This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] please help me cleaning my computer

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hello,
This is the second time i'm asking for help on this forum.
First time you really helped me solving the problems.
This time it is an simulair problem, but i do not know if i can solve it following the same instructions.

My startpage have changed, and a securitytoolbar is added on my browser called: security toolbar 7.1
Also litle windows are popping up one after the other with the following text:
1)Systemalert:malware threats
2) security alert: networm-i.virus
3) system performance monitor warning
4)security alert : spyware found
By clicking the balloons they offer me the solution for this problems!!!

here is the hijack log:
Logfile of HijackThis v1.99.1
Scan saved at 23:59:28, on 12-11-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\Mixer.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\WINDOWS\Fonts\svchost.exe
C:\WINDOWS\Fonts\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\WINDOWS\twain_32\A4CIS\WATCH.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Symantec Shared\NMain.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
G:\pre-program setup\hyjackthis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\mkxezdhh.dll
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\NEOSTR~1\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [Host Process] C:\WINDOWS\Fonts\svchost.exe
O4 - HKLM\..\Run: [d8d262ff] rundll32.exe "C:\WINDOWS\system32\tjvneptb.dll",b
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - Startup: Watch.lnk = C:\WINDOWS\twain_32\A4CIS\WATCH.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1191395562156
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://przedsionek.spaces.live.com/PhotoUpload/MsnPUpld.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{265DA8DA-DB25-4157-BAF9-842FB54BE0F8}: NameServer = 194.204.159.1 217.98.63.164
O17 - HKLM\System\CS1\Services\Tcpip\..\{265DA8DA-DB25-4157-BAF9-842FB54BE0F8}: NameServer = 194.204.159.1 217.98.63.164
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

best regards Ruud
Hi! Welcome to the WTT forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient.

Rename HijackThis
There is a possibility an infection which is hiding part of the HijackThis log because it's called hijackthis.exe.
Please rename hijackthis.exe to iseeu.exe by right-clicking on the Desktop icon and selecting Rename.

Now scan again and post a new log, please.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.
hello scotty, thank you for helping me. I did as you sugested and made an conection to my desktop, then changed the name in iseeu.exe. after the window from hijack appeared i opend the uninstal manager. a list appeared on the left side of the window, however clicking on save did not open an notepad but removed the hole window and i was back on my desktop. I tried it severall times but with the same results.I was not be able to kopy and save the list. Best regards Ruud
Hello scotty,
Today i made some scans with avg and ad-aware, they both found some errors and suspicious files wich were deleted.
I could close the security toolbar ,using the option in my browser.
I have no longer the anoying balloons popping up.
So can you have a look at the log file to see if my computer is save again?

Could it be that i'am missing some important files to play the on-line game enemy territory?
Everytime I open this game it looks like everyting works as it used to be, but after 10 second the game closed with the notice that a fealure has occured in ET.


Logfile of HijackThis v1.99.1
Scan saved at 17:56:57, on 13-11-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\Mixer.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\WINDOWS\Fonts\svchost.exe
C:\WINDOWS\Fonts\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\WINDOWS\twain_32\A4CIS\WATCH.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\OPScan.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Messenger\msmsgs.exe
G:\pre-program setup\hyjackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\NEOSTR~1\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [Host Process] C:\WINDOWS\Fonts\svchost.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [d8d262ff] rundll32.exe "C:\WINDOWS\system32\xhqhhcsr.dll",b
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\RunOnce: [Index Washer] C:\Program Files\Webroot\Washer\WashIdx.exe "ruud"
O4 - Startup: Watch.lnk = C:\WINDOWS\twain_32\A4CIS\WATCH.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1191395562156
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://przedsionek.spaces.live.com/PhotoUpload/MsnPUpld.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{265DA8DA-DB25-4157-BAF9-842FB54BE0F8}: NameServer = 194.204.159.1 217.98.63.164
O17 - HKLM\System\CS1\Services\Tcpip\..\{265DA8DA-DB25-4157-BAF9-842FB54BE0F8}: NameServer = 194.204.159.1 217.98.63.164
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\xhmtbmbs.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
Hi

You still have some baddies there.

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back in your next reply.


Download and Save ComboFix
  • Download this file from below:

    Here
  • Save it to your Desktop.
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.
hello Scotty,

here are the logs:

1) log combo fix:
ComboFix 07-11-08.3 - ruud 2007-11-13 22:17:30.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.48.1043.18.426 [GMT 1:00]
Gestart vanuit: C:\Documents and Settings\ruud\Bureaublad\ComboFix.exe
* Nieuw herstelpunt werd aangemaakt
.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users.WINDOWS\Menu Start\Live Safety Center.lnk
C:\Documents and Settings\All Users.WINDOWS\Menu Start\Online Security Guide.lnk
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\mkxezdhh.dllbox

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_DOMAINSERVICE
——-\DomainService


(((((((((((((((((((( Bestanden Gemaakt van 2007-10-13 to 2007-11-13 ))))))))))))))))))))))))))))))
.

2007-11-13 22:15 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-11-13 22:02 d——– C:\WINDOWS\ERUNT
2007-11-13 19:27 d——– C:\Documents and Settings\ruud\Application Data\Talkback
2007-11-13 19:27 2,810 –a—— C:\WINDOWS\mozver.dat
2007-11-13 10:36 88,128 –a—— C:\WINDOWS\system32\xhqhhcsr.dll
2007-11-13 10:33 71,232 –a—— C:\WINDOWS\system32\lqulsack.exe
2007-11-13 09:46 3,846 –a—— C:\WINDOWS\system32\tmp.reg
2007-11-13 09:40 71,232 –a—— C:\WINDOWS\system32\owtgvuax.exe
2007-11-13 08:30 80,448 –a—— C:\WINDOWS\system32\qjnpsvbv.dll
2007-11-12 22:59 d——– C:\Documents and Settings\ruud\Application Data\Grisoft
2007-11-12 22:58 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-12 22:57 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
2007-11-12 20:12 89,664 –a—— C:\WINDOWS\system32\tjvneptb.dll
2007-11-12 20:09 81,472 –a—— C:\WINDOWS\system32\ptmmqmaw.dll
2007-11-12 20:03 145,984 –a—— C:\WINDOWS\system32\hluvpgib.dll
2007-11-12 20:03 98,138 —hs—- C:\WINDOWS\system32\rrqss.bak2
2007-11-12 19:54 104,497 —hs—- C:\WINDOWS\system32\rrqss.ini2
2007-11-12 09:26 d——– C:\Incomplete
2007-11-12 09:26 d——– C:\Documents and Settings\ruud\Application Data\LimeWirePlus
2007-11-12 09:25 d——– C:\Program Files\LimeWire Plus
2007-11-12 08:50 d——– C:\WINDOWS\system32\NtmsData
2007-11-12 08:03 6,465 —hs—- C:\WINDOWS\system32\rrqss.bak1
2007-11-11 23:59 d——– C:\MFT 5555
2007-11-11 23:59 d——– C:\MFT 2540
2007-11-11 16:24 d——– C:\Program Files\Incomplete
2007-11-11 16:23 147,456 –a—— C:\WINDOWS\system32\vbzip10.dll
2007-11-11 16:18 d-a—— C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2007-11-10 20:49 d——– C:\Program Files\LimeWire
2007-11-10 20:49 d——– C:\Documents and Settings\ruud\Application Data\LimeWire
2007-11-04 21:14 d——– C:\Program Files\Common Files\SureThing Shared
2007-11-04 21:14 2,560 ——— C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-11-04 21:14 2,432 ——— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-11-04 19:47 237,568 –a—— C:\WINDOWS\system32\xvidvfw.dll
2007-11-04 19:40 d——– C:\Program Files\Yahoo!
2007-11-04 19:40 d——– C:\Program Files\illiminable
2007-11-04 19:40 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\YAHOO
2007-11-03 20:20 d——– C:\Program Files\Total Video Converter
2007-11-02 15:23 d——– C:\Program Files\Mozilla Thunderbird
2007-11-02 15:23 d——– C:\Documents and Settings\ruud\Application Data\Thunderbird
2007-11-02 15:23 335 –a—— C:\WINDOWS\nsreg.dat
2007-11-01 22:35 d——– C:\Program Files\eMule
2007-10-29 21:07 d——– C:\Program Files\UnderCoverXP
2007-10-29 20:09 d——– C:\Program Files\SlySoft
2007-10-29 20:01 d——– C:\Program Files\Elaborate Bytes
2007-10-25 23:10 552 –a—— C:\WINDOWS\system32\d3d8caps.dat
2007-10-24 20:21 d——– C:\Program Files\DSL Speed
2007-10-23 17:08 d——– C:\Program Files\SMAC
2007-10-23 07:06 d——– C:\Program Files\AvantGo Connect
2007-10-23 07:05 d——– C:\Program Files\Microsoft ActiveSync
2007-10-23 07:05 114,688 –a—— C:\WINDOWS\system32\MALSLIB.DLL
2007-10-23 07:05 65,613 –a—— C:\WINDOWS\system32\PPVEXP.DLL
2007-10-23 07:05 24,652 –a—— C:\WINDOWS\system32\UICOM.DLL
2007-10-22 23:06 d——– C:\Program Files\Windows Media Connect 2
2007-10-22 23:06 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2007-10-22 23:04 d——– C:\WINDOWS\system32\drivers\UMDF

