Op een laptop van de buren, zit (in elk geval zat) heel veel spyware en virussen.
Nu heb ik met Spybot er al een aantal weten te verwijderen (ruime 200 problemen), maar het werkt nog niet helemaal goed.
Als je opstart, had je eerst al een melding van dat de computer infected was en dat je antivirus moest downloaden. Deze was volgens mij nu de laatste keer weg. Wil je inloggen, dan gebeurt er een hele tijd niets en na ongeveer een kwartier a 20 minuten krijg je dan een blauw scherm te zien, met geluk kan je dan Windows Taakbeheer openen en zo via bestand - nieuwe taak enkele programma's starten.
De taakbalk is nog steeds nergens te zien, systeemherstel kan ik helaas ook niet uitschakelen want krijg geen verkenner of configuratie scherm geopend.
Gelijk na het opstarten van taakbeheer, heb ik al een aantal vreemde processen afgesloten.
BraveSentry stond ook op de laptop, maar die is er hopelijk al af (weet het niet zeker). Verder zijn al een 100 redirected hosts door Spybot gevonden en opgelost (allemaal adressen van virusscanner bedrijven).
Adaware heb ik ook geprobeerd te installeren, maar dat is tot op heden nog niet gelukt.
Het internet zelf doet het nog wel, al krijg je internet explorer niet gestart (maar de programma's kunnen wel updaten, dus er is wel een internet verbinding actief).
Na de laatste spybot scan, toen sinds het opnieuw opstarten, is de syteemdatum en tijd ook veranderd (naar 2006), alleen is nog niet gelukt om dit te herstellen (want heb geen klok/taakbalk/configuratiescherm).
Veilige modus wil helemaal niet starten (komt niet verder dan een zwart scherm).
Hierbij de lijst van de HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:51:05, on 11-4-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\drivers\spools.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://c:/windows/homepage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = file://c:/windows/homepage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://internetsearchservice.com/ie6.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://c:/windows/homepage.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://internetsearchservice.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
O2 - BHO: (no name) - {a201888d-05ad-4019-af85-a7df73b56d47} - C:\WINDOWS\system32\rqRKDtSj.dll (file missing)
O3 - Toolbar: pvnsmfor - {89175504-FC6D-43A2-BB07-E3247659C95A} - C:\WINDOWS\pvnsmfor.dll (file missing)
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKLM\..\RunOnce: [SpyHunter3 BatchedRemoval] C:\Program Files\Enigma Software Group\SpyHunter\br.exe
O4 - HKLM\..\RunOnce: [SpybotDeletingA7549] command /c del "C:\Documents and Settings\L.Koningen\Application Data\ultra\ultra.inf"
O4 - HKLM\..\RunOnce: [SpybotDeletingC234] cmd /c del "C:\Documents and Settings\L.Koningen\Application Data\ultra\ultra.inf"
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA3908] command /c del "C:\WINDOWS\system32\rqRKDtSj.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9739] cmd /c del "C:\WINDOWS\system32\rqRKDtSj.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7545] command /c del "C:\WINDOWS\system32\tgjjuptw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3322] cmd /c del "C:\WINDOWS\system32\tgjjuptw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA220] command /c del "C:\WINDOWS\system32\jkkJaxYO.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2529] cmd /c del "C:\WINDOWS\system32\jkkJaxYO.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7605] command /c del "C:\WINDOWS\system32\wsnpoem\audio.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6756] cmd /c del "C:\WINDOWS\system32\wsnpoem\audio.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2114] command /c del "C:\WINDOWS\system32\wsnpoem\video.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1194] cmd /c del "C:\WINDOWS\system32\wsnpoem\video.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4559] command /c del "C:\WINDOWS\system32\rqRKDtSj.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1207] cmd /c del "C:\WINDOWS\system32\rqRKDtSj.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7689] command /c del "C:\WINDOWS\system32\tgjjuptw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7225] cmd /c del "C:\WINDOWS\system32\tgjjuptw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB7735] command /c del "C:\Documents and Settings\L.Koningen\Application Data\ultra\ultra.inf"
O4 - HKCU\..\RunOnce: [SpybotDeletingD859] cmd /c del "C:\Documents and Settings\L.Koningen\Application Data\ultra\ultra.inf"
