Hoy,
Ik heb een virus gehad en verwijderd daarna gescand met NAV en online met Panda. Ik vermoed dat er nog iets niet goed is in Msconfig. Kan iemand mijn opstartlog
even nazien? Sorry ik zat zojuist verkeerd met mijn log.
StartupList report, 26-11-2003, 15:26:34
StartupList version: 1.52
Started from : C:\PROGRAM FILES\HIJACTHIS\HIJACKTHIS.EXE
Detected: Windows 98 SE (Win9x 4.10.2222A)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\LOGITECH\MOUSEWARE\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\ATNOTES\ATNOTES.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\HIJACTHIS\HIJACKTHIS.EXE
--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\WINDOWS\Start Menu\Programma's\Opstarten]
ATnotes.lnk = C:\Program Files\ATnotes\ATnotes.exe
Tclockex.exe.lnk = C:\Program Files\Klok Kalender\TCLOCKEX.EXE
Microsoft Office Snelzoeken.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
Taakcontrole = C:\WINDOWS\taskmon.exe
SystemTray = SysTray.Exe
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
ccRegVfy = "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
EM_EXEC = C:\PROGRA~1\LOGITECH\MOUSEW~1\SYSTEM\EM_EXEC.EXE
Systeemwerkbalk = SysTray.Exe
LoadQM = loadqm.exe
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
SchedulingAgent = mstask.exe
ccEvtMgr = "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
ScriptBlocking = "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=Explorer.exe
SCRNSAVE.EXE=
drivers=mmsystem.dll power.drv
--------------------------------------------------
C:\WINDOWS\WININIT.BAK listing:
(Created 26/11/2003, 11:13:10)
[rename]
NUL=D:\~MSSETUP.T\~msstfof.t\acmsetup.exe
NUL=D:\~MSSETUP.T\~msstfof.t\acmsetup.hlp
NUL=D:\~MSSETUP.T\~msstfof.t\mssetup.dll
NUL=D:\~MSSETUP.T\~msstfof.t\off97_bb.dll
NUL=D:\~MSSETUP.T\~msstfof.t\offsetup.ttf
NUL=D:\~MSSETUP.T\~msstfof.t\Word97.stf
NUL=D:\~MSSETUP.T\~msstfof.t\Word97.inf
NUL=D:\~MSSETUP.T\~msstfof.t\msvcrt20.dll
NUL=D:\~MSSETUP.T\~msstfof.t\msvcrt40.dll
NUL=D:\~MSSETUP.T\~msstfof.t\offclean.dll
NUL=D:\~MSSETUP.T\~msstfof.t\offcln97.opc
NUL=D:\~MSSETUP.T\~msstfof.t\ffast_bb.dll
NUL=D:\~MSSETUP.T\~msstfof.t\selfreg.dll
NUL=D:\~MSSETUP.T\~msstfof.t\32autole.dll
NUL=D:\~MSSETUP.T\~msstfof.t\wrd97inv.dll
NUL=D:\~MSSETUP.T\~msstfof.t\_MSSETUP._Q_
NUL=D:\~MSSETUP.T\~msstfof.t\acmsetup.exe
NUL=D:\~MSSETUP.T\~msstfof.t\acmsetup.hlp
NUL=D:\~MSSETUP.T\~msstfof.t\mssetup.dll
NUL=D:\~MSSETUP.T\~msstfof.t\off97_bb.dll
NUL=D:\~MSSETUP.T\~msstfof.t\offsetup.ttf
NUL=D:\~MSSETUP.T\~msstfof.t\Word97.stf
NUL=D:\~MSSETUP.T\~msstfof.t\Word97.inf
NUL=D:\~MSSETUP.T\~msstfof.t\msvcrt20.dll
NUL=D:\~MSSETUP.T\~msstfof.t\msvcrt40.dll
NUL=D:\~MSSETUP.T\~msstfof.t\offclean.dll
NUL=D:\~MSSETUP.T\~msstfof.t\offcln97.opc
NUL=D:\~MSSETUP.T\~msstfof.t\ffast_bb.dll
NUL=D:\~MSSETUP.T\~msstfof.t\selfreg.dll
NUL=D:\~MSSETUP.T\~msstfof.t\32autole.dll
NUL=D:\~MSSETUP.T\~msstfof.t\wrd97inv.dll
NUL=D:\~MSSETUP.T\~msstfof.t\_MSSETUP._Q_
--------------------------------------------------
C:\AUTOEXEC.BAT listing:
mode con codepage prepare=((850) C:\WINDOWS\COMMAND\ega.cpi)
mode con codepage select=850
SET Path=%Path%
--------------------------------------------------
Enumerating Browser Helper Objects:
NAV Helper - C:\Program Files\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}
(no name) - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
--------------------------------------------------
Enumerating Task Scheduler jobs:
Toepassing Optimalisatie Start.job
Symantec NetDetect.job
Norton AntiVirus - Mijn computer scannen.job
--------------------------------------------------
Enumerating Download Program Files:
[Update Class]
InProcServer32 = C:\WINDOWS\SYSTEM\IUCTL.DLL
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37937.376875
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
[{AD7FAFB0-16D6-40C3-AF27-585D6E6453FD}]
