Mededeling

Collapse
No announcement yet.

VX2 probleem

Collapse
X
  •  
  • Tijd
  • Show
Clear All
new posts

  • VX2 probleem

    Eerst maar even configuratie,zeker ??

    Windows XP-pro(nederlnds) - SP2 - volledig up-too date

    HJT-log :

    Logfile of HijackThis v1.99.0
    Scan saved at 18:58:29, on 2-1-2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\WINDOWS\System32\CTSvcCDA.exe
    C:\Program Files\ewido\security suite\ewidoctrl.exe
    C:\Program Files\ewido\security suite\ewidoguard.exe
    C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
    C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
    C:\Program Files\Common Files\Stardock\SDMCP.exe
    C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Creative\ShareDLL\CtNotify.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Logitech\MouseWare\system\em_exec.exe
    C:\WINDOWS\Mixer.exe
    C:\Program Files\Creative\ShareDLL\MediaDet.Exe
    C:\WINDOWS\system32\ntsmod.exe
    C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\TrojanHunter 4.0\THGuard.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\GPSoftware\Directory Opus\dopus.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\CursorXP\CursorXP.exe
    C:\Program Files\NetMeter\NetMeter.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
    C:\Program Files\InterVideo\WinDVD4PR\WinScheduler.exe
    C:\Program Files\ICONDESK\IconDesk.exe
    C:\Program Files\SpywareGuard\sgmain.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
    C:\Program Files\SpywareGuard\sgbhp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
    C:\HJT\hijackthis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    R3 - Default URLSearchHook is missing
    O1 - Hosts: 69.20.16.183 auto.search.msn.com
    O1 - Hosts: 69.20.16.183 search.netscape.com
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O1 - Hosts: 69.20.16.183 ieautosearch
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
    O3 - Toolbar: PopUpCop - {DB43E4E6-FF8A-4018-8C8E-F68587A44A73} - C:\PROGRA~1\PopUpCop\PopUpCop.dll
    O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
    O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
    O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
    O4 - HKLM\..\Run: [CreativeMixer] C:\Program Files\Creative\Audio2K\PROGRAM\CTMIX32.EXE /t
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [ntsmod] C:\WINDOWS\system32\ntsmod.exe
    O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
    O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\Program Files\Stardock\WinCustomize\BootSkin\bootskin.exe" /StartupJobs
    O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.0\THGuard.exe"
    O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon.exe -AutoStart
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [DOpus] C:\Program Files\GPSoftware\Directory Opus\dopus.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
    O4 - HKCU\..\Run: [ScanSpyware] "C:\Program Files\ScanSpyware v3.8.0.4\Scanner.exe"
    O4 - HKCU\..\Run: [C:\Program Files\NetMeter\NetMeter.exe] C:\Program Files\NetMeter\NetMeter.exe
    O4 - Startup: ICONDESK.lnk = C:\Program Files\ICONDESK\IconDesk.exe
    O4 - Startup: Rainlendar.lnk = C:\Program Files\Rainlendar\Rainlendar.exe
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: hp psc 1000 series.lnk = ?
    O4 - Global Startup: hpoddt01.exe.lnk = ?
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O4 - Global Startup: InterVideo WinScheduler.lnk = C:\Program Files\InterVideo\WinDVD4PR\WinScheduler.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: SnagIt 7.lnk = C:\Program Files\TechSmith\SnagIt 7\SnagIt32.exe
    O4 - Global Startup: SymmTime.lnk = ?
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Open Image in New Window - res://C:\Program Files\PopUpCop\popupcop.dll/imagenew
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://simcity.ea.com/update/EARTPX.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1102608662085
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
    O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.exe
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
    O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
    O23 - Service: iPod-service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Norton AntiVirus Auto-Protect - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
    O23 - Service: Norton Unerase Protection - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
    O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    nu m'n probleem : kort en krachtig VX2-variant

    ik heb al van alles geprobeerd , maar niks schijnt te helpen . Heb eens rondgekeken op Google enéén v.d. aangeboden oplossingen ( óók geproberd ) werkte ook niet :

    Was als volgt :

    Alle tijdelijke Internet bestanden verwijderen ( in alle accounts )
    Alles in recycle bin wegdoen ( prullenbak leegmaken )
    System restore even uitschakelen

    Opstarten in safe modus en Adaware SE een volledige scan laten doen . Op "scan summary " klikken en de "target family " aanvinken , in dit geval VX2 .
    Next en OK klikken . Adawre zegt dan dat - ie een dll niet kan verwijderen en vraagt of het dat bij en reboot mag doen . Echter ; die dll krijgt een
    nieuwe naam als je reboot , dus kan het programma dit niet . De VX2 - cleaner add-on vindt VX2 niet , m.a.w. geeft melding "system clean " ook al wéét ik dat het aanwezig is .


    Voorbeeldje van zo'n dll-melding van adaware SE :

    VX2 Object Recognized!
    Type : Process
    Data : q8860ilse8q60.dll
    Category : Malware
    Comment : (CSI MATCH)
    Object : C:\WINDOWS\system32\


    Warning! VX2 Object found in memory(C:\WINDOWS\system32\q8860ilse8q60.dll)



    de naam van dit dll'tje verandert bij elke reboot , dus is het voor adaware onmogelijk het te verwijderen .

    Ook Spybot krijgt het níet weg

    het herkent het wel , maar vraagt ook om en herstart om het te verwijderen - zelfde problem als hierboven beschreven .

    Maakt niet uit of system restore al dan niet is ingeschakeld : zelfde resultaat .

    Overigens gebeurt er nog iets wanneer Adaware tracht de dll te verwijderen : explorer reset ( niet internet explorer , maar explorer ) en opent het venster mijn documenten ( en ook opnieuw de melding dat je in safe mode zit , met optie om ja of nee te klikken ) .

    Kortom : nog steeds VX2 aanwezig , in weerwil van de enorme vracht programma's die ik geprobeerd heb om het te verwijderen . Wat doet VX2 ?? Het open te pas en te onpas IE-vensters ( terwijl ik IE niet eens gebruik : ben allang overgestapt op welke browser dan ook , zolang het maar niet IE is ) . Ik heb ook spywareguard lopen en Spywareblaster . Even een lijstje van programma's die ik heb geprobeerd of die nog actief zijn

    - Zonealarm
    - Norton systemworks 2004
    - Ewido security suite
    -Adaware SE ( met VX2-cleaner addon )
    - Trojan hunter ( herkent VX2 , zegt dat het verwijderd is , maar dit is niet het geval )
    - Spybot S&D 1.3
    - ook geprobeerd : spy sweeper, scan spyware en spy bouncer : helpt niet .




    Voor zover mogelijk loopt alles in de taakbalk ( dus constant op de achtergrond ) mee .

    Overigens ópent VX2 IE wel , maar slaagt het er niet in om de webpagina te openen , vanwege al die programma's



    Enig idee wat te doen ??

  • #2
    Verborgen bestanden weergeven :




    Download Find_It.zip:


    Uitpakken in een eigen folder
    in deze folder klik je op Find.bat (tandwiel)
    negeer de file not found berichten
    Het zal een text file maken , gelieve de inhoud daarvan hier te plaatsen



    Download DllCompare hier :


    Start het progie en klik op "Run Locate.com" en wacht enekel seconden tot de prescan afgerond is.
    Klik op de "Compare" knop om de nodige scans uit te voeren.
    Klik na de scan op "Make a Log of what was found" knop, plaats dat logje in je volgende post.



    download KillBox.zip voor LATER gebruik

    alsook voor later gebruik http://members.aol.com/toadbee/hoster.zip


    Kijk of je onderstaande file kan vinden in de opgegeven locatie
    C:/Windoews/system32/guard.tmp
    en laat me het weten (ja of nee)



    Plaats alle logs samen in je volgende post same met een vers hijackthis logje , EN NIET MEER HEROPSTARTEN NU
    not so Helpless ...

    Comment


    • #3
      Daar gaan we dan - in volgorde .

      Findit - log

      Warning! This utility will find legitimate files in addition to malware.
      Do not remove anything unless you are sure you know what you're doing.

      Find.bat is running from: C:\findit\Find It NT-2K-XP

      ------- System Files in System32 Directory -------
      Het volume in station C heeft geen naam.
      Het volumenummer is 10CC-2106

      Map van C:\WINDOWS\System32

      04-01-2005 13:25 224.320 dn2u01f9e.dll
      04-01-2005 00:18 223.399 lv8o09l3e.dll
      04-01-2005 00:07 224.728 k8jsli1718.dll
      03-01-2005 14:23 223.317 jt0o07d3e.dll
      02-01-2005 03:28 224.523 n44sleh71h4.dll
      01-01-2005 14:09 <DIR> dllcache
      01-01-2005 00:43 225.429 s0880aluedq80.dll
      30-12-2004 13:43 226.078 dn6u01j9e.dll
      29-12-2004 22:45 224.223 lvn2095oe.dll
      29-12-2004 21:21 225.201 s8pu0i79e8.dll
      10-12-2004 15:03 49.152 gpsB2.dll
      09-12-2004 20:13 <DIR> Microsoft
      30-09-1999 19:21 166.672 mstext35.dll
      28-09-1999 21:42 1.050.896 msjet35.dll
      09-09-1999 22:06 252.688 msexcl35.dll
      09-09-1999 22:06 168.720 msltus35.dll
      25-08-1999 14:57 415.504 msrepl35.dll
      10-06-1999 09:34 24.848 msjter35.dll
      10-06-1999 09:34 123.664 msjint35.dll
      07-06-1999 18:59 250.128 mspdox35.dll
      25-04-1999 17:00 368.912 Vbar332.dll
      25-04-1999 17:00 287.504 Msxbse35.dll
      25-04-1999 17:00 252.176 Msrd2x35.dll
      14-03-1995 05:22 720 argtmp39.dll
      22 bestand(en) 5.432.802 bytes
      2 map(pen) 11.230.937.088 bytes beschikbaar

      ------- Hidden Files in System32 Directory -------

      Het volume in station C heeft geen naam.
      Het volumenummer is 10CC-2106

      Map van C:\WINDOWS\System32

      04-01-2005 13:26 890 vsconfig.xml
      01-01-2005 14:09 <DIR> dllcache
      30-12-2004 00:40 4.212 zllictbl.dat
      16-12-2004 16:48 <DIR> GroupPolicy
      10-12-2004 15:03 49.152 gpsB2.dll
      09-12-2004 16:29 488 WindowsLogon.manifest
      09-12-2004 16:29 488 logonui.exe.manifest
      09-12-2004 16:29 749 sapi.cpl.manifest
      09-12-2004 16:29 749 ncpa.cpl.manifest
      09-12-2004 16:29 749 nwc.cpl.manifest
      09-12-2004 16:29 749 wuaucpl.cpl.manifest
      09-12-2004 16:29 749 cdplayer.exe.manifest
      10 bestand(en) 58.975 bytes
      2 map(pen) 11.230.932.992 bytes beschikbaar

