![]() |
|
#1
| |||
| |||
| Hi guys .. Ik opende een e-mail en kreeg een hit met Antivirus XP 2008 virus. Cant get rid of it. Alle hulp zeer op prijs gesteld .. |
|
#3
| |||
| |||
| Sorry mate I dont begrijpen .. Wat wil je dat ik te maken met dit alles? |
|
#4
| ||||||||||||
| ||||||||||||
| Neem de tijd om het te lezen en vervolgens voert u de software en na de log-bestanden, zodat we kunnen zien wat er aan de hand is met uw PC.
__________________
Mijn Systeem: Hybr! D
|
|
#5
| |||
| |||
| Heres de logs: SUPERAntiSpyware Scan Log http://www.superantispyware.com Gegenereerd 07.05.2008 op 05:20 PM Toepassing Versie: 4.15.1000 Core Rules Database Version: 3497 Trace Rules Database Version: 1488 Scan type: Quick Scan Totaal Scan tijd: 00:10:14 Geheugen objecten gescand: 268 Geheugen bedreigingen gedetecteerd: 1 Register-items gescand: 407 Griffie bedreigingen gedetecteerd: 26 Bestand objecten gescand: 6977 Bestand bedreigingen ontdekt: 175 Rogue.AntiVirus XP 2008 C: \ PROGRAM FILES \ RHCPV6J0EREL \ RHCPV6J0EREL.EXE C: \ PROGRAM FILES \ RHCPV6J0EREL \ RHCPV6J0EREL.EXE C: \ Documents and Settings \ All Users \ Start Menu \ Programs \ Antivirus XP 2008 \ Antivirus XP 2008.lnk C: \ Documents and Settings \ All Users \ Start Menu \ Programs \ Antivirus XP 2008 \ How to Register Antivirus XP 2008.lnk C: \ Documents and Settings \ All Users \ Start Menu \ Programs \ Antivirus XP 2008 \ License Agreement.lnk C: \ Documents and Settings \ All Users \ Start Menu \ Programs \ Antivirus XP 2008 \ Register Antivirus XP 2008.lnk C: \ Documents and Settings \ All Users \ Start Menu \ Programs \ Antivirus XP 2008 \ Uninstall.lnk C: \ Documents and Settings \ All Users \ Start Menu \ Programs \ Antivirus XP 2008 C: \ AA \ RHCPV6J0EREL \ RHCPV6J0EREL.EXE Rogue.Dropper / Gen [lphctv6j0erel] C: \ WINDOWS \ SYSTEM32 \ LPHCTV6J0EREL.EXE C: \ WINDOWS \ SYSTEM32 \ LPHCTV6J0EREL.EXE Adware.Tracking Cookie C: \ Documents and Settings \ Danny \ Cookies \ danny @ portie-sys [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ burstnet [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@media.adrevolver [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ clickbank [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ advertpro [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@e-2dj6wjnywnc5eeo.stats.esomniture [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ tribalfusion [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@adserver.mediarun [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ 192 [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ adviva [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@ehg-mgnlimited.hitbox [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ sex-video [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ Mediaplex [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@stat.onestat [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ adrevenue [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@ads.videhost [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@ads.pugetsoundsoftwar e [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ reclame [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ dubbelklik [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@www.burstnet [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@tracking.summitmedia. CO [1]. txt C: \ Documents and Settings \ Danny \ Cookies \ danny@bs.serving-sys [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ tacoda [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ s [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ Kontera [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@data.coremetrics [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ questionmarket [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ roiservice [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ adbrite [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@counter.hitslink [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@adserving.muppetism [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ cgi-bin [4]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@vhost.oddcast [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@rotator.adjuggler [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@s1.trafficmaxx [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@www.stilemedia [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@ads.ookla [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ neocounter2 [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@ad1.doublepimp [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@te.kontera [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ 9167811 [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ adrevolver [3]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ IndexTools [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ sexyandshocking [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ yadro [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@w00tpublishers.wootme dia [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@dynamic.media.adrevol ver [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@e-2dj6wfkokkcjcao.stats.esomniture [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ atwola [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ Zedo [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ adecn [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@mobilefun.112.2o7 [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@m1.webstats.motigo [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ adrevolver [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ 1068755026 [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ specificclick [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ firstchoice [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ 2o7 [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ TradeDoubler [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@ads.techguy [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ adultadworld [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@ehg-bestbuy.hitbox [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ firstchoice [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@ehg-twi.hitbox [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@ad.yieldmanager [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ revsci [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@statse.webtrendslive [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@exchange.ggmedia [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ adlegend [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ cgi-bin [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@shopping.112.2o7 [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@ehg-iwantoneofthose.hitbox [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@ads.digitalrock.co [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ 63701567 [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ overture [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@ad1.clickhype [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ a [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ bluestreak [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ StatCounter [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ atdmt [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@ads.pubmatic [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ 247realmedia [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@avgtechnologies.112.2 O7 [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ Bravenet [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@heavycom.122.2o7 [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@stat.dealtime [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@adopt.euroclick [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@server.iad.liveperson [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ fastclick [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ statief [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ adtech [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ verbeteren [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@ehg-systemax.hitbox [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ stilemedia [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ gostats [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@network-ca.247realmedia [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ hitbox [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ AdRotator [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ 1048893890 [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ cgi-bin [3]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@www.clash-media [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny @ indexstats [2]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@test.coremetrics [1]. Txt C: \ Documents and Settings \ Danny \ Cookies \ danny@eas.apm.emediate [1]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny @ adtech [2]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny@ehg-iwantoneofthose.hitbox [1]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny @ Sextracker [1]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny@ad.yieldmanager [1]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny@metacafe.122.2o7 [1]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny@stat.onestat [2]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny@counter4.sextracker [1]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny @ dubbelklik [1]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny @ atdmt [2]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny@as1.falkag [1]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny@hg1.hitbox [1]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny@c1.zedo [1]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny@counter13.sextracker [1]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny@counter15.sextracker [1]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny @ hitbox [2]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny @ adrevolver [2]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny @ adrevolver [1]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny @ Zedo [2]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny @ targetnet [1]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny@adopt.hbmediapro [2]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny @ 2o7 [1]. Txt C: \ Documents and Settings \ Danny \ Local Settings \ Temp \ Cookies \ danny @ atwola [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@stats.searchtrack [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ atdmt [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ vijftien [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@www.fifteen [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@e-2dj6wflisidjkko.stats.esomniture [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ adtech [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@marksandspencer.122 ,2 O7 [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ adrevolver [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@perf.overture [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ windowsmedia [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ StatCounter [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@msnportal.112.2o7 [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ rekeningen [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@e-2dj6wflyckcjabo.stats.esomniture [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@ehg-debenhams.hitbox [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@paypal.112.2o7 [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@tracker.roitesting [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ Bravenet [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@adopt.euroclick [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ indexstats [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@data4.perf.overture [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@bs.serving-sys [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ revsci [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ Mediaplex [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@etype.adbureau [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@112.2o7 [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ hitbox [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@ehg-bskyb.hitbox [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@ads.telegraph.co [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@statse.webtrendsliv e [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ questionmarket [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ portie-sys [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ TradeDoubler [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ IndexTools [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ 2o7 [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ reclame [2]. Txt Rogue.AntiSpywareExpert HKLM \ SYSTEM \ CurrentControlSet \ Enum \ Root \ LEGACY_CBE VTSVC HKLM \ SYSTEM \ CurrentControlSet \ Enum \ Root \ LEGACY_CBE VTSVC # NextInstance HKLM \ SYSTEM \ CurrentControlSet \ Enum \ Root \ LEGACY_CBE VTSVC \ 0000 HKLM \ SYSTEM \ CurrentControlSet \ Enum \ Root \ LEGACY_CBE VTSVC \ 0000 # Service HKLM \ SYSTEM \ CurrentControlSet \ Enum \ Root \ LEGACY_CBE VTSVC \ 0000 # Legacy HKLM \ SYSTEM \ CurrentControlSet \ Enum \ Root \ LEGACY_CBE VTSVC \ 0000 # ConfigFlags HKLM \ SYSTEM \ CurrentControlSet \ Enum \ Root \ LEGACY_CBE VTSVC \ 0000 # Class HKLM \ SYSTEM \ CurrentControlSet \ Enum \ Root \ LEGACY_CBE VTSVC \ 0000 # ClassGUID HKLM \ SYSTEM \ CurrentControlSet \ Enum \ Root \ LEGACY_CBE VTSVC \ 0000 # DeviceDesc HKLM \ SYSTEM \ CurrentControlSet \ Enum \ Root \ LEGACY_CBE VTSVC \ 0000 \ Control HKLM \ SYSTEM \ CurrentControlSet \ Enum \ Root \ LEGACY_CBE VTSVC \ 0000 \ Control # ActiveService HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc # Ty pe HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc # St kunst HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc # Er rorControl HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc # Im agePath HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc # Di splayName HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc # Ob jectName HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc # Op t HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc \ Se curity HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc \ Se curity # Veiligheid HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc \ En uhm HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc \ En um # 0 HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc \ En um # Graaf HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc \ En um # NextInstance NotHarmful.Sysinternals Bluescreen Screensaver C: \ WINDOWS \ SYSTEM32 \ BLPHCTV6J0EREL.SCR Trojan.Unclassified / CBEvtSvc C: \ WINDOWS \ SYSTEM32 \ CBEVTSVC.EXE C: \ WINDOWS \ Prefetch \ CBEVTSVC.EXE-2F4C36CD.pf Trojan.Unknown Oorsprong C: \ WINDOWS \ SYSTEM32 \ PHCTV6J0EREL.BMP Malwarebytes' Anti-Malware 1.19 Database versie: 924 Windows 5.1.2600 Service Pack 3 19:22:42 05/07/2008 mbam-log-7-5-2008 (19-22-42). txt Scan type: Volledige Scan (C: \ | D: \ | E: \ |) Objecten gescand: 113635 De verstreken tijd: 42 minuut (s), 4 seconde (n) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Geïnfecteerde bestanden: 4 Memory Processes Infected: (Geen kwaadaardige items gedetecteerd) Memory Modules Infected: (Geen kwaadaardige items gedetecteerd) Registry Keys Infected: HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Software Notifier (Rogue.Multiple) -> quarantaine en verwijderd. Registry Values Infected: (Geen kwaadaardige items gedetecteerd) Registry Data Items Infected: HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curre ntVersion \ Policies \ System \ NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> quarantaine en verwijderd. HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curre ntVersion \ Policies \ System \ NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> quarantaine en verwijderd. Folders Infected: (Geen kwaadaardige items gedetecteerd) Geïnfecteerde bestanden: C: \ System Volume Information \ _restore (CB12E2D1-8CFA-4FCC-A08D-7A3A985B54E4) \ RP2 \ A0000029.exe (Trojan.Downloader) -> quarantaine en verwijderd. C: \ System Volume Information \ _restore (CB12E2D1-8CFA-4FCC-A08D-7A3A985B54E4) \ RP2 \ A0000047.dll (Rogue.AntivirusXP2008) -> quarantaine en verwijderd. C: \ System Volume Information \ _restore (CB12E2D1-8CFA-4FCC-A08D-7A3A985B54E4) \ RP4 \ A0000262.exe (Trojan.Downloader) -> quarantaine en verwijderd. C: \ System Volume Information \ _restore (CB12E2D1-8CFA-4FCC-A08D-7A3A985B54E4) \ RP4 \ A0000485.dll (Rogue.AntivirusXP2008) -> quarantaine en verwijderd. JavaRa 1,08 Verwijdering Log.Report volgt na regel .