Mededeling

Collapse
No announcement yet.

last van popups celldorado graag advies

Collapse
X
  •  
  • Filter
  • Tijd
  • Show
Clear All
new posts

  • last van popups celldorado graag advies

    last van popup celldorado
    eerst hitman pro gedraaid en dit is hyack log
    dvd dank

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:14:27, on 28-12-2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16574)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
    C:\Program Files\CA\eTrust Antivirus\InoRT.exe
    C:\Program Files\CA\eTrust Antivirus\InoTask.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Dit.exe
    C:\WINDOWS\CNYHKey.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\D-Tools\daemon.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\PROGRA~1\MI3AA1~1\rapimgr.exe
    C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
    C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Microsoft Works\WkDStore.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\Program Files\WinRAR\WinRAR.exe
    C:\Program Files\WinRAR\WinRAR.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.texelsheep.nl/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.texelsheep.nl/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer van Het Net
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\nts.exe,C:\WINDOWS\wcvs.exe
    O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: IntelligentAdvisor - {6548BF73-58FF-71D5-F97D-17C71E323709} - C:\Program Files\IntelligentAdvisor\IntelligentAdvisor-2.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [Dit] Dit.exe
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
    O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
    O4 - HKLM\..\Run: [Realtime Monitor] "C:\PROGRA~1\CA\ETRUST~1\realmon.exe" -s
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] "C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe"
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Network Translation Service] "C:\WINDOWS\nts.exe" *
    O4 - HKLM\..\Run: [Windows Certificate Verification Service] "C:\WINDOWS\wcvs.exe" *
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
    O4 - HKCU\..\Run: [Dash upload] C:\DOCUME~1\RHOEKS~1\APPLIC~1\MEALAI~1\Multi City Soft.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Lokale service')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Netwerkservice')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Bluetooth Manager.lnk = ?
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Snelstart HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Mobiele favorieten maken... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=<HOMEPAGE>
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.nl/scanforvirus-en/kavwebscan_unicode.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/23b2b94751f7cd2f3306/netzip/RdxIE601.cab
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/NL-NL/a-UNO1/GAME_UNO1.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1167565654593
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167576335437
    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.mypix.com/importer/ImageUploader4.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} (PhotoPickConvert Class) - http://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5181/mcfscan.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://www.chat-united.com/controls/msnchat45.cab
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
    O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
    O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Network Translation Service (NTS) - Unknown owner - C:\WINDOWS\nts.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
    O23 - Service: Windows Certificate Verification Service (wcvs) - Unknown owner - C:\WINDOWS\wcvs.exe (file missing)
    O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe

    --
    End of file - 12521 bytes

  • #2
    Download: RVAXO.exe
    • Sla het bestand op je bureaublad op, dubbelklik het en kies voor "Unzip" om het uit te pakken.
    • Open nu de map RVAXO op je bureaublad en dubbeklik RVAXO.cmd
      Er zal een cmd-schermpje openen, daarin zullen snel enkele regels over niet gevonden bestanden voorbijkomen, dit is normaal.
    • Mogelijk start er ook een uninstaller van een rogue scanner op, sluit deze niet af maar volg eventuele aanwijzingen en laat deze gewoon zijn werk doen.
    • Daarna zal je PC herstarten, na de herstart opent het cmd-venster van RVAXO opnieuw.
      Laat deze lopen en wacht tot er een logfile opent: C:\RVAXO-results.log
    • Herstart je computer niet vanzelf, of start de tool niet na de reboot, doe dit dan handmatig.
    • Post de inhoud van de logfile in je volgende bericht.


    Download Combofix naar je Bureaublad.
    Dubbelklik op Combofix.exe
    Kies voor "Continue" door 1 te typen gevolgd door ENTER.
    Tijdens het runnen van de fix, NIET in het venster klikken, want dit zal je pc doen vasthangen.
    Wanneer de fix voltooid is en na herstart, zal de log combofix.txt openen.
    Plaats deze log in je volgende post.

    NOTA: Indien je virusscanner reageert met een melding van een scriptuitvoering, mag je dit negeren.

    Comment


    • #3
      logs

      bedankt voor je snelle reactie


      ----------------RVAXO.exe first run-------------

      Files found:

      C:\WINDOWS\tasks\ACBCCA1491377F60.job
      C:\WINDOWS\nts.exe

      Uninstallers Rogue scanners:


      Folders Found:


      Hosts-file was reset, If you use a custom hosts file please replace it...

      --------------RVAXO.exe last run---------------

      Files found:

      Folders Found:

      --------------RVAXO.exe finished----------------

      ComboFix 07-12-28.1 - r hoekstra 2007-12-28 10:44:20.1 - NTFSx86
      Microsoft Windows XP Home Edition 5.1.2600.2.1252.31.1043.18.118 [GMT 1:00]
      Gestart vanuit: C:\Documents and Settings\r hoekstra\Bureaublad\ComboFix.exe
      * Nieuw herstelpunt werd aangemaakt
      .

      (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      C:\Documents and Settings\r hoekstra\Application Data\inst.exe

      .
      ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

      .
      -------\LEGACY_WCVS


      (((((((((((((((((((( Bestanden Gemaakt van 2007-11-28 to 2007-12-28 ))))))))))))))))))))))))))))))
      .