      ---------- Files Named "Guard" -------------

      Het volume in station C heeft geen naam.
      Het volumenummer is 10CC-2106

      Map van C:\WINDOWS\System32

      02-01-2005 00:31 223.165 guard.tmp6827.tcf
      31-12-2004 14:06 223.637 guard.tmp9263.tcf
      31-12-2004 14:03 223.637 guard.tmp4475.tcf
      31-12-2004 05:01 222.254 guard.tmp6151.tcf
      31-12-2004 04:32 226.276 guard.tmp2424.tcf
      31-12-2004 03:16 226.276 guard.tmp2805.tcf
      31-12-2004 02:13 222.254 guard.tmp.tcf
      7 bestand(en) 1.567.499 bytes
      0 map(pen) 11.230.932.992 bytes beschikbaar

      --------- Temp Files in System32 Directory --------

      Het volume in station C heeft geen naam.
      Het volumenummer is 10CC-2106

      Map van C:\WINDOWS\System32

      04-08-2004 01:03 92.168 SET236.tmp
      04-08-2004 01:03 207.360 SET1AE.tmp
      04-08-2004 01:03 23.552 SET192.tmp
      04-08-2004 01:03 36.864 SET279.tmp
      04-08-2004 01:03 504.832 SET183.tmp
      04-08-2004 01:03 14.336 SET1CC.tmp
      04-08-2004 01:03 57.856 SET1E4.tmp
      04-08-2004 01:03 77.312 SET2E9.tmp
      04-08-2004 01:03 32.768 SET27E.tmp
      04-08-2004 01:03 69.632 SET27B.tmp
      04-08-2004 01:03 13.312 SET331.tmp
      04-08-2004 01:03 15.360 SET3F8.tmp
      04-08-2004 01:03 27.648 SET406.tmp
      04-08-2004 01:03 6.144 SET3F9.tmp
      04-08-2004 01:03 53.760 SET17D.tmp
      04-08-2004 01:03 176.640 SET17C.tmp
      04-08-2004 01:03 93.696 SET179.tmp
      04-08-2004 01:03 18.432 SET155.tmp
      04-08-2004 01:03 359.936 SET152.tmp
      04-08-2004 01:03 24.576 SET157.tmp
      04-08-2004 01:03 291.328 SET17E.tmp
      04-08-2004 01:03 19.968 SET160.tmp
      04-08-2004 01:03 82.944 SET161.tmp
      04-08-2004 01:03 172.544 SET17A.tmp
      04-08-2004 01:03 264.704 SET164.tmp
      04-08-2004 01:03 19.968 SET159.tmp
      04-08-2004 01:03 430.592 SET197.tmp
      04-08-2004 01:03 18.944 SET198.tmp
      04-08-2004 01:03 219.136 SET19E.tmp
      04-08-2004 01:03 728.576 SET1A1.tmp
      04-08-2004 01:03 578.560 SET1A2.tmp
      04-08-2004 01:03 175.616 SET195.tmp
      04-08-2004 01:03 602.624 SET1A5.tmp
      04-08-2004 01:03 37.888 SET1A6.tmp
      04-08-2004 01:03 132.608 SET1AB.tmp
      04-08-2004 01:03 13.824 SET1AC.tmp
      04-08-2004 01:03 78.336 SET1AD.tmp
      04-08-2004 01:03 49.152 SET193.tmp
      04-08-2004 01:03 279.552 SET191.tmp
      04-08-2004 01:03 90.624 SET1B6.tmp
      04-08-2004 01:03 390.144 SET1BA.tmp
      04-08-2004 01:03 297.472 SET1BB.tmp
      04-08-2004 01:03 46.080 SET1C0.tmp
      04-08-2004 01:03 181.760 SET1C4.tmp
      04-08-2004 01:03 714.752 SET1CB.tmp
      04-08-2004 01:03 67.584 SET190.tmp
      04-08-2004 01:03 333.824 SET188.tmp
      04-08-2004 01:03 659.456 SET185.tmp
      04-08-2004 01:03 32.768 SET184.tmp
      04-08-2004 01:03 179.200 SET182.tmp
      04-08-2004 01:03 16.896 SET180.tmp
      04-08-2004 01:03 99.840 SET17F.tmp
      04-08-2004 01:03 16.896 SET1A4.tmp
      04-08-2004 01:03 119.296 SET1AF.tmp
      04-08-2004 01:03 74.752 SET1E5.tmp
      04-08-2004 01:03 135.168 SET1F5.tmp
      04-08-2004 01:03 474.112 SET1FA.tmp
      04-08-2004 01:03 65.536 SET1FC.tmp
      04-08-2004 01:03 25.088 SET1FE.tmp
      04-08-2004 01:03 8.431.104 SET1FF.tmp
      04-08-2004 01:03 1.483.264 SET200.tmp
      04-08-2004 01:03 141.824 SET203.tmp
      04-08-2004 01:03 5.120 SET204.tmp
      04-08-2004 01:03 6.656 SET208.tmp
      04-08-2004 01:03 38.912 SET209.tmp
      04-08-2004 01:03 55.808 SET20D.tmp
      04-08-2004 01:03 18.944 SET20E.tmp
      04-08-2004 01:03 192.000 SET214.tmp
      04-08-2004 01:03 324.096 SET215.tmp
      04-08-2004 01:03 184.832 SET216.tmp
      04-08-2004 01:03 180.800 SET1E1.tmp
      04-08-2004 01:03 170.496 SET1DE.tmp
      04-08-2004 01:03 34.816 SET1DB.tmp
      04-08-2004 01:03 71.680 SET1DA.tmp
      04-08-2004 01:03 122.368 SET1CF.tmp
      04-08-2004 01:03 442.368 SET1E3.tmp
      04-08-2004 01:03 49.664 SET22F.tmp
      04-08-2004 01:03 59.904 SET22E.tmp
      04-08-2004 01:03 112.640 SET23C.tmp
      04-08-2004 01:03 69.632 SET241.tmp
      04-08-2004 01:03 8.192 SET242.tmp
      04-08-2004 01:03 34.304 SET24E.tmp
      04-08-2004 01:03 98.304 SET250.tmp
      04-08-2004 01:03 23.040 SET251.tmp
      04-08-2004 01:03 27.648 SET254.tmp
      04-08-2004 01:03 17.408 SET256.tmp
      04-08-2004 01:03 15.360 SET25A.tmp
      04-08-2004 01:03 83.456 SET268.tmp
      04-08-2004 01:03 1.281.024 SET26A.tmp
      04-08-2004 01:03 147.456 SET271.tmp
      04-08-2004 01:03 58.880 SET229.tmp
      04-08-2004 01:03 581.120 SET226.tmp
      04-08-2004 01:03 65.536 SET276.tmp
      04-08-2004 01:03 65.536 SET277.tmp
      04-08-2004 01:03 106.496 SET278.tmp
      04-08-2004 01:03 395.776 SET225.tmp
      04-08-2004 01:03 267.264 SET283.tmp
      04-08-2004 01:03 135.168 SET27C.tmp
      04-08-2004 01:03 24.576 SET27D.tmp
      04-08-2004 01:03 44.032 SET21F.tmp
      04-08-2004 01:03 16.384 SET27F.tmp
      04-08-2004 01:03 249.856 SET280.tmp
      04-08-2004 01:03 145.408 SET285.tmp
      04-08-2004 01:03 119.296 SET28A.tmp
      04-08-2004 01:03 143.360 SET2D7.tmp
      04-08-2004 01:03 43.520 SET28B.tmp
      04-08-2004 01:03 67.072 SET291.tmp
      04-08-2004 01:03 250.368 SET296.tmp
      04-08-2004 01:03 245.760 SET297.tmp
      04-08-2004 01:03 81.408 SET298.tmp
      04-08-2004 01:03 1.721.344 SET29A.tmp
      04-08-2004 01:03 12.288 SET29D.tmp
      04-08-2004 01:03 198.144 SET29F.tmp
      04-08-2004 01:03 407.040 SET2A0.tmp
      04-08-2004 01:03 332.288 SET2A4.tmp
      04-08-2004 01:03 17.920 SET2AA.tmp
      04-08-2004 01:03 36.352 SET2AB.tmp
      04-08-2004 01:03 90.112 SET2AE.tmp
      04-08-2004 01:03 66.560 SET2AF.tmp
      04-08-2004 01:03 1.236.480 SET2B1.tmp
      04-08-2004 01:03 247.296 SET2B6.tmp
      04-08-2004 01:03 343.040 SET2BE.tmp
      04-08-2004 01:03 413.696 SET2BF.tmp
      04-08-2004 01:03 195.584 SET2C2.tmp
      04-08-2004 01:03 115.712 SET2C5.tmp
      04-08-2004 01:03 30.208 SET2D5.tmp
      04-08-2004 01:03 2.804.224 SET2ED.tmp
      04-08-2004 01:03 57.344 SET309.tmp
      04-08-2004 01:03 73.728 SET307.tmp
      04-08-2004 01:03 44.032 SET2E4.tmp
      04-08-2004 01:03 36.864 SET304.tmp
      04-08-2004 01:03 4.608 SET2E7.tmp
      04-08-2004 01:03 331.264 SET2E8.tmp
      04-08-2004 01:03 294.400 SET303.tmp
      04-08-2004 01:03 6.656 SET2EB.tmp
      04-08-2004 01:03 71.680 SET30E.tmp
      04-08-2004 01:03 3.003.392 SET2F1.tmp
      04-08-2004 01:03 999.424 SET2F5.tmp
      04-08-2004 01:03 151.552 SET301.tmp
      04-08-2004 01:03 119.808 SET329.tmp
      04-08-2004 01:03 184.320 SET356.tmp
      04-08-2004 01:03 18.944 SET33B.tmp
      04-08-2004 01:03 294.400 SET347.tmp
      04-08-2004 01:03 18.944 SET324.tmp
      04-08-2004 01:03 1.028.096 SET327.tmp
      04-08-2004 01:03 87.040 SET30F.tmp
      04-08-2004 01:03 59.904 SET310.tmp
      04-08-2004 01:03 145.920 SET316.tmp
      04-08-2004 01:03 22.528 SET325.tmp
      04-08-2004 01:03 11.264 SET37F.tmp
      04-08-2004 01:03 347.648 SET384.tmp
      04-08-2004 01:03 95.232 SET35A.tmp
      04-08-2004 01:03 20.992 SET386.tmp
      04-08-2004 01:03 278.016 SET38F.tmp
      04-08-2004 01:03 75.264 SET364.tmp
      04-08-2004 01:03 110.080 SET369.tmp
      04-08-2004 01:03 14.336 SET3B6.tmp
      04-08-2004 01:03 243.200 SET39D.tmp
      04-08-2004 01:03 1.092.096 SET39C.tmp
      04-08-2004 01:03 55.808 SET39A.tmp
      04-08-2004 01:03 21.504 SET396.tmp
      04-08-2004 01:03 23.040 SET39E.tmp
      04-08-2004 01:03 49.152 SET40D.tmp
      04-08-2004 01:03 1.251.840 SET408.tmp
      04-08-2004 01:03 33.280 SET401.tmp
      04-08-2004 01:03 501.248 SET41C.tmp
      04-08-2004 01:03 164.864 SET404.tmp
      04-08-2004 01:03 62.464 SET40C.tmp
      04-08-2004 01:03 822.784 SET409.tmp
      04-08-2004 01:03 60.416 SET3FE.tmp
      04-08-2004 01:03 601.088 SET403.tmp
      04-08-2004 01:03 45.568 SET3CA.tmp
      04-08-2004 01:03 148.480 SET3CB.tmp
      04-08-2004 01:03 24.064 SET3D0.tmp
      04-08-2004 01:03 186.880 SET3DB.tmp
      04-08-2004 01:03 25.088 SET3F2.tmp
      04-08-2004 01:03 527.872 SET3FD.tmp
      04-08-2004 01:03 102.400 SET3FC.tmp
      04-08-2004 01:03 334.848 SET3FA.tmp
      04-08-2004 01:03 57.856 SET415.tmp
      04-08-2004 01:03 100.864 SET449.tmp
      04-08-2004 01:03 1.017.344 SET42E.tmp
      04-08-2004 01:03 77.312 SET42F.tmp
      04-08-2004 01:03 126.976 SET444.tmp
      04-08-2004 01:03 28.672 SET434.tmp
      04-08-2004 01:03 101.888 SET44F.tmp
      04-08-2004 01:03 58.880 SET43E.tmp
      04-08-2004 01:03 52.736 SET435.tmp
      04-08-2004 01:03 56.832 SET439.tmp
      04-08-2004 01:03 194.048 SET451.tmp
      04-08-2004 01:03 143.360 SET44C.tmp
      04-08-2004 01:03 42.496 SET43A.tmp
      04-08-2004 01:03 59.904 SET42C.tmp
      04-08-2004 01:03 197.632 SET424.tmp
      04-08-2004 01:03 628.224 SET427.tmp
      04-08-2004 01:03 229.888 SET429.tmp
      04-08-2004 01:02 5.632 SET173.tmp
      04-08-2004 01:02 98.304 SET275.tmp
      04-08-2004 01:02 12.288 SET272.tmp
      04-08-2004 01:02 24.576 SET2D8.tmp
      04-08-2004 01:02 884.736 SET2E6.tmp
      04-08-2004 01:02 48.128 SET2D2.tmp
      04-08-2004 01:02 12.288 SET305.tmp
      04-08-2004 01:02 3.584 SET37C.tmp
      04-08-2004 01:01 16.896 SET420.tmp
      03-08-2004 22:31 137.216 SET3AC.tmp
      03-08-2004 22:31 152.576 SET224.tmp
      17-07-2004 11:34 98.304 SET1E2.tmp
      07-09-2001 13:00 2.845 CONFIG.TMP
      209 bestand(en) 54.490.469 bytes
      0 map(pen) 11.230.912.512 bytes beschikbaar

