Archief - HijackThis log Sabe

Het archief is een bevroren moment uit een vorige versie van dit forum, met andere regels en andere bazen. Deze posts weerspiegelen op geen enkele manier onze huidige ideeën, waarden of wereldbeelden en zijn op sommige plaatsen gecensureerd wegens ontoelaatbaar. Veel zijn in een andere tijdsgeest gemaakt, al dan niet ironisch - zoals in het ironische subforum Off-Topic - en zouden op dit moment niet meer gepost (mogen) worden. Toch bieden we dit archief nog graag aan als informatiedatabank en naslagwerk. Lees er hier meer over of start een gesprek met anderen.

Sabe

Legacy Member
Logfile of HijackThis v1.99.1
Scan saved at 22:26:45, on 5/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Winamp\Winamp.exe
C:\Program Files\uTorrent\utorrent.exe
C:\Program Files\iVideoCodec\isamini.exe
C:\Program Files\iVideoCodec\isamonitor.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\SPYWAREfighter\spfprc.exe
D:\download\Windows-KB890830-V1.21.exe
c:\a36f65400cf9f0c697f87fb1\mrtstub.exe
C:\WINDOWS\system32\MRT.exe
C:\Program Files\MalwareWiper\MalwareWiper.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\download\HijackThis.exe
C:\Program Files\iVideoCodec\pmsngr.exe
C:\Program Files\iVideoCodec\pmmon.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: ScriptInocUI Class - - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {274c0420-ebe0-4f1d-b473-edd1aa9b85dd} - C:\Program Files\iVideoCodec\isaddon.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{3425EAC7-0640-2067-0206-060509060020}\MyToolBar.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FLASHF~2\IEFlash.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{3425EAC7-0640-2067-0206-060509060020}\MyToolBar.dll
O4 - HKLM\..\Run: [kis] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
O4 - HKLM\..\Run: [spywarefighterguard] C:\Program Files\SPYWAREfighter\spftray.exe
O4 - HKLM\..\Run: [MalwareWiper] C:\Program Files\MalwareWiper\MalwareWiper.exe /h
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0E3DDCF1-F16C-44BC-B374-86B4C2C0008A}: NameServer = 194.119.232.3,217.22.50.3
O17 - HKLM\System\CS1\Services\Tcpip\..\{0E3DDCF1-F16C-44BC-B374-86B4C2C0008A}: NameServer = 194.119.232.3,217.22.50.3
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: netdde.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winepi32 - C:\WINDOWS\SYSTEM32\winepi32.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: bonspells - {11853d5f-f894-4cc7-bbc3-fc7a9dcfd896} - C:\WINDOWS\system32\okkmtv.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: SPYWAREfighterRP - SpamFighter APS - C:\Program Files\SPYWAREfighter\spfprc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: wampapache - Unknown owner - c:\wamp\apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: wampmysqld - Unknown owner - c:\wamp\mysql\bin\mysqld-nt.exe

Jurgenv1

Legacy Member
* Je kan deze instructies best uitprinten of opslaan in een kladblokbestand, want straks zal je in veilige modus
moeten gaan werken, en dan is deze pagina niet beschikbaar (geen internet)

* Download smitRem.exe en sla dit op op het Bureaublad.
Dubbelklik op het bestand en pak het uit naar zijn eigen map op het Bureaublad.


* Download en installeer AVG Anti-Spyware.

  • Na de installatie, open AVG Anti-Spyware:
    * onder "Status", klik op Change state naast "Resident shield". (wijzig van active naar inactive!)
    * onder "Update", klik op de Start update knop.
    * onder "Scanner", tab "Settings":
    • - onder "How to act?", klik op "Recommended actions" en selecteer Quarantine. (ZEER BELANGRIJK!)
      * onder "Reports", selecteer Automatically generate report after every scan en verwijder het vinkje bij Only if threats were found
    Sluit AVG Anti-Spyware. Laat het nog niet scannen.

* Als je Adaware SE nog niet geïnstalleerd hebt, download, installeer en update het dan volgens de richtlijnen
die je kan vinden op: http://users.pandora.be/marcvn/spyware/1414188.htm
Download link van Ad-aware: http://www.lavasoftusa.com/products/ad-aware_se_personal.php

* Start je computer op in VEILIGE MODUS

* Open de smitrem-map op je bureaublad, en dubbelklik op RunThis.bat. Volg de aanwijzigingen op het scherm.
Je bureaublad en ikoontjes zullen even verdwijnen en daarna terug verschijnen, dit is normaal.
Wacht tot het tooltje zijn werk heeft gedaan en Disk Cleanup afgelopen is. Dit kan enige tijd duren, dus wees geduldig.

* Voer een volledige scan uit met Adaware en verwijder alles wat gevonden wordt.