      2007-12-28 10:35 . 2007-12-28 10:35 <DIR> d-------- C:\RVAXO
      2007-12-28 09:35 . 2007-12-28 09:55 575,630 --a------ C:\WINDOWS\system32\RVAXO.bat
      2007-12-28 09:35 . 2001-10-01 14:51 69,632 --a------ C:\WINDOWS\system32\remove.exe
      2007-12-28 07:58 . 2002-12-29 01:14 81,920 --a------ C:\WINDOWS\system32\Startup.cpl
      2007-12-27 19:33 . 2007-12-27 19:33 <DIR> d-------- C:\Program Files\DVD Shrink
      2007-12-27 19:33 . 2007-12-27 19:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DVD Shrink
      2007-12-27 19:16 . 2007-12-27 19:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\vsosdk
      2007-12-27 12:56 . 2007-12-27 15:42 <DIR> d-------- C:\Program Files\Spyware Doctor
      2007-12-27 12:56 . 2007-12-27 12:56 <DIR> d-------- C:\Documents and Settings\r hoekstra\Application Data\PC Tools
      2007-12-27 12:56 . 2007-12-27 12:57 74,240 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
      2007-12-27 12:56 . 2007-12-27 12:57 56,832 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
      2007-12-27 12:56 . 2007-10-18 00:14 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
      2007-12-27 12:56 . 2007-10-18 00:16 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
      2007-12-27 12:55 . 2007-12-27 12:59 <DIR> d-------- C:\Program Files\SpywareBlaster
      2007-12-27 12:52 . 2007-12-27 12:55 <DIR> d-------- C:\Temp
      2007-12-27 12:52 . 2007-12-27 12:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Prevx
      2007-12-26 17:44 . 2007-12-27 19:18 <DIR> d-------- C:\Program Files\DVDFab Platinum 4
      2007-12-26 17:44 . 2007-12-27 19:16 <DIR> d-------- C:\Documents and Settings\r hoekstra\Application Data\Vso
      2007-12-26 17:44 . 2007-12-26 17:44 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
      2007-12-26 17:44 . 2007-12-26 17:44 47,360 --a------ C:\Documents and Settings\r hoekstra\Application Data\pcouffin.sys
      2007-12-26 15:42 . 2007-12-26 15:44 24 ---hs---- C:\WINDOWS\S825D4743.tmp
      2007-12-26 13:09 . 2007-12-27 18:43 <DIR> d-------- C:\Documents and Settings\r hoekstra\Application Data\DVD Shrink
      2007-12-25 23:04 . 2004-04-23 15:01 1,383,936 --a------ C:\WINDOWS\system32\vcl70.bpl
      2007-12-25 23:04 . 2004-04-23 15:01 783,360 --a------ C:\WINDOWS\system32\rtl70.bpl
      2007-12-25 21:43 . 2007-12-25 23:04 <DIR> d-------- C:\Program Files\Dnote Software
      2007-12-25 20:33 . 2007-12-25 20:33 372,736 --a------ C:\WINDOWS\suinsta4001.exe
      2007-12-24 22:45 . 2007-12-25 20:33 <DIR> d-------- C:\Program Files\POI-Warner Medion-Navigator 5 Edition
      2007-12-24 17:51 . 2007-12-25 20:38 <DIR> d-------- C:\Program Files\POI-Warner MN5 Edition
      2007-12-24 17:11 . 2007-12-28 10:41 <DIR> d-------- C:\Program Files\IntelligentAdvisor
      2007-12-23 02:38 . 2007-12-23 02:38 <DIR> d-------- C:\Documents and Settings\r hoekstra\Application Data\Apple Computer
      2007-12-23 02:38 . 2007-12-28 07:44 54,156 --ah----- C:\WINDOWS\QTFont.qfn
      2007-12-23 02:38 . 2007-12-23 02:38 1,409 --a------ C:\WINDOWS\QTFont.for
      2007-12-23 02:37 . 2007-12-23 02:38 <DIR> d-------- C:\Program Files\iTunes
      2007-12-23 02:37 . 2007-12-23 02:37 <DIR> d-------- C:\Program Files\iPod
      2007-12-23 02:37 . 2007-12-23 02:37 <DIR> d-------- C:\Program Files\Common Files\Apple
      2007-12-23 02:31 . 2007-12-23 02:32 <DIR> d-------- C:\Program Files\QuickTime
      2007-12-23 02:31 . 2007-12-23 02:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
      2007-12-11 10:57 . 2007-12-11 10:57 65,536 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
      2007-12-11 10:57 . 2007-12-11 10:57 49,152 --a------ C:\WINDOWS\system32\QuickTime.qts
      2007-12-09 17:50 . 2007-12-09 17:50 <DIR> d-------- C:\Program Files\Apple Software Update
      2007-12-09 17:50 . 2007-12-09 17:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
      2007-12-08 15:24 . 2007-12-08 15:24 <DIR> d-------- C:\WINDOWS\McAfee.com
      2007-12-07 21:20 . 2007-12-07 21:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
      2007-12-07 17:57 . 2007-12-07 17:57 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
      2007-12-07 17:57 . 2007-12-07 17:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab

      .
      ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2007-12-28 09:52 13,440 ----a-w C:\WINDOWS\system32\drivers\USBCRFT.SYS
      2007-12-28 09:52 --------- d-----w C:\Program Files\SP2 Connection Patcher
      2007-12-27 20:18 --------- d-----w C:\Program Files\Zards software
      2007-12-27 20:17 --------- d-----w C:\Program Files\SlySoft
      2007-12-27 20:17 --------- d-----w C:\Program Files\Elaborate Bytes
      2007-12-27 14:39 --------- d-----w C:\Program Files\Hitman Pro
      2007-12-27 12:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
      2007-12-27 11:59 --------- d-----w C:\Documents and Settings\r hoekstra\Application Data\Lavasoft
      2007-12-27 11:55 --------- d-----w C:\Program Files\Lavasoft
      2007-12-24 20:42 26,216 ----a-w C:\Documents and Settings\r hoekstra\Application Data\wklnhst.dat
      2007-12-14 21:51 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
      2007-12-10 18:33 424 ----a-w C:\Documents and Settings\pieter\Application Data\wklnhst.dat
      2007-12-09 14:43 --------- d-----w C:\Program Files\LimeWire
      2007-12-07 21:46 102,664 ----a-w C:\WINDOWS\system32\drivers\tmcomm.sys
      2007-12-07 20:19 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
      2007-12-02 13:22 --------- d-----w C:\Program Files\Wolfenstein - Enemy Territory
      2007-11-15 14:13 --------- d--h--r C:\Documents and Settings\r hoekstra\Application Data\SecuROM
      2007-11-15 13:17 --------- d-----w C:\Program Files\EA SPORTS
      2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
      2007-11-11 19:17 --------- d-----w C:\Program Files\Finale NotePad 2005a
      2007-11-11 13:51 --------- d-----w C:\Program Files\Samsung
      2007-11-11 12:51 --------- d-----w C:\Documents and Settings\r hoekstra\Application Data\Toshiba
      2007-11-10 18:34 --------- d-----w C:\Program Files\D-Tools
      2007-11-01 17:33 --------- d-----w C:\Program Files\Prisma
      2007-01-07 22:05 2 --shatr C:\WINDOWS\winstart.bat
      .

      ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      REGEDIT4
      *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6548BF73-58FF-71D5-F97D-17C71E323709}]
      2007-12-11 22:27 1019904 --a------ C:\Program Files\IntelligentAdvisor\IntelligentAdvisor-2.dll

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24]
      "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 09:03]
      "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 17:34]
      "SP2 Connection Patcher"="C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" [2005-07-11 12:51]
      "Dash upload"="C:\DOCUME~1\RHOEKS~1\APPLIC~1\MEALAI~1\Multi City Soft.exe"

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Dit"="Dit.exe" [2003-12-29 23:33 C:\WINDOWS\Dit.exe]
      "Cmaudio"="RunDll32 cmicnfg.cpl"
      "CHotkey"="mHotkey.exe" [2004-02-05 13:45 C:\WINDOWS\mHotkey.exe]
      "ledpointer"="CNYHKey.exe" [2004-02-03 17:15 C:\WINDOWS\CNYHKey.exe]
      "Realtime Monitor"="C:\PROGRA~1\CA\ETRUST~1\realmon.exe" [2003-02-13 10:25]
      "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
      "PCMService"="C:\Program Files\Home Cinema\PowerCinema\PCMService.exe" [2004-02-19 10:09]
      "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 13:38]
      "HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 15:18]
      "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
      "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 09:12]
      "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-02-23 12:32]
      "Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-10 00:11]
      "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
      "BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 09:03 C:\WINDOWS\system32\bthprops.cpl]
      "DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 17:05]
      "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 09:03]
      "Network Translation Service"="C:\WINDOWS\nts.exe"
      "Windows Certificate Verification Service"="C:\WINDOWS\wcvs.exe"

      C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\
      Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2006-03-28 18:26:04]
      HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 22:31:38]
      Snelstart HP Image Zone.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 23:06:36]

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
      @=""

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
      @=""

      R3 Cap7134;MEDION (7134) WDM Video Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys [2003-06-05 10:04]
      R3 CardReaderFilter;Card Reader Filter;C:\WINDOWS\system32\Drivers\USBCRFT.SYS [2007-12-28 10:52]
      R3 Intels51;Creatix V.9X DSP Data Fax Modem;C:\WINDOWS\system32\DRIVERS\ctxs51.sys [2003-05-22 19:44]
      R3 PhTVTune;MEDION TV-TUNER 7134 MK2/3;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys [2003-06-12 10:47]
      R3 PRISM_A00;PRISM 802.11g Driver;C:\WINDOWS\system32\DRIVERS\PRISMA00.sys [2004-01-16 09:31]
      R3 UKBFLT;UKBFLT;C:\WINDOWS\system32\DRIVERS\UKBFLT.sys [2003-12-19 17:13]
      R3 wbscr;Winbond Smartcard Reader for I/O;C:\WINDOWS\system32\drivers\wbscr.sys [2002-04-24 12:07]

      .
      Inhoud van de 'Gedeelde Taken' map
      "2007-12-22 22:23:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
      - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
      .
      **************************************************************************

      catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2007-12-28 10:53:12
      Windows 5.1.2600 Service Pack 2 NTFS

      scannen van verborgen processen ...

      scannen van verborgen autostart items ...

      scannen van verborgen bestanden ...

      Scan succesvol afgerond
      verborgen bestanden: 0

      **************************************************************************
      .
      --------------------- DLLs Loaded Under Running Processes ---------------------

      PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
      -> C:\WINDOWS\HKCYDLL.dll
      .
      Voltooingstijd: 2007-12-28 10:54:51 - machine was rebooted
      .
      2007-12-27 17:04:02 --- E O F ---

      Comment


      • #4
        Download dit bestand: Deljob.exe (mirror)
        Plaats het op je bureaublad.
        Indien je virusscanner de download van deljob.exe blokkeert,
        schakel dan tijdelijk je virusscanner uit of download de zip-versie
        deljob.zip en pak deze uit naar je Bureaublad.
        Dubbelklik Deljob.exe.
        Een logje(logit.txt) zal openen, het bestandje kan je ook terugvinden op je bureaublad.
        Post de inhoud van logit.txt in je volgende bericht.

        Comment


        • #5
          logit

          --------------------------------------------------------
          No LOP jobs found
          --------------------------------------------------------
          Files remaining after cleaning

          AppleSoftwareUpdate.job
          --------------------------------------------------------
          App data folders

          De volumenaam van station C is BOOT
          Het volumenummer is 08AC-1C85

          Map van C:\Documents and Settings\r hoekstra\Application Data

          28-12-2007 11:13 <DIR> .
          28-12-2007 11:13 <DIR> ..
          26-06-2007 16:43 <DIR> Adobe
          26-06-2007 16:41 <DIR> AdobeUM
          01-03-2007 17:04 <DIR> Ahead
          23-12-2007 02:38 <DIR> APPLEC~1 Apple Computer
          13-02-2007 21:36 <DIR> ATI
          02-01-2007 20:19 <DIR> Autodesk
          25-05-2007 13:26 <DIR> Camfrog
          23-02-2004 09:52 <DIR> CYBERL~1 Cyberlink
          27-12-2007 18:43 <DIR> DVDSHR~1 DVD Shrink
          26-08-2007 20:38 <DIR> GETRIG~1 GetRightToGo
          02-06-2007 15:44 <DIR> Google
          28-12-2007 11:13 <DIR> Grisoft
          13-02-2004 14:23 <DIR> Help
          13-02-2004 23:48 <DIR> IDENTI~1 Identities
          23-02-2004 19:20 <DIR> INTERT~1 InterTrust
          27-12-2007 12:59 <DIR> Lavasoft
          26-06-2007 20:01 <DIR> LEADER~1 Leadertech
          04-03-2007 18:37 <DIR> MACROM~1 Macromedia
          27-08-2007 06:50 <DIR> MEALAI~1 mealaimscr
          02-11-2007 15:54 <DIR> MICROS~1 Microsoft
          27-09-2007 16:09 <DIR> MSN6
          27-12-2007 12:56 <DIR> PCTOOL~1 PC Tools
          23-02-2004 12:33 <DIR> Real
          09-01-2007 20:48 <DIR> Regrun
          15-11-2007 15:13 <DIR> SecuROM
          01-01-2007 21:06 <DIR> Sun
          11-11-2007 13:51 <DIR> Toshiba
          27-12-2007 19:16 <DIR> Vso
          26-08-2007 20:39 <DIR> Webroot
          0 bestand(en) 0 bytes
          31 map(pen) 48.701.640.704 bytes beschikbaar
          De volumenaam van station C is BOOT
          Het volumenummer is 08AC-1C85

