nieuw logje

  • Miranda

    Sorry Paul, het duurde even voordat ik reageerde, maar ik heb een paar dagen niet op de pc kunnen werken. Mijn systeem vraag ook steeds of ik winfixer 2005 wil installeren, wat moet ik met deze vraag???

    groetjes Miranda

    Logfile of HijackThis v1.99.1

    Scan saved at 15:43:47, on 29-10-2005

    Platform: Windows XP SP1 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\PROGRA~1\INSTAN~1\INSTAN~1\IWCTRL.EXE

    C:\WINDOWS\System32\sstray.exe

    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

    C:\Program Files\CyberLink\PowerVCRII\Agent.exe

    C:\PROGRA~1\HARDWA~1\Keyboard\Ikeymain.exe

    C:\PROGRA~1\HARDWA~1\Mouse\Amoumain.exe

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    C:\PROGRA~1\SYMANT~1\VPTray.exe

    C:\Program Files\Browser MOUSE\mouse32a.exe

    C:\Program Files\QuickTime\qttask.exe

    C:\WINDOWS\System32\ctfmon.exe

    C:\WINDOWS\System32\Ati2evxx.exe

    C:\Program Files\Symantec AntiVirus\DefWatch.exe

    C:\Program Files\Symantec AntiVirus\Rtvscan.exe

    C:\Program Files\Internet Explorer\IEXPLORE.EXE

    C:\Program Files\hijackthis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    R3 - Default URLSearchHook is missing

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll

    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

    O4 - HKLM\..\Run: C:\PROGRA~1\INSTAN~1\INSTAN~1\IWCTRL.EXE

    O4 - HKLM\..\Run: sstray.exe /r

    O4 - HKLM\..\Run: Ati2mdxx.exe

    O4 - HKLM\..\Run: C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

    O4 - HKLM\..\Run: C:\Program Files\Microsoft Works\WkDetect.exe

    O4 - HKLM\..\Run: C:\Program Files\Microsoft Works\wkfud.exe

    O4 - HKLM\..\Run: C:\Program Files\Microsoft Works\WksSb.exe /AllUsers

    O4 - HKLM\..\Run: C:\Program Files\CyberLink\PowerVCRII\Agent.exe

    O4 - HKLM\..\Run: C:\Program Files\CyberLink\PowerVCRII\RemoteAgent.exe

    O4 - HKLM\..\Run: C:\PROGRA~1\HARDWA~1\Keyboard\Ikeymain.exe

    O4 - HKLM\..\Run: C:\PROGRA~1\HARDWA~1\Mouse\Amoumain.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Symantec Shared\ccApp.exe”

    O4 - HKLM\..\Run: C:\PROGRA~1\SYMANT~1\VPTray.exe

    O4 - HKLM\..\Run: C:\Program Files\Browser MOUSE\mouse32a.exe

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: C:\Program Files\ISTsvc\istsvc.exe

    O4 - HKCU\..\Run: C:\WINDOWS\System32\ctfmon.exe

    O4 - HKCU\..\Run: “C:\Program Files\Shareaza\Shareaza.exe” -tray

    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html

    O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html

    O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html

    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html

    O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html

    O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O9 - Extra ‘Tools’ menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab

    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab

    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab

    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - “C:\PROGRA~1\MSNMES~1\msgrapp.dll” (file missing)

    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll

    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe

    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe

    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

  • pablo

    hoi miranda,

    ik zie in je logje geen oorzaak voor je winfixer probleem :?:)

    die moet je trouwens niet installeren ;)

    start hijack,klik op scan en vink de volgende regel aan:

    O4 - HKLM\..\Run: C:\Program Files\ISTsvc\istsvc.exe

    sluit alle vensters behalve hijack en klik op “fix checked”

    verwijder deze mappen indien aanwezig:

    C:\Program Files\ISTsvc

    C:\Program Files\surfaccuracy

    download de vundo removaltool naar je bureaublad:

    http://securityresponse.symantec.com/avcenter/venc/data/trojan.vundo.removal.tool.html

    dubbelklik het bestand en klik op “start”

    het tooltje zal een logje maken,bewaar dat ;)

    herstart je pc

    start nogmaals het tooltje en plaats daarna de twee logjes die het tooltje gemaakt heeft plus een nieuw hiojack log en vertel of je nog steeds die popups krijgt :)

    paul :)

  • pablo

    sluit wel je internet af voor je het tooltje laat scannen,zet desnoode eerst even je modem uit en zet die pas weer aan nadat je het tooltje voor de tweede keer hebt laten scannen ;)

    paul :)

  • Miranda

    Nou Paul, ik heb alles gedaan wat je zei. Maar hij geeft me maar 1 logje van Vundo. De tweede keer zei hij overigens ook dat het trojan virus niet te vinden was. Hierbij mijn logjes dus maar weer.

