Mededeling

Collapse
No announcement yet.

HomeSearchAssistent in programmalijst icm andere ongewenste zaken

Collapse
X
  •  
  • Tijd
  • Show
Clear All
new posts

  • HomeSearchAssistent in programmalijst icm andere ongewenste zaken

    HomeSearchAssistent staat in "Software lijst" samen met:
    - Search Extender
    - Search Relevancy
    - Shopping Wizzard
    - Your Sitebar
    - Windows ServeAd

    Ad-aware en Spybot zijn al gerund. Dit is de log.



    Logfile of HijackThis v1.98.2
    Scan saved at 22:00:15, on 1-1-2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\System32\nvsvc32.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\syshw.exe
    C:\WINNT\Explorer.EXE
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    E:\dl\prog\quicktime\extracted\installatie\qttask.exe
    C:\Program Files\FSI\F-Prot\F-StopW.EXE
    C:\WINNT\system32\CTHELPER.EXE
    C:\Program Files\Windows ServeAd\WinServAd.exe
    C:\WINNT\system32\sysfv32.exe
    C:\Program Files\Windows ServeAd\WinServSuit.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    E:\dl\prog\Hijackthis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\vyhwo.dll/sp.html#37680
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\vyhwo.dll/sp.html#37680
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\vyhwo.dll/sp.html#37680
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\vyhwo.dll/sp.html#37680
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\vyhwo.dll/sp.html#37680
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\vyhwo.dll/sp.html#37680
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\vyhwo.dll/sp.html#37680
    R3 - Default URLSearchHook is missing
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - e:\dl\acrobat-reader\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {C9654F9B-5DA7-6848-264B-261DD286C5D1} - C:\WINNT\javabt.dll
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [QuickTime Task] "E:\dl\prog\quicktime\extracted\installatie\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
    O4 - HKLM\..\Run: [F-StopW] C:\Program Files\FSI\F-Prot\F-StopW.EXE
    O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
    O4 - HKLM\..\Run: [EPSON Stylus C62 Series (Copy 2)] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P32 "EPSON Stylus C62 Series (Copy 2)" /O5 "LPT1:" /M "Stylus C62"
    O4 - HKLM\..\Run: [EPSON Stylus C62 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C62 Series" /O5 "LPT1:" /M "Stylus C62"
    O4 - HKLM\..\Run: [Windows ServeAd] C:\Program Files\Windows ServeAd\WinServAd.exe
    O4 - HKLM\..\Run: [sysfv32.exe] C:\WINNT\system32\sysfv32.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O15 - Trusted Zone: *.05p.com
    O15 - Trusted Zone: *.awmdabest.com
    O15 - Trusted Zone: *.blazefind.com
    O15 - Trusted Zone: *.clickspring.net
    O15 - Trusted Zone: *.flingstone.com
    O15 - Trusted Zone: *.frame.crazywinnings.com
    O15 - Trusted Zone: *.mt-download.com
    O15 - Trusted Zone: *.my-internet.info
    O15 - Trusted Zone: *.scoobidoo.com
    O15 - Trusted Zone: *.searchbarcash.com
    O15 - Trusted Zone: *.searchmiracle.com
    O15 - Trusted Zone: *.slotch.com
    O15 - Trusted Zone: *.static.topconverting.com
    O16 - DPF: {018A066F-584A-422F-AC4C-0B1F5FE5C040} (VacPro.olanda_ver3) - http://advnt01.com/dialer/olanda_ver3.CAB
    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/ClickYesToContinue/ie/bridge-c11.cab
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
    O16 - DPF: {771A1334-6B08-4A6B-AEDC-CF994BA2CEBE} (Installer Class) - http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cab
    O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
    O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.hostance.net/dialer/604444.exe
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4313/mcfscan.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{D3F0AF0F-5FFC-4084-B392-73B6206C2E41}: NameServer = 131.174.60.21,131.174.64.5

  • #2
    via add/remove optie in windows moet je "Windows ServeAd" verwijderen

    download dit tooltje :

    uitpakken in een eigen folder, klik vervolgens op getservice.bat
    het zal een text bestandje maaken getservice.txt , plaats dit in je volgende antwoord
    alsook een log met hijackthis 1.99.0

    alvast ook downloaden en klaarhouden voor later , dus best samen in een folder plaatsen :

    Discover the latest breaking news in the U.S. and around the world — politics, weather, entertainment, lifestyle, finance, sports and much more.


    en ad-aware scanner http://www.lavasoft.de/ op uw pc plaatsen
    not so Helpless ...

    Comment


    • #3
      Getservices:


      PsService v1.1 - local and remote services viewer/controller
      Copyright (C) 2001-2003 Mark Russinovich
      Sysinternals - www.sysinternals.com

