Mededeling

Collapse
No announcement yet.

Geinfecteerd.....ondanks beveiliging

Collapse
X
  •  
  • Filter
  • Tijd
  • Show
Clear All
new posts

  • Geinfecteerd.....ondanks beveiliging

    Ik maak gebruik van het pakket PC Veilig van Planet (F secure).
    In de afgelopen week werd dit programma 2 keer automatisch afgesloten " omdat er een fout was opgetreden"
    Gisteren kreeg ik een melding van een trojan die gevonden en geelimineerd zou zijn (heb helaas verzuimd op te schrijven om welke het ging).
    Maar..........wantrouwig als ik ben en omdat mijn PC de laatste tijd supertraag is heb ik- na adware, spybot - eerst een online scan gedaan met Panda en daarna nog eentje met Kaspersky.

    Panda vond dit:

    Incident Status Location

    Spyware:Cookie/Itrack Not disinfected C:\Documents and Settings\Ik zelf\Application Data\Mozilla\Firefox\Profiles\qnv3buqq.default\cookies.txt[ilead.itrack.it/]
    Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\Ik zelf\Application Data\Mozilla\Firefox\Profiles\qnv3buqq.default\cookies.txt[stat.onestat.com/]
    Spyware:Cookie/Weborama Not disinfected C:\Documents and Settings\Ik zelf\Application Data\Mozilla\Firefox\Profiles\qnv3buqq.default\cookies.txt[.weborama.fr/]
    Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Ik zelf\Application Data\Mozilla\Firefox\Profiles\qnv3buqq.default\cookies.txt[.serving-sys.com/]
    Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Ik zelf\Application Data\Mozilla\Firefox\Profiles\qnv3buqq.default\cookies.txt[www.burstbeacon.com/]
    Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Ik zelf\Application Data\Mozilla\Firefox\Profiles\qnv3buqq.default\cookies.txt[.com.com/]
    Spyware:Cookie/MetriWeb Not disinfected C:\Documents and Settings\Ik zelf\Application Data\Mozilla\Firefox\Profiles\qnv3buqq.default\cookies.txt[.metriweb.be/]
    Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Ik zelf\Application Data\Mozilla\Firefox\Profiles\qnv3buqq.default\cookies.txt[.xiti.com/]
    Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Ik zelf\Application Data\Mozilla\Firefox\Profiles\qnv3buqq.default\cookies.txt[.bs.serving-sys.com/]
    Potentially unwanted tool:Application/PRScheduler Not disinfected C:\Documents and Settings\Ik zelf\Mijn documenten\computer hulpprogramma´s\hijackthis\backups\backup-20060424-203931-779-PowerReg Scheduler.exe
    Virus:Generic Malware Disinfected C:\Documents and Settings\Ik zelf\Mijn documenten\cracks\WS_FTP Professional 2006 Ipswitch keygen.exe
    Virus:Generic Malware Disinfected C:\Program Files\Adobe\Adobe Photoshop CS2\Plug-Ins\Setup\SETUP.EXE
    Virus:Generic Malware

    maar........................

    Uit de scan van Kaspersy, waarvan hieronder het rapport, bleek er nog een 4-tal trojans aanwezig te zijn.

    Rapport:
    -------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER REPORT
    Sunday, March 30, 2008 10:15:58 AM
    Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.98.0
    Kaspersky Anti-Virus database last update: 29/03/2008
    Kaspersky Anti-Virus database records: 603936
    -------------------------------------------------------------------------------

    Scan Settings:
    Scan using the following antivirus database: standard
    Scan Archives: true
    Scan Mail Bases: true

    Scan Target - My Computer:
    A:\
    C:\
    D:\
    E:\
    F:\
    G:\
    H:\
    I:\
    J:\

    Scan Statistics:
    Total number of scanned objects: 117411
    Number of viruses found: 4
    Number of infected objects: 14
    Number of suspicious objects: 0
    Duration of the scan process: 02:16:29

