Kan iemand dit eens bekijken?

  • Kevander

    Dag iedereen

    Al een paar weken start mijn computer verschrikkelijk traag op (15min.) en afsluiten duurt ook al 5 tot 10min.

    Ik kreeg de laatste 2 dagen ook al virusmeldingen (Trojan met hoog risiconiveau).

    1 bestand, 1 browsercache

    c:\system volume information\_restore{…..\….\….exe)

    —————-

    Hijackthis

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 23:15:39, on 6/12/2009

    Platform: Windows XP SP3 (WinNT 5.01.2600)

    MSIE: Internet Explorer v8.00 (8.00.6001.18702)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    C:\Program Files\Bonjour\mDNSResponder.exe

    C:\Program Files\Java\jre6\bin\jqs.exe

    C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe

    C:\Program Files\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe

    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

    C:\WINDOWS\system32\svchost.exe

    C:\Program Files\Sony\VAIO Event Service\VESMgr.exe

    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe

    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe

    C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

    C:\Program Files\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\Apoint\Apoint.exe

    C:\WINDOWS\RTHDCPL.EXE

    C:\Program Files\Apoint\Apntex.exe

    C:\WINDOWS\system32\ICO.EXE

    C:\WINDOWS\system32\hkcmd.exe

    C:\WINDOWS\system32\igfxpers.exe

    C:\Program Files\Sony\VAIO Power Management\SPMgr.exe

    C:\Program Files\Sony\ISB Utility\ISBMgr.exe

    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

    C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe

    C:\Program Files\iTunes\iTunesHelper.exe

    C:\Program Files\Java\jre6\bin\jusched.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe

    C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe

    C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe

    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

    C:\Program Files\OpenOffice.org 3\program\soffice.exe

    C:\Program Files\iPod\bin\iPodService.exe

    C:\Program Files\OpenOffice.org 3\program\soffice.bin

    C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

    C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe

    C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe

    C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\Program Files\Java\jre6\bin\jucheck.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ui.skype.com/ui/0/2.0.0.73/nl/exitsurvey?

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen

    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.7.2.11\IPSBHO.DLL

    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

    O2 - BHO: Windows Live Aanmelden - Help - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll

    O2 - BHO: GoogleAFE - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\GoogleAFE.dll

    O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

    O4 - HKLM\..\Run: “C:\Program Files\Apoint\Apoint.exe”

    O4 - HKLM\..\Run: “RTHDCPL.EXE”

    O4 - HKLM\..\Run: “C:\Program Files\Realtek\InstallShield\AzMixerSel.exe”

    O4 - HKLM\..\Run: “ICO.EXE”

    O4 - HKLM\..\Run: “C:\WINDOWS\system32\igfxtray.exe”

    O4 - HKLM\..\Run: “C:\WINDOWS\system32\hkcmd.exe”

    O4 - HKLM\..\Run: “C:\WINDOWS\system32\igfxpers.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Sony\VAIO Power Management\SPMgr.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Sony\ISB Utility\ISBMgr.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe”

    O4 - HKLM\..\Run: “C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe” /Stationary

    O4 - HKLM\..\Run: “C:\Program Files\QuickTime\qttask.exe” -atboottime

    O4 - HKLM\..\Run: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

    O4 - HKLM\..\Run: “C:\Program Files\iTunes\iTunesHelper.exe”

    O4 - HKLM\..\Run: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

    O4 - HKLM\..\Run: “C:\Program Files\Java\jre6\bin\jusched.exe”

    O4 - HKCU\..\Run: C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: “C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe” /background

    O4 - HKCU\..\Run: “C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe” /NoDialog

    O4 - HKCU\..\Run: “C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe” -onlytray

    O4 - HKCU\..\Run: C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1

    O4 - HKCU\..\Run: “C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe”

    O4 - HKUS\S-1-5-18\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)

    O4 - HKUS\.DEFAULT\..\Run: C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)

    O4 - Startup: OneNote 2007 Schermopname en Snel starten.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

    O4 - Startup: OpenOffice.org 3.0 .lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe

    O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll

    O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll

    O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll

    O9 - Extra ‘Tools’ menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL

    O9 - Extra button: Unibet Poker - {C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - C:\Microgaming\Poker\UnibetpokerMPP\MPPoker.exe

