Mededeling

Collapse
No announcement yet.

angels****ed.com

Collapse
X
  •  
  • Filter
  • Tijd
  • Show
Clear All
new posts

  • angels****ed.com

    Kan er iemand hier naar mijn log kijken?
    IK hoop dat dit de juiste plaats is.
    Logfile of HijackThis v1.99.0
    Scan saved at 11:38:20, on 30-12-2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Norton Internet Security\ISSVC.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\PROGRA~1\HARDWA~1\Keyboard\Ikeymain.exe
    C:\PROGRA~1\HARDWA~1\Mouse\Amoumain.exe
    C:\PROGRA~1\AGROVI~1\Ibms\CMVTaak.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Rabotwin\RaboComm\RaboSessionMon.exe
    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\RaboCommSrv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\hijackthis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://angels****ed.com/se.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://angels****ed.com/se.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://angels****ed.com/se.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\Ipswitch\WS_FTP Home\wsbho2k0.dll
    O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
    O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\HARDWA~1\Keyboard\Ikeymain.exe
    O4 - HKLM\..\Run: [WheelMouse] C:\PROGRA~1\HARDWA~1\Mouse\Amoumain.exe
    O4 - HKLM\..\Run: [Agrovision taakplanner] C:\PROGRA~1\AGROVI~1\Ibms\CMVTaak.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O4 - Global Startup: Rabo Session Monitor.lnk = C:\Program Files\Rabotwin\RaboComm\RaboSessionMon.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O16 - DPF: {11120607-1001-1111-1000-110199901123} - ms-its:mhtml:file://C:\foo.mht!http://rubli.biz/xxx.chm::/dropper.exe
    O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: ISSvc - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Rabo Comm Server - Unknown - C:\WINDOWS\System32\RaboCommSrv.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    alvast bedankt.

  • #2
    even nog een aanvulling.
    als angels****ed.com wordt geopend verschijnt er ook een melding dat er een virus is gevonden.
    en wel downloader.trojan

    Comment


    • #3
      Hallo GertH,


      1. Scan met HijackThis en vink de volgende items aan:

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://angels****ed.com/se.html
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://angels****ed.com/se.html
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://angels****ed.com/se.html

      O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
      O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

      O16 - DPF: {11120607-1001-1111-1000-110199901123} - ms-its:mhtml:file://C:\foo.mht!http://rubli.biz/xxx.chm::/dropper.exe
      Sluit alle vensters behalve HijackThis zelf en klik op "Fix checked".

      2. Installeer AdAware SE Personal 1.05: http://www.nucia.eu/adaware/handleiding.html
      Haal de nieuwste updates op, doe de volledige scan, laat alles verwijderen wat wordt gevonden.

      3. Start de pc opnieuw op.

      4. Maak een nieuw HijackThis-log en plaats dat hier.

      Comment


      • #4
        heb deze items aangevinkt en gefixed.
        direct kwam de melding van een gevonden virus.
        bloodhound.exploit
        na oke de melding dat hij niet kon worden verwijderd omdat ie niet aangetroffen was.

        vervolgens adware en hier dan de nLogfile of HijackThis v1.99.0
        Scan saved at 17:42:20, on 30-12-2004
        Platform: Windows XP SP1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
        C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
        C:\Program Files\Norton Internet Security\ISSVC.exe
        C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
        C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
        C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\Common Files\Symantec Shared\ccApp.exe
        C:\PROGRA~1\HARDWA~1\Keyboard\Ikeymain.exe
        C:\PROGRA~1\HARDWA~1\Mouse\Amoumain.exe
        C:\PROGRA~1\AGROVI~1\Ibms\CMVTaak.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\WINDOWS\System32\ctfmon.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\Program Files\Rabotwin\RaboComm\RaboSessionMon.exe
        C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
        C:\WINDOWS\System32\nvsvc32.exe
        C:\WINDOWS\System32\RaboCommSrv.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
        C:\WINDOWS\System32\wuauclt.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
        C:\Program Files\hijackthis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://angels****ed.com/se.html
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://angels****ed.com/se.html
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://angels****ed.com/se.html
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
        O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\Ipswitch\WS_FTP Home\wsbho2k0.dll
        O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
        O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
        O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
        O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
        O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
        O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\HARDWA~1\Keyboard\Ikeymain.exe
        O4 - HKLM\..\Run: [WheelMouse] C:\PROGRA~1\HARDWA~1\Mouse\Amoumain.exe
        O4 - HKLM\..\Run: [Agrovision taakplanner] C:\PROGRA~1\AGROVI~1\Ibms\CMVTaak.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
        O4 - Global Startup: Rabo Session Monitor.lnk = C:\Program Files\Rabotwin\RaboComm\RaboSessionMon.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
        O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
        O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
        O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
        O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
        O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
        O23 - Service: ISSvc - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
        O23 - Service: Norton AntiVirus Auto-Protect Service - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
        O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
        O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
        O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
        O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
        O23 - Service: Symantec SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
        O23 - Service: Rabo Comm Server - Unknown - C:\WINDOWS\System32\RaboCommSrv.exe
        O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

        groetjes

        Comment


        • #5
          Trek je niets aan van de meldingen van Norton van "Bloodhound.exploit.6".

          Laat deze items nog eens fixen door HijackThis:

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://angels****ed.com/se.html
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://angels****ed.com/se.html
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://angels****ed.com/se.html
          Start de pc opnieuw op, scan weer met HijackThis en kijk of ze zijn teruggekomen. Laat me het weten.

