Re: Another Omegasearch problem
I've used spybot to delete all spyware. (the latest version)
I don't exactly know what to do with that program adaware.
I've deleted all the files that you suggested with Hijackthis (except that one of the postbank, that's my homebank, I'm from Holland

)
But the omegasearch spyware still returns.
Here is the logfile of adaware, maybe you can tell me which files to delete?
Thanks
Lavasoft Ad-aware Personal Build 6.181
Logfile created on :woensdag 7 april 2004 20:23:44
Created with Ad-aware Personal, free for private use.
Using reference-file :1R200 12.07.2003
______________________________________________________
Ad-aware Settings
=========================
Set : Activate in-depth scan (Recommended)
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep scan registry
7-4-2004 20:23:44 - Scan started. (Smart mode)
Listing running processes
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ThreadCreationTime : 7-4-2004 18:21:05
BasePriority : Normal
#:2 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ThreadCreationTime : 7-4-2004 18:21:10
BasePriority : High
#:3 [services.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7-4-2004 18:21:10
BasePriority : Normal
FileSize : 99 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Services en controllertoepassingen
InternalName : services.exe
OriginalFilename : services.exe
ProductName : Besturingssysteem Microsoft
Created on : 11-9-2002 12:00:00
Last accessed : 7-4-2004 17:49:17
Last modified : 11-9-2002 12:00:00
#:4 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7-4-2004 18:21:10
BasePriority : Normal
FileSize : 11 KB
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
OriginalFilename : lsass.exe
ProductName : Microsoft
Created on : 11-9-2002 12:00:00
Last accessed : 7-4-2004 17:49:17
Last modified : 11-9-2002 12:00:00
#:5 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7-4-2004 18:21:10
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 11-9-2002 12:00:00
Last accessed : 7-4-2004 17:49:17
Last modified : 11-9-2002 12:00:00
#:6 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 7-4-2004 18:21:10
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 11-9-2002 12:00:00
Last accessed : 7-4-2004 17:49:17
Last modified : 11-9-2002 12:00:00
#:7 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 7-4-2004 18:21:11
BasePriority : Normal
FileSize : 50 KB
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
OriginalFilename : spoolsv.exe
ProductName : Microsoft
Created on : 11-9-2002 12:00:00
Last accessed : 7-4-2004 17:49:17
Last modified : 11-9-2002 12:00:00
#:8 [nvsvc32.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 7-4-2004 18:21:11
BasePriority : Normal
FileSize : 80 KB
FileVersion : 6.14.10.5216
ProductVersion : 6.14.10.5216
Copyright : (C) NVIDIA Corporation. All rights reserved.
CompanyName : NVIDIA Corporation
FileDescription : NVIDIA Driver Helper Service, Version 52.16
InternalName : NVSVC
OriginalFilename : nvsvc32.exe
ProductName : NVIDIA Driver Helper Service, Version 52.16
Created on : 6-10-2003 13:16:00
Last accessed : 7-4-2004 17:49:17
Last modified : 6-10-2003 13:16:00
#:9 [explorer.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 7-4-2004 18:21:13
BasePriority : Normal
FileSize : 984 KB
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
CompanyName : Microsoft Corporation
FileDescription : Windows Verkenner
InternalName : explorer
OriginalFilename : EXPLORER.EXE
ProductName : Besturingssysteem Microsoft
Created on : 11-9-2002 12:00:00
Last accessed : 7-4-2004 18:21:13
Last modified : 11-9-2002 12:00:00
#:10 [itouch.exe]
FilePath : C:\Program Files\Logitech\iTouch\
ThreadCreationTime : 7-4-2004 18:21:14
BasePriority : Normal
FileSize : 872 KB
FileVersion : 2.20.243
ProductVersion : 2.20.243
Copyright : (C) 1998-2003 Logitech. All rights reserved.
CompanyName : Logitech Inc.
FileDescription : iTouch Application
InternalName : iTouch
OriginalFilename : iTouch.exe
ProductName : iTouch
Created on : 12-2-2004 12:59:13
Last accessed : 7-4-2004 18:21:05
Last modified : 1-12-2003 10:38:16
#:11 [logi_mwx.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 7-4-2004 18:21:14
BasePriority : Normal
FileSize : 19 KB
FileVersion : 9.79.016
ProductVersion : 9.79.016
Copyright : (C) 1987-2003 Logitech. All rights reserved.
CompanyName : Logitech Inc.
