Na Adaware 6 clean werkt internet niet meer.

Pagina: 1
Acties:

  • MrDummy
  • Registratie: April 2000
  • Laatst online: 25-07-2025

MrDummy

Nog steeds gek op anime...

Topicstarter
Bij collega heb ik adaware 6 (.181) laten uitvoeren, omdat er veel spyware is gevonden die voor popups zorgen.

Na eerste scan zijn er 531 stuks gevonden. Ze zijn allemaal weggehaald (volgens standaard keuze, dus alles aangevinkt) Backups zijn wel gemaakt.

Na booten scan ik nog een keer, 6 gevonden, maar eigenlijk niet veel. Toch weggehaald, en ook backup.

Internet werkt niet meer goed.
DCHP ip aanvragen wil niet meer. DNS werkt niet, ondanks handmatig intikken. Wel werkt netwerk zelf wel (intern pingen ok)
Extern pingen ook goed, maar alleen naar ipadres. Domeinnamen werken niet.

Ik merk dat bij opstarten een NT service error is: er wordt geprobeerd mpservice.exe (v4.4.0.0) te laden. Dat is niet eerder zo.

Hoe kan ik eenvoudig fixen? DCHP en DNS moeten weer werken. Dat zijn enige probleempunten.
Systeem: AMD 3000+, Windows XP NL met servicepack.

Hier de lijst 1e scan:
ArchiveData(rommel1.bckp)
======================================================

REMANENTBHO
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[6]=RegKey : AppID\BookedSpace.DLL
obj[11]=RegKey : BookedSpace.Extension
obj[346]=RegKey : SOFTWARE\BookedSpace

NETWORKESSENTIALS
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[7]=RegKey : AppID\{C81CFF28-6DF1-402F-B78C-D9493EF59882}
obj[42]=RegKey : CLSID\{D5C778F1-CF13-4E70-ADF0-45A953E7CB8B}
obj[45]=RegKey : CLSID\{E79061BA-B6E7-4A9D-A07C-C3CB561013B4}
obj[48]=RegKey : HP.Hopper
obj[49]=RegKey : HP.Hopper.1
obj[64]=RegKey : Interface\{1423903E-86CC-4470-8AB0-257C10D77D45}
obj[69]=RegKey : Interface\{4DEA7CA1-3372-4204-937C-2DD4A6ED6562}
obj[76]=RegKey : Interface\{A42DC659-33B5-409E-A433-650AC42ECCA4}
obj[77]=RegKey : Interface\{A8516F49-8046-4295-8EE9-C59D5041C9E2}
obj[83]=RegKey : Interface\{FB82CCD5-174B-4379-BC37-72D9B5ADAEDA}
obj[110]=RegKey : Software\DownloadWare
obj[113]=RegKey : Software\Hopper
obj[132]=RegKey : SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D5C778F1-CF13-4E70-ADF0-45A953E7CB8B}
obj[139]=RegKey : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Network Essentials
obj[150]=RegKey : Software\WebInstall
obj[153]=RegKey : SP.SmartPops
obj[154]=RegKey : SP.SmartPops.1
obj[161]=RegKey : TypeLib\{47350D97-09E9-4590-864E-3431DA53BF37}
obj[177]=RegKey : TypeLib\{FA777197-4BF7-4AA9-A088-A0D803198DE0}
obj[345]=Folder : c:\program files\Network Essentials

COMMONNAME
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[8]=RegKey : BabeIE.AgentIE
obj[9]=RegKey : BabeIE.AgentIE.1
obj[29]=RegKey : CLSID\{2EB3EFF2-F707-4EA8-81AA-4B65D2799F31}
obj[33]=RegKey : CLSID\{6656b666-992f-4d74-8588-8ca69e97d90c}
obj[36]=RegKey : CLSID\{9346A6BB-1ED0-4174-AFB4-13CD4EC0AA40}
obj[74]=RegKey : Interface\{99908473-1135-4009-BE4F-32B921F86ED9}
obj[94]=RegKey : Software\CLASSES\AppID\winnet.EXE
obj[95]=RegKey : Software\CLASSES\AppID\{118A2BFA-5AC7-4D29-BEB9-D68F4D2CCCAB}
obj[96]=RegKey : Software\CLASSES\BabeIE.Handler
obj[97]=RegKey : Software\CLASSES\BabeIE.Handler.1
obj[98]=RegKey : Software\CLASSES\BabeIE.Helper
obj[99]=RegKey : Software\CLASSES\BabeIE.Helper.1
obj[100]=RegKey : Software\CLASSES\Interface\{2D0F5208-3198-49A4-86A7-D65E9E582751}
obj[101]=RegKey : Software\CLASSES\Interface\{8ADBBE3E-1841-4708-85DF-727CCEE6220B}
obj[102]=RegKey : Software\CLASSES\PROTOCOLS\Handler\cn
obj[103]=RegKey : Software\CLASSES\Winnet.Update
obj[104]=RegKey : Software\CLASSES\Winnet.Update.1
obj[106]=RegKey : Software\CommonName
obj[115]=RegKey : Software\Microsoft\Internet Explorer\AdvancedOptions\CommonName
obj[120]=RegKey : Software\Microsoft\Internet Explorer\MenuExt\Add A Page Note
obj[121]=RegKey : Software\Microsoft\Internet Explorer\MenuExt\Bookmark This Page
obj[123]=RegKey : Software\Microsoft\Internet Explorer\MenuExt\Email This Link
obj[124]=RegKey : Software\Microsoft\Internet Explorer\MenuExt\Search using CommonName
obj[134]=RegKey : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CommonName
obj[171]=RegKey : TypeLib\{CC364A32-D59B-4E9C-9156-F0050C45005B}
obj[174]=RegKey : TypeLib\{D879D743-E2CC-4161-8034-2234203681C9}
obj[189]=RegKey : Winnet.Update
obj[190]=RegKey : Winnet.Update.1
obj[222]=RegKey : CLSID\{00000000-0000-0000-0000-000000000000}
obj[223]=RegKey : BabeIE.Handler
obj[224]=RegKey : BabeIE.Handler.1
obj[225]=RegKey : BabeIE.Helper
obj[226]=RegKey : BabeIE.Helper.1
obj[233]=RegKey : PROTOCOLS\Handler\cn
obj[347]=Folder : c:\program files\CommonName