------------------------------------ De JavaRa verwijderen is gestart op zaterdag jul 05 19:49:54 2008 Gevonden en verwijderd: C: \ Program Files \ Java \ jre1.6.0_05Found en verwijderd: SOFTWARE \ Javasoft \ Java Runtime Environment \ 1.4Found en verwijderd: SOFTWARE \ Classes \ JavaWebStart.isInstalled.1.5.0.0F OUND en verwijderd: Software \ Javasoft \ Java2D \ 1.5.0_02Found en verwijderd: Software \ Javasoft \ Java2D \ 1.5.0_04Found en verwijderd: Software \ Javasoft \ Java2D \ 1.5.0_06Found en verwijderd: Software \ Javasoft \ Java2D \ 1.5.0_09Found en verwijderd: Software \ Javasoft \ Java2D \ 1.5.0_10Found en verwijderd: Software \ Javasoft \ Java2D \ 1.5.0_11Found en verwijderd: SOFTWARE \ Classes \ JavaPlugin.150_02Found en verwijderd: SOFTWARE \ Classes \ JavaPlugin.150_04Found en verwijderd: SOFTWARE \ Classes \ JavaPlugin.150_06Found en verwijderd: SOFTWARE \ Classes \ JavaPlugin.150_09Found en verwijderd: SOFTWARE \ Classes \ JavaPlugin.150_10--------------------------------- --- Finished rapportage. Thanks guys |
|
#6
| |||
| |||
| Moeten de HijackThis log nu. |
|
#7
| |||
| |||
| Oeps sorry. Hier is het: Logbestand van Trend Micro HijackThis v2.0.2 Scan opgeslagen om 20:24:21 op 05.07.2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Draaiende processen: C: \ WINDOWS \ System32 \ Smss.exe C: \ WINDOWS \ system32 \ winlogon.exe C: \ WINDOWS \ system32 \ Services.exe C: \ WINDOWS \ system32 \ lsass.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ System32 \ svchost.exe C: \ WINDOWS \ system32 \ Spoolsv.exe C: \ WINDOWS \ System32 \ svchost.exe C: \ Program Files \ CA \ eTrust Antivirus \ InoRpc.exe C: \ Program Files \ CA \ eTrust Antivirus \ InoRT.exe C: \ Program Files \ CA \ eTrust Antivirus \ InoTask.exe C: \ Program Files \ SPAMfighter \ sfus.exe C: \ WINDOWS \ explorer.exe C: \ WINDOWS \ AGRSMMSG.exe C: \ WINDOWS \ System32 \ OSD.EXE C: \ WINDOWS \ system32 \ SB.exe C: \ Program Files \ Synaptics \ SynTP \ SynTPLpr.exe C: \ Program Files \ Synaptics \ SynTP \ Syntpenh.exe C: \ PROGRA ~ 1 \ CA \ eTrust ~ 1 \ realmon.exe C: \ Program Files \ QuickTime \ qttask.exe C: \ Program Files \ iTunes \ iTunesHelper.exe C: \ Program Files \ MusicMatch \ MusicMatch Jukebox \ mmtask.exe C: \ Program Files \ iPod \ bin \ iPodService.exe C: \ Program Files \ SPAMfighter \ SFAgent.exe C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe C: \ WINDOWS \ system32 \ rundll32.exe C: \ Program Files \ Java \ jre1.6.0_06 \ bin \ jusched.exe C: \ Program Files \ Messenger \ msmsgs.exe C: \ Program Files \ Verenigd Alerts \ UnitedAlerts.exe C: \ Program Files \ Google \ GoogleToolbarNotifier \ GoogleToolbarNo tifier.exe C: \ Program Files \ DNA \ btdna.exe C: \ Program Files \ Windows Media Player \ WMPNSCFG.exe C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe C: \ WINDOWS \ system32 \ sistray.exe C: \ Program Files \ MSN Toolbar Suite \ DS \ 02.05.0001.1119 \ nl-nl \ bin \ WindowsSearch.exe C: \ Program Files \ MSN Toolbar Suite \ DS \ 02.05.0001.1119 \ nl-nl \ bin \ WindowsSearchIndexer.exe C: \ Program Files \ Internet Explorer \ iexplore.exe C: \ Program Files \ WinZip \ WZQKPICK.EXE C: \ WINDOWS \ system32 \ wuauclt.exe C: \ Program Files \ Internet Explorer \ iexplore.exe C: \ Program Files \ MSN Toolbar Suite \ DS \ 02.05.0001.1119 \ nl-nl \ bin \ WindowsSearchFilter.exe C: \ Program Files \ Trend Micro \ HijackThis \ sniper.exe R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://news.bbc.co.uk/sport1/hi/football/default.stm R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.toysrus.co.uk/ R1 - HKCU \ Software \ Microsoft \ Internet Connection Wizard, ShellNext = http://www.toysrus.co.uk/ R3 - URLSearchHook: ICQ Toolbar - (855F3B16-6D32-4fe6-8A56-BBB695989046) - C: \ Program Files \ ICQToolbar \ toolbaru.dll (bestand ontbreekt) O2 - BHO: AcroIEHlprObj Class - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Adobe \ Acrobat 6.0 \ Reader \ ActiveX \ AcroIEHelper.dll O2 - BHO: RealPlayer Download and Record Plugin voor Internet Explorer - (3049C3E9-B461-4BC5-8870-4C09146192CA) - C: \ Program Files \ Real \ RealPlayer \ rpbrowserrecordplugin.dll O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.6.0_06 \ bin \ ssv.dll O2 - BHO: Google Toolbar Helper - (AA58ED58-01DD-4d91-8333-CF10577473F7) - c: \ Program Files \ Google \ googletoolbar3.dll O2 - BHO: Google Toolbar Notifier BHO - (AF69DE43-7D58-4638-B6FA-CE66B5AD205D) - C: \ Program Files \ Google \ GoogleToolbarNotifier \ 3.0.1225.9868 \ s wg.dll O2 - BHO: MSN Search Toolbar Helper - (BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0) - C: \ Program Files \ MSN Toolbar Suite \ TB \ 02.05.0000.1082 \ nl-nl \ msntb.dll O3 - Toolbar: ICQ Toolbar - (855F3B16-6D32-4fe6-8A56-BBB695989046) - C: \ Program Files \ ICQToolbar \ toolbaru.dll (bestand ontbreekt) O3 - Toolbar: MSN Search Toolbar - (BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0) - C: \ Program Files \ MSN Toolbar Suite \ TB \ 02.05.0000.1082 \ nl-nl \ msntb.dll O3 - Toolbar: & Google - (2318C2B1-4965-11D4-9B18-009027A5CD4F) - c: \ Program Files \ Google \ googletoolbar3.dll O4 - HKLM \ .. \ Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM \ .. \ Run: [OSD]% SystemRoot% \ System32 \ OSD.EXE O4 - HKLM \ .. \ Run: [SB] C: \ WINDOWS \ system32 \ SB.exe O4 - HKLM \ .. \ Run: [SynTPLpr] C: \ Program Files \ Synaptics \ SynTP \ SynTPLpr.exe O4 - HKLM \ .. \ Run: [SynTPEnh] C: \ Program Files \ Synaptics \ SynTP \ Syntpenh.exe O4 - HKLM \ .. \ Run: [SiSUSBRG] C: \ WINDOWS \ SiSUSBrg.exe O4 - HKLM \ .. \ Run: [NeroFilterCheck] C: \ WINDOWS \ system32 \ NeroCheck.exe O4 - HKLM \ .. \ Run: [Realtime Monitor] C: \ PROGRA ~ 1 \ CA \ eTrust ~ 1 \ realmon.exe-s O4 - HKLM \ .. \ Run: [UserFaultCheck]% systemroot% \ system32 \ dumprep 0-u O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe"-atboottime O4 - HKLM \ .. \ Run: [iTunesHelper] "C: \ Program Files \ iTunes \ iTunesHelper.exe" O4 - HKLM \ .. \ Run: [SiSPower] Rundll32.exe SiSPower.dll, ModeAgent O4 - HKLM \ .. \ Run: [mmtask] "C: \ Program Files \ MusicMatch \ MusicMatch Jukebox \ mmtask.exe" O4 - HKLM \ .. \ Run: [SPAMfighter Agent] "C: \ Program Files \ SPAMfighter \ SFAgent.exe" update vertraging 60 O4 - HKLM \ .. \ Run: [TkBellExe] "C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe"-osboot O4 - HKLM \ .. \ Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,, BluetoothAuthenticationAgent O4 - HKLM \ .. \ Run: [SMrhcpv6j0erel] C: \ Program Files \ rhcpv6j0erel \ rhcpv6j0erel.exe O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre1.6.0_06 \ bin \ jusched.exe" O4 - HKCU \ .. \ Run: [msmsgs] "C: \ Program Files \ Messenger \ msmsgs.exe" / achtergrond O4 - HKCU \ .. \ Run: [Verenigde Alerts] C: \ Program Files \ Verenigde Alerts \ UnitedAlerts.exe O4 - HKCU \ .. \ Run: [SWG] C: \ Program Files \ Google \ GoogleToolbarNotifier \ GoogleToolbarNo tifier.exe O4 - HKCU \ .. \ Run: [BitTorrent DNA] "C: \ Program Files \ DNA \ btdna.exe" O4 - HKCU \ .. \ Run: [WMPNSCFG] C: \ Program Files \ Windows Media Player \ WMPNSCFG.exe O4 - HKCU \ .. \ Run: [SUPERAntiSpyware] C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe O4 - HKUS \ S-1-5-18 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe (User 'SYSTEM') O4 - HKUS \. DEFAULT \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe (User 'Default user') O4 - Global Startup: Microsoft Office.lnk = C: \ Program Files \ Microsoft Office \ Office10 \ OSA.EXE O4 - Global Startup: Utility Tray.lnk = C: \ WINDOWS \ system32 \ sistray.exe O4 - Global Startup: Windows Desktop Search.lnk = C: \ Program Files \ MSN Toolbar Suite \ DS \ 02.05.0001.1119 \ nl-nl \ bin \ WindowsSearch.exe O4 - Global Startup: WinZip Quick Pick.lnk = C: \ Program Files \ WinZip \ WZQKPICK.EXE O8 - Extra context menu item: & Google Search - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: & ICQ Toolbar Search - res: / / C: \ Program Files \ ICQToolbar \ toolbaru.dll / SEARCH.HTML O8 - Extra context menu item: & MSN Search - res: / / C: \ Program Files \ MSN Toolbar Suite \ TB \ 02.05.0000.1082 \ nl-nl \ msntb.dll / search.htm O8 - Extra context menu item: Backward Links - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E & xporteren naar Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ MICROS ~ 3 \ Office10 \ EXCEL.EXE/3000 O8 - Extra context menu item: Open in new background tab - res: / / C: \ Program Files \ MSN Toolbar Suite \ TAB \ 02.05.0001.1119 \ nl-nl \ msntabres.dll/229? 4f61d6b2c8414b81896dc6b3a393b615 O8 - Extra context menu item: Openen in nieuw foreground tab - res: / / C: \ Program Files \ MSN Toolbar Suite \ TAB \ 02.05.0001.1119 \ nl-nl \ msntabres.dll/230? 4f61d6b2c8414b81896dc6b3a393b615 O8 - Extra context menu item: Gelijkwaardige pagina's - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Vertalen naar het Engels - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (geen naam) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_06 \ bin \ ssv.dll O9 - Extra 'Tools' MENUITEM: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_06 \ bin \ ssv.dll O9 - Extra button: (geen naam) - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe O9 - Extra 'Tools' MENUITEM: @ xpsp3res.dll, -20001 - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe O9 - Extra button: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe O9 - Extra 'Tools' MENUITEM: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe O9 - Extra knop: Medion-UK - (CE67CBC2-5CCB-4FC4-BA83-51AE4878170C) -- http://www.medion.co.uk (file missing) (HKCU) O16 - DPF: RaptisoftGameLoader -- http://www.miniclip.com/hamsterball/...gameloader.cab O16 - DPF: (17492023-C23A-453E-A040-C7C580BBF700) (Windows Genuine Advantage Validation Tool) -- http://go.microsoft.com/fwlink/?Link...04&clcid=0x409 O16 - DPF: (1803B9EF-9905-4F34-AFC4-05D1BAB28801) (RegUserCfgUI Class) -- http://us.dl1.yimg.com/download.yaho...1/yregucfg.cab O16 - DPF: (6414512B-B978-451D-A0D8-FCFDF33E833C) (WUWebControl Class) -- http://v5.windowsupdate.microsoft.co...?1106745510172 O16 - DPF: (6E32070A-766D-4EE6-879C-DC1FA91D2FC3) (MUWebControl Class) -- http://www.update.microsoft.com/micr...?1215253028000 O16 - DPF: (B38870E4-7ECB-40DA-8C6A-595F0A5519FF) (MsnMessengerSetupDownloadControl Class) -- http://messenger.msn.com/download/Ms...Downloader.cab O16 - DPF: (BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B) (Zylom Games Player) -- http://game07.zylom.com/activex/zylomgamesplayer.cab O16 - DPF: (E8F628B5-259A-4734-97EE-BA914D7BE941) (Driver Agent ActiveX Control) -- http://driveragent.com/files/driveragent.cab O20 - Winlogon Notify:! SASWinLogon - C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.dll O23 - Service: Google Updater Service (gusvc) - Google - C: \ Program Files \ Google \ Common \ Google Updater \ GoogleUpdaterService.exe O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc - C: \ Program Files \ CA \ eTrust Antivirus \ InoRpc.exe O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc - C: \ Program Files \ CA \ eTrust Antivirus \ InoRT.exe O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc - C: \ Program Files \ CA \ eTrust Antivirus \ InoTask.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc - C: \ Program Files \ iPod \ bin \ iPodService.exe O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C: \ Program Files \ SPAMfighter \ sfus.exe -- End of file - 10438 bytes |