.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-13 20:17 ——— d—–w C:\Documents and Settings\ruud\Application Data\MailWasherPro
2007-11-13 18:23 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-11-12 11:11 ——— d—–w C:\Documents and Settings\ruud\Application Data\ACD Systems
2007-11-12 11:07 ——— d—–w C:\Program Files\Norton SystemWorks
2007-11-12 08:39 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-11-12 07:34 ——— d—–w C:\Program Files\Wolfenstein - Enemy Territory
2007-11-11 20:05 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\TuneUp Software
2007-11-10 20:03 ——— d—–w C:\Program Files\Java
2007-11-08 11:20 ——— d—–w C:\Program Files\Weather Watcher
2007-11-06 16:21 ——— d—–w C:\Program Files\TuneUp Utilities 2007
2007-11-04 18:47 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-04 18:47 ——— d—–w C:\Program Files\Thomson
2007-10-26 17:14 ——— d—–w C:\Documents and Settings\ruud\Application Data\Apple Computer
2007-10-13 10:00 ——— d—–w C:\Program Files\Neostrada TP
2007-10-12 21:29 ——— d—–w C:\Program Files\Folder Lock
2007-10-12 21:26 308 —-a-w C:\sccfg.sys
2007-10-11 06:42 ——— d—–w C:\Program Files\Real
2007-10-11 06:42 ——— d—–w C:\Program Files\Common Files\xing shared
2007-10-11 06:42 ——— d—–w C:\Program Files\Common Files\Real
2007-10-10 07:07 31,096 —-a-w C:\Documents and Settings\ruud\Application Data\GDIPFONTCACHEV1.DAT
2007-10-10 06:06 ——— d—–w C:\Program Files\QuickTime
2007-10-07 20:51 ——— d—–w C:\Program Files\MSN Messenger
2007-10-07 20:11 ——— d—–w C:\Program Files\Common Files\Java
2007-10-04 22:22 ——— d—–w C:\Program Files\iPhoto Plus 4
2007-10-04 22:19 ——— d—–w C:\Program Files\TextBridge Classic
2007-10-04 22:17 ——— d—–w C:\Program Files\Trust
2007-10-04 22:04 ——— d—–w C:\Documents and Settings\ruud\Application Data\CyberLink
2007-10-04 22:02 ——— d—–w C:\Program Files\CyberLink
2007-10-04 22:02 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\CyberLink
2007-10-04 21:54 ——— d—–w C:\Program Files\iTunes
2007-10-04 21:54 ——— d—–w C:\Program Files\iPod
2007-10-04 21:54 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple Computer
2007-10-04 21:53 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-10-04 21:50 ——— d—–w C:\Program Files\DivX
2007-10-03 21:27 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\nView_Profiles
2007-10-03 20:54 ——— d—–w C:\Program Files\The All-Seeing Eye
2007-10-03 07:17 ——— d—–w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-10-01 06:50 ——— d—–w C:\Program Files\Uniblue
2007-10-01 06:50 ——— d—–w C:\Documents and Settings\ruud\Application Data\Uniblue
2007-09-29 17:56 ——— d—–w C:\Documents and Settings\ruud\Application Data\InternetCalls
2007-09-29 17:53 ——— d—–w C:\Program Files\InternetCalls.com
2007-09-28 20:42 ——— d—–w C:\Program Files\Codec Pack - All In 1
2007-09-28 14:15 ——— d—–w C:\Program Files\Common Files\Adobe
2007-09-28 10:33 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\avg7
2007-09-28 06:00 ——— d—–w C:\Documents and Settings\ruud\Application Data\AVG7
2007-09-27 21:21 ——— d—–w C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\AVG7
2007-09-27 21:07 ——— d—–w C:\Program Files\Common Files\Webroot Shared
2007-09-27 21:07 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Webroot
2007-09-27 20:05 ——— d—–w C:\Documents and Settings\ruud\Application Data\Symantec
2007-09-27 18:10 ——— d—–w C:\Program Files\PCI Audio Applications
2007-09-27 18:08 ——— d—–w C:\Program Files\ASUS
2007-09-27 18:05 ——— d—–w C:\Program Files\C-Media
2007-09-27 18:01 ——— d—–w C:\Documents and Settings\ruud\Application Data\InterTrust
2007-09-27 17:57 ——— d—–w C:\Documents and Settings\ruud\Application Data\PoivY
2007-09-27 17:31 ——— d—–w C:\Program Files\Webroot
2007-09-27 17:31 ——— d—–w C:\Documents and Settings\ruud\Application Data\Webroot
2007-09-27 17:19 737,280 —-a-w C:\WINDOWS\iun6002.exe
2007-09-27 16:08 ——— d—–w C:\Program Files\Common Files\ACD Systems
2007-09-27 16:08 ——— d—–w C:\Program Files\ACD Systems
2007-09-27 16:08 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\ACD Systems
2007-09-27 12:56 ——— d—–w C:\Documents and Settings\ruud\Application Data\TuneUp Software
2007-09-27 12:55 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-09-27 11:13 ——— d—–w C:\Program Files\FireTrust
2007-09-27 10:48 ——— d—–w C:\Program Files\Lavasoft
2007-09-27 10:46 ——— d—–w C:\Documents and Settings\ruud\Application Data\Lavasoft
2007-09-27 07:10 ——— d—–w C:\Program Files\SymNetDrv
2007-09-27 07:10 ——— d—–w C:\Program Files\Symantec
2007-09-27 06:52 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec
2007-09-27 06:47 4,608 —-a-w C:\WINDOWS\system32\drivers\symlcbrd.sys
2007-09-26 22:15 ——— d—–w C:\Program Files\microsoft frontpage
2007-09-05 13:43 69,960 —-a-w C:\WINDOWS\Unwash6.exe
2006-02-17 09:02 233,472 —ha-w C:\Documents and Settings\NetworkService.ZARZąDZANIE NT\NTUSER.DAT
2006-02-17 09:02 233,472 —ha-w C:\Documents and Settings\LocalService.ZARZąDZANIE NT\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{01CD0B31-9154-45F2-9414-F5D64B74EAF6}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3EC00D5E-ECA1-4990-ACC5-C50DD8895751}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 10:38]
"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [2003-10-16 18:07]
"WOOTASKBARICON"="C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe" [2003-10-16 18:07]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 16:32]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-09-27 08:10]
"C-Media Mixer"="Mixer.exe" [2001-10-22 18:24 C:\WINDOWS\mixer.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:03 C:\WINDOWS\system32\bthprops.cpl]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-10-29 15:50]
"nwiz"="nwiz.exe" [2004-10-29 15:50 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2004-10-29 15:50]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2005-10-18 10:58]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 16:35]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"CloneDVDElbyDelay"="C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" [2002-11-02 07:33]
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [2005-05-19 14:47]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-11 07:41]
"d8d262ff"="C:\WINDOWS\system32\xhqhhcsr.dll" [2007-11-13 10:36]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Norton SystemWorks"="C:\Program Files\Norton SystemWorks\cfgwiz.exe" [2004-09-10 03:12]
"Window Washer"="C:\Program Files\Webroot\Washer\wwDisp.exe" [2007-09-05 14:43]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:03]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 13:39]

C:\Documents and Settings\ruud\Menu Start\Programma's\Opstarten\
Watch.lnk - C:\WINDOWS\twain_32\A4CIS\WATCH.exe [2007-10-04 23:17:39]

C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programma's\Opstarten\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 09:01:04]
ZoneAlarm Pro.lnk - C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe [2007-09-27 13:38:07]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mkxezdhh]
mkxezdhh.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tuvutsr]
tuvutsr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

R2 ADPTEHCD;%ADPT_USBEHCD.DeviceDesc%;C:\WINDOWS\system32\DRIVERS\asusehcd.sys
R2 AUSBD_FilterService;AUSBD Filter Service;C:\WINDOWS\system32\DRIVERS\asususbd.sys
R2 MA1908Driver;MA1908Driver;\??\C:\WINDOWS\system32\drivers\ma1908.sys
R2 UxTuneUp;TuneUp Thema-uitbreiding;C:\WINDOWS\System32\svchost.exe -k netsvcs
R2 wwEngineSvc;Window Washer Engine;C:\Program Files\Webroot\Washer\WasherSvc.exe
R3 ADPTHUBD;%ADPT_USBBHUBD.DeviceDesc%;C:\WINDOWS\system32\DRIVERS\asus2hub.sys
R3 NPDriver;Norton Unerase Protection Driver;\??\C:\WINDOWS\System32\Drivers\NPDRIVER.SYS
S3 SDdriver;SDdriver;\??\C:\WINDOWS\System32\Drivers\sddriver.sys

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

.
Inhoud van de 'Gedeelde Taken' map
"2007-11-09 18:31:21 C:\WINDOWS\Tasks\Easy Onderhoud.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2007-11-09 21:18:55 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - ruud.job"
- C:\PROGRA~1\NORTON~1\NORTON~3\Navw32.exe
"2007-11-12 11:07:38 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
"2007-11-12 23:00:00 C:\WINDOWS\Tasks\Symantec Drmc.job"
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-13 22:23:08
Windows 5.1.2600 Service Pack 2 NTFS

scannen van verborgen processen …

scannen van verborgen autostart items …

scannen van verborgen bestanden …

Scan succesvol afgerond
verborgen bestanden: 0

**************************************************************************
.
Voltooingstijd: 2007-11-13 22:25:50 - machine was rebooted
.
— E O F —

2) Log Sdfix :

SDFix: Version 1.114

Run by [removed] on di 13-11-2007 at 22:03

Microsoft Windows XP [versie 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\X.DAT - Deleted
C:\Z.DAT - Deleted
C:\n.bat - Deleted
C:\winlogon.exe - Deleted
C:\WINDOWS\Fonts\Crack.exe - Deleted
C:\WINDOWS\Fonts\svchost.exe - Deleted


Folder C:\WINDOWS\Fonts\' - Removed

Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-13 22:09:58
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0cbf011aeb]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0cbf011aeb]

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\InternetCalls.com\\InternetCalls\\InternetCalls.exe"="C:\\Program Files\\InternetCalls.com\\InternetCalls\\InternetCalls.exe:*:Enabled:InternetCalls"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\Yahoo!\\Yahoo! Music Engine\\YahooMusicEngine.exe"="C:\\Program Files\\Yahoo!\\Yahoo! Music Engine\\YahooMusicEngine.exe:*:Enabled:Yahoo! Music Engine"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\WINDOWS\\system32\\rloriwhu.exe"="C:\\WINDOWS\\system32\\rlo"
"C:\\WINDOWS\\system32\\xhmtbmbs.exe"="C:\\WINDOWS\\system32\\xhm"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

Remaining Files:
—————

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Tue 13 Nov 2007 20,640 ..SH. — "C:\WINDOWS\system32\mkxezdhh.dllbox"
Mon 12 Nov 2007 7,612 ..SH. — "C:\WINDOWS\system32\rrqss.tmp"
Mon 12 Nov 2007 6,465 ..SH. — "C:\WINDOWS\system32\rrqss.bak1"
Tue 13 Nov 2007 98,138 ..SH. — "C:\WINDOWS\system32\rrqss.bak2"
Fri 2 Nov 2007 4,348 A.SH. — "C:\Documents and Settings\All Users.WINDOWS\DRM\DRMv1.bak"
Mon 22 Oct 2007 0 A.SH. — "C:\Documents and Settings\All Users.WINDOWS\DRM\Cache\Indiv01.tmp"

Finished!

3) Log Hijackthis:

Logfile of HijackThis v1.99.1
Scan saved at 22:36:40, on 13-11-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\Mixer.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\WINDOWS\twain_32\A4CIS\WATCH.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\NOTEPAD.EXE
G:\pre-program setup\hyjackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL
O2 - BHO: (no name) - {01CD0B31-9154-45F2-9414-F5D64B74EAF6} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {3EC00D5E-ECA1-4990-ACC5-C50DD8895751} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\NEOSTR~1\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [d8d262ff] rundll32.exe "C:\WINDOWS\system32\xhqhhcsr.dll",b
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - Startup: Watch.lnk = C:\WINDOWS\twain_32\A4CIS\WATCH.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1191395562156
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://przedsionek.spaces.live.com/PhotoUpload/MsnPUpld.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{265DA8DA-DB25-4157-BAF9-842FB54BE0F8}: NameServer = 194.204.159.1 217.98.63.164
O17 - HKLM\System\CS1\Services\Tcpip\..\{265DA8DA-DB25-4157-BAF9-842FB54BE0F8}: NameServer = 194.204.159.1 217.98.63.164
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: mkxezdhh - mkxezdhh.dll (file missing)
O20 - Winlogon Notify: tuvutsr - tuvutsr.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

Best regards Ruud
Hi

Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

File::
C:\WINDOWS\system32\xhqhhcsr.dll
C:\WINDOWS\system32\lqulsack.exe
C:\WINDOWS\system32\owtgvuax.exe
C:\WINDOWS\system32\qjnpsvbv.dll
C:\WINDOWS\system32\tjvneptb.dll
C:\WINDOWS\system32\ptmmqmaw.dll
C:\WINDOWS\system32\hluvpgib.dll
C:\WINDOWS\system32\rrqss.bak2
C:\WINDOWS\system32\rrqss.ini2
C:\WINDOWS\system32\rrqss.bak1
C:\WINDOWS\system32\vbzip10.dll
C:\WINDOWS\iun6002.exe
C:\WINDOWS\system32\rloriwhu.exe
C:\WINDOWS\system32\mkxezdhh.dllbox
C:\WINDOWS\system32\rrqss.tmp