      ---------------- User Agent ------------

      REGEDIT4

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
      "{B0B034E1-46C4-45DB-B211-344BE5AB0E55}"=""


      ------------ Keys Under Notify ------------

      REGEDIT4

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
      "DLLName"="Ati2evxx.dll"
      "Asynchronous"=dword:00000000
      "Impersonate"=dword:00000001
      "Lock"="AtiLockEvent"
      "Logoff"="AtiLogoffEvent"
      "Logon"="AtiLogonEvent"
      "Disconnect"="AtiDisConnectEvent"
      "Reconnect"="AtiReConnectEvent"
      "Safe"=dword:00000000
      "Shutdown"="AtiShutdownEvent"
      "StartScreenSaver"="AtiStartScreenSaverEvent"
      "StartShell"="AtiStartShellEvent"
      "Startup"="AtiStartupEvent"
      "StopScreenSaver"="AtiStopScreenSaverEvent"
      "Unlock"="AtiUnLockEvent"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
      "Asynchronous"=dword:00000000
      "Impersonate"=dword:00000000
      "DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
      "Logoff"="ChainWlxLogoffEvent"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
      "Asynchronous"=dword:00000000
      "Impersonate"=dword:00000000
      "DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
      "Logoff"="CryptnetWlxLogoffEvent"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
      "DLLName"="cscdll.dll"
      "Logon"="WinlogonLogonEvent"
      "Logoff"="WinlogonLogoffEvent"
      "ScreenSaver"="WinlogonScreenSaverEvent"
      "Startup"="WinlogonStartupEvent"
      "Shutdown"="WinlogonShutdownEvent"
      "StartShell"="WinlogonStartShellEvent"
      "Impersonate"=dword:00000000
      "Asynchronous"=dword:00000001

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MCPClient]
      "Asynchronous"=dword:00000000
      "DllName"="C:\\Program Files\\Common Files\\Stardock\\mcpstub.dll"
      "Startup"="MCPSystemStartup"
      "Logon"="MCPLogonStartup"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ModuleUsage]
      "Asynchronous"=dword:00000000
      "DllName"="C:\\WINDOWS\\system32\\lv8o09l3e.dll"
      "Impersonate"=dword:00000000
      "Logon"="WinLogon"
      "Logoff"="WinLogoff"
      "Shutdown"="WinShutdown"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
      "DLLName"="wlnotify.dll"
      "Logon"="SCardStartCertProp"
      "Logoff"="SCardStopCertProp"
      "Lock"="SCardSuspendCertProp"
      "Unlock"="SCardResumeCertProp"
      "Enabled"=dword:00000001
      "Impersonate"=dword:00000001
      "Asynchronous"=dword:00000001

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
      "Asynchronous"=dword:00000000
      "DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
      "Impersonate"=dword:00000000
      "StartShell"="SchedStartShell"
      "Logoff"="SchedEventLogOff"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
      "Logoff"="WLEventLogoff"
      "Impersonate"=dword:00000000
      "Asynchronous"=dword:00000001
      "DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
      "DLLName"="WlNotify.dll"
      "Lock"="SensLockEvent"
      "Logon"="SensLogonEvent"
      "Logoff"="SensLogoffEvent"
      "Safe"=dword:00000001
      "MaxWait"=dword:00000258
      "StartScreenSaver"="SensStartScreenSaverEvent"
      "StopScreenSaver"="SensStopScreenSaverEvent"
      "Startup"="SensStartupEvent"
      "Shutdown"="SensShutdownEvent"
      "StartShell"="SensStartShellEvent"
      "PostShell"="SensPostShellEvent"
      "Disconnect"="SensDisconnectEvent"
      "Reconnect"="SensReconnectEvent"
      "Unlock"="SensUnlockEvent"
      "Impersonate"=dword:00000001
      "Asynchronous"=dword:00000001

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
      "Asynchronous"=dword:00000000
      "DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
      "Impersonate"=dword:00000000
      "Logoff"="TSEventLogoff"
      "Logon"="TSEventLogon"
      "PostShell"="TSEventPostShell"
      "Shutdown"="TSEventShutdown"
      "StartShell"="TSEventStartShell"
      "Startup"="TSEventStartup"
      "MaxWait"=dword:00000258
      "Reconnect"="TSEventReconnect"
      "Disconnect"="TSEventDisconnect"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB]
      "Asynchronous"=dword:00000000
      "DllName"="C:\\Program Files\\Stardock\\Object Desktop\\WindowBlinds\\fastload.dll"
      "Startup"="StartSys"
      "Logon"="StartWB"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
      "DLLName"="wlnotify.dll"
      "Logon"="RegisterTicketExpiredNotificationEvent"
      "Logoff"="UnregisterTicketExpiredNotificationEvent"
      "Impersonate"=dword:00000001
      "Asynchronous"=dword:00000001


      ------------------ Locate.com Results ------------------

      C:\WINDOWS\SYSTEM32\
      cdplay~1.man Thu 9 Dec 2004 16:29:48 A..HR 749 0,73 K
      dn2u01~1.dll Tue 4 Jan 2005 13:25:32 ..S.R 224.320 219,06 K
      dn6u01~1.dll Thu 30 Dec 2004 13:43:06 ..S.R 226.078 220,78 K
      gpsb2.dll Fri 10 Dec 2004 15:03:26 A.SH. 49.152 48,00 K
      jt0o07~1.dll Mon 3 Jan 2005 14:23:38 ..S.R 223.317 218,08 K
      k8jsli~1.dll Tue 4 Jan 2005 0:07:12 ..S.R 224.728 219,46 K
      logonu~1.man Thu 9 Dec 2004 16:29:54 A..HR 488 0,48 K
      lv8o09~1.dll Tue 4 Jan 2005 0:18:30 ..S.R 223.399 218,16 K
      lvn209~1.dll Wed 29 Dec 2004 22:45:06 ..S.R 224.223 218,96 K
      n44sle~1.dll Sun 2 Jan 2005 3:28:10 ..S.R 224.523 219,26 K
      ncpacp~1.man Thu 9 Dec 2004 16:29:48 A..HR 749 0,73 K
      nwccpl~1.man Thu 9 Dec 2004 16:29:48 A..HR 749 0,73 K
      s0880a~1.dll Sat 1 Jan 2005 0:43:48 ..S.R 225.429 220,14 K
      s8pu0i~1.dll Wed 29 Dec 2004 21:21:54 ..S.R 225.201 219,92 K
      sapicp~1.man Thu 9 Dec 2004 16:29:48 A..HR 749 0,73 K
      vsconfig.xml Tue 4 Jan 2005 13:26:44 A..H. 890 0,87 K
      window~1.man Thu 9 Dec 2004 16:29:54 A..HR 488 0,48 K
      wuaucp~1.man Thu 9 Dec 2004 16:29:48 A..HR 749 0,73 K
      zllictbl.dat Thu 30 Dec 2004 0:40:28 ...H. 4.212 4,11 K

      19 items found: 19 files, 0 directories.
      Total of file sizes: 2.080.193 bytes 1,98 M

      ------------ Strings.exe Qoologic Results ------------


      -------------- Strings.exe Aspack Results -------------

      C:\WINDOWS\system32\Formats.dll: .aspack
      C:\WINDOWS\system32\ntdll.dll: .aspack
      C:\WINDOWS\system32\ShellPicture.dll: .aspack

      ----------------- HKLM Run Key ------------------

      REGEDIT4

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
      "zBrowser Launcher"="C:\\Program Files\\Logitech\\iTouch\\iTouch.exe"
      "Logitech Utility"="Logi_MwX.Exe"
      "Disc Detector"="C:\\Program Files\\Creative\\ShareDLL\\CtNotify.exe"
      "CreativeMixer"="C:\\Program Files\\Creative\\Audio2K\\PROGRAM\\CTMIX32.EXE /t"
      "ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
      "AcctMgr"="C:\\Program Files\\Norton SystemWorks\\Password Manager\\AcctMgr.exe /startup"
      "SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_06\\bin\\jusched.exe"
      "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
      "C-Media Mixer"="Mixer.exe /startup"
      "NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
      "ntsmod"="C:\\WINDOWS\\system32\\ntsmod.exe"
      "SpybotSnD"="\"C:\\Program Files\\Spybot - Search & Destroy\\SpybotSD.exe\""
      "Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
      "LogonStudio"="\"C:\\Program Files\\WinCustomize\\LogonStudio\\logonstudio.exe\" /RANDOM"
      "BootSkin Startup Jobs"="\"C:\\Program Files\\Stardock\\WinCustomize\\BootSkin\\bootskin.exe\" /StartupJobs"
      "THGuard"="\"C:\\Program Files\\TrojanHunter 4.0\\THGuard.exe\""
      "Babylon Client"="C:\\Program Files\\Babylon\\Babylon.exe -AutoStart"

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
      "Installed"="1"

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
      "Installed"="1"
      "NoChange"="1"