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/en/

    O15 - Trusted Zone: *.sony-europe.com

    O15 - Trusted Zone: *.sonystyle-europe.com

    O15 - Trusted Zone: *.vaio-link.com

    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab

    O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/42.20/uploader2.cab

    O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.1.cab

    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab

    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab

    O16 - DPF: {6989C944-3529-4DA8-8C60-187E95F580E2} (SecureSession Class) - http://leeum.samsungfoundation.org/book/include/SecuiJoinsIE.cab

    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab

    O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://virusscanner.telenet.be/fscax.cab

    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab

    O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab

    O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5739/mcfscan.cab

    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

    O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

    O23 - Service: Google Update Service (gupdate1c98df4e8fa6852) (gupdate1c98df4e8fa6852) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe

    O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe

    O23 - Service: Norton AntiVirus - Symantec Corporation - C:\Program Files\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe

    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe

    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

    O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe

    O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe

    O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe

    O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe

    O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe

    O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe

    O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe

    O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe

    O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

    End of file - 14272 bytes

    Combofix log

    ComboFix 09-12-06.07 - Naam 06/12/2009 23:41.2.1 - x86

    Microsoft Windows XP Home Edition 5.1.2600.3.1252.31.1043.18.1014.357

    Gestart vanuit: c:\documents and settings\Naam\Bureaublad\ComboFix.exe

    AV: Norton AntiVirus *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}

    .

    (((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    c:\documents and settings\Naam\Menu Start\Programma's\Opstarten\OpenOffice.org 3.0 .lnk

    c:\windows\system32\twain_32.dll

    .

    (((((((((((((((((((( Bestanden Gemaakt van 2009-11-06 to 2009-12-06 ))))))))))))))))))))))))))))))

    .

    2009-12-06 22:19 . 2009-12-06 22:18 399872 —-a-w- c:\windows\system32\CF9335.exe

    2009-12-06 20:51 . 2009-12-06 20:52 ——– d—–w- c:\program files\Microsoft Web Designer Tools

    2009-12-06 17:06 . 2009-12-06 18:19 ——– d—–w- c:\windows\SxsCaPendDel

    2009-12-06 16:49 . 2009-09-22 08:00 259440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091206.005\ECMSVR32.DLL

    2009-12-06 16:49 . 2009-09-16 08:00 2747952 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091206.005\CCERASER.DLL

    2009-12-06 16:49 . 2009-08-27 08:00 371248 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091206.005\EECTRL.SYS

    2009-12-06 16:49 . 2009-08-27 08:00 102448 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091206.005\ERASER.SYS

    2009-12-06 16:49 . 2009-08-25 08:00 84912 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091206.005\NAVENG.SYS

    2009-12-06 16:49 . 2009-08-25 08:00 177520 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091206.005\NAVENG32.DLL

    2009-12-06 16:49 . 2009-08-25 08:00 1647984 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091206.005\NAVEX32A.DLL

    2009-12-06 16:49 . 2009-08-25 08:00 1323568 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091206.005\NAVEX15.SYS

    2009-12-01 19:08 . 2009-12-01 19:08 ——– d—–w- c:\documents and settings\Naam\advfn

    2009-11-28 17:34 . 2009-12-06 18:33 79488 —-a-w- c:\documents and settings\Naam\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll

    2009-11-17 15:43 . 2009-11-17 15:43 152576 —-a-w- c:\documents and settings\Naam\Application Data\Sun\Java\jre1.6.0_17\lzma.dll

    2009-11-12 22:28 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091111.001\Scxpx86.dll

    2009-11-12 22:28 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091111.001\IDSXpx86.sys

    2009-11-12 22:28 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091111.001\IDSxpx86.dll

    2009-11-12 22:28 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091111.001\IDSvix86.sys

    2009-11-12 22:28 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091111.001\IDSviA64.sys

    2009-11-11 21:40 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091107.001\Scxpx86.dll

    2009-11-11 21:40 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091107.001\IDSXpx86.sys

    2009-11-11 21:40 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091107.001\IDSxpx86.dll

    2009-11-11 21:40 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091107.001\IDSvix86.sys

    2009-11-11 21:40 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091107.001\IDSviA64.sys

    .