|
#8
| |||
| |||
| Nog werk te doen. Downloaden SDFix.exe en sla het op uw bureaublad. Dubbelklik op SDFix.exe en het zal extract de bestanden naar% systemdrive% (Station met de Windows-map, meestal C: \ SDFix) Nu dan herstart de computer in Veilige modus door het doen van de volgende:
---------- Volgende bericht toevoegen SDFix log EEN NIEUWE HijackThis log |
|
#9
| |||
| |||
| OK Volgende logs SDFix: Version 1.201 Gerund door Danny op 05.07.2008 op 21:08 Microsoft Windows XP [Version 5.1.2600] Running Van: C: \ Liedjes \ SDFix Controle Services : Restoring Default Security Values Restoring Default Hosts File Rebooten Controle Files : Geen Trojan Files Found Het verwijderen van tijdelijke bestanden ADS Check : Final Check : CatchMe 0.3.1361.2 W2K/XP/Vista - rootkit / stealth malware detector, Gmer, http://www.gmer.net Rootkit scan 2008-07-05 21:21:39 Windows 5.1.2600 Service Pack 3 NTFS het scannen van verborgen processen ... scanning hidden services & systeemcomponent ... [HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Servic es \ BTHPORT \ Parameters \ Keys \ 000c55050b1d] [HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet003 \ Services \ B THPORT \ Parameters \ Keys \ 000c55050b1d] scanning hidden registry entries ... [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Prefetcher] "TracesProcessed" = dword: 000000aa "TracesSuccessful" = dword: 00000005 het scannen van verborgen bestanden ... scannen is voltooid verborgen processen: 0 verborgen diensten: 0 verborgen bestanden: 0 Overige diensten : Authorized Application Key Export: [HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Servic es \ SharedAccess \ Parameters \ firewallpolicy \ standaard profiel \ authorizedapplications \ list] "% windir% \ \ system32 \ \ sessmgr.exe" = "% windir% \ \ systematische M32 \ \ sessmgr.exe: *: Enabled: @ Xpsp2res.dll, -22019" "C: \ \ Program Files \ \ CA \ \ eTrust Antivirus \ \ InoRpc.exe" = "C: \ \ Program Files \ \ CA \ \ eTrust Antivirus \ \ InoRpc.exe: *: Enabled: eTrust Antivirus - RPC Server " "C: \ \ Program Files \ \ CA \ \ eTrust Antivirus \ \ InocIT.exe" = "C: \ \ Program Files \ \ CA \ \ eTrust Antivirus \ \ InocIT.exe: *: Enabled: eTrust Antivirus - Local Scanner " "C: \ \ Program Files \ \ CA \ \ eTrust Antivirus \ \ Realmon.exe" = "C: \ \ Program Files \ \ CA \ \ eTrust Antivirus \ \ Realmon.exe: *: Enabled: eTrust Antivirus - Realtime monitor " "C: \ \ Program Files \ \ Messenger \ \ msmsgs.exe" = "C: \ \ Program Files \ \ Messenger \ \ msmsgs.exe: *: Enabled: Windows Messenger" "C: \ \ Program Files \ \ Verenigd Alerts \ \ UnitedAlerts.exe" = "C: \ \ Program Files \ \ Verenigd Alerts \ \ UnitedAlerts.exe" "C: \ \ Program Files \ \ ICQ \ \ Icq.exe" = "C: \ \ Program Files \ \ ICQ \ \ Icq.exe: *: Enabled: ICQ" "C: \ \ Program Files \ \ CA \ \ eTrust Antivirus \ \ Shellscn.exe" = "C: \ \ Program Files \ \ CA \ \ eTrust Antivirus \ \ Shellscn.exe: *: Enabled: Shellscn" "C: \ \ Program Files \ \ iTunes \ \ iTunes.exe" = "C: \ \ Program Files \ \ iTunes \ \ iTunes.exe: *: Enabled: iTunes" "C: \ \ StubInstaller.exe" = "C: \ \ StubInstaller.exe: *: E nabled: LimeWire swarmed installer" "C: \ \ Program Files \ \ LimeWire \ \ LimeWire.exe" = "C: \ \ Program Files \ \ LimeWire \ \ LimeWire.exe: *: Enabled: LimeWire" "C: \ \ Program Files \ \ MSN Messenger \ \ msnmsgr.exe" = "C: \ \ Program Files \ \ MSN Messenger \ \ msnmsgr.exe: *: Enabled: MSN Messenger 7.5" "C: \ \ Program Files \ \ BitTorrent_DNA \ \ dna.exe" = "C: \ \ Program Files \ \ BitTorrent_DNA \ \ dna.exe: *: Enabled: BitTorren t DNA" "C: \ \ Program Files \ \ DNA \ \ btdna.exe" = "C: \ \ Program Files \ \ DNA \ \ btdna.exe: *: Enabled: DNA" "% windir% \ \ Network Diagnostic \ \ xpnetdiag.exe" = "% windir% \ \ Network Diagnostic \ \ xpnetdiag.exe: *: Enabled: @ xpsp3res.dll, -20000" [HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Servic es \ SharedAccess \ Parameters \ firewallpolicy \ domainpr ofile \ authorizedapplications \ list] "% windir% \ \ system32 \ \ sessmgr.exe" = "% windir% \ \ systematische M32 \ \ sessmgr.exe: *: Enabled: @ Xpsp2res.dll, -22019" "C: \ \ Program Files \ \ Verenigd Alerts \ \ UnitedAlerts.exe" = "C: \ \ Program Files \ \ Verenigd Alerts \ \ UnitedAlerts.exe" "C: \ \ Program Files \ \ MSN Messenger \ \ msnmsgr.exe" = "C: \ \ Program Files \ \ MSN Messenger \ \ msnmsgr.exe: *: Enabled: MSN Messenger 7.5" "% windir% \ \ Network Diagnostic \ \ xpnetdiag.exe" = "% windir% \ \ Network Diagnostic \ \ xpnetdiag.exe: *: Enabled: @ xpsp3res.dll, -20000" Resterende bestanden : Verborgen bestanden met attributen : Woensdag 26 januari 2005 4.704 A.SH. --- "C: \ WINDOWS \ system32 \ KGyGaAvL.sys" Wo 13 jul 2005 4,348 .. SH. --- "C: \ Documents and Settings \ All Users \ DRM \ DRMv1.bak" Zaterdag 5 juli 2008 0 A.SH. --- "C: \ Documents and Settings \ All Users \ DRM \ Cache \ Indiv01.tmp" Maandag 13 juni 2005 7.420 A.. H. --- "C: \ Documents and Settings \ Rozzie \ Local Settings \ Temp \ Mar15.tmp" Maandag 13 juni 2005 7.420 A.. H. --- "C: \ Documents and Settings \ Rozzie \ Local Settings \ Temp \ Mar9.tmp" Maandag 13 juni 2005 7.420 A.. H. --- "C: \ Documents and Settings \ Rozzie \ Local Settings \ Temp \ MarA.tmp" Zaterdag 5 juli 2008 96 A.. H. --- "C: \ Documents and Settings \ All Users \ Application Data \ avg8 (2) \ scanlogs \ srmcheck.tmp" Woensdag 13 juli 2005 4.348 ... H. --- "C: \ Documents and Settings \ Danny \ Mijn documenten \ Mijn muziek \ License Backup \ drmv1key.bak" Woensdag 25 januari 2006 20 A.. H. --- "C: \ Documents and Settings \ Danny \ Mijn documenten \ Mijn muziek \ License Backup \ drmv1lic.bak" Woensdag 13 juli 2005 312 A.SH. --- "C: \ Documents and Settings \ Danny \ Mijn documenten \ Mijn muziek \ License Backup \ drmv2key.bak" Klaar! en Logbestand van Trend Micro HijackThis v2.0.2 Scan opgeslagen om 21:33:52 op 05.07.2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Draaiende processen: C: \ WINDOWS \ System32 \ Smss.exe C: \ WINDOWS \ system32 \ winlogon.exe C: \ WINDOWS \ system32 \ Services.exe C: \ WINDOWS \ system32 \ lsass.