Op deze website gebruiken we cookies om content en advertenties te personaliseren, om functies voor social media te bieden en om ons websiteverkeer te analyseren. Ook delen we informatie over uw gebruik van onze site met onze partners voor social media, adverteren en analyse. Deze partners kunnen deze gegevens combineren met andere informatie die u aan ze heeft verstrekt of die ze hebben verzameld op basis van uw gebruik van hun services. Meer informatie.

Akkoord

Vraag & Antwoord

Beveiliging & privacy

Hulp nodig bij Trojan Vundo

None
11 antwoorden
  • Ik heb VundoFix en Hijackthis al uitgevoerd:

    Bij VundoFik krijg ik alleen dit logje is dit goed?:

    C:\windows\system32\ddaby.dll
    C:\windows\system32\ybadd.ini
    C:\windows\system32\ybadd.ini2

    ——————————————————

    Deze is van Hijackthis:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 20:11:34, on 2-12-2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
    C:\Acer\Empowering Technology\admServ.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Norton AntiVirus
    avapsvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Eset
    od32krn.exe
    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Acer\Empowering Technology\admtray.exe
    C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
    C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
    C:\Acer\Empowering Technology\eRecovery\Monitor.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\Acer\OrbiCam\CameraAssistant.exe
    C:\WINDOWS\system32\ElkCtrl.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\WINDOWS\system32\mmrtkrnl.exe
    C:\Program Files\Spyware Doctor\SDTrayApp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\system32\wbem\unsecapp.exe
    C:\DOCUME~1\KENPEE~1\LOCALS~1\Temp\RtkBtMnt.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dutch.ircfast2.com/index.php?rvs=hompag
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.aceradvantage.com/stdreg
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: {69b8a4bf-778f-f719-9624-1183feef4178} - {8714feef-3811-4269-917f-f877fb4a8b96} - C:\WINDOWS\system32\uebwjlil.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {96FC5013-52B0-44A6-968B-6AE72887A5E4} - (no file)
    O2 - BHO: (no name) - {9A1DD4B4-A4D8-4428-80BE-21A91963A86E} - C:\WINDOWS\system32\ddaby.dll (file missing)
    O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
    O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [LaunchApp] Alaunch
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [ADMTray.exe] "C:\Acer\Empowering Technology\admtray.exe"
    O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
    O4 - HKLM\..\Run: [ntiMUI] C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7
    tiMUI.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
    O4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot
    O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
    O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Acer\OrbiCam\CameraAssistant.exe
    O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Acer\OrbiCam\InstallHelper.exe /inspect
    O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [Realtime Audio Engine] "mmrtkrnl.exe" /i
    O4 - HKLM\..\Run: [jcjijkhq] rundll32.exe "C:\Program Files\exwzodgx\ufkhyjwz.dll",Init
    O4 - HKLM\..\Run: [Hitman Pro Expiration Helper] "C:\Program Files\Hitman Pro\xphelper.exe"
    O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ww\msntabres.dll.mui/229?1f72b401548c4d769bc621dc83caf537
    O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ww\msntabres.dll.mui/230?1f72b401548c4d769bc621dc83caf537
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\Monopoly\Images\stg_drm.ocx
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\Monopoly\Images\armhelper.ocx
    O20 - Winlogon Notify: winkve32 - winkve32.dll (file missing)
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
    O23 - Service: Norton AntiVirus Auto-Protect-service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus
    avapsvc.exe
    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset
    od32krn.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    O23 - Service: Planner voor Automatische LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe


    End of file - 13977 bytes



    Zou aub iemand me nu verder willen helpen ik weet nu niet hoe ik verder moet.
  • ik heb ook nog even ComboFix gedaan:

    ComboFix 07-12-02.5 - Ken Peeters 2007-12-02 20:15:30.1 - [b:d27114e633]FAT32[/b:d27114e633][/color:d27114e633]x86
    Microsoft Windows XP Professional 5.1.2600.2.1252.31.1043.18.448 [GMT 1:00]
    Gestart vanuit: C:\Documents and Settings\Ken Peeters\Bureaublad\ComboFix.exe
    * Nieuw herstelpunt werd aangemaakt
    .

    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\WINDOWS\system32\drivers
    pf.sys
    C:\WINDOWS\system32\packet.dll
    C:\WINDOWS\system32\pthreadVC.dll
    C:\WINDOWS\system32\uebwjlil.dll
    C:\WINDOWS\system32\WanPacket.dll
    C:\WINDOWS\system32\wpcap.dll

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

    .
    ——-\NPF


    (((((((((((((((((((( Bestanden Gemaakt van 2007-11-02 to 2007-12-02 ))))))))))))))))))))))))))))))
    .

