Vraag & Antwoord

Beveiliging & privacy

HijackThis log, feedback please

2 antwoorden
  • Logfile of HijackThis v1.99.1 Scan saved at 17:28:25, on 30-6-2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Mixer.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Microsoft Hardware\Keyboard\type32.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\D-Tools\daemon.exe C:\Program Files\Archive\archive.exe C:\Program Files\Iptp\Tzqdhu.exe C:\Program Files\Microsoft AntiSpyware\gcasServ.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe C:\Program Files\E-Color\Common\IconMgr.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\Program Files\Norton AntiVirus\SAVScan.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Messenger\msmsgs.exe C:\Documents and Settings\Bert.BB-HS63R9V81S21\Bureaublad\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://student.rug.nl/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen R3 - Default URLSearchHook is missing O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {841CEDB1-39A8-4F80-0000-000005000000} - C:\WINDOWS\system32\qtzasrbx.dll (file missing) O2 - BHO: (no name) - {842C13B2-39A8-4F80-0000-000005000000} - C:\WINDOWS\system32\fkotexcj.dll (file missing) O2 - BHO: (no name) - {842CB3B1-39A8-4F80-0000-000005000000} - C:\WINDOWS\system32\dgwtweuf.dll (file missing) O2 - BHO: (no name) - {844C85B2-39A8-4F80-0000-000005000000} - (no file) O2 - BHO: (no name) - {846C9FB1-39A8-4F80-0000-000005000000} - C:\WINDOWS\system32\jonqyoca.dll (file missing) O2 - BHO: (no name) - {849C8DB1-39A8-4F80-0000-000005000000} - C:\WINDOWS\system32\nxzdxcgi.dll (file missing) O2 - BHO: (no name) - {849CB2B2-39A8-4F80-0000-000005000000} - C:\WINDOWS\system32\bxpuowbw.dll (file missing) O2 - BHO: (no name) - {849CEFB1-39A8-4F80-0000-000005000000} - C:\WINDOWS\system32\zjmrtvuw.dll (file missing) O2 - BHO: (no name) - {84CC98B1-39A8-4F80-0000-000005000000} - (no file) O2 - BHO: (no name) - {84DC82B2-39A8-4F80-0000-000005000000} - C:\WINDOWS\system32\gdrmjvnv.dll (file missing) O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O2 - BHO: (no name) - {CB090179-ED44-75FF-9A35-25D0685CEFCE} - C:\WINDOWS\System32\ubpldota.dll (file missing) O2 - BHO: (no name) - {EB241F7D-19F6-0BB1-8B7A-453ACAB5210E} - C:\WINDOWS\System32\sbrpwgga.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: (no name) - {86227D9C-0EFE-4f8a-AA55-30386A3F5686} - (no file) O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe O4 - HKLM\..\Run: [Archive] C:\Program Files\Archive\archive.exe O4 - HKLM\..\Run: [Bdgjjjt] C:\Program Files\Iptp\Tzqdhu.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R O4 - HKCU\..\Run: [Steam] D:\half life\\Steam.exe -silent O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe O4 - Global Startup: E-Color.lnk = C:\Program Files\E-Color\Common\IconMgr.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .MOV: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su-newocx/ocx/15009/CTSUEng.cab O16 - DPF: {1230CB21-C88D-11CF-0000-000000000000} - http://nl.browserupdate.co.uk/cabs/nl0001/nllo0001.cab O16 - DPF: {8731163E-77B9-4F91-9122-F112521C28AF} (MMSPlayerX Class) - http://212.41.157.233:8080/mmawap/jsp/composer/player/mmsPlayer.cab O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su-newocx/ocx/15010/CTPID.cab O23 - Service: kuxfwtpvvzuv (6) - Unknown owner - C:\WINDOWS\system32\6.exe (file missing) O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe vertel wat moet ik eruit gooien???