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ System32 \ svchost.exe C: \ WINDOWS \ system32 \ Spoolsv.exe C: \ WINDOWS \ System32 \ svchost.exe C: \ Program Files \ CA \ eTrust Antivirus \ InoRpc.exe C: \ Program Files \ CA \ eTrust Antivirus \ InoRT.exe C: \ Program Files \ CA \ eTrust Antivirus \ InoTask.exe C: \ Program Files \ SPAMfighter \ sfus.exe C: \ WINDOWS \ explorer.exe C: \ WINDOWS \ AGRSMMSG.exe C: \ WINDOWS \ System32 \ OSD.EXE C: \ WINDOWS \ system32 \ SB.exe C: \ Program Files \ Synaptics \ SynTP \ SynTPLpr.exe C: \ Program Files \ Synaptics \ SynTP \ Syntpenh.exe C: \ PROGRA ~ 1 \ CA \ eTrust ~ 1 \ realmon.exe C: \ Program Files \ QuickTime \ qttask.exe C: \ Program Files \ iTunes \ iTunesHelper.exe C: \ Program Files \ MusicMatch \ MusicMatch Jukebox \ mmtask.exe C: \ Program Files \ iPod \ bin \ iPodService.exe C: \ Program Files \ SPAMfighter \ SFAgent.exe C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe C: \ WINDOWS \ system32 \ rundll32.exe C: \ Program Files \ Java \ jre1.6.0_06 \ bin \ jusched.exe C: \ Program Files \ Messenger \ msmsgs.exe C: \ Program Files \ Verenigd Alerts \ UnitedAlerts.exe C: \ Program Files \ Google \ GoogleToolbarNotifier \ GoogleToolbarNo tifier.exe C: \ Program Files \ DNA \ btdna.exe C: \ WINDOWS \ system32 \ wuauclt.exe C: \ Program Files \ Windows Media Player \ WMPNSCFG.exe C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe C: \ WINDOWS \ system32 \ sistray.exe C: \ WINDOWS \ system32 \ msiexec.exe C: \ Program Files \ MSN Toolbar Suite \ DS \ 02.05.0001.1119 \ nl-nl \ bin \ WindowsSearch.exe C: \ Program Files \ WinZip \ WZQKPICK.EXE C: \ Program Files \ MSN Toolbar Suite \ DS \ 02.05.0001.1119 \ nl-nl \ bin \ WindowsSearchIndexer.exe C: \ Program Files \ MSN Toolbar Suite \ DS \ 02.05.0001.1119 \ nl-nl \ bin \ WindowsSearchFilter.exe C: \ Program Files \ Internet Explorer \ iexplore.exe C: \ Program Files \ Trend Micro \ HijackThis \ sniper.exe R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://news.bbc.co.uk/sport1/hi/football/default.stm R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.toysrus.co.uk/ R1 - HKCU \ Software \ Microsoft \ Internet Connection Wizard, ShellNext = http://www.toysrus.co.uk/ R3 - URLSearchHook: ICQ Toolbar - (855F3B16-6D32-4fe6-8A56-BBB695989046) - C: \ Program Files \ ICQToolbar \ toolbaru.dll (bestand ontbreekt) O2 - BHO: AcroIEHlprObj Class - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Adobe \ Acrobat 6.0 \ Reader \ ActiveX \ AcroIEHelper.dll O2 - BHO: RealPlayer Download and Record Plugin voor Internet Explorer - (3049C3E9-B461-4BC5-8870-4C09146192CA) - C: \ Program Files \ Real \ RealPlayer \ rpbrowserrecordplugin.dll O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.6.0_06 \ bin \ ssv.dll O2 - BHO: Google Toolbar Helper - (AA58ED58-01DD-4d91-8333-CF10577473F7) - c: \ Program Files \ Google \ googletoolbar3.dll O2 - BHO: Google Toolbar Notifier BHO - (AF69DE43-7D58-4638-B6FA-CE66B5AD205D) - C: \ Program Files \ Google \ GoogleToolbarNotifier \ 3.0.1225.9868 \ s wg.dll O2 - BHO: MSN Search Toolbar Helper - (BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0) - C: \ Program Files \ MSN Toolbar Suite \ TB \ 02.05.0000.1082 \ nl-nl \ msntb.dll O3 - Toolbar: ICQ Toolbar - (855F3B16-6D32-4fe6-8A56-BBB695989046) - C: \ Program Files \ ICQToolbar \ toolbaru.dll (bestand ontbreekt) O3 - Toolbar: MSN Search Toolbar - (BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0) - C: \ Program Files \ MSN Toolbar Suite \ TB \ 02.05.0000.1082 \ nl-nl \ msntb.dll O3 - Toolbar: & Google - (2318C2B1-4965-11D4-9B18-009027A5CD4F) - c: \ Program Files \ Google \ googletoolbar3.dll O4 - HKLM \ .. \ Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM \ .. \ Run: [OSD]% SystemRoot% \ System32 \ OSD.EXE O4 - HKLM \ .. \ Run: [SB] C: \ WINDOWS \ system32 \ SB.exe O4 - HKLM \ .. \ Run: [SynTPLpr] C: \ Program Files \ Synaptics \ SynTP \ SynTPLpr.exe O4 - HKLM \ .. \ Run: [SynTPEnh] C: \ Program Files \ Synaptics \ SynTP \ Syntpenh.exe O4 - HKLM \ .. \ Run: [SiSUSBRG] C: \ WINDOWS \ SiSUSBrg.exe O4 - HKLM \ .. \ Run: [NeroFilterCheck] C: \ WINDOWS \ system32 \ NeroCheck.exe O4 - HKLM \ .. \ Run: [Realtime Monitor] C: \ PROGRA ~ 1 \ CA \ eTrust ~ 1 \ realmon.exe-s O4 - HKLM \ .. \ Run: [UserFaultCheck]% systemroot% \ system32 \ dumprep 0-u O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe"-atboottime O4 - HKLM \ .. \ Run: [iTunesHelper] "C: \ Program Files \ iTunes \ iTunesHelper.exe" O4 - HKLM \ .. \ Run: [SiSPower] Rundll32.exe SiSPower.dll, ModeAgent O4 - HKLM \ .. \ Run: [mmtask] "C: \ Program Files \ MusicMatch \ MusicMatch Jukebox \ mmtask.exe" O4 - HKLM \ .. \ Run: [SPAMfighter Agent] "C: \ Program Files \ SPAMfighter \ SFAgent.exe" update vertraging 60 O4 - HKLM \ .. \ Run: [TkBellExe] "C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe"-osboot O4 - HKLM \ .. \ Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,, BluetoothAuthenticationAgent O4 - HKLM \ .. \ Run: [SMrhcpv6j0erel] C: \ Program Files \ rhcpv6j0erel \ rhcpv6j0erel.exe O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre1.6.0_06 \ bin \ jusched.exe" O4 - HKCU \ .. \ Run: [msmsgs] "C: \ Program Files \ Messenger \ msmsgs.exe" / achtergrond O4 - HKCU \ .. \ Run: [Verenigde Alerts] C: \ Program Files \ Verenigde Alerts \ UnitedAlerts.exe O4 - HKCU \ .. \ Run: [SWG] C: \ Program Files \ Google \ GoogleToolbarNotifier \ GoogleToolbarNo tifier.exe O4 - HKCU \ .. \ Run: [BitTorrent DNA] "C: \ Program Files \ DNA \ btdna.exe" O4 - HKCU \ .. \ Run: [WMPNSCFG] C: \ Program Files \ Windows Media Player \ WMPNSCFG.exe O4 - HKCU \ .. \ Run: [SUPERAntiSpyware] C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe O4 - HKUS \ S-1-5-18 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe (User 'SYSTEM') O4 - HKUS \. DEFAULT \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe (User 'Default user') O4 - Global Startup: Microsoft Office.lnk = C: \ Program Files \ Microsoft Office \ Office10 \ OSA.EXE O4 - Global Startup: Utility Tray.lnk = C: \ WINDOWS \ system32 \ sistray.exe O4 - Global Startup: Windows Desktop Search.lnk = C: \ Program Files \ MSN Toolbar Suite \ DS \ 02.05.0001.1119 \ nl-nl \ bin \ WindowsSearch.exe O4 - Global Startup: WinZip Quick Pick.lnk = C: \ Program Files \ WinZip \ WZQKPICK.EXE O8 - Extra context menu item: & Google Search - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: & ICQ Toolbar Search - res: / / C: \ Program Files \ ICQToolbar \ toolbaru.dll / SEARCH.HTML O8 - Extra context menu item: & MSN Search - res: / / C: \ Program Files \ MSN Toolbar Suite \ TB \ 02.05.0000.1082 \ nl-nl \ msntb.dll / search.htm O8 - Extra context menu item: Backward Links - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E & xporteren naar Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ MICROS ~ 3 \ Office10 \ EXCEL.EXE/3000 O8 - Extra context menu item: Open in new background tab - res: / / C: \ Program Files \ MSN Toolbar Suite \ TAB \ 02.05.0001.1119 \ nl-nl \ msntabres.dll/229? 4f61d6b2c8414b81896dc6b3a393b615 O8 - Extra context menu item: Openen in nieuw foreground tab - res: / / C: \ Program Files \ MSN Toolbar Suite \ TAB \ 02.05.0001.1119 \ nl-nl \ msntabres.dll/230? 4f61d6b2c8414b81896dc6b3a393b615 O8 - Extra context menu item: Gelijkwaardige pagina's - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Vertalen naar het Engels - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (geen naam) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_06 \ bin \ ssv.dll O9 - Extra 'Tools' MENUITEM: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_06 \ bin \ ssv.dll O9 - Extra button: (geen naam) - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe O9 - Extra 'Tools' MENUITEM: @ xpsp3res.dll, -20001 - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe O9 - Extra button: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe O9 - Extra 'Tools' MENUITEM: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe O9 - Extra knop: Medion-UK - (CE67CBC2-5CCB-4FC4-BA83-51AE4878170C) -- http://www.medion.co.uk (file missing) (HKCU) O16 - DPF: RaptisoftGameLoader -- http://www.miniclip.com/hamsterball/...gameloader.cab O16 - DPF: (17492023-C23A-453E-A040-C7C580BBF700) (Windows Genuine Advantage Validation Tool) -- http://go.microsoft.com/fwlink/?Link...04&clcid=0x409 O16 - DPF: (1803B9EF-9905-4F34-AFC4-05D1BAB28801) (RegUserCfgUI Class) -- http://us.dl1.yimg.com/download.yaho...1/yregucfg.cab O16 - DPF: (6414512B-B978-451D-A0D8-FCFDF33E833C) (WUWebControl Class) -- http://v5.windowsupdate.microsoft.co...?1106745510172 O16 - DPF: (6E32070A-766D-4EE6-879C-DC1FA91D2FC3) (MUWebControl Class) -- http://www.update.microsoft.com/micr...?1215253028000 O16 - DPF: (B38870E4-7ECB-40DA-8C6A-595F0A5519FF) (MsnMessengerSetupDownloadControl Class) -- http://messenger.msn.com/download/Ms...Downloader.cab O16 - DPF: (BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B) (Zylom Games Player) -- http://game07.zylom.com/activex/zylomgamesplayer.cab O16 - DPF: (E8F628B5-259A-4734-97EE-BA914D7BE941) (Driver Agent ActiveX Control) -- http://driveragent.com/files/driveragent.cab O20 - Winlogon Notify:! SASWinLogon - C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.dll O23 - Service: Google Updater Service (gusvc) - Google - C: \ Program Files \ Google \ Common \ Google Updater \ GoogleUpdaterService.exe O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc - C: \ Program Files \ CA \ eTrust Antivirus \ InoRpc.exe O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc - C: \ Program Files \ CA \ eTrust Antivirus \ InoRT.exe O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc - C: \ Program Files \ CA \ eTrust Antivirus \ InoTask.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc - C: \ Program Files \ iPod \ bin \ iPodService.exe O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C: \ Program Files \ SPAMfighter \ sfus.exe -- End of file - 10422 bytes |
|
#10
| |||
| |||
| Ik moet wat meer informatie over een paar bestanden. Na de links hier om de resultaten bij voltooid. Scan Verdachte File (s) Bezoek Virustotal (Indien meer dan een bestand moet gescand moeten worden gedaan afzonderlijk en logs geplaatst voor elk een)
Code: C: \ Program Files \ rhcpv6j0erel \ rhcpv6j0erel.exe
Code: C: \ Program Files \ Verenigd Alerts \ UnitedAlerts.exe |
![]() |
|
| Bladwijzers |
Gelijkaardige Draden | ||||
| Draad | Thread Starter | Forum | Antwoorden | Last Post |
| Kaspersky Antivirus 2009, Eset NOD32 Antivirus, McAfee VirusScan Enterprise | runoades | Virus, spyware & Security | 2 | 3rd Dec 2008 13:54 |
| AntiVirus XP 2008! | ParsleyAigh | Virus, spyware & Security | 53 | 3e Sep 2008 16:28 |
| WinPatrol 2008 | evilfantasy | Virus, spyware & Security | 0 | 25 apr 2008 16:03 |
| Wooohhhhhooooooooo !!!!!!!!!!! 2008 !!!!!!!! | cheesewheels99 | Off Topic Discussie | 4 | De 7 januari 2008 07:52 |
| Beste antivirus | Vlad | Virus, spyware & Security | 29 | 10 okt 2007 12:47 |
| Thread Tools | |
| |