Helpmij tegen spyware offensief (deel 2)

Status
Niet open voor verdere reacties.
Geplaatst door justme
Dit is de eerste keer dat ik dit programma gebruik dus kunnen jullie mij alsjeblieft vertellen welke dingen ik mag verwijderen?

O2 - BHO: (no name) - {04079851-5845-4dea-848C-3ECD647AA554} - (no file)
O2 - BHO: (no name) - {237D0A5C-2818-4BB8-8E9C-D19F67DC2FC6} - (no file)

O4 - HKLM\..\Run: [runvxd32] C:\WINDOWS\wreg32.exe

O4 - HKLM\..\RunServices: [runvxd32] C:\WINDOWS\wreg32.exe

O4 - HKCU\..\Run: [runvxd32] C:\WINDOWS\wreg32.exe

O4 - HKCU\..\RunServices: [runvxd32] C:\WINDOWS\wreg32.exe

O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab

O16 - DPF: {841A9192-5690-11D4-A258-0040954A01BE} (DialXSCtl Object) - http://dialxs.nl/install/dialxs.ocx

Hoi justme,

Vink de bovenstaande aan, sluit alle vensters behalve HijackThis en klik op Fix checked.

Surf dan naar http://www.kaspersky.co.uk/remoteviruschk.html en laat daar C:\WINDOWS\wreg32.exe eens scannen.
Lijkt mij een trojan of virus.

Laat je het resultaat even weten?

Groetjes,

Pieter
 
Hoi Pieter,

Zou je mij ook uit de brand kunnen helpen?


Logfile of HijackThis v1.97.7
Scan saved at 9:36:31, on 23-12-2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\WINDOWS\tppaldr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\ctfmon.exe
E:\activesync\WCESCOMM.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Bastiaan\Mijn documenten\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.hotsearchbox.com/ie/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\tppaldr.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SystemSearch] REGEDIT.EXE -S c:\ie.reg
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "E:\activesync\WCESCOMM.EXE"
O4 - Global Startup: Microsoft Office.lnk = E:\Outlook 2000\Office\OSA9.EXE
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite (HKLM)
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .wmv: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll
O12 - Plugin for .wvx: C:\Program Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/SU/ocx/12119/CTSUEng.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...apple.com/qt503/nl/win/QuickTimeInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Besturing) - http://a840.g.akamai.net/7/840/537/7bffc02f794163/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/SU/ocx/12119/CTPID.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O16 - DPF: {FE8287E9-5F43-11D3-ABCA-00105A5C1F46} (HouseCall Control) - http://www.housecall.nl/housecall/xscan4.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{80722907-D417-4210-A6D8-79A8951A7982}: NameServer = 195.121.1.34 195.121.1.66




Alvast bedankt!
 
Geplaatst door Bas_weet_niet
Hoi Pieter,

Zou je mij ook uit de brand kunnen helpen?


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.hotsearchbox.com/ie/

O4 - HKLM\..\Run: [SystemSearch] REGEDIT.EXE -S c:\ie.reg

Alvast bedankt!

Hoi Bas,

Download, unzip en run: http://www.merijn.org/files/cwshredder.zip

Start dan opnieuw op en draai HijackThis nog een keer.
Kijk even of de twee bovenstaande weg zijn.

Zoniet, even handmatig fixen.

Groetjes,

Pieter
 
Pieter,

ik heb je adviezen opgevolgd en alles werkt weer naar behoren.
Bedankt voor je hulp en moeite!
 
Geplaatst door Pieter Arntz


Hoi justme,

Vink de bovenstaande aan, sluit alle vensters behalve HijackThis en klik op Fix checked.

Surf dan naar http://www.kaspersky.co.uk/remoteviruschk.html en laat daar C:\WINDOWS\wreg32.exe eens scannen.
Lijkt mij een trojan of virus.

Laat je het resultaat even weten?

