opstart & verbindingen

  • Erik

    Dit is troep:

    O4 - HKCU\..\Run: “C:\Program Files\Osirius\Stop SpyWare\StopSpyWare.exe” /start

  • Aalex

    ja, dat vermoeden had ik al, probleem is alleen dat ik het zgn al had verwijderd maar dat het nog steeds in ‘C’ zit …ik had hem al via configuratie verwijderd, maar blijkt er idd nog steeds in te zitten.

  • Erik

    Doe een online scan bij Panda, bewaar het logje en plaats dat hier: http://www.pandasoftware.com/products/activescan.htm

  • Aalex

    thnx!

    Osirius zit in ‘C’ program files en kán hem nieteens verwijderen … geeft melding dat toegang is geweigerd en/of waarschijnlijk in gebruik is …

    Ga nu gelijk een logje maken, tot zo!

  • Aalex

    Error on downloading ActiveScanAn error has occurred downloading Panda ActiveScan. Please repeat the process. If the error occurs again, restart your system and try againPossible causes of this error are:

    Not allowing the application's ActiveX control to be downloaded.

    Problems with the Internet connection.

    The error could be due to a download error or an installation error due to lack of hard disk space, privileges etc.,…

    kom niet echt ver hiermee op dit moment …

  • Erik

    Voer een onlinescan uit met Kaspersky WebScanner http://www.kaspersky.com/downloads/kws/kavwebscan.html

    Klik accept

    Men zal vragen of je de activeX wil installeren, klik ja.

    Het zal daarna beginnen met de database/definition files te downloaden.

    Wanneer dit gedaan is, klik op “Next”

    * Klik “Scan Settings”

    Selecteer het volgende: (zal normaal zo al standaard staan)

    °Scan using the following Anti-Virus database: Standard

    °Scan Options: Scan Archives

    Scan Mail Bases

    * Klik OK

    * Onder ‘select a target to scan’, kies “My Computer”

    * Nu zal het beginnen scannen. Dit zal een tijdje duren, dus asjeblief wees geduldig.

    Wanneer de scan gedaan is zal het een lijst tonen van alle geïnfecteerde bestanden.

    * Klik op de “Save as Text”- knop:

    Bewaar die log naar je bureaublad en kopieer en plak die in je volgend bericht.

  • Aalex

    Osirius als het goed is verwijderd …

    log:

    Logfile of HijackThis v1.99.1

    Scan saved at 14:21:31, on 9-11-2005

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    C:\WINDOWS\system32\brsvc01a.exe

    C:\WINDOWS\system32\LEXBCES.EXE

    C:\WINDOWS\system32\brss01a.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\LEXPPS.EXE

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Sitecom\Bluetooth Software\bin\btwdins.exe

    C:\WINDOWS\System32\CTsvcCDA.exe

    C:\Program Files\Norton AntiVirus\navapsvc.exe

    C:\Program Files\Norton AntiVirus\SAVScan.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\System32\MsPMSPSv.exe

    C:\PROGRA~1\PHILIP~1\VProperty.exe

    C:\WINDOWS\system32\rundll32.exe

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    C:\Program Files\Winamp\winampa.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

    C:\Program Files\MSN Messenger\msnmsgr.exe

    C:\Program Files\Trend Micro\Tmas\Tmas.exe

    C:\Program Files\Trust\240TH Direct Webscan Gold\Driver\WATCH.exe

    C:\WINDOWS\system32\wscntfy.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\WINDOWS\system32\NOTEPAD.EXE

    D:\Documenten en Settings\gebruiker.YOUR-OP32140JPF\Bureaublad\hijackthis.exe

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll

    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll

    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll

    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

    O4 - HKLM\..\Run: C:\PROGRA~1\PHILIP~1\VProperty.exe

    O4 - HKLM\..\Run: rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

    O4 - HKLM\..\Run: “C:\Program Files\Common Files\Symantec Shared\ccApp.exe”