VX2.BETTERINTERNET
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[10]=RegKey : bidll.bidllobj.1
obj[12]=RegKey : CLSID\{000006b1-19b5-414a-849f-2a3c64ae6939}
obj[43]=RegKey : CLSID\{DDFFA75A-E81D-4454-89FC-B9FD0631E726}
obj[44]=RegKey : CLSID\{DDFFA75A-E81D-4454-89FC-B9FD0631E726}\InprocServer32
obj[205]=RegValue : SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
obj[279]=File : c:\windows\system32\msg{ba3dac41-caa5-414a-b5fb-9fcfb6a95b01}0110.dll
obj[348]=RegKey : Software\Dbi
obj[349]=RegKey : Software\Microsoft\Windows\CurrentVersion\Uninstall\Dbi
obj[350]=File : c:\docume~1\sky\locals~1\temp\bi.cab
obj[351]=File : c:\docume~1\sky\locals~1\temp\bi.dll
obj[352]=File : c:\docume~1\sky\locals~1\temp\bi.inf
obj[353]=File : c:\docume~1\sky\locals~1\temp\biprep.exe
obj[354]=File : c:\docume~1\sky\locals~1\temp\bw.exe
obj[355]=File : c:\windows\bi.dll
obj[356]=File : c:\windows\biprep.exe
obj[357]=File : c:\windows\inf\bi.inf

LYCOS SIDESEARCH
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[13]=RegKey : CLSID\{00000762-3965-4A1A-98CE-3D4BF457D4C8}
obj[114]=RegKey : SOFTWARE\Lycos\Sidesearch
obj[116]=RegKey : SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{000007AB-7059-463E-BD44-101A1750D732}
obj[117]=RegKey : SOFTWARE\Microsoft\Internet Explorer\Extensions\{000007C6-17DF-4438-92A4-DE5537471BA3}
obj[358]=Folder : c:\program files\lycos\Sidesearch
obj[359]=File : c:\program files\lycos\sidesearch\offline.htm
obj[360]=File : c:\program files\lycos\sidesearch\sidesearch1311.dll
obj[361]=File : c:\program files\lycos\sidesearch\temp
obj[362]=File : c:\program files\lycos\sidesearch\uninst.exe

TOPPICKS
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[14]=RegKey : CLSID\{00000EF1-0786-4633-87C6-1AA7A44296DA}
obj[18]=RegKey : CLSID\{0352960F-47BE-11D5-AB93-00D0B760B4EB}
obj[27]=RegKey : CLSID\{1717A4A5-D63A-4F70-B373-AE4AA46D1236}
obj[32]=RegKey : CLSID\{5C40012E-44CA-11D7-8411-0002A5F9D08E}
obj[34]=RegKey : CLSID\{80e81a0e-9741-4fbc-8ee3-3b78c04ada1d}
obj[39]=RegKey : CLSID\{c6958acd-d866-4349-9f7b-fdb73384f697}
obj[41]=RegKey : CLSID\{CBDB0279-9D76-48AC-ABD3-8CB9A4D73D4A}
obj[50]=RegKey : HtCheck2.CheckPage
obj[51]=RegKey : HtCheck2.CheckPage.1
obj[52]=RegKey : HtCheck2.CHelpObj
obj[53]=RegKey : HtCheck2.CHelpObj.1
obj[54]=RegKey : htchecksvr.scanpage
obj[55]=RegKey : htchecksvr.scanpage.1
obj[56]=RegKey : IdiumUpdater.IdiumSysUpdater
obj[57]=RegKey : IdiumUpdater.IdiumSysUpdater.1
obj[71]=RegKey : Interface\{5C40012D-44CA-11D7-8411-0002A5F9D08E}
obj[72]=RegKey : Interface\{5C40012F-44CA-11D7-8411-0002A5F9D08E}
obj[78]=RegKey : Interface\{C809EE32-C648-459B-9A99-5CB20F61DCFC}
obj[80]=RegKey : Interface\{DAE6416E-491D-11D5-AB93-00D0B760B4EB}
obj[81]=RegKey : Interface\{EB29CD69-7020-4D1D-A0BE-72130DFBA9F7}
obj[126]=RegKey : SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0352960F-47BE-11D5-AB93-00D0B760B4EB}
obj[147]=RegKey : Software\ToPicks
obj[156]=RegKey : topicks.topicksbar
obj[157]=RegKey : topicks.topicksbar.1
obj[158]=RegKey : ToPicksReg.ToPickReg1
obj[159]=RegKey : ToPicksReg.ToPickReg1.1
obj[162]=RegKey : TypeLib\{49D25A3F-28EF-4F38-BF7F-BC5FE6D39FA7}
obj[164]=RegKey : TypeLib\{5C400120-44CA-11D7-8411-0002A5F9D08E}
obj[168]=RegKey : TYPELIB\{9a7cfeda-5911-4ef1-b49a-35c34230ffc1}
obj[173]=RegKey : TYPELIB\{d6be4255-97c9-4d5c-9801-91dadda92d81}
obj[175]=RegKey : TypeLib\{DAE64161-491D-11D5-AB93-00D0B760B4EB}
obj[227]=RegValue : Software\Microsoft\Windows\CurrentVersion\Run
obj[280]=Folder : c:\program files\ToPicks
obj[281]=Folder : c:\docume~1\sky\locals~1\temp\IdSeUpdate
obj[282]=File : c:\program files\topicks\bin
obj[283]=File : c:\program files\topicks\graphic
obj[284]=File : c:\program files\topicks\icons.exe