      SERVICE_NAME: Alerter
      Notifies selected users and computers of administrative alerts.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\services.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Alerter
      DEPENDENCIES : LanmanWorkstation
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: AppMgmt
      Provides software installation services such as Assign, Publish, and Remove.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\services.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Application Management
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: awhost32
      "Hiermee kunnen remote pcAnywhere-gebruikers verbinding maken met deze pc."
      TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\Program Files\Symantec\pcAnywhere\awhost32.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : pcAnywhere Host Service
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: BITS
      Transfers files in the background using idle network bandwidth. If the service is disabled, then any functions that depend on BITS, such as Windows Update or MSN Explorer will be unable to automatically download programs and other information.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k BITSgroup
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Background Intelligent Transfer Service
      DEPENDENCIES : LanmanWorkstation
      : Rpcss
      : SENS
      : Wmi
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: Browser
      Maintains an up-to-date list of computers on your network and supplies the list to programs that request it.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\services.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Computer Browser
      DEPENDENCIES : LanmanWorkstation
      : LanmanServer
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: cisvc
      Indexes contents and properties of files on local and remote computers; provides rapid access to files through flexible querying language.
      TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\cisvc.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Indexing Service
      DEPENDENCIES : RPCSS
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: ClipSrv
      Supports ClipBook Viewer, which allows pages to be seen by remote ClipBooks.
      TYPE : 10 WIN32_OWN_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\clipsrv.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : ClipBook
      DEPENDENCIES : NetDDE
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: Dhcp
      Manages network configuration by registering and updating IP addresses and DNS names.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\services.exe
      LOAD_ORDER_GROUP : TDI
      TAG : 0
      DISPLAY_NAME : DHCP Client
      DEPENDENCIES : Tcpip
      : Afd
      : NetBT
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: dmadmin
      Administrative service for disk management requests
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\System32\dmadmin.exe /com
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Logical Disk Manager Administrative Service
      DEPENDENCIES : RpcSs
      : PlugPlay
      : DmServer
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: dmserver
      Logical Disk Manager Watchdog Service
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\System32\services.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Logical Disk Manager
      DEPENDENCIES : RpcSs
      : PlugPlay
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: Dnscache
      Resolves and caches Domain Name System (DNS) names.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\services.exe
      LOAD_ORDER_GROUP : TDI
      TAG : 0
      DISPLAY_NAME : DNS Client
      DEPENDENCIES : Tcpip
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: EPSONStatusAgent2
      (null)
      TYPE : 10 WIN32_OWN_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : EPSON Printer Status Agent2
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: Eventlog
      Logs event messages issued by programs and Windows. Event Log reports contain information that can be useful in diagnosing problems. Reports are viewed in Event Viewer.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\services.exe
      LOAD_ORDER_GROUP : Event log
      TAG : 0
      DISPLAY_NAME : Event Log
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: EventSystem
      Provides automatic distribution of events to subscribing COM components.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
      LOAD_ORDER_GROUP : Network
      TAG : 0
      DISPLAY_NAME : COM+ Event System
      DEPENDENCIES : RPCSS
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: Fax
      Helps you send and receive faxes
      TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\faxsvc.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Fax Service
      DEPENDENCIES : TapiSrv
      : RpcSs
      : PlugPlay
      : Spooler
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: lanmanserver
      Provides RPC support and file, print, and named pipe sharing.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\services.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Server
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: lanmanworkstation
      Provides network connections and communications.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\services.exe
      LOAD_ORDER_GROUP : NetworkProvider
      TAG : 0
      DISPLAY_NAME : Workstation
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: LmHosts
      Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\services.exe
      LOAD_ORDER_GROUP : TDI
      TAG : 0
      DISPLAY_NAME : TCP/IP NetBIOS Helper Service
      DEPENDENCIES : NetBT
      : Afd
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: Messenger
      Sends and receives messages transmitted by administrators or by the Alerter service.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\services.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Messenger
      DEPENDENCIES : LanmanWorkstation
      : NetBIOS
      : RpcSS
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: mnmsrvc
      Allows authorized people to remotely access your Windows desktop using NetMeeting.
      TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\System32\mnmsrvc.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : NetMeeting Remote Desktop Sharing
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: MSDTC
      Coordinates transactions that are distributed across two or more databases, message queues, file systems, or other transaction protected resource managers.
      TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\System32\msdtc.exe
      LOAD_ORDER_GROUP : MS Transactions
      TAG : 1
      DISPLAY_NAME : Distributed Transaction Coordinator
      DEPENDENCIES : RPCSS
      : SamSS
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: MSIServer
      Installs, repairs and removes software according to instructions contained in .MSI files.
      TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\System32\MsiExec.exe /V
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Windows Installer
      DEPENDENCIES : RpcSs
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: NetDDE
      Provides network transport and security for dynamic data exchange (DDE).
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\netdde.exe
      LOAD_ORDER_GROUP : NetDDEGroup
      TAG : 0
      DISPLAY_NAME : Network DDE
      DEPENDENCIES : NetDDEDSDM
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: NetDDEdsdm
      Manages shared dynamic data exchange and is used by Network DDE
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\netdde.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Network DDE DSDM
      DEPENDENCIES :
      : EGrLocalSystem
      : Network DDE DSDM
      : etwork DDE
      : ted Transaction Coordinator
      : trative Service
      : b
      : 
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: Netlogon
      Supports pass-through authentication of account logon events for computers in a domain.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\lsass.exe
      LOAD_ORDER_GROUP : RemoteValidation
      TAG : 0
      DISPLAY_NAME : Net Logon
      DEPENDENCIES : LanmanWorkstation
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: Netman
      Manages objects in the Network and Dial-Up Connections folder, in which you can view both local area network and remote connections.
      TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Network Connections
      DEPENDENCIES : RpcSs
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: NtLmSsp
      Provides security to remote procedure call (RPC) programs that use transports other than named pipes.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\lsass.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : NT LM Security Support Provider
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: NtmsSvc
      Manages removable media, drives, and libraries.
      TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Removable Storage
      DEPENDENCIES : RpcSs
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: NVSvc
      (null)
      TYPE : 10 WIN32_OWN_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\System32\nvsvc32.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : NVIDIA Driver Helper Service
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: PlugPlay
      Manages device installation and configuration and notifies programs of device changes.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\services.exe
      LOAD_ORDER_GROUP : PlugPlay
      TAG : 0
      DISPLAY_NAME : Plug and Play
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: PolicyAgent
      Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\lsass.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : IPSEC Policy Agent
      DEPENDENCIES : RPCSS
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: ProtectedStorage
      Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users.
      TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\services.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Protected Storage
      DEPENDENCIES : RpcSs
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: RasAuto
      Creates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address.
      TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\svchost.exe -k netsvcs
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Remote Access Auto Connection Manager
      DEPENDENCIES : RasMan
      : Tapisrv
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: RasMan
      Creates a network connection.
      TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\svchost.exe -k netsvcs
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Remote Access Connection Manager
      DEPENDENCIES : Tapisrv
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: RemoteAccess
      Offers routing services to businesses in local area and wide area network environments.
      TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS
      START_TYPE : 4 DISABLED
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\svchost.exe -k netsvcs
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Routing and Remote Access
      DEPENDENCIES : RpcSS
      : +NetBIOSGroup
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: RemoteRegistry
      Allows remote registry manipulation.
      TYPE : 10 WIN32_OWN_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\regsvc.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Remote Registry Service
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem
      FAIL_RESET_PERIOD : 0 seconds
      FAILURE_ACTIONS : Restart DELAY: 1000 seconds

