Archief - Check log

Het archief is een bevroren moment uit een vorige versie van dit forum, met andere regels en andere bazen. Deze posts weerspiegelen op geen enkele manier onze huidige ideeën, waarden of wereldbeelden en zijn op sommige plaatsen gecensureerd wegens ontoelaatbaar. Veel zijn in een andere tijdsgeest gemaakt, al dan niet ironisch - zoals in het ironische subforum Off-Topic - en zouden op dit moment niet meer gepost (mogen) worden. Toch bieden we dit archief nog graag aan als informatiedatabank en naslagwerk. Lees er hier meer over of start een gesprek met anderen.

Api3

Legacy Member
Heb wa probs mee menne winamp dus liever eerst eens laten checke :)

here you go:

Logfile of HijackThis v1.99.1
Scan saved at 14:54:59, on 3-11-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
c:\wamp\apache2\bin\Apache.exe
C:\Program Files\NetDrive\wdService.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\wamp\apache2\bin\Apache.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\ISP Monitor\isp.exe
C:\Program Files\PowerStrip\pstrip.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\wamp\wampserver.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\CTPdeSrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Mijn Documenten\Downloads\Programmas\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTHelper] :CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] :C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [PowerStrip] c:\program files\powerstrip\pstrip.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKCU\..\Run: [ISPMonitor] C:\Program Files\ISP Monitor\isp.exe
O4 - HKCU\..\Run: [Powerstrip] "C:\Program Files\PowerStrip\pstrip.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] :"d:\games\steam\steam.exe" -silent
O4 - Startup: WampServer.lnk = C:\wamp\wampserver.exe
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1153585676218
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: wampapache - Unknown owner - c:\wamp\apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: wampmysqld - Unknown owner - c:\wamp\mysql\bin\mysqld-nt.exe
O23 - Service: WebDrive Service (WebDriveService) - Unknown owner - C:\Program Files\NetDrive\wdService.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)

Jurgenv1

Legacy Member
* Je Java software is verouderd. oudere versies hebben lekken die malware de kans geeft om zich te installeren op je systeem. Doe eerst deze stappen om Java te de-installeren en de nieuwere versie te installeren:

  • Download de nieuwste versie hier: Java Runtime Environment (JRE) 5.0 Update 9.
  • Scroll naar beneden tot waar er staat: "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Klik dan rechts op de "Download" knop.
  • Vink het volgende aan waar er staat: "Accept License Agreement".
  • De pagina zal herladen.
  • Klik op de link om Windows Offline Installation te downloaden met Meerdere-talen En bewaar het naar je bureaublad.
  • Sluit alle programma's die eventueel open zijn - Zeker je web browser!
  • Ga dan naar Start > Configuratiescherm en dubbelklik op software en verwijder alle oudere versies van Java.
  • Vink alles aan met Java Runtime Environment (JRE of J2SE) in de naam.
  • Klik dan op Verwijderen of Wijzig/Verwijder knop.
  • Herhaal dit tot alle oudere versies verdwenen zijn.
  • Na het verwijderen van alle oudere versies, herstart dan je pc.
  • Dubbelkik dan op jre-1_5_0_09-windows-i586-p.exe op je bureaublad om de nieuwste versie van Java te installeren.

* Download Dr.Web CureIt naar je bureaublad:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Dubbelklik drweb-cureit.exe en sta het toe om de express scan te starten.
  • Dit zal de bestanden scannen die momenteel in het geheugen geladen zijn en wanneer er iets gevonden wordt, klik de Yes to all knop bij de vraag 'cure it?'. Dit is enkel een korte scan.
  • Eenmaal de korte scan is beeïndigd, Klik Options > Change Settings
  • Kies de "Scan"-tab en verwijder het vinkje bij "Heuristic analyse"
  • Terug in het hoofdvenster kan je de drives selecteren die je wilt laten scannen.
  • Selecteer hier alle drives. Een rood bolletje zal dan tevoorschijn komen op de drives die je laat scannen.
  • Klik daarna de groene pijl rechts om de scan te starten.
  • Klik 'Yes to all' wanneer er gevraagd wordt om cure of move uit te voeren.
  • Wanneer de scan gedaan is, kijk of je volgende icoontje kan aanklikken dat staat naast hetgeen gevonden werd:
    check.gif
  • Indien wel, klik erop en daarna klik op het icoontje er net onder en kies: Move incurable zoals je zal zien in volgende afbeelding:
    move.gif

    Dit zal de bestanden verplaatsen naar volgende map %userprofile%\DoctorWeb\quarantaine-folder indien het niet gedesinfecteerd kan worden. (dit in het geval dat we samples nodig hebben)
  • Na bovenstaande te selecteren, in het menu bovenaan van Dr.Web CureIt, klik file en kies save report list. Bewaar de log op je bureaublad.
  • Sluit daarna Dr.Web Cureit.
  • Herstart je computer!! Belangrijke stap, want het kan zijn dat Dr.Web Cureit bestanden zal verplaatsen/verwijderen tijdens herstart.
  • Na het herstarten, Kopieer en plak de inhoud van die log die je eerder hebt bewaard in je volgende post met een nieuw hijackthis logje.

Api3

Legacy Member
ok kzit mee serieuse shit nu, heb trouwens alles gedaan wat je vroeg jurgen, maar nu heb ik iets raars voor, steeds popups etc (dikke vuiligheid diek per ongeluk heb binnengehaald) dus best nog eens nazien :D

Logfile of HijackThis v1.99.1
Scan saved at 19:44:26, on 8-11-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ishost.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\ismini.exe
C:\program files\powerstrip\pstrip.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\ipwins\ipwins.exe
C:\Program Files\Common Files\{CC5BAF39-07DA-1043-1216-05110904001f}\Update.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ISP Monitor\isp.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\wamp\wampserver.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
c:\wamp\apache2\bin\Apache.exe
C:\Program Files\NetDrive\wdService.exe
C:\wamp\apache2\bin\Apache.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Mijn Documenten\Downloads\Programmas\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{3C5BAF39-07DA-1043-1216-05110904001f}\MyToolBar.dll
O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{3C5BAF39-07DA-1043-1216-05110904001f}\MyToolBar.dll
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [CTHelper] :CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] :C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [PowerStrip] "c:\program files\powerstrip\pstrip.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [CTDrive] "rundll32.exe" C:\WINDOWS\system32\drvwov.dll,startup
O4 - HKLM\..\Run: [IpWins] "C:\Program Files\ipwins\ipwins.exe"
O4 - HKCU\..\Run: [Powerstrip] "C:\Program Files\PowerStrip\pstrip.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] :"d:\games\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ISPMonitor] C:\Program Files\ISP Monitor\isp.exe
O4 - Startup: WampServer.lnk = C:\wamp\wampserver.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1153585676218
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: wincnw32 - C:\WINDOWS\SYSTEM32\wincnw32.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: wampapache - Unknown owner - c:\wamp\apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: wampmysqld - Unknown owner - c:\wamp\mysql\bin\mysqld-nt.exe
O23 - Service: WebDrive Service (WebDriveService) - Unknown owner - C:\Program Files\NetDrive\wdService.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)

Jurgenv1

Legacy Member
Komt ervan illegale site's te bezoeken.