O4 - HKCU\..\RunOnce: [SpybotDeletingB238] command /c del "C:\WINDOWS\system32\rqRKDtSj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3158] cmd /c del "C:\WINDOWS\system32\rqRKDtSj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5465] command /c del "C:\WINDOWS\system32\tgjjuptw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7016] cmd /c del "C:\WINDOWS\system32\tgjjuptw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3365] command /c del "C:\WINDOWS\system32\jkkJaxYO.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4468] cmd /c del "C:\WINDOWS\system32\jkkJaxYO.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4731] command /c del "C:\WINDOWS\system32\wsnpoem\audio.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6063] cmd /c del "C:\WINDOWS\system32\wsnpoem\audio.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4256] command /c del "C:\WINDOWS\system32\wsnpoem\video.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1937] cmd /c del "C:\WINDOWS\system32\wsnpoem\video.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6750] command /c del "C:\WINDOWS\system32\rqRKDtSj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8154] cmd /c del "C:\WINDOWS\system32\rqRKDtSj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2068] command /c del "C:\WINDOWS\system32\tgjjuptw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD813] cmd /c del "C:\WINDOWS\system32\tgjjuptw.dll_old"
O4 - HKLM\..\Policies\Explorer\Run: [Dc5h4Y1Kza] C:\Documents and Settings\All Users\Application Data\ehuvehqt\olkjmdsp.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe (User '?')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe (User 'Default user')
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Adobe Reader Snelle start.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://cdn.drivecleaner.com/installdrivecleanerstart_nl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by109w.bay109.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1138974549875
O16 - DPF: {B0A2C7FC-8666-44D6-A990-2FCE3B933341} (ING Bank Autorisatiescherm) - https://secure.ingbank.nl/download/DigiSign.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\wowfx.dll
O20 - Winlogon Notify: crypt - C:\WINDOWS\SYSTEM32\crypts.dll
O20 - Winlogon Notify: WinNt32 - C:\WINDOWS\SYSTEM32\WinNt32.dll
O21 - SSODL: IaNzImnw - {205919F0-8AF3-B35A-DDEB-26E059C28FCA} - C:\WINDOWS\system32\rbe.dll
O21 - SSODL: WebProxy - {66186F05-BBBB-4a39-864F-72D84615C679} - sockots64.dll (file missing)
O21 - SSODL: mpfanvqg - {D7CF407F-4893-4D78-8D51-CFDE70120749} - C:\WINDOWS\mpfanvqg.dll (file missing)
O21 - SSODL: vbksrofa - {BA6FA5D3-0170-47FE-9542-D27D9FA2CAC2} - C:\WINDOWS\vbksrofa.dll (file missing)
O21 - SSODL: oledll - {12345B67-1234-1234-D123-7F84D123BC7D} - C:\WINDOWS\system32\wm1dap.dll
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: Googles Onlines Search Services - Unknown owner - C:\WINDOWS\system32\wnslogan.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ICF - Unknown owner - C:\WINDOWS\system32\icf.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Wachtwoordvalidatie voor Symantec IS (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
O23 - Service: Office Source Engine oseanbmService (oseanbmservice) - Unknown owner - C:\WINDOWS\system32\dhcpd.exe
O23 - Service: Planner voor Automatische LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\spools.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
--
End of file - 13548 bytes
Nu heb ik met Spybot er al een aantal weten te verwijderen (ruime 200 problemen), maar het werkt nog niet helemaal goed.
Als je opstart, had je eerst al een melding van dat de computer infected was en dat je antivirus moest downloaden. Deze was volgens mij nu de laatste keer weg. Wil je inloggen, dan gebeurt er een hele tijd niets en na ongeveer een kwartier a 20 minuten krijg je dan een blauw scherm te zien, met geluk kan je dan Windows Taakbeheer openen en zo via bestand - nieuwe taak enkele programma's starten.
De taakbalk is nog steeds nergens te zien, systeemherstel kan ik helaas ook niet uitschakelen want krijg geen verkenner of configuratie scherm geopend.
Gelijk na het opstarten van taakbeheer, heb ik al een aantal vreemde processen afgesloten.
BraveSentry stond ook op de laptop, maar die is er hopelijk al af (weet het niet zeker). Verder zijn al een 100 redirected hosts door Spybot gevonden en opgelost (allemaal adressen van virusscanner bedrijven).
Adaware heb ik ook geprobeerd te installeren, maar dat is tot op heden nog niet gelukt.
Het internet zelf doet het nog wel, al krijg je internet explorer niet gestart (maar de programma's kunnen wel updaten, dus er is wel een internet verbinding actief).
Na de laatste spybot scan, toen sinds het opnieuw opstarten, is de syteemdatum en tijd ook veranderd (naar 2006), alleen is nog niet gelukt om dit te herstellen (want heb geen klok/taakbalk/configuratiescherm).
Veilige modus wil helemaal niet starten (komt niet verder dan een zwart scherm).