    2007-12-02 19:28 . 2007-12-02 19:28 <DIR> d——– C:\Documents and Settings\Ken Peeters\DoctorWeb
    2007-12-02 19:09 . 2007-12-02 19:09 <DIR> d——– C:\Program Files\Trend Micro
    2007-12-02 18:34 . 2007-12-02 18:34 <DIR> d——– C:\VundoFix Backups
    2007-12-02 18:31 . 2007-12-02 19:19 793,784 —hs—- C:\WINDOWS\system32
    fiiidec.ini
    2007-12-02 12:58 . 2007-12-02 12:58 <DIR> d——– C:\Documents and Settings\LocalService\Application Data\Symantec
    2007-12-02 12:58 . 2007-12-02 12:59 <DIR> d——– C:\Documents and Settings\LocalService\Application Data\ATI
    2007-12-02 12:57 . 2007-12-02 12:58 <DIR> dr-h—– C:\Documents and Settings\LocalService\Onlangs geopend
    2007-12-02 12:57 . 2007-12-02 12:58 <DIR> dr——- C:\Documents and Settings\LocalService\Mijn documenten
    2007-12-02 12:57 . 2007-12-02 12:57 <DIR> d——– C:\Documents and Settings\LocalService\Menu Start
    2007-12-02 12:57 . 2007-12-02 12:58 <DIR> dr——- C:\Documents and Settings\LocalService\Favorieten
    2007-12-02 12:57 . 2007-12-02 12:57 <DIR> d——– C:\Documents and Settings\LocalService\Bureaublad
    2007-12-02 12:37 . 2007-12-02 12:37 142 –a—— C:\WINDOWS\wininit.ini
    2007-12-02 12:00 . 2007-12-02 12:01 <DIR> d——– C:\Documents and Settings\Ken Peeters\Application Data\Lavasoft
    2007-12-02 11:40 . 2007-12-02 11:40 <DIR> d——– C:\Program Files\Spyware Doctor
    2007-12-02 11:40 . 2007-12-02 11:40 <DIR> d——– C:\Documents and Settings\Ken Peeters\Application Data\PC Tools
    2007-12-02 11:40 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
    2007-12-02 11:40 . 2007-10-18 00:16 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
    2007-12-02 11:40 . 2007-10-18 00:15 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
    2007-12-02 11:40 . 2007-10-18 00:14 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
    2007-12-02 11:40 . 2007-10-18 00:16 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
    2007-12-02 11:39 . 2007-12-02 11:39 <DIR> d——– C:\Program Files\Webroot
    2007-12-02 11:39 . 2007-12-02 11:39 <DIR> d——– C:\Documents and Settings\LocalService\Application Data\Webroot
    2007-12-02 11:39 . 2007-12-02 11:39 <DIR> d——– C:\Documents and Settings\All Users\Application Data\Webroot
    2007-12-02 11:39 . 2007-03-01 19:54 144,960 –a—— C:\WINDOWS\system32\drivers\ssidrv.sys
    2007-12-02 11:39 . 2007-03-01 19:54 22,080 –a—— C:\WINDOWS\system32\drivers\sshrmd.sys
    2007-12-02 11:39 . 2007-03-01 19:54 21,056 –a—— C:\WINDOWS\system32\drivers\sskbfd.sys
    2007-12-02 11:39 . 2007-03-01 19:54 20,544 –a—— C:\WINDOWS\system32\drivers\SSFS0509.sys
    2007-12-02 11:38 . 2007-12-02 11:38 <DIR> d——– C:\Documents and Settings\Ken Peeters\Application Data\Webroot
    2007-12-02 11:38 . 2007-12-02 11:38 164 –a—— C:\install.dat
    2007-12-02 11:37 . 2007-12-02 11:37 <DIR> d——– C:\Program Files\Lavasoft
    2007-12-02 11:37 . 2007-12-02 11:37 <DIR> d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2007-12-02 11:36 . 2007-12-02 11:37 <DIR> d——– C:\Program Files\SpywareBlaster
    2007-12-02 11:36 . 2005-08-25 18:18 118,784 –a—— C:\WINDOWS\system32\MSSTDFMT.DLL
    2007-12-02 11:36 . 2005-08-25 18:19 115,920 –a—— C:\WINDOWS\system32\MSINET.OCX
    2007-12-02 11:35 . 2007-12-02 11:25 512,096 –a—— C:\WINDOWS\system32\drivers\amon.sys
    2007-12-02 11:35 . 2007-12-02 11:25 298,104 –a—— C:\WINDOWS\system32\imon.dll
    2007-12-02 11:35 . 2007-12-02 11:25 15,424 –a—— C:\WINDOWS\system32\drivers
    od32drv.sys
    2007-12-02 11:22 . 2007-12-02 11:22 <DIR> d——– C:\Documents and Settings\All Users\Application Data\Prevx
    2007-12-02 11:09 . 2007-12-02 11:09 <DIR> d——– C:\WINDOWS\system32\GroupPolicy
    2007-12-02 11:09 . 2007-12-02 11:09 <DIR> d——– C:\Program Files\Hitman Pro
    2007-12-02 11:09 . 2006-02-28 13:43 1,077,344 –a—— C:\WINDOWS\system32\mscomctl.ocx
    2007-12-01 18:14 . 2007-12-01 18:14 <DIR> d——– C:\Program Files\Dwxfqvpw
    2007-12-01 11:45 . 2007-12-01 11:45 <DIR> d——– C:\Program Files\Windows Media Connect 2
    2007-12-01 11:44 . 2007-12-01 11:44 <DIR> d——– C:\WINDOWS\system32\drivers\UMDF
    2007-12-01 03:01 . 2007-12-01 03:01 <DIR> d——– C:\Program Files\Windows Live Favorites
    2007-11-29 18:19 . 2007-11-29 18:19 <DIR> d——– C:\WINDOWS\system32\LogFiles
    2007-11-29 18:19 . 2007-12-02 18:24 107,832 –a—— C:\WINDOWS\system32\PnkBstrB.exe
    2007-11-29 18:19 . 2007-11-29 18:23 66,872 –a—— C:\WINDOWS\system32\PnkBstrA.exe
    2007-11-29 18:19 . 2007-12-02 18:25 22,328 –a—— C:\WINDOWS\system32\drivers\PnkBstrK.sys
    2007-11-29 18:19 . 2007-11-29 18:20 22,328 –a—— C:\Documents and Settings\Ken Peeters\Application Data\PnkBstrK.sys
    2007-11-29 18:19 . 2007-11-29 18:19 319 –a—— C:\WINDOWS\game.ini
    2007-11-24 13:58 . 2007-11-24 13:58 <DIR> d——– C:\Program Files\Guild Wars
    2007-11-21 15:24 . 2004-08-18 09:34 442,368 -ra—— C:\WINDOWS\system32\vp6vfw.dll
    2007-11-19 16:36 . 2007-11-19 16:36 <DIR> d——– C:\TEMP
    2007-11-18 20:34 . 2007-11-18 20:34 <DIR> d——– C:\Documents and Settings\Ken Peeters\Application Data\Samsung
    2007-11-18 19:58 . 2007-11-18 19:58 <DIR> d——– C:\WINDOWS\system32\Samsung_USB_Drivers
    2007-11-18 19:58 . 2006-05-03 22:53 174,592 –a—— C:\WINDOWS\system32\framedyn.dll
    2007-11-18 19:58 . 2005-08-30 17:59 94,000 –a—— C:\WINDOWS\system32\drivers\ss_mdm.sys
    2007-11-18 19:58 . 2005-08-30 17:57 58,320 –a—— C:\WINDOWS\system32\drivers\ss_bus.sys
    2007-11-18 19:58 . 2005-08-30 17:58 8,304 –a—— C:\WINDOWS\system32\drivers\ss_mdfl.sys
    2007-11-18 19:58 . 2005-08-30 17:58 6,144 –a—— C:\WINDOWS\system32\drivers\ss_cmnt.sys
    2007-11-18 19:58 . 2005-08-30 17:58 6,144 –a—— C:\WINDOWS\system32\drivers\ss_cm.sys
    2007-11-18 19:58 . 2005-08-30 17:57 5,808 –a—— C:\WINDOWS\system32\drivers\ss_whnt.sys
    2007-11-18 19:58 . 2005-08-30 17:57 5,808 –a—— C:\WINDOWS\system32\drivers\ss_wh.sys
    2007-11-18 19:58 . 2005-08-28 20:51 766 –a—— C:\WINDOWS\system32\Uninstall.ico
    2007-11-18 19:57 . 2007-11-18 19:57 <DIR> d——– C:\Program Files\Samsung
    2007-11-18 19:57 . 2006-07-24 16:05 5,632 –a—— C:\WINDOWS\system32\drivers\StarOpen.sys
    2007-11-18 10:31 . 2007-11-18 10:31 <DIR> d——– C:\Documents and Settings\Ken Peeters\Application Data\CyberLink
    2007-11-18 10:31 . 2007-11-18 10:31 <DIR> d——– C:\Documents and Settings\All Users\Application Data\CyberLink
    2007-11-17 17:55 . 2007-11-17 17:55 <DIR> d——– C:\Program Files\VirtualDJ
    2007-11-17 15:23 . 2007-11-17 15:23 <DIR> d——– C:\Documents and Settings\Ken Peeters\Application Data\AlcaTech
    2007-11-17 15:22 . 2007-11-17 15:22 <DIR> d——– C:\Documents and Settings\All Users\Application Data\AlcaTech
    2007-11-17 15:20 . 2007-11-17 15:20 <DIR> d——– C:\Documents and Settings\Ken Peeters\Application Data\GetRightToGo
    2007-11-13 20:31 . 2007-11-13 20:31 <DIR> d——– C:\Program Files\Filesweb
    2007-11-13 20:20 . 2007-11-13 20:20 <DIR> d——– C:\Program Files\Ashkon Software
    2007-11-13 20:17 . 2007-11-13 20:17 <DIR> d——– C:\WINDOWS\system32\FFSJ
    2007-11-13 20:17 . 2007-11-13 20:17 <DIR> d——– C:\Documents and Settings\Ken Peeters\Application Data\FFSJ
    2007-11-13 20:17 . 2007-11-13 20:17 704,793 –a—— C:\WINDOWS\unins000.exe
    2007-11-13 20:17 . 2007-11-13 20:17 3,732 –a—— C:\WINDOWS\unins000.dat
    2007-11-13 20:12 . 2007-11-13 20:12 <DIR> d——– C:\WINDOWS\[u:d27114e633]0[/u:d27114e633]01 File Joiner & Splitter Pro
    2007-11-13 20:12 . 2007-11-13 20:12 <DIR> d——– C:\Program Files\[u:d27114e633]0[/u:d27114e633]01 File Joiner & Splitter Pro
    2007-11-13 20:06 . 2007-11-13 20:06 <DIR> d——– C:\Program Files\[u:d27114e633]0[/u:d27114e633]01 Joiner
    2007-11-10 10:44 . 2007-11-10 10:46 10,740 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.CAT
    2007-11-10 10:44 . 2007-11-10 10:46 805 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.INF
    2007-11-08 18:55 . 2007-11-08 18:55 19 –a—— C:\WINDOWS\popcinfo.dat
    2007-11-05 16:19 . 2007-11-05 16:19 <DIR> d——– C:\Program Files\Common Files\DirectX
    2007-11-05 16:14 . 2007-11-05 16:14 <DIR> d——– C:\Program Files\EA GAMES
    2007-11-05 16:00 . 2007-11-05 16:00 <DIR> d——– C:\WINDOWS\Downloaded Installations
    2007-11-04 17:49 . 2007-11-04 17:49 <DIR> d——– C:\Program Files\Zylom Games
    2007-11-04 17:49 . 2007-11-04 17:49 <DIR> d——– C:\Documents and Settings\Ken Peeters\Application Data\Zylom
    2007-11-04 17:49 . 2007-11-04 17:49 <DIR> d——– C:\Documents and Settings\Ken Peeters\Application Data\PlayFirst
    2007-11-04 17:49 . 2007-11-04 17:49 <DIR> d——– C:\Documents and Settings\All Users\Application Data\Zylom
    2007-11-04 17:49 . 2007-11-04 17:49 <DIR> d——– C:\Documents and Settings\All Users\Application Data\PlayFirst
    2007-11-04 10:42 . 2007-11-04 10:42 <DIR> d——– C:\Program Files\Monopoly
    2007-11-04 10:42 . 2007-11-04 10:42 <DIR> d——– C:\Documents and Settings\Ken Peeters\Application Data\SpinTop
    2007-11-04 10:42 . 2007-11-04 10:42 <DIR> d——– C:\Documents and Settings\All Users\Application Data\TEMP
    2007-11-04 10:37 . 2007-11-04 10:37 <DIR> d——– C:\Program Files\Parkeerbonnen Monopoly