      SERVICE_NAME: RpcLocator
      Manages the RPC name service database.
      TYPE : 10 WIN32_OWN_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\locator.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Remote Procedure Call (RPC) Locator
      DEPENDENCIES : LanmanWorkstation
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: RpcSs
      Provides the endpoint mapper and other miscellaneous RPC services.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\svchost -k rpcss
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Remote Procedure Call (RPC)
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: RSVP
      Provides network signaling and local traffic control setup functionality for QoS-aware programs and control applets.
      TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\rsvp.exe -s
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : QoS RSVP
      DEPENDENCIES : TcpIp
      : Afd
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: SamSs
      Stores security information for local user accounts.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\lsass.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Security Accounts Manager
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: SCardDrv
      Provides support for legacy smart card readers attached to the computer.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 0 IGNORE
      BINARY_PATH_NAME : C:\WINNT\System32\SCardSvr.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Smart Card Helper
      DEPENDENCIES : +Smart Card Reader
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: SCardSvr
      Manages and controls access to a smart card inserted into a smart card reader attached to the computer.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 0 IGNORE
      BINARY_PATH_NAME : C:\WINNT\System32\SCardSvr.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Smart Card
      DEPENDENCIES : PlugPlay
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: Schedule
      Enables a program to run at a designated time.
      TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\MSTask.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Task Scheduler
      DEPENDENCIES : RpcSs
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: seclogon
      Enables starting processes under alternate credentials
      TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 0 IGNORE
      BINARY_PATH_NAME : C:\WINNT\system32\services.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : RunAs Service
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: SENS
      Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\svchost.exe -k netsvcs
      LOAD_ORDER_GROUP : Network
      TAG : 0
      DISPLAY_NAME : System Event Notification
      DEPENDENCIES : EventSystem
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: SharedAccess
      Provides network address translation, addressing, and name resolution services for all computers on your home network through a dial-up connection.
      TYPE : 120 WIN32_SHARE_PROCESS INTERACTIVE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\svchost.exe -k netsvcs
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Internet Connection Sharing
      DEPENDENCIES : RasMan
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: Spooler
      Loads files to memory for later printing.
      TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\spoolsv.exe
      LOAD_ORDER_GROUP : SpoolerGroup
      TAG : 0
      DISPLAY_NAME : Print Spooler
      DEPENDENCIES : RPCSS
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: StiSvc
      (null)
      TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\stisvc.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Still Image Service
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: SysmonLog
      Configures performance logs and alerts.
      TYPE : 10 WIN32_OWN_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\smlogsvc.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Performance Logs and Alerts
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: TapiSrv
      Provides Telephony API (TAPI) support for programs that control telephony devices and IP based voice connections on the local computer and, through the LAN, on servers that are also running the service.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Telephony
      DEPENDENCIES : PlugPlay
      : RpcSs
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: TlntSvr
      Allows a remote user to log on to the system and run console programs using the command line.
      TYPE : 10 WIN32_OWN_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\tlntsvr.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Telnet
      DEPENDENCIES : RpcSs
      : TcpIp
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: TrkWks
      Sends notifications of files moving between NTFS volumes in a network domain.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\services.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Distributed Link Tracking Client
      DEPENDENCIES : RpcSs
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: UPS
      Manages an uninterruptible power supply (UPS) connected to the computer.
      TYPE : 10 WIN32_OWN_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\System32\ups.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Uninterruptible Power Supply
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: UtilMan
      Starts and configures accessibility tools from one window
      TYPE : 110 WIN32_OWN_PROCESS INTERACTIVE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\System32\UtilMan.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Utility Manager
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: W32Time
      Sets the computer clock.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\System32\services.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Windows Time
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: WinMgmt
      Provides system management information.
      TYPE : 10 WIN32_OWN_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 0 IGNORE
      BINARY_PATH_NAME : C:\WINNT\System32\WBEM\WinMgmt.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Windows Management Instrumentation
      DEPENDENCIES : RPCSS
      SERVICE_START_NAME: LocalSystem
      FAIL_RESET_PERIOD : 86400 seconds
      FAILURE_ACTIONS : Restart DELAY: 60000 seconds
      : Restart DELAY: 60000 seconds

      SERVICE_NAME: WmdmPmSN
      Retrieves the serial number of any portable media player connected to this computer. If this service is stopped, protected content might not be down loaded to the device.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Portable Media Serial Number Service
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: Wmi
      Provides systems management information to and from drivers.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\Services.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Windows Management Instrumentation Driver Extensions
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: wuauserv
      Enables the download and installation of critical Windows updates. If the service is disabled, the operating system can be manually updated at the Windows Update Web site.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\system32\svchost.exe -k wugroup
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Automatic Updates
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: WZCSVC
      Provides authenticated network access control using IEEE 802.1x for wired and wireless Ethernet networks.
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 3 DEMAND_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\System32\svchost.exe -k netsvcs
      LOAD_ORDER_GROUP : TDI
      TAG : 0
      DISPLAY_NAME : Wireless Configuration
      DEPENDENCIES : RpcSs
      : Ndisuio
      : ProtectedStorage
      : WMI
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: ZESOFT
      ZESoft Driver
      TYPE : 10 WIN32_OWN_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 1 NORMAL
      BINARY_PATH_NAME : C:\WINNT\zeta.exe
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : ZESOFT
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem

      SERVICE_NAME: %AF夶À¨
      (null)
      TYPE : 20 WIN32_SHARE_PROCESS
      START_TYPE : 2 AUTO_START
      ERROR_CONTROL : 0 IGNORE
      BINARY_PATH_NAME : C:\WINNT\syshw.exe /s
      LOAD_ORDER_GROUP :
      TAG : 0
      DISPLAY_NAME : Network Security Service
      DEPENDENCIES :
      SERVICE_START_NAME: LocalSystem



      Hijack log:

      Logfile of HijackThis v1.99.0
      Scan saved at 18:19:59, on 2-1-2005
      Platform: Windows 2000 SP4 (WinNT 5.00.2195)
      MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

      Running processes:
      C:\WINNT\System32\smss.exe
      C:\WINNT\system32\winlogon.exe
      C:\WINNT\system32\services.exe
      C:\WINNT\system32\lsass.exe
      C:\WINNT\system32\svchost.exe
      C:\WINNT\system32\spoolsv.exe
      C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
      C:\WINNT\System32\svchost.exe
      C:\WINNT\System32\nvsvc32.exe
      C:\WINNT\system32\regsvc.exe
      C:\WINNT\system32\MSTask.exe
      C:\WINNT\system32\stisvc.exe
      C:\WINNT\System32\WBEM\WinMgmt.exe
      C:\WINNT\system32\svchost.exe
      C:\WINNT\syshw.exe
      C:\WINNT\Explorer.EXE
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      E:\dl\prog\quicktime\extracted\installatie\qttask.exe
      C:\Program Files\FSI\F-Prot\F-StopW.EXE
      C:\WINNT\system32\CTHELPER.EXE
      C:\WINNT\system32\sysfv32.exe
      C:\Program Files\MSN Messenger\msnmsgr.exe
      E:\dl\prog\winamp\Winamp3\Studio.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\WINNT\system32\mshta.exe
      E:\dl\prog\HijackThis 1.99\HijackThis 1.99.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\vyhwo.dll/sp.html#37680
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\vyhwo.dll/sp.html#37680
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\vyhwo.dll/sp.html#37680
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\vyhwo.dll/sp.html#37680
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\vyhwo.dll/sp.html#37680
      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\vyhwo.dll/sp.html#37680
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\vyhwo.dll/sp.html#37680
      R3 - Default URLSearchHook is missing
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - e:\dl\acrobat-reader\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: (no name) - {C9654F9B-5DA7-6848-264B-261DD286C5D1} - C:\WINNT\javabt.dll
      O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
      O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [QuickTime Task] "E:\dl\prog\quicktime\extracted\installatie\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
      O4 - HKLM\..\Run: [F-StopW] C:\Program Files\FSI\F-Prot\F-StopW.EXE
      O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
      O4 - HKLM\..\Run: [EPSON Stylus C62 Series (Copy 2)] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P32 "EPSON Stylus C62 Series (Copy 2)" /O5 "LPT1:" /M "Stylus C62"
      O4 - HKLM\..\Run: [EPSON Stylus C62 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C62 Series" /O5 "LPT1:" /M "Stylus C62"
      O4 - HKLM\..\Run: [sysfv32.exe] C:\WINNT\system32\sysfv32.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
      O15 - Trusted Zone: *.05p.com
      O15 - Trusted Zone: *.awmdabest.com
      O15 - Trusted Zone: *.blazefind.com
      O15 - Trusted Zone: *.clickspring.net
      O15 - Trusted Zone: *.flingstone.com
      O15 - Trusted Zone: *.frame.crazywinnings.com
      O15 - Trusted Zone: *.mt-download.com
      O15 - Trusted Zone: *.my-internet.info
      O15 - Trusted Zone: *.scoobidoo.com
      O15 - Trusted Zone: *.searchbarcash.com
      O15 - Trusted Zone: *.searchmiracle.com
      O15 - Trusted Zone: *.slotch.com
      O15 - Trusted Zone: *.static.topconverting.com
      O15 - Trusted Zone: *.05p.com (HKLM)
      O15 - Trusted Zone: *.awmdabest.com (HKLM)
      O15 - Trusted Zone: *.blazefind.com (HKLM)
      O15 - Trusted Zone: *.clickspring.net (HKLM)
      O15 - Trusted Zone: *.flingstone.com (HKLM)
      O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
      O15 - Trusted Zone: *.mt-download.com (HKLM)
      O15 - Trusted Zone: *.my-internet.info (HKLM)
      O15 - Trusted Zone: *.scoobidoo.com (HKLM)
      O15 - Trusted Zone: *.searchbarcash.com (HKLM)
      O15 - Trusted Zone: *.searchmiracle.com (HKLM)
      O15 - Trusted Zone: *.slotch.com (HKLM)
      O15 - Trusted Zone: *.static.topconverting.com (HKLM)
      O15 - Trusted IP range: 206.161.125.149
      O15 - Trusted IP range: 206.161.125.149 (HKLM)
      O16 - DPF: {018A066F-584A-422F-AC4C-0B1F5FE5C040} (VacPro.olanda_ver3) - http://advnt01.com/dialer/olanda_ver3.CAB
      O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/ClickYesToContinue/ie/bridge-c11.cab
      O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
      O16 - DPF: {771A1334-6B08-4A6B-AEDC-CF994BA2CEBE} (Installer Class) - http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cab
      O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
      O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.hostance.net/dialer/604444.exe
      O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4313/mcfscan.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{D3F0AF0F-5FFC-4084-B392-73B6206C2E41}: NameServer = 131.174.60.21,131.174.64.5
      O23 - Service: pcAnywhere Host Service - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
      O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
      O23 - Service: EPSON Printer Status Agent2 - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
      O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
      O23 - Service: ZESOFT - Unknown - C:\WINNT\zeta.exe
      O23 - Service: Network Security Service - Unknown - C:\WINNT\syshw.exe

      Comment


      • #4
        Indien nog niet gedaan, onderstaande tooltje moet je op uw pc hebben


        Discover the latest breaking news in the U.S. and around the world — politics, weather, entertainment, lifestyle, finance, sports and much more.