    O4 - HKLM\..\Run: C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer

    O4 - HKLM\..\Run: C:\Program Files\Winamp\winampa.exe

    O4 - HKCU\..\Run: “C:\Program Files\Messenger\msmsgs.exe” /background

    O4 - HKCU\..\Run: “C:\Program Files\Osirius\Stop SpyWare\StopSpyWare.exe” /start

    O4 - HKCU\..\Run: “C:\Program Files\MSN Messenger\msnmsgr.exe” /background

    O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe

    O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe

    O4 - Global Startup: Watch.lnk = C:\Program Files\Trust\240TH Direct Webscan Gold\Driver\WATCH.exe

    O8 - Extra context menu item: &Google Zoeken - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html

    O8 - Extra context menu item: &Woord vertalen in het Nederlands - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html

    O8 - Extra context menu item: Gelijkwaardige pagina's - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html

    O8 - Extra context menu item: Koppelingspagina's - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html

    O8 - Extra context menu item: Opgeslagen momentopname van de pagina - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html

    O8 - Extra context menu item: Verzenden naar &Bluetooth - C:\Program Files\Sitecom\Bluetooth Software\btsendto_ie_ctx.htm

    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Bluetooth Software\btsendto_ie.htm

    O9 - Extra ‘Tools’ menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Bluetooth Software\btsendto_ie.htm

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab

    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab

    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - “C:\PROGRA~1\MSNMES~1\msgrapp.dll” (file missing)

    O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe

    O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\Sitecom\Bluetooth Software\bin\btwdins.exe

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe

    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

    O23 - Service: Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe

    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe

    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

  • Aalex

    ok, dank je wel!

    ik was net ff te vlug met voorgaande quote … heb inmiddels Osirius verwijderd als het goed is maar ga nu gelijk jouw advies uitvoeren.

    Het zal waarschijnlijk idd wel eventjes duren maar krijg nu opeens goede moed!

    groet Aalex.

  • Aalex

    Scan voltooid!

    (slik) … kwam meer tegen als wat ik verwacht had … bovendien is hiermee wel mun nickname direct naar de knoppen (A) …

    Logje:

    ——————————————————————————-

    KASPERSKY ON-LINE SCANNER REPORT

    Wednesday, November 09, 2005 15:44:05

    Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)

    Kaspersky On-line Scanner version: 5.0.67.0

    Kaspersky Anti-Virus database last update: 9/11/2005

    Kaspersky Anti-Virus database records: 149396

    ——————————————————————————-

    Scan Settings:

    Scan using the following antivirus database: standard

    Scan Archives: true

    Scan Mail Bases: true

    Scan Target - My Computer:

    A:\

    C:\

    D:\

    E:\

    F:\

    Scan Statistics:

    Total number of scanned objects: 55106

    Number of viruses found: 22

    Number of infected objects: 67

    Number of suspicious objects: 1

    Duration of the scan process: 3518 sec

    Infected Object Name - Virus Name

    C:\download\driver\CEDP.Stealer.exe Infected: Trojan-Dropper.Win32.180Solutions.b

    C:\Program Files\Norton AntiVirus\Quarantine\0339490D Infected: Trojan-Downloader.Win32.Swizzor.cn

    C:\Program Files\Norton AntiVirus\Quarantine\03E0562D Infected: Trojan-Downloader.Win32.Swizzor.cn

    C:\Program Files\Norton AntiVirus\Quarantine\0EC9050C Infected: Trojan-Downloader.Win32.Swizzor.bz

    C:\Program Files\Norton AntiVirus\Quarantine\14D36324.txt Infected: Backdoor.Perl.Shellbot.a

    C:\Program Files\Norton AntiVirus\Quarantine\1DEA418C Infected: Trojan-Downloader.Win32.Swizzor.bz

    C:\Program Files\Norton AntiVirus\Quarantine\250B1388 Infected: Trojan-Downloader.Win32.Swizzor.bz

    C:\Program Files\Norton AntiVirus\Quarantine\26507311 Infected: Trojan-Downloader.Win32.Swizzor.cb

    C:\Program Files\Norton AntiVirus\Quarantine\2E3E5597.class Infected: Exploit.Java.Bytverify

    C:\Program Files\Norton AntiVirus\Quarantine\2E3E5597.htm Infected: Exploit.VBS.Phel.a

    C:\Program Files\Norton AntiVirus\Quarantine\2E633A02.class Infected: Trojan.Java.ClassLoader.c