Groetjes,

Pieter

Hoi Pieter ik ben naar die website gesurfd en kreeg dit als resultaat:
Current object: wreg32.exe


wreg32.exe/EXE-file Ok

Statistics:

--------------------------------------------------------------------------------
Known viruses: 79779 Updated: 23.12.2003
File size (Kb): 191 Scan time: 00:00:01
Speed (Kb/sec): 191 Virus bodies: 0
Archives: 1 Packed: 0
Folders: 0 Files: 2
Suspicious: 0 Warnings: 0
 
Hmmmm. Toch vertrouw ik hem niet. Wil je hem eens naar me mailen?
Adres vind je in het eerste bericht van dit draadje.

Groetjes,

Pieter
 
Ok hij is opgestuurd en ik denk dat je wel gelijk hebt want hotmail geeft ook al aan dat het bestand mogelijk onveilig is : (
 
Hm. Hotmail gebruikt McAfee dacht ik.
Zou kunnen, als ik straks thuiskom weet ik het gauw genoeg.(Hoop ik)

Groetjes,

Pieter
 
Logfile of HijackThis v1.97.7
Scan saved at 22:37:48, on 23-12-03
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\CA\ETRUST\INOCULATEIT\INOTASK.EXE
C:\PROGRAM FILES\CA\ETRUST\INOCULATEIT\INORT9X.EXE
C:\PROGRAM FILES\CA\ETRUST\INOCULATEIT\INORPC.EXE
C:\PROGRAM FILES\WINROUTE PRO\WINROUTE.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\WINDOWS\LOGWAT95.EXE
C:\PROGRAM FILES\CA\ETRUST\INOCULATEIT\REALMON.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\RUNDLL32.EXE
C:\PROGRAM FILES\WINROUTE PRO\WRCTRL.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM FILES\MULTIMEDIA HOTKEY PROGRAM\MMKBD.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SOL.EXE
C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
D:\DOWNLOADS.D\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.hotsearchbox.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.hotsearchbox.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.hotsearchbox.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.hotsearchbox.com/ie/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ad.nl/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.hotsearchbox.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.hotsearchbox.com/ie/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.hotsearchbox.com/ie/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.hotsearchbox.com/ie/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.hotsearchbox.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer aangeboden door @Home
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxy:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
F1 - win.ini: run=hpfsched
O2 - BHO: (no name) - {FFCBEECE-FB0C-11D2-AB16-00104B9BBBD2} - C:\WINDOWS\SYSTEM\AHIEHELP.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [Taakcontrole] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [LogWatch] C:\WINDOWS\LogWat95.exe
O4 - HKLM\..\Run: [Realtime Monitor] "C:\Program Files\CA\eTrust\InoculateIT\realmon.exe"
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [SystemSearch] REGEDIT.EXE -S c:\ie.reg
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [InoTask] C:\Program Files\CA\eTrust\InoculateIT\InoTask.exe
O4 - HKLM\..\RunServices: [InoRT] C:\Program Files\CA\eTrust\InoculateIT\InoRT9x.exe
O4 - HKLM\..\RunServices: [InoRPC] C:\Program Files\CA\eTrust\InoculateIT\InoRpc.exe
O4 - HKLM\..\RunServices: [WinRoute] "C:\Program Files\WinRoute Pro\winroute.exe" /hide
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
O4 - HKCU\..\Run: [WrCtrl] "C:\Program Files\WinRoute Pro\wrctrl.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE" /background
O4 - Startup: Multimedia Hotkey Program.lnk = C:\Program Files\Multimedia Hotkey Program\MMKbd.exe
O9 - Extra button: Real.com (HKLM)
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37928.0533796296
O16 - DPF: {841A9192-5690-11D4-A258-0040954A01BE} (DialXSCtl Object) - http://www.x0.nl/install2/dialxs.ocx


Ik hoop dat je er iets uit kunt halen, want er blijft steeds met Adaware steeds iets in quarantaine staan.
 