        1/
        copier deze post in een notepad bestand en sla het op als een txt file
        Verbreek de verbinding met indeternet
        en maak geen verbinding meer tot alles is uitgevoerd

        LEES ALLES EERST EENS DOOR alvorens te starten met de fix.


        2/
        verborgen bestanden weergeven :
        Open Deze computer
        Selecteer in de menubalk Extra en dan Mapopties.
        Selecteer de tab Weergave
        Bij Verborgen bestanden en mappen selecteer je Verborgen bestanden en mappen weergeven
        Bij Bestanden en mappen haal je het vinkje weg bij: Beveiligde besturingssysteembestanden verbergen (aanbevolen).
        Klik "yes" om te bevestigen
        Klik OK.



        3/
        ga naar Start
        dan uitvoeren
        in de box type je "services.msc" zonder de quotes
        en dan enter
        in de lijst die je nu krijgt ga je naar Network Security Service (NSS) en stop ("disable") dit

        Sluit alle vensters



        4/
        start terug op in veilige modus
        Start Windows, of, als Windows actief is, sluit Windows af en start opnieuw op.
        Druk op de toets F8 als u de zwart-witte balk ‘Windows wordt gestart’ onderaan het scherm ziet. Het opstartmenu van Windows 2000 verschijnt.
        Kies de Veilige modus die op uw situatie van toepassing is en druk op Enter



        5/
        Open taakbeheer en stop de onderstaande processes indien aanwezig :
        syshw.exe
        sysfv32.exe



        6/
        Scan opnieuw met hijackthis en vink onderstaande lijntjes aan :
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\vyhwo.dll/sp.html#37680
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\vyhwo.dll/sp.html#37680

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINNT\vyhwo.dll/sp.html#37680
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINNT\vyhwo.dll/sp.html#37680
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINNT\vyhwo.dll/sp.html#37680
        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\vyhwo.dll/sp.html#37680
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINNT\vyhwo.dll/sp.html#37680

        R3 - Default URLSearchHook is missing

        O2 - BHO: (no name) - {C9654F9B-5DA7-6848-264B-261DD286C5D1} - C:\WINNT\javabt.dll

        O4 - HKLM\..\Run: [sysfv32.exe] C:\WINNT\system32\sysfv32.exe

        O15 - Trusted Zone: *.05p.com
        O15 - Trusted Zone: *.awmdabest.com
        O15 - Trusted Zone: *.blazefind.com
        O15 - Trusted Zone: *.clickspring.net
        O15 - Trusted Zone: *.flingstone.com
        O15 - Trusted Zone: *.frame.crazywinnings.com
        O15 - Trusted Zone: *.mt-download.com
        O15 - Trusted Zone: *.my-internet.info
        O15 - Trusted Zone: *.scoobidoo.com
        O15 - Trusted Zone: *.searchbarcash.com
        O15 - Trusted Zone: *.searchmiracle.com
        O15 - Trusted Zone: *.slotch.com
        O15 - Trusted Zone: *.static.topconverting.com
        O15 - Trusted Zone: *.05p.com (HKLM)
        O15 - Trusted Zone: *.awmdabest.com (HKLM)
        O15 - Trusted Zone: *.blazefind.com (HKLM)
        O15 - Trusted Zone: *.clickspring.net (HKLM)
        O15 - Trusted Zone: *.flingstone.com (HKLM)
        O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
        O15 - Trusted Zone: *.mt-download.com (HKLM)
        O15 - Trusted Zone: *.my-internet.info (HKLM)
        O15 - Trusted Zone: *.scoobidoo.com (HKLM)
        O15 - Trusted Zone: *.searchbarcash.com (HKLM)
        O15 - Trusted Zone: *.searchmiracle.com (HKLM)
        O15 - Trusted Zone: *.slotch.com (HKLM)
        O15 - Trusted Zone: *.static.topconverting.com (HKLM)
        O15 - Trusted IP range: 206.161.125.149
        O15 - Trusted IP range: 206.161.125.149 (HKLM)

        O16 - DPF: {018A066F-584A-422F-AC4C-0B1F5FE5C040} (VacPro.olanda_ver3) - http://advnt01.com/dialer/olanda_ver3.CAB
        O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/C.../bridge-c11.cab
        O16 - DPF: {771A1334-6B08-4A6B-AEDC-CF994BA2CEBE} (Installer Class) - http://www.ysbweb.com/ist/softwares...ysb_regular.cab
        O16 - DPF: {DB893839-10F0-4AF9-92FA-B23528F530AF} - http://deposito.hostance.net/dialer/604444.exe

        O23 - Service: Network Security Service - Unknown - C:\WINNT\syshw.exe
        SLUIT ALLE VENSTER EN KLIK OP FIX


        7/
        verwijder de onderstaande bestanden uit de opgegeven locatie :

        C:\WINNT\vyhwo.dll
        C:\WINNT\javabt.dll
        C:\WINNT\system32\sysfv32.exe
        C:\WINNT\syshw.exe



        8/
        open windows verkenner
        in de adresbalk type je

        C:\documents and settings\GEBRUIKERSNAAM(voor alle users op de pc)\local settings\temp\
        en verwijder je alles uit de temp folder , niet de folder zelf

        C:\Window\Temp\
        en verwijder je alles uit de temp folder , niet de folder zelf

        sneller kan ook gewoon in de adresbalk %temp% typen en alles verwijderen.