    C:\Program Files\Norton AntiVirus\Quarantine\2E6663FE.class Infected: Trojan.Java.ClassLoader.Dummy.a

    C:\Program Files\Norton AntiVirus\Quarantine\2E6663FE.htm Infected: Exploit.VBS.Phel.a

    C:\Program Files\Norton AntiVirus\Quarantine\2E6663FE.zip/GetAccess.class Infected: Trojan.Java.ClassLoader.c

    C:\Program Files\Norton AntiVirus\Quarantine\2E6663FE.zip/InsecureClassLoader.class Infected: Exploit.Java.Bytverify

    C:\Program Files\Norton AntiVirus\Quarantine\2E6663FE.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a

    C:\Program Files\Norton AntiVirus\Quarantine\2E6663FE.zip/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v

    C:\Program Files\Norton AntiVirus\Quarantine\2E6663FE.zip Infected: Trojan-Downloader.Java.OpenConnection.v

    C:\Program Files\Norton AntiVirus\Quarantine\2FEB6852.htm Infected: Exploit.VBS.Phel.a

    C:\Program Files\Norton AntiVirus\Quarantine\34A8754A Infected: Trojan-Downloader.Win32.Swizzor.bz

    C:\Program Files\Norton AntiVirus\Quarantine\34AB1F46 Infected: Trojan-Downloader.Win32.Swizzor.bo

    C:\Program Files\Norton AntiVirus\Quarantine\34AE4942 Infected: Trojan-Downloader.Win32.Swizzor.cn

    C:\Program Files\Norton AntiVirus\Quarantine\34B51D3B Infected: Trojan-Downloader.Win32.Swizzor.bz

    C:\Program Files\Norton AntiVirus\Quarantine\34BB7134 Infected: Trojan-Downloader.Win32.Swizzor.cn

    C:\Program Files\Norton AntiVirus\Quarantine\34BF1B30 Infected: Trojan-Downloader.Win32.Swizzor.bz

    C:\Program Files\Norton AntiVirus\Quarantine\34C2452D Infected: Trojan-Downloader.Win32.Swizzor.bz

    C:\Program Files\Norton AntiVirus\Quarantine\3D716B0E Infected: Trojan-Downloader.Win32.Swizzor.bo

    C:\Program Files\Norton AntiVirus\Quarantine\6C185110 Infected: Trojan-Downloader.Win32.Swizzor.cn

    C:\Program Files\Norton AntiVirus\Quarantine\75A03235 Infected: Trojan-Downloader.Win32.Swizzor.bz

    D:\Documenten en Settings\All Users.WINDOWS\Application Data\clock ref jump sign\bolt name.exe Infected: Trojan.Win32.Krepper.ab

    D:\Documenten en Settings\Dennis\Local Settings\Temp\68b8c921.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\6acf525c.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\6ad4a2e8.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\6b07d4ed.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\6b64d524.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\6e60bb2d.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\7028c1ff.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\7279ce4e.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\755fdadb.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\75bba295.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\7793e226.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\79a5889a.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\7a3abe17.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\7bfa2d72.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\7c8bc6b9.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\7eddf8fc.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\7f116ad9.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\Rem6FA.exe Suspicious: Type_Win32

    D:\Documenten en Settings\Dennis\Local Settings\Temp\sta473.exe Infected: Trojan-Downloader.Win32.Swizzor.bi

    D:\Documenten en Settings\Dennis\Local Settings\Temp\sta56C.exe Infected: Trojan-Downloader.Win32.Swizzor.bi

    D:\Documenten en Settings\Dennis\Local Settings\Temp\sta573.exe Infected: Trojan-Downloader.Win32.Swizzor.bi

    D:\Documenten en Settings\Dennis\Local Settings\Temp\sta587.exe Infected: Trojan-Downloader.Win32.Swizzor.bi

    D:\Documenten en Settings\Dennis\Local Settings\Temp\sta8FA.exe Infected: Trojan-Downloader.Win32.Swizzor.aw

    D:\Documenten en Settings\Dennis\Local Settings\Temp\staAE6.exe Infected: Trojan-Downloader.Win32.Swizzor.bi

    D:\Documenten en Settings\Dennis\Local Settings\Temp\Temporary Internet Files\Content.IE5\QHGBALU5\index2.htm Infected: Trojan-Dropper.Win32.RunMe

    D:\Documenten en Settings\Dennis\Local Settings\Temp\Temporary Internet Files\Content.IE5\QHGBALU5\index.htm Infected: Trojan-Dropper.Win32.RunMe

    D:\Documenten en Settings\Dennis\Local Settings\Temp\UpdatedUpdaterInstall.exe/data0002/data0003 Infected: Trojan-Downloader.Win32.Keenval

    D:\Documenten en Settings\Dennis\Local Settings\Temp\UpdatedUpdaterInstall.exe/data0002/data0004 Infected: Trojan-Downloader.Win32.Keenval

    D:\Documenten en Settings\Dennis\Local Settings\Temp\UpdatedUpdaterInstall.exe/data0002/data0005 Infected: Trojan-Downloader.Win32.Keenval

    D:\Documenten en Settings\Dennis\Local Settings\Temp\UpdatedUpdaterInstall.exe/data0002 Infected: Trojan-Downloader.Win32.Keenval

    D:\Documenten en Settings\Dennis\Local Settings\Temp\UpdatedUpdaterInstall.exe/data0008 Infected: Trojan-Downloader.Win32.Keenval.f

    D:\Documenten en Settings\Dennis\Local Settings\Temp\UpdatedUpdaterInstall.exe/data0009/data0003 Infected: Trojan-Downloader.Win32.Keenval.f

    D:\Documenten en Settings\Dennis\Local Settings\Temp\UpdatedUpdaterInstall.exe/data0009 Infected: Trojan-Downloader.Win32.Keenval.f

    D:\Documenten en Settings\Dennis\Local Settings\Temp\UpdatedUpdaterInstall.exe Infected: Trojan-Downloader.Win32.Keenval.f

    D:\Documenten en Settings\Gebruiker\Local Settings\Temp\gdjhclal.htm Infected: Trojan.JS.Pooter.b

    D:\Documenten en Settings\Gebruiker\Local Settings\Temp\mplbgpek.htm Infected: Trojan.JS.Pooter.b

    D:\Documenten en Settings\gebruiker.YOUR-OP32140JPF\Application Data\tons start joy\Trust Blue Plan Global.exe Infected: Trojan-Downloader.Win32.Swizzor.ca

    D:\System Volume Information\_restore{D855C4FE-7C37-4491-8D01-595A6E8DF93A}\RP511\A0075530.exe Infected: Trojan-Downloader.Win32.Swizzor.bb

    Scan process completed.

  • Aalex

    Is het de bedoeling dat ik deze items handmatig stuk voor stuk zelf moet verwijderen en zoja, kan iemand mij vertellen wat wel en wat niet weg kan?

    Voorbeeld: …Wanneer ik bijvoorbeeld

    D:\Documenten en Settings\Dennis\Local Settings\Temp\UpdatedUpdaterInstall.exe/data0002/data0003 Infected: Trojan-Downloader.Win32.Keenval

    via het zoekprogramma opvraag blijkt dat het om het bijgaande logje te gaan … kan dit kloppen? … zo ja, hoe is dit dan mogelijk en is het juist dat ik dit moet verwijderen??

    groet “Aalex” …

    ——————————————————————————-

    KASPERSKY ON-LINE SCANNER REPORT

    Wednesday, November 09, 2005 15:44:05

    Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)

    Kaspersky On-line Scanner version: 5.0.67.0

    Kaspersky Anti-Virus database last update: 9/11/2005

    Kaspersky Anti-Virus database records: 149396

    ——————————————————————————-

    Scan Settings:

    Scan using the following antivirus database: standard

    Scan Archives: true

    Scan Mail Bases: true

    Scan Target - My Computer:

    A:\

    C:\

    D:\

    E:\

    F:\

    Scan Statistics:

    Total number of scanned objects: 55106

    Number of viruses found: 22

    Number of infected objects: 67

    Number of suspicious objects: 1

    Duration of the scan process: 3518 sec

    Infected Object Name - Virus Name

    C:\download\driver\CEDP.Stealer.exe Infected: Trojan-Dropper.Win32.180Solutions.b