          Comment


          • #6
            ze zijn dr nog
            Logfile of HijackThis v1.99.0
            Scan saved at 18:19:09, on 30-12-2004
            Platform: Windows XP SP1 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
            C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
            C:\Program Files\Norton Internet Security\ISSVC.exe
            C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
            C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
            C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\SOUNDMAN.EXE
            C:\Program Files\Common Files\Symantec Shared\ccApp.exe
            C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
            C:\PROGRA~1\HARDWA~1\Keyboard\Ikeymain.exe
            C:\PROGRA~1\HARDWA~1\Mouse\Amoumain.exe
            C:\PROGRA~1\AGROVI~1\Ibms\CMVTaak.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\WINDOWS\System32\ctfmon.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\Program Files\Rabotwin\RaboComm\RaboSessionMon.exe
            C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
            C:\WINDOWS\System32\nvsvc32.exe
            C:\WINDOWS\System32\RaboCommSrv.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
            C:\WINDOWS\System32\wuauclt.exe
            C:\WINDOWS\System32\wuauclt.exe
            C:\Program Files\hijackthis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://angels****ed.com/se.html
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://angels****ed.com/se.html
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://angels****ed.com/se.html
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
            O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\Ipswitch\WS_FTP Home\wsbho2k0.dll
            O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
            O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
            O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
            O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
            O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
            O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
            O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
            O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\HARDWA~1\Keyboard\Ikeymain.exe
            O4 - HKLM\..\Run: [WheelMouse] C:\PROGRA~1\HARDWA~1\Mouse\Amoumain.exe
            O4 - HKLM\..\Run: [Agrovision taakplanner] C:\PROGRA~1\AGROVI~1\Ibms\CMVTaak.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
            O4 - Global Startup: Rabo Session Monitor.lnk = C:\Program Files\Rabotwin\RaboComm\RaboSessionMon.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
            O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
            O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
            O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
            O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
            O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
            O23 - Service: ISSvc - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
            O23 - Service: Norton AntiVirus Auto-Protect Service - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
            O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
            O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
            O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
            O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
            O23 - Service: Symantec SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
            O23 - Service: Rabo Comm Server - Unknown - C:\WINDOWS\System32\RaboCommSrv.exe
            O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

            Comment


            • #7
              Dan is er dus een boosdoener actief die niet in het log te zien is.


              Laten we eerst het volgende proberen:

              Download en installeer Registrar Lite: http://www.resplendence.com/download/reglite.exe
              Start dit programma.
              Kopieer de onderstaande vetgedrukte regel en plak deze in de balk bij "Address":

              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs

              Druk op Enter.
              Dubbelklik op AppInit_DLLs om de Data editor te openen.
              Onderaan dit venster zie je het veld "Value".
              Kijk of in dat veld de naam van een dll-bestand staat.
              Schrijf de volledige naam van het pad op waar deze dll file zich bevindt. Doe dit heel precies, maak geen fouten. (Kopieer en plak het eventueel in txt-bestand.)
              Sluit Registrar Lite.

              Plaats hier in je volgende bericht exact wat je bij "Value" aantrof.

              Comment


              • #8
                hier staat niks

                Comment


                • #9
                  Start HijackThis.
                  Kies "Misc Tools".
                  Zet een vinkje voor "List also minor sections (full)" en ook een vinkje voor "List empty sections (complete)".
                  Klik "Generate StartupList".

                  Kladblok zal openen met een tamelijk lang logbestand erin. Kopieer dat volledig en plak het hier in je volgende bericht.

                  Comment


                  • #10
                    oke hier is ieStartupList report, 30-12-2004, 19:11:14
                    StartupList version: 1.52.2
                    Started from : C:\Program Files\hijackthis.EXE
                    Detected: Windows XP SP1 (WinNT 5.01.2600)
                    Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
                    * Using default options
                    * Including empty and uninteresting sections
                    * Showing rarely important sections
                    ==================================================

                    Running processes:

                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                    C:\Program Files\Norton Internet Security\ISSVC.exe
                    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\WINDOWS\SOUNDMAN.EXE
                    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                    C:\PROGRA~1\HARDWA~1\Keyboard\Ikeymain.exe
                    C:\PROGRA~1\HARDWA~1\Mouse\Amoumain.exe
                    C:\PROGRA~1\AGROVI~1\Ibms\CMVTaak.exe
                    C:\Program Files\QuickTime\qttask.exe
                    C:\WINDOWS\System32\ctfmon.exe
                    C:\Program Files\Messenger\msmsgs.exe
                    C:\Program Files\Rabotwin\RaboComm\RaboSessionMon.exe
                    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                    C:\WINDOWS\System32\nvsvc32.exe
                    C:\WINDOWS\System32\RaboCommSrv.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
                    C:\WINDOWS\System32\wuauclt.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\WINDOWS\System32\wuauclt.exe
                    C:\Program Files\hijackthis.exe

                    --------------------------------------------------

                    Listing of startup folders:

                    Shell folders Startup:
                    [C:\Documents and Settings\Gert & Ans\Menu Start\Programma's\Opstarten]
                    *No files*

                    Shell folders AltStartup:
                    *Folder not found*

                    User shell folders Startup:
                    *Folder not found*

                    User shell folders AltStartup:
                    *Folder not found*

                    Shell folders Common Startup:
                    [C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten]
                    Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                    Rabo Session Monitor.lnk = C:\Program Files\Rabotwin\RaboComm\RaboSessionMon.exe

                    Shell folders Common AltStartup:
                    *Folder not found*

                    User shell folders Common Startup:
                    *Folder not found*

                    User shell folders Alternate Common Startup:
                    *Folder not found*

                    --------------------------------------------------

                    Checking Windows NT UserInit:

                    [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                    UserInit = C:\WINDOWS\system32\userinit.exe,

                    [HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
                    *Registry key not found*

                    [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                    *Registry value not found*

                    [HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
                    *Registry key not found*

                    --------------------------------------------------

                    Autorun entries from Registry:
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

                    SoundMan = SOUNDMAN.EXE
                    NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                    nwiz = nwiz.exe /install
                    ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                    SSC_UserPrompt = C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
                    NeroCheck = C:\WINDOWS\system32\NeroCheck.exe
                    Symantec NetDriver Monitor = C:\PROGRA~1\SYMNET~1\SNDMon.exe
                    iKeyWorks = C:\PROGRA~1\HARDWA~1\Keyboard\Ikeymain.exe
                    WheelMouse = C:\PROGRA~1\HARDWA~1\Mouse\Amoumain.exe
                    Agrovision taakplanner = C:\PROGRA~1\AGROVI~1\Ibms\CMVTaak.exe
                    QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime

                    --------------------------------------------------

                    Autorun entries from Registry:
                    HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

                    *No values found*

                    --------------------------------------------------

                    Autorun entries from Registry:
                    HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

                    *No values found*

                    --------------------------------------------------

                    Autorun entries from Registry:
                    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

                    *Registry key not found*

                    --------------------------------------------------

                    Autorun entries from Registry:
                    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

                    *Registry key not found*

                    --------------------------------------------------

                    Autorun entries from Registry:
                    HKCU\Software\Microsoft\Windows\CurrentVersion\Run

                    CTFMON.EXE = C:\WINDOWS\System32\ctfmon.exe
                    MSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /background

                    --------------------------------------------------

                    Autorun entries from Registry:
                    HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

                    *Registry key not found*

                    --------------------------------------------------

                    Autorun entries from Registry:
                    HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

                    *Registry key not found*

                    --------------------------------------------------

                    Autorun entries from Registry:
                    HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

                    *Registry key not found*

                    --------------------------------------------------

                    Autorun entries from Registry:
                    HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

                    *Registry key not found*

                    --------------------------------------------------

                    Autorun entries from Registry:
                    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

                    *Registry key not found*

                    --------------------------------------------------

                    Autorun entries from Registry:
                    HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

                    *Registry key not found*

                    --------------------------------------------------

                    Autorun entries in Registry subkeys of:
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

                    [OptionalComponents]
                    *No values found*

                    --------------------------------------------------

                    Autorun entries in Registry subkeys of:
                    HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
                    *No subkeys found*

                    --------------------------------------------------

                    Autorun entries in Registry subkeys of:
                    HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
                    *No subkeys found*

                    --------------------------------------------------

                    Autorun entries in Registry subkeys of:
                    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
                    *Registry key not found*

                    --------------------------------------------------

                    Autorun entries in Registry subkeys of:
                    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
                    *Registry key not found*

                    --------------------------------------------------

                    Autorun entries in Registry subkeys of:
                    HKCU\Software\Microsoft\Windows\CurrentVersion\Run
                    *No subkeys found*

                    --------------------------------------------------

                    Autorun entries in Registry subkeys of:
                    HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
                    *Registry key not found*

                    --------------------------------------------------

                    Autorun entries in Registry subkeys of:
                    HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
                    *Registry key not found*

                    --------------------------------------------------

                    Autorun entries in Registry subkeys of:
                    HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
                    *Registry key not found*

                    --------------------------------------------------

                    Autorun entries in Registry subkeys of:
                    HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
                    *Registry key not found*

                    --------------------------------------------------

                    Autorun entries in Registry subkeys of:
                    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
                    *Registry key not found*

                    --------------------------------------------------

                    Autorun entries in Registry subkeys of:
                    HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
                    *Registry key not found*

                    --------------------------------------------------

                    File association entry for .EXE:
                    HKEY_CLASSES_ROOT\exefile\shell\open\command

                    (Default) = "%1" %*

                    --------------------------------------------------

                    File association entry for .COM:
                    HKEY_CLASSES_ROOT\comfile\shell\open\command

                    (Default) = "%1" %*

                    --------------------------------------------------

                    File association entry for .BAT:
                    HKEY_CLASSES_ROOT\batfile\shell\open\command

                    (Default) = "%1" %*

                    --------------------------------------------------

                    File association entry for .PIF:
                    HKEY_CLASSES_ROOT\piffile\shell\open\command

                    (Default) = "%1" %*

                    --------------------------------------------------

                    File association entry for .SCR:
                    HKEY_CLASSES_ROOT\scrfile\shell\open\command

                    (Default) = "%1" /S

                    --------------------------------------------------

                    File association entry for .HTA:
                    HKEY_CLASSES_ROOT\htafile\shell\open\command

                    (Default) = C:\WINDOWS\System32\mshta.exe "%1" %*

                    --------------------------------------------------

                    File association entry for .TXT:
                    HKEY_CLASSES_ROOT\txtfile\shell\open\command

                    (Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

                    --------------------------------------------------

                    Enumerating Active Setup stub paths:
                    HKLM\Software\Microsoft\Active Setup\Installed Components
                    (* = disabled by HKCU twin)

                    [>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
                    StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

                    [>{26923b43-4d38-484f-9b9e-de460746276c}] *
                    StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

                    [>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
                    StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

                    [>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
                    StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

                    [{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
                    StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

                    [{306D6C21-C1B6-4629-986C-E59E1875B8AF}]
                    StubPath = "C:\WINDOWS\System32\rundll32.exe" "C:\Program Files\Messenger\msgsc.dll",ShowIconsUser

                    [{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
                    StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

                    [{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
                    StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

