Mededeling

Collapse
No announcement yet.

Comodo Firewall

Collapse
X
  •  
  • Filter
  • Tijd
  • Show
Clear All
new posts

  • Comodo Firewall

    Hallo allemaal

    Fijne feestdagen toegewenst en alvast een gelukkig nieuw jaar.

    mijn pc draait en reageert ook traag en loopt vage bestanden zonder naam te kopieren..

    ook is mijn toegang tot de programmabeheer en toegang tot de taakbeheer geblokkeerd

    Dit is de hijack log...

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:31:47, on 26-12-2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\acer\Acer eConsole\MediaServerService.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\COMODO\Firewall\cmdagent.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Acer\eRecovery\Monitor.exe
    C:\WINDOWS\system32\VTTimer.exe
    C:\WINDOWS\system32\VTtrayp.exe
    C:\Program Files\Acer\Acer eMode Management\AspireService.exe
    C:\Program Files\Acer\Acer eConsole\MediaSync.exe
    C:\Program Files\Muiltmedia keyboard Utility\2.0\KbdAp32A.exe
    C:\Program Files\Browser Mouse\mouse32a.exe
    C:\Program Files\TomTom HOME\TomTomHOME.exe
    C:\Program Files\SPYWAREfighter\spftray.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
    C:\Program Files\COMODO\Firewall\cfp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\Documents and Settings\baby_E-tje\Program Files\BitTorrent_DNA\dna.exe
    C:\PROGRA~1\MICROS~2\rapimgr.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\suspend.exe
    C:\Program Files\hijack\HijackThis.exe

    O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [LaunchApp] Alaunch
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
    O4 - HKLM\..\Run: [ntiMUI] C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
    O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe
    O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe
    O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Muiltmedia keyboard Utility\2.0\KbdAp32A.exe
    O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser Mouse\mouse32a.exe
    O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
    O4 - HKLM\..\Run: [spywarefighterguard] C:\Program Files\SPYWAREfighter\spftray.exe
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Medichi] medichi.exe
    O4 - HKLM\..\Run: [Medichi2] medichi2.exe
    O4 - HKLM\..\Run: [EliteProtector] "C:\Program Files\EliteProtector\EliteProtector.exe" hide
    O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -s
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [DNA] "C:\Documents and Settings\baby_E-tje\Program Files\BitTorrent_DNA\dna.exe"
    O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/re...s/MSNPUpld.cab
    O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cache.hyvz.com/statics/Aurigm...eUploader4.cab
    O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by129fd.bay129.hotmail.msn.co...x/HMAtchmt.ocx
    O20 - AppInit_DLLs: murka.dat
    O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\acer\Acer eConsole\MediaServerService.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: Planner voor Automatische LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

    --
    End of file - 8989 bytes
    Last edited by dinga; 25-12-07, 18:06. Reden: onvoldoende/verkeerde informatie in onderwerp

  • #2
    internet verbind naar upspiral

    Mijn vorige onderwerp was verkeerd ik kom er net achter dat de comodo firewall na de problem pas door mijn zoon is geinstalleerd.

    hierbij ook mijn recente hijack log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 3:38:45, on 28-12-2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\acer\Acer eConsole\MediaServerService.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Acer\eRecovery\Monitor.exe
    C:\WINDOWS\system32\VTTimer.exe
    C:\WINDOWS\system32\VTtrayp.exe
    C:\Program Files\Acer\Acer eMode Management\AspireService.exe
    C:\Program Files\Acer\Acer eConsole\MediaSync.exe
    C:\Program Files\Muiltmedia keyboard Utility\2.0\KbdAp32A.exe
    C:\Program Files\Browser Mouse\mouse32a.exe
    C:\Program Files\TomTom HOME\TomTomHOME.exe
    C:\Program Files\SPYWAREfighter\spftray.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
    C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\Documents and Settings\baby_E-tje\Program Files\BitTorrent_DNA\dna.exe
    C:\PROGRA~1\MICROS~2\rapimgr.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\hijack\HijackThis.exe

    O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [LaunchApp] Alaunch
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
    O4 - HKLM\..\Run: [ntiMUI] C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
    O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe
    O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe
    O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Muiltmedia keyboard Utility\2.0\KbdAp32A.exe
    O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser Mouse\mouse32a.exe
    O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
    O4 - HKLM\..\Run: [spywarefighterguard] C:\Program Files\SPYWAREfighter\spftray.exe
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Medichi] medichi.exe
    O4 - HKLM\..\Run: [Medichi2] medichi2.exe
    O4 - HKLM\..\Run: [EliteProtector] "C:\Program Files\EliteProtector\EliteProtector.exe" hide
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [DNA] "C:\Documents and Settings\baby_E-tje\Program Files\BitTorrent_DNA\dna.exe"
    O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
    O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cache.hyvz.com/statics/Aurigma/ImageUploader4.cab
    O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by129fd.bay129.hotmail.msn.com/activex/HMAtchmt.ocx
    O20 - AppInit_DLLs: murka.dat
    O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\acer\Acer eConsole\MediaServerService.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: Planner voor Automatische LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

    --
    End of file - 8518 bytes

    Comment


    • #3
      Hallo Dinga,

      Dit ziet er niet al te best uit.
      Heb je een windows XP installatie-cd bij de hand?

      Sluit alle open vensters.
      Start HijackThis nog een keer en plaats een vinkje bij de volgende items:

      O4 - HKLM\..\Run: [Medichi] medichi.exe
      O4 - HKLM\..\Run: [Medichi2] medichi2.exe
      O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
      O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
      O20 - AppInit_DLLs: murka.dat


      Klik daarna op "Fix checked" en sluit HijackThis af.

      Download combofix.exe: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
      Plaats het op je bureaublad.
      Dubbelklik er op om het programma te starten.
      In het scherm dat verschijnt tik je een 1 in om het cleaning- en analysesproces te laten uitvoeren.
      Volg de instructies op het scherm.
      Als het tooltje klaar is, opent er een logfile (combofix.txt).
      Post de inhoud van dit bestandje samen met een nieuwe hijackthislog.


      Wil combofix niet starten, dan hernoem je het bestand combofix.exe naar test.exe (mag ook een andere naam zijn hoor)

      Comment


      • #4
        combofix log en hijack log

        hoi Marckie
        Bedankt voor je reactie... ik heb alleen geen XP-installatie cd
        Xp was voorgeinstalleerd bij aanschaf.. ik heb wel jou reactie uitgevoerd en deze logs zijn eruit gekomen..

        Combofix log
        ComboFix 07-12-21.4 - baby_E-tje 2007-12-28 9:44:41.9 - FAT32x86
        Gestart vanuit: C:\Documents and Settings\baby_E-tje\Bureaublad\test.exe
        * Nieuw herstelpunt werd aangemaakt
        .

        (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
        .

        C:\Documents and Settings\baby_E-tje\Application Data\antivirus.exe
        C:\WINDOWS\system32\UpMedia

        .
        (((((((((((((((((((( Bestanden Gemaakt van 2007-11-28 to 2007-12-28 ))))))))))))))))))))))))))))))
        .

        2007-12-27 12:36 . 2007-12-27 12:36 <DIR> d--hs---- C:\FOUND.011
        2007-12-27 10:26 . 2007-12-27 10:26 268 --ah----- C:\sqmdata03.sqm
        2007-12-27 10:26 . 2007-12-27 10:26 244 --ah----- C:\sqmnoopt03.sqm
        2007-12-26 06:22 . 2007-12-26 06:22 9,216 --a------ C:\WINDOWS\system32\suspend.exe
        2007-12-25 22:35 . 2007-12-25 22:35 <DIR> d-------- C:\Program Files\COMODO
        2007-12-25 22:35 . 2007-12-25 22:35 <DIR> d-------- C:\Documents and Settings\baby_E-tje\Application Data\Comodo
        2007-12-25 01:07 . 2007-12-25 01:07 <DIR> d-------- C:\Program Files\EliteProtector
        2007-12-25 01:05 . 2007-12-28 03:29 6,144 --a------ C:\WINDOWS\system32\user32.dat
        2007-12-25 01:03 . 2007-12-28 03:28 8,192 --a------ C:\WINDOWS\medichi2.exe
        2007-12-25 01:03 . 2007-12-28 03:28 5,632 --a------ C:\WINDOWS\medichi.exe
        2007-12-25 01:02 . 2007-12-25 01:02 35,840 --a------ C:\WINDOWS\wsystmp_kyg.exe
        2007-12-25 01:01 . 2005-06-01 14:36 18,944 --a------ C:\WINDOWS\system32\wowfx(3).dll
        2007-12-25 01:01 . 2005-06-01 13:24 18,944 --a------ C:\WINDOWS\system32\wowfx(2).dll
        2007-12-25 01:01 . 2007-12-25 01:01 15,872 --a------ C:\WINDOWS\windsk.dll
        2007-12-25 00:43 . 2007-12-25 00:43 34,049 --a------ C:\WINDOWS\trayicon.exe
        2007-12-24 14:36 . 2007-12-24 14:36 <DIR> d--hs---- C:\FOUND.010
        2007-12-21 18:26 . 2007-12-21 18:26 <DIR> d-------- C:\Documents and Settings\baby_E-tje\Application Data\DivX
        2007-12-21 18:22 . 2007-12-21 18:22 <DIR> d-------- C:\Program Files\DivX
        2007-12-18 17:59 . 2007-12-18 17:59 <DIR> d--hs---- C:\FOUND.009
        2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Temp
        2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Settings
        2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Par2
        2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Newsgroups
        2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Import
        2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Downloads
        2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Bodies
        2007-12-14 04:55 . 2007-12-14 04:55 <DIR> d--hs---- C:\FOUND.008
        2007-12-12 22:08 . 2007-03-21 20:33 503,808 --a------ C:\WINDOWS\system32\MSVCP71.DLL
        2007-12-12 22:08 . 2007-03-21 20:33 348,160 --a------ C:\WINDOWS\system32\MSVCR71.DLL
        2007-12-11 23:35 . 2007-12-11 23:35 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
        2007-12-11 23:35 . 2007-12-11 23:35 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb
        2007-12-11 23:34 . 2007-12-11 23:34 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
        2007-12-11 23:34 . 2007-12-11 23:34 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
        2007-12-11 23:34 . 2007-12-11 23:34 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
        2007-12-11 23:32 . 2007-12-11 23:32 352,401 --a------ C:\WINDOWS\system32\DivXMedia.ax
        2007-12-11 23:32 . 2007-12-11 23:32 156,992 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
        2007-12-11 23:32 . 2007-12-11 23:32 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
        2007-12-11 04:18 . 2007-12-11 04:18 <DIR> d--hs---- C:\FOUND.007
        2007-11-30 23:57 . 2007-11-30 23:57 317,616 --a------ C:\WINDOWS\system32\drivers\srtspl.sys
        2007-11-30 23:57 . 2007-11-30 23:57 279,088 --a------ C:\WINDOWS\system32\drivers\srtsp.sys
        2007-11-30 23:57 . 2007-11-30 23:57 43,696 --a------ C:\WINDOWS\system32\drivers\srtspx.sys
        2007-11-30 23:57 . 2007-11-30 23:57 10,549 --a------ C:\WINDOWS\system32\drivers\srtspx.cat
        2007-11-30 23:57 . 2007-11-30 23:57 10,549 --a------ C:\WINDOWS\system32\drivers\srtspl.cat
        2007-11-30 23:57 . 2007-11-30 23:57 10,545 --a------ C:\WINDOWS\system32\drivers\srtsp.cat
        2007-11-30 23:57 . 2007-11-30 23:57 1,430 --a------ C:\WINDOWS\system32\drivers\srtspl.inf
        2007-11-30 23:57 . 2007-11-30 23:57 1,421 --a------ C:\WINDOWS\system32\drivers\srtspx.inf
        2007-11-30 23:57 . 2007-11-30 23:57 1,415 --a------ C:\WINDOWS\system32\drivers\srtsp.inf
        2007-11-28 00:42 . 2007-11-28 00:42 268 --ah----- C:\sqmdata02.sqm
        2007-11-28 00:42 . 2007-11-28 00:42 244 --ah----- C:\sqmnoopt02.sqm

