Ik kwam er vandaag pas achter dat Admilli Services iets kwaadaardigs is....
heb de map al verscheidene malen verwijderd, maar ja, hij komt dus steeds
weer terug!!
Adaware en Spybot reeds laten scannen, hieronder mijn HJT log
Alvast bedankt voor de hulp!!
AREND!!
Logfile of HijackThis v1.99.0
Scan saved at 15:36:01, on 31-12-2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
c:\RECYCLER\system32\MSSvc.EXE
c:\RECYCLER\system32\userlist.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
c:\RECYCLER\system32\MSSvc.EXE
c:\RECYCLER\system32\runbatch.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\WINNT\system32\svhost.exe
C:\WINNT\RUNDLL16.EXE
C:\winnt\win32\ntlm.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
D:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Admilli Service\AdmilliKeep.exe
C:\WINNT\system32\ruwm.exe
C:\WINNT\system32\svhost.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
D:\Programs\RegCleaner\RegCleanr.exe
D:\Program Files\Avant Browser\avant.exe
D:\PROGRA~1\LAVASOFT\AD-AWA~1\AD-AWARE.EXE
C:\Program Files\Admilli Service\AdmilliServ.exe
C:\WINNT\explorer.exe
D:\Program Files\IrfanView\I_VIEW32.EXE
D:\Programs\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gmail.google.com/gmail
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Microsoft Synchronization Manager] svhost.exe
O4 - HKLM\..\Run: [Windows DLL Loader] C:\WINNT\RUNDLL16.EXE
O4 - HKLM\..\Run: [Windows+Services] c:\winnt\win32\ntlm.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] D:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [Admilli Service] C:\Program Files\Admilli Service\AdmilliServ.exe
O4 - HKLM\..\RunServices: [Microsoft Synchronization Manager] svhost.exe
O4 - HKLM\..\RunOnce: [AAW] "D:\PROGRA~1\LAVASOFT\AD-AWA~1\AD-AWARE.EXE" "+b1"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [JavaUpdate0.07] C:\WINNT\system32\ruwm.exe
O4 - HKCU\..\Run: [Microsoft Synchronization Manager] svhost.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Snelstart HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: Alle links in deze pagina openen... - D:\Program Files\Avant Browser\OpenAllLinks.htm
O8 - Extra context menu item: Blokkeer alle plaatjes afkomstig van dezelfde server - D:\Program Files\Avant Browser\AddAllToADBlackList.htm
O8 - Extra context menu item: Markeren - D:\Program Files\Avant Browser\Highlight.htm
O8 - Extra context menu item: Toevoegen aan Reclame Black List - D:\Program Files\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: Zoeken - D:\Program Files\Avant Browser\Search.htm
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = rovict.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = rovict.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = rovict.local
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
O23 - Service: Logical Disk Manager Administrative-service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: MSSvc msnet - Unknown - c:\RECYCLER\system32\MSSvc.EXE
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: MSSvc runbatch - Unknown - c:\RECYCLER\system32\MSSvc.EXE
heb de map al verscheidene malen verwijderd, maar ja, hij komt dus steeds
weer terug!!

Adaware en Spybot reeds laten scannen, hieronder mijn HJT log
Alvast bedankt voor de hulp!!
AREND!!
Logfile of HijackThis v1.99.0
Scan saved at 15:36:01, on 31-12-2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
c:\RECYCLER\system32\MSSvc.EXE
c:\RECYCLER\system32\userlist.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
c:\RECYCLER\system32\MSSvc.EXE
c:\RECYCLER\system32\runbatch.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\WINNT\system32\svhost.exe
C:\WINNT\RUNDLL16.EXE
C:\winnt\win32\ntlm.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
D:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Admilli Service\AdmilliKeep.exe
C:\WINNT\system32\ruwm.exe
C:\WINNT\system32\svhost.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
D:\Programs\RegCleaner\RegCleanr.exe
D:\Program Files\Avant Browser\avant.exe
D:\PROGRA~1\LAVASOFT\AD-AWA~1\AD-AWARE.EXE
C:\Program Files\Admilli Service\AdmilliServ.exe
C:\WINNT\explorer.exe
D:\Program Files\IrfanView\I_VIEW32.EXE
D:\Programs\hijackthis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gmail.google.com/gmail
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Microsoft Synchronization Manager] svhost.exe
O4 - HKLM\..\Run: [Windows DLL Loader] C:\WINNT\RUNDLL16.EXE
O4 - HKLM\..\Run: [Windows+Services] c:\winnt\win32\ntlm.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] D:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [Admilli Service] C:\Program Files\Admilli Service\AdmilliServ.exe
O4 - HKLM\..\RunServices: [Microsoft Synchronization Manager] svhost.exe
O4 - HKLM\..\RunOnce: [AAW] "D:\PROGRA~1\LAVASOFT\AD-AWA~1\AD-AWARE.EXE" "+b1"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [JavaUpdate0.07] C:\WINNT\system32\ruwm.exe
O4 - HKCU\..\Run: [Microsoft Synchronization Manager] svhost.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Snelstart HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: Alle links in deze pagina openen... - D:\Program Files\Avant Browser\OpenAllLinks.htm
O8 - Extra context menu item: Blokkeer alle plaatjes afkomstig van dezelfde server - D:\Program Files\Avant Browser\AddAllToADBlackList.htm
O8 - Extra context menu item: Markeren - D:\Program Files\Avant Browser\Highlight.htm
O8 - Extra context menu item: Toevoegen aan Reclame Black List - D:\Program Files\Avant Browser\AddToADBlackList.htm
O8 - Extra context menu item: Zoeken - D:\Program Files\Avant Browser\Search.htm
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = rovict.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = rovict.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = rovict.local
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
O23 - Service: Logical Disk Manager Administrative-service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: MSSvc msnet - Unknown - c:\RECYCLER\system32\MSSvc.EXE
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: MSSvc runbatch - Unknown - c:\RECYCLER\system32\MSSvc.EXE
Comment