                    [{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
                    StubPath = rundll32.exe advpack.dll,LaunchINFSection %SystemRoot%\INF\msmsgs.inf,BLC.Install.PerUser

                    [{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
                    StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub

                    [{7790769C-0471-11d2-AF11-00C04FA35D02}] *
                    StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

                    [{89820200-ECBD-11cf-8B85-00AA005B4340}] *
                    StubPath = regsvr32.exe /s /n /i:U shell32.dll

                    [{89820200-ECBD-11cf-8B85-00AA005B4383}] *
                    StubPath = %SystemRoot%\system32\ie4uinit.exe

                    --------------------------------------------------

                    Enumerating ICQ Agent Autostart apps:
                    HKCU\Software\Mirabilis\ICQ\Agent\Apps

                    *Registry key not found*

                    --------------------------------------------------

                    Load/Run keys from C:\WINDOWS\WIN.INI:

                    load=*INI section not found*
                    run=*INI section not found*

                    Load/Run keys from Registry:

                    HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
                    HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
                    HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
                    HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
                    HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
                    HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
                    HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
                    HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
                    HKCU\..\Windows NT\CurrentVersion\Windows: load=
                    HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
                    HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
                    HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
                    HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

                    --------------------------------------------------

                    Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

                    Shell=*INI section not found*
                    SCRNSAVE.EXE=*INI section not found*
                    drivers=*INI section not found*

                    Shell & screensaver key from Registry:

                    Shell=Explorer.exe
                    SCRNSAVE.EXE=C:\WINDOWS\System32\logon.scr
                    drivers=*Registry value not found*

                    Policies Shell key:

                    HKCU\..\Policies: Shell=*Registry key not found*
                    HKLM\..\Policies: Shell=*Registry value not found*

                    --------------------------------------------------

                    Checking for EXPLORER.EXE instances:

                    C:\WINDOWS\Explorer.exe: PRESENT!

                    C:\Explorer.exe: not present
                    C:\WINDOWS\Explorer\Explorer.exe: not present
                    C:\WINDOWS\System\Explorer.exe: not present
                    C:\WINDOWS\System32\Explorer.exe: not present
                    C:\WINDOWS\Command\Explorer.exe: not present
                    C:\WINDOWS\Fonts\Explorer.exe: not present

                    --------------------------------------------------

                    Checking for superhidden extensions:

                    .lnk: HIDDEN! (arrow overlay: yes)
                    .pif: HIDDEN! (arrow overlay: yes)
                    .exe: not hidden
                    .com: not hidden
                    .bat: not hidden
                    .hta: not hidden
                    .scr: not hidden
                    .shs: HIDDEN!
                    .shb: HIDDEN!
                    .vbs: not hidden
                    .vbe: not hidden
                    .wsh: not hidden
                    .scf: HIDDEN! (arrow overlay: NO!)
                    .url: HIDDEN! (arrow overlay: yes)
                    .js: not hidden
                    .jse: not hidden

                    --------------------------------------------------

                    Verifying REGEDIT.EXE integrity:

                    - Regedit.exe found in C:\WINDOWS
                    - .reg open command is normal (regedit.exe %1)
                    - Company name OK: 'Microsoft Corporation'
                    - Original filename OK: 'REGEDIT.EXE'
                    - File description: 'Register-editor'

                    Registry check passed

                    --------------------------------------------------

                    Enumerating Browser Helper Objects:

                    (no name) - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
                    Ipswitch.WsftpBrowserHelper - C:\Program Files\Ipswitch\WS_FTP Home\wsbho2k0.dll - {601ED020-FB6C-11D3-87D8-0050DA59922B}
                    Norton Internet Security - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll - {9ECB9560-04F9-4bbc-943D-298DDF1699E1}
                    NAV Helper - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}

                    --------------------------------------------------

                    Enumerating Task Scheduler jobs:

                    Norton AntiVirus - Scan my computer - Gert & Ans.job
                    Symantec NetDetect.job

                    --------------------------------------------------

                    Enumerating Download Program Files:

                    [QuickTime Object]
                    InProcServer32 = C:\Program Files\QuickTime\QTPlugin.ocx
                    CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab

                    [Shockwave Flash Object]
                    InProcServer32 = C:\WINDOWS\System32\macromed\flash\Flash.ocx
                    CODEBASE = http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

                    --------------------------------------------------

                    Enumerating Winsock LSP files:

                    NameSpace #1: C:\WINDOWS\System32\mswsock.dll
                    NameSpace #2: C:\WINDOWS\System32\winrnr.dll
                    NameSpace #3: C:\WINDOWS\System32\mswsock.dll
                    Protocol #1: C:\WINDOWS\system32\mswsock.dll
                    Protocol #2: C:\WINDOWS\system32\mswsock.dll
                    Protocol #3: C:\WINDOWS\system32\mswsock.dll
                    Protocol #4: C:\WINDOWS\system32\rsvpsp.dll
                    Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
                    Protocol #6: C:\WINDOWS\system32\mswsock.dll
                    Protocol #7: C:\WINDOWS\system32\mswsock.dll
                    Protocol #8: C:\WINDOWS\system32\mswsock.dll
                    Protocol #9: C:\WINDOWS\system32\mswsock.dll
                    Protocol #10: C:\WINDOWS\system32\mswsock.dll
                    Protocol #11: C:\WINDOWS\system32\mswsock.dll
                    Protocol #12: C:\WINDOWS\system32\mswsock.dll
                    Protocol #13: C:\WINDOWS\system32\mswsock.dll
                    Protocol #14: C:\WINDOWS\system32\mswsock.dll
                    Protocol #15: C:\WINDOWS\system32\mswsock.dll

