Mededeling

Collapse
No announcement yet.

Infectie : your pc is infected with spyware

Collapse
X
  •  
  • Filter
  • Tijd
  • Show
Clear All
new posts

  • Infectie : your pc is infected with spyware

    Goedenavond ,

    ik heb sinds eergisteren een maffe (naar mijn idee maf...) melding vanuit de taakbalk dat ik spyware heb na een clean install.

    "Dangerous infection was detected on your PC
    The system wil now download and install most efficient animalware program to prevent data loss and your private information theft.
    Click here to protect your computer from the biggest mallware threats."

    Onder een andere topic van iemand anders met hetzelfde probleem ben ik er in iedergeval achter dat het vanuit een spyware proggie komt( na install van AVG) en niet vanuit windows.

    ik heb alvast avg anti-spyware 7.5 geinstalleerd en smit-rem.

    Dit is alvast de hijackthis log :

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:34:09, on 20-3-2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16608)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\resetservice.exe
    c:\windows\system32\drivers\services.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\PowerISO\PWRISOVM.EXE
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\DOCUME~1\Rayner\LOCALS~1\Temp\IMAdvertiser.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\MSMSGS.EXE
    C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    C:\Program Files\Bat\X_Bat.exe
    C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    F:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\notepad.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    C:\Program Files\McAfee\MSC\mcupdui.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Windows Desktop Search\WindowsSearchFilter.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Documents and Settings\Rayner\Bureaublad\HiJackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = wwwproxy.xs4all.nl:8080
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = https://
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\mgmrwmrv.exe,
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [IMprocess] C:\DOCUME~1\Rayner\LOCALS~1\Temp\IMAdvertiser.EXE
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Lokale service')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Netwerkservice')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe
    O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O23 - Service: McAfee Application Installer Cleanup (0153311205974296) (0153311205974296mcinstcleanup) - McAfee, Inc. - C:\DOCUME~1\Rayner\LOCALS~1\Temp\015331~1.EXE
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - F:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: Reset 5 - Unknown owner - C:\WINDOWS\system32\srvany.exe (file missing)
    O23 - Service: Windows Services Control - FileZilla Project - c:\windows\system32\drivers\services.exe

    --
    End of file - 7097 bytes


    Ik hoop dat ik verder geholpen kan worden en zeker mbt de HiJack this log daar ik echt 0,0 verstand van heb.

    Bij voorbaat dank !

  • #2
    Download: RVAXO.exe
    • Sla het bestand op je bureaublad op, dubbelklik het en kies voor "Unzip" om het uit te pakken.
    • Start de computer in veilige modus.
    • Open nu de map RVAXO op je bureaublad en dubbeklik RunMe.cmd
      Er zal een cmd-schermpje openen, daarin zullen snel enkele regels over niet gevonden bestanden voorbijkomen, dit is normaal.
    • Mogelijk start er ook een uninstaller van een rogue scanner op, sluit deze niet af maar volg eventuele aanwijzingen en laat deze gewoon zijn werk doen.
    • Daarna zal je PC herstarten, laat hem nu weer in normale modus starten. Na de herstart opent het cmd-venster van RVAXO opnieuw.
      Laat deze lopen en wacht tot er een logfile opent: C:\RVAXO-results.log
    • Herstart je computer niet vanzelf, of start de tool niet na de reboot, doe dit dan handmatig.
    • Post de inhoud van de logfile in je volgende bericht.
    Download Deckard's System Scanner naar je Bureaublad.
    • Sluit alle toepassingen en vensters.
    • Dubbelklik op dss.exe om het te activeren, en volg de aanwijzingen.
    • Wanneer de scan volledig is, zal een tekstbestand - main.txt - openen.
    • Kopiëer (Ctrl+A gevolgd door Ctrl+C) en plak (Ctrl+V) de inhoud van main.txt in je volgende antwoord.

    Opmerking: Sommige firewalls kunnen waarschuwen dat sigcheck.exe probeert verbinding te maken met het internet
    - zorg dat sigcheck.exe toestemming krijgt om dit te doen !
    Tevens kan het gebeuren dat je Antivirus DSS als verdacht aangeeft, of zelfs probeert te verwijderen.
    Laat je Antivirus dit niet verwijderen ! (In dit geval is het misschien beter om tijdens de scan van DSS je Antivirus even uit te schakelen)

    Comment


    • #3
      RVAXO.exe kan niet worden gedownload. De homepage van de desbetreffende persoon is down...

      edit: got it... opslaan als wilt nog eens helpen..

      other edit : ALs dit een .exe file is... hoe gaan we dit dan uitpakken ?
      Last edited by Krespo; 20-03-08, 23:42.

      Comment


      • #4
        Probeer het hier eens.

        Comment


        • #5
          oke hier dan de logjes :

          RVAXO

          ---RVAXO.exe Updated: 2008-03-20---first run---
          Uninstallers:

          Files found:
          C:\WINDOWS\system32\yybeg.ini2
          C:\WINDOWS\pskt.ini
          C:\WINDOWS\assys.dll
          C:\WINDOWS\ffnsys.dll
          C:\WINDOWS\rsczsys.dll
          C:\WINDOWS\mfnsys.dll
          C:\WINDOWS\uawin.dll
          C:\WINDOWS\snsys.dll
          C:\WINDOWS\gstcore.dll
          C:\WINDOWS\system32\exec1.exe
          C:\WINDOWS\system32\drivers\services.exe

          Folders Found:
          C:\Program Files\seekmo

          Hosts-file was reset, If you use a custom hosts file please replace it...

          --------------RVAXO.exe last run---------------
          Not deleted items:

          --------------RVAXO.exe finished----------------


          DSS :

          Deckard's System Scanner v20071014.68
          Run by Rayner on 2008-03-20 23:16:37
          Computer is in Normal Mode.
          --------------------------------------------------------------------------------

          -- System Restore --------------------------------------------------------------

          Successfully created a Deckard's System Scanner Restore Point.


          -- Last 5 Restore Point(s) --
          144: 2008-03-20 22:16:40 UTC - RP144 - Deckard's System Scanner Restore Point
          143: 2008-03-20 21:43:16 UTC - RP143 - Software Distribution Service 3.0
          142: 2008-03-20 20:52:11 UTC - RP142 - Software Distribution Service 3.0
          141: 2008-03-20 00:38:17 UTC - RP141 - Ad-Aware Restore Point 2008-03-20 01:38:15
          140: 2008-03-20 00:31:50 UTC - RP140 - Installed Ad-Aware 2007


          -- First Restore Point --
          1: 2008-03-19 21:11:15 UTC - RP1 - Controlepunt van systeem


          Backed up registry hives.
          Performed disk cleanup.


          Mochten er nog fouten zijn , dan hoor(lees) ik het graag

          Comment


          • #6
            Logje(main.txt) van Deckard's System Scanner is een beetje kort.
            Is dit alles wat in dat logje stond?

            Comment


            • #7
              the long version... ( I think...)


              Deckard's System Scanner v20071014.68
              Run by Rayner on 2008-03-20 23:16:37
              Computer is in Normal Mode.
              --------------------------------------------------------------------------------

              -- System Restore --------------------------------------------------------------

              Successfully created a Deckard's System Scanner Restore Point.


              -- Last 5 Restore Point(s) --
              144: 2008-03-20 22:16:40 UTC - RP144 - Deckard's System Scanner Restore Point
              143: 2008-03-20 21:43:16 UTC - RP143 - Software Distribution Service 3.0
              142: 2008-03-20 20:52:11 UTC - RP142 - Software Distribution Service 3.0
              141: 2008-03-20 00:38:17 UTC - RP141 - Ad-Aware Restore Point 2008-03-20 01:38:15
              140: 2008-03-20 00:31:50 UTC - RP140 - Installed Ad-Aware 2007


              -- First Restore Point --
              1: 2008-03-19 21:11:15 UTC - RP1 - Controlepunt van systeem


              Backed up registry hives.
              Performed disk cleanup.



              -- HijackThis (run as Rayner.exe) ----------------------------------------------

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 23:17:57, on 20-3-2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16608)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              F:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
              c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
              c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
              C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
              C:\Program Files\McAfee\MPF\MPFSrv.exe
              C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
              C:\Program Files\Windows Desktop Search\wds_sl.exe
              C:\WINDOWS\system32\WgaTray.exe
              C:\WINDOWS\RTHDCPL.EXE
              C:\Program Files\QuickTime\qttask.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\Program Files\PowerISO\PWRISOVM.EXE
              C:\Program Files\iPod\bin\iPodService.exe
              C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
              C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
              C:\WINDOWS\system32\rundll32.exe
              C:\WINDOWS\system32\Rundll32.exe
              C:\Program Files\Messenger\MSMSGS.EXE
              C:\Program Files\Windows Desktop Search\WindowsSearch.exe
              C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
              C:\Program Files\Bat\X_Bat.exe
              C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
              C:\Documents and Settings\Rayner\Bureaublad\dss.exe
              C:\Program Files\Windows Desktop Search\WindowsSearchFilter.exe
              C:\DOCUME~1\Rayner\BUREAU~1\Rayner.exe

              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = wwwproxy.xs4all.nl:8080
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = https://
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
              F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\mgmrwmrv.exe,
              O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
              O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
              O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
              O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
              O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
              O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
              O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-92c6-ce7eb590a94d} - (no file)
              O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2c7e78fbab38} - (no file)
              O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
              O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
              O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
              O2 - BHO: BatBHO - {63F7460B-C831-4142-A4AA-5EC303EC4343} - C:\Program Files\Bat\Bat.dll
              O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
              O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
              O2 - BHO: (no name) - {87CADEB4-0FD4-4288-9EC3-AD7C14EDFC54} - C:\WINDOWS\system32\ljjhfda.dll
              O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7960230792f1} - (no file)
              O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
              O2 - BHO: (no name) - {A8235A32-CC9C-4D69-9384-759EE8D0FEB2} - C:\WINDOWS\system32\gebyy.dll
              O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
              O2 - BHO: {b562966d-dbf5-adb8-1bb4-869ebffcb81e} - {e18bcffb-e968-4bb1-8bda-5fbdd669265b} - C:\WINDOWS\system32\ntuepksi.dll
              O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)
              O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
              O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
              O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
              O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
              O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
              O4 - HKLM\..\Run: [e87c986c] rundll32.exe "C:\WINDOWS\system32\jpdbthqn.dll",b
              O4 - HKLM\..\Run: [BMeb4fabf0] Rundll32.exe "C:\WINDOWS\system32\jxwnaqws.dll",s
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Lokale service')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Netwerkservice')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
              O4 - Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe
              O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
              O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
              O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
              O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
              O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
              O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
              O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O20 - Winlogon Notify: ljjhfda - C:\WINDOWS\SYSTEM32\ljjhfda.dll
              O20 - Winlogon Notify: reset5 - C:\WINDOWS\SYSTEM32\reset5.dll
              O23 - Service: McAfee Application Installer Cleanup (0153311205974296) (0153311205974296mcinstcleanup) - Unknown owner - C:\DOCUME~1\Rayner\LOCALS~1\Temp\015331~1.EXE (file missing)
              O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - F:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
              O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
              O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
              O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
              O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
              O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
              O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
              O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
              O23 - Service: Reset 5 - Unknown owner - C:\WINDOWS\system32\srvany.exe (file missing)

              --
              End of file - 8925 bytes

              -- File Associations -----------------------------------------------------------

              All associations okay.