SCBAR
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[15]=RegKey : CLSID\{00041A26-7033-432C-94C7-6371DE343822}
obj[31]=RegKey : CLSID\{49de8655-4d15-4536-b67c-2aa6c1106740}
obj[37]=RegKey : CLSID\{9368d063-44be-49b9-bd14-bb9663fd38fc}
obj[65]=RegKey : Interface\{1EB48AA7-D3FE-4E4C-AC8E-B01594496AC0}
obj[66]=RegKey : Interface\{42BD9965-303D-4CFB-AAE0-DCADCB791A55}
obj[82]=RegKey : Interface\{F5F0A448-2BCD-459E-8743-C39154EE1CA8}
obj[169]=RegKey : TYPELIB\{a8f92c35-530b-4907-922c-ce31d4b6b14a}
obj[179]=RegKey : webcom.webbho
obj[180]=RegKey : webcom.webbho.1
obj[181]=RegKey : webcom.webcommand
obj[182]=RegKey : webcom.webcommand.1
obj[183]=RegKey : webcom.websearch
obj[184]=RegKey : webcom.websearch.1
obj[363]=RegValue : SOFTWARE\Microsoft\Windows\CurrentVersion\Run
obj[364]=Folder : c:\program files\scbar
obj[365]=File : c:\program files\scbar\data
obj[366]=File : c:\program files\scbar\v2

MYSEARCH
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[16]=RegKey : CLSID\{014DA6C9-189F-421a-88CD-07CFE51CFF10}
obj[17]=RegKey : CLSID\{014DA6CD-189F-421a-88CD-07CFE51CFF10}

MY-WAY SPEEDBAR
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[19]=RegKey : CLSID\{0494D0D1-F8E0-41ad-92A3-14154ECE70AC}
obj[20]=RegKey : CLSID\{0494D0D2-F8E0-41ad-92A3-14154ECE70AC}
obj[21]=RegKey : CLSID\{0494D0D3-F8E0-41ad-92A3-14154ECE70AC}
obj[22]=RegKey : CLSID\{0494D0D5-F8E0-41ad-92A3-14154ECE70AC}
obj[23]=RegKey : CLSID\{0494D0D7-F8E0-41ad-92A3-14154ECE70AC}
obj[24]=RegKey : CLSID\{0494D0D9-F8E0-41ad-92A3-14154ECE70AC}
obj[25]=RegKey : CLSID\{0494D0DB-F8E0-41ad-92A3-14154ECE70AC}
obj[60]=RegKey : Interface\{0494D0D4-F8E0-41AD-92A3-14154ECE70AC}
obj[61]=RegKey : Interface\{0494D0D6-F8E0-41AD-92A3-14154ECE70AC}
obj[62]=RegKey : Interface\{0494D0DA-F8E0-41AD-92A3-14154ECE70AC}
obj[63]=RegKey : Interface\{0494D0DC-F8E0-41AD-92A3-14154ECE70AC}
obj[84]=RegKey : MyWayToolBar.NetscapeShutdown
obj[85]=RegKey : MyWayToolBar.NetscapeShutdown.1
obj[86]=RegKey : MyWayToolBar.NetscapeStartup
obj[87]=RegKey : MyWayToolBar.NetscapeStartup.1
obj[88]=RegKey : MyWayToolBar.SettingsPlugin
obj[89]=RegKey : MyWayToolBar.SettingsPlugin.1
obj[127]=RegKey : SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0494D0D1-F8E0-41ad-92A3-14154ECE70AC}
obj[137]=RegKey : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\My Way Speedbar Uninstall
obj[142]=RegKey : SOFTWARE\MyWay
obj[160]=RegKey : TypeLib\{0494D0D0-F8E0-41AD-92A3-14154ECE70AC}
obj[192]=RegValue : SOFTWARE\Microsoft\Internet Explorer\Toolbar
obj[206]=RegValue : Software\Netscape\Netscape Navigator\Automation Shutdown
obj[207]=RegValue : Software\Netscape\Netscape Navigator\Automation Startup
obj[367]=Folder : c:\program files\MyWay
obj[368]=Folder : c:\program files\myway\myBar
obj[369]=File : c:\program files\myway\mybar\1.bin\my2ns.exe
obj[370]=File : c:\program files\myway\mybar\1.bin\mybar.dll
obj[371]=File : c:\program files\myway\mybar\1.bin\mylogo.gif
obj[372]=File : c:\program files\myway\mybar\1.bin\myuninst.hta
obj[373]=File : c:\program files\myway\mybar\1.bin\myunsetp.hta
obj[374]=File : c:\program files\myway\mybar\1.bin\mywaypluginproxy.class
obj[375]=File : c:\program files\myway\mybar\1.bin\npmyway.dll
obj[376]=File : c:\program files\myway\mybar\1.bin\partner.dat
obj[377]=File : c:\program files\myway\mybar\1.bin\uninstall.inf

SHOPNAV HIJACKER
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[26]=RegKey : CLSID\{14b3d246-6274-40b5-8d50-6c2ade2ab29b}
obj[90]=RegKey : SNHlprObj.SNHlprObj
obj[91]=RegKey : SNHlprObj.SNHlprObj.1
obj[128]=RegKey : SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{14b3d246-6274-40b5-8d50-6c2ade2ab29b}
obj[145]=RegKey : SOFTWARE\Srng
obj[203]=RegValue : SOFTWARE\Microsoft\Windows\CurrentVersion\Run
obj[378]=RegKey : Interface\{CE7C3CEF-4B15-11D1-ABED-709549C10000}
obj[379]=RegKey : Typelib\{CE7C3CE2-4B15-11D1-ABED-709549C10000}
obj[380]=Folder : c:\program files\Srng
obj[381]=File : c:\program files\srng
obj[382]=File : c:\program files\srng\file.zip
obj[383]=File : c:\program files\srng\snhelper.dll
obj[384]=File : c:\program files\srng\srng.exe
obj[385]=File : c:\program files\srng\srng.lock
obj[386]=File : c:\program files\srng\srnghelper.exe
obj[387]=File : c:\program files\srng\srnginit.exe
obj[388]=File : c:\program files\srng\srngutil.exe

