Beste Nucia medewerker,
Mijn pc in nu heel erg traag, en krijg ook tijdens het internetten veel popus en ongewenste websites.
Ik heb mijn pc gescand met spyware doctor, en heeft een aantal spyware gevonden zoals:
- spyware.known_Bad_sites (2 infecties)
- Trojan.Block-Checker (3infecties) bestand: System32\ustart.exe
- Application.nirCmd (15 infecties)
- Trojan.Generic (1 infecties)
Ik heb daarna combofix gedownload en hiervan de log:
ComboFix 08-04-24.1 - Moviemax 04/27/2008 9:58:19.2 - NTFSx86
Gestart vanuit: C:\Documents and Settings\Moviemax\Bureaublad\ComboFix.exe
* Resident AV is active
WAARSCHUWING - DE RECOVERY CONSOLE IS NIET OP DIT SYSTEEM GEINSTALLEERD !!
.
(((((((((((((((((((( Bestanden Gemaakt van 2008-03-27 to 2008-04-27 ))))))))))))))))))))))))))))))
.
Geen nieuwe bestanden aangemaakt in deze periode
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-27 07:58 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-27 07:09 --------- d-----w C:\Program Files\Windows XP Home-Pro-2003 SP2 Crack
2008-04-27 06:44 --------- d-----w C:\Program Files\Circle Developement
2008-04-27 06:22 --------- d-----w C:\Program Files\Free Internet Window Washer
2008-04-26 22:03 --------- d-----w C:\Program Files\Eset
2008-04-26 21:41 --------- d-----w C:\Program Files\Spyware Doctor
2008-04-26 20:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-04-26 19:43 --------- d-----w C:\Program Files\Google
2008-04-26 19:40 --------- d-----w C:\Documents and Settings\Moviemax\Application Data\MSN6
2008-04-26 19:32 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-04-26 19:31 --------- d-----w C:\Program Files\Yahoo!
2008-04-26 18:52 512,096 ----a-w C:\WINDOWS\system32\drivers\amon.sys
2008-04-26 18:52 298,104 ----a-w C:\WINDOWS\system32\imon.dll
2008-04-26 18:52 15,424 ----a-w C:\WINDOWS\system32\drivers\nod32drv.sys
2008-04-19 11:24 --------- d-----w C:\Program Files\A-G-I
2008-04-07 19:43 --------- d-----w C:\Documents and Settings\Moviemax\Application Data\Yahoo!
2008-04-07 17:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-04-03 13:19 --------- d-----w C:\Documents and Settings\Moviemax\Application Data\WarnSkipFast
2008-04-03 13:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\flag ace stupid data
2008-04-03 13:18 --------- d-----w C:\Program Files\WarnSkipFast
2008-04-03 13:18 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-04-01 21:46 --------- d-----w C:\Program Files\Windows Live
2008-04-01 19:42 --------- d-----w C:\Program Files\exploration.net
2008-04-01 19:40 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
2008-04-01 19:39 --------- d-----w C:\Program Files\Common Files\Softwin
2008-04-01 17:43 --------- d-----w C:\Documents and Settings\Moviemax\Application Data\Bitdefender
2008-04-01 17:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\BitDefender
2008-04-01 17:42 --------- d-----w C:\Program Files\Softwin
2008-03-24 19:04 --------- d-----w C:\Documents and Settings\Moviemax\Application Data\AdobeUM
2008-03-20 08:10 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-13 22:16 --------- d-----w C:\Documents and Settings\Moviemax\Application Data\Voipwise
2008-03-13 21:30 --------- d-----w C:\Program Files\Voipwise.com
2008-03-13 18:41 --------- d-----w C:\Program Files\Common Files\xing shared
2008-03-13 18:41 --------- d-----w C:\Program Files\Common Files\Real
2008-03-13 18:40 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-03-13 18:40 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-03-13 18:40 --------- d-----w C:\Program Files\Real
2008-03-13 16:14 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-03-13 13:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-03-12 22:56 --------- d-----w C:\Program Files\MSXML 4.0
2008-03-12 21:40 --------- d-----w C:\Program Files\Brother
2008-03-12 21:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-12 21:38 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-12 21:37 --------- d-----w C:\Program Files\ScanSoft
2008-03-12 21:37 --------- d-----w C:\Program Files\Common Files\ScanSoft Shared
2008-03-12 21:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\ScanSoft
2008-03-12 21:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-03-12 21:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Brother
2008-03-12 21:09 --------- d-----w C:\Program Files\Logitech
2008-03-12 21:00 --------- d-----w C:\Program Files\keath
2008-03-12 20:47 --------- d-----w C:\Documents and Settings\Moviemax\Application Data\.gaim
2008-03-12 20:46 --------- d-----w C:\Program Files\Common Files\Logitech
2008-03-12 20:34 --------- d-----w C:\Program Files\Hitman Pro
2008-03-12 20:32 --------- d-----w C:\Documents and Settings\Moviemax\Application Data\Lavasoft
2008-03-12 20:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-12 20:15 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2008-03-12 19:51 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-12 19:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:39 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 09:05 662,528 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-01 09:17 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
.