Sorry Pieter,
ben vergeten om een aanhef hierboven te zetten...;)
bij deze dan:

Hoi Pieter,

Hierbij mijn log....
 
Hier die van mij (heb spyware en virus problemen gehad ben geloof ik redelijk schoon)

Logfile of HijackThis v1.97.7
Scan saved at 23:14:45, on 23-12-2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\LEXPPS.EXE
C:\WINNT\Explorer.EXE
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\ZONELABS\vsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
D:\PROGRA~1\ZONEAL~1\zlclient.exe
D:\PROGRA~1\INCRED~1\bin\IMAPP.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
D:\Program Files\FlashGet\flashget.exe
C:\Documents and Settings\Bart\Bureaublad\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.startpagina.nl/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {000E7270-CC7A-0786-8E7A-DA09B51938A6} - C:\WINNT\System32\n3tpa1.dll
O2 - BHO: (no name) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - D:\Program Files\SnagIt 6\SnagItBHO.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\program files\adobe\acro\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - D:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - D:\Program Files\SnagIt 6\SnagItIEAddin.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\PROGRA~1\FLASHGET\fgiebar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [PrinTray] C:\WINNT\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [Zone Labs Client] D:\PROGRA~1\ZONEAL~1\zlclient.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - D:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://D:\PROGRA~1\office\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Ontvang alles met FlashGet - D:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Ontvang met FlashGet - D:\Program Files\FlashGet\jc_link.htm
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: FlashGet (HKLM)
O9 - Extra 'Tools' menuitem: &FlashGet (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .exe: D:\Program Files\opera\PLUGINS\NPFgc1.dll
O12 - Plugin for .iso: D:\Program Files\opera\PLUGINS\NPFgc1.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .zip: D:\Program Files\opera\PLUGINS\NPFgc1.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {9052EF88-394B-4F5E-BB0C-8C933FD5BD4C} (CoolTabs v1.5.0.4) -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37877.4606481481
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} (ddm_download.ddm_control) - http://download.rfwnad.com/cab/dlaccell.CAB
O16 - DPF: {FE8287E9-5F43-11D3-ABCA-00105A5C1F46} (HouseCall Control) - http://www.housecall.nl/housecall/xscan4.cab
 
Van Adaware snap ik niks...:(
Ik heb sinds gister al zo'n 6x gescand, dingen verwijderd, en later staan ze er even zo vrolijk weer...
Wat doe ik in vredesnaam verkeerd...?
Ik ben verder gegaan zonder de items aan te vinken en met vinkjes voor de items, en na een update (ook zonder trouwens) staan ze er weer...!

Wie helpt me hiermee...????
 
Geplaatst door Thea41


R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.hotsearchbox.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.hotsearchbox.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.hotsearchbox.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.hotsearchbox.com/ie/

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.hotsearchbox.com/ie/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.hotsearchbox.com/ie/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.hotsearchbox.com/ie/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.hotsearchbox.com/ie/

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.hotsearchbox.com/ie/

O4 - HKLM\..\Run: [SystemSearch] REGEDIT.EXE -S c:\ie.reg
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup

O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net

O16 - DPF: {841A9192-5690-11D4-A258-0040954A01BE} (DialXSCtl Object) - http://www.x0.nl/install2/dialxs.ocx

Hoi Thea41,

Download, unzip en run: http://www.merijn.org/files/cwshredder.zip

Ga dan naar Configuratiescherm > Software en verwijder New.Net aka NewDotNet (Domains)

Start dan opnieuw op, draai HijackThis nog een keer en Fix alles dat ik hierboven gequote heb dat nog aanwezig is.

Groetjes,

Pieter
 
Geplaatst door bartb112
Hier die van mij (heb spyware en virus problemen gehad ben geloof ik redelijk schoon)

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {000E7270-CC7A-0786-8E7A-DA09B51938A6} - C:\WINNT\System32\n3tpa1.dll

O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} (ddm_download.ddm_control) - http://download.rfwnad.com/cab/dlaccell.CAB

[/url]

Hoi bartb112,

Vink de bovenstaande aan, sluit alle vensters behalve HijackThis en klik op Fix checked.