    Infected Object Name / Virus Name / Last Action
    C:\Documents and Settings\All Users\Application Data\F-Secure\logs\FSMA\fsma.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
    C:\Documents and Settings\All Users\ntuser.dat Object is locked skipped
    C:\Documents and Settings\All Users\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\Ik zelf\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\Ik zelf\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\Ik zelf\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\Ik zelf\Local Settings\Geschiedenis\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\Ik zelf\Local Settings\Geschiedenis\History.IE5\MSHist012008032920080330\index.dat Object is locked skipped
    C:\Documents and Settings\Ik zelf\Local Settings\Temp\~DF350F.tmp Object is locked skipped
    C:\Documents and Settings\Ik zelf\Local Settings\Temp\~DFD5A.tmp Object is locked skipped
    C:\Documents and Settings\Ik zelf\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\Ik zelf\Mijn documenten\computer hulpprogramma´s\antispyware downloads\rbkiller (rapidblasterkiller).exe Object is locked skipped
    C:\Documents and Settings\Ik zelf\Mijn documenten\DRIVER DOWNLOADS\DRIVERDOWNLOADS\alcatel\alcawh95.sys Object is locked skipped
    C:\Documents and Settings\Ik zelf\ntuser.dat Object is locked skipped
    C:\Documents and Settings\Ik zelf\NTUSER.DAT.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Geschiedenis\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
    C:\Program Files\Adobe\Adobe Photoshop CS2\Presets\Photoshop Actions\Install Creator PRO 2\icp-SETUP.exe Object is locked skipped
    C:\Program Files\PC Veilig\Anti-Virus\dbupdate.log Object is locked skipped
    C:\Program Files\PC Veilig\Anti-Virus\deleteme_msg.log Object is locked skipped
    C:\Program Files\PC Veilig\Anti-Virus\fsqh.exe.Qrt.log Object is locked skipped
    C:\Program Files\PC Veilig\Anti-Virus\perf.dat Object is locked skipped
    C:\Program Files\PC Veilig\Anti-Virus\power.dat Object is locked skipped
    C:\Program Files\PC Veilig\Common\policy.bpf Object is locked skipped
    C:\Program Files\PC Veilig\Common\policy.ipf Object is locked skipped
    C:\Program Files\PC Veilig\FSAUA\program\fsaua.dbg Object is locked skipped
    C:\Program Files\PC Veilig\FSAUA\program\fsaua.log Object is locked skipped
    C:\Program Files\PC Veilig\FSAUA\program\fsbwupst.log Object is locked skipped
    C:\Program Files\PC Veilig\Spam Control\log\fs_sa_log.txt Object is locked skipped
    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    C:\System Volume Information\_restore{4D330D6C-E06C-4DE2-937A-2F0ADD0F1F8A}\RP702\A0087339.0xe Infected: Trojan-Clicker.Win32.VB.mo skipped
    C:\System Volume Information\_restore{4D330D6C-E06C-4DE2-937A-2F0ADD0F1F8A}\RP702\A0087343.exe Object is locked skipped
    C:\System Volume Information\_restore{4D330D6C-E06C-4DE2-937A-2F0ADD0F1F8A}\RP702\A0087344.exe Object is locked skipped
    C:\System Volume Information\_restore{4D330D6C-E06C-4DE2-937A-2F0ADD0F1F8A}\RP702\A0087345.exe Object is locked skipped
    C:\System Volume Information\_restore{4D330D6C-E06C-4DE2-937A-2F0ADD0F1F8A}\RP702\A0087346.exe/run.exe Infected: Trojan-Downloader.Win32.Small.ckj skipped
    C:\System Volume Information\_restore{4D330D6C-E06C-4DE2-937A-2F0ADD0F1F8A}\RP702\A0087346.exe ZIP: infected - 1 skipped