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
      "Installed"="1"


      

      dll-compare log

      * DLLCompare Log version(1.0.0.127)
      Files Found that Windows does not See or cannot Access
      *Not everything listed here means you are infected!
      ________________________________________________

      C:\WINDOWS\SYSTEM32\argtmp39.dll Tue 14 Mar 1995 5:22:22 ..S.. 720 0,70 K
      C:\WINDOWS\SYSTEM32\dn2u01~1.dll Tue 4 Jan 2005 13:25:32 ..S.R 224.320 219,06 K
      C:\WINDOWS\SYSTEM32\dn6u01~1.dll Thu 30 Dec 2004 13:43:06 ..S.R 226.078 220,78 K
      C:\WINDOWS\SYSTEM32\gpsb2.dll Fri 10 Dec 2004 15:03:26 A.SH. 49.152 48,00 K
      C:\WINDOWS\SYSTEM32\jt0o07~1.dll Mon 3 Jan 2005 14:23:38 ..S.R 223.317 218,08 K
      C:\WINDOWS\SYSTEM32\k8jsli~1.dll Tue 4 Jan 2005 0:07:12 ..S.R 224.728 219,46 K
      C:\WINDOWS\SYSTEM32\lv8o09~1.dll Tue 4 Jan 2005 0:18:30 ..S.R 223.399 218,16 K
      C:\WINDOWS\SYSTEM32\lvn209~1.dll Wed 29 Dec 2004 22:45:06 ..S.R 224.223 218,96 K
      C:\WINDOWS\SYSTEM32\msexcl35.dll Thu 9 Sep 1999 22:06:38 A.S.. 252.688 246,77 K
      C:\WINDOWS\SYSTEM32\msjet35.dll Tue 28 Sep 1999 21:42:48 A.S.. 1.050.896 1,00 M
      C:\WINDOWS\SYSTEM32\msjint35.dll Thu 10 Jun 1999 9:34:04 A.S.. 123.664 120,77 K
      C:\WINDOWS\SYSTEM32\msjter35.dll Thu 10 Jun 1999 9:34:04 A.S.. 24.848 24,27 K
      C:\WINDOWS\SYSTEM32\msltus35.dll Thu 9 Sep 1999 22:06:38 A.S.. 168.720 164,77 K
      C:\WINDOWS\SYSTEM32\mspdox35.dll Mon 7 Jun 1999 18:59:34 A.S.. 250.128 244,27 K
      C:\WINDOWS\SYSTEM32\msrd2x35.dll Sun 25 Apr 1999 17:00:00 A.S.. 252.176 246,27 K
      C:\WINDOWS\SYSTEM32\msrepl35.dll Wed 25 Aug 1999 14:57:26 A.S.. 415.504 405,77 K
      C:\WINDOWS\SYSTEM32\mstext35.dll Thu 30 Sep 1999 19:21:24 A.S.. 166.672 162,77 K
      C:\WINDOWS\SYSTEM32\msxbse35.dll Sun 25 Apr 1999 17:00:00 A.S.. 287.504 280,77 K
      C:\WINDOWS\SYSTEM32\n44sle~1.dll Sun 2 Jan 2005 3:28:10 ..S.R 224.523 219,26 K
      C:\WINDOWS\SYSTEM32\s0880a~1.dll Sat 1 Jan 2005 0:43:48 ..S.R 225.429 220,14 K
      C:\WINDOWS\SYSTEM32\s8pu0i~1.dll Wed 29 Dec 2004 21:21:54 ..S.R 225.201 219,92 K
      C:\WINDOWS\SYSTEM32\vbar332.dll Sun 25 Apr 1999 17:00:00 A.S.. 368.912 360,27 K
      ________________________________________________

      1.349 items found: 1.349 files (22 H/S), 0 directories.
      Total of file sizes: 284.907.655 bytes 271,71 M

      Administrator Account = True

      AppInit_DLLs value = wbsys.dll (not hidden)
      --------------------End log---------------------


      HJT - log

      Logfile of HijackThis v1.99.0
      Scan saved at 13:56:04, on 4-1-2005
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\System32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      C:\WINDOWS\System32\CTSvcCDA.exe
      C:\Program Files\ewido\security suite\ewidoctrl.exe
      C:\Program Files\ewido\security suite\ewidoguard.exe
      C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
      C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
      C:\Program Files\Common Files\Stardock\SDMCP.exe
      C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
      C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\Program Files\Creative\ShareDLL\CtNotify.exe
      C:\Program Files\Common Files\Symantec Shared\ccApp.exe
      C:\Program Files\Creative\ShareDLL\MediaDet.Exe
      C:\Program Files\Logitech\MouseWare\system\em_exec.exe
      C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\WINDOWS\Mixer.exe
      C:\WINDOWS\system32\ntsmod.exe
      C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\TrojanHunter 4.0\THGuard.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\GPSoftware\Directory Opus\dopus.exe
      C:\Program Files\CursorXP\CursorXP.exe
      C:\Program Files\NetMeter\NetMeter.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
      C:\Program Files\InterVideo\WinDVD4PR\WinScheduler.exe
      C:\Program Files\TechSmith\SnagIt 7\SnagIt32.exe
      C:\Program Files\ICONDESK\IconDesk.exe
      C:\Program Files\SpywareGuard\sgmain.exe
      C:\Program Files\TechSmith\SnagIt 7\TSCHelp.exe
      C:\Program Files\SpywareGuard\sgbhp.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
      C:\WINDOWS\System32\svchost.exe
      C:\HJT\hijackthis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
      R3 - Default URLSearchHook is missing
      O1 - Hosts: 69.20.16.183 auto.search.msn.com
      O1 - Hosts: 69.20.16.183 search.netscape.com
      O1 - Hosts: 69.20.16.183 ieautosearch
      O1 - Hosts: 69.20.16.183 ieautosearch
      O1 - Hosts: 69.20.16.183 ieautosearch
      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
      O3 - Toolbar: PopUpCop - {DB43E4E6-FF8A-4018-8C8E-F68587A44A73} - C:\PROGRA~1\PopUpCop\PopUpCop.dll
      O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
      O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
      O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
      O4 - HKLM\..\Run: [CreativeMixer] C:\Program Files\Creative\Audio2K\PROGRAM\CTMIX32.EXE /t
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [ntsmod] C:\WINDOWS\system32\ntsmod.exe
      O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
      O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
      O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
      O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\Program Files\Stardock\WinCustomize\BootSkin\bootskin.exe" /StartupJobs
      O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.0\THGuard.exe"
      O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon.exe -AutoStart
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [DOpus] C:\Program Files\GPSoftware\Directory Opus\dopus.exe
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [C:\Program Files\NetMeter\NetMeter.exe] C:\Program Files\NetMeter\NetMeter.exe
      O4 - Startup: ICONDESK.lnk = C:\Program Files\ICONDESK\IconDesk.exe
      O4 - Startup: Rainlendar.lnk = C:\Program Files\Rainlendar\Rainlendar.exe
      O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: hp psc 1000 series.lnk = ?
      O4 - Global Startup: hpoddt01.exe.lnk = ?
      O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
      O4 - Global Startup: InterVideo WinScheduler.lnk = C:\Program Files\InterVideo\WinDVD4PR\WinScheduler.exe
      O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O4 - Global Startup: SnagIt 7.lnk = C:\Program Files\TechSmith\SnagIt 7\SnagIt32.exe
      O4 - Global Startup: SymmTime.lnk = ?
      O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
      O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
      O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
      O8 - Extra context menu item: Open Image in New Window - res://C:\Program Files\PopUpCop\popupcop.dll/imagenew
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://simcity.ea.com/update/EARTPX.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1102608662085
      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
      O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
      O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.exe
      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
      O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
      O23 - Service: iPod-service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Norton AntiVirus Auto-Protect - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
      O23 - Service: Norton Unerase Protection - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
      O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
      O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
      O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
      O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe



      dat is het . Er staan guard.tmp bestanden in de windows \system32 folder , maar deze hebben de extensie tcf en zijn "gemerkt " door adaware .

      Nog iets : bij tijd en wijle krijg ik de volgende foutmelding bij het opstarten van het systeem :

      "er is een uitzondering opgetreden in C:\windows\system32\"asledit.dll",Umonitor " .

      Ik weet niet of de dll die daarin vermeld wordt altijd dezelfde is . Ik vermoed dat spyguard, spyblaster, Spybot óf adaware dit geval heeft "beschadigd "

      Overigens geeft trojan hunter soms melding dat VX2 resident is in het geheugen , maar soms ook niet ( denk dat dit afhangt van de naam van de dll )

      Comment


      • #4
        Wat zijn overigens al die SET-bestanden ??

        Comment


        • #5
          KOPIER alle onderstaande text in een text file
          VERVOLGENS uw internet verbinding verbreken!!


          Dan, start notepad, en copy/paste de quetebox text in de file
          Sla de file op als alle bestanden (*.*) met de naam fixme.reg


          REGEDIT4

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
          "{B0B034E1-46C4-45DB-B211-344BE5AB0E55}"=-


          [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ModuleUsage]



          Nu mag je KILLBOX uitpakken in zijn eigen folder
          vervolgens klik je op KillBox.exe om het te gebruiken

          In het hoofdscherm ga je naar "tools" in het hoofdmenu en klik je op "Delete Temp Files."

          Terug in het hoofscherm klik selecteer je de optie "Delete on Reboot"

          In de box "Full Path of File to Delete", kopier en plak de onderstaande lijn:

          C:\WINDOWS\SYSTEM32\jt0o07~1.dll

          Klik op htee knopje met de rode cirkel en het witte kruis.
          Bij de vraag om te herstarten (reboot) klik "NO"

          Herhaal bovenstaande procedure voor alle onderstaande lijntjes (elk appart), telkens NO voor de reboot

          C:\WINDOWS\SYSTEM32\gpsb2.dll
          C:\WINDOWS\SYSTEM32\s0880a~1.dll
          C:\WINDOWS\SYSTEM32\n44sle~1.dll
          C:\WINDOWS\SYSTEM32\dn6u01~1.dll
          C:\WINDOWS\SYSTEM32\k8jsli~1.dll
          C:\WINDOWS\SYSTEM32\lv8o09~1.dll
          C:\WINDOWS\SYSTEM32\dn2u01~1.dll
          C:\WINDOWS\SYSTEM32\s8pu0i~1.dll
          C:\WINDOWS\SYSTEM32\lvn209~1.dll
          C:\WINDOWS\SYSTEM32\dn2u01f9e.dll
          C:\WINDOWS\SYSTEM32\lv8o09l3e.dll
          C:\WINDOWS\SYSTEM32\k8jsli1718.dll
          C:\WINDOWS\SYSTEM32\jt0o07d3e.dll
          C:\WINDOWS\SYSTEM32\n44sleh71h4.dll
          C:\WINDOWS\SYSTEM32\guard.tmp6827.tcf
          C:\WINDOWS\SYSTEM32\guard.tmp9263.tcf
          C:\WINDOWS\SYSTEM32\guard.tmp4475.tcf
          C:\WINDOWS\SYSTEM32\guard.tmp6151.tcf
          C:\WINDOWS\SYSTEM32\guard.tmp2424.tcf
          C:\WINDOWS\SYSTEM32\guard.tmp2805.tcf
          C:\WINDOWS\SYSTEM32\guard.tmp.tcf




          Ten laatste plaats je in de "Full Path of File to Delete" box, kopier en plak onderstaande:

          C:\WINDOWS\System32\guard.tmp

          Klik opnieuw op de rode cirkel met het witte kruis.
          Bij de vraag om te rebooten (heropstarten) klik je op "YES"


          Scan opnieuw met hijackthis
          vink de onderstaande lijntje aan
          R3 - Default URLSearchHook is missing
          O1 - Hosts: 69.20.16.183 auto.search.msn.com
          O1 - Hosts: 69.20.16.183 search.netscape.com
          O1 - Hosts: 69.20.16.183 ieautosearch
          O1 - Hosts: 69.20.16.183 ieautosearch
          O1 - Hosts: 69.20.16.183 ieautosearch
          sluit alle vensters behalve hijackthis
          KLIK OP FIX


          Herstart de PC.