Start dan opnieuw op en verwijder:
C:\WINNT\System32\n3tpa1.dll <= kan zijn dat hij al weg is

Groetjes,

Pieter
 
Geplaatst door Thea41
Van Adaware snap ik niks...:(
Ik heb sinds gister al zo'n 6x gescand, dingen verwijderd, en later staan ze er even zo vrolijk weer...
Wat doe ik in vredesnaam verkeerd...?
Ik ben verder gegaan zonder de items aan te vinken en met vinkjes voor de items, en na een update (ook zonder trouwens) staan ze er weer...!

Wie helpt me hiermee...????

Hoi Thea 41,

Dat komt waarschijnlijk doordat AdAWare maar een gedeelte van CWS weghaalt.

Na het draaien van CWShredder moet dat opgelost zijn.

Groetjes,

Pieter
 
Hoi Pieter,

Alles gedaan. Nu blijft er met Adaware nog een item staan en dat is iets met Kernell.32. Die blijft erin, wat ik ook doe. Verder is alles weg...!:thumb:

Ik heb nog 1 vraagje: in mijn temporary internetfiles blijven een aantal (16) dingen staan, die niet te verwijderen zijn. Enig idee hoe dat kan? Het zijn verschillende dingen, bv.: http://ad.nl.doubleclick.net/adj/algemeendagblad.nl/homeskyscraper;sz=120x600;tile=2;ord=1071850493210?

http://www.kuchl.at/dergasthof.html

http://www.ad.nl/images/kleindoublea175.jpg

iets van de rabobank met .ccs op het eind

http://www2.telegraaf.nl/template/ver1/images/transparent.gif

en de rest is met dezelfde icons als hierboven.
 
Hoi Thea41,

Kun je dat stukje met kernell eens uit het log van AdAware knippen en posten.
Dat klinkt wel erg verdacht. :confused:

Om de overgebleven rommel uit je Temp Inet files weg te krijgen zijn waarschijnlijk wel erg drastische maatregelen nodig. (Als er niks gevaarlijks tussen staat, zou ik daar niet aan beginnen)

Groetjes,

Pieter
 
Lavasoft Ad-aware Personal Build 6.181
Logbestand gemaakt op:woensdag 24 december 2003 11:59:08
Created with Ad-aware Personal, free for private use.
Gebruikt referentiebestand01R240 23.12.2003
______________________________________________________

Ad-aware Settings
=========================
Geactiveerd : Intensieve datascan activeren
Geactiveerd : Veilige modus (altijd vragen om bevestiging)
Geactiveerd : Scan actieve processen
Geactiveerd : Scan register
Geactiveerd : Diepe registerscan


24-12-03 11:59:08 - Scan started. (Smart mode)

Lijst van geladen processen:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯

#:1 [kernel32.dll]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4293870577
Threads : 4
Priority : High
FileSize : 464 KB
FileVersion : 4.10.2222
ProductVersion : 4.10.2222
Copyright : Copyright (C) Microsoft Corp. 1991-1999
CompanyName : Microsoft Corporation
FileDescription : Win32 Kernel-kerncomponent
InternalName : KERNEL32
OriginalFilename : KERNEL32.DLL
ProductName : Besturingssysteem Microsoft(R) Windows(R)
Created on : 1-1-01
Last accessed : 23-12-03 23:00:00
Last modified : 5-5-99 21:22:00

#:2 [msgsrv32.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294940505
Threads : 1
Priority : Normal
FileSize : 11 KB
FileVersion : 4.10.2222
ProductVersion : 4.10.2222
Copyright : Copyright (C) Microsoft Corp. 1992-1998
CompanyName : Microsoft Corporation
FileDescription : Windows 32-bits VxD-berichtserver
InternalName : MSGSRV32
OriginalFilename : MSGSRV32.EXE
ProductName : Besturingssysteem Microsoft(R) Windows(R)
Created on : 1-1-01
Last accessed : 23-12-03 23:00:00
Last modified : 5-5-99 21:22:00

