hi again..
thanx for helping me so quick..
everything went well except for this, cause when i tried to find these files:
C:\WINDOWS\system32\abasa5jrp.exe<--Delete this file
C:\WINDOWS\system32\abasa5jrp.exe<--Delete this file
I couldn't find them..
here are the logs were you for asked:
Logfile of HijackThis v1.99.1
Scan saved at 18:54:05, on 31-3-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Media Access\MediaAccK.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Media Access\MediaAccess.exe
C:\Program Files\Digital Image\Monitor.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HiJack THis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://svcs.microsof...enger&Country=0R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [ITUNES] itune.exe
O4 - HKLM\..\Run: [ap9h4qmo] C:\WINDOWS\system32\ap9h4qmo.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\RunServices: [ITUNES] itune.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Global Startup: Digital Image Monitor.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zon...kr.cab31267.cabO16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall-bet...all/xscan60.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....467&clcid=0x409O16 - DPF: {6211AC26-A1B4-422A-AC52-1E70B7D24465} (FileSharingCtrl Class) -
http://appdirectory....sharingctrl.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Besturing) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) -
http://messenger.zon...wn.cab31267.cabO23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
and
Incident Status Location
Adware:Adware/WUpd No disinfected C:\Program Files\Media Access\MediaAccK.exe
Adware:Adware/WUpd No disinfected C:\Program Files\Media Access\MediaAccess.exe
Adware:Adware/WUpd No disinfected C:\Program Files\Media Access\MediaAccC.dll
Adware:Adware/WUpd No disinfected C:\PROGRA~1\MEDIAA~1\MEDIAA~1.EXE
Adware:Adware/SaveNow No disinfected Windows Registry
Adware:Adware/CWS No disinfected C:\Documents and Settings\Thomas.GROENENDAAL\Favorieten\Fun & Games\Betting.lnk
Adware:Adware/BHO No disinfected Windows Registry
Adware:Adware/Apropos No disinfected C:\DOCUME~1\THOMAS~1.GRO\LOCALS~1\Temp\cfout.txt
Adware:Adware/SideFind No disinfected Windows Registry
Adware:Adware/WUpd No disinfected C:\Program Files\Media Access
Adware:Adware/WhenUSearch No disinfected C:\Program Files\Common Files\Whenu
Adware:Adware/WinAD No disinfected C:\autosupdate.exe
Adware:Adware/WinAD No disinfected C:\dd.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Els.GROENENDAAL\Local Settings\Temp\4aIAot.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Els.GROENENDAAL\Local Settings\Temp\5DmjKF.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Els.GROENENDAAL\Local Settings\Temp\afrDPF.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Els.GROENENDAAL\Local Settings\Temp\CBaAIw.exe
Adware:Adware/WinAD No disinfected C:\Documents and Settings\Els.GROENENDAAL\Local Settings\Temporary Internet Files\Content.IE5\Q5IYUQJT\dd[1].exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Frank.GROENENDAAL\Local Settings\Temp\ccJbdE.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Frank.GROENENDAAL\Local Settings\Temp\F0hxe8.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Frank.GROENENDAAL\Local Settings\Temp\fdckFN.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Frank.GROENENDAAL\Local Settings\Temp\fFJXwC.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Frank.GROENENDAAL\Local Settings\Temp\GjfqF7.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Frank.GROENENDAAL\Local Settings\Temp\KZFPe2.exe
Adware:Adware/SAHAgent No disinfected C:\Documents and Settings\Frank.GROENENDAAL\Local Settings\Temp\temp.fr587D
Adware:Adware/SAHAgent No disinfected C:\Documents and Settings\Frank.GROENENDAAL\Local Settings\Temp\temp.fr5E45
Adware:Adware/SAHAgent No disinfected C:\Documents and Settings\Frank.GROENENDAAL\Local Settings\Temp\temp.fr667D
Adware:Adware/SAHAgent No disinfected C:\Documents and Settings\Frank.GROENENDAAL\Local Settings\Temp\temp.fr6AE8
Spyware:Spyware/Dyfuca No disinfected C:\Documents and Settings\Frank.GROENENDAAL\Local Settings\Temp\temp.frA5D8
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Frank.GROENENDAAL\Local Settings\Temp\YLM4kk.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Myrthe.GROENENDAAL\Local Settings\Temp\1y570B.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Myrthe.GROENENDAAL\Local Settings\Temp\2QbeIS.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Myrthe.GROENENDAAL\Local Settings\Temp\7RNJfe.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Myrthe.GROENENDAAL\Local Settings\Temp\r5IEGM.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Myrthe.GROENENDAAL\Local Settings\Temp\tnQTBQ.exe