          Nu de hoster.zip uitpakken
          Selecteer "Restore Original Hosts"
          Klik OK en dan "exit Hoster"

          heropstarten


          nu mage je terug op het net

          Doe een scan met ad-aware zoals hier opgegeven met de vx2 add-on




          Download en installeer http://www.ccleaner.com/
          Start CCleaner en klik op Run Cleaner rechts onderaan


          Laat me weten of je problem hebt met uw RecycleBin
          maak een text file met wat onbeduiden text
          sla het op
          en dan verwijderen
          nu moet je opletten of je de vraag krijkt om het naar de vuilabk te sturen of niet
          indien neen dan is er een probleem , laat me het weten .


          laatste reboot alvorens....ik een vers logje willen met onderstaande progies
          DLLCompare log
          HijackThis log
          Find_It log




          Doe een scan met http://www.kaspersky.com/scanforvirus eerst "browse" en dan "submit
          C:\WINDOWS\system32\ntsmod.exe
          C:\windows\system32\asledit.dll
          laat mle weten wat de resultaten zijn
          not so Helpless ...

          Comment


          • #6
            moet ik het regfile meteen uitvoeren ??

            Dus : voordat ik de andere dingen doe ?

            Comment


            • #7
              Nu mag je KILLBOX uitpakken in zijn eigen folder vervolgens klik je op KillBox.exe om het te gebruiken In het hoofdscherm ga je naar "tools" in het hoofdmenu en klik je op "Delete Temp Files." Terug in het hoofscherm klik selecteer je de optie "Delete on Reboot" In de box "Full Path of File to Delete", kopier en plak de onderstaande lijn: C:\WINDOWS\SYSTEM32\jt0o07~1.dll Klik op htee knopje met de rode cirkel en het witte kruis. Bij de vraag om te herstarten (reboot) klik "NO" Herhaal bovenstaande procedure voor alle onderstaande lijntjes (elk appart), telkens NO voor de reboot C:\WINDOWS\SYSTEM32\gpsb2.dll C:\WINDOWS\SYSTEM32\s0880a~1.dll C:\WINDOWS\SYSTEM32\n44sle~1.dll C:\WINDOWS\SYSTEM32\dn6u01~1.dll C:\WINDOWS\SYSTEM32\k8jsli~1.dll C:\WINDOWS\SYSTEM32\lv8o09~1.dll C:\WINDOWS\SYSTEM32\dn2u01~1.dll C:\WINDOWS\SYSTEM32\s8pu0i~1.dll C:\WINDOWS\SYSTEM32\lvn209~1.dll C:\WINDOWS\SYSTEM32\dn2u01f9e.dll C:\WINDOWS\SYSTEM32\lv8o09l3e.dll C:\WINDOWS\SYSTEM32\k8jsli1718.dll C:\WINDOWS\SYSTEM32\jt0o07d3e.dll C:\WINDOWS\SYSTEM32\n44sleh71h4.dll C:\WINDOWS\SYSTEM32\guard.tmp6827.tcf C:\WINDOWS\SYSTEM32\guard.tmp9263.tcf C:\WINDOWS\SYSTEM32\guard.tmp4475.tcf C:\WINDOWS\SYSTEM32\guard.tmp6151.tcf C:\WINDOWS\SYSTEM32\guard.tmp2424.tcf C:\WINDOWS\SYSTEM32\guard.tmp2805.tcf C:\WINDOWS\SYSTEM32\guard.tmp.tcf Ten laatste plaats je in de "Full Path of File to Delete" box, kopier en plak onderstaande: C:\WINDOWS\System32\guard.tmp Klik opnieuw op de rode cirkel met het witte kruis. Bij de vraag om te rebooten (heropstarten) klik je op "YES"

              Kwam tot hier en kreeg toen volgende boodschap ( moest ook terug het net op om dit mee te delen , dus vóór de reboot ) :

              " PendingFilerenameOperations Registry data has been removed by external process "

              Slecht nieuws , denk ik , zal wel opnieuw moeten beginnen

              Comment


              • #8
                ok kijk of er een van die dll's die ik boven vernoem nog in de C:\WINDOWS\SYSTEM32\ folder zitten.
                zo ja verwijder ze dan manueel en vervolgens heropstarten.

                vervolgens doe je een nieuwe scan met Find_It:

                en met hijackthis
                en plaats beide logjes hier
                not so Helpless ...

                Comment


                • #9
                  Zover ik kan zien zitten er nog twee in , na de reboot . Ik heb overigens gezien ( voordat ik systemm terug opstartte ) dat somminge dll's in de lijst reeds van naam waren veranderd ( vergeleken met de lijst die je had gegeven ) . Héle kleine verschillen , dus het was geen problem om te zien welke bedoeld werden . Héél erg slim, VX2 - ze waren trouwens geen van allen verwijderd , maar ik heb de overige dll's manueel verwijderd , ze waren allemaal write-protect en twee ervan ( degene die nog aanwezig zijn ) waren in gebruik .

                  FIND it log

                  Warning! This utility will find legitimate files in addition to malware.
                  Do not remove anything unless you are sure you know what you're doing.

                  Find.bat is running from: C:\findit\Find It NT-2K-XP

                  ------- System Files in System32 Directory -------
                  Het volume in station C heeft geen naam.
                  Het volumenummer is 10CC-2106

                  Map van C:\WINDOWS\System32

                  04-01-2005 19:32 224.398 j8p00i7me8.dll
                  04-01-2005 13:25 224.320 dn2u01f9e.dll
                  01-01-2005 14:09 <DIR> dllcache
                  10-12-2004 15:03 49.152 gpsB2.dll
                  09-12-2004 20:13 <DIR> Microsoft
                  30-09-1999 19:21 166.672 mstext35.dll
                  28-09-1999 21:42 1.050.896 msjet35.dll
                  09-09-1999 22:06 168.720 msltus35.dll
                  09-09-1999 22:06 252.688 msexcl35.dll
                  25-08-1999 14:57 415.504 msrepl35.dll
                  10-06-1999 09:34 24.848 msjter35.dll
                  10-06-1999 09:34 123.664 msjint35.dll
                  07-06-1999 18:59 250.128 mspdox35.dll
                  25-04-1999 17:00 252.176 Msrd2x35.dll
                  25-04-1999 17:00 368.912 Vbar332.dll
                  25-04-1999 17:00 287.504 Msxbse35.dll
                  14-03-1995 05:22 720 argtmp39.dll
                  15 bestand(en) 3.860.302 bytes
                  2 map(pen) 11.508.248.576 bytes beschikbaar

                  ------- Hidden Files in System32 Directory -------

                  Het volume in station C heeft geen naam.
                  Het volumenummer is 10CC-2106

                  Map van C:\WINDOWS\System32

                  04-01-2005 19:34 890 vsconfig.xml
                  01-01-2005 14:09 <DIR> dllcache
                  30-12-2004 00:40 4.212 zllictbl.dat
                  16-12-2004 16:48 <DIR> GroupPolicy
                  10-12-2004 15:03 49.152 gpsB2.dll
                  09-12-2004 16:29 488 WindowsLogon.manifest
                  09-12-2004 16:29 488 logonui.exe.manifest
                  09-12-2004 16:29 749 sapi.cpl.manifest
                  09-12-2004 16:29 749 ncpa.cpl.manifest
                  09-12-2004 16:29 749 nwc.cpl.manifest
                  09-12-2004 16:29 749 wuaucpl.cpl.manifest
                  09-12-2004 16:29 749 cdplayer.exe.manifest
                  10 bestand(en) 58.975 bytes
                  2 map(pen) 11.508.244.480 bytes beschikbaar

                  ---------- Files Named "Guard" -------------

                  Het volume in station C heeft geen naam.
                  Het volumenummer is 10CC-2106

                  Map van C:\WINDOWS\System32

                  02-01-2005 00:31 223.165 guard.tmp6827.tcf
                  31-12-2004 14:06 223.637 guard.tmp9263.tcf
                  31-12-2004 14:03 223.637 guard.tmp4475.tcf
                  31-12-2004 05:01 222.254 guard.tmp6151.tcf
                  31-12-2004 04:32 226.276 guard.tmp2424.tcf
                  31-12-2004 03:16 226.276 guard.tmp2805.tcf
                  6 bestand(en) 1.345.245 bytes
                  0 map(pen) 11.508.244.480 bytes beschikbaar

                  --------- Temp Files in System32 Directory --------

                  Het volume in station C heeft geen naam.
                  Het volumenummer is 10CC-2106

                  Map van C:\WINDOWS\System32


                  ---------------- User Agent ------------

                  REGEDIT4

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
                  "{B0B034E1-46C4-45DB-B211-344BE5AB0E55}"=""


                  ------------ Keys Under Notify ------------

                  REGEDIT4

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
                  "DLLName"="Ati2evxx.dll"
                  "Asynchronous"=dword:00000000
                  "Impersonate"=dword:00000001
                  "Lock"="AtiLockEvent"
                  "Logoff"="AtiLogoffEvent"
                  "Logon"="AtiLogonEvent"
                  "Disconnect"="AtiDisConnectEvent"
                  "Reconnect"="AtiReConnectEvent"
                  "Safe"=dword:00000000
                  "Shutdown"="AtiShutdownEvent"
                  "StartScreenSaver"="AtiStartScreenSaverEvent"
                  "StartShell"="AtiStartShellEvent"
                  "Startup"="AtiStartupEvent"
                  "StopScreenSaver"="AtiStopScreenSaverEvent"
                  "Unlock"="AtiUnLockEvent"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
                  "Asynchronous"=dword:00000000
                  "Impersonate"=dword:00000000
                  "DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
                  "Logoff"="ChainWlxLogoffEvent"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
                  "Asynchronous"=dword:00000000
                  "Impersonate"=dword:00000000
                  "DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
                  "Logoff"="CryptnetWlxLogoffEvent"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
                  "DLLName"="cscdll.dll"
                  "Logon"="WinlogonLogonEvent"
                  "Logoff"="WinlogonLogoffEvent"
                  "ScreenSaver"="WinlogonScreenSaverEvent"
                  "Startup"="WinlogonStartupEvent"
                  "Shutdown"="WinlogonShutdownEvent"
                  "StartShell"="WinlogonStartShellEvent"
                  "Impersonate"=dword:00000000
                  "Asynchronous"=dword:00000001

