PDA

View Full Version : remove saihoi



blastblast
2010-03-22, 14:02
Hello i have tried to remove saihoi with ; Spybot-S&D, RunAlyzer, RootAlyzer and Total Commander. So far no succes.

Total commander cannot find the file.
Spybot does not find it eiher.
Runalyzer finds it, but after i remove it, it comes back.
Rootalyzer does not find it.

Help me please!

Here is my log;

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:01:24, on 22-3-2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\windows\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\Common

Files\InstallShield\UpdateService\isuspm.exe
C:\windows\system32\RUNDLL32.EXE
C:\Program Files\Hard Drive

Inspector\HDInspector.exe
C:\Program Files\McAfee\Common

Framework\UdaterUI.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\McAfee\Common

Framework\McTray.exe
C:\windows\system32\ctfmon.exe
C:\PROGRA~1\WI1F86~1\MESSEN~1\msnmsgr.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Microsoft

ActiveSync\wcescomm.exe
C:\Documents and Settings\Dennis\saihoi.exe
C:\Program Files\Sweex\Installer\WINXP\SWU.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\windows\system32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\WINDOWS\system32\HDDSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common

Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\Common

Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan

Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan

Enterprise\VsTskMgr.exe
C:\Program Files\NVIDIA

Corporation\nTune\nTuneService.exe
C:\windows\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\windows\system32\svchost.exe
C:\Program Files\TomTom HOME

2\TomTomHOMEService.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Adobe\Reader

9.0\Reader\AcroRd32.exe
C:\Program Files\Safer

Networking\RunAlyzer\RunAlyzer.exe
C:\Program Files\Trend

Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet

Explorer\Main,Start Page =

http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Page_URL =

http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet

Explorer\Main,Start Page =

http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet

Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: SnagIt Toolbar Loader -

{00C6482D-C502-44C8-8409-FCE54AD9C208} -

C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll
O2 - BHO: AcroIEHelperStub -

{18DF081C-E8AD-4283-A596-FA578C2EBDC3} -

C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) -

{5C255C8A-E604-49b4-9D64-90988571CECB} - (no

file)
O2 - BHO: scriptproxy -

{7DB2D5A0-7241-4E79-B68D-6309F01C5231} -

C:\Program Files\McAfee\VirusScan

Enterprise\scriptcl.dll
O2 - BHO: Windows Live Aanmelden - Help -

{9030D464-4C02-4ABF-8ECC-5164760863C6} -

C:\Program Files\Common Files\Microsoft

Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper -

{DBC80044-A445-435b-BC74-9C25C1C588A9} -

C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl -

{E7E6F031-17CE-4C07-BC86-EABFE594F69C} -

C:\Program

Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Snagit -

{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} -

C:\Program Files\TechSmith\Snagit

9\SnagitIEAddin.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program

Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro]

"C:\Program Files\Comodo\Firewall\CPF.exe"

/background
O4 - HKLM\..\Run: [ISUSPM] "C:\Program

Files\Common

Files\InstallShield\UpdateService\isuspm.exe"

-scheduler
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE

C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HDInspector.exe] C:\Program

Files\Hard Drive Inspector\HDInspector.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program

Files\McAfee\VirusScan Enterprise\SHSTAT.EXE"

/STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program

Files\McAfee\Common Framework\UdaterUI.exe"

/StartedFromRunKey
O4 - HKLM\..\Run: [SunJavaUpdateSched]

"C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck]

%systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program

Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MSConfig]

C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe

/auto
O4 - HKCU\..\Run: [CTFMON.EXE]

C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr]

"C:\PROGRA~1\WI1F86~1\MESSEN~1\msnmsgr.exe"

/background
O4 - HKCU\..\Run: [Skype] "C:\Program

Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [H/PC Connection Agent]

"C:\Program Files\Microsoft

ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [saihoi] C:\Documents and

Settings\Dennis\saihoi.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE]

C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale

service')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE]

C:\WINDOWS\system32\CTFMON.EXE (User

'Netwerkservice')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE]

C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE]

C:\WINDOWS\system32\CTFMON.EXE (User 'Default

user')
O4 - Startup: Registration Brothers In Arms.LNK =

M:\Support\Register\RegistrationReminder.exe
O4 - Global Startup: Sweex WiFi Utility.lnk =

