Hoi Hekelgem,
Open een kladblokbestand.
Kopieer en plak daarin de onderstaande vetgedrukte tekst.
File::
C:\DOCUMENTS AND SETTINGS\ALL USERS\MENU START\Online Security Guide.url
C:\DOCUMENTS AND SETTINGS\ALL USERS\MENU START\Security Troubleshooting.url
C:\DOCUMENTS AND SETTINGS\MOENS\FAVORIETEN\Videos.url
C:\WINDOWS\unvise32.exe
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\load]
[HKEY_LOCAL_MACHINE\SOFTWARE\swearware, combofix_wow]
[HKEY_LOCAL_MACHINE\SOFTWARE\swearware, Runs]
[HKEY_LOCAL_MACHINE\SOFTWARE\swearware, snapshot]
[HKEY_LOCAL_MACHINE\SOFTWARE\swearware]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME, NextInstance]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, Legacy]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, ConfigFlags]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, Class]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, ClassGUID]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, DeviceDesc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000, Capabilities]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000\LogConf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000\Control]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME\0000]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme, Type]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme, ErrorControl]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme, Start]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme, ImagePath]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme, Group]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme\Enum, 0]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme\Enum, Count]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme\Enum, NextInstance]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme\Enum]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\catchme]
[HKEY_USERS\S-1-5-21-1292428093-1202660629-839522115-1004\Software\Wget]
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}, (Default)]
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID, (Default)]
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\ProgID]
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF]
[HKEY_USERS\S-1-5-21-1292428093-1202660629-839522115-1004\Software\Microsoft\Internet Explorer\Desktop\General, Wallpaper]
[HKEY_USERS\S-1-5-19\Control Panel\Desktop, Wallpaper]
[HKEY_USERS\S-1-5-20\Control Panel\Desktop, Wallpaper]
[HKEY_USERS\S-1-5-21-1292428093-1202660629-839522115-1004\Control Panel\Desktop, Wallpaper]
[HKEY_USERS\S-1-5-18\Control Panel\Desktop, Wallpaper]
[HKEY_USERS\S-1-5-19\Control Panel\Desktop, WallpaperStyle]
[HKEY_USERS\S-1-5-20\Control Panel\Desktop, WallpaperStyle]
[HKEY_USERS\S-1-5-21-1292428093-1202660629-839522115-1004\Control Panel\Desktop, WallpaperStyle]
[HKEY_USERS\S-1-5-18\Control Panel\Desktop, WallpaperStyle]
[HKEY_USERS\S-1-5-19\Control Panel\Colors, Background]
[HKEY_USERS\S-1-5-20\Control Panel\Colors, Background]
[HKEY_USERS\S-1-5-21-1292428093-1202660629-839522115-1004\Control Panel\Colors, Background]
[HKEY_USERS\S-1-5-18\Control Panel\Colors, Background]
Sla dit bestand op je bureaublad op als CFScript.txt.
Sleep CFScript.txt in ComboFix.exe
Dit zal ComboFix doen herstarten. Start opnieuw op als dat gevraagd wordt.
Post na herstart de inhoud van de Combofix.txt in je volgende antwoord. En laat dan Spyware Doctor nog eens runnen.
KAPE