((((((((((((((((((((((((((((( [email protected] 04-27-2008_ 0.15.14.54 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-26 19:01:39 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-27 06:01:52 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-27 06:02:12 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_5cc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
12/17/2007 11:12 AM 56360 --a------ C:\Program Files\Windows Live\Family Safety\fssbho.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\PROGRA~1\WI1F86~1\MESSEN~1\msnmsgr.exe" [10/18/2007 12:34 PM 5724184]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [02/12/2006 02:30 PM 36864]
"Toolmode"="C:\DOCUME~1\Moviemax\APPLIC~1\WARNSK~1\Software Less.exe" [04/03/2008 03:18 PM 418304]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 02:03 AM 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [04/26/2008 09:42 PM 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [12/26/2005 07:53 PM 77824]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [11/10/2005 02:03 PM 36975]
"fssui"="C:\Program Files\Windows Live\Family Safety\fssui.exe" [12/17/2007 11:12 AM 243240]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [10/14/2003 11:22 AM 155648]
"PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [03/18/2005 01:40 PM 57393]
"IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [03/18/2005 01:53 PM 40960]
"BrMfcWnd"="C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe" [03/28/2006 04:48 PM 622592]
"SetDefPrt"="C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe" [01/26/2005 07:02 PM 49152]
"ControlCenter3"="C:\Program Files\Brother\ControlCenter3\brctrcen.exe" [04/10/2006 03:58 PM 61440]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [03/13/2008 08:40 PM 185896]
"Stupid Data Dart Wave"="C:\Documents and Settings\All Users\Application Data\flag ace stupid data\Poke way.exe" [04/27/2008 08:04 AM 2610176]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [04/26/2008 08:52 PM 949376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [08/04/2004 02:03 AM 15360]
C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\
Adobe Reader Snelle start.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 00:05:26 29696]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-26 21:42:55 124400]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 08/04/2004 02:03 AM 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 06/21/2005 05:44 PM 126976 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 06/21/2005 05:48 PM 155648 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
C:\WINDOWS\system32\LVCOMSX.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"%windir%\\system32\\ccapp.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Voipwise.com\\Voipwise\\Voipwise.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
R2 fssfltr;FssFltr;C:\WINDOWS\system32\DRIVERS\fssfltr.sys [10/17/2007 02:53 PM]
R2 fsssvc;Windows Live OneCare Family Safety;"C:\Program Files\Windows Live\Family Safety\fsssvc.exe" [12/17/2007 11:13 AM]
R2 MSSQL$TOTAL;MSSQL$TOTAL;C:\Program Files\Microsoft SQL Server\MSSQL$TOTAL\Binn\sqlservr.exe [12/17/2002 06:26 PM]
R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps snelle ethernet-adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys [08/03/2004 11:31 PM]
S3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys [10/15/2004 01:50 PM]
S3 SQLAgent$TOTAL;SQLAgent$TOTAL;C:\Program Files\Microsoft SQL Server\MSSQL$TOTAL\Binn\sqlagent.EXE [12/17/2002 06:23 PM]
.
Inhoud van de 'Gedeelde Taken' map
"2008-04-27 08:00:05 C:\WINDOWS\Tasks\AD922E7B9095A85B.job"
- c:\docume~1\moviemax\applic~1\warnsk~1\File Test Road.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-27 10:03:10
Windows 5.1.2600 Service Pack 2 NTFS
scannen van verborgen processen ...
scannen van verborgen autostart items ...
scannen van verborgen bestanden ...
Scan succesvol afgerond
verborgen bestanden: 0
**************************************************************************
.
--------------------- DLLs Geladen Onder Lopende Processen ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\Program Files\Eset\pr_imon.dll
.
Voltooingstijd: 04/27/2008 10:07:54
ComboFix-quarantined-files.txt 2008-04-27 08:07:18
ComboFix2.txt 2008-04-26 22:16:34
Pre-Run: 18,208,210,944 bytes beschikbaar
Post-Run: 18,313,392,128 bytes beschikbaar
160 --- E O F --- 2008-04-26 18:59:18[/COLOR]
Kunt u uit deze gegevens mij verder helpen?