Download combofix.exe: http://download.bleepingcomputer.com/sUBs/combofix.exe
Plaats het op je bureaublad.
Dubbelklik er op om het programma te starten.
In het scherm dat verschijnt tik je een Y in om het cleaningsprocess te starten.
Volg de instructies op het scherm.
Als het tooltje klaar is, opent er een logfile (combofix.txt) Post de inhoud van dit bestandje samen met een nieuwe hijackthislog.

Api3

Legacy Member
ok, hier komt het:
Simon Dhoore - 06-11-08 21:19:56,29 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\Simon Dhoore\Bureaublad"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\ishost.exe
C:\WINDOWS\system32\ismini.exe
C:\WINDOWS\system32\issearch.exe
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\Inetget2
C:\WINDOWS\system32\components
C:\Program Files\Common Files\{3C5BAF39-07DA-1043-1216-05110904001f}
C:\Program Files\Ipwins
C:\Program Files\Common Files\{CC5BAF39-07DA-1043-1216-05110904001f}


((((((((((((((((((((((((((((((( Files Created from 2006-10-08 to 2006-11-08 ))))))))))))))))))))))))))))))))))


2006-11-08 19:28 684,032 --a------ C:\WINDOWS\system32\libeay32.dll
2006-11-08 19:28 155,648 --a------ C:\WINDOWS\system32\ssleay32.dll
2006-11-08 17:31 72,192 --a------ C:\WINDOWS\unlite3.exe
2006-11-07 14:21 59,392 --a------ C:\WINDOWS\system32\drvwov.dll
2006-11-06 23:44 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2006-11-06 21:07 106,496 --a------ C:\WINDOWS\system32\impgsje.dll
2006-11-06 21:02 59,392 --a------ C:\WINDOWS\system32\drvdeb.dll
2006-11-06 21:02 15,872 --a------ C:\WINDOWS\system32\wincnw32.dll
2006-11-05 21:39 816,672 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-11-05 21:39 4,960 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys
2006-11-05 21:39 4,224 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-11-05 21:39 3,968 --a------ C:\WINDOWS\system32\drivers\avgclean.sys
2006-11-05 21:39 28,416 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-11-05 21:39 18,240 --a------ C:\WINDOWS\system32\drivers\avgmfx86.sys
2006-11-03 14:08 129,784 --------- C:\WINDOWS\system32\pxafs.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-11-08 21:21 -------- d-------- C:\Program Files\Common Files
2006-11-08 21:18 -------- d-------- C:\Program Files\Mozilla Firefox
2006-11-08 19:12 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-11-08 18:34 -------- d-------- C:\Documents and Settings\Simon Dhoore\Application Data\Azureus
2006-11-08 17:31 -------- d-------- C:\Program Files\Bradbury
2006-11-08 14:46 -------- d-------- C:\Program Files\totalcmd
2006-11-08 12:59 -------- d-------- C:\Program Files\Mozilla Thunderbird
2006-11-07 23:34 -------- d-------- C:\Program Files\Winamp
2006-11-07 23:22 -------- d-------- C:\Documents and Settings\Simon Dhoore\Application Data\Winamp
2006-11-07 22:56 -------- d-------- C:\Program Files\EditPlus 2
2006-11-07 22:54 -------- d-------- C:\Documents and Settings\Simon Dhoore\Application Data\Bradsoft.com
2006-11-06 23:46 -------- d-------- C:\Program Files\Windows Media Player
2006-11-06 23:46 -------- d-------- C:\Program Files\Internet Explorer
2006-11-06 23:44 -------- d-------- C:\Program Files\Outlook Express
2006-11-06 23:44 -------- d-------- C:\Program Files\Common Files\System
2006-11-06 23:43 -------- d-------- C:\Program Files\MSXML 4.0
2006-11-06 23:22 -------- d-------- C:\Program Files\Hitman Pro
2006-11-06 21:32 -------- d-------- C:\Documents and Settings\Simon Dhoore\Application Data\Lavasoft
2006-11-06 21:27 -------- d-------- C:\Program Files\Lavasoft
2006-11-06 21:03 -------- d-------- C:\Program Files\Registry Mechanic
2006-11-06 20:54 -------- d-------- C:\Program Files\mIRC
2006-11-06 20:37 -------- d-------- C:\Program Files\FlashFXP
2006-11-05 21:41 -------- d-------- C:\Documents and Settings\Simon Dhoore\Application Data\AVG7
2006-11-05 21:39 -------- d---s---- C:\Documents and Settings\Simon Dhoore\Application Data\Microsoft
2006-11-05 21:39 -------- d-------- C:\Program Files\Grisoft
2006-11-04 03:28 737280 --a------ C:\WINDOWS\iun6002.exe
2006-11-04 03:28 -------- d-------- C:\Program Files\ISP Monitor
2006-11-03 19:53 -------- d-------- C:\Program Files\Java
2006-11-03 19:53 -------- d-------- C:\Program Files\Common Files\Java
2006-11-03 15:13 -------- d-------- C:\Program Files\Microsoft SQL Server
2006-11-03 15:12 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-11-03 15:11 -------- d-------- C:\Program Files\Microsoft.NET
2006-11-03 15:10 -------- d-------- C:\Program Files\Microsoft SQL Server 2005 Mobile Edition
2006-11-03 15:10 -------- d-------- C:\Program Files\Microsoft Device Emulator
2006-11-03 15:06 -------- d-------- C:\Program Files\MSBuild
2006-11-03 15:06 -------- d-------- C:\Program Files\Microsoft Visual Studio 8
2006-11-03 15:06 -------- d-------- C:\Program Files\HTML Help Workshop
2006-11-03 15:05 -------- d-------- C:\Program Files\Common Files\Merge Modules
2006-11-03 15:02 -------- d-------- C:\Program Files\Common Files\Business Objects
2006-11-03 15:01 -------- d-------- C:\Program Files\CE Remote Tools
2006-11-03 15:00 -------- d-------- C:\Program Files\Microsoft Office
2006-11-03 14:39 -------- d-------- C:\Program Files\MozBackup
2006-11-03 14:39 -------- d-------- C:\Program Files\iPod
2006-11-02 22:47 -------- d-------- C:\Program Files\RealVNC
2006-11-02 22:44 -------- d-------- C:\Program Files\MSN Messenger
2006-11-02 22:44 -------- d-------- C:\Program Files\Messenger Plus!
2006-10-28 03:10 -------- d-------- C:\Documents and Settings\Simon Dhoore\Application Data\Xfire
2006-10-27 23:18 -------- d---s---- C:\Program Files\Xfire
2006-10-25 19:34 12464 --a------ C:\WINDOWS\system32\drivers\secdrv.sys
2006-10-21 12:49 -------- d-------- C:\Program Files\WowReader
2006-10-03 01:15 -------- d-------- C:\Program Files\DVD Decrypter
2006-09-25 18:21 -------- d-------- C:\Program Files\Ventrilo
2006-09-25 18:21 -------- d-------- C:\Program Files\Common Files\Wise Installation Wizard
2006-09-13 06:07 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-09-12 17:51 1245184 --a------ C:\WINDOWS\system32\msxml4.dll
2006-09-03 16:50 73 --a------ C:\WINDOWS\system32\ssprs.dll
2006-09-03 16:50 205 --a------ C:\WINDOWS\system32\lsprst7.dll
2006-09-03 16:50 1025 --a------ C:\WINDOWS\system32\sysprs7.dll
2006-09-03 16:50 1025 --a------ C:\WINDOWS\system32\clauth2.dll
2006-09-03 16:50 1025 --a------ C:\WINDOWS\system32\clauth1.dll
2006-09-01 14:32 82432 --a------ C:\WINDOWS\system32\msxml4r.dll
2006-09-01 12:08 1334032 --a------ C:\WINDOWS\system32\msxml6.dll
2006-08-25 16:51 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-25 04:47 115880 --------- C:\WINDOWS\system32\pxinsi64.exe
2006-08-21 13:28 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 10:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-16 12:59 100352 --a------ C:\WINDOWS\system32\6to4svc.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Powerstrip"="\"C:\\Program Files\\PowerStrip\\pstrip.exe\""
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Steam"=":\"d:\\games\\steam\\steam.exe\" -silent"
"ISPMonitor"="C:\\Program Files\\ISP Monitor\\isp.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"type32"="\"C:\\Program Files\\Microsoft IntelliType Pro\\type32.exe\""
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE"
"CTSysVol"="\"C:\\Program Files\\Creative\\SBAudigy2ZS\\Surround Mixer\\CTSysVol.exe\" /r"
"CTHelper"=":CTHELPER.EXE"
"SBDrvDet"=":C:\\Program Files\\Creative\\SB Drive Det\\SBDrvDet.exe /r"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"PowerStrip"="\"c:\\program files\\powerstrip\\pstrip.exe\""
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"AVG7_CC"="\"C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe\" /STARTUP"
"CTDrive"="\"rundll32.exe\" C:\\WINDOWS\\system32\\drvwov.dll,startup"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Mijn huidige introductiepagina"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e4,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,4b,00,00,00,00,00,00,00,b5,04,00,00,e4,03,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,4b,00,00,00,00,00,00,00,b5,04,00,00,e4,03,\
00,00,01,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Preloader van browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Cache-daemon voor onderdeelcategorieën"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wincnw32