    .
    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2007-11-10 09:46 60,800 —-a-w C:\WINDOWS\system32\S32EVNT1.DLL
    2007-11-10 09:46 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
    2007-10-30 15:00 25,280 —-a-w C:\WINDOWS\system32\drivers\hamachi.sys
    2007-10-26 10:51 ——— d—–w C:\Program Files\AWS
    2007-10-26 10:42 ——— d—–w C:\Program Files\DAEMON Tools
    2007-10-26 10:31 685,816 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
    2007-10-25 16:44 8,507,392 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
    2007-10-24 13:20 ——— d—–w C:\Program Files\Metin2.us
    2007-10-24 10:23 11,973 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
    2007-10-24 10:01 ——— d—–w C:\Program Files\Activision
    2007-10-23 20:56 ——— d—–w C:\Program Files\QuickPar
    2007-10-23 19:24 352,256 —-a-w C:\WINDOWS\eSellerateEngine.dll
    2007-10-23 19:08 ——— d—–w C:\Documents and Settings\Ken Peeters\Application Data\GrabIt
    2007-10-23 19:07 ——— d—–w C:\Program Files\GrabIt
    2007-10-23 19:03 ——— d—–w C:\Program Files\FTDv3.8
    2007-10-23 17:31 ——— d–h–r C:\Documents and Settings\Ken Peeters\Application Data\SecuROM
    2007-10-23 17:20 ——— d—–w C:\Program Files\EA SPORTS
    2007-10-23 14:52 ——— d—–w C:\Documents and Settings\Ken Peeters\Application Data\Apple Computer
    2007-10-23 09:11 ——— d—–w C:\Program Files\QuickTime
    2007-10-23 09:11 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
    2007-10-23 09:10 ——— d—–w C:\Program Files\Apple Software Update
    2007-10-23 09:10 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
    2007-10-22 12:32 98,304 —-a-w C:\WINDOWS\system32\CmdLineExt.dll
    2007-10-22 12:27 ——— d—–w C:\Program Files\KONAMI
    2007-10-20 13:31 ——— d—–w C:\Program Files\Xfire
    2007-10-20 13:31 ——— d—–w C:\Documents and Settings\NetworkService\Application Data\Xfire
    2007-10-20 13:31 ——— d—–w C:\Documents and Settings\Ken Peeters\Application Data\Xfire
    2007-10-20 10:43 ——— d—–w C:\Program Files\GameSpy Arcade
    2007-10-20 10:39 ——— d—–w C:\Program Files\Microsoft Games
    2007-10-20 09:36 1,170,430 —-a-w C:\WINDOWS\Mall Tycoon 2 Uninstaller.exe
    2007-10-19 14:42 ——— d—–w C:\Documents and Settings\Ken Peeters\Application Data\LimeWire
    2007-10-19 14:41 ——— d—–w C:\Program Files\LimeWire
    2007-10-16 15:21 ——— d—–w C:\Program Files\Hamachi
    2007-10-16 15:21 ——— d—–w C:\Documents and Settings\Ken Peeters\Application Data\Hamachi
    2007-10-14 14:55 ——— d—–w C:\Program Files\Warcraft III
    2007-10-14 13:00 ——— d—–w C:\Program Files\Microsoft CAPICOM 2.1.0.2
    2007-10-13 13:47 ——— d—–w C:\Program Files\Java
    2007-10-13 13:46 ——— d—–w C:\Program Files\Common Files\Java
    2007-10-13 13:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
    2007-10-12 20:39 ——— d—–w C:\Program Files\Windows Live
    2007-10-12 20:39 ——— d—–w C:\Program Files\Messenger Plus! Live
    2007-10-12 20:05 ——— d—–w C:\Program Files\Windows Live Toolbar
    2007-10-12 20:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
    2007-10-12 20:02 ——— d—–w C:\Program Files\MSN Messenger
    2007-10-12 19:38 ——— d—–w C:\Program Files\MSXML 4.0
    2007-10-07 18:52 ——— d—–w C:\Program Files\Real
    2007-10-07 18:52 ——— d—–w C:\Program Files\Common Files\xing shared
    2007-10-07 18:52 ——— d—–w C:\Program Files\Common Files\Real
    2007-10-07 16:29 ——— d—–w C:\Program Files\Softwarehouse Macco
    2007-10-07 15:01 ——— d—–w C:\Program Files\Teach2000
    2007-10-07 14:38 ——— d—–w C:\Documents and Settings\Ken Peeters\Application Data\Talkback
    2007-10-07 14:31 ——— d—–w C:\Program Files\Google
    2007-10-07 14:06 ——— d—–w C:\Program Files\Common Files\Logitech
    2007-10-07 14:06 ——— d—–w C:\Program Files\Common Files\Acer
    2007-10-07 14:05 ——— d—–w C:\Program Files\Acer
    2007-10-07 14:03 21,275 —-a-w C:\WINDOWS\system32\drivers\AegisP.sys
    2007-10-07 14:03 ——— d—–w C:\Program Files\WinPCap
    2007-10-07 14:03 ——— d—–w C:\Documents and Settings\All Users\Application Data\Intel
    2007-10-07 14:02 ——— d—–w C:\Program Files\Launch Manager
    2007-10-07 14:00 ——— d—–w C:\Documents and Settings\Ken Peeters\Application Data\ATI
    2007-10-07 13:54 ——— d—–w C:\Program Files\ATI Technologies
    2007-10-01 13:49 542,088 —-a-w C:\WINDOWS\system32\SymNeti.dll
    2007-10-01 13:49 161,160 —-a-w C:\WINDOWS\system32\SymRedir.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{96FC5013-52B0-44A6-968B-6AE72887A5E4}]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9A1DD4B4-A4D8-4428-80BE-21A91963A86E}]
    C:\WINDOWS\system32\ddaby.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-02 13:00]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-17 16:15]
    "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
    "DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-08-16 13:24]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-17 22:40]
    "LaunchApp"="Alaunch" []
    "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-11-02 00:11]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-02 00:11]
    "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-09-02 13:00]
    "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-09-02 13:00]
    "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-09-02 13:00]
    "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-11-03 00:25]
    "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-11-03 00:22]
    "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-11-03 00:26]
    "ADMTray.exe"="C:\Acer\Empowering Technology\admtray.exe" [2005-10-24 16:45]
    "eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2005-12-27 15:50]
    "ntiMUI"="C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7
    tiMUI.exe" [2005-05-11 17:15]
    "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-09-16 16:27]
    "RTHDCPL"="RTHDCPL.EXE" [2006-04-04 02:44 C:\WINDOWS\RTHDCPL.exe]
    "AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2005-08-24 23:21]
    "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 17:41]
    "ePower_DMC"="C:\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-05-09 11:54]
    "Acer ePower Management"="C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe" [2006-05-08 18:41]
    "LManager"="C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE" [2006-04-03 17:03]
    "eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\Monitor.exe" [2006-01-24 18:00]
    "LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2006-03-31 10:47]
    "LogitechCameraAssistant"="C:\Program Files\Acer\OrbiCam\CameraAssistant.exe" [2006-03-31 10:24]
    "LogitechVideo[inspector]"="C:\Program Files\Acer\OrbiCam\InstallHelper.exe" [2006-03-31 10:32]
    "LogitechCameraService(E)"="C:\WINDOWS\system32\ElkCtrl.exe" [2004-11-01 17:22]
    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-07 19:52]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
    "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
    "Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 10:22]
    "Realtime Audio Engine"="mmrtkrnl.exe" [2007-07-18 15:52 C:\WINDOWS\system32\mmrtkrnl.exe]
    "Hitman Pro Expiration Helper"="C:\Program Files\Hitman Pro\xphelper.exe" [2007-01-30 14:41]
    "SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-11-02 17:24]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-02 13:00]

    C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\
    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
    "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon
    otify\winkve32]
    winkve32.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
    @=""

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
    @=""

    R0 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys
    R1 OsaFsLoc;OsaFsLoc;\??\C:\WINDOWS\system32\drivers\OsaFsLoc.sys
    R2 EpmPsd;Acer EPM Power Scheme Driver;\??\C:\WINDOWS\system32\drivers\epm-psd.sys
    R2 EpmShd;Acer EPM System Hardware Driver;\??\C:\WINDOWS\system32\drivers\epm-shd.sys
    R2 int15.sys;int15.sys;\??\C:\Acer\Empowering Technology\eRecovery\int15.sys
    R2 osaio;osaio;\??\C:\WINDOWS\system32\drivers\osaio.sys
    R2 osanbm;osanbm;\??\C:\WINDOWS\system32\drivers\osanbm.sys
    R3 DKbFltr;Dritek Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\DKbFltr.sys
    R3 lv321av;Logitech USB PC Camera (VC0321);C:\WINDOWS\system32\Drivers\lv321av.sys
    R3 LVPrcMon;Logitech LVPrcMon Driver;\??\C:\WINDOWS\system32\drivers\LVPrcMon.sys
    R3 NdisFilt;OSA NdisFilter Protocol;C:\WINDOWS\system32\Drivers\NdisFilt.sys
    R3 SMCB000;SMSC CIR HID Miniport Device Driver;C:\WINDOWS\system32\DRIVERS\hidsmsc.sys
    S3 AVerE506;AVerE506 service;C:\WINDOWS\system32\DRIVERS\AVerE506.sys
    S3 AVerM115;AVerM115 service;C:\WINDOWS\system32\DRIVERS\AVerM115.sys
    S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys
    S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys
    S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys

    .
    Inhoud van de 'Gedeelde Taken' map
    "2007-11-30 22:28:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    "2007-12-02 19:19:22 C:\WINDOWS\Tasks\Norton AntiVirus - Volledige systeemscan uitvoeren - Ken Peeters.job"
    - C:\PROGRA~1\NORTON~1\Navw32.exe
    "2007-12-02 19:16:04 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
    - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
    .
    **************************************************************************

    catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-12-02 20:20:43
    Windows 5.1.2600 Service Pack 2 FAT NTAPI

    scannen van verborgen processen …

    scannen van verborgen autostart items …

    scannen van verborgen bestanden …

    Scan succesvol afgerond
    verborgen bestanden: 0

    **************************************************************************
    .
    Voltooingstijd: 2007-12-02 20:22:21 - machine was rebooted
    .
    — E O F —
  • 1. Ga naar start –> configuratiescherm –> software en verwijder daar:
    [b:c4952df97b]
    Hitman Pro, inclusief al zijn trail componenten, spyware doctor, nod32 etc.
    [/b:c4952df97b]

    2. Start Hijackthis, kies voor [i:c4952df97b]'Do a system scan only'[/i:c4952df97b] en vink onderstaande regels aan:
    [b:c4952df97b]
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: {69b8a4bf-778f-f719-9624-1183feef4178} - {8714feef-3811-4269-917f-f877fb4a8b96} - C:\WINDOWS\system32\uebwjlil.dll
    O2 - BHO: (no name) - {96FC5013-52B0-44A6-968B-6AE72887A5E4} - (no file)
    O2 - BHO: (no name) - {9A1DD4B4-A4D8-4428-80BE-21A91963A86E} - C:\WINDOWS\system32\ddaby.dll (file missing)
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [jcjijkhq] rundll32.exe "C:\Program Files\exwzodgx\ufkhyjwz.dll",Init
    O20 - Winlogon Notify: winkve32 - winkve32.dll (file missing)
    [/b:c4952df97b]

    Sluit nu [u:c4952df97b]alle[/u:c4952df97b] openstaande vensters, behalve Hijackthis en klik op [b:c4952df97b]Fix Checked[/b:c4952df97b].

    3. Open Kladblok, kopiëer en plak het volgende (vetgedrukte tekst) in een leeg venster:
    [b:c4952df97b]
    File::
    C:\WINDOWS\system32
    fiiidec.ini

    Folder::
    C:\VundoFix Backups
    C:\Program Files\Dwxfqvpw

    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{96FC5013-52B0-44A6-968B-6AE72887A5E4}]
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9A1DD4B4-A4D8-4428-80BE-21A91963A86E}]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon
    otify\winkve32]
    [/b:c4952df97b]
    Sla dit op op je Bureaublad als [b:c4952df97b]CFScript.txt[/b:c4952df97b]

    Sleep [b:c4952df97b]CFScript.txt[/b:c4952df97b] in [b:c4952df97b]ComboFix.exe[/b:c4952df97b] zoals getoond in onderstaand voorbeeld :

    [img:c4952df97b]http://img.photobucket.com/albums/v666/sUBs/CFScript.gif[/img:c4952df97b]

    Dit zal [b:c4952df97b]ComboFix[/b:c4952df97b] doen herstarten.
    Start opnieuw op als daarom gevraagd wordt,
    en post de inhoud van de [b:c4952df97b]Combofix.txt[/b:c4952df97b] in je volgende antwoord samen met een nieuw HijackThislogje.

    Succes!
    Pim :)
  • Bij Hijackthis vond ik deze 3 regels niet:

    [b:1da18f9c3b] 02 - BHO: {69b8a4bf-778f-f719-9624-1183feef4178} - {8714feef-3811-4269-917f-f877fb4a8b96} - C:\WINDOWS\system32\uebwjlil.dll
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [jcjijkhq] rundll32.exe "C:\Program Files\exwzodgx\ufkhyjwz.dll",Init [/b:1da18f9c3b]



    Logje Combofix:

    ComboFix 07-12-02.5 - Ken Peeters 2007-12-03 17:47:07.2 - [b:1da18f9c3b]FAT32[/b:1da18f9c3b][/color:1da18f9c3b]x86
    Microsoft Windows XP Professional 5.1.2600.2.1252.31.1043.18.470 [GMT 1:00]
    Gestart vanuit: C:\Documents and Settings\Ken Peeters\Bureaublad\ComboFix.exe
    Command switches used :: C:\Documents and Settings\Ken Peeters\Bureaublad\CFScript.txt
    * Nieuw herstelpunt werd aangemaakt

    FILE
    C:\WINDOWS\system32
    fiiidec.ini
    .

    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Program Files\Dwxfqvpw
    C:\VundoFix Backups
    C:\VundoFix Backups\addmorefiles.txt
    C:\VundoFix Backups\ddaby.dll.bad
    C:\VundoFix Backups\jkklk.dll.bad
    C:\VundoFix Backups\klkkj.ini.bad
    C:\VundoFix Backups\klkkj.ini2.bad
    C:\VundoFix Backups\ybadd.ini.bad
    C:\VundoFix Backups\ybadd.ini2.bad
    C:\WINDOWS\system32
    fiiidec.ini

    .
    (((((((((((((((((((( Bestanden Gemaakt van 2007-11-03 to 2007-12-03 ))))))))))))))))))))))))))))))
    .

    2007-12-02 19:28 . 2007-12-02 19:28 <DIR> d——– C:\Documents and Settings\Ken Peeters\DoctorWeb
    2007-12-02 19:09 . 2007-12-02 19:09 <DIR> d——– C:\Program Files\Trend Micro
    2007-12-02 12:58 . 2007-12-02 12:58 <DIR> d——– C:\Documents and Settings\LocalService\Application Data\Symantec
    2007-12-02 12:58 . 2007-12-02 12:59 <DIR> d——– C:\Documents and Settings\LocalService\Application Data\ATI
    2007-12-02 12:57 . 2007-12-02 12:58 <DIR> dr-h—– C:\Documents and Settings\LocalService\Onlangs geopend
    2007-12-02 12:57 . 2007-12-02 12:58 <DIR> dr——- C:\Documents and Settings\LocalService\Mijn documenten
    2007-12-02 12:57 . 2007-12-02 12:57 <DIR> d——– C:\Documents and Settings\LocalService\Menu Start
    2007-12-02 12:57 . 2007-12-02 12:58 <DIR> dr——- C:\Documents and Settings\LocalService\Favorieten
    2007-12-02 12:57 . 2007-12-02 12:57 <DIR> d——– C:\Documents and Settings\LocalService\Bureaublad
    2007-12-02 12:37 . 2007-12-02 12:37 142 –a—— C:\WINDOWS\wininit.ini
    2007-12-02 12:00 . 2007-12-02 12:01 <DIR> d——– C:\Documents and Settings\Ken Peeters\Application Data\Lavasoft
    2007-12-02 11:40 . 2005-09-23 08:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
    2007-12-02 11:38 . 2007-12-02 11:38 164 –a—— C:\install.dat
    2007-12-02 11:37 . 2007-12-02 11:37 <DIR> d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2007-12-02 11:36 . 2005-08-25 18:18 118,784 –a—— C:\WINDOWS\system32\MSSTDFMT.DLL
    2007-12-02 11:36 . 2005-08-25 18:19 115,920 –a—— C:\WINDOWS\system32\MSINET.OCX
    2007-12-02 11:35 . 2007-12-02 11:25 512,096 –a—— C:\WINDOWS\system32\drivers\amon.sys
    2007-12-02 11:35 . 2007-12-02 11:25 298,104 –a—— C:\WINDOWS\system32\imon.dll
    2007-12-02 11:35 . 2007-12-02 11:25 15,424 –a—— C:\WINDOWS\system32\drivers
    od32drv.sys
    2007-12-02 11:22 . 2007-12-02 11:22 <DIR> d——– C:\Documents and Settings\All Users\Application Data\Prevx
    2007-12-02 11:09 . 2007-12-02 11:09 <DIR> d——– C:\WINDOWS\system32\GroupPolicy
    2007-12-02 11:09 . 2007-12-02 11:09 <DIR> d——– C:\Program Files\Hitman Pro
    2007-12-02 11:09 . 2006-02-28 13:43 1,077,344 –a—— C:\WINDOWS\system32\mscomctl.ocx
    2007-12-01 11:45 . 2007-12-01 11:45 <DIR> d——– C:\Program Files\Windows Media Connect 2
    2007-12-01 11:44 . 2007-12-01 11:44 <DIR> d——– C:\WINDOWS\system32\drivers\UMDF
    2007-12-01 03:01 . 2007-12-01 03:01 <DIR> d——– C:\Program Files\Windows Live Favorites
    2007-11-29 18:19 . 2007-11-29 18:19 <DIR> d——– C:\WINDOWS\system32\LogFiles
    2007-11-29 18:19 . 2007-12-02 18:24 107,832 –a—— C:\WINDOWS\system32\PnkBstrB.exe
    2007-11-29 18:19 . 2007-11-29 18:23 66,872 –a—— C:\WINDOWS\system32\PnkBstrA.exe
    2007-11-29 18:19 . 2007-12-02 18:25 22,328 –a—— C:\WINDOWS\system32\drivers\PnkBstrK.sys
    2007-11-29 18:19 . 2007-11-29 18:20 22,328 –a—— C:\Documents and Settings\Ken Peeters\Application Data\PnkBstrK.sys
    2007-11-29 18:19 . 2007-11-29 18:19 319 –a—— C:\WINDOWS\game.ini
    2007-11-24 13:58 . 2007-11-24 13:58 <DIR> d——– C:\Program Files\Guild Wars
    2007-11-21 15:24 . 2004-08-18 09:34 442,368 -ra—— C:\WINDOWS\system32\vp6vfw.dll
    2007-11-19 16:36 . 2007-11-19 16:36 <DIR> d——– C:\TEMP
    2007-11-18 20:34 . 2007-11-18 20:34 <DIR> d——– C:\Documents and Settings\Ken Peeters\Application Data\Samsung
    2007-11-18 19:58 . 2007-11-18 19:58 <DIR> d——– C:\WINDOWS\system32\Samsung_USB_Drivers
    2007-11-18 19:58 . 2006-05-03 22:53 174,592 –a—— C:\WINDOWS\system32\framedyn.dll
    2007-11-18 19:58 . 2005-08-30 17:59 94,000 –a—— C:\WINDOWS\system32\drivers\ss_mdm.sys
    2007-11-18 19:58 . 2005-08-30 17:57 58,320 –a—— C:\WINDOWS\system32\drivers\ss_bus.sys
    2007-11-18 19:58 . 2005-08-30 17:58 8,304 –a—— C:\WINDOWS\system32\drivers\ss_mdfl.sys
    2007-11-18 19:58 . 2005-08-30 17:58 6,144 –a—— C:\WINDOWS\system32\drivers\ss_cmnt.sys
    2007-11-18 19:58 . 2005-08-30 17:58 6,144 –a—— C:\WINDOWS\system32\drivers\ss_cm.sys
    2007-11-18 19:58 . 2005-08-30 17:57 5,808 –a—— C:\WINDOWS\system32\drivers\ss_whnt.sys
    2007-11-18 19:58 . 2005-08-30 17:57 5,808 –a—— C:\WINDOWS\system32\drivers\ss_wh.sys
    2007-11-18 19:58 . 2005-08-28 20:51 766 –a—— C:\WINDOWS\system32\Uninstall.ico
    2007-11-18 19:57 . 2007-11-18 19:57 <DIR> d——– C:\Program Files\Samsung
    2007-11-18 19:57 . 2006-07-24 16:05 5,632 –a—— C:\WINDOWS\system32\drivers\StarOpen.sys
    2007-11-18 10:31 . 2007-11-18 10:31 <DIR> d——– C:\Documents and Settings\Ken Peeters\Application Data\CyberLink
    2007-11-18 10:31 . 2007-11-18 10:31 <DIR> d——– C:\Documents and Settings\All Users\Application Data\CyberLink
    2007-11-17 17:55 . 2007-11-17 17:55 <DIR> d——– C:\Program Files\VirtualDJ
    2007-11-17 15:23 . 2007-11-17 15:23 <DIR> d——– C:\Documents and Settings\Ken Peeters\Application Data\AlcaTech
    2007-11-17 15:22 . 2007-11-17 15:22 <DIR> d——– C:\Documents and Settings\All Users\Application Data\AlcaTech
    2007-11-17 15:20 . 2007-11-17 15:20 <DIR> d——– C:\Documents and Settings\Ken Peeters\Application Data\GetRightToGo
    2007-11-13 20:31 . 2007-11-13 20:31 <DIR> d——– C:\Program Files\Filesweb
    2007-11-13 20:20 . 2007-11-13 20:20 <DIR> d——– C:\Program Files\Ashkon Software
    2007-11-13 20:17 . 2007-11-13 20:17 <DIR> d——– C:\WINDOWS\system32\FFSJ
    2007-11-13 20:17 . 2007-11-13 20:17 <DIR> d——– C:\Documents and Settings\Ken Peeters\Application Data\FFSJ
    2007-11-13 20:17 . 2007-11-13 20:17 704,793 –a—— C:\WINDOWS\unins000.exe
    2007-11-13 20:17 . 2007-11-13 20:17 3,732 –a—— C:\WINDOWS\unins000.dat
    2007-11-13 20:12 . 2007-11-13 20:12 <DIR> d——– C:\WINDOWS\[u:1da18f9c3b]0[/u:1da18f9c3b]01 File Joiner & Splitter Pro
    2007-11-13 20:12 . 2007-11-13 20:12 <DIR> d——– C:\Program Files\[u:1da18f9c3b]0[/u:1da18f9c3b]01 File Joiner & Splitter Pro
    2007-11-13 20:06 . 2007-11-13 20:06 <DIR> d——– C:\Program Files\[u:1da18f9c3b]0[/u:1da18f9c3b]01 Joiner
    2007-11-10 10:44 . 2007-11-10 10:46 10,740 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.CAT
    2007-11-10 10:44 . 2007-11-10 10:46 805 –a—— C:\WINDOWS\system32\drivers\SYMEVENT.INF
    2007-11-08 18:55 . 2007-11-08 18:55 19 –a—— C:\WINDOWS\popcinfo.dat
    2007-11-05 16:19 . 2007-11-05 16:19 <DIR> d——– C:\Program Files\Common Files\DirectX
    2007-11-05 16:14 . 2007-11-05 16:14 <DIR> d——– C:\Program Files\EA GAMES
    2007-11-05 16:00 . 2007-11-05 16:00 <DIR> d——– C:\WINDOWS\Downloaded Installations
    2007-11-04 17:49 . 2007-11-04 17:49 <DIR> d——– C:\Program Files\Zylom Games
    2007-11-04 17:49 . 2007-11-04 17:49 <DIR> d——– C:\Documents and Settings\Ken Peeters\Application Data\Zylom
    2007-11-04 17:49 . 2007-11-04 17:49 <DIR> d——– C:\Documents and Settings\Ken Peeters\Application Data\PlayFirst
    2007-11-04 17:49 . 2007-11-04 17:49 <DIR> d——– C:\Documents and Settings\All Users\Application Data\Zylom
    2007-11-04 17:49 . 2007-11-04 17:49 <DIR> d——– C:\Documents and Settings\All Users\Application Data\PlayFirst
    2007-11-04 10:42 . 2007-11-04 10:42 <DIR> d——– C:\Program Files\Monopoly
    2007-11-04 10:42 . 2007-11-04 10:42 <DIR> d——– C:\Documents and Settings\Ken Peeters\Application Data\SpinTop
    2007-11-04 10:42 . 2007-11-04 10:42 <DIR> d——– C:\Documents and Settings\All Users\Application Data\TEMP
    2007-11-04 10:37 . 2007-11-04 10:37 <DIR> d——– C:\Program Files\Parkeerbonnen Monopoly

    .
    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2007-11-10 09:46 60,800 —-a-w C:\WINDOWS\system32\S32EVNT1.DLL
    2007-11-10 09:46 123,952 —-a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
    2007-10-30 15:00 25,280 —-a-w C:\WINDOWS\system32\drivers\hamachi.sys
    2007-10-26 10:51 ——— d—–w C:\Program Files\AWS
    2007-10-26 10:42 ——— d—–w C:\Program Files\DAEMON Tools
    2007-10-26 10:31 685,816 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
    2007-10-25 16:44 8,507,392 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
    2007-10-24 13:20 ——— d—–w C:\Program Files\Metin2.us
    2007-10-24 10:23 11,973 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
    2007-10-24 10:01 ——— d—–w C:\Program Files\Activision
    2007-10-23 20:56 ——— d—–w C:\Program Files\QuickPar
    2007-10-23 19:24 352,256 —-a-w C:\WINDOWS\eSellerateEngine.dll
    2007-10-23 19:08 ——— d—–w C:\Documents and Settings\Ken Peeters\Application Data\GrabIt
    2007-10-23 19:07 ——— d—–w C:\Program Files\GrabIt
    2007-10-23 19:03 ——— d—–w C:\Program Files\FTDv3.8
    2007-10-23 17:31 ——— d–h–r C:\Documents and Settings\Ken Peeters\Application Data\SecuROM
    2007-10-23 17:20 ——— d—–w C:\Program Files\EA SPORTS
    2007-10-23 14:52 ——— d—–w C:\Documents and Settings\Ken Peeters\Application Data\Apple Computer
    2007-10-23 09:11 ——— d—–w C:\Program Files\QuickTime
    2007-10-23 09:11 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple Computer
    2007-10-23 09:10 ——— d—–w C:\Program Files\Apple Software Update
    2007-10-23 09:10 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
    2007-10-22 12:32 98,304 —-a-w C:\WINDOWS\system32\CmdLineExt.dll
    2007-10-22 12:27 ——— d—–w C:\Program Files\KONAMI
    2007-10-20 13:31 ——— d—–w C:\Program Files\Xfire
    2007-10-20 13:31 ——— d—–w C:\Documents and Settings\NetworkService\Application Data\Xfire
    2007-10-20 13:31 ——— d—–w C:\Documents and Settings\Ken Peeters\Application Data\Xfire
    2007-10-20 10:43 ——— d—–w C:\Program Files\GameSpy Arcade
    2007-10-20 10:39 ——— d—–w C:\Program Files\Microsoft Games
    2007-10-20 09:36 1,170,430 —-a-w C:\WINDOWS\Mall Tycoon 2 Uninstaller.exe
    2007-10-19 14:42 ——— d—–w C:\Documents and Settings\Ken Peeters\Application Data\LimeWire
    2007-10-19 14:41 ——— d—–w C:\Program Files\LimeWire
    2007-10-16 15:21 ——— d—–w C:\Program Files\Hamachi
    2007-10-16 15:21 ——— d—–w C:\Documents and Settings\Ken Peeters\Application Data\Hamachi
    2007-10-14 14:55 ——— d—–w C:\Program Files\Warcraft III
    2007-10-14 13:00 ——— d—–w C:\Program Files\Microsoft CAPICOM 2.1.0.2
    2007-10-13 13:47 ——— d—–w C:\Program Files\Java
    2007-10-13 13:46 ——— d—–w C:\Program Files\Common Files\Java
    2007-10-13 13:41 ——— d—–w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
    2007-10-12 20:39 ——— d—–w C:\Program Files\Windows Live
    2007-10-12 20:39 ——— d—–w C:\Program Files\Messenger Plus! Live
    2007-10-12 20:05 ——— d—–w C:\Program Files\Windows Live Toolbar
    2007-10-12 20:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
    2007-10-12 20:02 ——— d—–w C:\Program Files\MSN Messenger
    2007-10-12 19:38 ——— d—–w C:\Program Files\MSXML 4.0
    2007-10-07 18:52 ——— d—–w C:\Program Files\Real
    2007-10-07 18:52 ——— d—–w C:\Program Files\Common Files\xing shared
    2007-10-07 18:52 ——— d—–w C:\Program Files\Common Files\Real
    2007-10-07 16:29 ——— d—–w C:\Program Files\Softwarehouse Macco
    2007-10-07 15:01 ——— d—–w C:\Program Files\Teach2000
    2007-10-07 14:38 ——— d—–w C:\Documents and Settings\Ken Peeters\Application Data\Talkback
    2007-10-07 14:31 ——— d—–w C:\Program Files\Google
    2007-10-07 14:06 ——— d—–w C:\Program Files\Common Files\Logitech
    2007-10-07 14:06 ——— d—–w C:\Program Files\Common Files\Acer
    2007-10-07 14:05 ——— d—–w C:\Program Files\Acer
    2007-10-07 14:03 21,275 —-a-w C:\WINDOWS\system32\drivers\AegisP.sys
    2007-10-07 14:03 ——— d—–w C:\WINDOWS\system32\config\systemprofile\Application Data\Intel
    2007-10-07 14:03 ——— d—–w C:\Program Files\WinPCap
    2007-10-07 14:03 ——— d—–w C:\Documents and Settings\All Users\Application Data\Intel
    2007-10-07 14:02 ——— d—–w C:\Program Files\Launch Manager
    2007-10-07 14:00 ——— d—–w C:\Documents and Settings\Ken Peeters\Application Data\ATI
    2007-10-07 13:54 ——— d—–w C:\Program Files\ATI Technologies
    2007-10-01 13:49 542,088 —-a-w C:\WINDOWS\system32\SymNeti.dll
    2007-10-01 13:49 161,160 —-a-w C:\WINDOWS\system32\SymRedir.dll
    .

    ((((((((((((((((((((((((((((( snapshot@2007-12-02_20.21.48.57 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2006-11-02 21:52:44 316,416 —-a-w C:\WINDOWS\inf\unregmp2.exe
    + 2007-06-27 14:57:10 317,952 —-a-w C:\WINDOWS\inf\unregmp2.exe
    - 2006-10-18 20:47:16 414,208 —-a-w C:\WINDOWS\system32\dllcache\msscp.dll
    + 2006-12-04 15:21:50 414,720 —-a-w C:\WINDOWS\system32\dllcache\msscp.dll
    - 2006-11-02 21:52:44 316,416 —-a-w C:\WINDOWS\system32\dllcache\unregmp2.exe
    + 2007-06-27 14:57:10 317,952 —-a-w C:\WINDOWS\system32\dllcache\unregmp2.exe
    - 2006-10-18 20:47:20 10,834,432 —-a-w C:\WINDOWS\system32\dllcache\wmp.dll
    + 2007-06-11 22:51:12 10,834,944 —-a-w C:\WINDOWS\system32\dllcache\wmp.dll
    - 2006-10-18 20:47:16 414,208 —-a-w C:\WINDOWS\system32\msscp.dll
    + 2006-12-04 15:21:50 414,720 —-a-w C:\WINDOWS\system32\msscp.dll
    - 2006-10-18 20:47:20 10,834,432 —-a-w C:\WINDOWS\system32\wmp.dll
    + 2007-06-11 22:51:12 10,834,944 —-a-w C:\WINDOWS\system32\wmp.dll
    .
    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-02 13:00]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-17 16:15]
    "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
    "DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-08-16 13:24]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-17 22:40]
    "LaunchApp"="Alaunch" []
    "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-11-02 00:11]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-02 00:11]
    "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-09-02 13:00]
    "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-09-02 13:00]
    "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-09-02 13:00]
    "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-11-03 00:25]
    "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-11-03 00:22]
    "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-11-03 00:26]
    "ADMTray.exe"="C:\Acer\Empowering Technology\admtray.exe" [2005-10-24 16:45]
    "eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2005-12-27 15:50]
    "ntiMUI"="C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7
    tiMUI.exe" [2005-05-11 17:15]
    "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-09-16 16:27]
    "RTHDCPL"="RTHDCPL.EXE" [2006-04-04 02:44 C:\WINDOWS\RTHDCPL.exe]
    "AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2005-08-24 23:21]
    "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 17:41]
    "ePower_DMC"="C:\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2006-05-09 11:54]
    "Acer ePower Management"="C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe" [2006-05-08 18:41]
    "LManager"="C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE" [2006-04-03 17:03]
    "eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\Monitor.exe" [2006-01-24 18:00]
    "LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2006-03-31 10:47]
    "LogitechCameraAssistant"="C:\Program Files\Acer\OrbiCam\CameraAssistant.exe" [2006-03-31 10:24]
    "LogitechVideo[inspector]"="C:\Program Files\Acer\OrbiCam\InstallHelper.exe" [2006-03-31 10:32]
    "LogitechCameraService(E)"="C:\WINDOWS\system32\ElkCtrl.exe" [2004-11-01 17:22]
    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-07 19:52]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
    "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
    "Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 10:22]
    "Realtime Audio Engine"="mmrtkrnl.exe" [2007-07-18 15:52 C:\WINDOWS\system32\mmrtkrnl.exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-09-02 13:00]

    C:\Documents and Settings\All Users\Menu Start\Programma's\Opstarten\
    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
    "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

    R0 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys
    R1 OsaFsLoc;OsaFsLoc;\??\C:\WINDOWS\system32\drivers\OsaFsLoc.sys
    R2 EpmPsd;Acer EPM Power Scheme Driver;\??\C:\WINDOWS\system32\drivers\epm-psd.sys
    R2 EpmShd;Acer EPM System Hardware Driver;\??\C:\WINDOWS\system32\drivers\epm-shd.sys
    R2 int15.sys;int15.sys;\??\C:\Acer\Empowering Technology\eRecovery\int15.sys
    R2 osaio;osaio;\??\C:\WINDOWS\system32\drivers\osaio.sys
    R2 osanbm;osanbm;\??\C:\WINDOWS\system32\drivers\osanbm.sys
    R3 DKbFltr;Dritek Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\DKbFltr.sys
    R3 lv321av;Logitech USB PC Camera (VC0321);C:\WINDOWS\system32\Drivers\lv321av.sys
    R3 LVPrcMon;Logitech LVPrcMon Driver;\??\C:\WINDOWS\system32\drivers\LVPrcMon.sys
    R3 NdisFilt;OSA NdisFilter Protocol;C:\WINDOWS\system32\Drivers\NdisFilt.sys
    R3 SMCB000;SMSC CIR HID Miniport Device Driver;C:\WINDOWS\system32\DRIVERS\hidsmsc.sys
    S3 AVerE506;AVerE506 service;C:\WINDOWS\system32\DRIVERS\AVerE506.sys
    S3 AVerM115;AVerM115 service;C:\WINDOWS\system32\DRIVERS\AVerM115.sys
    S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys
    S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys
    S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys

    *Newly Created Service* - INT15.SYS
    .
    Inhoud van de 'Gedeelde Taken' map
    "2007-11-30 22:28:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    "2007-12-03 16:50:20 C:\WINDOWS\Tasks\Norton AntiVirus - Volledige systeemscan uitvoeren - Ken Peeters.job"
    - C:\PROGRA~1\NORTON~1\Navw32.exeh/TASK:
    "2007-12-02 19:16:04 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
    - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
    .
    **************************************************************************

    catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-12-03 17:50:53
    Windows 5.1.2600 Service Pack 2 FAT NTAPI

    scannen van verborgen processen …

    scannen van verborgen autostart items …

    scannen van verborgen bestanden …

    Scan succesvol afgerond
    verborgen bestanden: 0

    **************************************************************************
    .
    Voltooingstijd: 2007-12-03 17:52:25 - machine was rebooted
    C:\ComboFix2.txt … 2007-12-02 20:22
    .
    — E O F —





    Logje Hijackthis:


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17:55:56, on 3-12-2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
    C:\Acer\Empowering Technology\admServ.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Norton AntiVirus
    avapsvc.exe
    C:\Program Files\Eset
    od32krn.exe
    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Acer\Empowering Technology\admtray.exe
    C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
    C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
    C:\Acer\Empowering Technology\eRecovery\Monitor.exe
    C:\WINDOWS\system32\wbem\unsecapp.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\Acer\OrbiCam\CameraAssistant.exe
    C:\WINDOWS\system32\ElkCtrl.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\WINDOWS\system32\mmrtkrnl.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\DOCUME~1\KENPEE~1\LOCALS~1\Temp\RtkBtMnt.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Symantec\LiveUpdate\AUpdate.exe
    C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dutch.ircfast2.com/index.php?rvs=hompag
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.aceradvantage.com/stdreg
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
    O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [LaunchApp] Alaunch
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [ADMTray.exe] "C:\Acer\Empowering Technology\admtray.exe"
    O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
    O4 - HKLM\..\Run: [ntiMUI] C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7
    tiMUI.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
    O4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot
    O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
    O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Acer\OrbiCam\CameraAssistant.exe
    O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Acer\OrbiCam\InstallHelper.exe /inspect
    O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [Realtime Audio Engine] "mmrtkrnl.exe" /i
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ww\msntabres.dll.mui/229?1f72b401548c4d769bc621dc83caf537
    O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-ww\msntabres.dll.mui/230?1f72b401548c4d769bc621dc83caf537
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\Monopoly\Images\stg_drm.ocx
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\Monopoly\Images\armhelper.ocx
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
    O23 - Service: Norton AntiVirus Auto-Protect-service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus
    avapsvc.exe
    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset
    od32krn.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    O23 - Service: Planner voor Automatische LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


    End of file - 12740 bytes
  • Download ATF Cleaner (by Atribune)

    Dubbelklik op ATF cleaner om het programma te starten.
    Op het tabblad "Main", plaats je een vinkje bij [b:4b0ff9faaf]Select All[/b:4b0ff9faaf].
    Klik op de knop [b:4b0ff9faaf]Empty Selected[/b:4b0ff9faaf].

    Het volgende doen als je ook [u:4b0ff9faaf]FireFox[/u:4b0ff9faaf] als browser hebt:
    Klik op tabblad "Firefox", plaats een vinkje bij [b:4b0ff9faaf]Select All[/b:4b0ff9faaf].
    Wil je de door Firefox opgeslagen wachtwoorden behouden, dan klik je in het venster dat verschijnt op "No".
    (dit haalt het vinkje weer weg bij "Firefox saved passwords")
    Klik op de knop [b:4b0ff9faaf]Empty Selected.[/b:4b0ff9faaf]

    Het volgende doen als je ook [u:4b0ff9faaf]Opera[/u:4b0ff9faaf] als browser hebt:
    Klik op tabblad "Opera", plaats een vinkje bij [b:4b0ff9faaf]Select All[/b:4b0ff9faaf].
    Wil je de door Opera opgeslagen wachtwoorden behouden, dan klik je in het venster dat verschijnt op "No".
    Klik op de knop [b:4b0ff9faaf]Empty Selected[/b:4b0ff9faaf].
    Ga naar het tabblad "Main" en klik op de knop [b:4b0ff9faaf]Exit[/b:4b0ff9faaf] om het programma af te sluiten.