    C:\Program Files\Norton AntiVirus\Quarantine\0339490D Infected: Trojan-Downloader.Win32.Swizzor.cn

    C:\Program Files\Norton AntiVirus\Quarantine\03E0562D Infected: Trojan-Downloader.Win32.Swizzor.cn

    C:\Program Files\Norton AntiVirus\Quarantine\0EC9050C Infected: Trojan-Downloader.Win32.Swizzor.bz

    C:\Program Files\Norton AntiVirus\Quarantine\14D36324.txt Infected: Backdoor.Perl.Shellbot.a

    C:\Program Files\Norton AntiVirus\Quarantine\1DEA418C Infected: Trojan-Downloader.Win32.Swizzor.bz

    C:\Program Files\Norton AntiVirus\Quarantine\250B1388 Infected: Trojan-Downloader.Win32.Swizzor.bz

    C:\Program Files\Norton AntiVirus\Quarantine\26507311 Infected: Trojan-Downloader.Win32.Swizzor.cb

    C:\Program Files\Norton AntiVirus\Quarantine\2E3E5597.class Infected: Exploit.Java.Bytverify

    C:\Program Files\Norton AntiVirus\Quarantine\2E3E5597.htm Infected: Exploit.VBS.Phel.a

    C:\Program Files\Norton AntiVirus\Quarantine\2E633A02.class Infected: Trojan.Java.ClassLoader.c

    C:\Program Files\Norton AntiVirus\Quarantine\2E6663FE.class Infected: Trojan.Java.ClassLoader.Dummy.a

    C:\Program Files\Norton AntiVirus\Quarantine\2E6663FE.htm Infected: Exploit.VBS.Phel.a

    C:\Program Files\Norton AntiVirus\Quarantine\2E6663FE.zip/GetAccess.class Infected: Trojan.Java.ClassLoader.c

    C:\Program Files\Norton AntiVirus\Quarantine\2E6663FE.zip/InsecureClassLoader.class Infected: Exploit.Java.Bytverify

    C:\Program Files\Norton AntiVirus\Quarantine\2E6663FE.zip/Dummy.class Infected: Trojan.Java.ClassLoader.Dummy.a

    C:\Program Files\Norton AntiVirus\Quarantine\2E6663FE.zip/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.v

    C:\Program Files\Norton AntiVirus\Quarantine\2E6663FE.zip Infected: Trojan-Downloader.Java.OpenConnection.v

    C:\Program Files\Norton AntiVirus\Quarantine\2FEB6852.htm Infected: Exploit.VBS.Phel.a

    C:\Program Files\Norton AntiVirus\Quarantine\34A8754A Infected: Trojan-Downloader.Win32.Swizzor.bz

    C:\Program Files\Norton AntiVirus\Quarantine\34AB1F46 Infected: Trojan-Downloader.Win32.Swizzor.bo

    C:\Program Files\Norton AntiVirus\Quarantine\34AE4942 Infected: Trojan-Downloader.Win32.Swizzor.cn

    C:\Program Files\Norton AntiVirus\Quarantine\34B51D3B Infected: Trojan-Downloader.Win32.Swizzor.bz

    C:\Program Files\Norton AntiVirus\Quarantine\34BB7134 Infected: Trojan-Downloader.Win32.Swizzor.cn

    C:\Program Files\Norton AntiVirus\Quarantine\34BF1B30 Infected: Trojan-Downloader.Win32.Swizzor.bz

    C:\Program Files\Norton AntiVirus\Quarantine\34C2452D Infected: Trojan-Downloader.Win32.Swizzor.bz

    C:\Program Files\Norton AntiVirus\Quarantine\3D716B0E Infected: Trojan-Downloader.Win32.Swizzor.bo

    C:\Program Files\Norton AntiVirus\Quarantine\6C185110 Infected: Trojan-Downloader.Win32.Swizzor.cn

    C:\Program Files\Norton AntiVirus\Quarantine\75A03235 Infected: Trojan-Downloader.Win32.Swizzor.bz

    D:\Documenten en Settings\All Users.WINDOWS\Application Data\clock ref jump sign\bolt name.exe Infected: Trojan.Win32.Krepper.ab