              -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

              R1 SCDEmu - c:\windows\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>


              -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

              S2 0153311205974296mcinstcleanup (McAfee Application Installer Cleanup (0153311205974296)) - c:\docume~1\rayner\locals~1\temp\015331~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service (file missing)
              S2 Reset 5 - c:\windows\system32\srvany.exe (file missing)


              -- Device Manager: Disabled ----------------------------------------------------

              No disabled devices found.


              -- Scheduled Tasks -------------------------------------------------------------

              2008-03-20 16:11:00 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
              2008-03-20 01:51:10 342 --a------ C:\WINDOWS\Tasks\McDefragTask.job
              2008-03-20 01:51:08 334 --a------ C:\WINDOWS\Tasks\McQcTask.job


              -- Files created between 2008-02-20 and 2008-03-20 -----------------------------

              2008-03-20 22:58:22 177496 --ahs---- C:\WINDOWS\system32\yybeg.ini2
              2008-03-20 22:55:20 0 d-------- C:\RVAXO
              2008-03-20 22:53:29 747874 --a------ C:\WINDOWS\system32\RVAXO.bat
              2008-03-20 22:53:29 69632 --a------ C:\WINDOWS\system32\remove.exe
              2008-03-20 22:46:45 0 d--h----- C:\WINDOWS\PIF
              2008-03-20 21:55:07 0 d-------- C:\Program Files\MSXML 6.0
              2008-03-20 21:39:15 87104 --a------ C:\WINDOWS\system32\jpdbthqn.dll
              2008-03-20 21:36:31 91712 --a------ C:\WINDOWS\system32\ntuepksi.dll
              2008-03-20 21:36:23 89664 --a------ C:\WINDOWS\system32\jxwnaqws.dll
              2008-03-20 21:23:45 0 d-------- C:\Documents and Settings\Rayner\Application Data\Grisoft
              2008-03-20 21:21:02 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
              2008-03-20 07:35:15 0 d-------- C:\Program Files\180solutions
              2008-03-20 01:50:33 0 d-------- C:\Program Files\McAfee.com
              2008-03-20 01:50:06 0 d-------- C:\Program Files\Common Files\McAfee
              2008-03-20 01:49:27 0 d-------- C:\Program Files\McAfee
              2008-03-20 01:46:57 0 d-------- C:\Documents and Settings\All Users\Application Data\McAfee
              2008-03-20 01:31:15 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
              2008-03-20 01:31:00 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
              2008-03-19 22:11:05 305728 --a------ C:\WINDOWS\system32\gebyy.dll
              2008-03-19 22:03:35 0 d-------- C:\Documents and Settings\All Users\Application Data\Avg8
              2008-03-19 22:03:15 0 d-------- C:\WINDOWS\StartHtmico
              2008-03-19 22:02:31 90112 -ra------ C:\WINDOWS\system32\CNMCP78.exe <Not Verified; CANON INC.; Canon BJ Raster Printer Driver Installer>
              2008-03-19 22:02:10 0 d--h----- C:\Documents and Settings\All Users\Application Data\CanonBJ
              2008-03-19 22:00:10 0 d-------- C:\Program Files\Canon
              2008-03-19 18:53:34 10240 --a------ C:\WINDOWS\voiceip.dll
              2008-03-19 18:53:34 13824 --a------ C:\WINDOWS\swin32.dll
              2008-03-19 18:53:34 10752 --a------ C:\WINDOWS\stcloader.exe
              2008-03-19 18:53:34 23808 --a------ C:\WINDOWS\cdsm32.dll
              2008-03-19 18:53:34 0 d-------- C:\Program Files\stc
              2008-03-19 18:53:33 18176 --a------ C:\WINDOWS\mssvr.exe
              2008-03-19 18:53:33 11776 --a------ C:\WINDOWS\mspphe.dll
              2008-03-19 18:53:33 29440 --a------ C:\WINDOWS\bokja.exe
              2008-03-19 18:53:33 18688 --a------ C:\WINDOWS\bjam.dll
              2008-03-19 18:53:33 9984 --a------ C:\WINDOWS\2020search2.dll
              2008-03-19 18:53:33 28160 --a------ C:\WINDOWS\2020search.dll
              2008-03-19 18:53:32 16128 --a------ C:\WINDOWS\system32\WER8274.DLL
              2008-03-19 18:53:32 27136 --a------ C:\WINDOWS\system32\MSIXU.DLL
              2008-03-19 18:53:32 13056 --a------ C:\WINDOWS\180ax.exe
              2008-03-19 18:53:32 0 d-------- C:\Program Files\zango
              2008-03-19 18:53:32 0 d-------- C:\Program Files\180searchassistant
              2008-03-19 18:53:32 0 d-------- C:\Program Files\180search assistant
              2008-03-19 18:53:31 14848 --a------ C:\WINDOWS\updatetc.exe
              2008-03-19 18:53:31 18432 --a------ C:\WINDOWS\system32\MSNSA32.dll
              2008-03-19 18:53:31 26624 --a------ C:\WINDOWS\salm.exe
              2008-03-19 18:53:31 10496 --a------ C:\WINDOWS\saiemod.dll
              2008-03-19 18:53:31 19968 --a------ C:\WINDOWS\msapasrc.dll
              2008-03-19 18:53:31 23552 --a------ C:\WINDOWS\msa64chk.dll
              2008-03-19 18:53:31 0 d-------- C:\WINDOWS\FLEOK
              2008-03-19 18:53:30 15360 --a------ C:\WINDOWS\system32\SIPSPI32.dll
              2008-03-19 18:53:30 29440 --a------ C:\WINDOWS\system32\shdocpe.dll
              2008-03-19 18:53:30 12544 --a------ C:\WINDOWS\system32\ntnut32.exe
              2008-03-19 18:53:30 8448 --a------ C:\WINDOWS\shdocpl.dll
              2008-03-19 18:53:30 15360 --a------ C:\WINDOWS\shdocpe.dll
              2008-03-19 18:53:30 15872 --a------ C:\WINDOWS\ntnut.exe
              2008-03-19 18:53:29 22272 --a------ C:\WINDOWS\winsb.dll
              2008-03-19 18:53:29 24576 --a------ C:\WINDOWS\browserad.dll
              2008-03-19 18:53:29 32768 --a------ C:\WINDOWS\aviwrap32.dll
              2008-03-19 18:53:29 31488 --a------ C:\WINDOWS\avisynthex32.dll
              2008-03-19 18:53:29 0 d-------- C:\Program Files\Sysmnt
              2008-03-19 18:53:28 23552 --a------ C:\WINDOWS\avifile32.dll
              2008-03-19 18:53:28 22016 --a------ C:\WINDOWS\autodisc32.dll
              2008-03-19 18:53:28 16384 --a------ C:\WINDOWS\audiosrv32.dll
              2008-03-19 18:53:28 15104 --a------ C:\WINDOWS\ati2dvag32.dll
              2008-03-19 18:53:28 21760 --a------ C:\WINDOWS\ati2dvaa32.dll
              2008-03-19 18:53:28 14848 --a------ C:\WINDOWS\athprxy32.dll
              2008-03-19 18:53:28 27392 --a------ C:\WINDOWS\asycfilt32.dll
              2008-03-19 18:53:28 13312 --a------ C:\WINDOWS\asferror32.dll
              2008-03-19 18:53:27 9472 --a------ C:\WINDOWS\changeurl_30.dll
              2008-03-19 18:53:27 21760 --a------ C:\WINDOWS\apphelp32.dll
              2008-03-19 18:53:25 0 d-------- C:\Documents and Settings\All Users\Application Data\Rabio
              2008-03-19 18:39:57 0 d-------- C:\Program Files\AVG
              2008-03-19 18:38:54 37376 --a------ C:\WINDOWS\system32\ljjhfda.dll
              2008-03-19 18:38:54 97 --a------ C:\Extractor.bat
              2008-03-19 18:38:36 0 d-------- C:\Program Files\Bat
              2008-03-19 18:38:25 4 --a------ C:\WINDOWS\system32\winfrun32.bin
              2008-03-19 18:37:37 0 d-------- C:\Program Files\QuickPar
              2008-03-19 18:36:49 0 d-------- C:\Documents and Settings\Rayner\Application Data\Windows Desktop Search
              2008-03-19 18:36:10 0 d-------- C:\Program Files\Windows Desktop Search
              2008-03-19 18:30:52 0 d-------- C:\WINDOWS\system32\appmgmt
              2008-03-19 18:29:28 0 d-------- C:\Documents and Settings\Rayner\Application Data\ATI
              2008-03-19 18:29:28 0 d-------- C:\Documents and Settings\All Users\Application Data\ATI
              2008-03-19 18:20:14 0 d-------- C:\WINDOWS\SHELLNEW
              2008-03-19 18:20:13 0 d-------- C:\Program Files\Microsoft.NET
              2008-03-19 18:11:50 0 d-------- C:\Program Files\MSBuild
              2008-03-19 18:09:25 0 d-------- C:\WINDOWS\system32\XPSViewer
              2008-03-19 18:09:09 0 d-------- C:\Program Files\Reference Assemblies
              2008-03-19 18:08:11 0 d-------- C:\Program Files\Windows Media Connect 2
              2008-03-19 18:07:39 0 d-------- C:\WINDOWS\system32\LogFiles
              2008-03-19 18:07:39 0 d-------- C:\WINDOWS\system32\drivers\UMDF
              2008-03-19 18:04:56 0 d-------- C:\WINDOWS\RegisteredPackages
              2008-03-19 18:04:04 0 d-------- C:\WINDOWS\system32\URTTemp
              2008-03-19 17:54:18 0 --a------ C:\WINDOWS\ativpsrm.bin
              2008-03-19 17:49:37 110592 --a------ C:\WINDOWS\system32\drivers\zlib1d.dll <Not Verified; ; zlib>
              2008-03-19 17:45:59 0 d-------- C:\Program Files\NewsLeecher
              2008-03-19 17:44:58 0 d-------- C:\WINDOWS\system32\nl-nl
              2008-03-19 17:43:48 0 d-------- C:\WINDOWS\network diagnostic
              2008-03-19 17:39:23 0 d-------- C:\WINDOWS\pss
              2008-03-19 00:36:35 0 d-------- C:\Documents and Settings\LocalService\Menu Start
              2008-03-19 00:35:56 0 d-------- C:\WINDOWS\Prefetch
              2008-03-18 23:36:19 0 d-------- C:\WINDOWS\provisioning
              2008-03-18 23:36:19 0 d-------- C:\WINDOWS\peernet
              2008-03-18 23:35:24 0 d-------- C:\WINDOWS\ServicePackFiles
              2008-03-18 23:32:37 0 d-------- C:\WINDOWS\EHome
              2008-03-18 23:27:47 0 d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
              2008-03-18 23:27:44 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
              2008-03-18 23:17:27 0 d-------- C:\Program Files\PowerISO
              2008-03-18 23:14:43 0 d-------- C:\Documents and Settings\Rayner\Application Data\WinRAR
              2008-03-18 23:13:57 0 d--hs---- C:\Documents and Settings\Rayner\Application Data\.#
              2008-03-18 23:13:57 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
              2008-03-18 23:13:54 1706870 -r-h----- C:\WINDOWS\wwwwizdll.exe <Not Verified; T; DNS>
              2008-03-18 16:24:04 1751 --a------ C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
              2008-03-17 21:16:25 26112 --a------ C:\WINDOWS\system32\xpsp1hfm.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
              2008-03-17 21:12:59 171280 --a------ C:\WINDOWS\system32\jit.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
              2008-03-17 21:12:59 139536 --a------ C:\WINDOWS\system32\javaee.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
              2008-03-17 21:12:59 313856 --a------ C:\WINDOWS\system32\dx3j.dll <Not Verified; Microsoft Corporation; Microsoft® DirectX for Java>
              2008-03-17 21:12:59 46352 --a------ C:\WINDOWS\setdebug.exe <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
              2008-03-17 21:12:59 6550 --a------ C:\WINDOWS\jautoexp.dat
              2008-03-17 21:12:57 113 --a------ C:\WINDOWS\system32\zonedon.reg
              2008-03-17 21:12:57 113 --a------ C:\WINDOWS\system32\zonedoff.reg
              2008-03-17 21:12:57 171792 --a------ C:\WINDOWS\system32\wjview.exe <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
              2008-03-17 21:12:57 286992 --a------ C:\WINDOWS\system32\vmhelper.dll <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
              2008-03-17 21:12:57 21264 --a------ C:\WINDOWS\system32\msjdbc10.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
              2008-03-17 21:12:56 947472 --a------ C:\WINDOWS\system32\msjava.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
              2008-03-17 21:12:56 154384 --a------ C:\WINDOWS\system32\msawt.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
              2008-03-17 21:12:56 172304 --a------ C:\WINDOWS\system32\jview.exe <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
              2008-03-17 21:12:56 15120 --a------ C:\WINDOWS\system32\jdbgmgr.exe <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
              2008-03-17 21:12:56 404752 --a------ C:\WINDOWS\system32\javart.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
              2008-03-17 21:12:56 63248 --a------ C:\WINDOWS\system32\javaprxy.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
              2008-03-17 21:12:56 187152 --a------ C:\WINDOWS\system32\javacypt.dll <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
              2008-03-17 21:12:55 49424 --a------ C:\WINDOWS\system32\clspack.exe <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
              2008-03-15 09:55:17 0 d-------- C:\Documents and Settings\Rayner\Application Data\Talkback
              2008-03-15 09:55:07 0 --a------ C:\WINDOWS\nsreg.dat
              2008-03-15 09:53:10 0 d-------- C:\Program Files\DAMN NFO Viewer
              2008-03-15 09:48:46 0 d-------- C:\Documents and Settings\Rayner\Application Data\Apple Computer
              2008-03-15 09:48:43 0 d-------- C:\Program Files\iPod
              2008-03-15 09:48:41 0 d-------- C:\Program Files\iTunes
              2008-03-15 09:48:28 0 d-------- C:\Program Files\QuickTime
              2008-03-15 09:48:23 0 d-------- C:\Program Files\Apple Software Update
              2008-03-15 09:48:16 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
              2008-03-15 09:48:00 107134 --a------ C:\WINDOWS\UninstallFirefox.exe
              2008-03-15 09:47:53 3444 --a------ C:\WINDOWS\mozver.dat
              2008-03-15 09:47:53 0 d-------- C:\Documents and Settings\Rayner\Application Data\Mozilla
              2008-03-15 01:19:48 0 d-------- C:\Program Files\BitComet
              2008-03-15 01:06:37 8192 --a------ C:\WINDOWS\system32\resetwpa.reg
              2008-03-15 01:06:37 370 --a------ C:\WINDOWS\system32\reset5.dat
              2008-03-15 01:05:42 0 d--h----- C:\Documents and Settings\Administrator\Sjablonen
              2008-03-15 01:05:42 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
