![]() |
|
#1
| |||
| |||
| Ik heb gelezen dat dit slecht is, ik heb geen Internet Explorer openen, maar het draait nog steeds in mijn Taakbeheer (I dont denk dat het hoort te zijn, in hoofdletters), is het afremmen van mijn computer. Is het een virus? spyware etc? Hoe verwijder ik het? |
|
#2
| |||
| |||
| Laat een snelle blik. Download en hernoemen HijackThis (HJT)
|
|
#3
| |||
| |||
| For some reason I cant IEXPLORE.EXE zie hier, maar het is zeker in de tm Logbestand van Trend Micro HijackThis v2.0.2 Scan opgeslagen in 7:02:55 uur, op 1.15.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Draaiende processen: C: \ WINDOWS \ System32 \ Smss.exe C: \ WINDOWS \ system32 \ winlogon.exe C: \ WINDOWS \ system32 \ Services.exe C: \ WINDOWS \ system32 \ lsass.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ System32 \ svchost.exe C: \ WINDOWS \ system32 \ Spoolsv.exe C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgamsvr.exe C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgupsvc.exe C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgemc.exe C: \ WINDOWS \ system32 \ nvsvc32.exe C: \ WINDOWS \ system32 \ PnkBstrA.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ Program Files \ Windows Live \ Messenger \ usnsvc.exe C: \ WINDOWS \ explorer.exe C: \ WINDOWS \ RTHDCPL.EXE C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgcc.exe C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ jusched.exe C: \ WINDOWS \ system32 \ wuauclt.exe C: \ WINDOWS \ system32 \ RUNDLL32.EXE C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe C: \ Program Files \ Microsoft Office \ Office12 \ GrooveMonitor.exe C: \ WINDOWS \ system32 \ LVCOMSX.EXE C: \ Program Files \ Logitech \ Video \ LogiTray.exe C: \ Program Files \ Internet Explorer \ iexplore.exe C: \ WINDOWS \ system32 \ Ctfmon.exe C: \ Program Files \ DNA \ btdna.exe C: \ Program Files \ Internet Explorer \ iexplore.exe C: \ Program Files \ Logitech \ Video \ FxSvr2.exe C: \ Program Files \ Mozilla Firefox \ firefox.exe C: \ Program Files \ Windows Media Player \ Wmplayer.exe C: \ WINDOWS \ system32 \ wuauclt.exe C: \ Program Files \ Trend Micro \ HijackThis \ sniper.exe.exe R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Search Bar = http://red.clientapps.yahoo.com/cust...search/ie.html R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.yahoo.com/ R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://www.yahoo.com R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.yahoo.com R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ SearchURL, (Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com R1 - HKCU \ Software \ Microsoft \ Internet Connection Wizard, ShellNext = http://www.yahoo.com/ O2 - BHO: Yahoo! Companion BHO - (02478D38-C3F9-4efb-9B51-7695ECA05670) - C: \ Program Files \ Yahoo! \ Companion \ installs \ CPN \ ycomp5_6_0_1.d ll O2 - BHO: Adobe PDF Reader Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Common Files \ Adobe \ Acrobat \ ActiveX \ AcroIEHelper.dll O2 - BHO: Groove GFS Browser Helper - (72853161-30C5-4D22-B7F9-0BBC1D38A37E) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ GRA8E1 ~ 1.dll O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll O2 - BHO: (geen naam) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (geen file) O2 - BHO: Windows Live Sign-in Helper - (9030D464-4C02-4ABF-8ECC-5164760863C6) - C: \ Program Files \ Common Files \ Microsoft Shared \ Windows Live \ WindowsLiveLogin.dll O3 - Toolbar: & Yahoo! Companion - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ Program Files \ Yahoo! \ Companion \ installs \ CPN \ ycomp5_6_0_1.d ll O4 - HKLM \ .. \ Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM \ .. \ Run: [SkyTel] SkyTel.EXE O4 - HKLM \ .. \ Run: [Alcmtr] ALCMTR.EXE O4 - HKLM \ .. \ Run: [AVG7_CC] C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgcc.exe / STARTUP O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ jusched.exe" O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe"-atboottime O4 - HKLM \ .. \ Run: [Adobe Reader Speed Launcher] "C: \ Program Files \ Adobe \ Reader 8.0 \ Reader \ Reader_sl.exe" O4 - HKLM \ .. \ Run: [NvCplDaemon] RUNDLL32.EXE C: \ WINDOWS \ system32 \ NvCpl.dll, NvStartup O4 - HKLM \ .. \ Run: [nwiz] nwiz.exe / install O4 - HKLM \ .. \ Run: [NvMediaCenter] RUNDLL32.EXE C: \ WINDOWS \ system32 \ NvMcTray.dll, NvTaskbarInit O4 - HKLM \ .. \ Run: [TkBellExe] "C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe"-osboot O4 - HKLM \ .. \ Run: [GrooveMonitor] "C: \ Program Files \ Microsoft Office \ Office12 \ GrooveMonitor.exe" O4 - HKLM \ .. \ Run: [LVCOMSX] C: \ WINDOWS \ system32 \ LVCOMSX.EXE O4 - HKLM \ .. \ Run: [LogitechVideoRepair] C: \ Program Files \ Logitech \ Video \ ISStart.exe O4 - HKLM \ .. \ Run: [LogitechVideoTray] C: \ Program Files \ Logitech \ Video \ LogiTray.exe O4 - HKLM \ .. \ Run: [Tweede vleermuis creatieve piek] C: \ Documents and Settings \ All Users \ Application Data \ Axis Leesmij Tweede Bat \ dode lite.exe O4 - HKCU \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe O4 - HKCU \ .. \ Run: [BitTorrent DNA] "C: \ Program Files \ DNA \ btdna.exe" O4 - HKCU \ .. \ Run: [curblicense] C: \ DOCUME ~ 1 \ Richard \ TOEPASSINGEN ~ 1 \ WAYBOW ~ 1 \ Nurb meer noun.exe O4 - HKUS \ S-1-5-19 \ .. \ Run: [AVG7_Run] C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgw.exe / RunOnce (User 'LOCAL SERVICE') O4 - HKUS \ S-1-5-20 \ .. \ Run: [AVG7_Run] C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgw.exe / RunOnce (User 'NETWORK SERVICE') O4 - HKUS \ S-1-5-18 \ .. \ Run: [AVG7_Run] C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgw.exe / RunOnce (User 'SYSTEM') O4 - HKUS \. DEFAULT \ .. \ Run: [AVG7_Run] C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgw.exe / RunOnce (User 'Default user') O8 - Extra context menu item: E & xporteren naar Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ EXCEL.EXE/3000 O9 - Extra button: (geen naam) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll O9 - Extra 'Tools' MENUITEM: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll O9 - Extra button: Verzenden naar OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ ONBttnIE.dll O9 - Extra 'Tools' MENUITEM: S & einde aan OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ ONBttnIE.dll O9 - Extra button: Onderzoek - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ REFIEBAR.DLL O9 - Extra button: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe O9 - Extra 'Tools' MENUITEM: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe O16 - DPF: (6414512B-B978-451D-A0D8-FCFDF33E833C) (WUWebControl Class) -- http://www.update.microsoft.com/wind...?1197308803562 O16 - DPF: (C3F79A2B-B9B4-4A66-B012-3EE46475B072) (MessengerStatsClient Class) -- http://messenger.zone.msn.com/binary...t.cab56907.cab O18 - Protocol: grooveLocalGWS - (88FED34C-F0CA-4636-A375-3CB6248B04CD) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ GR99D3 ~ 1.dll O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - Grisoft, sro - C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - Grisoft, sro - C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - Grisoft, sro - C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgemc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C: \ WINDOWS \ system32 \ nvsvc32.exe O23 - Service: PnkBstrA - Onbekende eigenaar - C: \ WINDOWS \ system32 \ PnkBstrA.exe -- End of file - 7104 bytes |
|
#4
| |||
| |||
| Ja dat heb slecht infecties. Stap 1 Please download NoLop.exe naar het bureaublad:
--------------- Stap 2 Downloaden SUPERAntispyware Free Edition (SAS)
Stap 3 Voer een nieuwe HijackThis scan en post de log ---------- Volgende bericht gelieve toe te voegen. De inhoud van C: \ NoLop.log SuperAntispyware log Nieuw HijackThis log Het kan meer dan een bericht te krijgen van de logs geplaatst. Dit is prima als dat nodig is. |
|
#5
| |||
| |||