#:3 [mprexe.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294935081
Threads : 1
Priority : Normal
FileSize : 28 KB
FileVersion : 4.10.1998
ProductVersion : 4.10.1998
Copyright : Copyright (C) Microsoft Corp. 1993-1998
CompanyName : Microsoft Corporation
FileDescription : WIN32 Network Interface Service Process
InternalName : MPREXE
OriginalFilename : MPREXE.EXE
ProductName : Microsoft(R) Windows(R) Operating System
Created on : 1-1-01
Last accessed : 23-12-03 23:00:00
Last modified : 5-5-99 21:22:00

#:4 [mstask.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294961589
Threads : 2
Priority : Normal
FileSize : 110 KB
FileVersion : 4.71.1972.1
ProductVersion : 4.71.1972.1
Copyright : Copyright (C) Microsoft Corp. 2000
CompanyName : Microsoft Corporation
FileDescription : Taakplanner Engine
InternalName : Taakplanner
OriginalFilename : mstask.exe
ProductName : Microsoft
Created on : 3-11-03 9:20:33
Last accessed : 23-12-03 23:00:00
Last modified : 3-11-03 9:20:34

#:5 [mmtask.tsk]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294847657
Threads : 1
Priority : Normal
FileSize : 1 KB
FileVersion : 4.03.1998
ProductVersion : 4.03.1998
Copyright : Copyright
CompanyName : Microsoft Corporation
FileDescription : Multimedia background task support module
InternalName : mmtask.tsk
OriginalFilename : mmtask.tsk
ProductName : Microsoft Windows
Created on : 1-1-01
Last accessed : 23-12-03 23:00:00
Last modified : 5-5-99 21:22:00

#:6 [inotask.exe]
FilePath : C:\PROGRAM FILES\CA\ETRUST\INOCULATEIT\
ProcessID : 4294961477
Threads : 5
Priority : Normal
FileSize : 213 KB
FileVersion : 6.0.96.0
ProductVersion : 6.0.96.0
Copyright : Copyright (c) 1992-2001 Computer Associates International, Inc.
CompanyName : Computer Associates International, Inc.
InternalName : InoTask.exe
OriginalFilename : InoTask.exe
ProductName : InoculateIT
Created on : 2-11-03 21:37:50
Last accessed : 23-12-03 23:00:00
Last modified : 19-7-01 18:20:30

#:7 [inort9x.exe]
FilePath : C:\PROGRAM FILES\CA\ETRUST\INOCULATEIT\
ProcessID : 4294882709
Threads : 8
Priority : Normal
FileSize : 157 KB
FileVersion : 6.0.96.0
ProductVersion : 6.0.96.0
Copyright : Copyright (c) 1992-2001 Computer Associates International, Inc.
CompanyName : Computer Associates International, Inc.
InternalName : InoRT9x.exe
OriginalFilename : InoRT9x.exe
ProductName : InoculateIT
Created on : 2-11-03 21:37:53
Last accessed : 23-12-03 23:00:00
Last modified : 19-7-01 18:20:18

#:8 [inorpc.exe]
FilePath : C:\PROGRAM FILES\CA\ETRUST\INOCULATEIT\
ProcessID : 4294879017
Threads : 8
Priority : Normal
FileSize : 133 KB
FileVersion : 6.0.96.0
ProductVersion : 6.0.96.0
Copyright : Copyright (c) 1992-2001 Computer Associates International, Inc.
CompanyName : Computer Associates International, Inc.
InternalName : InoRpc.exe
OriginalFilename : InoRpc.exe
ProductName : InoculateIT
Created on : 2-11-03 21:38:04
Last accessed : 23-12-03 23:00:00
Last modified : 19-7-01 18:20:14