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MCPClient]
                  "Asynchronous"=dword:00000000
                  "DllName"="C:\\Program Files\\Common Files\\Stardock\\mcpstub.dll"
                  "Startup"="MCPSystemStartup"
                  "Logon"="MCPLogonStartup"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
                  "DLLName"="wlnotify.dll"
                  "Logon"="SCardStartCertProp"
                  "Logoff"="SCardStopCertProp"
                  "Lock"="SCardSuspendCertProp"
                  "Unlock"="SCardResumeCertProp"
                  "Enabled"=dword:00000001
                  "Impersonate"=dword:00000001
                  "Asynchronous"=dword:00000001

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
                  "Asynchronous"=dword:00000000
                  "DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
                  "Impersonate"=dword:00000000
                  "StartShell"="SchedStartShell"
                  "Logoff"="SchedEventLogOff"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
                  "Logoff"="WLEventLogoff"
                  "Impersonate"=dword:00000000
                  "Asynchronous"=dword:00000001
                  "DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
                  "DLLName"="WlNotify.dll"
                  "Lock"="SensLockEvent"
                  "Logon"="SensLogonEvent"
                  "Logoff"="SensLogoffEvent"
                  "Safe"=dword:00000001
                  "MaxWait"=dword:00000258
                  "StartScreenSaver"="SensStartScreenSaverEvent"
                  "StopScreenSaver"="SensStopScreenSaverEvent"
                  "Startup"="SensStartupEvent"
                  "Shutdown"="SensShutdownEvent"
                  "StartShell"="SensStartShellEvent"
                  "PostShell"="SensPostShellEvent"
                  "Disconnect"="SensDisconnectEvent"
                  "Reconnect"="SensReconnectEvent"
                  "Unlock"="SensUnlockEvent"
                  "Impersonate"=dword:00000001
                  "Asynchronous"=dword:00000001

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SideBySide]
                  "Asynchronous"=dword:00000000
                  "DllName"="C:\\WINDOWS\\system32\\dn2u01f9e.dll"
                  "Impersonate"=dword:00000000
                  "Logon"="WinLogon"
                  "Logoff"="WinLogoff"
                  "Shutdown"="WinShutdown"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
                  "Asynchronous"=dword:00000000
                  "DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
                  "Impersonate"=dword:00000000
                  "Logoff"="TSEventLogoff"
                  "Logon"="TSEventLogon"
                  "PostShell"="TSEventPostShell"
                  "Shutdown"="TSEventShutdown"
                  "StartShell"="TSEventStartShell"
                  "Startup"="TSEventStartup"
                  "MaxWait"=dword:00000258
                  "Reconnect"="TSEventReconnect"
                  "Disconnect"="TSEventDisconnect"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB]
                  "Asynchronous"=dword:00000000
                  "DllName"="C:\\Program Files\\Stardock\\Object Desktop\\WindowBlinds\\fastload.dll"
                  "Startup"="StartSys"
                  "Logon"="StartWB"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
                  "DLLName"="wlnotify.dll"
                  "Logon"="RegisterTicketExpiredNotificationEvent"
                  "Logoff"="UnregisterTicketExpiredNotificationEvent"
                  "Impersonate"=dword:00000001
                  "Asynchronous"=dword:00000001


                  ------------------ Locate.com Results ------------------

                  C:\WINDOWS\SYSTEM32\
                  cdplay~1.man Thu 9 Dec 2004 16:29:48 A..HR 749 0,73 K
                  dn2u01~1.dll Tue 4 Jan 2005 13:25:32 ..S.R 224.320 219,06 K
                  gpsb2.dll Fri 10 Dec 2004 15:03:26 A.SH. 49.152 48,00 K
                  j8p00i~1.dll Tue 4 Jan 2005 19:32:54 ..S.R 224.398 219,14 K
                  logonu~1.man Thu 9 Dec 2004 16:29:54 A..HR 488 0,48 K
                  ncpacp~1.man Thu 9 Dec 2004 16:29:48 A..HR 749 0,73 K
                  nwccpl~1.man Thu 9 Dec 2004 16:29:48 A..HR 749 0,73 K
                  sapicp~1.man Thu 9 Dec 2004 16:29:48 A..HR 749 0,73 K
                  vsconfig.xml Tue 4 Jan 2005 19:34:38 A..H. 890 0,87 K
                  window~1.man Thu 9 Dec 2004 16:29:54 A..HR 488 0,48 K
                  wuaucp~1.man Thu 9 Dec 2004 16:29:48 A..HR 749 0,73 K
                  zllictbl.dat Thu 30 Dec 2004 0:40:28 ...H. 4.212 4,11 K

                  12 items found: 12 files, 0 directories.
                  Total of file sizes: 507.693 bytes 495,79 K

                  ------------ Strings.exe Qoologic Results ------------


                  -------------- Strings.exe Aspack Results -------------

                  C:\WINDOWS\system32\Formats.dll: .aspack
                  C:\WINDOWS\system32\ntdll.dll: .aspack
                  C:\WINDOWS\system32\ShellPicture.dll: .aspack

                  ----------------- HKLM Run Key ------------------

                  REGEDIT4

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
                  "zBrowser Launcher"="C:\\Program Files\\Logitech\\iTouch\\iTouch.exe"
                  "Logitech Utility"="Logi_MwX.Exe"
                  "Disc Detector"="C:\\Program Files\\Creative\\ShareDLL\\CtNotify.exe"
                  "CreativeMixer"="C:\\Program Files\\Creative\\Audio2K\\PROGRAM\\CTMIX32.EXE /t"
                  "ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
                  "AcctMgr"="C:\\Program Files\\Norton SystemWorks\\Password Manager\\AcctMgr.exe /startup"
                  "SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_06\\bin\\jusched.exe"
                  "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
                  "C-Media Mixer"="Mixer.exe /startup"
                  "NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
                  "ntsmod"="C:\\WINDOWS\\system32\\ntsmod.exe"
                  "SpybotSnD"="\"C:\\Program Files\\Spybot - Search & Destroy\\SpybotSD.exe\""
                  "Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
                  "LogonStudio"="\"C:\\Program Files\\WinCustomize\\LogonStudio\\logonstudio.exe\" /RANDOM"
                  "BootSkin Startup Jobs"="\"C:\\Program Files\\Stardock\\WinCustomize\\BootSkin\\bootskin.exe\" /StartupJobs"
                  "THGuard"="\"C:\\Program Files\\TrojanHunter 4.0\\THGuard.exe\""
                  "Babylon Client"="C:\\Program Files\\Babylon\\Babylon.exe -AutoStart"

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
                  "Installed"="1"

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
                  "Installed"="1"
                  "NoChange"="1"

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
                  "Installed"="1"


                  


                  HJT log

                  Logfile of HijackThis v1.99.0
                  Scan saved at 19:48:51, on 4-1-2005
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\System32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Common Files\Stardock\SDMCP.exe
                  C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  C:\Program Files\Creative\ShareDLL\CtNotify.exe
                  C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                  C:\Program Files\Logitech\MouseWare\system\em_exec.exe
                  C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe
                  C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
                  C:\Program Files\QuickTime\qttask.exe
                  C:\Program Files\Creative\ShareDLL\MediaDet.Exe
                  C:\WINDOWS\Mixer.exe
                  C:\WINDOWS\system32\ntsmod.exe
                  C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                  C:\Program Files\TrojanHunter 4.0\THGuard.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\GPSoftware\Directory Opus\dopus.exe
                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  C:\Program Files\CursorXP\CursorXP.exe
                  C:\Program Files\Babylon\babyl.exe
                  C:\Program Files\Messenger\msmsgs.exe
                  C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                  C:\Program Files\NetMeter\NetMeter.exe
                  C:\WINDOWS\System32\CTSvcCDA.exe
                  C:\Program Files\ewido\security suite\ewidoctrl.exe
                  C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
                  C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
                  C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
                  C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
                  C:\Program Files\InterVideo\WinDVD4PR\WinScheduler.exe
                  C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                  C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                  C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
                  C:\Program Files\TechSmith\SnagIt 7\SnagIt32.exe
                  C:\Program Files\Symmetricom\SymmTime\SymmTime.exe
                  C:\Program Files\ICONDESK\IconDesk.exe
                  C:\Program Files\SpywareGuard\sgmain.exe
                  C:\Program Files\TechSmith\SnagIt 7\TSCHelp.exe
                  C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
                  C:\Program Files\SpywareGuard\sgbhp.exe
                  C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
                  C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
                  C:\HJT\hijackthis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
                  R3 - Default URLSearchHook is missing
                  O1 - Hosts: 69.20.16.183 auto.search.msn.com
                  O1 - Hosts: 69.20.16.183 search.netscape.com
                  O1 - Hosts: 69.20.16.183 ieautosearch
                  O1 - Hosts: 69.20.16.183 ieautosearch
                  O1 - Hosts: 69.20.16.183 ieautosearch
                  O1 - Hosts: 69.20.16.183 ieautosearch
                  O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
                  O3 - Toolbar: PopUpCop - {DB43E4E6-FF8A-4018-8C8E-F68587A44A73} - C:\PROGRA~1\PopUpCop\PopUpCop.dll
                  O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
                  O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
                  O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
                  O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
                  O4 - HKLM\..\Run: [CreativeMixer] C:\Program Files\Creative\Audio2K\PROGRAM\CTMIX32.EXE /t
                  O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                  O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                  O4 - HKLM\..\Run: [ntsmod] C:\WINDOWS\system32\ntsmod.exe
                  O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
                  O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                  O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
                  O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\Program Files\Stardock\WinCustomize\BootSkin\bootskin.exe" /StartupJobs
                  O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.0\THGuard.exe"
                  O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon.exe -AutoStart
                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [DOpus] C:\Program Files\GPSoftware\Directory Opus\dopus.exe
                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
                  O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                  O4 - HKCU\..\Run: [C:\Program Files\NetMeter\NetMeter.exe] C:\Program Files\NetMeter\NetMeter.exe
                  O4 - Startup: ICONDESK.lnk = C:\Program Files\ICONDESK\IconDesk.exe
                  O4 - Startup: Rainlendar.lnk = C:\Program Files\Rainlendar\Rainlendar.exe
                  O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
                  O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                  O4 - Global Startup: hp psc 1000 series.lnk = ?
                  O4 - Global Startup: hpoddt01.exe.lnk = ?
                  O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
                  O4 - Global Startup: InterVideo WinScheduler.lnk = C:\Program Files\InterVideo\WinDVD4PR\WinScheduler.exe
                  O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                  O4 - Global Startup: SnagIt 7.lnk = C:\Program Files\TechSmith\SnagIt 7\SnagIt32.exe
                  O4 - Global Startup: SymmTime.lnk = ?
                  O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
                  O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
                  O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                  O8 - Extra context menu item: Open Image in New Window - res://C:\Program Files\PopUpCop\popupcop.dll/imagenew
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://simcity.ea.com/update/EARTPX.cab
                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1102608662085
                  O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
                  O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
                  O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
                  O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                  O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
                  O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                  O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.exe
                  O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
                  O23 - Service: iPod-service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: Norton AntiVirus Auto-Protect - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
                  O23 - Service: Norton Unerase Protection - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                  O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
                  O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
                  O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
                  O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
                  O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

                  Comment


                  • #10
                    schijnbaar zijn de "guard " bestanden ook niet verwijderd zie ik nu

                    Comment


                    • #11
                      gebruik deze versie eens van killbox :



                      KOPIER alle onderstaande text in een text file
                      VERVOLGENS uw internet verbinding verbreken!!