              2008-03-15 01:05:42 0 d--h----- C:\Documents and Settings\Administrator\Onlangs geopend
              2008-03-15 01:05:42 524288 --a------ C:\Documents and Settings\Administrator\NTUSER.DAT
              2008-03-15 01:05:42 0 d--h----- C:\Documents and Settings\Administrator\Netwerkprinteromgeving
              2008-03-15 01:05:42 0 d--h----- C:\Documents and Settings\Administrator\NetHood
              2008-03-15 01:05:42 0 d-------- C:\Documents and Settings\Administrator\Mijn documenten
              2008-03-15 01:05:42 0 dr------- C:\Documents and Settings\Administrator\Menu Start
              2008-03-15 01:05:42 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
              2008-03-15 01:05:42 0 d-------- C:\Documents and Settings\Administrator\Favorieten
              2008-03-15 01:05:42 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
              2008-03-15 01:05:42 0 d-------- C:\Documents and Settings\Administrator\Bureaublad
              2008-03-15 01:05:42 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
              2008-03-15 01:05:42 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
              2008-03-15 00:50:00 0 d--hs---- C:\Documents and Settings\Rayner\UserData
              2008-03-15 00:36:08 593920 -----n--- C:\WINDOWS\system32\ati2sgag.exe <Not Verified; ; ATI Smart>
              2008-03-15 00:35:59 0 d-------- C:\Program Files\ATI Technologies
              2008-03-15 00:35:30 0 d-------- C:\ATI
              2008-03-15 00:18:42 0 d-------- C:\WINDOWS\system32\Lang
              2008-03-15 00:17:31 49152 -ra------ C:\WINDOWS\system32\ChCfg.exe
              2008-03-15 00:17:14 0 d-------- C:\WINDOWS\system32\RTCOM
              2008-03-15 00:16:47 0 d-------- C:\Program Files\Realtek
              2008-03-15 00:16:45 520192 -ra------ C:\WINDOWS\RtlExUpd.dll <Not Verified; Realtek Semiconductor Corp.; RtlExUpd Dynamic Link Library>
              2008-03-15 00:16:45 315392 --a------ C:\WINDOWS\HideWin.exe <Not Verified; Realtek Semiconductor Corp.; HD Audio Hide windows program>
              2008-03-15 00:08:40 0 d-------- C:\Documents and Settings\Rayner\Application Data\Macromedia
              2008-03-15 00:08:40 0 d-------- C:\Documents and Settings\Rayner\Application Data\Adobe
              2008-03-15 00:00:36 0 d-------- C:\WINDOWS\system32\bits
              2008-03-15 00:00:15 0 d-------- C:\WINDOWS\system32\PreInstall
              2008-03-15 00:00:14 0 d--h----- C:\WINDOWS\$hf_mig$
              2008-03-14 23:54:50 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
              2008-03-14 23:53:40 0 d-------- C:\WINDOWS\SoftwareDistribution
              2008-03-14 23:52:52 0 d-------- C:\Program Files\Common Files\ODBC
              2008-03-14 23:52:50 0 d-------- C:\Program Files\Common Files\SpeechEngines
              2008-03-14 23:52:49 0 dr------- C:\Program Files
              2008-03-14 23:52:49 0 d-------- C:\Program Files\Common Files
              2008-03-14 23:52:26 0 d--h----- C:\Documents and Settings\Default User\Sjablonen
              2008-03-14 23:52:26 0 dr-h----- C:\Documents and Settings\Default User\SendTo
              2008-03-14 23:52:26 0 d--h----- C:\Documents and Settings\Default User\Onlangs geopend
              2008-03-14 23:52:26 0 d--h----- C:\Documents and Settings\Default User\Netwerkprinteromgeving
              2008-03-14 23:52:26 0 d--h----- C:\Documents and Settings\Default User\NetHood
              2008-03-14 23:52:26 0 d-------- C:\Documents and Settings\Default User\Mijn documenten
              2008-03-14 23:52:26 0 dr------- C:\Documents and Settings\Default User\Menu Start
              2008-03-14 23:52:26 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
              2008-03-14 23:52:26 0 d-------- C:\Documents and Settings\Default User\Favorieten
              2008-03-14 23:52:26 0 d---s---- C:\Documents and Settings\Default User\Cookies
              2008-03-14 23:52:26 0 d-------- C:\Documents and Settings\Default User\Bureaublad
              2008-03-14 23:52:26 0 d--h----- C:\Documents and Settings\All Users\Sjablonen
              2008-03-14 23:52:26 0 dr------- C:\Documents and Settings\All Users\Menu Start
              2008-03-14 23:52:26 0 d-------- C:\Documents and Settings\All Users\Favorieten
              2008-03-14 23:52:26 0 dr------- C:\Documents and Settings\All Users\Documenten
              2008-03-14 23:52:26 0 d-------- C:\Documents and Settings\All Users\Bureaublad
              2008-03-14 23:52:17 0 d-------- C:\WINDOWS\system32\CatRoot2
              2008-03-14 23:52:17 0 d-------- C:\WINDOWS\system32\CatRoot
              2008-03-14 23:52:12 0 dr-h----- C:\Documents and Settings\Default User\Application Data
              2008-03-14 23:52:12 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
              2008-03-14 23:52:11 0 dr-h----- C:\Documents and Settings\All Users\Application Data
              2008-03-14 23:52:11 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
              2008-03-14 23:51:57 0 d-------- C:\Documents and Settings
              2008-03-14 23:50:03 0 d-------- C:\Documents and Settings\Rayner\Application Data\vlc
              2008-03-14 23:48:42 0 d-------- C:\Program Files\VideoLAN
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\WinSxS
              2008-03-14 23:48:19 0 dr------- C:\WINDOWS\Web
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\twain_32
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\wins
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\wbem
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\usmt
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\spool
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\ShellExt
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\Setup
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\ras
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\oobe
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\npp
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\mui
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\inetsrv
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\IME
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\icsxml
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\ias
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\export
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\drivers
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\drivers\etc
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\drivers\disdn
              2008-03-14 23:48:19 0 dr-hs--c- C:\WINDOWS\system32\dllcache
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\dhcp
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\config
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\3com_dmi
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\3076
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\2052
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\1054
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\1043
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\1042
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\1041
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\1037
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\1033
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\1031
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\1028
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\1025
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\security
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\Resources
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\repair
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\mui
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\msapps
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\msagent
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\Media
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\java
              2008-03-14 23:48:19 0 d--h----- C:\WINDOWS\inf
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\ime
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\Help
              2008-03-14 23:48:19 0 dr--s---- C:\WINDOWS\Fonts
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\Driver Cache
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\Debug
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\Cursors
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\Connection Wizard
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\Config
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\AppPatch
              2008-03-14 23:48:19 0 d-------- C:\WINDOWS\addins
              2008-03-14 23:41:52 0 d---s---- C:\WINDOWS\system32\Microsoft
              2008-03-14 23:30:27 0 d-------- C:\WINDOWS\OPTIONS
              2008-03-14 23:30:27 0 d--h----- C:\Program Files\InstallShield Installation Information
              2008-03-14 23:30:27 0 d-------- C:\Program Files\Belkin
              2008-03-14 23:30:12 0 d-------- C:\f5d5005v2000-en
              2008-03-14 23:27:53 0 d-------- C:\WINDOWS\system32\ReinstallBackups
              2008-03-14 23:27:19 1428 --a------ C:\WINDOWS\system32\drivers\nvphy.bin
              2008-03-14 23:27:02 0 d-------- C:\Program Files\Common Files\InstallShield
              2008-03-14 23:26:53 0 d-------- C:\MCP55_nvidia_system_MB
              2008-03-14 23:24:44 0 d-------- C:\Documents and Settings\Rayner\Application Data\U3
              2008-03-14 23:21:15 0 d--hs---- C:\WINDOWS\Installer
              2008-03-14 23:21:12 0 d-------- C:\Documents and Settings\Rayner\Application Data\Identities
              2008-03-14 23:21:06 0 d--h----- C:\Documents and Settings\Rayner\Sjablonen
              2008-03-14 23:21:06 0 dr-h----- C:\Documents and Settings\Rayner\SendTo
              2008-03-14 23:21:06 0 dr-h----- C:\Documents and Settings\Rayner\Onlangs geopend
              2008-03-14 23:21:06 3407872 --ah----- C:\Documents and Settings\Rayner\NTUSER.DAT
              2008-03-14 23:21:06 0 d--h----- C:\Documents and Settings\Rayner\Netwerkprinteromgeving
              2008-03-14 23:21:06 0 d--h----- C:\Documents and Settings\Rayner\NetHood
              2008-03-14 23:21:06 0 dr------- C:\Documents and Settings\Rayner\Mijn documenten
              2008-03-14 23:21:06 0 dr------- C:\Documents and Settings\Rayner\Menu Start
              2008-03-14 23:21:06 0 d--h----- C:\Documents and Settings\Rayner\Local Settings
              2008-03-14 23:21:06 0 dr------- C:\Documents and Settings\Rayner\Favorieten
              2008-03-14 23:21:06 0 d--hs---- C:\Documents and Settings\Rayner\Cookies
              2008-03-14 23:21:06 0 d-------- C:\Documents and Settings\Rayner\Bureaublad
              2008-03-14 23:21:06 0 dr-h----- C:\Documents and Settings\Rayner\Application Data
              2008-03-14 23:20:25 0 d--hs---- C:\System Volume Information
              2008-03-14 23:20:24 262144 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
              2008-03-14 23:20:24 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
              2008-03-14 23:20:24 0 d--hs---- C:\Documents and Settings\NetworkService\Cookies
              2008-03-14 23:20:24 0 d-------- C:\Documents and Settings\NetworkService\Application Data
              2008-03-14 23:20:24 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
              2008-03-14 23:20:24 262144 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
              2008-03-14 23:20:24 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
              2008-03-14 23:20:24 0 d--hs---- C:\Documents and Settings\LocalService\Cookies
              2008-03-14 23:20:24 0 d-------- C:\Documents and Settings\LocalService\Application Data
              2008-03-14 23:20:24 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
              2008-03-14 23:18:04 0 d-------- C:\WINDOWS\system32\xircom
              2008-03-14 23:18:04 0 d-------- C:\Program Files\microsoft frontpage
              2008-03-14 23:17:56 229376 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
              2008-03-14 23:17:52 0 -rahs---- C:\MSDOS.SYS
              2008-03-14 23:17:52 0 -rahs---- C:\IO.SYS
              2008-03-14 23:17:52 0 --a------ C:\CONFIG.SYS
              2008-03-14 23:17:52 0 --a------ C:\AUTOEXEC.BAT
              2008-03-14 23:17:10 0 d--hs---- C:\Documents and Settings\All Users\DRM
              2008-03-14 23:17:02 0 dr------- C:\WINDOWS\Offline Web Pages
              2008-03-14 23:17:02 0 d---s---- C:\WINDOWS\Downloaded Program Files
              2008-03-14 23:16:38 0 d-------- C:\WINDOWS\system32\DirectX
              2008-03-14 23:15:58 0 d---s---- C:\WINDOWS\Tasks
              2008-03-14 23:15:55 0 d-------- C:\Program Files\Common Files\MSSoap
              2008-03-14 23:15:51 0 d-------- C:\WINDOWS\srchasst
              2008-03-14 23:15:50 0 d-------- C:\WINDOWS\system32\Macromed
              2008-03-14 23:15:49 0 d-------- C:\Program Files\Movie Maker
              2008-03-14 23:15:46 0 d-------- C:\WINDOWS\system32\Restore
              2008-03-14 23:15:46 0 d-------- C:\WINDOWS\PCHealth
              2008-03-14 23:15:17 21748 --a------ C:\WINDOWS\system32\emptyregdb.dat
              2008-03-14 23:15:04 0 d-------- C:\WINDOWS\Registration
              2008-03-14 23:14:59 0 d--h----- C:\Program Files\WindowsUpdate
              2008-03-14 23:14:59 0 d-------- C:\Program Files\Online Services
              2008-03-14 23:14:54 0 d-------- C:\Program Files\Messenger
              2008-03-14 23:14:49 0 d-------- C:\Program Files\MSN Gaming Zone
              2008-03-14 23:14:12 0 d-------- C:\Program Files\Windows NT
              2008-03-14 23:14:10 0 d-------- C:\WINDOWS\system32\MsDtc
              2008-03-14 23:14:09 0 d-------- C:\WINDOWS\system32\Com