FileDescription : Logitech Launcher Application
InternalName : Logi_MWX
OriginalFilename : Logi_MWX.exe
ProductName : MouseWare
Created on : 12-2-2004 12:59:40
Last accessed : 7-4-2004 18:21:05
Last modified : 7-11-2003 8:50:00
#:12 [dragdiag.exe]
FilePath : C:\Program Files\Alcatel\SpeedTouch USB\
ThreadCreationTime : 7-4-2004 18:21:14
BasePriority : Normal
FileSize : 840 KB
FileVersion : 201.2.0.0
ProductVersion : 201.2.0.0
Copyright : Copyright
CompanyName : THOMSON multimedia
FileDescription : SpeedTouch Statistics
ProductName : SpeedTouch USB
Created on : 12-2-2004 18:40:56
Last accessed : 7-4-2004 18:21:05
Last modified : 12-11-2002 10:02:08
#:13 [hpztsb04.exe]
FilePath : C:\WINDOWS\System32\spool\drivers\w32x86\3\
ThreadCreationTime : 7-4-2004 18:21:14
BasePriority : Normal
FileSize : 192 KB
FileVersion : 2,80,0,0
ProductVersion : 2,80,0,0
Copyright : Copyright (c) Hewlett-Packard Company 1999-2001
CompanyName : HP
ProductName : HP DeskJet
Created on : 12-2-2004 18:50:49
Last accessed : 7-4-2004 18:21:05
Last modified : 12-10-2001 9:57:26
#:14 [fivedart2.exe]
FilePath : C:\PROGRA~1\STUPID~1\
ThreadCreationTime : 7-4-2004 18:21:14
BasePriority : Normal
FileSize : 228 KB
Created on : 27-3-2004 11:14:19
Last accessed : 7-4-2004 18:21:05
Last modified : 27-3-2004 11:14:16
#:15 [ctfmon.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 7-4-2004 18:21:14
BasePriority : Normal
FileSize : 13 KB
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
OriginalFilename : CTFMON.EXE
ProductName : Microsoft
Created on : 11-9-2002 12:00:00
Last accessed : 7-4-2004 18:21:05
Last modified : 11-9-2002 12:00:00
#:16 [rundll32.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 7-4-2004 18:21:14
BasePriority : Normal
FileSize : 31 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Een DLL-bestand als toepassing starten
InternalName : rundll
OriginalFilename : RUNDLL.EXE
ProductName : Besturingssysteem Microsoft
Created on : 11-9-2002 12:00:00
Last accessed : 7-4-2004 18:21:14
Last modified : 11-9-2002 12:00:00
#:17 [wzqkpick.exe]
FilePath : C:\Program Files\WinZip\
ThreadCreationTime : 7-4-2004 18:21:15
BasePriority : Normal
FileSize : 104 KB
FileVersion : 1.0 (32-bit)
ProductVersion : 8.1 (4319)
Copyright : Copyright (c) WinZip Computing, Inc. 1991-2001 - All Rights Reserved
CompanyName : WinZip Computing, Inc.
FileDescription : WinZip Executable
InternalName : WZQKPICK.EXE
OriginalFilename : WZQKPICK.EXE
ProductName : WinZip
Created on : 12-2-2004 20:13:11
Last accessed : 7-4-2004 18:21:05
Last modified : 11-10-2002 7:10:00
#:18 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ThreadCreationTime : 7-4-2004 18:21:31
BasePriority : Normal
FileSize : 89 KB
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
OriginalFilename : IEXPLORE.EXE
ProductName : Besturingssysteem Microsoft
Created on : 12-2-2004 12:34:42
Last accessed : 7-4-2004 18:21:31
Last modified : 11-9-2002 12:00:00
#:19 [ad-aware.exe]
FilePath : D:\C Schijf\Franke\Van alles wat\Ad-aware 6\
ThreadCreationTime : 7-4-2004 18:23:39
BasePriority : Normal
FileSize : 668 KB
FileVersion : 6.0.1.181
ProductVersion : 6.0.0.0
Copyright : Copyright
CompanyName : Lavasoft Sweden
FileDescription : Ad-aware 6 core application
InternalName : Ad-aware.exe
OriginalFilename : Ad-aware.exe
ProductName : Lavasoft Ad-aware Plus
Created on : 6-4-2004 11:18:58
Last accessed : 6-4-2004 22:00:00
Last modified : 12-7-2003 20:00:20
Memory scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 0
Started registry scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
DyFuCA Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : DyFuCA_BH.BHObj
DyFuCA Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : DyFuCA_BH.BHObj.1
DyFuCA Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : Interface\{1C01D150-91A4-4DE0-9BF8-A35D1BDF1001}
DyFuCA Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Avenue Media
DyFuCA Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Avenue Media\Internet Optimizer
Dialer Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CURRENT_USER
Object : Software\Coulomb
DyFuCA Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : Software\FCI
Alexa Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
DyFuCA Object recognized!
Type : RegKey
Data : DyFuCA
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DyFuCA
DyFuCA Object recognized!
