Vraag & Antwoord

Beveiliging & privacy

HiJack logje.. Veel last van spyware en Zeer trage computer.

9 antwoorden
  • Hoi allemaal, Ik had al problemen met mijn eigen computer (die het al helemaal niet meer doet :? ) Maar nu keek ik op de computer van me broer en dit is helemaal niet meer normaal. Inplaats van een snelle goede computer is het een zeer trage computer geworden met veel spyware. En veel popups waarin ze waarschuwen dat mijn privacy niet meer veilig is. Daarom hier een HiJack logje. Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 9:41:00, on 31-10-2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE C:\WINDOWS\system32\wuauclt.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\MSN Messenger\usnsvc.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Sam\Mijn documenten\HiJackThis_v2.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: MSVPS System - {24038BE3-4EF2-41E2-A603-4CE3BDD9E874} - C:\WINDOWS\movctrlqtn.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: The nssfrch - {1699137C-B90E-4488-97BC-575C896C2B5C} - C:\WINDOWS\nssfrch.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Openen in een nieuwe achtergrondtab - res://C:\Program Files\Windows Live Toolbar\Components\nl-nl\msntabres.dll.mui/229?f441ed9ea50a4f5db1ab5f7332cfd143 O8 - Extra context menu item: Openen in een nieuwe voorgrondtab - res://C:\Program Files\Windows Live Toolbar\Components\nl-nl\msntabres.dll.mui/230?f441ed9ea50a4f5db1ab5f7332cfd143 O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O21 - SSODL: bxsbang - {BDBEC5F8-930D-45DB-AAD2-FAE8B044C47F} - C:\WINDOWS\bxsbang.dll O21 - SSODL: ocgrep - {0D65BF58-0D71-41F1-8A69-B0F981BEEDEB} - C:\WINDOWS\ocgrep.dll O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm -- End of file - 8153 bytes
  • Download [url=http://download.bleepingcomputer.com/sUBs/Beta/ComboFix.exe]Combofix[/url] naar je Bureaublad. [list:e940510c04] Dubbelklik [b:e940510c04]Combofix.exe[/b:e940510c04] Volg de instructies, aanvaard de disclaimer door "[b:e940510c04]1[/b:e940510c04]" te typen en te bevestigen via "[b:e940510c04]Enter[/b:e940510c04]". Tijdens het runnen van de fix, [b:e940510c04]NIET[/b:e940510c04] in het venster klikken, want dit zal je pc doen vasthangen.[/list:u:e940510c04] Wanneer de fix voltooid is en na herstart, zal de log combofix.txt openen. [i:e940510c04]Plaats deze log in je volgende post samen met een nieuw HijackThis log.[/i:e940510c04] [b:e940510c04]Note:[/b:e940510c04] Indien je virusscanner reageert tijdens het downloaden of gebruik van Combofix, mag je dit negeren.
  • ComboFix 07-10-30.5 - Sam 2007-10-31 12:51:55.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1043.18.79 [GMT 1:00]Gestart vanuit: C:\Documents and Settings\Sam\Bureaublad\ComboFix.exe * Nieuw herstelpunt werd aangemaakt . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\Sam\Bureaublad\Error Cleaner.url C:\Documents and Settings\Sam\Bureaublad\Privacy Protector.url C:\Documents and Settings\Sam\Bureaublad\Spyware&Malware Protection.url C:\Documents and Settings\Sam\Favorieten\Error Cleaner.url C:\Documents and Settings\Sam\Favorieten\Privacy Protector.url C:\Documents and Settings\Sam\Favorieten\Spyware&Malware Protection.url C:\Program Files\VideoAccessCodec C:\Program Files\VideoAccessCodec\install.ico C:\Program Files\VideoAccessCodec\Uninstall.exe C:\Program Files\VideoAccessCodec\VideoAccessCodec.ocx C:\WINDOWS\dat.txt C:\WINDOWS\nssfrch.dll C:\WINDOWS\privacy_danger C:\WINDOWS\privacy_danger\images\capt.gif C:\WINDOWS\privacy_danger\images\danger.jpg C:\WINDOWS\privacy_danger\images\down.gif C:\WINDOWS\privacy_danger\images\spacer.gif C:\WINDOWS\privacy_danger\index.htm C:\WINDOWS\rs.txt C:\WINDOWS\search_res.txt . (((((((((((((((((((( Bestanden Gemaakt van 2007-09-28 to 2007-10-31 )))))))))))))))))))))))))))))) . 