        .
        ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2007-12-25 00:02 37,888 ----a-w C:\WINDOWS\system32\drivers\beep.sys
        2007-12-25 00:02 37,888 ----a-w C:\WINDOWS\system32\dllcache\beep.sys
        2007-12-11 22:34 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
        2007-12-11 22:34 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
        2007-12-11 22:34 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
        2007-12-11 22:34 129,784 ------w C:\WINDOWS\system32\pxafs.dll
        2007-12-11 22:34 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
        2007-12-11 22:34 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
        2007-12-11 22:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
        2007-12-11 22:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
        2007-12-11 22:33 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
        2007-12-11 22:33 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
        2007-12-11 22:33 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
        2007-12-11 22:33 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
        2007-12-11 22:33 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
        2007-12-11 22:33 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
        2007-12-11 22:33 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
        2007-12-11 22:33 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
        2007-12-11 22:33 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
        2007-12-11 22:33 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
        2007-12-05 12:01 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
        2007-12-05 12:01 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
        2007-12-05 12:01 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
        2007-12-05 12:01 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
        2007-11-22 12:46 --------- d-----w C:\Program Files\Microsoft.NET
        2007-11-14 07:29 450,560 ----a-w C:\WINDOWS\system32\dllcache\jscript.dll
        2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
        2007-10-30 10:20 3,079,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
        2007-10-29 22:45 1,291,776 ----a-w C:\WINDOWS\system32\quartz.dll
        2007-10-29 22:45 1,291,776 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
        2007-10-25 16:57 8,501,760 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
        2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
        2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
        2007-10-11 06:14 96,768 ----a-w C:\WINDOWS\system32\dllcache\inseng.dll
        2007-10-11 06:14 662,528 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
        2007-10-11 06:14 616,960 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
        2007-10-11 06:14 55,808 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
        2007-10-11 06:14 532,480 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
        2007-10-11 06:14 474,624 ----a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
        2007-10-11 06:14 449,024 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
        2007-10-11 06:14 39,424 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
        2007-10-11 06:14 357,888 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
        2007-10-11 06:14 251,392 ----a-w C:\WINDOWS\system32\dllcache\iepeers.dll
        2007-10-11 06:14 205,312 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
        2007-10-11 06:14 16,384 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
        2007-10-11 06:14 151,552 ----a-w C:\WINDOWS\system32\dllcache\cdfview.dll
        2007-10-11 06:14 146,432 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
        2007-10-11 06:14 1,494,528 ----a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
        2007-10-11 06:14 1,057,280 ----a-w C:\WINDOWS\system32\dllcache\danim.dll
        2007-10-11 06:14 1,023,488 ----a-w C:\WINDOWS\system32\dllcache\browseui.dll
        2007-10-10 11:16 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe
        .

        ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        REGEDIT4
        *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]
        "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-06-25 12:14]
        "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-23 18:39]
        "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-20 22:36]
        "DNA"="C:\Documents and Settings\baby_E-tje\Program Files\BitTorrent_DNA\dna.exe" [2007-05-30 09:55]
        "BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [2007-09-08 00:01]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "LaunchApp"="Alaunch"
        "SoundMan"="SOUNDMAN.EXE" [2005-06-08 08:31 C:\WINDOWS\SOUNDMAN.EXE]
        "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-07-15 01:07]
        "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 05:00]
        "MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 05:00]
        "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 05:00]
        "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 05:00]
        "eRecoveryService"="C:\Program Files\Acer\eRecovery\Monitor.exe" [2005-06-20 09:03]
        "ntiMUI"="C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 18:15]
        "VTTimer"="VTTimer.exe" [2005-05-13 12:57 C:\WINDOWS\system32\VTTimer.exe]
        "VTTrayp"="VTtrayp.exe" [2005-05-13 12:57 C:\WINDOWS\system32\VTTrayp.exe]
        "AspireService"="C:\Program Files\Acer\Acer eMode Management\AspireService.exe" [2005-06-04 12:40]
        "MediaSync"="C:\Program Files\Acer\Acer eConsole\MediaSync.exe" [2005-06-01 14:25]
        "FLMK08KB"="C:\Program Files\Muiltmedia keyboard Utility\2.0\KbdAp32A.exe" [2006-01-21 16:31]
        "FLMOFFICE4DMOUSE"="C:\Program Files\Browser Mouse\mouse32a.exe" [2006-01-21 16:32]
        "TomTomHOME.exe"="C:\Program Files\TomTom HOME\TomTomHOME.exe" [2007-03-14 16:52]
        "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
        "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 23:59]
        "osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2007-01-14 01:11]
        "spywarefighterguard"="C:\Program Files\SPYWAREfighter\spftray.exe" [2007-06-08 11:52]
        "Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 10:22]
        "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
        "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-22 15:09]
        "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
        "EliteProtector"="C:\Program Files\EliteProtector\EliteProtector.exe"

        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
        "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 05:00]

        C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\
        WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-04-15 11:51:53]

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
        SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, wowfx.dll

        R1 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys [2004-12-17 17:14]
        R2 int15.sys;int15.sys;C:\Program Files\Acer\eRecovery\int15.sys [2005-01-13 14:46]
        S3 SpyFighter;SpyFighter Guard Device;C:\Program Files\SPYWAREfighter\spyfighter.sys [2007-06-08 11:52]
        S4 SPYWAREfighterRP;SPYWAREfighterRP;"C:\Program Files\SPYWAREfighter\spfprc.exe" [2007-06-08 11:52]

        .
        Inhoud van de 'Gedeelde Taken' map
        "2007-12-24 17:36:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
        - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
        "2007-12-24 20:50:04 C:\WINDOWS\Tasks\Norton AntiVirus - Volledige systeemscan - baby_E-tje.job"
        - C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
        .
        **************************************************************************

        catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2007-12-28 09:46:58
        Windows 5.1.2600 Service Pack 2 FAT NTAPI

        scannen van verborgen processen ...

        scannen van verborgen autostart items ...

        scannen van verborgen bestanden ...

        Scan succesvol afgerond
        verborgen bestanden: 0

        **************************************************************************
        .
        Voltooingstijd: 2007-12-28 9:47:30
        C:\ComboFix-quarantined-files.txt ... 2007-08-31 11:15
        C:\combofixlog.txt ... 2007-08-26 03:09
        C:\ComboFix3.txt ... 2007-08-30 16:53
        C:\ComboFix2.txt ... 2007-08-31 11:15
        .
        2007-12-25 02:27:22 --- E O F ---


        En de nieuwe hijack log..