                      Dan, start notepad, en copy/paste de quetebox text in de file
                      Sla de file op als alle bestanden (*.*) met de naam fixme.reg


                      REGEDIT4

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
                      "{B0B034E1-46C4-45DB-B211-344BE5AB0E55}"=-


                      [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SideBySide]



                      Nu mag je KILLBOX uitpakken in zijn eigen folder
                      vervolgens klik je op KillBox.exe om het te gebruiken

                      In het hoofdscherm ga je naar "tools" in het hoofdmenu en klik je op "Delete Temp Files."

                      Terug in het hoofscherm klik selecteer je de optie "Delete on Reboot"

                      In de box "Full Path of File to Delete", kopier en plak de onderstaande lijn:

                      C:\WINDOWS\System32\gpsB2.dll

                      Klik op htee knopje met de rode cirkel en het witte kruis.
                      Bij de vraag om te herstarten (reboot) klik "NO"

                      Herhaal bovenstaande procedure voor alle onderstaande lijntjes (elk appart), telkens NO voor de reboot


                      C:\WINDOWS\System32\j8p00i7me8.dll
                      C:\WINDOWS\System32\dn2u01f9e.dll
                      C:\WINDOWS\System32\guard.tmp6827.tcf
                      C:\WINDOWS\System32\guard.tmp9263.tcf
                      C:\WINDOWS\System32\guard.tmp4475.tcf
                      C:\WINDOWS\System32\guard.tmp2424.tcf
                      C:\WINDOWS\System32\guard.tmp2805.tcf



                      Ten laatste plaats je in de "Full Path of File to Delete" box, kopier en plak onderstaande:

                      C:\WINDOWS\System32\guard.tmp

                      Klik opnieuw op de rode cirkel met het witte kruis.
                      Bij de vraag om te rebooten (heropstarten) klik je op "YES"


                      Scan opnieuw met hijackthis
                      vink de onderstaande lijntje aan
                      R3 - Default URLSearchHook is missing
                      O1 - Hosts: 69.20.16.183 auto.search.msn.com
                      O1 - Hosts: 69.20.16.183 search.netscape.com
                      O1 - Hosts: 69.20.16.183 ieautosearch
                      O1 - Hosts: 69.20.16.183 ieautosearch
                      O1 - Hosts: 69.20.16.183 ieautosearch
                      O1 - Hosts: 69.20.16.183 ieautosearch
                      sluit alle vensters behalve hijackthis
                      KLIK OP FIX


                      Herstart de PC.


                      Nu de hoster.zip uitpakken
                      Selecteer "Restore Original Hosts"
                      Klik OK en dan "exit Hoster"

                      heropstarten


                      nu mage je terug op het net

                      Doe een scan met ad-aware zoals hier opgegeven met de vx2 add-on




                      Download en installeer http://www.ccleaner.com/
                      Start CCleaner en klik op Run Cleaner rechts onderaan


                      Laat me weten of je problem hebt met uw RecycleBin
                      maak een text file met wat onbeduiden text
                      sla het op
                      en dan verwijderen
                      nu moet je opletten of je de vraag krijkt om het naar de vuilabk te sturen of niet
                      indien neen dan is er een probleem , laat me het weten .


                      laatste reboot alvorens....ik een vers logje willen met onderstaande progies
                      HijackThis log
                      Find_It log




                      Doe een scan met http://www.kaspersky.com/scanforvirus eerst "browse" en dan "submit
                      C:\WINDOWS\system32\ntsmod.exe
                      C:\windows\system32\asledit.dll
                      laat mle weten wat de resultaten zijn
                      not so Helpless ...

                      Comment


                      • #12
                        http://users.telenet.be/Helpless/fightforasafeinternet/menu/adaware.html

                        deze link is dood , maar als ik het mij goed herinner moet je Adaware een volledige scan laten doen ( zowel normaal als in safe mode - beide dus ) en dan de VX2 - cleaner starten ( mocht ie nog aanwezig zijn ) .

                        Het ziet er naar uit dat ik alle "kwaaie " dll's eruit gekregen heb , maar ik moest behoorlijk improviseren . Er waren er een aantal in gebruik en killbox gaf dezelfde melding als ik hierboven aangaf : "PendingFilerename operations Registry data has been removed by external process " .

                        Ik heb toem wintasks geopend en een aanntal processen gestopt . Heb gewoon geprobeerd tot killbox de dll's wél kon verwijderen .

                        Even om zeker te zijn : adawre volledige scan laten doen in safe mode ?? En in gewone modus ??

                        Vervolgens VX-cleaner starten,indien nodig ??

                        Comment


                        • #13
                          excuses , link werkt wel

                          Comment


                          • #14
                            Download de gratis VX2 Cleaner hier : plvx2cleaner.exe




                            Sluit Ad-Aware SE build 1.05 en Ad-Watch (indien bezig)
                            Install de VX2 Cleaner door er 2x op the kliken, met onderstaande als automatish gevolg



                            Start Ad-Aware SE build 1.05
                            ga naar “Add-ons”
                            Selecteer de VX2 Cleaner plug-in en klik op “Run Plugin”




                            Indien uw pc niet is geinfecteerd dan klik je op “Close”.




                            indien uw pc geinfecteerd is .....

                            Selecteer “Clean System”
                            pc Her-opstarten
                            Scan de pc opnieuw met Ad-Aware
                            delete alle VX2 objects de werden gevonden
                            pc nog eens Her-opstarten
                            En een tweede Scan uitvoeren om zeker te zijn dat alles weg is.


                            not so Helpless ...

                            Comment


                            • #15
                              HJT-log

                              Logfile of HijackThis v1.99.0
                              Scan saved at 22:06:11, on 4-1-2005
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\System32\Ati2evxx.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\Common Files\Stardock\SDMCP.exe
                              C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbload.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                              C:\Program Files\Logitech\iTouch\iTouch.exe
                              C:\Program Files\Creative\ShareDLL\CtNotify.exe
                              C:\Program Files\Creative\Audio2K\PROGRAM\CTMIX32.EXE
                              C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                              C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe
                              C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
                              C:\Program Files\QuickTime\qttask.exe
                              C:\Program Files\Logitech\MouseWare\system\em_exec.exe
                              C:\Program Files\Creative\ShareDLL\MediaDet.Exe
                              C:\WINDOWS\Mixer.exe
                              C:\WINDOWS\system32\ntsmod.exe
                              C:\Program Files\TrojanHunter 4.0\THGuard.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\GPSoftware\Directory Opus\dopus.exe
                              C:\Program Files\Babylon\babyl.exe
                              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                              C:\Program Files\CursorXP\CursorXP.exe
                              C:\Program Files\Messenger\msmsgs.exe
                              C:\Program Files\NetMeter\NetMeter.exe
                              C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
                              C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
                              C:\Program Files\InterVideo\WinDVD4PR\WinScheduler.exe
                              C:\Program Files\TechSmith\SnagIt 7\SnagIt32.exe
                              C:\Program Files\Symmetricom\SymmTime\SymmTime.exe
                              C:\Program Files\ICONDESK\IconDesk.exe
                              C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
                              C:\Program Files\SpywareGuard\sgmain.exe
                              C:\Program Files\TechSmith\SnagIt 7\TSCHelp.exe
                              C:\Program Files\SpywareGuard\sgbhp.exe
                              C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                              C:\WINDOWS\System32\CTSvcCDA.exe
                              C:\Program Files\ewido\security suite\ewidoctrl.exe
                              C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
                              C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
                              C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                              C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
                              C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
                              C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Norton SystemWorks\Norton Antivirus\OPScan.exe
                              C:\HJT\hijackthis.exe

                              O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton Antivirus\NavShExt.dll
                              O3 - Toolbar: PopUpCop - {DB43E4E6-FF8A-4018-8C8E-F68587A44A73} - C:\PROGRA~1\PopUpCop\PopUpCop.dll
                              O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
                              O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                              O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
                              O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
                              O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
                              O4 - HKLM\..\Run: [CreativeMixer] C:\Program Files\Creative\Audio2K\PROGRAM\CTMIX32.EXE /t
                              O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                              O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe /startup
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                              O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
                              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                              O4 - HKLM\..\Run: [ntsmod] C:\WINDOWS\system32\ntsmod.exe
                              O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
                              O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                              O4 - HKLM\..\Run: [LogonStudio] "C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" /RANDOM
                              O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\Program Files\Stardock\WinCustomize\BootSkin\bootskin.exe" /StartupJobs
                              O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.0\THGuard.exe"
                              O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon.exe -AutoStart
                              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [DOpus] C:\Program Files\GPSoftware\Directory Opus\dopus.exe
                              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                              O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe
                              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                              O4 - HKCU\..\Run: [C:\Program Files\NetMeter\NetMeter.exe] C:\Program Files\NetMeter\NetMeter.exe
                              O4 - Startup: ICONDESK.lnk = C:\Program Files\ICONDESK\IconDesk.exe
                              O4 - Startup: Rainlendar.lnk = C:\Program Files\Rainlendar\Rainlendar.exe
                              O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
                              O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                              O4 - Global Startup: hp psc 1000 series.lnk = ?
                              O4 - Global Startup: hpoddt01.exe.lnk = ?
                              O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
                              O4 - Global Startup: InterVideo WinScheduler.lnk = C:\Program Files\InterVideo\WinDVD4PR\WinScheduler.exe
                              O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
                              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                              O4 - Global Startup: SnagIt 7.lnk = C:\Program Files\TechSmith\SnagIt 7\SnagIt32.exe
                              O4 - Global Startup: SymmTime.lnk = ?
                              O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
                              O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
                              O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                              O8 - Extra context menu item: Open Image in New Window - res://C:\Program Files\PopUpCop\popupcop.dll/imagenew
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
                              O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://simcity.ea.com/update/EARTPX.cab
                              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1102608662085
                              O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
                              O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
                              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
                              O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
                              O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                              O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
                              O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                              O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.exe
                              O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
                              O23 - Service: iPod-service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: Norton AntiVirus Auto-Protect - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\navapsvc.exe
                              O23 - Service: Norton Unerase Protection - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
                              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                              O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Antivirus\SAVScan.exe
                              O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
                              O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
                              O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
                              O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

                              en find it log

                              Warning! This utility will find legitimate files in addition to malware.
                              Do not remove anything unless you are sure you know what you're doing.