    groetjes Miranda

    Logfile of HijackThis v1.99.1

    Scan saved at 10:44:30, on 30-10-2005

    Platform: Windows XP SP1 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\PROGRA~1\INSTAN~1\INSTAN~1\IWCTRL.EXE

    C:\WINDOWS\System32\sstray.exe

    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

    C:\Program Files\CyberLink\PowerVCRII\Agent.exe

    C:\PROGRA~1\HARDWA~1\Keyboard\Ikeymain.exe

    C:\PROGRA~1\HARDWA~1\Mouse\Amoumain.exe

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    C:\PROGRA~1\SYMANT~1\VPTray.exe

    C:\Program Files\Browser MOUSE\mouse32a.exe

    C:\Program Files\QuickTime\qttask.exe

    C:\WINDOWS\System32\ctfmon.exe

    C:\Program Files\Shareaza\Shareaza.exe

    C:\WINDOWS\System32\Ati2evxx.exe

    C:\Program Files\Symantec AntiVirus\DefWatch.exe

    C:\Program Files\Symantec AntiVirus\Rtvscan.exe

    C:\WINDOWS\System32\wuauclt.exe

    C:\Program Files\hijackthis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    R3 - Default URLSearchHook is missing

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll

    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

    O4 - HKLM\..\Run: C:\PROGRA~1\INSTAN~1\INSTAN~1\IWCTRL.EXE

    O4 - HKLM\..\Run: sstray.exe /r

    O4 - HKLM\..\Run: Ati2mdxx.exe

    O4 - HKLM\..\Run: C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

    O4 - HKLM\..\Run: C:\Program Files\Microsoft Works\WkDetect.exe

    O4 - HKLM\..\Run: C:\Program Files\Microsoft Works\wkfud.exe

    O4 - HKLM\..\Run: C:\Program Files\Microsoft Works\WksSb.exe /AllUsers

    O4 - HKLM\..\Run: C:\Program Files\CyberLink\PowerVCRII\Agent.exe

    O4 - HKLM\..\Run: C:\Program Files\CyberLink\PowerVCRII\RemoteAgent.exe

    O4 - HKLM\..\Run: C:\PROGRA~1\HARDWA~1\Keyboard\Ikeymain.exe

    O4 - HKLM\..\Run: C:\PROGRA~1\HARDWA~1\Mouse\Amoumain.exe

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Symantec Shared\ccApp.exe”

    O4 - HKLM\..\Run: C:\PROGRA~1\SYMANT~1\VPTray.exe

    O4 - HKLM\..\Run: C:\Program Files\Browser MOUSE\mouse32a.exe

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKCU\..\Run: C:\WINDOWS\System32\ctfmon.exe

    O4 - HKCU\..\Run: “C:\Program Files\Shareaza\Shareaza.exe” -tray

    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html

    O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html

    O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html

    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html

    O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html

    O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O9 - Extra ‘Tools’ menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE

    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab

    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab

    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab

    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - “C:\PROGRA~1\MSNMES~1\msgrapp.dll” (file missing)

    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll

    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe

    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe

    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

    Symantec Trojan.Vundo Removal Tool 1.4.0

    C:\System Volume Information: (not scanned)

    Trojan.Vundo has not been found on your computer.

  • pablo

    hoi miranda,

    ik neem aan dat je wel nog steeds die popups krijgt? doe dan dit even ;)

    1. Download L2Mfix.

    -Plaats het bestand op je bureaublad.

    -Klik op l2mfix.exe.

    -Klik op Accept.

    -Zorg dat de l2mfix-map op je bureaublad geplaatst wordt.

    -Klik op Install.

    -Op je bureaublad open je de map l2mfix.

    -Klik op l2fix.bat.

    -Klik op “1” om optie te 1 selecteren: Run Find Log.

    -Dit gaat even duren. Na een tijdje wordt er een kladblokbestand geopend.

    2. kopieer die tekst en plaats die hier.

    paul :)

  • pablo

    1. Download L2Mfix.

    -Plaats het bestand op je bureaublad.

    -Klik op l2mfix.exe.

    -Klik op Accept.

    -Zorg dat de l2mfix-map op je bureaublad geplaatst wordt.

    -Klik op Install.

    -Op je bureaublad open je de map l2mfix.

    -Klik op l2fix.bat.

    -Klik op “1” om optie te 1 selecteren: Run Find Log.

    -Dit gaat even duren. Na een tijdje wordt er een kladblokbestand geopend.