    Hoe is het inmiddels met je problemen?

    Pim
  • Volgens mij is het virus weg. Tenminste ik heb geen last meer gehad.
    Ontzettend bedankt :D :D :D

    Als het er toch nog op zou zitten laat ik nog wel wat weten

    Groetjes,
  • Prima Jan, ik hoor het wel :wink:

    Doe het volgende ook nog even:

    Deinstalleer Combofix:
    Ga naar start –> uitvoeren en typ daar: [b:0b88ab0bc4]combofix /u[/b:0b88ab0bc4]
    Combofix wordt nu verwijderd en er wordt een nieuw herstelpunt aangemaakt.

    Lees om herhaling te voorkomen deze beveiligingstips nog eens door:
    http://www.jawwi.nl/nederlands/tips/beveiligen/beveiligen.html

    Pim
  • Ben ik weer,

    Volgens mij (weet niet zeker) heb ik het virus nog steeds.

    Als ik met de verkenner bezig ben blijft die de hele tijd vasthangen.
    Explorer.exe chrasht ook de hele tijd.

    Ik heb wel al AVG Spyware, Spyblaster en Comodon Firewall Pro gedownload van die site die je in de vorige post vernoemd had.


    —————————————————————————-


    Hier Hijackthis logje:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 16:08:52, on 4-12-2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Acer\Empowering Technology\admtray.exe
    C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Acer\Empowering Technology\admServ.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
    C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
    C:\Acer\Empowering Technology\eRecovery\Monitor.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\Acer\OrbiCam\CameraAssistant.exe
    C:\WINDOWS\system32\ElkCtrl.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\system32\mmrtkrnl.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Norton AntiVirus
    avapsvc.exe
    C:\Program Files\Eset
    od32krn.exe
    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\DOCUME~1\KENPEE~1\LOCALS~1\Temp\RtkBtMnt.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\system32\wbem\unsecapp.exe
    C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\World of Warcraft\WoW-2.3.0-enGB-downloader.exe
    C:\WINDOWS\system32\drwtsn32.exe
    C:\WINDOWS\system32\drwtsn32.exe
    C:\Program Files\COMODO\Firewall\cfp.exe
    C:\WINDOWS\system32\drwtsn32.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\explorer.exe
    C:\PROGRA~1\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dutch.ircfast2.com/index.php?rvs=hompag
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.aceradvantage.com/stdreg
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
    O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [LaunchApp] Alaunch
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [ADMTray.exe] "C:\Acer\Empowering Technology\admtray.exe"
    O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
    O4 - HKLM\..\Run: [ntiMUI] C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7
    tiMUI.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
    O4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot
    O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
    O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Acer\OrbiCam\CameraAssistant.exe
    O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Acer\OrbiCam\InstallHelper.exe /inspect
    O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [Realtime Audio Engine] "mmrtkrnl.exe" /i
    O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fssui.exe" -autorun
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -s
    O4 - HKLM\..\RunOnce: [WMC_0] C:\WINDOWS\system32\regsvr32.exe /s "C:\WINDOWS\system32\wmv8dmod.dll"
    O4 - HKLM\..\RunOnce: [WMC_1] C:\WINDOWS\system32\regsvr32.exe /s "C:\WINDOWS\system32\mp4sds32.ax"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\Monopoly\Images\stg_drm.ocx
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\Monopoly\Images\armhelper.ocx
    O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
    O23 - Service: Norton AntiVirus Auto-Protect-service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus
    avapsvc.exe
    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset
    od32krn.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    O23 - Service: Planner voor Automatische LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


    End of file - 13971 bytes
  • Je bent nu veel te overbeveiligd! Teveel beveiligingsprogramma's leiden tot traagheid
    en tot die vastlopers die je noemt. Ook gaan deze elkaar tegenwerken, het heeft dus
    totaal geen zin.

    Start hijackthis, kies voor 'Do a system scan only' en vink onderstaande regels aan:
    [b:58a9d9c8d1]
    O4 - HKLM\..\RunOnce: [WMC_0] C:\WINDOWS\system32\regsvr32.exe /s "C:\WINDOWS\system32\wmv8dmod.dll"
    O4 - HKLM\..\RunOnce: [WMC_1] C:\WINDOWS\system32\regsvr32.exe /s "C:\WINDOWS\system32\mp4sds32.ax"
    [/b:58a9d9c8d1]

    Sluit alle openstaande vensters, behalve Hijackthis en klik op 'Fix checked'

    Je hebt meerdere anti spyware programma's naast elkaar lopen: Spybot's Teatimer, AVG Anti Spyware en Ad-watch van AdAware. AVG Antispyware zou ik zoiezo niet actief laten, omdat deze handmatig moet worden geupdate en vrij nutteloos is om actief te laten. Daarnaast moet je jezelf beperken tot Spybot of Adware. Deze kan je wel eenmaal in de zoveel tijd laten scannen, maar laat deze niet realtime lopen.

    Verder zie ik ook een trail draaien van NOD32, misschien dat deze is meegekomen met HitmanPro. Kijk eens of je deze kan verwijderen via start –> configuratiescherm –> software. Indien je besluit om anti spyware programma's te verwijderen, kan dat ook op deze manier.

    Herstart vervolgens je PC en post een nieuw logje van Hijackthis.

    Succes!

    Pim
  • Oeps :P Ik dacht dat ik van Trojan-Scanner, Spyware-Scanner , virusscanner en firewall enzo allemaal 1 van moest installeren.

    Ik heb nu nog:
    Ad-Aware = gedownload
    Comodo Firewall Pro = gedownload
    Norton Antivirus = gekocht

    Is dat goed?

    ———————————————————–

    Hijackthis:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 16:59:53, on 4-12-2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
    C:\Acer\Empowering Technology\admServ.exe
    C:\Program Files\COMODO\Firewall\cmdagent.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Norton AntiVirus
    avapsvc.exe
    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Acer\Empowering Technology\eRecovery\Monitor.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Acer\Empowering Technology\admtray.exe
    C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
    C:\WINDOWS\system32\wbem\unsecapp.exe
    C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
    C:\Acer\Empowering Technology\eRecovery\Monitor.exe
    C:\WINDOWS\system32\LVCOMSX.EXE
    C:\Program Files\Acer\OrbiCam\CameraAssistant.exe
    C:\WINDOWS\system32\ElkCtrl.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\WINDOWS\system32\mmrtkrnl.exe
    C:\Program Files\Windows Live\Family Safety\fssui.exe
    C:\Program Files\COMODO\Firewall\cfp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\DOCUME~1\KENPEE~1\LOCALS~1\Temp\RtkBtMnt.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Program Files\Windows Live Toolbar\msn_sl.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dutch.ircfast2.com/index.php?rvs=hompag
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.aceradvantage.com/stdreg
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
    O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [LaunchApp] Alaunch
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [ADMTray.exe] "C:\Acer\Empowering Technology\admtray.exe"
    O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
    O4 - HKLM\..\Run: [ntiMUI] C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7
    tiMUI.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
    O4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe boot
    O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXE
    O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Acer\OrbiCam\CameraAssistant.exe
    O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Acer\OrbiCam\InstallHelper.exe /inspect
    O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [Realtime Audio Engine] "mmrtkrnl.exe" /i
    O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fssui.exe" -autorun
    O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -s
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Lokale service')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Netwerkservice')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\Monopoly\Images\stg_drm.ocx
    O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\Monopoly\Images\armhelper.ocx
    O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\Firewall\cmdagent.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
    O23 - Service: Norton AntiVirus Auto-Protect-service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus
    avapsvc.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    O23 - Service: Planner voor Automatische LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


    End of file - 13678 bytes
  • Nu gaat je pc al een stukje sneller zeker :)

    Verder heeft Norton al een ingebouwde firewall zie ik net, dus Comodo kan je ook verwijderen via configuratiescherm –> software.

    Vergeet dan niet even te controleren of deze map weg is:
    C:\Program Files\[b:ede342e572]COMODO[/b:ede342e572].

    Hoe is het verder met je problemen?

    Pim

Beantwoord deze vraag

Dit is een gearchiveerde pagina. Antwoorden is niet meer mogelijk.