          Map van C:\Documents and Settings\All Users\Application Data

          28-12-2007 11:13 <DIR> .
          28-12-2007 11:13 <DIR> ..
          26-07-2007 17:19 <DIR> Adobe
          13-02-2004 17:17 <DIR> Ahead
          09-12-2007 17:50 <DIR> Apple
          23-12-2007 02:31 <DIR> APPLEC~1 Apple Computer
          02-01-2007 20:11 <DIR> Autodesk
          31-12-2006 15:37 <DIR> CYBERL~1 CyberLink
          27-12-2007 19:44 <DIR> DVDSHR~1 DVD Shrink
          04-08-2007 10:26 <DIR> ELABOR~1 Elaborate Bytes
          29-08-2007 07:13 <DIR> FLAGAC~1 flag ace stupid data
          26-06-2007 20:04 <DIR> Google
          28-12-2007 11:13 <DIR> Grisoft
          31-12-2006 20:09 <DIR> HEWLET~1 Hewlett-Packard
          07-12-2007 17:57 <DIR> KASPER~1 Kaspersky Lab
          07-12-2007 21:20 <DIR> Lavasoft
          27-12-2007 12:55 <DIR> MICROS~1 Microsoft
          31-12-2006 12:42 <DIR> MSN6
          13-02-2004 17:22 <DIR> MUVEET~1 muvee Technologies
          27-12-2007 12:52 <DIR> Prevx
          27-12-2007 13:32 <DIR> SPYBOT~1 Spybot - Search & Destroy
          24-08-2007 16:25 <DIR> SURFRI~1 SurfRight
          27-08-2007 19:29 <DIR> TEMP
          18-01-2007 19:20 <DIR> Trymedia
          27-12-2007 19:16 <DIR> vsosdk
          31-12-2006 15:52 <DIR> WINDOW~1 Windows Genuine Advantage
          0 bestand(en) 0 bytes
          26 map(pen) 48.701.636.608 bytes beschikbaar
          --------------------------------------------------------

          Comment


          • #6
            Open de map RVAXO op je bureaublad en dubbelklik Uninstall.cmd
            Dit zal alles van RVAXO doen verwijderen.

            Download de bijlage: CFScript.txt

            Sleep CFScript.txt in ComboFix.exe zoals getoond in onderstaand voorbeeld :



            Dit zal ComboFix doen herstarten.
            Start opnieuw op als daarom gevraagd wordt,
            en post de inhoud van de Combofix.txt in je volgende antwoord.
            Bijgevoegde Bestanden

            Comment


            • #7
              log2

              ComboFix 07-12-28.1 - r hoekstra 2007-12-28 12:29:37.2 - NTFSx86
              Microsoft Windows XP Home Edition 5.1.2600.2.1252.31.1043.18.182 [GMT 1:00]
              Gestart vanuit: C:\Documents and Settings\r hoekstra\Bureaublad\ComboFix.exe
              Command switches used :: C:\Documents and Settings\r hoekstra\Bureaublad\cfscript.txt
              * Nieuw herstelpunt werd aangemaakt

              FILE
              C:\WINDOWS\S825D4743.tmp
              .

              (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
              .

              C:\Documents and Settings\All Users\Application Data\flag ace stupid data
              C:\Documents and Settings\r hoekstra\Application Data\mealaimscr
              C:\Documents and Settings\r hoekstra\Application Data\mealaimscr\0
              C:\Program Files\IntelligentAdvisor
              C:\Program Files\IntelligentAdvisor\IntelligentAdvisor-2.dll
              C:\Program Files\IntelligentAdvisor\IntelligentAdvisor.dat
              C:\Program Files\IntelligentAdvisor\pcre3.dll
              C:\Program Files\IntelligentAdvisor\uninstall.exe
              C:\Program Files\mealaimscr
              C:\WINDOWS\S825D4743.tmp

              .
              (((((((((((((((((((( Bestanden Gemaakt van 2007-11-28 to 2007-12-28 ))))))))))))))))))))))))))))))
              .