    2. kopieer die tekst en plaats die hier

  • Miranda

    Nou, ik hoop dat jij er iets mee kunt, Paul. Ik kan er in ieder geval geen chocola van maken!!!

    groetjes Miranda

    L2MFIX find log 1.04a

    These are the registry keys present

    **********************************************************************************

    Winlogon/notify:

    Windows Registry Editor Version 5.00

    “Asynchronous”=dword:00000000

    “Impersonate”=dword:00000000

    “DllName”=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\

    6c,00,00,00

    “Logoff”=“ChainWlxLogoffEvent”

    “Asynchronous”=dword:00000000

    “Impersonate”=dword:00000000

    “DllName”=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “Logoff”=“CryptnetWlxLogoffEvent”

    “DLLName”=“cscdll.dll”

    “Logon”=“WinlogonLogonEvent”

    “Logoff”=“WinlogonLogoffEvent”

    “ScreenSaver”=“WinlogonScreenSaverEvent”

    “Startup”=“WinlogonStartupEvent”

    “Shutdown”=“WinlogonShutdownEvent”

    “StartShell”=“WinlogonStartShellEvent”

    “Impersonate”=dword:00000000

    “Asynchronous”=dword:00000001

    “Logoff”=“NavLogoffEvent”

    “DllName”=“C:\\WINDOWS\\System32\\NavLogon.dll”

    “StartShell”=“NavStartShellEvent”

    “DLLName”=“wlnotify.dll”

    “Logon”=“SCardStartCertProp”

    “Logoff”=“SCardStopCertProp”

    “Lock”=“SCardSuspendCertProp”

    “Unlock”=“SCardResumeCertProp”

    “Enabled”=dword:00000001

    “Impersonate”=dword:00000001

    “Asynchronous”=dword:00000001

    “Asynchronous”=dword:00000000

    “DllName”=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “Impersonate”=dword:00000000

    “StartShell”=“SchedStartShell”

    “Logoff”=“SchedEventLogOff”

    “Logoff”=“WLEventLogoff”

    “Impersonate”=dword:00000000

    “Asynchronous”=dword:00000001

    “DllName”=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “DLLName”=“WlNotify.dll”

    “Lock”=“SensLockEvent”

    “Logon”=“SensLogonEvent”

    “Logoff”=“SensLogoffEvent”

    “Safe”=dword:00000001

    “MaxWait”=dword:00000258

    “StartScreenSaver”=“SensStartScreenSaverEvent”

    “StopScreenSaver”=“SensStopScreenSaverEvent”

    “Startup”=“SensStartupEvent”

    “Shutdown”=“SensShutdownEvent”

    “StartShell”=“SensStartShellEvent”

    “PostShell”=“SensPostShellEvent”

    “Disconnect”=“SensDisconnectEvent”

    “Reconnect”=“SensReconnectEvent”

    “Unlock”=“SensUnlockEvent”

    “Impersonate”=dword:00000001

    “Asynchronous”=dword:00000001

    “Asynchronous”=dword:00000000

    “DllName”=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\

    6c,00,6c,00,00,00

    “Impersonate”=dword:00000000

    “Logoff”=“TSEventLogoff”

    “Logon”=“TSEventLogon”

    “PostShell”=“TSEventPostShell”

    “Shutdown”=“TSEventShutdown”

    “StartShell”=“TSEventStartShell”

    “Startup”=“TSEventStartup”

    “MaxWait”=dword:00000258

    “Reconnect”=“TSEventReconnect”

    “Disconnect”=“TSEventDisconnect”

    “DLLName”=“wlnotify.dll”

    “Logon”=“RegisterTicketExpiredNotificationEvent”

    “Logoff”=“UnregisterTicketExpiredNotificationEvent”

    “Impersonate”=dword:00000001

    “Asynchronous”=dword:00000001

    RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above

    Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)

    This program is Freeware, use it on your own risk!

    Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:

    (ID-NI) ALLOW Read INGEBOUWD\Gebruikers

    (ID-IO) ALLOW Read INGEBOUWD\Gebruikers

    (ID-NI) ALLOW Full access INGEBOUWD\Administrators

    (ID-IO) ALLOW Full access INGEBOUWD\Administrators

    (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM

    (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM

    (ID-IO) ALLOW Full access MAKER EIGENAAR

    **********************************************************************************

    useragent:

    Windows Registry Editor Version 5.00

    “iebar”=“”

    **********************************************************************************

    Shell Extension key:

    Windows Registry Editor Version 5.00

    “{00022613-0000-0000-C000-000000000046}”=“Eigenschappenvenster van multimediabestand”

    “{176d6597-26d3-11d1-b350-080036a75b03}”=“ICM-scannerbeheer”

    “{1F2E5C40-9550-11CE-99D2-00AA006E086C}”=“Het tabblad Beveiliging”

    “{3EA48300-8CF6-101B-84FB-666CCB9BCD32}”=“Eigenschappenblad voor OLE-docbestand”

    “{40dd6e20-7c17-11ce-a804-00aa003ca9f6}”=“Shell-uitbreidingen voor delen”

    “{41E300E0-78B6-11ce-849B-444553540000}”=“PlusPack CPL Extension”