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 9:52:05, on 28-12-2007
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\acer\Acer eConsole\MediaServerService.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
        C:\Program Files\Acer\eRecovery\Monitor.exe
        C:\WINDOWS\system32\VTTimer.exe
        C:\WINDOWS\system32\VTtrayp.exe
        C:\Program Files\Acer\Acer eMode Management\AspireService.exe
        C:\Program Files\Acer\Acer eConsole\MediaSync.exe
        C:\Program Files\Muiltmedia keyboard Utility\2.0\KbdAp32A.exe
        C:\Program Files\Browser Mouse\mouse32a.exe
        C:\Program Files\TomTom HOME\TomTomHOME.exe
        C:\Program Files\SPYWAREfighter\spftray.exe
        C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
        C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
        C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\MSN Messenger\MsnMsgr.Exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Microsoft ActiveSync\wcescomm.exe
        C:\Documents and Settings\baby_E-tje\Program Files\BitTorrent_DNA\dna.exe
        C:\PROGRA~1\MICROS~2\rapimgr.exe
        C:\Program Files\WinZip\WZQKPICK.EXE
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\internet explorer\iexplore.exe
        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
        C:\WINDOWS\system32\suspend.exe
        C:\WINDOWS\explorer.exe
        C:\WINDOWS\system32\notepad.exe
        C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
        C:\Program Files\hijack\HijackThis.exe

        O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O4 - HKLM\..\Run: [LaunchApp] Alaunch
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
        O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
        O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
        O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
        O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
        O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
        O4 - HKLM\..\Run: [ntiMUI] C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
        O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
        O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
        O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe
        O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe
        O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Muiltmedia keyboard Utility\2.0\KbdAp32A.exe
        O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser Mouse\mouse32a.exe
        O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
        O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
        O4 - HKLM\..\Run: [spywarefighterguard] C:\Program Files\SPYWAREfighter\spftray.exe
        O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [EliteProtector] "C:\Program Files\EliteProtector\EliteProtector.exe" hide
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
        O4 - HKCU\..\Run: [DNA] "C:\Documents and Settings\baby_E-tje\Program Files\BitTorrent_DNA\dna.exe"
        O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
        O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
        O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by129fd.bay129.hotmail.msn.com/activex/HMAtchmt.ocx
        O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\acer\Acer eConsole\MediaServerService.exe
        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
        O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
        O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
        O23 - Service: Planner voor Automatische LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
        O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

        --
        End of file - 8218 bytes

        Comment


        • #5
          Open een kladblokbestand.
          Kopieer de ondestaande code, en plak deze in het kladblokbestand.
          Sla het kladblokbestand op als CFScript.txt
          Code:
          File::
          C:\WINDOWS\system32\drivers\beep.sys
          C:\WINDOWS\system32\dllcache\beep.sys
          C:\WINDOWS\medichi.exe
          C:\WINDOWS\medichi2.exe
          C:\WINDOWS\system32\murka.dat
          
          Registry::
          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
          "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
          Sleep nu het bestand CFScript.txt in het bestand ComboFix.exe

          ComboFix zal opnieuw starten.
          Wanneer ComboFix klaar is, dit kan na een herstart zijn, opent er een logfile.
          Post de inhoud van de logfile.


          (lukt het niet dan sleep je CFScript in test.exe)
          Last edited by Marckie; 25-12-07, 18:44.

          Comment


          • #6
            combofix met CFScript

            Hallo Marckie..

            Bedankt weer voor je snelle reactie

            Hierbij de combofix log met CFScript..

            ComboFix 07-12-21.4 - baby_E-tje 2007-12-28 10:03:30.10 - FAT32x86
            Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1043.18.124 [GMT 1:00]
            Gestart vanuit: C:\Documents and Settings\baby_E-tje\Bureaublad\test.exe
            Command switches used :: C:\Documents and Settings\baby_E-tje\Bureaublad\CFScript.txt
            * Nieuw herstelpunt werd aangemaakt

            FILE
            C:\WINDOWS\medichi.exe
            C:\WINDOWS\medichi2.exe
            C:\WINDOWS\system32\dllcache\beep.sys
            C:\WINDOWS\system32\drivers\beep.sys
            C:\WINDOWS\system32\murka.dat
            .

            (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
            .

            C:\WINDOWS\medichi.exe
            C:\WINDOWS\medichi2.exe
            C:\WINDOWS\system32\dllcache\beep.sys
            C:\WINDOWS\system32\drivers\beep.sys

            .
            (((((((((((((((((((( Bestanden Gemaakt van 2007-11-28 to 2007-12-28 ))))))))))))))))))))))))))))))
            .

            2007-12-27 12:36 . 2007-12-27 12:36 <DIR> d--hs---- C:\FOUND.011
            2007-12-27 10:26 . 2007-12-27 10:26 268 --ah----- C:\sqmdata03.sqm
            2007-12-27 10:26 . 2007-12-27 10:26 244 --ah----- C:\sqmnoopt03.sqm
            2007-12-26 06:22 . 2007-12-26 06:22 9,216 --a------ C:\WINDOWS\system32\suspend.exe
            2007-12-25 22:35 . 2007-12-25 22:35 <DIR> d-------- C:\Program Files\COMODO
            2007-12-25 22:35 . 2007-12-25 22:35 <DIR> d-------- C:\Documents and Settings\baby_E-tje\Application Data\Comodo
            2007-12-25 01:07 . 2007-12-25 01:07 <DIR> d-------- C:\Program Files\EliteProtector
            2007-12-25 01:05 . 2007-12-28 03:29 6,144 --a------ C:\WINDOWS\system32\user32.dat
            2007-12-25 01:02 . 2007-12-25 01:02 35,840 --a------ C:\WINDOWS\wsystmp_kyg.exe
            2007-12-25 01:01 . 2005-06-01 14:36 18,944 --a------ C:\WINDOWS\system32\wowfx(3).dll
            2007-12-25 01:01 . 2005-06-01 13:24 18,944 --a------ C:\WINDOWS\system32\wowfx(2).dll
            2007-12-25 01:01 . 2007-12-25 01:01 15,872 --a------ C:\WINDOWS\windsk.dll
            2007-12-25 00:43 . 2007-12-25 00:43 34,049 --a------ C:\WINDOWS\trayicon.exe
            2007-12-24 14:36 . 2007-12-24 14:36 <DIR> d--hs---- C:\FOUND.010
            2007-12-21 18:26 . 2007-12-21 18:26 <DIR> d-------- C:\Documents and Settings\baby_E-tje\Application Data\DivX
            2007-12-21 18:22 . 2007-12-21 18:22 <DIR> d-------- C:\Program Files\DivX
            2007-12-18 17:59 . 2007-12-18 17:59 <DIR> d--hs---- C:\FOUND.009
            2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Temp
            2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Settings
            2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Par2
            2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Newsgroups
            2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Import
            2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Downloads
            2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Bodies
            2007-12-14 04:55 . 2007-12-14 04:55 <DIR> d--hs---- C:\FOUND.008
            2007-12-12 22:08 . 2007-03-21 20:33 503,808 --a------ C:\WINDOWS\system32\MSVCP71.DLL
            2007-12-12 22:08 . 2007-03-21 20:33 348,160 --a------ C:\WINDOWS\system32\MSVCR71.DLL
            2007-12-11 23:35 . 2007-12-11 23:35 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
            2007-12-11 23:35 . 2007-12-11 23:35 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb
            2007-12-11 23:34 . 2007-12-11 23:34 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
            2007-12-11 23:34 . 2007-12-11 23:34 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
            2007-12-11 23:34 . 2007-12-11 23:34 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
            2007-12-11 23:32 . 2007-12-11 23:32 352,401 --a------ C:\WINDOWS\system32\DivXMedia.ax
            2007-12-11 23:32 . 2007-12-11 23:32 156,992 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
            2007-12-11 23:32 . 2007-12-11 23:32 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
            2007-12-11 04:18 . 2007-12-11 04:18 <DIR> d--hs---- C:\FOUND.007
            2007-11-30 23:57 . 2007-11-30 23:57 317,616 --a------ C:\WINDOWS\system32\drivers\srtspl.sys
            2007-11-30 23:57 . 2007-11-30 23:57 279,088 --a------ C:\WINDOWS\system32\drivers\srtsp.sys
            2007-11-30 23:57 . 2007-11-30 23:57 43,696 --a------ C:\WINDOWS\system32\drivers\srtspx.sys
            2007-11-30 23:57 . 2007-11-30 23:57 10,549 --a------ C:\WINDOWS\system32\drivers\srtspx.cat
            2007-11-30 23:57 . 2007-11-30 23:57 10,549 --a------ C:\WINDOWS\system32\drivers\srtspl.cat
            2007-11-30 23:57 . 2007-11-30 23:57 10,545 --a------ C:\WINDOWS\system32\drivers\srtsp.cat
            2007-11-30 23:57 . 2007-11-30 23:57 1,430 --a------ C:\WINDOWS\system32\drivers\srtspl.inf
            2007-11-30 23:57 . 2007-11-30 23:57 1,421 --a------ C:\WINDOWS\system32\drivers\srtspx.inf
            2007-11-30 23:57 . 2007-11-30 23:57 1,415 --a------ C:\WINDOWS\system32\drivers\srtsp.inf
            2007-11-28 00:42 . 2007-11-28 00:42 268 --ah----- C:\sqmdata02.sqm
            2007-11-28 00:42 . 2007-11-28 00:42 244 --ah----- C:\sqmnoopt02.sqm

            .
            ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
            .
            2007-12-11 22:34 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
            2007-12-11 22:34 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
            2007-12-11 22:34 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
            2007-12-11 22:34 129,784 ------w C:\WINDOWS\system32\pxafs.dll
            2007-12-11 22:34 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
            2007-12-11 22:34 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
            2007-12-11 22:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
            2007-12-11 22:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
            2007-12-11 22:33 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
            2007-12-11 22:33 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
            2007-12-11 22:33 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
            2007-12-11 22:33 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
            2007-12-11 22:33 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
            2007-12-11 22:33 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
            2007-12-11 22:33 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
            2007-12-11 22:33 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
            2007-12-11 22:33 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
            2007-12-11 22:33 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
            2007-12-05 12:01 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
            2007-12-05 12:01 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
            2007-12-05 12:01 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
            2007-12-05 12:01 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
            2007-11-22 12:46 --------- d-----w C:\Program Files\Microsoft.NET
            2007-11-14 07:29 450,560 ----a-w C:\WINDOWS\system32\dllcache\jscript.dll
            2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
            2007-10-30 10:20 3,079,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
            2007-10-29 22:45 1,291,776 ----a-w C:\WINDOWS\system32\quartz.dll
            2007-10-29 22:45 1,291,776 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
            2007-10-25 16:57 8,501,760 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
            2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
            2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
            2007-10-11 06:14 96,768 ----a-w C:\WINDOWS\system32\dllcache\inseng.dll
            2007-10-11 06:14 662,528 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
            2007-10-11 06:14 616,960 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
            2007-10-11 06:14 55,808 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
            2007-10-11 06:14 532,480 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
            2007-10-11 06:14 474,624 ----a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
            2007-10-11 06:14 449,024 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
            2007-10-11 06:14 39,424 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
            2007-10-11 06:14 357,888 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
            2007-10-11 06:14 251,392 ----a-w C:\WINDOWS\system32\dllcache\iepeers.dll
            2007-10-11 06:14 205,312 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
            2007-10-11 06:14 16,384 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
            2007-10-11 06:14 151,552 ----a-w C:\WINDOWS\system32\dllcache\cdfview.dll
            2007-10-11 06:14 146,432 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
            2007-10-11 06:14 1,494,528 ----a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
            2007-10-11 06:14 1,057,280 ----a-w C:\WINDOWS\system32\dllcache\danim.dll
            2007-10-11 06:14 1,023,488 ----a-w C:\WINDOWS\system32\dllcache\browseui.dll
            2007-10-10 11:16 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe
            .

            ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            REGEDIT4
            *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]
            "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-06-25 12:14]
            "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-23 18:39]
            "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-20 22:36]
            "DNA"="C:\Documents and Settings\baby_E-tje\Program Files\BitTorrent_DNA\dna.exe" [2007-05-30 09:55]
            "BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [2007-09-08 00:01]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "LaunchApp"="Alaunch"
            "SoundMan"="SOUNDMAN.EXE" [2005-06-08 08:31 C:\WINDOWS\SOUNDMAN.EXE]
            "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-07-15 01:07]
            "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 05:00]
            "MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 05:00]
            "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 05:00]
            "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 05:00]
            "eRecoveryService"="C:\Program Files\Acer\eRecovery\Monitor.exe" [2005-06-20 09:03]
            "ntiMUI"="C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 18:15]
            "VTTimer"="VTTimer.exe" [2005-05-13 12:57 C:\WINDOWS\system32\VTTimer.exe]
            "VTTrayp"="VTtrayp.exe" [2005-05-13 12:57 C:\WINDOWS\system32\VTTrayp.exe]
            "AspireService"="C:\Program Files\Acer\Acer eMode Management\AspireService.exe" [2005-06-04 12:40]
            "MediaSync"="C:\Program Files\Acer\Acer eConsole\MediaSync.exe" [2005-06-01 14:25]
            "FLMK08KB"="C:\Program Files\Muiltmedia keyboard Utility\2.0\KbdAp32A.exe" [2006-01-21 16:31]
            "FLMOFFICE4DMOUSE"="C:\Program Files\Browser Mouse\mouse32a.exe" [2006-01-21 16:32]
            "TomTomHOME.exe"="C:\Program Files\TomTom HOME\TomTomHOME.exe" [2007-03-14 16:52]
            "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
            "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 23:59]
            "osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2007-01-14 01:11]
            "spywarefighterguard"="C:\Program Files\SPYWAREfighter\spftray.exe" [2007-06-08 11:52]
            "Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 10:22]
            "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
            "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-22 15:09]
            "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
            "EliteProtector"="C:\Program Files\EliteProtector\EliteProtector.exe"

            [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
            "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 05:00]

            C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\
            WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-04-15 11:51:53]

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
            SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, wowfx.dll

            R1 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys [2004-12-17 17:14]
            R2 int15.sys;int15.sys;C:\Program Files\Acer\eRecovery\int15.sys [2005-01-13 14:46]
            S3 SpyFighter;SpyFighter Guard Device;C:\Program Files\SPYWAREfighter\spyfighter.sys [2007-06-08 11:52]
            S4 SPYWAREfighterRP;SPYWAREfighterRP;"C:\Program Files\SPYWAREfighter\spfprc.exe" [2007-06-08 11:52]

            .
            Inhoud van de 'Gedeelde Taken' map
            "2007-12-24 17:36:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
            - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
            "2007-12-24 20:50:04 C:\WINDOWS\Tasks\Norton AntiVirus - Volledige systeemscan - baby_E-tje.job"
            - C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
            .
            **************************************************************************

            catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2007-12-28 10:05:28
            Windows 5.1.2600 Service Pack 2 FAT NTAPI

            scannen van verborgen processen ...

            scannen van verborgen autostart items ...

            scannen van verborgen bestanden ...

            Scan succesvol afgerond
            verborgen bestanden: 0

            **************************************************************************
            .
            Voltooingstijd: 2007-12-28 10:05:59
            C:\ComboFix2.txt ... 2007-12-28 09:47
            C:\ComboFix-quarantined-files.txt ... 2007-08-31 11:15
            C:\combofixlog.txt ... 2007-08-26 03:09
            C:\ComboFix3.txt ... 2007-08-31 11:15
            .
            2007-12-25 02:27:22 --- E O F ---

            En ook een nieuwe hijack log..

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 10:16:02, on 28-12-2007
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\acer\Acer eConsole\MediaServerService.exe
            C:\WINDOWS\SOUNDMAN.EXE
            C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
            C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            C:\Program Files\Acer\eRecovery\Monitor.exe
            C:\WINDOWS\system32\VTTimer.exe
            C:\WINDOWS\system32\VTtrayp.exe
            C:\Program Files\Acer\Acer eMode Management\AspireService.exe
            C:\Program Files\Acer\Acer eConsole\MediaSync.exe
            C:\Program Files\Muiltmedia keyboard Utility\2.0\KbdAp32A.exe
            C:\Program Files\Browser Mouse\mouse32a.exe
            C:\Program Files\TomTom HOME\TomTomHOME.exe
            C:\Program Files\Common Files\Symantec Shared\ccApp.exe
            C:\Program Files\SPYWAREfighter\spftray.exe
            C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
            C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\MSN Messenger\MsnMsgr.Exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Program Files\Microsoft ActiveSync\wcescomm.exe
            C:\Documents and Settings\baby_E-tje\Program Files\BitTorrent_DNA\dna.exe
            C:\PROGRA~1\MICROS~2\rapimgr.exe
            C:\Program Files\WinZip\WZQKPICK.EXE
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Program Files\internet explorer\iexplore.exe
            C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\WINDOWS\system32\NOTEPAD.EXE
            C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
            C:\Program Files\hijack\HijackThis.exe

            O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O4 - HKLM\..\Run: [LaunchApp] Alaunch
            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
            O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
            O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
            O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
            O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
            O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
            O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
            O4 - HKLM\..\Run: [ntiMUI] C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
            O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
            O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
            O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe
            O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe
            O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Muiltmedia keyboard Utility\2.0\KbdAp32A.exe
            O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser Mouse\mouse32a.exe
            O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
            O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
            O4 - HKLM\..\Run: [spywarefighterguard] C:\Program Files\SPYWAREfighter\spftray.exe
            O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
            O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [EliteProtector] "C:\Program Files\EliteProtector\EliteProtector.exe" hide
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
            O4 - HKCU\..\Run: [DNA] "C:\Documents and Settings\baby_E-tje\Program Files\BitTorrent_DNA\dna.exe"
            O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
            O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
            O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
            O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by129fd.bay129.hotmail.msn.com/activex/HMAtchmt.ocx
            O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\acer\Acer eConsole\MediaServerService.exe
            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
            O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
            O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
            O23 - Service: Planner voor Automatische LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
            O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

            --
            End of file - 8252 bytes

            Comment


            • #7
              Open een kladblokbestand.
              Kopieer onderstaande code in dit kladblokbestand.
              Ga naar Bestand - Opslaan als.
              Bij "Opslaan in" kies je: Bureaublad
              Bij "Bestandsnaam" zet je: look.bat
              Bij "Opslaan als type" selecteer je: Alle bestanden (*.*).
              Klik op de knop Opslaan.
              Code:
              dir %Systemdrive%\beep.sys /a h /s > files.txt
              start notepad files.txt
              Dubbelklik op look.bat en post de inhoud van de logfile die opent.

              Comment


              • #8
                Doe dit ook nog even:
                Open een kladblokbestand.
                Kopieer onderstaande code in dit kladblokbestand.
                Ga naar Bestand - Opslaan als.
                Bij "Opslaan in" kies je: Bureaublad
                Bij "Bestandsnaam" zet je: fix.reg
                Bij "Opslaan als type" selecteer je: Alle bestanden (*.*).
                Klik op de knop Opslaan.
                Code:
                REGEDIT4
                
                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
                "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
                Dubbelklik op de fix.reg file en laat de wijzigingen aan het register toevoegen.

                Comment


                • #9
                  look.bat logfile

                  Hoi Marckie..

                  Je snelheid is weer geniaal.. Hierbij de look.bat logfile

                  De volumenaam van station C is ACER
                  Het volumenummer is 320D-180E

                  Map van C:\WINDOWS\system32\drivers

                  04-08-2004 05:00 4.224 beep.sys
                  1 bestand(en) 4.224 bytes

                  Map van C:\WINDOWS\system32\dllcache

                  04-08-2004 05:00 4.224 beep.sys
                  1 bestand(en) 4.224 bytes

                  Comment


                  • #10
                    Mooi zo dinga.
                    Herstart je computer even, maak een nieuwe log met combofix en post deze.
                    (deze keer niet test.exe, maar combofix.exe gebruiken aub)
                    Meldt even of er nog problemen zijn.

                    Comment


                    • #11
                      Combofix log

                      Hoi Marckie..

                      Hierbij de laatste Combofix log..

                      Verder lijkt alles goed te zijn nu.. erg bedankt voor je moeite

                      ComboFix 07-12-21.4 - baby_E-tje 2007-12-28 10:51:53.11 - FAT32x86
                      Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1043.18.39 [GMT 1:00]
                      Gestart vanuit: C:\Documents and Settings\baby_E-tje\Bureaublad\ComboFix.exe
                      .

                      (((((((((((((((((((( Bestanden Gemaakt van 2007-11-28 to 2007-12-28 ))))))))))))))))))))))))))))))
                      .

