Emsisoft Emergency Kit - Versie 3.0 Laatste Update: 25-12-2012 13:23:49 Scaninstellingen: Scantype: Diepe scan Objecten: Rootkits, Geheugen, Sporen, C:\ Detecteer riskware: Uit Scan archieven: Aan ADS Scan: Aan Bestandsextensiefilter: Uit Geavanceerde cache: Aan Directe schijftoegang: Uit Scan gestart: 25-12-2012 13:24:47 C:\Program Files\Spytech Software\Spytech SpyAgent Ontdekt: Trace.File.Spytech SpyAgent (A) C:\Program Files\Spytech Software Ontdekt: Trace.File.Spytech SpyAnywhere (A) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\spytech spyagent Ontdekt: Trace.File.SpytechSpyAgent (A) C:\Program Files\WhiteSmoke\ Ontdekt: Trace.File.WhiteSmoke (A) C:\Windows\Base64.dll Ontdekt: Trace.File.NetVizor (A) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spytech SpyAgent\Remove Spytech SpyAgent.lnk Ontdekt: Trace.File.Spytech SpyAgent (A) C:\Windows\system32\sinvfct.dll Ontdekt: Trace.File.NetVizor 5.4 (A) Value: HKEY_CLASSES_ROOT\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\INPROCSERVER32 -> ThreadingModel Ontdekt: Trace.Registry.Bara de instrumente web a ISJ Bacau (A) Key: hkey_users\s-1-5-21-2331348273-910670993-731982724-1000\software\imesh Ontdekt: Trace.Registry.IMesh (A) Value: hkey_users\s-1-5-21-2331348273-910670993-731982724-1000\software\imesh -> LastOpenFileDir Ontdekt: Trace.Registry.iMesh (A) Value: HKEY_CLASSES_ROOT\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}\INPROCSERVER32 -> ThreadingModel Ontdekt: Trace.Registry.Widomaker Toolbar (A) Value: HKEY_CLASSES_ROOT\CLSID\{57CADC46-58FF-4105-B733-5A9F3FC9783C} -> AppID Ontdekt: Trace.Registry.els.mywebtattoo.com (A) Value: HKEY_CLASSES_ROOT\CLSID\{57CADC46-58FF-4105-B733-5A9F3FC9783C}\INPROCSERVER32 -> ThreadingModel Ontdekt: Trace.Registry.els.mywebtattoo.com (A) C:\ProgramData\sacache\7\324136.log -> (JAVASCRIPT 1) Ontdekt: Trojan.JS.Redirector.ASR (B) C:\ProgramData\sacache\7\324136.log -> (JAVASCRIPT-COMPILATION) Ontdekt: Trojan.JS.Redirector.ASR (B) Gescand 605035 Gevonden 15 Scan geëindigd: 26-12-2012 10:47:46 Scantijd: 21:22:59 C:\ProgramData\sacache\7\324136.log -> (JAVASCRIPT 1) In quarantaine Trojan.JS.Redirector.ASR (B) Value: HKEY_CLASSES_ROOT\CLSID\{57CADC46-58FF-4105-B733-5A9F3FC9783C} -> AppID In quarantaine Trace.Registry.els.mywebtattoo.com (A) Value: HKEY_CLASSES_ROOT\CLSID\{57CADC46-58FF-4105-B733-5A9F3FC9783C}\INPROCSERVER32 -> ThreadingModel In quarantaine Trace.Registry.els.mywebtattoo.com (A) Value: HKEY_CLASSES_ROOT\CLSID\{FCBCCB87-9224-4B8D-B117-F56D924BEB18}\INPROCSERVER32 -> ThreadingModel In quarantaine Trace.Registry.Widomaker Toolbar (A) Key: hkey_users\s-1-5-21-2331348273-910670993-731982724-1000\software\imesh In quarantaine Trace.Registry.IMesh (A) Value: hkey_users\s-1-5-21-2331348273-910670993-731982724-1000\software\imesh -> LastOpenFileDir In quarantaine Trace.Registry.IMesh (A) Value: HKEY_CLASSES_ROOT\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\INPROCSERVER32 -> ThreadingModel In quarantaine Trace.Registry.Bara de instrumente web a ISJ Bacau (A) C:\Windows\system32\sinvfct.dll In quarantaine Trace.File.NetVizor 5.4 (A) C:\Windows\Base64.dll In quarantaine Trace.File.NetVizor (A) C:\Program Files\WhiteSmoke\ In quarantaine Trace.File.WhiteSmoke (A) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\spytech spyagent In quarantaine Trace.File.SpytechSpyAgent (A) C:\Program Files\Spytech Software In quarantaine Trace.File.Spytech SpyAnywhere (A) C:\Program Files\Spytech Software\Spytech SpyAgent In quarantaine Trace.File.Spytech SpyAgent (A) C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spytech SpyAgent\Remove Spytech SpyAgent.lnk In quarantaine Trace.File.Spytech SpyAgent (A) In quarantaine 14