Mijn pc in nu heel erg traag, en krijg ook tijdens het internetten veel popus en ongewenste websites.
Ik heb mijn pc gescand met spyware doctor, en heeft een aantal spyware gevonden zoals:
- spyware.known_Bad_sites (2 infecties)
- Trojan.Block-Checker (3infecties) bestand: System32\ustart.exe
- Application.nirCmd (15 infecties)
- Trojan.Generic (1 infecties)
Ik heb daarna combofix gedownload en hiervan de log:
ComboFix 08-04-24.1 - Moviemax 04/27/2008 9:58:19.2 - NTFSx86
Gestart vanuit: C:\Documents and Settings\Moviemax\Bureaublad\ComboFix.exe
* Resident AV is active
WAARSCHUWING - DE RECOVERY CONSOLE IS NIET OP DIT SYSTEEM GEINSTALLEERD !!
.
(((((((((((((((((((( Bestanden Gemaakt van 2008-03-27 to 2008-04-27 ))))))))))))))))))))))))))))))
.
Geen nieuwe bestanden aangemaakt in deze periode
.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-27 07:58 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-27 07:09 --------- d-----w C:\Program Files\Windows XP Home-Pro-2003 SP2 Crack
2008-04-27 06:44 --------- d-----w C:\Program Files\Circle Developement
2008-04-27 06:22 --------- d-----w C:\Program Files\Free Internet Window Washer
2008-04-26 22:03 --------- d-----w C:\Program Files\Eset
2008-04-26 21:41 --------- d-----w C:\Program Files\Spyware Doctor
2008-04-26 20:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-04-26 19:43 --------- d-----w C:\Program Files\Google
2008-04-26 19:40 --------- d-----w C:\Documents and Settings\Moviemax\Application Data\MSN6
2008-04-26 19:32 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-04-26 19:31 --------- d-----w C:\Program Files\Yahoo!
2008-04-26 18:52 512,096 ----a-w C:\WINDOWS\system32\drivers\amon.sys
2008-04-26 18:52 298,104 ----a-w C:\WINDOWS\system32\imon.dll
2008-04-26 18:52 15,424 ----a-w C:\WINDOWS\system32\drivers\nod32drv.sys
2008-04-19 11:24 --------- d-----w C:\Program Files\A-G-I
2008-04-07 19:43 --------- d-----w C:\Documents and Settings\Moviemax\Application Data\Yahoo!
2008-04-07 17:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-04-03 13:19 --------- d-----w C:\Documents and Settings\Moviemax\Application Data\WarnSkipFast
2008-04-03 13:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\flag ace stupid data
2008-04-03 13:18 --------- d-----w C:\Program Files\WarnSkipFast
2008-04-03 13:18 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-04-01 21:46 --------- d-----w C:\Program Files\Windows Live
2008-04-01 19:42 --------- d-----w C:\Program Files\exploration.net
2008-04-01 19:40 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
2008-04-01 19:39 --------- d-----w C:\Program Files\Common Files\Softwin
2008-04-01 17:43 --------- d-----w C:\Documents and Settings\Moviemax\Application Data\Bitdefender
2008-04-01 17:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\BitDefender
2008-04-01 17:42 --------- d-----w C:\Program Files\Softwin
2008-03-24 19:04 --------- d-----w C:\Documents and Settings\Moviemax\Application Data\AdobeUM
2008-03-20 08:10 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-13 22:16 --------- d-----w C:\Documents and Settings\Moviemax\Application Data\Voipwise
2008-03-13 21:30 --------- d-----w C:\Program Files\Voipwise.com
2008-03-13 18:41 --------- d-----w C:\Program Files\Common Files\xing shared
2008-03-13 18:41 --------- d-----w C:\Program Files\Common Files\Real
2008-03-13 18:40 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-03-13 18:40 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-03-13 18:40 --------- d-----w C:\Program Files\Real
2008-03-13 16:14 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-03-13 13:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-03-12 22:56 --------- d-----w C:\Program Files\MSXML 4.0
2008-03-12 21:40 --------- d-----w C:\Program Files\Brother
2008-03-12 21:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-12 21:38 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-12 21:37 --------- d-----w C:\Program Files\ScanSoft
2008-03-12 21:37 --------- d-----w C:\Program Files\Common Files\ScanSoft Shared
2008-03-12 21:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\ScanSoft
2008-03-12 21:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2008-03-12 21:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Brother
2008-03-12 21:09 --------- d-----w C:\Program Files\Logitech
2008-03-12 21:00 --------- d-----w C:\Program Files\keath
2008-03-12 20:47 --------- d-----w C:\Documents and Settings\Moviemax\Application Data\.gaim
2008-03-12 20:46 --------- d-----w C:\Program Files\Common Files\Logitech
2008-03-12 20:34 --------- d-----w C:\Program Files\Hitman Pro
2008-03-12 20:32 --------- d-----w C:\Documents and Settings\Moviemax\Application Data\Lavasoft
2008-03-12 20:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-12 20:15 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2008-03-12 19:51 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-12 19:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:39 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 09:05 662,528 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-01 09:17 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
.