Folder::
C:\SDFix

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{01CD0B31-9154-45F2-9414-F5D64B74EAF6}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3EC00D5E-ECA1-4990-ACC5-C50DD8895751}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"d8d262ff"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mkxezdhh]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tuvutsr]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\system32\rloriwhu.exe"=-
"C:\WINDOWS\system32\xhmtbmbs.exe"=-

DirLook::
C:\MFT 5555
C:\MFT 2540
C:\WINDOWS\system32\rlo
C:\WINDOWS\system32\xhm

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log with a new HijackThis log.
good evening scotty, here are the logs:

1) log combo fix:

ComboFix 07-11-08.3 - ruud 2007-11-14 20:56:52.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.48.1043.18.457 [GMT 1:00]
Gestart vanuit: C:\Documents and Settings\ruud\Bureaublad\ComboFix.exe
Command switches used :: C:\Documents and Settings\ruud\Bureaublad\CFScript.txt
* Nieuw herstelpunt werd aangemaakt

FILE
C:\WINDOWS\iun6002.exe
C:\WINDOWS\system32\hluvpgib.dll
C:\WINDOWS\system32\lqulsack.exe
C:\WINDOWS\system32\mkxezdhh.dllbox
C:\WINDOWS\system32\owtgvuax.exe
C:\WINDOWS\system32\ptmmqmaw.dll
C:\WINDOWS\system32\qjnpsvbv.dll
C:\WINDOWS\system32\rloriwhu.exe
C:\WINDOWS\system32\rrqss.bak1
C:\WINDOWS\system32\rrqss.bak2
C:\WINDOWS\system32\rrqss.ini2
C:\WINDOWS\system32\rrqss.tmp
C:\WINDOWS\system32\tjvneptb.dll
C:\WINDOWS\system32\vbzip10.dll
C:\WINDOWS\system32\xhqhhcsr.dll
.

(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\SDFix
C:\SDFix\apps\assosfix.reg
C:\SDFix\apps\cliptext.exe
C:\SDFix\apps\download.exe
C:\SDFix\apps\dummy.sys
C:\SDFix\apps\Enable_Command_Prompt.reg
C:\SDFix\apps\ERDNT.E_E
C:\SDFix\apps\ERDNTDOS.LOC
C:\SDFix\apps\ERDNTWIN.LOC
C:\SDFix\apps\ERUNT.EXE
C:\SDFix\apps\ERUNT.LOC
C:\SDFix\apps\fix.reg
C:\SDFix\apps\FixBH.reg
C:\SDFix\apps\FIXCU.reg
C:\SDFix\apps\FIXLM.reg
C:\SDFix\apps\FixPath.exe
C:\SDFix\apps\FixRedir.reg
C:\SDFix\apps\FixWebCheck.reg
C:\SDFix\apps\fixXP.reg
C:\SDFix\apps\FixXPsp2.reg
C:\SDFix\apps\HPFix.reg
C:\SDFix\apps\HPFix2.reg
C:\SDFix\apps\HPFix3.reg
C:\SDFix\apps\HPFix4.reg
C:\SDFix\apps\isadmin.exe
C:\SDFix\apps\leg2.txt
C:\SDFix\apps\legacy.txt
C:\SDFix\apps\legacybk.txt
C:\SDFix\apps\locate.com
C:\SDFix\apps\LS.exe
C:\SDFix\apps\MD5File.exe
C:\SDFix\apps\moveex.exe
C:\SDFix\apps\MyGcpvFix.reg
C:\SDFix\apps\MyGkFix2.reg
C:\SDFix\apps\Process.exe
C:\SDFix\apps\procs.exe
C:\SDFix\apps\psservice.exe
C:\SDFix\apps\RegDACL.exe
C:\SDFix\apps\regedit.exe
C:\SDFix\apps\Rem.txt
C:\SDFix\apps\Rem2.txt
C:\SDFix\apps\Replace\W2K.exe
C:\SDFix\apps\Replace\w2k\null.sys
C:\SDFix\apps\Replace\XP.exe
C:\SDFix\apps\Replace\xp\null.sys
C:\SDFix\apps\Reset_AppInit_DLLs.reg
C:\SDFix\apps\RestartIt!.exe
C:\SDFix\apps\Restore_SecurityCenter.reg
C:\SDFix\apps\Restore_SharedAccess.reg
C:\SDFix\apps\sc.exe
C:\SDFix\apps\SF.exe
C:\SDFix\apps\shutdown.exe
C:\SDFix\apps\srv2.txt
C:\SDFix\apps\svc.txt
C:\SDFix\apps\svcbk.txt
C:\SDFix\apps\swreg.exe
C:\SDFix\apps\swsc.exe
C:\SDFix\apps\unzip.exe
C:\SDFix\apps\WINMSG.EXE
C:\SDFix\apps\zip.exe
C:\SDFix\backups\attrib.exe
C:\SDFix\backups\backupreg.zip
C:\SDFix\backups\backups.zip
C:\SDFix\backups\delzip6.txt
C:\SDFix\backups\find.exe
C:\SDFix\backups\findstr.exe
C:\SDFix\backups\HOSTS
C:\SDFix\backups\regedit.exe
C:\SDFix\catchme.exe
C:\SDFix\dummy.sys
C:\SDFix\Report.txt
C:\SDFix\RunThis.bat
C:\SDFix\SDFIX_ReadMe_Online.url
C:\SDFix\Thumbs.db
C:\WINDOWS\iun6002.exe
C:\WINDOWS\system32\hluvpgib.dll
C:\WINDOWS\system32\lqulsack.exe
C:\WINDOWS\system32\owtgvuax.exe
C:\WINDOWS\system32\ptmmqmaw.dll
C:\WINDOWS\system32\qjnpsvbv.dll
C:\WINDOWS\system32\rrqss.bak1
C:\WINDOWS\system32\rrqss.bak2
C:\WINDOWS\system32\rrqss.ini2
C:\WINDOWS\system32\rrqss.tmp
C:\WINDOWS\system32\tjvneptb.dll
C:\WINDOWS\system32\vbzip10.dll
C:\WINDOWS\system32\xhqhhcsr.dll

.
(((((((((((((((((((( Bestanden Gemaakt van 2007-10-14 to 2007-11-14 ))))))))))))))))))))))))))))))
.

2007-11-13 22:15 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-11-13 22:02 d——– C:\WINDOWS\ERUNT
2007-11-13 19:27 d——– C:\Documents and Settings\ruud\Application Data\Talkback
2007-11-13 19:27 2,810 –a—— C:\WINDOWS\mozver.dat
2007-11-13 09:46 3,846 –a—— C:\WINDOWS\system32\tmp.reg
2007-11-12 22:59 d——– C:\Documents and Settings\ruud\Application Data\Grisoft
2007-11-12 22:58 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-12 22:57 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
2007-11-12 09:26 d——– C:\Incomplete
2007-11-12 09:26 d——– C:\Documents and Settings\ruud\Application Data\LimeWirePlus
2007-11-12 09:25 d——– C:\Program Files\LimeWire Plus
2007-11-12 08:50 d——– C:\WINDOWS\system32\NtmsData
2007-11-11 23:59 d——– C:\MFT 5555
2007-11-11 23:59 d——– C:\MFT 2540
2007-11-11 16:24 d——– C:\Program Files\Incomplete
2007-11-11 16:18 d-a—— C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2007-11-10 20:49 d——– C:\Program Files\LimeWire
2007-11-10 20:49 d——– C:\Documents and Settings\ruud\Application Data\LimeWire
2007-11-04 21:14 d——– C:\Program Files\Common Files\SureThing Shared
2007-11-04 21:14 2,560 ——— C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-11-04 21:14 2,432 ——— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-11-04 19:47 237,568 –a—— C:\WINDOWS\system32\xvidvfw.dll
2007-11-04 19:40 d——– C:\Program Files\Yahoo!
2007-11-04 19:40 d——– C:\Program Files\illiminable
2007-11-04 19:40 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\YAHOO
2007-11-03 20:20 d——– C:\Program Files\Total Video Converter
2007-11-02 15:23 d——– C:\Program Files\Mozilla Thunderbird
2007-11-02 15:23 d——– C:\Documents and Settings\ruud\Application Data\Thunderbird
2007-11-02 15:23 335 –a—— C:\WINDOWS\nsreg.dat
2007-11-01 22:35 d——– C:\Program Files\eMule
2007-10-29 21:07 d——– C:\Program Files\UnderCoverXP
2007-10-29 20:09 d——– C:\Program Files\SlySoft
2007-10-29 20:01 d——– C:\Program Files\Elaborate Bytes
2007-10-25 23:10 552 –a—— C:\WINDOWS\system32\d3d8caps.dat
2007-10-24 20:21 d——– C:\Program Files\DSL Speed
2007-10-23 17:08 d——– C:\Program Files\SMAC
2007-10-23 07:06 d——– C:\Program Files\AvantGo Connect
2007-10-23 07:05 d——– C:\Program Files\Microsoft ActiveSync
2007-10-23 07:05 114,688 –a—— C:\WINDOWS\system32\MALSLIB.DLL
2007-10-23 07:05 65,613 –a—— C:\WINDOWS\system32\PPVEXP.DLL
2007-10-23 07:05 24,652 –a—— C:\WINDOWS\system32\UICOM.DLL
2007-10-22 23:06 d——– C:\Program Files\Windows Media Connect 2
2007-10-22 23:06 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2007-10-22 23:04 d——– C:\WINDOWS\system32\drivers\UMDF