        9/
        aangezien we nog steeds in veilige modus zitten
        ga je nu naar de folder van de downloads waar je AboutBuster plaatste

        klik nu op de AboutBuster.exe
        laat het zijn werk doen en sla dan het verslagje op dat het maakte in een text file


        10/
        Doe nu een scan met ad-aware
        zoals hier staat



        11/
        nu ga je naar de hoster die je downloade
        je mag hoster.zip uitpakken
        klik op "Restore Original Hosts" en dan op "OK".
        verlaat het progie


        12/
        ga naar de system32 folder en zoek de shell.dll file
        Indien niet aanwezig ga naar System32\dllcache zoek het daar (shell.dll)
        en copie/past het naar de system32 folder



        13/
        reboot in normale modus
        ga terug online en doe een online scan met :




        14/
        uitschakelen system restore: http://www.pchell.com/virus/systemrestore.shtml
        Reboot
        inschakelen system restore.


        15/
        een vers hijackthis-logje plaatsen om nog wat overblijfsels op te kuisen
        en ook het aboutbuster-logje ,en niet heropstarten na het plaatsen v/d logjes!!!

        je zal zien dat er wat lijntjes terug komen in de R1 en de O15 die zullen we dan later aanpakken, dus doe er zelf niets aan aub, ik zou willen zien welke terugkomen (meestal toch in onschadelijke vorm)
        Last edited by Helpless; 02-01-05, 19:42.
        not so Helpless ...

        Comment


        • #5
          Er deden zich enkele problemen voor. Vanaf het moment dat ik weer online moest. Ik kon in de veilige modus mijn internet connectie niet meer in de lucht krijgen. Ik heb toen ge-reboot en mijn internetconnectie hersteld (in normale modus). Eenmaal in de lucht kon ik mijn system restore niet uitschakelen. Dit aangezien ik w2k gebruik en de uitleg enkel over Win ME en XP gaat (heb wel geprobeerd maar ik krijg niet hetgeen in beeld dat daar wordt omschreven). Ik ben wel ingelogd als admin.

          Ik heb wel een Hijack log en aboutbuster gedraaid:

          Scanned at: 0:29:05 on: 3-1-2005


          -- Scan 1 ---------------------------
          About:Buster Version 4.0
          Reference List : 19

          No ADS found on system
          Attempted Clean Of Temp folder.
          Pages Reset... Done!

          -- Scan 2 ---------------------------
          About:Buster Version 4.0
          Reference List : 19

          No ADS found on system
          Attempted Clean Of Temp folder.
          Pages Reset... Done!



          Logfile of HijackThis v1.99.0
          Scan saved at 0:27:24, on 3-1-2005
          Platform: Windows 2000 SP4 (WinNT 5.00.2195)
          MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

          Running processes:
          C:\WINNT\System32\smss.exe
          C:\WINNT\system32\winlogon.exe
          C:\WINNT\system32\services.exe
          C:\WINNT\system32\lsass.exe
          C:\WINNT\system32\svchost.exe
          C:\WINNT\system32\spoolsv.exe
          C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
          C:\WINNT\System32\svchost.exe
          C:\WINNT\System32\nvsvc32.exe
          C:\WINNT\system32\regsvc.exe
          C:\WINNT\system32\MSTask.exe
          C:\WINNT\system32\stisvc.exe
          C:\WINNT\System32\WBEM\WinMgmt.exe
          C:\WINNT\system32\svchost.exe
          C:\WINNT\Explorer.EXE
          C:\Program Files\Common Files\Real\Update_OB\realsched.exe
          E:\dl\prog\quicktime\extracted\installatie\qttask.exe
          C:\Program Files\FSI\F-Prot\F-StopW.EXE
          C:\WINNT\system32\CTHELPER.EXE
          C:\WINNT\system32\NOTEPAD.EXE
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\WINNT\system32\rundll32.exe
          C:\WINNT\hh.exe
          E:\dl\prog\HijackThis 1.99\HijackThis 1.99.exe

          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - e:\dl\acrobat-reader\Reader\ActiveX\AcroIEHelper.ocx
          O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
          O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [QuickTime Task] "E:\dl\prog\quicktime\extracted\installatie\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
          O4 - HKLM\..\Run: [F-StopW] C:\Program Files\FSI\F-Prot\F-StopW.EXE
          O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
          O4 - HKLM\..\Run: [EPSON Stylus C62 Series (Copy 2)] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P32 "EPSON Stylus C62 Series (Copy 2)" /O5 "LPT1:" /M "Stylus C62"
          O4 - HKLM\..\Run: [EPSON Stylus C62 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C62 Series" /O5 "LPT1:" /M "Stylus C62"
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
          O15 - Trusted Zone: *.frame.crazywinnings.com
          O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
          O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
          O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
          O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4313/mcfscan.cab
          O17 - HKLM\System\CCS\Services\Tcpip\..\{D3F0AF0F-5FFC-4084-B392-73B6206C2E41}: NameServer = 131.174.60.21,131.174.64.5
          O23 - Service: pcAnywhere Host Service - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
          O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
          O23 - Service: EPSON Printer Status Agent2 - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
          O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
          O23 - Service: ZESOFT - Unknown - C:\WINNT\zeta.exe (file missing)

          Comment


          • #6
            sorry , geen system restore in w2k, force of habbit.

            deze 2 nog eens fixen met hijackthis
            O15 - Trusted Zone: *.frame.crazywinnings.com
            O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)

            je log ziet er goed uit , nu nog enkele dagen afwachten het zou immers zo moeten blijven , maar het kan nog steeds terugkomen.

            lees dit , en plaats zeker spywareblaster op uw pc
            alsook ad-aware regelmatig gebruiken samen met spybot s&d is een must
            not so Helpless ...