                    --------------------------------------------------

                    Enumerating Windows NT/2000/XP services

                    Microsoft ACPI-stuurprogramma: System32\DRIVERS\ACPI.sys (system)
                    Microsoft Kernel akoestische echo-opheffing: system32\drivers\aec.sys (manual start)
                    Omgeving voor AFD-netwerkondersteuning: \SystemRoot\System32\drivers\afd.sys (autostart)
                    Intel AGP Bus Filter: System32\DRIVERS\agp440.sys (system)
                    Service for WDM 3D Audio Driver: system32\drivers\ALCXSENS.SYS (manual start)
                    Service for Realtek AC97 Audio (WDM): system32\drivers\ALCXWDM.SYS (manual start)
                    Alerter: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
                    Application Layer Gateway-service: %SystemRoot%\System32\alg.exe (manual start)
                    Compatible PS/2 Port Mouse Driver: System32\DRIVERS\Amps2prt.sys (manual start)
                    Application Management: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
                    Stuurprogramma voor RAS asyncrone media: System32\DRIVERS\asyncmac.sys (manual start)
                    Standaard IDE/ESDI-vasteschijfcontroller: System32\DRIVERS\atapi.sys (system)
                    ATM ARP-client-protocol: System32\DRIVERS\atmarpc.sys (manual start)
                    Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
                    Audiostub-stuurprogramma: System32\DRIVERS\audstub.sys (manual start)
                    Intelligente achtergrondsoverdrachtservice: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
                    Computer Browser: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
                    Symantec Event Manager: "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe" (autostart)
                    Symantec Network Proxy: "C:\Program Files\Common Files\Symantec Shared\ccProxy.exe" (autostart)
                    Symantec Password Validation: "C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe" (manual start)
                    Symantec Settings Manager: "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe" (autostart)
                    Cd-rom-stuurprogramma: System32\DRIVERS\cdrom.sys (system)
                    Indexing-service: %SystemRoot%\system32\cisvc.exe (manual start)
                    ClipBook: %SystemRoot%\system32\clipsrv.exe (manual start)
                    COM+-systeemtoepassing: C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
                    Services voor cryptografie: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
                    DHCP Client: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
                    Stuurprogramma voor schijfstations: System32\DRIVERS\disk.sys (system)
                    Logical Disk Manager Administrative-service: %SystemRoot%\System32\dmadmin.exe /com (manual start)
                    dmboot: System32\drivers\dmboot.sys (disabled)
                    dmio: System32\drivers\dmio.sys (disabled)
                    dmload: System32\drivers\dmload.sys (disabled)
                    Logical Disk Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
                    Microsoft Kernel DLS-synthesizer: system32\drivers\DMusic.sys (manual start)
                    DNS Client: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart)
                    Microsoft IEEE-1284.4-stuurprogramma: System32\DRIVERS\Dot4.sys (manual start)
                    Stuurprogramma voor printerklasse voor IEEE-1284.4: System32\DRIVERS\Dot4Prt.sys (manual start)
                    Stuurprogramma voor scannerklasse voor IEEE-1284.4: System32\DRIVERS\Dot4Scan.sys (manual start)
                    Microsoft Kernel DRM-audiodecoder: system32\drivers\drmkaud.sys (manual start)
                    Service voor het rapporteren van fouten: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
                    Event Log: %SystemRoot%\system32\services.exe (autostart)
                    COM+-gebeurtenissysteem: C:\WINDOWS\System32\svchost.exe -k netsvcs (manual start)
                    EzInstall: \??\E:\ezinstall\EzInstall.sys (manual start)
                    Compatibiliteit voor Snelle gebruikerswisseling: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
                    Stuurprogramma voor diskettestationcontroller: System32\DRIVERS\fdc.sys (manual start)
                    Stuurprogramma voor diskettestation: System32\DRIVERS\flpydisk.sys (manual start)
                    Stuurprogramma voor Volumebeheer: System32\DRIVERS\ftdisk.sys (system)
                    Spelpoort-enumerator: System32\DRIVERS\gameenum.sys (manual start)
                    Algemene pakketclassificeerder: System32\DRIVERS\msgpc.sys (manual start)
                    Help en ondersteuning: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
                    Apparaattoegang via menselijke interface: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
                    Stuurprogramma voor i8042-toetsenbord en PS/2-muispoort: System32\DRIVERS\i8042prt.sys (system)
                    Filterstuurprogramma voor het branden van cd's: System32\DRIVERS\imapi.sys (system)
                    COM-service voor IMAPI cd-branders: C:\WINDOWS\System32\imapi.exe (manual start)
                    IP Traffic Filter Driver: System32\DRIVERS\ipfltdrv.sys (manual start)
                    IP in IP Tunnel Driver: System32\DRIVERS\ipinip.sys (manual start)
                    IP Network Address Translator: System32\DRIVERS\ipnat.sys (manual start)
                    IPSEC-stuurprogramma: System32\DRIVERS\ipsec.sys (system)
                    IR Enumerator-service: System32\DRIVERS\irenum.sys (manual start)
                    PnP ISA/EISA Bus-stuurprogramma: System32\DRIVERS\isapnp.sys (system)
                    ISSvc: C:\Program Files\Norton Internet Security\ISSVC.exe (autostart)
                    Stuurprogramma voor verschillende toetsenbordtypen: System32\DRIVERS\kbdclass.sys (system)
                    Microsoft Kernel Wave-audiomixer: system32\drivers\kmixer.sys (manual start)
                    Server: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
                    Workstation: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
                    TCP/IP NetBIOS Helper: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
                    Messenger: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
                    NetMeeting Remote Desktop Sharing: C:\WINDOWS\System32\mnmsrvc.exe (manual start)
                    Stuurprogramma voor muistypen: System32\DRIVERS\mouclass.sys (system)
                    WebDav-client-redirector: System32\DRIVERS\mrxdav.sys (manual start)
                    MRXSMB: System32\DRIVERS\mrxsmb.sys (system)
                    Distributed Transaction Coordinator: C:\WINDOWS\System32\msdtc.exe (manual start)
                    Windows Installer: C:\WINDOWS\System32\msiexec.exe /V (manual start)
                    Microsoft Streaming Service-proxy: system32\drivers\MSKSSRV.sys (manual start)
                    Microsoft Streaming Clock-proxy: system32\drivers\MSPCLOCK.sys (manual start)
                    Microsoft Streaming Kwaliteitsbeheer Proxy: system32\drivers\MSPQM.sys (manual start)
                    Microsoft MPU-401 MIDI UART-stuurprogramma: system32\drivers\msmpu401.sys (manual start)
                    Norton AntiVirus Auto-Protect Service: "C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe" (autostart)
                    NAVENG: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20041229.035\NAVENG.Sys (manual start)
                    NAVEX15: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20041229.035\NavEx15.Sys (manual start)
                    RAS NDIS TAPI-stuurprogramma: System32\DRIVERS\ndistapi.sys (manual start)
                    I/O-protocol van NDIS-gebruikermodus: System32\DRIVERS\ndisuio.sys (manual start)
                    RAS NDIS WAN-stuurprogramma: System32\DRIVERS\ndiswan.sys (manual start)
                    NetBIOS-interface: System32\DRIVERS\netbios.sys (system)
                    NetBios over Tcpip: System32\DRIVERS\netbt.sys (system)
                    Network DDE: %SystemRoot%\system32\netdde.exe (manual start)
                    Network DDE DSDM: %SystemRoot%\system32\netdde.exe (manual start)
                    Net Logon: %SystemRoot%\System32\lsass.exe (manual start)
                    Network Connections: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
                    Network Location Awareness (NLA): %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
                    NT LM Security Support Provider: %SystemRoot%\System32\lsass.exe (manual start)
                    Verwisselbare opslag: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
                    nv: System32\DRIVERS\nv4_mini.sys (manual start)
                    NVIDIA Display Driver Service: %SystemRoot%\System32\nvsvc32.exe (autostart)