.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-14 19:01 ——— d—–w C:\Documents and Settings\ruud\Application Data\MailWasherPro
2007-11-14 18:54 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-11-14 12:59 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-11-12 11:11 ——— d—–w C:\Documents and Settings\ruud\Application Data\ACD Systems
2007-11-12 11:07 ——— d—–w C:\Program Files\Norton SystemWorks
2007-11-12 07:34 ——— d—–w C:\Program Files\Wolfenstein - Enemy Territory
2007-11-11 20:05 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\TuneUp Software
2007-11-10 20:03 ——— d—–w C:\Program Files\Java
2007-11-08 11:20 ——— d—–w C:\Program Files\Weather Watcher
2007-11-06 16:21 ——— d—–w C:\Program Files\TuneUp Utilities 2007
2007-11-04 18:47 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-04 18:47 ——— d—–w C:\Program Files\Thomson
2007-10-26 17:14 ——— d—–w C:\Documents and Settings\ruud\Application Data\Apple Computer
2007-10-13 10:00 ——— d—–w C:\Program Files\Neostrada TP
2007-10-12 21:29 ——— d—–w C:\Program Files\Folder Lock
2007-10-12 21:26 308 —-a-w C:\sccfg.sys
2007-10-11 06:42 ——— d—–w C:\Program Files\Real
2007-10-11 06:42 ——— d—–w C:\Program Files\Common Files\xing shared
2007-10-11 06:42 ——— d—–w C:\Program Files\Common Files\Real
2007-10-10 07:07 31,096 —-a-w C:\Documents and Settings\ruud\Application Data\GDIPFONTCACHEV1.DAT
2007-10-10 06:06 ——— d—–w C:\Program Files\QuickTime
2007-10-07 20:51 ——— d—–w C:\Program Files\MSN Messenger
2007-10-07 20:11 ——— d—–w C:\Program Files\Common Files\Java
2007-10-04 22:22 ——— d—–w C:\Program Files\iPhoto Plus 4
2007-10-04 22:19 ——— d—–w C:\Program Files\TextBridge Classic
2007-10-04 22:17 ——— d—–w C:\Program Files\Trust
2007-10-04 22:04 ——— d—–w C:\Documents and Settings\ruud\Application Data\CyberLink
2007-10-04 22:02 ——— d—–w C:\Program Files\CyberLink
2007-10-04 22:02 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\CyberLink
2007-10-04 21:54 ——— d—–w C:\Program Files\iTunes
2007-10-04 21:54 ——— d—–w C:\Program Files\iPod
2007-10-04 21:54 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple Computer
2007-10-04 21:53 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-10-04 21:50 ——— d—–w C:\Program Files\DivX
2007-10-03 21:27 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\nView_Profiles
2007-10-03 20:54 ——— d—–w C:\Program Files\The All-Seeing Eye
2007-10-03 07:17 ——— d—–w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-10-01 06:50 ——— d—–w C:\Program Files\Uniblue
2007-10-01 06:50 ——— d—–w C:\Documents and Settings\ruud\Application Data\Uniblue
2007-09-29 17:56 ——— d—–w C:\Documents and Settings\ruud\Application Data\InternetCalls
2007-09-29 17:53 ——— d—–w C:\Program Files\InternetCalls.com
2007-09-28 20:42 ——— d—–w C:\Program Files\Codec Pack - All In 1
2007-09-28 14:15 ——— d—–w C:\Program Files\Common Files\Adobe
2007-09-28 10:33 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\avg7
2007-09-28 06:00 ——— d—–w C:\Documents and Settings\ruud\Application Data\AVG7
2007-09-27 21:21 ——— d—–w C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\AVG7
2007-09-27 21:07 ——— d—–w C:\Program Files\Common Files\Webroot Shared
2007-09-27 21:07 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Webroot
2007-09-27 20:05 ——— d—–w C:\Documents and Settings\ruud\Application Data\Symantec
2007-09-27 18:10 ——— d—–w C:\Program Files\PCI Audio Applications
2007-09-27 18:08 ——— d—–w C:\Program Files\ASUS
2007-09-27 18:05 ——— d—–w C:\Program Files\C-Media
2007-09-27 18:01 ——— d—–w C:\Documents and Settings\ruud\Application Data\InterTrust
2007-09-27 17:57 ——— d—–w C:\Documents and Settings\ruud\Application Data\PoivY
2007-09-27 17:31 ——— d—–w C:\Program Files\Webroot
2007-09-27 17:31 ——— d—–w C:\Documents and Settings\ruud\Application Data\Webroot
2007-09-27 16:08 ——— d—–w C:\Program Files\Common Files\ACD Systems
2007-09-27 16:08 ——— d—–w C:\Program Files\ACD Systems
2007-09-27 16:08 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\ACD Systems
2007-09-27 12:56 ——— d—–w C:\Documents and Settings\ruud\Application Data\TuneUp Software
2007-09-27 12:55 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-09-27 11:13 ——— d—–w C:\Program Files\FireTrust
2007-09-27 10:48 ——— d—–w C:\Program Files\Lavasoft
2007-09-27 10:46 ——— d—–w C:\Documents and Settings\ruud\Application Data\Lavasoft
2007-09-27 07:10 ——— d—–w C:\Program Files\SymNetDrv
2007-09-27 07:10 ——— d—–w C:\Program Files\Symantec
2007-09-27 06:52 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec
2007-09-27 06:47 4,608 —-a-w C:\WINDOWS\system32\drivers\symlcbrd.sys
2007-09-26 22:15 ——— d—–w C:\Program Files\microsoft frontpage
2007-09-05 13:43 69,960 —-a-w C:\WINDOWS\Unwash6.exe
2006-02-17 09:02 233,472 —ha-w C:\Documents and Settings\NetworkService.ZARZąDZANIE NT\NTUSER.DAT
2006-02-17 09:02 233,472 —ha-w C:\Documents and Settings\LocalService.ZARZąDZANIE NT\NTUSER.DAT
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\MFT 2540 —-