GATOR
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[28]=RegKey : CLSID\{21FFB6C0-0DA1-11D5-A9D5-00500413153C}
obj[112]=RegKey : SOFTWARE\Gator.com
obj[199]=RegValue : SOFTWARE\Microsoft\Windows\CurrentVersion\Run
obj[302]=Folder : c:\program files\common files\CMEII
obj[303]=Folder : c:\program files\common files\GMT
obj[304]=Folder : c:\program files\Gator.com
obj[305]=File : c:\program files\common files\cmeii\cmediagnostics.log
obj[306]=File : c:\program files\common files\cmeii\cmeiiapi.dll
obj[307]=File : c:\program files\common files\cmeii\cmesys.exe
obj[308]=File : c:\program files\common files\cmeii\gappmgr.dll
obj[309]=File : c:\program files\common files\cmeii\gatorsupportinfo.txt
obj[310]=File : c:\program files\common files\cmeii\gcontroller.dll
obj[311]=File : c:\program files\common files\cmeii\gdwldeng.dll
obj[312]=File : c:\program files\common files\cmeii\giocl.dll
obj[313]=File : c:\program files\common files\cmeii\gioclclient.dll
obj[314]=File : c:\program files\common files\cmeii\gmtproxy.dll
obj[315]=File : c:\program files\common files\cmeii\gobjs.dll
obj[316]=File : c:\program files\common files\cmeii\gstore.dll
obj[317]=File : c:\program files\common files\cmeii\gstoreserver.dll
obj[318]=File : c:\program files\common files\cmeii\gtools.dll
obj[319]=File : c:\program files\common files\cmeii\gui
obj[320]=File : c:\program files\common files\cmeii\store
obj[321]=File : c:\program files\common files\gmt\data
obj[322]=File : c:\program files\common files\gmt\downloadtemp
obj[323]=File : c:\program files\common files\gmt\eggcengine.dll
obj[324]=File : c:\program files\common files\gmt\egieengine.dll
obj[325]=File : c:\program files\common files\gmt\egieprocess.dll
obj[326]=File : c:\program files\common files\gmt\egnsengine.dll
obj[327]=File : c:\program files\common files\gmt\fillin.wav
obj[328]=File : c:\program files\common files\gmt\gator.log
obj[329]=File : c:\program files\common files\gmt\gatorres.dll
obj[330]=File : c:\program files\common files\gmt\gatorstubsetup.exe
obj[331]=File : c:\program files\common files\gmt\gmt.exe.manifest
obj[332]=File : c:\program files\common files\gmt\guninstaller.exe
obj[333]=File : c:\program files\common files\gmt\helper.wav
obj[334]=File : c:\program files\common files\gmt\mepbs.dat
obj[335]=File : c:\program files\common files\gmt\mepcme.dat
obj[336]=File : c:\program files\common files\gmt\mepcmeft.dat
obj[337]=File : c:\program files\common files\gmt\mepgh.dat
obj[338]=File : c:\program files\common files\gmt\mepimg.dat
obj[339]=File : c:\program files\common files\gmt\meprca.dat
obj[340]=File : c:\program files\common files\gmt\scripts
obj[341]=File : c:\program files\common files\gmt\w12yk2crt7
obj[342]=File : c:\program files\gator.com\gator
obj[343]=File : c:\windows\gatorpatch.log
obj[344]=File : c:\windows\gatorpdpsetup.log

SAHAGENT
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[30]=RegKey : CLSID\{30402FF4-3E71-4A1C-9B4B-1CD3486A9FB2}
obj[68]=RegKey : Interface\{4828C95F-C5DB-4AB6-A945-8D8EC44B98A8}
obj[70]=RegKey : Interface\{4E570F74-DEEE-4FCF-B960-FEEFA4B8C6FC}
obj[148]=RegKey : SOFTWARE\VGroup
obj[152]=RegKey : Software\WinSock2\Layered Provider Sample
obj[185]=RegKey : WEBInstaller.execute
obj[186]=RegKey : WEBInstaller.execute.1
obj[201]=RegValue : SOFTWARE\Microsoft\Windows\CurrentVersion\Run
obj[234]=LSP : LAYERED MSAFD Tcpip [TCP/IP] (c:\windows\system32\lsp.dll)
obj[235]=File : c:\windows\system32\lsp.dll
obj[236]=LSP : LAYERED MSAFD Tcpip [UDP/IP] (c:\windows\system32\lsp.dll)
obj[237]=LSP : LAYERED MSAFD Tcpip [RAW/IP] (c:\windows\system32\lsp.dll)
obj[238]=LSP : LAYERED RSVP UDP Service Provider (c:\windows\system32\lsp.dll)
obj[239]=LSP : LAYERED RSVP TCP Service Provider (c:\windows\system32\lsp.dll)
obj[240]=LSP : LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{FC6069E7-B214-41DA-8A6D-306F42A5CEC7}] SEQPACKET 3 (c:\windows\system32\lsp.dll)
obj[241]=LSP : LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{FC6069E7-B214-41DA-8A6D-306F42A5CEC7}] DATAGRAM 3 (c:\windows\system32\lsp.dll)
obj[242]=LSP : LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{29D80C57-4D7C-4985-BE63-17572FA4E49F}] SEQPACKET 0 (c:\windows\system32\lsp.dll)
obj[243]=LSP : LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{29D80C57-4D7C-4985-BE63-17572FA4E49F}] DATAGRAM 0 (c:\windows\system32\lsp.dll)
obj[244]=LSP : LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{CDD1BF4D-973F-41FB-84EE-70415F850CAE}] SEQPACKET 1 (c:\windows\system32\lsp.dll)
obj[245]=LSP : LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{CDD1BF4D-973F-41FB-84EE-70415F850CAE}] DATAGRAM 1 (c:\windows\system32\lsp.dll)
obj[246]=LSP : LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{972E5C85-9C57-4202-BEAF-40729CA1B946}] SEQPACKET 2 (c:\windows\system32\lsp.dll)
obj[247]=LSP : LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{972E5C85-9C57-4202-BEAF-40729CA1B946}] DATAGRAM 2 (c:\windows\system32\lsp.dll)
obj[248]=LSP : LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{124F0D54-F0D5-4D35-A939-8DBB31A1B32E}] SEQPACKET 4 (c:\windows\system32\lsp.dll)
obj[249]=LSP : LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{124F0D54-F0D5-4D35-A939-8DBB31A1B32E}] DATAGRAM 4 (c:\windows\system32\lsp.dll)
obj[250]=LSP : LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{7B5B2ACD-5826-4784-AC5F-3B26161C4236}] SEQPACKET 5 (c:\windows\system32\lsp.dll)
obj[251]=LSP : LAYERED MSAFD NetBIOS [\Device\NetBT_Tcpip_{7B5B2ACD-5826-4784-AC5F-3B26161C4236}] DATAGRAM 5 (c:\windows\system32\lsp.dll)
obj[252]=LSP : LAYERED_PROVIDER (c:\windows\system32\lsp.dll)
obj[278]=File : c:\windows\system32\lsp.dll
obj[389]=File : c:\windows\system32\sahdownloader.exe
obj[390]=File : c:\windows\system32\v.dat
obj[391]=File : c:\windows\system32\vg.dat
obj[392]=File : c:\windows\downloaded program files\setup.inf
obj[393]=File : c:\windows\downloaded program files\webinstaller.dll
obj[394]=File : c:\windows\downloaded program files\xmlparse_.dll
obj[395]=File : c:\windows\downloaded program files\xmltok_.dll
obj[396]=File : c:\windows\sahuninstall.exe
obj[397]=File : c:\sahagent.log