                              Find.bat is running from: C:\findit\Find It NT-2K-XP

                              ------- System Files in System32 Directory -------
                              Het volume in station C heeft geen naam.
                              Het volumenummer is 10CC-2106

                              Map van C:\WINDOWS\System32

                              01-01-2005 14:09 <DIR> dllcache
                              09-12-2004 20:13 <DIR> Microsoft
                              30-09-1999 19:21 166.672 mstext35.dll
                              28-09-1999 21:42 1.050.896 msjet35.dll
                              09-09-1999 22:06 252.688 msexcl35.dll
                              09-09-1999 22:06 168.720 msltus35.dll
                              25-08-1999 14:57 415.504 msrepl35.dll
                              10-06-1999 09:34 24.848 msjter35.dll
                              10-06-1999 09:34 123.664 msjint35.dll
                              07-06-1999 18:59 250.128 mspdox35.dll
                              25-04-1999 17:00 252.176 Msrd2x35.dll
                              25-04-1999 17:00 368.912 Vbar332.dll
                              25-04-1999 17:00 287.504 Msxbse35.dll
                              14-03-1995 05:22 720 argtmp39.dll
                              12 bestand(en) 3.362.432 bytes
                              2 map(pen) 11.548.803.072 bytes beschikbaar

                              ------- Hidden Files in System32 Directory -------

                              Het volume in station C heeft geen naam.
                              Het volumenummer is 10CC-2106

                              Map van C:\WINDOWS\System32

                              04-01-2005 21:19 890 vsconfig.xml
                              01-01-2005 14:09 <DIR> dllcache
                              30-12-2004 00:40 4.212 zllictbl.dat
                              16-12-2004 16:48 <DIR> GroupPolicy
                              10-12-2004 15:03 49.152 gpsB2.dll
                              09-12-2004 16:29 488 WindowsLogon.manifest
                              09-12-2004 16:29 488 logonui.exe.manifest
                              09-12-2004 16:29 749 sapi.cpl.manifest
                              09-12-2004 16:29 749 ncpa.cpl.manifest
                              09-12-2004 16:29 749 nwc.cpl.manifest
                              09-12-2004 16:29 749 wuaucpl.cpl.manifest
                              09-12-2004 16:29 749 cdplayer.exe.manifest
                              10 bestand(en) 58.975 bytes
                              2 map(pen) 11.548.798.976 bytes beschikbaar

                              ---------- Files Named "Guard" -------------

                              Het volume in station C heeft geen naam.
                              Het volumenummer is 10CC-2106

                              Map van C:\WINDOWS\System32

                              04-01-2005 21:16 224.398 guard.tmp
                              1 bestand(en) 224.398 bytes
                              0 map(pen) 11.548.798.976 bytes beschikbaar

                              --------- Temp Files in System32 Directory --------

                              Het volume in station C heeft geen naam.
                              Het volumenummer is 10CC-2106

                              Map van C:\WINDOWS\System32

                              04-01-2005 21:16 224.398 guard.tmp
                              1 bestand(en) 224.398 bytes
                              0 map(pen) 11.548.794.880 bytes beschikbaar

                              ---------------- User Agent ------------

                              REGEDIT4

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
                              "{B0B034E1-46C4-45DB-B211-344BE5AB0E55}"=""


                              ------------ Keys Under Notify ------------

                              REGEDIT4

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
                              "DLLName"="Ati2evxx.dll"
                              "Asynchronous"=dword:00000000
                              "Impersonate"=dword:00000001
                              "Lock"="AtiLockEvent"
                              "Logoff"="AtiLogoffEvent"
                              "Logon"="AtiLogonEvent"
                              "Disconnect"="AtiDisConnectEvent"
                              "Reconnect"="AtiReConnectEvent"
                              "Safe"=dword:00000000
                              "Shutdown"="AtiShutdownEvent"
                              "StartScreenSaver"="AtiStartScreenSaverEvent"
                              "StartShell"="AtiStartShellEvent"
                              "Startup"="AtiStartupEvent"
                              "StopScreenSaver"="AtiStopScreenSaverEvent"
                              "Unlock"="AtiUnLockEvent"

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
                              "Asynchronous"=dword:00000000
                              "Impersonate"=dword:00000000
                              "DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c,00
                              "Logoff"="ChainWlxLogoffEvent"

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
                              "Asynchronous"=dword:00000000
                              "Impersonate"=dword:00000000
                              "DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c,6c,00
                              "Logoff"="CryptnetWlxLogoffEvent"

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
                              "DLLName"="cscdll.dll"
                              "Logon"="WinlogonLogonEvent"
                              "Logoff"="WinlogonLogoffEvent"
                              "ScreenSaver"="WinlogonScreenSaverEvent"
                              "Startup"="WinlogonStartupEvent"
                              "Shutdown"="WinlogonShutdownEvent"
                              "StartShell"="WinlogonStartShellEvent"
                              "Impersonate"=dword:00000000
                              "Asynchronous"=dword:00000001

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\H323TSP]
                              "Asynchronous"=dword:00000000
                              "DllName"="C:\\WINDOWS\\system32\\l4n4le5q1h.dll"
                              "Impersonate"=dword:00000000
                              "Logon"="WinLogon"
                              "Logoff"="WinLogoff"
                              "Shutdown"="WinShutdown"

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MCPClient]
                              "Asynchronous"=dword:00000000
                              "DllName"="C:\\Program Files\\Common Files\\Stardock\\mcpstub.dll"
                              "Startup"="MCPSystemStartup"
                              "Logon"="MCPLogonStartup"

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
                              "DLLName"="wlnotify.dll"
                              "Logon"="SCardStartCertProp"
                              "Logoff"="SCardStopCertProp"
                              "Lock"="SCardSuspendCertProp"
                              "Unlock"="SCardResumeCertProp"
                              "Enabled"=dword:00000001
                              "Impersonate"=dword:00000001
                              "Asynchronous"=dword:00000001

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
                              "Asynchronous"=dword:00000000
                              "DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
                              "Impersonate"=dword:00000000
                              "StartShell"="SchedStartShell"
                              "Logoff"="SchedEventLogOff"

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
                              "Logoff"="WLEventLogoff"
                              "Impersonate"=dword:00000000
                              "Asynchronous"=dword:00000001
                              "DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c,6c,00

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
                              "DLLName"="WlNotify.dll"
                              "Lock"="SensLockEvent"
                              "Logon"="SensLogonEvent"
                              "Logoff"="SensLogoffEvent"
                              "Safe"=dword:00000001
                              "MaxWait"=dword:00000258
                              "StartScreenSaver"="SensStartScreenSaverEvent"
                              "StopScreenSaver"="SensStopScreenSaverEvent"
                              "Startup"="SensStartupEvent"
                              "Shutdown"="SensShutdownEvent"
                              "StartShell"="SensStartShellEvent"
                              "PostShell"="SensPostShellEvent"
                              "Disconnect"="SensDisconnectEvent"
                              "Reconnect"="SensReconnectEvent"
                              "Unlock"="SensUnlockEvent"
                              "Impersonate"=dword:00000001
                              "Asynchronous"=dword:00000001

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
                              "Asynchronous"=dword:00000000
                              "DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c,6c,00
                              "Impersonate"=dword:00000000
                              "Logoff"="TSEventLogoff"
                              "Logon"="TSEventLogon"
                              "PostShell"="TSEventPostShell"
                              "Shutdown"="TSEventShutdown"
                              "StartShell"="TSEventStartShell"
                              "Startup"="TSEventStartup"
                              "MaxWait"=dword:00000258
                              "Reconnect"="TSEventReconnect"
                              "Disconnect"="TSEventDisconnect"

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB]
                              "Asynchronous"=dword:00000000
                              "DllName"="C:\\Program Files\\Stardock\\Object Desktop\\WindowBlinds\\fastload.dll"
                              "Startup"="StartSys"
                              "Logon"="StartWB"

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
                              "DLLName"="wlnotify.dll"
                              "Logon"="RegisterTicketExpiredNotificationEvent"
                              "Logoff"="UnregisterTicketExpiredNotificationEvent"
                              "Impersonate"=dword:00000001
                              "Asynchronous"=dword:00000001


                              ------------------ Locate.com Results ------------------

                              C:\WINDOWS\SYSTEM32\
                              cdplay~1.man Thu 9 Dec 2004 16:29:48 A..HR 749 0,73 K
                              gpsb2.dll Fri 10 Dec 2004 15:03:26 A..H. 49.152 48,00 K
                              logonu~1.man Thu 9 Dec 2004 16:29:54 A..HR 488 0,48 K
                              ncpacp~1.man Thu 9 Dec 2004 16:29:48 A..HR 749 0,73 K
                              nwccpl~1.man Thu 9 Dec 2004 16:29:48 A..HR 749 0,73 K
                              sapicp~1.man Thu 9 Dec 2004 16:29:48 A..HR 749 0,73 K
                              vsconfig.xml Tue 4 Jan 2005 21:19:44 A..H. 890 0,87 K
                              window~1.man Thu 9 Dec 2004 16:29:54 A..HR 488 0,48 K
                              wuaucp~1.man Thu 9 Dec 2004 16:29:48 A..HR 749 0,73 K
                              zllictbl.dat Thu 30 Dec 2004 0:40:28 ...H. 4.212 4,11 K

                              10 items found: 10 files, 0 directories.
                              Total of file sizes: 58.975 bytes 57,59 K

                              ------------ Strings.exe Qoologic Results ------------


                              -------------- Strings.exe Aspack Results -------------

                              C:\WINDOWS\system32\Formats.dll: .aspack
                              C:\WINDOWS\system32\ntdll.dll: .aspack
                              C:\WINDOWS\system32\ShellPicture.dll: .aspack

                              ----------------- HKLM Run Key ------------------

                              REGEDIT4

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
                              "zBrowser Launcher"="C:\\Program Files\\Logitech\\iTouch\\iTouch.exe"
                              "Logitech Utility"="Logi_MwX.Exe"
                              "Disc Detector"="C:\\Program Files\\Creative\\ShareDLL\\CtNotify.exe"
                              "CreativeMixer"="C:\\Program Files\\Creative\\Audio2K\\PROGRAM\\CTMIX32.EXE /t"
                              "ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
                              "AcctMgr"="C:\\Program Files\\Norton SystemWorks\\Password Manager\\AcctMgr.exe /startup"
                              "SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_06\\bin\\jusched.exe"
                              "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
                              "C-Media Mixer"="Mixer.exe /startup"
                              "NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
                              "ntsmod"="C:\\WINDOWS\\system32\\ntsmod.exe"
                              "SpybotSnD"="\"C:\\Program Files\\Spybot - Search & Destroy\\SpybotSD.exe\""
                              "Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
                              "LogonStudio"="\"C:\\Program Files\\WinCustomize\\LogonStudio\\logonstudio.exe\" /RANDOM"
                              "BootSkin Startup Jobs"="\"C:\\Program Files\\Stardock\\WinCustomize\\BootSkin\\bootskin.exe\" /StartupJobs"
                              "THGuard"="\"C:\\Program Files\\TrojanHunter 4.0\\THGuard.exe\""
                              "Babylon Client"="C:\\Program Files\\Babylon\\Babylon.exe -AutoStart"

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
                              "Installed"="1"

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
                              "Installed"="1"
                              "NoChange"="1"

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
                              "Installed"="1"


                              


                              Ik heb overigens ook het bestand NTSmod.exe laten scannen op KAV -site , maar dit bleek in orde . Resultaten van hierboven zijn ná CC-cleaner , maar vóór Hoster gedraaid heeft .

                              Adaware vond VX2 niet , vond twee objecten : wijziging van homepage ( waarschijnlijk doordat Spybot die op slot heeft gezet ) en MRU-list

                              Comment

                              Sorry, you are not authorized to view this page
                              Working...
                              X
                              😀
                              🥰
                              🤢
                              😎
                              😡
                              👍
                              👎