* Start AVG Anti-Spyware.
  • * Klik op Scan en kies Complete System Scan.
    Na de scan; volg onderstaande instructies :
    BELANGRIJK : Klik niet op de "Save Scan Report" knop vooraleer je de "Apply all Actions" knop hebt aangeklikt !
    * Draag er zorg voor dat Set all elements to: op Quarantine staat (1),
    zoniet klik op de link en kies Quarantine in de popup menu. (2)
    (Dit geldt niet voor cookies, deze worden onveranderlijk gedelete !)
    * Onderaan het venster klik op de Apply all Actions knop. (3)
    ewidoscan.jpg

    * Wanneer je de melding krijgt 'All actions have been applied', klik je onderaan op de knop Save Report.

* Ga dan naar Start -> configuratiescherm -> vormgeving en thema's -> bureaublad ->bureaublad aanpassen -> Website -> haal het vinkje weg bij "Security Info" als het er nog staat.

* Herstart je computer in normale modus.

* Download ATF cleaner (by Atribune)

Dubbelklik op ATF cleaner om het programma te starten.
Op het tabblad "Main", plaats je een vinkje bij Select All.
Klik op de knop Empty Selected.

Gebruik je ook Firefox als browser:
Klik op tabblad "Firefox", plaats een vinkje bij Select All.
Wil je de door Firefox opgeslagen wachtwoorden behouden, dan klik je in het venster dat verschijnt op "No".
(dit verwijdert het vinkje bij "Firefox saved passwords")
Klik op de knop Empty Selected.

Gebruik je ook Opera als browser:
Klik op tabblad "Opera", plaats een vinkje bij Select All.
Wil je de door Opera opgeslagen wachtwoorden behouden, dan klik je in het venster dat verschijnt op "No".
Klik op de knop Empty Selected.
Ga naar het tabblad "Main" en klik op de knop Exit om het programma af te sluiten.

* Doe een online scan via Panda's online virus scan en bewaar het rapport dat je krijgt na het scannen

* Herstart je pc nogmaals en plaats dan een nieuw logje van Hijackthis, samen met het rapport van AVG Anti-Spyware 7.5 en Panda, Post de log van de smitRem tool, die je hier kan vinden: C:\smitfiles.txt.

KO

Legacy Member
Sabe zei:
die ivideocodec.exe doet ambetant ...

Die ivideocodec.exe is een Trojan...

Ik zie ook dat een van je malwarescanners, zelfs malware is....
Zie http://en.wikipedia.org/wiki/MalwareWipe.
Als je dit programma kan verwijderen via Configuratiescherm -> Software zeker doen.

Ook is het gebruik van 2 Virusscanners gelijktijdig af te raden, ik zie dat je zowel Norton en Kaspersky tegelijk hebt lopen.

Sabe

Legacy Member
Ok, merci ... kga het morgen avond eens allemaal toepassen

Jurgenv1

Legacy Member
=[KO]=;7811011 zei:
Die ivideocodec.exe is een Trojan...

Ik zie ook dat een van je malwarescanners, zelfs malware is....
Zie http://en.wikipedia.org/wiki/MalwareWipe.
Als je dit programma kan verwijderen via Configuratiescherm -> Software zeker doen.

Ook is het gebruik van 2 Virusscanners gelijktijdig af te raden, ik zie dat je zowel Norton en Kaspersky tegelijk hebt lopen.

En behoord tot de Zlob familie, ik weet er wel raad mee. ;)

Sabe

Legacy Member
LOG SMITREM:


smitRem © log file
version 3.2

by noahdfear


Microsoft Windows XP [versie 5.1.2600]
"IE"="6.0000"

Running from
C:\Documents and Settings\Sabe\Bureaublad\smitrem\smitRem

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pre-run SharedTask Export

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright(C) 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Preloader van browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Cache-daemon voor onderdeelcategorieën"
"{11853d5f-f894-4cc7-bbc3-fc7a9dcfd896}"="bonspells"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Appinitdll check ........ Thank you Grinler!

dumphive.exe (C)2000-2004 Markus Stephany
REGEDIT4

[Windows]
"AppInit_DLLs"=" netdde.dll,C:\\PROGRA~1\\KASPER~1\\KASPER~1.0\\adialhk.dll"
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

XP Firewall allowed access

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\mIRC\\mirc.exe"="C:\\Program Files\\mIRC\\mirc.exe:*:Enabled:mIRC"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
"C:\\Program Files\\FlashFXP\\FlashFXP.exe"="C:\\Program Files\\FlashFXP\\FlashFXP.exe:*:Enabled:FlashFXP v3"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\AVP.EXE"="C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\AVP.EXE:*:Enabled:Kaspersky Anti-Virus"
"C:\\Program Files\\SHOUTcast\\sc_serv.exe"="C:\\Program Files\\SHOUTcast\\sc_serv.exe:*:Enabled:sc_serv"
"C:\\Program Files\\Radio Toolbox\\rtb.exe"="C:\\Program Files\\Radio Toolbox\\rtb.exe:*:Enabled:Radio Toolbox"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Soulseek\\slsk.exe"="C:\\Program Files\\Soulseek\\slsk.exe:*:Enabled:SoulSeek"
"C:\\Program Files\\uTorrent\\utorrent.exe"="C:\\Program Files\\uTorrent\\utorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\Last.fm\\LastFM.exe"="C:\\Program Files\\Last.fm\\LastFM.exe:*:Enabled:LastFM"
"C:\\wamp\\Apache2\\bin\\Apache.exe"="C:\\wamp\\Apache2\\bin\\Apache.exe:*:Enabled:Apache HTTP Server"
"C:\\Program Files\\LeechFTP\\Leechftp.exe"="C:\\Program Files\\LeechFTP\\Leechftp.exe:*:Enabled:LeechFTP"
"C:\\Program Files\\Valve\\hl.exe"="C:\\Program Files\\Valve\\hl.exe:*:Enabled:Half-Life Launcher"
"D:\\Sid Meier's Railroads!\\RailRoads.exe"="D:\\Sid Meier's Railroads!\\RailRoads.exe:*:Enabled:Sid Meier's Railroads!"

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


checking for ShudderLTD key

ShudderLTD key not present!

checking for PSGuard.com key


PSGuard.com key not present!


checking for WinHound.com key


WinHound.com key not present!


checking for drsmartload2 key


drsmartload2 key not present!

spyaxe uninstaller NOT present
Winhound uninstaller NOT present
SpywareStrike uninstaller NOT present
AlfaCleaner uninstaller NOT present
SpyFalcon uninstaller NOT present
SpywareQuake uninstaller NOT present
SpywareSheriff uninstaller NOT present
Trust Cleaner uninstaller NOT present
SpyHeal uninstaller NOT present
VirusBurst uninstaller NOT present
BraveSentry uninstaller NOT present
AntiVermins uninstaller NOT present
VirusBursters uninstaller NOT present

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Existing Pre-run Files


~~~ Program Files ~~~

iVideoCodec
VirusBursters


~~~ Shortcuts ~~~

Online Security Guide.url
Online Security Guide.url
Security Troubleshooting.url
Security Troubleshooting.url


~~~ Favorites ~~~

Antivirus Test Online.url


~~~ system32 folder ~~~

okkmtv.dll
amcompat.tlb
nscompat.tlb


~~~ Icons in System32 ~~~

ot.ico


~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 [email protected]
Killing PID 1016 'explorer.exe'

Starting registry repairs

Registry repairs complete

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

SharedTask Export after registry fix

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright(C) 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Preloader van browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Cache-daemon voor onderdeelcategorieën"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Deleting files

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Remaining Post-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~



~~~ Wininet.dll ~~~

CLEAN! :)

Sabe

Legacy Member
AVG LOG:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 18:18:40 6/11/2006

+ Scan result:



HKLM\SOFTWARE\Classes\AppID\{70F17C8C-1744-41B6-9D07-575DB448DCC5} -> Adware.Generic : Cleaned with backup (quarantined).
C:\Program Files\Common Files\{3425EAC7-0640-2067-0206-060509060020}\mytoolbar.#ll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Common Files\{E425EAC7-0640-2067-0206-060509060020}\services.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP151\A0042467.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP151\A0042470.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP150\A0042439.exe -> Backdoor.Ciadoor.13 : Cleaned with backup (quarantined).
C:\Documents and Settings\Sabe\DoctorWeb\Quarantine\isamonito0.exe -> Downloader.Zlob.aus : Cleaned with backup (quarantined).
C:\Documents and Settings\Sabe\DoctorWeb\Quarantine\isamonitor.exe -> Downloader.Zlob.aus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP149\A0042358.dll -> Downloader.Zlob.aus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP149\A0042359.exe -> Downloader.Zlob.aus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP149\A0042360.exe -> Downloader.Zlob.aus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP150\A0042370.dll -> Downloader.Zlob.aus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP150\A0042371.exe -> Downloader.Zlob.aus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP150\A0042372.exe -> Downloader.Zlob.aus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP150\A0042394.dll -> Downloader.Zlob.aus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP150\A0042395.exe -> Downloader.Zlob.aus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP150\A0042396.exe -> Downloader.Zlob.aus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP151\A0042463.exe -> Downloader.Zlob.aus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP151\A0042468.dll -> Downloader.Zlob.aus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP151\A0042469.exe -> Downloader.Zlob.aus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP151\A0042485.exe -> Downloader.Zlob.aus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP151\A0042504.exe -> Downloader.Zlob.aus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP151\A0042505.exe -> Downloader.Zlob.aus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP151\A0042506.exe -> Downloader.Zlob.aus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP151\A0042507.exe -> Downloader.Zlob.aus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP151\A0042508.exe -> Downloader.Zlob.aus : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP151\A0042509.dll -> Downloader.Zlob.aus : Cleaned with backup (quarantined).
C:\Documents and Settings\Sabe\Local Settings\Temporary Internet Files\Content.IE5\8HCXYBST\antzom[1].exe -> Hijacker.Small.lr : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7BBF60E4-5755-40C6-9E8F-C2AD5922AE6E}\RP151\A0042515.dll -> Not-A-Virus.Hoax.Win32.Renos.gb : Cleaned with backup (quarantined).
:mozilla.103:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.104:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.105:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.106:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.254:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.756:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.757:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.261:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.827:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.309:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned.
:mozilla.760:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.17:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.385:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Estat : Cleaned.
:mozilla.117:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.118:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.119:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.120:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.121:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.170:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.176:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.177:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.178:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.179:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.227:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.918:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.919:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.920:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.469:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Ivwbox : Cleaned.
:mozilla.842:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.843:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.181:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.182:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.183:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.184:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.620:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.647:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.648:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.649:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.650:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.651:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.115:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.116:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.781:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.782:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.790:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.832:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.229:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.230:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.231:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.232:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.85:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.87:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.88:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.681:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.716:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.717:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.234:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.186:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.187:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.188:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.190:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.191:C:\Documents and Settings\Sabe\Application Data\Mozilla\Firefox\Profiles\zjbff462.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\WINDOWS\system32\winepi32.dll -> Trojan.Agent.vg : Cleaned with backup (quarantined).