            Comment


            • #7
              ik zie de volgende items nog in mijn programmalijst staan:

              - search relevancy
              - shopathomeselect agent

              Ik heb mijn pc inmiddels behangen met (o.a.) de volgende antispyware software

              - spyblaster
              - spyguard
              - spysweeper

              Maargoed, mijn vraag is wat ik met die resterende programmaitems moet doen. Hier zijn mijn logs:

              Logfile of HijackThis v1.99.0
              Scan saved at 16:23:10, on 11-1-2005
              Platform: Windows 2000 SP4 (WinNT 5.00.2195)
              MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

              Running processes:
              C:\WINNT\System32\smss.exe
              C:\WINNT\system32\winlogon.exe
              C:\WINNT\system32\services.exe
              C:\WINNT\system32\lsass.exe
              C:\WINNT\system32\svchost.exe
              C:\WINNT\system32\spoolsv.exe
              C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
              C:\WINNT\System32\svchost.exe
              C:\WINNT\System32\nvsvc32.exe
              C:\WINNT\system32\regsvc.exe
              C:\WINNT\system32\MSTask.exe
              C:\WINNT\system32\stisvc.exe
              C:\WINNT\System32\WBEM\WinMgmt.exe
              C:\WINNT\system32\svchost.exe
              C:\WINNT\Explorer.EXE
              C:\Program Files\Common Files\Real\Update_OB\realsched.exe
              E:\dl\prog\quicktime\extracted\installatie\qttask.exe
              C:\Program Files\FSI\F-Prot\F-StopW.EXE
              C:\WINNT\system32\CTHELPER.EXE
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\Program Files\DeskAd Service\DeskAdServ.exe
              C:\Program Files\DeskAd Service\DeskAdKeep.exe
              C:\temp\salm.exe
              C:\WINNT\system32\SahAgent.exe
              C:\Program Files\MSN Messenger\msnmsgr.exe
              E:\dl\prog\Spyguard\SpywareGuard\sgmain.exe
              E:\dl\prog\Spyguard\SpywareGuard\sgbhp.exe
              E:\dl\prog\winamp\Winamp3\Studio.exe
              E:\dl\prog\Kazaa Lite K++\Kazaa Lite K++\KazaaLite.kpp
              C:\WINNT\system32\mshta.exe
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              E:\dl\prog\HijackThis 1.99\HijackThis 1.99.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - e:\dl\acrobat-reader\Reader\ActiveX\AcroIEHelper.ocx
              O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - E:\dl\prog\Spyguard\SpywareGuard\dlprotect.dll
              O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
              O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [QuickTime Task] "E:\dl\prog\quicktime\extracted\installatie\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
              O4 - HKLM\..\Run: [F-StopW] C:\Program Files\FSI\F-Prot\F-StopW.EXE
              O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
              O4 - HKLM\..\Run: [EPSON Stylus C62 Series (Copy 2)] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P32 "EPSON Stylus C62 Series (Copy 2)" /O5 "LPT1:" /M "Stylus C62"
              O4 - HKLM\..\Run: [EPSON Stylus C62 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C62 Series" /O5 "LPT1:" /M "Stylus C62"
              O4 - HKLM\..\Run: [DeskAd Service] C:\Program Files\DeskAd Service\DeskAdServ.exe
              O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
              O4 - HKLM\..\Run: [dodmlsh] C:\WINNT\dodmlsh.exe
              O4 - HKLM\..\Run: [SAHAgent] C:\WINNT\system32\SahAgent.exe
              O4 - Startup: SpywareGuard.lnk = E:\dl\prog\Spyguard\SpywareGuard\sgmain.exe
              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
              O15 - Trusted Zone: *.frame.crazywinnings.com
              O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
              O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/CDTInc/ie/bridge-c18.cab
              O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
              O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
              O16 - DPF: {8731163E-77B9-4F91-9122-F112521C28AF} (MMSPlayerX Class) - http://212.41.157.233:8080/mmawap/jsp/composer/player/mmsPlayer.cab
              O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4313/mcfscan.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{D3F0AF0F-5FFC-4084-B392-73B6206C2E41}: NameServer = 131.174.60.21,131.174.64.5
              O23 - Service: pcAnywhere Host Service - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
              O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
              O23 - Service: EPSON Printer Status Agent2 - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
              O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe



              Scanned at: 16:26:28 on: 11-1-2005


              -- Scan 1 ---------------------------
              About:Buster Version 4.0
              Reference List : 19

              No ADS found on system
              Attempted Clean Of Temp folder.
              Pages Reset... Done!

              -- Scan 2 ---------------------------
              About:Buster Version 4.0
              Reference List : 19

              No ADS found on system
              Attempted Clean Of Temp folder.
              Pages Reset... Done!

              Comment


              • #8
                1/
                Open taakbeheer en stop de onderstaande processes indien aanwezig :

                DeskAdServ.exe
                salm.exe
                dodmlsh.exe
                SahAgent.exe



                2/
                via add/remove optie kan je de onderstaande verwijderen
                - search relevancy
                - shopathomeselect agent


                3/
                Scan opnieuw met hijackthis en vink onderstaande lijntjes aan :
                O4 - HKLM\..\Run: [DeskAd Service] C:\Program Files\DeskAd Service\DeskAdServ.exe
                O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
                O4 - HKLM\..\Run: [dodmlsh] C:\WINNT\dodmlsh.exe
                O4 - HKLM\..\Run: [SAHAgent] C:\WINNT\system32\SahAgent.exe
                O15 - Trusted Zone: *.frame.crazywinnings.com
                O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
                O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/C.../bridge-c18.cab
                SLUIT ALLE VENSTER EN KLIK OP FIX


                4/
                verborgen bestanden weergeven en in veilige modus opstarten.