              -- Find3M Report ---------------------------------------------------------------

              2008-03-20 21:59:29 509454 --a------ C:\WINDOWS\system32\perfh013.dat
              2008-03-20 21:59:29 91006 --a------ C:\WINDOWS\system32\perfc013.dat
              2008-03-15 01:19:53 2560 --a------ C:\WINDOWS\system32\BitCometRes.dll <Not Verified; BitComet; BitComet BCTP Helper>
              2008-03-14 23:52:26 62 --ahs---- C:\Documents and Settings\Rayner\Application Data\desktop.ini


              -- Registry Dump ---------------------------------------------------------------

              *Note* empty entries & legit default entries are not shown


              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000250-0320-4dd4-be4f-7566d2314352}]

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{13197ace-6851-45c3-a7ff-c281324d5489}]

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{15651c7c-e812-44a2-a9ac-b467a2233e7d}]

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4e1075f4-eec4-4a86-add7-cd5f52858c31}]

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4e7bd74f-2b8d-469e-92c6-ce7eb590a94d}]

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5929cd6e-2062-44a4-b2c5-2c7e78fbab38}]

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5dafd089-24b1-4c5e-bd42-8ca72550717b}]

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5fa6752a-c4a0-4222-88c2-928ae5ab4966}]

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{622cc208-b014-4fe0-801b-874a5e5e403a}]

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{63F7460B-C831-4142-A4AA-5EC303EC4343}]
              07-03-2008 21:15 413696 --a------ C:\Program Files\Bat\Bat.dll

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8674aea0-9d3d-11d9-99dc-00600f9a01f1}]

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{87CADEB4-0FD4-4288-9EC3-AD7C14EDFC54}]
              19-03-2008 18:38 37376 --a------ C:\WINDOWS\system32\ljjhfda.dll

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{965a592f-8efa-4250-8630-7960230792f1}]

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9c5b2f29-1f46-4639-a6b4-828942301d3e}]

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A8235A32-CC9C-4D69-9384-759EE8D0FEB2}]
              19-03-2008 22:11 305728 --a------ C:\WINDOWS\system32\gebyy.dll

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cf021f40-3e14-23a5-cba2-717765728274}]

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e18bcffb-e968-4bb1-8bda-5fbdd669265b}]
              20-03-2008 21:36 91712 --a------ C:\WINDOWS\system32\ntuepksi.dll

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{fc3a74e5-f281-4f10-ae1e-733078684f3c}]

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ffff0001-0002-101a-a3c9-08002b2f49fb}]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "RTHDCPL"="RTHDCPL.EXE" [29-01-2008 15:47 C:\WINDOWS\RTHDCPL.exe]
              "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [25-10-2006 18:58]
              "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [30-10-2006 09:36]
              "PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [05-06-2006 15:06]
              "StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [21-01-2008 12:17]
              "mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [03-08-2007 22:33]
              "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [11-06-2007 10:25]
              "e87c986c"="C:\WINDOWS\system32\jpdbthqn.dll" [20-03-2008 21:39]
              "BMeb4fabf0"="C:\WINDOWS\system32\jxwnaqws.dll" [20-03-2008 21:36]

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04-08-2004 09:03]
              "MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" [13-10-2004 17:24]

              C:\Documents and Settings\Rayner\Menu Start\Programma's\Opstarten\
              Bat - Auto Update.lnk - C:\Program Files\Bat\Bat.exe [19-3-2008 18:38:34]

              C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\
              Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [26-3-2006 22:44:08]

              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
              "DisableTaskMgr"=1 (0x1)
              "DisableRegistryTools"=0 (0x0)

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
              "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [21-11-2006 14:50 233472]
              "{87CADEB4-0FD4-4288-9EC3-AD7C14EDFC54}"= C:\WINDOWS\system32\ljjhfda.dll [19-03-2008 18:38 37376]

              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
              "Userinit"="C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\mgmrwmrv.exe,"

              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjhfda]
              ljjhfda.dll 19-03-2008 18:38 37376 C:\WINDOWS\system32\ljjhfda.dll

              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\reset5]
              reset5.dll 09-09-2002 21:30 17408 C:\WINDOWS\system32\reset5.dll

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
              "Authentication Packages"= msv1_0 C:\WINDOWS\system32\gebyy.dll

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
              @="Service"

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
              @=""

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
              @=""

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
              @="Service"

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
              @="Volume shadow copy"




              -- End of Deckard's System Scanner: finished at 2008-03-20 23:19:52 ------------

              Comment


              • #8
                Download Malwarebytes' Anti-Malware op je bureaublad.
                Dubbelklik mbam-setup.exe en kies voor "Next" om de tool te installeren.
                Als de installatie voltooid is zet je vinkjes bij "Update MalwareBytes' Anti-Malware" en bij "Launch MalwareBytes' Anti-Malware".
                Druk daarna op "Finish".
                Kies in het hoofdscherm voor de tab "Scanner" en selecteer het keuzerondje "Perform full scan".
                Druk op de knop "Scan" en zorg dat al je harde schijven/partities aangevinkt staan.
                Druk dan op de knop "Start Scan".
                Wanneer de scan voltooid is klik je op OK, daarna op "Show Results" om de resultaten te zien.
                Zorg ervoor dat alles aangevinkt is, klik daarna op "Remove Selected".
                Als het programma je computer wil laten herstarten, sta je dit toe.
                Daarna opent een logje(mbam-log-XX-XX-XXXX(xx-xx-xx).txt)
                Post deze log in je volgende bericht tesamen met een nieuw logje van Deckard's System Scanner

                Comment


                • #9
                  Hierbij de 2 logjes van malware bytes en DSS

                  Malwarebytes' Anti-Malware 1.09
                  Database versie: 515

                  Scan type: Volledige Scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|K:\|L:\|N:\|Q:\|)
                  Objecten gescand: 155773
                  Verstreken tijd: 1 hour(s), 58 minute(s), 58 second(s)

                  Geheugenprocessen geïnfecteerd: 1
                  Geheugenmodulen geïnfecteerd: 3
                  Registersleutels geïnfecteerd: 49
                  Registerwaarden geïnfecteerd: 1
                  Registerdata bestanden geïnfecteerd: 2
                  Mappen geïnfecteerd: 10
                  Bestanden geïnfecteerd: 80

                  Geheugenprocessen geïnfecteerd:
                  c:\program files\Bat\X_Bat.exe (Adware.Batco) -> Unloaded process successfully.