2007-10-31 12:51 51,200 --a------ C:\WINDOWS\NirCmd.exe 2007-10-30 15:36 339,968 --a------ C:\WINDOWS\ocgrep.dll 2007-10-30 15:36 107,008 --a------ C:\WINDOWS\kthemup.exe 2007-10-30 15:35 290,816 --a------ C:\WINDOWS\movctrlqtn.dll 2007-10-30 15:35 262,144 --a------ C:\WINDOWS\bxsbang.dll 2007-10-26 15:36 <DIR> d-------- C:\Program Files\VirtualDJ 2007-10-26 11:59 <DIR> d-------- C:\Documents and Settings\Sam\Application Data\BSplayer Pro 2007-10-26 11:59 <DIR> d-------- C:\Documents and Settings\Sam\Application Data\BSplayer 2007-10-26 11:58 <DIR> d-------- C:\Program Files\Webteh 2007-10-24 12:36 <DIR> dr-h----- C:\Documents and Settings\Sam\Application Data\SecuROM 2007-10-24 12:36 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll 2007-10-24 12:14 <DIR> d-------- C:\Program Files\EA Sports 2007-10-20 13:21 <DIR> d-------- C:\Program Files\Windows Live Safety Center 2007-10-12 12:43 <DIR> d-------- C:\Documents and Settings\Sam\Application Data\Nokia Multimedia Player 2007-10-11 15:49 <DIR> d-------- C:\Program Files\GameSpy Arcade 2007-10-11 15:49 <DIR> d-------- C:\NVIDIA 2007-09-27 17:51 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys 2007-09-27 17:51 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys 2007-09-27 07:21 <DIR> d---s---- C:\Documents and Settings\Sam\UserData 2007-09-23 16:57 <DIR> d-------- C:\Documents and Settings\Sam\Phone Browser 2007-09-23 16:57 <DIR> d-------- C:\Documents and Settings\Sam\Application Data\DataLayer 2007-09-23 14:15 <DIR> d-------- C:\Program Files\Windows Media Connect 2 2007-09-23 14:13 <DIR> d-------- C:\WINDOWS\system32\LogFiles 2007-09-23 14:13 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF 2007-09-23 14:06 25,827,912 --a------ C:\Program Files\wmp11-windowsxp-x86-nl-nl.exe 2007-09-17 15:30 <DIR> d-------- C:\Documents and Settings\Sam\Application Data\Apple Computer 2007-09-17 15:29 <DIR> d-------- C:\Program Files\iTunes 2007-09-17 15:29 <DIR> d-------- C:\Program Files\iPod 2007-09-17 15:27 <DIR> d-------- C:\Program Files\QuickTime 2007-09-17 15:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer 2007-09-17 15:26 <DIR> d-------- C:\Program Files\Common Files\Apple 2007-09-17 15:26 <DIR> d-------- C:\Program Files\Apple Software Update 2007-09-17 15:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple 2007-09-16 12:44 <DIR> d-------- C:\Program Files\Common Files\Adobe 2007-09-16 12:44 <DIR> d-------- C:\Documents and Settings\Sam\Application Data\AdobeUM 2007-09-16 11:08 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2 2007-09-16 11:08 221,184 --a------ C:\WINDOWS\system32\wmpns.dll 2007-09-16 11:02 <DIR> d-------- C:\Program Files\MSXML 4.0 2007-09-16 09:20 271,224 --a------ C:\WINDOWS\system32\mucltui.dll 2007-09-16 09:20 207,736 --a------ C:\WINDOWS\system32\muweb.dll 2007-09-16 09:18 <DIR> d-------- C:\Documents and Settings\Sam\Contacts 2007-09-15 20:43 <DIR> d-------- C:\Program Files\Windows Live Favorites 2007-09-15 20:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar 2007-09-15 20:41 <DIR> d-------- C:\Program Files\Windows Live Toolbar 2007-09-15 20:40 <DIR> d-------- C:\Program Files\MSN Messenger 2007-09-15 20:34 <DIR> d-------- C:\Program Files\Nokia 2007-09-15 20:34 <DIR> d-------- C:\Program Files\Common Files\PCSuite 2007-09-15 20:34 <DIR> d-------- C:\Program Files\Common Files\Nokia 2007-09-15 20:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Installations 2007-09-15 11:23 <DIR> d-------- C:\Documents and Settings\Sam\Application Data\Nokia 2007-09-15 11:22 <DIR> d-------- C:\Documents and Settings\Sam\Application Data\PC Suite 2007-09-15 11:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Downloaded Installations 2007-09-15 11:00 <DIR> d-------- C:\Program Files\Google 2007-09-14 14:28 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe 2007-09-14 14:21 <DIR> d-------- C:\Documents and Settings\Sam\Incomplete 2007-09-14 14:21 <DIR> d-------- C:\Documents and