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

Completion time: 06-11-08 21:21:52.93
C:\ComboFix.txt ... 06-11-08 21:21


HIJACKTHISLOG:
Logfile of HijackThis v1.99.1
Scan saved at 21:22:52, on 8-11-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
c:\wamp\apache2\bin\Apache.exe
C:\Program Files\NetDrive\wdService.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\wamp\apache2\bin\Apache.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\program files\powerstrip\pstrip.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ISP Monitor\isp.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\wamp\wampserver.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
D:\Mijn Documenten\Downloads\Programmas\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: (no name) - {C004DEC2-2623-438e-9CA2-C9043AB28508} - (no file)
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [CTHelper] :CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] :C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [PowerStrip] "c:\program files\powerstrip\pstrip.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [CTDrive] "rundll32.exe" C:\WINDOWS\system32\drvwov.dll,startup
O4 - HKCU\..\Run: [Powerstrip] "C:\Program Files\PowerStrip\pstrip.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] :"d:\games\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ISPMonitor] C:\Program Files\ISP Monitor\isp.exe
O4 - Startup: WampServer.lnk = C:\wamp\wampserver.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1153585676218
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: wincnw32 - C:\WINDOWS\SYSTEM32\wincnw32.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: wampapache - Unknown owner - c:\wamp\apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: wampmysqld - Unknown owner - c:\wamp\mysql\bin\mysqld-nt.exe
O23 - Service: WebDrive Service (WebDriveService) - Unknown owner - C:\Program Files\NetDrive\wdService.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)

Jurgenv1

Legacy Member
* Je kan deze instructies best uitprinten of opslaan in een kladblokbestand, want straks zal je in veilige modus
moeten gaan werken, en dan is deze pagina niet beschikbaar (geen internet)

* Download smitRem.exe en sla dit op op het Bureaublad.
Dubbelklik op het bestand en pak het uit naar zijn eigen map op het Bureaublad.


* Download en installeer AVG Anti-Spyware.

  • Na de installatie, open AVG Anti-Spyware:
    * onder "Status", klik op Change state naast "Resident shield". (wijzig van active naar inactive!)
    * onder "Update", klik op de Start update knop.
    * onder "Scanner", tab "Settings":
    • - onder "How to act?", klik op "Recommended actions" en selecteer Quarantine. (ZEER BELANGRIJK!)
      * onder "Reports", selecteer Automatically generate report after every scan en verwijder het vinkje bij Only if threats were found
    Sluit AVG Anti-Spyware. Laat het nog niet scannen.

* Als je Adaware SE nog niet geïnstalleerd hebt, download, installeer en update het dan volgens de richtlijnen
die je kan vinden op: http://users.pandora.be/marcvn/spyware/1414188.htm
Download link van Ad-aware: http://www.lavasoftusa.com/products/ad-aware_se_personal.php

* Start je computer op in VEILIGE MODUS

* Open de smitrem-map op je bureaublad, en dubbelklik op RunThis.bat. Volg de aanwijzigingen op het scherm.
Je bureaublad en ikoontjes zullen even verdwijnen en daarna terug verschijnen, dit is normaal.
Wacht tot het tooltje zijn werk heeft gedaan en Disk Cleanup afgelopen is. Dit kan enige tijd duren, dus wees geduldig.

* Voer een volledige scan uit met Adaware en verwijder alles wat gevonden wordt.

* Start AVG Anti-Spyware.
  • * Klik op Scan en kies Complete System Scan.
    Na de scan; volg onderstaande instructies :
    BELANGRIJK : Klik niet op de "Save Scan Report" knop vooraleer je de "Apply all Actions" knop hebt aangeklikt !
    * Draag er zorg voor dat Set all elements to: op Quarantine staat (1),
    zoniet klik op de link en kies Quarantine in de popup menu. (2)
    (Dit geldt niet voor cookies, deze worden onveranderlijk gedelete !)
    * Onderaan het venster klik op de Apply all Actions knop. (3)
    ewidoscan.jpg

    * Wanneer je de melding krijgt 'All actions have been applied', klik je onderaan op de knop Save Report.

* Ga dan naar Start -> configuratiescherm -> vormgeving en thema's -> bureaublad ->bureaublad aanpassen -> Website -> haal het vinkje weg bij "Security Info" als het er nog staat.

* Herstart je computer in normale modus.

* Download ATF cleaner (by Atribune)

Dubbelklik op ATF cleaner om het programma te starten.
Op het tabblad "Main", plaats je een vinkje bij Select All.
Klik op de knop Empty Selected.

Gebruik je ook Firefox als browser:
Klik op tabblad "Firefox", plaats een vinkje bij Select All.
Wil je de door Firefox opgeslagen wachtwoorden behouden, dan klik je in het venster dat verschijnt op "No".
(dit verwijdert het vinkje bij "Firefox saved passwords")
Klik op de knop Empty Selected.

Gebruik je ook Opera als browser:
Klik op tabblad "Opera", plaats een vinkje bij Select All.
Wil je de door Opera opgeslagen wachtwoorden behouden, dan klik je in het venster dat verschijnt op "No".
Klik op de knop Empty Selected.
Ga naar het tabblad "Main" en klik op de knop Exit om het programma af te sluiten.