                  Geheugenmodulen geïnfecteerd:
                  C:\WINDOWS\system32\gebyy.dll (Trojan.Vundo) -> Unloaded module successfully.
                  C:\WINDOWS\system32\jpdbthqn.dll (Trojan.Vundo) -> Unloaded module successfully.
                  C:\WINDOWS\system32\ljjhfda.dll (Trojan.Vundo) -> Unloaded module successfully.

                  Registersleutels geïnfecteerd:
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a8235a32-cc9c-4d69-9384-759ee8d0feb2} (Trojan.Vundo) -> Delete on reboot.
                  HKEY_CLASSES_ROOT\CLSID\{a8235a32-cc9c-4d69-9384-759ee8d0feb2} (Trojan.Vundo) -> Delete on reboot.
                  HKEY_CLASSES_ROOT\Interface\{71493218-e553-4fa8-85e2-e6d18fa75509} (Rogue.SpyMaxx) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Typelib\{f4f41439-82fc-4681-acb0-7d3798f685c0} (Rogue.SpyMaxx) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{1e33f406-ab8f-4153-a5c8-089aeff5cc87} (Rogue.SpyMaxx) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{15651c7c-e812-44a2-a9ac-b467a2233e7d} (Adware.123Mania) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{622cc208-b014-4fe0-801b-874a5e5e403a} (Adware.123Mania) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\AppID\{f663b917-591f-4172-8d87-3d7d729007ca} (Adware.Batco) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\bat.batbho (Adware.Batco) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{63f7460b-c831-4142-a4aa-5ec303ec4343} (Adware.Batco) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{63f7460b-c831-4142-a4aa-5ec303ec4343} (Adware.Batco) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\bat.batbho.1 (Adware.Batco) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{d279bc2b-a85b-4559-8fd9-ddc55f5d402d} (Adware.Batco) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Typelib\{b80a3586-caa5-41c8-89bf-e617f0b6cfbf} (Adware.Batco) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9c5b2f29-1f46-4639-a6b4-828942301d3e} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ffff0001-0002-101a-a3c9-08002b2f49fb} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00000250-0320-4dd4-be4f-7566d2314352} (Fake.Dropped.Malware.Renos) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{13197ace-6851-45c3-a7ff-c281324d5489} (Fake.Dropped.Malware.Renos) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4e1075f4-eec4-4a86-add7-cd5f52858c31} (Fake.Dropped.Malware.Renos) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4e7bd74f-2b8d-469e-92c6-ce7eb590a94d} (Fake.Dropped.Malware.Renos) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5929cd6e-2062-44a4-b2c5-2c7e78fbab38} (Fake.Dropped.Malware.Renos) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5dafd089-24b1-4c5e-bd42-8ca72550717b} (Fake.Dropped.Malware.Renos) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5fa6752a-c4a0-4222-88c2-928ae5ab4966} (Fake.Dropped.Malware.Renos) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8674aea0-9d3d-11d9-99dc-00600f9a01f1} (Fake.Dropped.Malware.Renos) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{965a592f-8efa-4250-8630-7960230792f1} (Fake.Dropped.Malware.Renos) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cf021f40-3e14-23a5-cba2-717765728274} (Fake.Dropped.Malware.Renos) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fc3a74e5-f281-4f10-ae1e-733078684f3c} (Fake.Dropped.Malware.Renos) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\Software\IMAdvertiser (Adware.SearchTwo) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\Software\BATCO (Adware.Batco) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Batco (Adware.Batco) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\bat.DLL (Adware.Batco) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Bat (Adware.Batco) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Bat (Adware.Batco) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\jkwslist (Malware.Trace) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\Software\Microsoft\aldd (Malware.Trace) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\Software\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{87cadeb4-0fd4-4288-9ec3-ad7c14edfc54} (Trojan.Vundo) -> Delete on reboot.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{87cadeb4-0fd4-4288-9ec3-ad7c14edfc54} (Trojan.Vundo) -> Delete on reboot.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ljjhfda (Trojan.Vundo) -> Delete on reboot.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

                  Registerwaarden geïnfecteerd:
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{87cadeb4-0fd4-4288-9ec3-ad7c14edfc54} (Trojan.Vundo) -> Delete on reboot.

                  Registerdata bestanden geïnfecteerd:
                  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\gebyy.dll -> Delete on reboot.
                  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\gebyy.dll -> Delete on reboot.

                  Mappen geïnfecteerd:
                  C:\Program Files\180searchassistant (Adware.180Solutions) -> Quarantined and deleted successfully.
                  C:\Program Files\180solutions (Adware.180Solutions) -> Quarantined and deleted successfully.
                  C:\Program Files\zango (Adware.180Solutions) -> Quarantined and deleted successfully.
                  C:\Program Files\180search assistant (Adware.180Solutions) -> Quarantined and deleted successfully.
                  C:\Program Files\Bat (Adware.Batco) -> Quarantined and deleted successfully.
                  C:\Program Files\stc (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\Program Files\Sysmnt (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\FLEOK (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\Documents and Settings\All Users\Application Data\Rabio\Search Enhancer (Adware.SearchEnhancer) -> Quarantined and deleted successfully.
                  C:\Documents and Settings\All Users\Application Data\Rabio (Adware.Rabio) -> Quarantined and deleted successfully.

                  Bestanden geïnfecteerd:
                  c:\program files\Bat\X_Bat.exe (Adware.Batco) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\gebyy.dll (Trojan.Vundo) -> Delete on reboot.
                  C:\WINDOWS\system32\yybeg.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\yybeg.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\jpdbthqn.dll (Trojan.Vundo) -> Delete on reboot.
                  C:\WINDOWS\system32\nqhtbdpj.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\Program Files\Bat\Bat.dll (Adware.Batco) -> Quarantined and deleted successfully.
                  C:\Documents and Settings\Rayner\Local Settings\Temporary Internet Files\Content.IE5\UG1DB73B\BatSetup[1].exe (Adware.Batco) -> Quarantined and deleted successfully.
                  C:\Documents and Settings\Rayner\Local Settings\Temporary Internet Files\Content.IE5\UG1DB73B\syswcc32[1].exe (Adware.Webhancer) -> Quarantined and deleted successfully.
                  C:\Program Files\Bat\Bat.exe (Adware.Batco) -> Quarantined and deleted successfully.
                  C:\Program Files\Bat\un_BatSetup_15041.exe (Adware.Rabio) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{4F6E2E2C-50C3-497E-B053-8AC36B7FA5A5}\RP138\A0010673.exe (Adware.Batco) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{4F6E2E2C-50C3-497E-B053-8AC36B7FA5A5}\RP139\A0011641.exe (Adware.Batco) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{4F6E2E2C-50C3-497E-B053-8AC36B7FA5A5}\RP142\A0012417.exe (Adware.Batco) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{4F6E2E2C-50C3-497E-B053-8AC36B7FA5A5}\RP143\A0013544.exe (Adware.Batco) -> Quarantined and deleted successfully.
                  Q:\System Volume Information\_restore{4F6E2E2C-50C3-497E-B053-8AC36B7FA5A5}\RP141\A0011673.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
                  C:\Program Files\180searchassistant\saap.exe (Adware.180Solutions) -> Quarantined and deleted successfully.
                  C:\Program Files\180searchassistant\sac.exe (Adware.180Solutions) -> Quarantined and deleted successfully.
                  C:\Program Files\180solutions\sais.exe (Adware.180Solutions) -> Quarantined and deleted successfully.
                  C:\Program Files\zango\zango.exe (Adware.180Solutions) -> Quarantined and deleted successfully.
                  C:\Program Files\180search assistant\180sa.exe (Adware.180Solutions) -> Quarantined and deleted successfully.
                  C:\Program Files\180search assistant\sau.exe (Adware.180Solutions) -> Quarantined and deleted successfully.
                  C:\Program Files\Bat\Bat.dll.intermediate.manifest (Adware.Batco) -> Quarantined and deleted successfully.
                  C:\Program Files\Bat\Bat.original (Adware.Batco) -> Quarantined and deleted successfully.
                  C:\Program Files\Bat\Info.dll (Adware.Batco) -> Quarantined and deleted successfully.
                  C:\Program Files\Bat\un_BatSetup_15041.txt (Adware.Batco) -> Quarantined and deleted successfully.
                  C:\Program Files\Bat\X_Bat.log (Adware.Batco) -> Quarantined and deleted successfully.
                  C:\Program Files\stc\csv5p070.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\Program Files\Sysmnt\Ssmgr.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\FLEOK\180ax.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\avifile32.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\avisynthex32.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\aviwrap32.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\bjam.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\bokja.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\browserad.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\cdsm32.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\changeurl_30.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\didduid.ini (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\msa64chk.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\msapasrc.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\mspphe.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\123messenger.per (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\mssvr.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\ntnut.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\saiemod.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\salm.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\shdocpe.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\shdocpl.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\stcloader.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\swin32.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\updatetc.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\voiceip.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\winsb.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\MSIXU.DLL (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\MSNSA32.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\ntnut32.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\shdocpe.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\SIPSPI32.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\WER8274.DLL (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\Installer\id53.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\180ax.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\2020search.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\2020search2.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\apphelp32.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\asferror32.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\asycfilt32.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\athprxy32.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\ati2dvaa32.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\ati2dvag32.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\audiosrv32.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\autodisc32.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                  C:\WINDOWS\licencia.txt (Malware.Trace) -> Quarantined and deleted successfully.
                  C:\WINDOWS\telefonos.txt (Malware.Trace) -> Quarantined and deleted successfully.
                  C:\WINDOWS\textos.txt (Malware.Trace) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\winfrun32.bin (Malware.Trace) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\ljjhfda.dll (Trojan.Vundo) -> Delete on reboot.
                  C:\Documents and Settings\Rayner\Bureaublad\spyaway_setup.exe (Rogue.SpyAway) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\dllcache\services.xml (Heuristic.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\drivers\services.xml (Heuristic.Reserved.Word.Exploit) -> Quarantined and deleted successfully.