                    IPX Traffic Filter Driver: System32\DRIVERS\nwlnkflt.sys (manual start)
                    IPX Traffic Forwarder Driver: System32\DRIVERS\nwlnkfwd.sys (manual start)
                    Stuurprogramma voor parallelle poort: System32\DRIVERS\parport.sys (manual start)
                    PCI Bus-stuurprogramma: System32\DRIVERS\pci.sys (system)
                    PCIIde: System32\DRIVERS\pciide.sys (system)
                    Plug and Play: %SystemRoot%\system32\services.exe (autostart)
                    IPSEC-services: %SystemRoot%\System32\lsass.exe (autostart)
                    WAN-minipoort (PPTP): System32\DRIVERS\raspptp.sys (manual start)
                    Stuurprogramma voor processor: System32\DRIVERS\processr.sys (system)
                    Protected Storage: %SystemRoot%\system32\lsass.exe (autostart)
                    QoS-pakketplanner: System32\DRIVERS\psched.sys (manual start)
                    Stuurprogramma voor Directe parallelle verbinding: System32\DRIVERS\ptilink.sys (manual start)
                    Stuurprogramma voor Automatische verbinding voor RAS: System32\DRIVERS\rasacd.sys (system)
                    Remote Access Auto Connection Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
                    WAN-minipoort (L2TP): System32\DRIVERS\rasl2tp.sys (manual start)
                    Verbindingsbeheer voor RAS: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
                    PPPOE-RAS-stuurprogramma: System32\DRIVERS\raspppoe.sys (manual start)
                    Direct Parallel: System32\DRIVERS\raspti.sys (manual start)
                    Rdbss: System32\DRIVERS\rdbss.sys (system)
                    RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
                    Helpsessiebeheer voor Extern bureaublad: C:\WINDOWS\system32\sessmgr.exe (manual start)
                    Stuurprogramma voor afspeelfilter van digitale cd-audio: System32\DRIVERS\redbook.sys (system)
                    Routing and Remote Access: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
                    Remote Procedure Call (RPC) Locator: %SystemRoot%\System32\locator.exe (manual start)
                    Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
                    QoS RSVP: %SystemRoot%\System32\rsvp.exe (manual start)
                    Realtek RTL8139/810x Family Fast Ethernet NIC NT Driver: System32\DRIVERS\R8139n51.SYS (manual start)
                    Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
                    SAVRT: \??\C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT.SYS (manual start)
                    SAVRTPEL: \??\C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRTPEL.SYS (system)
                    SAVScan: C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe (manual start)
                    ScriptBlocking Service: C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe (autostart)
                    Smart Card Helper: %SystemRoot%\System32\SCardSvr.exe (manual start)
                    Smart Card: %SystemRoot%\System32\SCardSvr.exe (manual start)
                    Task Scheduler: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
                    Secdrv: System32\DRIVERS\secdrv.sys (manual start)
                    Secondary Logon: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
                    System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
                    Serenum Filter-stuurprogramma: System32\DRIVERS\serenum.sys (manual start)
                    Stuurprogramma voor seriële poort: System32\DRIVERS\serial.sys (system)
                    Internet Connection Firewall (ICF) / Internet Connection Sharing (ICS): %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
                    Shell Hardware Detection: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
                    Symantec Network Drivers Service: C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (autostart)
                    SPBBCDrv: \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (system)
                    Symantec SPBBCSvc: C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (autostart)
                    Microsoft Kernel-audiosplitsing: system32\drivers\splitter.sys (manual start)
                    Print Spooler: %SystemRoot%\system32\spoolsv.exe (autostart)
                    Stuurprogramma voor systeemherstelfilter: System32\DRIVERS\sr.sys (system)
                    System Restore-service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
                    SRV: System32\DRIVERS\srv.sys (manual start)
                    Rabo Comm Server: "C:\WINDOWS\System32\RaboCommSrv.exe" (autostart)
                    SSDP Discovery-service: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
                    Windows Image Acquisition (WIA): %SystemRoot%\System32\svchost.exe -k imgsvc (autostart)
                    Software Bus-stuurprogramma: System32\DRIVERS\swenum.sys (manual start)
                    Microsoft Kernel GS Wavetable-synthesizer: system32\drivers\swmidi.sys (manual start)
                    MS Software Shadow Copy Provider: C:\WINDOWS\System32\dllhost.exe /Processid:{C7E45067-56F8-4FDA-A1C9-FD801F995392} (manual start)
                    Symantec Core LC: C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (autostart)
                    SYMDNS: \SystemRoot\System32\Drivers\SYMDNS.SYS (manual start)
                    SymEvent: \??\C:\Program Files\Symantec\SYMEVENT.SYS (manual start)
                    SYMFW: \SystemRoot\System32\Drivers\SYMFW.SYS (manual start)
                    SYMIDS: \SystemRoot\System32\Drivers\SYMIDS.SYS (manual start)
                    SYMIDSCO: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\idsdefs\20041123.015\symidsco.sys (manual start)
                    symlcbrd: \??\C:\WINDOWS\System32\drivers\symlcbrd.sys (autostart)
                    SYMNDIS: \SystemRoot\System32\Drivers\SYMNDIS.SYS (manual start)
                    SYMREDRV: \SystemRoot\System32\Drivers\SYMREDRV.SYS (manual start)
                    SYMTDI: \SystemRoot\System32\Drivers\SYMTDI.SYS (system)
                    Microsoft Kernel-systeemaudioapparaat: system32\drivers\sysaudio.sys (manual start)
                    Performance Logs and Alerts: %SystemRoot%\system32\smlogsvc.exe (manual start)
                    Telephony: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
                    Stuurprogramma voor TCP/IP-protocol: System32\DRIVERS\tcpip.sys (system)
                    Stuurprogramma voor terminal-apparaat: System32\DRIVERS\termdd.sys (system)
                    Terminal Services: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
                    Thema's: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
                    Distributed Link Tracking Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
                    Microcode Update-stuurprogramma: System32\DRIVERS\update.sys (manual start)
                    Uploadbeheer: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
                    Universele Plug en Play-apparaathost: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
                    Uninterruptible Power Supply: %SystemRoot%\System32\ups.exe (manual start)
                    Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: System32\DRIVERS\usbehci.sys (manual start)
                    USB2 Enabled Hub: System32\DRIVERS\usbhub.sys (manual start)
                    Stuurprogramma voor USB-massaopslag: System32\DRIVERS\USBSTOR.SYS (manual start)
                    Microsoft USB Universal Host Controller Miniport Driver: System32\DRIVERS\usbuhci.sys (manual start)
                    VgaSave: \SystemRoot\System32\drivers\vga.sys (system)
                    Volume Shadow Copy: %SystemRoot%\System32\vssvc.exe (manual start)
                    Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
                    RAS IP ARP-stuurprogramma: System32\DRIVERS\wanarp.sys (manual start)
                    Stuurprogramma voor Microsoft WINMM WDM-audiocompatibiliteit: system32\drivers\wdmaud.sys (manual start)
                    ISDN PCI CAPI: System32\DRIVERS\WDMCAPI.sys (system)
                    NDIS WAN miniport: System32\DRIVERS\wdmwanmp.sys (manual start)
                    WebClient: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
                    WINFLASH: \??\C:\WINDOWS\System32\DRIVERS\WINFLASH.sys (manual start)
                    Windows Management Instrumentation: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
                    Serienummerservice voor draagbare media: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
                    WMI-prestatieadapter: C:\WINDOWS\System32\wbem\wmiapsrv.exe (manual start)
                    Automatische updates: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
                    Wireless Zero Configuration-service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)