2007-11-11 22:19 998 –a—— C:\MFT 2540\sound\ExtScheduledSoundHeader$1.class
2007-11-11 22:19 976 –a—— C:\MFT 2540\qd3d\camera\CameraPlacement$1.class
2007-11-11 22:19 958 –a—— C:\MFT 2540\sound\SoundComponentData$1.class
2007-11-11 22:19 949 –a—— C:\MFT 2540\std\clocks\TimeCallBack.class
2007-11-11 22:19 936 –a—— C:\MFT 2540\qd3d\camera\CameraData$1.class
2007-11-11 22:19 934 –a—— C:\MFT 2540\sound\CompressionInfo$1.class
2007-11-11 22:19 932 –a—— C:\MFT 2540\qd\text\ScrpSTElement$1.class
2007-11-11 22:19 929 –a—— C:\MFT 2540\std\clocks\QTCallBack$1.class
2007-11-11 22:19 929 –a—— C:\MFT 2540\qd\WinNativeGraphics$1.class
2007-11-11 22:19 923 –a—— C:\MFT 2540\std\anim\SpriteWorld$1.class
2007-11-11 22:19 922 –a—— C:\MFT 2540\qd3d\math\Quaternion$1.class
2007-11-11 22:19 916 –a—— C:\MFT 2540\QTObjectManagement$1.class
2007-11-11 22:19 914 –a—— C:\MFT 2540\qd3d\math\Matrix4x4$1.class
2007-11-11 22:19 914 –a—— C:\MFT 2540\qd3d\math\Matrix3x3$1.class
2007-11-11 22:19 913 –a—— C:\MFT 2540\std\clocks\TimeBase$1.class
2007-11-11 22:19 913 –a—— C:\MFT 2540\std\clocks\CBRunner$1.class
2007-11-11 22:19 906 –a—— C:\MFT 2540\qd3d\math\Vector3D$1.class
2007-11-11 22:19 906 –a—— C:\MFT 2540\qd3d\math\Vector2D$1.class
2007-11-11 22:19 905 –a—— C:\MFT 2540\qd\OpenCPicParams$1.class
2007-11-11 22:19 898 –a—— C:\MFT 2540\qd3d\math\Point3D$1.class
2007-11-11 22:19 898 –a—— C:\MFT 2540\qd3d\math\Point2D$1.class
2007-11-11 22:19 894 –a—— C:\MFT 2540\sound\SndCommand$1.class
2007-11-11 22:19 894 –a—— C:\MFT 2540\sound\SndChannel$1.class
2007-11-11 22:19 889 –a—— C:\MFT 2540\std\clocks\Clock$1.class
2007-11-11 22:19 887 –a—— C:\MFT 2540\std\clocks\CBRunner$2.class
2007-11-11 22:19 886 –a—— C:\MFT 2540\sound\SPBDevice$1.class
2007-11-11 22:19 886 –a—— C:\MFT 2540\sound\SndHandle$1.class
2007-11-11 22:19 883 –a—— C:\MFT 2540\std\anim\Sprite$1.class
2007-11-11 22:19 882 –a—— C:\MFT 2540\std\clocks\CBRunner$1QTJPrivelegedAction.class
2007-11-11 22:19 881 –a—— C:\MFT 2540\qd\QDDimension$1.class
2007-11-11 22:19 878 –a—— C:\MFT 2540\sound\SCStatus$1.class
2007-11-11 22:19 873 –a—— C:\MFT 2540\qd\QDGraphics$1.class
2007-11-11 22:19 873 –a—— C:\MFT 2540\qd\ColorTable$1.class
2007-11-11 22:19 871 –a—— C:\MFT 2540\sound\SoundRunner$1QTJPrivelegedAction.class
2007-11-11 22:19 870 –a—— C:\MFT 2540\sound\SndInfo$1.class
2007-11-11 22:19 865 –a—— C:\MFT 2540\qd\SetGWorld$1.class
2007-11-11 22:19 8589 –a—— C:\MFT 2540\QTObjectManagement.class
2007-11-11 22:19 854 –a—— C:\MFT 2540\sound\Sound$1.class
2007-11-11 22:19 849 –a—— C:\MFT 2540\qd\QDPoint$1.class
2007-11-11 22:19 849 –a—— C:\MFT 2540\qd\QDColor$1.class
2007-11-11 22:19 849 –a—— C:\MFT 2540\qd\Polygon$1.class
2007-11-11 22:19 849 –a—— C:\MFT 2540\qd\GDevice$1.class
2007-11-11 22:19 841 –a—— C:\MFT 2540\qd\Region$1.class
2007-11-11 22:19 841 –a—— C:\MFT 2540\qd\QDRect$1.class
2007-11-11 22:19 841 –a—— C:\MFT 2540\qd\QDFont$1.class
2007-11-11 22:19 841 –a—— C:\MFT 2540\qd\PixMap$1.class
2007-11-11 22:19 838 –a—— C:\MFT 2540\sound\SPB$1.class
2007-11-11 22:19 8346 –a—— C:\MFT 2540\qd\Pict.class
2007-11-11 22:19 825 –a—— C:\MFT 2540\qd\Pict$1.class
2007-11-11 22:19 7972 –a—— C:\MFT 2540\sound\SPBDevice.class
2007-11-11 22:19 7923 –a—— C:\MFT 2540\qd\QDColor.class
2007-11-11 22:19 791 –a—— C:\MFT 2540\std\clocks\ExtremesCallBack.class
2007-11-11 22:19 7790 –a—— C:\MFT 2540\std\clocks\TimeBase.class
2007-11-11 22:19 751 –a—— C:\MFT 2540\qd3d\camera\OrthographicCameraData$1PrivelegedAction.class
2007-11-11 22:19 736 –a—— C:\MFT 2540\qd3d\camera\ViewPlaneCameraData$1PrivelegedAction.class
2007-11-11 22:19 732 –a—— C:\MFT 2540\sound\ExtScheduledSoundHeader$1PrivelegedAction.class
2007-11-11 22:19 722 –a—— C:\MFT 2540\QTSession$1.class
2007-11-11 22:19 716 –a—— C:\MFT 2540\qd3d\camera\CameraPlacement$1PrivelegedAction.class
2007-11-11 22:19 7155 –a—— C:\MFT 2540\qd3d\math\Matrix4x4.class
2007-11-11 22:19 707 –a—— C:\MFT 2540\sound\SoundComponentData$1PrivelegedAction.class
2007-11-11 22:19 692 –a—— C:\MFT 2540\sound\CompressionInfo$1PrivelegedAction.class
2007-11-11 22:19 691 –a—— C:\MFT 2540\qd3d\camera\CameraData$1PrivelegedAction.class
2007-11-11 22:19 690 –a—— C:\MFT 2540\qd\WinNativeGraphics$1PrivelegedAction.class
2007-11-11 22:19 687 –a—— C:\MFT 2540\std\clocks\QTCallBack$1PrivelegedAction.class
2007-11-11 22:19 6847 –a—— C:\MFT 2540\std\anim\Sprite.class
2007-11-11 22:19 684 –a—— C:\MFT 2540\std\anim\SpriteWorld$1PrivelegedAction.class
2007-11-11 22:19 683 –a—— C:\MFT 2540\QTObjectManagement$1PrivelegedAction.class
2007-11-11 22:19 683 –a—— C:\MFT 2540\qd3d\math\Quaternion$1PrivelegedAction.class
2007-11-11 22:19 678 –a—— C:\MFT 2540\qd3d\math\Matrix4x4$1PrivelegedAction.class
2007-11-11 22:19 678 –a—— C:\MFT 2540\qd3d\math\Matrix3x3$1PrivelegedAction.class
2007-11-11 22:19 677 –a—— C:\MFT 2540\std\clocks\TimeBase$1PrivelegedAction.class
2007-11-11 22:19 677 –a—— C:\MFT 2540\std\clocks\CBRunner$1PrivelegedAction.class
2007-11-11 22:19 675 –a—— C:\MFT 2540\qd\OpenCPicParams$1PrivelegedAction.class
2007-11-11 22:19 673 –a—— C:\MFT 2540\qd3d\math\Vector3D$1PrivelegedAction.class
2007-11-11 22:19 673 –a—— C:\MFT 2540\qd3d\math\Vector2D$1PrivelegedAction.class
2007-11-11 22:19 668 –a—— C:\MFT 2540\qd3d\math\Point3D$1PrivelegedAction.class
2007-11-11 22:19 668 –a—— C:\MFT 2540\qd3d\math\Point2D$1PrivelegedAction.class
2007-11-11 22:19 667 –a—— C:\MFT 2540\sound\SndCommand$1PrivelegedAction.class
2007-11-11 22:19 667 –a—— C:\MFT 2540\sound\SndChannel$1PrivelegedAction.class
2007-11-11 22:19 666 –a—— C:\MFT 2540\qd\text\ScrpSTElement$1PrivelegedAction.class
2007-11-11 22:19 662 –a—— C:\MFT 2540\std\clocks\Clock$1PrivelegedAction.class
2007-11-11 22:19 662 –a—— C:\MFT 2540\sound\SPBDevice$1PrivelegedAction.class
2007-11-11 22:19 662 –a—— C:\MFT 2540\sound\SndHandle$1PrivelegedAction.class
2007-11-11 22:19 660 –a—— C:\MFT 2540\qd\QDDimension$1PrivelegedAction.class
2007-11-11 22:19 659 –a—— C:\MFT 2540\std\anim\Sprite$1PrivelegedAction.class
2007-11-11 22:19 657 –a—— C:\MFT 2540\sound\SCStatus$1PrivelegedAction.class
2007-11-11 22:19 655 –a—— C:\MFT 2540\qd\QDGraphics$1PrivelegedAction.class
2007-11-11 22:19 655 –a—— C:\MFT 2540\qd\ColorTable$1PrivelegedAction.class
2007-11-11 22:19 6530 –a—— C:\MFT 2540\qd\QDConstants.class
2007-11-11 22:19 652 –a—— C:\MFT 2540\sound\SndInfo$1PrivelegedAction.class
2007-11-11 22:19 650 –a—— C:\MFT 2540\qd\SetGWorld$1PrivelegedAction.class
2007-11-11 22:19 642 –a—— C:\MFT 2540\sound\Sound$1PrivelegedAction.class
2007-11-11 22:19 640 –a—— C:\MFT 2540\qd\QDPoint$1PrivelegedAction.class
2007-11-11 22:19 640 –a—— C:\MFT 2540\qd\QDColor$1PrivelegedAction.class
2007-11-11 22:19 640 –a—— C:\MFT 2540\qd\Polygon$1PrivelegedAction.class
2007-11-11 22:19 640 –a—— C:\MFT 2540\qd\GDevice$1PrivelegedAction.class
2007-11-11 22:19 638 –a—— C:\MFT 2540\QTSession$2PrivelegedAction.class
2007-11-11 22:19 635 –a—— C:\MFT 2540\qd\Region$1PrivelegedAction.class
2007-11-11 22:19 635 –a—— C:\MFT 2540\qd\QDRect$1PrivelegedAction.class
2007-11-11 22:19 635 –a—— C:\MFT 2540\qd\QDFont$1PrivelegedAction.class
2007-11-11 22:19 635 –a—— C:\MFT 2540\qd\PixMap$1PrivelegedAction.class
2007-11-11 22:19 632 –a—— C:\MFT 2540\sound\SPB$1PrivelegedAction.class
2007-11-11 22:19 625 –a—— C:\MFT 2540\qd\Pict$1PrivelegedAction.class
2007-11-11 22:19 609 –a—— C:\MFT 2540\std\clocks\CBRunner$MRJIdler.class
2007-11-11 22:19 609 –a—— C:\MFT 2540\sound\SoundRunner$MRJIdler.class
2007-11-11 22:19 5689 –a—— C:\MFT 2540\qd3d\math\Quaternion.class
2007-11-11 22:19 546 –a—— C:\MFT 2540\QTSession$1PrivelegedAction.class
2007-11-11 22:19 5434 –a—— C:\MFT 2540\sound\SndChannel.class
2007-11-11 22:19 5225 –a—— C:\MFT 2540\qd3d\math\Matrix3x3.class
2007-11-11 22:19 513 –a—— C:\MFT 2540\MacDoQuit.class
2007-11-11 22:19 5120 –a—— C:\MFT 2540\sound\SPB.class
2007-11-11 22:19 4982 –a—— C:\MFT 2540\std\anim\SpriteWorld.class
2007-11-11 22:19 4959 –a—— C:\MFT 2540\qd\QDPoint.class
2007-11-11 22:19 4955 –a—— C:\MFT 2540\std\clocks\CBRunner.class
2007-11-11 22:19 4909 –a—— C:\MFT 2540\qd\text\ScrpSTElement.class
2007-11-11 22:19 481 –a—— C:\MFT 2540\sound\SoundRunner$SoundMethodClosure.class
2007-11-11 22:19 476 –a—— C:\MFT 2540\std\clocks\CBRunner$CBMethodClosure.class
2007-11-11 22:19 4758 –a—— C:\MFT 2540\qd3d\math\Point3D.class
2007-11-11 22:19 4753 –a—— C:\MFT 2540\sound\SoundRunner.class
2007-11-11 22:19 4719 –a—— C:\MFT 2540\sound\ExtScheduledSoundHeader.class
2007-11-11 22:19 457 –a—— C:\MFT 2540\sound\SoundRunner$SInterruptClosure.class
2007-11-11 22:19 4541 –a—— C:\MFT 2540\qd3d\math\Vector3D.class
2007-11-11 22:19 436 –a—— C:\MFT 2540\qd\QDException.class
2007-11-11 22:19 4342 –a—— C:\MFT 2540\sound\SoundComponentData.class
2007-11-11 22:19 404 –a—— C:\MFT 2540\sound\SoundException.class
2007-11-11 22:19 401 –a—— C:\MFT 2540\qd3d\QD3DException.class
2007-11-11 22:19 3999 –a—— C:\MFT 2540\qd3d\camera\CameraData.class
2007-11-11 22:19 3984 –a—— C:\MFT 2540\qd3d\camera\CameraPlacement.class
2007-11-11 22:19 3953 –a—— C:\MFT 2540\qd\WinNativeGraphics.class
2007-11-11 22:19 3869 –a—— C:\MFT 2540\qd\PixMap.class
2007-11-11 22:19 3786 –a—— C:\MFT 2540\qd3d\math\Vector2D.class
2007-11-11 22:19 3755 –a—— C:\MFT 2540\QTObject.class
2007-11-11 22:19 370 –a—— C:\MFT 2540\std\clocks\InterruptClosure.class
2007-11-11 22:19 3655 –a—— C:\MFT 2540\qd\GDevice.class
2007-11-11 22:19 362 –a—— C:\MFT 2540\QTUnknownOSException.class
2007-11-11 22:19 3608 –a—— C:\MFT 2540\qd\OpenCPicParams.class
2007-11-11 22:19 3526 –a—— C:\MFT 2540\qd\QDDimension.class
2007-11-11 22:19 3494 –a—— C:\MFT 2540\std\clocks\QTCallBack.class
2007-11-11 22:19 3477 –a—— C:\MFT 2540\sound\SndHandle.class
2007-11-11 22:19 3425 –a—— C:\MFT 2540\qd\Polygon.class
2007-11-11 22:19 3274 –a—— C:\MFT 2540\sound\SCStatus.class
2007-11-11 22:19 3213 –a—— C:\MFT 2540\sound\CompressionInfo.class
2007-11-11 22:19 3174 –a—— C:\MFT 2540\sound\SndCommand.class
2007-11-11 22:19 2878 –a—— C:\MFT 2540\qd\ColorTable.class
2007-11-11 22:19 2872 –a—— C:\MFT 2540\qd\NativeGraphics.class
2007-11-11 22:19 2767 –a—— C:\MFT 2540\qd3d\camera\CameraViewPort.class
2007-11-11 22:19 264 –a—— C:\MFT 2540\qd\NativeGraphicsException.class
2007-11-11 22:19 261 –a—— C:\MFT 2540\QTNullPointerException.class
2007-11-11 22:19 2482 –a—— C:\MFT 2540\qd3d\transform\RotateTransformData.class
2007-11-11 22:19 2475 –a—— C:\MFT 2540\qd3d\camera\ViewPlaneCameraData.class
2007-11-11 22:19 2352 –a—— C:\MFT 2540\qd3d\math\Point2D.class
2007-11-11 22:19 2311 –a—— C:\MFT 2540\qd3d\camera\OrthographicCameraData.class
2007-11-11 22:19 224 –a—— C:\MFT 2540\QTRuntimeHandler.class
2007-11-11 22:19 2216 –a—— C:\MFT 2540\qd3d\camera\CameraRange.class
2007-11-11 22:19 21751 –a—— C:\MFT 2540\qd\QDGraphics.class
2007-11-11 22:19 206 –a—— C:\MFT 2540\qd\QDDrawer.class
2007-11-11 22:19 2003 –a—— C:\MFT 2540\QTRuntimeException.class
2007-11-11 22:19 1960 –a—— C:\MFT 2540\QTException.class
2007-11-11 22:19 1927 –a—— C:\MFT 2540\sound\SndInfo.class
2007-11-11 22:19 1814 –a—— C:\MFT 2540\std\clocks\Clock.class
2007-11-11 22:19 175 –a—— C:\MFT 2540\sound\SoundCallBack.class
2007-11-11 22:19 166 –a—— C:\MFT 2540\sound\SICompletion.class
2007-11-11 22:19 1611 –a—— C:\MFT 2540\qd\SetGWorld.class
2007-11-11 22:19 1586 –a—— C:\MFT 2540\qd3d\QD3DConstants.class
2007-11-11 22:19 1575 –a—— C:\MFT 2540\QTConstants.class
2007-11-11 22:19 1495 –a—— C:\MFT 2540\sound\SoundRunner$1.class
2007-11-11 22:19 1386 –a—— C:\MFT 2540\qd\QDFont.class
2007-11-11 22:19 1340 –a—— C:\MFT 2540\qd3d\camera\ViewAngleAspectCameraData.class
2007-11-11 22:19 1253 –a—— C:\MFT 2540\sound\Sound.class
2007-11-11 22:19 12317 –a—— C:\MFT 2540\QTSession.class
2007-11-11 22:19 11201 –a—— C:\MFT 2540\sound\SoundConstants.class
2007-11-11 22:19 11166 –a—— C:\MFT 2540\qd\QDRect.class
2007-11-11 22:19 1105 –a—— C:\MFT 2540\QTSession$QTFrame.class
2007-11-11 22:19 1095 –a—— C:\MFT 2540\std\clocks\RateCallBack.class
2007-11-11 22:19 1055 –a—— C:\MFT 2540\qd\MacNativeGraphics.class
2007-11-11 22:19 10437 –a—— C:\MFT 2540\qd\Region.class
2007-11-11 22:19 1039 –a—— C:\MFT 2540\sound\SoundRunner$SndCallbackRunner.class
2007-11-11 22:19 1032 –a—— C:\MFT 2540\qd3d\camera\OrthographicCameraData$1.class
2007-11-11 22:19 1021 –a—— C:\MFT 2540\sound\SoundRunner$CompletionRunner.class
2007-11-11 22:19 1008 –a—— C:\MFT 2540\qd3d\camera\ViewPlaneCameraData$1.class