                      2007-12-27 12:36 . 2007-12-27 12:36 <DIR> d--hs---- C:\FOUND.011
                      2007-12-27 10:26 . 2007-12-27 10:26 268 --ah----- C:\sqmdata03.sqm
                      2007-12-27 10:26 . 2007-12-27 10:26 244 --ah----- C:\sqmnoopt03.sqm
                      2007-12-26 06:22 . 2007-12-26 06:22 9,216 --a------ C:\WINDOWS\system32\suspend.exe
                      2007-12-25 22:35 . 2007-12-25 22:35 <DIR> d-------- C:\Program Files\COMODO
                      2007-12-25 22:35 . 2007-12-25 22:35 <DIR> d-------- C:\Documents and Settings\baby_E-tje\Application Data\Comodo
                      2007-12-25 01:07 . 2007-12-25 01:07 <DIR> d-------- C:\Program Files\EliteProtector
                      2007-12-25 01:05 . 2007-12-28 03:29 6,144 --a------ C:\WINDOWS\system32\user32.dat
                      2007-12-25 01:02 . 2007-12-25 01:02 35,840 --a------ C:\WINDOWS\wsystmp_kyg.exe
                      2007-12-25 01:01 . 2005-06-01 14:36 18,944 --a------ C:\WINDOWS\system32\wowfx(3).dll
                      2007-12-25 01:01 . 2005-06-01 13:24 18,944 --a------ C:\WINDOWS\system32\wowfx(2).dll
                      2007-12-25 01:01 . 2007-12-25 01:01 15,872 --a------ C:\WINDOWS\windsk.dll
                      2007-12-25 00:43 . 2007-12-25 00:43 34,049 --a------ C:\WINDOWS\trayicon.exe
                      2007-12-24 14:36 . 2007-12-24 14:36 <DIR> d--hs---- C:\FOUND.010
                      2007-12-21 18:26 . 2007-12-21 18:26 <DIR> d-------- C:\Documents and Settings\baby_E-tje\Application Data\DivX
                      2007-12-21 18:22 . 2007-12-21 18:22 <DIR> d-------- C:\Program Files\DivX
                      2007-12-18 17:59 . 2007-12-18 17:59 <DIR> d--hs---- C:\FOUND.009
                      2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Temp
                      2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Settings
                      2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Par2
                      2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Newsgroups
                      2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Import
                      2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Downloads
                      2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Bodies
                      2007-12-14 04:55 . 2007-12-14 04:55 <DIR> d--hs---- C:\FOUND.008
                      2007-12-12 22:08 . 2007-03-21 20:33 503,808 --a------ C:\WINDOWS\system32\MSVCP71.DLL
                      2007-12-12 22:08 . 2007-03-21 20:33 348,160 --a------ C:\WINDOWS\system32\MSVCR71.DLL
                      2007-12-11 23:35 . 2007-12-11 23:35 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
                      2007-12-11 23:35 . 2007-12-11 23:35 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb
                      2007-12-11 23:34 . 2007-12-11 23:34 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
                      2007-12-11 23:34 . 2007-12-11 23:34 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
                      2007-12-11 23:34 . 2007-12-11 23:34 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
                      2007-12-11 23:32 . 2007-12-11 23:32 352,401 --a------ C:\WINDOWS\system32\DivXMedia.ax
                      2007-12-11 23:32 . 2007-12-11 23:32 156,992 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
                      2007-12-11 23:32 . 2007-12-11 23:32 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
                      2007-12-11 04:18 . 2007-12-11 04:18 <DIR> d--hs---- C:\FOUND.007
                      2007-11-30 23:57 . 2007-11-30 23:57 317,616 --a------ C:\WINDOWS\system32\drivers\srtspl.sys
                      2007-11-30 23:57 . 2007-11-30 23:57 279,088 --a------ C:\WINDOWS\system32\drivers\srtsp.sys
                      2007-11-30 23:57 . 2007-11-30 23:57 43,696 --a------ C:\WINDOWS\system32\drivers\srtspx.sys
                      2007-11-30 23:57 . 2007-11-30 23:57 10,549 --a------ C:\WINDOWS\system32\drivers\srtspx.cat
                      2007-11-30 23:57 . 2007-11-30 23:57 10,549 --a------ C:\WINDOWS\system32\drivers\srtspl.cat
                      2007-11-30 23:57 . 2007-11-30 23:57 10,545 --a------ C:\WINDOWS\system32\drivers\srtsp.cat
                      2007-11-30 23:57 . 2007-11-30 23:57 1,430 --a------ C:\WINDOWS\system32\drivers\srtspl.inf
                      2007-11-30 23:57 . 2007-11-30 23:57 1,421 --a------ C:\WINDOWS\system32\drivers\srtspx.inf
                      2007-11-30 23:57 . 2007-11-30 23:57 1,415 --a------ C:\WINDOWS\system32\drivers\srtsp.inf
                      2007-11-28 00:42 . 2007-11-28 00:42 268 --ah----- C:\sqmdata02.sqm
                      2007-11-28 00:42 . 2007-11-28 00:42 244 --ah----- C:\sqmnoopt02.sqm

                      .
                      ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      2007-12-11 22:34 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
                      2007-12-11 22:34 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
                      2007-12-11 22:34 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
                      2007-12-11 22:34 129,784 ------w C:\WINDOWS\system32\pxafs.dll
                      2007-12-11 22:34 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
                      2007-12-11 22:34 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
                      2007-12-11 22:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
                      2007-12-11 22:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
                      2007-12-11 22:33 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
                      2007-12-11 22:33 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
                      2007-12-11 22:33 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
                      2007-12-11 22:33 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
                      2007-12-11 22:33 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
                      2007-12-11 22:33 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
                      2007-12-11 22:33 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
                      2007-12-11 22:33 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
                      2007-12-11 22:33 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
                      2007-12-11 22:33 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
                      2007-12-05 12:01 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
                      2007-12-05 12:01 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
                      2007-12-05 12:01 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
                      2007-12-05 12:01 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
                      2007-11-22 12:46 --------- d-----w C:\Program Files\Microsoft.NET
                      2007-11-14 07:29 450,560 ----a-w C:\WINDOWS\system32\dllcache\jscript.dll
                      2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
                      2007-10-30 10:20 3,079,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
                      2007-10-29 22:45 1,291,776 ----a-w C:\WINDOWS\system32\quartz.dll
                      2007-10-29 22:45 1,291,776 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
                      2007-10-25 16:57 8,501,760 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
                      2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
                      2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
                      2007-10-11 06:14 96,768 ----a-w C:\WINDOWS\system32\dllcache\inseng.dll
                      2007-10-11 06:14 662,528 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
                      2007-10-11 06:14 616,960 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
                      2007-10-11 06:14 55,808 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
                      2007-10-11 06:14 532,480 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
                      2007-10-11 06:14 474,624 ----a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
                      2007-10-11 06:14 449,024 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
                      2007-10-11 06:14 39,424 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
                      2007-10-11 06:14 357,888 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
                      2007-10-11 06:14 251,392 ----a-w C:\WINDOWS\system32\dllcache\iepeers.dll
                      2007-10-11 06:14 205,312 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
                      2007-10-11 06:14 16,384 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
                      2007-10-11 06:14 151,552 ----a-w C:\WINDOWS\system32\dllcache\cdfview.dll
                      2007-10-11 06:14 146,432 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
                      2007-10-11 06:14 1,494,528 ----a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
                      2007-10-11 06:14 1,057,280 ----a-w C:\WINDOWS\system32\dllcache\danim.dll
                      2007-10-11 06:14 1,023,488 ----a-w C:\WINDOWS\system32\dllcache\browseui.dll
                      2007-10-10 11:16 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe
                      .

                      ((((((((((((((((((((((((((((( [email protected]_ 9.47.02,89 )))))))))))))))))))))))))))))))))))))))))
                      .
                      - 2007-12-25 00:02:20 37,888 ----a-w C:\WINDOWS\system32\dllcache\beep.sys
                      + 2004-08-04 04:00:00 4,224 ----a-w C:\WINDOWS\system32\dllcache\beep.sys
                      - 2007-12-25 00:02:20 37,888 ----a-w C:\WINDOWS\system32\drivers\beep.sys
                      + 2004-08-04 04:00:00 4,224 ----a-w C:\WINDOWS\system32\drivers\beep.sys
                      .
                      ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      .
                      REGEDIT4
                      *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]
                      "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-06-25 12:14]
                      "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-23 18:39]
                      "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-20 22:36]
                      "DNA"="C:\Documents and Settings\baby_E-tje\Program Files\BitTorrent_DNA\dna.exe" [2007-05-30 09:55]
                      "BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [2007-09-08 00:01]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "LaunchApp"="Alaunch"
                      "SoundMan"="SOUNDMAN.EXE" [2005-06-08 08:31 C:\WINDOWS\SOUNDMAN.EXE]
                      "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-07-15 01:07]
                      "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 05:00]
                      "MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 05:00]
                      "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 05:00]
                      "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 05:00]
                      "eRecoveryService"="C:\Program Files\Acer\eRecovery\Monitor.exe" [2005-06-20 09:03]
                      "ntiMUI"="C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 18:15]
                      "VTTimer"="VTTimer.exe" [2005-05-13 12:57 C:\WINDOWS\system32\VTTimer.exe]
                      "VTTrayp"="VTtrayp.exe" [2005-05-13 12:57 C:\WINDOWS\system32\VTTrayp.exe]
                      "AspireService"="C:\Program Files\Acer\Acer eMode Management\AspireService.exe" [2005-06-04 12:40]
                      "MediaSync"="C:\Program Files\Acer\Acer eConsole\MediaSync.exe" [2005-06-01 14:25]
                      "FLMK08KB"="C:\Program Files\Muiltmedia keyboard Utility\2.0\KbdAp32A.exe" [2006-01-21 16:31]
                      "FLMOFFICE4DMOUSE"="C:\Program Files\Browser Mouse\mouse32a.exe" [2006-01-21 16:32]
                      "TomTomHOME.exe"="C:\Program Files\TomTom HOME\TomTomHOME.exe" [2007-03-14 16:52]
                      "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
                      "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 23:59]
                      "osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2007-01-14 01:11]
                      "spywarefighterguard"="C:\Program Files\SPYWAREfighter\spftray.exe" [2007-06-08 11:52]
                      "Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 10:22]
                      "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
                      "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-22 15:09]
                      "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
                      "EliteProtector"="C:\Program Files\EliteProtector\EliteProtector.exe"

                      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                      "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 05:00]

                      C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\
                      WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-04-15 11:51:53]

                      R1 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys [2004-12-17 17:14]
                      R2 int15.sys;int15.sys;C:\Program Files\Acer\eRecovery\int15.sys [2005-01-13 14:46]
                      S3 SpyFighter;SpyFighter Guard Device;C:\Program Files\SPYWAREfighter\spyfighter.sys [2007-06-08 11:52]
                      S4 SPYWAREfighterRP;SPYWAREfighterRP;"C:\Program Files\SPYWAREfighter\spfprc.exe" [2007-06-08 11:52]

                      .
                      Inhoud van de 'Gedeelde Taken' map
                      "2007-12-24 17:36:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
                      - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
                      "2007-12-24 20:50:04 C:\WINDOWS\Tasks\Norton AntiVirus - Volledige systeemscan - baby_E-tje.job"
                      - C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
                      .
                      **************************************************************************

                      catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                      Rootkit scan 2007-12-28 10:54:45
                      Windows 5.1.2600 Service Pack 2 FAT NTAPI

                      scannen van verborgen processen ...

                      scannen van verborgen autostart items ...

                      scannen van verborgen bestanden ...

