader Class) - http://dload.ipbill.com/del/loader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DE591B16-A452-11D6-AED1-0001030A4E46} (PBGNX Control) - https://gto.postbank.nl/GTO/PBGNX.cab
O16 - DPF: {EB6AFDAB-E16D-430B-A5EE-0408A12289DC} - http://download.fordaleltd.com/install/setup.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7E08B654-26C1-4CCC-8DFE-2D96CD2F4AB1}: NameServer = 194.134.5.55 194.134.5.5

wat moet ik nu verder doen??
 
Re: startpagina

Geplaatst door willemknigge
heb hetzelfde probleem met de startpagina.
vervolgens heb ik adaware en hijack.this gedwld en de instructie gevolgd.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.defaultsearch.com/search...ie/searchmn.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.defaultsearch.com/search...ie/searchba.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.defaultsearch.com/search...ie/searchmn.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.defaultsearch.com/search...ie/searchmn.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.defaultsearch.com/search...ie/searchcs.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.defaultsearch.com/search...ie/searchsa.htm

O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKCU\..\Run: [System Soap Pro] C:\PROGRA~1\SYSTEM~1\soap.exe min
O16 - DPF: {421A63BA-4632-43E0-A942-3B4AB645BE51} - http://download-ak.systemsoap.com/s...stemsoappro.cab
O16 - DPF: {486E48B5-ABF2-42BB-A327-2679DF3FB822} - http://akamai.downloadv3.com/binaries/IA/ia_XP.cab
O16 - DPF: {94742E3F-D9A1-4780-9A87-2FFA43655DA2} - http://akamai.downloadv3.com/binari...TML_pack_XP.cab
O16 - DPF: {EB6AFDAB-E16D-430B-A5EE-0408A12289DC} - http://download.fordaleltd.com/install/setup.cab



wat moet ik nu verder doen??
vink bovenstaanden aan en klik op "fix checked" :thumb:
 
log file

Hallo,

Zou iemand naar mijn log file willen kijken.
Heb eerst ad aware laten draaien maar vind niets, krijg steeds een ongevraagde startpagina en zit met een vervelende search balk verder is de computer erg traag.
Wat kan ik verwijderen?

groeten Lineke

Logfile of HijackThis v1.97.3
Scan saved at 14:51:33, on 7-12-03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\VIRUSSCAN\AVSYNMGR.EXE
C:\PROGRAM FILES\MESSENGER PLUS! 2\MSGPLUS.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WND.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\VIRUSSCAN\VSSTAT.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\PDESK\PDESK.EXE
C:\WINDOWS\APPLICATION DATA\MSBB.EXE
C:\WINDOWS\SYSTEM\93018740.EXE
C:\WINDOWS\WT\UPDATER\WCMDMGR.EXE
C:\WINDOWS\APPLICATION DATA\ZOAUJHBL.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\VIRUSSCAN\AVCONSOL.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WNF.EXE
C:\PROGRAM FILES\CLOCKSYNC\SYNC.EXE
C:\WINDOWS\TEMP\XGB194.TMP
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\VIRUSSCAN\VSHWIN32.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\VIRUSSCAN\WEBSCANX.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\NOTEPAD.EXE
D:\PROGRAM FILES\DOWNLOADS\HIJACKTHIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearchnow.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://mysearchnow.com/searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = mysearchnow.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://mysearchnow.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearchnow.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://mysearchnow.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://mysearchnow.com/searchbar.html
F1 - win.ini: run=hpfsched
O2 - BHO: (no name) - {000E7270-CC7A-0786-8E7A-DA09B51938A6} - C:\WINDOWS\SYSTEM\N3TPA1.DLL
O2 - BHO: (no name) - {edbfdb80-2853-11d8-a46a-444553540000} - C:\WINDOWS\APPLICATION DATA\LMPRTHCREK.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: jhhdssyeyep - {edbfdb81-2853-11d8-a46a-444553540000} - C:\WINDOWS\APPLICATION DATA\LMPRTHCREK.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [CriticalUpdate] C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINDOWS\SYSTEM\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKLM\..\Run: [msbb] C:\WINDOWS\APPLICATION DATA\MSBB.EXE
O4 - HKLM\..\Run: [SCQH] C:\WINDOWS\SCQH.exe
O4 - HKLM\..\Run: [BELT] C:\WINDOWS\BELT.exe
O4 - HKLM\..\Run: [93018740.exe] C:\WINDOWS\System\93018740.exe
O4 - HKLM\..\Run: [FMPSWZD] C:\WINDOWS\FMPSWZD.exe
O4 - HKLM\..\Run: [blcrem] C:\WINDOWS\APPLIC~1\zoaujhbl.exe -QuieT
O4 - HKLM\..\Run: [70518130.exe] C:\WINDOWS\System\70518130.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [McAfeeVirusScanService] C:\Program Files\Network Associates\VirusScan\AVSYNMGR.EXE
O4 - HKLM\..\RunServices: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKCU\..\Run: [Weather] C:\PROGRAM FILES\AWS\WEATHERBUG\WEATHER.EXE 1
O4 - HKCU\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [ClockSync] C:\Program Files\ClockSync\Sync.exe
O4 - Startup: Event Reminder.lnk = D:\Program files\printshop\The Print Shop\PSRemind.exe
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37907.254212963
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {DE591B16-A452-11D6-AED1-0001030A4E46} (PBGNX Control) - https://gto.postbank.nl/GTO/PBGNX.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/1d/player.virtools.com/downloads/player/Install2.1/Installer.exe
O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} (WildTangent Control) - http://www.wildtangent.com/install/wdriver/ddc/shockwave/wtinst.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {E3802230-F0E2-4A75-9947-EAB78DD8153F} (InstallerX Class) - http://www.euroklik.nl/cab/EasyWebInstaller.cab
O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktanks/BTDownloadCtrl.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.soundclick.com/CFIDE/classes/CFJava.cab
O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} (ddm_download.ddm_control) - http://download.rfwnad.com/cab/dlaccell.CAB
O16 - DPF: {0C3F7D74-ADA5-4976-8908-A8189590DAFA} (3DGreetings.com Player 2.0) - http://expressit.broderbund.com/Plugin/3DGreetings/vroom.CAB
 