    “{42071712-76d4-11d1-8b24-00a0c9068ff3}”=“Configuratiescherm-uitbreiding Beeldschermadapter”

    “{42071713-76d4-11d1-8b24-00a0c9068ff3}”=“Configuratiescherm-uitbreiding Monitor”

    “{42071714-76d4-11d1-8b24-00a0c9068ff3}”=“Configuratiescherm-uitbreiding Beeldscherm-panning”

    “{4E40F770-369C-11d0-8922-00A024AB2DBB}”=“Het tabblad Beveiliging”

    “{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}”=“Compatibiliteitspagina”

    “{56117100-C0CD-101B-81E2-00AA004AE837}”=“Knipselgegevensverwerker van shell”

    “{59099400-57FF-11CE-BD94-0020AF85B590}”=“Schijfkopieer-uitbreiding”

    “{59be4990-f85c-11ce-aff7-00aa003ca9f6}”=“Shell-uitbreidingen voor Microsoft Windows Network-objecten”

    “{5DB2625A-54DF-11D0-B6C4-0800091AA605}”=“ICM-monitorbeheer”

    “{675F097E-4C4D-11D0-B6C1-0800091AA605}”=“ICM-printerbeheer”

    “{764BF0E1-F219-11ce-972D-00AA00A14F56}”=“Shell-uitbreidingen voor bestandscompressie”

    “{77597368-7b15-11d0-a0c2-080036af3f03}”=“Shell-uitbreiding voor Web Printer”

    “{7988B573-EC89-11cf-9C00-00AA00A14F56}”=“Disk Quota UI”

    “{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}”=“Snelmenu Codering”

    “{85BBD920-42A0-1069-A2E4-08002B30309D}”=“Werkmap”

    “{88895560-9AA2-1069-930E-00AA0030EBC8}”=“HyperTerminal-pictogramuitbreiding”

    “{BD84B380-8CA2-1069-AB1D-08000948F534}”=“Fonts”

    “{DBCE2480-C732-101B-BE72-BA78E9AD5B27}”=“ICC-profiel”

    “{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}”=“Het tabblad Beveiliging voor printers”

    “{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}”=“Shell-uitbreidingen voor delen”

    “{f92e8c40-3d33-11d2-b1aa-080036a75b03}”=“Display TroubleShoot CPL Extension”

    “{7444C717-39BF-11D1-8CD9-00C04FC29D45}”=“Crypto PKO-extensie”

    “{7444C719-39BF-11D1-8CD9-00C04FC29D45}”=“Crypto-handtekeningextensie”

    “{7007ACC7-3202-11D1-AAD2-00805FC1270E}”=“Netwerkverbindingen”

    “{992CFFA0-F557-101A-88EC-00DD010CCC48}”=“Netwerkverbindingen”

    “{E211B736-43FD-11D1-9EFB-0000F8757FCD}”=“Scanners en camera's”

    “{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}”=“Scanners en camera's”

    “{905667aa-acd6-11d2-8080-00805f6596d2}”=“Scanners en camera's”

    “{3F953603-1008-4f6e-A73A-04AAC7A992F1}”=“Scanners en camera's”

    “{83bbcbf3-b28a-4919-a5aa-73027445d672}”=“Scanners en camera's”

    “{F0152790-D56E-4445-850E-4F3117DB740C}”=“Remote Sessions CPL Extension”

    “{5F327514-6C5E-4d60-8F16-D07FA08A78ED}”=“Auto Update Property Sheet Extension”

    “{60254CA5-953B-11CF-8C96-00AA00B8708C}”=“Shell-uitbreidingen voor Windows Script Host”

    “{2206CDB2-19C1-11D1-89E0-00C04FD7A829}”=“Microsoft Data Link”

    “{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}”=“Tasks Folder Icon Handler”

    “{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}”=“Tasks Folder Shell Extension”

    “{D6277990-4C6A-11CF-8D87-00AA0060F5BF}”=“Geplande taken”

    “{0DF44EAA-FF21-4412-828E-260A8728E7F1}”=“Taakbalk en menu Start”

    “{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}”=“Zoeken”

    “{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}”=“Help en ondersteuning”

    “{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}”=“Help en ondersteuning”

    “{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}”=“Uitvoeren…”

    “{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}”=“Internet”

    “{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}”=“E-mail”

    “{D20EA4E1-3957-11d2-A40B-0C5020524152}”=“Lettertypen”

    “{D20EA4E1-3957-11d2-A40B-0C5020524153}”=“Systeembeheer”

    “{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}”=“Audio Media Properties Handler”

    “{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}”=“Video Media Properties Handler”

    “{E4B29F9D-D390-480b-92FD-7DDB47101D71}”=“Wav Properties Handler”