Adware:Adware/WinAD No disinfected C:\Documents and Settings\Myrthe.GROENENDAAL\Local Settings\Temporary Internet Files\Content.IE5\OJVZ2W5H\dd[1].exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Myrthe.GROENENDAAL\Local Settings\Temporary Internet Files\Content.IE5\S58X6305\istsvc[1].exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Thomas.GROENENDAAL\Local Settings\Temp\0p8gOb.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Thomas.GROENENDAAL\Local Settings\Temp\3b4rWH.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Thomas.GROENENDAAL\Local Settings\Temp\A748be.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Thomas.GROENENDAAL\Local Settings\Temp\AEeEKZ.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Thomas.GROENENDAAL\Local Settings\Temp\aKFwGB.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Thomas.GROENENDAAL\Local Settings\Temp\aPg98G.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Thomas.GROENENDAAL\Local Settings\Temp\CBk3kd.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Thomas.GROENENDAAL\Local Settings\Temp\d2ecuy.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Thomas.GROENENDAAL\Local Settings\Temp\P1mdNe.exe
Spyware:Spyware/Dyfuca No disinfected C:\Documents and Settings\Thomas.GROENENDAAL\Local Settings\Temp\temp.fr2D2D
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Thomas.GROENENDAAL\Local Settings\Temp\UBoKUD.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Thomas.GROENENDAAL\Local Settings\Temp\ZBh4t9.exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Thomas.GROENENDAAL\Local Settings\Temp\ZINcBP.exe
Adware:Adware/WinAD No disinfected C:\Documents and Settings\Thomas.GROENENDAAL\Local Settings\Temporary Internet Files\Content.IE5\E90NM1E1\dd[1].exe
Adware:Adware/WUpd No disinfected C:\Program Files\Media Access\MediaAccC.dll
Adware:Adware/WUpd No disinfected C:\Program Files\Media Access\MediaAccess.exe
Adware:Adware/WUpd No disinfected C:\Program Files\Media Access\MediaAccK.exe
Spyware:Spyware/Dyfuca No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\31AE3836-48C5-462C-BE8F-01E95B\8402D579-F965-47A3-884B-02166A
Adware:Adware/WUpd No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\3E085D10-9632-4A29-9F3F-0DD450\478B4AA3-7555-4439-85FD-BF295E
Adware:Adware/WUpd No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\3E085D10-9632-4A29-9F3F-0DD450\F279055B-F9C7-4BD1-B6BF-6C2AE2
Adware:Adware/WUpd No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\3E40D68F-4692-4C42-B3CA-A00D55\5A99DEC0-95B1-4EEB-98E5-3B7224
Adware:Adware/WUpd No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\3E40D68F-4692-4C42-B3CA-A00D55\67C8BD1A-545A-4CB3-8044-5BA3C2
Adware:Adware/SAHAgent No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\435E869E-F81C-4062-97EA-6E6094\EFCD3078-CC56-4943-A356-9462D9
Spyware:Spyware/ISTbar No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\46A2BB9F-5359-4929-BE69-6FDE93\63D3E242-E077-4703-A185-309D9E
Adware:Adware/SAHAgent No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\6370FD0B-C7BE-4ED8-AFD4-DAF9DE\B201089E-63C8-4AB7-8804-B1AA2E
Adware:Adware/WUpd No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\81CCB204-BE11-4465-967D-A81DA6\0A87083B-53E2-4DFA-A311-C374C5
Adware:Adware/WUpd No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\81CCB204-BE11-4465-967D-A81DA6\CF413EDB-1CCC-479E-ABB1-5B1A31
Adware:Adware/WUpd No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\87867535-0C64-460C-84A2-DEEAAF\0488E002-2515-4D8F-9F22-CE66DA
Adware:Adware/WUpd No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\87867535-0C64-460C-84A2-DEEAAF\6DBA3325-5DA3-4396-AFF4-DA9096
Adware:Adware/SAHAgent No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\8E6AAD7B-A702-4101-8FEB-AA174C\64CC5FCD-5A4F-4D85-94AC-DE1155
Adware:Adware/SAHAgent No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\C22E2043-A8D4-40DB-8C6C-04B651\EE64E929-1B33-47FA-A8DD-FCBD75
Adware:Adware/WUpd No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\C3F5BE9F-7F63-41AC-B685-F41A7E\533ED00B-9BE7-4F84-8F31-3B1722
Adware:Adware/WUpd No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\C3F5BE9F-7F63-41AC-B685-F41A7E\F38445CC-0ADD-46ED-8506-66260C
Adware:Adware/SAHAgent No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\C6E99FE7-B097-4957-84F6-329567\B37BC1CD-998B-495C-8588-28822D
Adware:Adware/SAHAgent No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\D2CFD1C6-DD39-43A3-B941-C0C9B6\01362B38-2860-42BC-81DE-041741
Spyware:Spyware/ISTbar No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\D4D1C5BF-52B4-4A77-B4F0-860F7D\6D0034E2-A1DD-47AF-BE5D-90BF22
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\lwfmujf.exe
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\nsorvq.exe
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\system32\abasa5jrp.exe
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\system32\abasa5jrp.ini
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\system32\hochkaod3.exe
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\system32\hochkaod3.ini
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\system32\qh4mkbv9.dll
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\system32\u6f6uftuc.ini
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\u6f6uftuc.exe