| Nolop log: NoLop! Aanmelden bij Skate_Punk_21 Fix loopt uit: C: \ Program Files \ Mozilla Firefox [1.15.2008] [7:34:10 PM] --- Infectie Files Found/Removed--- C: \ WINDOWS \ taken \ ADB7C425918477B9.job Begin Removal ... Rebooten ... Het verwijderen van Lop de resterende bestanden / mappen ... Bezig met bewerken van Register ... ** Fix Complete! ** --- Aanbieding AppData submappen --- C: \ Documents and Settings \ All Users \ Application Data \ Adobe C: \ Documents and Settings \ All Users \ Application Data \ Apple C: \ Documents and Settings \ All Users \ Application Data \ Apple Computer C: \ Documents and Settings \ All Users \ Application Data \ Avg7 C: \ Documents and Settings \ All Users \ Application Data \ Axis Leesmij Tweede Bat C: \ Documents and Settings \ All Users \ Application Data \ Grisoft C: \ Documents and Settings \ All Users \ Application Data \ Messenger Plus! - Lege map C: \ Documents and Settings \ All Users \ Application Data \ Microsoft C: \ Documents and Settings \ All Users \ Application Data \ Microsoft Help C: \ Documents and Settings \ All Users \ Application Data \ Nvidia - lege map C: \ Documents and Settings \ All Users \ Application Data \ Sony C: \ Documents and Settings \ All Users \ Application Data \ Temp - lege map C: \ Documents and Settings \ All Users \ Application Data \ Windows Genuine Advantage C: \ Documents and Settings \ All Users \ Application Data \ Wlinstaller C: \ Documents and Settings \ Default User \ Application Data \ Microsoft C: \ Documents and Settings \ LocalService \ Application Data \ Avg7 - lege map C: \ Documents and Settings \ LocalService \ Application Data \ Microsoft C: \ Documents and Settings \ LocalService \ Application Data \ Xfire - lege map C: \ Documents and Settings \ NetworkService \ Application Data \ Microsoft C: \ Documents and Settings \ NetworkService \ Application Data \ Xfire - lege map C: \ Documents and Settings \ Richard \ Application Data \ Adobe C: \ Documents and Settings \ Richard \ Application Data \ Apple Computer C: \ Documents and Settings \ Richard \ Application Data \ Avg7 C: \ Documents and Settings \ Richard \ Application Data \ Bittorrent C: \ Documents and Settings \ Richard \ Application Data \ Divx C: \ Documents and Settings \ Richard \ Application Data \ Dna C: \ Documents and Settings \ Richard \ Application Data \ Dvdcss C: \ Documents and Settings \ Richard \ Application Data \ Fotowire C: \ Documents and Settings \ Richard \ Application Data \ gtk-2.0 C: \ Documents and Settings \ Richard \ Application Data \ Identities C: \ Documents and Settings \ Richard \ Application Data \ InstallShield C: \ Documents and Settings \ Richard \ Application Data \ Macromedia C: \ Documents and Settings \ Richard \ Application Data \ Microsoft C: \ Documents and Settings \ Richard \ Application Data \ Monkeyjam C: \ Documents and Settings \ Richard \ Application Data \ Mozilla C: \ Documents and Settings \ Richard \ Application Data \ Publish Providers - lege map C: \ Documents and Settings \ Richard \ Application Data \ Real C: \ Documents and Settings \ Richard \ Application Data \ SmartFTP C: \ Documents and Settings \ Richard \ Application Data \ Sony C: \ Documents and Settings \ Richard \ Application Data \ Sony Setup C: \ Documents and Settings \ Richard \ Application Data \ zondag C: \ Documents and Settings \ Richard \ Application Data \ Systemrequirementslab C: \ Documents and Settings \ Richard \ Application Data \ vlc C: \ Documents and Settings \ Richard \ Application Data \ Waybowsreal C: \ Documents and Settings \ Richard \ Application Data \ Xfire Super anti spyware log: SUPERAntiSpyware Scan Log http://www.superantispyware.com Gegenereerd 01.15.2008 op 08:32 PM Toepassing Versie: 3-9-1008 Core Rules Database Version: 3380 Trace Rules Database Version: 1374 Scan type: Volledige Scan Totaal Scan tijd: 00:46:41 Geheugen objecten gescand: 385 Geheugen bedreigingen gedetecteerd: 0 Register-items gescand: 5574 Griffie bedreigingen gedetecteerd: 0 Bestand objecten gescand: 40825 Bestand bedreigingen gedetecteerd: 66 Adware.Tracking Cookie C: \ Documents and Settings \ Richard \ Cookies \ richard @ cassave [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ fastclick [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@server.lon.livepe rson [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ casalemedia [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@www.ppctracking [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@adopt.euroclick [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ portie-sys [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@www.adserver5 [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ carphonewarehouse .112.2 O7 [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@m1.webstats.motig o [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@msnportal.112.2o7 [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@ads.vlaze [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@reduxads.valuead [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@rotator.adjuggler [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ 888 [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ uk [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ 247realmedia [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@adfarm1.adition [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@login.tracking101 [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@stats.channel4 [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ azjmp [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@partygaming.122.2 O7 [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ dubbelklik [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ reclame [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@bs.serving-sys [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ bluestreak [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@anad.tacoda [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@ehg-youtube.hitbox [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@banner.carnavalca Sino [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ 60915153 [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@tracking.foxnews [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@ad.yieldmanager [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@ads.veoh [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@www.clash-media [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@a.websponsors [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@banner.casino.bla ckpoolclub.co [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@prospect.adbureau [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ adrevolver [3]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@banner.bingo.blac kpoolclub.co [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@media.adrevolver [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ cgi-bin [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ p [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ Lycos-de [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ tribalfusion [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@eas.apm.emediate [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@anat.tacoda [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@ad.zanox [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ netto-ontvangsten [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ hitbox [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ revsci [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@statse.webtrendsl ive [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ questionmarket [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@ads.addynamix [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ 2o7 [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ pacificpoker [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ Mediaplex [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@media.xfire [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ atdmt [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ apmebf [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ PartyPoker [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ Zedo [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ adrevolver [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ TradeDoubler [2]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard@adserver.filefron t [1]. Txt C: \ Documents and Settings \ Richard \ Cookies \ richard @ a [1]. Txt Adware.180solutions/ZangoSearch C: \ System Volume Information \ _restore (39B7D61A-C471-441E-B6D4-5930E1D582CD) \ RP37 \ A0003673.EXE Hi jack log: Logbestand van Trend Micro HijackThis v2.0.2 Scan opgeslagen in 8:38:58 uur, op 1.15.