    “{87D62D94-71B3-4b9a-9489-5FE6850DC73E}”=“Avi Properties Handler”

    “{A6FD9E45-6E44-43f9-8644-08598F5A74D9}”=“Midi Properties Handler”

    “{c5a40261-cd64-4ccf-84cb-c394da41d590}”=“Video Thumbnail Extractor”

    “{5E6AB780-7743-11CF-A12B-00AA004AE837}”=“Microsoft Internet-werkbalk”

    “{22BF0C20-6DA7-11D0-B373-00A0C9034938}”=“Downloadstatus”

    “{91EA3F8B-C99B-11d0-9815-00C04FD91972}”=“Uitgebreide shell-map”

    “{6413BA2C-B461-11d1-A18A-080036B11A03}”=“Uitgebreide shell-map 2”

    “{F61FFEC1-754F-11d0-80CA-00AA005B4383}”=“BandProxy”

    “{7BA4C742-9E81-11CF-99D3-00AA004AE837}”=“Microsoft-browserbalk”

    “{30D02401-6A81-11d0-8274-00C04FD5AE38}”=“Zoekbalk”

    “{32683183-48a0-441b-a342-7c2a440a9478}”=“Mediabalk”

    “{169A0691-8DF9-11d1-A1C4-00C04FD75D13}”=“Zoeken binnen deelvenster”

    “{07798131-AF23-11d1-9111-00A0C98BA67D}”=“Zoeken op het web”

    “{AF4F6510-F982-11d0-8595-00AA004CD6D8}”=“Hulpprogramma met opties voor registerboomstructuur”

    “{01E04581-4EEE-11d0-BFE9-00AA005B4383}”=“&Adres”

    “{A08C11D2-A228-11d0-825B-00AA005B4383}”=“Address EditBox”

    “{00BB2763-6A77-11D0-A535-00C04FD7D062}”=“Microsoft AutoAanvullen”

    “{7376D660-C583-11d0-A3A5-00C04FD706EC}”=“TridentImageExtractor”

    “{6756A641-DE71-11d0-831B-00AA005B4383}”=“MRU-lijst voor AutoAanvullen”

    “{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}”=“Aangepaste MRU-lijst voor AutoAanvullen”

    “{7e653215-fa25-46bd-a339-34a2790f3cb7}”=“Toegankelijk”

    “{acf35015-526e-4230-9596-becbe19f0ac9}”=“Pop-upbalk Volgen”

    “{E0E11A09-5CB8-4B6C-8332-E00720A168F2}”=“Parser voor adresbalk”

    “{00BB2764-6A77-11D0-A535-00C04FD7D062}”=“Lijst voor AutoAanvullen: Microsoft Geschiedenis”

    “{03C036F1-A186-11D0-824A-00AA005B4383}”=“Lijst voor AutoAanvullen: Microsoft Shell-map”

    “{00BB2765-6A77-11D0-A535-00C04FD7D062}”=“Microsoft-container met meervoudige lijst voor AutoAanvullen”

    “{ECD4FC4E-521C-11D0-B792-00A0C90312E1}”=“Sitemenu van shell-band”

    “{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}”=“Shell DeskBarApp”

    “{ECD4FC4C-521C-11D0-B792-00A0C90312E1}”=“Shell DeskBar”

    “{ECD4FC4D-521C-11D0-B792-00A0C90312E1}”=“Shell Rebar BandSite”

    “{DD313E04-FEFF-11d1-8ECD-0000F87A470C}”=“Gebruikersondersteuning”

    “{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}”=“Globale mapinstellingen”

    “{EFA24E61-B078-11d0-89E4-00C04FC9E26E}”=“Favorites Band”

    “{0A89A860-D7B1-11CE-8350-444553540000}”=“Shell Automation Inproc Service”

    “{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}”=“Shell DocObject Viewer”

    “{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}”=“Microsoft Browser Architecture”

    “{FBF23B40-E3F0-101B-8488-00AA003E56F8}”=“InternetShortcut”

    “{3C374A40-BAE4-11CF-BF7D-00AA006946EE}”=“Microsoft Url-geschiedenisservice”

    “{FF393560-C2A7-11CF-BFF4-444553540000}”=“Geschiedenis”

    “{7BD29E00-76C1-11CF-9DD0-00A0C9034933}”=“Tijdelijke Internet-bestanden”

    “{7BD29E01-76C1-11CF-9DD0-00A0C9034933}”=“Tijdelijke Internet-bestanden”

    “{CFBFAE00-17A6-11D0-99CB-00C04FD64497}”=“Microsoft Url-zoeken Hook”

    “{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}”=“IE4 Suite-welkomstscherm”

    “{67EA19A0-CCEF-11d0-8024-00C04FD75D13}”=“CDF Extension Copy Hook”

    “{131A6951-7F78-11D0-A979-00C04FD705A2}”=“ISFBand OC”