    C:\System Volume Information\_restore{4D330D6C-E06C-4DE2-937A-2F0ADD0F1F8A}\RP702\A0087346.exe CryptFF: infected - 1 skipped
    C:\System Volume Information\_restore{4D330D6C-E06C-4DE2-937A-2F0ADD0F1F8A}\RP702\A0087347.exe Object is locked skipped
    C:\System Volume Information\_restore{4D330D6C-E06C-4DE2-937A-2F0ADD0F1F8A}\RP702\A0087348.exe/run.exe/stream/data0006 Infected: Trojan-Downloader.Win32.Zlob.avs skipped
    C:\System Volume Information\_restore{4D330D6C-E06C-4DE2-937A-2F0ADD0F1F8A}\RP702\A0087348.exe/run.exe/stream Infected: Trojan-Downloader.Win32.Zlob.avs skipped
    C:\System Volume Information\_restore{4D330D6C-E06C-4DE2-937A-2F0ADD0F1F8A}\RP702\A0087348.exe/run.exe Infected: Trojan-Downloader.Win32.Zlob.avs skipped
    C:\System Volume Information\_restore{4D330D6C-E06C-4DE2-937A-2F0ADD0F1F8A}\RP702\A0087348.exe ZIP: infected - 3 skipped
    C:\System Volume Information\_restore{4D330D6C-E06C-4DE2-937A-2F0ADD0F1F8A}\RP702\A0087348.exe CryptFF: infected - 3 skipped
    C:\System Volume Information\_restore{4D330D6C-E06C-4DE2-937A-2F0ADD0F1F8A}\RP702\A0087349.exe Object is locked skipped
    C:\System Volume Information\_restore{4D330D6C-E06C-4DE2-937A-2F0ADD0F1F8A}\RP702\A0087350.exe/run.exe/stream/data0006 Infected: Trojan-Downloader.Win32.Zlob.avo skipped
    C:\System Volume Information\_restore{4D330D6C-E06C-4DE2-937A-2F0ADD0F1F8A}\RP702\A0087350.exe/run.exe/stream Infected: Trojan-Downloader.Win32.Zlob.avo skipped
    C:\System Volume Information\_restore{4D330D6C-E06C-4DE2-937A-2F0ADD0F1F8A}\RP702\A0087350.exe/run.exe Infected: Trojan-Downloader.Win32.Zlob.avo skipped
    C:\System Volume Information\_restore{4D330D6C-E06C-4DE2-937A-2F0ADD0F1F8A}\RP702\A0087350.exe ZIP: infected - 3 skipped
    C:\System Volume Information\_restore{4D330D6C-E06C-4DE2-937A-2F0ADD0F1F8A}\RP702\A0087350.exe CryptFF: infected - 3 skipped
    C:\System Volume Information\_restore{4D330D6C-E06C-4DE2-937A-2F0ADD0F1F8A}\RP750\change.log Object is locked skipped
    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
    C:\WINDOWS\SchedLgU.Txt Object is locked skipped
    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
    C:\WINDOWS\Sti_Trace.log Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\default Object is locked skipped
    C:\WINDOWS\system32\config\default.LOG Object is locked skipped
    C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
    C:\WINDOWS\system32\config\SAM Object is locked skipped
    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
    C:\WINDOWS\system32\config\software Object is locked skipped
    C:\WINDOWS\system32\config\software.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\system Object is locked skipped
    C:\WINDOWS\system32\config\system.LOG Object is locked skipped
    C:\WINDOWS\system32\h323log.txt Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
    C:\WINDOWS\Temp\AVP3822.tmp Object is locked skipped
    C:\WINDOWS\Temp\AVP3823.tmp Object is locked skipped
    C:\WINDOWS\Temp\AVP3826.tmp Object is locked skipped
    C:\WINDOWS\Temp\AVP3827.tmp Object is locked skipped
    C:\WINDOWS\wiadebug.log Object is locked skipped
    C:\WINDOWS\wiaservc.log Object is locked skipped
    C:\WINDOWS\WindowsUpdate.log Object is locked skipped
    D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