              2007-12-28 11:13 . 2007-12-28 11:13 <DIR> d-------- C:\Documents and Settings\r hoekstra\Application Data\Grisoft
              2007-12-28 11:13 . 2007-12-28 11:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
              2007-12-28 11:13 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
              2007-12-28 10:35 . 2007-12-28 10:35 <DIR> d-------- C:\RVAXO
              2007-12-28 09:35 . 2007-12-28 09:55 575,630 --a------ C:\WINDOWS\system32\RVAXO.bat
              2007-12-28 09:35 . 2001-10-01 14:51 69,632 --a------ C:\WINDOWS\system32\remove.exe
              2007-12-28 07:58 . 2002-12-29 01:14 81,920 --a------ C:\WINDOWS\system32\Startup.cpl
              2007-12-27 19:33 . 2007-12-27 19:33 <DIR> d-------- C:\Program Files\DVD Shrink
              2007-12-27 19:33 . 2007-12-27 19:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DVD Shrink
              2007-12-27 19:16 . 2007-12-27 19:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\vsosdk
              2007-12-27 12:56 . 2007-12-27 15:42 <DIR> d-------- C:\Program Files\Spyware Doctor
              2007-12-27 12:56 . 2007-12-27 12:56 <DIR> d-------- C:\Documents and Settings\r hoekstra\Application Data\PC Tools
              2007-12-27 12:56 . 2007-12-27 12:57 74,240 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
              2007-12-27 12:56 . 2007-12-27 12:57 56,832 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
              2007-12-27 12:56 . 2007-10-18 00:14 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
              2007-12-27 12:56 . 2007-10-18 00:16 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
              2007-12-27 12:55 . 2007-12-28 11:08 <DIR> d-------- C:\Program Files\SpywareBlaster
              2007-12-27 12:52 . 2007-12-27 12:55 <DIR> d-------- C:\Temp
              2007-12-27 12:52 . 2007-12-27 12:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Prevx
              2007-12-26 17:44 . 2007-12-27 19:18 <DIR> d-------- C:\Program Files\DVDFab Platinum 4
              2007-12-26 17:44 . 2007-12-27 19:16 <DIR> d-------- C:\Documents and Settings\r hoekstra\Application Data\Vso
              2007-12-26 17:44 . 2007-12-26 17:44 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
              2007-12-26 17:44 . 2007-12-26 17:44 47,360 --a------ C:\Documents and Settings\r hoekstra\Application Data\pcouffin.sys
              2007-12-26 13:09 . 2007-12-27 18:43 <DIR> d-------- C:\Documents and Settings\r hoekstra\Application Data\DVD Shrink
              2007-12-25 23:04 . 2004-04-23 15:01 1,383,936 --a------ C:\WINDOWS\system32\vcl70.bpl
              2007-12-25 23:04 . 2004-04-23 15:01 783,360 --a------ C:\WINDOWS\system32\rtl70.bpl
              2007-12-25 21:43 . 2007-12-25 23:04 <DIR> d-------- C:\Program Files\Dnote Software
              2007-12-25 20:33 . 2007-12-25 20:33 372,736 --a------ C:\WINDOWS\suinsta4001.exe
              2007-12-24 22:45 . 2007-12-25 20:33 <DIR> d-------- C:\Program Files\POI-Warner Medion-Navigator 5 Edition
              2007-12-24 17:51 . 2007-12-25 20:38 <DIR> d-------- C:\Program Files\POI-Warner MN5 Edition
              2007-12-23 02:38 . 2007-12-23 02:38 <DIR> d-------- C:\Documents and Settings\r hoekstra\Application Data\Apple Computer
              2007-12-23 02:38 . 2007-12-28 07:44 54,156 --ah----- C:\WINDOWS\QTFont.qfn
              2007-12-23 02:38 . 2007-12-23 02:38 1,409 --a------ C:\WINDOWS\QTFont.for
              2007-12-23 02:37 . 2007-12-23 02:38 <DIR> d-------- C:\Program Files\iTunes
              2007-12-23 02:37 . 2007-12-23 02:37 <DIR> d-------- C:\Program Files\iPod
              2007-12-23 02:37 . 2007-12-23 02:37 <DIR> d-------- C:\Program Files\Common Files\Apple
              2007-12-23 02:31 . 2007-12-23 02:32 <DIR> d-------- C:\Program Files\QuickTime
              2007-12-23 02:31 . 2007-12-23 02:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
              2007-12-11 10:57 . 2007-12-11 10:57 65,536 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
              2007-12-11 10:57 . 2007-12-11 10:57 49,152 --a------ C:\WINDOWS\system32\QuickTime.qts
              2007-12-09 17:50 . 2007-12-09 17:50 <DIR> d-------- C:\Program Files\Apple Software Update
              2007-12-09 17:50 . 2007-12-09 17:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
              2007-12-08 15:24 . 2007-12-08 15:24 <DIR> d-------- C:\WINDOWS\McAfee.com
              2007-12-07 21:20 . 2007-12-07 21:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
              2007-12-07 17:57 . 2007-12-07 17:57 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
              2007-12-07 17:57 . 2007-12-07 17:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab

              .
              ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
              .
              2007-12-28 09:52 13,440 ----a-w C:\WINDOWS\system32\drivers\USBCRFT.SYS
              2007-12-28 09:52 --------- d-----w C:\Program Files\SP2 Connection Patcher
              2007-12-27 20:18 --------- d-----w C:\Program Files\Zards software
              2007-12-27 20:17 --------- d-----w C:\Program Files\SlySoft
              2007-12-27 20:17 --------- d-----w C:\Program Files\Elaborate Bytes
              2007-12-27 14:39 --------- d-----w C:\Program Files\Hitman Pro
              2007-12-27 12:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
              2007-12-27 11:59 --------- d-----w C:\Documents and Settings\r hoekstra\Application Data\Lavasoft
              2007-12-27 11:55 --------- d-----w C:\Program Files\Lavasoft
              2007-12-24 20:42 26,216 ----a-w C:\Documents and Settings\r hoekstra\Application Data\wklnhst.dat
              2007-12-14 21:51 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
              2007-12-14 21:51 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
              2007-12-10 18:33 424 ----a-w C:\Documents and Settings\pieter\Application Data\wklnhst.dat
              2007-12-09 14:43 --------- d-----w C:\Program Files\LimeWire
              2007-12-07 21:46 102,664 ----a-w C:\WINDOWS\system32\drivers\tmcomm.sys
              2007-12-07 20:19 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
              2007-12-02 13:22 --------- d-----w C:\Program Files\Wolfenstein - Enemy Territory
              2007-11-15 14:13 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
              2007-11-15 14:13 --------- d--h--r C:\Documents and Settings\r hoekstra\Application Data\SecuROM
              2007-11-15 13:17 --------- d-----w C:\Program Files\EA SPORTS
              2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
              2007-11-11 19:17 --------- d-----w C:\Program Files\Finale NotePad 2005a
              2007-11-11 13:51 --------- d-----w C:\Program Files\Samsung
              2007-11-11 12:51 --------- d-----w C:\Documents and Settings\r hoekstra\Application Data\Toshiba
              2007-11-10 18:34 --------- d-----w C:\Program Files\D-Tools
              2007-11-10 15:15 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
              2007-11-01 17:33 --------- d-----w C:\Program Files\Prisma
              2007-10-29 22:45 1,291,776 ----a-w C:\WINDOWS\system32\quartz.dll
              2007-10-25 09:00 230,912 ----a-w C:\WINDOWS\system32\wmasf.dll
              2007-01-07 22:05 2 --shatr C:\WINDOWS\winstart.bat
              .

              ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
              .
              .
              REGEDIT4
              *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24]
              "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 09:03]
              "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 17:34]
              "SP2 Connection Patcher"="C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" [2005-07-11 12:51]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "Dit"="Dit.exe" [2003-12-29 23:33 C:\WINDOWS\Dit.exe]
              "Cmaudio"="RunDll32 cmicnfg.cpl"
              "CHotkey"="mHotkey.exe" [2004-02-05 13:45 C:\WINDOWS\mHotkey.exe]
              "ledpointer"="CNYHKey.exe" [2004-02-03 17:15 C:\WINDOWS\CNYHKey.exe]
              "Realtime Monitor"="C:\PROGRA~1\CA\ETRUST~1\realmon.exe" [2003-02-13 10:25]
              "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
              "PCMService"="C:\Program Files\Home Cinema\PowerCinema\PCMService.exe" [2004-02-19 10:09]
              "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 13:38]
              "HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 15:18]
              "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
              "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 09:12]
              "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-02-23 12:32]
              "Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-10 00:11]
              "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
              "BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 09:03 C:\WINDOWS\system32\bthprops.cpl]
              "DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 17:05]
              "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56]
              "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]

              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
              "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 09:03]

              C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\
              Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2006-03-28 18:26:04]
              HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 22:31:38]
              Snelstart HP Image Zone.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 23:06:36]

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
              @=""

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
              @=""

              R3 Cap7134;MEDION (7134) WDM Video Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys [2003-06-05 10:04]
              R3 CardReaderFilter;Card Reader Filter;C:\WINDOWS\system32\Drivers\USBCRFT.SYS [2007-12-28 10:52]
              R3 Intels51;Creatix V.9X DSP Data Fax Modem;C:\WINDOWS\system32\DRIVERS\ctxs51.sys [2003-05-22 19:44]
              R3 PhTVTune;MEDION TV-TUNER 7134 MK2/3;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys [2003-06-12 10:47]
              R3 PRISM_A00;PRISM 802.11g Driver;C:\WINDOWS\system32\DRIVERS\PRISMA00.sys [2004-01-16 09:31]
              R3 UKBFLT;UKBFLT;C:\WINDOWS\system32\DRIVERS\UKBFLT.sys [2003-12-19 17:13]
              R3 wbscr;Winbond Smartcard Reader for I/O;C:\WINDOWS\system32\drivers\wbscr.sys [2002-04-24 12:07]

              *Newly Created Service* - AVG_ANTI-SPYWARE_DRIVER
              *Newly Created Service* - AVG_ANTI-SPYWARE_GUARD
              .
              Inhoud van de 'Gedeelde Taken' map
              "2007-12-22 22:23:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
              - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
              .
              **************************************************************************

              catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2007-12-28 12:35:03
              Windows 5.1.2600 Service Pack 2 NTFS

              scannen van verborgen processen ...

              scannen van verborgen autostart items ...

              scannen van verborgen bestanden ...

              Scan succesvol afgerond
              verborgen bestanden: 0

              **************************************************************************
              .
              Voltooingstijd: 2007-12-28 12:35:58
              C:\ComboFix2.txt ... 2007-12-28 10:54
              .
              2007-12-27 17:04:02 --- E O F ---

              Comment


              • #8
                Uninstall van RVAXO werkte blijkbaar niet

                Open CFScript.txt en verwijder alles dat daar in staat.
                Zet de volgende vetgedrukte tekst er weer in:


                Folder::
                C:\RVAXO
                C:\Documents and Settings\r hoekstra\Bureaublad\RVAXO

                File::
                C:\firstrun3.log
                C:\rvaxo-results.log
                C:\WINDOWS\system32\RVAXO.bat
                C:\WINDOWS\system32\remove.exe
                C:\Documents and Settings\r hoekstra\Bureaublad\RVAXO.exe



                Sleep CFScript.txt over Combofix.exe zoals je dat eerder deed.
                Combofix toont daana een nieuw logje, post dat eens en vertel of je nog problemen ondervind

                Comment


                • #9
                  logje

                  ComboFix 07-12-28.1 - r hoekstra 2007-12-28 16:53:29.3 - NTFSx86
                  Gestart vanuit: C:\Documents and Settings\r hoekstra\Bureaublad\ComboFix.exe
                  Command switches used :: C:\Documents and Settings\r hoekstra\Bureaublad\CFScript.txt
                  * Nieuw herstelpunt werd aangemaakt

                  FILE
                  C:\Documents and Settings\r hoekstra\Bureaublad\RVAXO.exe
                  C:\firstrun3.log
                  C:\rvaxo-results.log
                  C:\WINDOWS\system32\remove.exe
                  C:\WINDOWS\system32\RVAXO.bat
                  .

                  (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
                  .

                  C:\Documents and Settings\r hoekstra\Bureaublad\RVAXO
                  C:\Documents and Settings\r hoekstra\Bureaublad\RVAXO.exe
                  C:\Documents and Settings\r hoekstra\Bureaublad\RVAXO\RVAXO.cmd
                  C:\Documents and Settings\r hoekstra\Bureaublad\RVAXO\RVAXO1
                  C:\Documents and Settings\r hoekstra\Bureaublad\RVAXO\Rvaxo2
                  C:\Documents and Settings\r hoekstra\Bureaublad\RVAXO\RVAXO3
                  C:\Documents and Settings\r hoekstra\Bureaublad\RVAXO\RVAXO4
                  C:\Documents and Settings\r hoekstra\Bureaublad\RVAXO\Rvaxo5
                  C:\Documents and Settings\r hoekstra\Bureaublad\RVAXO\Rvaxo6
                  C:\Documents and Settings\r hoekstra\Bureaublad\RVAXO\Uninstall.cmd
                  C:\firstrun3.log
                  C:\rvaxo-results.log
                  C:\RVAXO
                  C:\RVAXO\results.log
                  C:\WINDOWS\system32\remove.exe
                  C:\WINDOWS\system32\RVAXO.bat

                  .
                  (((((((((((((((((((( Bestanden Gemaakt van 2007-11-28 to 2007-12-28 ))))))))))))))))))))))))))))))
                  .