    “{9461b922-3c5a-11d2-bf8b-00c04fb93661}”=“Search Assistant OC”

    “{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}”=“Het Internet”

    “{871C5380-42A0-1069-A2EA-08002B30309D}”=“Internet Name Space”

    “{EFA24E64-B078-11d0-89E4-00C04FC9E26E}”=“Explorer-band”

    “{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}”=“Sendmail service”

    “{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}”=“Sendmail service”

    “{88C6C381-2E85-11D0-94DE-444553540000}”=“Cachemap van ActiveX”

    “{E6FB5E20-DE35-11CF-9C87-00AA005127ED}”=“WebCheck”

    “{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}”=“Subscription Mgr”

    “{F5175861-2688-11d0-9C5E-00AA00A45957}”=“Map met abonnementen”

    “{08165EA0-E946-11CF-9C87-00AA005127ED}”=“WebCheckWebCrawler”

    “{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}”=“WebCheckChannelAgent”

    “{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}”=“TrayAgent”

    “{7D559C10-9FE9-11d0-93F7-00AA0059CE02}”=“Code Download Agent”

    “{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}”=“ConnectionAgent”

    “{D8BD2030-6FC9-11D0-864F-00AA006809D9}”=“PostAgent”

    “{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}”=“WebCheck SyncMgr Handler”

    “{352EC2B7-8B9A-11D1-B8AE-006008059382}”=“Shell Toepassingsbeheer”

    “{0B124F8F-91F0-11D1-B8B5-006008059382}”=“Programma voor inventarisatie van ge‹nstalleerde toepassingen”

    “{CFCCC7A0-A282-11D1-9082-006008059382}”=“Darwin App Publisher”

    “{e84fda7c-1d6a-45f6-b725-cb260c236066}”=“Shell Image Verbs”

    “{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}”=“Shell Image Data Factory”

    “{3F30C968-480A-4C6C-862D-EFC0897BB84B}”=“GDI- en bestandsextractieprogramma voor miniaturen”

    “{9DBD2C50-62AD-11d0-B806-00C04FD706EC}”=“Informatie over de handler voor miniatuurweergaven (DOCFILES)”

    “{EAB841A0-9550-11cf-8C16-00805F1408F3}”=“HTML-extractie voor miniatuurweergaven”

    “{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}”=“Shell Image Property Handler”

    “{CC6EEFFB-43F6-46c5-9619-51D571967F7D}”=“Wizard Webpublicaties”

    “{add36aa8-751a-4579-a266-d66f5202ccbb}”=“Afdrukken via het web bestellen”

    “{6b33163c-76a5-4b6c-bf21-45de9cd503a1}”=“Shell-object voor publicatiewizard”

    “{58f1f272-9240-4f51-b6d4-fd63d1618591}”=“Wizard Passport”

    “{7A9D77BD-5403-11d2-8785-2E0420524153}”=“Gebruikersaccounts”

    “{BD472F60-27FA-11cf-B8B4-444553540000}”=“Compressed (zipped) Folder Right Drag Handler”

    “{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}”=“Compressed (zipped) Folder SendTo Target”

    “{f39a0dc0-9cc8-11d0-a599-00c04fd64433}”=“Kanaal-bestand”

    “{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}”=“Kanaal-snelkoppeling”

    “{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}”=“Handler-object voor kanalen”

    “{f3da0dc0-9cc8-11d0-a599-00c04fd64437}”=“Channel Menu”

    “{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}”=“Channel Properties”

    “{63da6ec0-2e98-11cf-8d82-444553540000}”=“FTP Folders Webview”

    “{883373C3-BF89-11D1-BE35-080036B11A03}”=“Microsoft DocProp Shell Ext”

    “{A9CF0EAE-901A-4739-A481-E35B73E47F6D}”=“Microsoft DocProp Inplace Edit Box Control”

    “{8EE97210-FD1F-4B19-91DA-67914005F020}”=“Microsoft DocProp Inplace ML Edit Box Control”

    “{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}”=“Microsoft DocProp Inplace Droplist Combo Control”

    “{6A205B57-2567-4A2C-B881-F787FAB579A3}”=“Microsoft DocProp Inplace Calendar Control”

    “{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}”=“Microsoft DocProp Inplace Time Control”

    “{8A23E65E-31C2-11d0-891C-00A024AB2DBB}”=“Directory Query UI”

    “{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}”=“Shell properties for a DS object”

    “{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}”=“Directory Object Find”

    “{F020E586-5264-11d1-A532-0000F8757D7E}”=“Directory Start/Search Find”

    “{0D45D530-764B-11d0-A1CA-00AA00C16E65}”=“Directory Property UI”

    “{62AE1F9A-126A-11D0-A14B-0800361B1103}”=“Directory Context Menu Verbs”