#:9 [winroute.exe]
FilePath : C:\PROGRAM FILES\WINROUTE PRO\
ProcessID : 4294872393
Threads : 5
Priority : High
FileSize : 472 KB
FileVersion : 4, 0, 0, 1
Created on : 3-11-03 20:14:13
Last accessed : 23-12-03 23:00:00
Last modified : 1-12-00 17:23:52

#:10 [mdm.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294901293
Threads : 2
Priority : Normal
FileSize : 116 KB
FileVersion : 6.00.8149
ProductVersion : 6.00.8149
Copyright : Copyright (C) Microsoft Corp. 1997-1998
CompanyName : Microsoft Corporation
FileDescription : Machine Debug Manager
InternalName : mdm.exe
OriginalFilename : mdm.exe
ProductName : Microsoft (R) Visual Studio
Created on : 4-9-98 5:09:08
Last accessed : 23-12-03 23:00:00
Last modified : 4-9-98 5:09:08

#:11 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 4294825401
Threads : 18
Priority : Normal
FileSize : 176 KB
FileVersion : 4.72.3110.1
ProductVersion : 4.72.3110.1
Copyright : Copyright (C) Microsoft Corp. 1981-1997
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
OriginalFilename : EXPLORER.EXE
ProductName : Microsoft(R) Windows NT(R) Operating System
Created on : 5-5-99 21:22:00
Last accessed : 23-12-03 23:00:00
Last modified : 5-5-99 21:22:00

#:12 [taskmon.exe]
FilePath : C:\WINDOWS\
ProcessID : 4294715861
Threads : 1
Priority : Normal
FileSize : 28 KB
FileVersion : 4.10.1998
ProductVersion : 4.10.1998
Copyright : Copyright (C) Microsoft Corp. 1998
CompanyName : Microsoft Corporation
FileDescription : Task Monitor
InternalName : TaskMon
OriginalFilename : TASKMON.EXE
ProductName : Microsoft(R) Windows(R) Operating System
Created on : 1-1-01
Last accessed : 23-12-03 23:00:00
Last modified : 5-5-99 21:22:00

#:13 [systray.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294680753
Threads : 2
Priority : Normal
FileSize : 32 KB
FileVersion : 4.10.2222
ProductVersion : 4.10.2222
Copyright : Copyright (C) Microsoft Corp. 1993-1998
CompanyName : Microsoft Corporation
FileDescription : Toepassing Systeemwerkbalk
InternalName : SYSTRAY
OriginalFilename : SYSTRAY.EXE
ProductName : Besturingssysteem Microsoft(R) Windows(R)
Created on : 1-1-01
Last accessed : 23-12-03 23:00:00
Last modified : 5-5-99 21:22:00

#:14 [realplay.exe]
FilePath : C:\PROGRAM FILES\REAL\REALPLAYER\
ProcessID : 4294705113
Threads : 6
Priority : Normal
FileSize : 25 KB
FileVersion : 6.0.9.380
ProductVersion : 6.0.9.380
Copyright : Copyright
CompanyName : RealNetworks, Inc.
FileDescription : RealPlayer
InternalName : REALPLAY
OriginalFilename : REALPLAY.EXE
ProductName : RealPlayer (32-bit)
Created on : 2-11-03 20:51:07
Last accessed : 23-12-03 23:00:00
Last modified : 2-11-03 20:51:08

#:15 [logwat95.exe]
FilePath : C:\WINDOWS\
ProcessID : 4294784557
Threads : 1
Priority : Normal
FileSize : 48 KB
Created on : 8-6-00 11:22:02
Last accessed : 23-12-03 23:00:00
Last modified : 8-6-00 11:22:02