—- Directory of C:\MFT 5555 —-

2007-11-11 22:19 802 –a—— C:\MFT 5555\JDirectLinker$MethodSpec.class
2007-11-11 22:19 756 –a—— C:\MFT 5555\JDirectLinker$Library.class
2007-11-11 22:19 635 –a—— C:\MFT 5555\QuickTimeLib.class
2007-11-11 22:19 5701 –a—— C:\MFT 5555\JDirectLinker.class
2007-11-11 22:19 528 –a—— C:\MFT 5555\QTStreamingLib.class
2007-11-11 22:19 527 –a—— C:\MFT 5555\QuickTimeVRLib.class
2007-11-11 22:19 509 –a—— C:\MFT 5555\SoundLib.class
2007-11-11 22:19 508 –a—— C:\MFT 5555\PrimitivesLib.class
2007-11-11 22:19 384 –a—— C:\MFT 5555\QuickDraw3DLib.class
2007-11-11 22:19 3500 –a—— C:\MFT 5555\ProcInfo.class
2007-11-11 22:19 288 –a—— C:\MFT 5555\MCUPP.class
2007-11-11 22:19 286 –a—— C:\MFT 5555\MCX_14.class
2007-11-11 22:19 278 –a—— C:\MFT 5555\MCX.class
2007-11-11 22:19 2219 –a—— C:\MFT 5555\QTNative.class
2007-11-11 22:19 191 –a—— C:\MFT 5555\QD3DJavaLib.class
2007-11-11 22:19 1501 –a—— C:\MFT 5555\MethodClosure.class
2007-11-11 22:19 125 –a—— C:\MFT 5555\SharedLibrary.class

—- Directory of C:\WINDOWS\system32\rlo —-

C:\WINDOWS\system32\rlo\

—- Directory of C:\WINDOWS\system32\xhm —-

C:\WINDOWS\system32\xhm\


((((((((((((((((((((((((((((( snapshot@2007-11-13_22.24.24.09 )))))))))))))))))))))))))))))))))))))))))
.
- 2006-12-19 21:51:37 8,500,736 -c—-w C:\WINDOWS\system32\dllcache\shell32.dll
+ 2007-10-25 16:44:49 8,507,392 -c–a-w C:\WINDOWS\system32\dllcache\shell32.dll
+ 2007-06-11 20:34:34 2,115,816 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
+ 2007-06-11 20:34:40 190,696 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2007-11-14 15:06:03 45,218 —-a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
- 2007-09-28 05:19:39 18,089,592 —-a-w C:\WINDOWS\system32\MRT.exe
+ 2007-11-02 07:12:57 18,238,072 —-a-w C:\WINDOWS\system32\MRT.exe
- 2007-11-13 21:12:57 39,992 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-11-14 14:07:51 39,992 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2007-11-13 21:13:00 53,374 —-a-w C:\WINDOWS\system32\perfc013.dat
+ 2007-11-14 14:07:51 53,374 —-a-w C:\WINDOWS\system32\perfc013.dat
- 2007-11-13 21:13:00 311,604 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-11-14 14:07:51 311,604 —-a-w C:\WINDOWS\system32\perfh009.dat
- 2007-11-13 21:13:00 364,210 —-a-w C:\WINDOWS\system32\perfh013.dat
+ 2007-11-14 14:07:51 364,210 —-a-w C:\WINDOWS\system32\perfh013.dat
- 2007-11-13 18:23:04 103,736 —-a-w C:\WINDOWS\system32\PnkBstrB.exe
+ 2007-11-14 18:54:09 103,736 —-a-w C:\WINDOWS\system32\PnkBstrB.exe
- 2006-12-19 21:51:37 8,500,736 —-a-w C:\WINDOWS\system32\shell32.dll
+ 2007-10-25 16:44:49 8,507,392 —-a-w C:\WINDOWS\system32\shell32.dll
- 2007-06-14 10:56:58 369,664 —-a-w C:\WINDOWS\system32\xpsp3res.dll
+ 2007-10-29 15:07:26 369,664 —-a-w C:\WINDOWS\system32\xpsp3res.dll
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 10:38]
"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [2003-10-16 18:07]
"WOOTASKBARICON"="C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe" [2003-10-16 18:07]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 16:32]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-09-27 08:10]
"C-Media Mixer"="Mixer.exe" [2001-10-22 18:24 C:\WINDOWS\mixer.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:03 C:\WINDOWS\system32\bthprops.cpl]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-10-29 15:50]
"nwiz"="nwiz.exe" [2004-10-29 15:50 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2004-10-29 15:50]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2005-10-18 10:58]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 16:35]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"CloneDVDElbyDelay"="C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" [2002-11-02 07:33]
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [2005-05-19 14:47]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-11 07:41]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Norton SystemWorks"="C:\Program Files\Norton SystemWorks\cfgwiz.exe" [2004-09-10 03:12]
"Window Washer"="C:\Program Files\Webroot\Washer\wwDisp.exe" [2007-09-05 14:43]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:03]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 13:39]

C:\Documents and Settings\ruud\Menu Start\Programma's\Opstarten\
Watch.lnk - C:\WINDOWS\twain_32\A4CIS\WATCH.exe [2007-10-04 23:17:39]

C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programma's\Opstarten\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 09:01:04]
ZoneAlarm Pro.lnk - C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe [2007-09-27 13:38:07]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

R2 ADPTEHCD;%ADPT_USBEHCD.DeviceDesc%;C:\WINDOWS\system32\DRIVERS\asusehcd.sys
R2 AUSBD_FilterService;AUSBD Filter Service;C:\WINDOWS\system32\DRIVERS\asususbd.sys
R2 MA1908Driver;MA1908Driver;\??\C:\WINDOWS\system32\drivers\ma1908.sys
R2 UxTuneUp;TuneUp Thema-uitbreiding;C:\WINDOWS\System32\svchost.exe -k netsvcs
R2 wwEngineSvc;Window Washer Engine;C:\Program Files\Webroot\Washer\WasherSvc.exe
R3 ADPTHUBD;%ADPT_USBBHUBD.DeviceDesc%;C:\WINDOWS\system32\DRIVERS\asus2hub.sys
R3 NPDriver;Norton Unerase Protection Driver;\??\C:\WINDOWS\System32\Drivers\NPDRIVER.SYS
S3 SDdriver;SDdriver;\??\C:\WINDOWS\System32\Drivers\sddriver.sys

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

.
Inhoud van de 'Gedeelde Taken' map
"2007-11-09 18:31:21 C:\WINDOWS\Tasks\Easy Onderhoud.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2007-11-09 21:18:55 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - ruud.job"
- C:\PROGRA~1\NORTON~1\NORTON~3\Navw32.exe
"2007-11-12 11:07:38 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
"2007-11-13 23:00:00 C:\WINDOWS\Tasks\Symantec Drmc.job"
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-14 21:03:54
Windows 5.1.2600 Service Pack 2 NTFS

scannen van verborgen processen …

scannen van verborgen autostart items …

scannen van verborgen bestanden …

Scan succesvol afgerond
verborgen bestanden: 0

**************************************************************************
.
Voltooingstijd: 2007-11-14 21:08:27 - machine was rebooted
C:\ComboFix2.txt … 2007-11-13 22:25
.
— E O F —
2) log hijackthis:

Logfile of HijackThis v1.99.1
Scan saved at 21:14:05, on 14-11-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\Mixer.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\WINDOWS\twain_32\A4CIS\WATCH.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
G:\pre-program setup\hyjackthis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\NEOSTR~1\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - Startup: Watch.lnk = C:\WINDOWS\twain_32\A4CIS\WATCH.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1191395562156
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://przedsionek.spaces.live.com/PhotoUpload/MsnPUpld.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{265DA8DA-DB25-4157-BAF9-842FB54BE0F8}: NameServer = 194.204.159.1 217.98.63.164
O17 - HKLM\System\CS1\Services\Tcpip\..\{265DA8DA-DB25-4157-BAF9-842FB54BE0F8}: NameServer = 194.204.159.1 217.98.63.164
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

Best regards Ruud
Hi

Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

Folder::
C:\WINDOWS\system32\rlo 
C:\WINDOWS\system32\xhm

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.



Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:

      + Extended(If available otherwise Standard)
    • Scan Options:

      + Scan Archives
      + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post with a new HijackThis log.
With the exception of Internet Explorer, which is needed for the Kaspersky Scan, keep ALL programs closed until the scan is complete.
hello scotty,
Here are the logs:

1) combofix :

ComboFix 07-11-08.3 - ruud 2007-11-15 18:31:10.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.48.1043.18.383 [GMT 1:00]
Gestart vanuit: C:\Documents and Settings\ruud\Bureaublad\ComboFix.exe
Command switches used :: C:\Documents and Settings\ruud\Bureaublad\CFScript.txt
* Nieuw herstelpunt werd aangemaakt
.

(((((((((((((((((((( Bestanden Gemaakt van 2007-10-15 to 2007-11-15 ))))))))))))))))))))))))))))))
.