((((((((((((((((((((((((((((( [email protected] 04-27-2008_ 0.15.14.54 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-26 19:01:39 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-27 06:01:52 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-27 06:02:12 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_5cc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
12/17/2007 11:12 AM 56360 --a------ C:\Program Files\Windows Live\Family Safety\fssbho.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\PROGRA~1\WI1F86~1\MESSEN~1\msnmsgr.exe" [10/18/2007 12:34 PM 5724184]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [02/12/2006 02:30 PM 36864]
"Toolmode"="C:\DOCUME~1\Moviemax\APPLIC~1\WARNSK~1\Software Less.exe" [04/03/2008 03:18 PM 418304]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 02:03 AM 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [04/26/2008 09:42 PM 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [12/26/2005 07:53 PM 77824]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [11/10/2005 02:03 PM 36975]
"fssui"="C:\Program Files\Windows Live\Family Safety\fssui.exe" [12/17/2007 11:12 AM 243240]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [10/14/2003 11:22 AM 155648]
"PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [03/18/2005 01:40 PM 57393]
"IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [03/18/2005 01:53 PM 40960]
"BrMfcWnd"="C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe" [03/28/2006 04:48 PM 622592]
"SetDefPrt"="C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe" [01/26/2005 07:02 PM 49152]
"ControlCenter3"="C:\Program Files\Brother\ControlCenter3\brctrcen.exe" [04/10/2006 03:58 PM 61440]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [03/13/2008 08:40 PM 185896]
"Stupid Data Dart Wave"="C:\Documents and Settings\All Users\Application Data\flag ace stupid data\Poke way.exe" [04/27/2008 08:04 AM 2610176]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [04/26/2008 08:52 PM 949376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [08/04/2004 02:03 AM 15360]
C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\
Adobe Reader Snelle start.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 00:05:26 29696]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-26 21:42:55 124400]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 08/04/2004 02:03 AM 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 06/21/2005 05:44 PM 126976 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 06/21/2005 05:48 PM 155648 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
C:\WINDOWS\system32\LVCOMSX.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"%windir%\\system32\\ccapp.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Voipwise.com\\Voipwise\\Voipwise.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
R2 fssfltr;FssFltr;C:\WINDOWS\system32\DRIVERS\fssfltr.sys [10/17/2007 02:53 PM]
R2 fsssvc;Windows Live OneCare Family Safety;"C:\Program Files\Windows Live\Family Safety\fsssvc.exe" [12/17/2007 11:13 AM]
R2 MSSQL$TOTAL;MSSQL$TOTAL;C:\Program Files\Microsoft SQL Server\MSSQL$TOTAL\Binn\sqlservr.exe [12/17/2002 06:26 PM]
R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps snelle ethernet-adapter;C:\WINDOWS\system32\DRIVERS\AN983.sys [08/03/2004 11:31 PM]
S3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys [10/15/2004 01:50 PM]
S3 SQLAgent$TOTAL;SQLAgent$TOTAL;C:\Program Files\Microsoft SQL Server\MSSQL$TOTAL\Binn\sqlagent.EXE [12/17/2002 06:23 PM]
.
Inhoud van de 'Gedeelde Taken' map
"2008-04-27 08:00:05 C:\WINDOWS\Tasks\AD922E7B9095A85B.job"
- c:\docume~1\moviemax\applic~1\warnsk~1\File Test Road.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-27 10:03:10
Windows 5.1.2600 Service Pack 2 NTFS
scannen van verborgen processen ...
scannen van verborgen autostart items ...
scannen van verborgen bestanden ...
Scan succesvol afgerond
verborgen bestanden: 0
**************************************************************************
.
--------------------- DLLs Geladen Onder Lopende Processen ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\Program Files\Eset\pr_imon.dll
.
Voltooingstijd: 04/27/2008 10:07:54
ComboFix-quarantined-files.txt 2008-04-27 08:07:18
ComboFix2.txt 2008-04-26 22:16:34
Pre-Run: 18,208,210,944 bytes beschikbaar
Post-Run: 18,313,392,128 bytes beschikbaar
160 --- E O F --- 2008-04-26 18:59:18[/COLOR]
Kunt u uit deze gegevens mij verder helpen?
Comment