                      Scan succesvol afgerond
                      verborgen bestanden: 0

                      **************************************************************************
                      .
                      Voltooingstijd: 2007-12-28 10:55:19
                      C:\ComboFix3.txt ... 2007-12-28 09:47
                      C:\ComboFix2.txt ... 2007-12-28 10:06
                      C:\ComboFix-quarantined-files.txt ... 2007-08-31 11:15
                      C:\combofixlog.txt ... 2007-08-26 03:09
                      .
                      2007-12-25 02:27:22 --- E O F ---

                      Comment


                      • #12
                        Graag gedaan dinga. We kunnen nu de restantjes van deze infectie verwijderen.
                        Download Dr.Web CureIt en plaats het op je bureaublad: cureit.exe.

                        Dubbelklik op cureit.exe, en klik daarna op Start om het programma een snelle scan te laten uitvoeren.
                        Deze snelle scan zal de bestanden scannen die momenteel in het geheugen geladen zijn.
                        Wordt er wat gevonden, dan laat je CureIt dit repareren.
                        - Verschijnt er een venster met een aanbieding tot kopen met 50% korting, dan klik je deze weg met het kruisje.
                        Daarna zal het hoofdvenster zichtbaar worden.
                        - Kies bovenaan in het menu Optie voor Taal en wijzig deze naar Dutch (Nederlands), indien deze anders ingesteld staat.
                        - In het menu Opties kies je voor Instellingen veranderen (F9).
                        Op het tabblad "Scan" haal je het vinkje weg bij Heuristic Analyse.
                        Druk op Toepassen.
                        Op het tabblad "Bestandstypen" moet bij Scan mode geselecteerd zijn: Alle bestanden.
                        Op het tabblad "Acties" stel je het volgende in bij Malware:
                        -Adware: Verplaats
                        -Dialers: Verplaats
                        -Jokes: Rapportage
                        -Riskware: Rapportage
                        -Hacktools: Verplaats
                        Nog steeds op het tabblad "Acties" stel je het volgende in bij Objecten:
                        - Geïnfecteerde objecten: Repareer
                        - Onrepareerbare: Verplaats
                        - Verdachte objecten: Rapportage
                        Haal dan het vinkje weg bij: Prompt bij actie.
                        Druk op Toepassen.
                        Druk daarna op OK.
                        Terug in het hoofdvenster kan je selecteren welke scan je wil uitvoeren.
                        - Selecteer Volledige scan
                        Klik op de groene pijl aan de rechterkant om de scan te starten.
                        Indien de geïnfecteerde bestanden niet kunnen gedesinfecteerd worden, zullen deze verplaatst worden naar de map %userprofile%\DoctorWeb\Quarantine.
                        - Als de scan klaar is kies je in het menu voor Bestand voor Rapportagelijst opslaan en sla je de log op op je bureaublad.
                        - Sluit daarna Dr.Web Cureit.

                        Herstart je computer.
                        Dit moet je zeker uitvoeren, want het kan zijn dat Dr.Web Cureit bestanden zal verplaatsen of verwijderen na een herstart.

                        Als de computer opnieuw gestart is, kopieer en plak je de inhoud van de log die je eerder hebt opgeslagen op je bureaublad, in je volgende post.
                        Post ook een nieuwe hijackthislog en een nieuwe log van combofix.

                        Comment


                        • #13
                          Drweb log

                          Hoi Marckie.

                          Hierbij de Drweb log

                          FILE0008.CHK C:\FOUND.002 Adware.Zango Verplaatst.
                          trayicon.exe C:\WINDOWS Trojan.DownLoader.38353 Verwijderd.
                          windsk.dll C:\WINDOWS Trojan.DownLoader.38353 Verwijderd.
                          wsystmp_kyg.exe C:\WINDOWS Trojan.MulDrop.9326 Verwijderd.
                          suspend.exe C:\WINDOWS\system32 Trojan.Click.5018 Verwijderd.
                          user32.dat C:\WINDOWS\system32 Trojan.Click.5014 Verwijderd.
                          A0023494.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP110 Trojan.Fakealert.398 Verwijderd.
                          A0023495.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP110 Trojan.Click.5014 Verwijderd.
                          A0023554.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP111 Trojan.Fakealert.398 Verwijderd.
                          A0023555.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP111 Trojan.Click.5014 Verwijderd.
                          A0023636.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP112 Trojan.Fakealert.398 Verwijderd.
                          A0023637.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP112 Trojan.Click.5014 Verwijderd.
                          A0023692.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP114 Trojan.Fakealert.398 Verwijderd.
                          A0023693.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP114 Trojan.Click.5014 Verwijderd.
                          A0023758.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP114 Trojan.Fakealert.398 Verwijderd.
                          A0023759.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP114 Trojan.Click.5014 Verwijderd.
                          A0024758.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP114 Trojan.Fakealert.398 Verwijderd.
                          A0024759.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP114 Trojan.Click.5014 Verwijderd.
                          A0025758.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP115 Trojan.Fakealert.398 Verwijderd.
                          A0025759.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP115 Trojan.Click.5014 Verwijderd.
                          A0026141.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116 Trojan.Click.5014 Verwijderd.
                          A0026142.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116 Trojan.Fakealert.398 Verwijderd.
                          A0026200.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116 Trojan.Fakealert.398 Verwijderd.
                          A0026201.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116 Trojan.Click.5014 Verwijderd.
                          A0026406.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116 Trojan.Fakealert.398 Verwijderd.
                          A0026407.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116 Trojan.Click.5014 Verwijderd.
                          A0026609.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116 Trojan.Fakealert.398 Verwijderd.
                          A0026610.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116 Trojan.Click.5014 Verwijderd.
                          A0026661.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116 Trojan.Fakealert.398 Verwijderd.
                          A0026662.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116 Trojan.Click.5014 Verwijderd.
                          A0027661.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116 Trojan.Fakealert.398 Verwijderd.
                          A0027662.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116 Trojan.Click.5014 Verwijderd.
                          A0028661.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116 Trojan.Fakealert.398 Verwijderd.
                          A0028662.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116 Trojan.Click.5014 Verwijderd.
                          A0028815.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP118 Trojan.Fakealert.398 Verwijderd.
                          A0028816.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP118 Trojan.Click.5014 Verwijderd.
                          A0028817.sys C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP118 Trojan.MulDrop.9325 Verwijderd.
                          A0028818.sys C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP118 Trojan.MulDrop.9325 Verwijderd.
                          A0028959.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP118 Trojan.DownLoader.38353 Verwijderd.
                          A0028960.dll C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP118 Trojan.DownLoader.38353 Verwijderd.
                          A0028961.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP118 Trojan.MulDrop.9326 Verwijderd.
                          A0028962.exe C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP118 Trojan.Click.5018 Verwijderd.
                          medichi.exe.vir C:\qoobox\Quarantine\C\WINDOWS Trojan.Fakealert.398 Verwijderd.
                          medichi2.exe.vir C:\qoobox\Quarantine\C\WINDOWS Trojan.Click.5014 Verwijderd.
                          beep.sys.vir C:\qoobox\Quarantine\C\WINDOWS\system32\dllcache Trojan.MulDrop.9325 Verwijderd.