    ((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2009-12-06 21:15 . 2008-12-03 23:07 ——– d—–w- c:\documents and settings\All Users\Application Data\SMART Technologies

    2009-12-06 21:10 . 2006-03-01 14:14 ——– d–h–w- c:\program files\InstallShield Installation Information

    2009-12-06 21:03 . 2009-03-23 16:49 ——– d—–w- c:\program files\Lavasoft

    2009-12-06 21:03 . 2008-08-31 21:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft

    2009-12-06 21:03 . 2009-03-23 16:27 ——– dc-h–w- c:\documents and settings\All Users\Application Data\~0

    2009-12-06 20:52 . 2008-09-16 17:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help

    2009-12-06 20:16 . 2008-12-03 22:25 416 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\MSDN\9.0\1033\ResourceCache.dll

    2009-12-06 16:54 . 2008-08-31 23:03 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater

    2009-12-06 16:36 . 2006-03-01 16:45 ——– d—–w- c:\program files\Sony

    2009-12-06 16:22 . 2006-03-01 16:59 ——– d—–w- c:\documents and settings\All Users\Application Data\Sony Corporation

    2009-12-06 14:37 . 2006-03-01 16:47 ——– d—–w- c:\program files\Common Files\Adobe

    2009-11-29 21:04 . 2009-09-15 09:53 ——– d—–w- c:\documents and settings\Naam\Application Data\Download Manager

    2009-11-05 02:57 . 2009-11-01 01:37 205784 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

    2009-11-05 02:21 . 2008-11-05 20:11 ——– d—–w- c:\documents and settings\Naam\Application Data\FileZilla

    2009-10-28 22:37 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSvix86.sys

    2009-10-28 22:37 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSXpx86.sys

    2009-10-28 22:37 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\Scxpx86.dll

    2009-10-28 22:37 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSxpx86.dll

    2009-10-28 22:37 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSviA64.sys

    2009-10-25 08:47 . 2006-03-01 02:56 99612 —-a-w- c:\windows\system32\perfc013.dat

    2009-10-25 08:47 . 2006-03-01 02:56 530248 —-a-w- c:\windows\system32\perfh013.dat

    2009-10-06 09:52 . 2008-12-09 15:37 1 —-a-w- c:\documents and settings\Naam\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys

    2009-10-05 16:08 . 2009-03-23 18:31 15688 —-a-w- c:\windows\system32\lsdelete.exe

    2009-09-11 14:20 . 2006-03-01 02:55 136192 —-a-w- c:\windows\system32\msv1_0.dll

    2009-09-11 08:31 . 2008-12-06 14:09 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL

    2009-09-11 08:31 . 2008-12-06 14:09 124976 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS

    2009-09-10 20:38 . 2008-09-01 14:55 77528 —-a-w- c:\documents and settings\Naam\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

    .

    ((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

    REGEDIT4

    “updateMgr”=“c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1”

    “MsnMsgr”=“c:\program files\Windows Live\Messenger\MsnMsgr.Exe”

    “Nokia.PCSync”=“c:\program files\Nokia\Nokia PC Suite 7\PCSync2.exe”

    “PC Suite Tray”=“c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe”

    “swg”=“c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe”

    “VAIO Update 4”=“c:\program files\Sony\VAIO Update 4\VAIOUpdt.exe ”

    “Apoint”=“c:\program files\Apoint\Apoint.exe”

    “RTHDCPL”=“RTHDCPL.EXE”

    “AzMixerSel”=“c:\program files\Realtek\InstallShield\AzMixerSel.exe”

    “Mouse Suite 98 Daemon”=“ICO.EXE”

    “igfxtray”=“c:\windows\system32\igfxtray.exe”

    “igfxhkcmd”=“c:\windows\system32\hkcmd.exe”

    “igfxpers”=“c:\windows\system32\igfxpers.exe”

    “SonyPowerCfg”=“c:\program files\Sony\VAIO Power Management\SPMgr.exe”

    “ISBMgr.exe”=“c:\program files\Sony\ISB Utility\ISBMgr.exe”

    “GrooveMonitor”=“c:\program files\Microsoft Office\Office12\GrooveMonitor.exe”

    “QuickTime Task”=“c:\program files\QuickTime\qttask.exe”

    “iTunesHelper”=“c:\program files\iTunes\iTunesHelper.exe”

    “AppleSyncNotifier”=“c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe”

    “SunJavaUpdateSched”=“c:\program files\Java\jre6\bin\jusched.exe”

    “CTFMON.EXE”=“c:\windows\system32\CTFMON.EXE”

    c:\documents and settings\Naam\Menu Start\Programma's\Opstarten\

    OneNote 2007 Schermopname en Snel starten.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE

    2005-05-20 16:42 73728 —-a-w- c:\windows\system32\VESWinlogon.dll

    @=“FSFilter Activity Monitor”

    “DisableMonitoring”=dword:00000001

    “DisableMonitoring”=dword:00000001

    “DisableMonitoring”=dword:00000001

    “%windir%\\system32\\sessmgr.exe”=

    “%windir%\\Network Diagnostic\\xpnetdiag.exe”=

    “c:\\Program Files\\LimeWire\\LimeWire.exe”=

    “c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE”=

    “c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE”=

    “c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE”=

    “c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe”=

    “c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe”=

    “c:\\Program Files\\QuickTime\\QuickTimePlayer.exe”=

    “c:\\Program Files\\Bonjour\\mDNSResponder.exe”=

    “c:\\WINDOWS\\system32\\dpvsetup.exe”=

    “c:\\Program Files\\iTunes\\iTunes.exe”=

    “12001:UDP”= 12001:UDP:SMART WebServer Handshake Multicast Port

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys

    R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1007020.00B\SymEFA.sys

    R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NAV\1007020.00B\BHDrvx86.sys

    R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1007020.00B\cchpx86.sys

    R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091111.001\IDSXpx86.sys

    R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB –> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB

    R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe

    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys

    S2 gupdate1c98df4e8fa6852;Google Update Service (gupdate1c98df4e8fa6852);c:\program files\Google\Update\GoogleUpdate.exe

    S3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter;\??\c:\docume~1\KEVINV~1\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsgk.sys –> c:\docume~1\KEVINV~1\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsgk.sys

    S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB –> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB

    — Andere Services/Drivers In Geheugen —

    *NewlyCreated* - OSE

    .

    ——- Bijkomende Scan ——-

    .

    uStart Page = hxxp://www.google.be/

    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8

    uInternet Connection Wizard,ShellNext = hxxp://ui.skype.com/ui/0/2.0.0.73/nl/exitsurvey?

    uInternet Settings,ProxyOverride = *.local

    IE: E&xporteren naar Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000

    IE: {{C53BFCFC-7A54-4627-AEBA-2CD4871FCA97} - c:\microgaming\Poker\UnibetpokerMPP\MPPoker.exe

    Trusted Zone: sony-europe.com

    Trusted Zone: sonystyle-europe.com

    Trusted Zone: vaio-link.com

    DPF: {6989C944-3529-4DA8-8C60-187E95F580E2} - hxxp://leeum.samsungfoundation.org/book/include/SecuiJoinsIE.cab

    .

    - - - - ORPHANS VERWIJDERD - - - -

    HKLM-Run-Ad-Watch - c:\program files\Lavasoft\Ad-Aware\AAWTray.exe

    SafeBoot-Lavasoft Ad-Aware Service

    AddRemove-HijackThis - c:\documents and settings\Naam\Local Settings\Temporary Internet Files\Content.IE5\L9CWMV7L\HijackThis.exe

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

    Rootkit scan 2009-12-07 00:04

    Windows 5.1.2600 Service Pack 3 NTFS

    scannen van verborgen processen …

    scannen van verborgen autostart items …

    scannen van verborgen bestanden …

    Scan succesvol afgerond

    verborgen bestanden: 0

    **************************************************************************

    “ImagePath”=“\”c:\program files\Norton AntiVirus\Engine\16.7.2.11\ccSvcHst.exe\“ /s \”Norton AntiVirus\“ /m \”c:\program files\Norton AntiVirus\Engine\16.7.2.11\diMaster.dll\“ /prefetch:1”

    .

    ——————— DLLs Geladen Onder Lopende Processen ———————

    - - - - - - - > ‘winlogon.exe’(1284)

    c:\windows\system32\VESWinlogon.dll

    .

    Voltooingstijd: 2009-12-07 00:11

    ComboFix-quarantined-files.txt 2009-12-06 23:10

    ComboFix2.txt 2009-02-23 00:04

    Pre-Run: 2.716.930.048 bytes beschikbaar

    Post-Run: 5.912.367.104 bytes beschikbaar

    - - End Of File - - 5390244C9B5B61894F7DC044FD7C8173

  • Kevander

    Iemand even tijd?

  • dick

    installeer trojanhunter5.0.deze verwijderd de geinfecteerde bestanden.