DOWNLOADWARE
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[35]=RegKey : CLSID\{85A702BA-EA8F-4B83-AA07-07A5186ACD7E}
obj[109]=RegKey : SOFTWARE\DownloadWare
obj[129]=RegKey : SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{85A702BA-EA8F-4B83-AA07-07A5186ACD7E}
obj[197]=RegValue : Software\Microsoft\Windows\CurrentVersion\Run
obj[285]=Folder : c:\program files\DownloadWare
obj[286]=File : c:\program files\downloadware\cfg
obj[287]=File : c:\program files\downloadware\downloads
obj[288]=File : c:\program files\downloadware\temp

IGETNET
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[38]=RegKey : CLSID\{947e6d5a-4b9f-4cf4-91b3-562ca8d03313}
obj[130]=RegKey : SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{947e6d5a-4b9f-4cf4-91b3-562ca8d03313}
obj[167]=RegKey : TYPELIB\{95b3af07-0e4f-4cdf-acfd-3d4efd9aec0b}
obj[200]=RegValue : SOFTWARE\Microsoft\Windows\CurrentVersion\Run
obj[398]=RegValue : Software\Microsoft\Internet Explorer\URLSearchHooks

WEBHANCER
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[40]=RegKey : CLSID\{c900b400-cdfe-11d3-976a-00e02913a9e0}
obj[79]=RegKey : Interface\{C89435B0-CDFE-11D3-976A-00E02913A9E0}
obj[131]=RegKey : Software\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{c900b400-cdfe-11d3-976a-00e02913a9e0}
obj[141]=RegKey : Software\Microsoft\Windows\CurrentVersion\Uninstall\webHancer Agent
obj[149]=RegKey : Software\webHancer
obj[170]=RegKey : TypeLib\{C8CB3870-CDFE-11D3-976A-00E02913A9E0}
obj[172]=RegKey : Typelib\{CDE442A3-DC2C-467E-A311-B4BC775D86C5}
obj[187]=RegKey : WhIeHelperObj.WhIeHelperObj
obj[188]=RegKey : WhIeHelperObj.WhIeHelperObj.1
obj[204]=RegValue : Software\Microsoft\Windows\CurrentVersion\Run
obj[399]=Folder : c:\program files\webHancer
obj[400]=File : c:\program files\webhancer\programs\license.txt
obj[401]=File : c:\program files\webhancer\programs\readme.txt
obj[402]=File : c:\program files\webhancer\programs\sporder.dll
obj[403]=File : c:\program files\webhancer\programs\wbhshare.dll
obj[404]=File : c:\program files\webhancer\programs\whagent.exe
obj[405]=File : c:\program files\webhancer\programs\whagent.ini
obj[406]=File : c:\program files\webhancer\programs\whiehlpr.dll
obj[407]=File : c:\program files\webhancer\programs\whieshm.dll
obj[408]=File : c:\program files\webhancer\programs\whsurvey.exe
obj[409]=File : c:\program files\webhancer\programs\whsurvey.ini
obj[410]=File : c:\windows\webhdll.dll
obj[411]=File : c:\windows\whagent.inf
obj[412]=File : c:\windows\whinstaller.exe
obj[413]=File : c:\windows\whinstaller.ini

FAVORITEMAN
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[46]=RegKey : F1.Organizer
obj[47]=RegKey : F1.Organizer.1
obj[163]=RegKey : TypeLib\{53F066F0-A4C0-4F46-83EB-2DFD03F938CF}
obj[176]=RegKey : TypeLib\{EF100007-F409-426A-9E7C-CB211F2A9786}
obj[193]=RegValue : Software\Microsoft\Windows
obj[194]=RegValue : Software\Microsoft\Windows
obj[195]=RegValue : Software\Microsoft\Windows
obj[277]=File : c:\windows\system32\im64.dll

CLEARSEARCH
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[58]=RegKey : ie_clrsch.iehooks
obj[59]=RegKey : ie_clrsch.iehooks.1
obj[75]=RegKey : Interface\{A351D4B1-BF54-41F1-BEC0-8A1C4ECD72C7}
obj[105]=RegKey : SOFTWARE\CLRSCH
obj[414]=Folder : c:\program files\ClearSearch
obj[415]=Folder : c:\docume~1\sky\locals~1\temp\ClrSch
obj[416]=File : c:\program files\clearsearch\bi.dll
obj[417]=File : c:\program files\clearsearch\clrschieplugin.dll
obj[418]=File : c:\program files\clearsearch\control.dat
obj[419]=File : c:\program files\clearsearch\csbi.dll
obj[420]=File : c:\program files\clearsearch\csie.dll
obj[421]=File : c:\program files\clearsearch\cssb.dll
obj[422]=File : c:\program files\clearsearch\csss.dll
obj[423]=File : c:\program files\clearsearch\cszt.dll
obj[424]=File : c:\program files\clearsearch\ie_clrsch.dll
obj[425]=File : c:\program files\clearsearch\loader.exe
obj[426]=File : c:\program files\clearsearch\ss.dll

STOPPOP
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[67]=RegKey : Interface\{4534CD6B-59D6-43FD-864B-06A0D843444A}

FLASHTRACK
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[73]=RegKey : Interface\{6E83AE1C-F69C-4AED-AF98-D23C24C6FA4B}
obj[111]=RegKey : SOFTWARE\Flt
obj[166]=RegKey : TypeLib\{7955EA20-E0D6-4A77-88B6-120674D979EA}