                    --------------------------------------------------

                    Enumerating Windows NT logon/logoff scripts:
                    *No scripts set to run*

                    Windows NT checkdisk command:
                    BootExecute = autocheck autochk *

                    Windows NT 'Wininit.ini':
                    PendingFileRenameOperations: *Registry value not found*

                    --------------------------------------------------

                    Enumerating ShellServiceObjectDelayLoad items:

                    PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
                    CDBurn: C:\WINDOWS\system32\SHELL32.dll
                    WebCheck: C:\WINDOWS\System32\webcheck.dll
                    SysTray: C:\WINDOWS\System32\stobject.dll

                    --------------------------------------------------
                    Autorun entries from Registry:
                    HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

                    *Registry key not found*

                    --------------------------------------------------

                    Autorun entries from Registry:
                    HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

                    *Registry key not found*

                    --------------------------------------------------

                    End of report, 33.328 bytes
                    Report generated in 0,156 seconds

                    Command line options:
                    /verbose - to add additional info on each section
                    /complete - to include empty sections and unsuspicious data
                    /full - to include several rarely-important sections
                    /force9x - to include Win9x-only startups even if running on WinNT
                    /forcent - to include WinNT-only startups even if running on Win9x
                    /forceall - to include all Win9x and WinNT startups, regardless of platform
                    /history - to list version history only

                    Comment


                    • #11
                      Dat levert dus ook niets op.