    Scan process completed.
    ----------------
    Aangezien ik met deze scan van Kaspersky de boel niet kan verwijderen plaats ik ook nog even een HJT-log zodat iemand van jullie mij door dit wederom tijdrovende , stomvervelende woud van ellende kunnen loodsen

    Ik vraag me af of PC veilig wel zo veilig is.

    Log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:32:07, on 30-3-2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16608)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\PC Veilig\Anti-Virus\fsgk32st.exe
    C:\Program Files\PC Veilig\Common\FSMA32.EXE
    C:\Program Files\PC Veilig\Anti-Virus\FSGK32.EXE
    C:\Program Files\PC Veilig\Common\FSMB32.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\RealVNC\VNC4\WinVNC4.exe
    C:\Program Files\PC Veilig\Common\FCH32.EXE
    C:\Program Files\PC Veilig\Common\FAMEH32.EXE
    C:\Program Files\PC Veilig\Anti-Virus\fsqh.exe
    C:\Program Files\PC Veilig\FSAUA\program\fsaua.exe
    C:\Program Files\PC Veilig\Anti-Virus\fssm32.exe
    C:\Program Files\PC Veilig\FWES\Program\fsdfwd.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\MULTIM~1\MMKBD.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
    C:\Program Files\Google\Gmail Notifier\gnotify.exe
    C:\Program Files\PC Veilig\Common\FSM32.EXE
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
    C:\Documents and Settings\Ik zelf\Menu Start\Programma's\Opstarten\S2kCtl.exe
    C:\Program Files\SpywareGuard\sgmain.exe
    C:\Program Files\PC Veilig\FSGUI\fsguidll.exe
    C:\Program Files\SpywareGuard\sgbhp.exe
    C:\Program Files\PC Veilig\FSAUA\program\fsus.exe
    C:\Program Files\PC Veilig\Anti-Virus\fsav32.exe
    C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O4 - HKLM\..\Run: [Multimedir KBD] C:\PROGRA~1\MULTIM~1\MMKBD.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [zzzHPSETUP] J:\Setup.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\PC Veilig\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\PC Veilig\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Gadwin PrintScreen 2.6] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: S2kCtl.exe
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Locate Spot on Map by GPS - C:\Program Files\Opanda\IExif 2.26\IExifMap.htm
    O8 - Extra context menu item: View Exif/GPS/IPTC with IExif - C:\Program Files\Opanda\IExif 2.26\IExifCom.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1155299731000
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\PC Veilig\Anti-Virus\fsgk32st.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\PC Veilig\FSAUA\program\fsaua.exe
    O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\PC Veilig\FWES\Program\fsdfwd.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\PC Veilig\Common\FSMA32.EXE
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\Win32\RpcDataSrv.exe
    O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\RpcSandraSrv.exe
    O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

    --
    End of file - 8676 bytes

  • #2
    Ik heb de afgelopen 2 dagen niet stil gezeten en heb zelf al wat zitten knutselen.Uit de scan van vanochtend (Panda) bleek dat de trojans in ieder geval weg zijn.
    Ze bleken in de restore map te zitten. Ik heb PC veilig/Fsecure na veel strubbelingen kunnen deinstalleren en opieuw kunnen installeren, heb de boel opgeschoond met JV16 tools, systeemherstel uit en weer aangezet en nog wat dingen waarmee ik jullie niet zal vermoeien. Ik zal vanavond even een nieuw logje plaatsen om te laten kijken of er nog wat dingen zijn achtergebleven.

    Comment


    • #3
      Hier is het nieuwe log:

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 19:42:07, on 1-4-2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16608)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\PC Veilig\Anti-Virus\fsgk32st.exe
      C:\Program Files\PC Veilig\Common\FSMA32.EXE
      C:\Program Files\PC Veilig\Anti-Virus\FSGK32.EXE
      C:\Program Files\PC Veilig\Common\FSMB32.EXE
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\PC Veilig\Common\FCH32.EXE
      C:\Program Files\PC Veilig\Anti-Virus\fssm32.exe
      C:\Program Files\PC Veilig\Common\FAMEH32.EXE
      C:\Program Files\PC Veilig\Anti-Virus\fsqh.exe
      C:\Program Files\PC Veilig\FSAUA\program\fsaua.exe
      C:\Program Files\PC Veilig\FWES\Program\fsdfwd.exe
      C:\PROGRA~1\MULTIM~1\MMKBD.exe
      C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
      C:\Program Files\Google\Gmail Notifier\gnotify.exe
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      C:\Program Files\PC Veilig\Common\FSM32.EXE
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
      C:\Documents and Settings\Ik zelf\Menu Start\Programma's\Opstarten\S2kCtl.exe
      C:\Program Files\SpywareGuard\sgmain.exe
      C:\Program Files\PC Veilig\FSGUI\fsguidll.exe
      C:\Program Files\SpywareGuard\sgbhp.exe
      C:\Program Files\PC Veilig\FSAUA\program\fsus.exe
      C:\Program Files\PC Veilig\Anti-Virus\fsav32.exe
      C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
      C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
      O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O4 - HKLM\..\Run: [Multimedir KBD] C:\PROGRA~1\MULTIM~1\MMKBD.exe
      O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [zzzHPSETUP] J:\Setup.exe
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
      O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
      O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\PC Veilig\Common\FSM32.EXE" /splash
      O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\PC Veilig\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Gadwin PrintScreen 2.6] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Startup: S2kCtl.exe
      O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
      O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O8 - Extra context menu item: Locate Spot on Map by GPS - C:\Program Files\Opanda\IExif 2.26\IExifMap.htm
      O8 - Extra context menu item: View Exif/GPS/IPTC with IExif - C:\Program Files\Opanda\IExif 2.26\IExifCom.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
      O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1155299731000
      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
      O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\PC Veilig\Anti-Virus\fsgk32st.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\PC Veilig\FSAUA\program\fsaua.exe
      O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\PC Veilig\FWES\Program\fsdfwd.exe
      O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\PC Veilig\Common\FSMA32.EXE
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

      --
      End of file - 8140 bytes

      Comment


      • #4
        Je logjes zien er goed uit, de dingen die worden gevonden zitten dan ook in Quartaine of systeemherstel.

        * Clean de Cache and Cookies in IE:

        * Sluit Internet Explorer.
        * Ga naar Configuratiescherm > Internet Opties > tab Algemeen
        * Klik de Cookies verwijderen knop
        * Klik op de Bestanden verwijderen knop ernaast
        * Vink aan: Ook alle off line items verwijderen, klik OK

        * Clean de Cache and Cookies in Firefox (In geval Firefox geïnstalleerd is):

        * Go to Extra > Opties.
        * Klik Privacy in het menu.
        * Klik op de knop wissen (Geschiedenis, Cookies, Cache).
        * Klik OK om het venster opnieuw te sluiten.

        * Clean andere Temporary files + Prullenbak

        * Ga naar Start > Uitvoeren en typ: cleanmgr en klik ok.
        * Laat het je systeem scannen op bestanden die moeten verwijderd worden
        * Zorg er wel voor dat je daar enkel maar 'tijdelijke bestanden', 'tijdelijke internetbestanden' en 'prullenbak' staan aangevinkt.
        * Klik daarna op OK.



        Schakel Systeemherstel uit. Herstart de computer. Schakel Systeemherstel weer in.
        Kijk hier hoe je je systeemherstel moet uitschakelen.
        Hiermee verwijder je eventuele restanten van de infecties uit je systeemherstel.
        Groet,
        Pimmerd

        Comment


        • #5
          Zoals je kunt lezen in mijn eerdere bericht heb ik de boel al opgeschoond en systeemherstel uit- en ingeschakeld.

          Is het log verder OK?

          Comment


          • #6
            Ja, je log ziet er verder goed uit
            Groet,
            Pimmerd

            Comment


            • #7
              OK dank je wel.

              Comment


              • #8
                Graag gedaan
                Groet,
                Pimmerd

                Comment

                Sorry, you are not authorized to view this page
                Working...
                X