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Draaiende processen: C: \ WINDOWS \ System32 \ Smss.exe C: \ WINDOWS \ system32 \ winlogon.exe C: \ WINDOWS \ system32 \ Services.exe C: \ WINDOWS \ system32 \ lsass.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ System32 \ svchost.exe C: \ WINDOWS \ system32 \ Spoolsv.exe C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgamsvr.exe C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgupsvc.exe C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgemc.exe C: \ WINDOWS \ system32 \ nvsvc32.exe C: \ WINDOWS \ system32 \ PnkBstrA.exe C: \ WINDOWS \ explorer.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ RTHDCPL.EXE C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgcc.exe C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ jusched.exe C: \ Program Files \ Adobe \ Reader 8.0 \ Reader \ Reader_sl.exe C: \ WINDOWS \ system32 \ RUNDLL32.EXE C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe C: \ Program Files \ Microsoft Office \ Office12 \ GrooveMonitor.exe C: \ WINDOWS \ system32 \ LVCOMSX.EXE C: \ Program Files \ Logitech \ Video \ LogiTray.exe C: \ WINDOWS \ system32 \ Ctfmon.exe C: \ Program Files \ DNA \ btdna.exe C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe C: \ Program Files \ Internet Explorer \ iexplore.exe C: \ Program Files \ Internet Explorer \ iexplore.exe C: \ Program Files \ Logitech \ Video \ FxSvr2.exe C: \ Program Files \ Mozilla Firefox \ firefox.exe C: \ WINDOWS \ system32 \ wuauclt.exe C: \ WINDOWS \ system32 \ wuauclt.exe C: \ Program Files \ Trend Micro \ HijackThis \ sniper.exe.exe R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://www.yahoo.com R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.yahoo.com R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ SearchURL, (Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com R1 - HKCU \ Software \ Microsoft \ Internet Connection Wizard, ShellNext = http://www.yahoo.com/ O2 - BHO: Yahoo! Companion BHO - (02478D38-C3F9-4efb-9B51-7695ECA05670) - C: \ Program Files \ Yahoo! \ Companion \ installs \ CPN \ ycomp5_6_0_1.d ll O2 - BHO: Adobe PDF Reader Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Common Files \ Adobe \ Acrobat \ ActiveX \ AcroIEHelper.dll O2 - BHO: Groove GFS Browser Helper - (72853161-30C5-4D22-B7F9-0BBC1D38A37E) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ GRA8E1 ~ 1.dll O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll O2 - BHO: (geen naam) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (geen file) O2 - BHO: Windows Live Sign-in Helper - (9030D464-4C02-4ABF-8ECC-5164760863C6) - C: \ Program Files \ Common Files \ Microsoft Shared \ Windows Live \ WindowsLiveLogin.dll O3 - Toolbar: & Yahoo! Companion - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ Program Files \ Yahoo! \ Companion \ installs \ CPN \ ycomp5_6_0_1.d ll O4 - HKLM \ .. \ Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM \ .. \ Run: [SkyTel] SkyTel.EXE O4 - HKLM \ .. \ Run: [Alcmtr] ALCMTR.EXE O4 - HKLM \ .. \ Run: [AVG7_CC] C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgcc.exe / STARTUP O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ jusched.exe" O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe"-atboottime O4 - HKLM \ .. \ Run: [Adobe Reader Speed Launcher] "C: \ Program Files \ Adobe \ Reader 8.0 \ Reader \ Reader_sl.exe" O4 - HKLM \ .. \ Run: [NvCplDaemon] RUNDLL32.EXE C: \ WINDOWS \ system32 \ NvCpl.dll, NvStartup O4 - HKLM \ .. \ Run: [nwiz] nwiz.exe / install O4 - HKLM \ .. \ Run: [NvMediaCenter] RUNDLL32.EXE C: \ WINDOWS \ system32 \ NvMcTray.dll, NvTaskbarInit O4 - HKLM \ .. \ Run: [TkBellExe] "C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe"-osboot O4 - HKLM \ .. \ Run: [GrooveMonitor] "C: \ Program Files \ Microsoft Office \ Office12 \ GrooveMonitor.exe" O4 - HKLM \ .. \ Run: [LVCOMSX] C: \ WINDOWS \ system32 \ LVCOMSX.EXE O4 - HKLM \ .. \ Run: [LogitechVideoRepair] C: \ Program Files \ Logitech \ Video \ ISStart.exe O4 - HKLM \ .. \ Run: [LogitechVideoTray] C: \ Program Files \ Logitech \ Video \ LogiTray.exe O4 - HKLM \ .. \ Run: [Tweede vleermuis creatieve piek] C: \ Documents and Settings \ All Users \ Application Data \ Axis Leesmij Tweede Bat \ dode lite.exe O4 - HKCU \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe O4 - HKCU \ .. \ Run: [BitTorrent DNA] "C: \ Program Files \ DNA \ btdna.exe" O4 - HKCU \ .. \ Run: [curblicense] C: \ DOCUME ~ 1 \ Richard \ TOEPASSINGEN ~ 1 \ WAYBOW ~ 1 \ Nurb meer noun.exe O4 - HKCU \ .. \ Run: [SUPERAntiSpyware] C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe O4 - HKUS \ S-1-5-19 \ .. \ Run: [AVG7_Run] C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgw.exe / RunOnce (User 'LOCAL SERVICE') O4 - HKUS \ S-1-5-20 \ .. \ Run: [AVG7_Run] C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgw.exe / RunOnce (User 'NETWORK SERVICE') O4 - HKUS \ S-1-5-18 \ .. \ Run: [AVG7_Run] C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgw.exe / RunOnce (User 'SYSTEM') O4 - HKUS \. DEFAULT \ .. \ Run: [AVG7_Run] C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgw.exe / RunOnce (User 'Default user') O8 - Extra context menu item: E & xporteren naar Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ EXCEL.EXE/3000 O9 - Extra button: (geen naam) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll O9 - Extra 'Tools' MENUITEM: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll O9 - Extra button: Verzenden naar OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ ONBttnIE.dll O9 - Extra 'Tools' MENUITEM: S & einde aan OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ ONBttnIE.dll O9 - Extra button: Onderzoek - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ REFIEBAR.DLL O9 - Extra button: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe O9 - Extra 'Tools' MENUITEM: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe O16 - DPF: (6414512B-B978-451D-A0D8-FCFDF33E833C) (WUWebControl Class) -- http://www.update.microsoft.com/wind...?1197308803562 O16 - DPF: (C3F79A2B-B9B4-4A66-B012-3EE46475B072) (MessengerStatsClient Class) -- http://messenger.zone.msn.com/binary...t.cab56907.cab O18 - Protocol: grooveLocalGWS - (88FED34C-F0CA-4636-A375-3CB6248B04CD) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ GR99D3 ~ 1.dll O20 - Winlogon Notify:! SASWinLogon - C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.dll O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - Grisoft, sro - C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - Grisoft, sro - C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - Grisoft, sro - C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgemc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C: \ WINDOWS \ system32 \ nvsvc32.exe O23 - Service: PnkBstrA - Onbekende eigenaar - C: \ WINDOWS \ system32 \ PnkBstrA.exe -- End of file - 7041 bytes Ik hoop dat dit voldoende is |
|
#6
| |||
| |||
| Open HijackThis en selecteer Doe een systeemscan alleen plaats dan een vinkje naast: O2 - BHO: (geen naam) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (geen file) Sluit alle vensters behalve HijackThis en klik op Fix gecontroleerd Afsluiten HijackThis. ---------- Please download Combofix door subs uit een van de onderstaande links. (Probeer alle drie indien nodig)BELANGRIJK - Combofix.exe MOET worden opgeslagen op uw uw Desktop.
De scan zal tijdelijk uitschakelen van uw bureaublad. Als onderbroken kan uw computer bevroren. Als dit gebeurt, moet u opnieuw opstarten om het bureaublad. ---------- Volgende bericht Combofix log |
|
#7
| |||
| |||