2007-11-15 14:11 d——– C:\Program Files\Common Files\xing shared
2007-11-13 22:15 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-11-13 22:02 d——– C:\WINDOWS\ERUNT
2007-11-13 19:27 d——– C:\Documents and Settings\ruud\Application Data\Talkback
2007-11-13 19:27 2,810 –a—— C:\WINDOWS\mozver.dat
2007-11-13 09:46 3,846 –a—— C:\WINDOWS\system32\tmp.reg
2007-11-12 22:59 d——– C:\Documents and Settings\ruud\Application Data\Grisoft
2007-11-12 22:58 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-12 22:57 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
2007-11-12 09:26 d——– C:\Incomplete
2007-11-12 09:26 d——– C:\Documents and Settings\ruud\Application Data\LimeWirePlus
2007-11-12 09:25 d——– C:\Program Files\LimeWire Plus
2007-11-12 08:50 d——– C:\WINDOWS\system32\NtmsData
2007-11-11 23:59 d——– C:\MFT 5555
2007-11-11 23:59 d——– C:\MFT 2540
2007-11-11 16:24 d——– C:\Program Files\Incomplete
2007-11-11 16:18 d-a—— C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2007-11-10 20:49 d——– C:\Program Files\LimeWire
2007-11-10 20:49 d——– C:\Documents and Settings\ruud\Application Data\LimeWire
2007-11-04 21:14 d——– C:\Program Files\Common Files\SureThing Shared
2007-11-04 21:14 2,560 ——— C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-11-04 21:14 2,432 ——— C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-11-04 19:47 237,568 –a—— C:\WINDOWS\system32\xvidvfw.dll
2007-11-04 19:40 d——– C:\Program Files\Yahoo!
2007-11-04 19:40 d——– C:\Program Files\illiminable
2007-11-04 19:40 d——– C:\Documents and Settings\All Users.WINDOWS\Application Data\YAHOO
2007-11-03 20:20 d——– C:\Program Files\Total Video Converter
2007-11-02 15:23 d——– C:\Program Files\Mozilla Thunderbird
2007-11-02 15:23 d——– C:\Documents and Settings\ruud\Application Data\Thunderbird
2007-11-02 15:23 335 –a—— C:\WINDOWS\nsreg.dat
2007-11-01 22:35 d——– C:\Program Files\eMule
2007-10-29 21:07 d——– C:\Program Files\UnderCoverXP
2007-10-29 20:09 d——– C:\Program Files\SlySoft
2007-10-29 20:01 d——– C:\Program Files\Elaborate Bytes
2007-10-25 23:10 552 –a—— C:\WINDOWS\system32\d3d8caps.dat
2007-10-24 20:21 d——– C:\Program Files\DSL Speed
2007-10-23 17:08 d——– C:\Program Files\SMAC
2007-10-23 07:06 d——– C:\Program Files\AvantGo Connect
2007-10-23 07:05 d——– C:\Program Files\Microsoft ActiveSync
2007-10-23 07:05 114,688 –a—— C:\WINDOWS\system32\MALSLIB.DLL
2007-10-23 07:05 65,613 –a—— C:\WINDOWS\system32\PPVEXP.DLL
2007-10-23 07:05 24,652 –a—— C:\WINDOWS\system32\UICOM.DLL
2007-10-22 23:06 d——– C:\Program Files\Windows Media Connect 2
2007-10-22 23:06 221,184 –a—— C:\WINDOWS\system32\wmpns.dll
2007-10-22 23:04 d——– C:\WINDOWS\system32\drivers\UMDF

.
((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-15 17:30 ——— d—–w C:\Documents and Settings\ruud\Application Data\MailWasherPro
2007-11-15 13:10 ——— d—–w C:\Program Files\Common Files\Real
2007-11-14 18:54 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-11-14 18:54 103,736 —-a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-11-14 12:59 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-11-12 11:11 ——— d—–w C:\Documents and Settings\ruud\Application Data\ACD Systems
2007-11-12 11:07 ——— d—–w C:\Program Files\Norton SystemWorks
2007-11-12 07:34 ——— d—–w C:\Program Files\Wolfenstein - Enemy Territory
2007-11-11 20:05 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\TuneUp Software
2007-11-10 20:03 ——— d—–w C:\Program Files\Java
2007-11-08 11:20 ——— d—–w C:\Program Files\Weather Watcher
2007-11-06 16:21 ——— d—–w C:\Program Files\TuneUp Utilities 2007
2007-11-04 18:47 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-04 18:47 ——— d—–w C:\Program Files\Thomson
2007-10-26 17:14 ——— d—–w C:\Documents and Settings\ruud\Application Data\Apple Computer
2007-10-13 10:00 ——— d—–w C:\Program Files\Neostrada TP
2007-10-12 21:29 ——— d—–w C:\Program Files\Folder Lock
2007-10-12 21:26 308 —-a-w C:\sccfg.sys
2007-10-11 06:42 ——— d—–w C:\Program Files\Real
2007-10-10 07:07 31,096 —-a-w C:\Documents and Settings\ruud\Application Data\GDIPFONTCACHEV1.DAT
2007-10-10 06:06 ——— d—–w C:\Program Files\QuickTime
2007-10-07 20:51 ——— d—–w C:\Program Files\MSN Messenger
2007-10-07 20:11 ——— d—–w C:\Program Files\Common Files\Java
2007-10-04 22:22 ——— d—–w C:\Program Files\iPhoto Plus 4
2007-10-04 22:19 ——— d—–w C:\Program Files\TextBridge Classic
2007-10-04 22:17 ——— d—–w C:\Program Files\Trust
2007-10-04 22:04 ——— d—–w C:\Documents and Settings\ruud\Application Data\CyberLink
2007-10-04 22:02 ——— d—–w C:\Program Files\CyberLink
2007-10-04 22:02 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\CyberLink
2007-10-04 21:54 ——— d—–w C:\Program Files\iTunes
2007-10-04 21:54 ——— d—–w C:\Program Files\iPod
2007-10-04 21:54 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple Computer
2007-10-04 21:53 ——— d—–w C:\Program Files\Common Files\InstallShield
2007-10-04 21:50 ——— d—–w C:\Program Files\DivX
2007-10-03 21:59 66,872 —-a-w C:\WINDOWS\system32\PnkBstrA.exe
2007-10-03 21:27 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\nView_Profiles
2007-10-03 20:54 ——— d—–w C:\Program Files\The All-Seeing Eye
2007-10-03 07:17 ——— d—–w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-10-01 06:50 ——— d—–w C:\Program Files\Uniblue
2007-10-01 06:50 ——— d—–w C:\Documents and Settings\ruud\Application Data\Uniblue
2007-09-29 17:56 ——— d—–w C:\Documents and Settings\ruud\Application Data\InternetCalls
2007-09-29 17:53 ——— d—–w C:\Program Files\InternetCalls.com
2007-09-28 20:42 ——— d—–w C:\Program Files\Codec Pack - All In 1
2007-09-28 14:15 ——— d—–w C:\Program Files\Common Files\Adobe
2007-09-28 10:33 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\avg7
2007-09-28 06:00 ——— d—–w C:\Documents and Settings\ruud\Application Data\AVG7
2007-09-27 21:21 ——— d—–w C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\AVG7
2007-09-27 21:07 ——— d—–w C:\Program Files\Common Files\Webroot Shared
2007-09-27 21:07 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Webroot
2007-09-27 20:05 ——— d—–w C:\Documents and Settings\ruud\Application Data\Symantec
2007-09-27 18:10 ——— d—–w C:\Program Files\PCI Audio Applications
2007-09-27 18:08 ——— d—–w C:\Program Files\ASUS
2007-09-27 18:05 4,608 —-a-w C:\WINDOWS\system32\w95inf32.dll
2007-09-27 18:05 ——— d—–w C:\Program Files\C-Media
2007-09-27 18:01 ——— d—–w C:\Documents and Settings\ruud\Application Data\InterTrust
2007-09-27 17:57 ——— d—–w C:\Documents and Settings\ruud\Application Data\PoivY
2007-09-27 17:31 ——— d—–w C:\Program Files\Webroot
2007-09-27 17:31 ——— d—–w C:\Documents and Settings\ruud\Application Data\Webroot
2007-09-27 16:08 ——— d—–w C:\Program Files\Common Files\ACD Systems
2007-09-27 16:08 ——— d—–w C:\Program Files\ACD Systems
2007-09-27 16:08 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\ACD Systems
2007-09-27 12:56 ——— d—–w C:\Documents and Settings\ruud\Application Data\TuneUp Software
2007-09-27 12:55 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-09-27 11:13 ——— d—–w C:\Program Files\FireTrust
2007-09-27 10:48 ——— d—–w C:\Program Files\Lavasoft
2007-09-27 10:46 ——— d—–w C:\Documents and Settings\ruud\Application Data\Lavasoft
2007-09-27 07:10 ——— d—–w C:\Program Files\SymNetDrv
2007-09-27 07:10 ——— d—–w C:\Program Files\Symantec
2007-09-27 06:52 ——— d—–w C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec
2007-09-27 06:47 4,608 —-a-w C:\WINDOWS\system32\drivers\symlcbrd.sys
2007-09-26 22:15 ——— d—–w C:\Program Files\microsoft frontpage
2007-09-05 13:43 69,960 —-a-w C:\WINDOWS\Unwash6.exe
2007-08-21 06:18 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
.

((((((((((((((((((((((((((((( snapshot@2007-11-13_22.24.24.09 )))))))))))))))))))))))))))))))))))))))))
.
- 2006-12-19 21:51:37 8,500,736 -c—-w C:\WINDOWS\system32\dllcache\shell32.dll
+ 2007-10-25 16:44:49 8,507,392 -c–a-w C:\WINDOWS\system32\dllcache\shell32.dll
+ 2007-06-11 20:34:34 2,115,816 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
+ 2007-06-11 20:34:40 190,696 —-a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2007-11-14 15:06:03 45,218 —-a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
- 2007-09-28 05:19:39 18,089,592 —-a-w C:\WINDOWS\system32\MRT.exe
+ 2007-11-02 07:12:57 18,238,072 —-a-w C:\WINDOWS\system32\MRT.exe
- 2007-11-13 21:12:57 39,992 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-11-15 07:24:10 39,992 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2007-11-13 21:13:00 53,374 —-a-w C:\WINDOWS\system32\perfc013.dat
+ 2007-11-15 07:24:10 53,374 —-a-w C:\WINDOWS\system32\perfc013.dat
- 2007-11-13 21:13:00 311,604 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-11-15 07:24:10 311,604 —-a-w C:\WINDOWS\system32\perfh009.dat
- 2007-11-13 21:13:00 364,210 —-a-w C:\WINDOWS\system32\perfh013.dat
+ 2007-11-15 07:24:10 364,210 —-a-w C:\WINDOWS\system32\perfh013.dat
- 2007-10-11 06:41:49 278,528 —-a-w C:\WINDOWS\system32\pncrt.dll
+ 2007-11-15 13:10:24 278,528 —-a-w C:\WINDOWS\system32\pncrt.dll
- 2007-10-11 06:41:51 6,656 —-a-w C:\WINDOWS\system32\pndx5016.dll
+ 2007-11-15 13:10:28 6,656 —-a-w C:\WINDOWS\system32\pndx5016.dll
- 2007-10-11 06:41:51 5,632 —-a-w C:\WINDOWS\system32\pndx5032.dll
+ 2007-11-15 13:10:28 5,632 —-a-w C:\WINDOWS\system32\pndx5032.dll
- 2007-10-11 06:42:05 185,688 —-a-w C:\WINDOWS\system32\rmoc3260.dll
+ 2007-11-15 13:10:49 185,944 —-a-w C:\WINDOWS\system32\rmoc3260.dll
- 2006-12-19 21:51:37 8,500,736 —-a-w C:\WINDOWS\system32\shell32.dll
+ 2007-10-25 16:44:49 8,507,392 —-a-w C:\WINDOWS\system32\shell32.dll
- 2007-06-14 10:56:58 369,664 —-a-w C:\WINDOWS\system32\xpsp3res.dll
+ 2007-10-29 15:07:26 369,664 —-a-w C:\WINDOWS\system32\xpsp3res.dll
.
((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 10:38]
"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [2003-10-16 18:07]
"WOOTASKBARICON"="C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe" [2003-10-16 18:07]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 16:32]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-09-27 08:10]
"C-Media Mixer"="Mixer.exe" [2001-10-22 18:24 C:\WINDOWS\mixer.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:03 C:\WINDOWS\system32\bthprops.cpl]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-10-29 15:50]
"nwiz"="nwiz.exe" [2004-10-29 15:50 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2004-10-29 15:50]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2005-10-18 10:58]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 16:35]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"CloneDVDElbyDelay"="C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" [2002-11-02 07:33]
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [2005-05-19 14:47]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-11-15 14:10]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Norton SystemWorks"="C:\Program Files\Norton SystemWorks\cfgwiz.exe" [2004-09-10 03:12]
"Window Washer"="C:\Program Files\Webroot\Washer\wwDisp.exe" [2007-09-05 14:43]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:03]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 13:39]