Type : RegKey
Data : Internet Optimizer
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Optimizer
DyFuCA Object recognized!
Type : RegKey
Data : Internet Optimizer
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Optimizer Active Alert
DyFuCA Object recognized!
Type : RegKey
Data : Internet Optimizer
Rootkey : HKEY_LOCAL_MACHINE
Object : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Optimizer Software Installer
DyFuCA Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : TypeLib\{0BE10B0D-B4DB-4693-9B1F-9AEAD54D17DC}
DyFuCA Object recognized!
Type : RegKey
Data :
Rootkey : HKEY_CLASSES_ROOT
Object : TypeLib\{40B1D454-9CA4-43CC-86AA-CB175EAC52FB}
Registry scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 14
Objects found so far: 14
Started deep registry scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainStart Page.com/passthrough/
Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "http://omegasearch.com/passthrough/index.html?http://www.wanadoo.nl/"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "http://omegasearch.com/passthrough/index.html?http://www.wanadoo.nl/"
Deep registry scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 1
Objects found so far: 15
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Tracking Cookie Object recognized!
Type : File
Data : dhr. hiemstra@doubleclick[1].txt
Object : C:\Documents and Settings\Dhr. Hiemstra\Cookies\
Created on : 7-4-2004 18:01:48
Last accessed : 7-4-2004 18:01:49
Last modified : 7-4-2004 18:01:49
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Deep scanning and examining files (C

ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Performing conditional scans..
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
DyFuCA Object recognized!
Type : Folder
Object : c:\program files\Internet Optimizer
DyFuCA Object recognized!
Type : File
Data : actalert.exe
Object : c:\program files\internet optimizer\
FileSize : 64 KB
Created on : 22-2-2004 15:11:11
Last accessed : 7-4-2004 17:49:17
Last modified : 22-2-2004 15:11:11
DyFuCA Object recognized!
Type : File
Data : install.exe
Object : c:\program files\internet optimizer\
FileSize : 44 KB
Created on : 22-2-2004 15:11:24
Last accessed : 7-4-2004 17:55:23
Last modified : 22-2-2004 15:11:24
DyFuCA Object recognized!
Type : File
Data : optimize.exe
Object : c:\program files\internet optimizer\
FileSize : 68 KB
Created on : 22-2-2004 15:11:10
Last accessed : 7-4-2004 17:49:17
Last modified : 27-2-2004 14:14:38
DyFuCA Object recognized!
Type : File
Data : sim
Object : c:\program files\internet optimizer\
Created on : 22-2-2004 15:12:24
Last accessed : 7-4-2004 16:06:14
Last modified : 3-4-2004 7:24:15
DyFuCA Object recognized!
Type : File
Data : update
Object : c:\program files\internet optimizer\
Created on : 22-2-2004 15:11:10
Last accessed : 7-4-2004 17:55:23
Last modified : 27-2-2004 14:14:37
DyFuCA Object recognized!
Type : File
Data : actalert.exe
Object : c:\program files\internet optimizer\update\
FileSize : 64 KB
Created on : 22-2-2004 15:11:11
Last accessed : 7-4-2004 17:55:23
Last modified : 22-2-2004 15:11:11
DyFuCA Object recognized!
Type : File
Data : install.exe
Object : c:\program files\internet optimizer\update\
FileSize : 44 KB
Created on : 22-2-2004 15:11:23
Last accessed : 7-4-2004 17:55:23
Last modified : 22-2-2004 15:11:24
DyFuCA Object recognized!
Type : File
Data : optimize.exe
Object : c:\program files\internet optimizer\update\
FileSize : 68 KB
Created on : 27-2-2004 14:14:37
Last accessed : 7-4-2004 17:55:23
Last modified : 27-2-2004 14:14:38
Dialer Object recognized!
Type : Folder
Object : c:\windows\Coder
Dialer Object recognized!
Type : Folder
Object : c:\program files\dialers
Dialer Object recognized!
Type : File
Data : coder.log
Object : c:\windows\coder\
FileSize : 1 KB
Created on : 28-2-2004 12:36:38
Last accessed : 7-4-2004 17:55:23
Last modified : 28-2-2004 12:40:57
Dialer Object recognized!
Type : File
Data : _11416-hcd-0-0-.exe
Object : c:\windows\coder\
FileSize : 30 KB
FileVersion : 2.2.3.253
ProductVersion : 3.0.0.0
FileDescription : Anw
Created on : 28-2-2004 12:36:38
Last accessed : 7-4-2004 17:55:23
Last modified : 28-2-2004 12:40:02
Conditional scan result:
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 13
Objects found so far: 29
20:24:13 Scan complete
Summary of this scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Total scanning time :00:00:29:484
Objects scanned :30248
Objects identified :29
Objects ignored :0
New objects :29