Re: log file

Geplaatst door lineke57
Hallo,

Zou iemand naar mijn log file willen kijken.
Heb eerst ad aware laten draaien maar vind niets, krijg steeds een ongevraagde startpagina en zit met een vervelende search balk verder is de computer erg traag.
Wat kan ik verwijderen?

groeten Lineke

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearchnow.com/searchbar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://mysearchnow.com/searchbar.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = mysearchnow.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://mysearchnow.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearchnow.com/searchbar.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://mysearchnow.com/searchbar.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://mysearchnow.com/searchbar.html

O2 - BHO: (no name) - {000E7270-CC7A-0786-8E7A-DA09B51938A6} - C:\WINDOWS\SYSTEM\N3TPA1.DLL
O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKLM\..\Run: [SCQH] C:\WINDOWS\SCQH.exe
O4 - HKLM\..\Run: [BELT] C:\WINDOWS\BELT.exe
O4 - HKLM\..\Run: [93018740.exe] C:\WINDOWS\System\93018740.exe
O4 - HKLM\..\Run: [FMPSWZD] C:\WINDOWS\FMPSWZD.exe
O4 - HKLM\..\Run: [blcrem] C:\WINDOWS\APPLIC~1\zoaujhbl.exe -QuieT
O4 - HKLM\..\Run: [70518130.exe] C:\WINDOWS\System\70518130.exe

O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} (WildTangent Control) - http://www.wildtangent.com/install/...wave/wtinst.cab
O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} (ddm_download.ddm_control) - http://download.rfwnad.com/cab/dlaccell.CAB
O16 - DPF: {0C3F7D74-ADA5-4976-8908-A8189590DAFA} (3DGreetings.com Player 2.0) - http://expressit.broderbund.com/Plu...tings/vroom.CAB
vink bovenstaanden aan en klik op "fix checked" :thumb:
 
niet helemaal gelukt

Hallo aaajeetee,

Ik heb je advies opgevolgd maar blijf toch nog met de searchbalk zitten.
Ik heb verwijderd wat je hebt aangegeven en de computer opnieuw opgestart maar er staan toch nog een paar in die ik verwijderd had.
Hierbij de nieuwe scan, graag je advies.