* Doe een online scan via Panda's online virus scan en bewaar het rapport dat je krijgt na het scannen

* Herstart je pc nogmaals en plaats dan een nieuw logje van Hijackthis, samen met het rapport van AVG Anti-Spyware 7.5 en Panda, Post de log van de smitRem tool, die je hier kan vinden: C:\smitfiles.txt.

Api3

Legacy Member
HIJACKTHIS:
Logfile of HijackThis v1.99.1
Scan saved at 0:57:28, on 9-11-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
c:\wamp\apache2\bin\Apache.exe
C:\Program Files\NetDrive\wdService.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\wamp\apache2\bin\Apache.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\program files\powerstrip\pstrip.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ISP Monitor\isp.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\wamp\wampserver.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\mspaint.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Mijn Documenten\Downloads\Programmas\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [CTHelper] :CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] :C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [PowerStrip] "c:\program files\powerstrip\pstrip.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvpuw.dll,startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Powerstrip] "C:\Program Files\PowerStrip\pstrip.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] :"d:\games\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ISPMonitor] C:\Program Files\ISP Monitor\isp.exe
O4 - Startup: WampServer.lnk = C:\wamp\wampserver.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1153585676218
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: wincnw32 - wincnw32.dll (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: wampapache - Unknown owner - c:\wamp\apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: wampmysqld - Unknown owner - c:\wamp\mysql\bin\mysqld-nt.exe
O23 - Service: WebDrive Service (WebDriveService) - Unknown owner - C:\Program Files\NetDrive\wdService.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)

AVG-ANTISPYWARE:
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 23:28:03 8-11-2006

+ Scan result:



C:\Documents and Settings\Simon Dhoore\DoctorWeb\Quarantine\SetupDTSB.exe -> Adware.SaveNow : Cleaned.
C:\System Volume Information\_restore{932FBB12-369E-4836-A63C-27AFDBDCF52E}\RP151\A0039013.exe -> Adware.SaveNow : Cleaned.
C:\System Volume Information\_restore{932FBB12-369E-4836-A63C-27AFDBDCF52E}\RP155\A0040428.exe -> Downloader.Zlob.auw : Cleaned.
C:\System Volume Information\_restore{932FBB12-369E-4836-A63C-27AFDBDCF52E}\RP157\A0044715.exe -> Downloader.Zlob.avb : Cleaned.
C:\System Volume Information\_restore{932FBB12-369E-4836-A63C-27AFDBDCF52E}\RP157\A0045714.exe -> Downloader.Zlob.avb : Cleaned.
C:\System Volume Information\_restore{932FBB12-369E-4836-A63C-27AFDBDCF52E}\RP159\A0045917.exe -> Downloader.Zlob.avb : Cleaned.
C:\System Volume Information\_restore{932FBB12-369E-4836-A63C-27AFDBDCF52E}\RP159\A0046917.exe -> Downloader.Zlob.avb : Cleaned.
C:\System Volume Information\_restore{932FBB12-369E-4836-A63C-27AFDBDCF52E}\RP159\A0046983.exe -> Downloader.Zlob.avb : Cleaned.
C:\Documents and Settings\Simon Dhoore\DoctorWeb\Quarantine\CrackSearche0.exe -> Not-A-Virus.HackTool.Win32.CrackSearch.a : Cleaned.
C:\Documents and Settings\Simon Dhoore\DoctorWeb\Quarantine\CrackSearcher.exe -> Not-A-Virus.HackTool.Win32.CrackSearch.a : Cleaned.
E:\Dowloads\Appz\cracksearcher.zip/CrackSearcher.exe -> Not-A-Virus.HackTool.Win32.CrackSearch.a : Cleaned.
:mozilla.141:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.142:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.20:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.180:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.181:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.182:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.555:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Gamershell : Cleaned.
:mozilla.556:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Gamershell : Cleaned.
:mozilla.557:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Gamershell : Cleaned.
:mozilla.558:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Gamershell : Cleaned.
:mozilla.57:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.672:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.294:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Hypertracker : Cleaned.
:mozilla.185:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Planetactive : Cleaned.
:mozilla.90:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Quarterserver : Cleaned.
:mozilla.183:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.155:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.156:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.157:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.161:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
C:\WINDOWS\system32\wincnw32.dll -> Trojan.Agent.vg : Cleaned.


::Report end

PANDA:

Incident Status Location

Spyware:Cookie/MetriWeb Not disinfected C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt[.metriweb.be/]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Simon Dhoore\Bureaublad\smitRem\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Simon Dhoore\Bureaublad\smitRem.exe[smitRem/Process.exe]
Adware:Adware/Adservice Not disinfected C:\WINDOWS\system32\drvdeb.dll
Potentially unwanted tool:Application/MotherboardMonitor.A Not disinfected D:\Mijn Documenten\Backups\mirc\Nonamescript\script\dlls\moo.dll
Hacktool:HackTool/CrackSearch.A Not disinfected E:\Dowloads\Appz\cracksearcher.zip[CrackSearcher.exe]


SMITRITE:

smitRem © log file
version 3.2

by noahdfear


Microsoft Windows XP [versie 5.1.2600]
"IE"="6.0000"

Running from
C:\Documents and Settings\Simon Dhoore\Bureaublad\smitRem

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pre-run SharedTask Export

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright(C) 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Preloader van browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Cache-daemon voor onderdeelcategorieën"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Appinitdll check ........ Thank you Grinler!

dumphive.exe (C)2000-2004 Markus Stephany
REGEDIT4

[Windows]
"AppInit_DLLs"=""
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

XP Firewall allowed access

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"="C:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe:*:Enabled:Apache HTTP Server"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe:*:Enabled:avgemc.exe"

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


checking for ShudderLTD key

ShudderLTD key not present!

checking for PSGuard.com key


PSGuard.com key not present!


checking for WinHound.com key


WinHound.com key not present!


checking for drsmartload2 key


drsmartload2 key not present!

spyaxe uninstaller NOT present
Winhound uninstaller NOT present
SpywareStrike uninstaller NOT present
AlfaCleaner uninstaller NOT present
SpyFalcon uninstaller NOT present
SpywareQuake uninstaller NOT present
SpywareSheriff uninstaller NOT present
Trust Cleaner uninstaller NOT present
SpyHeal uninstaller NOT present
VirusBurst uninstaller NOT present
BraveSentry uninstaller NOT present
AntiVermins uninstaller NOT present
VirusBursters uninstaller NOT present

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Existing Pre-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~

amcompat.tlb
ishost.exe
ismini.exe
nscompat.tlb
logfiles


~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 [email protected]
Killing PID 840 'explorer.exe'
Killing PID 840 'explorer.exe'

Starting registry repairs

Registry repairs complete

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

SharedTask Export after registry fix

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright(C) 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Preloader van browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Cache-daemon voor onderdeelcategorieën"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Deleting files