NCASE
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[92]=RegKey : SOFTWARE\180solutions
obj[93]=RegKey : SOFTWARE\180solutions\msbb
obj[136]=RegKey : Software\Microsoft\Windows\CurrentVersion\Uninstall\msbb
obj[138]=RegKey : Software\Microsoft\Windows\CurrentVersion\Uninstall\nCASE
obj[230]=RegValue : Software\Microsoft\Windows\CurrentVersion\Run
obj[231]=RegValue : Software\Microsoft\Windows\CurrentVersion\Run
obj[232]=File : c:\windows\wadgknqu.exe
obj[294]=Folder : c:\program files\n-CASE
obj[295]=File : c:\program files\n-case\fiz1
obj[296]=File : c:\program files\n-case\fiz2
obj[297]=File : c:\program files\n-case\fiz3
obj[298]=File : c:\program files\n-case\fiz4
obj[299]=File : c:\program files\n-case\fleok
obj[300]=File : c:\program files\n-case\kyf.dat
obj[301]=File : c:\program files\n-case\ncmyb.dll

CYDOOR
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[107]=RegKey : software\cydoor
obj[108]=RegKey : Software\Cydoor
obj[133]=RegKey : Software\Microsoft\Windows\CurrentVersion\Uninstall\AdSupport_270
obj[427]=Folder : c:\windows\system32\AdCache
obj[428]=File : c:\windows\system32\adcache\b_270_0_1_500300.gif
obj[429]=File : c:\windows\system32\adcache\b_270_0_1_500400.gif
obj[430]=File : c:\windows\system32\adcache\b_270_0_1_519800.gif
obj[431]=File : c:\windows\system32\adcache\b_270_0_1_520200.gif
obj[432]=File : c:\windows\system32\adcache\b_270_0_1_531600.gif
obj[433]=File : c:\windows\system32\adcache\b_270_0_1_532300.gif
obj[434]=File : c:\windows\system32\adcache\b_270_0_1_536800.gif
obj[435]=File : c:\windows\system32\adcache\b_270_0_1_539000.gif
obj[436]=File : c:\windows\system32\adcache\b_270_0_1_548900.gif
obj[437]=File : c:\windows\system32\adcache\b_270_0_1_578700.gif
obj[438]=File : c:\windows\system32\adcache\b_270_0_1_581400.gif
obj[439]=File : c:\windows\system32\adcache\b_270_0_1_581500.gif
obj[440]=File : c:\windows\system32\adcache\b_270_0_1_597000.gif
obj[441]=File : c:\windows\system32\adcache\b_270_0_1_597500.gif
obj[442]=File : c:\windows\system32\adcache\b_270_0_1_603300.gif
obj[443]=File : c:\windows\system32\adcache\b_270_0_1_614300.gif
obj[444]=File : c:\windows\system32\adcache\b_270_0_1_720900.gif
obj[445]=File : c:\windows\system32\adcache\b_270_0_1_757500.gif
obj[446]=File : c:\windows\system32\adcache\b_270_0_1_757600.gif
obj[447]=File : c:\windows\system32\adcache\b_270_0_2_500300.gif
obj[448]=File : c:\windows\system32\adcache\b_270_0_2_500400.gif
obj[449]=File : c:\windows\system32\adcache\b_270_0_2_502800.gif
obj[450]=File : c:\windows\system32\adcache\b_270_0_2_519800.gif
obj[451]=File : c:\windows\system32\adcache\b_270_0_2_520200.gif
obj[452]=File : c:\windows\system32\adcache\b_270_0_2_531600.gif
obj[453]=File : c:\windows\system32\adcache\b_270_0_2_532300.gif
obj[454]=File : c:\windows\system32\adcache\b_270_0_2_539000.gif
obj[455]=File : c:\windows\system32\adcache\b_270_0_2_548900.gif
obj[456]=File : c:\windows\system32\adcache\b_270_0_2_581400.gif
obj[457]=File : c:\windows\system32\adcache\b_270_0_2_585500.gif
obj[458]=File : c:\windows\system32\adcache\b_270_0_2_592600.gif
obj[459]=File : c:\windows\system32\adcache\b_270_0_2_592800.gif
obj[460]=File : c:\windows\system32\adcache\b_270_0_2_597500.gif
obj[461]=File : c:\windows\system32\adcache\b_270_0_3_500300.gif
obj[462]=File : c:\windows\system32\adcache\b_270_0_3_502800.gif
obj[463]=File : c:\windows\system32\adcache\b_270_0_3_502900.gif
obj[464]=File : c:\windows\system32\adcache\b_270_0_3_519800.gif
obj[465]=File : c:\windows\system32\adcache\b_270_0_3_520200.gif
obj[466]=File : c:\windows\system32\adcache\b_270_0_3_531600.gif
obj[467]=File : c:\windows\system32\adcache\b_270_0_3_532300.gif
obj[468]=File : c:\windows\system32\adcache\b_270_0_3_539000.gif
obj[469]=File : c:\windows\system32\adcache\b_270_0_3_542400.gif
obj[470]=File : c:\windows\system32\adcache\b_270_0_3_543700.gif
obj[471]=File : c:\windows\system32\adcache\b_270_0_3_548900.gif
obj[472]=File : c:\windows\system32\adcache\b_270_0_3_698200.gif
obj[473]=File : c:\windows\system32\adcache\b_270_0_3_699100.gif
obj[474]=File : c:\windows\system32\adcache\b_270_0_3_699600.gif
obj[475]=File : c:\windows\system32\adcache\b_270_0_3_725500.gif
obj[476]=File : c:\windows\system32\adcache\b_270_0_3_727700.gif
obj[477]=File : c:\windows\system32\adcache\b_270_0_3_728100.gif
obj[478]=File : c:\windows\system32\adcache\b_270_0_4_522300.gif
obj[479]=File : c:\windows\system32\adcache\b_270_1_1_500500.htm
obj[480]=File : c:\windows\system32\adcache\b_270_1_1_559400.htm
obj[481]=File : c:\windows\system32\adcache\b_270_1_1_592400.htm
obj[482]=File : c:\windows\system32\adcache\b_270_1_1_602100.htm
obj[483]=File : c:\windows\system32\adcache\b_270_1_1_610700.htm
obj[484]=File : c:\windows\system32\adcache\b_270_1_1_662000.htm
obj[485]=File : c:\windows\system32\adcache\b_270_1_1_663700.htm
obj[486]=File : c:\windows\system32\adcache\b_270_1_1_705800.htm
obj[487]=File : c:\windows\system32\adcache\b_270_1_1_731900.htm
obj[488]=File : c:\windows\system32\adcache\b_270_1_1_775300.htm
obj[489]=File : c:\windows\system32\adcache\b_270_1_2_592400.htm
obj[490]=File : c:\windows\system32\adcache\b_270_1_2_602100.htm
obj[491]=File : c:\windows\system32\adcache\b_270_1_2_610700.htm
obj[492]=File : c:\windows\system32\adcache\b_270_1_2_662000.htm
obj[493]=File : c:\windows\system32\adcache\b_270_1_2_764000.htm
obj[494]=File : c:\windows\system32\adcache\b_270_1_2_764000.swf
obj[495]=File : c:\windows\system32\adcache\b_270_1_3_545200.htm
obj[496]=File : c:\windows\system32\adcache\b_270_1_3_662000.htm
obj[497]=File : c:\windows\system32\adcache\b_270_1_4_509300.htm
obj[498]=File : c:\windows\system32\adcache\b_270_1_4_602100.htm
obj[499]=File : c:\windows\system32\adcache\b_563200.htm
obj[500]=File : c:\windows\system32\adcache\b_593100.htm
obj[501]=File : c:\windows\system32\adcache\temp
obj[502]=File : c:\windows\system32\cd_clint.dll