C:\Documents and Settings\ruud\Menu Start\Programma's\Opstarten\
Watch.lnk - C:\WINDOWS\twain_32\A4CIS\WATCH.exe [2007-10-04 23:17:39]

C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programma's\Opstarten\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 09:01:04]
ZoneAlarm Pro.lnk - C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe [2007-09-27 13:38:07]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

R2 ADPTEHCD;%ADPT_USBEHCD.DeviceDesc%;C:\WINDOWS\system32\DRIVERS\asusehcd.sys
R2 AUSBD_FilterService;AUSBD Filter Service;C:\WINDOWS\system32\DRIVERS\asususbd.sys
R2 MA1908Driver;MA1908Driver;\??\C:\WINDOWS\system32\drivers\ma1908.sys
R2 UxTuneUp;TuneUp Thema-uitbreiding;C:\WINDOWS\System32\svchost.exe -k netsvcs
R2 wwEngineSvc;Window Washer Engine;C:\Program Files\Webroot\Washer\WasherSvc.exe
R3 ADPTHUBD;%ADPT_USBBHUBD.DeviceDesc%;C:\WINDOWS\system32\DRIVERS\asus2hub.sys
R3 NPDriver;Norton Unerase Protection Driver;\??\C:\WINDOWS\System32\Drivers\NPDRIVER.SYS
S3 SDdriver;SDdriver;\??\C:\WINDOWS\System32\Drivers\sddriver.sys

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

.
Inhoud van de 'Gedeelde Taken' map
"2007-11-09 18:31:21 C:\WINDOWS\Tasks\Easy Onderhoud.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2007-11-09 21:18:55 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - ruud.job"
- C:\PROGRA~1\NORTON~1\NORTON~3\Navw32.exe
"2007-11-12 11:07:38 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
"2007-11-14 23:00:00 C:\WINDOWS\Tasks\Symantec Drmc.job"
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-15 18:34:19
Windows 5.1.2600 Service Pack 2 NTFS

scannen van verborgen processen …

scannen van verborgen autostart items …

scannen van verborgen bestanden …

Scan succesvol afgerond
verborgen bestanden: 0

**************************************************************************
.
Voltooingstijd: 2007-11-15 18:36:12
C:\ComboFix2.txt … 2007-11-14 21:08
C:\ComboFix3.txt … 2007-11-13 22:25
.
— E O F —






2) kaspersky online scan :

KASPERSKY ONLINE SCANNER REPORT
Thursday, November 15, 2007 10:21:00 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 15/11/2007
Kaspersky Anti-Virus database records: 459936
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
E:\
F:\
G:\
Scan Statistics
Total number of scanned objects 73061
Number of viruses found 11
Number of infected objects 32
Number of suspicious objects 12
Duration of the scan process 02:31:01

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users.WINDOWS\Application Data\Symantec\LiveUpdate\2007-11-15_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Geschiedenis\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\ruud\Application Data\$_hpcst$.hpc Object is locked skipped
C:\Documents and Settings\ruud\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\ruud\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\ruud\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\ruud\Local Settings\Geschiedenis\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\ruud\Local Settings\Temp\WCESLog.log Object is locked skipped
C:\Documents and Settings\ruud\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\ruud\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\ruud\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\ruud\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPStop.log Object is locked skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\QuarantineB96289C.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\QuarantineBB3227B.tmp/[From [removed]][Date Tue, 23 Oct 2007 12:41:15 +0200]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\QuarantineBB3227B.tmp/[From [removed]][Date Tue, 23 Oct 2007 12:41:15 +0200]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\QuarantineBB3227B.tmp Mail: suspicious - 2 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\QuarantineBB3227B.tmp CryptFF: suspicious - 2 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\19CB5321.exe Infected: not-a-virus:AdWare.Win32.BHO.aa skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\19D2271A.tmp Infected: not-a-virus:AdWare.Win32.BHO.aa skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\261C0825.t$m Infected: P2P-Worm.Win32.Kapucen.ac skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\53B24279.tmp/[From [removed]][Date Wed, 10 Oct 2007 11:51:59 +0200]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\53B24279.tmp/[From [removed]][Date Wed, 10 Oct 2007 11:51:59 +0200]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\53B24279.tmp Mail: suspicious - 2 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\53B24279.tmp CryptFF: suspicious - 2 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\6AC67314.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\76061AB3.tmp/[From [removed]][Date Wed, 10 Oct 2007 11:51:59 +0200]/UNNAMED/html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\76061AB3.tmp/[From [removed]][Date Wed, 10 Oct 2007 11:51:59 +0200]/UNNAMED Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\76061AB3.tmp Mail: suspicious - 2 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\76061AB3.tmp CryptFF: suspicious - 2 skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\77EF3C50.tmp Infected: Email-Worm.Win32.NetSky.q skipped
C:\qoobox\Quarantine\C\SDFix\backups\backups.zip.vir/backups/Crack.exe Infected: Trojan.Win32.Agent.cmn skipped
C:\qoobox\Quarantine\C\SDFix\backups\backups.zip.vir/backups/svchost.exe Infected: Trojan.Win32.Agent.cmn skipped
C:\qoobox\Quarantine\C\SDFix\backups\backups.zip.vir/backups/winlogon.exe Infected: not-a-virus:PSWTool.Win32.PassView.k skipped
C:\qoobox\Quarantine\C\SDFix\backups\backups.zip.vir ZIP: infected - 3 skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\lqulsack.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\qoobox\Quarantine\C\WINDOWS\system32\owtgvuax.exe.vir Infected: Trojan.Win32.Obfuscated.kp skipped
C:\RECYCLER\NPROTECT\NPROTECT.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP69\A0028507.exe Infected: Trojan.Win32.Agent.cmn skipped
C:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP69\A0028508.exe Infected: Trojan.Win32.Agent.cmn skipped
C:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP69\A0028509.exe Infected: Trojan.Win32.Agent.cmn skipped
C:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP72\A0028735.exe Infected: Trojan-Downloader.Win32.VB.bsb skipped
C:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP72\A0028737.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.ajq skipped
C:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP72\A0028738.exe Infected: Trojan-Downloader.Win32.Small.gll skipped
C:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP72\A0028739.exe Infected: Trojan-Downloader.Win32.VB.bsb skipped
C:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP72\A0036034.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP72\A0037928.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP72\A0039957.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP73\A0045278.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.ajq skipped
C:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP74\A0046805.exe Infected: not-a-virus:PSWTool.Win32.PassView.k skipped
C:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP74\A0046806.exe Infected: Trojan.Win32.Agent.cmn skipped
C:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP74\A0046807.exe Infected: Trojan.Win32.Agent.cmn skipped
C:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP75\A0047056.exe Infected: Trojan.Win32.Agent.cmn skipped
C:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP75\A0047058.exe Infected: Trojan.Win32.Agent.cmn skipped
C:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP75\A0047059.exe Infected: not-a-virus:PSWTool.Win32.PassView.k skipped
C:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP77\A0047241.dll Infected: not-a-virus:AdWare.Win32.SecToolBar.k skipped
C:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP77\A0047242.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP77\A0047243.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP78\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\SEND-HOME.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\TEMP\ZLT049bf.TMP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\657f940bfe57719e29dccbcd363c\msxml4-KB927978-enu.log Object is locked skipped
D:\RECYCLER\NPROTECT\NPROTECT.LOG Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{2FD2B4CB-FA7E-45AD-B3B2-C4F0B778A99E}\RP78\change.log Object is locked skipped
Scan process completed.
Hi

Follow the instructions here-
Norton Quarantine

and delete all files in the Quarantine folder. Remember to follow the instructions for your version of Norton.


The kaspersky online scanner can be removed through Add/Remove Programs, if you do not wish to keep it.


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the x and the /u, it needs to be there.

    [external image: Posted Image]
  • When shown the disclaimer, Select "2"

Now post a new HijackThis log, and let me know how your computer is behaving now.
Hello Scotty, here is the log:
After running combofix with the command you gave me the program uninstalled itself.
my computer behaves very good, is ,as far as i can see ,a bit quicker as before.
Best regards Ruud

PS: in the reportbox from norton are also some back ups, i didn't delete them, only 3 fils in the quaratainedepartment.

Logfile of HijackThis v1.99.1
Scan saved at 21:50:15, on 16-11-2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\Mixer.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\WINDOWS\twain_32\A4CIS\WATCH.exe
C:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe
C:\Program Files\Outlook Express\msimn.exe
C:\PROGRA~1\MOZILL~2\FIREFOX.EXE
G:\pre-program setup\hyjackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\NEOSTR~1\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Norton SystemWorks] "C:\Program Files\Norton SystemWorks\cfgwiz.exe" /GUID {05858CFD-5CC4-4ceb-AAAF-CF00BF39736A} /MODE CfgWiz
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - Startup: Watch.lnk = C:\WINDOWS\twain_32\A4CIS\WATCH.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1191395562156
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://przedsionek.spaces.live.com/PhotoUpload/MsnPUpld.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{265DA8DA-DB25-4157-BAF9-842FB54BE0F8}: NameServer = 194.204.159.1 217.98.63.164
O17 - HKLM\System\CS1\Services\Tcpip\..\{265DA8DA-DB25-4157-BAF9-842FB54BE0F8}: NameServer = 194.204.159.1 217.98.63.164
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
Hi

Congrats. You are all clean. :thumbup:


1 - Update Adobe Reader
Earlier versions of Adobe Reader have known security flaws so it is recommended that you update your copy
  • Go to Start > Control Panel > Add/Remove Programs
  • Remove ALL instances of Adobe Reader
  • Re-boot your computer as required.
  • Once ALL versions of Adobe Reader have been uninstalled, visit: www.adobe.com/uk/products/acrobat/readstep2.html and download the latest version of Adobe Reader
OR, after uninstalling Adobe Reader, you could try installing Foxit Reader from >here<
Foxit Reader has fewer add-ons therefore loads more quickly.


Here are some free programs I recommend, although you will not need them all.

Spybot Search and Destroy
Download it from here . Just choose a mirror and off you go.
Find here the tutorial on how to use Spybot properly here

Install Spyware Guard
Download it from here
Find here the tutorial on how to use Spyware Guard here

Install SpyWare Blaster
Download it from here
Find here the tutorial on how to use Spyware Blaster here

Install WinPatrol
Download it from here
Here you can find information about how WinPatrol works here


Make sure your Windows is ALWAYS up to date!

An unpatched Windows is vulnerable and even with the "best" Antivirus and Firewall installed, malware will find its way through.
So visit http://windowsupdate.microsoft.com/ to download and install the latest updates.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Please check out Tony Klein's article "How did I get infected in the first place?"


Follow this list and your potential for being infected again will reduce dramatically.

I'd be grateful if you could reply to this post so that I know you have read it and, if you've no other questions, the thread can be closed.
hello scotty, I've read the instructions and i will follow them up to make sure my computers stays clean. Again thank you very much for helping me solving this problems . Greetz Ruud

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI