Mededeling

Collapse
No announcement yet.

Erg vervelende spyware, Adaware enz. helpt niets

Collapse
X
  •  
  • Filter
  • Tijd
  • Show
Clear All
new posts

  • Erg vervelende spyware, Adaware enz. helpt niets

    Logfile of HijackThis v1.99.0
    Scan saved at 13:56:32, on 26-12-04
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v5.50 SP1 (5.50.4522.1800)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\MDM.EXE
    C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
    C:\PROGRAM FILES\MESSENGER PLUS! 3\MSGPLUS.EXE
    C:\WINDOWS\SYSTEM\RPCSS.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\LOADQM.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
    C:\WINDOWS\SYSTEM\P2P NETWORKING\P2P NETWORKING.VXD
    C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
    C:\WINDOWS\SYSTEM\LVCOMS.EXE
    C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
    C:\WINDOWS\SYSTEM\QTTASK.EXE
    C:\PROGRAM FILES\CASHBACK\BIN\CASHBACK.EXE
    C:\WINDOWS\SYSTEM\INTERNAT.EXE
    C:\PROGRAM FILES\BULLSEYE NETWORK\BIN\BARGAINS.EXE
    C:\PROGRAM FILES\NAVISEARCH\BIN\NLS.EXE
    C:\ATI\ATIDESK\ATISCHED.EXE
    C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WNF.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
    C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL
    = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
    http://www.qybidzyuochzlhxrbyacobhuz.com/yKrd08FUMtyLlJ/3e4WgtxyQ0UgfyCaATlIFoiJmdukAQGESxGKhQbHqCJyAICPO.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    http://www.oneway.nl/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant =
    about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    http://www.findthewebsiteyouneed.com/default_tc.asp
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName
    = Koppelingen
    O2 - BHO: Google Toolbar Helper -
    {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program
    files\google\googletoolbar1.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
    C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {960033B4-4823-9954-2465-3F3975CD8F72} -
    C:\WINDOWS\APPLICATION DATA\README BITS\REGS INSIDE.EXE
    O2 - BHO: ADP UrlCatcher Class -
    {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\SYSTEM\MSBE.DLL
    O2 - BHO: NLS UrlCatcher Class -
    {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\SYSTEM\NVMS.DLL
    O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14}
    - C:\WINDOWS\SYSTEM\MSCB.DLL
    O3 - Toolbar: @msdxmLC.dll,[email protected],&Radio -
    {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} -
    c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: IEMenuExtension toolbar -
    {6b95678d-30a4-4ff8-a72f-4208340c1f7f} - C:\PROGRAM
    FILES\IEMENUEXTENSION\TBEXTN.DLL
    O4 - HKLM\..\Run: [Taakcontrole] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe
    powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
    O4 - HKLM\..\Run: [AtiKey] atiptkad.exe
    O4 - HKLM\..\Run: [ATIGART] c:\ATI\GART\ATIGART.exe
    O4 - HKLM\..\Run: [AtiQiPcl] AtiQiPcl.exe
    O4 - HKLM\..\Run: [CreativeMixer] C:\SBPCI\ctmix32.exe /T
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
    O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\AVAST4\ashmaisv.exe
    O4 - HKLM\..\Run: [ScanRegistry] "C:\Windows\scanregw.exe /autorun"
    O4 - HKLM\..\Run: [P2P NETWORKING] C:\WINDOWS\SYSTEM\P2P
    NETWORKING\P2P NETWORKING.VXD /AUTOSTART
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [LVComs] C:\WINDOWS\SYSTEM\LVComS.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program
    Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\Run: [Log readme two amen] C:\WINDOWS\Application
    Data\Blah bore log readme\HopeStart.exe
    O4 - HKLM\..\Run: [CashBack] C:\Program Files\CashBack\bin\cashback.exe
    O4 - HKLM\..\Run: [IE Menu Extension toolbar] rundll32.exe
    "C:\PROGRA~1\IEMENU~1\tbextn.dll" DllShowTB
    O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye
    Network\bin\bargains.exe
    O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe
    powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
    O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
    O4 - HKLM\..\RunServices: [avast!] C:\Program Files\Alwil
    Software\Avast4\ashServ.exe
    O4 - HKLM\..\RunServices: [MessengerPlus3] "C:\Program Files\Messenger
    Plus! 3\MsgPlus.exe"
    O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus!
    3\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [Log bags] C:\WINDOWS\APPLIC~1\SPAMAC~1\mapi title tons.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN
    MESSENGER\MSNMSGR.EXE" /background
    O4 - Startup: ATISched.lnk = C:\ATI\ATIDESK\atisched.exe
    O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
    Office\Office\OSA9.EXE
    O8 - Extra context menu item: &Google Search - res://C:\PROGRAM
    FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
    O8 - Extra context menu item: Cached Snapshot of Page -
    res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
    O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM
    FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
    O8 - Extra context menu item: Backward Links - res://C:\PROGRAM
    FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
    O8 - Extra context menu item: Translate into English -
    res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -
    C:\WINDOWS\SYSTEM\Shdocvw.dll
    O16 - DPF: {689ff870-2ac0-11d5-b634-00c04faedb18} -
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
    (MessengerStatsClient Class) -
    http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
    http://messenger.zone.msn.com/binary/msgrchkr.cab
    O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags
    Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab27571.cab
    O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) -
    http://static.topconverting.com/activex/loader2.ocx
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
    http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4416/mcfscan.cab
    O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 192.168.2.1

  • #2
    1/
    de lop infectie via messangerPlus kan je volgens deze stappen eraf krijgen

    2/
    Downloaded en Install en Setup Spybot S&D,

    3/
    Download and Installen Setup Ad-Aware SE,


    4/
    A2 squared is een trojan scanner die werkt zoals spybot s&d maar dan voor trojans.
    Download en install A2 squared free Trojan scanner
    Activeer uw gratis versie van A squared en selecteer vervolgensv
    "Scan your computer for malware infections"
    selecteer de stations en klik op "Scan selected folders".


    5/
    vervolgens deze nieuwe versie van HIJACKTHIS gebruiken voor een vers logje

    het zal wat extra info geven
    not so Helpless ...

    Comment


    • #3
      Ik heb de stappen uitgevoerd. Hier dan een nieuwe scan.


      Logfile of HijackThis v1.99.0
      Scan saved at 16:45:04, on 2-1-05
      Platform: Windows 98 SE (Win9x 4.10.2222A)
      MSIE: Internet Explorer v5.50 SP1 (5.50.4522.1800)

      Running processes:
      C:\WINDOWS\SYSTEM\KERNEL32.DLL
      C:\WINDOWS\SYSTEM\MSGSRV32.EXE
      C:\WINDOWS\SYSTEM\MPREXE.EXE
      C:\WINDOWS\SYSTEM\mmtask.tsk
      C:\WINDOWS\SYSTEM\MSTASK.EXE
      C:\WINDOWS\SYSTEM\MDM.EXE
      C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
      C:\WINDOWS\EXPLORER.EXE
      C:\WINDOWS\TASKMON.EXE
      C:\WINDOWS\LOADQM.EXE
      C:\WINDOWS\SYSTEM\STIMON.EXE
      C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
      C:\WINDOWS\SYSTEM\P2P NETWORKING\P2P NETWORKING.VXD
      C:\PROGRAM FILES\WINAMP\WINAMPA.EXE
      C:\WINDOWS\SYSTEM\RPCSS.EXE
      C:\WINDOWS\SYSTEM\INTERNAT.EXE
      C:\WINDOWS\SYSTEM\LVCOMS.EXE
      C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
      C:\WINDOWS\SYSTEM\QTTASK.EXE
      C:\ATI\ATIDESK\ATISCHED.EXE
      C:\WINDOWS\SYSTEM\DDHELP.EXE
      C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WNF.EXE
      C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
      C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.zmgwuymufcaqdrtsb.com/OvnGvhKOc3RufOsi7bSnPPmstXQ2B/N6lBdnVrlW89bQD/8qT8RCUVuZGQNpDzzT.html
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.oneway.nl/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O3 - Toolbar: @msdxmLC.dll,[email protected],&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [Taakcontrole] C:\WINDOWS\taskmon.exe
      O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
      O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
      O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
      O4 - HKLM\..\Run: [AtiKey] atiptkad.exe
      O4 - HKLM\..\Run: [ATIGART] c:\ATI\GART\ATIGART.exe
      O4 - HKLM\..\Run: [AtiQiPcl] AtiQiPcl.exe
      O4 - HKLM\..\Run: [CreativeMixer] C:\SBPCI\ctmix32.exe /T
      O4 - HKLM\..\Run: [LoadQM] loadqm.exe
      O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
      O4 - HKLM\..\Run: [ashMaiSv] C:\PROGRA~1\ALWILS~1\AVAST4\ashmaisv.exe
      O4 - HKLM\..\Run: [ScanRegistry] "C:\Windows\scanregw.exe /autorun"
      O4 - HKLM\..\Run: [P2P NETWORKING] C:\WINDOWS\SYSTEM\P2P NETWORKING\P2P NETWORKING.VXD /AUTOSTART
      O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
      O4 - HKLM\..\Run: [LVComs] C:\WINDOWS\SYSTEM\LVComS.exe
      O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
      O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
      O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
      O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
      O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
      O4 - HKLM\..\RunServices: [avast!] C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
      O4 - Startup: ATISched.lnk = C:\ATI\ATIDESK\atisched.exe
      O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
      O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
      O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
      O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
      O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
      O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
      O16 - DPF: {689ff870-2ac0-11d5-b634-00c04faedb18} -
      O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
      O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
      O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
      O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab27571.cab
      O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4416/mcfscan.cab
      O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 192.168.2.1

      Comment


      • #4
        doe een nieuwe scan met hijackthis
        vink de onderstaande lijntjes aan
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.zmgwuymufcaqdrtsb.com/Ov...uZGQNpDzzT.html
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
        Sluit alle vensters behalve hijackthis
        KLIK OP FIX


        plaats een vers logje

        nu ik zou ook iets kwijtwillen over je p2p , namelijk verwijder het en pak een spyware free p2p tooltje , je kan er alles over lezen hier : http://www.spywareinfo.com/articles/p2p/
        Infected <--> Clean
        not so Helpless ...

        Comment


        • #5
          Super, bedankt !

          Helemaal te gek zeg.

          Alles is weer normaal volgens mij. Heb jij enig idee hoe deze ellende in mijn pc is gekomen ?

          Bedankt voor jou tijd en moeite !!!!!!!!!

          Bey Bey en laterzzz B0J0

          Comment


          • #6
            ja met messanger plus , kleine lettertjes lezen volgende keer , boeltje mag je gebruiken maar moet je ZONDER sponsors installeren.
            enne voor alle zekerheid zou ik toch graag een vers hijackthis logje zien.
            not so Helpless ...

            Comment


            • #7
              Ik vraag me even wat af, misschien wel offtopic hier. Maar ik was de topic starter. Ik snap niet dat B0J0 kan zeggen dat het bij hem/haar helpt... terwijl het mijn posting was...

              Comment


              • #8
                Oorspronkelijk geplaatst door bjbd
                Ik vraag me even wat af, misschien wel offtopic hier. Maar ik was de topic starter. Ik snap niet dat B0J0 kan zeggen dat het bij hem/haar helpt... terwijl het mijn posting was...
                B0J0 was bliijkbaar een beetje verdwaald... Zijn thread staat hier: http://www.nucia.eu/forum/showthread.php?p=8434

                Comment


                • #9
                  had ik niet eens gemerkt bjbd, sorry daarvoor , maar je mag de stappen uitvoern en een vers logje plaatsen
                  not so Helpless ...

                  Comment


                  • #10
                    En ik heb helemaal vergeten te melden dat dit bovenstaande probleem is opgelost. Alleen ben ik het nieuwe logje vergeten te plaatsen.

                    En op het systeem is nu een van aanbevolen P2P programma's geinstalleerd.

                    Comment

                    Sorry, you are not authorized to view this page
                    Working...
                    X