                  Comment


                  • #10

                    DSS


                    Deckard's System Scanner v20071014.68
                    Run by Rayner on 2008-03-21 07:51:10
                    Computer is in Normal Mode.
                    --------------------------------------------------------------------------------



                    -- HijackThis (run as Rayner.exe) ----------------------------------------------

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 7:51:17, on 21-3-2008
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16608)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    F:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
                    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
                    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                    C:\Program Files\McAfee\MPF\MPFSrv.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\WINDOWS\system32\WgaTray.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
                    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
                    C:\Program Files\Windows Desktop Search\wds_sl.exe
                    C:\WINDOWS\RTHDCPL.EXE
                    C:\Program Files\QuickTime\qttask.exe
                    C:\Program Files\iTunes\iTunesHelper.exe
                    C:\Program Files\PowerISO\PWRISOVM.EXE
                    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
                    C:\Program Files\iPod\bin\iPodService.exe
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                    C:\WINDOWS\system32\Rundll32.exe
                    C:\Program Files\Messenger\MSMSGS.EXE
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                    C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
                    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\Documents and Settings\Rayner\Bureaublad\dss.exe
                    C:\DOCUME~1\Rayner\BUREAU~1\Rayner.exe

                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = wwwproxy.xs4all.nl:8080
                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = https://
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
                    O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
                    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
                    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
                    O2 - BHO: {b562966d-dbf5-adb8-1bb4-869ebffcb81e} - {e18bcffb-e968-4bb1-8bda-5fbdd669265b} - C:\WINDOWS\system32\ntuepksi.dll
                    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
                    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
                    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
                    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                    O4 - HKLM\..\Run: [e87c986c] rundll32.exe "C:\WINDOWS\system32\jpdbthqn.dll",b
                    O4 - HKLM\..\Run: [BMeb4fabf0] Rundll32.exe "C:\WINDOWS\system32\jxwnaqws.dll",s
                    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Lokale service')
                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Netwerkservice')
                    O4 - Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe
                    O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
                    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
                    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
                    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                    O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
                    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O20 - Winlogon Notify: reset5 - C:\WINDOWS\SYSTEM32\reset5.dll
                    O23 - Service: McAfee Application Installer Cleanup (0153311205974296) (0153311205974296mcinstcleanup) - Unknown owner - C:\DOCUME~1\Rayner\LOCALS~1\Temp\015331~1.EXE (file missing)
                    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - F:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
                    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
                    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
                    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
                    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
                    O23 - Service: Reset 5 - Unknown owner - C:\WINDOWS\system32\srvany.exe (file missing)