groeten Lineke



Logfile of HijackThis v1.97.3
Scan saved at 17:02:21, on 7-12-03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\VIRUSSCAN\AVSYNMGR.EXE
C:\PROGRAM FILES\MESSENGER PLUS! 2\MSGPLUS.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WND.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\WINDOWS\SYSTEM\PDESK\PDESK.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\APPLICATION DATA\MSBB.EXE
C:\PROGRAM FILES\CLOCKSYNC\SYNC.EXE
C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WNF.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\VIRUSSCAN\VSSTAT.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\VIRUSSCAN\VSHWIN32.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\VIRUSSCAN\AVCONSOL.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\NETWORK ASSOCIATES\VIRUSSCAN\WEBSCANX.EXE
D:\PROGRAM FILES\DOWNLOADS\HIJACKTHIS\HIJACKTHIS.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://mysearchnow.com/searchbar.html
F1 - win.ini: run=hpfsched
O2 - BHO: (no name) - {edbfdb80-2853-11d8-a46a-444553540000} - C:\WINDOWS\APPLICATION DATA\LMPRTHCREK.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: jhhdssyeyep - {edbfdb81-2853-11d8-a46a-444553540000} - C:\WINDOWS\APPLICATION DATA\LMPRTHCREK.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [CriticalUpdate] C:\WINDOWS\SYSTEM\wucrtupd.exe -startup
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Matrox Powerdesk] C:\WINDOWS\SYSTEM\PDesk\PDesk.exe /Autolaunch
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [msbb] C:\WINDOWS\APPLICATION DATA\MSBB.EXE
O4 - HKLM\..\Run: [501650.exe] C:\WINDOWS\System\501650.exe
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [McAfeeVirusScanService] C:\Program Files\Network Associates\VirusScan\AVSYNMGR.EXE
O4 - HKLM\..\RunServices: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
O4 - HKCU\..\Run: [Weather] C:\PROGRAM FILES\AWS\WEATHERBUG\WEATHER.EXE 1
O4 - HKCU\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [ClockSync] C:\Program Files\ClockSync\Sync.exe
O4 - HKCU\..\RunServices: [Weather] C:\PROGRAM FILES\AWS\WEATHERBUG\WEATHER.EXE 1
O4 - HKCU\..\RunServices: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
O4 - HKCU\..\RunServices: [ClockSync] C:\Program Files\ClockSync\Sync.exe
O4 - Startup: Event Reminder.lnk = D:\Program files\printshop\The Print Shop\PSRemind.exe
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37907.254212963
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {DE591B16-A452-11D6-AED1-0001030A4E46} (PBGNX Control) - https://gto.postbank.nl/GTO/PBGNX.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/1d/player.virtools.com/downloads/player/Install2.1/Installer.exe
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {E3802230-F0E2-4A75-9947-EAB78DD8153F} (InstallerX Class) - http://www.euroklik.nl/cab/EasyWebInstaller.cab
O16 - DPF: {E13F1132-4CA0-4005-84D3-51406E27D269} (BTDownloadCtrl Control) - http://www.shockwave.com/content/thinktanks/BTDownloadCtrl.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.soundclick.com/CFIDE/classes/CFJava.cab
 
nog een

Dag Pieter,

Zou je mijn log ook even kunnen checken.
Mijn systeem geeft steeds aan dust exe ontbreekt en dat blijkt nu een virus (worm). Het is mij nog steeds niet gelukt hem te verwijderen. Een ander raadde mij aan jou mijn log even te posten zodat je mij wat tips zou kunnen geven

Alvast dank

Ger

Spybot nieuwste versie (1.97.7):

ogfile of HijackThis v1.97.7
Scan saved at 16:44:46, on 7-12-2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Speed Disk\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Classic PhoneTools\CapFax.EXE
C:\Program Files\Medion\PowerCinema\My_TV\Agent.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Winamp3\winampa.exe
C:\WINDOWS\BQTray.exe
C:\Program Files\Trust\250S Series\lwbwheel.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\Norton Utilities\SYSDOC32.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINDOWS\twain_32\A4CIS\WATCH.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.multikabel.nl
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer aangeboden door Multikabel
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
F0 - system.ini: Shell=Explorer.exe dust.exe
F2 - REG:system.ini: Shell=Explorer.exe dust.exe
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {4c7c073d-b5a1-4394-a258-04647e8cd6be} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [CapFax] C:\Program Files\Classic PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [Agent] C:\Program Files\Medion\PowerCinema\My_TV\Agent.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [BurnQuick Queue] C:\WINDOWS\BQTray.exe
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Trust\250S Series\lwbwheel.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - Startup: Microsoft Office Snelzoeken.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Office Opstarten.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: Watch.lnk = C:\WINDOWS\twain_32\A4CIS\WATCH.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Norton System Doctor.lnk = C:\Program Files\Norton Utilities\SYSDOC32.EXE
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O14 - IERESET.INF: START_PAGE_URL=http://www.multikabel.nl
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/...ector/swdir.cab
O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.trojanscan.com/trojanscan/TDECntrl.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/...n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Besturing) - http://a840.g.akamai.net/7/840/537/...all/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/Sh...n/bin/cabsa.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pu...ash/swflash.cab
O16 - DPF: {DE591B16-A452-11D6-AED1-0001030A4E46} (PBGNX Control) - https://www.p3.postbank.nl/GTO/PBGNX.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/i...307/mcfscan.cab
O16 - DPF: {FE8287E9-5F43-11D3-ABCA-00105A5C1F46} (HouseCall Control) - http://www.housecall.nl/housecall/xscan4.cab



Alvast dank

Ger
 
Hallo aaajeetee,

Ik had met ad aware gescand en kreeg geen meldingen, ik heb nu ge-update en krijg een melding van een trojan genaamd AdClicker-O, mijn virusscan kan het alleen niet opschonen of verwijderen dus ik zal eerst eens kijken of ik daar van een andere manier af kan komen of heeft iemand een tip en wat moet ik uit mijn laatst gescande hijack this log file verwijderen.
Alvast bedankt voor je hulp.