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Remaining Post-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~



~~~ Wininet.dll ~~~

CLEAN! :)


heb dit alles dus gedaan, maar heb nog steeds dit probleem:
http://img463.imageshack.us/img463/2039/adwarele7.jpg

is dus een spyware diek nie wegkrijg, dit heeft steeds popup etc, zeer vervelend.

alvast bedankt voor uw tijd en hulp.

Jurgenv1

Legacy Member
* Download en unzip Killbox naar je bureaublad.
Klik op killbox.exe.
Selecteer de optie "Delete on reboot".
In het veld "Full Path of File to Delete" kopieer en plak je het volgende:

C:\WINDOWS\system32\drvdeb.dll



Klik op de knop: single file (!Belangrijk!)

Daarna, Klik op de rode cirkel met het wit kruisje erin.
Killbox zal zeggen dat deze file zal verwijderd worden on reboot.. vraagt om nu te rebooten. Klik YES.

Je pc moet nu rebooten.

Download roguescanfix_setup.

Dubbelklik op roguescanfix_setup om het te installeren.

Na de installatie krijg je de vraag om het programma te laten opstarten. Kies dan JA/YES.

Nota: Deze tool heeft internet connectie nodig zodat het een extra bestand kan downloaden om deze tool te laten werken.
Indien je Firewall een alert geeft, sta het toe en blokkeer het niet
Indien je daarna nog steeds de melding krijgt dat BFU.exe niet aanwezig is, download BFU.exe van hier.
Unzip het en plaats BFU.exe in de c:\PROGRAM FILES\Roguescanfix-map. Dubbelklik daarna opnieuw op Roguescanfix.bat


Er zal een dosvenster openen met een keuzemenu.
Kies hier optie #1: Run roguescanfix

Deze tool zal sommige ongewenste programma's deïnstalleren en gerelateerde bestanden en registersleutels verwijderen.
Indien sommige bestanden niet kunnen verwijderd worden, zal deze tool vragen of je je pc opnieuw wilt opstarten.
Zorg er wel eerst voor dat het deïnstalleren van de ongewenste programma's voltooid is vooraleer je op 'Yes' klikt om je pc opnieuw te laten opstarten.

Er zal een kladblokbestandje openen. Plaats de inhoud van dat bestandje in je volgende antwoord, samen met een nieuw logje van Hijackthis.
(Het bestandje vind je ook in c:\program files\roguescanfix\task.txt)

Api3

Legacy Member
HIJACKTHIS:
Logfile of HijackThis v1.99.1
Scan saved at 17:45:28, on 9-11-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\program files\powerstrip\pstrip.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ISP Monitor\isp.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\wamp\wampserver.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
c:\wamp\apache2\bin\Apache.exe
C:\Program Files\NetDrive\wdService.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\wamp\apache2\bin\Apache.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Mijn Documenten\Downloads\Programmas\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [CTHelper] :CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] :C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [PowerStrip] "c:\program files\powerstrip\pstrip.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvpuw.dll,startup
O4 - HKCU\..\Run: [Powerstrip] "C:\Program Files\PowerStrip\pstrip.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] :"d:\games\steam\steam.exe" -silent
O4 - HKCU\..\Run: [ISPMonitor] C:\Program Files\ISP Monitor\isp.exe
O4 - Startup: WampServer.lnk = C:\wamp\wampserver.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1153585676218
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: wincnw32 - wincnw32.dll (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: wampapache - Unknown owner - c:\wamp\apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: wampmysqld - Unknown owner - c:\wamp\mysql\bin\mysqld-nt.exe
O23 - Service: WebDrive Service (WebDriveService) - Unknown owner - C:\Program Files\NetDrive\wdService.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)

ROGUESCAN:
Export SharedTaskScheduler key
------------------------------
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Preloader van browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Cache-daemon voor onderdeelcategorieën"

Jurgenv1

Legacy Member
Kan je eens AVG antispyware opnieuw laten runnen in veilige modus en mij het rapport hier posten?

Api3

Legacy Member
sorry voor late antwoord, hier het raport:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 23:44:51 14-11-2006

+ Scan result:



C:\!KillBox\drvdeb.dll -> Not-A-Virus.Hoax.Win32.Renos.ge : Cleaned with backup (quarantined).
:mozilla.48:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.40:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.41:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.42:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.43:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.44:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.45:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.46:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.47:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Simon Dhoore\Cookies\simon [email protected][2].txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.87:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.88:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.53:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.54:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.55:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.56:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.57:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.68:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.69:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.70:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.71:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.72:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.89:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.90:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\Simon Dhoore\Cookies\simon dhoore@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.61:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.62:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.63:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.64:C:\Documents and Settings\Simon Dhoore\Application Data\Mozilla\Firefox\Profiles\ljrmygnr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.


::Report end

Api3

Legacy Member
combofix log:


Simon Dhoore - 06-11-15 14:01:32,98 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\Simon Dhoore\Bureaublad"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\components


((((((((((((((((((((((((((((((( Files Created from 2006-10-15 to 2006-11-15 ))))))))))))))))))))))))))))))))))


2006-11-12 23:42 98,304 --a------ C:\WINDOWS\system32CmdLineExt.dll
2006-11-08 22:09 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-11-08 22:08 101,888 --a------ C:\WINDOWS\system32\drvpuw.dll
2006-11-08 19:28 684,032 --a------ C:\WINDOWS\system32\libeay32.dll
2006-11-08 19:28 155,648 --a------ C:\WINDOWS\system32\ssleay32.dll
2006-11-08 17:31 72,192 --a------ C:\WINDOWS\unlite3.exe
2006-11-06 23:44 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2006-11-05 21:39 816,672 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-11-05 21:39 4,960 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys
2006-11-05 21:39 4,224 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-11-05 21:39 3,968 --a------ C:\WINDOWS\system32\drivers\avgclean.sys
2006-11-05 21:39 28,416 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-11-05 21:39 18,240 --a------ C:\WINDOWS\system32\drivers\avgmfx86.sys
2006-11-04 20:25 1,321,744 --a------ C:\WINDOWS\system32\msxml6.dll
2006-11-04 14:14 1,245,696 --a------ C:\WINDOWS\system32\msxml4.dll
2006-11-03 14:08 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2006-10-31 22:43 233,984 --a------ C:\WINDOWS\system32\gc.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-11-15 13:56 -------- d-------- C:\Program Files\Mozilla Firefox
2006-11-15 00:13 -------- d-------- C:\Documents and Settings\Simon Dhoore\Application Data\Xfire
2006-11-15 00:08 -------- d-------- C:\Program Files\Internet Explorer
2006-11-15 00:06 -------- d-------- C:\Program Files\Mozilla Thunderbird
2006-11-14 23:49 -------- d---s---- C:\Program Files\Xfire
2006-11-11 20:16 -------- d-------- C:\Program Files\mIRC
2006-11-10 18:14 -------- d-------- C:\Program Files\FlashFXP
2006-11-10 18:09 -------- d-------- C:\Documents and Settings\Simon Dhoore\Application Data\Azureus
2006-11-09 17:50 -------- d-------- C:\Program Files\Roguescanfix
2006-11-08 23:54 -------- d-------- C:\Program Files\PowerStrip
2006-11-08 23:54 -------- d-------- C:\Program Files\NetDrive
2006-11-08 23:49 -------- d-------- C:\Program Files\Microsoft IntelliType Pro
2006-11-08 23:48 -------- d-------- C:\Program Files\ISP Monitor
2006-11-08 22:12 -------- d-------- C:\Program Files\Lavasoft
2006-11-08 22:09 -------- d-------- C:\Program Files\Grisoft
2006-11-08 21:42 -------- d-------- C:\Documents and Settings\Simon Dhoore\Application Data\PC Tools
2006-11-08 21:21 -------- d-------- C:\Program Files\Common Files
2006-11-08 19:12 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-11-08 17:31 -------- d-------- C:\Program Files\Bradbury
2006-11-08 14:46 -------- d-------- C:\Program Files\totalcmd
2006-11-07 23:34 -------- d-------- C:\Program Files\Winamp
2006-11-07 23:22 -------- d-------- C:\Documents and Settings\Simon Dhoore\Application Data\Winamp
2006-11-07 22:56 -------- d-------- C:\Program Files\EditPlus 2
2006-11-07 22:54 -------- d-------- C:\Documents and Settings\Simon Dhoore\Application Data\Bradsoft.com
2006-11-06 23:46 -------- d-------- C:\Program Files\Windows Media Player
2006-11-06 23:44 -------- d-------- C:\Program Files\Outlook Express
2006-11-06 23:44 -------- d-------- C:\Program Files\Common Files\System
2006-11-06 23:43 -------- d-------- C:\Program Files\MSXML 4.0
2006-11-06 23:22 -------- d-------- C:\Program Files\Hitman Pro
2006-11-06 21:32 -------- d-------- C:\Documents and Settings\Simon Dhoore\Application Data\Lavasoft
2006-11-06 21:03 -------- d-------- C:\Program Files\Registry Mechanic
2006-11-05 21:41 -------- d-------- C:\Documents and Settings\Simon Dhoore\Application Data\AVG7
2006-11-05 21:39 -------- d---s---- C:\Documents and Settings\Simon Dhoore\Application Data\Microsoft
2006-11-04 03:28 737280 --a------ C:\WINDOWS\iun6002.exe
2006-11-03 19:53 -------- d-------- C:\Program Files\Java
2006-11-03 19:53 -------- d-------- C:\Program Files\Common Files\Java
2006-11-03 15:13 -------- d-------- C:\Program Files\Microsoft SQL Server
2006-11-03 15:12 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-11-03 15:11 -------- d-------- C:\Program Files\Microsoft.NET
2006-11-03 15:10 -------- d-------- C:\Program Files\Microsoft SQL Server 2005 Mobile Edition
2006-11-03 15:10 -------- d-------- C:\Program Files\Microsoft Device Emulator
2006-11-03 15:06 -------- d-------- C:\Program Files\MSBuild
2006-11-03 15:06 -------- d-------- C:\Program Files\Microsoft Visual Studio 8
2006-11-03 15:06 -------- d-------- C:\Program Files\HTML Help Workshop
2006-11-03 15:05 -------- d-------- C:\Program Files\Common Files\Merge Modules
2006-11-03 15:02 -------- d-------- C:\Program Files\Common Files\Business Objects
2006-11-03 15:01 -------- d-------- C:\Program Files\CE Remote Tools
2006-11-03 15:00 -------- d-------- C:\Program Files\Microsoft Office
2006-11-03 14:39 -------- d-------- C:\Program Files\MozBackup
2006-11-03 14:39 -------- d-------- C:\Program Files\iPod
2006-11-02 22:47 -------- d-------- C:\Program Files\RealVNC
2006-11-02 22:44 -------- d-------- C:\Program Files\MSN Messenger
2006-11-02 22:44 -------- d-------- C:\Program Files\Messenger Plus!
2006-10-25 19:34 12464 --a------ C:\WINDOWS\system32\drivers\secdrv.sys
2006-10-21 12:49 -------- d-------- C:\Program Files\WowReader
2006-10-13 13:41 65536 --a------ C:\WINDOWS\system32\nwwks.dll
2006-10-13 13:41 64000 --a------ C:\WINDOWS\system32\nwapi32.dll
2006-10-13 13:41 144384 --a------ C:\WINDOWS\system32\nwprovau.dll
2006-10-13 11:23 163584 --a------ C:\WINDOWS\system32\drivers\nwrdr.sys
2006-10-03 01:15 -------- d-------- C:\Program Files\DVD Decrypter
2006-09-25 18:21 -------- d-------- C:\Program Files\Ventrilo
2006-09-25 18:21 -------- d-------- C:\Program Files\Common Files\Wise Installation Wizard
2006-09-13 06:07 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-09-03 16:50 73 --a------ C:\WINDOWS\system32\ssprs.dll
2006-09-03 16:50 205 --a------ C:\WINDOWS\system32\lsprst7.dll
2006-09-03 16:50 1025 --a------ C:\WINDOWS\system32\sysprs7.dll
2006-09-03 16:50 1025 --a------ C:\WINDOWS\system32\clauth2.dll
2006-09-03 16:50 1025 --a------ C:\WINDOWS\system32\clauth1.dll
2006-09-01 14:32 82432 --a------ C:\WINDOWS\system32\msxml4r.dll
2006-08-25 16:51 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-25 04:47 115880 --------- C:\WINDOWS\system32\pxinsi64.exe
2006-08-21 13:28 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 10:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-17 13:30 727040 --a------ C:\WINDOWS\system32\lsasrv.dll
2006-08-17 13:30 132096 --a------ C:\WINDOWS\system32\wkssvc.dll
2006-08-16 12:59 100352 --a------ C:\WINDOWS\system32\6to4svc.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Powerstrip"="\"C:\\Program Files\\PowerStrip\\pstrip.exe\""
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Steam"=""
"ISPMonitor"="C:\\Program Files\\ISP Monitor\\isp.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"type32"="\"C:\\Program Files\\Microsoft IntelliType Pro\\type32.exe\""
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE"
"CTSysVol"="\"C:\\Program Files\\Creative\\SBAudigy2ZS\\Surround Mixer\\CTSysVol.exe\" /r"
"CTHelper"=":CTHELPER.EXE"
"SBDrvDet"=":C:\\Program Files\\Creative\\SB Drive Det\\SBDrvDet.exe /r"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"PowerStrip"="\"c:\\program files\\powerstrip\\pstrip.exe\""
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"AVG7_CC"="\"C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe\" /STARTUP"
"CTDrive"="rundll32.exe C:\\WINDOWS\\system32\\drvpuw.dll,startup"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Mijn huidige introductiepagina"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e4,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,4b,00,00,00,00,00,00,00,b5,04,00,00,e4,03,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,4b,00,00,00,00,00,00,00,b5,04,00,00,e4,03,\