C:\Program Files\Sweex\Installer\WINXP\SWU.exe
O8 - Extra context menu item: E&xporteren naar

Microsoft Excel -

res://C:\PROGRA~1\MI699F~1\OFFICE11\EXCEL.EXE/300

0
O9 - Extra button: Create Mobile Favorite -

{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} -

C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) -

{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} -

C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Mobiele favorieten

maken... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F}

- C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Onderzoek -

{92780B25-18CC-41C8-B9BE-3C9C571A8263} -

C:\PROGRA~1\MI699F~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) -

{e2e2dd38-d088-4134-82b7-f2ba38496583} -

C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001

- {e2e2dd38-d088-4134-82b7-f2ba38496583} -

C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\windows\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\windows\system32\shdocvw.dll
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1}

(ewidoOnlineScan Control) -

http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}

(WUWebControl Class) -

http://www.update.microsoft.com/windowsupdate/v6/

V5Controls/en/x86/client/wuweb_site.cab?118979874

0750
O16 - DPF: {9522589E-57B9-46C5-9A77-1F1C1CCBE550}

(F-Secure Online Scanner 2.1 (CD version)) -

file:///C:/Documents%20and%20Settings/Dennis/Loca

l%20Settings/Temp/OnlineScanner/is2007ols/fscax.c

ab
O18 - Protocol: skype4com -

{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -

C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service

(aawservice) - Lavasoft - C:\Program

Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Comodo Application Agent

(CmdAgent) - COMODO - C:\Program

Files\Comodo\Firewall\cmdagent.exe
O23 - Service: getPlus(R) Helper - NOS

Microsystems Ltd. - C:\Program

Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: HDD Information Service (HDDSvc) -

AltrixSoft (http://www.altrixsoft.com/) -

C:\WINDOWS\system32\HDDSvc.exe
O23 - Service: InstallDriver Table Manager

(IDriverT) - Macrovision Corporation - C:\Program

Files\Common Files\InstallShield\Driver\11\Intel

32\IDriverT.exe
O23 - Service: Java Quick Starter

(JavaQuickStarterService) - Sun Microsystems,

Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc

Labeling Service (LightScribeService) -

Hewlett-Packard Company - C:\Program Files\Common

Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Framework Service

(McAfeeFramework) - McAfee, Inc. - C:\Program

Files\McAfee\Common

Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) -

McAfee, Inc. - C:\Program Files\McAfee\VirusScan

Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager

(McTaskManager) - McAfee, Inc. - C:\Program

Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: NMIndexingService - Nero AG -

C:\Program Files\Common

Files\Nero\Lib\NMIndexingService.exe
O23 - Service: nTune Service (nTuneService) -

NVIDIA - C:\Program Files\NVIDIA

Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service

(NVSvc) - NVIDIA Corporation -

C:\windows\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP -

C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0

(experimental) (rpcapd) - CACE Technologies, Inc.

- C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: StarWind AE Service

(StarWindServiceAE) - Unknown owner - C:\Program

Files\Alcohol Soft\Alcohol

120\StarWind\StarWindServiceAE.exe (file missing)
O23 - Service: TomTomHOMEService - TomTom -

C:\Program Files\TomTom HOME

2\TomTomHOMEService.exe
O23 - Service: Win2k3NodeDisabler - Unknown owner

- C:\Documents and

Settings\Dennis\Bureaublad\Win2k3NodeDisabler\Win

2k3NodeDisabler.exe (file missing)

--
End of file - 9852 bytes

blastblast
2010-03-22, 14:04
I used this thread to try to get rid of the saihoi (<$PROFILE>\saihoi.exe) ;

http://89.238.64.41/showthread.php?t=56244

tashi
2010-03-22, 18:41
Hello blastblast,


Posting additional comments or logs before a volunteer responds, can push you back instead of forward, because your thread ends up with a newer date. In addition helpers would think you are already being assisted because of the post count. For that reason we may merge such posts but please do not count on it.

Note: In notepad under Format, uncheck "Word Wrap" Produce all HJT logs like this, single spaced.
single-spaced - (of type or print) not having a blank space between lines. Otherwise the log is hard to read. "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Please start a new topic and provide a link back to this one. :)

Best regards