                          Ook de Drweb log in Klad

                          FILE0008.CHK;C:\FOUND.002;Adware.Zango;Verplaatst.;
                          trayicon.exe;C:\WINDOWS;Trojan.DownLoader.38353;Verwijderd.;
                          windsk.dll;C:\WINDOWS;Trojan.DownLoader.38353;Verwijderd.;
                          wsystmp_kyg.exe;C:\WINDOWS;Trojan.MulDrop.9326;Verwijderd.;
                          suspend.exe;C:\WINDOWS\system32;Trojan.Click.5018;Verwijderd.;
                          user32.dat;C:\WINDOWS\system32;Trojan.Click.5014;Verwijderd.;
                          A0023494.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP110;Trojan.Fakealert.398;Verwijderd.;
                          A0023495.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP110;Trojan.Click.5014;Verwijderd.;
                          A0023554.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP111;Trojan.Fakealert.398;Verwijderd.;
                          A0023555.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP111;Trojan.Click.5014;Verwijderd.;
                          A0023636.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP112;Trojan.Fakealert.398;Verwijderd.;
                          A0023637.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP112;Trojan.Click.5014;Verwijderd.;
                          A0023692.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP114;Trojan.Fakealert.398;Verwijderd.;
                          A0023693.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP114;Trojan.Click.5014;Verwijderd.;
                          A0023758.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP114;Trojan.Fakealert.398;Verwijderd.;
                          A0023759.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP114;Trojan.Click.5014;Verwijderd.;
                          A0024758.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP114;Trojan.Fakealert.398;Verwijderd.;
                          A0024759.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP114;Trojan.Click.5014;Verwijderd.;
                          A0025758.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP115;Trojan.Fakealert.398;Verwijderd.;
                          A0025759.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP115;Trojan.Click.5014;Verwijderd.;
                          A0026141.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116;Trojan.Click.5014;Verwijderd.;
                          A0026142.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116;Trojan.Fakealert.398;Verwijderd.;
                          A0026200.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116;Trojan.Fakealert.398;Verwijderd.;
                          A0026201.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116;Trojan.Click.5014;Verwijderd.;
                          A0026406.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116;Trojan.Fakealert.398;Verwijderd.;
                          A0026407.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116;Trojan.Click.5014;Verwijderd.;
                          A0026609.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116;Trojan.Fakealert.398;Verwijderd.;
                          A0026610.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116;Trojan.Click.5014;Verwijderd.;
                          A0026661.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116;Trojan.Fakealert.398;Verwijderd.;
                          A0026662.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116;Trojan.Click.5014;Verwijderd.;
                          A0027661.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116;Trojan.Fakealert.398;Verwijderd.;
                          A0027662.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116;Trojan.Click.5014;Verwijderd.;
                          A0028661.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116;Trojan.Fakealert.398;Verwijderd.;
                          A0028662.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP116;Trojan.Click.5014;Verwijderd.;
                          A0028815.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP118;Trojan.Fakealert.398;Verwijderd.;
                          A0028816.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP118;Trojan.Click.5014;Verwijderd.;
                          A0028817.sys;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP118;Trojan.MulDrop.9325;Verwijderd.;
                          A0028818.sys;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP118;Trojan.MulDrop.9325;Verwijderd.;
                          A0028959.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP118;Trojan.DownLoader.38353;Verwijderd.;
                          A0028960.dll;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP118;Trojan.DownLoader.38353;Verwijderd.;
                          A0028961.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP118;Trojan.MulDrop.9326;Verwijderd.;
                          A0028962.exe;C:\System Volume Information\_restore{42425AC2-B498-4953-A5CE-0607CBF2FC22}\RP118;Trojan.Click.5018;Verwijderd.;
                          medichi.exe.vir;C:\qoobox\Quarantine\C\WINDOWS;Trojan.Fakealert.398;Verwijderd.;
                          medichi2.exe.vir;C:\qoobox\Quarantine\C\WINDOWS;Trojan.Click.5014;Verwijderd.;
                          beep.sys.vir;C:\qoobox\Quarantine\C\WINDOWS\system32\dllcache;Trojan.MulDrop.9325;Verwijderd.;

                          En de Hijack Log

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 12:32:08, on 28-12-2007
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                          C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\Program Files\acer\Acer eConsole\MediaServerService.exe
                          C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                          C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                          C:\WINDOWS\SOUNDMAN.EXE
                          C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                          C:\Program Files\Acer\eRecovery\Monitor.exe
                          C:\WINDOWS\system32\VTTimer.exe
                          C:\WINDOWS\system32\VTtrayp.exe
                          C:\Program Files\Acer\Acer eMode Management\AspireService.exe
                          C:\Program Files\Acer\Acer eConsole\MediaSync.exe
                          C:\Program Files\Muiltmedia keyboard Utility\2.0\KbdAp32A.exe
                          C:\Program Files\Browser Mouse\mouse32a.exe
                          C:\Program Files\TomTom HOME\TomTomHOME.exe
                          C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                          C:\Program Files\SPYWAREfighter\spftray.exe
                          C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                          C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\MSN Messenger\MsnMsgr.Exe
                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          C:\Program Files\Microsoft ActiveSync\wcescomm.exe
                          C:\Documents and Settings\baby_E-tje\Program Files\BitTorrent_DNA\dna.exe
                          C:\PROGRA~1\MICROS~2\rapimgr.exe
                          C:\Program Files\WinZip\WZQKPICK.EXE
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\internet explorer\iexplore.exe
                          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                          C:\WINDOWS\system32\wuauclt.exe
                          C:\Program Files\hijack\HijackThis.exe

                          O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O4 - HKLM\..\Run: [LaunchApp] Alaunch
                          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                          O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                          O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                          O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                          O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                          O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                          O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
                          O4 - HKLM\..\Run: [ntiMUI] C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
                          O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                          O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
                          O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe
                          O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe
                          O4 - HKLM\..\Run: [FLMK08KB] C:\Program Files\Muiltmedia keyboard Utility\2.0\KbdAp32A.exe
                          O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser Mouse\mouse32a.exe
                          O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                          O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
                          O4 - HKLM\..\Run: [spywarefighterguard] C:\Program Files\SPYWAREfighter\spftray.exe
                          O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                          O4 - HKLM\..\Run: [EliteProtector] "C:\Program Files\EliteProtector\EliteProtector.exe" hide
                          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
                          O4 - HKCU\..\Run: [DNA] "C:\Documents and Settings\baby_E-tje\Program Files\BitTorrent_DNA\dna.exe"
                          O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
                          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
                          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
                          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                          O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
                          O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                          O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                          O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cab
                          O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by129fd.bay129.hotmail.msn.com/activex/HMAtchmt.ocx
                          O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\acer\Acer eConsole\MediaServerService.exe
                          O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                          O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                          O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
                          O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                          O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                          O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                          O23 - Service: Planner voor Automatische LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                          O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                          O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

                          --
                          End of file - 8142 bytes


                          En de Combofix log

                          ComboFix 07-12-21.4 - baby_E-tje 2007-12-28 12:33:21.12 - FAT32x86
                          Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1043.18.214 [GMT 1:00]
                          Gestart vanuit: C:\Documents and Settings\baby_E-tje\Bureaublad\ComboFix.exe
                          .

                          (((((((((((((((((((( Bestanden Gemaakt van 2007-11-28 to 2007-12-28 ))))))))))))))))))))))))))))))
                          .

                          2007-12-27 12:36 . 2007-12-27 12:36 <DIR> d--hs---- C:\FOUND.011
                          2007-12-27 10:26 . 2007-12-27 10:26 268 --ah----- C:\sqmdata03.sqm
                          2007-12-27 10:26 . 2007-12-27 10:26 244 --ah----- C:\sqmnoopt03.sqm
                          2007-12-25 22:35 . 2007-12-25 22:35 <DIR> d-------- C:\Program Files\COMODO
                          2007-12-25 22:35 . 2007-12-25 22:35 <DIR> d-------- C:\Documents and Settings\baby_E-tje\Application Data\Comodo
                          2007-12-25 01:07 . 2007-12-25 01:07 <DIR> d-------- C:\Program Files\EliteProtector
                          2007-12-25 01:01 . 2005-06-01 14:36 18,944 --a------ C:\WINDOWS\system32\wowfx(3).dll
                          2007-12-25 01:01 . 2005-06-01 13:24 18,944 --a------ C:\WINDOWS\system32\wowfx(2).dll
                          2007-12-24 14:36 . 2007-12-24 14:36 <DIR> d--hs---- C:\FOUND.010
                          2007-12-21 18:26 . 2007-12-21 18:26 <DIR> d-------- C:\Documents and Settings\baby_E-tje\Application Data\DivX
                          2007-12-21 18:22 . 2007-12-21 18:22 <DIR> d-------- C:\Program Files\DivX
                          2007-12-18 17:59 . 2007-12-18 17:59 <DIR> d--hs---- C:\FOUND.009
                          2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Temp
                          2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Settings
                          2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Par2
                          2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Newsgroups
                          2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Import
                          2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Downloads
                          2007-12-15 20:20 . 2007-12-15 20:20 <DIR> d-------- C:\Program Files\Bodies
                          2007-12-14 04:55 . 2007-12-14 04:55 <DIR> d--hs---- C:\FOUND.008
                          2007-12-12 22:08 . 2007-03-21 20:33 503,808 --a------ C:\WINDOWS\system32\MSVCP71.DLL
                          2007-12-12 22:08 . 2007-03-21 20:33 348,160 --a------ C:\WINDOWS\system32\MSVCR71.DLL
                          2007-12-11 23:35 . 2007-12-11 23:35 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
                          2007-12-11 23:35 . 2007-12-11 23:35 4,816 --a------ C:\WINDOWS\system32\divxsm.tlb
                          2007-12-11 23:34 . 2007-12-11 23:34 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
                          2007-12-11 23:34 . 2007-12-11 23:34 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
                          2007-12-11 23:34 . 2007-12-11 23:34 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
                          2007-12-11 23:32 . 2007-12-11 23:32 352,401 --a------ C:\WINDOWS\system32\DivXMedia.ax
                          2007-12-11 23:32 . 2007-12-11 23:32 156,992 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
                          2007-12-11 23:32 . 2007-12-11 23:32 12,288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll
                          2007-12-11 04:18 . 2007-12-11 04:18 <DIR> d--hs---- C:\FOUND.007
                          2007-11-30 23:57 . 2007-11-30 23:57 317,616 --a------ C:\WINDOWS\system32\drivers\srtspl.sys
                          2007-11-30 23:57 . 2007-11-30 23:57 279,088 --a------ C:\WINDOWS\system32\drivers\srtsp.sys
                          2007-11-30 23:57 . 2007-11-30 23:57 43,696 --a------ C:\WINDOWS\system32\drivers\srtspx.sys
                          2007-11-30 23:57 . 2007-11-30 23:57 10,549 --a------ C:\WINDOWS\system32\drivers\srtspx.cat
                          2007-11-30 23:57 . 2007-11-30 23:57 10,549 --a------ C:\WINDOWS\system32\drivers\srtspl.cat
                          2007-11-30 23:57 . 2007-11-30 23:57 10,545 --a------ C:\WINDOWS\system32\drivers\srtsp.cat
                          2007-11-30 23:57 . 2007-11-30 23:57 1,430 --a------ C:\WINDOWS\system32\drivers\srtspl.inf
                          2007-11-30 23:57 . 2007-11-30 23:57 1,421 --a------ C:\WINDOWS\system32\drivers\srtspx.inf
                          2007-11-30 23:57 . 2007-11-30 23:57 1,415 --a------ C:\WINDOWS\system32\drivers\srtsp.inf
                          2007-11-28 00:42 . 2007-11-28 00:42 268 --ah----- C:\sqmdata02.sqm
                          2007-11-28 00:42 . 2007-11-28 00:42 244 --ah----- C:\sqmnoopt02.sqm