                    --
                    End of file - 7169 bytes

                    -- Files created between 2008-02-21 and 2008-03-21 -----------------------------

                    2008-03-21 00:54:16 0 d-------- C:\Documents and Settings\Rayner\Application Data\Malwarebytes
                    2008-03-21 00:54:08 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                    2008-03-21 00:54:07 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
                    2008-03-21 00:53:28 0 d-------- C:\Program Files\Common Files\Download Manager
                    2008-03-20 22:55:20 0 d-------- C:\RVAXO
                    2008-03-20 22:53:29 747874 --a------ C:\WINDOWS\system32\RVAXO.bat
                    2008-03-20 22:53:29 69632 --a------ C:\WINDOWS\system32\remove.exe
                    2008-03-20 22:46:45 0 d--h----- C:\WINDOWS\PIF
                    2008-03-20 21:55:07 0 d-------- C:\Program Files\MSXML 6.0
                    2008-03-20 21:39:15 87104 -----n--- C:\WINDOWS\system32\jpdbthqn.dll
                    2008-03-20 21:36:31 91712 --a------ C:\WINDOWS\system32\ntuepksi.dll
                    2008-03-20 21:36:23 89664 --a------ C:\WINDOWS\system32\jxwnaqws.dll
                    2008-03-20 21:23:45 0 d-------- C:\Documents and Settings\Rayner\Application Data\Grisoft
                    2008-03-20 21:21:02 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
                    2008-03-20 01:50:33 0 d-------- C:\Program Files\McAfee.com
                    2008-03-20 01:50:06 0 d-------- C:\Program Files\Common Files\McAfee
                    2008-03-20 01:49:27 0 d-------- C:\Program Files\McAfee
                    2008-03-20 01:46:57 0 d-------- C:\Documents and Settings\All Users\Application Data\McAfee
                    2008-03-20 01:31:15 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
                    2008-03-20 01:31:00 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
                    2008-03-19 22:11:05 305728 -----n--- C:\WINDOWS\system32\gebyy.dll
                    2008-03-19 22:03:35 0 d-------- C:\Documents and Settings\All Users\Application Data\Avg8
                    2008-03-19 22:03:15 0 d-------- C:\WINDOWS\StartHtmico
                    2008-03-19 22:02:31 90112 -ra------ C:\WINDOWS\system32\CNMCP78.exe <Not Verified; CANON INC.; Canon BJ Raster Printer Driver Installer>
                    2008-03-19 22:02:10 0 d--h----- C:\Documents and Settings\All Users\Application Data\CanonBJ
                    2008-03-19 22:00:10 0 d-------- C:\Program Files\Canon
                    2008-03-19 18:39:57 0 d-------- C:\Program Files\AVG
                    2008-03-19 18:38:54 37376 -----n--- C:\WINDOWS\system32\ljjhfda.dll
                    2008-03-19 18:38:54 97 --a------ C:\Extractor.bat
                    2008-03-19 18:37:37 0 d-------- C:\Program Files\QuickPar
                    2008-03-19 18:36:49 0 d-------- C:\Documents and Settings\Rayner\Application Data\Windows Desktop Search
                    2008-03-19 18:36:10 0 d-------- C:\Program Files\Windows Desktop Search
                    2008-03-19 18:30:52 0 d-------- C:\WINDOWS\system32\appmgmt
                    2008-03-19 18:29:28 0 d-------- C:\Documents and Settings\Rayner\Application Data\ATI
                    2008-03-19 18:29:28 0 d-------- C:\Documents and Settings\All Users\Application Data\ATI
                    2008-03-19 18:20:14 0 d-------- C:\WINDOWS\SHELLNEW
                    2008-03-19 18:20:13 0 d-------- C:\Program Files\Microsoft.NET
                    2008-03-19 18:11:50 0 d-------- C:\Program Files\MSBuild
                    2008-03-19 18:09:25 0 d-------- C:\WINDOWS\system32\XPSViewer
                    2008-03-19 18:09:09 0 d-------- C:\Program Files\Reference Assemblies
                    2008-03-19 18:08:11 0 d-------- C:\Program Files\Windows Media Connect 2
                    2008-03-19 18:07:39 0 d-------- C:\WINDOWS\system32\LogFiles
                    2008-03-19 18:07:39 0 d-------- C:\WINDOWS\system32\drivers\UMDF
                    2008-03-19 18:04:56 0 d-------- C:\WINDOWS\RegisteredPackages
                    2008-03-19 18:04:04 0 d-------- C:\WINDOWS\system32\URTTemp
                    2008-03-19 17:54:18 0 --a------ C:\WINDOWS\ativpsrm.bin
                    2008-03-19 17:49:37 110592 --a------ C:\WINDOWS\system32\drivers\zlib1d.dll <Not Verified; ; zlib>
                    2008-03-19 17:45:59 0 d-------- C:\Program Files\NewsLeecher
                    2008-03-19 17:44:58 0 d-------- C:\WINDOWS\system32\nl-nl
                    2008-03-19 17:43:48 0 d-------- C:\WINDOWS\network diagnostic
                    2008-03-19 17:39:23 0 d-------- C:\WINDOWS\pss
                    2008-03-19 00:36:35 0 d-------- C:\Documents and Settings\LocalService\Menu Start
                    2008-03-19 00:35:56 0 d-------- C:\WINDOWS\Prefetch
                    2008-03-18 23:36:19 0 d-------- C:\WINDOWS\provisioning
                    2008-03-18 23:36:19 0 d-------- C:\WINDOWS\peernet
                    2008-03-18 23:35:24 0 d-------- C:\WINDOWS\ServicePackFiles
                    2008-03-18 23:32:37 0 d-------- C:\WINDOWS\EHome
                    2008-03-18 23:27:47 0 d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
                    2008-03-18 23:27:44 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
                    2008-03-18 23:17:27 0 d-------- C:\Program Files\PowerISO
                    2008-03-18 23:14:43 0 d-------- C:\Documents and Settings\Rayner\Application Data\WinRAR
                    2008-03-18 23:13:57 0 d--hs---- C:\Documents and Settings\Rayner\Application Data\.#
                    2008-03-18 23:13:57 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
                    2008-03-18 23:13:54 1706870 -r-h----- C:\WINDOWS\wwwwizdll.exe <Not Verified; T; DNS>
                    2008-03-18 16:24:04 1751 --a------ C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
                    2008-03-17 21:16:25 26112 --a------ C:\WINDOWS\system32\xpsp1hfm.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
                    2008-03-17 21:12:59 171280 --a------ C:\WINDOWS\system32\jit.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
                    2008-03-17 21:12:59 139536 --a------ C:\WINDOWS\system32\javaee.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
                    2008-03-17 21:12:59 313856 --a------ C:\WINDOWS\system32\dx3j.dll <Not Verified; Microsoft Corporation; Microsoft® DirectX for Java>
                    2008-03-17 21:12:59 46352 --a------ C:\WINDOWS\setdebug.exe <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
                    2008-03-17 21:12:59 6550 --a------ C:\WINDOWS\jautoexp.dat
                    2008-03-17 21:12:57 113 --a------ C:\WINDOWS\system32\zonedon.reg
                    2008-03-17 21:12:57 113 --a------ C:\WINDOWS\system32\zonedoff.reg
                    2008-03-17 21:12:57 171792 --a------ C:\WINDOWS\system32\wjview.exe <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
                    2008-03-17 21:12:57 286992 --a------ C:\WINDOWS\system32\vmhelper.dll <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
                    2008-03-17 21:12:57 21264 --a------ C:\WINDOWS\system32\msjdbc10.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
                    2008-03-17 21:12:56 947472 --a------ C:\WINDOWS\system32\msjava.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
                    2008-03-17 21:12:56 154384 --a------ C:\WINDOWS\system32\msawt.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
                    2008-03-17 21:12:56 172304 --a------ C:\WINDOWS\system32\jview.exe <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
                    2008-03-17 21:12:56 15120 --a------ C:\WINDOWS\system32\jdbgmgr.exe <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
                    2008-03-17 21:12:56 404752 --a------ C:\WINDOWS\system32\javart.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
                    2008-03-17 21:12:56 63248 --a------ C:\WINDOWS\system32\javaprxy.dll <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
                    2008-03-17 21:12:56 187152 --a------ C:\WINDOWS\system32\javacypt.dll <Not Verified; Microsoft Corporation; Besturingssysteem Microsoft® Windows®>
                    2008-03-17 21:12:55 49424 --a------ C:\WINDOWS\system32\clspack.exe <Not Verified; Microsoft Corporation; Microsoft(R) Windows (R) Operating System>
                    2008-03-15 09:55:17 0 d-------- C:\Documents and Settings\Rayner\Application Data\Talkback
                    2008-03-15 09:55:07 0 --a------ C:\WINDOWS\nsreg.dat
                    2008-03-15 09:53:10 0 d-------- C:\Program Files\DAMN NFO Viewer
                    2008-03-15 09:48:46 0 d-------- C:\Documents and Settings\Rayner\Application Data\Apple Computer
                    2008-03-15 09:48:43 0 d-------- C:\Program Files\iPod
                    2008-03-15 09:48:41 0 d-------- C:\Program Files\iTunes
                    2008-03-15 09:48:28 0 d-------- C:\Program Files\QuickTime
                    2008-03-15 09:48:23 0 d-------- C:\Program Files\Apple Software Update
                    2008-03-15 09:48:16 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
                    2008-03-15 09:48:00 107134 --a------ C:\WINDOWS\UninstallFirefox.exe
                    2008-03-15 09:47:53 3444 --a------ C:\WINDOWS\mozver.dat
                    2008-03-15 09:47:53 0 d-------- C:\Documents and Settings\Rayner\Application Data\Mozilla
                    2008-03-15 01:19:48 0 d-------- C:\Program Files\BitComet
                    2008-03-15 01:06:37 8192 --a------ C:\WINDOWS\system32\resetwpa.reg
                    2008-03-15 01:06:37 370 --a------ C:\WINDOWS\system32\reset5.dat
                    2008-03-15 01:05:42 0 d--h----- C:\Documents and Settings\Administrator\Sjablonen
                    2008-03-15 01:05:42 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
                    2008-03-15 01:05:42 0 d--h----- C:\Documents and Settings\Administrator\Onlangs geopend
                    2008-03-15 01:05:42 524288 --a------ C:\Documents and Settings\Administrator\NTUSER.DAT
                    2008-03-15 01:05:42 0 d--h----- C:\Documents and Settings\Administrator\Netwerkprinteromgeving
                    2008-03-15 01:05:42 0 d--h----- C:\Documents and Settings\Administrator\NetHood
                    2008-03-15 01:05:42 0 d-------- C:\Documents and Settings\Administrator\Mijn documenten
                    2008-03-15 01:05:42 0 dr------- C:\Documents and Settings\Administrator\Menu Start
                    2008-03-15 01:05:42 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
                    2008-03-15 01:05:42 0 d-------- C:\Documents and Settings\Administrator\Favorieten
                    2008-03-15 01:05:42 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
                    2008-03-15 01:05:42 0 d-------- C:\Documents and Settings\Administrator\Bureaublad
                    2008-03-15 01:05:42 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
                    2008-03-15 01:05:42 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
                    2008-03-15 00:50:00 0 d--hs---- C:\Documents and Settings\Rayner\UserData
                    2008-03-15 00:36:08 593920 -----n--- C:\WINDOWS\system32\ati2sgag.exe <Not Verified; ; ATI Smart>
                    2008-03-15 00:35:59 0 d-------- C:\Program Files\ATI Technologies
                    2008-03-15 00:35:30 0 d-------- C:\ATI
                    2008-03-15 00:18:42 0 d-------- C:\WINDOWS\system32\Lang
                    2008-03-15 00:17:31 49152 -ra------ C:\WINDOWS\system32\ChCfg.exe
                    2008-03-15 00:17:14 0 d-------- C:\WINDOWS\system32\RTCOM
                    2008-03-15 00:16:47 0 d-------- C:\Program Files\Realtek
                    2008-03-15 00:16:45 520192 -ra------ C:\WINDOWS\RtlExUpd.dll <Not Verified; Realtek Semiconductor Corp.; RtlExUpd Dynamic Link Library>
                    2008-03-15 00:16:45 315392 --a------ C:\WINDOWS\HideWin.exe <Not Verified; Realtek Semiconductor Corp.; HD Audio Hide windows program>
                    2008-03-15 00:08:40 0 d-------- C:\Documents and Settings\Rayner\Application Data\Macromedia
                    2008-03-15 00:08:40 0 d-------- C:\Documents and Settings\Rayner\Application Data\Adobe
                    2008-03-15 00:00:36 0 d-------- C:\WINDOWS\system32\bits
                    2008-03-15 00:00:15 0 d-------- C:\WINDOWS\system32\PreInstall
                    2008-03-15 00:00:14 0 d--h----- C:\WINDOWS\$hf_mig$
                    2008-03-14 23:54:50 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
                    2008-03-14 23:53:40 0 d-------- C:\WINDOWS\SoftwareDistribution
                    2008-03-14 23:52:52 0 d-------- C:\Program Files\Common Files\ODBC
                    2008-03-14 23:52:50 0 d-------- C:\Program Files\Common Files\SpeechEngines
                    2008-03-14 23:52:49 0 dr------- C:\Program Files
                    2008-03-14 23:52:49 0 d-------- C:\Program Files\Common Files
                    2008-03-14 23:52:26 0 d--h----- C:\Documents and Settings\Default User\Sjablonen
                    2008-03-14 23:52:26 0 dr-h----- C:\Documents and Settings\Default User\SendTo
                    2008-03-14 23:52:26 0 d--h----- C:\Documents and Settings\Default User\Onlangs geopend
                    2008-03-14 23:52:26 0 d--h----- C:\Documents and Settings\Default User\Netwerkprinteromgeving
                    2008-03-14 23:52:26 0 d--h----- C:\Documents and Settings\Default User\NetHood
                    2008-03-14 23:52:26 0 d-------- C:\Documents and Settings\Default User\Mijn documenten
                    2008-03-14 23:52:26 0 dr------- C:\Documents and Settings\Default User\Menu Start
                    2008-03-14 23:52:26 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
                    2008-03-14 23:52:26 0 d-------- C:\Documents and Settings\Default User\Favorieten
                    2008-03-14 23:52:26 0 d---s---- C:\Documents and Settings\Default User\Cookies
                    2008-03-14 23:52:26 0 d-------- C:\Documents and Settings\Default User\Bureaublad
                    2008-03-14 23:52:26 0 d--h----- C:\Documents and Settings\All Users\Sjablonen
                    2008-03-14 23:52:26 0 dr------- C:\Documents and Settings\All Users\Menu Start
                    2008-03-14 23:52:26 0 d-------- C:\Documents and Settings\All Users\Favorieten
                    2008-03-14 23:52:26 0 dr------- C:\Documents and Settings\All Users\Documenten
                    2008-03-14 23:52:26 0 d-------- C:\Documents and Settings\All Users\Bureaublad
                    2008-03-14 23:52:17 0 d-------- C:\WINDOWS\system32\CatRoot2
                    2008-03-14 23:52:17 0 d-------- C:\WINDOWS\system32\CatRoot
                    2008-03-14 23:52:12 0 dr-h----- C:\Documents and Settings\Default User\Application Data
                    2008-03-14 23:52:12 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
                    2008-03-14 23:52:11 0 dr-h----- C:\Documents and Settings\All Users\Application Data
                    2008-03-14 23:52:11 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
                    2008-03-14 23:51:57 0 d-------- C:\Documents and Settings
                    2008-03-14 23:50:03 0 d-------- C:\Documents and Settings\Rayner\Application Data\vlc
                    2008-03-14 23:48:42 0 d-------- C:\Program Files\VideoLAN
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\WinSxS
                    2008-03-14 23:48:19 0 dr------- C:\WINDOWS\Web
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\twain_32
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\wins
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\wbem
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\usmt
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\spool
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\ShellExt
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\Setup
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\ras
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\oobe
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\npp
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\mui
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\inetsrv
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\IME
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\icsxml
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\ias
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\export
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\drivers
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\drivers\etc
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\drivers\disdn
                    2008-03-14 23:48:19 0 dr-hs--c- C:\WINDOWS\system32\dllcache
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\dhcp
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\config
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\3com_dmi
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\3076
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\2052
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\1054
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\1043
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\1042
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\1041
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\1037
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\1033
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\1031
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\1028
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system32\1025
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\system
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\security
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\Resources
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\repair
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\mui
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\msapps
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\msagent
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\Media
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\java
                    2008-03-14 23:48:19 0 d--h----- C:\WINDOWS\inf
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\ime
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\Help
                    2008-03-14 23:48:19 0 dr--s---- C:\WINDOWS\Fonts
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\Driver Cache
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\Debug
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\Cursors
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\Connection Wizard
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\Config
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\AppPatch
                    2008-03-14 23:48:19 0 d-------- C:\WINDOWS\addins
                    2008-03-14 23:41:52 0 d---s---- C:\WINDOWS\system32\Microsoft
                    2008-03-14 23:30:27 0 d-------- C:\WINDOWS\OPTIONS
                    2008-03-14 23:30:27 0 d--h----- C:\Program Files\InstallShield Installation Information
                    2008-03-14 23:30:27 0 d-------- C:\Program Files\Belkin
                    2008-03-14 23:30:12 0 d-------- C:\f5d5005v2000-en
                    2008-03-14 23:27:53 0 d-------- C:\WINDOWS\system32\ReinstallBackups
                    2008-03-14 23:27:19 1428 --a------ C:\WINDOWS\system32\drivers\nvphy.bin
                    2008-03-14 23:27:02 0 d-------- C:\Program Files\Common Files\InstallShield
                    2008-03-14 23:26:53 0 d-------- C:\MCP55_nvidia_system_MB
                    2008-03-14 23:24:44 0 d-------- C:\Documents and Settings\Rayner\Application Data\U3
                    2008-03-14 23:21:15 0 d--hs---- C:\WINDOWS\Installer
                    2008-03-14 23:21:12 0 d-------- C:\Documents and Settings\Rayner\Application Data\Identities
                    2008-03-14 23:21:06 0 d--h----- C:\Documents and Settings\Rayner\Sjablonen
                    2008-03-14 23:21:06 0 dr-h----- C:\Documents and Settings\Rayner\SendTo
                    2008-03-14 23:21:06 0 dr-h----- C:\Documents and Settings\Rayner\Onlangs geopend
                    2008-03-14 23:21:06 3407872 --ah----- C:\Documents and Settings\Rayner\NTUSER.DAT
                    2008-03-14 23:21:06 0 d--h----- C:\Documents and Settings\Rayner\Netwerkprinteromgeving
                    2008-03-14 23:21:06 0 d--h----- C:\Documents and Settings\Rayner\NetHood
                    2008-03-14 23:21:06 0 dr------- C:\Documents and Settings\Rayner\Mijn documenten
                    2008-03-14 23:21:06 0 dr------- C:\Documents and Settings\Rayner\Menu Start
                    2008-03-14 23:21:06 0 d--h----- C:\Documents and Settings\Rayner\Local Settings
                    2008-03-14 23:21:06 0 dr------- C:\Documents and Settings\Rayner\Favorieten
                    2008-03-14 23:21:06 0 d--hs---- C:\Documents and Settings\Rayner\Cookies
                    2008-03-14 23:21:06 0 d-------- C:\Documents and Settings\Rayner\Bureaublad
                    2008-03-14 23:21:06 0 dr-h----- C:\Documents and Settings\Rayner\Application Data
                    2008-03-14 23:20:25 0 d--hs---- C:\System Volume Information
                    2008-03-14 23:20:24 262144 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
                    2008-03-14 23:20:24 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
                    2008-03-14 23:20:24 0 d--hs---- C:\Documents and Settings\NetworkService\Cookies
                    2008-03-14 23:20:24 0 d-------- C:\Documents and Settings\NetworkService\Application Data
                    2008-03-14 23:20:24 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
                    2008-03-14 23:20:24 262144 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
                    2008-03-14 23:20:24 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
                    2008-03-14 23:20:24 0 d--hs---- C:\Documents and Settings\LocalService\Cookies
                    2008-03-14 23:20:24 0 d-------- C:\Documents and Settings\LocalService\Application Data
                    2008-03-14 23:20:24 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
                    2008-03-14 23:18:04 0 d-------- C:\WINDOWS\system32\xircom
                    2008-03-14 23:18:04 0 d-------- C:\Program Files\microsoft frontpage
                    2008-03-14 23:17:56 229376 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
                    2008-03-14 23:17:52 0 -rahs---- C:\MSDOS.SYS
                    2008-03-14 23:17:52 0 -rahs---- C:\IO.SYS
                    2008-03-14 23:17:52 0 --a------ C:\CONFIG.SYS
                    2008-03-14 23:17:52 0 --a------ C:\AUTOEXEC.BAT
                    2008-03-14 23:17:10 0 d--hs---- C:\Documents and Settings\All Users\DRM
                    2008-03-14 23:17:02 0 dr------- C:\WINDOWS\Offline Web Pages
                    2008-03-14 23:17:02 0 d---s---- C:\WINDOWS\Downloaded Program Files
                    2008-03-14 23:16:38 0 d-------- C:\WINDOWS\system32\DirectX
                    2008-03-14 23:15:58 0 d---s---- C:\WINDOWS\Tasks
                    2008-03-14 23:15:55 0 d-------- C:\Program Files\Common Files\MSSoap
                    2008-03-14 23:15:51 0 d-------- C:\WINDOWS\srchasst
                    2008-03-14 23:15:50 0 d-------- C:\WINDOWS\system32\Macromed
                    2008-03-14 23:15:49 0 d-------- C:\Program Files\Movie Maker
                    2008-03-14 23:15:46 0 d-------- C:\WINDOWS\system32\Restore
                    2008-03-14 23:15:46 0 d-------- C:\WINDOWS\PCHealth
                    2008-03-14 23:15:17 21748 --a------ C:\WINDOWS\system32\emptyregdb.dat
                    2008-03-14 23:15:04 0 d-------- C:\WINDOWS\Registration
                    2008-03-14 23:14:59 0 d--h----- C:\Program Files\WindowsUpdate
                    2008-03-14 23:14:59 0 d-------- C:\Program Files\Online Services
                    2008-03-14 23:14:54 0 d-------- C:\Program Files\Messenger
                    2008-03-14 23:14:49 0 d-------- C:\Program Files\MSN Gaming Zone
                    2008-03-14 23:14:12 0 d-------- C:\Program Files\Windows NT
                    2008-03-14 23:14:10 0 d-------- C:\WINDOWS\system32\MsDtc
                    2008-03-14 23:14:09 0 d-------- C:\WINDOWS\system32\Com