CODEBASE = http://dload.ipbill.com/del/loader.cab
[DD_v4.DDv4]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\DD_V4.OCX
CODEBASE = http://www.drivershq.com/DD_v4.CAB
[HouseCall Besturing]
InProcServer32 = C:\WINDOWS\DOWNLO~1\XSCAN53.OCX
CODEBASE = http://a840.g.akamai.net/7/840/537/0fb5e03023def1/housecall.antivirus.com/housecall/xscan53.cab
[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\DIRECTOR\SWDIR.DLL
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
[Microsoft Office Tools on the Web Control]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\OUTC.DLL
CODEBASE = http://officeupdate.microsoft.com/TemplateGallery/downloads/outc.cab
[MSN Chat Control 4.5]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\MSNCHAT45.OCX
CODEBASE = http://fdl.msn.com/public/chat/msnchat45.cab
[HouseCall Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\XSCAN51.OCX
CODEBASE = http://www.housecall.nl/housecall/xscan4.cab
[ddm_download.ddm_control]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\DDM_CONTROL.OCX
CODEBASE = http://download.rfwnad.com/cab/ddm_control.CAB
[InstallShield International Setup Player]
InProcServer32 = c:\WINDOWS\DOWNLO~1\ISETUP.DLL
CODEBASE = http://www.installengine.com/engine/isetup.cab
[ActiveScan Installer Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\ASINST.DLL
CODEBASE = http://www.pandasoftware.com/activescan/as5/asinst.cab
[TimetickerLittleHelpers.usfServer]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\TCPSERVER.OCX
CODEBASE = http://www.timeticker.com/Timeset/TcpServer.CAB
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
WebCheck: C:\WINDOWS\SYSTEM\WEBCHECK.DLL
--------------------------------------------------
End of report, 7.698 bytes
Report generated in 0,256 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Ik heb een virus gehad en verwijderd daarna gescand met NAV en online met Panda. Ik vermoed dat er nog iets niet goed is in Msconfig. Kan iemand mijn opstartlog
even nazien? Sorry ik zat zojuist verkeerd met mijn log.
StartupList report, 26-11-2003, 15:26:34
StartupList version: 1.52
Started from : C:\PROGRAM FILES\HIJACTHIS\HIJACKTHIS.EXE
Detected: Windows 98 SE (Win9x 4.10.2222A)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\PROGRAM FILES\LOGITECH\MOUSEWARE\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\ATNOTES\ATNOTES.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\HIJACTHIS\HIJACKTHIS.EXE
--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\WINDOWS\Start Menu\Programma's\Opstarten]
ATnotes.lnk = C:\Program Files\ATnotes\ATnotes.exe
Tclockex.exe.lnk = C:\Program Files\Klok Kalender\TCLOCKEX.EXE
Microsoft Office Snelzoeken.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
ScanRegistry = C:\WINDOWS\scanregw.exe /autorun
Taakcontrole = C:\WINDOWS\taskmon.exe
SystemTray = SysTray.Exe
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
ccRegVfy = "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
EM_EXEC = C:\PROGRA~1\LOGITECH\MOUSEW~1\SYSTEM\EM_EXEC.EXE
Systeemwerkbalk = SysTray.Exe
LoadQM = loadqm.exe
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
LoadPowerProfile = Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
SchedulingAgent = mstask.exe
ccEvtMgr = "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
ScriptBlocking = "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=Explorer.exe
SCRNSAVE.EXE=
drivers=mmsystem.dll power.drv
--------------------------------------------------
C:\WINDOWS\WININIT.BAK listing:
(Created 26/11/2003, 11:13:10)
[rename]
NUL=D:\~MSSETUP.T\~msstfof.t\acmsetup.exe
NUL=D:\~MSSETUP.T\~msstfof.t\acmsetup.hlp
NUL=D:\~MSSETUP.T\~msstfof.t\mssetup.dll
NUL=D:\~MSSETUP.T\~msstfof.t\off97_bb.dll
NUL=D:\~MSSETUP.T\~msstfof.t\offsetup.ttf
NUL=D:\~MSSETUP.T\~msstfof.t\Word97.stf
NUL=D:\~MSSETUP.T\~msstfof.t\Word97.inf