00,00,01,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Preloader van browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Cache-daemon voor onderdeelcategorieën"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"=dword:00000000
"NoColorChoice"=dword:00000000
"NoSizeChoice"=dword:00000000
"NoDispBackgroundPage"=dword:00000000
"NoDispScrSavPage"=dword:00000000
"NoDispCPL"=dword:00000000
"NoVisualStyleChoice"=dword:00000000
"NoDispSettingsPage"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoActiveDesktop"=dword:00000000
"NoSaveSettings"=dword:00000000
"ClassicShell"=dword:00000000
"NoThemesTab"=dword:00000000
"ForceActiveDesktopOn"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"DisableTaskMgr"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktopChanges"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wincnw32

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

Completion time: 06-11-15 14:02:21.23
C:\ComboFix.txt ... 06-11-15 14:02
C:\ComboFix2.txt ... 06-11-08 21:21

Jurgenv1

Legacy Member
Download VundoFix.exe naar je bureaublad.
  • Dubbelklik VundoFix.exe om het te starten.
  • Klik de Scan for Vundo knop.
  • Eenmaal gedaan met scannen, klik de Remove Vundo knop.
  • Je zal een melding krijgen of je de bestanden wilt laten verwijderen, klik YES
  • Nadat je Yes hebt geklikt, zullen de icoontjes op je bureaublad verdwijnen tijdens het verwijderen van Vundo.
  • Wanneer voltooid zal je de melding krijgen dat het je PC zal afsluiten, klik OK.
  • Start je pc terug opnieuw op.
  • Post de inhoud van C:\vundofix.txt en een nieuwe hijackthislog in je volgende post.
Note: Het is mogelijk dat vundofix een bestand gevonden heeft dat niet kon verwijderd worden.
In dit geval zal VundoFix na het heropstarten van je pc nog eens opstarten. Dan moet je de instructies van hierboven nog eens uitvoeren vanaf: "Click the Scan for Vundo."

Jurgenv1

Legacy Member
* Download en unzip Killbox naar je bureaublad.
Klik op killbox.exe.
Selecteer de optie "Delete on reboot".
In het veld "Full Path of File to Delete" kopieer en plak je het volgende:

C:\WINDOWS\system32\drvpuw.dll

Klik op de knop: single file (!Belangrijk!)

Daarna, Klik op de rode cirkel met het wit kruisje erin.
Killbox zal zeggen dat deze file zal verwijderd worden on reboot.. vraagt om nu te rebooten. Klik YES.

Je pc moet nu rebooten.

* Post dan een nieuw hijackthis logje hier met een nieuwe log van combofix.

Api3

Legacy Member
done:

HIJACKTHIS:
Logfile of HijackThis v1.99.1
Scan saved at 19:22:52, on 16-11-2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\PowerStrip\pstrip.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ISP Monitor\isp.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\wamp\wampserver.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
c:\wamp\apache2\bin\Apache.exe
C:\Program Files\NetDrive\wdService.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\wamp\apache2\bin\Apache.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
D:\Mijn Documenten\Downloads\Programmas\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [CTSysVol] "C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" /r
O4 - HKLM\..\Run: [CTHelper] :CTHELPER.EXE
O4 - HKLM\..\Run: [SBDrvDet] :C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [PowerStrip] "c:\program files\powerstrip\pstrip.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvpuw.dll,startup
O4 - HKCU\..\Run: [Powerstrip] "C:\Program Files\PowerStrip\pstrip.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISPMonitor] C:\Program Files\ISP Monitor\isp.exe
O4 - Startup: WampServer.lnk = C:\wamp\wampserver.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1153585676218
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15023/CTPID.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: wincnw32 - wincnw32.dll (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing)
O23 - Service: wampapache - Unknown owner - c:\wamp\apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: wampmysqld - Unknown owner - c:\wamp\mysql\bin\mysqld-nt.exe
O23 - Service: WebDrive Service (WebDriveService) - Unknown owner - C:\Program Files\NetDrive\wdService.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)

COMBOFIX:
Simon Dhoore - 06-11-16 19:23:24,48 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\Simon Dhoore\Bureaublad"

((((((((((((((((((((((((((((((( Files Created from 2006-10-16 to 2006-11-16 ))))))))))))))))))))))))))))))))))


2006-11-12 23:42 98,304 --a------ C:\WINDOWS\system32CmdLineExt.dll
2006-11-08 22:09 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-11-08 19:28 684,032 --a------ C:\WINDOWS\system32\libeay32.dll
2006-11-08 19:28 155,648 --a------ C:\WINDOWS\system32\ssleay32.dll
2006-11-08 17:31 72,192 --a------ C:\WINDOWS\unlite3.exe
2006-11-06 23:44 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2006-11-05 21:39 816,672 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-11-05 21:39 4,960 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys
2006-11-05 21:39 4,224 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-11-05 21:39 3,968 --a------ C:\WINDOWS\system32\drivers\avgclean.sys
2006-11-05 21:39 28,416 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-11-05 21:39 18,240 --a------ C:\WINDOWS\system32\drivers\avgmfx86.sys
2006-11-04 20:25 1,321,744 --a------ C:\WINDOWS\system32\msxml6.dll
2006-11-04 14:14 1,245,696 --a------ C:\WINDOWS\system32\msxml4.dll
2006-11-03 14:08 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2006-10-31 22:43 233,984 --a------ C:\WINDOWS\system32\gc.dll


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-11-16 19:22 -------- d-------- C:\Program Files\Mozilla Firefox
2006-11-15 00:13 -------- d-------- C:\Documents and Settings\Simon Dhoore\Application Data\Xfire
2006-11-15 00:08 -------- d-------- C:\Program Files\Internet Explorer
2006-11-15 00:06 -------- d-------- C:\Program Files\Mozilla Thunderbird
2006-11-14 23:49 -------- d---s---- C:\Program Files\Xfire
2006-11-11 20:16 -------- d-------- C:\Program Files\mIRC
2006-11-10 18:14 -------- d-------- C:\Program Files\FlashFXP
2006-11-10 18:09 -------- d-------- C:\Documents and Settings\Simon Dhoore\Application Data\Azureus
2006-11-09 17:50 -------- d-------- C:\Program Files\Roguescanfix
2006-11-08 23:54 -------- d-------- C:\Program Files\PowerStrip
2006-11-08 23:54 -------- d-------- C:\Program Files\NetDrive
2006-11-08 23:49 -------- d-------- C:\Program Files\Microsoft IntelliType Pro
2006-11-08 23:48 -------- d-------- C:\Program Files\ISP Monitor
2006-11-08 22:12 -------- d-------- C:\Program Files\Lavasoft
2006-11-08 22:09 -------- d-------- C:\Program Files\Grisoft
2006-11-08 21:42 -------- d-------- C:\Documents and Settings\Simon Dhoore\Application Data\PC Tools
2006-11-08 21:21 -------- d-------- C:\Program Files\Common Files
2006-11-08 19:12 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-11-08 17:31 -------- d-------- C:\Program Files\Bradbury
2006-11-08 14:46 -------- d-------- C:\Program Files\totalcmd