                    -- Find3M Report ---------------------------------------------------------------

                    2008-03-21 00:17:58 512410 --a------ C:\WINDOWS\system32\perfh013.dat
                    2008-03-21 00:17:58 92052 --a------ C:\WINDOWS\system32\perfc013.dat
                    2008-03-15 01:19:53 2560 --a------ C:\WINDOWS\system32\BitCometRes.dll <Not Verified; BitComet; BitComet BCTP Helper>
                    2008-03-14 23:52:26 62 --ahs---- C:\Documents and Settings\Rayner\Application Data\desktop.ini


                    -- Registry Dump ---------------------------------------------------------------

                    *Note* empty entries & legit default entries are not shown


                    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e18bcffb-e968-4bb1-8bda-5fbdd669265b}]
                    20-03-2008 21:36 91712 --a------ C:\WINDOWS\system32\ntuepksi.dll

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "RTHDCPL"="RTHDCPL.EXE" [29-01-2008 15:47 C:\WINDOWS\RTHDCPL.exe]
                    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [25-10-2006 18:58]
                    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [30-10-2006 09:36]
                    "PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [05-06-2006 15:06]
                    "StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [21-01-2008 12:17]
                    "mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [03-08-2007 22:33]
                    "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [11-06-2007 10:25]
                    "e87c986c"="C:\WINDOWS\system32\jpdbthqn.dll" [21-03-2008 07:44]
                    "BMeb4fabf0"="C:\WINDOWS\system32\jxwnaqws.dll" [20-03-2008 21:36]

                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" [13-10-2004 17:24]
                    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04-08-2004 09:03]

                    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
                    "DisableTaskMgr"=1 (0x1)
                    "DisableRegistryTools"=0 (0x0)

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                    "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [21-11-2006 14:50 233472]

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\reset5]
                    reset5.dll 09-09-2002 21:30 17408 C:\WINDOWS\system32\reset5.dll

                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
                    SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
                    @="Service"

                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
                    @=""

                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
                    @=""

                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
                    @="Service"

                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
                    @="Volume shadow copy"




                    -- End of Deckard's System Scanner: finished at 2008-03-21 07:53:08 ------------

                    Comment


                    • #11
                      Open een kladblokbestand.
                      Kopieer onderstaande (alles wat vetgedrukt is) in dit kladblokbestand.

                      @ECHO OFF
                      IF EXIST log.txt DEL log.txt
                      sc delete "Reset 5"
                      ren C:\WINDOWS\system32\ntuepksi.dll ntuepksi.bak
                      ren C:\WINDOWS\system32\jpdbthqn.dll jpdbthqn.bak
                      ren C:\WINDOWS\system32\jxwnaqws.dll jxwnaqws.bak
                      ECHO Deleting files>>log.txt
                      FOR %%g in (
                      C:\WINDOWS\system32\jpdbthqn.dll
                      C:\WINDOWS\system32\ntuepksi.dll
                      C:\WINDOWS\system32\jxwnaqws.dll
                      C:\WINDOWS\system32\jpdbthqn.bak
                      C:\WINDOWS\system32\ntuepksi.bak
                      C:\WINDOWS\system32\jxwnaqws.bak
                      C:\WINDOWS\system32\gebyy.dll
                      C:\WINDOWS\system32\ljjhfda.dll
                      C:\Extractor.bat) DO (
                      IF EXIST %%g (
                      ATTRIB -r -s -h %%g
                      DEL %%g
                      IF EXIST %%g (
                      ECHO %%g not deleted>>log.txt
                      ) ELSE (
                      ECHO %%g deleted>>log.txt)
                      ) ELSE (
                      ECHO %%g not found>>log.txt))
                      START NOTEPAD.EXE log.txt

                      Ga naar Bestand - Opslaan als.
                      Bij "Opslaan in" kies je: Bureaublad
                      Bij "Bestandsnaam" zet je: del.bat
                      Bij "Opslaan als type" selecteer je: Alle bestanden (*.*).
                      Klik op de knop Opslaan.

                      Dubbelklik op del.bat en post de inhoud van de logfile die opent.

                      Start HijackThis opnieuw, maak een nieuwe log en post deze.

                      Comment


                      • #12
                        Krijg trouwens ook nog de melding over dat ik me windows niet meer legitiem is ...
                        hierbij de logjes zoals gevraagd :

                        Deleting files
                        C:\WINDOWS\system32\jpdbthqn.dll not found
                        C:\WINDOWS\system32\ntuepksi.dll not found
                        C:\WINDOWS\system32\jxwnaqws.dll not found
                        C:\WINDOWS\system32\jpdbthqn.bak deleted
                        C:\WINDOWS\system32\ntuepksi.bak deleted
                        C:\WINDOWS\system32\jxwnaqws.bak not deleted
                        C:\WINDOWS\system32\gebyy.dll deleted
                        C:\WINDOWS\system32\ljjhfda.dll deleted
                        C:\Extractor.bat deleted

                        Hijack this log :

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 18:50:59, on 22-3-2008
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16608)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        F:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                        C:\WINDOWS\Explorer.EXE
                        c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
                        c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
                        C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                        C:\Program Files\McAfee\MPF\MPFSrv.exe
                        C:\Program Files\Windows Desktop Search\wds_sl.exe
                        C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
                        C:\WINDOWS\RTHDCPL.EXE
                        C:\Program Files\QuickTime\qttask.exe
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\Program Files\PowerISO\PWRISOVM.EXE
                        C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                        C:\WINDOWS\system32\Rundll32.exe
                        C:\Program Files\Messenger\MSMSGS.EXE
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
                        C:\Program Files\iPod\bin\iPodService.exe
                        C:\WINDOWS\system32\wuauclt.exe
                        C:\WINDOWS\system32\WgaTray.exe
                        C:\WINDOWS\system32\wuauclt.exe
                        C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
                        C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
                        C:\WINDOWS\system32\notepad.exe
                        C:\Documents and Settings\Rayner\Bureaublad\HiJackThis.exe

                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = wwwproxy.xs4all.nl:8080
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = https://
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
                        O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
                        O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
                        O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
                        O2 - BHO: {b562966d-dbf5-adb8-1bb4-869ebffcb81e} - {e18bcffb-e968-4bb1-8bda-5fbdd669265b} - C:\WINDOWS\system32\ntuepksi.dll (file missing)
                        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                        O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
                        O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
                        O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
                        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                        O4 - HKLM\..\Run: [e87c986c] rundll32.exe "C:\WINDOWS\system32\jpdbthqn.dll",b
                        O4 - HKLM\..\Run: [BMeb4fabf0] Rundll32.exe "C:\WINDOWS\system32\jxwnaqws.dll",s
                        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Lokale service')
                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Netwerkservice')
                        O4 - Startup: Bat - Auto Update.lnk = C:\Program Files\Bat\Bat.exe
                        O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                        O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
                        O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
                        O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
                        O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                        O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.7.4.dll
                        O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O20 - Winlogon Notify: reset5 - C:\WINDOWS\SYSTEM32\reset5.dll
                        O23 - Service: McAfee Application Installer Cleanup (0153311205974296) (0153311205974296mcinstcleanup) - Unknown owner - C:\DOCUME~1\Rayner\LOCALS~1\Temp\015331~1.EXE (file missing)
                        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - F:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                        O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                        O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
                        O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
                        O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
                        O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                        O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
                        O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe

                        --
                        End of file - 7097 bytes

                        Comment


                        • #13
                          Start Hijackthis en vink alleen de volgende regels aan:
                          O2 - BHO: {b562966d-dbf5-adb8-1bb4-869ebffcb81e} - {e18bcffb-e968-4bb1-8bda-5fbdd669265b} - C:\WINDOWS\system32\ntuepksi.dll (file missing)
                          O4 - HKLM\..\Run: [e87c986c] rundll32.exe "C:\WINDOWS\system32\jpdbthqn.dll",b
                          O4 - HKLM\..\Run: [BMeb4fabf0] Rundll32.exe "C:\WINDOWS\system32\jxwnaqws.dll",s

                          Sluit alle openstaande vensters(behalve Hijackthis) en klik op "Fix checked".

                          Herstart je computer.

                          Verwijder dit bestand:
                          C:\WINDOWS\system32\jxwnaqws.bak

                          Post een nieuw logje van Hijackthis ter controle

                          Comment


                          • #14
                            het is gelukt het bestand te verwijderen. Alleen kom ik windows niet niet normaal meer in, enkel veilige modus. Krijg bsod dat te snel gaat. Had auto reboot uitgezet maar hy valt in die bsod steeds. Deze post is via mobiel. Wireless dus dat scheelt. Chkdsk al aan et draaien maar ik vrees et ergste.

                            Comment


                            • #15
                              Vreemd, wanneer is dat begonnen?

                              Je zou sfc /scannow kunnen ingeven in een CMD-scherm.
                              Dan wordt je systeem vanaf een installatie-CD(als je die hebt) gecontroleerd op ontbrekende en corrupte bestanden.

                              Comment

                              Sorry, you are not authorized to view this page
                              Working...
                              X