                  2007-12-28 11:13 . 2007-12-28 11:13 <DIR> d-------- C:\Documents and Settings\r hoekstra\Application Data\Grisoft
                  2007-12-28 11:13 . 2007-12-28 11:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
                  2007-12-28 11:13 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
                  2007-12-28 07:58 . 2002-12-29 01:14 81,920 --a------ C:\WINDOWS\system32\Startup.cpl
                  2007-12-27 19:33 . 2007-12-27 19:33 <DIR> d-------- C:\Program Files\DVD Shrink
                  2007-12-27 19:33 . 2007-12-27 19:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DVD Shrink
                  2007-12-27 19:16 . 2007-12-27 19:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\vsosdk
                  2007-12-27 12:56 . 2007-12-27 15:42 <DIR> d-------- C:\Program Files\Spyware Doctor
                  2007-12-27 12:56 . 2007-12-27 12:56 <DIR> d-------- C:\Documents and Settings\r hoekstra\Application Data\PC Tools
                  2007-12-27 12:56 . 2007-12-27 12:57 74,240 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
                  2007-12-27 12:56 . 2007-12-27 12:57 56,832 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
                  2007-12-27 12:56 . 2007-10-18 00:14 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
                  2007-12-27 12:56 . 2007-10-18 00:16 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
                  2007-12-27 12:55 . 2007-12-28 11:08 <DIR> d-------- C:\Program Files\SpywareBlaster
                  2007-12-27 12:52 . 2007-12-27 12:55 <DIR> d-------- C:\Temp
                  2007-12-27 12:52 . 2007-12-27 12:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Prevx
                  2007-12-26 17:44 . 2007-12-27 19:18 <DIR> d-------- C:\Program Files\DVDFab Platinum 4
                  2007-12-26 17:44 . 2007-12-27 19:16 <DIR> d-------- C:\Documents and Settings\r hoekstra\Application Data\Vso
                  2007-12-26 17:44 . 2007-12-26 17:44 47,360 --a------ C:\WINDOWS\system32\drivers\pcouffin.sys
                  2007-12-26 17:44 . 2007-12-26 17:44 47,360 --a------ C:\Documents and Settings\r hoekstra\Application Data\pcouffin.sys
                  2007-12-26 13:09 . 2007-12-27 18:43 <DIR> d-------- C:\Documents and Settings\r hoekstra\Application Data\DVD Shrink
                  2007-12-25 23:04 . 2004-04-23 15:01 1,383,936 --a------ C:\WINDOWS\system32\vcl70.bpl
                  2007-12-25 23:04 . 2004-04-23 15:01 783,360 --a------ C:\WINDOWS\system32\rtl70.bpl
                  2007-12-25 21:43 . 2007-12-25 23:04 <DIR> d-------- C:\Program Files\Dnote Software
                  2007-12-25 20:33 . 2007-12-25 20:33 372,736 --a------ C:\WINDOWS\suinsta4001.exe
                  2007-12-24 22:45 . 2007-12-25 20:33 <DIR> d-------- C:\Program Files\POI-Warner Medion-Navigator 5 Edition
                  2007-12-24 17:51 . 2007-12-25 20:38 <DIR> d-------- C:\Program Files\POI-Warner MN5 Edition
                  2007-12-23 02:38 . 2007-12-23 02:38 <DIR> d-------- C:\Documents and Settings\r hoekstra\Application Data\Apple Computer
                  2007-12-23 02:37 . 2007-12-23 02:38 <DIR> d-------- C:\Program Files\iTunes
                  2007-12-23 02:37 . 2007-12-23 02:37 <DIR> d-------- C:\Program Files\iPod
                  2007-12-23 02:37 . 2007-12-23 02:37 <DIR> d-------- C:\Program Files\Common Files\Apple
                  2007-12-23 02:31 . 2007-12-23 02:32 <DIR> d-------- C:\Program Files\QuickTime
                  2007-12-23 02:31 . 2007-12-23 02:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
                  2007-12-11 10:57 . 2007-12-11 10:57 65,536 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
                  2007-12-11 10:57 . 2007-12-11 10:57 49,152 --a------ C:\WINDOWS\system32\QuickTime.qts
                  2007-12-09 17:50 . 2007-12-09 17:50 <DIR> d-------- C:\Program Files\Apple Software Update
                  2007-12-09 17:50 . 2007-12-09 17:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
                  2007-12-08 15:24 . 2007-12-08 15:24 <DIR> d-------- C:\WINDOWS\McAfee.com
                  2007-12-07 21:20 . 2007-12-07 21:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
                  2007-12-07 17:57 . 2007-12-07 17:57 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
                  2007-12-07 17:57 . 2007-12-07 17:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab

                  .
                  ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  2007-12-28 09:52 13,440 ----a-w C:\WINDOWS\system32\drivers\USBCRFT.SYS
                  2007-12-28 09:52 --------- d-----w C:\Program Files\SP2 Connection Patcher
                  2007-12-27 20:18 --------- d-----w C:\Program Files\Zards software
                  2007-12-27 20:17 --------- d-----w C:\Program Files\SlySoft
                  2007-12-27 20:17 --------- d-----w C:\Program Files\Elaborate Bytes
                  2007-12-27 14:39 --------- d-----w C:\Program Files\Hitman Pro
                  2007-12-27 12:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                  2007-12-27 11:59 --------- d-----w C:\Documents and Settings\r hoekstra\Application Data\Lavasoft
                  2007-12-27 11:55 --------- d-----w C:\Program Files\Lavasoft
                  2007-12-24 20:42 26,216 ----a-w C:\Documents and Settings\r hoekstra\Application Data\wklnhst.dat
                  2007-12-14 21:51 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
                  2007-12-14 21:51 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
                  2007-12-10 18:33 424 ----a-w C:\Documents and Settings\pieter\Application Data\wklnhst.dat
                  2007-12-09 14:43 --------- d-----w C:\Program Files\LimeWire
                  2007-12-07 21:46 102,664 ----a-w C:\WINDOWS\system32\drivers\tmcomm.sys
                  2007-12-07 20:19 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
                  2007-12-02 13:22 --------- d-----w C:\Program Files\Wolfenstein - Enemy Territory
                  2007-11-15 14:13 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
                  2007-11-15 14:13 --------- d--h--r C:\Documents and Settings\r hoekstra\Application Data\SecuROM
                  2007-11-15 13:17 --------- d-----w C:\Program Files\EA SPORTS
                  2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
                  2007-11-11 19:17 --------- d-----w C:\Program Files\Finale NotePad 2005a
                  2007-11-11 13:51 --------- d-----w C:\Program Files\Samsung
                  2007-11-11 12:51 --------- d-----w C:\Documents and Settings\r hoekstra\Application Data\Toshiba
                  2007-11-10 18:34 --------- d-----w C:\Program Files\D-Tools
                  2007-11-10 15:15 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
                  2007-11-01 17:33 --------- d-----w C:\Program Files\Prisma
                  2007-10-29 22:45 1,291,776 ----a-w C:\WINDOWS\system32\quartz.dll
                  2007-10-25 09:00 230,912 ----a-w C:\WINDOWS\system32\wmasf.dll
                  2007-01-07 22:05 2 --shatr C:\WINDOWS\winstart.bat
                  .