Lineke
 
opgelost

Hallo aajeetee,


Ik heb de trojan AdClicker-O kunnen verwijderen en heb daarna alsnog de dingen verwijderd die na jou eerste uitleg waren blijven staan en nu ben ik die vervelende search balk kwijt.
Dus het probleem is toch nog opgelost.
Bedankt en de groetjes van Lineke
 
Hallo aajeetee,

bij deze mijn log ;)

Logfile of HijackThis v1.97.7
Scan saved at 19:53:18, on 7-12-2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE
C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Antivirus Titanium\Pavsrv51.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Panda Software\Panda Antivirus Titanium\AVENGINE.EXE
C:\Program Files\Panda Software\Panda Antivirus Titanium\pavProxy.exe
C:\windows\redirect5.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Jenny\Local Settings\Temp\Tijdelijke map 2 voor hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.paradigit.nl
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.0.0.138:80
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Titanium\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [IW_ControlCenter] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [VOBID] C:\Program Files\Pinnacle\InstantCDDVD\\InstantDrive\InstantDrive.exe /remount
O4 - HKLM\..\Run: [redirect] C:\windows\redirect5.exe
O4 - HKLM\..\Run: [easywww] c:\windows\easywww2.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O14 - IERESET.INF: START_PAGE_URL=http://www.paradigit.nl
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37961.3601041667
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O16 - DPF: {FE8287E9-5F43-11D3-ABCA-00105A5C1F46} (HouseCall Control) - http://www.housecall.nl/housecall/xscan4.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FC59E1A3-A514-48D9-9006-EEEA652D0738}: NameServer = 194.109.6.66,194.109.9.99

Ik hoop dat het allemaal een beetje in orde is.. Alvast bedankt iig!

Groetjes, Jen
 
Wat ik vergeten was erbij te zetten; Ik heb eerst spy-bot gebruikt en daarna hijack, sorry!

Groetjes, Jen
 
Geplaatst door Seal
Hallo aajeetee,

bij deze mijn log ;)

O4 - HKLM\..\Run: [redirect] C:\windows\redirect5.exe
O4 - HKLM\..\Run: [easywww] c:\windows\easywww2.exe

Groetjes, Jen
alleen even naar bovenstaanden kijken...als het iets is wat je geïnstalleerd hebt, dan laten staan :)
zo niet, dan aanvinken en op "fix checked" klikken :thumb:
voor de rest schoon :)
 
Re: nog een

Geplaatst door jerryleelewis
Dag Pieter,


F0 - system.ini: Shell=Explorer.exe dust.exe
F2 - REG:system.ini: Shell=Explorer.exe dust.exe

vink bovenstaanden aan en klik op "fix checked" :thumb:
 
Re: log

Geplaatst door RA10
Hier is mijn log, en mijn computer is ook een stuk langzamer geworden

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.windowws.cc/sp.htm?id=9
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.windowws.cc/sp.htm?id=9
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sweeties.teensfestival.com/search.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.windowws.cc/sp.htm?id=9

O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE

O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART

O4 - HKLM\..\Run: [Online Service] C:\WINDOWS\svchost.exe

O4 - HKCU\..\Run: [Windows Control] C:\WINDOWS\control.exe

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O15 - Trusted Zone: *.waitsex.com

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.6.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/1662a922ea6943b9fa05/netzip/RdxIE601.cab

O16 - DPF: {B942A249-D1E7-4C11-98AE-FCB76B08747F} (RealArcadeRdxIE Class) - http://games-dl.real.com/gameconsole/Bundler/CAB/RealArcadeRdxIE.cab

Vink de bovenstaande aan, sluit alle vensters behalve HijackThis en klik op Fix checked:

Daarna download, unzip en run CWShredder

Verwijder C:\WINDOWS\svchost.exe <= let op dat je de goede pakt. De echte zit in de System32 map en daar moet je vanaf blijven.

Groetjes,

Pieter
 
Status
Niet open voor verdere reacties.
Terug
Bovenaan Onderaan