    D:\Documenten en Settings\Dennis\Local Settings\Temp\68b8c921.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\6acf525c.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\6ad4a2e8.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\6b07d4ed.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\6b64d524.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\6e60bb2d.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\7028c1ff.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\7279ce4e.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\755fdadb.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\75bba295.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\7793e226.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\79a5889a.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\7a3abe17.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\7bfa2d72.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\7c8bc6b9.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\7eddf8fc.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\7f116ad9.exe Infected: Trojan-Downloader.Win32.Swizzor.bk

    D:\Documenten en Settings\Dennis\Local Settings\Temp\Rem6FA.exe Suspicious: Type_Win32

    D:\Documenten en Settings\Dennis\Local Settings\Temp\sta473.exe Infected: Trojan-Downloader.Win32.Swizzor.bi

    D:\Documenten en Settings\Dennis\Local Settings\Temp\sta56C.exe Infected: Trojan-Downloader.Win32.Swizzor.bi

    D:\Documenten en Settings\Dennis\Local Settings\Temp\sta573.exe Infected: Trojan-Downloader.Win32.Swizzor.bi

    D:\Documenten en Settings\Dennis\Local Settings\Temp\sta587.exe Infected: Trojan-Downloader.Win32.Swizzor.bi

    D:\Documenten en Settings\Dennis\Local Settings\Temp\sta8FA.exe Infected: Trojan-Downloader.Win32.Swizzor.aw

    D:\Documenten en Settings\Dennis\Local Settings\Temp\staAE6.exe Infected: Trojan-Downloader.Win32.Swizzor.bi

    D:\Documenten en Settings\Dennis\Local Settings\Temp\Temporary Internet Files\Content.IE5\QHGBALU5\index2.htm Infected: Trojan-Dropper.Win32.RunMe

    D:\Documenten en Settings\Dennis\Local Settings\Temp\Temporary Internet Files\Content.IE5\QHGBALU5\index.htm Infected: Trojan-Dropper.Win32.RunMe

    D:\Documenten en Settings\Dennis\Local Settings\Temp\UpdatedUpdaterInstall.exe/data0002/data0003 Infected: Trojan-Downloader.Win32.Keenval

    D:\Documenten en Settings\Dennis\Local Settings\Temp\UpdatedUpdaterInstall.exe/data0002/data0004 Infected: Trojan-Downloader.Win32.Keenval

    D:\Documenten en Settings\Dennis\Local Settings\Temp\UpdatedUpdaterInstall.exe/data0002/data0005 Infected: Trojan-Downloader.Win32.Keenval

    D:\Documenten en Settings\Dennis\Local Settings\Temp\UpdatedUpdaterInstall.exe/data0002 Infected: Trojan-Downloader.Win32.Keenval

    D:\Documenten en Settings\Dennis\Local Settings\Temp\UpdatedUpdaterInstall.exe/data0008 Infected: Trojan-Downloader.Win32.Keenval.f

    D:\Documenten en Settings\Dennis\Local Settings\Temp\UpdatedUpdaterInstall.exe/data0009/data0003 Infected: Trojan-Downloader.Win32.Keenval.f

    D:\Documenten en Settings\Dennis\Local Settings\Temp\UpdatedUpdaterInstall.exe/data0009 Infected: Trojan-Downloader.Win32.Keenval.f

    D:\Documenten en Settings\Dennis\Local Settings\Temp\UpdatedUpdaterInstall.exe Infected: Trojan-Downloader.Win32.Keenval.f

    D:\Documenten en Settings\Gebruiker\Local Settings\Temp\gdjhclal.htm Infected: Trojan.JS.Pooter.b

    D:\Documenten en Settings\Gebruiker\Local Settings\Temp\mplbgpek.htm Infected: Trojan.JS.Pooter.b

    D:\Documenten en Settings\gebruiker.YOUR-OP32140JPF\Application Data\tons start joy\Trust Blue Plan Global.exe Infected: Trojan-Downloader.Win32.Swizzor.ca

    D:\System Volume Information\_restore{D855C4FE-7C37-4491-8D01-595A6E8DF93A}\RP511\A0075530.exe Infected: Trojan-Downloader.Win32.Swizzor.bb

    Scan process completed.