Settings\Sam\Application Data\LimeWire 2007-09-14 14:20 <DIR> d-------- C:\Program Files\Java 2007-09-14 14:19 <DIR> d-------- C:\Program Files\Common Files\Java 2007-09-14 13:33 <DIR> d-------- C:\Program Files\Windows Defender 2007-09-14 13:25 <DIR> d-------- C:\Program Files\Realtek AC97 2007-09-14 13:25 10,528,768 --a------ C:\WINDOWS\system32\RTLCPL.exe 2007-09-14 13:25 4,027,840 -ra------ C:\WINDOWS\system32\drivers\alcxwdm.sys 2007-09-14 13:25 577,536 --a------ C:\WINDOWS\soundman.exe 2007-09-14 13:25 315,392 --a------ C:\WINDOWS\alcupd.exe 2007-09-14 13:25 217,088 --a------ C:\WINDOWS\Alcrmv.exe 2007-09-14 13:25 147,456 --a------ C:\WINDOWS\system32\RtlCPAPI.dll 2007-09-14 13:25 49,152 --a------ C:\WINDOWS\system32\ChCfg.exe 2007-09-14 13:16 4,274,816 --a------ C:\WINDOWS\system32\nv4_disp.dll 2007-09-14 13:16 1,897,408 --a------ C:\WINDOWS\system32\drivers\nv4_mini.sys 2007-09-14 13:16 57,856 --a------ C:\WINDOWS\system32\drivers\redbook.sys 2007-09-14 13:16 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2007-09-14 13:16 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys 2007-09-14 13:15 2,944 --a------ C:\WINDOWS\system32\drivers\msmpu401.sys 2007-09-14 13:14 <DIR> d--h----- C:\Documents and Settings\Default User\Sjablonen 2007-09-14 13:14 <DIR> d--h----- C:\Documents and Settings\Default User\Onlangs geopend 2007-09-14 13:14 <DIR> d--h----- C:\Documents and Settings\Default User\Netwerkprinteromgeving 2007-09-14 13:14 <DIR> d-------- C:\Documents and Settings\Default User\Mijn documenten 2007-09-14 13:14 <DIR> dr------- C:\Documents and Settings\Default User\Menu Start 2007-09-14 13:14 <DIR> d-------- C:\Documents and Settings\Default User\Favorieten 2007-09-14 13:14 <DIR> d-------- C:\Documents and Settings\Default User\Bureaublad 2007-09-14 13:14 <DIR> d--h----- C:\Documents and Settings\All Users\Sjablonen 2007-09-14 13:14 <DIR> dr------- C:\Documents and Settings\All Users\Menu Start 2007-09-14 13:14 <DIR> d-------- C:\Documents and Settings\All Users\Favorieten 2007-09-14 13:14 <DIR> dr------- C:\Documents and Settings\All Users\Documenten 2007-09-14 13:14 <DIR> d-------- C:\Documents and Settings\All Users\Bureaublad 2007-09-14 13:09 145,792 --a------ C:\WINDOWS\system32\drivers\portcls.sys 2007-09-14 13:09 145,792 --a--c--- C:\WINDOWS\system32\dllcache\portcls.sys 2007-09-14 13:09 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys 2007-09-14 13:09 60,288 --a--c--- C:\WINDOWS\system32\dllcache\drmk.sys 2007-09-14 13:09 10,624 --a------ C:\WINDOWS\system32\drivers\gameenum.sys 2007-09-14 13:09 4,096 --a------ C:\WINDOWS\system32\ksuser.dll 2007-09-14 13:09 4,096 --a--c--- C:\WINDOWS\system32\dllcache\ksuser.dll 2007-09-14 13:08 76,288 --a------ C:\WINDOWS\system32\usbui.dll 2007-09-14 13:08 20,992 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys 2007-09-14 13:07 <DIR> dr------- C:\Program Files 2007-09-14 13:03 <DIR> d--h----- C:\WINDOWS\$hf_mig$ . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-10-31 11:56 --------- d-----w C:\Program Files\Symantec AntiVirus 2007-10-12 11:41 --------- d--h--w C:\Program Files\InstallShield Installation Information 2007-10-12 11:39 --------- d-----w C:\Program Files\Common Files\InstallShield 2007-09-16 12:04 --------- d-----w C:\Program Files\Microsoft Works 2007-09-14 11:58 4,608 ----a-w C:\WINDOWS\system32\w95inf32.dll 2007-09-14 11:58 --------- d-----w C:\Program Files\CyberLink 2007-09-14 11:47 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2007-09-14 11:46 --------- d-----w C:\Program Files\Symantec 2007-09-14 11:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec 2007-09-14 11:37 --------- d-----w C:\Program Files\Common Files\LightScribe 2007-09-14 11:37 --------- d-----w C:\Program Files\Common Files\Ahead 2007-09-14 11:35 --------- d-----w C:\Program Files\Nero 2007-09-14 11:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero 2007-09-14 11:31 --------- d-----w C:\Program Files\Microsoft.NET 2007-09-14 10:24 --------- d-----w C:\Program Files\microsoft frontpage 2007-08-21 06:18 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll 2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll 2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe 2007-07-30 17:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll 2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll 2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll 2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll 2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll 2007-07-09 13:11 584,192 ----a-w C:\WINDOWS\system32\rpcrt4.dll . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{24038BE3-4EF2-41E2-A603-4CE3BDD9E874}] 2007-10-29 09:37 290816 --a------ C:\WINDOWS\movctrlqtn.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{1699137C-B90E-4488-97BC-575C896C2B5C}"= C:\WINDOWS\nssfrch.dll [ ] [HKEY_CLASSES_ROOT\CLSID\{1699137C-B90E-4488-97BC-575C896C2B5C}] [HKEY_CLASSES_ROOT\nssfrch.ToolBar.1] [HKEY_CLASSES_ROOT\TypeLib\{0BA91B73-6B31-4E93-86EC-787A7EB6BF66}] [HKEY_CLASSES_ROOT\nssfrch.ToolBar] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 14:40] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-07 12:02] "vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-03-17 05:34] "SoundMan"="SOUNDMAN.EXE" [2006-11-17 04:42 C:\WINDOWS\soundman.exe] "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00] "PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2005-12-13 07:49] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-07 15:55] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-16 09:18] "PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2005-11-30 15:56] "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54] [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\[u:bf49d074d9]0[/u:bf49d074d9]] Source= file:///C:\WINDOWS\privacy_danger\index.htm FriendlyName= Privacy Protection [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "bxsbang"= {BDBEC5F8-930D-45DB-AAD2-FAE8B044C47F} - C:\WINDOWS\bxsbang.dll [2007-10-29 09:37 262144] "ocgrep"= {0D65BF58-0D71-41F1-8A69-B0F981BEEDEB} - C:\WINDOWS\ocgrep.dll [2007-10-29 09:37 339968] . Inhoud van de 'Gedeelde Taken' map "2007-09-17 14:27:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" "2007-10-31 11:49:05 C:\WINDOWS\Tasks\Controleren op updates voor Windows Live Toolbar.job" "2007-10-31 11:50:41 C:\WINDOWS\Tasks\MP Scheduled Scan.job" - C:\Program Files\Windows Defender\MpCmdRun.exe . ************************************************************************** catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-10-31 12:56:32 Windows 5.1.2600 Service Pack 2 NTFS scannen van verborgen processen ... scannen van verborgen autostart items ... scannen van verborgen bestanden ... Scan succesvol afgerond verborgen bestanden: 0 ************************************************************************** . Voltooingstijd: 2007-10-31 12:59:24 - machine was rebooted . --- E O F --- --------------------------------------------------- Logfile of Trend Micro HijackThis v2.0.0 (BETA) Scan saved at 13:19:34, on 31-10-2007 Platform: Windows XP SP2 (WinNT 5.01.2600) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\MSN Messenger\usnsvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\notepad.exe C:\WINDOWS\explorer.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Documents and Settings\Sam\Mijn documenten\HiJackThis_v2.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: The nssfrch - {1699137C-B90E-4488-97BC-575C896C2B5C} - C:\WINDOWS\nssfrch.dll (file missing) O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Openen in een nieuwe achtergrondtab - res://C:\Program Files\Windows Live Toolbar\Components\nl-nl\msntabres.dll.mui/229?f441ed9ea50a4f5db1ab5f7332cfd143 O8 - Extra context menu item: Openen in een nieuwe voorgrondtab - res://C:\Program Files\Windows Live Toolbar\Components\nl-nl\msntabres.dll.mui/230?f441ed9ea50a4f5db1ab5f7332cfd143 O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O22 - SharedTaskScheduler: Preloader van browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Cache-daemon voor onderdeelcategorieën - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- End of file - 7881 bytes