                          .
                          ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          2007-12-11 22:34 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
                          2007-12-11 22:34 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
                          2007-12-11 22:34 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
                          2007-12-11 22:34 129,784 ------w C:\WINDOWS\system32\pxafs.dll
                          2007-12-11 22:34 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
                          2007-12-11 22:34 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
                          2007-12-11 22:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
                          2007-12-11 22:33 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
                          2007-12-11 22:33 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
                          2007-12-11 22:33 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
                          2007-12-11 22:33 682,496 ----a-w C:\WINDOWS\system32\DivX.dll
                          2007-12-11 22:33 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
                          2007-12-11 22:33 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
                          2007-12-11 22:33 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
                          2007-12-11 22:33 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
                          2007-12-11 22:33 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
                          2007-12-11 22:33 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
                          2007-12-11 22:33 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
                          2007-12-05 12:01 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
                          2007-12-05 12:01 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
                          2007-12-05 12:01 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
                          2007-12-05 12:01 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
                          2007-11-22 12:46 --------- d-----w C:\Program Files\Microsoft.NET
                          2007-11-14 07:29 450,560 ----a-w C:\WINDOWS\system32\dllcache\jscript.dll
                          2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
                          2007-10-30 10:20 3,079,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
                          2007-10-29 22:45 1,291,776 ----a-w C:\WINDOWS\system32\quartz.dll
                          2007-10-29 22:45 1,291,776 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
                          2007-10-25 16:57 8,501,760 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
                          2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
                          2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
                          2007-10-11 06:14 96,768 ----a-w C:\WINDOWS\system32\dllcache\inseng.dll
                          2007-10-11 06:14 662,528 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
                          2007-10-11 06:14 616,960 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
                          2007-10-11 06:14 55,808 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
                          2007-10-11 06:14 532,480 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
                          2007-10-11 06:14 474,624 ----a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
                          2007-10-11 06:14 449,024 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
                          2007-10-11 06:14 39,424 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
                          2007-10-11 06:14 357,888 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
                          2007-10-11 06:14 251,392 ----a-w C:\WINDOWS\system32\dllcache\iepeers.dll
                          2007-10-11 06:14 205,312 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
                          2007-10-11 06:14 16,384 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
                          2007-10-11 06:14 151,552 ----a-w C:\WINDOWS\system32\dllcache\cdfview.dll
                          2007-10-11 06:14 146,432 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
                          2007-10-11 06:14 1,494,528 ----a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
                          2007-10-11 06:14 1,057,280 ----a-w C:\WINDOWS\system32\dllcache\danim.dll
                          2007-10-11 06:14 1,023,488 ----a-w C:\WINDOWS\system32\dllcache\browseui.dll
                          2007-10-10 11:16 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe
                          .

                          ((((((((((((((((((((((((((((( [email protected]_ 9.47.02,89 )))))))))))))))))))))))))))))))))))))))))
                          .
                          - 2007-12-25 00:02:20 37,888 ----a-w C:\WINDOWS\system32\dllcache\beep.sys
                          + 2004-08-04 04:00:00 4,224 ----a-w C:\WINDOWS\system32\dllcache\beep.sys
                          - 2007-12-25 00:02:20 37,888 ----a-w C:\WINDOWS\system32\drivers\beep.sys
                          + 2004-08-04 04:00:00 4,224 ----a-w C:\WINDOWS\system32\drivers\beep.sys
                          .
                          ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          .
                          REGEDIT4
                          *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]
                          "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-06-25 12:14]
                          "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-23 18:39]
                          "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-20 22:36]
                          "DNA"="C:\Documents and Settings\baby_E-tje\Program Files\BitTorrent_DNA\dna.exe" [2007-05-30 09:55]
                          "BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [2007-09-08 00:01]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "LaunchApp"="Alaunch"
                          "SoundMan"="SOUNDMAN.EXE" [2005-06-08 08:31 C:\WINDOWS\SOUNDMAN.EXE]
                          "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-07-15 01:07]
                          "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 05:00]
                          "MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 05:00]
                          "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 05:00]
                          "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 05:00]
                          "eRecoveryService"="C:\Program Files\Acer\eRecovery\Monitor.exe" [2005-06-20 09:03]
                          "ntiMUI"="C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 18:15]
                          "VTTimer"="VTTimer.exe" [2005-05-13 12:57 C:\WINDOWS\system32\VTTimer.exe]
                          "VTTrayp"="VTtrayp.exe" [2005-05-13 12:57 C:\WINDOWS\system32\VTTrayp.exe]
                          "AspireService"="C:\Program Files\Acer\Acer eMode Management\AspireService.exe" [2005-06-04 12:40]
                          "MediaSync"="C:\Program Files\Acer\Acer eConsole\MediaSync.exe" [2005-06-01 14:25]
                          "FLMK08KB"="C:\Program Files\Muiltmedia keyboard Utility\2.0\KbdAp32A.exe" [2006-01-21 16:31]
                          "FLMOFFICE4DMOUSE"="C:\Program Files\Browser Mouse\mouse32a.exe" [2006-01-21 16:32]
                          "TomTomHOME.exe"="C:\Program Files\TomTom HOME\TomTomHOME.exe" [2007-03-14 16:52]
                          "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
                          "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 23:59]
                          "osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2007-01-14 01:11]
                          "spywarefighterguard"="C:\Program Files\SPYWAREfighter\spftray.exe" [2007-06-08 11:52]
                          "Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 10:22]
                          "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
                          "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-22 15:09]
                          "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
                          "EliteProtector"="C:\Program Files\EliteProtector\EliteProtector.exe"

                          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                          "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 05:00]

                          C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\
                          WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-04-15 11:51:53]

                          R1 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys [2004-12-17 17:14]
                          R2 int15.sys;int15.sys;C:\Program Files\Acer\eRecovery\int15.sys [2005-01-13 14:46]
                          S3 SpyFighter;SpyFighter Guard Device;C:\Program Files\SPYWAREfighter\spyfighter.sys [2007-06-08 11:52]
                          S4 SPYWAREfighterRP;SPYWAREfighterRP;"C:\Program Files\SPYWAREfighter\spfprc.exe" [2007-06-08 11:52]

                          .
                          Inhoud van de 'Gedeelde Taken' map
                          "2007-12-24 17:36:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
                          - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
                          "2007-12-24 20:50:04 C:\WINDOWS\Tasks\Norton AntiVirus - Volledige systeemscan - baby_E-tje.job"
                          - C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
                          .
                          **************************************************************************

                          catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                          Rootkit scan 2007-12-28 12:35:33
                          Windows 5.1.2600 Service Pack 2 FAT NTAPI

                          scannen van verborgen processen ...

                          scannen van verborgen autostart items ...

                          scannen van verborgen bestanden ...

                          Scan succesvol afgerond
                          verborgen bestanden: 0

                          **************************************************************************
                          .
                          Voltooingstijd: 2007-12-28 12:36:08
                          C:\ComboFix3.txt ... 2007-12-28 10:06
                          C:\ComboFix2.txt ... 2007-12-28 10:55
                          C:\ComboFix-quarantined-files.txt ... 2007-08-31 11:15
                          C:\combofixlog.txt ... 2007-08-26 03:09
                          .
                          2007-12-25 02:27:22 --- E O F ---

                          Comment


                          • #14
                            Ga naar deze website: http://www.virustotal.com/en/indexf.html
                            Laat volgend bestandje scannen: C:\WINDOWS\system32\wowfx(3).dll
                            Post het resultaat van de scan.

                            Comment


                            • #15
                              Virus total log

                              Hoi Mackie..

                              Dit is de virus total log..

                              File wowfx_3_.dll received on 12.25.2007 14:52:47 (CET)
                              Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED


                              Result: 18/32 (56.25%)
                              Loading server information...
                              Your file is queued in position: ___.
                              Estimated start time is between ___ and ___ .
                              Do not close the window until scan is complete.
                              The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
                              If you are waiting for more than five minutes you have to resend your file.
                              Your file is being scanned by VirusTotal in this moment,
                              results will be shown as they're generated.
                              Compact Print results
                              Your file has expired or does not exists.
                              Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

                              You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
                              Email:


                              Antivirus Version Last Update Result
                              AhnLab-V3 - - -
                              AntiVir - - TR/Crypt.XDR.Gen
                              Authentium - - W32/Dropper.gen6
                              Avast - - -
                              AVG - - Generic9.AGZV
                              BitDefender - - -
                              CAT-QuickHeal - - Trojan.Qhost.abh
                              ClamAV - - -
                              DrWeb - - -
                              eSafe - - -
                              eTrust-Vet - - -
                              Ewido - - -
                              FileAdvisor - - -
                              Fortinet - - -
                              F-Prot - - W32/Dropper.gen6
                              F-Secure - - Trojan.Win32.Qhost.abh
                              Ikarus - - Trojan.Win32.Qhost.abh
                              Kaspersky - - Trojan.Win32.Qhost.abh
                              McAfee - - -
                              Microsoft - - Trojan:Win32/Warece.A
                              NOD32v2 - - Win32/TrojanDownloader.FakeAlert.G
                              Norman - - W32/Qhost.CZK
                              Panda - - Suspicious file
                              Prevx1 - - Generic.Malware
                              Rising - - -
                              Sophos - - Troj/Agent-GIX
                              Sunbelt - - -
                              Symantec - - -
                              TheHacker - - Trojan/Qhost.abh
                              VBA32 - - Win32.TrojanDownloader.FakeAlert.G
                              VirusBuster - - Trojan.Qhost.EP
                              Webwasher-Gateway - - Trojan.Crypt.XDR.Gen
                              Additional information
                              MD5: 6c17d2eeadf24dd2030e79d377dad70d

                              Comment

                              Sorry, you are not authorized to view this page
                              Working...
                              X