EBATES MONEYMAKER
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[118]=RegKey : Software\Microsoft\Internet Explorer\Extensions\{7F241C00-DAB6-11d5-AAA8-0001028DF1BC}
obj[122]=RegKey : Software\Microsoft\Internet Explorer\MenuExt\Ebates
obj[135]=RegKey : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ebatesver2.xml
obj[191]=RegValue : Software\Microsoft\Internet Explorer\Extensions\CmdMapping
obj[198]=RegValue : SOFTWARE\Microsoft\Windows\CurrentVersion\Run
obj[503]=Folder : c:\program files\EbatesMoeMoneyMaker
obj[504]=File : c:\program files\ebatesmoemoneymaker\applicationdata
obj[505]=File : c:\program files\ebatesmoemoneymaker\applications
obj[506]=File : c:\program files\ebatesmoemoneymaker\ebatesmoemoneymaker.exe
obj[507]=File : c:\program files\ebatesmoemoneymaker\ebatesmoemoneymaker.inf
obj[508]=File : c:\program files\ebatesmoemoneymaker\ebatesmoemoneymaker1.exe
obj[509]=File : c:\program files\ebatesmoemoneymaker\ebates_readme2.txt
obj[510]=File : c:\program files\ebatesmoemoneymaker\system

ALEXA
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[119]=RegKey : SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}

LOP.COM
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[125]=RegKey : Software\Microsoft\Windows\CurrentVersion\Backup
obj[151]=RegKey : Software\WinActive\Basic
obj[228]=RegValue : Software\Microsoft\Windows\CurrentVersion\Run
obj[229]=File : c:\program files\window active\winactive.exe
obj[511]=RegKey : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ActiveDesktop
obj[512]=RegKey : Software\WinActive
obj[513]=Folder : c:\documents and settings\sky\favorieten\ Computers
obj[514]=Folder : c:\documents and settings\sky\favorieten\ Internet
obj[515]=Folder : c:\documents and settings\sky\favorieten\ Online Gaming
obj[516]=Folder : c:\documents and settings\sky\favorieten\ Travel
obj[517]=Folder : c:\program files\Window Active
obj[518]=Folder : c:\docume~1\sky\locals~1\temp\delete.me
obj[519]=File : c:\program files\window active\unbzip2s.dll
obj[520]=File : c:\docume~1\sky\locals~1\temp\delete.me\xpp3.dat

BROADCASTPC
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[140]=RegKey : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RVP
obj[144]=RegKey : Software\RVP
obj[196]=RegValue : SOFTWARE\Microsoft\Windows\CurrentVersion\RUN
obj[289]=Folder : c:\program files\Flt
obj[290]=Folder : c:\program files\RVP
obj[291]=File : c:\program files\flt\flt.dll
obj[292]=File : c:\program files\flt\flt.mon
obj[293]=File : c:\program files\rvp\uninst.exe

NETRATINGS
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[143]=RegKey : SOFTWARE\NetRatings
obj[521]=Folder : c:\program files\NetRatings
obj[522]=Folder : c:\program files\netratings\Premeter

SECONDTHOUGHT
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[146]=RegKey : software\stc\client
obj[202]=RegValue : SOFTWARE\Microsoft\Windows\CurrentVersion\Run
obj[523]=RegKey : software\stc
obj[524]=Folder : c:\program files\STC
obj[525]=File : c:\program files\stc\clrschp038.exe
obj[526]=File : c:\program files\stc\internetfeatures.exe
obj[527]=File : c:\program files\stc\slmss.exe
obj[528]=File : c:\program files\stc\stc.exe
obj[529]=File : c:\windows\system32\2ndsrch.dll
obj[530]=File : c:\windows\system32\stcloader.exe

WURLDMEDIA
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[155]=RegKey : tchk.tchkbho

MSVIEW
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[165]=RegKey : TypeLib\{690BCCB4-6B83-4203-AE77-038C116594EC}
obj[178]=RegKey : VX2.VX2Obj

WINDOWS
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[208]=RegData : Software\Microsoft\MediaPlayer\Player\Settings

POSSIBLE BROWSER HIJACK ATTEMPT
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[209]=RegData : Software\Microsoft\Internet Explorer\Main
obj[210]=RegData : Software\Microsoft\Internet Explorer\Main
obj[211]=RegData : Software\Microsoft\Internet Explorer\SearchURL
obj[212]=RegData : Software\Microsoft\Internet Explorer\Main
obj[213]=RegData : Software\Microsoft\Internet Explorer\SearchURL
obj[214]=RegData : Software\Microsoft\Internet Explorer\SearchURL
obj[215]=RegData : Software\Microsoft\Internet Explorer\Main
obj[216]=RegData : Software\Microsoft\Internet Explorer\SearchURL
obj[217]=RegData : Software\Microsoft\Internet Explorer\Main
obj[218]=RegData : Software\Microsoft\Internet Explorer\Search
obj[219]=RegData : Software\Microsoft\Internet Explorer\Main
obj[220]=RegKey : Software\shfrbwbypyto
obj[221]=RegKey : Software\Srng