Hierbij de lijst van de HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:51:05, on 11-4-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\drivers\spools.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://c:/windows/homepage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = file://c:/windows/homepage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://internetsearchservice.com/ie6.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://c:/windows/homepage.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = file://c:/windows/homepage.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://internetsearchservice.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
O2 - BHO: (no name) - {a201888d-05ad-4019-af85-a7df73b56d47} - C:\WINDOWS\system32\rqRKDtSj.dll (file missing)
O3 - Toolbar: pvnsmfor - {89175504-FC6D-43A2-BB07-E3247659C95A} - C:\WINDOWS\pvnsmfor.dll (file missing)
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKLM\..\RunOnce: [SpyHunter3 BatchedRemoval] C:\Program Files\Enigma Software Group\SpyHunter\br.exe
O4 - HKLM\..\RunOnce: [SpybotDeletingA7549] command /c del "C:\Documents and Settings\L.Koningen\Application Data\ultra\ultra.inf"
O4 - HKLM\..\RunOnce: [SpybotDeletingC234] cmd /c del "C:\Documents and Settings\L.Koningen\Application Data\ultra\ultra.inf"
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA3908] command /c del "C:\WINDOWS\system32\rqRKDtSj.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9739] cmd /c del "C:\WINDOWS\system32\rqRKDtSj.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7545] command /c del "C:\WINDOWS\system32\tgjjuptw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3322] cmd /c del "C:\WINDOWS\system32\tgjjuptw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA220] command /c del "C:\WINDOWS\system32\jkkJaxYO.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC2529] cmd /c del "C:\WINDOWS\system32\jkkJaxYO.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7605] command /c del "C:\WINDOWS\system32\wsnpoem\audio.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6756] cmd /c del "C:\WINDOWS\system32\wsnpoem\audio.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2114] command /c del "C:\WINDOWS\system32\wsnpoem\video.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1194] cmd /c del "C:\WINDOWS\system32\wsnpoem\video.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4559] command /c del "C:\WINDOWS\system32\rqRKDtSj.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1207] cmd /c del "C:\WINDOWS\system32\rqRKDtSj.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7689] command /c del "C:\WINDOWS\system32\tgjjuptw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7225] cmd /c del "C:\WINDOWS\system32\tgjjuptw.dll_old"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB7735] command /c del "C:\Documents and Settings\L.Koningen\Application Data\ultra\ultra.inf"
O4 - HKCU\..\RunOnce: [SpybotDeletingD859] cmd /c del "C:\Documents and Settings\L.Koningen\Application Data\ultra\ultra.inf"
O4 - HKCU\..\RunOnce: [SpybotDeletingB238] command /c del "C:\WINDOWS\system32\rqRKDtSj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3158] cmd /c del "C:\WINDOWS\system32\rqRKDtSj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5465] command /c del "C:\WINDOWS\system32\tgjjuptw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7016] cmd /c del "C:\WINDOWS\system32\tgjjuptw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3365] command /c del "C:\WINDOWS\system32\jkkJaxYO.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4468] cmd /c del "C:\WINDOWS\system32\jkkJaxYO.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4731] command /c del "C:\WINDOWS\system32\wsnpoem\audio.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6063] cmd /c del "C:\WINDOWS\system32\wsnpoem\audio.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4256] command /c del "C:\WINDOWS\system32\wsnpoem\video.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1937] cmd /c del "C:\WINDOWS\system32\wsnpoem\video.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6750] command /c del "C:\WINDOWS\system32\rqRKDtSj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8154] cmd /c del "C:\WINDOWS\system32\rqRKDtSj.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2068] command /c del "C:\WINDOWS\system32\tgjjuptw.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD813] cmd /c del "C:\WINDOWS\system32\tgjjuptw.dll_old"
O4 - HKLM\..\Policies\Explorer\Run: [Dc5h4Y1Kza] C:\Documents and Settings\All Users\Application Data\ehuvehqt\olkjmdsp.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe (User '?')
O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe (User 'Default user')
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Adobe Reader Snelle start.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://cdn.drivecleaner.com/installdrivecleanerstart_nl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by109w.bay109.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1138974549875
O16 - DPF: {B0A2C7FC-8666-44D6-A990-2FCE3B933341} (ING Bank Autorisatiescherm) - https://secure.ingbank.nl/download/DigiSign.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\wowfx.dll
O20 - Winlogon Notify: crypt - C:\WINDOWS\SYSTEM32\crypts.dll
O20 - Winlogon Notify: WinNt32 - C:\WINDOWS\SYSTEM32\WinNt32.dll
O21 - SSODL: IaNzImnw - {205919F0-8AF3-B35A-DDEB-26E059C28FCA} - C:\WINDOWS\system32\rbe.dll
O21 - SSODL: WebProxy - {66186F05-BBBB-4a39-864F-72D84615C679} - sockots64.dll (file missing)
O21 - SSODL: mpfanvqg - {D7CF407F-4893-4D78-8D51-CFDE70120749} - C:\WINDOWS\mpfanvqg.dll (file missing)
O21 - SSODL: vbksrofa - {BA6FA5D3-0170-47FE-9542-D27D9FA2CAC2} - C:\WINDOWS\vbksrofa.dll (file missing)
O21 - SSODL: oledll - {12345B67-1234-1234-D123-7F84D123BC7D} - C:\WINDOWS\system32\wm1dap.dll
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: Googles Onlines Search Services - Unknown owner - C:\WINDOWS\system32\wnslogan.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: ICF - Unknown owner - C:\WINDOWS\system32\icf.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Wachtwoordvalidatie voor Symantec IS (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\NPROTECT.EXE
O23 - Service: Office Source Engine oseanbmService (oseanbmservice) - Unknown owner - C:\WINDOWS\system32\dhcpd.exe
O23 - Service: Planner voor Automatische LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\spools.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~3\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
--
End of file - 13548 bytes
Comment