  • Download de nieuwste versie van Hijackthis en maak daarmee volgende keer je logje: http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe Start Hijackthis, kies voor 'Do a system scan only' en vink onderstaande regels aan: [b:b3bc0c92c8] O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O3 - Toolbar: The nssfrch - {1699137C-B90E-4488-97BC-575C896C2B5C} - C:\WINDOWS\nssfrch.dll (file missing) [/b:b3bc0c92c8] Sluit alle openstaande vensters en klik op 'fix Checked' Open Kladblok, kopiëer en plak het volgende (vetgedrukte tekst) in een leeg venster: [b:b3bc0c92c8] File:: C:\WINDOWS\ocgrep.dll C:\WINDOWS\kthemup.exe C:\WINDOWS\movctrlqtn.dll C:\WINDOWS\bxsbang.dll C:\WINDOWS\nssfrch.dll C:\WINDOWS\privacy_danger\index.htm Registry: [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{24038BE3-4EF2-41E2-A603-4CE3BDD9E874}] [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] [-HKEY_CLASSES_ROOT\CLSID\{1699137C-B90E-4488-97BC-575C896C2B5C}] [-HKEY_CLASSES_ROOT\nssfrch.ToolBar.1] [-HKEY_CLASSES_ROOT\TypeLib\{0BA91B73-6B31-4E93-86EC-787A7EB6BF66}] [-HKEY_CLASSES_ROOT\nssfrch.ToolBar] [-HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] [/b:b3bc0c92c8] Sla dit op op je Bureaublad als [b:b3bc0c92c8]CFScript.txt[/b:b3bc0c92c8] Sleep [b:b3bc0c92c8]CFScript.txt[/b:b3bc0c92c8] in [b:b3bc0c92c8]ComboFix.exe[/b:b3bc0c92c8] zoals getoond in onderstaand voorbeeld : [img:b3bc0c92c8]http://img.photobucket.com/albums/v666/sUBs/CFScript.gif[/img:b3bc0c92c8] Dit zal [b:b3bc0c92c8]ComboFix[/b:b3bc0c92c8] doen herstarten. Start opnieuw op als daarom gevraagd wordt en post de inhoud van de Combofix.txt in je volgende antwoord samen met een nieuw HijackThislogje. Pim
  • Hej Pim, Bedankt voor de snelle antwoorden :wink: ComboFix 07-10-30.5 - Sam 2007-10-31 14:55:48.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1043.18.85 [GMT 1:00] Gestart vanuit: C:\Documents and Settings\Sam\Bureaublad\ComboFix.exe Command switches used :: C:\Documents and Settings\Sam\Bureaublad\CFScript.txt * Nieuw herstelpunt werd aangemaakt FILE:: C:\WINDOWS\bxsbang.dll C:\WINDOWS\kthemup.exe C:\WINDOWS\movctrlqtn.dll C:\WINDOWS\nssfrch.dll C:\WINDOWS\ocgrep.dll C:\WINDOWS\privacy_danger\index.htm . (((((((((((((((((((((((((((((((((( Andere Verwijderingen ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\bxsbang.dll C:\WINDOWS\kthemup.exe C:\WINDOWS\main_uninstaller.exe C:\WINDOWS\ocgrep.dll . (((((((((((((((((((( Bestanden Gemaakt van 2007-09-28 to 2007-10-31 )))))))))))))))))))))))))))))) . 2007-10-31 14:51 <DIR> dr-h----- C:\Documents and Settings\Sam\Onlangs geopend 2007-10-31 13:30 <DIR> d-------- C:\Program Files\CCleaner 2007-10-31 12:51 51,200 --a------ C:\WINDOWS\NirCmd.exe 2007-10-26 15:36 <DIR> d-------- C:\Program Files\VirtualDJ 2007-10-26 11:59 <DIR> d-------- C:\Documents and Settings\Sam\Application Data\BSplayer Pro 2007-10-26 11:59 <DIR> d-------- C:\Documents and Settings\Sam\Application Data\BSplayer 2007-10-26 11:58 <DIR> d-------- C:\Program Files\Webteh 2007-10-24 12:36 <DIR> dr-h----- C:\Documents and Settings\Sam\Application Data\SecuROM 2007-10-24 12:36 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll 2007-10-24 12:14 <DIR> d-------- C:\Program Files\EA Sports 2007-10-20 13:21 <DIR> d-------- C:\Program Files\Windows Live Safety Center 2007-10-12 12:43 <DIR> d-------- C:\Documents and Settings\Sam\Application Data\Nokia Multimedia Player 2007-10-11 15:49 <DIR> d-------- C:\Program Files\GameSpy Arcade 2007-10-11 