#:16 [realmon.exe]
FilePath : C:\PROGRAM FILES\CA\ETRUST\INOCULATEIT\
ProcessID : 4294700617
Threads : 4
Priority : Normal
FileSize : 365 KB
FileVersion : 6.0.96.0
ProductVersion : 6.0.96.0
Copyright : Copyright (c) 1992-2001 Computer Associates International, Inc.
CompanyName : Computer Associates International, Inc.
InternalName : Realmon.exe
OriginalFilename : Realmon.exe
ProductName : InoculateIT
Created on : 2-11-03 21:37:53
Last accessed : 23-12-03 23:00:00
Last modified : 19-7-01 18:21:20

#:17 [loadqm.exe]
FilePath : C:\WINDOWS\
ProcessID : 4294691021
Threads : 3
Priority : Normal
FileSize : 7 KB
FileVersion : 5.4.1103.3
ProductVersion : 5.4.1103.3
Copyright : Copyright (C) Microsoft Corp. 1981-1999
CompanyName : Microsoft Corporation
FileDescription : Microsoft QMgr
InternalName : LOADQM.EXE
OriginalFilename : LOADQM.EXE
ProductName : QMgr Loader
Created on : 3-11-03 9:36:35
Last accessed : 23-12-03 23:00:00
Last modified : 3-5-00 16:23:10

#:18 [stimon.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294691201
Threads : 5
Priority : Normal
FileSize : 112 KB
FileVersion : 4.10.2222
ProductVersion : 4.10.2222
Copyright : Copyright (C) Microsoft Corp. 1996-1998
CompanyName : Microsoft Corporation
FileDescription : Monitor voor Still Image-apparaten
InternalName : STIMON
OriginalFilename : STIMON.EXE
ProductName : Besturingssysteem Microsoft(R) Windows(R)
Created on : 1-1-01
Last accessed : 23-12-03 23:00:00
Last modified : 5-5-99 21:22:00

#:19 [wrctrl.exe]
FilePath : C:\PROGRAM FILES\WINROUTE PRO\
ProcessID : 4294583953
Threads : 1
Priority : Normal
FileSize : 40 KB
Created on : 3-11-03 20:14:13
Last accessed : 23-12-03 23:00:00
Last modified : 13-12-99 12:19:50

#:20 [msnmsgr.exe]
FilePath : C:\PROGRAM FILES\MSN MESSENGER\
ProcessID : 4294579221
Threads : 2
Priority : Normal
FileSize : 4568 KB
FileVersion : 6.1.0203
ProductVersion : Version 6.1
Copyright : Copyright (c) Microsoft Corporation 1997-2003
CompanyName : Microsoft Corporation
FileDescription : Messenger
InternalName : msnmsgr
OriginalFilename : msnmsgr.exe
ProductName : Messenger
Created on : 19-11-03 21:50:18
Last accessed : 23-12-03 23:00:00
Last modified : 19-11-03 21:50:18

#:21 [mmkbd.exe]
FilePath : C:\PROGRAM FILES\MULTIMEDIA HOTKEY PROGRAM\
ProcessID : 4294690537
Threads : 1
Priority : Normal
FileSize : 1368 KB
FileVersion : 2, 1, 0, 1
ProductVersion : 2, 5, 0, 1
Copyright : (C)SITECSOFT 2000
CompanyName : SITECSOFT Co., LTD.
FileDescription : MMKbd
InternalName : MMKbd
OriginalFilename : MMKbd.EXE
ProductName : MMKbd
Created on : 3-11-03 19:17:53
Last accessed : 23-12-03 23:00:00
Last modified : 30-1-01 14:08:08

#:22 [wmiexe.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294529977
Threads : 3
Priority : Normal
FileSize : 16 KB
FileVersion : 5.00.1755.1
ProductVersion : 5.00.1755.1
Copyright : Copyright (C) Microsoft Corp. 1981-1998
CompanyName : Microsoft Corporation
FileDescription : WMI service exe housing
InternalName : wmiexe
OriginalFilename : wmiexe.exe
ProductName : Microsoft(R) Windows NT(R) Operating System
Created on : 1-1-01
Last accessed : 23-12-03 23:00:00
Last modified : 5-5-99 21:22:00