| ComboFix 08-01-15.4 - Richard 2008-01-15 21:03:57.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.587 [GMT 0:00] Running from: C: \ Documents and Settings \ Richard \ Desktop \ ComboFix.exe * Gemaakt van een nieuw herstelpunt WARNING-THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE GEÏNSTALLEERD! . ((((((((((((((((((((((((( Bestanden Gemaakt van 2007-12-15 tot 2008-01-15 ))))))))))) )))))))))))))))))))) . 2008-01-15 21:03. 2000-08-31 08:00 51.200 - a ------ C: \ WINDOWS \ NirCmd.exe 2008-01-15 19:41. 2008-01-15 20:38 <DIR> d -------- C: \ Program Files \ SUPERAntiSpyware 2008-01-15 19:41. 2008-01-15 19:41 <DIR> d -------- C: \ Program Files \ Common Files \ Wise Installation Wizard 2008-01-15 19:41. 2008-01-15 19:41 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ SUPERAntiSpyware.com 2008-01-15 19:41. 2008-01-15 19:41 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ SUPERAntiSpyware.com 2008-01-15 19:34. 2008-01-15 19:36 <DIR> d -------- C: \ NoLopBackups 2008-01-15 19:01. 2008-01-15 19:01 <DIR> d -------- C: \ Program Files \ Trend Micro 2008-01-15 16:32. 2008-01-15 16:32 <DIR> d -------- C: \ Program Files \ WayBowsReal 2008-01-11 10:27. 2005-05-26 15:34 2297552 - a ------ C: \ WINDOWS \ system32 \ d3dx9_26.dll 2008-01-11 10:26. 2008-01-11 10:26 22.328 - a ------ C: \ Documents and Settings \ Richard \ Application Data \ PnkBstrK.sys 2008-01-11 10:25. 2008-01-11 10:25 319 - a ------ C: \ WINDOWS \ game.ini 2008-01-11 10:15. 2008-01-11 10:15 <DIR> d -------- C: \ Program Files \ Activision 2008-01-11 10:14. 2008-01-11 10:14 <DIR> d - hs ---- C: \ WINDOWS \ ftpcache 2008-01-11 00:29. 2008-01-11 00:29 54.608 - a ------ C: \ WINDOWS \ system32 \ xfcodec.dll 2008-01-05 21:00. 2008-01-05 21:00 <DIR> d - h ----- C: \ WINDOWS \ $ hf_mig $ 2008-01-03 18:41. 2008-01-03 18:41 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ Messenger Plus! 2008-01-03 18:00. 2008-01-03 18:00 <DIR> d -------- C: \ Program Files \ Messenger Plus! Leven 2008-01-03 18:00. 2008-01-15 19:36 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ WayBowsReal 2008-01-03 18:00. 2008-01-15 16:33 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ Axis Leesmij Tweede Bat 2007-12-30 16:54. 2007-12-30 16:54 <DIR> d -------- C: \ Program Files \ Whisper Technologie 2007-12-30 16:36. 2007-12-30 16:36 <DIR> d -------- C: \ Program Files \ SmartFTP Client 2.5 Setup Files 2007-12-30 16:36. 2007-12-30 16:36 <DIR> d -------- C: \ Program Files \ SmartFTP Client 2007-12-30 16:36. 2007-12-30 16:36 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ SmartFTP 2007-12-30 07:48. 2007-12-30 07:48 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ Sony 2007-12-30 07:48. 2007-12-30 07:48 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ Publish Providers 2007-12-30 07:45. 2007-12-30 07:45 <DIR> d -------- C: \ Program Files \ Vstplugins 2007-12-30 07:45. 2007-12-30 07:45 <DIR> d -------- C: \ Program Files \ Sony 2007-12-30 07:45. 2007-12-30 07:45 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ Sony 2007-12-30 07:39. 2007-12-30 07:39 <DIR> d -------- C: \ Program Files \ Sony Setup 2007-12-30 07:39. 2007-12-30 07:39 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ Sony Setup 2007-12-29 23:30. 2008-01-15 17:00 54,156 - ah ----- C: \ WINDOWS \ QTFont.qfn 2007-12-29 23:30. 2007-12-29 23:30 1409 - a ------ C: \ WINDOWS \ QTFont.for 2007-12-29 15:45. 2007-12-29 15:45 <DIR> d -------- C: \ Program Files \ FOD 2007-12-29 15:45. 2007-12-29 15:45 286,720 --------- C: \ WINDOWS \ Setup1.exe 2007-12-29 15:45. 2007-12-29 15:45 73,216 - a ------ C: \ WINDOWS \ ST6UNST.EXE 2007-12-29 12:08. 2004-08-03 23:10 10,880 - a ------ C: \ WINDOWS \ system32 \ drivers \ NdisIP.sys 2007-12-29 12:08. 2004-08-03 23:10 10,880 - a - c --- C: \ WINDOWS \ system32 \ dllcache \ ndisip.sys 2007-12-29 12:08. 2004-08-03 22:58 5504 - a ------ C: \ WINDOWS \ system32 \ drivers \ MSTEE.sys 2007-12-29 12:08. 2004-08-03 22:58 5504 - a - c --- C: \ WINDOWS \ system32 \ dllcache \ mstee.sys 2007-12-29 12:04. 2007-12-29 12:04 <DIR> d -------- C: \ SXS 2007-12-29 12:04. 2007-12-29 12:04 <DIR> d -------- C: \ Program Files \ Logitech 2007-12-29 12:04. 2007-12-29 12:04 <DIR> d -------- C: \ Program Files \ Common Files \ FotoWire 2007-12-29 12:04. 2007-12-29 12:04 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ FotoWire 2007-12-29 12:03. 2007-12-29 12:03 <DIR> d -------- C: \ Program Files \ Common Files \ Logitech 2007-12-28 19:09. 2007-12-28 19:46 <DIR> d -------- C: \ Program Files \ eMule 2007-12-28 17:29. 2007-12-28 17:29 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ DivX 2007-12-27 00:05. 2007-12-27 00:05 <DIR> d -------- C: \ Fraps 2007-12-27 00:05. 2007-12-27 00:05 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ TEMP 2007-12-24 17:11. 2007-07-30 19:19 271,224 - a ------ C: \ WINDOWS \ system32 \ mucltui.dll 2007-12-24 17:11. 2007-07-30 19:19 207,736 - a ------ C: \ WINDOWS \ system32 \ muweb.dll 2007-12-24 17:11. 2007-07-30 19:19 30,072 - a ------ C: \ WINDOWS \ system32 \ mucltui.dll.mui 2007-12-23 21:01. 2008-01-03 20:48 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ gtk-2.0 2007-12-23 21:01. 2007-12-23 21:01 <DIR> d -------- C: \ Documents and Settings \ Richard \. Miniaturen 2007-12-23 21:00. 2007-12-23 21:00 <DIR> d -------- C: \ Program Files \ GIMP-2.0 2007-12-23 21:00. 2008-01-03 20:54 <DIR> d -------- C: \ Documents and Settings \ Richard \. Gimp-2.4 2007-12-22 15:39. 2007-12-22 15:39 <DIR> d -------- C: \ Program Files \ DNA 2007-12-22 15:39. 2008-01-15 20:56 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ DNA 2007-12-22 15:39. 2007-12-28 19:40 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ BitTorrent 2007-12-22 15:22. 2007-12-22 15:22 <DIR> d -------- C: \ Program Files \ Audacity 2007-12-22 15:21. 2007-12-22 15:21 <DIR> d -------- C: \ Program Files \ MonkeyJam 2007-12-22 15:21. 2007-12-22 15:21 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ MonkeyJam 2007-12-22 15:21. 2005-02-27 17:11 424,960 - a ------ C: \ WINDOWS \ system32 \ wavdest.ax 2007-12-21 15:27. 2007-12-21 15:27 <DIR> d -------- C: \ Program Files \ Microsoft Works 2007-12-21 15:27. 2006-10-26 19:56 32,592 - a ------ C: \ WINDOWS \ system32 \ msonpmon.dll 2007-12-21 15:26. 2007-12-21 15:26 <DIR> d -------- C: \ Program Files \ MSBuild 2007-12-21 15:23. 2007-12-21 15:26 <DIR> d -------- C: \ WINDOWS \ SHELLNEW 2007-12-21 15:22. 2007-12-21 15:22 <DIR> dr-h ----- C: \ MSOCACHE 2007-12-21 15:22. 2007-12-21 15:27 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ Microsoft Help 2007-12-19 19:56. 2007-12-28 13:01 <DIR> d -------- C: \ Program Files \ DivX 2007-12-15 23:51. 2007-12-15 23:51 <DIR> d -------- C: \ Program Files \ VideoLAN 2007-12-15 23:51. 2007-12-15 23:51 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ vlc 2007-12-15 23:51. 2007-12-15 23:51 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ dvdcss 2007-12-15 23:36. 2007-12-22 15:29 <DIR> d -------- C: \ Program Files \ Real 2007-12-15 23:36. 2007-12-15 23:36 <DIR> d -------- C: \ Program Files \ Common Files \ Xing gedeelde 2007-12-15 23:36. 2007-12-15 23:36 <DIR> d -------- C: \ Program Files \ Common Files \ Real . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))) )))))))))))))))))))))))))))))))))))))))))))) . 2008-01-15 19:36 --------- d ----- w C: \ Program Files \ Xfire 2008-01-15 17:54 --------- d ----- w C: \ Documents and Settings \ Richard \ Application Data \ AVG7 2008-01-15 17:54 --------- d ----- w C: \ Documents and Settings \ All Users \ Application Data \ avg7 2008-01-15 17:46 22,328 ---- aw C: \ WINDOWS \ system32 \ drivers \ PnkBstrK.sys 2008-01-15 17:46 107,832 ---- aw C: \ WINDOWS \ system32 \ PnkBstrB.exe 2008-01-15 17:45 --------- d ----- w C: \ Documents and Settings \ Richard \ Application Data \ Xfire 2008-01-11 23:18 --------- d ----- w C: \ Program Files \ SpeedFan 2008-01-11 22:26 5,615 ---- aw C: \ Program Files \ install.log 2008-01-11 19:06 66,872 ---- aw C: \ WINDOWS \ system32 \ PnkBstrA.exe 2008-01-11 10:25 --------- d - h - w C: \ Program Files \ InstallShield Installation Information 2007-12-22 15:26 --------- d ----- w C: \ Program Files \ Common Files \ InstallShield 2007-12-21 18:56 --------- d ----- w C: \ Program Files \ Wolfenstein - Enemy Territory 2007-12-12 21:45 --------- d ----- w C: \ Program Files \ Common Files \ Adobe 2007-12-12 21:43 --------- d ----- w C: \ Documents and Settings \ All Users \ Application Data \ NVIDIA 2007-12-12 21:31 --------- d ----- w C: \ Program Files \ SystemRequirementsLab 2007-12-12 20:38 --------- d ----- w C: \ Documents and Settings \ Richard \ Application Data \ Apple Computer 2007-12-12 20:32 --------- d ----- w C: \ Program Files \ Windows Media Connect 2 2007-12-12 20:04 --------- d ----- w C: \ Program Files \ QuickTime 2007-12-12 20:03 --------- d ----- w C: \ Program Files \ Apple Software Update 2007-12-12 20:03 --------- d ----- w C: \ Documents and Settings \ All Users \ Application Data \ Apple Computer 2007-12-12 20:03 --------- d ----- w C: \ Documents and Settings \ All Users \ Application Data \ Apple 2007-12-10 22:14 --------- d ----- w C: \ Documents and Settings \ LocalService \ Application Data \ Xfire 2007-12-10 22:01 --------- d ----- w C: \ Documents and Settings \ NetworkService \ Application Data \ Xfire 2007-12-10 18:58 --------- d ----- w C: \ Program Files \ CCleaner 2007-12-10 18:02 --------- d ----- w C: \ Program Files \ Java 2007-12-10 18:02 --------- d ----- w C: \ Documents and Settings \ Richard \ Application Data \ SystemRequirementsLab 2007-12-10 18:00 --------- d ----- w C: \ Program Files \ Common Files \ Java 2007-12-10 17:54 --------- dcsh - w C: \ Program Files \ Common Files \ WindowsLiveInstaller 2007-12-10 17:54 --------- d ----- w C: \ Program Files \ Windows Live 2007-12-10 17:50 --------- d ----- w C: \ Documents and Settings \ All Users \ Application Data \ WLInstaller 2007-12-10 17:39 --------- d ----- w C: \ Program Files \ RivaTuner v2.06 2007-12-08 22:50 12,464 ---- aw C: \ WINDOWS \ system32 \ drivers \ secdrv.sys 2007-12-07 18:43 499,712 ---- aw C: \ WINDOWS \ system32 \ msvcp71.dll 2007-12-07 18:43 348,160 ---- aw C: \ WINDOWS \ system32 \ msvcr71.dll 2007-12-07 18:43 --------- d ----- w C: \ Documents and Settings \ LocalService \ Application Data \ AVG7 2007-12-07 18:42 --------- d ----- w C: \ Documents and Settings \ All Users \ Application Data \ Grisoft 2007-12-07 18:24 --------- d ----- w C: \ Program Files \ AquaMark3 2007-12-07 17:45 --------- d ----- w C: \ Program Files \ Realtek 2007-12-07 17:45 --------- d ----- w C: \ Documents and Settings \ Richard \ Application Data \ InstallShield 2007-12-07 17:44 4,716 ---- aw C: \ WINDOWS \ gdrv.sys 2007-12-07 17:43 --------- d ----- w C: \ Program Files \ Intel 2007-12-07 17:42 --------- d ----- w C: \ Program Files \ Yahoo! 2007-12-07 17:37 --------- d ----- w C: \ Program Files \ Microsoft FrontPage 2007-12-04 01:33 823,296 ---- aw C: \ WINDOWS \ system32 \ divx_xx0c.dll 2007-12-04 01:33 823,296 ---- aw C: \ WINDOWS \ system32 \ divx_xx07.dll 2007-12-04 01:33 802,816 ---- aw C: \ WINDOWS \ system32 \ divx_xx11.dll 2007-12-04 01:33 682,496 ---- aw C: \ WINDOWS \ system32 \ DivX.dll 2007-11-29 22:30 524,288 ---- aw C: \ WINDOWS \ system32 \ DivXsm.exe 2007-11-29 22:30 3,596,288 ---- aw C: \ WINDOWS \ system32 \ qt-dx331.dll 2007-11-29 22:30 200,704 ---- aw C: \ WINDOWS \ system32 \ ssldivx.dll 2007-11-29 22:30 1,044,480 ---- aw C: \ WINDOWS \ system32 \ libdivx.dll 2007-11-29 22:28 81,920 ---- aw C: \ WINDOWS \ system32 \ dpl100.dll 2007-11-29 22:28 196,608 ---- aw C: \ WINDOWS \ system32 \ dtu100.dll 2007-11-28 21:55 156,992 ---- aw C: \ WINDOWS \ system32 \ DivXCodecVersionChecker.exe 2007-11-28 21:53 593,920 ---- aw C: \ WINDOWS \ system32 \ dpuGUI11.dll 2007-11-28 21:53 57,344 ---- aw C: \ WINDOWS \ system32 \ dpv11.dll 2007-11-28 21:53 53,248 ---- aw C: \ WINDOWS \ system32 \ dpuGUI10.dll 2007-11-28 21:53 344,064 ---- aw C: \ WINDOWS \ system32 \ dpus11.dll 2007-11-28 21:53 294,912 ---- aw C: \ WINDOWS \ system32 \ dpu11.dll 2007-11-28 21:53 294,912 ---- aw C: \ WINDOWS \ system32 \ dpu10.dll 2007-11-28 21:52 12,288 ---- aw C: \ WINDOWS \ system32 \ DivXWMPExtType.dll 2007-11-21 18:23 81,920 ---- aw C: \ WINDOWS \ system32 \ frapsvid.dll 2007-10-18 11:31 51.224 ---- aw C: \ WINDOWS \ system32 \ sirenacm.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))) )))))))))))))))))))))))))))))))))))))))) . . * Note * empty entries & legit default entries worden niet weergegeven REGEDIT4 [HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curre ntVersion \ Run] "Ctfmon.exe" = "C: \ WINDOWS \ system32 \ Ctfmon.exe" [2004-08-04 12:00 15360] "BitTorrent DNA" = "C: \ Program Files \ DNA \ btdna.exe" [2007-12-22 15:39 290112] "curblicense" = "C: \ DOCUME ~ 1 \ Richard \ TOEPASSINGEN ~ 1 \ WAYBOW ~ 1 \ Nurb meer noun.exe" [2008-01-15 16:32 443904] "SUPERAntiSpyware" = "C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Run] "RTHDCPL" = "RTHDCPL.EXE" [2006-11-14 09:21 16270848 C: \ WINDOWS \ RTHDCPL.exe] "SkyTel" = "SkyTel.EXE" [2006-05-16 10:04 2879488 C: \ WINDOWS \ SkyTel.exe] "AVG7_CC" = "C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgcc.exe" [2007-12-20 16:29 579072] "SunJavaUpdateSched" = "C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ jusched.exe" [2007-09-25 01:11 132496] "QuickTime Task" = "C: \ Program Files \ QuickTime \ qttask.exe" [2007-10-19 20:16 286720] "Adobe Reader Speed Launcher" = "C: \ Program Files \ Adobe \ Reader 8.0 \ Reader \ Reader_sl.exe" [2007-10-10 19:51 39792] "NvCplDaemon" = "C: \ WINDOWS \ system32 \ NvCpl.dll" [2007-09-17 01:07 8491008] "nwiz" = "nwiz.exe" [2007-09-17 01:07 1626112 C: \ WINDOWS \ system32 \ nwiz.exe] "NvMediaCenter" = "C: \ WINDOWS \ system32 \ NvMcTray. Dll" [2007-09-17 01:07 81920] "TkBellExe" = "C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe" [2007-12-15 23:36 185896] "GrooveMonitor" = "C: \ Program Files \ Microsoft Office \ Office12 \ GrooveMonitor.exe" [2006-10-27 00:47 31016] "LVCOMSX" = "C: \ WINDOWS \ system32 \ LVCOMSX.EXE" [2004-02-25 16:15 221184] "LogitechVideoRepair" = "C: \ Program Files \ Logitech \ Video \ ISStart.exe" [2004-02-25 17:15 454656] "LogitechVideoTray" = "C: \ Program Files \ Logitech \ Video \ LogiTray.exe" [2004-02-25 17:06 212992] "Tweede vleermuis creatieve piek" = "C: \ Documents and Settings \ All Users \ Application Data \ Axis Leesmij Tweede Bat \ dode lite.exe" [2008-01-15 20:37 1348608] [HKEY_USERS \. DEFAULT \ Software \ Microsoft \ Windows \ Cur rentVersion \ Run] "AVG7_Run" = "C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgw.exe" [2007-12-07 18:42 219136] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ valuta entversion \ Explorer \ shellexecutehooks] "(5AE067D3-9AFB-48E0-853A-EBB7F4A000DA)" = C: \ Program Files \ SUPERAntiSpyware \ SASSEH.DLL [2006-12-20 13:55 77824] [HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ Notify \! SASWinLogon] C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.dll 2007-04-19 13:41 294912 C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.dll S3 gdrv; gdrv, C: \ WINDOWS \ gdrv.sys [2007-12-07 17:44] S3 PhilCam8116; Logitech QuickCam Pro 3000 (PID_08B0), C: \ WINDOWS \ system32 \ drivers \ CamDrL2 1.sys [2004-02-14 04:09] * Newly Created Service * - PROCEXP90 . Inhoud van de 'Geplande taken' map "2007-12-12 20:03:45 C: \ WINDOWS \ Tasks \ AppleSoftwareUpdate.job" - C: \ Program Files \ Apple Software Update \ SoftwareUpdate.exe . ************************************************** ************************ CatchMe 0.3.1344 W2K/XP/Vista - rootkit / stealth malware detector, Gmer, http://www.gmer.net Rootkit scan 2008-01-15 21:04:58 Windows 5.1.2600 Service Pack 2 NTFS het scannen van verborgen processen ... het scannen van verborgen autostart items ... het scannen van verborgen bestanden ... scannen is voltooid verborgen bestanden: 0 ************************************************** ************************ . Afronding tijd: 2008-01-15 21:05:11 . 2008-01-05 21:00:15 --- EOF --- |
|
#8
| |||
| |||
| Verwijder deze bestanden / mappen, als volgt: 1. Ga naar Start > Rennen > Type Notepad.exe en klik op OK Kladblok te openen. Het moet worden Kladblok, Wordpad niet.
Dossier: C: \ Documents and Settings \ All Users \ Application Data \ Axis Leesmij Tweede Bat \ dode lite.exe C: \ DOCUME ~ 1 \ Richard \ TOEPASSINGEN ~ 1 \ WAYBOW ~ 1 \ Nurb meer noun.exe Griffie: [HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curre ntVersion \ Run] "curblicense" =- [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Run] "Tweede vleermuis creatieve piek" =- 3. Ga naar het Kladblok-venster en klik op Bewerken > Plakken 4. Klik vervolgens op Bestand > Redden 5. Geef het bestand de naam CFScript.txt - Sla het bestand op uw bureaublad 6. Vervolgens sleept u de CFScript (houd de linker muisknop te slepen, terwijl het bestand) en de daling van het (laat de linker muisknop) in ComboFix.exe zoals je kunt zien in het screenshot hieronder. Belangrijk: Voer deze instructie zorgvuldig! ![]() ComboFix zal beginnen uit te voeren, volg de instructies. Na een reboot (in geval er gevraagd om opnieuw op te starten), zal een log voor je. Post dat log (Combofix.txt) in je volgende antwoord. Opmerking: Niet muisklik combofix het venster terwijl het draait. Dat kan ertoe leiden dat uw systeem te bevriezen ---------- Voer een nieuwe HijackThis scan en post het log. ---------- Volgende bericht Combofix log Nieuw HijackThis log |