TRACKING COOKIE
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[253]=File : c:\documents and settings\sky\cookies\sky@a.as-us.falkag[1].txt
obj[254]=File : c:\documents and settings\sky\cookies\sky@adserv.internetfuel[2].txt
obj[255]=File : c:\documents and settings\sky\cookies\sky@as-us.falkag[2].txt
obj[256]=File : c:\documents and settings\sky\cookies\sky@as1.falkag[1].txt
obj[257]=File : c:\documents and settings\sky\cookies\sky@atdmt[2].txt
obj[258]=File : c:\documents and settings\sky\cookies\sky@bfast[1].txt
obj[259]=File : c:\documents and settings\sky\cookies\sky@bilbo.counted[2].txt
obj[260]=File : c:\documents and settings\sky\cookies\sky@bis.180solutions[2].txt
obj[262]=File : c:\documents and settings\sky\cookies\sky@cms[1].txt
obj[263]=File : c:\documents and settings\sky\cookies\sky@counter2.hitslink[1].txt
obj[264]=File : c:\documents and settings\sky\cookies\sky@doubleclick[2].txt
obj[265]=File : c:\documents and settings\sky\cookies\sky@etype.adbureau[1].txt
obj[266]=File : c:\documents and settings\sky\cookies\sky@fastclick[2].txt
obj[267]=File : c:\documents and settings\sky\cookies\sky@gator[1].txt
obj[268]=File : c:\documents and settings\sky\cookies\sky@lop[1].txt
obj[269]=File : c:\documents and settings\sky\cookies\sky@netshelter.adtrix[2].txt
obj[270]=File : c:\documents and settings\sky\cookies\sky@qksrv[1].txt
obj[271]=File : c:\documents and settings\sky\cookies\sky@rub[1].txt
obj[272]=File : c:\documents and settings\sky\cookies\sky@stat.onestat[2].txt
obj[273]=File : c:\documents and settings\sky\cookies\sky@tradedoubler[1].txt
obj[274]=File : c:\documents and settings\sky\cookies\sky@tribalfusion[1].txt
obj[275]=File : c:\documents and settings\sky\cookies\sky@webpdp.gator[2].txt
obj[276]=File : c:\documents and settings\sky\cookies\sky@z1.adserver[1].txt

OTHER
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[261]=File : c:\documents and settings\sky\cookies\sky@cgi-bin[2].txt
En tweede scan:
ArchiveData(rommel2.bckp)
======================================================

REMANENTBHO
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[0]=RegKey : AppID\BookedSpace.DLL
obj[1]=RegKey : BookedSpace.Extension
obj[6]=RegKey : SOFTWARE\BookedSpace

VX2.BETTERINTERNET
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[2]=RegKey : CLSID\{DDFFA75A-E81D-4454-89FC-B9FD0631E726}
obj[3]=RegKey : CLSID\{DDFFA75A-E81D-4454-89FC-B9FD0631E726}\InprocServer32
obj[4]=RegValue : SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

TRACKING COOKIE
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[5]=File : c:\documents and settings\sky\cookies\sky@a.as-us.falkag[2].txt

  • shadowlyse
  • Registratie: Juni 2002
  • Laatst online: 02-08 13:12
Het is opzich niet gewenst om een complete screendump van al die meuk hier neer te pleuren :)

  • Voutloos
  • Registratie: Januari 2002
  • Niet online
Zet die backup maar terug, want zo'n lijst door lezen, kunnen we niet aan beginnen hoor.

Dit klinkt misschien niet zo aardig, maar het is gewoon onbegonnen werk.

Het is misschien slimmer om vanaf de oude situatie met beperkende opties steeds een beetje weg te halen, zodat je wat gerichter het probleem vind, danwel alvast een deel van de spyware weggooid.

[ Voor 3% gewijzigd door Voutloos op 14-01-2004 23:48 ]

{signature}


  • DJSmiley
  • Registratie: Mei 2000
  • Laatst online: 15-08 11:31
Spyware vern*kt je TCP/IP gedoe, heb ik vaker gezien.

Alles eraf mikken, en deze 2 regkeys weer toevoegen:

http://www.djsmiley.com/wsock/wsock.reg
http://www.djsmiley.com/wsock/wsock2.reg


En dan rebooten

Deze keys doen hetzelfde WinsockXPfix. Dat tooltje kun je uiteraard ook downen ;)

Verwijderd

Probeer anders RegClean is van MS zelf dus kan geen kwaad lijkt mij om het te proberen . ;)

http://www.zdnet.nl/downl.cfm?id=7691

edit :
- Na eerste scan zijn er 531 stuks gevonden -
Misschien is een Popup/Ads Killer geen overbodige luxe :+

[ Voor 31% gewijzigd door Verwijderd op 15-01-2004 00:00 ]


  • kakanox
  • Registratie: Oktober 2002
  • Laatst online: 30-07 14:45
zoek zelf eens door die lijst heen, en kijk of je de vermiste bestanden kan vinden in dat bestand of een bestand dat erbij lijkt te horen. zoek anders het bestand eens op in de registry en haal de link ernaar (tijdelijk?) weg..

verder: GoT begint zo langzamerhand meer te letten op een paradijs voor wethouders en rechtertjes die op hun werk niet aan hun trekken lijken te komen, dan op een forum waar je ook nog informatie kan krijgen. je mag hier toch wat vragen? die lap tekst kan je best overheen scrollen, zo moeilijk is dat niet met moderne muisjes!

Ga toch fietsen.


Verwijderd

kHeb net de lijst gelezen (ja echt :)) en er staat niet echt iets in waarvan ik zeg "Dat moet terug!" , lijkt mij dat de tips van djsmiley en smarty_6000 van toepassing zijn.
Over die mpservice.exe: Zoek 'm op in de registry en verwijderen!

  • MrDummy
  • Registratie: April 2000
  • Laatst online: 25-07-2025

MrDummy

Nog steeds gek op anime...

Topicstarter
wat doet mpservic.exe eigenlijk? (zonder e dus, want het is al 8 letters lang)
Pagina: 1