#:23 [ddhelp.exe]
FilePath : C:\WINDOWS\SYSTEM\
ProcessID : 4294378265
Threads : 7
Priority : Realtime
FileSize : 31 KB
FileVersion : 4.08.01.0881
ProductVersion : 4.08.01.0881
Copyright : Copyright
CompanyName : Microsoft Corporation
FileDescription : Microsoft DirectX Helper
InternalName : DDHelp.exe
OriginalFilename : DDHelp.exe
ProductName : Microsoft
Created on : 3-11-03 18:18:13
Last accessed : 23-12-03 23:00:00
Last modified : 30-10-01 7:10:00

#:24 [sol.exe]
FilePath : C:\WINDOWS\
ProcessID : 4294414545
Threads : 1
Priority : Normal
FileSize : 167 KB
FileVersion : 4.10.1998
ProductVersion : 4.10.1998
Copyright : Copyright (C) Microsoft Corp. 1991-1998
CompanyName : Microsoft Corporation
FileDescription : Windows Patience (spel)
InternalName : Sol
OriginalFilename : SOL.EXE
ProductName : Besturingssysteem Microsoft(R) Windows(R)
Created on : 8-11-03 17:55:05
Last accessed : 23-12-03 23:00:00
Last modified : 5-5-99 21:22:00

#:25 [iexplore.exe]
FilePath : C:\PROGRAM FILES\INTERNET EXPLORER\
ProcessID : 4294477813
Threads : 25
Priority : Normal
FileSize : 89 KB
FileVersion : 6.00.2800.1106
ProductVersion : 6.00.2800.1106
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
OriginalFilename : IEXPLORE.EXE
ProductName : Besturingssysteem Microsoft
Created on : 3-9-02 23:00:00
Last accessed : 23-12-03 23:00:00
Last modified : 3-9-02 23:00:00

#:26 [ad-aware.exe]
FilePath : C:\PROGRAM FILES\LAVASOFT\AD-AWARE 6\
ProcessID : 4294246825
Threads : 2
Priority : Normal
FileSize : 668 KB
FileVersion : 6.0.1.181
ProductVersion : 6.0.0.0
Copyright : Copyright
CompanyName : Lavasoft Sweden
FileDescription : Ad-aware 6 core application
InternalName : Ad-aware.exe
OriginalFilename : Ad-aware.exe
ProductName : Lavasoft Ad-aware Plus
Created on : 23-12-03 20:14:05
Last accessed : 23-12-03 23:00:00
Last modified : 12-7-03 21:00:20

Resultaat van bestandsscan:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Nieuwe objecten: 0
Totaal tot nu toe geïdentificeerde objecten: 0


Start scan register
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯

Resultaat van registerscan:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Nieuwe objecten: 0
Totaal tot nu toe geïdentificeerde objecten: 0


Started deep registry scan
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯

Resultaat diepe registerscan:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Nieuwe objecten: 0
Totaal tot nu toe geïdentificeerde objecten: 0


¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯

Tracking Cookie Object herkend!
Typ : Bestanden
Data : thea@doubleclick[1].txt
Object : C:\WINDOWS\Cookies\

Created on : 24-12-03 10:32:51
Last accessed : 23-12-03 23:00:00
Last modified : 24-12-03 10:32:52


¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯


Dieptescan van bestanden (C:)
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯


Performing conditional scans..
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯

Conditional scan result:
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Nieuwe objecten: 0
Totaal tot nu toe geïdentificeerde objecten: 1


12:02:03 Systeemscan gereed

Samenvatting van het onderzoek
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
Totale tijd systeemscan:00:02:53:670
Objecten gescand:32141
Objecten geïdentificeerd:1
Objecten genegeerd:0
Nieuwe objecten:1


Nou Pieter,

Een hele waslijst....
 
Status
Niet open voor verdere reacties.
Terug
Bovenaan Onderaan