|
#9
| |||
| |||
| ComboFix 08-01-15.4 - Richard 2008-01-15 22:03:05.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.560 [GMT 0:00] Running from: C: \ Documents and Settings \ Richard \ Desktop \ ComboFix.exe Command switches gebruikt:: C: \ Documents and Settings \ Richard \ Desktop \ CFScript.txt * Gemaakt van een nieuw herstelpunt WARNING-THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE GEÏNSTALLEERD! FILE C: \ DOCUME ~ 1 \ Richard \ TOEPASSINGEN ~ 1 \ WAYBOW ~ 1 \ Nurb meer noun.exe C: \ Documents and Settings \ All Users \ Application Data \ Axis Leesmij Tweede Bat \ dode lite.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))) )))))))))))))))))))))))))))))))))))))))) . C: \ DOCUME ~ 1 \ Richard \ TOEPASSINGEN ~ 1 \ WAYBOW ~ 1 \ Nurb meer noun.exe C: \ Documents and Settings \ All Users \ Application Data \ Axis Leesmij Tweede Bat \ dode lite.exe . ((((((((((((((((((((((((( Bestanden Gemaakt van 2007-12-15 tot 2008-01-15 ))))))))))) )))))))))))))))))))) . 2008-01-15 21:03. 2000-08-31 08:00 51.200 - a ------ C: \ WINDOWS \ NirCmd.exe 2008-01-15 19:41. 2008-01-15 20:38 <DIR> d -------- C: \ Program Files \ SUPERAntiSpyware 2008-01-15 19:41. 2008-01-15 19:41 <DIR> d -------- C: \ Program Files \ Common Files \ Wise Installation Wizard 2008-01-15 19:41. 2008-01-15 19:41 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ SUPERAntiSpyware.com 2008-01-15 19:41. 2008-01-15 19:41 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ SUPERAntiSpyware.com 2008-01-15 19:34. 2008-01-15 19:36 <DIR> d -------- C: \ NoLopBackups 2008-01-15 19:01. 2008-01-15 19:01 <DIR> d -------- C: \ Program Files \ Trend Micro 2008-01-15 16:32. 2008-01-15 16:32 <DIR> d -------- C: \ Program Files \ WayBowsReal 2008-01-11 10:27. 2005-05-26 15:34 2297552 - a ------ C: \ WINDOWS \ system32 \ d3dx9_26.dll 2008-01-11 10:26. 2008-01-11 10:26 22.328 - a ------ C: \ Documents and Settings \ Richard \ Application Data \ PnkBstrK.sys 2008-01-11 10:25. 2008-01-11 10:25 319 - a ------ C: \ WINDOWS \ game.ini 2008-01-11 10:15. 2008-01-11 10:15 <DIR> d -------- C: \ Program Files \ Activision 2008-01-11 10:14. 2008-01-11 10:14 <DIR> d - hs ---- C: \ WINDOWS \ ftpcache 2008-01-11 00:29. 2008-01-11 00:29 54.608 - a ------ C: \ WINDOWS \ system32 \ xfcodec.dll 2008-01-05 21:00. 2008-01-05 21:00 <DIR> d - h ----- C: \ WINDOWS \ $ hf_mig $ 2008-01-03 18:41. 2008-01-03 18:41 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ Messenger Plus! 2008-01-03 18:00. 2008-01-03 18:00 <DIR> d -------- C: \ Program Files \ Messenger Plus! Leven 2008-01-03 18:00. 2008-01-15 22:03 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ WayBowsReal 2008-01-03 18:00. 2008-01-15 22:03 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ Axis Leesmij Tweede Bat 2007-12-30 16:54. 2007-12-30 16:54 <DIR> d -------- C: \ Program Files \ Whisper Technologie 2007-12-30 16:36. 2007-12-30 16:36 <DIR> d -------- C: \ Program Files \ SmartFTP Client 2.5 Setup Files 2007-12-30 16:36. 2007-12-30 16:36 <DIR> d -------- C: \ Program Files \ SmartFTP Client 2007-12-30 16:36. 2007-12-30 16:36 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ SmartFTP 2007-12-30 07:48. 2007-12-30 07:48 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ Sony 2007-12-30 07:48. 2007-12-30 07:48 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ Publish Providers 2007-12-30 07:45. 2007-12-30 07:45 <DIR> d -------- C: \ Program Files \ Vstplugins 2007-12-30 07:45. 2007-12-30 07:45 <DIR> d -------- C: \ Program Files \ Sony 2007-12-30 07:45. 2007-12-30 07:45 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ Sony 2007-12-30 07:39. 2007-12-30 07:39 <DIR> d -------- C: \ Program Files \ Sony Setup 2007-12-30 07:39. 2007-12-30 07:39 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ Sony Setup 2007-12-29 23:30. 2008-01-15 17:00 54,156 - ah ----- C: \ WINDOWS \ QTFont.qfn 2007-12-29 23:30. 2007-12-29 23:30 1409 - a ------ C: \ WINDOWS \ QTFont.for 2007-12-29 15:45. 2007-12-29 15:45 <DIR> d -------- C: \ Program Files \ FOD 2007-12-29 15:45. 2007-12-29 15:45 286,720 --------- C: \ WINDOWS \ Setup1.exe 2007-12-29 15:45. 2007-12-29 15:45 73,216 - a ------ C: \ WINDOWS \ ST6UNST.EXE 2007-12-29 12:08. 2004-08-03 23:10 10,880 - a ------ C: \ WINDOWS \ system32 \ drivers \ NdisIP.sys 2007-12-29 12:08. 2004-08-03 23:10 10,880 - a - c --- C: \ WINDOWS \ system32 \ dllcache \ ndisip.sys 2007-12-29 12:08. 2004-08-03 22:58 5504 - a ------ C: \ WINDOWS \ system32 \ drivers \ MSTEE.sys 2007-12-29 12:08. 2004-08-03 22:58 5504 - a - c --- C: \ WINDOWS \ system32 \ dllcache \ mstee.sys 2007-12-29 12:04. 2007-12-29 12:04 <DIR> d -------- C: \ SXS 2007-12-29 12:04. 2007-12-29 12:04 <DIR> d -------- C: \ Program Files \ Logitech 2007-12-29 12:04. 2007-12-29 12:04 <DIR> d -------- C: \ Program Files \ Common Files \ FotoWire 2007-12-29 12:04. 2007-12-29 12:04 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ FotoWire 2007-12-29 12:03. 2007-12-29 12:03 <DIR> d -------- C: \ Program Files \ Common Files \ Logitech 2007-12-28 19:09. 2007-12-28 19:46 <DIR> d -------- C: \ Program Files \ eMule 2007-12-28 17:29. 2007-12-28 17:29 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ DivX 2007-12-27 00:05. 2007-12-27 00:05 <DIR> d -------- C: \ Fraps 2007-12-27 00:05. 2007-12-27 00:05 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ TEMP 2007-12-24 17:11. 2007-07-30 19:19 271,224 - a ------ C: \ WINDOWS \ system32 \ mucltui.dll 2007-12-24 17:11. 2007-07-30 19:19 207,736 - a ------ C: \ WINDOWS \ system32 \ muweb.dll 2007-12-24 17:11. 2007-07-30 19:19 30,072 - a ------ C: \ WINDOWS \ system32 \ mucltui.dll.mui 2007-12-23 21:01. 2008-01-03 20:48 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ gtk-2.0 2007-12-23 21:01. 2007-12-23 21:01 <DIR> d -------- C: \ Documents and Settings \ Richard \. Miniaturen 2007-12-23 21:00. 2007-12-23 21:00 <DIR> d -------- C: \ Program Files \ GIMP-2.0 2007-12-23 21:00. 2008-01-03 20:54 <DIR> d -------- C: \ Documents and Settings \ Richard \. Gimp-2.4 2007-12-22 15:39. 2007-12-22 15:39 <DIR> d -------- C: \ Program Files \ DNA 2007-12-22 15:39. 2008-01-15 22:03 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ DNA 2007-12-22 15:39. 2007-12-28 19:40 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ BitTorrent 2007-12-22 15:22. 2007-12-22 15:22 <DIR> d -------- C: \ Program Files \ Audacity 2007-12-22 15:21. 2007-12-22 15:21 <DIR> d -------- C: \ Program Files \ MonkeyJam 2007-12-22 15:21. 2007-12-22 15:21 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ MonkeyJam 2007-12-22 15:21. 2005-02-27 17:11 424,960 - a ------ C: \ WINDOWS \ system32 \ wavdest.ax 2007-12-21 15:27. 2007-12-21 15:27 <DIR> d -------- C: \ Program Files \ Microsoft Works 2007-12-21 15:27. 2006-10-26 19:56 32,592 - a ------ C: \ WINDOWS \ system32 \ msonpmon.dll 2007-12-21 15:26. 2007-12-21 15:26 <DIR> d -------- C: \ Program Files \ MSBuild 2007-12-21 15:23. 2007-12-21 15:26 <DIR> d -------- C: \ WINDOWS \ SHELLNEW 2007-12-21 15:22. 2007-12-21 15:22 <DIR> dr-h ----- C: \ MSOCACHE 2007-12-21 15:22. 2007-12-21 15:27 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ Microsoft Help 2007-12-19 19:56. 2007-12-28 13:01 <DIR> d -------- C: \ Program Files \ DivX 2007-12-15 23:51. 2007-12-15 23:51 <DIR> d -------- C: \ Program Files \ VideoLAN 2007-12-15 23:51. 2007-12-15 23:51 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ vlc 2007-12-15 23:51. 2007-12-15 23:51 <DIR> d -------- C: \ Documents and Settings \ Richard \ Application Data \ dvdcss 2007-12-15 23:36. 2007-12-22 15:29 <DIR> d -------- C: \ Program Files \ Real 2007-12-15 23:36. 2007-12-15 23:36 <DIR> d -------- C: \ Program Files \ Common Files \ Xing gedeelde 2007-12-15 23:36. 2007-12-15 23:36 <DIR> d -------- C: \ Program Files \ Common Files \ Real . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))) )))))))))))))))))))))))))))))))))))))))))))) . 