15:49 <DIR> d-------- C:\NVIDIA 2007-09-27 17:51 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys 2007-09-27 17:51 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys 2007-09-27 07:21 <DIR> d---s---- C:\Documents and Settings\Sam\UserData 2007-09-23 16:57 <DIR> d-------- C:\Documents and Settings\Sam\Phone Browser 2007-09-23 16:57 <DIR> d-------- C:\Documents and Settings\Sam\Application Data\DataLayer 2007-09-23 14:15 <DIR> d-------- C:\Program Files\Windows Media Connect 2 2007-09-23 14:13 <DIR> d-------- C:\WINDOWS\system32\LogFiles 2007-09-23 14:13 <DIR> d-------- C:\WINDOWS\system32\drivers\UMDF 2007-09-23 14:06 25,827,912 --a------ C:\Program Files\wmp11-windowsxp-x86-nl-nl.exe 2007-09-17 15:30 <DIR> d-------- C:\Documents and Settings\Sam\Application Data\Apple Computer 2007-09-17 15:29 <DIR> d-------- C:\Program Files\iTunes 2007-09-17 15:29 <DIR> d-------- C:\Program Files\iPod 2007-09-17 15:27 <DIR> d-------- C:\Program Files\QuickTime 2007-09-17 15:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer 2007-09-17 15:26 <DIR> d-------- C:\Program Files\Common Files\Apple 2007-09-17 15:26 <DIR> d-------- C:\Program Files\Apple Software Update 2007-09-17 15:26 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple 2007-09-16 12:44 <DIR> d-------- C:\Program Files\Common Files\Adobe 2007-09-16 12:44 <DIR> d-------- C:\Documents and Settings\Sam\Application Data\AdobeUM 2007-09-16 11:08 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2 2007-09-16 11:08 221,184 --a------ C:\WINDOWS\system32\wmpns.dll 2007-09-16 11:02 <DIR> d-------- C:\Program Files\MSXML 4.0 2007-09-16 09:20 271,224 --a------ C:\WINDOWS\system32\mucltui.dll 2007-09-16 09:20 207,736 --a------ C:\WINDOWS\system32\muweb.dll 2007-09-16 09:18 <DIR> d-------- C:\Documents and Settings\Sam\Contacts 2007-09-15 20:43 <DIR> d-------- C:\Program Files\Windows Live Favorites 2007-09-15 20:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar 2007-09-15 20:41 <DIR> d-------- C:\Program Files\Windows Live Toolbar 2007-09-15 20:40 <DIR> d-------- C:\Program Files\MSN Messenger 2007-09-15 20:34 <DIR> d-------- C:\Program Files\Nokia 2007-09-15 20:34 <DIR> d-------- C:\Program Files\Common Files\PCSuite 2007-09-15 20:34 <DIR> d-------- C:\Program Files\Common Files\Nokia 2007-09-15 20:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Installations 2007-09-15 11:23 <DIR> d-------- C:\Documents and Settings\Sam\Application Data\Nokia 2007-09-15 11:22 <DIR> d-------- C:\Documents and Settings\Sam\Application Data\PC Suite 2007-09-15 11:20 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Downloaded Installations 2007-09-15 11:00 <DIR> d-------- C:\Program Files\Google 2007-09-14 14:28 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe 2007-09-14 14:21 <DIR> d-------- C:\Documents and Settings\Sam\Incomplete 2007-09-14 14:21 <DIR> d-------- C:\Documents and Settings\Sam\Application Data\LimeWire 2007-09-14 14:20 <DIR> d-------- C:\Program Files\Java 2007-09-14 14:19 <DIR> d-------- C:\Program Files\Common Files\Java 2007-09-14 13:33 <DIR> d-------- C:\Program Files\Windows Defender 2007-09-14 13:25 <DIR> d-------- C:\Program Files\Realtek AC97 2007-09-14 13:25 10,528,768 --a------ C:\WINDOWS\system32\RTLCPL.exe 2007-09-14 13:25 4,027,840 -ra------ C:\WINDOWS\system32\drivers\alcxwdm.sys 2007-09-14 13:25 577,536 --a------ C:\WINDOWS\soundman.exe 2007-09-14 13:25 315,392 --a------ C:\WINDOWS\alcupd.exe 2007-09-14 13:25 217,088 --a------ C:\WINDOWS\Alcrmv.exe 2007-09-14 13:25 147,456 --a------ C:\WINDOWS\system32\RtlCPAPI.dll 2007-09-14 13:25 49,152 --a------ C:\WINDOWS\system32\ChCfg.exe 2007-09-14 13:16 4,274,816 --a------ C:\WINDOWS\system32\nv4_disp.dll 2007-09-14 13:16 1,897,408 --a------ C:\WINDOWS\system32\drivers\nv4_mini.sys 2007-09-14 13:16 57,856 --a------ C:\WINDOWS\system32\drivers\redbook.sys 2007-09-14 13:16 5,376 --a------ C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2007-09-14 13:16 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys 2007-09-14 13:15 2,944 --a------ C:\WINDOWS\system32\drivers\msmpu401.sys 2007-09-14 13:14 <DIR> d--h----- C:\Documents and Settings\Default User\Sjablonen 2007-09-14 13:14 <DIR> d--h----- C:\Documents and Settings\Default User\Onlangs geopend 2007-09-14 13:14 <DIR> d--h----- C:\Documents and Settings\Default User\Netwerkprinteromgeving 2007-09-14 13:14 <DIR> d-------- C:\Documents and Settings\Default User\Mijn documenten 2007-09-14 13:14 <DIR> dr------- C:\Documents and Settings\Default User\Menu Start 2007-09-14 13:14 <DIR> d-------- C:\Documents and Settings\Default User\Favorieten 2007-09-14 13:14 <DIR> d-------- C:\Documents and Settings\Default User\Bureaublad 2007-09-14 13:14 <DIR> d--h----- C:\Documents and Settings\All Users\Sjablonen 2007-09-14 13:14 <DIR> dr------- C:\Documents and Settings\All Users\Menu Start 2007-09-14 13:14 <DIR> d-------- C:\Documents and Settings\All Users\Favorieten 2007-09-14 13:14 <DIR> dr------- C:\Documents and Settings\All Users\Documenten 2007-09-14 13:14 <DIR> d-------- C:\Documents and Settings\All Users\Bureaublad 2007-09-14 13:09 145,792 --a------ C:\WINDOWS\system32\drivers\portcls.sys 2007-09-14 13:09 145,792 --a--c--- C:\WINDOWS\system32\dllcache\portcls.sys 2007-09-14 13:09 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys 2007-09-14 13:09 60,288 --a--c--- C:\WINDOWS\system32\dllcache\drmk.sys 2007-09-14 13:09 10,624 --a------ C:\WINDOWS\system32\drivers\gameenum.sys 2007-09-14 13:09 4,096 --a------ C:\WINDOWS\system32\ksuser.dll 2007-09-14 13:09 4,096 --a--c--- C:\WINDOWS\system32\dllcache\ksuser.dll 2007-09-14 13:08 76,288 --a------ C:\WINDOWS\system32\usbui.dll 2007-09-14 13:08 20,992 --a------ C:\WINDOWS\system32\drivers\RTL8139.sys 2007-09-14 13:07 <DIR> dr------- C:\Program Files 2007-09-14 13:03 <DIR> d--h----- C:\WINDOWS\$hf_mig$ . ((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-10-31 14:00 --------- d-----w C:\Program Files\Symantec AntiVirus 2007-10-12 11:41 --------- d--h--w C:\Program Files\InstallShield Installation Information 2007-10-12 11:39 --------- d-----w C:\Program Files\Common Files\InstallShield 2007-09-16 12:04 --------- d-----w C:\Program Files\Microsoft Works 2007-09-14 11:58 4,608 ----a-w C:\WINDOWS\system32\w95inf32.dll 2007-09-14 11:58 --------- d-----w C:\Program Files\CyberLink 2007-09-14 11:47 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2007-09-14 11:46 --------- d-----w C:\Program Files\Symantec 2007-09-14 11:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec 2007-09-14 11:37 --------- d-----w C:\Program Files\Common Files\LightScribe 2007-09-14 11:37 --------- d-----w C:\Program Files\Common Files\Ahead 2007-09-14 11:35 --------- d-----w C:\Program Files\Nero 2007-09-14 11:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero 2007-09-14 11:31 --------- d-----w C:\Program Files\Microsoft.NET 2007-09-14 10:24 --------- d-----w C:\Program Files\microsoft frontpage 2007-08-21 06:18 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll 2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll 2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe 2007-07-30 17:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll 2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll 2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll 2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll 2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll 2007-07-09 13:11 584,192 ----a-w C:\WINDOWS\system32\rpcrt4.dll . ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten ))))))))))))))))))))))))))))))))))))))))))))))))))) . . *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 14:40] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-07 12:02] "vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-03-17 05:34] "SoundMan"="SOUNDMAN.EXE" [2006-11-17 04:42 C:\WINDOWS\soundman.exe] "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00] "PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2005-12-13 07:49] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-07 15:55] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 13:00] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-16 09:18] "PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2005-11-30 15:56] "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54] . Inhoud van de 'Gedeelde Taken' map "2007-09-17 14:27:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" "2007-10-31 13:49:00 C:\WINDOWS\Tasks\Controleren op updates voor Windows Live Toolbar.job" "2007-10-31 13:47:53 C:\WINDOWS\Tasks\MP Scheduled Scan.job" . ************************************************************************** catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-10-31 14:59:38 Windows 5.1.2600 Service Pack 2 NTFS scannen van verborgen processen ... scannen van verborgen autostart items ... scannen van verborgen bestanden ... Scan succesvol afgerond verborgen bestanden: 0 ************************************************************************** . Voltooingstijd: 2007-10-31 15:01:46 - machine was rebooted C:\ComboFix2.txt ... 2007-10-31 12:59 . --- E O F --- -------------------------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:07:20, on 31-10-2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/ R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Openen in een nieuwe achtergrondtab - res://C:\Program Files\Windows Live Toolbar\Components\nl-nl\msntabres.dll.mui/229?f441ed9ea50a4f5db1ab5f7332cfd143 O8 - Extra context menu item: Openen in een nieuwe voorgrondtab - res://C:\Program Files\Windows Live Toolbar\Components\nl-nl\msntabres.dll.mui/230?f441ed9ea50a4f5db1ab5f7332cfd143 O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- End of file - 7422 bytes
  • Dat ziet er weer goed uit! De versie van Java die je gebruikt is verouderd. Oudere versies kunnen beveiligingslekken bevatten waardoor malware de kans krijgt om zich te installeren op je computer. Doe eerst deze stappen om Java te de-installeren en de nieuwere versie te installeren: [list:eeb62ee064] Download [url=http://javadl.sun.com/webapps/download/AutoDL?BundleId=12798]Java Runtime Environment (JRE) 6u3[/url] en plaatst het op je Bureaublad. Sluit alle actieve programma's en zeker je browser. Ga dan naar Start - Configuratiescherm - Software en verwijder alle oudere versies van Java uit de Softwarelijst. Vink alles aan met Java Runtime Environment (JRE of J2SE) in de naam. Klik op Verwijderen of op de knop 'Wijzig/Verwijder'. Herhaal dit tot alle oudere versies verdwenen zijn. Herstart daarna de computer Zoek op je Bureaublad naar jre-6u3-windows-i586-p.exe. Dubbelklik er op om de nieuwste versie van Java te installeren. [/list:u:eeb62ee064] Hoe is het inmiddels met je problemen? Pim
  • Alles loopt nu weer prima. Heel erg bedankt!! :D
  • Graag gedaan! :) Best kan je nog even je systeemherstel resetten om malware uit je systeemherstel te halen: http://users.telenet.be/marcvn/spyware/1852808.htm Lees deze beveiligingstips ook eens door: http://users.telenet.be/marcvn/spyware/1564073.htm Pim
  • Ik zag dat je aanraadt om het volgende te verwijderen: O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) Wat is dit? Want ik heb dat ook in mijn HJT-log staan en het viel mij op. Wij krijgen al een paar dagen bij het starten van Windows een foutmelding met Exception Processing Message C0000013, er zou een schijf missen. Zou bovenstaande regel iets te maken kunnen met deze foutmelding? Virusscanner AVG Free vindt niets en Ad Aware/Spybot ook niet.

Beantwoord deze vraag

Weet jij het antwoord op deze vraag? Registreer of meld je aan met je account

Dit is een gearchiveerde pagina. Antwoorden is niet meer mogelijk.