::Report end

Sabe

Legacy Member
LOG HIJACKTHIS:

Logfile of HijackThis v1.99.1
Scan saved at 18:33:34, on 6/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\SPYWAREfighter\spfprc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
c:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\MsiExec.exe
C:\WINDOWS\system32\MsiExec.exe
D:\download\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: ScriptInocUI Class - - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FLASHF~2\IEFlash.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [spywarefighterguard] C:\Program Files\SPYWAREfighter\spftray.exe
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0E3DDCF1-F16C-44BC-B374-86B4C2C0008A}: NameServer = 194.119.232.3,217.22.50.3
O17 - HKLM\System\CS1\Services\Tcpip\..\{0E3DDCF1-F16C-44BC-B374-86B4C2C0008A}: NameServer = 194.119.232.3,217.22.50.3
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: netdde.dll,
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winepi32 - winepi32.dll (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: SPYWAREfighterRP - SpamFighter APS - C:\Program Files\SPYWAREfighter\spfprc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: wampapache - Unknown owner - c:\wamp\apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: wampmysqld - Unknown owner - c:\wamp\mysql\bin\mysqld-nt.exe

Sabe

Legacy Member
zitten nog aantal programmas tussen precies die ik moet weg krijgen:

norton, spywarefighter

Jurgenv1

Legacy Member
Probeer spyware fighter en Norton internet security dan te de-installeren via software, na het de-installeren moet je dit tooltje runnen om alle restjes te verwijderen:
http://service1.symantec.com/SUPPOR...9163ea0b7308d62d80256fe000519e78?OpenDocument

Installeer dan een gratis en goeie antivirus dat je pc niet zo erg vertraagd: AVG Free antivirus, antivir en Avast! Home edition zijn er een paar van. :) Voor Avast moet je wel nog eens gratis registreren voor je de antivirus kan gebruiken, zie hier voor meer info.

Daarna is het zeer belangrijk dat je de definitie's van je antivirus update, zodat je beschermd bent tegen de nieuwste bedreigingen.

Sabe

Legacy Member
spyware figher is gewist ....

norton kan ik niet wissen, ook niet via software ... ik moet me inloggen met het admin pass in norton zelf .. maar dit lukt niet en heb niet eens een pass...

alvast bedankt voor alle uitleg, het werkte perfect ;)

Jurgenv1

Legacy Member
Anders het tooltje om norton te verwijderen ook eens in veilige modus uitproberen en kijken of het daar werkt en nog restjes verwijderd. :)
Het archief is een bevroren moment uit een vorige versie van dit forum, met andere regels en andere bazen. Deze posts weerspiegelen op geen enkele manier onze huidige ideeën, waarden of wereldbeelden en zijn op sommige plaatsen gecensureerd wegens ontoelaatbaar. Veel zijn in een andere tijdsgeest gemaakt, al dan niet ironisch - zoals in het ironische subforum Off-Topic - en zouden op dit moment niet meer gepost (mogen) worden. Toch bieden we dit archief nog graag aan als informatiedatabank en naslagwerk. Lees er hier meer over of start een gesprek met anderen.
Terug
Bovenaan