NUL=D:\~MSSETUP.T\~msstfof.t\msvcrt20.dll
NUL=D:\~MSSETUP.T\~msstfof.t\msvcrt40.dll
NUL=D:\~MSSETUP.T\~msstfof.t\offclean.dll
NUL=D:\~MSSETUP.T\~msstfof.t\offcln97.opc
NUL=D:\~MSSETUP.T\~msstfof.t\ffast_bb.dll
NUL=D:\~MSSETUP.T\~msstfof.t\selfreg.dll
NUL=D:\~MSSETUP.T\~msstfof.t\32autole.dll
NUL=D:\~MSSETUP.T\~msstfof.t\wrd97inv.dll
NUL=D:\~MSSETUP.T\~msstfof.t\_MSSETUP._Q_
NUL=D:\~MSSETUP.T\~msstfof.t\acmsetup.exe
NUL=D:\~MSSETUP.T\~msstfof.t\acmsetup.hlp
NUL=D:\~MSSETUP.T\~msstfof.t\mssetup.dll
NUL=D:\~MSSETUP.T\~msstfof.t\off97_bb.dll
NUL=D:\~MSSETUP.T\~msstfof.t\offsetup.ttf
NUL=D:\~MSSETUP.T\~msstfof.t\Word97.stf
NUL=D:\~MSSETUP.T\~msstfof.t\Word97.inf
NUL=D:\~MSSETUP.T\~msstfof.t\msvcrt20.dll
NUL=D:\~MSSETUP.T\~msstfof.t\msvcrt40.dll
NUL=D:\~MSSETUP.T\~msstfof.t\offclean.dll
NUL=D:\~MSSETUP.T\~msstfof.t\offcln97.opc
NUL=D:\~MSSETUP.T\~msstfof.t\ffast_bb.dll
NUL=D:\~MSSETUP.T\~msstfof.t\selfreg.dll
NUL=D:\~MSSETUP.T\~msstfof.t\32autole.dll
NUL=D:\~MSSETUP.T\~msstfof.t\wrd97inv.dll
NUL=D:\~MSSETUP.T\~msstfof.t\_MSSETUP._Q_
--------------------------------------------------
C:\AUTOEXEC.BAT listing:
mode con codepage prepare=((850) C:\WINDOWS\COMMAND\ega.cpi)
mode con codepage select=850
SET Path=%Path%
--------------------------------------------------
Enumerating Browser Helper Objects:
NAV Helper - C:\Program Files\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}
(no name) - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
--------------------------------------------------
Enumerating Task Scheduler jobs:
Toepassing Optimalisatie Start.job
Symantec NetDetect.job
Norton AntiVirus - Mijn computer scannen.job
--------------------------------------------------
Enumerating Download Program Files:
[Update Class]
InProcServer32 = C:\WINDOWS\SYSTEM\IUCTL.DLL
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37937.376875
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\FLASH\FLASH.OCX
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
[{AD7FAFB0-16D6-40C3-AF27-585D6E6453FD}]
CODEBASE = http://dload.ipbill.com/del/loader.cab
[DD_v4.DDv4]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\DD_V4.OCX
CODEBASE = http://www.drivershq.com/DD_v4.CAB
[HouseCall Besturing]
InProcServer32 = C:\WINDOWS\DOWNLO~1\XSCAN53.OCX
CODEBASE = http://a840.g.akamai.net/7/840/537/0fb5e03023def1/housecall.antivirus.com/housecall/xscan53.cab
[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\SYSTEM\MACROMED\DIRECTOR\SWDIR.DLL
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
[Microsoft Office Tools on the Web Control]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\OUTC.DLL
CODEBASE = http://officeupdate.microsoft.com/TemplateGallery/downloads/outc.cab
[MSN Chat Control 4.5]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\MSNCHAT45.OCX
CODEBASE = http://fdl.msn.com/public/chat/msnchat45.cab
[HouseCall Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\XSCAN51.OCX
CODEBASE = http://www.housecall.nl/housecall/xscan4.cab
[ddm_download.ddm_control]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\DDM_CONTROL.OCX
CODEBASE = http://download.rfwnad.com/cab/ddm_control.CAB
[InstallShield International Setup Player]
InProcServer32 = c:\WINDOWS\DOWNLO~1\ISETUP.DLL
CODEBASE = http://www.installengine.com/engine/isetup.cab
[ActiveScan Installer Class]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\ASINST.DLL
CODEBASE = http://www.pandasoftware.com/activescan/as5/asinst.cab
[TimetickerLittleHelpers.usfServer]
InProcServer32 = C:\WINDOWS\DOWNLOADED PROGRAM FILES\TCPSERVER.OCX
CODEBASE = http://www.timeticker.com/Timeset/TcpServer.CAB
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
WebCheck: C:\WINDOWS\SYSTEM\WEBCHECK.DLL
--------------------------------------------------
End of report, 7.698 bytes
Report generated in 0,256 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only