2008-01-15 19:36 --------- d ----- w C: \ Program Files \ Xfire 2008-01-15 17:54 --------- d ----- w C: \ Documents and Settings \ Richard \ Application Data \ AVG7 2008-01-15 17:54 --------- d ----- w C: \ Documents and Settings \ All Users \ Application Data \ avg7 2008-01-15 17:46 22,328 ---- aw C: \ WINDOWS \ system32 \ drivers \ PnkBstrK.sys 2008-01-15 17:45 --------- d ----- w C: \ Documents and Settings \ Richard \ Application Data \ Xfire 2008-01-11 23:18 --------- d ----- w C: \ Program Files \ SpeedFan 2008-01-11 22:26 5,615 ---- aw C: \ Program Files \ install.log 2008-01-11 10:25 --------- d - h - w C: \ Program Files \ InstallShield Installation Information 2007-12-22 15:26 --------- d ----- w C: \ Program Files \ Common Files \ InstallShield 2007-12-21 18:56 --------- d ----- w C: \ Program Files \ Wolfenstein - Enemy Territory 2007-12-12 21:45 --------- d ----- w C: \ Program Files \ Common Files \ Adobe 2007-12-12 21:43 --------- d ----- w C: \ Documents and Settings \ All Users \ Application Data \ NVIDIA 2007-12-12 21:31 --------- d ----- w C: \ Program Files \ SystemRequirementsLab 2007-12-12 20:38 --------- d ----- w C: \ Documents and Settings \ Richard \ Application Data \ Apple Computer 2007-12-12 20:32 --------- d ----- w C: \ Program Files \ Windows Media Connect 2 2007-12-12 20:04 --------- d ----- w C: \ Program Files \ QuickTime 2007-12-12 20:03 --------- d ----- w C: \ Program Files \ Apple Software Update 2007-12-12 20:03 --------- d ----- w C: \ Documents and Settings \ All Users \ Application Data \ Apple Computer 2007-12-12 20:03 --------- d ----- w C: \ Documents and Settings \ All Users \ Application Data \ Apple 2007-12-10 22:14 --------- d ----- w C: \ Documents and Settings \ LocalService \ Application Data \ Xfire 2007-12-10 22:01 --------- d ----- w C: \ Documents and Settings \ NetworkService \ Application Data \ Xfire 2007-12-10 18:58 --------- d ----- w C: \ Program Files \ CCleaner 2007-12-10 18:02 --------- d ----- w C: \ Program Files \ Java 2007-12-10 18:02 --------- d ----- w C: \ Documents and Settings \ Richard \ Application Data \ SystemRequirementsLab 2007-12-10 18:00 --------- d ----- w C: \ Program Files \ Common Files \ Java 2007-12-10 17:54 --------- dcsh - w C: \ Program Files \ Common Files \ WindowsLiveInstaller 2007-12-10 17:54 --------- d ----- w C: \ Program Files \ Windows Live 2007-12-10 17:50 --------- d ----- w C: \ Documents and Settings \ All Users \ Application Data \ WLInstaller 2007-12-10 17:39 --------- d ----- w C: \ Program Files \ RivaTuner v2.06 2007-12-08 22:50 12,464 ---- aw C: \ WINDOWS \ system32 \ drivers \ secdrv.sys 2007-12-07 18:43 --------- d ----- w C: \ Documents and Settings \ LocalService \ Application Data \ AVG7 2007-12-07 18:42 --------- d ----- w C: \ Documents and Settings \ All Users \ Application Data \ Grisoft 2007-12-07 18:24 --------- d ----- w C: \ Program Files \ AquaMark3 2007-12-07 17:45 --------- d ----- w C: \ Program Files \ Realtek 2007-12-07 17:45 --------- d ----- w C: \ Documents and Settings \ Richard \ Application Data \ InstallShield 2007-12-07 17:44 4,716 ---- aw C: \ WINDOWS \ gdrv.sys 2007-12-07 17:43 --------- d ----- w C: \ Program Files \ Intel 2007-12-07 17:42 --------- d ----- w C: \ Program Files \ Yahoo! 2007-12-07 17:37 --------- d ----- w C: \ Program Files \ Microsoft FrontPage . ((((((((((((((((((((((((((((( Snapshot@2008-01-15_21.05.00.95 )))))))))) ))))))))))))))))))))))))))))))) . - 2008-01-15 21:03:50 225.280 ---- aw C: \ WINDOWS \ erdnt \ Hiv-backup \ Users \00000001 \ Ntuser.dat + 2008-01-15 22:03:02 225.280 ---- aw C: \ WINDOWS \ erdnt \ Hiv-backup \ Users \00000001 \ Ntuser.dat - 2008-01-15 21:03:50 8.192 ---- aw C: \ WINDOWS \ erdnt \ Hiv-backup \ Users \00000002 \ UsrClass.dat + 2008-01-15 22:03:02 8.192 ---- aw C: \ WINDOWS \ erdnt \ Hiv-backup \ Users \00000002 \ UsrClass.dat - 2008-01-15 21:03:50 229.376 ---- aw C: \ WINDOWS \ erdnt \ Hiv-backup \ Users \00000003 \ Ntuser.dat + 2008-01-15 22:03:02 229.376 ---- aw C: \ WINDOWS \ erdnt \ Hiv-backup \ Users \00000003 \ Ntuser.dat - 2008-01-15 21:03:50 8.192 ---- aw C: \ WINDOWS \ erdnt \ Hiv-backup \ Users \00000004 \ UsrClass.dat + 2008-01-15 22:03:02 8.192 ---- aw C: \ WINDOWS \ erdnt \ Hiv-backup \ Users \00000004 \ UsrClass.dat - 2008-01-15 21:03:50 3.670.016 ---- aw C: \ WINDOWS \ erdnt \ Hiv-backup \ Users \00000005 \ Ntuser.dat + 2008-01-15 22:03:02 3.670.016 ---- aw C: \ WINDOWS \ erdnt \ Hiv-backup \ Users \00000005 \ Ntuser.dat - 2008-01-15 21:03:50 208.896 ---- aw C: \ WINDOWS \ erdnt \ Hiv-backup \ Users \00000006 \ UsrClass.dat + 2008-01-15 22:03:02 208.896 ---- aw C: \ WINDOWS \ erdnt \ Hiv-backup \ Users \00000006 \ UsrClass.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))) )))))))))))))))))))))))))))))))))))))))) . . * Note * empty entries & legit default entries worden niet weergegeven REGEDIT4 [HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curre ntVersion \ Run] "Ctfmon.exe" = "C: \ WINDOWS \ system32 \ Ctfmon.exe" [2004-08-04 12:00 15360] "BitTorrent DNA" = "C: \ Program Files \ DNA \ btdna.exe" [2007-12-22 15:39 290112] "curblicense" = "C: \ DOCUME ~ 1 \ Richard \ TOEPASSINGEN ~ 1 \ WAYBOW ~ 1 \ Nurb meer noun.exe" [] "SUPERAntiSpyware" = "C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Run] "RTHDCPL" = "RTHDCPL.EXE" [2006-11-14 09:21 16270848 C: \ WINDOWS \ RTHDCPL.exe] "SkyTel" = "SkyTel.EXE" [2006-05-16 10:04 2879488 C: \ WINDOWS \ SkyTel.exe] "AVG7_CC" = "C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgcc.exe" [2007-12-20 16:29 579072] "SunJavaUpdateSched" = "C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ jusched.exe" [2007-09-25 01:11 132496] "QuickTime Task" = "C: \ Program Files \ QuickTime \ qttask.exe" [2007-10-19 20:16 286720] "Adobe Reader Speed Launcher" = "C: \ Program Files \ Adobe \ Reader 8.0 \ Reader \ Reader_sl.exe" [2007-10-10 19:51 39792] "NvCplDaemon" = "C: \ WINDOWS \ system32 \ NvCpl.dll" [2007-09-17 01:07 8491008] "nwiz" = "nwiz.exe" [2007-09-17 01:07 1626112 C: \ WINDOWS \ system32 \ nwiz.exe] "NvMediaCenter" = "C: \ WINDOWS \ system32 \ NvMcTray. Dll" [2007-09-17 01:07 81920] "TkBellExe" = "C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe" [2007-12-15 23:36 185896] "GrooveMonitor" = "C: \ Program Files \ Microsoft Office \ Office12 \ GrooveMonitor.exe" [2006-10-27 00:47 31016] "LVCOMSX" = "C: \ WINDOWS \ system32 \ LVCOMSX.EXE" [2004-02-25 16:15 221184] "LogitechVideoRepair" = "C: \ Program Files \ Logitech \ Video \ ISStart.exe" [2004-02-25 17:15 454656] "LogitechVideoTray" = "C: \ Program Files \ Logitech \ Video \ LogiTray.exe" [2004-02-25 17:06 212992] "Tweede vleermuis creatieve piek" = "C: \ Documents and Settings \ All Users \ Application Data \ Axis Leesmij Tweede Bat \ dode lite.exe" [] [HKEY_USERS \. DEFAULT \ Software \ Microsoft \ Windows \ Cur rentVersion \ Run] "AVG7_Run" = "C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgw.exe" [2007-12-07 18:42 219136] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ valuta entversion \ Explorer \ shellexecutehooks] "(5AE067D3-9AFB-48E0-853A-EBB7F4A000DA)" = C: \ Program Files \ SUPERAntiSpyware \ SASSEH.DLL [2006-12-20 13:55 77824] [HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ Notify \! SASWinLogon] C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.dll 2007-04-19 13:41 294912 C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.dll S3 gdrv; gdrv, C: \ WINDOWS \ gdrv.sys [2007-12-07 17:44] S3 PhilCam8116; Logitech QuickCam Pro 3000 (PID_08B0), C: \ WINDOWS \ system32 \ drivers \ CamDrL2 1.sys [2004-02-14 04:09] . Inhoud van de 'Geplande taken' map "2007-12-12 20:03:45 C: \ WINDOWS \ Tasks \ AppleSoftwareUpdate.job" - C: \ Program Files \ Apple Software Update \ SoftwareUpdate.exe . ************************************************** ************************ CatchMe 0.3.1344 W2K/XP/Vista - rootkit / stealth malware detector, Gmer, http://www.gmer.net Rootkit scan 2008-01-15 22:05:20 Windows 5.1.2600 Service Pack 2 NTFS het scannen van verborgen processen ... het scannen van verborgen autostart items ... het scannen van verborgen bestanden ... scannen is voltooid verborgen bestanden: 0 ************************************************** ************************ . Afronding tijd: 2008-01-15 22:06:11 - machine werd herstart ComboFix-quarantaine-files.txt 2008-01-15 22:06:09 ComboFix2.txt 2008-01-15 21:05:12 . 2008-01-05 21:00:15 --- EOF --- Logbestand van Trend Micro HijackThis v2.0.2 Scan opgeslagen om 10:07:19 PM, op 1.15.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Draaiende processen: C: \ WINDOWS \ System32 \ Smss.exe C: \ WINDOWS \ system32 \ winlogon.exe C: \ WINDOWS \ system32 \ Services.exe C: \ WINDOWS \ system32 \ lsass.