    “{ECF03A33-103D-11d2-854D-006008059367}”=“MyDocs Copy Hook”

    “{ECF03A32-103D-11d2-854D-006008059367}”=“MyDocs Drop Target”

    “{4a7ded0a-ad25-11d0-98a8-0800361b1103}”=“MyDocs Properties”

    “{750fdf0e-2a26-11d1-a3ea-080036587f03}”=“Offline Files Menu”

    “{10CFC467-4392-11d2-8DB4-00C04FA31A66}”=“Offline Files Folder Options”

    “{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}”=“Map Off line bestanden”

    “{143A62C8-C33B-11D1-84FE-00C04FA34A14}”=“Microsoft Agent Character Property Sheet Handler”

    “{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}”=“DfsShell”

    “{60fd46de-f830-4894-a628-6fa81bc0190d}”=“%DESC_PublishDropTarget%”

    “{7A80E4A8-8005-11D2-BCF8-00C04F72C717}”=“MMC Icon Handler”

    “{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}”=“.CAB file viewer”

    “{32714800-2E5F-11d0-8B85-00AA0044F941}”=“&Personen…”

    “{8DD448E6-C188-4aed-AF92-44956194EB1F}”=“Windows Media Player Play as Playlist Context Menu Handler”

    “{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}”=“Windows Media Player Burn Audio CD Context Menu Handler”

    “{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}”=“Windows Media Player Add to Playlist Context Menu Handler”

    “{F5D92341-0A64-11D0-9956-0000E8096023}”=“CD Copy Shell Extension”

    “{F5D92342-0A64-11D0-9956-0000E8096023}”=“CD Wizard Shell Extension”

    “{F5D92344-0A64-11D0-9956-0000E8096023}”=“InstantWrite Shellextension”

    “{BDEADF00-C265-11D0-BCED-00A0C90AB50F}”=“Webmappen”

    “{42042206-2D85-11D3-8CFF-005004838597}”=“Microsoft Office HTML Icon Handler”

    “{BDA77241-42F6-11d0-85E2-00AA001FE28C}”=“LDVP Shell Extensions”

    “{0006F045-0000-0000-C000-000000000046}”=“Microsoft Outlook Custom Icon Handler”

    “{640167b4-59b0-47a6-b335-a6b3c0695aea}”=“Portable Media Devices”

    “{cc86590a-b60a-48e6-996b-41d25ed39a1e}”=“Portable Media Devices Menu”

    **********************************************************************************

    HKEY ROOT CLASSIDS:

    **********************************************************************************

    Files Found are not all bad files:

    **********************************************************************************

    Directory Listing of system files:

    Het volume in station C heeft geen naam.

    Het volumenummer is D826-C786

    Map van C:\WINDOWS\System32

    24-10-2005 20:30 dllcache

    19-11-2002 18:12 Microsoft

    05-01-2002 04:40 487.424 msvcp70.dll

    1 bestand(en) 487.424 bytes

    2 map(pen) 106.876.576.256 bytes beschikbaar

  • pablo

    hoi miranda,

    dit geeft ook niet het resultaat wat ik gehoopt had :?:)

    kan je een online scan doen bij kaspersky?

    http://www.kaspersky.com/downloads/kws/kavwebscan.html

    bewaar het logje wat gemaakt word en plaats dat even hier :)

    paul :)

  • Miranda

    Nou, daar komt ie dan!!

    groetjes Miranda

    ——————————————————————————-

    KASPERSKY ON-LINE SCANNER REPORT

    Wednesday, November 02, 2005 16:59:03

    Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)

    Kaspersky On-line Scanner version: 5.0.67.0

    Kaspersky Anti-Virus database last update: 2/11/2005

    Kaspersky Anti-Virus database records: 148181

    ——————————————————————————-

    Scan Settings:

    Scan using the following antivirus database: standard

    Scan Archives: true

    Scan Mail Bases: true

    Scan Target - My Computer:

    A:\

    C:\

    D:\

    E:\

    F:\

    G:\

    H:\

    Scan Statistics:

    Total number of scanned objects: 37658

    Number of viruses found: 21

    Number of infected objects: 36

    Number of suspicious objects: 0

    Duration of the scan process: 1458 sec

    Infected Object Name - Virus Name

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01F00000.VBN Infected: Exploit.VBS.Phel.a

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\01F00001.VBN Infected: Exploit.VBS.Phel.a

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\02480000.VBN Infected: Backdoor.Win32.Webdor.p

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\030C0000.VBN Infected: Trojan.Win32.StartPage.up

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80000.VBN/BlackBox.class Infected: Exploit.Java.ByteVerify

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80000.VBN/VerifierBug.class Infected: Exploit.Java.ByteVerify

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80000.VBN/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03A80000.VBN Infected: Trojan-Downloader.Java.OpenConnection.aa

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\03C80000.VBN Infected: P2P-Worm.Win32.Darby.o

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08C40000.VBN Infected: Exploit.HTML.IframeBof

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09100000.VBN Infected: Trojan-Downloader.JS.gen

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09100001.VBN Infected: Trojan-Downloader.Win32.Donn.ab

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\09100002.VBN Infected: Trojan-Downloader.Win32.Donn.ab

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A0C0000.VBN Infected: Backdoor.Win32.Webdor.p

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A0C0001.VBN Infected: Backdoor.Win32.Webdor.p

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A0C0002.VBN Infected: Trojan.Win32.StartPage.up

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A0C0003.VBN Infected: Trojan.Win32.StartPage.up

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0A700000.VBN Infected: Trojan.Win32.StartPage.nk

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0AE40000.VBN Infected: Backdoor.Win32.Rbot.aeu

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0E5C0000.VBN Infected: Trojan.Win32.StartPage.nk

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0E5C0001.VBN Infected: Trojan.Win32.StartPage.nk

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0E5C0002.VBN Infected: Trojan.Win32.StartPage.nk

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\0E5C0003.VBN Infected: Trojan.Win32.StartPage.nk

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\1BB00000.VBN Infected: Trojan-Downloader.Win32.Agent.il

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\1BB00001.VBN Infected: Trojan-Downloader.Win32.Agent.il

    C:\Documents and Settings\All Users\Documenten\backups\backup-20050215-174823-522.dll Infected: Trojan-Clicker.Win32.Adpower.a

    C:\RECYCLER\S-1-5-21-2324168567-3153272810-1362697065-500\Dc1\Evczeex.exe Infected: Trojan.Win32.Small.cy

    C:\RECYCLER\S-1-5-21-2324168567-3153272810-1362697065-500\Dc5.exe Infected: Trojan-Downloader.Win32.Agent.is

    C:\System Volume Information\_restore{C6B202E0-56D8-451B-8809-C1B5A26C69B4}\RP154\A0039255.dll Infected: Trojan-Downloader.Win32.IstBar.ms

    C:\System Volume Information\_restore{C6B202E0-56D8-451B-8809-C1B5A26C69B4}\RP154\A0039259.exe Infected: Trojan-Downloader.Win32.IstBar.ij

    C:\System Volume Information\_restore{C6B202E0-56D8-451B-8809-C1B5A26C69B4}\RP154\A0039261.exe Infected: Trojan-Downloader.Win32.IstBar.gen

    C:\WINDOWS\system32\appsys.exe Infected: Trojan-Downloader.Win32.Delf.au

    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\CHAJGT2J\istdownload.exe Infected: Trojan-Downloader.Win32.IstBar.gen

    C:\WINDOWS\system32\mssce.exe Infected: Trojan-Dropper.Win32.Juntador.c

    C:\WINDOWS\system32\ntdpds.exe Infected: Trojan.Win32.Crypt.t

    C:\WINDOWS\system32\screnacm.dll Infected: Trojan.Win32.Crypt.t

    Scan process completed.

  • pablo

    hoi miranda,

    download de killbox en pak hem uit naar je bureaublad

    http://www.downloads.subratam.org/KillBox.zip

    start de killbox en zet een vinkje bij “delete on reboot”

    kopieer de vetgedrukte tekst:

    C:\RECYCLER\S-1-5-21-2324168567-3153272810-1362697065-500\Dc1\Evczeex.exe

    C:\RECYCLER\S-1-5-21-2324168567-3153272810-1362697065-500\Dc5.exe

    C:\WINDOWS\system32\appsys.exe

    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\CHAJGT2J\istdownload.exe

    C:\WINDOWS\system32\mssce.exe

    C:\WINDOWS\system32\ntdpds.exe

    C:\WINDOWS\system32\screnacm.dll

    open “file” in het killboxmenu bovenaan en kies: Paste from clipboard

    je zal zien, het bovenstaande vetgedrukte zal staan in het “Full Path of File to Delete”-veld.

    Er is een klein pijltje naast dat veld. Als je daarop klikt zal je al die bovenstaande lijntjes ( indien bestanden aanwezig ) die je gekopieerd hebt zien staan ( dat is tenminste de bedoeling )

    Daarna klik je op de rode knop met het wit kruisje erin,klik in beide popschermpjes op JA,je pc zal herstarten,als je een melding ziet over pendingfilerename herstart dan handmatig.

    download op deze pagina: http://www.billsway.com/vbspage/

    de Registry search tool en pak hem uit naar je bureaublad.

    start op in veilige modus ( uitleg )

    start het tooltje door RegSrch.vbs te dubbelklikken

    In zoekveld geef je volgende string in: adchannel

    Je register wordt nu doorzocht.

    Als er wat gevonden wordt, dan opent er een wordpad bestand,bewaar dat en plaats dat even hier :)

    paul :)