                      Misschien zoek ik het wel te ver. Laten we iets eenvoudigers proberen, wie weet werkt het:

                      1. Download CCleaner alvast. Installeer het, maar gebruik het nog niet.
                      Link: http://www.ccleaner.com/

                      2. Download CWShredder alvast. Installeer het, maar gebruik het nog niet.
                      Link: http://cwshredder.net/bin/CWShredder.exe

                      3. Herstart de pc in veilige modus: http://www.virushelp.nl/veilige_modus.htm

                      * Scan nu (in veilige modus dus) met HijackThis en vink de volgende items aan:

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://angels****ed.com/se.html
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://angels****ed.com/se.html
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://angels****ed.com/se.html
                      Sluit alle vensters behalve HijackThis zelf en klik op "Fix checked".

                      * Draai (nog steeds in veilige modus) CWShredder. Gebruik de Fix knop.

                      * Start (nog steeds in veilige modus) CCleaner. Controleer of het tabblad Windows geselecteerd is (linksboven) en klik op "Run Cleaner" (rechtsonder).

                      4. Herstart de pc in 'normale modus'.

                      5. Maak een nieuw HijackThis-log en plaats dat hier.

                      Comment


                      • #12
                        Logfile of HijackThis v1.99.0
                        Scan saved at 9:42:44, on 31-12-2004
                        Platform: Windows XP SP1 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                        C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                        C:\Program Files\Norton Internet Security\ISSVC.exe
                        C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                        C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                        C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\WINDOWS\SOUNDMAN.EXE
                        C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                        C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
                        C:\PROGRA~1\HARDWA~1\Keyboard\Ikeymain.exe
                        C:\PROGRA~1\HARDWA~1\Mouse\Amoumain.exe
                        C:\PROGRA~1\AGROVI~1\Ibms\CMVTaak.exe
                        C:\Program Files\QuickTime\qttask.exe
                        C:\WINDOWS\System32\ctfmon.exe
                        C:\Program Files\Messenger\msmsgs.exe
                        C:\Program Files\Rabotwin\RaboComm\RaboSessionMon.exe
                        C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                        C:\WINDOWS\System32\nvsvc32.exe
                        C:\WINDOWS\System32\RaboCommSrv.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                        C:\WINDOWS\System32\wuauclt.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
                        C:\WINDOWS\System32\wuauclt.exe
                        d:\Mijn documenten\hijackthis.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://angels****ed.com/se.html
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://angels****ed.com/se.html
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://angels****ed.com/se.html
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                        O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\Ipswitch\WS_FTP Home\wsbho2k0.dll
                        O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
                        O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                        O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
                        O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                        O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
                        O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
                        O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
                        O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\HARDWA~1\Keyboard\Ikeymain.exe
                        O4 - HKLM\..\Run: [WheelMouse] C:\PROGRA~1\HARDWA~1\Mouse\Amoumain.exe
                        O4 - HKLM\..\Run: [Agrovision taakplanner] C:\PROGRA~1\AGROVI~1\Ibms\CMVTaak.exe
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
                        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                        O4 - Global Startup: Rabo Session Monitor.lnk = C:\Program Files\Rabotwin\RaboComm\RaboSessionMon.exe
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                        O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                        O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                        O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                        O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
                        O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                        O23 - Service: ISSvc - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
                        O23 - Service: Norton AntiVirus Auto-Protect Service - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                        O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                        O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                        O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
                        O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                        O23 - Service: Symantec SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                        O23 - Service: Rabo Comm Server - Unknown - C:\WINDOWS\System32\RaboCommSrv.exe
                        O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

                        Comment


                        • #13
                          Geen idee wat hier aan de hand is.


                          Download DLL Compare: http://www.atribune.org/downloads/DllCompare.exe
                          Plaats het in een eigen map.
                          Start DLL Compare.
                          Klik op "Locate.com".
                          Als het programma aangeeft dat de scan compleet is (in blauwe lettertjes), klik dan op "Compare".
                          Is die scan klaar, klik dan op "Make a log of what was found".
                          Open het log, kopieer het en plaats het hier in je volgende bericht.


                          Download SilentRunners: http://forums.techguy.org/attachment...chmentid=44795
                          Unzip het naar een eigen map.
                          Draai SilentRunners.vbs
                          Schrik niet: Norton zal waarschijnlijk alarm staan. Geef dan toestemming voor het draaien van dit script.
                          Er zal een tekstbestand worden aangemaakt. Kopieer dat en plaats ook dat in je volgende bericht.


                          Ik ben benieuwd of er iets aan het licht zal komen.

                          Comment


                          • #14
                            oke hier de 1e log rest komt zo.
                            * DLLCompare Log version(1.0.0.127)
                            Files Found that Windows does not See or cannot Access
                            *Not everything listed here means you are infected!
                            ________________________________________________

                            O^E says: "There were no files found "
                            ________________________________________________

                            1.157 items found: 1.157 files, 0 directories.
                            Total of file sizes: 229.839.507 bytes 219,19 M

                            Administrator Account = True

                            --------------------End log---------------------

                            Comment


                            • #15
                              als ik silent runners draai komt er een een text bestandje in beeld dat zo snel weer wegspringt dat ik geen tijd heb om te zien waar ik het heen geschreven is.

                              Comment

                              Sorry, you are not authorized to view this page
                              Working...
                              X