2006-11-07 23:34 -------- d-------- C:\Program Files\Winamp
2006-11-07 23:22 -------- d-------- C:\Documents and Settings\Simon Dhoore\Application Data\Winamp
2006-11-07 22:56 -------- d-------- C:\Program Files\EditPlus 2
2006-11-07 22:54 -------- d-------- C:\Documents and Settings\Simon Dhoore\Application Data\Bradsoft.com
2006-11-06 23:46 -------- d-------- C:\Program Files\Windows Media Player
2006-11-06 23:44 -------- d-------- C:\Program Files\Outlook Express
2006-11-06 23:44 -------- d-------- C:\Program Files\Common Files\System
2006-11-06 23:43 -------- d-------- C:\Program Files\MSXML 4.0
2006-11-06 23:22 -------- d-------- C:\Program Files\Hitman Pro
2006-11-06 21:32 -------- d-------- C:\Documents and Settings\Simon Dhoore\Application Data\Lavasoft
2006-11-06 21:03 -------- d-------- C:\Program Files\Registry Mechanic
2006-11-05 21:41 -------- d-------- C:\Documents and Settings\Simon Dhoore\Application Data\AVG7
2006-11-05 21:39 -------- d---s---- C:\Documents and Settings\Simon Dhoore\Application Data\Microsoft
2006-11-04 03:28 737280 --a------ C:\WINDOWS\iun6002.exe
2006-11-03 19:53 -------- d-------- C:\Program Files\Java
2006-11-03 19:53 -------- d-------- C:\Program Files\Common Files\Java
2006-11-03 15:13 -------- d-------- C:\Program Files\Microsoft SQL Server
2006-11-03 15:12 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-11-03 15:11 -------- d-------- C:\Program Files\Microsoft.NET
2006-11-03 15:10 -------- d-------- C:\Program Files\Microsoft SQL Server 2005 Mobile Edition
2006-11-03 15:10 -------- d-------- C:\Program Files\Microsoft Device Emulator
2006-11-03 15:06 -------- d-------- C:\Program Files\MSBuild
2006-11-03 15:06 -------- d-------- C:\Program Files\Microsoft Visual Studio 8
2006-11-03 15:06 -------- d-------- C:\Program Files\HTML Help Workshop
2006-11-03 15:05 -------- d-------- C:\Program Files\Common Files\Merge Modules
2006-11-03 15:02 -------- d-------- C:\Program Files\Common Files\Business Objects
2006-11-03 15:01 -------- d-------- C:\Program Files\CE Remote Tools
2006-11-03 15:00 -------- d-------- C:\Program Files\Microsoft Office
2006-11-03 14:39 -------- d-------- C:\Program Files\MozBackup
2006-11-03 14:39 -------- d-------- C:\Program Files\iPod
2006-11-02 22:47 -------- d-------- C:\Program Files\RealVNC
2006-11-02 22:44 -------- d-------- C:\Program Files\MSN Messenger
2006-11-02 22:44 -------- d-------- C:\Program Files\Messenger Plus!
2006-10-25 19:34 12464 --a------ C:\WINDOWS\system32\drivers\secdrv.sys
2006-10-21 12:49 -------- d-------- C:\Program Files\WowReader
2006-10-13 13:41 65536 --a------ C:\WINDOWS\system32\nwwks.dll
2006-10-13 13:41 64000 --a------ C:\WINDOWS\system32\nwapi32.dll
2006-10-13 13:41 144384 --a------ C:\WINDOWS\system32\nwprovau.dll
2006-10-13 11:23 163584 --a------ C:\WINDOWS\system32\drivers\nwrdr.sys
2006-10-03 01:15 -------- d-------- C:\Program Files\DVD Decrypter
2006-09-25 18:21 -------- d-------- C:\Program Files\Ventrilo
2006-09-25 18:21 -------- d-------- C:\Program Files\Common Files\Wise Installation Wizard
2006-09-13 06:07 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
2006-09-03 16:50 73 --a------ C:\WINDOWS\system32\ssprs.dll
2006-09-03 16:50 205 --a------ C:\WINDOWS\system32\lsprst7.dll
2006-09-03 16:50 1025 --a------ C:\WINDOWS\system32\sysprs7.dll
2006-09-03 16:50 1025 --a------ C:\WINDOWS\system32\clauth2.dll
2006-09-03 16:50 1025 --a------ C:\WINDOWS\system32\clauth1.dll
2006-09-01 14:32 82432 --a------ C:\WINDOWS\system32\msxml4r.dll
2006-08-25 16:51 617472 --a------ C:\WINDOWS\system32\comctl32.dll
2006-08-25 04:47 115880 --------- C:\WINDOWS\system32\pxinsi64.exe
2006-08-21 13:28 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 10:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-08-17 13:30 727040 --a------ C:\WINDOWS\system32\lsasrv.dll
2006-08-17 13:30 132096 --a------ C:\WINDOWS\system32\wkssvc.dll
2006-08-16 12:59 100352 --a------ C:\WINDOWS\system32\6to4svc.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Powerstrip"="\"C:\\Program Files\\PowerStrip\\pstrip.exe\""
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Steam"=""
"ISPMonitor"="C:\\Program Files\\ISP Monitor\\isp.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"type32"="\"C:\\Program Files\\Microsoft IntelliType Pro\\type32.exe\""
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE"
"CTSysVol"="\"C:\\Program Files\\Creative\\SBAudigy2ZS\\Surround Mixer\\CTSysVol.exe\" /r"
"CTHelper"=":CTHELPER.EXE"
"SBDrvDet"=":C:\\Program Files\\Creative\\SB Drive Det\\SBDrvDet.exe /r"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"PowerStrip"="\"c:\\program files\\powerstrip\\pstrip.exe\""
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"AVG7_CC"="\"C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe\" /STARTUP"
"CTDrive"="rundll32.exe C:\\WINDOWS\\system32\\drvpuw.dll,startup"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Mijn huidige introductiepagina"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e4,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,4b,00,00,00,00,00,00,00,b5,04,00,00,e4,03,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,4b,00,00,00,00,00,00,00,b5,04,00,00,e4,03,\
00,00,01,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Preloader van browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Cache-daemon voor onderdeelcategorieën"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispAppearancePage"=dword:00000000
"NoColorChoice"=dword:00000000
"NoSizeChoice"=dword:00000000
"NoDispBackgroundPage"=dword:00000000
"NoDispScrSavPage"=dword:00000000
"NoDispCPL"=dword:00000000
"NoVisualStyleChoice"=dword:00000000
"NoDispSettingsPage"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"NoActiveDesktop"=dword:00000000
"NoSaveSettings"=dword:00000000
"ClassicShell"=dword:00000000
"NoThemesTab"=dword:00000000
"ForceActiveDesktopOn"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"DisableTaskMgr"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktopChanges"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wincnw32

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

Completion time: 06-11-16 19:24:08.92
C:\ComboFix.txt ... 06-11-16 19:24
C:\ComboFix2.txt ... 06-11-15 14:02
C:\ComboFix3.txt ... 06-11-08 21:21


da popup start nu niet meer op maar ik krijg bij het opstarten wel een fout van kan drvpuw.dll niet laden..

Jurgenv1

Legacy Member
* Fix de volgende regel in hijackthis:

O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvpuw.dll,startup

* Herstart je pc en kijk of het gebeterd is. :)
Het archief is een bevroren moment uit een vorige versie van dit forum, met andere regels en andere bazen. Deze posts weerspiegelen op geen enkele manier onze huidige ideeën, waarden of wereldbeelden en zijn op sommige plaatsen gecensureerd wegens ontoelaatbaar. Veel zijn in een andere tijdsgeest gemaakt, al dan niet ironisch - zoals in het ironische subforum Off-Topic - en zouden op dit moment niet meer gepost (mogen) worden. Toch bieden we dit archief nog graag aan als informatiedatabank en naslagwerk. Lees er hier meer over of start een gesprek met anderen.
Terug
Bovenaan