New Malware

  • Hennie

    wil iemand naar mijn hijackfiles kijken ik krijg steeds bij Macaffee dat ik een trojan heb

    hij kan hem niet verwijderen en ook het bestand trust.exe ik heb adware er al overheen gehaald

    alvast bedankt

    Logfile of HijackThis v1.99.1

    Scan saved at 15:21:11, on 24-10-2005

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\LEXBCES.EXE

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\LEXPPS.EXE

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\system32\hkcmd.exe

    C:\WINDOWS\system32\igfxpers.exe

    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

    C:\WINDOWS\stsystra.exe

    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

    C:\Program Files\Dell\Media Experience\DMXLauncher.exe

    C:\WINDOWS\system32\dla\tfswctrl.exe

    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

    C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe

    C:\WINDOWS\system32\rundll32.exe

    C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe

    C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe

    C:\PROGRA~1\mcafee.com\agent\mcagent.exe

    C:\PROGRA~1\mcafee.com\vso\mcvsescn.exe

    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

    C:\Program Files\MSN Messenger\MsnMsgr.Exe

    c:\progra~1\intern~1\iexplore.exe

    c:\progra~1\mcafee.com\vso\mcvsftsn.exe

    C:\Program Files\Messenger\msmsgs.exe

    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    c:\PROGRA~1\mcafee.com\vso\mcshield.exe

    C:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe

    C:\Documents and Settings\Hennie van der Woude\Bureaublad\downloads\hijackthis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.nl

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wanadoo.nl

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.wanadoo.nl/

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer aangeboden door Wanadoo Cable v2.0c NL

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {38FD5796-4D30-BCCC-D932-AABE4AB1BC80} - C:\DOCUME~1\HENNIE~1\APPLIC~1\CASHAC~1\Draw Dent.exe

    O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet6_90.dll

    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll

    O4 - HKLM\..\Run: C:\WINDOWS\system32\igfxtray.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\hkcmd.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\igfxpers.exe

    O4 - HKLM\..\Run: C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

    O4 - HKLM\..\Run: stsystra.exe

    O4 - HKLM\..\Run: “C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe”

    O4 - HKLM\..\Run: C:\Program Files\Dell\Media Experience\DMXLauncher.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\dla\tfswctrl.exe

    O4 - HKLM\..\Run: C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe” -start

    O4 - HKLM\..\Run: “C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe”

    O4 - HKLM\..\Run: rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s

    O4 - HKLM\..\Run: C:\Documents and Settings\All Users\Application Data\SKIP DOES PLUS FRAG\Save four.exe

    O4 - HKLM\..\Run: “C:\Program Files\BearShare\BearShare.exe” /pause

    O4 - HKLM\..\Run: “c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe” /checktask

    O4 - HKLM\..\Run: “c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe”

    O4 - HKLM\..\Run: c:\PROGRA~1\mcafee.com\agent\mcagent.exe

    O4 - HKLM\..\Run: C:\PROGRA~1\mcafee.com\agent\McUpdate.exe

    O4 - HKLM\..\Run: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

    O4 - HKCU\..\Run: “C:\Program Files\MSN Messenger\MsnMsgr.Exe” /background

    O4 - HKCU\..\Run: C:\DOCUME~1\HENNIE~1\APPLIC~1\KINDPI~1\trust eggs.exe

    O4 - HKCU\..\Run: “C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe” -n=200

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll

    O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra button: Website - {8F7E9332-1E21-450F-ADDA-7DC90E0E152D} - http://internet.casema.net/helpdesk/ (file missing) (HKCU)

    O9 - Extra button: Help - {93493E23-40B0-44F2-9713-6AD8EC95784C} - file:///C|/Program Files/Wanadoo Cable/Help/index.html (file missing) (HKCU)

    O10 - Hijacked Internet access by New.Net

    O10 - Hijacked Internet access by New.Net

    O10 - Hijacked Internet access by New.Net

    O10 - Hijacked Internet access by New.Net

    O10 - Hijacked Internet access by New.Net

    O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.nl

    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/nl/4,0,0,83/mcinsctl.cab

    O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://us-download.mcafee.com/products/protected/mvt/mvt.cab

    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab

    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/nl/1,0,0,20/mcgdmgr.cab

    O17 - HKLM\System\CCS\Services\Tcpip\..\{34313E57-394A-40EC-ABE6-329E6CE79F23}: NameServer = 194.134.5.5 194.134.5.55

    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - “C:\PROGRA~1\MSNMES~1\msgrapp.dll” (file missing)

    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll

    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

    O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe

    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe

    O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

  • killerbee

    Plaats daarna ff een nieuw log van HJT.

    suc6

  • Hennie

    Logfile of HijackThis v1.99.1

    Scan saved at 17:21:29, on 24-10-2005

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\LEXBCES.EXE

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\LEXPPS.EXE

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\system32\hkcmd.exe

    C:\WINDOWS\system32\igfxpers.exe

    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

    C:\WINDOWS\stsystra.exe

    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

    C:\Program Files\Dell\Media Experience\DMXLauncher.exe

    C:\WINDOWS\system32\dla\tfswctrl.exe

    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

    C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe

    C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe

    C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe

    C:\PROGRA~1\mcafee.com\vso\mcvsescn.exe

    c:\program files\mcafee.com\agent\mcagent.exe

    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

    C:\Program Files\MSN Messenger\MsnMsgr.Exe

    c:\progra~1\intern~1\iexplore.exe

    c:\progra~1\mcafee.com\vso\mcvsftsn.exe

    C:\Program Files\Messenger\msmsgs.exe

    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    c:\PROGRA~1\mcafee.com\vso\mcshield.exe

    C:\Documents and Settings\Hennie van der Woude\Bureaublad\games\hijackthis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.nl

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.wanadoo.nl

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.wanadoo.nl/

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer aangeboden door Wanadoo Cable v2.0c NL

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {38FD5796-4D30-BCCC-D932-AABE4AB1BC80} - C:\DOCUME~1\HENNIE~1\APPLIC~1\CASHAC~1\Draw Dent.exe

    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll

    O4 - HKLM\..\Run: C:\WINDOWS\system32\igfxtray.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\hkcmd.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\igfxpers.exe

    O4 - HKLM\..\Run: C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

    O4 - HKLM\..\Run: stsystra.exe

    O4 - HKLM\..\Run: “C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe”

    O4 - HKLM\..\Run: C:\Program Files\Dell\Media Experience\DMXLauncher.exe

    O4 - HKLM\..\Run: C:\WINDOWS\system32\dla\tfswctrl.exe

    O4 - HKLM\..\Run: C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe” -start

    O4 - HKLM\..\Run: “C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe”

    O4 - HKLM\..\Run: C:\Documents and Settings\All Users\Application Data\SKIP DOES PLUS FRAG\Save four.exe

    O4 - HKLM\..\Run: “C:\Program Files\BearShare\BearShare.exe” /pause

    O4 - HKLM\..\Run: “c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe” /checktask

    O4 - HKLM\..\Run: “c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe”

    O4 - HKLM\..\Run: c:\PROGRA~1\mcafee.com\agent\mcagent.exe

    O4 - HKLM\..\Run: C:\PROGRA~1\mcafee.com\agent\mcupdate.exe

    O4 - HKLM\..\Run: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

    O4 - HKCU\..\Run: “C:\Program Files\MSN Messenger\MsnMsgr.Exe” /background

    O4 - HKCU\..\Run: “C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe” -n=200

    O4 - HKCU\..\Run: C:\DOCUME~1\HENNIE~1\APPLIC~1\KINDPI~1\trust eggs.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll

    O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra button: Website - {8F7E9332-1E21-450F-ADDA-7DC90E0E152D} - http://internet.casema.net/helpdesk/ (file missing) (HKCU)

    O9 - Extra button: Help - {93493E23-40B0-44F2-9713-6AD8EC95784C} - file:///C|/Program Files/Wanadoo Cable/Help/index.html (file missing) (HKCU)

    O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.nl

    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/nl/4,0,0,83/mcinsctl.cab

    O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://us-download.mcafee.com/products/protected/mvt/mvt.cab

    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab

    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/nl/1,0,0,20/mcgdmgr.cab

    O17 - HKLM\System\CCS\Services\Tcpip\..\{34313E57-394A-40EC-ABE6-329E6CE79F23}: NameServer = 194.134.5.5 194.134.5.55

    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - “C:\PROGRA~1\MSNMES~1\msgrapp.dll” (file missing)

    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll

    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

    O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe

    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe

    O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

  • Hennie

    het is gelukt om hem weg te krijgen ik heb hem in config stop gezet automatisch opstarten vinkje weggehaald viruscanner erover, daarna nog een keer en nu is hij schoon

  • Erik

    Weet je dat zeker :?

  • Hennie

    ik heb daarna nog gescand en hij geeft ook de waarschuwing niet meer dus ik hoop het wel.

  • Erik

    Mischien kan je nog een vers HJT logje plaatsen :?

  • killerbee

    Download de trialversie van Ewido Security Suite

    Installeer het programma en controleer of er updates beschikbaar zijn.

    Installleer deze ook.

    Laat Ewido nog niet scannen.

    Start je computer op in VEILIGE MODUS

    *BELANGRIJK* Zorg dat de verborgen bestanden en systeembestanden worden weergegeven.

    (klik voor hulp)

    Start HJT en doe een systemscan only en vink de volgende regels aan en klik op fix checked

    02 - BHO: (no name) - {38FD5796-4D30-BCCC-D932-AABE4AB1BC80} - C:\DOCUME~1\HENNIE~1\APPLIC~1\CASHAC~1\Draw Dent.exe

    O4 - HKLM\..\Run: C:\Documents and Settings\All Users\Application Data\SKIP DOES PLUS FRAG\Save four.exe

    O4 - HKCU\..\Run: C:\DOCUME~1\HENNIE~1\APPLIC~1\KINDPI~1\trust eggs.exe

    O9 - Extra button: Website - {8F7E9332-1E21-450F-ADDA-7DC90E0E152D} - internet.casema.net/helpdesk/ (file missing) (HKCU)

    O9 - Extra button: Help - {93493E23-40B0-44F2-9713-6AD8EC95784C} - file:///C|/Program Files/Wanadoo Cable/Help/index.html (file missing) (HKCU)

    Verwijder tevens de volgende bestanden:

    C:\DOCUME~1\HENNIE~1\APPLIC~1\CASHAC~1\Draw Dent.exe

    verwijder de volgende mappen:

    C:\Documents and Settings\All Users\Application Data\SKIP DOES PLUS FRAG

    C:\DOCUME~1\HENNIE~1\APPLIC~1\KINDPI~1

    start Ewido

    Open Ewido Security Suite

    · klik op Scanner

    · Klik op complete system scan

    · Laat het programma je pc scannen

    Tijdens de scan zal je gevraagd worden of je gevonden bestanden wil verwijderen. Klik dan op OK

    Als de scan beëindigd is, zal je een knop zien Bewaar rapport

    · Klik op Bewaar rapport

    · Sla het rapport op op je bureaublad

    · Sluit Ewido af

    Start daarna je pc opnieuw op in normale modus en plaats ff een nieuw HJT log en het log van Ewido.