                5/
                verwijder de onderstaande bestanden uit de opgegeven locatie :
                C:\Program Files\DeskAd Service\
                c:\temp\salm.exe
                C:\WINNT\dodmlsh.exe
                C:\WINNT\system32\SahAgent.exe


                6/
                post een vers logje
                not so Helpless ...

                Comment


                • #9
                  Ging niet helemaal in orde.

                  Stap 1:

                  Staat nu een proces SAgent2.exe tussen.


                  Stap 2:
                  het un-installen van de genoemde programma´s was geen makkie. Je komt in allerlei uninstall wizards van die programma´s terecht die op alle mogelijk manieren ervoor proberen te zorgen dat je de zooi niet uninstalld (vragen als: "wil je discontinue yes or no" en "uninstallen heeft waarschijnlijk consequenties voor het goed functioneren van je systeem, wil je dit wel?" e.d. Ook moet je je internetconnectie open laten staan bij het uninstallen maar die heb ik daarop juist afgesloten.

                  Ook hier blijven nog programma´s achter zoals
                  - uninstall180search assistent
                  - shopathomeselect agent


                  stap 5:

                  Hier kom ik in diverse mappen nog andere files tegen waarvan ik zeker weet dat ze er niet horen . Ik heb ze echter laten staan uit angst schade aan te richten.

                  Hier is mijn nieuwe hijack log:

                  Logfile of HijackThis v1.99.0
                  Scan saved at 22:35:28, on 11-1-2005
                  Platform: Windows 2000 SP4 (WinNT 5.00.2195)
                  MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

                  Running processes:
                  C:\WINNT\System32\smss.exe
                  C:\WINNT\system32\winlogon.exe
                  C:\WINNT\system32\services.exe
                  C:\WINNT\system32\lsass.exe
                  C:\WINNT\system32\svchost.exe
                  C:\WINNT\system32\spoolsv.exe
                  C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
                  C:\WINNT\System32\svchost.exe
                  C:\WINNT\System32\nvsvc32.exe
                  C:\WINNT\system32\regsvc.exe
                  C:\WINNT\system32\MSTask.exe
                  C:\WINNT\system32\stisvc.exe
                  C:\WINNT\System32\WBEM\WinMgmt.exe
                  C:\WINNT\system32\svchost.exe
                  C:\WINNT\Explorer.EXE
                  C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                  E:\dl\prog\quicktime\extracted\installatie\qttask.exe
                  C:\Program Files\FSI\F-Prot\F-StopW.EXE
                  C:\WINNT\system32\CTHELPER.EXE
                  E:\dl\prog\Spyguard\SpywareGuard\sgmain.exe
                  E:\dl\prog\Spyguard\SpywareGuard\sgbhp.exe
                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                  E:\dl\prog\HijackThis 1.99\HijackThis 1.99.exe
                  C:\WINNT\notepad.exe
                  C:\WINNT\system32\mshta.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
                  O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - e:\dl\acrobat-reader\Reader\ActiveX\AcroIEHelper.ocx
                  O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - E:\dl\prog\Spyguard\SpywareGuard\dlprotect.dll
                  O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
                  O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe
                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [QuickTime Task] "E:\dl\prog\quicktime\extracted\installatie\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
                  O4 - HKLM\..\Run: [F-StopW] C:\Program Files\FSI\F-Prot\F-StopW.EXE
                  O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
                  O4 - HKLM\..\Run: [EPSON Stylus C62 Series (Copy 2)] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P32 "EPSON Stylus C62 Series (Copy 2)" /O5 "LPT1:" /M "Stylus C62"
                  O4 - HKLM\..\Run: [EPSON Stylus C62 Series] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C62 Series" /O5 "LPT1:" /M "Stylus C62"
                  O4 - Startup: SpywareGuard.lnk = E:\dl\prog\Spyguard\SpywareGuard\sgmain.exe
                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                  O15 - Trusted Zone: *.frame.crazywinnings.com
                  O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
                  O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
                  O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
                  O16 - DPF: {8731163E-77B9-4F91-9122-F112521C28AF} (MMSPlayerX Class) - http://212.41.157.233:8080/mmawap/jsp/composer/player/mmsPlayer.cab
                  O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/1,5,0,4313/mcfscan.cab
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{D3F0AF0F-5FFC-4084-B392-73B6206C2E41}: NameServer = 131.174.60.21,131.174.64.5
                  O23 - Service: pcAnywhere Host Service - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
                  O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
                  O23 - Service: EPSON Printer Status Agent2 - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
                  O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe

                  Comment


                  • #10
                    SAgent2.exe is ok dat is voor uw printer

                    beide folders kan je manueel verwijderen , ze lijken niet meer gelink met uw register
                    - uninstall180search assistent
                    - shopathomeselect agent

                    Logje lijkt goed , heb je nog popups ?
                    not so Helpless ...

                    Comment


                    • #11
                      nee, geen popups. veel dank voor uw wijze raad

                      Comment


                      • #12
                        het meeste heb je al , dus pure info --> preventie
                        not so Helpless ...

                        Comment


                        • #13
                          O15 - Trusted Zone: *.frame.crazywinnings.com
                          O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)

                          Deze blijven toch maar terugkomen he..niet erg?!

                          ShopathomeSelect agent krijg ik niet uit mijn prog lijst. hij geeft een melding "uninstall happens after reboot". Na een reboot staat hij er echter nog.. Is dit erg?!

                          Mijn dank is groot

                          Comment


                          • #14
                            die O15 heb ik gewoon overzien , best dat je terugkomt.

                            deze effe downloaden http://www.mvps.org/winhelp2002/DelDomains.inf
                            rechtermuisknop-klik er op en kies voor INSTALL
                            Last edited by Helpless; 12-01-05, 10:53.
                            not so Helpless ...

                            Comment

                            Sorry, you are not authorized to view this page
                            Working...
                            X
                            😀
                            🥰
                            🤢
                            😎
                            😡
                            👍
                            👎