  • Download en installeer [url=http://www.ccleaner.com/]CCleaner[/url]. Klik bovenaan op de knop "Opties". Kies links in het scherm voor "Gevorderden". Haal het vinkje weg bij "Verwijder alleen tijdelijke bestanden in de windows systeemmap die ouder zijn dan 48 uur". Sluit CCleaner. Gebruik het programma nog niet. Zorg ervoor dat alle verborgen bestanden en mappen weergegeven worden.[url=http://users.telenet.be/marcvn/spyware/1117602.htm]Hoe verborgen bestanden en mappen weergeven.[/url]. Sluit alle open vensters, run HijackThis nog een keer en plaats een vinkje bij de volgende items: [b:e7a4a6f1b6]R3 - Default URLSearchHook is missing O2 - BHO: (no name) - {841CEDB1-39A8-4F80-0000-000005000000} - C:\WINDOWS\system32\qtzasrbx.dll (file missing) O2 - BHO: (no name) - {842C13B2-39A8-4F80-0000-000005000000} - C:\WINDOWS\system32\fkotexcj.dll (file missing) O2 - BHO: (no name) - {842CB3B1-39A8-4F80-0000-000005000000} - C:\WINDOWS\system32\dgwtweuf.dll (file missing) O2 - BHO: (no name) - {844C85B2-39A8-4F80-0000-000005000000} - (no file) O2 - BHO: (no name) - {846C9FB1-39A8-4F80-0000-000005000000} - C:\WINDOWS\system32\jonqyoca.dll (file missing) O2 - BHO: (no name) - {849C8DB1-39A8-4F80-0000-000005000000} - C:\WINDOWS\system32\nxzdxcgi.dll (file missing) O2 - BHO: (no name) - {849CB2B2-39A8-4F80-0000-000005000000} - C:\WINDOWS\system32\bxpuowbw.dll (file missing) O2 - BHO: (no name) - {849CEFB1-39A8-4F80-0000-000005000000} - C:\WINDOWS\system32\zjmrtvuw.dll (file missing) O2 - BHO: (no name) - {84CC98B1-39A8-4F80-0000-000005000000} - (no file) O2 - BHO: (no name) - {84DC82B2-39A8-4F80-0000-000005000000} - C:\WINDOWS\system32\gdrmjvnv.dll (file missing) O2 - BHO: (no name) - {CB090179-ED44-75FF-9A35-25D0685CEFCE} - C:\WINDOWS\System32\ubpldota.dll (file missing) O2 - BHO: (no name) - {EB241F7D-19F6-0BB1-8B7A-453ACAB5210E} - C:\WINDOWS\System32\sbrpwgga.dll O3 - Toolbar: (no name) - {86227D9C-0EFE-4f8a-AA55-30386A3F5686} - (no file) O4 - HKLM\..\Run: [Archive] C:\Program Files\Archive\archive.exe O4 - HKLM\..\Run: [Bdgjjjt] C:\Program Files\Iptp\Tzqdhu.exe O16 - DPF: {1230CB21-C88D-11CF-0000-000000000000} - http://nl.browserupdate.co.uk/cabs/nl0001/nllo0001.cab O23 - Service: kuxfwtpvvzuv (6) - Unknown owner - C:\WINDOWS\system32\6.exe (file missing)[/b:e7a4a6f1b6] Klik daarna op "Fix checked" en sluit HijackThis af. Start de computer in [url=http://users.pandora.be/marcvn/spyware/1378056.htm]veilige modus[/url]. Zoek via Windows verkenner naar volgende bestanden of mappen, en verwijder deze indien ze nog aanwezig zijn: C:\Program Files\Archive C:\Program Files\Iptp Start Ccleaner en klik op de knop "Opschonen". Herstart de computer in normale modus. Start HijackThis opnieuw, maak een nieuwe log en post deze.

Beantwoord deze vraag

Weet jij het antwoord op deze vraag? Registreer of meld je aan met je account

Dit is een gearchiveerde pagina. Antwoorden is niet meer mogelijk.