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ System32 \ svchost.exe C: \ WINDOWS \ system32 \ Spoolsv.exe C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgamsvr.exe C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgupsvc.exe C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgemc.exe C: \ WINDOWS \ system32 \ nvsvc32.exe C: \ WINDOWS \ system32 \ PnkBstrA.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ explorer.exe C: \ WINDOWS \ RTHDCPL.EXE C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgcc.exe C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ jusched.exe C: \ Program Files \ Adobe \ Reader 8.0 \ Reader \ Reader_sl.exe C: \ WINDOWS \ system32 \ RUNDLL32.EXE C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe C: \ Program Files \ Microsoft Office \ Office12 \ GrooveMonitor.exe C: \ WINDOWS \ system32 \ LVCOMSX.EXE C: \ Program Files \ Logitech \ Video \ LogiTray.exe C: \ WINDOWS \ system32 \ Ctfmon.exe C: \ Program Files \ DNA \ btdna.exe C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe C: \ Program Files \ Logitech \ Video \ FxSvr2.exe C: \ WINDOWS \ system32 \ wuauclt.exe C: \ WINDOWS \ system32 \ notepad.exe C: \ WINDOWS \ system32 \ wuauclt.exe C: \ Program Files \ Mozilla Firefox \ firefox.exe C: \ Program Files \ Trend Micro \ HijackThis \ sniper.exe.exe R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://www.yahoo.com R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.yahoo.com R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ SearchURL, (Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com R1 - HKCU \ Software \ Microsoft \ Internet Connection Wizard, ShellNext = http://www.yahoo.com/ O2 - BHO: Yahoo! Companion BHO - (02478D38-C3F9-4efb-9B51-7695ECA05670) - C: \ Program Files \ Yahoo! \ Companion \ installs \ CPN \ ycomp5_6_0_1.d ll O2 - BHO: Adobe PDF Reader Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Common Files \ Adobe \ Acrobat \ ActiveX \ AcroIEHelper.dll O2 - BHO: Groove GFS Browser Helper - (72853161-30C5-4D22-B7F9-0BBC1D38A37E) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ GRA8E1 ~ 1.dll O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll O2 - BHO: Windows Live Sign-in Helper - (9030D464-4C02-4ABF-8ECC-5164760863C6) - C: \ Program Files \ Common Files \ Microsoft Shared \ Windows Live \ WindowsLiveLogin.dll O3 - Toolbar: & Yahoo! Companion - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ Program Files \ Yahoo! \ Companion \ installs \ CPN \ ycomp5_6_0_1.d ll O4 - HKLM \ .. \ Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM \ .. \ Run: [SkyTel] SkyTel.EXE O4 - HKLM \ .. \ Run: [AVG7_CC] C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgcc.exe / STARTUP O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ jusched.exe" O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe"-atboottime O4 - HKLM \ .. \ Run: [Adobe Reader Speed Launcher] "C: \ Program Files \ Adobe \ Reader 8.0 \ Reader \ Reader_sl.exe" O4 - HKLM \ .. \ Run: [NvCplDaemon] RUNDLL32.EXE C: \ WINDOWS \ system32 \ NvCpl.dll, NvStartup O4 - HKLM \ .. \ Run: [nwiz] nwiz.exe / install O4 - HKLM \ .. \ Run: [NvMediaCenter] RUNDLL32.EXE C: \ WINDOWS \ system32 \ NvMcTray.dll, NvTaskbarInit O4 - HKLM \ .. \ Run: [TkBellExe] "C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe"-osboot O4 - HKLM \ .. \ Run: [GrooveMonitor] "C: \ Program Files \ Microsoft Office \ Office12 \ GrooveMonitor.exe" O4 - HKLM \ .. \ Run: [LVCOMSX] C: \ WINDOWS \ system32 \ LVCOMSX.EXE O4 - HKLM \ .. \ Run: [LogitechVideoRepair] C: \ Program Files \ Logitech \ Video \ ISStart.exe O4 - HKLM \ .. \ Run: [LogitechVideoTray] C: \ Program Files \ Logitech \ Video \ LogiTray.exe O4 - HKLM \ .. \ Run: [Tweede vleermuis creatieve piek] C: \ Documents and Settings \ All Users \ Application Data \ Axis Leesmij Tweede Bat \ dode lite.exe O4 - HKCU \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe O4 - HKCU \ .. \ Run: [BitTorrent DNA] "C: \ Program Files \ DNA \ btdna.exe" O4 - HKCU \ .. \ Run: [curblicense] C: \ DOCUME ~ 1 \ Richard \ TOEPASSINGEN ~ 1 \ WAYBOW ~ 1 \ Nurb meer noun.exe O4 - HKCU \ .. \ Run: [SUPERAntiSpyware] C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe O4 - HKUS \ S-1-5-19 \ .. \ Run: [AVG7_Run] C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgw.exe / RunOnce (User 'LOCAL SERVICE') O4 - HKUS \ S-1-5-20 \ .. \ Run: [AVG7_Run] C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgw.exe / RunOnce (User 'NETWORK SERVICE') O4 - HKUS \ S-1-5-18 \ .. \ Run: [AVG7_Run] C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgw.exe / RunOnce (User 'SYSTEM') O4 - HKUS \. DEFAULT \ .. \ Run: [AVG7_Run] C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgw.exe / RunOnce (User 'Default user') O8 - Extra context menu item: E & xporteren naar Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ EXCEL.EXE/3000 O9 - Extra button: (geen naam) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll O9 - Extra 'Tools' MENUITEM: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll O9 - Extra button: Verzenden naar OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ ONBttnIE.dll O9 - Extra 'Tools' MENUITEM: S & einde aan OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ ONBttnIE.dll O9 - Extra button: Onderzoek - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ REFIEBAR.DLL O9 - Extra button: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe O9 - Extra 'Tools' MENUITEM: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe O16 - DPF: (6414512B-B978-451D-A0D8-FCFDF33E833C) (WUWebControl Class) -- http://www.update.microsoft.com/wind...?1197308803562 O16 - DPF: (C3F79A2B-B9B4-4A66-B012-3EE46475B072) (MessengerStatsClient Class) -- http://messenger.zone.msn.com/binary...t.cab56907.cab O18 - Protocol: grooveLocalGWS - (88FED34C-F0CA-4636-A375-3CB6248B04CD) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ GR99D3 ~ 1.dll O20 - Winlogon Notify:! SASWinLogon - C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.dll O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - Grisoft, sro - C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - Grisoft, sro - C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - Grisoft, sro - C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgemc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C: \ WINDOWS \ system32 \ nvsvc32.exe O23 - Service: PnkBstrA - Onbekende eigenaar - C: \ WINDOWS \ system32 \ PnkBstrA.exe -- End of file - 6716 bytes |
|
#10
| |||
| |||
| Ga naar My Computer-> Extra-> Mapopties-> View tabblad:
---------- Druk op CTRL + ALT + DELETE om Process Monitor. Klik op het tabblad Processen en vermoorden van de processen voor lite.exe <<Of dood Lite.exe noun.exe <<Of Nurb meer noun.exe ---------- Open HijackThis en selecteer Doe een systeemscan alleen plaats dan een vinkje naast: (indien gevonden) O4 - HKLM \ .. \ Run: [Tweede vleermuis creatieve piek] C: \ Documents and Settings \ All Users \ Application Data \ Axis Leesmij Tweede Bat \ dode lite.exe O4 - HKCU \ .. \ Run: [curblicense] C: \ DOCUME ~ 1 \ Richard \ TOEPASSINGEN ~ 1 \ WAYBOW ~ 1 \ Nurb meer noun.exe Sluit alle vensters behalve HijackThis en klik op Fix gecontroleerd Afsluiten HijackThis. ---------- Open Deze computer vanaf het bureaublad en locathe en verwijder deze bestanden. (indien gevonden) C: \ Documents and Settings \ All Users \ Application Data \ Axis Leesmij Tweede Bat \dode lite.exe C: \ DOCUME ~ 1 \ Richard \ TOEPASSINGEN ~ 1 \ WAYBOW ~ 1 \Nurb meer noun.exe ---------- Voer de F-Secure Online Scanner Opmerking: Deze scanner werkt alleen met Internet Explorer!
---------- Volgende bericht toevoegen F-Secure log Nieuw HijackThis log |
![]() |
|
| Bladwijzers |
Gelijkaardige Draden | ||||
| Draad | Thread Starter | Forum | Antwoorden | Last Post |
| Iexplore.exe | electra369 | Virus, spyware & Security | 1 | 12 Jan 2009 00:16 |
| Iexplore virus en nog meer? | rreiss | Virus, spyware & Security | 1 | 19 okt 2008 18:46 |
| Iexplore.exe # 3 | jman8700 | Virus, spyware & Security | 8 | 29 mei 2008 10:39 |
| Iexplore.exe # 2 | opetke | Virus, spyware & Security | 3 | De 3 februari 2008 16:18 |
| Een ander iexplore>. < | gevoel | Virus, spyware & Security | 20 | 18 Jan 2008 08:15 |
| Thread Tools | |
| |