bramiebramie
wzl-lid
Sinds 21/10/2004
T: 4
R: 6
|
21/10/2004 -
19:58u
| Quote
|
Aangezien ik nogal wat last heb van pop-up,... heb ik zowel ad-aware, spybot, northon hun werk laten doen ==>alle adware, spyware, virussen,... laten verwijderen. Zonder resultaat Laatste oplossing: hijackthis, maar wat mag ik verwijderen???
Logfile of HijackThis v1.98.2 Scan saved at 20:17:28, on 21/10/2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe C:\WINDOWS\System32\ec27ser.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\htpatch.exe C:\Program Files\Winamp\winampa.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\QuickTime\qttask.exe C:\Program Files\Messenger Plus! 3\MsgPlus.exe C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe C:\WINDOWS\Twain_32\FlatBed\HotKey.exe C:\WINDOWS\Dit.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\WINDOWS\DitExp.exe C:\WINDOWS\System32\mstar2.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\MD40323\ICON.EXE c:\progra~1\intern~1\iexplore.exe C:\Program Files\SmartDisk\FlashPath for SD Memory Card\FPSDstat.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\SmartDisk\FlashPath\sdstat.exe C:\Documents and Settings\Bram87\Bureaublad\MyWebSearch\bar\2.bin\MWSOEMON.EXE C:\Program Files\Microsoft Office\Office\OSA.EXE C:\Program Files\Siemens\SANTIS WLAN\WlanMonitor.exe C:\Program Files\AIM Productions\Sticky Notes\RoMemo.exe C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\ativopen.exe C:\Program Files\Internet Explorer\iexplore.exe C:\PROGRA~1\WINZIP\winzip32.exe C:\Documents and Settings\Bram87\Local Settings\Temp\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.aojkihrdphvkd.uk/ZwvDRN_avhCCf0ikX3ZRu3yIKTKolLVc50ItCNGgA2YLzKf3yoomAMDLyd26w1Lb.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file //C Program%20Files/MStartEnter/Portal/portal.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Startpagina = file //C Program%20Files/MStartEnter/Portal/portal.html O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe O4 - HKLM\..\Run: [zzzHPSETUP] G:\Setup.exe O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe O4 - HKLM\..\Run: [VOBRegCheck] C:\WINDOWS\System32\VOBREGCheck.exe -CheckReg O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [Runner] C:\WINDOWS\csrss.exe /i O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [PCMService] C:\Program Files\Medion Home CinemaXL\PowerCinema\PCMService.exe O4 - HKLM\..\Run: [optionsect32test] C:\Documents and Settings\All Users\Application Data\bird name option sect\once ping.exe O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [lkvoh] C:\WINDOWS\lkvoh.exe O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe O4 - HKLM\..\Run: [HotKey] C:\WINDOWS\Twain_32\FlatBed\HotKey.exe O4 - HKLM\..\Run: [fij] C:\WINDOWS\fij.exe O4 - HKLM\..\Run: [Dit] Dit.exe O4 - HKLM\..\Run: [dgb] C:\WINDOWS\dgb.exe O4 - HKLM\..\Run: [ativopen] C:\WINDOWS\system32\ativopen.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe O4 - HKLM\..\Run: [safebrowseboltbits] C:\Documents and Settings\All Users\Application Data\ShimFileSafeBrowse\HELPEACH.exe O4 - HKLM\..\Run: [Classes] C:\WINDOWS\System32\mstar2.exe O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart O4 - HKCU\..\Run: [default army] C:\DOCUME~1\Bram87\APPLIC~1\WAVEBO~1\bits 4 intra.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: 2Mega Camera Manager Monitor.lnk = ? O4 - Global Startup: FlashPath for SD Memory Card Status.lnk = C:\Program Files\SmartDisk\FlashPath for SD Memory Card\FPSDstat.exe O4 - Global Startup: FlashPath Monitor.lnk = C:\Program Files\SmartDisk\FlashPath\sdstat.exe O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Documents and Settings\Bram87\Bureaublad\MyWebSearch\bar\2.bin\MWSOEMON.EXE O4 - Global Startup: Office Opstarten.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE O4 - Global Startup: SANTIS USB and PC Card Utility.lnk = C:\Program Files\Siemens\SANTIS WLAN\WlanMonitor.exe O4 - Global Startup: Sticky Notes.lnk = C:\Program Files\AIM Productions\Sticky Notes\RoMemo.exe O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe O4 - Global Startup: updater.lnk = C:\Program Files\Common Files\updater\wupdater.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O10 - Broken Internet access because of LSP provider 'osmim.dll' missing O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
|
bramiebramie
wzl-lid
Sinds 21/10/2004
T:4 -
R:6
|
21/10/2004 -
20:08u
| Quote
|
Als er nog iemand een gmail-invite heeft mag die verzonden worden naar bram_naudts23@hotmail.com wanhopig opzoek naar een invite.
Laatst aangepast door
bramiebramie
op 21/10/2004 20:15:20u
(1x aangepast)
|
Husky
wzl-lid
Sinds 24/5/2004
T:7 -
R:30
|
21/10/2004 -
20:20u
| Quote
|
Hey Bram²
Ik weet er niet zo veel van, maar er staan wel een aantal verdachte dingen tussen.. Scan nog eens met Hijackthis -> save log -> en post die log dan hier pcpitstop (registreren is wel nodig)
Lees zeker de 'important topics' en let goed op dat je enkel wordt geholpen door een expert.
Voor de gmail-acounts is er een andere post
|
Blackov
wzl-lid
Sinds 24/9/2004
T:26 -
R:741
|
21/10/2004 -
20:23u
| Quote
|
wa ge ook gewoon kunt doen is de 'running processes' die ge ni echt vertrouwd (of vertrouwt??) gewoon es in type bij google, en dan (meestal) de eerste site aan klikke en die geeft aan (as ge geluk hebt) da et nx is 
vb -> google -> smss.exe -> Process File: smss or smss.exe Process Name: Session Manager Subsystem Description: smss.exe is a process which is a part of the Microsoft Windows Operating System. It is called the Session Manager SubSystem and is responsible for handling sessions on your system. This program is important for the stable and secure running of your computer and should not be terminated.
Author: Microsoft Corp. Part Of: Microsoft Windows Operating System
System Process: Yes Background Process: Yes Uses Network: No Hardware Related: No Common Errors: N/A Security Risk (0-5): 0 Virus: No Spyware: No
ik hoop da ge nu wa verder geraakt
Laatst aangepast door
Blackov
op 21/10/2004 20:24:23u
(1x aangepast)
|