                  ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  REGEDIT4
                  *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24]
                  "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 09:03]
                  "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 17:34]
                  "SP2 Connection Patcher"="C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" [2005-07-11 12:51]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "Dit"="Dit.exe" [2003-12-29 23:33 C:\WINDOWS\Dit.exe]
                  "Cmaudio"="RunDll32 cmicnfg.cpl"
                  "CHotkey"="mHotkey.exe" [2004-02-05 13:45 C:\WINDOWS\mHotkey.exe]
                  "ledpointer"="CNYHKey.exe" [2004-02-03 17:15 C:\WINDOWS\CNYHKey.exe]
                  "Realtime Monitor"="C:\PROGRA~1\CA\ETRUST~1\realmon.exe" [2003-02-13 10:25]
                  "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
                  "PCMService"="C:\Program Files\Home Cinema\PowerCinema\PCMService.exe" [2004-02-19 10:09]
                  "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 13:38]
                  "HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 15:18]
                  "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
                  "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 09:12]
                  "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-02-23 12:32]
                  "Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-10 00:11]
                  "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
                  "BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 09:03 C:\WINDOWS\system32\bthprops.cpl]
                  "DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 17:05]
                  "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56]
                  "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]

                  [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                  "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 09:03]

                  C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\
                  Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2006-03-28 18:26:04]
                  HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 22:31:38]
                  Snelstart HP Image Zone.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 23:06:36]

                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
                  @=""

                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
                  @=""

                  R3 Cap7134;MEDION (7134) WDM Video Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys [2003-06-05 10:04]
                  R3 CardReaderFilter;Card Reader Filter;C:\WINDOWS\system32\Drivers\USBCRFT.SYS [2007-12-28 10:52]
                  R3 Intels51;Creatix V.9X DSP Data Fax Modem;C:\WINDOWS\system32\DRIVERS\ctxs51.sys [2003-05-22 19:44]
                  R3 PhTVTune;MEDION TV-TUNER 7134 MK2/3;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys [2003-06-12 10:47]
                  R3 PRISM_A00;PRISM 802.11g Driver;C:\WINDOWS\system32\DRIVERS\PRISMA00.sys [2004-01-16 09:31]
                  R3 UKBFLT;UKBFLT;C:\WINDOWS\system32\DRIVERS\UKBFLT.sys [2003-12-19 17:13]
                  R3 wbscr;Winbond Smartcard Reader for I/O;C:\WINDOWS\system32\drivers\wbscr.sys [2002-04-24 12:07]

                  *Newly Created Service* - AVG_ANTI-SPYWARE_DRIVER
                  *Newly Created Service* - AVG_ANTI-SPYWARE_GUARD
                  .
                  Inhoud van de 'Gedeelde Taken' map
                  "2007-12-22 22:23:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
                  - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
                  .
                  **************************************************************************

                  catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2007-12-28 17:00:15
                  Windows 5.1.2600 Service Pack 2 NTFS

                  scannen van verborgen processen ...

                  scannen van verborgen autostart items ...

                  scannen van verborgen bestanden ...

                  Scan succesvol afgerond
                  verborgen bestanden: 0

                  **************************************************************************
                  .
                  Voltooingstijd: 2007-12-28 17:01:05
                  C:\ComboFix2.txt ... 2007-12-28 12:36
                  C:\ComboFix3.txt ... 2007-12-28 10:54
                  .
                  2007-12-27 17:04:02 --- E O F ---

                  en of ik nu gevrijwaard ben probeer ik direkt ff uit en dan hoor/zie je het heir

                  met vr grt romke

                  Comment


                  • #10
                    probleem mogelijk opgelost

                    het lijkt erop dat ik nu vrij ben van de popup van celldorado
                    het avg spyware geinstalleerd en hoop nu ook vrij t kunne blijven
                    bedankt voor je hulp

                    met vr gr romke

                    Comment


                    • #11
                      Graag gedaan hoor

                      Doe dit nog:

                      Verwijder de volgende map:
                      C:\Qoobox

                      Maak dan je prullenbak leeg.

                      Download ATF cleaner (mirror)(gemaakt door Atribune)

                      Belangrijk: Sluit al je browservensters(IE en/of Firefox en/of Opera) om de tool goed te kunnen laten werken.

                      Dubbelklik op ATF cleaner om het programma te starten.
                      Op het tabblad "Main", plaats je een vinkje bij Select All.
                      Klik op de knop Empty Selected.

                      Het volgende doen als je ook FireFox als browser hebt:
                      Klik op tabblad "Firefox", plaats een vinkje bij Select All.
                      Wil je de door Firefox opgeslagen wachtwoorden behouden, dan klik je in het venster dat verschijnt op "No".
                      (dit haalt het vinkje weer weg bij "Firefox saved passwords")
                      Klik op de knop Empty Selected.

                      Het volgende doen als je ook Opera als browser hebt:
                      Klik op tabblad "Opera", plaats een vinkje bij Select All.
                      Wil je de door Opera opgeslagen wachtwoorden behouden, dan klik je in het venster dat verschijnt op "No".
                      Klik op de knop Empty Selected.
                      Ga naar het tabblad "Main" en klik op de knop Exit om het programma af te sluiten.

                      Ga naar Start - Uitvoeren en geef hier het volgende in:
                      Combofix /U
                      Druk daarna op OK.
                      Let op: Er moet een spatie tussen Combofix en /U zitten.

                      Dit zal Combofix deïnstalleren.

                      Schakel Systeemherstel uit. Herstart de computer. Schakel Systeemherstel weer in.
                      Kijk hier hoe je je systeemherstel moet uitschakelen.
                      Hiermee verwijder je eventuele restanten van de infecties uit je systeemherstel.

                      Dan denk ik dat alles weer OK is

                      Comment

                      Sorry, you are not authorized to view this page
                      Working...
                      X